Somebody in the leadership meeting says "we should be doing something with AI", everyone nods, and a week later three different trials are running and nobody is sure what any of them are for.
Buying an AI tool is the easy part. Microsoft already includes a web-based Copilot Chat with eligible Microsoft 365 plans, and paid assistants are a credit card away. The hard part is getting something that saves real time, in the systems you already run, without creating a privacy problem or a mess nobody owns.
These four questions will not make the decision for you. They will tell you whether you are ready to make it.
1. Is your information in order?
AI tools work from the information you give them. If your documents are split across personal OneDrives, email attachments, a file server nobody has tidied in years and three versions of the same price list, the answers will be as muddled as the source.
Signs you have work to do first:
- Staff regularly ask each other "which version is the current one?"
- Important documents live in someone's inbox rather than a shared location.
- The file server and SharePoint both hold copies of the same folders.
- Nobody can say who owns a given SharePoint site or Teams team.
In a Microsoft 365 business, a well-structured SharePoint and Teams environment is the foundation for most practical AI. Cleaning it up is dull work. It is also useful whether or not you ever buy an AI licence.
2. Are your permissions right?
Microsoft says Microsoft 365 Copilot only surfaces organisational data that a user already has at least view permission for. That is the right design. It also means Copilot is an extremely efficient way to find everything a person can technically open, including things they were never meant to see.
Most organisations have years of loose sharing: folders shared with "Everyone except external users", links set to "anyone in the organisation", a former manager's HR folder still visible to their old team. Before AI arrived, obscurity hid most of it. A tool that can search and summarise across everything removes the obscurity.
So review who can see what before you switch on an assistant that reads your files. Start with HR, finance, payroll and board material. We go through the specific SharePoint settings to check in Copilot oversharing and SharePoint permissions.
3. Which process are you actually improving?
"We should use AI" is not a project. "Two people spend most of Monday sorting the shared inbox" is.
The projects that pay off start with a specific, repeatable task that eats staff time and follows rules you could write down. For example:
- sorting, routing and logging incoming email
- onboarding and offboarding staff accounts
- regular reconciliations and billing checks
- document reviews and approvals that need an audit trail
For each candidate, write down how long it takes today, how often it happens, and what a mistake costs. That gives you something to measure the tool against, and an honest way to say no when a trial does not earn its keep.
Be wary of starting with the most visible, highest-stakes process in the business. Pick something frequent, a bit tedious and low-risk. You want to learn how the tools behave before you trust them with something that matters.
4. Who owns it once it is running?
A prototype that works in a demo is the start of the job, not the end. Once an automation is doing real work, someone has to watch it, fix it when a supplier changes an invoice format, and be able to show what it did and why.
Without an owner, AI tools multiply quietly. Each department signs up for its own, costs spread across credit cards, and a workflow the business now depends on has no vendor or support contract behind it. Decide the owner before the trial starts, along with where its activity is logged and who reviews the output.
Meanwhile, your staff are already using AI
Whatever the organisation decides, some staff are already pasting text into public chatbots. That is where the privacy risk sits today.
The Office of the Australian Information Commissioner (OAIC) says privacy obligations apply to any personal information put into an AI system and to any output that contains personal information. As a matter of best practice it recommends organisations do not enter personal information, and particularly sensitive information, into AI chatbots, including publicly available ones. It also expects businesses to do due diligence before adopting an AI product, to keep humans checking the output, and to update their privacy policies to say how they use AI.
A short, plain policy that says which tools are approved and what must never go into them does more than a ban nobody follows. We cover how to write one in Shadow AI: a staff policy that works.
A sensible first step
- Pick one process from question three and measure it.
- Tidy the information that process depends on.
- Review permissions on the sites it touches.
- Name an owner and decide how you will know it is working.
- Run a small, time-boxed trial with a handful of people, then decide on the numbers.
Where Geidi fits
Geidi AI is Geidi's newest division. It offers practical AI and automation, built safely on the Microsoft 365 environments, infrastructure and security Geidi already manages, with the same fixed scopes, review gates and audit trails as its managed services. Projects it has built and runs today include email triage and dispatch, Microsoft 365 administration, recurring task workflows and controlled document processes, and Geidi's AI practice is aligned to ISO/IEC 42001. If one of these questions has you thinking, start with a conversation.
Sources
- Microsoft Learn: Data, privacy and security for Microsoft Copilot
- Microsoft Learn: License options for Microsoft Copilot
- Microsoft Learn: Overview of Microsoft Copilot Chat
- Office of the Australian Information Commissioner: Guidance on privacy and the use of commercially available AI products

