Skip to content
Client login

Free Audit

Artificial intelligence

The AI your staff already use: what leaves the business, and the one page of rules that is enough

You bought nothing and it is already in service, on personal accounts. The problem is not the tool — it is that nobody knows what goes through it.

Published on 12 May 2026 — Algeria Agency

The article beside this one is about the tool: what it does well, how it fails, and what you must not entrust to it. It addresses somebody deciding whether to start.

This one starts from a different and more common fact: you already started, without deciding to. Somebody in your business pasted a quotation into an assistant to reword it, a customer list to sort it, a contract to summarise it. It happened on a personal account, free of charge, on a Tuesday, with nobody asking anything.

That is not a fault, and most of the time it is not even a mistake: the work came out better and faster. The problem is elsewhere and fits in one sentence — nobody in the business knows what went out, where it went, or who owns the history.

This article says what actually leaves, why nothing allows you to notice, why banning makes it worse, and what the page of rules that is enough looks like. It also says the one thing we refuse to do on your behalf.

You have already adopted it, and nobody decided to

Business technology usually arrives from the top: somebody buys, it is installed, people are trained, a procedure is written. This one arrived from below and free, so none of the four steps happened.

It came in through the people who write: whoever drafts the quotations, whoever answers customer messages, whoever prepares the minutes, whoever translates into Arabic or French what arrived in the other language. Those are exactly the roles that handle the most content you would rather did not circulate.

An owner usually learns of it by accident, in a passing sentence — "I asked it to reword this" — or by recognising a style that is not that person’s. By then the practice is several months old.

This has to be said plainly because everything after it depends on the point: the people who did this broke no instruction, since there was none. Treating the situation as a fault is the surest way to lose the one thing you need, which is to know what is happening.

So the useful question is not "who did this". It is: what went out, should it have gone out, and what has to be written down so that next time is a decision rather than a reflex.

What actually leaves

What leaves is not "data" in the abstract. It is pasted text, whole, with everything in it, because nobody cleans a document before asking for a summary of it — that would be doing the work you are delegating.

In an ordinary Algerian business that means: quotations with the prices charged and the discounts allowed, customer lists with names, phone numbers and addresses, live contracts, commission tables, bank statements, letters from lawyers, minutes in which people are discussed by name.

In some trades it goes further. A practice pastes a case file. A surgery pastes a report. A travel agency pastes a passport to extract the details. An accountant pastes a balance sheet. Each of those gestures takes four seconds and moves a document whose circulation had until then been controlled.

There is also what leaves without text: a screenshot, a photograph of a document lying on a desk, an attached file. Assistants read all of them, which removes the last practical obstacle that still existed two years ago.

The conclusion is not that this must stop. It is that your business now has an outbound channel nobody opened deliberately and nobody looks at — and an unwatched channel is the only kind that genuinely poses a problem.

Nothing disappears: it is a copy, and that is why nobody notices

The reason this runs for months unnoticed is simple and worth stating: nothing is missing. The document is still in the folder, the file is still on the machine, the list is still in the spreadsheet.

Every control reflex a business has is built on absence. You notice that cash is short, that a file has gone from the cabinet, that stock no longer reconciles. Here there is no absence to observe, so none of those reflexes fires.

The technical tools do not see it either, for a fundamental reason: from the network’s point of view, pasting text into an assistant looks exactly like writing a message. It is not a file leaving, it is typing, on a site that is otherwise legitimate and used for real work.

So there is no signal, no alert, no end-of-month report. The only way to know what went out is to ask people, and the only way to get an honest answer is to have said beforehand that the question is not an accusation.

That is the difference between this and an ordinary leak: no investigation is possible, only a conversation. Which makes the written page more important, not less, since it is the only mechanism that acts before rather than after.

The real problem is the personal account, not the tool

Almost every use described here runs through a personal account, opened with a personal address, often on the free tier. That detail, rather than the choice of assistant, produces most of the consequences.

A personal account belongs to the person. The history of what was pasted into it belongs to them too, including when it is your quotations and your customers. The day they leave the business, that history goes with them, and nothing you do can change it.

A personal account also cannot be revoked. You close a work mailbox, withdraw a server login, take back a phone — you can close nothing at a supplier whose contract binds a person rather than your company.

Finally, a personal account is the one you have no visibility into, no settings on and no recourse over. The business tiers of the same tools generally offer different guarantees about retention and reuse of submitted content; on a free personal account those settings are neither yours nor checkable by you.

Hence a conclusion that often surprises: the first decision is not whether to permit or forbid AI, it is to move the existing use onto an account the business owns. It is an administrative act, it costs little, and it changes the ownership of everything that follows.

Banning does not work, and here is what it produces

The instinctive reaction of an owner discovering this practice is to ban it. That is understandable and it is the worst of the three available choices, behind "permit it silently" and "write a rule".

A ban does not remove the practice because it does not remove the reason for it. Somebody who used to draft quotations in three quarters of an hour and now drafts them in ten minutes is not going back to three quarters of an hour. They will carry on, on their personal phone, off the company network.

What a ban actually produces is the end of the conversation. While nothing was forbidden, somebody could say "I asked it to reword this" without thinking; once it is forbidden nobody says it, and you lose the only source of information you had.

It also selects perversely: the most cautious people obey and the others do not. You end up with the practice concentrated among the people least inclined to ask themselves questions, which is the opposite of the intended result.

The tenable position is narrow and fits in a sentence: the practice is permitted, it is named, it is bounded by a short list of what does not leave, and it happens on a company account. Everything else is secrecy management against people trying to do good work.

Three categories of content, one decision per category

A usable rule cannot be a list of documents, because a list of documents is always incomplete and is out of date within a month. It has to sort by category, and three are enough.

The first category is what is already public: an advertisement, a product description, site copy, a job posting, a message you were going to publish anyway. There is nothing to protect and the rule is "go ahead". By volume it is also the majority of useful uses.

The second is what is yours and not public: prices charged, margins, customer lists, contracts, salaries, internal procedures, unannounced projects. Here the rule is not "never", it is "not as it stands" — you can ask for help with the shape of a quotation without pasting the prices, and with the structure of a contract without pasting the counterparty’s name.

The third is what belongs to somebody else and was entrusted to you: a client’s file, their documents, their personal data, what they told you in confidence. The rule there is different in kind and is the subject of the next section.

The useful discipline is a single reflex teachable in ten minutes: before pasting, say out loud which of the three categories the thing in your hands belongs to. People rarely get it wrong once the question has been put to them.

What belongs to a third party is not a matter of caution

The first two categories concern your own interest: you decide what risk you take with your own information, and that is your right. The third is not yours and the logic changes entirely.

When a client entrusts you with their file, their statements, their records or the list of their own customers, they entrusted them to you. They did not consent to that content being passed to a supplier whose name they do not know, and "it was to go faster" has no value from where they stand.

Some professions also carry a formal duty of confidentiality that has nothing to do with caution: law, health, accountancy, advisory work. For those, the question is not whether the supplier is serious but whether the information was permitted to leave the practice at all.

The practical rule is therefore stricter and simpler than for your own information: what was entrusted to you does not leave, in any version, on any account, including a business one. What can leave is your question, written without the client’s content — and that is almost always sufficient, because the difficulty is generally one of method rather than of the file.

If a case genuinely requires the content to leave, that is a decision taken with the client and recorded in writing. It is no longer an internal usage rule, it is an agreement, and nobody but they can give it.

The page of rules that is enough

A ten-page usage policy will not be read and will have no effect. What has an effect is one page, written in the languages your people work in, displayed where they see it, and reread once a year.

It contains five things and no more. The permitted tools, by name. The account to use, which is the company’s. The three categories from the previous section, with two examples each taken from your own business. The rule about what was entrusted to you, written separately and in one line. And the name of the person to ask when somebody does not know.

That last point is the most important and the most often left out. A rule with nobody to ask becomes a rule applied by guesswork, and people guess in the direction that suits them when they are in a hurry — which is precisely when they reach for an assistant.

Two sentences are worth including verbatim. "What you produce with an assistant, you sign": that settles the question of review without having to discuss reliability. And "if in doubt, ask rather than guess — nobody is in trouble for asking": without the second clause, the first does not work.

Writing the page takes a morning. Having everybody sign it is legally worth little in most cases and worth a great deal otherwise: it is the moment the conversation happens, and that conversation is the real mechanism.

The company account: what it actually changes

Moving from a personal account to a company one is not a security measure in the usual sense: it stops nobody pasting anything. It changes three other things, each of which matters more than it looks.

Ownership first. The history belongs to the business, does not leave with the person, and access is withdrawn on the day they go, like any other access. It is the only way to bring this tool into the leavers’ procedure you already have for mailboxes and keys.

Settings next. The business tiers of the major assistants offer different guarantees about the retention and reuse of submitted content. Those settings exist and can be checked; on a free personal account they are neither yours nor visible to you.

And the rule last, which needs somewhere to land. While the practice runs on personal accounts, a company instruction governs something the company does not hold, which makes it unenforceable and makes that obvious. A shared account gives the page of rules a real object.

The cost is one subscription per person concerned, and "the people concerned" are usually three or four rather than the whole payroll. It is the highest-return spend in this whole subject — not because it protects anything, but because it makes every other decision possible.

What your business must still be able to do itself

There is one thing neither a rule nor a subscription settles, and it is the only one that can cost dearly in the long run: your people’s ability to judge a result.

The article beside this one states it as a failure mode — the tool is wrong with confidence, and a false text is as well written as a true one. The practical internal consequence is that review is not a formality: it is the only barrier there is, and it rests on somebody who knows the subject.

So the risk is not that an assistant gets something wrong; it is that it gets something wrong in a domain where nobody at your end can tell any more. It happens slowly: the person who drafted quotations stops doing the arithmetic in their head, the person who wrote contracts stops knowing the clauses, and two years later there are no reviewers, only approvers.

The rule that protects is short: only use an assistant on tasks whose result somebody in the business could verify. It forbids nothing today; it forbids putting yourself tomorrow in a position where you can no longer check what you deliver.

That rule has a consequence for us, and it is in the last section: there are things we refuse to do on your behalf for exactly this reason, because a competence you delegate to us entirely is one you will no longer have in order to correct us.

Why this article cites no usage rate

You have probably seen figures of the form "x% of employees use AI at work without telling their employer". We cite none of them, and the reason is not only that none of them covers Algeria.

They all come from the same instrument: people are asked to declare a practice they were never given permission for. The under-reporting is therefore not random noise — it depends on one specific variable, the employer’s presumed severity.

And that variable is correlated with what is being measured, in the wrong direction. The more a business has banned without governing, the less its people declare, and the lower the resulting figure. The measurement is most wrong exactly where the problem is largest, and an owner comparing themselves to the average is reassured in proportion to how little they should be.

This is a property of the instrument rather than a defect of the sample: running a wider survey does not fix it, because the error comes not from the number of respondents but from the relationship between the question and the respondent’s situation.

What we look at instead is three questions you can answer today, with no survey. Is there a company account for these tools, yes or no? Is there a written page, yes or no? And can you name the last three documents anybody pasted into an assistant? The third has no answer in almost every business, and that absence of an answer is the finding — not a percentage.

What we do, and what we refuse to do

We write the page of rules with you, in your working languages, with your own examples rather than generic ones — a rule illustrated by the quotation your business actually sends is understood first time.

We set up the company accounts, check the retention settings that exist at the chosen supplier, and add those accounts to your leavers’ procedure alongside the mailbox and the keys. It is short work and there is nothing spectacular about it.

We refuse to audit what has already gone out. Not on principle but because it is impossible: there is no trace on the company side, and the only record sits in personal accounts we have neither the right nor the wish to open. Anybody selling you that audit is selling a reconstruction, not a measurement.

We refuse to install monitoring on workstations to detect this use. It is technically possible and produces two certain results: the practice moves to personal phones, and you lose the trust that was your only source of information. Surveillance cannot replace a rule people have understood.

And we refuse to take on a task whose result nobody at your end could verify. If you ask us to automate a piece of writing your team can no longer review, we will propose training somebody first, even when that delays the project and reduces what we invoice — because this tool’s failure mode is being wrong with confidence, and a confident error nobody can detect is no longer an error, it is a decision.

Frequently asked questions

Should we ban AI for our employees?

No. A ban does not remove the practice — it moves it onto personal phones and ends the conversations that were informing you. It also selects backwards: the most cautious obey and the rest carry on. Permit it, name the tools, write down what does not leave, and provide a company account.

How do we find out what has already gone out?

You cannot, and that is the heart of it: nothing is missing, so nothing is noticed, and to the network pasting text looks like writing a message. The only method is to ask people, having first said the question is not an accusation. Anybody selling a retrospective audit is selling a reconstruction.

Is a paid account really safer?

It stops you pasting nothing. It changes three other things: the history belongs to the business and does not leave with the person, access is withdrawn on departure like any other, and retention settings become checkable by you. That is what makes the rule enforceable.

What about our own clients’ files?

They do not leave, in any version and on any account, including a business one. That content is not yours — it was entrusted to you. What can leave is your question written without the file, which is almost always enough, since the difficulty is usually one of method. Any exception is decided with the client, in writing.

What proportion of employees use these tools without saying so?

We cite no figure. All of them come from self-reporting on an unauthorised practice, so the under-reporting depends on the employer’s presumed severity — and it is largest where the problem is largest. The measurement is most wrong for the reader who most needs it.

Where do we start if we have done nothing at all?

With one question put to three people who write a lot: what are you using an assistant for at the moment. The answer gives you the real list of uses, which is shorter and more reasonable than feared. The page of rules is then written in a morning from that list.

Where we come in

Three people who write will tell you, if you ask without threatening, what they already put through these tools. The answer is always broader than expected.

  • We draft your rules in the languages you work in, from your own cases.
  • We open the company accounts and check the retention settings.
  • We add a line to the employment contract rather than a memo.

We will install no endpoint monitoring to detect this: it is possible, it destroys trust, and it moves the problem out of sight.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy