AI governance. Rules before rollout.
Define approved sources, blocked data, named reviewers, Microsoft 365 controls and saved evidence for one workflow before the usage spreads.
Controls that make a pilot repeatable
Plain rules for what AI can touch, who reviews it and what proof is kept.
Human approval
Drafts pause for the right reviewer before customers, money or records are affected.
Data boundaries
Approved and blocked sources written down before usage scales.
Microsoft 365 guardrails
Identity, device trust, Teams, SharePoint and DLP control what can be used or shared.
Audit trail
Source, reviewer, decision and output saved where the workflow needs a trail.
Staff policy
Plain rules for what AI can do, what stays out, and when to escalate.
Pilot measurement
Judged by time saved, quality, risk, cycle time or a clear decision signal.
Staff are ahead of the business
More than half of employees use AI for work, while about a third of businesses say they use it. Governance starts with what is already in use.
- Employees using AI for work55%
- Businesses with 10+ staff using AI35%
- 28%0 to 9 staff
- 35%10 or more
- 49%250 or more
Few manage the risk
Fewer than a quarter of businesses using or considering AI have practices to manage its cyber risk.
- 24%Manage AI security risk
- 76%No AI security practices reported
What is being used
Text generation leads, closely followed by tools that create images and other visual content. Each needs its own data rules.
- Text generation (large language models)18%
- Visual content creation16%
- Data processing (machine learning)12%
- Image processing (machine learning)6%
- Robotics2%
See the workflow examples
Choose the department and the decision owner before choosing a tool.
A useful governance boundary
- 01
Identity
Who can use the workflow, from which device and with what role.
- 02
Data boundary
Approved sources and hard exclusions are written down.
- 03
Approval and evidence
A named reviewer signs off and the source, decision and output are saved.
Questions teams ask first
What does the first step cost?
The AI Rollout Diagnostic is £1,500 fixed for two weeks. It covers one workflow decision and ends with one recommendation: build, pause, clean up first or do nothing.
Do we need Copilot already?
No. The diagnostic can recommend Copilot, ChatGPT, Claude, private tools, or no new licence until the workflow is clear.
Can this work in a regulated business?
Yes, if approval, source boundaries, data handling and audit trail are designed before the pilot scales.
Do you build workflows or only advise?
Both. The work can include workflow design, governance, Microsoft 365 guardrails, Microsoft 365 Copilot rollout, connecting AI to your own tools, and technical implementation where needed.
Related pages
