
If you’re a Houston small business owner and you think your team isn’t using AI at work, you’re wrong. They are. They’re just not telling you because they’re not sure if they’re allowed.
The risk isn’t AI itself. The risk is using the wrong tool, the wrong way, with the wrong data. Some uses are completely safe and dramatically increase productivity. Some uses are quietly leaking your client information to third parties in ways you’d never approve if asked.
Here’s what’s actually happening, what to do about it, and a simple acceptable-use policy you can roll out this week.
What employees are actually doing with AI
The honest current state in most Houston small businesses we work with:
- Drafting emails to clients, sometimes pasting in the original client message for context
- Summarizing meeting notes (sometimes uploading the recording)
- Writing or reviewing contracts (pasting in the contract)
- Generating reports from spreadsheet data (pasting in the spreadsheet)
- Coding small scripts (pasting in proprietary code)
- Translating customer communications
- Researching prospects (occasionally including non-public information)
Most of this is genuinely useful. Some of it is creating exposure that nobody on your team understands.
Which tools leak by default
The free, consumer-facing versions of most AI tools — ChatGPT free tier, Gemini free tier, Claude.ai free tier, perplexity.ai — explicitly use your inputs to train future models, unless you actively turn off that setting (and even then, your data sits on their servers).
If an employee pasted a client’s NDA-covered information, a draft contract, or sensitive customer data into one of those tools, that data is now in the vendor’s system. For a regulated business (medical, legal, financial), that may constitute a data breach.
Which tools enterprise-protect
The paid / enterprise versions of these tools handle data very differently:
- Microsoft Copilot for Microsoft 365 — data stays in your tenant, isn’t used to train models, inherits your existing M365 permissions.
- ChatGPT Enterprise / Team / API — data not used to train, retention controls, business associate agreements available.
- Anthropic Claude for Work / API — similar enterprise controls.
- Google Workspace AI features (Gemini for Workspace) — data stays in your Workspace tenant.
The pricing is meaningful (typically $20-30/user/month on top of base licensing) but for any business handling client-confidential information, the safety upgrade is required, not optional.
A simple acceptable-use policy template
One paragraph, signed by every employee:
"AI tools can be a productivity asset, but they also create data-handling risk. Employees may use [APPROVED LIST: e.g., Microsoft Copilot] for work tasks. Employees may not paste client-confidential, financial, health, legal, or proprietary information into any other AI tool, including free consumer versions (e.g., ChatGPT free, Gemini free, Claude.ai). When in doubt, ask before pasting. Violations may result in disciplinary action and, for regulated data, may trigger breach notification obligations."
The policy needs to be specific. Listing approved tools is more effective than abstract rules.
Three quick wins from AI without the risk
- Email drafting in Outlook with Copilot. Copilot for M365 drafts emails that inherit your tenant’s data permissions. The output is consistent, faster than scratch, and the inputs stay in your environment.
- Meeting summarization in Teams or Zoom. Both platforms now offer native AI summary features that don’t leave the conferencing platform.
- Internal Q&A on your own documents. Tools like Copilot or enterprise ChatGPT can search and answer questions about your own SharePoint / OneDrive content without exposing it externally.
What to do this quarter
- Survey your team: which AI tools are people actually using? Don’t punish; you need honest data to set policy.
- Pick an approved tool stack (typically: Microsoft Copilot for Office productivity, plus whatever else your business genuinely needs).
- Roll out the acceptable-use policy. Have every employee sign.
- Train on the approved tools. Show people the productivity wins so they don’t fall back to the unapproved ones.
- If you’re in healthcare, legal, or financial services, get your attorney to review the AI use policy before it goes out.
Need help setting this up?
We help Houston-area small businesses roll out enterprise-safe AI policies, deploy Microsoft Copilot, and train teams to use it well. As part of managed services, or as a one-off engagement through our IT consulting practice.
Book a free discovery call to talk through your situation.
Aspendora Technologies provides managed IT, cybersecurity, and cloud solutions including Microsoft Copilot deployment to Houston-area small businesses since 2010.
