Practical AI for SMEs

Your Staff Are Already Using AI — What Should You Do About It?

A practical five-step starting point for small businesses: find out what people use, check the accounts and information, and give staff guidance they can remember.

8 min read — Altitude IT Support

An employee uses ChatGPT to improve an email.

Someone else puts meeting notes into an AI summariser. Another member of staff uses Copilot. Someone discovers an AI tool that can analyse a spreadsheet. Another installs an AI browser extension.

Management may never have formally introduced AI.

But AI has arrived anyway.

Your staff are already using AI — what should you do? A practical five-step path for small businesses: find out, approve, check accounts, protect information and guide staff.
AI use often arrives through ordinary work before anybody has bought an AI product.

You don't have to buy AI for AI to enter your business.

That is not a reason to panic. It is a reason to get a little visibility and provide a sensible default. Most employees who use AI at work are probably trying to work faster, write better, solve a problem or remove repetitive work. They are not necessarily trying to bypass management or put the business at risk.

A blanket ban can simply push usage further underground. Unrestricted use is not sensible either. The practical answer is not “everyone use AI” or “no one use AI”. It is:

Use the right AI, with the right account, for the right information.

This guide is for a UK small business with roughly 5–100 users: an owner, office manager, operations manager, internal IT contact or Microsoft 365 administrator who wants to know what to do next without starting an academic AI governance programme.

The first five things to do

Start with these five practical steps. They are deliberately ordinary. The objective is to establish a useful day-to-day approach, not to produce a 40-page policy before anyone can use a tool.

1. Find out what people are using

Ask staff what AI tools they use for work and what they use them for. Ask which account they use and whether they have connected the tool to any business systems.

Useful questions

  • Which AI tools do you use for work?
  • What do you use them for?
  • Which account do you use?
  • Have you connected them to any business systems?
  • Have you installed an extension, add-in or meeting assistant?

Do not make this an interrogation. Explain that the objective is visibility, not catching people out. A short anonymous form, a team conversation or a question during a normal IT review can be enough to discover common use cases.

You are looking for patterns such as drafting, transcription, translation, spreadsheet analysis, research, customer replies, coding, meeting summaries and image creation. You are also looking for where the AI came from: a website, an app subscription, a browser extension, a Microsoft 365 feature or a tool somebody connected to a business system.

2. Decide what is approved

Create a simple approved list. Three categories are often enough:

  • Approved — the business has considered the tool, account, data and intended use.
  • Restricted — use may be suitable for limited tasks or with extra permission.
  • Not approved — do not use it with business information.

Do not invent vendor recommendations just to fill the list. Approval depends on the organisation’s licensing, security, data, contracts, requirements and configuration. A tool that is appropriate for one business may be the wrong fit for another, and a free personal account is not automatically equivalent to a business subscription.

For example, the business may decide that its managed Microsoft Copilot experience is approved for day-to-day work, that an external transcription tool needs prior approval, and that personal AI accounts must not receive confidential business information. The exact list should be based on what the business has actually checked.

3. Check the accounts

This is one of the most practical steps. Someone saying “I use Copilot” or “I use ChatGPT” does not tell management enough.

Ask:

Business account or personal account?

The same logo can represent different products, plans and controls. An employee may have a personal Microsoft account and a work Microsoft 365 account, a personal Google account and a business Google Workspace account, or a personal AI subscription and a business licence. The interface may look very similar. The business controls may not be.

Check the account before you check the prompt. For work information, the default should be the account and AI experience approved by the business. That does not mean every personal AI use is a security incident. It means personal and business use should not be confused.

Altitude IT’s guide to which Microsoft Copilot a business should use explains why “we have Copilot” is not an AI inventory: account, licence, tenant, administration, data and permissions all matter.

4. Decide what information can go into AI

Create straightforward guidance about information that needs consideration. Examples may include:

  • customer information and personal data;
  • passwords, access codes and security details;
  • financial information and payment details;
  • confidential documents, contracts and pricing;
  • employee information;
  • intellectual property, designs and source material; and
  • information covered by a client or supplier confidentiality obligation.

Do not claim that none of these can ever be used with AI. The answer depends on the tool, account, contract, configuration, purpose and business requirements. A business-managed tool may have a different position from an unknown free service, and a summarisation task may need different controls from a public marketing draft.

The question is not just:

Can AI do this?

It is:

Should this information go into this AI?

5. Give staff simple guidance

Most small businesses do not initially need a long AI manual. They need rules people can remember and a clear person or route to ask when a situation is unclear.

A practical staff rule

  • Use the approved business AI.
  • Use your business account.
  • Check before sharing sensitive information.
  • Verify important AI output.
  • Don't connect unknown AI to business systems.
  • Ask if you're unsure.

This is enough to improve behaviour while the business learns more. The guidance should be visible in the places people work and should be explained without treating ordinary curiosity as misconduct.

The Altitude IT 10-Second AI Check

Before putting business information into AI, ask five questions:

  1. Which AI am I using?
  2. Which account am I using?
  3. Is it approved for business use?
  4. Should this information go into it?
  5. Will I check the result?
The Altitude IT 10-second AI Check: which AI, which account, is it approved, should the data go into it, and will the result be checked?
Five questions. Ten seconds. Much better AI hygiene.

This catches the wrong browser profile, a personal sign-in, an unfamiliar tool, sensitive information being pasted without thought and an important answer being accepted without checking. It is a small pause that works across different vendors and tools.

Personal accounts, business accounts and the same logo

Employees may have personal Microsoft accounts, work Microsoft accounts, personal Google accounts, business Google accounts, personal AI subscriptions and business AI licences. They may also have more than one browser profile or more than one device.

Same logo. Different account. Potentially very different control.

That is why the first question should not be “Which brand is this?” It should be “Which identity and subscription are active, and is this the route the business has approved?” The answer affects who manages the account, what the business can configure, what information may be connected and what happens when someone changes role or leaves.

Keep the guidance practical. Ask staff to use the business account for business information, make the approved route easy to find and explain what to do if they are unsure. Do not rely on a policy that nobody can remember or a logo that does not identify the account.

Microsoft Copilot: “We have Copilot” is not an AI inventory

Altitude IT is Microsoft-focused, so Microsoft Copilot is a common part of these conversations. “Copilot” can refer to different Microsoft AI experiences. What someone can access depends on their account, licence, tenant, administration, data and permissions.

A work account does not automatically mean the user has the full Microsoft 365 Copilot experience. Copilot Chat and paid Microsoft 365 Copilot can have different capabilities and requirements. A Copilot button in Word, Outlook or Teams does not prove that every employee has the same licence or access to the same business data.

“We have Copilot” is not an AI inventory. Record which users have which licence, which experience is approved, what it is intended for and what the relevant account and permission controls are.

For Microsoft 365 support, account and licensing guidance, see Microsoft 365 Support Manchester. If you are considering Copilot, review the identity, permissions and configuration foundations before expanding use.

Check your Microsoft 365 permissions

AI does not magically repair poor access control. If staff already have inappropriate access to SharePoint, Teams, OneDrive, files, folders or sites, AI capabilities connected to those environments can make existing permission problems more consequential or easier to surface.

AI doesn't create bad permissions. It can expose the consequences of them.

Review:

  • SharePoint site and library access;
  • Teams membership, shared channels and guests;
  • OneDrive and other shared files;
  • external sharing links;
  • old users and users who changed role; and
  • administrative privileges.

This is normal Microsoft 365 security hygiene. It is not a reason to block useful AI by default. The goal is to make sure access reflects how the business actually works. The Microsoft 365 Security Baseline Review is the structured route when identity, sharing and security settings need a deeper look.

Don't forget browser extensions and add-ins

AI use is not limited to websites and chat windows. Staff may encounter it through browser extensions, Outlook add-ins, meeting tools, transcription software, design tools, CRM systems, marketing software and productivity apps.

The AI tool you don't know about may be inside software you do know about.

Ask what extensions and add-ins are installed on business browsers and Microsoft 365 apps. Check what permissions they request, what information they can read, whether they can connect to business systems and whether the business has approved them. You do not need to treat every add-in as malicious; you do need to know what it can do.

Meeting AI needs a short practical review

AI meeting assistants and transcription services are increasingly common. Before adoption, consider:

  • Who is recording?
  • Who knows?
  • Where does the recording or transcript go?
  • Who can access it?
  • How long is it retained?
  • What other systems can it connect to?

These are practical technology and information-handling questions, not legal advice. The answers should be clear enough for staff to explain which meeting tools are approved and when a transcript needs extra care.

AI output still needs checking

AI can produce incorrect information, invented facts, poor recommendations, inappropriate wording and outdated information. The more consequential the work, the more important human review becomes.

AI output is input to human judgement, not a substitute for it.

Ask staff to check important customer communications, financial information, technical recommendations, contractual wording and anything that could cause harm if it is wrong. A quick review is part of using the tool well, not an admission that AI is useless.

What can Altitude IT help with?

Altitude IT can help with the practical technology foundations around AI adoption, including:

  • Microsoft 365 account review;
  • Copilot account and licensing guidance;
  • user and administrator access;
  • SharePoint and Teams permissions;
  • security configuration;
  • approved-tool discussions;
  • practical staff AI guidance;
  • basic AI acceptable-use guidance;
  • identifying obvious technology risks; and
  • helping establish sensible day-to-day AI use.

That is everyday IT administration applied to a changing part of the IT estate. It does not claim specialist technical Shadow AI discovery capability, and it does not replace a wider governance programme.

When does this become an Altitude AI job?

Not every AI question needs an AI transformation project. Sometimes it is simply good IT administration.

Altitude IT

Microsoft 365, accounts, Copilot setup, licensing, permissions, security and everyday user guidance.

Altitude AI

Organisation-wide AI discovery, Shadow AI discovery, AI estate inventory, formal governance, strategy, agents, workflows, risk assessment and ongoing AI estate management.

If the business needs the second kind of work, explore Altitude AI and its wider AI discovery and readiness conversation. Keep the boundary clear: this article is about what a small business should do when employees are already using AI, not about mapping and governing an entire AI estate.

Shadow AI as an IT support conversation

Shadow AI is often discussed as if employees are deliberately hiding technology. In practice, it may begin with somebody trying to summarise a long document or remove a repetitive task. The sensible first response is to make the approved route clear, ask what people are using and provide a safe way to ask questions.

AI is becoming part of the IT estate. It should be managed like part of the IT estate.

Just as an IT review considers users, devices, software, licences, security, access and backups, it should increasingly ask: What AI is being used? That question can sit inside normal technology reviews without turning every conversation into a specialist discovery exercise.

For a plain-English explanation of what Shadow AI is and why it matters, read the IT Club guide to staff using AI. Altitude IT’s role here is the practical next step for the SME: what to ask, what to check and what to tell staff.

The business owner checklist

Use this as a short review, not a score

  • ☐ Ask staff what AI they use
  • ☐ Identify personal versus business accounts
  • ☐ Create an approved AI list
  • ☐ Set simple data rules
  • ☐ Review Microsoft 365 permissions
  • ☐ Check AI browser extensions and add-ins
  • ☐ Review meeting AI tools
  • ☐ Give staff basic guidance
  • ☐ Check important AI output
  • ☐ Review periodically

AI needs an Operational Heartbeat

AI is changing too quickly for a policy written once and forgotten. New features appear inside software the business already uses. People change roles. Licences change. Browser extensions and add-ins accumulate. Staff leave. Microsoft changes Copilot capabilities and settings.

Add AI to the normal technology heartbeat. Periodically check:

  • AI tools and users;
  • licences and accounts;
  • Microsoft 365 permissions;
  • browser extensions and add-ins;
  • meeting tools;
  • new AI features;
  • departed employees;
  • approved-tool guidance; and
  • staff understanding.

This does not have to become a monthly committee. It can be a short item in a quarterly technology or security review, with a named owner and a clear record of decisions.

The Altitude IT view

You do not have to buy AI for AI to enter your business. The answer is not to ignore it, and it is not automatically to ban it.

Start with visibility. Decide what is approved. Check the accounts. Decide what information can go into AI. Give staff simple guidance. Then include AI in the normal review of users, devices, software, licences, security and access.

Use the right AI, with the right account, for the right information. For a small business, that is a practical starting point.

Frequently Asked Questions

Can employees use ChatGPT for work?

They should use the AI tools and accounts approved by the business for work information. Whether a particular ChatGPT plan or account is suitable depends on the tool, account, contract, configuration, purpose and the information being used. Ask which account is active before allowing business data into it.

Should businesses ban ChatGPT?

A blanket ban may push useful work further underground, while unrestricted use is not sensible. A better starting point is to find out what staff use, create an approved and restricted list, set simple information rules and give people a route to ask questions.

What is Shadow AI?

Shadow AI is AI use in an organisation that has not been formally approved, documented or managed. It may be as simple as a personal AI account, browser extension, meeting assistant or add-in used for work. Employees are not necessarily being malicious; the business needs visibility and proportionate guidance.

Should staff use personal AI accounts?

For business information, the default should be an approved business account and AI experience. Personal AI is not automatically unsafe for personal or non-confidential use, but it may not provide the same organisational controls, ownership or administration. Staff should check before using a personal account for work.

What information should employees put into AI?

It depends on the tool, account, contract, configuration, purpose and business requirements. Customer information, personal data, passwords, financial information, confidential documents, contracts, employee information and intellectual property should all prompt a check before being entered.

How do I create simple AI rules for staff?

Start with rules people can remember: use the approved business AI, use the business account, check before sharing sensitive information, verify important output, do not connect unknown AI to business systems and ask if unsure. Expand the guidance as real use cases emerge.

Is Microsoft Copilot safe for business?

Safety depends on the Copilot experience, account, licence, tenant, administration, data and permissions. Microsoft Copilot does not automatically grant access to everything, but poor Microsoft 365 permissions can make existing over-sharing easier to surface. Review the foundations before expanding use.

How should a small business manage AI?

Find out what people use, decide what is approved, check personal versus business accounts, set information rules and give staff simple guidance. Review Microsoft 365 permissions, browser extensions, add-ins, meeting tools and AI licences as part of the normal technology heartbeat.

Should AI be part of IT support?

Yes. AI is becoming part of the IT estate through accounts, licences, apps, extensions, add-ins, permissions and connected systems. Practical AI questions can often be handled as ordinary IT administration. Organisation-wide AI discovery and formal governance are separate, deeper work.

Can Altitude IT help with staff using AI?

Altitude IT can help with Microsoft 365 accounts, Copilot setup and licensing, user access, SharePoint and Teams permissions, security configuration, approved-tool discussions and practical staff guidance. It does not claim specialist technical Shadow AI discovery capability.

When should we speak to Altitude AI?

Speak to Altitude AI when the business needs organisation-wide AI discovery, Shadow AI discovery, an AI estate inventory, formal governance, AI strategy, agent or workflow work, AI risk assessment or ongoing AI estate management. Not every AI question needs that level of programme.

Not sure what AI your staff should be using?

Altitude IT can help with the practical foundations around AI use: Microsoft 365 accounts, Copilot setup and licensing, permissions, security configuration and straightforward guidance for your team.

Talk to Altitude IT Explore Altitude AI