Current use assessment
Which AI tools are already in use, under which accounts and for what, based on cloud app logs and a short anonymous staff survey.
In most companies AI is already in use, whether or not anyone approved it. An administrator pastes a contract into a free chatbot to summarise it, a salesperson uploads the price list to draft a proposal, a technician copies a snippet of code complete with credentials to get help debugging it. With the free tiers of many services, that data may be used to train models and is out of your hands. Simply banning it does not work, because the tools are useful and people will carry on from their phones. What works is deciding what is allowed, providing an approved tool with the right safeguards and preparing your systems so the AI cannot see what it should not. If you plan to switch on Microsoft 365 Copilot, there is also a step almost nobody takes first: reviewing permissions, because Copilot surfaces documents shared by mistake within seconds.
This service covers security and rules of use. Choosing business use cases and delivering AI projects belong to our artificial intelligence area.
Which AI tools are already in use, under which accounts and for what, based on cloud app logs and a short anonymous staff survey.
Which tools are approved, which data must never be entered (health data, payroll, identifiable customers, credentials), how AI output is checked before it goes out and who decides on new cases.
Setting up a business option such as Copilot with enterprise data protection, Gemini in Google Workspace or ChatGPT Team or Enterprise, with company sign-in and data excluded from training.
A review of SharePoint sites open to the whole organisation, “anyone with the link” shares, inherited folders and sensitivity labels, so Copilot shows each person only what they were already meant to see.
Using Defender for Cloud Apps or web filtering to block or warn on unapproved AI services, plus DLP rules that stop labelled data being pasted into them.
A video-call session with examples from your sector: what to ask, what never to paste, how to spot errors and made-up answers, and how to recognise AI-generated voice or video impersonation.
Rules and an approved alternative first, blocks afterwards. Blocking without offering anything just moves the use onto personal phones.
An inventory of real AI use and the data being entered, without pointing fingers at anyone.
The policy written with management and HR, and the approved tool configured.
Permissions and labels reviewed in Microsoft 365 or Google Workspace before AI is connected to company documents.
A session for staff, warnings on unapproved tools and a review after three months.
Copilot does not create new permission problems; it uncovers the ones you already had. If the payroll folder was shared with the whole company by a mistake four years ago, nobody found it before; now it only takes asking how much the sales director earns. That is why the permission review always comes before activation, never after.
It depends on the tool, the contract and the data. With a free version and identifiable personal data, it is unlikely to sit well with the GDPR. With a business version that has a data processing agreement, an EU region and data excluded from training, it may be workable. The legal assessment is for your DPD or adviser; Apply supplies the technical facts about each option.
For the most common SME uses, such as drafting, summarising or translating, the main obligations are AI literacy for staff and transparency in certain situations. High-risk uses, such as automated recruitment screening, carry far stricter requirements. We help you work out where each use sits; the legal interpretation is for your adviser.
You can, but experience shows the use simply moves to personal phones, where you have no control at all. It is safer to offer an approved option with clear rules and protected data, and block only the alternatives that fall short.
It depends on how much clutter has built up. For a fifty-person company on SharePoint and OneDrive it is usually a matter of days or a few weeks. We start with sites holding sensitive data and with links open to the whole organisation, which is where nearly all the problems turn up.
Tell us which AI tools are already used in your company and whether you plan to enable Copilot or Gemini. We will reply with the first steps to do it safely.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.