
AI in the workplace: permissions first, licences after
Whether your people use AI is no longer the question. They already do, usually on a personal account. The question is which one you enable, what happens to your data, and what the assistant is allowed to see. That last one is where it goes wrong.
AI is already on your desks. Not because you rolled it out, but because people open it in a browser tab on a personal account. That is the riskiest version there is: no contract, no visibility, and company text ending up somewhere you cannot point to.
The distinction that matters is not which vendor you pick but whether you are on the business or the consumer tier. A business agreement says who owns the input, whether it is trained on, and where it is processed. A free account says none of that.
The real work is not the licence but the permissions. An assistant that searches your own files shows what the user could already open. If your SharePoint is wide open, AI makes that visible in a single query.
What is already running without you switching it on
In almost every organisation where this conversation starts, AI turns out to be in use already. Not rolled out, not discussed, simply opened. Someone pastes a complaint letter into a chat window to get a polite reply out of it. Someone has a quote summarised. Someone asks for a spreadsheet formula and pastes in three columns of real revenue alongside it.
That does not happen out of defiance. It happens because it works and because nothing has been agreed. Offer no choice and you get the choice people make themselves, which is almost always the free version of whatever they use at home.
To that extent this is the same problem as shadow IT: tooling that delivers value and sits outside your view. The difference is that here nothing is shared as a file — text is typed — so there is no trace left behind for you to find later.
The point is that the question is not whether you permit AI. In practice that decision has been made. The question is whether it falls inside or outside your agreements.
Where your data goes
There is one distinction that matters more than any other, and it does not run between vendors but straight through every vendor: the consumer tier and the business tier are different products on different terms.
On a consumer account the service is free or cheap because you are not the customer but the user. The terms allow what you type to be used to improve the model unless you turn that off yourself. There is no data processing agreement, so under the GDPR you have no arrangement covering the personal data that ends up in it. And you have no view of who inside that vendor can reach it.
A business agreement — whether that is Microsoft, Google, OpenAI or Anthropic — does cover those things. What to read for yourself before you sign:
- Is your input trained on? On business subscriptions the answer is no by default, but it is worded differently per product and it is the first sentence you want to be able to find again.
- Is there a data processing agreement? Without one you cannot evidence what happens to personal data, and that is exactly what a regulator asks for.
- Where is it processed? Some vendors offer processing inside the EU, others do not or only on a more expensive tier. This is the same trade-off set out under digital sovereignty, and the answer here is rarely black and white.
- How long is it kept? Conversations are usually retained for a while for abuse detection. That is defensible; not knowing for how long is not.
What we see organisations that handle this well actually do is not complicated: enable one business vendor, pay for it, and block the consumer versions on the work account. That costs a licence and removes most of the risk.
The assistant reads what the user could already read
This is the part that does not come up in the sales conversation and that delays most rollouts.
An assistant that searches your own files — Copilot in Microsoft 365, Gemini in Google Workspace, or another connector over your documents — works within the permissions of whoever asks the question. It invents no access. That sounds reassuring and it is not, because it means it shows precisely which permissions in your environment are too wide.
In practice it goes like this. A SharePoint site was created years ago for a project and set to "everyone in the organisation" because that was quicker. Since then it has held the folder with salary data, or the report on a reorganisation that never happened. Nobody found it, because nobody went looking. Then along comes an assistant that can search everything at once, and someone types a question that document happens to be the best answer to.
Nothing went wrong with the AI. What went wrong happened years earlier. But it surfaces on the day you switch the assistant on, and then it is called the AI project.
What helps against that, in this order:
- Look at what is open first. Which sites and folders are set to organisation-wide or to a shareable link with no expiry. That is a report you can have in a day.
- Clean up the worst before you roll out, not after. Cleaning up afterwards means the content has already been out.
- Put sensitive places out of reach with labels or by excluding the assistant from them. Every serious vendor has a control for this.
- Start with a group of ten to twenty people. Whatever they hit first would otherwise surface for everyone at once.
This is the same work as the identity layer in Zero Trust, and it is why we rarely treat an AI rollout as a licensing question.
Which vendor, and why it matters less than you think
No vendor wins on every point, and in most cases the choice is decided not by the model but by where your documents already live.
If everything sits in Microsoft 365, Copilot is the shortest route: it is inside the programs people already open, it works within your existing permissions, and there is nothing extra to connect. If you work in Google Workspace, the same goes for Gemini. That is not a judgement about quality, it is a judgement about friction — an assistant that lives in a separate tab goes unused half the time.
Then there is the category that sits apart from your office suite: ChatGPT and Claude in their business form. Those are strong for work that is mostly text and reasoning — drafting a concept, holding a long tender against a specification, reviewing a piece of code — and weaker at looking inside your own documents unless you explicitly connect them.
What we most often see work in practice is a combination, and that is not a weak compromise. The assistant inside your office suite for daily work, and one standalone for the people who lean on it heavily. Two licences are cheaper than a rollout nobody uses.
What we advise against is postponing the choice until there is a winner. There will not be one, and in the meantime your people are using the free version.
What your agreements need to say
Since the European AI Act there is a formal side to this too, and it is smaller than the headline suggests. The Act is aimed mainly at those who build AI systems and at high-risk applications; an employee using an assistant to write an email does not fall under that.
One obligation does touch everyone deploying AI: you have to make sure the people working with it know enough about it to use it sensibly. That is not a certificate, it is explanation — what it can and cannot do, and what you do not put into it. That has applied since early 2025.
Beyond that, most of the questions you get are simply GDPR. Personal data typed into an assistant is still personal data, and the lawful basis, the retention period and the processing agreement all still apply.
A usable AI policy fits on one page and answers five questions:
- Which tools are allowed. By name, with the business tier specified, because "AI is fine" is not an agreement.
- What does not go into them. Personal data about clients or colleagues, medical data, passwords, and source code or contracts under a confidentiality clause.
- Who remains responsible. What the assistant produces is a draft. Whoever sends it is the author.
- Where it must not decide. Anything about people — applications, appraisals, case files — should not come out of a model without someone looking at it.
- Where to go with a question. Without that address the policy gets ignored rather than consulted.
That single page is worth more than an extensive set of rules nobody reads, and it can be written in an afternoon.
Questions we get about this
The ones that come up most often once this is on the table.
Does the vendor train on the data we type in?
On business subscriptions the answer is no by default, and on consumer accounts it is yes by default unless the user turns it off. That difference is the main reason to pay for a business tier and block the free versions on the work account. Every vendor words it differently in the terms, so read that sentence once yourself rather than relying on what the salesperson says. And record what you found, because that is the evidence an auditor wants to see.
Can Copilot reach documents someone is not allowed to see?
No. An assistant working over your own files stays within the permissions of the user asking the question. The problem is that in most environments those permissions are wider than anyone thinks: sites set to the whole organisation, shareable links with no expiry, folders from projects years ago. The assistant makes that visible; it does not cause it. That is why we look at permissions first and at the rollout second.
Do we have to pick one vendor, or can we run more than one?
More than one is allowed and often works better. The assistant inside your office suite has the advantage of reaching your documents and of people meeting it without opening a different program. A standalone assistant is stronger for work that is mostly writing and reasoning. What you do not want is ten different ones, each with its own account and its own terms. Two you chose deliberately is a decision; ten that appeared by themselves is shadow IT.
What does the AI Act say about ordinary office use?
Less than most people think. The Act is aimed mainly at those placing AI systems on the market and at high-risk applications, such as in healthcare or in recruitment. An employee having an assistant draft an email does not fall under that. What does apply to everyone is that you must make sure your people understand enough about AI to use it sensibly. That is a matter of explaining, not of a course with a diploma.
Where this sits with us
The services this subject falls under.
Want to know what an assistant would find at your place?
An overview of what is open organisation-wide takes a day to produce, and it is useful whether or not you go ahead with AI.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.