Discovery
We find out which services staff use and what kind of information ends up in them.
Work documents are already being pasted into chatbots, and management usually has no idea. The goal is not to ban it but to see which information is leaving the company and to give people a safe way of doing the same job.
The field is new, but the risks are familiar: leaks through prompts, dependence on an outside service and liability for other people's data. On top of that, the EU AI Act requires, among other things, that staff using AI have sufficient understanding of it.
We find out which services staff use and what kind of information ends up in them.
What may be sent, what may not, and which services are approved. A clear document instead of a blanket ban.
Microsoft 365 Copilot or a business edition of another service where your data is not used for training.
Before Copilot is switched on, we tidy up sharing in SharePoint and Teams, because Copilot surfaces anything the user can technically access.
A data processing agreement and a check of where data is processed, so any transfer outside the EU is documented.
For the rare cases where data must never leave your environment: a model in your own cloud tenant in the EU.
We start with an honest picture. A ban without an alternative does not work, people just stop mentioning it.
We look at network traffic and cloud app usage in Defender and talk to departments. Usage is typically wider than expected.
We write the rules and explain them with concrete examples in a short online session.
Staff receive an approved tool, and unapproved services can be blocked.
Usage is tracked, the rules adjusted and the list of approved services kept current.
Responsibility for personal data stays with you, whoever ends up processing it. An employee who pastes a spreadsheet of customer names into a free chatbot has handed personal data to a third party, possibly outside the EU and without a data processing agreement. Here the rules must come before any technology.
Those with business terms in which the provider commits not to train on your data, and whose terms you have actually read. Free personal versions do not belong on the list.
Details of named individuals, CPR numbers, contract terms, source code from internal systems, passwords and keys. The list is short, which is exactly why people can remember it and stick to it.
Copilot respects your existing permissions and, for European customers, processes data within Microsoft's EU Data Boundary. The problem is that many organisations share far too widely, so Copilot may surface payslips or contracts to the wrong person. That is why we fix access first.
Rarely. Business access to an external service plus clear rules is usually enough. A private model makes sense when requirements forbid data from leaving your environment.
Describe what you want AI to do and how confidential the information is. We will propose a solution, from rules alone to a model in your own tenant.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.