Service · Cybersecurity

Secure use of AI

Artificial intelligence has already arrived in your company, usually without passing by the management. Someone has a letter checked, someone else asks for a summary of a contract, a third person pastes in a salary table to get the gist of it. Banning does not work: the habit simply moves onto a personal phone where nobody can see it. What works is naming an acceptable tool, saying in three lines what must never be pasted into it, and then checking what is really going on.

One tool
approved for the whole company
Three rules
short enough to be remembered
Visibility
over the services actually in use
Training
short and shaped per department

Where this service reaches

This is first and foremost an organisational question. The technical part comes second, once everyone knows what is allowed and why the line sits where it does.

Put your scope to an engineer

Choosing an acceptable service

A business offer where the provider commits contractually not to train models on your material, with processing in the European Union where that is available, and terms you have genuinely read.

Usage rules

A single page: what may be submitted, what must never be, and the duty to reread anything produced before it goes to a client or into a file.

Accounts and access

Access through the company account with a second factor, never through a personal subscription paid on someone's own card and claimed back on expenses. Access is withdrawn when they leave, like everything else.

Visibility over usage

We measure which services are genuinely being reached from your network and your managed machines. The gap against what management imagines is usually instructive.

Technical guardrails

Sensitivity labels that stop a classified document being pasted into an outside service, blocking of services you did not approve on managed machines, and a warning message rather than a hard block where the use is merely debatable.

Training by department

Half an hour for the sales team, half an hour for administration, built around their own documents. A record of who attended is kept.

The way an engagement runs

We begin by looking at what already happens, before writing a single rule. A rule that ignores actual practice will not survive the first urgent deadline.

01

Observation

Traffic towards these services analysed and departments interviewed. Real usage almost always exceeds what gets said in a meeting.

02

Rules

The rules drafted and then discussed against concrete cases from your own work, in a short online session.

03

Alternative

The approved tool made available with access and payment handled centrally, and the services you decided against treated as you choose.

04

Follow-up

Usage tracked, rules corrected and the approved list refreshed, because the market shifts every quarter.

Responsibility for the data stays with you whatever tool is used. The colleague who pastes a named list of clients in arrears into a free service is passing personal data to a third party, possibly outside the European Union and with no processing agreement whatsoever. That is why the rules have to come before the tool, not after it.

Questions and answers

Those with clear business terms, where the provider undertakes not to reuse your material for training and where you can verify where processing happens. Free consumer versions have no place on the list, however much nicer they are to use.

Anything identifying individuals, medical records, the contents of client contracts, the source code of your internal applications, passwords and access keys. The list is short, which is precisely why people remember it.

It respects the permissions that already exist, which makes it mostly a revealer. If the folder holding payslips is shared with the whole company, Copilot will cheerfully summarise it for anyone who asks. So we always tidy up sharing before switching the assistant on, never the other way round.

Rarely. Business access to an existing service plus clear rules covers it almost every time. A model inside your own environment earns its keep when a regulation or a contractual undertaking forbids the data from leaving, which happens in parts of legal and medical work.

The European AI regulation expects organisations to ensure a sufficient level of competence among the people using such systems, without prescribing a format. A short session shaped around each department, with a record of who attended, is a reasonable answer. How far the duty reaches in your case is worth confirming with your legal counsel.

Set the boundaries before AI settles in by itself

Tell us what your teams want to use it for and how sensitive the material involved is. We will propose rules and a tool that fits.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.