Can You Trust AI With Your Business Data? It's the Wrong Question.
- Shay

- 1 day ago
- 12 min read

A client asked me a question the other day that made me stop for a moment.
“Do you trust AI?”
My answer was no. I don't blindly trust AI, but I also don't blindly trust anything that can connect to the internet.
That doesn't mean I don't use AI. I use it every day in my own business, and I've helped clients implement it in theirs. I think these tools can be incredibly useful, but I want to understand what I'm giving them access to, what information is being used, how that information is handled and what controls I can put around it.
I approach other technology much the same way. There are applications I won't use on my phone or iPad because I'm not comfortable with the information they collect, how that information is stored or what other companies may ultimately have access to it. Health applications are one example. I've personally chosen not to use them because I don't want to put that kind of information into a system unless I'm comfortable with what happens to the data after I provide it.
AI isn't fundamentally different in that respect. The difference is that AI can make it incredibly easy to provide a lot of information without necessarily stopping to think about where that information is going or what the application may be able to access.
What made my client's question particularly interesting was that this wasn't coming from a company that had never used AI. I had already been working with AI in their business for quite some time. One owner uses it throughout the day and loves what it can do, while the other remains much more suspicious of it.
I actually think that's a healthy conversation for a business to have. The answer doesn't need to be that everyone should trust AI, and it doesn't need to be that the business should ban it. The better question is what are we allowing AI to access, and what controls have we put around it?
This Business Had Already Been Using AI
About a year and a half ago, I rolled out Microsoft Copilot to three users in the company as a controlled test. I didn't enable it for everyone simply because the technology was available.
At that point, I had already spent considerable time working on the company's Microsoft 365 environment. Security groups and SharePoint permissions controlled which employees could access different areas of company information, and other security controls were already in place.
More recently, I implemented Claude Teams and connected it to the company's Microsoft 365 environment through an MCP connector. Again, I wasn't starting with AI and trying to figure out security afterward. I was adding another technology to an environment where the underlying permissions and access structure already existed.
The employees aren't taking the company's SharePoint library and uploading it into Claude. Claude can retrieve information through the Microsoft 365 connection based on the access available to the user. That makes the Microsoft 365 security groups and SharePoint permissions I had already established an important part of the AI implementation.
I also configured single sign-on so employees use the company's existing Microsoft identity to authenticate to Claude. That makes things easier for employees, but it also keeps access tied more closely to an identity system the business already manages. If an employee leaves and that Microsoft identity is disabled, it can no longer be used to authenticate to the company's Claude environment through SSO.
That matters because employee offboarding shouldn't depend on someone remembering later that a former employee had another standalone account somewhere.
AI Governance for Small Business Starts Before You Turn On the AI
One of the most important parts of this client's AI implementation actually happened long before Claude entered the picture. Their Microsoft 365 environment had already been hardened, access to company information was structured around employee roles and I already understood how the company operated and how employees worked with its information.
If I walk into a business where nobody really knows who has access to what, where sensitive information is stored, whether former employees or outside providers still have access, or how Microsoft 365 is configured, connecting an AI platform deeply into that environment isn't where I want to start.
AI doesn't fix an underlying permissions problem. If an employee already has access to information they shouldn't have, an AI system working within that employee's permissions doesn't magically know that access was a mistake. The problem existed before AI was introduced, and AI may make that existing problem easier to expose or magnify.
That's one of the reasons SNL-Tech Services offers both a Microsoft 365 Audit and an IT Baseline Assessment.
A Microsoft 365 Audit allows me to look specifically at the Microsoft 365 environment, including identities, administrative access, authentication, security policies, licensing, SharePoint access and other controls. If the larger concern is that the business doesn't really know how its technology is set up anymore, an IT Baseline Assessment gives me a broader look at the company's computers, devices, network, backups, security, cloud services, remote or field access, documentation and the way employees actually work.
Depending on what a business wants AI to do, I may need to understand one or both of those environments before recommending that AI be connected more deeply into company systems.
Before I ask which AI product should we use, I want to know what we're about to connect it to.
What AI Is Already Being Used in Your Business?
Another important part of this implementation had very little to do with configuring Claude. Before moving forward, I wanted to understand what employees had already been doing with AI.
I reviewed personal AI accounts that had been used for company work and looked at whether company information had been included in those conversations. Where company information had been used in personal AI chats, those conversations were deleted rather than simply pretending that the company's AI use began on the day I implemented Claude Teams.
I also put an Acceptable AI Use Policy in place so employees had clear expectations about which tools were approved, how company information could be handled and what types of information weren't appropriate for use with AI.
Most employees who start using AI aren't trying to bypass company security. They're trying to get their jobs done. Someone discovers that AI can help write an email, summarize a document, research a problem or eliminate an hour of repetitive work. If the business hasn't given employees guidance, each person may end up making their own decision about what is appropriate to put into an AI system.
This is sometimes called Shadow AI—employees using AI tools for business purposes without the company necessarily knowing which tools are being used or what company information is being provided to them. The terminology isn't particularly important to the business owner. What matters is whether employees are already making AI decisions for the company without the company realizing it.
Before deciding where you want to go with AI, it's worth understanding where you already are.
Access to Information Doesn't Automatically Mean It Should Be Used With AI
The Microsoft 365 permissions were an important layer, but they weren't the only layer. An employee may legitimately have access to information because they need it to do their job. That doesn't automatically mean the company wants that information used with AI.
For this client, I established additional hard rules around categories of sensitive information, including areas involving HR, financial information, estimating and bids. Those rules reflected the way this particular company operates and the types of information it considers sensitive.
That is also why I don't think a generic AI policy downloaded from the internet is enough for every business. A construction company, law firm, healthcare practice and landscaping company don't necessarily have the same information, workflows, contractual obligations or business requirements. The rules need to reflect the company using the technology.
Permission to access information isn't automatically permission to use that information with AI.
Setting Rules Wasn't Enough. I Wanted to Know Whether They Worked.
Once the company instructions and hard rules were established, I tested them. I did what I think any good IT person should do after putting a new control in place: I tried to find ways around it.
I changed the way I phrased requests, tried different ways of asking Claude for information that should have been outside the boundaries I established and tested whether I could persuade it to change numbers or produce something that wasn't consistent with the company's instructions.
Some of those early tests showed me places where the instructions needed to be more specific. I adjusted them and tested again. I continued that process until I was consistently getting the expected behavior, including Claude refusing requests that fell outside the rules I had established. I don't want to assume a control works simply because I created it. I want to verify the result.
I took the same approach with the skills I created for individual projects and workflows. Those tests weren't about whether I could get around a restriction. They were about whether Claude was actually producing the result the business needed. If a skill didn't produce the correct output, I refined the instructions and tested it again until I was getting the expected results.
For me, there are two questions that need to be answered before I'm comfortable putting an AI workflow into regular business use: does it stay within the boundaries I've established, and does it actually do the job correctly and consistently enough to be useful?
A secure AI workflow that consistently produces the wrong result isn't particularly useful. An AI workflow that produces fantastic results but has inappropriate access to company information isn't something I'm comfortable deploying either. Both sides matter, and human review still matters. AI can make mistakes, so employees still need to review important output before it becomes a customer communication, estimate, financial decision or other important business work product.
Giving Employees AI Isn't the Same as Teaching Them How to Use It
There was another part of the implementation I didn't want to overlook. I could build projects, skills, policies and rules, but employees still needed to understand how to use what I had created.
I built a How to Use Claude project and shared it with the team. When an employee goes into that project, they don't need to know exactly what to ask or how to write a complicated prompt just to get started. They can simply type “Hi,” and Claude gives them options based on the projects, skills and workflows I have created for the company.
From there, the employee can choose what they want help with. Claude can walk them through using a particular project, explain how one of the company's skills works, help determine which workflow is appropriate for what they're trying to accomplish or help them develop a better prompt.
I wanted employees to have somewhere they could go when the real question was simply, “I know we have all of this. How do I actually use it?”
That may sound like a small part of AI governance, but I think it's an important one. If the approved company AI environment is difficult to use while an employee's personal AI account is easy, I've given that employee a reason to work around the controls I've spent time establishing.
Good AI governance shouldn't only tell employees what they can't do. It should make it easier for them to use the approved tools correctly.
Buying an AI Subscription Isn't an AI Strategy
Buying ChatGPT Business, Claude Teams or Microsoft Copilot isn't an AI strategy. It's a software purchase.
AI governance for small business isn't just about creating a policy or choosing an approved AI platform. This is one of the reasons SNL-Tech Services offers an AI Governance Assessment. Before I recommend an AI platform, write policies or start connecting AI to company systems, I want to understand which tools are already being used, whether employees are using personal or company-managed accounts, what information is being used with AI, what systems those tools can access, what the business considers sensitive and what policies and controls should exist around their use.
Those decisions also shouldn't be made once and forgotten. AI tools change quickly. New features appear, connectors change, employees discover new ways to use the technology and the business itself changes. I don't think AI should be treated as something that gets configured once and then ignored.
This is one of the reasons SNL-Tech Services offers an AI Governance Assessment. Before I recommend an AI platform, write policies or start connecting AI to company systems, I want to understand which tools are already being used, whether employees are using personal or company-managed accounts, what information is being used with AI, what systems those tools can access, what the business considers sensitive and what policies and controls should exist around their use.
Sometimes that assessment may show that the foundation is already there. Sometimes it may uncover a Microsoft 365 environment that needs attention first. In other situations, the business may need an IT Baseline Assessment because the larger issue isn't AI at all—the company doesn't have a clear picture of its technology environment.
So, Do I Trust AI?
I keep coming back to the question my client asked me because I think it captures where a lot of business owners are right now.
One person may use AI throughout the day and see enormous potential in it. Another may look at the same technology and wonder why anyone would trust it with company information. I don't think either person has to win that argument before the business can move forward.
I don't blindly trust AI, but I also don't think a business needs to blindly trust AI to benefit from it. I want to understand what we're using, what it can access, what information we're allowing it to work with, how identities and permissions are configured, what rules employees are expected to follow and where a human still needs to make the decision. I want to test the controls instead of assuming they work, test the output instead of assuming it's correct, and adjust things when the results aren't what I expect.
That's really not very different from the way I approach the rest of a client's technology. The goal isn't to convince everyone to trust AI. The goal is to determine where it makes sense for the business, put reasonable controls around it and make sure the underlying technology environment is ready for what you're asking AI to do.
Where Should a Small Business Start With AI?
If your business is already using AI, or you suspect employees may be using it on their own, I wouldn't necessarily start by banning the technology or buying another subscription. I would start by understanding what's already happening.
Which AI tools are employees using? Are they using personal or company-managed accounts? What company information is being used? What can those tools access? Do your Microsoft 365 or Google Workspace permissions actually reflect who should have access to company information? What information does the business consider sensitive? What shouldn't be used with AI? Do employees have an Acceptable AI Use Policy and an approved, practical way to use AI when it genuinely helps them do their jobs?
Those are some of the questions I work through as part of an SNL-Tech Services AI Governance Assessment.
If the answers reveal that the underlying Microsoft 365 environment isn't well understood, I may recommend starting with a Microsoft 365 Audit. If the business doesn't really have a current picture of its overall technology environment, an IT Baseline Assessment may be the better starting point.
I don't want to recommend connecting AI more deeply into a business until I understand what I'm connecting it to. AI can be an incredibly useful tool, and I've seen firsthand what it can do when it is implemented thoughtfully. But the technology itself isn't where responsible AI adoption begins.
“Responsible AI adoption doesn't start with choosing an AI product. It starts with understanding the business, securing the environment underneath it and then deciding how AI fits into it.” — SNL-Tech Services
Frequently Asked Questions About AI in a Small Business
Can employees use ChatGPT, Claude or Copilot for work?
They can, but the business should make an intentional decision about which AI tools are approved and how employees are allowed to use them. If employees are using personal AI accounts for company work without guidance, the business may have little visibility into what company information is being entered into those systems. An Acceptable AI Use Policy, company-managed accounts where appropriate and employee guidance can help establish clearer boundaries.
Is it safe to connect AI to Microsoft 365?
It can be appropriate to connect an AI platform to Microsoft 365, but I want to understand the Microsoft 365 environment first. Existing permissions matter because an AI system may be able to work with information a user is already authorized to access. If those permissions are broader than they should be, connecting AI doesn't correct the underlying problem. This is one reason a Microsoft 365 Audit may make sense before a business begins a deeper AI integration.
Does my small business need an AI policy?
If employees are using AI for company work, I think the business should establish expectations around its use. The policy should reflect the way the company actually operates, including which AI tools are approved, whether personal accounts can be used, what types of company information shouldn't be used with AI, when human review is required and what employees should do if they're unsure whether something is appropriate.
What is Shadow AI?
Shadow AI generally refers to employees using AI tools for business purposes without the company necessarily knowing which tools are being used or how company information is being handled. It doesn't automatically mean employees are doing something malicious. Often, an employee simply found a useful tool before the company established rules around it. The first step is understanding what is already being used and then deciding what the business wants to allow going forward.
What is an AI Governance Assessment?
An AI Governance Assessment looks at how AI is already being used within a business and what should be put in place around that use. For SNL-Tech Services, that can include reviewing AI tools and accounts, how company information is being used, access and permissions, sensitive information, acceptable-use requirements, employee guidance and the underlying technology environment. If I find that Microsoft 365 or the broader IT environment needs attention first, I may recommend a Microsoft 365 Audit or IT Baseline Assessment before moving further with AI.




Comments