AI in the workplace: three guardrails every business should have in place

AI is no longer a futuristic concept – it's already embedded in your daily workflows. Microsoft is rolling out Copilot across Word, Excel, Outlook and PowerPoint for all Microsoft 365 business customers globally, and your staff are already using AI tools to draft emails, analyse data and generate content.

The convenience is undeniable, but without proper safeguards, AI adoption can quietly create serious security risks for your business. Here are the three essential guardrails every company should have in place right now.

Guardrail #1: Stop sensitive client data being typed into AI prompts

This is the single biggest risk facing businesses adopting AI today. We've seen multiple cases where staff type sensitive information – Australian bank account numbers, UK National Insurance numbers, confidential client details – directly into AI prompts without thinking twice.

The problem? These prompts get stored, models get retrained on your data, and metadata gets captured by third parties. Your competitive advantage and client confidentiality could end up in places you never intended.

What to implement:

  • Microsoft Purview Data Loss Prevention (DLP) policies for AI prompts – This automatically prevents sensitive financial identifiers, identity documents and confidential categories from being shared with AI models.
  • Note: Full DLP-for-AI capability requires Microsoft 365 E5 or the new E7 Frontier Suite.

If you're a Secure365 client, baseline DLP for AI prompts is already live in your environment. We're also reviewing additional Purview controls under CCS that will roll out over the coming months.

Guardrail #2: Lock the door on third-party AI tools

The next risk walks in through an open browser tab. A staff member signs up to a free AI meeting note-taker, authorises it against their work calendar, and suddenly a third-party provider you've never heard of has access to every internal meeting and client review conversation.

Gartner's 2026 cyber trends report identified unmanaged AI agents as one of the three biggest new risk categories of the year. It's not the AI tools you've vetted that hurt you – it's the seventeen AI apps your team connected without telling anyone.

What to implement:

  • Disable third-party AI publishers in Microsoft 365 to prevent unsanctioned AI agents from being installed by individual users
  • Review SharePoint permissions before turning Copilot loose – remember, Copilot can read anything your user can read
  • Set a clear "approved AI tools" list and put it in your staff handbook. Make ChatGPT, Claude, Gemini off-limits for client work

Guardrail #3: Create an AI policy everyone understands

The third guardrail isn't technical – it's behavioural. In every conversation I've had with business owners recently, the question is always the same: "What should our position on AI even be?" Yet most firms don't have a written answer.

Regulators like the FCA and ASIC are signalling that financial services firms need to demonstrate AI governance as part of their operational resilience obligations. "We didn't think about it" won't cut it in an audit or regulatory review.

Your AI policy should cover: 1. Which AI tools are approved for work use (and which aren't) 2. What types of data must never go into AI prompts 3. Who owns AI decisions in your business 4. How AI use is reviewed (quarterly checks are plenty for most businesses)

That's it – one page that will outlast most AI products on the market today.

Why this matters now

The World Economic Forum's Global Cybersecurity Outlook 2026 found that 94% of cyber leaders believe AI will be the biggest driver of change in cybersecurity this year. Microsoft Copilot Cowork, launched June 16th, introduces a delegated AI agent that can send email, post in Teams and schedule meetings on behalf of users – built directly into your existing interface.

AI is becoming part of every Microsoft 365 user experience globally over the coming weeks, whether you're prepared or not. The good news? These controls exist, they're built into Microsoft 365, and for Secure365 clients, the foundational layers are already live in your environment.

The remaining work is human: deciding what your firm's AI position actually is, writing it down, and pointing your team to it.

Your next step

If you'd like to see where your tenant stands today with these guardrails, book a 15-minute call – no obligation, no jargon. We'll show you exactly what's protected and what needs attention.