Helium – AI automation agency logo
Helium – AI automation agency logo
Helium – AI automation agency logo
Helium – AI automation agency logo

The AI Your Team Is Already Using

Somebody in your business pasted a client document into a free tool last week. Banning it does not work and pretending otherwise leaves you exposed. Here is the position that does.

Ask your team who uses AI at work and you will get a modest show of hands. The real number is higher, and the people not putting their hands up are not being dishonest. They do not think of it as a business decision.

Somebody drafted a client email with it. Somebody summarised a contract. Somebody pasted a spreadsheet in to work out a formula. None of them asked, because nobody told them it was a question.

The exposure is specific

Not abstract, and worth naming precisely so the conversation stays practical rather than alarmist.

Client information left the business. A contract, a client list or a personal file pasted into a consumer tool has been transmitted to a third party you have no agreement with. In Quebec, under Law 25, and anywhere else with equivalent rules, that is a disclosure you cannot account for.

You cannot answer the question. When a client asks what you hold and who processes it, the honest answer is that you do not fully know. That is a worse position than a policy you have to explain.

Output nobody checked. A confidently wrong summary of a contract that went to a client, with nobody aware it was generated.

Consumer terms. Free tiers frequently reserve broader rights over what you submit than business agreements do. Same technology, different contract, and the difference is the whole exposure.

Banning it does not work

Every business that tried has the same result: usage moves to personal phones and personal accounts, where you have no visibility at all.

The reason is that it genuinely helps people, and a rule preventing somebody from doing their job faster loses to the deadline in front of them. You have not removed the exposure. You have removed your knowledge of it.

Worse, a ban tells your best people that the business is behind. That is a retention problem as well as a security one.

What the regulators actually expect

The European Union’s AI Act entered into force on 1 August 2024, with its first obligations applying from 2 February 2025. Those include a requirement that staff dealing with AI systems have adequate AI literacy.

The Act only reaches you if the output of your systems is used inside the Union, so for most Canadian and US businesses it does not apply directly. It is worth reading anyway, because it is the clearest published statement of what a reasonable standard looks like, and because the questions it asks are the ones your larger clients will start asking within two years.

The literacy requirement is the relevant one here, and it is satisfied by an afternoon and a written note rather than by a certification programme. It is also, conveniently, the exact thing that fixes shadow usage.

The position that works

Provide a sanctioned tool, on business terms, and be specific about the boundary.

Pay for a business account. The commercial terms are materially different from the free tier, and the cost is trivial against the exposure. This one step removes most of the risk on its own.

Write one page, not a policy document. What may go in, what may not, and who to ask. If it runs to eight pages nobody reads it and you are back where you started.

Draw the line around identifiable information. Client names, personal data, anything under an NDA. General questions, drafting, summarising your own material and working through a problem are fine and should be actively encouraged.

Require a human check on anything that leaves the building. Not a review process. A named person reads it before a client does.

Say what happens when somebody gets it wrong. If the answer is discipline, people will hide mistakes and you will find out late. Make reporting it the easy option.

Ask before you write anything

Do not draft the policy first. Spend a week finding out what is actually happening.

Ask each team what they use, for what, and what it saves them. Frame it as wanting to buy the right tools rather than as an audit, and you will get honest answers. Frame it as compliance and you will get silence and no change in behaviour.

That week produces two things. A realistic picture of your exposure, and a list of the tasks where AI is already earning its keep in your business, which is the best possible shortlist for what to build properly.

The three questions to answer for your clients

Separate from your internal position, larger clients are beginning to ask about this in procurement, and the firms with written answers win against the firms who go away to find out.

Do you use AI in delivering our work, and where. A straight yes with specifics beats a vague no, because the vague no stops being credible the moment somebody sees a draft.

Does our information leave your business, and to whom. This is the one they actually care about, and it is answerable in a sentence once you are on business terms.

Who checks the output before it reaches us. Naming a person and a step is the whole answer.

Three sentences, agreed once, and every person in your business can give the same reply. That consistency is worth more than the content.

The opportunity hiding in the problem

This is the part most businesses miss while worrying about the risk.

Your team has already run an unmanaged experiment and identified where AI helps in your specific business. That is expensive research you got for free. The person quietly drafting proposals faster has found a process worth building properly, with your data, on your terms, running for everybody rather than for one person who happened to try.

Shadow usage is a signal about where the value is. Treat it as intelligence rather than as a breach and it points directly at what to do next.

This week
  • Ask, without consequences attached. You need the truth more than you need compliance.

  • Buy business accounts for whatever is genuinely being used.

  • Write the one page and put it where people will see it.

  • Take the two most common uses and build them properly.

A business that has done those four is in a better position than one that banned it, and considerably better than one that has not looked.

Sources
  • European Commission, Regulatory framework for AI. In force 1 August 2024; first obligations, including AI literacy, applied from 2 February 2025.

AI Optimize takes the things your team is already doing informally and builds them properly, on your data, with the audit trail and the disclosure in place. Start at Custom AI Integrations.

Related reading

WHAT WE BUILD

This is the part we solve