You're not early. In McKinsey's 2025 global survey, 88% of organizations said they use AI in at least one part of the business. Microsoft says 90% of the Fortune 500 use Microsoft 365 Copilot.
Plenty of people are already using it outside any company setup. In Microsoft and LinkedIn's 2024 survey, 78% of AI users said they bring their own AI tools to work. In our experience, that usually means a personal ChatGPT account connected to everything, with no settings changed.
It can look complicated from the outside. The companies that went first have already worked out the practices, and for most businesses they come down to three settings and three decisions. You don't need to be perfect. Follow this guide and you'll be well ahead of most people using AI today.
The real question is what AI can reach
Nobody wants AI that only works when you copy and paste into a chat. The value comes from connecting it to your email, calendar, files and CRM. So the question isn't what you're willing to paste. It's what those connections can reach, and what the AI can do with them.
That's where people get stuck, usually because nobody has said what's actually sensitive. Here's a pattern we see often. A business wants AI connected to its CRM. The IT provider says no, because it holds client data. So we ask what's in there: names, companies, job titles, business emails and notes from calls. The contact details are mostly on LinkedIn or the company's website already, and the notes are ordinary business notes.
The caution wasn't wrong. It was aimed at the wrong thing. When nothing has been sorted, blocking everything is the safe answer. It also means the AI can't do much for you.
Three settings
- Training off, and a team workspace once there's more than one of you. On a personal plan, turn training off. Once a team shares client work, a business workspace means the company owns the accounts and data, can remove someone's access the day they leave, and can control which apps people connect.
- Connections need approval. In Microsoft 365 or Google Workspace, your IT provider can require admin approval before anyone connects an AI app to email or files. Connections become a decision, not an accident.
- Drafts, not sends. Where the tool allows it, leave send and write permissions off to start. AI prepares the email and a person sends it. That also limits the damage if an email or web page contains hidden instructions aimed at the AI. Ask IT to disable sending and editing in the app and its granted permissions. Check the actual connection; instructions alone are not a lock.
Three decisions
- What's restricted? Ask of any information: if it landed in a competitor's inbox or the news, what would actually happen? For most businesses the restricted list is short: government ID numbers, bank and card numbers, health records, trade secrets, and anything a law or contract says you can't share. For other information, confirm the intended use, provider terms and access with IT before connecting.
- What's in each system you connect? Many connectors can reach everything your login can open, not just one folder. So decide system by system, not file by file. If a few items are truly restricted, keep them somewhere the connection doesn't use, such as a separate account. Confirm it with a quick test, not an assumption.
- What can it do on its own? Start with AI drafting and a person deciding. Widen it as the results earn trust. AI can write a polished draft with a wrong figure in it, and courts and tribunals have now dealt with AI-invented content in more than 2,000 decisions. So a person checks facts, figures and sources before anything goes to a client, commits money or affects someone.
Why this holds up: layers that cover each other
No single control is perfect. What makes AI workable with sensitive information is a few simple layers, each covering the others' gaps.
- What's in reach. Restricted information stays out of the systems AI can reach, or is labelled so the connection skips it, where your plan supports that. What isn't there can't leak.
- What the connection can do. Only the connections IT has approved, read-only where you can, and no sending or deleting to start. Even if AI sees something it shouldn't, it has far fewer ways to move it.
- How it's told to work. Written instructions, both in the AI's settings or project instructions and in your team's documented processes. For example: never put salaries or banking details in a summary, flag anything from the HR folder, and keep every client email as a draft. Instructions aren't a lock, but they steer the AI away from trouble.
- A person checks. Nothing goes out without someone reading it. That's the last catch for anything the other layers miss.
With all four in place, you can do serious work with sensitive information: summarizing client files, drafting from contracts, preparing board updates. These layers reduce risk; they do not guarantee that sensitive information stays within the business. Connecting a system can let the provider process its information before anyone reviews an AI draft.
What this looks like in practice
The owner or CEO of a 60-person services firm wants AI across email, calendar, the CRM and SharePoint.
| System | What's in it | Decision |
|---|---|---|
| Calendar | Meetings, names, locations | Everyday. Connect it. |
| CRM | Clients, deals, notes, some pricing | Mostly everyday; pricing is confidential. Connect it. |
| SharePoint / OneDrive | Proposals and client work, plus finance and HR folders | Payroll, staff records and banking details are restricted. Before connecting, ask IT to check both indexed search and live connections. Restrictions on one may not apply to the other. Use a separate account if the connection cannot exclude what it should not reach. |
| Everything. People send what they send. | You can't keep things out of an inbox, so protect it through the account and the actions: a business workspace, AI drafts, the CEO sends. |
The CEO connects each system after IT confirms its access and permitted use. The project instructions add the third layer: never put salaries or banking details in a draft, and flag anything from HR for review. The protection doesn't come from keeping AI away from the work. It comes from the layers working together.
Does it matter if AI trains on your data?
For most businesses, less than people think. Training means a model learns general patterns from a very large number of conversations. It isn't someone reading your files. It matters most if you hold proprietary know-how you'd never want a competitor to benefit from, or a contract says your data can't be used this way.
Either way, it's one setting. Personal ChatGPT and Claude accounts let you turn training off, and business plans from OpenAI and Anthropic don't train on your data by default. What a business plan really adds is control for teams: the company owns the accounts, can remove access when someone leaves, and can manage which apps people connect. For a one-person business, a personal plan with training off can be enough, if its terms and controls fit the information and work.
Bringing in your IT provider
Your IT provider's job is to reduce risk, so their first answer is often "lock it down." That's the right instinct for their role. Whether the upside is worth a given risk is a business decision. It's yours, made with their advice.
The fastest way to a useful answer is to bring specifics. Not "is AI safe?" but: "Here's our restricted list. Here's the account. These are the connections we want. AI drafts and a person sends. What do you need to approve that?"
It also helps to know what IT usually sees. Many of their clients already use personal AI accounts with no guardrails. A business that arrives with a restricted list, the right account and drafts-only permissions is a big step up, and most IT providers will be glad to see it.
How we do it, and how our clients do it
We run our own business on ChatGPT and Claude. AI prepares the work. Chase, our founder, approves anything that leaves the business: emails, posts, prices, legal terms, payments and account changes.
With clients, the AI runs in the client's own account, and we don't keep logins to their systems. We start by asking what's actually in each system; the restricted list is usually shorter than anyone expected. Their IT provider approves the account and connections, and we talk to IT directly or send a one-page checklist. AI drafts, and the client sends.
Where to start
Put the three settings in place. Connect calendar and CRM first, since they usually hold everyday information. Add email and files with sending and editing turned off. Run it for a couple of weeks, then widen what the AI can do on its own.
Worth knowing
- In personal ChatGPT, a reply you rate with a thumbs up or down can still be used for training, even with training turned off.
- Many AI tools remember past chats. For sensitive work, use a temporary chat or turn memory off.
- Turn on two-step sign-in for every account the AI connects to. A connected assistant makes a stolen password more costly.
- Don't paste passwords or access keys into a chat, and remove AI access the day someone leaves.
- If a contract requires Canadian data storage, check where the tool stores data before you connect it.
- Canada's privacy laws apply to AI like any other tool: collect what you need, use it the way people expect, and protect it. This guide isn't legal advice; for regulated information, ask a privacy lawyer.
Accurate as of September 25, 2026. AI plans, settings and features change often, so check your provider's current documentation before relying on any detail here.
Sources
- McKinsey, 88% of organizations use AI in at least one business function: The state of AI in 2025
- Microsoft, 90% of the Fortune 500 use Microsoft 365 Copilot: Microsoft AI in Action
- Microsoft and LinkedIn, 78% of AI users bring their own AI tools to work: 2024 Work Trend Index
- ChatGPT training settings, feedback and business plans: OpenAI, how your data is used to improve model performance and OpenAI business data privacy
- Claude training settings and commercial plans: Anthropic, updates to consumer terms and Anthropic Privacy Center
- Admin approval for AI apps: Microsoft Entra, configure user consent and Google Workspace, control which apps access Workspace data
- Connectors can reach everything your login can open: OpenAI SharePoint apps and Claude Microsoft 365 connector security guide
- Memory and temporary chats: OpenAI Memory FAQ and Claude Help Center
- Court decisions involving AI-invented content: AI Hallucination Cases database
- Canadian privacy law and generative AI: Office of the Privacy Commissioner of Canada


