AI is already part of how your team works. Nobody has agreed the rules for it yet.
A practical AI readiness starting point for UK businesses: get your data, permissions and policy sorted before you add more AI tools.
Why AI adoption trips up more businesses than expected
AI adoption tends to go wrong in a predictable way. A marketing team turns on a writing tool and it drafts from brand guidelines that stopped being accurate two years ago. A finance team asks an assistant to summarise last quarter’s numbers and it blends two versions of the same spreadsheet that don’t agree with each other. Neither is really a tool problem. Both are a data problem that AI just makes visible faster.
The same applies to who can see what. A leaver’s account that was never closed, a shared drive nobody owns, a folder that got locked down for one project and never revisited: none of that is new risk. AI just moves through it faster than a person would, surfacing whatever a login already allows.
What needs to happen first before AI adoption
Reviewing permissions and access.
Most businesses have files split across SharePoint, an old server nobody’s got round to decommissioning, and a handful of personal OneDrive accounts, full of duplicate versions and drafts nobody’s deleted. An AI tool has no way of knowing which one’s right, so it works with whatever’s put in front of it.
Permissions
Access reviews tend to slip once a business gets past about fifty people. Someone moves from sales into operations and keeps their old client list. A contractor’s account outlives the contract by a year. AI doesn’t create these gaps, it just makes them easier to walk into.
THE AI TOOLS YOUR team is already using
Someone in HR summarises a disciplinary meeting in ChatGPT to save time writing it up. A sales manager pastes a client’s contract terms into an AI tool to draft a renewal email. Most businesses have no rule for either. NCSC guidance is clear: information put into a public AI tool is visible to the company that owns it, and may be used to train future versions.
DATA, PERMISSIONS, POLICY, THEN TOOLS
Sort the data first. Then work out who can see it. Then write the policy. Only after that does it make sense to add more tools. Most businesses do this backwards, tools first, and spend the rest of the project untangling what that caused. The ICO’s guidance on AI and data protection makes the same point from a different angle: the obligations around accuracy, security and accountability don’t move just because a decision was made by an AI tool.
"Andy was so helpful, worked tirelessly to try and resolve the situation and made a very stressful situation bearable.
Most importantly he returned called when he said he would and even calls back to check the situation had been resolved”
Darran Ford | Owner, Handi Hire
Three AI readinesschecks you can do this week
None of this depends on the template. Here are three things worth doing this week regardless, and none of them cost anything.
Audit the AI tools your team already uses
You’ll likely hear ChatGPT, Copilot, Grammarly, Fireflies, Otter, and one or two you’ve never heard of. What matters more than the list is finding out whether any of it has ever touched something you’d rather it hadn’t.
Check your document store is AI-ready
Open SharePoint or whichever platform sits underneath your case management system. Look at the top level. Is it organised by matter and access-controlled, or has it become a place people drop things.
Run a Microsoft 365 permissions review
The admin centre shows exactly who can see what. Start with finance, HR and anything sensitive, and look specifically for people who changed roles a while back but never lost access to where they used to work.
Are You a Law Firm?
The order of operations is the same, but the stakes are different. Client confidentiality, legal privilege and the SRA’s supervision requirements mean a law firm’s AI policy has to answer questions a generic one doesn’t, including when you’re required to tell a client you’ve used AI on their matter. We’ve written a version of this for law firms that covers exactly that.
Rather have a conversation?
Cloud Geeni has spent more than three decades as an IT partner to UK businesses, so working through AI readiness isn’t new territory for us. A 30-minute call is enough to see where you currently stand and what to prioritise first.