Artificial intelligence is already becoming part of everyday business. Employees are using AI to draft emails, summarize documents, research topics, analyze information, prepare reports, and speed up routine work.

For business leaders, the next question is not simply whether employees will use AI. It is whether the organization understands how that use affects company data, customer information, cybersecurity, and compliance obligations.

That matters even more for financial institutions, CPA firms, law firms, healthcare organizations, construction and engineering firms, and other businesses that handle sensitive information.

The National Institute of Standards and Technology (NIST) recommends managing AI risk throughout the technology lifecycle and aligning those decisions with an organization's goals, regulatory requirements, risk tolerance, and available resources. Its AI Risk Management Framework organizes that work around four functions: Govern, Map, Measure, and Manage. (NIST)

Before your organization expands its use of AI, these seven questions can help identify where additional safeguards may be needed.

1. What AI tools are employees actually using?

Start with visibility.

Your organization may have approved Microsoft Copilot or another enterprise AI platform, but employees may also be experimenting with free AI chatbots, browser extensions, meeting assistants, document tools, and other applications.

That can make it difficult to know what company information is being shared, where it is going, or whether the tool has been reviewed by IT, security, compliance, or leadership.

An AI inventory should identify which tools are being used, who is using them, what business purpose they support, and what types of information employees are allowed to provide to them.

This is also where an acceptable-use policy becomes important. Employees should have clear guidance about approved AI tools and the types of information that should not be entered into unapproved systems.

2. What company or customer information could those AI tools access?

AI risk often begins with the information being processed.

The Federal Trade Commission has warned that customers may reveal sensitive or confidential information when using AI services, including internal company documents and information belonging to their own customers. (Federal Trade Commission)

Before expanding AI use, organizations should know where sensitive information is stored and how it is handled. Depending on the business, that could include:

  • Customer financial information
  • Tax and payroll records
  • Legal documents and privileged information
  • Protected health information
  • Employee records
  • Contracts
  • Intellectual property
  • Internal financial or strategic information

Data discovery and classification become increasingly important when AI tools can search, summarize, or process information across an organization.

The goal is to understand which information requires additional protection before AI becomes another way to access or use it.

3. Who already has access to sensitive information?

AI can make an existing access-control problem much easier to see.

Consider an employee who has access to a SharePoint folder containing information that is no longer relevant to their job. Before AI, that information might have been difficult to find and rarely opened. An AI assistant capable of searching authorized company content may make the same information much easier to surface.

Microsoft explains that SharePoint and OneDrive access controls affect what Copilot can discover and reference, but Copilot does not change the user's underlying permissions. Microsoft also points to sharing controls, governance policies, sensitivity labels, and data loss prevention settings as ways organizations can reduce oversharing risk. (Microsoft Learn)

Before expanding AI use, review areas such as:

  • User permissions
  • Shared folders and SharePoint sites
  • Guest access
  • Former employee access
  • Administrative privileges
  • Access to confidential or regulated information

For organizations that need ongoing support managing users, devices, Microsoft 365, security controls, and the broader IT environment, AvTek's Managed IT Services are designed to simplify day-to-day IT management while strengthening security. (AvTek Solutions, Inc.)

4. Are your AI policies backed by actual security controls?

An AI policy is a good starting point. It should not be the only safeguard.

If your policy says confidential information should not be entered into certain AI tools, the organization should determine whether technical controls can help support that requirement.

Depending on the environment, those controls may include:

  • Identity and access controls
  • Sensitivity labels
  • Data loss prevention policies
  • Application restrictions
  • Sharing controls
  • Logging and auditing
  • Employee security awareness

Microsoft documents several of these controls for Copilot, including sensitivity labels, DLP conditions, sharing settings, and governance policies that affect what information Copilot can discover or process. (Microsoft Learn)

A written policy tells employees what the organization expects. Security controls can help reduce the chance that a simple mistake turns into a larger problem.

5. Can you monitor and document how AI is being used?

For regulated organizations, documentation matters.

If a customer, auditor, regulator, cyber insurer, or board member asks how your organization is managing AI risk, can you show what controls are in place and how they are being monitored?

Microsoft 365 can capture audit records related to Copilot prompts, responses, and referenced content. Microsoft Purview can also support retention, eDiscovery, and compliance investigations involving Copilot activity. (Microsoft Learn)

The specific tools will differ by organization, but several questions are worth asking:

Can you determine who used an AI system?

Can you identify what information was involved?

Can you investigate activity if something goes wrong?

Can you show what controls your organization has implemented?

NIST's AI Risk Management Framework also emphasizes documenting and prioritizing identified AI risks and continuing to manage them as systems, risks, and business needs change. (NIST AI Resource Center)

This is one reason AI governance fits naturally into an existing compliance program.

AvTek's Compliance as a Service helps regulated organizations assess cybersecurity and compliance gaps, develop and maintain policies and evidence, improve governance, and prepare for audits and examinations throughout the year. (AvTek Solutions, Inc.)

6. How does AI use affect your existing compliance and privacy obligations?

AI may introduce new technology, but many of the obligations surrounding the information it processes already exist.

A healthcare organization still has responsibilities around protected health information. A bank still has obligations related to customer information and cybersecurity. A CPA firm still needs to protect tax, payroll, and personally identifiable information. A law firm still needs to safeguard confidential and privileged material.

Before approving a new AI tool, businesses should understand:

  • What information the system will receive
  • Where that information is processed or stored
  • Who can access it
  • How long it is retained
  • Whether it may be used for additional purposes
  • Whether the vendor's practices align with contractual and regulatory requirements

The FTC has specifically cautioned AI providers about honoring privacy and confidentiality commitments involving customer information. (Federal Trade Commission)

What AI Risk Looks Like in a Regulated Business

The technology may be similar across industries, but the information at risk and the business consequences can look very different.

Financial Institutions

Banks and other financial institutions may need to consider customer financial information, internal banking data, vendor risk, access controls, cybersecurity governance, and regulatory expectations.

AI should be evaluated within the institution's broader cybersecurity and compliance program, including risk assessments, documented controls, third-party oversight, and leadership reporting.

AvTek's Compliance as a Service is built to help financial institutions strengthen cybersecurity compliance, improve audit readiness, maintain evidence throughout the year, and align their programs with frameworks including NIST CSF 2.0. (AvTek Solutions, Inc.)

CPA Firms

CPA firms often possess tax records, payroll information, Social Security numbers, financial statements, banking information, and other sensitive client data.

Before employees use AI to summarize documents, draft client communications, or assist with research, firms should know which tools are approved and what information may be shared with them.

AI governance can also help CPA firms demonstrate that the organization has considered the security and privacy implications of new technology instead of allowing adoption to happen without oversight.

Law Firms

Law firms have additional concerns around confidential client information, privileged communications, matter files, contracts, internal work product, and case strategy.

AI tools can support research and document preparation, but firms should establish clear expectations about approved applications, client information, access rights, and review procedures.

Existing permissions also deserve attention. An AI tool that can quickly locate information across a large document environment can make overly broad access much more consequential.

Healthcare and Home Health Organizations

Healthcare organizations need to pay close attention to protected health information, employee access, vendor relationships, and the systems being used to process patient information.

Before using an AI application with sensitive healthcare information, organizations should determine whether the use is permitted, how the vendor handles the information, and what security or contractual safeguards are required.

Construction and Engineering Firms

Construction and engineering organizations may hold valuable project plans, bids, contracts, designs, customer information, intellectual property, and operational data.

Employees may see obvious productivity benefits from AI, especially when drafting proposals, summarizing specifications, reviewing documents, or preparing communications. Those benefits should be paired with clear rules around confidential project and customer information.

Across all of these industries, the questions remain similar: What information do we have? Who can access it? Which AI tools can interact with it? What controls are in place? Can we demonstrate that those controls are being managed?

7. Who is responsible for AI risk as usage changes?

Someone needs to own the process.

That does not necessarily mean hiring a Chief AI Officer or creating an entirely new department. For many small and midsize businesses, responsibility may be shared among leadership, IT, cybersecurity, compliance, legal counsel, and department managers.

The important part is having a defined process for:

  • Reviewing new AI applications
  • Assessing proposed use cases
  • Updating policies
  • Addressing security or compliance gaps
  • Reviewing vendor risk
  • Communicating important issues to leadership
  • Reassessing AI use over time

NIST describes AI risk management as a continuous process. Its framework calls for organizations to continue managing deployed AI systems as technologies, risks, business needs, and expectations change. (NIST AI Resource Center)

Organizations with an internal IT department may also need additional cybersecurity or compliance expertise without handing over control of their environment. AvTek's Co-Managed IT Services can supplement an internal team with capabilities including Microsoft 365 security, identity and endpoint management, cybersecurity monitoring, backup, and vCSO advisory support. (AvTek Solutions, Inc.)

AI Readiness Starts With the Environment You Already Have

Businesses do not need every AI question answered before they can benefit from the technology.

They should, however, understand the environment AI is entering.

That means knowing what data the organization has, where it is stored, who can access it, which AI applications are approved, what employees are permitted to share, and how the organization will monitor and document its efforts.

For regulated businesses, this work should connect to the cybersecurity and compliance program already in place.

AvTek Solutions helps organizations identify technology and cybersecurity risks, address gaps, strengthen security controls, document compliance efforts, and reduce the complexity of managing IT. Our services span managed IT, cybersecurity, compliance, AI governance, and related technology needs. (AvTek Solutions, Inc.)

If your organization is considering Microsoft Copilot, generative AI tools, or broader AI adoption, now is a good time to evaluate whether your existing security and compliance controls are ready to support it.

Frequently Asked Questions About AI Security and Governance

Is having an AI acceptable-use policy enough?

An acceptable-use policy is an important part of AI governance, but it should be supported by appropriate security controls and business processes.

Organizations should also consider access permissions, approved applications, data protection, monitoring, employee training, and procedures for reviewing new AI tools.


Can employees put client information into ChatGPT or other AI tools?

That depends on the information, the AI service, your organization's policies, applicable contracts and regulations, and the vendor's data-handling practices.

Employees should not assume information is appropriate to submit simply because an AI tool is publicly available. Organizations should establish clear rules about approved tools and sensitive information.


Does Microsoft 365 Copilot automatically give employees access to confidential information?

No. Microsoft says Copilot works with existing Microsoft 365 permissions rather than granting users additional access.

However, existing oversharing or overly broad permissions can affect what information Copilot can discover and reference. That is why reviewing SharePoint, OneDrive, sharing settings, permissions, and information-protection controls is an important part of Copilot readiness. (Microsoft Learn)


How often should an organization review AI risk?

There is no single schedule that fits every organization.

AI risk should be reviewed regularly and when meaningful changes occur, such as approving a new AI platform, introducing a new use case, changing access to sensitive information, adding a new vendor, or receiving new regulatory requirements.

NIST recommends continuous AI risk management throughout the AI system lifecycle. (NIST AI Resource Center)


Who should be involved in AI governance?

Depending on the organization, AI governance may require input from business leadership, IT, cybersecurity, compliance, legal counsel, human resources, and the departments using the technology.

Smaller businesses may not need a formal AI governance committee, but responsibility for approving AI tools and managing related risks should be clearly assigned.


What should a business review before adopting Microsoft Copilot?

At a minimum, businesses should review existing Microsoft 365 permissions, SharePoint and OneDrive sharing, sensitive information, data protection policies, identity controls, and employee guidance.

Microsoft's own documentation shows that existing access and governance settings directly influence what Copilot can discover and reference. (Microsoft Learn)

Ready to Assess Your AI Readiness?

AI can help employees work more efficiently, but adoption should be supported by a clear understanding of your data, access controls, cybersecurity risks, and compliance responsibilities.

AvTek Solutions can help you assess your current environment, identify gaps, and develop a practical plan for managing AI securely as its use grows across your organization.

Talk with AvTek Solutions about your AI readiness, cybersecurity, or compliance needs.