Bridging the gap between academic research and real-world solutions

In the pursuit of scientific advancement, the journey from theoretical research to tangible solutions is often fraught with challenges.

Written by

Joshua Ashton

Insight

7 Oct 2026

4 min read

Post Image

AI Governance: Adopt AI Without Losing Control

Buying an AI licence is a technology decision.

Deciding what it can access, what people can use it for and who remains accountable is a governance decision.

An organisation might approve an AI assistant to help draft documents. That does not automatically mean it should also have access to confidential employee records, connect to every business application or make changes without human approval.

The question is not simply:

“Which AI tool should we buy?”

It is:

“How do we use AI to improve the business without losing control of our data, decisions and operations?”

For SMEs, the answer should be practical. Clear ownership, proportionate controls, useful training and evidence that the technology is delivering value.

Not an unrestricted rollout. Not a policy that prevents every useful experiment.

A managed approach to adoption.

Start by understanding where AI is already being used

Before introducing another platform, establish your current position.

The National Cyber Security Centre describes shadow AI as AI use outside an organisation’s approved systems and processes. Its guidance highlights the risks of losing visibility over sensitive information and recommends understanding why employees use unapproved tools so that suitable alternatives can be provided. National Cyber Security Centre

Start with a straightforward conversation across the business.

Which tools are people using? What tasks are they trying to improve? Are they using company accounts or personal accounts? What information are they uploading, and have any tools been connected to business systems?

Capture the answers in a simple AI register. For each use case, record the tool, business purpose, accountable owner, information involved, connected systems and approval status.

This is not an exercise in catching people out.

It is an opportunity to understand demand and make informed decisions about what to support, restrict or replace.

You need a view of how AI is being used—not just a list of licences purchased by IT.

Assess the use case, not just the platform

Approving a product should not mean approving every possible use of it.

Consider three different activities:

  • Drafting a paragraph from information already approved for publication.

  • Analysing identifiable employee performance records.

  • Allowing an agent to update customer records and send external communications.

These activities involve different information, consequences and levels of autonomy. They should not pass through an identical approval process.

For each proposed use, ask what the system needs to access, what it can change, who could be affected and what would happen if its output were wrong.

Then agree controls proportionate to those consequences.

A useful pilot might need approved data, a named owner and review before publication. A workflow affecting people, finances or production systems needs a more detailed assessment and stronger safeguards.

Approve a defined use case with clear boundaries—not an unlimited permission to “use AI”.

Give the policy something practical to say

“Use AI responsibly” is an intention. It is not an operating instruction.

A useful AI policy should help an employee make a decision during a normal working day.

Which tools and accounts are approved?

Specify the services, account types and uses the organisation has assessed. Provide a route for requesting a new tool rather than leaving employees to make their own procurement decisions.

What information can be used?

Explain which information is permitted, restricted or prohibited in each approved service. Include examples relevant to your business, such as customer records, commercial proposals, employee information and internal technical documentation.

What needs human review?

Define which outputs must be checked before use and which actions require approval before they happen. Name the responsible role rather than assuming “someone in the team” will review them.

Keep the guidance close to real work. Show employees how to handle an unexpected answer, report a possible data exposure and ask for help.

The organisation should also assign an accountable business owner to each material AI use case, supported by IT, security and privacy expertise where needed.

A policy is the starting point. Ownership, configuration, training and review make it operational.

For Copilot, review the permissions behind the experience

Microsoft Copilot in Microsoft 365 respects the access permissions of the person using it. Microsoft also states that prompts, responses and organisational data accessed through Microsoft Graph are not used to train its foundation large language models. Those protections matter, but they do not establish whether your existing permissions are appropriate. Microsoft Learn

The practical implication is straightforward: respecting permissions is not the same as correcting excessive permissions.

For example, a confidential document might already be accessible to a wider internal group than intended. The governance issue is the existing access—not an assumption that Copilot has bypassed it.

Before widening adoption, review SharePoint and Teams ownership, broad access groups, sharing arrangements, sensitive information and the suitability of connected knowledge sources.

Also assess agents and connectors separately. Microsoft advises organisations to review an agent’s permissions, privacy statement and terms rather than assuming every extension has identical data-handling arrangements. Microsoft Learn

An AI rollout should include a review of the information environment it will operate within.

Understand what happens to the data

“Not used for model training” answers one important question. It does not answer every question about storage, retention, access or onward processing.

Microsoft’s own documentation, for example, explains that Copilot interaction history can be stored and managed through retention and compliance capabilities. Microsoft Learn

Before approving a service, establish what information it receives, where it is processed, how long it is retained, who can access it and what happens when additional features or integrations are enabled.

Where personal data is involved, consider the purpose, lawful basis, transparency, data minimisation and responsibilities of the organisations handling it. The ICO explains that a data protection impact assessment is required where processing is likely to result in a high risk to individuals; not every AI use automatically meets that threshold. ICO

For employment decisions or other consequential uses, obtain appropriate privacy and legal input before deployment.

The approval should relate to the actual service, configuration and intended use, not simply the name on the subscription.

Human oversight needs to be meaningful

An answer can be fluent and still be wrong.

The NCSC highlights that generative AI can present incorrect statements as facts and produce biased outputs. That makes the review process important wherever an answer could affect a customer, an employee or a business decision. National Cyber Security Centre

However, adding “a human checks it” to a process is not enough.

The reviewer needs the knowledge, time and source information to challenge the result. They also need the authority to reject it.

For customer communications, that might mean checking factual claims, contractual commitments and tone before sending. For an internal policy assistant, it might mean checking the cited policy and escalating exceptions rather than treating the generated answer as the policy itself.

The UK Government’s AI Cyber Security Code of Practice includes human responsibility and oversight among its principles. It also emphasises that, where human oversight is a risk control, the system must be designed to make that oversight effective. GOV.UK

Human approval should be a genuine control, not a rubber stamp.

Treat AI agents as systems that can act

The distinction between an assistant and an agent matters when a system moves beyond suggesting an answer and starts taking actions.

A drafting assistant may produce text for a person to review. An agent connected to business applications might also update records, send messages or trigger workflows.

The NCSC’s guidance recommends controls proportionate to an agent’s autonomy and the consequences of failure. It explicitly warns against relying on prompting alone. National Cyber Security Centre

For a business deployment, define the systems and actions the agent is permitted to use. Restrict its access to what the task requires, enforce approval before consequential actions, record its activity and establish how to stop it.

Those controls should exist in permissions, integrations and workflow design—not solely in an instruction telling the agent to behave carefully.

For example, an agent asked to prepare a supplier update should not automatically receive permission to amend payment details.

Give the system the minimum authority needed to deliver the intended outcome.

Prove value before expanding access

Security is essential, but a controlled deployment should also demonstrate a useful business outcome.

Start with a specific process rather than a broad ambition to “become AI-enabled”.

Consider an internal knowledge assistant that helps staff find answers in approved policies and procedures. A sensible pilot would use a defined set of current documents, respect user access, reference its sources and provide an escalation route when it cannot answer reliably.

Test it with realistic questions, including ambiguous requests, outdated information and questions different users should not be authorised to answer.

Then measure the result.

Did employees find correct information more quickly? How much checking was required? Were answers useful enough to reduce work, or did they create additional correction and support?

Include licensing, usage, integration and operational costs when assessing value. Time saved on an initial draft is not the same as time saved on the completed task.

This builds on the principle in our article on Azure cost optimisation and governance: understand consumption, ownership and business value before expanding expenditure. Symposium IT

Scale what has demonstrated value—not simply what produced an impressive demonstration.

Keep governance active after launch

Approval should not be the last review.

Reassess an AI use case when its data sources, permissions, model, integrations or intended purpose change. A tool approved to summarise public material should not quietly evolve into a system processing sensitive records.

NIST’s AI Risk Management Framework organises risk management around Govern, Map, Measure and Manage, with governance operating across the other activities. It describes risk management as continuous throughout the AI lifecycle, rather than a one-off checklist. NIST SI Resource Center

For an SME, a practical review should bring together the business owner and the people responsible for operating the service.

Check whether it still delivers the intended outcome, whether users are following the approved process, whether permissions remain appropriate and whether incidents or near misses have exposed weaknesses.

Keep a proportionate evidence trail: the approval decision, risk assessment, testing results, access reviews, training and corrective actions.

The objective is not to collect paperwork for its own sake. It is to explain why the organisation trusts the system to perform the role it has been given.

A practical starting point for SMEs

You do not need to deploy AI everywhere at once.

Begin with one worthwhile use case and answer five questions:

  1. Who owns it? Name the person accountable for its purpose, performance and ongoing review.

  2. What can it access? Define the approved information, accounts and connected systems.

  3. What can it do? Separate suggestions from actions and specify where approval is required.

  4. How will we test it? Agree success criteria and unacceptable outcomes before the pilot.

  5. How will we operate it? Establish monitoring, support, incident handling and a route to stop the service.

Use the answers to decide whether to proceed, improve the controls or choose a different approach.

That creates a practical foundation for adoption without turning every experiment into a major transformation programme.

How Symposium IT helps

Symposium IT’s Managed AI service helps organisations identify useful opportunities, assess readiness, prove value and move into supported operation.

Our approach follows Discover → Prove → Build → Operate, with governance throughout. That connects the AI use case to the wider environment: identity, data, security, business processes and cost.

For production services, Symposium One – AI Complete provides ongoing governance, monitoring and support, including access reviews, knowledge-source administration, usage and cost monitoring, and value reporting. Symposium IT

Whether you are introducing Copilot, assessing existing AI use or considering a business agent, start with the outcome you need and the controls required to support it.

Request an AI Readiness Call with Symposium IT.

Adopt AI without losing control.

Assured today. Ready tomorrow.

Continue reading