Use AI with confidence, not exposure
Very few managed providers can credibly advise on AI governance. It is the thing we are asked about most, and the thing most businesses have no answer for.
The question is no longer whether your business uses AI. It is whether you know where your confidential information goes when it does.
In almost every organisation we assess, staff are already using AI tools. Usually on personal accounts, usually without anyone senior knowing which ones, and usually with no guidance about what may and may not be entered into them. That is not a technology failure. It is a governance gap, and it is one that can be closed in weeks rather than quarters.
Four principles we work from.
Measurable return, or do not do it
We start every AI conversation with the same question: what would this actually change, and how would you measure it? If there is no answer, the honest recommendation is to wait. A great deal of AI spend in the last two years bought activity rather than outcome.
The confidentiality problem
The risk very few businesses have addressed is not the technology. It is that an employee pastes a contract, a payroll file or a client record into a public tool, and the business now has no idea where that information sits or who trained on it.
A policy people will follow
A policy nobody reads is not a control. We help you write one that is short, specific about what may never leave the business, and clear about which tools are approved. Then we make sure the technical guardrails match what the document says.
Walking alongside, not ahead
Most leadership teams do not need an AI strategy consultant. They need someone to sit with them while they work out what is real, what is noise, and what is worth trying next quarter.
A position you can defend to a client, an insurer or a board.
The deliverable is not a strategy deck. It is a small number of concrete things that change how the business operates.
- An inventory of what AI tooling is genuinely in use today
- A written, one page AI use policy in plain language
- Named categories of information that may never leave the business
- Technical guardrails that match what the policy claims
- A short list of uses worth piloting, each with a way to measure it

Questions about AI in your business.
Is it risky to let staff use AI tools?
It depends entirely on which tools and what they put into them. The risk is rarely the model itself. It is that confidential information leaves the business through a channel nobody sanctioned and nobody is logging. That is a governance problem with a governance answer: approved tools, clear boundaries on what may never be entered, and technical controls that match the policy.
Banning it outright almost never works. Staff use it anyway, on personal accounts, where you have no visibility at all.
Where does AI actually return something measurable?
In our clients, the consistent wins have been narrow and unglamorous: summarising long documents, drafting first versions of routine correspondence, and searching internal knowledge that people previously had to ask a colleague for. In healthcare adjacent settings we have seen real gains in billing accuracy and in auditing internal systems for anomalies.
The pattern is that AI pays when it removes a repetitive step in an existing process, and disappoints when it is bought as a strategy in itself.
Do we need an AI policy if we are only fifty people?
Yes, and it is easier at fifty than at two hundred. The document does not need to be long. It needs to name which tools are approved, state plainly what categories of information may never be entered into any external system, and say who to ask when someone is unsure. One page, understood, beats twenty pages filed away.
Can you help if we have already started using AI without any rules?
That is the usual situation and it is not a problem. We start by finding out what is actually in use, which is normally more than leadership expects. Then we work out what has already been exposed, put boundaries around the tools worth keeping, and write the policy afterwards, once it can describe reality rather than an intention.
Bring your AI questions to the first conversation.
Most executives arrive with the same two: what should we actually be using it for, and what have we already exposed. Both are good starting points.
