The Two Faces of Workplace AI
Generative AI is now a mainstream workplace tool, with recent surveys showing a dramatic rise in adoption among professionals. This has led to two distinct trends. The first is enterprise-grade AI, like Microsoft's Copilot, which is integrated directly
into business software suites. These tools are designed with corporate data protection in mind, promising that a company's information will not be used to train public models. The second, and more chaotic, trend is 'Bring Your Own AI' (BYOAI). This is where employees use personal accounts for public AI tools like ChatGPT or other services to perform work tasks. This 'shadow AI' usage introduces significant risks because the organization has no visibility or control over how company data is being handled.
How Copilots Access Company Data
For a personal AI assistant to be truly useful, it needs context. In a work setting, that context is your company's data: emails, documents, chat histories, and meeting notes. Enterprise solutions like Microsoft Copilot access this information through a secure layer like the Microsoft Graph, which acts as a gateway to content in services such as SharePoint and Outlook. Crucially, these systems are designed to respect existing user permissions. The AI can only see and process information that the specific user already has permission to access. It cannot bypass established security controls to fetch data from a restricted folder or a private chat.
The Real Problem: Over-Permissive Access
While enterprise AI tools won't break existing permissions, they can expose how flawed those permissions often are. Many organisations suffer from years of 'permission creep,' where employees have access to far more data than they strictly need. Think of old SharePoint sites, public Teams channels with sensitive files, or broad access given to a project team that was never revoked. An employee might technically have 'view' access to a document containing confidential salary information without even knowing it exists. A broad query to a copilot could inadvertently surface this data, not by breaking rules, but by efficiently finding what the user was already permitted to see. This makes auditing and tightening existing file permissions a critical first step before a wide AI rollout.
The Danger of 'Bring Your Own AI'
The risks multiply when employees use personal AI accounts for work. When a user copies and pastes a draft of a confidential memo or sensitive client data into a free, public AI tool, that information leaves the company's secure environment. Depending on the tool's terms, that data could be stored, shared, or even used to train the public AI model, potentially exposing it to competitors or the public. This creates a host of issues, including data leakage, intellectual property loss, and compliance violations with regulations like GDPR. Furthermore, if the AI generates false information—a known issue called 'hallucination'—and an employee incorporates it into a report, it can poison the company's own knowledge base.
Establishing AI Governance
Banning AI tools is not a viable long-term strategy. Instead, businesses need to create a strong data governance framework for AI use. This starts with establishing clear policies on which tools are approved and how they can be used. For enterprise-grade tools, administrators have controls to monitor usage and set policies. For example, Microsoft allows admins to block the use of personal Copilot subscriptions on work documents if it doesn't meet company standards. Employee training is equally vital. Staff need to understand the risks of using unapproved tools and be educated on how to use sanctioned AI responsibly, without feeding it sensitive or proprietary information. The goal is to make safe AI use an asset, not a liability.














