Somewhere in your company this week, an employee pasted something into a free AI account to save an hour. A customer list. A contract with pricing terms in it. They were not being reckless. They had a deadline, the tool was sitting in a browser tab, and nobody had told them not to.
In the meeting where that work got discussed, there is a fair chance an AI notetaker nobody approved was recording. Those bots ride in on calendar invites, follow employees into client calls, and park transcripts in an account your IT team has never seen. Most companies discover them only when a client asks who else was on the call.
This is not rare. When Varonis scanned 1,000 real-world IT environments for its 2025 State of Data Security Report, it found unverified apps, including unsanctioned AI, in 98 percent of them.
Defender, DNS logs, firewall app views and RMM tools may see traces of shadow AI but, even then, only if someone is specifically looking. Free-tier AI accounts leave little to no trace in your tenant. There is little evidence and there are few controls to satisfy a regulator’s inquiry or stand up to a compliance criterion. And are you prepared for the day when a client asks: what happened to our data?
The instinct is to ban the tools. That fails. Employees who found a way to do their job faster will keep doing it on their phones. The companies getting this right go the other direction. They make the sanctioned path faster than the unsanctioned one, then build the governance underneath it.
Here is what actually changed. AI did not introduce a new class of risk. It removed the friction that quietly contained the risks previously. For twenty years, one practical control on over-permissioned data was that nobody had time to search through it. AI removes that limitation. The same shift is coming for action: assistants that read are becoming agents that write, file, and send. So it’s not about what can they see, but rather what are they able to do on your behalf. Every step in this guide is one of those two questions applied to your environment.
There are two timelines here, and confusing them is the most common mistake I see. One is a containment problem you can act on this week: find out who is on free-tier accounts and move them to business-tier account. That is days of work, and in many cases it costs nothing. The other is a foundation problem that takes a quarter: data governance, access review, written policy, deliberate tool selection. Start the first one now. Do not wait for the second to finish.
1. Your data is not ready, and permissions are the reason
Every AI assistant worth deploying can access the information your employees already have permission to reach. That sounds harmless until you examine what those permissions actually include.
The same Varonis report, built on scans of nearly 10 billion files, found that 99 percent of organizations have sensitive data sitting where AI can surface it, and 88 percent still have stale but enabled user accounts in their environment. One company in ten had labeled its files.
That matches what we see in the environments we manage. Personal OneDrive folders holding the working copy of something that matters. A shared drive inherited in an acquisition three years ago that nobody ever cleaned up. A departed employee’s mailbox with the only copy of a signed agreement. Permissions pile up the same way. Someone moves from finance to operations and keeps both sets of access. A contractor gets read rights to an entire site for one project and never loses them.
A person with too much access rarely stumbles onto what they should not see, because browsing is slow and boring. AI removes the friction. Ask a question, and the assistant searches everything that person is entitled to, instantly, and summarizes it.
Over-permissioning that sat harmless for years becomes a live exposure the day you turn AI on.
You can see the shape of the problem in the work clients bring us. A nonprofit keeps donor records in one system and case notes in another, with a decade of exported spreadsheets in between, and wants AI to answer questions across all of it. A logistics team tracks ocean carrier schedules across three portals, a shared mailbox, and a spreadsheet one person maintains by hand, and wants AI to flag the exceptions. An operations lead wants project status pulled together from tasks that live in four places. Every one of those is a good use case. Every one of them either fails or leaks if the data underneath is duplicated, stale, or open to more people than it should be.
Before you deploy anything: inventory where business data actually lives, run an access review on your ten most sensitive locations, apply sensitivity labels to what matters, and archive what should have been archived years ago. It is unglamorous work. It is also the difference between a rollout that produces answers and one that produces an incident.
2. Write the AI use policy before you need it
Most mid-market companies land in one of two places. Either there is no AI policy and everyone improvises, or there is a blanket prohibition that everyone ignores. Both are understandable. Neither survives the first incident.
A workable policy fits on two pages and answers five questions.
- Which tools are approved, by name, and who approves a new one.
- What data never goes into an AI tool under any circumstance. Be specific to your business: PHI, cardholder data, unreleased financials, source code, client records covered by a confidentiality clause.
- What the rule is for AI notetakers in internal and client meetings, including whether attendees have to be told.
- When AI-assisted work has to be disclosed, and to whom.
- What happens when someone uses an unapproved tool. If the answer is nothing, you do not have a policy.
Then tell people. Most employees have no idea a free account may be training on what they type, and no idea their company already pays for a tool that will not. A 30-minute all-hands closes more risk than a policy document nobody opens.
One thing to check before you write any of it: what you have already promised your own customers. Client agreements signed in the last two years increasingly carry AI clauses, and cyber insurance renewals now ask pointed questions about AI use and controls. Read what you have signed before you set your internal rules, not after.
3. Pick your AI tools on purpose
Most companies do not choose an AI platform. They inherit one, because a department bought licenses or because everyone defaulted to whatever they use at home. That is how you end up paying for three assistants that do not talk to each other and governing none of them.
Four platforms are worth considering for mid-market work. Getting the names right matters, because the consumer version and the business version are different products with different terms.
- Microsoft Copilot is the paid add-on. Microsoft Copilot Chat is the version included with Microsoft 365 business-tier accounts. Microsoft renamed both in 2026, dropping the “365” from the product names. Both are covered by enterprise data protection, and Microsoft states that prompts, responses, and data accessed through Microsoft Graph are not used to train foundation models.
- ChatGPT Business, which OpenAI renamed from ChatGPT Team in August 2025, and ChatGPT Enterprise above it. OpenAI does not train on business inputs or outputs by default.
- Claude Team and Claude Enterprise, sold under Claude for Work. Anthropic excludes those plans from the consumer training setting.
- Gemini in Google Workspace, for companies standardized on Google rather than Microsoft.
Choose on four criteria: where your data already lives, what your compliance obligations require, what your people will actually use, and what you can govern with the admin capacity you have. That last one decides more than anyone expects.
Then there is what you will be sold next. The pitch is moving from assistants that answer questions to agents that take actions without a person in the loop. Agents hold standing credentials, so the governance question changes from what data can it see to what can it do on our behalf, and who reviews what it did. “Let’s pilot an agent” is an identity and access decision, not a software purchase.
One example is Microsoft’s newer agent-based capabilities, including Copilot Cowork, which Microsoft moved to general availability in June. It does multi-step work rather than answering a question: reading inbound documents, pulling out the fields that matter, filing them, and flagging the ones a person needs to see. What matters for a mid-market company is where it runs. It sits inside the Microsoft 365 environment you already pay for, under the same Entra ID identity, the same permissions and the same audit trail as everything else, rather than arriving as a separate tool with its own logins and its own governance question. Confirm which licenses it needs before you plan around it. And because it writes real files on your behalf, someone has to own reviewing what it did.
4. Paid business accounts are not optional
This is the containment track, and it is the fastest risk reduction available to you.
Consumer terms permit training on submitted content, either by default or through a setting most people click past at signup. On some platforms, allowing it also extends data retention from days to years. Training rights are only the headline risk. The deeper problem is what consumer tiers do not have: no admin visibility, no DLP, no retention controls, no eDiscovery, no audit trail, and no BAA. And are you prepared for the day a client asks, “What happened to our data?”.
Vendor terms in this space change often. Everything here is accurate as of September 2026. Verify current terms before you rely on them.
Start here if you are on Microsoft 365, because you may already own the fix. Most business subscriptions include Microsoft Copilot Chat at no additional license cost, with enterprise data protection applied to work prompts. If your people are on free ChatGPT today because nothing sanctioned was available, the answer may be sitting in your tenant, switched off and unannounced. Turn it on, point your team at it, and you have moved a real share of your shadow AI onto governed ground this week.
For paid seats, business-tier accounts run roughly $20 to $30 per user per month. 20 users is a few thousand dollars a year. Set that against one incident response engagement, one contract lost over a confidentiality breach, or the legal review triggered by a single regulator’s question. Net/net, the upside of reasonable AI investment can be economically eclipsed by a single misstep.
THE NEXT 30 DAYS
- Survey which AI tools your employees are actually using. Ask without penalty, because you need the truth more than you need compliance.
- Turn on Microsoft Copilot Chat, or the business tier that fits your stack, and tell everyone it exists.
- Move anyone using AI for work off a consumer account.
- Inventory the AI notetakers sitting on your calendars and shut down the ones nobody approved.
- Draft the two-page policy and cover it in a 30-minute all-hands.
5. Why we recommend Microsoft Copilot for most clients
Disclosure first. Dynamic Quest is a Microsoft partner. Take the recommendation with that in mind and hold me to the reasoning rather than the conclusion.
For most mid-market companies already running Microsoft 365, Copilot is the right starting point, for reasons that have little to do with model quality. On raw capability the four platforms are closer than the marketing suggests.
- It works inside the applications people already have open. Adoption fails from friction far more often than from capability.
- It inherits the identity, conditional access, sensitivity labels, retention, and audit you already run, so you govern AI with controls your team already knows.
- Copilot Chat gives you a governed entry point at no additional license cost, so you can move people off consumer accounts before you have finished the budget conversation about paid seats.
There is a catch, and a technical reader will find it anyway. Copilot honors the permissions you already have, which is a strength and a warning at the same time. It creates no new permissions. It will surface everything an employee technically has access to and never would have found by browsing. For most companies that makes a permissions review the prerequisite to a successful Copilot rollout, not a follow-up to it. It is exactly why data readiness is section one.
Scope the first rollout narrowly. Start with the two or three teams where the use case is clearest, prove it there, then expand. You buy fewer seats while you are still learning what the tool is worth in your business, and adoption holds better because your early users become the internal case study instead of the cautionary tale.
If your business runs on Google Workspace, Gemini in Google Workspace is the same argument with a different logo. If you have a specific workload where another platform is clearly stronger, use it, and govern it under the same rules. In these early days, avoid complexity – stick to fewer platforms to lessen risk and surface area. Expand when tools and efficiencies have matured.
Where to start, and what you may already have
If Dynamic Quest already manages your Microsoft 365, some of this is work we can start on with you.
The rest depends on where you actually stand today, which makes it a conversation rather than a proposal. Twenty minutes on where your company sits against these five steps, and an honest answer about which of them you can skip. Clients, ask your DQ team or reply to the note that brought you here. Everyone else, we are glad to have the same conversation.
If you would rather start by listening, we are running a live session on this on Wednesday, September 16 at 1:00 PM ET, with time for questions at the end. Register here