Gen AI Protection
Your team is already using AI. This is how you make it safe.
See which AI tools your people actually use, stop confidential data being pasted into them, and block the prompts designed to trick them — without banning the tools your team now relies on.
The risk nobody is tracking
AI arrived in most UK businesses without a rollout, a policy or a budget line. It came in through the browser, one person at a time.
Shadow AI
Staff sign up to AI tools with their work email and nobody is told. You cannot govern what you cannot see.
Data walking out
A contract pasted in to be summarised, a spreadsheet uploaded for analysis — client information leaves your control in one click.
Prompt injection
Hidden instructions buried in a document or web page can turn an AI assistant against the person using it.
No answer for the auditor
Clients, insurers and tender questionnaires are already asking how you govern AI. “We are not sure” is an expensive answer.
What we put in place
Six things that turn AI from an unmanaged risk into a tool your team can use with confidence — all of it running on the devices we already look after.
Visibility first
We discover every browser-based AI tool in use across your managed devices — by person, by tool, by how often. You see real adoption before anyone writes a rule.
An approved-tools list
Together we decide which AI tools are approved, which are simply watched and which are off-limits. That decision is then enforced on the endpoint, not buried in a policy document.
Sensitive data stays in
Prompts and file uploads are checked for personal data, card and bank details, health information and anything you have marked confidential. We can log it quietly or stop it before it reaches the model.
Malicious prompts blocked
Prompt injection and jailbreak attempts are caught on the device, so a poisoned document or web page cannot quietly hijack an assistant your team trusts.
Evidence you can hand over
Plain-English reporting on which tools were used, what was blocked and why — the trail you need for GDPR accountability, your insurer and client due diligence.
Guidance for your people
Staff get a clear explanation at the moment it matters rather than a telling-off afterwards. In our experience most teams learn the boundary within a fortnight.
Banning AI does not work. Ignoring it works even less.
Every business we talk to has landed in one of two places. Either AI has been quietly banned — in which case people use it on their phones and you have lost all visibility — or it has been quietly allowed, and nobody knows what has been pasted into it. Neither is a position you would choose.
There is a third option, and it is the one we build. Let people use the AI that genuinely makes them faster, agree which tools are sanctioned, and put a guard between your confidential information and the public models. The tools stay. The client data stays in.
Because we already manage your devices, there is nothing new to buy, install or learn. It becomes another part of the security baseline that sits under your IT support — monitored, reported on and reviewed with you.
How we roll it out
A deliberately unhurried rollout: we watch before we block, so nobody has their work interrupted by a rule that was never tested against how your business actually operates.
Two weeks of listening
We enable discovery in monitor-only mode across your managed devices. Nothing is blocked. At the end you get an honest picture of which AI tools your team already uses and what they are putting into them.
Agree what approved means
A short workshop: which tools are sanctioned, which are merely watched, and what counts as sensitive in your business. We write it up as an AI acceptable-use policy in language you can hand straight to staff.
Turn on data protection in detect mode
Your rules go live, but only to log. You see exactly what would have been blocked and we tune out the false positives before anyone is interrupted.
Switch to enforcement
Once the rules are right, blocking is enabled. Staff get an on-screen explanation of why something was stopped, and every event is logged for review.
Review it every quarter
New AI tools appear constantly and your team will find them. We review usage, update the approved list and give you a report you can share with your board or your clients.
Every Gen AI Protection deployment includes
Find out what your team is already using.
Two weeks of discovery gives you an honest picture of AI use across your business — nothing blocked, nothing disrupted, no obligation at the end of it.
Frequently Asked Questions
No — and we would usually advise against it. Blocking the popular tools outright pushes people onto their phones, where you have no visibility at all. The aim is to let your team use AI that genuinely helps, while making sure client records, personal data and commercially sensitive material never leave your business with it.
The browser-based assistants your team actually uses — ChatGPT, Microsoft Copilot, Google Gemini and the rest — plus the ones you have not heard of yet. Discovery is the point: it surfaces whatever is in use across your managed devices, including tools that arrived without anyone asking IT.
No. The check happens on the device, against the rules you agreed, and what we report on is which tools are used and which policies were triggered. It is there to stop your data leaving the business, not to read your team's work. Exactly what is retained and who can see it is agreed with you in writing before enforcement is switched on.
The inspection happens locally as a prompt is submitted, so there is no noticeable delay. The bigger risk to productivity is a badly tuned rule, which is why we run in detect-only mode first and clear out the false positives before anything is enforced.
It is not a Cyber Essentials control in its own right, but it produces exactly the evidence those conversations need: a documented acceptable-use policy, a record of which software is in use, and proof that personal data is prevented from being sent to third-party services. That maps directly onto ISO 27001 access and asset controls and onto your GDPR accountability obligations.
Microsoft protects data inside its own services, and Copilot inside your tenant is a reasonably safe place for company information. What it cannot see is the member of staff who pastes a client contract into a free AI tool in another browser tab. That gap — the public tools, in the browser, on any site — is what this closes.
Deployment onto managed devices takes a day or two, then we deliberately watch for a fortnight before enforcing anything, so allow around a month end to end. It is priced per user per month alongside your managed IT support, and we quote it only after discovery — so you are paying for the coverage you actually need. Call 01704 320640 for a figure.