Why SMEs Need Both to Deploy AI Securely

  • 68% of organisations have already experienced AI-related data leaks

  • 77% of employees admit to pasting sensitive data into AI tools

  • Copilot only respects the permissions you’ve already set — are they correct?

  • A clear AI policy and readiness check can prevent “data shocks” before they happen

  • Why we chose M365 Copilot as our AI platform for its strong security measures


Why an AI Policy Is Essential

Imagine an eager employee pasting a confidential client list into a free AI chatbot to “get some quick insights.” Without guidelines, they might not realize that this action could inadvertently expose private data to a third-party service. This isn’t a hypothetical – it’s exactly what happened at Thames Valley bank in July 2025. Employees in the marketing department were using a third-party generative AI tool without oversight, feeding it confidential customer data to draft personalized marketing content. Unbeknownst to them, the AI model ingested and learned from this data, effectively commingling 75,000+ customers’ financial details with the AI’s public dataset. An external user of the same service exposed fragments of TVB’s customers via ‘prompt injection’.

These employees didn’t intended harm – they were trying to work faster – but their company suffered real data exposure because there weren’t clear rules in place. An AI usage policy is your organisation’s playbook to prevent such mishaps. It sets clear rules and expectations for if and how employees can use AI at work.

The AI policy should cover
  • Approved vs. unapproved tools: For example, you might allow Microsoft 365 Copilot for internal use, but forbid public chatbots like the free ChatGPT for any work-related data. This distinction matters because data fed into public AI services can leave your control (as Samsung learned), whereas enterprise tools like Copilot offer guarantees that data stays within your tenant.
  • Data handling guidelines: Define what types of information are never to be shared with AI. This usually includes customer personal data, financial records, trade secrets, and anything regulated. Employees may not realize that even “anonymised” data could be risky – your policy must spell it out clearly.
  • Privacy, compliance and ethics: Reinforce that any AI use must comply with UK GDPR and internal confidentiality agreements. If your industry has special regulations (finance, healthcare, etc.), call them out. For instance, a bank’s AI policy might forbid inputting client account details into external AI tools due to financial privacy rules. Also set expectations for ethical AI use (no using AI to do anything fraudulent or discriminatory) and require human oversight on critical decisions.
  • Accountability and transparency: Make it clear that employees should document significant AI-assisted work. If someone uses AI to generate a client report or decision, they should note that. This creates an audit trail and builds a culture of transparency. The policy might also require teams to get approval before deploying any new AI tool, ensuring IT/security can evaluate it first.

Creating an AI policy isn’t about stifling innovation – it’s about setting safe boundaries so employees can leverage AI without putting the business at risk. It’s increasingly expected, too. In 2025, 69% of business leaders cited AI-related data leaks as a top security concern. By getting an AI policy in place now, you’re not only protecting your data but also educating your team. Employees generally appreciate clear guidance; it empowers them to use new tools responsibly rather than leaving them to guess what’s okay.


What an AI Readiness Assessment Entails (and Why It Prevents “Data Shocks”)

Even with a solid policy, you also need to ensure your IT environment is prepared for AI. This is where an AI readiness assessment comes in. Think of it as a pre-deployment check-up for your data and permissions. A major focus is checking your SharePoint and Microsoft 365 permissions. Why? Because tools like Microsoft Copilot will only show users data they already have access to. Copilot itself strictly adheres to your existing permission models – it won’t magically expose files that you couldn’t see normally. However, if those underlying permissions are too loose (whether by accident or via legacy settings), you could have a scenario where Copilot ends up revealing documents that technically anyone in the company could see, but you never intended to be widely visible. In other words, Copilot might wake you up to permissions mistakes.

Data Shocks

For example, say your company has a SharePoint site with broad access – perhaps an “All Company” folder that inadvertently contains a few sensitive files. Without an AI assistant, those files might just sit there, mostly unnoticed. But once Copilot is enabled, an employee’s innocent question (“Hey Copilot, summarise our Q4 financial results”) could cause Copilot to surface content from those files. Suddenly, people are seeing information they shouldn’t have seen. That kind of unpleasant surprise is what we mean by “data shock,” and a readiness assessment helps you avoid it. Here’s what an AI readiness assessment typically involves:

  • SharePoint permission audit: Identify sites, folders or files that are accessible to too many people.
  • Teams and OneDrive audit: Similar checks for Microsoft Teams channels and OneDrive shares. The goal is to ensure that each data repository has appropriate, limited access before AI rolls out.
  • Data classification review: Ensure that important documents and sites have appropriate sensitivity labels (e.g. Public, Internal, Confidential).
  • Compliance and DLP settings: Verify that your data loss prevention (DLP) policies are in place and tuned for AI scenarios.
  • Licensing and technical setup: Confirm you have the necessary licenses and infrastructure for Copilot.
Proactive Assessment

By conducting this assessment, you are proactively closing any security or permission gaps. It’s much better to discover that a SharePoint site containing HR data was mistakenly shared with the whole company and fix it before Copilot goes live, rather than after someone asks the AI and discovers a sensitive document. It’s easy for such things to happen over time. An AI rollout is the perfect trigger to do some house-cleaning. In short, the readiness assessment ensures your AI assistant will operate only within the bounds you intend. It’s the technical counterpart to your AI policy – the policy governs people’s behaviour, and the readiness review governs systems and data. Together, they dramatically reduce the chance of an AI accident or breach.


Why We Chose Microsoft Copilot:

There are many AI solutions out there, but not all are created equal on security. A big reason we selected Microsoft 365 Copilot is the security guarantee that your data stays within your Microsoft 365 tenant. What does that mean in practice?

Data Stays in Your Tenant

Firstly, any prompt you enter into Copilot and any response it generates remain within Microsoft’s cloud – they are not used to train the underlying large language model. This is fundamentally different from many public AI services. For example, if you use the free version of ChatGPT, your inputs might be used to improve OpenAI’s model (unless you opt out each time). With Copilot, Microsoft’s policy is explicit: “Prompts, responses, and data accessed through Microsoft Graph aren’t used to train the foundation AI models”. In other words, your business data isn’t leaving your control or becoming someone else’s training material – it stays private to you.

Processing happens in a secure cloud environment

Secondly, Copilot’s AI processing happens in the Azure OpenAI service, within Microsoft’s secure cloud environment. None of your content is sent to OpenAI’s public servers. Azure OpenAI doesn’t cache your data or keep it once you get your answer. We can confidently tell our stakeholders (and regulators, if needed) that using Copilot doesn’t send our data out into the ether. It stays under the strict safeguards of our trusted cloud environment. Additionally, because Copilot only surfaces data that users already have permission to access, it inherently respects our existing security framework. We don’t have to worry that an AI might ignore our SharePoint permissions or HR file restrictions – that can’t happen with Copilot. By choosing an AI that’s integrated with Microsoft 365, we leverage all the security investments we’ve already made (identity management, MFA, data loss prevention, etc.). Copilot slots into our existing setup instead of bypassing it.

To illustrate the benefit, consider the alternative some companies face: employees using third-party AI tools by uploading company documents to them. Besides the obvious risk of leaks, that’s a compliance nightmare – you have no visibility or control once data is in some external AI service. With Copilot, all AI interactions stay within our Microsoft tenant. We even get audit logs of Copilot’s queries and responses (they’re stored as part of the user’s activity history). We can apply retention policies to that data just like we do for emails or documents. This level of oversight simply isn’t possible with random AI apps from the internet.

Microsoft’s Commitment to Security

Finally, Microsoft’s overall commitment to security and compliance with Copilot gave us confidence. Copilot inherits the same compliance certifications and legal protections as Microsoft 365 (UK GDPR, data residency, SOC audits, etc.). Microsoft also built in additional safeguards specifically for Copilot, like the ability to block certain sensitive info from being shown, or to fine-tune which content sources it can use. Essentially, Copilot was designed from the ground up for enterprise use. We view it as an AI assistant that’s enterprise-ready, not an experimental consumer toy. That alignment with our security culture made the choice easy.


Wrapping Up

AI can be a game-changer for productivity – helping draft documents, summarise data, and provide insights in seconds. For SMEs, it can level the playing field with larger competitors. But to leverage it responsibly, you need proper guardrails in place. By implementing an AI policy, everyone in your company knows how to use (and not use) AI tools. By doing an AI readiness assessment, you ensure your data and permissions are in order. These steps work hand-in-hand: the policy influences user behaviour, and the readiness review fortifies your IT environment. When you prepare properly, your team can explore AI’s benefits without fear. You can be confident that it will only operate on what it’s supposed to. Our own journey to enabling Microsoft Copilot was enlightening – it feels great to embrace innovation in a way that satisfies our security standards.

Bottom line for SME leaders and CISOs: Don’t skip the “boring” prep work. Create your AI usage policy early, and run a thorough AI readiness assessment of your data environment. This is the best way to unlock AI’s potential safely. With those foundations in place, you can confidently adopt tools like Copilot, knowing that your organisation’s knowledge stays secure and only the right people see the right information.


✅ Take Action Now

Contact Cyber & Data Protection today to discover how our tailored data protection solutions and extensive Managed Data Protection services can keep your business within compliance and internally secure with AI policies.

📧 Email: [email protected]
📞 Call: +44 1743 644404

Privacy Preference Center