AI · Security
Welcome AI into your workplace with creativity and caution
Generative AI is now built into the apps you already use. Here are practical guidelines for using those features without exposing your business information.
August 20, 2025
Generative AI tools are now built into the applications and services your organization already uses every day. Here are practical guidelines for using those features without compromising your business information.
Review terms of service and licensing agreements
Free AI models usually allow your inputs to be used for training, which means the data you let the tool review may not stay private.
Paid models generally keep prompts within your organization's tenant, which is what you want. But not always. (Midjourney, for example, is designed as a content-sharing platform, so even images generated with paid accounts can be viewed by users outside your organization.)
Generative AI tools are still evolving quickly, as are the businesses built with them. Licensing and service agreements can and will change, so stay informed.
Exercise discretion with sensitive data
Even within organizational silos, you may choose to keep AI tools away from personally identifiable information (PII) or other confidential data. But you may already be entrusting sensitive data to cloud storage and other online tools, and a paid AI tool will likely give you the same level of data protection and privacy.
For example, if your organization uses Google Drive for file storage, Google Gemini respects the existing access controls of your Workspace. If an employee does not have "View" access to a specific folder in Drive, Gemini cannot retrieve or summarize any data from that folder for that employee.
Fact-check AI outputs for accuracy
Evaluate AI-generated responses for accuracy. AI is designed to sound right, not necessarily to be right. Generative AI models can share false or misleading information, or return biased responses.
Continue to follow good security practices
Policy updates and staff training should include guidance on the use of AI within your organization. Policies should outline permissible usage, data-handling guidelines, and prohibited activities.
And while it should go without saying, make sure accounts are secure. Strong passwords and multifactor authentication (MFA) have always been critical steps for organizational security.
The age of AI is still in its early stages. As individuals and organizations integrate AI into daily operations, a strong emphasis on security, data management, and staff training will be essential. That approach lets your organization take advantage of this new tool while managing the risks that come with it.
For a free consultation and written estimate, send us a message.