27/05/2026
“How do we let staff use tools like ChatGPT or Claude… without losing control?”
This is one of the most common questions we’re getting right now.
A team wants to use AI tools.
The business sees the value.
IT sees the risk.
So what do you do?
👉 The mistake: saying “no”
👉 The bigger mistake: saying “yes” to everything
The answer sits in the middle.
What works is having a simple, repeatable decision model:
1. What type of AI is it?
• Standalone tool (ChatGPT, Claude)
• Embedded (Copilot in Microsoft 365, AI in business apps)
2. What data is allowed?
• Non-sensitive only?
• Internal business data?
• Client data under strict controls?
3. What’s the risk vs value?
• High value + manageable risk → controlled approval
• High risk + unclear value → restrict
4. Can you monitor and review?
• Usage visibility matters more than perfection
The businesses getting this right aren’t blocking AI —
They’re governing it properly.
AI adoption isn’t slowing down.
Your guardrails need to catch up.
Curious — how are you handling new AI tool requests internally?