Living guide · AI & Emerging Tech

Using AI in Your Business: Which Tools, Where Your Data Goes, and the Policy You Need Before Anyone Starts

Your staff are already using AI, whether or not you have decided anything. The question is whether they are pasting client data into a free chatbot or working inside a tool that keeps it in your tenant. Here is how we advise businesses to use AI well: Copilot as the default, other tools for what they are best at, staff trained, and a short policy everyone has read.

Last reviewed 24 September 2026 Published 24 September 2026 11 min read
Book a Discovery Call
This guide is for you if
  • Staff are already using ChatGPT or similar and nobody has said what is and is not allowed.
  • You want the productivity gain without a data breach, an ICO complaint or a client finding out their contract was pasted into a chatbot.
  • You have been offered Copilot licences and want to know whether to say yes and what to do first.

The short answer

Use Microsoft Copilot as your default AI tool because it works on your own data inside your Microsoft 365 tenant, under the same permissions and protections as everything else there, and Microsoft does not train its models on it. Use ChatGPT, Claude, Gemini and the rest for what they are genuinely better at, on business accounts with data controls, and never with client or personal data. Set Copilot up properly before you licence it, train your staff, and write a one-page AI usage policy that says which tools are approved, what may and may not be shared, and who is accountable for what the AI produces.

In this guide
  1. 1. It is already happening
  2. 2. Why Copilot first
  3. 3. Set it up safely
  4. 4. The other tools
  5. 5. The policy
  6. 6. Training
  7. 7. How we help
  8. 8. FAQs
01

It is already happening in your business

Every survey of UK workplaces says the same thing and our own audits confirm it: a large share of staff use an AI assistant at work, most of them a free consumer one, and most without telling anyone. They paste in a customer email to draft a reply, a spreadsheet to find the pattern, a contract to summarise the clauses.

That is not malice. It is people trying to do their jobs faster with the tools in front of them. But a free chatbot on a personal account is outside every control you have: no idea what was shared, no record, no way to delete it, and terms of service that may allow the provider to keep and learn from it. If a client asked "has our data ever been put into an AI tool?", most businesses could not answer.

The fix is not to ban AI. Bans do not work and they hand the advantage to competitors. The fix is to give people a safe default, be honest about when other tools are better, and write down the rules.

02

Why we recommend Copilot as the default

Microsoft 365 Copilot is the AI assistant built into Word, Excel, Outlook, Teams and the rest, and it has one property the consumer tools do not: it works on your data, inside your tenant, under your existing controls.

  • It only sees what the signed-in person is allowed to see. Permissions, sensitivity labels and data loss prevention all apply.
  • Prompts, responses and the data it reads through Microsoft 365 stay within Microsoft's enterprise data boundary. Microsoft states that they are not used to train the underlying models, and the same enterprise data protection terms cover both the paid licence and the free Copilot Chat that comes with your plan.
  • It is covered by the same UK GDPR contractual terms, audit logs and retention policies as your email and files. When the ICO or a client asks where the data went, there is an answer.
  • There is nothing new for staff to log into. It is a button in the apps they already use.

For most businesses that means: switch on Copilot Chat for everyone at no extra cost, and buy the paid Copilot licence for the people who write, summarise and sit in meetings all day. Our Copilot readiness and licences page covers which licence and the current UK prices.

Not sure which of these applies to your business? Ask an engineer.

Book a Discovery Call
03

Setting Copilot up safely is a separate skill

Buying the licence is not the same as being ready for it. Copilot can read everything the person using it can read, and in most small businesses that is far more than anyone intended, because SharePoint permissions were never designed. If a junior can open the directors' folder because a site was shared with Everyone in 2021, Copilot will cheerfully summarise the board pack for them.

Before licensing anyone we check five things: where the data actually lives, who can see what (the sharing reports are usually a shock), who would use it and for what, whether people are prepared, and how a pilot will be measured. Then we fix the oversharing, apply sensitivity labels to the documents that matter, configure the Copilot settings, and run a pilot with a named group before rolling out. The Copilot readiness check is the full list.

This is the part that most businesses skip, and the part that turns Copilot from a data leak into an asset.

04

The other tools are genuinely good, for the right jobs

Copilot is the safe default, not the best tool for everything. ChatGPT, Claude, Gemini, Grok and others are often better at particular tasks, and pretending otherwise just sends staff back to using them in secret.

TaskWhere the other tools shine
Long, careful writing and editingClaude and ChatGPT are frequently preferred for drafting proposals, reports and difficult emails from scratch.
Research and current informationGemini, Grok and ChatGPT with web access are strong at pulling together up-to-date information and sources.
Code, formulas and technical problem-solvingClaude and ChatGPT are excellent for scripts, Excel formulas, and explaining an error message.
Images, presentations and creative workThe consumer tools have richer image and design capabilities than Copilot in most Office apps.
Thinking out loudA general assistant with no access to your data is a fine place to work through an idea, precisely because there is no data in it.

The rules for using them are what matter:

  • Use business or enterprise accounts, not personal ones. ChatGPT Business, Claude for Work, Gemini for Workspace and similar have data controls, admin management and terms that exclude your data from training. Free personal accounts usually do not.
  • Never put client data, personal data or anything confidential into a tool outside your tenant. Names, contracts, financials, HR matters, anything you would not email to a stranger. Use Copilot for that, or anonymise it first.
  • Treat the output as a draft from a confident junior. Check facts, check figures, check that it has not invented a case or a statistic. The person who sends it is accountable for it, not the tool.
  • Assume it may be wrong about the law, tax and medicine. Use it to prepare questions for a professional, not to replace one.
  • Keep company accounts on company email, so access ends when the person leaves.
05

The AI usage policy: one page, read by everyone

You do not need a 20-page document. You need one page that a new starter reads on day one and that answers the questions people actually have. A good one covers:

  1. Approved tools. Copilot as the default. Named other tools, on company business accounts only. Anything else needs asking first.
  2. What may be shared, and where. Client, personal, financial and confidential data: Copilot only. General knowledge, public information and anonymised examples: any approved tool. A short list of things that never go into any AI tool, such as passwords, card details and anything under NDA.
  3. Checking the output. The person using the tool owns the result and checks it before it goes anywhere. Facts, figures, quotes and legal or regulatory statements are verified.
  4. Transparency. When to tell a client or a colleague that AI was used, and when it must not be used at all (some client contracts and regulated activities say so).
  5. Personal data and UK GDPR. AI use is data processing. The ICO expects you to know what personal data goes into which tool and on what basis. For most businesses that means: personal data stays in Copilot, and anything more ambitious gets a data protection assessment first.
  6. Training and questions. Who to ask, and that everyone does the short training before they use the tools.
  7. What happens when it goes wrong. Report it, do not hide it. A pasted document is far easier to deal with in the first hour.

The policy sits alongside your acceptable use and data protection policies, and it is reviewed twice a year because the tools change faster than anything else you use. We provide a template and adapt it to how your business actually works.

06

Training: an hour, in their own work

The training that works is short and specific. Not "what is AI", but: here is Copilot in your inbox, here is how to summarise this thread, here is what happens when you ask it about a folder you should not have access to, here is the one thing you must never paste into ChatGPT. Forty-five minutes with the team's real documents, a written prompt guide, and a named champion in the business who keeps it alive after week two.

The businesses that get value from AI are not the ones with the most licences. They are the ones where people know what to use it for and where the line is.

07

How we help, and where to start

We do the whole thing or any part of it: the Copilot readiness review and the permissions fixes, the licence review so you only pay for people who will use it, the AI usage policy adapted to your business, the staff training, and the ongoing management of the tenant so the controls stay in place as people join and leave.

If you are not sure where you stand, the conversation starts with a short call and the last Microsoft invoice. We will tell you what your people are probably already doing, what to switch on, what to switch off, and what to write down.

08

Frequently asked questions

Is Copilot safe to use with client data?

Yes, with the tenant set up properly. Copilot works inside your Microsoft 365 tenant under your existing permissions, labels and data loss prevention, and Microsoft states that prompts, responses and the data accessed through Microsoft 365 are not used to train its models. The risk is oversharing inside your own tenant, which is why the readiness review comes first.

Can staff use ChatGPT, Claude or Gemini at work?

Yes, for the right tasks, on company business accounts with data controls, and never with client, personal or confidential data. That is exactly what the AI usage policy sets out, so people know rather than guess.

Do we need an AI policy if we are a small business?

Yes. It is one page, it takes an afternoon, and it is the difference between 'we knew what our staff were doing' and 'we found out from a client'. It is also what an insurer, an auditor or a customer's due diligence will ask to see.

Does using AI count as processing personal data under UK GDPR?

If personal data goes into it, yes. The ICO's guidance on AI and data protection applies. Keeping personal data inside Copilot, where your existing GDPR terms and controls cover it, is the simplest way to stay on the right side of that.

Will AI replace jobs in our business?

In our experience it removes the parts of jobs people dislike, summarising, drafting, finding the thing in the folder, and gives the time back. Businesses that measure a pilot properly usually find the gain is real but smaller than the hype, and concentrated in a handful of roles. Licence those roles and let everyone else use Copilot Chat.

What should we do first?

Three things this month: switch on Copilot Chat for everyone, write the one-page policy and get everyone to read it, and run the sharing reports in Microsoft 365 to see what people can actually reach. Then decide on paid licences with evidence.

Get AI working safely in your business

A short call to see what your people are already doing, what to switch on, what to lock down, and what to write down. We will bring the policy template and the readiness checklist.

  • Which tools to approve and on what accounts.
  • What Copilot can currently reach that it should not.
  • A one-page AI usage policy adapted to you.
  • Who to licence, and a short training plan.
Book an AI adoption chat

Sources

Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.

  1. 1.Microsoft Learn: Data, privacy and security for Microsoft 365 Copilot · accessed 24 September 2026
  2. 2.ICO: Artificial intelligence and data protection guidance · accessed 24 September 2026
  3. 3.NCSC: AI and cyber security, what you need to know · accessed 24 September 2026

What has changed on this page

  • 24 September 2026Page published.

More guides

Related reading