Depending on which headline you’ve read this week, artificial intelligence is either about to make us all vastly more productive or become rather too clever for its own good.

Big conversations are underway about where AI technology is heading, how much freedom increasingly capable systems should be given, and what happens when they start doing things their developers hadn’t quite expected.

Meanwhile, back in Cumbria, the conversations we’re having with businesses are a little more immediate. Who in the team is using AI? Which tools are they using? What information are they putting into them, and does the business actually have any control over it? That’s what AI governance comes down to for most small and medium businesses – not stopping people from using AI, but knowing how it’s being used.

Microsoft Copilot for business comes up regularly because so many of our clients already use Microsoft 365, but it’s only one part of a much bigger picture. ChatGPT, Claude, Gemini and a growing number of specialist AI assistant tools are finding their way into everyday working life, sometimes because the business has made a conscious decision to use them and sometimes because somebody has found a useful tool online and quietly added it to their working day.

We can see why. Used well, AI can take some of the slog out of everyday jobs, from summarising meetings and drafting documents to analysing information and dealing with the action list everyone has been carefully ignoring since Tuesday.

The question isn’t really “Should we have Copilot?” anymore. It’s “How is AI being used across our business, and do we actually have any control over it?”

When helpful becomes a little too helpful

Anyone who has spent time with AI will know how enthusiastic it can be. Ask Claude to tidy an action list and, given half a chance, it can feel like you’ve accidentally employed a very eager graduate who has reorganised the meeting notes, suggested a new workflow and is now wondering whether you’d like a five-year strategic plan before lunch. It can be incredibly useful, although occasionally you do want to tell it to calm down a bit.

That enthusiasm needs more thought when AI becomes part of everyday business. Which tools are people using? Are they company-approved services or free accounts somebody has signed up for? What can those services access, and what information are people sharing with them?

Copilot is a good example because it sits within the Microsoft environment many of our clients already use. Microsoft 365 Copilot works with the permissions already in place within Microsoft 365, so if somebody can access company information through their account, Copilot may be able to work with that information too.

Other AI products and services work differently, which is exactly the point. Saying “we use AI tools for business” doesn’t describe one product, one set of permissions or one approach to privacy. It’s becoming a whole category of technology that businesses need to think about in much the same way they already think about software, cloud services and access to company systems.

What are people actually putting into it?

This is probably the bit we’d encourage every business to think about, because controlling what an AI service can access is only half the story. The other half is what your team is choosing to give it.

It’s very easy to drop a proposal, spreadsheet, customer email or contract into an AI tool and ask for help, without really thinking about the sensitive business or customer information going with it.

IT teams have spent years worrying about shadow IT – unapproved software creeping into the business. AI has just given it a new, more enthusiastic form.
The AI tool to worry about, therefore, might not be the one your IT team knows about. People naturally find tools that make their jobs easier, whether that’s ChatGPT, Claude or a free PDF summariser, but problems arise when nobody has agreed which tools are safe to use, what can be shared with them or where that information goes afterwards.

Sometimes the immediate AI threat to a Cumbrian company isn’t a supercomputer plotting the downfall of humanity. It’s Dave copying the customer database into a free AI tool because he wants some help sorting the postcode column.

Our apologies to all the Daves out there.

Cumbrian fencing

We’ve recently had clients asking us about restricting access to particular applications or controlling who can use certain AI capabilities. Those are really sensible questions we’d encourage every business and organisation to ask.

AI doesn’t need to be an all-or-nothing decision. Access can be managed around the needs of the business and the roles within it, just as you would with other systems and company information – which is really just AI risk management without the jargon.

For one organisation, that might mean giving certain teams access to approved AI tools while restricting others. For another, it might mean reviewing Microsoft 365 permissions before rolling Copilot out more widely. Businesses with particular requirements around data residency or GDPR  may also need to look more closely at the Microsoft services and licensing they’re using, rather than assuming that every AI service handles data in exactly the same way.

In other words, you can put a fence around AI without putting it back in the box. Being Cumbrian, we’re fairly comfortable with fences. (Dry stone walls are also available, although Microsoft support for those remains limited.)

A bit of policy goes a long way

Nobody at iTek is going to suggest writing a 94-page AI acceptable use policy that gets saved to SharePoint and never opened again. What matters is giving people straightforward guidance about which AI services they can use, what they shouldn’t put into them and when something needs checking by an actual human being.

That last part is particularly easy to forget because AI can be remarkably convincing even when it’s wrong. If it’s helping with customer communications, contracts, financial information or business decisions, somebody still needs to check what comes back. “Claude seemed pretty sure” probably isn’t going to carry much weight afterwards.

At iTek, we like technology that makes people’s working lives easier, and AI can certainly do that. What we don’t particularly like is technology creeping into a business without anyone knowing what it can access, where the data is going or who is responsible for it.

That’s why we’re already talking to clients across Cumbria about the wider picture, from ChatGPT, Claude and other AI services to Copilot data security, Microsoft 365 permissions, data location, GDPR and sensible AI governance policies around how teams use these tools.

The aim isn’t to stop people using AI. It’s to let them use it with some sensible boundaries around it, so the business gets the benefit without handing over the keys to everything in the process.

As for whether AI will eventually pose a threat to humanity, we’ll leave that one to the researchers for now.

We’ve got enough on making sure it doesn’t have access to the HR folder.