Service · IT security

Safe use of AI

In most businesses AI is already in use, whether management knows it or not. The assistant asks a chatbot to polish customer emails, sales summarise lengthy enquiries from big industrial clients, accounts upload a spreadsheet to have a formula explained, and someone has installed a browser extension that reads every web page. Many of these services run on personal accounts and free tiers, where entered content may under certain terms be used for training. Banning them achieves little: anyone who has found a tool useful will simply use it quietly on their phone. It makes more sense to offer a safe route. That means an approved tool on a business licence, clear rules on which data may go in, technical guardrails and a short training session. The EU Artificial Intelligence Act also requires organisations deploying AI systems to ensure their staff have sufficient AI literacy, and we lay the foundations for that too.

Business licence
with no training on your data
One page
of AI rules everyone understands
Shadow AI
made visible rather than ignored
AI Act
staff AI literacy on record

Everything this covers

The goal is not to slow AI down, but to use it so that customer and business data does not end up where it does not belong.

Settle the details with an engineer

Current usage

Which AI services are really being used? Sign-in records, browser extensions and network traffic, plus a short anonymous staff survey, reveal what happens day to day.

Choosing a tool

Microsoft 365 Copilot, Copilot Chat with a work account, ChatGPT on a business plan, Gemini in Google Workspace, or others. We compare privacy terms, data location, contractual basis and cost, and recommend what fits your existing set-up.

Permissions before Copilot

An AI assistant in Microsoft 365 finds everything a user is able to read, including the forgotten folder of salary lists. Before roll-out we therefore review and tidy up sharing in SharePoint and OneDrive.

AI policy

A brief set of rules: which tools are allowed, which data must never be entered, such as health records or client files, how outputs are checked and who to ask.

Technical guardrails

Blocking unapproved AI services or showing a notice when they are opened, DLP rules against uploading confidential content, and control over browser extensions and app consents.

Training and evidence

A short video session on sensible use, common pitfalls and data protection, with an attendance list documenting your AI literacy measures under Article 4 of the AI Act.

Our working method

Within a few weeks you move from “everyone doing their own thing” to managed use that the team is happy to adopt.

01

Survey

Mapping the AI services in use and the tasks where they genuinely help the team.

02

Decision

Selecting one or two approved tools, reviewing contract and privacy terms with your legal adviser, cleaning up permissions.

03

Launch

Licensing, configuration, guardrails and policy, followed by training for all staff over video.

04

Fine-tuning

After a few weeks, a look at actual usage, adjustments to the rules and new use cases added.

A ban without an alternative only makes AI use invisible. Staff who have found a chatbot helpful do not give it up; they switch to their own devices. An approved tool with clear rules brings that usage back to where you can oversee it.

Frequently asked questions

Under Article 4, organisations deploying AI systems must ensure their staff have sufficient AI literacy for their tasks. Typical use of assistants rarely triggers further specific obligations. That changes if AI is used, for example, in decisions about staff. The AI service desk of the Austrian regulator RTR offers guidance; the legal assessment belongs with your adviser.

Under the current business terms of these providers, no. That applies only to business plans accessed with a work account, not to personal or free accounts. We check the terms of the chosen tool before approving it.

That is a question for your lawyer and depends on the tool, the contract and the purpose. Health data is a special category under Article 9 GDPR, and professionals bound by confidentiality have extra obligations. Our advice to begin with: exclude such data explicitly in the policy and back that up technically.

Through sign-in logs in Entra ID or Google, cloud app reports in Defender and the firewall web filter. These show no content, only which services are accessed and how often. We analyse them in a privacy-compliant way.

Use AI without giving your data away

Tell us how AI is used in your business today. We will suggest a route that suits your data and your team.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.