
Somewhere on your team, people are probably already using AI tools. ChatGPT to draft an email, Copilot to summarize a document, Fireflies or Otter to transcribe a meeting. Nobody asked permission, and nobody ran it through a security review first, because it doesn't feel like a security decision. It feels like a productivity tool, the same way a faster spreadsheet or a better calendar app would.
That's exactly where the real risk hides. This usually gets treated as a productivity question instead of a data governance policy question: what is this tool actually allowed to see, and who decided that? Bit by Bit sells IT and security services, so it's fair to expect us to say adopting AI carelessly is dangerous. But this genuinely isn’t a solved problem we’re selling you the answer to. It’s a current challenge, and Bit by Bit is working through the exact same tension internally, in real time. What follows is what's at risk, and one concrete step you can take this week (no security expertise required).
"Everybody who we work with, or many of them, are trying to use these tools. It's like getting into a car without ever having taken a driving course or getting a driver's license. You're just operating this vehicle without any kind of training, and it's dangerous."
— Melanie Oswald, Service Desk Manager, Bit by Bit
What's Actually at Risk When AI Tools Aren't Governed
The risk was never AI itself. It's what happens the moment an AI tool gets connected to your business's data (your files, your email, your recordings) without anyone deciding what it should and shouldn't be able to see. This is the boundary between what's sometimes called shadow AI — tools employees adopt on their own, outside any formal review — and AI that's actually been evaluated before it touches anything sensitive.
Melanie draws the line between low-risk and real-risk use about as clearly as it can be drawn: a tool that's just answering questions on the open web, with nothing connected behind it, carries a lot less risk. The moment you connect that same tool to your Microsoft 365 environment, letting it read emails, transcribe meetings, or access shared files, you're in a different situation entirely. You've now given it access to your voice, your documents, your recordings, and you don't fully know what it does with any of that, or what it means for your organization's safety and compliance. This is particularly dangerous when it comes to free online AI tools.
"Once you upload a document into the tool and ask an opinion of it, if it's not a paid version, there's a very good likelihood you've just shared a document that is now public domain."
— Ivan Shore, VP Sales & Marketing, Bit by Bit
Melanie is also specific about how casually that access often gets granted, too: picture a shared file server where everyone already has access to every folder, including one holding financial records. Someone decides they want a tool to "work with this," clicks a button, and that folder, financials and all, is now visible to it. Nobody sat down and decided that should be allowed. It just happened, one click at a time.
Independent research backs up exactly how routine this has become: Awareways' 2025 Trend Report found that 75% of employees already use AI for work-related tasks, and 78% of them do so without their IT department's knowledge or oversight, while organizations, on average, have visibility into less than 11% of what's actually happening. And the data flowing into these tools is getting more sensitive, not less. Cyberhaven's 2025 AI Adoption and Risk Report, drawn from 7 million workers, found that 34.8% of the corporate data employees now input into AI tools is sensitive, up from 27.4% a year earlier and more than triple the 10.7% recorded two years prior. This is the AI security risk that a governance conversation is trying to head off: not AI itself, but data leaving your control before anyone decided it should.
Why This Is Harder Than It Looks (Even for an MSP)
If this sounds like what's already happening on your team, you're not behind; you're just at the point where it's worth pausing and taking stock. It's genuinely challenging to figure out the right approach right now, because everyone is working through it at the same time.
AI compliance in this space isn't a document you write once and file away. It's something that’s continually evolving with changing tools. Melanie describes how Bit by Bit's own approach has already changed shape: “early on, we had people sign a risk acknowledgement waiver before rolling AI tools out. That got cumbersome, so now, instead, we have a direct conversation with the point of contact or leadership at each organization, walk through the risks plainly, and get their acknowledgement before moving forward”.
The First Practical Step, If You Have No Policy at All
You don't need a finished AI governance policy this week. You need one deliberate first step, and Melanie's guidance breaks into four components:
- Talk to your IT provider first. They can guide you toward real best practices instead of you guessing alone. This is the natural starting point for any AI risk management effort.
- Be deliberate about what data you're connecting. Before giving any AI tool access to anything, understand exactly which folders and what data it can now see. Melanie's own practice: rather than opening up an entire folder structure, she created one dedicated folder and gave the tool access to only that. It’s a conscious choice about what it can touch, instead of a default "yes" to everything.
- Read what the AI provider actually publishes about risk. Every major AI vendor publishes risk and safety disclosures, and they're usually more readable than typical terms and conditions. It’s real information they want you to have, not legal filler.
- Escalate if you're not the decision-maker. If AI use is happening informally and you're not the one who sets policy, go to leadership directly: "I've been starting to use AI; what policies do we have?" That single question is often enough to trigger a real company-wide conversation.
None of this requires you to become a security expert. It requires treating access to your data as a decision someone actively makes, rather than something that happens by default the first time someone clicks "allow." A basic AI risk assessment can start exactly there.
Why Waiting Isn't a Neutral Choice
None of this is an argument for avoiding AI. The businesses that don't find some way to adopt AI into their daily routine are going to fall behind on productivity, because the pace of change here is fast. The message isn't "don't adopt AI"; it's "govern it." Standing still doesn't remove the risk; it just means you're not getting the upside either, while the risk of ungoverned, informal use keeps compounding in the background.
The stakes of getting this wrong keep climbing. IBM's 2024 Cost of a Data Breach Report put the global average cost of a breach at $4.88 million. That’s a 10% jump from the year before, the largest single-year increase since the pandemic, with more than one-third of breaches involving what the report calls shadow data: information nobody was fully tracking. Ungoverned AI access is exactly the kind of thing that quietly grows that category. The conversation is worth having this week, because waiting doesn't actually buy you any safety.
Have This Conversation Before It Becomes a Bigger One
AI tools themselves aren't the risk. Using them without anyone deciding what they can touch is. Book a free assessment and we'll help you have the governance conversation your team probably hasn't had yet.
Quick Answers to Common Questions
Should my team stop using AI tools until we have a policy?
Not necessarily, and stopping outright usually isn't realistic anyway. The more useful move right now is a direct conversation: if you're not the decision-maker, raise it with leadership today rather than waiting for a full policy to exist first. The goal is awareness and a deliberate first step, not a hard freeze.
Is Microsoft Copilot safer than tools like ChatGPT or Claude?
It is somewhat lower-risk in one specific way, but not risk-free. Microsoft's own documentation states that for users signed in with an organizational account, prompts and responses aren't used to train Microsoft's underlying foundation models, and Copilot only surfaces data that a given user already has at least view permissions to access. That's a real, meaningful distinction, but it doesn't mean Copilot use requires no thought at all. It's still worth understanding exactly what it's connected to in your environment, the same as any other tool.
Who should be involved in this conversation at my company?
More than one person, and not just whoever happens to be curious about AI. This shouldn't sit with a single enthusiastic employee experimenting on their own. It belongs with leadership, informed by IT. If you're the one who noticed AI creeping into daily use on your team, your job is to be the one who raises it, not the one who quietly decides the policy alone.
How do I create an AI acceptable use policy for employees?
Start smaller than "policy." Before you need a formal document, you need these three in place: a conversation with your IT provider, a clear decision about what data any AI tool can access, and leadership awareness of what's already happening informally. A written policy is easier to build once those three things already exist. Trying to write one from a blank page, before you've had that groundwork, is where most efforts stall out.
What data should employees not share with AI tools at work?
Anything you wouldn't want visible to a tool that hasn't been formally reviewed: financial records, customer data, employee personal information, and anything from folders with broad, unreviewed access. The safer default is the one Melanie uses personally: a single dedicated folder or workspace with only what a given tool actually needs, rather than blanket access to everything.