Current usage
Which AI services are really being used? Sign-in records, browser extensions and network traffic, plus a short anonymous staff survey, reveal what happens day to day.
The goal is not to slow AI down, but to use it so that customer and business data does not end up where it does not belong.
Which AI services are really being used? Sign-in records, browser extensions and network traffic, plus a short anonymous staff survey, reveal what happens day to day.
Microsoft 365 Copilot, Copilot Chat with a work account, ChatGPT on a business plan, Gemini in Google Workspace, or others. We compare privacy terms, data location, contractual basis and cost, and recommend what fits your existing set-up.
An AI assistant in Microsoft 365 finds everything a user is able to read, including the forgotten folder of salary lists. Before roll-out we therefore review and tidy up sharing in SharePoint and OneDrive.
A brief set of rules: which tools are allowed, which data must never be entered, such as health records or client files, how outputs are checked and who to ask.
Blocking unapproved AI services or showing a notice when they are opened, DLP rules against uploading confidential content, and control over browser extensions and app consents.
A short video session on sensible use, common pitfalls and data protection, with an attendance list documenting your AI literacy measures under Article 4 of the AI Act.
Within a few weeks you move from “everyone doing their own thing” to managed use that the team is happy to adopt.
Mapping the AI services in use and the tasks where they genuinely help the team.
Selecting one or two approved tools, reviewing contract and privacy terms with your legal adviser, cleaning up permissions.
Licensing, configuration, guardrails and policy, followed by training for all staff over video.
After a few weeks, a look at actual usage, adjustments to the rules and new use cases added.
A ban without an alternative only makes AI use invisible. Staff who have found a chatbot helpful do not give it up; they switch to their own devices. An approved tool with clear rules brings that usage back to where you can oversee it.
Under Article 4, organisations deploying AI systems must ensure their staff have sufficient AI literacy for their tasks. Typical use of assistants rarely triggers further specific obligations. That changes if AI is used, for example, in decisions about staff. The AI service desk of the Austrian regulator RTR offers guidance; the legal assessment belongs with your adviser.
Under the current business terms of these providers, no. That applies only to business plans accessed with a work account, not to personal or free accounts. We check the terms of the chosen tool before approving it.
That is a question for your lawyer and depends on the tool, the contract and the purpose. Health data is a special category under Article 9 GDPR, and professionals bound by confidentiality have extra obligations. Our advice to begin with: exclude such data explicitly in the policy and back that up technically.
Through sign-in logs in Entra ID or Google, cloud app reports in Defender and the firewall web filter. These show no content, only which services are accessed and how often. We analyse them in a privacy-compliant way.
Tell us how AI is used in your business today. We will suggest a route that suits your data and your team.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.