🤖 AI Governance
Using AI safely: ChatGPT and Copilot with company data, AI policy, and readiness.
Can employees use ChatGPT with company data?
Yes, but only on an account your company controls. OpenAI states that by default it does not use inputs or outputs from ChatGPT Business, Enterprise, Edu or its API to improve its models, while personal ChatGPT accounts may be used for training unless the user opts out. Pair a business plan with a written AI policy, data-classification rules and admin-managed sign-in.
What should a company AI governance policy include?
An AI governance policy should name the approved AI tools, define which data may and may not be used in them, require human review of AI output that affects customers or decisions, assign an accountable owner, and set a process for approving new tools and reporting incidents. NIST's voluntary AI Risk Management Framework is the most widely used reference for structuring it.
Should my business use Microsoft Copilot or ChatGPT?
Both are defensible on their business plans: Microsoft says Copilot prompts, responses and Microsoft Graph data are not used to train foundation models, and OpenAI says it does not train on ChatGPT Business, Enterprise or API data by default. Copilot fits companies already standardized on Microsoft 365 because it inherits existing permissions and labels; ChatGPT is a separate platform you must govern.
What is an AI readiness assessment and does my company need one?
An AI readiness assessment is a structured review of whether your data, access permissions, security controls, policies and people are prepared for AI tools. It finds over-shared files, unmanaged AI use and missing governance before rollout, then ranks practical use cases. Any company about to license Copilot or ChatGPT broadly, or handling regulated data, should do one first.
How do we prepare our company for Microsoft Copilot?
Getting ready for Microsoft Copilot means fixing who can see what before you assign licenses. Microsoft states Copilot surfaces any organizational data a user already has at least view permission to, so the core work is finding over-shared SharePoint, OneDrive and Teams content, labeling sensitive files, enforcing multifactor authentication, turning on audit logging and piloting with a small group first.
What is the difference between ChatGPT Business and ChatGPT Enterprise?
Both plans keep your data out of OpenAI model training by default, and both have completed SOC 2 Type 2 audits. ChatGPT Business is the self-serve plan for small and growing teams, with SAML single sign-on, MFA and admin roles. ChatGPT Enterprise is bought through OpenAI sales and adds SCIM provisioning, custom role-based access, a Compliance API audit log and, for eligible customers, data residency.
How do we secure AI agents that can take actions in our systems?
Secure agentic AI by treating each agent as a privileged identity: give it the least access and fewest tools it needs, treat everything it reads as untrusted input, require human approval for high-impact actions, log every tool call and keep an inventory of approved agents. OWASP's Top 10 for Agentic Applications, published December 2025, ranks agent goal hijack as the first risk.
What is shadow AI and how do we stop it?
Shadow AI is employees using AI tools your company has not approved, usually on personal accounts, which puts company data under terms you never agreed to. You control it by offering an approved, company-managed AI tool, discovering which AI sites are in use, warning or blocking when sensitive data goes to unapproved ones, and publishing a short acceptable-use policy. Bans alone rarely work.
How should we classify company data before using AI tools?
Classify data into a small number of levels, such as Public, General, Confidential and Highly Confidential, then state for each level which AI tools may process it. Apply the levels as persistent labels, for example Microsoft Purview sensitivity labels, so AI tools and data loss prevention can enforce them. Regulated data, such as health information or CUI, needs its own explicit rule.
Where should a small business start with AI?
A small business should start with AI by setting a short usage policy, choosing business-grade tools with clear data protections, cleaning up file permissions, and running two or three measured pilots on real, repetitive work such as drafting, summarizing or document search. Expand only what demonstrably saves time without exposing sensitive data. Governance and data hygiene come before custom AI projects.
CIO Support is an executive technology library published by LAN Service Group, Inc. — an IT management, cybersecurity, compliance and AI services firm in San Ramon, California, serving businesses since 1992.
Talk to LAN Service Group