AI security

Before Your Team Uses AI at Work, Set These Basic Rules

Four practical questions that help small businesses use AI without exposing client, employee or business information.

Why this matters now

Most small businesses did not wait for a policy before someone on the team opened ChatGPT to draft an email, summarize a file, or answer a client question faster. That is normal. It is also exactly the gap the Canadian Centre for Cyber Security is asking organizations to close. On May 29, 2026, the Cyber Centre updated its guidance, Top 10 Artificial Intelligence Security Actions: A Primer (ITSAP.10.049). It is built for organizations of all sizes, not just large enterprises with IT departments.

The human problem

Your team is not being careless. When people are stretched thin, answering emails, covering for absent coworkers, and trying to keep up, AI feels like relief. The risk is not bad intentions. It is that no one has said out loud what is safe to type into an AI tool and what is not. Client files, staff records, passwords, medical notes and financial data can be pasted into a public AI tool in seconds.

Four questions to answer in writing

What can staff use AI for? What information should never go into AI tools? Who reviews AI output? Which tools are approved? Drafting non-confidential emails, creating checklists and summarizing public information may be reasonable starting uses. Client records, employee information, passwords, financial details, contracts, medical information and confidential operational documents should not be copied into public AI tools without proper review.

Practical examples

In a veterinary clinic, one approved tool might help draft client follow-up messages, while medical records and payment information remain prohibited and a staff member reviews every message. In an independent hotel, AI might help draft guest replies or marketing copy, while guest ID numbers, payment details and booking data remain outside the tool and a manager reviews the result.

What to do next

Write one page. Answer the four questions. Share it with your team. Revisit it in three months as AI use in your business evolves. This is general guidance, not legal advice. Businesses should review their specific data-handling obligations, including requirements under Quebec’s Law 25 where applicable, with a qualified legal or privacy professional.

The POWERME perspective

AI should not be added on top of an already overloaded team. It should remove pressure from the right places. That starts with safer workflows, protected data, human approval and clear rules staff can actually follow.

Original sources

Useful adoption starts with the right question.

Which process adds the most pressure to your team today?

Request a free consultation

Your Sunday read

One clear idea for a better start to the week.

Every Sunday, get one practical idea about AI, workflows and simpler operations.