Skip to content
AI & Automation

How to bring AI into your company without losing control of it

A practical guide for SMEs: what to decide before choosing an AI tool, how to keep client data out of personal accounts, and what a proper setup looks like.

The question we hear most often is not “should we be using AI?”. It is “what do we do about the fact that people are already using it?”.

Because that is what is happening in most of the companies we walk into. Someone in sales put a client quote into a free chat to have it rewritten more nicely. Someone in accounting pasted in a bank statement to have a fee explained to them. A colleague in support has a personal account, paid for out of his own pocket, into which he has copied entire conversations with clients. Nobody acted in bad faith. Each of them solved a problem of the moment.

The result is that the company already has AI adoption. It just doesn't know about it, doesn't control it, and can't show a client or an auditor where the data ended up if anyone asks.

That is where any serious discussion about AI in a company starts. Not with the tool.

The first rule: do not ban, prescribe

The reflex of many managers, once they realise what is going on, is a ban. “AI is not to be used with company data.” It sounds responsible and it doesn't work.

A blanket ban doesn't stop the usage. It moves it. People who have discovered that they can finish a two-hour job in twenty minutes are not going to give that up. They will carry on on their personal phone, during a break, without telling anyone. You have turned a visible problem into an invisible one.

A policy only works if it is precise enough to be followed. “Do not put client data into tools the company does not administer” is a rule a person can apply. “Use AI responsibly” is not.

That lesson was confirmed again in an implementation at an industrial group with operations in several countries: the policy only worked once it was translated into concrete rules and into the technical settings that enforce them. A nicely written document with no controls behind it is a wish, not a policy.

Step 1: decide which data is allowed in

Before any choice of tool, the company has to answer a single question: what categories of information do we have, and where is each of them allowed to go?

For an SME, three levels are enough:

  • Public or internal with no risk. Marketing copy, general documentation, internal procedures with no personal data. Can be used with any tool the company has approved.
  • Confidential. Quotes, contracts, financial data, information about clients and employees. Can only be used in tools the company administers, where the data is not used to train the model and there is access control.
  • Restricted. Sensitive personal data, health data, information covered by specific confidentiality clauses, data subject to EU residency obligations. Does not go into any tool without a separate assessment.

This classification is not bureaucracy. It is what lets you tell a client, with an argument behind it, what happens to their data. And it is the only way you can train your people without asking them to guess.

Step 2: not everyone needs the same access

The second common mistake is to treat AI as a single thing. It isn't.

A chat where a person asks questions and gets answers is one thing. A tool that is given access to the company's files, email or calendar and carries out tasks is something else entirely. An automated process that runs on its own, with no human in the loop, is a third category.

The risk grows from one level to the next, and the control should grow with it. Someone in marketing needs the first level. Someone in operations who delegates recurring reports may need the second. The third level is only switched on where there is a clear use case, a named person accountable for it, and a defined limit on what the system is allowed to do.

Tiered access also solves a problem of a different nature: it puts an end to the “why does he get it and I don't” conversations. The answer becomes a rule, not the manager's personal decision.

Step 3: a company account, not personal accounts

This is where it is decided, in practice, whether AI adoption is under control or not.

Personal accounts, free or paid, have three fundamental problems. The data can be used to train the model, depending on each user's own settings, which the company cannot see. Nobody can administer anything: neither grant access nor withdraw it when an employee leaves. And when the person leaves, the conversations leave with them.

Our recommendation is clear: if the company uses AI, use a team plan. Both major providers, Anthropic (Claude) and OpenAI (ChatGPT), have plans of this kind, with central administration and with data excluded from training. The difference in cost compared with individual accounts is small relative to what it solves.

We work on Claude, both internally and in the implementations we do for clients, and we recommend it. Not because its answers read more nicely, but for three things that matter in a company:

The knowledge belongs to the company, not to each individual. Shared projects have a common knowledge base and common instructions: the procedures, the tone, the company context are set up once and the whole team works from them. Nobody has to explain the company from scratch every single time. Conversations stay private, the knowledge is shared.

You can delegate work, not just ask questions. Cowork allows a task across files and applications (a recurring report, a consolidation of documents, a compliance check over a set of contracts) to be delegated rather than carried out manually by copy-pasting out of a chat. This is where the real productivity difference lies, and this is where the second level of access above makes sense.

Control belongs to the administrator. Domain verification and blocking of new personal accounts created on the company domain, single sign-on (SSO) through the company's existing identity, a spending cap, data excluded from training by default. Taking over personal accounts that already exist on the domain is only possible on the Enterprise plan. And the team plan starts at two users, so there is no minimum threshold that shuts out small companies.

In a company that already has Microsoft 365 or Google Workspace, integration with the existing identity means that access to AI is granted and withdrawn the same way as access to email. When the person leaves the company, they leave AI too. That is what “under control” means.

Step 4: a one-hour training session and a one-page guide

Nobody reads a ten-page policy. What works is a one-page guide, with concrete examples of “yes” and “no”, and a short session in which people see how the work is done properly on their own real cases.

The guide has to answer the questions people actually have: can I put in a client quote? (yes, in the company account, not in your personal one), can I put in a CV received through recruitment? (no, not without the candidate's consent), can I ask it to rewrite an email for me? (yes), can I let AI send the email? (no, not without checking it).

The wording matters as much as the content. A rule that sounds like somebody's personal decision gets negotiated. A rule that is company policy gets respected.

Step 5: review after three months

The setup is not an event. After three months, you need to know who is using it, for what, and where situations came up that the guide did not cover. They almost always do. A good use case was discovered by someone in accounting, a rule turned out to be too strict and people went around it, a level of access needs to be extended.

The review is what keeps the policy precise. And a precise policy is the only kind that gets respected.

What a properly built setup looks like

In concrete terms, for an SME, a properly built setup means: the data classification agreed together with the leadership team, the team plan configured on the company domain and tied to the existing identity (Microsoft 365 or Google Workspace), the access levels defined by role, the shared projects built with the company's knowledge, the one-page guide written around the team's real cases, and a training session. Plus the review at three months.

That is exactly what we do, both for our own company and for our clients. If AI is already being used in your company but nobody can say exactly how, where and with what data, this is the right moment for a conversation.