Service · Cybersecurity

Secure use of AI

In most companies AI is already in use, whether or not anyone approved it. An administrator pastes a contract into a free chatbot to summarise it, a salesperson uploads the price list to draft a proposal, a technician copies a snippet of code complete with credentials to get help debugging it. With the free tiers of many services, that data may be used to train models and is out of your hands. Simply banning it does not work, because the tools are useful and people will carry on from their phones. What works is deciding what is allowed, providing an approved tool with the right safeguards and preparing your systems so the AI cannot see what it should not. If you plan to switch on Microsoft 365 Copilot, there is also a step almost nobody takes first: reviewing permissions, because Copilot surfaces documents shared by mistake within seconds.

1 policy
two pages, in plain language
Approved tool
with data kept out of training
Permissions
reviewed before Copilot is enabled
EU AI Act
as the reference framework

What falls within the scope of this service

This service covers security and rules of use. Choosing business use cases and delivering AI projects belong to our artificial intelligence area.

Pin down the details with one of our engineers

Current use assessment

Which AI tools are already in use, under which accounts and for what, based on cloud app logs and a short anonymous staff survey.

Usage policy

Which tools are approved, which data must never be entered (health data, payroll, identifiable customers, credentials), how AI output is checked before it goes out and who decides on new cases.

Approved tool

Setting up a business option such as Copilot with enterprise data protection, Gemini in Google Workspace or ChatGPT Team or Enterprise, with company sign-in and data excluded from training.

Preparing Microsoft 365 for Copilot

A review of SharePoint sites open to the whole organisation, “anyone with the link” shares, inherited folders and sensitivity labels, so Copilot shows each person only what they were already meant to see.

Controlling unapproved tools

Using Defender for Cloud Apps or web filtering to block or warn on unapproved AI services, plus DLP rules that stop labelled data being pasted into them.

Practical training

A video-call session with examples from your sector: what to ask, what never to paste, how to spot errors and made-up answers, and how to recognise AI-generated voice or video impersonation.

How the engagement unfolds, one stage at a time

Rules and an approved alternative first, blocks afterwards. Blocking without offering anything just moves the use onto personal phones.

01

Assessment

An inventory of real AI use and the data being entered, without pointing fingers at anyone.

02

Rules and tool

The policy written with management and HR, and the approved tool configured.

03

Data preparation

Permissions and labels reviewed in Microsoft 365 or Google Workspace before AI is connected to company documents.

04

Training and control

A session for staff, warnings on unapproved tools and a review after three months.

Copilot does not create new permission problems; it uncovers the ones you already had. If the payroll folder was shared with the whole company by a mistake four years ago, nobody found it before; now it only takes asking how much the sales director earns. That is why the permission review always comes before activation, never after.

Common questions

It depends on the tool, the contract and the data. With a free version and identifiable personal data, it is unlikely to sit well with the GDPR. With a business version that has a data processing agreement, an EU region and data excluded from training, it may be workable. The legal assessment is for your DPD or adviser; Apply supplies the technical facts about each option.

For the most common SME uses, such as drafting, summarising or translating, the main obligations are AI literacy for staff and transparency in certain situations. High-risk uses, such as automated recruitment screening, carry far stricter requirements. We help you work out where each use sits; the legal interpretation is for your adviser.

You can, but experience shows the use simply moves to personal phones, where you have no control at all. It is safer to offer an approved option with clear rules and protected data, and block only the alternatives that fall short.

It depends on how much clutter has built up. For a fifty-person company on SharePoint and OneDrive it is usually a matter of days or a few weeks. We start with sites holding sensitive data and with links open to the whole organisation, which is where nearly all the problems turn up.

Use AI without giving your data away

Tell us which AI tools are already used in your company and whether you plan to enable Copilot or Gemini. We will reply with the first steps to do it safely.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.