AI is moving incredibly quickly, and businesses are understandably keen to take advantage of it.
But alongside the excitement around productivity and automation, there’s another question businesses need to be asking:
Do you actually know what AI tools your staff are using and what those tools have access to?
When we talk about AI governance, we’re not talking about AI ethics. That’s a separate conversation around things like bias, transparency, and responsible use.
AI governance is much more practical.
It’s about understanding what AI tools are operating inside your business, what data they can access, what permissions they have, and whether anyone is actually monitoring them.
And as AI becomes more embedded in everyday work, this is becoming a very real business risk.
AI Is Becoming the New Shadow IT
We’ve seen versions of this problem before.
Years ago, an employee might download a piece of software onto a work computer without IT approval. It may have looked useful, but nobody really knew what was sitting behind it or what risks it introduced, which is what shadow IT is.
AI agents are creating a similar problem, except now they can potentially access far more of the business.
An employee might find an AI tool, connect it to their work account, and approve access to their email, calendar, CRM, or documents without giving it much thought.
Before long, an external AI tool could potentially see a significant amount of company and customer information, and the business itself may not even know the connection exists.
That’s why one of the first things we recommend is auditing the AI tools already being used across the business.

Do You Know What Your Staff Have Connected?
An AI audit doesn’t just mean checking whether staff are using ChatGPT.
Businesses should also look at AI agents, browser extensions, meeting assistants, automated tools, and AI features being introduced into existing software.
The important questions are:
- What AI tools are currently being used?
- What information can they access?
- What permissions have been granted?
- Does the AI actually need that level of access?
- Are staff using business-approved accounts or personal accounts?
Businesses may be surprised by what they find.
The aim isn’t to stop people from using AI. It’s to understand where it is being used so it can be managed properly.
Give AI the Bare Minimum Access
One of the most important principles of AI security is simple:
Give AI only the access it genuinely needs.
If an AI agent only needs to read information, it shouldn’t automatically have permission to edit it.
If it doesn’t need to delete anything, it shouldn’t have delete permissions.
And if it only needs information from your CRM, there may be no reason for it to access an employee’s entire inbox, calendar, and document library.
The more access a system has, the greater the potential consequences if something goes wrong.
AI is powerful, but it is not perfect. It can misunderstand instructions, hallucinate information, and produce inconsistent results.
Businesses should be deliberately controlling what AI can see and what it is allowed to do.
Keep AI Inside Systems You Already Control
This is where we believe CRM systems have an important role to play.
Rather than allowing staff to independently connect different AI applications directly to company data, approved AI tools can be embedded into systems the business already controls.
For example, when AI operates from within your CRM, you can control what information it can access, what actions it can perform and which users can use it.
You also gain better visibility over how AI is interacting with your business information.
At A1CRM, we believe this is a much safer approach.
AI should sit within your technology environment, not outside it with unrestricted access to everything.
Centralising AI also gives businesses more control over costs. Not every task requires the most powerful or expensive AI model available, and businesses can choose the right model for the right job rather than leaving those decisions entirely to individual users.
Staff Need to Understand Data Sensitivity
Technology controls are only part of the solution.
Staff also need to understand what information is appropriate to give an AI system.
A simple way to approach this is to separate information into three categories:
Public information: Content already available on your website, social media, or public marketing material.
Internal information: Operational information intended to stay within the business.
Confidential information: Customer records, financial information, contracts, passwords, personal data, or commercially sensitive information.
Employees may not have bad intentions when they paste confidential information into an AI platform. They may simply be trying to complete a task more efficiently.
But once sensitive information is entered into an unapproved external tool, the business may lose control over how that information is handled.
That is why clear internal AI policies and staff training are becoming increasingly important.
Keep Reviewing Your AI Providers
Approving an AI platform shouldn’t be a one-time decision.
Privacy policies, terms and conditions, and data-handling practices can change over time.
Businesses should periodically review the AI providers they rely on and understand how information is being stored, processed, and potentially used.
As AI technology changes, governance needs to change with it.

Follow the 90/10 Rule
At A1CRM, we believe businesses should follow what we call the 90/10 rule.
Let AI do 90% of the work.
Keep the final 10% human.
AI can research, summarise, analyse, draft and prepare recommendations.
But before something important is sent, published, changed or acted on, a person should still review and approve it.
Think of that final 10% as a safety brake.
AI can produce incorrect information with a high level of confidence. It can misunderstand context or give different answers when working from the same data.
Human oversight allows businesses to benefit from automation without removing accountability.
The goal isn’t to replace people.
It’s to use AI to make people significantly more productive while keeping human judgement where it matters.
What Should an Internal AI Policy Include?
Every business using AI should now consider having an internal AI policy.
It doesn’t need to be complicated, but it should clearly explain:
- Which AI tools are approved for business use.
- Whether staff need approval before installing AI tools or browser extensions.
- What types of information can and cannot be entered into AI.
- What systems and permissions AI tools are allowed to access.
- When human review and approval are required.
- Rules around AI-generated content and intellectual property.
- How staff should report an AI-related security issue.
- Who is responsible for reviewing AI platforms and vendor policies.
Most importantly, staff need to understand the policy.
Creating a document and filing it away somewhere isn’t enough.
AI Isn’t Going Away, So Businesses Need to Govern It Properly
We don’t believe businesses should be afraid of AI.
There is enormous value in this technology, and we’re only at the beginning of what it will be able to automate and improve.
But businesses need to maintain control.
Know which AI tools are being used.
Know what they can access.
Limit their permissions.
Train staff to recognise sensitive information.
Review your AI providers.
And keep a human involved in important decisions.
The businesses that succeed with AI won’t necessarily be the ones using the most tools.
They’ll be the ones using AI in a structured, secure, and deliberate way.

At A1CRM, that’s where we believe CRM and AI need to come together, giving businesses the productivity benefits of AI while still keeping control of their data, systems, and customer relationships.
AI should work inside your business, not have unrestricted access to it.
Not sure how AI is currently being used across your business?
A1CRM can help you review how AI fits within your existing CRM and technology stack, identify potential risks, and create a more controlled approach to AI adoption.
Talk to us about building a safer, more controlled approach to AI within your CRM.



