01543 524594  ·  hello@initialit.co.uk
CYBER ESSENTIALS · MICROSOFT PARTNER · UK HELPDESK · 5.0 ★ GOOGLE
HomeBlog › Cyber Security

It’s Time to Govern Your Team’s AI Use: A Guide for Lichfield Businesses

Shadow AI is leaking business data without anyone noticing. Here is how to govern your team’s AI use, the practical way, for Lichfield and Staffordshire businesses.

Andy Price · Founder1 June 2026 · 8 min read

Governing your team’s AI use means three practical things: decide which AI tools are approved for work, be clear about what data must never go into them, and put enough visibility in place to see what is actually happening. You do not ban AI and you do not pretend it is harmless. You set sensible rules so staff can use it without quietly leaking your business data.

Hi, I’m Andy from Initial IT in Lichfield. Let me ask the slightly uncomfortable question I put to business owners across Staffordshire and the West Midlands: do you know which AI tools your team is using, and what they are putting into them? Most owners think they do. Then we dig a little deeper, and it turns out the answer is no.

Key takeaways

  • AI use at work has surged, with the number of users tripling in a year. Governance has not kept up.
  • Nearly half of people using AI at work do so through personal or unsanctioned accounts. This is “shadow AI”.
  • The real risk is staff pasting sensitive data into tools your business cannot see, control or audit.
  • Incidents of sensitive data going into AI tools have roughly doubled in the last year.
  • The answer is not a ban. It is approved tools, clear rules on what can be shared, and visibility.

How fast has AI use really grown at work?

Faster than almost anything I have seen. Generative AI tools like ChatGPT and Gemini slipped into everyday work incredibly quickly because they are genuinely useful, for drafting emails, summarising documents, brainstorming and solving problems faster. The trouble is they arrived so fast that governance never caught up.

Recent reporting on how businesses use generative AI is eye-opening. The number of users tripled in a single year, and people are not just dabbling. They rely on it. Prompt usage has exploded, with some organisations sending tens of thousands of prompts a month, and the very largest running into the millions. On the surface that looks like efficiency. Underneath, it is something you need to get a grip on.

What is shadow AI, and why should you worry?

Shadow AI is staff using AI tools the business has not approved, usually through personal accounts. The reports suggest nearly half of people using AI at work are doing exactly that. It means your people are uploading text, files and data into systems the business does not control, cannot see and cannot audit.

That is where the risk creeps in. When someone pastes information into an AI tool, they are not only asking a question. They are sharing data. Sometimes that data includes customer details, internal documents, pricing, intellectual property, or even login credentials, often without anyone realising. Incidents involving sensitive data being sent to AI tools have roughly doubled in the last year, and the average organisation now sees hundreds of these every month.

Is this an insider threat or an outsider one?

This is where a lot of businesses get caught out. They picture AI risk as hacking from the outside. In practice it more often looks like a well-meaning employee copying and pasting the wrong thing into the wrong box at the wrong time.

These are not malicious insiders. They are people trying to get their job done faster. But because personal AI apps sit outside company controls, the effect is the same: sensitive data leaves the building. And attackers are getting smarter too, using AI themselves to sift leaked data and craft more convincing phishing. If you want the plain-English version of how those attacks land, our guide on cyber security for small business is a good place to start.

Does uncontrolled AI use create a compliance problem?

It can, and quietly. If you operate in a regulated environment, or simply handle sensitive customer data, uncontrolled AI use can put you in breach of your own policies or someone else’s regulations without anyone noticing until it is too late. For a law firm in Lichfield or an accountancy practice in Tamworth, that is not a hypothetical, it is a real exposure.

The UK Information Commissioner’s Office sets clear expectations here, and its guidance on AI and data protection is worth a read. As sensitive information flows into unapproved AI ecosystems, data governance gets harder to maintain, not easier. If your sector has specific obligations, our pages on IT support for law firms and accountants cover what good looks like.

So what does good AI governance look like?

It is not banning AI. That ship has sailed, and a ban just pushes people onto personal accounts where you have zero visibility. It is also not pretending AI is harmless. The real answer is governance, and it is more practical than it sounds.

It means deciding which AI tools are approved for work, being clear about what can and cannot be shared with them, and putting visibility and controls in place so data does not quietly drift where it should not. A big part of that is keeping AI inside tools you already control. If your business runs Microsoft 365, using Copilot within your own tenant keeps data under your roof rather than scattered across personal accounts, which is exactly the kind of thing we set up through our Microsoft 365 work. And it means helping your team understand the risks, not in a scary way, but in a practical, grown-up one.

Quick check: where does your business stand on cyber security?

The questions in our free 2-minute Cyber Security Health Check are the eleven we ask every new client first. Score yourself, see the per-category breakdown, get the three highest-impact fixes for your specific gaps. No marketing list.

Take the 2-minute Cyber Health Check

Frequently asked questions

Should we just ban AI tools at work?

I would not. A ban rarely stops people, it just moves the activity onto personal accounts where you cannot see it. You are usually safer approving a sensible tool, setting clear rules, and giving people a good option than driving the behaviour underground.

What is the single most important rule to set?

Be explicit about what must never be pasted into AI tools: customer data, anything confidential, pricing, intellectual property and login details. One clear, written line on that prevents most of the accidental leaks we see.

How do we even know if our staff are using shadow AI?

Most businesses do not, which is the problem. The right monitoring and controls give you visibility of what is being used and where data is going. It is part of treating AI like any other tool that touches your data, and something we can help you put in place.

Is Microsoft Copilot safer than staff using ChatGPT on personal accounts?

For business data, generally yes, because Copilot inside your own Microsoft 365 tenant keeps that data under your control and policies rather than in a personal account you cannot govern. The tool still needs sensible rules, but it starts from a much stronger position.

Can Initial IT help us put AI governance in place?

Yes. We help businesses across Lichfield and the West Midlands decide which tools to approve, set the rules, add the controls and educate the team. Have a look at our cyber security service or get in touch.

AI is already part of how work gets done. Ignoring it does not make it safer, but governing it does. If you want a hand putting the right policies in place and bringing your team with you, my team and I are here. Just get in touch.

– Andy Price, Founder & MD, Initial IT · 01543 524 594 · hello@initialit.co.uk

Related reading

Read nextHow Much Does Managed IT Support Cost in the UK?Read nextIn-House IT vs Outsourced MSP: Which Is Right for a UK SMB?Read nextFrom freelancer to MSP: how to switch IT providers without downtime