From improving productivity to automating repetitive tasks and accelerating decision-making, AI is already transforming the way organisations operate. "Businesses should be excited about the opportunities AI presents," says Lee Tuck, Head of Marketing and Growth at TriStratus. "The real competitive advantage isn't simply using AI. It's using it securely, responsibly and in a way that aligns with your business objectives."
According to Mr Tuck, AI is no longer something organisations are planning for in the future. Employees are already using it every day, often without their employer even realising it.
"The biggest benefit AI provides is giving employees back their time. By automating routine tasks, teams can focus on higher-value work that requires human judgement, creativity and customer engagement."
The real challenge isn't AI. It's unmanaged AI. As with every major technological advancement, AI introduces new risks alongside new opportunities. Rather than asking whether employees should use AI, businesses should be asking: ‘Do we know which AI tools our employees are already using?’ Many organisations would struggle to answer that question.
Employees are increasingly using AI assistants such as ChatGPT and other publicly available tools to draft emails, summarise meetings, analyse spreadsheets, generate reports and write code. While these tools can significantly improve productivity, using personal or consumer AI accounts without organisational approval can bypass existing security controls, governance policies and contractual protections.
This growing trend has become known as Shadow AI. Much like the rise of Shadow IT several years ago, Shadow AI introduces visibility and governance challenges rather than simply technology challenges. Businesses need to understand those risks.
Lee Tuck says: “One of the biggest misconceptions surrounding AI is that every AI platform handles information in the same way.” Consumer AI services, enterprise AI platforms and privately deployed AI environments all have different security, contractual and data handling models.
"The issue isn't simply whether employees are using AI," explains Mr Tuck. "It's whether they're using approved services, whether sensitive information is being shared appropriately and whether the organisation has governance around its use."
Whenever confidential information is submitted to an unapproved third-party AI service, organisations may lose effective control over how that information is processed, retained, or transferred. The level of risk depends on the platform being used, the account type, the organisation's contractual agreements, and the security settings in place.
For businesses operating in regulated industries such as iGaming, financial services, and healthcare, this becomes particularly important.
Information such as KYC documentation, source-of-funds information, player transaction history, commercially sensitive analytics, customer records, or confidential financial information should never be entered into public AI services unless appropriate controls and approvals exist.
Unauthorised disclosure or inappropriate processing of confidential or personal information can expose organisations to contractual disputes, regulatory investigations, financial penalties, and reputational damage.
Compliance is evolving alongside the technology rather than ahead of it. Artificial intelligence is developing faster than many organisations can adapt. At the same time, the regulatory landscape continues to evolve.
The EU Artificial Intelligence Act entered into force in August 2024 and is being implemented in stages across Europe. Alongside the GDPR and sector-specific regulatory requirements, organisations now need to consider AI governance as part of their wider compliance strategy.
"Many AI providers operate globally," says Mr Tuck. "Businesses need to understand where their information is processed, what contractual safeguards exist, and whether the service they're using aligns with their own security and compliance obligations."
The objective is not to eliminate risk completely, which would be impossible, but to understand and manage it. Some organisations have responded by attempting to block AI tools altogether. Mr Tuck believes this approach is unlikely to succeed.
"Employees naturally adopt technologies that help them work faster and more efficiently. Trying to ban AI altogether simply drives its use underground. Instead, organisations need visibility, governance and education." The goal should be controlled adoption rather than prohibition.
Mr Tuck suggests five practical steps every business looking to adopt AI securely should take.
- Identify which AI tools employees are already using, including browser-based services and personal accounts used for work.
- Classify information that should never be submitted to public or unapproved AI services.
- Approve specific AI platforms, account types, and business use cases.
- Implement an AI Acceptable Use Policy with appropriate governance, approval processes, and human oversight.
- Train employees regularly and review AI usage, exceptions and incidents as technology continues to evolve.
"People remain the first and last line of defence," says Mr Tuck. "The technology is only one part of the equation. Employees need to understand what they can use, what information can be shared and how to validate AI-generated content."
In some cases, enterprise AI platforms may be a better alternative. Approved enterprise AI platforms can provide significantly stronger governance and security than consumer services, provided they are configured correctly.
Solutions such as Microsoft 365 Copilot offer enterprise-grade identity controls, data protection, and residency capabilities for eligible customers. However, they should form part of a wider governance framework rather than being viewed as an automatic guarantee of GDPR compliance.
Technology alone cannot replace governance. This is where the TriStratus team excels and can help organisations adopt AI safely. TriStratus works alongside internal IT teams and existing technology providers to help organisations implement AI securely without slowing innovation.
Rather than simply recommending products, the company delivers practical governance and implementation services, including:
- AI usage and Shadow AI discovery
- AI readiness assessments
- Data flow and risk assessments
- AI governance frameworks and acceptable use policies
- Microsoft 365 Copilot readiness and security assessments
- Identity, access and data classification reviews
- Employee AI literacy and awareness training
- Ongoing governance reviews and security monitoring
"Our role is to help businesses embrace AI confidently," explains Mr Tuck. "The organisations that gain the greatest competitive advantage won't necessarily be those using the most AI. They'll be the ones using it securely, responsibly and with the right governance from day one."
Mr Tuck believes that the future belongs to organisations that govern AI well. AI adoption is no longer a topic organisations can put off. It is already happening inside every organisation.
The question is not whether employees are using AI. The question is whether your business knows how it is being used, whether appropriate controls are in place, and whether that use supports your business goals without exposing the organisation to unnecessary risk.
A well-governed AI strategy enables organisations to improve productivity, protect sensitive information and innovate with confidence.
Start with a TriStratus AI Readiness and Governance Assessment to identify current AI usage, information risks, policy gaps, and the controls needed for secure, responsible AI adoption.
Main Image: