AI governance and security field notes. Source-backed checks.
Practical notes for UK teams deploying AI agents, ChatGPT, Microsoft 365 Copilot and customer-facing automation.
Latest field notes
Current changes turned into practical checks. Sorted newest first.
AI Crawlers, robots.txt and llms.txt for SMEs
Training crawlers and search crawlers are different bots; block the first if you want, but think hard before blocking the second.
Copilot Agent Billing: Budgets, Caps and Alerts
Per-user licences still cover everyday Copilot chat; agentic work now draws Copilot Credits, so budget it like any other metered cloud service.
Copilot Managed Runtime: Governance Checklist
Managed Runtime moves Copilot-built apps inside the tenant boundary; the governance decisions still belong to you, and they are easier made before the first app ships.
Copilot Studio Agent Security: An SME Baseline
Stop anonymous agents, limit channels and connectors, and enforce it at environment level before makers publish their first Copilot Studio agent.
Copilot Usage Exports: UK Privacy Checks
De-identified does not mean anonymous in a 30 person firm; decide who can export Copilot usage data and why before anyone downloads it.
Making Tax Digital and AI Bookkeeping Safely
Let AI sort and suggest; keep a person responsible for categories, quarterly figures and anything sent to HMRC.
Structured Data for AI Search: UK SME Guide
Structured data describes your business accurately; it is not a ticket into AI Overviews, and Google says no special schema is needed.
Copilot Semantic Index and Oversharing Fix
Microsoft 365 Copilot indexes everything a user has access to. Clean up broad 'Everyone except external users' permissions before enabling Copilot licences.
Model Context Protocol Security and Audit Logging
Model Context Protocol connects AI agents directly to company tools and databases. Securing MCP requires strict tool permissions, human approval gates and full audit logs.
Securing SQLite and Postgres MCP Connectors
Connecting Claude Code or Cursor to SQL databases via MCP requires strict read-only database roles, table whitelisting, and query sanitisation.
Shadow AI Discovery with Defender Cloud Apps
Employees paste sensitive company data into consumer AI apps. Use Defender for Cloud Apps discovery to detect, sanction, or block unapproved AI services.
Agent Prompt Injection Is Not SQL Injection
Separate instruction integrity, tool authorization, data validation and output handling instead of borrowing one control for every layer.
AI Agent Approvals vs Permissions
Separate what the agent is allowed to do from what a person must approve for this specific action.
AI Chatbot Customer Support: Escalation Rules
Define when the bot must stop, what context a human receives and which actions remain unavailable to the model.
AI Chatbot Usage Limits: Business Continuity Plan
Map critical work to a documented fallback before a limit appears, and keep model switching separate from access-control decisions.
AI Chatbot Vendor Due Diligence Checklist
Turn vendor claims into workflow-specific questions about data, identity, tools, limits, support and exit.
AI Content at Scale: Avoid Search Spam
Publish only when each page has a distinct audience, evidence, owner and reason to exist.
AI HR Data Boundaries for Chatbots
Split general policy help from case-level employee data and keep sensitive decisions out of an unreviewed chat path.
AI Memory Poisoning: Business Assistant Controls
Separate durable preferences from task facts and require a visible review path before memory changes influence future work.
AI Overviews: Search Console Measurement Guide
Separate search demand, page visibility, clicks and qualified outcomes; do not treat one metric as proof of AI visibility.
AI Refunds: Keep Human Approval in the Loop
Let deterministic rules calculate eligibility and require an authorised person to approve exceptions or high-value refunds.
AI Search Content That Earns Citations
Choose questions with a real audience, add original detail and make each important claim easy to check.
AI Visibility: Mentions and Citations
Define mention, citation, position, source and qualified outcome before comparing tools or publishing more pages.
ChatGPT “Something Went Wrong”: A Practical Fix
The generic ChatGPT error tells you almost nothing, so find the failing layer with a clean new chat, a short prompt and a second network before touching tenant settings.
ChatGPT Agent Browser Safety Checklist
Browser agents turn web pages into inputs and actions. Keep logins, apps, approvals and external writes inside a narrow task boundary.
ChatGPT App Permissions: Read vs Write Actions
An enabled ChatGPT app is not one permission. Review connection scope, available actions and when the user must approve.
ChatGPT Citations That Look Right: Verify Them
A citation-shaped answer is not evidence. Open the source, check that it says what ChatGPT says it says, and mark every claim that the source does not support.
ChatGPT Connectors and Oversharing: Audit Guide
Connector security starts in the source system. ChatGPT cannot make a broadly shared folder private after it is connected.
ChatGPT Deep Research: Source Control for SMEs
Deep research in ChatGPT is a research workflow, not an automatic truth engine. Choose the sources it may use, inspect every citation and keep the decision with a person.
ChatGPT Delete vs Archive: Retention at Work
Archiving a ChatGPT chat only hides it, deleting it starts a retention clock, and neither one removes saved memories, project files or records created in connected apps.
ChatGPT File Upload Failed: Network Checks
A successful prompt does not prove ChatGPT can upload files. Uploads use a different path, a different domain and different limits from ordinary chat, so check those before blaming the file.
ChatGPT Google Drive Scope Error: How to Fix It
When ChatGPT says Google needs admin approval, the cause is almost always an OAuth scope that your Google Workspace administrator has not trusted for the OpenAI app. Compare the scopes the connector asks for with the scopes the admin has approved.
ChatGPT Memory for Work: Privacy Questions
Memory in ChatGPT is useful context, not a harmless convenience. Decide what may persist, who controls it and how a user removes it before staff rely on it for work.
ChatGPT Message Limits: A Team Capacity Plan
Hitting a ChatGPT message limit is an availability event, so plan workloads, fallbacks and stop rules before the busy week rather than sharing accounts.
ChatGPT Model Change: Fix Output Regressions
A model update is a production change when people depend on the output. Keep a small set of known-good tasks and compare behaviour before the new default reaches everyone.
ChatGPT Not Working on a Work Network: Fixes
When ChatGPT works on a phone but not on the office network, compare the two paths before you change anything. The fix is usually a named allow rule or a proxy exception, not guesswork.
ChatGPT Projects for Teams: Set the Boundary
A shared ChatGPT Project keeps chats, files and instructions in one place, which makes it a new access surface that needs an owner, a source scope and an offboarding step.
ChatGPT SSO Login Errors: A UK Workspace Fix
ChatGPT single sign-on problems are usually identity mapping or network problems, not ChatGPT problems. Collect the exact error before you touch the identity provider or the workspace.
ChatGPT Stuck on Thinking: Triage for Teams
When ChatGPT sits on Thinking or loading, start a new chat and compare model, browser and network before feeding more into a conversation that has already stalled.
ChatGPT Temporary Chat: What It Does at Work
Temporary Chat keeps a conversation out of your history and memory, but it is not a data-loss control for files, connected apps or anything you paste that you should not have shared.
ChatGPT Voice Not Working: Firewall Checks
Text chat can work while ChatGPT Voice fails, so separate microphone permission, device audio, UDP port 3478 and company firewall policy before blaming the app.
ChatGPT vs Claude vs Gemini for Business
The right choice depends on where your data already lives, who administers the tenant and what the team will actually do with the tool, not on which model tops this month's benchmark.
ChatGPT Web Prompt Injection: A Business Fix
Prompt injection through web pages is not fixed by telling ChatGPT to be careful; the fix is limiting what untrusted content can make the workflow do.
ChatGPT WebSocket Errors: What IT Should Check
ChatGPT can load its page over ordinary HTTPS and still fail to answer because the streaming connection behind it is blocked, rewritten or dropped by the office network.
Claude Code Authentication Errors: SSO Checks
Most Claude Code login failures come from the wrong credential winning, an expired session or an organisation policy, and each of those has a different owner.
Claude Code Command Not Found: Install Fix
If the terminal says claude is not found straight after installing, the binary is almost always there and the shell simply cannot see it yet.
Claude Code Hooks: Put Checks Before the Merge
A review gate built from Claude Code hooks runs the same cheap checks on every agent action, so the human reviewer only sees diffs that have already passed the boring tests.
Claude Code MCP Security Checklist
Every MCP server you attach to Claude Code adds a new set of tools, a new credential and a new source of untrusted text, so review each one the way you would review a supplier integration.
Claude Code on WSL: Fix Slow Repositories
When Claude Code crawls on WSL, the repository is almost always sitting on the Windows drive under /mnt/c rather than in the Linux filesystem.
Claude Code over SSH: Tmux and Copy-Paste Fixes
Most copy-paste and line-break problems with Claude Code over SSH are a tmux or terminal setting, not a fault in Claude Code itself.
Claude Code Permission Prompts: Safe Settings
Constant permission prompts are Claude Code telling you that the allowlist does not match the work, and the fix is a short, specific set of rules rather than a blanket bypass.
Claude Code Rollouts: Build an Evaluation Suite
Before Claude Code gets wider access to your repositories, build a small evaluation suite of real tasks that shows what it does well, where it fails and whether the guardrails hold.
Claude Context Window Full: Practical Fixes
A full context window is a different problem from a usage limit, and the fix is to give Claude less to carry, not to buy more capacity.
Claude Not Working: Outage or Capacity?
When Claude stops responding, the message on screen tells you whether it is an outage, a capacity squeeze, your own usage limit or a problem on your side.
Claude Projects: Context Management
A Claude Project works best as a small, curated working space with a clear owner, not as a copy of the shared drive.
Claude Usage Credits: Budget the Overflow
Usage credits let a paid Claude plan keep working after the included allowance runs out, so the real decision is who may spend them and how much.
Claude Usage Limit Reached: What Teams Can Do
Claude's usage limit is a rolling five-hour window plus a weekly cap, shared across chat and Claude Code, so a small team should plan around it rather than treat it as a fault.
Custom GPT Actions: A Small Business Review
A Custom GPT action is an API integration with a conversational front end. Review it like an integration, not like a prompt.
Gemini API Context Caching: Cost Controls
Gemini context caching cuts the cost of sending the same large prompt repeatedly, but only when you cache stable material, set a sensible expiry and measure the saving.
Gemini API Function Calling: Approval Controls
Gemini decides which function to call and with what arguments, but your application runs it, so the approval gate belongs in your code and not in the prompt.
Gemini Chrome Agent: Approval Checklist
Gemini in Chrome can read your open tabs, reach into Workspace pages and browse on your behalf, so decide what it may see and what it may submit before anyone at work switches it on.
Gemini Google Apps: Data Boundary Review
Before Gemini is allowed to read Gmail, Drive or Calendar for a business task, check which account type is in use, which apps the administrator has enabled, and where the resulting chats are kept.
Gemini Not Working: Error 1076 and 1099 Fixes
Google does not publish a meaning for Gemini error numbers such as 1076 and 1099, so treat the number as a label for your ticket and work through account, browser, network and status checks in order.
Gemini Personal Intelligence: Privacy Review
Personal Intelligence lets a personal Gemini account draw on Gmail, Photos, Search history and more, and Google may use what it learns to improve its models, so a business needs a clear line between personal Gemini and work data.
Gemini Usage Limits: Five-Hour and Weekly Resets
Gemini app limits are compute based, refresh every five hours and cap out weekly, so a small team should plan model choice and fallbacks rather than expect a fixed number of prompts.
Gemini Voice, Camera and Screen Sharing at Work
Gemini Live can hear the room, see through the camera and watch the whole screen, so set rules for consent, what is on screen and where the transcript goes before staff use it for work.
Google AI Overviews: How Business Citations Work
Google says there is nothing special to add for AI Overviews, so a business earns citations by being indexed, snippet-eligible and genuinely useful, and it measures them in Search Console.
Google AI Search Visibility for UK SMEs
Pick a short list of commercial questions, measure where your pages already appear in AI Overviews and AI Mode, then strengthen those pages before writing anything new.
Indirect Prompt Injection in Support Tickets
Keep customer text out of the instruction channel and let the application, not the model, decide which tools and data are in scope for a ticket.
Local AI vs Cloud AI: Privacy and Trade-offs
Map the whole data path for both options, including prompts, logs, model files, telemetry, updates, operators and backups, before deciding which is more private for your business.
MCP Tool Poisoning: Security Checklist
Treat every MCP server's metadata, tool descriptions and returned content as untrusted input until a person or a policy layer has reviewed and approved them.
Move Chat Between AI Assistants Safely
Treat a copied conversation as a new data transfer with its own trust boundary, and carry over a short verified brief rather than the whole thread.
Ollama Port 11434: Local AI Security
Keep Ollama bound to localhost unless you have a reason not to, check what is actually listening on port 11434, and put a firewall and a proxy between the API and anything that is not your own machine.
Unicode Prompt Injection in AI Skills
Make every character in a skill file visible to the person approving it, and keep skill text out of the trusted instruction channel until it has been reviewed.
Voice AI Meeting Transcripts: Privacy Controls
Decide the purpose, lawful basis, participant notice, access group and retention period for meeting transcripts before anyone switches transcription on.
Agentic AI security checklist for SMEs
An agent that can take action needs a smaller permission set, shorter-lived credentials, visible logs and a tested way to stop it.
AI agents and UK consumer law
An AI supplier does not take responsibility away from the business. Customer-facing agents need truthful wording, tested rules, monitoring and a stop route.
AI recruitment safeguards for UK employers
Calling a tool decision-support does not make it so. Map who or what actually decides, then give candidates clear information and real recourse.
ChatGPT Business write actions checklist
App access, action access and approval prompts are different controls. Review all three before ChatGPT can change company systems.
EU AI Act transparency checklist
The EU AI Act transparency rules have applied since 2 August 2026. UK businesses need an inventory of customer-facing AI, clear disclosures and evidence that each control works.
Microsoft 365 Copilot sensitivity labels
Copilot-generated files can inherit the highest source sensitivity label. That helps only when the labels, permissions and exceptions are already sound.
AI use has nearly tripled
About a third of UK businesses with ten or more staff now use AI, up from one in eight in late 2023.
- Sep 2023: 11.9%
- Dec 2023: 11.8%
- Mar 2024: 13.8%
- Jun 2024: 14.8%
- Sep 2024: 17.8%
- Dec 2024: 18.2%
- Mar 2025: 20.6%
- Jun 2025: 25.1%
- Sep 2025: 27.2%
- Dec 2025: 28.7%
- Mar 2026: 32.1%
- Jun 2026: 34.9%
Agents are early
About three in ten developers use AI agents at work. These notes cover how to run them safely.
- Use agents daily14.1%
- Use agents weekly9%
- Use agents monthly or less7.8%
- Plan to17.4%
- Autocomplete only13.8%
- No plans37.9%
- Accuracy of what agents produce86.9%
- Security and privacy of data81.4%
Start with the use case
Choose a bounded workflow before choosing a product or licence.
Related pages

Stuck on an AI workflow?
A short call is usually enough to find the first safe step.