At a glance
Staff are already using AI at work. The main risk is not simply whether they use it, but what information they put into it, which accounts and tools they use, and whether the business has decided what is acceptable. A small business does not need an elaborate AI governance programme. It needs a short rule staff can understand, a limited list of approved tools, clear categories for business information, sensible access controls and practical training. Recent UK research found that 88% of surveyed decision makers believed external AI tools were being used within their organisations, while 51% feared staff were putting sensitive information into unauthorised tools.
What has happened
AI tools are now easy to access and useful for drafting, summarising, translating, analysing and generating ideas. Staff can often start using them within minutes, sometimes through personal accounts without the business knowing.
That creates a practical problem. An employee can copy customer details, quotations, source code, contracts or internal plans into a third party service before anyone has considered whether that information should leave the business.
A Consultancy.uk report published in 2026 described research by Turbotic involving more than 1,000 senior decision makers in UK businesses. It reported that 88% believed external AI tools were being used within their organisation, while 51% feared employees were feeding sensitive company information into unauthorised tools. The same report said 86% of UK employees felt they had not been adequately trained.
These are reported perceptions rather than a measurement of AI use across every UK business, but they illustrate the issue. Telling staff to be careful is not much of a control if nobody has defined what they can use, what they can share or what they should do when something goes wrong.
A total ban may reduce visible AI use, but it can also push useful work onto personal accounts and phones. A better objective is controlled use.
Who this applies to
- Small businesses where staff use public or workplace AI tools without recorded approval.
- Firms handling customer information, employee records, quotations, financial information, contracts or commercially sensitive material.
- Managers who want staff to benefit from AI without allowing confidential information into unknown services.
- Businesses that provide an AI tool but have no clear rule about what may be entered into it.
It is less relevant where a business has genuinely established that staff do not use AI for work. Even then, that should be checked rather than assumed.
Set clear rules for what staff may share
The first step is deciding what information staff can and cannot put into AI tools.
A useful rule should be short enough to remember and specific enough to guide normal work. Public or unapproved AI tools should not receive confidential client information, employee personal data, passwords, API keys, regulated information, trade secrets, financial records, legal dispute material or customer lists.
The BizTek Connection guidance lists similar categories and makes an important distinction: sensitive information may only be suitable where the particular platform and use have been specifically approved.
The business also needs to say what staff can do. Otherwise people are left to guess.
| Information | Suitable position |
|---|---|
| Public, non sensitive material | Permitted in an approved tool, with human checking |
| Internal working material | Restricted unless the tool and purpose are approved |
| Customer, employee or confidential business data | Prohibited in public tools unless specifically approved |
| Passwords, keys, secrets and regulated information | Do not enter into an AI tool |
General, non confidential information can often be used for tasks such as drafting, improving wording, summarising public material or explaining a concept, provided that someone checks the result.
Internal information should normally be treated as restricted unless the approved tool and workflow specifically cover it.
Personal data needs particular care. The Information Commissioner's Office states that processing remains processing even when it is incidental or unintentional. Using personal information because an AI tool needs it does not remove the business's data protection responsibilities.
The rule should live in one managed location and have a named owner. A generic template is of limited value if it does not reflect the firm's customers, contracts, systems and working practices.
Approve tools and limit access
Approving ChatGPT, Copilot or another AI product by name is not enough.
The business also needs to decide which account type, settings, integrations and uses are approved. Relevant questions include what the provider says about prompts and uploaded files, how long information is retained, what administrative controls are available and what other systems the tool can access.
A paid business account may provide stronger controls than a personal account, but paying for a service does not automatically make every use appropriate.
Access should also reflect what each person actually needs. Shared passwords make it difficult to establish who did what. Individual accounts, company managed sign in and removing access when someone changes role provide clearer control.
Integrations deserve separate consideration. A tool that helps someone draft an email does not automatically need access to their entire mailbox. An AI assistant used for writing does not necessarily need access to customer records, shared storage or source code.
The business should maintain a simple record showing each approved tool, who owns it, what it may be used for, what information is prohibited and any agreed exceptions.
Train staff and respond to mistakes
Training should reflect the work people actually do.
Staff need to understand that a customer email, quotation, employee record, contract or supplier document may still contain confidential or personal information even when it is only being pasted into a tool for summarising.
They also need to understand that AI output can be wrong. Approving a tool does not remove the need for someone to check the work it produces.
Mistakes need a clear reporting route. If someone pastes restricted information into an unapproved service, the useful response is immediate reporting rather than concealment.
A named person should be able to establish what was shared, which service received it, whether access or stored information can be removed and whether anyone else needs to be informed.
The Lorikeet Security guide identifies accidental disclosure as a practical risk and recommends having a response when an employee believes information has been shared incorrectly.
Incidents should also improve the rules. If staff repeatedly need an exception, the approved workflow may be too restrictive. If several people keep using the same unapproved tool, the business may need to provide a supported alternative.
Where this falls short
- A policy cannot show what happened if the business has no ownership, account records or review process.
- Access controls may not cover personal devices, browser extensions or connected services.
- An approved tool can still produce inaccurate, biased or unsuitable output.
- Removing names from a document may not remove all identifying information or commercial sensitivity.
- UK data protection duties still depend on the purpose and circumstances of processing.
These limits are reasons to build controls around how people genuinely use AI, rather than assuming a policy alone will remove the risk.
Worked example
Illustrative before and after: a small recruitment agency handles candidate CVs, client requirements, interview notes and salary information.
Before, a consultant copies a candidate's CV and interview notes into a public chatbot to help prepare a candidate summary. Another member of staff uses the same service to rewrite a client's job description.
Nobody knows whether the accounts are personal, whether information is retained or what other data has previously been entered. The agency has told staff to be careful with confidential information, but has not defined which tools or information are approved.
After, the agency classifies candidate information, client correspondence, interview notes and commercially sensitive terms as restricted.
Staff can still use an approved workplace AI tool for suitable drafting and non confidential tasks. A consultant might use AI to improve the structure of a candidate summary, but personal information is only processed through an approved workflow with the appropriate controls.
The AI tool does not receive access to the entire recruitment database, shared inbox or document store simply because one task would benefit from AI.
Staff know which tools they can use, what information requires approval and what to do if information is entered into the wrong service.
AI remains useful. The difference is that the agency has decided where it belongs in the process and what information it is allowed to handle.
Implevo's View
This is worth addressing where AI use is already happening informally, particularly where staff handle customer correspondence, pricing, employee information, supplier records or other sensitive business information.
It does not usually make sense to start by buying elaborate monitoring software.
The better starting point is understanding which AI tools people already use, what information moves into them and where a useful process can be supported without giving a tool unnecessary access.
The difficult part is deciding which tools staff can use, what information they can put into them, who approves exceptions and how those rules are applied within the systems people already work with.
Implevo would start by reviewing how information currently moves between staff, shared systems and AI tools. From there, the business can identify where simple rules are enough and where an approved workflow, access control or integration would provide a safer and more useful way to work.
This is the kind of issue an Implevo Discovery Day can help uncover as part of a wider review of how your business uses AI and automation.
References
- Half of UK firms fear staff are feeding company secrets to AI, Consultancy.uk, 9 September 2026
- What Business Information Should You Never Put Into an AI Tool?, BizTek Connection, 22 July 2026
- An Employee's Guide to Using AI Safely and Securely, Lorikeet Security, 28 April 2026
- How do we ensure lawfulness in AI?, Information Commissioner's Office, 28 October 2024