Itequia

Without governance, there is no security in the use of AI

Gobernanza en el uso de la IA

When someone on your team pastes a document into a chatbot to have it summarised, that information goes on a journey almost nobody keeps track of. First, it leaves the company; then it reaches a third party’s server; and, depending on the tool, it may be stored, processed, or used to train a model. Governing the use of AI is, first and foremost, about knowing where that data ends up and being able to prove it.

What does governing the use of AI mean?

Governing AI is not about drafting a document nobody reads. It means defining, with clear criteria, three things: which tools each team can use, with what kind of data, and with what level of logging and oversight.

Most organisations are not starting from scratch. Among other things, they already have access policies, information classification, and device controls in place for the rest of their technology. The problem is that AI usually comes in outside that framework. According to IBM’s Cost of a Data Breach report (2025 edition), 63% of organisations that suffered a breach had no AI governance policies.

Integrated tool vs. standalone tool

The difference between an AI tool integrated into your environment and a standalone one is not in what it can do. It’s in what happens to your data.

A consumer tool inherits nothing from your organisation. It doesn’t know your permissions, it doesn’t respect the confidentiality labels on your documents, and it leaves no record you can audit. And it remains the usual route. According to Netskope’s Cloud and Threat Report 2026, 47% of generative AI use at work happens through personal accounts. Outside any corporate control.

On top of that, there’s the question of training. According to OpenAI’s documentation, in the consumer versions of ChatGPT (Free and Plus) data is used by default to train the model, unless the user manually disables it. In the business versions and the API, however, it is not. But even with it disabled, the content still goes out to the provider’s infrastructure.

A tool integrated into your environment (like Microsoft 365 Copilot within your own tenant) works with the permissions and labels you already have. Inside the same security perimeter as the rest of your information.

The cost of not being able to prove it

Without traceability, the problem isn’t just that data leaves it’s that if something goes wrong, you can’t know what was exposed or demonstrate that you acted with due diligence.

The regulatory framework is pushing in the same direction. The EU AI Act is already being applied in phases: the obligations for general-purpose models have been in force since August 2025, and throughout 2026 those for high-risk systems come into effect. Fines can reach €35 million or 7% of global turnover. Moreover, it affects any company whose use of AI has an impact on people in the EU, regardless of where it is headquartered. Finally, this regulation does not replace the GDPR: personal data entered into an AI tool remains subject to the same obligations as always.

Allowing or blocking is not the only option

Faced with this, many organisations swing between two extremes: letting each team use whatever they want, or blocking everything. Neither works. The first leaves the door open; the second pushes usage to where there is no visibility and gives up the productivity gains.

There is a third way: allowing the use of AI, but within a governed environment, where the tool inherits your permissions, respects the classification of your information, and keeps a record of what happens. It’s the difference between prohibiting and being able to say yes with control.

At Itequia, as a Microsoft 365 partner, we help organisations bring their use of AI into the same governance framework they already apply to the rest of their information. If you’d like a free initial review of how AI is being used in your company and where your data ends up, write to us at welcome@itequia.com. You can see how we apply AI to custom software here.


Frequently asked questions

Is the information I type into ChatGPT or other public AI tools used to train the model?

It depends on the version. According to OpenAI’s documentation, in consumer accounts (Free and Plus) data is used by default to improve the model, although users can disable this in their settings without the company being able to enforce it centrally. In the business versions (ChatGPT Business and Enterprise) and the API, your data is not used for training by default.

So with the business version it’s already safe to send any data?

Not quite. The fact that your data isn’t used for training doesn’t mean it stays at home: it still goes out to the provider’s infrastructure and remains in their logs. For regulated or sensitive data, the criterion is not to trust an opt-out checkbox, but not to send it outside a controlled environment. That is exactly what good governance solves.

Which Microsoft tools are involved in AI governance, and what does each one do?

Microsoft Purview classifies and labels information and applies data loss prevention (DLP) rules, including over Copilot; Microsoft Defender for Cloud Apps discovers and assesses which AI applications are being used; and Microsoft Intune and Entra control devices and access. Each covers one piece; together they keep AI within the same framework as the rest of your data.


Governance in the use of AI | Itequia AI Web