Your business is already using AI. Has your governance caught up?

Learn how to identify the AI tools already in use across your business, manage access and data risks, and put practical governance in place.

AI tools often enter a business through one employee, one browser tab and one free trial at a time.

A member of the marketing team uses AI to improve or speed up content creation. A manager introduces a meeting assistant, while finance tests an automation platform.

Each decision may solve a genuine problem, but together they can leave the business with a collection of tools that nobody manages.

Leaders may not know which tools employees use, what information those tools can access or who approved them. Former employees may still have accounts, while current employees may have connected AI products to company email, files or customer data without involving IT.

Why businesses should review AI use now

Article 50 of the EU AI Act began to apply on 2 August 2026. It introduced transparency requirements for providers and deployers of certain AI systems.

Providers of directly interactive AI systems must make sure people know when they’re interacting with AI. Providers of generative systems must add machine-readable markings to relevant outputs.

Organisations that deploy certain systems must also tell people when they use emotion recognition or biometric categorisation, and label deepfakes and some AI-generated public-interest text where no human has reviewed it or taken editorial responsibility for it.

The European Commission’s guidance on Article 50 transparency requirements explains who must comply and what the rules cover.

These rules don’t require businesses to label every piece of content that an AI tool helped create, and they don’t cover every routine use of an AI writing assistant.

The Act can also apply to organisations outside the EU if they place an AI system or general-purpose AI model on the EU market, or put an AI system into service or use it within the EU. Businesses that think the rules may apply to them should seek legal advice based on their circumstances.

The European Commission’s guide to the scope and application of the AI Act provides more information for organisations inside and outside the EU.

For MSPs and their customers, the August date also provides a useful reason to review the technology itself.

You need to know which tools employees use, where those tools connect and whether your current security controls cover them.

Start with an AI tools register

You can’t manage technology when nobody has recorded it.

An AI tools register gives the business a clear view of the products and features that employees use. It should include platforms that the business buys centrally, free accounts, trials and AI features that suppliers have added to existing software.

AI now appears in far more than tools such as ChatGPT or Microsoft Copilot. Employees may use it through meeting platforms, customer relationship management systems, design software, service desks, finance products and collaboration tools.

For each tool, record:

  • Who uses it
  • What they use it for
  • Who owns the account
  • Whether the business has approved it
  • What information it can access
  • Which company systems it connects to
  • Whether the business pays for it
  • When someone last reviewed it

This exercise may reveal that several departments pay for products that perform similar jobs. It may also uncover free accounts that employees created with company email addresses, old trials that still hold business data or integrations that nobody remembers approving.

Your MSP can help identify applications, review sign-in records and check connections across your technology estate. Department heads can then explain how their teams use each product and whether it still provides enough value.

Set practical rules around company information

Employees may understand that they need to protect confidential information and still feel unsure about what they can enter into an AI tool.

A customer service employee may want to paste in a customer email and ask for a summary. A manager may want to upload meeting notes. Someone in finance may ask a tool to review a contract, while a developer may share part of the company’s code to help diagnose an error.

The answer will depend on the information involved, the product, the account type, the supplier’s terms and the controls that the business has configured.

Clear guidance should tell employees which tools they can use and what information they can share.

The business might allow employees to use public information for basic drafting tasks in one tool, while requiring a company-controlled account for internal documents. Leaders may also prohibit employees from sharing customer data, passwords, financial details or sensitive employee information without approval.

Your IT partner can review account settings, data controls, retention options and supplier documentation. Your legal or data protection advisers should answer questions about personal data and regulatory duties.

Employees need rules they can apply during a normal working day. A broad instruction to use AI responsibly doesn’t give them enough guidance.

Check which systems AI tools can access

Employees can get more value from AI tools when they connect them to email, documents, calendars and business applications. Those connections also give the tools access to more information.

A meeting assistant may access calendars, calls and recordings. An AI search tool may scan SharePoint or Google Drive. A finance team may connect an automation platform to customer records. A browser extension may read information from every page an employee opens.

Before managers approve a connection, they should check:

  • Which information the tool can read
  • Whether it can create, change or delete information
  • Which employees can use the connection
  • Whether administrators can control access centrally
  • How the business can remove access
  • What the supplier does with stored data when the contract ends

Teams should also review the permissions that employees already hold. An AI assistant connected to a badly organised document library may give employees access to information they shouldn’t see.

Leaders should review AI alongside identity management, file permissions, multifactor authentication and regular access checks.

The National Cyber Security Centre’s guidance for leaders using AI helps managers, board members and senior executives understand the security risks and benefits of using AI tools.

Give employees approved tools

Employees who see a clear benefit from using AI may create personal accounts or use products without involving IT.

Company-controlled tools give them a safer option.

Some suppliers give business account administrators stronger access controls, clearer data settings and central management options than they give users of free consumer accounts. Suppliers set different terms and controls for each subscription level, so someone needs to review the details before the organisation approves a product.

Your MSP can review:

  • Account ownership and administration
  • Single sign-on options
  • Multifactor authentication
  • User permissions
  • Data storage and retention settings
  • Connections to existing systems
  • Joiner and leaver processes
  • Supplier security information

Business leaders can then decide whether the tool meets the organisation’s needs and whether employees need training before they use it.

Identify customer-facing AI

Some teams use AI within internal processes. Others use it to communicate with customers or influence the service they receive.

Customers may speak to an AI chatbot on your website. The service desk may use AI to categorise tickets or draft replies. The marketing team may generate customer communications. An automation platform may decide where employees should route an enquiry.

Record each customer-facing use and give one person responsibility for it.

That person should understand what the system does, what information it uses and when an employee needs to check the output. They should also know how to switch it off or move to a manual process when it isn’t working as expected.

Your MSP can help identify the systems, integrations and technical controls. Business leaders should decide where employees need to review the output, while legal advisers can confirm any disclosure or compliance requirements.

Make the policy match reality

A policy has little value when employees don’t recognise the tools or working practices it describes.

Build the policy from the tools register and the technical review.

Employees should know which tools they can use, what information they can share, how they can request a new product and who they should contact when something goes wrong.

The IT team or MSP should know how to remove access when someone leaves, review new integrations and check whether suppliers have changed important terms or features.

Leaders should treat the policy as part of normal technology management. They should review it alongside software licences, security controls, access permissions and supplier contracts.

Five practical steps for August

A business can start with five actions:

  1. Create a register of every AI tool and feature that employees use.
  2. Identify which tools connect to company systems or hold company data.
  3. Remove unused accounts, trials and integrations.
  4. Give employees clear guidance on approved tools and information sharing.
  5. Give one person responsibility for every customer-facing or business-critical AI use.

AI can save time, reduce repetitive administration and help employees work more effectively. Businesses gain more from those tools when leaders know what people use and manage them with the same care as every other part of IT.

IT Naturally can help you identify AI use across your environment, review your readiness for Microsoft 365 Copilot, support the development of a Responsible AI Use Policy and put the technical governance in place to help you adopt AI securely and responsibly.

Get in touch if you’d like to talk through where to start.