Your Employees Are Already Using AI. Here’s How to Find Out What They’re Doing With It.

The question isn’t whether people at your firm are using AI tools. They are. The question is what they’re doing with them, and whether the data they’re feeding into those tools is data you’d be comfortable explaining to a client.

Research puts the number at around 38% of employees sharing sensitive data with AI tools that haven’t been approved by their employer. For a law firm, that number hits differently. Client matter details, privileged communications, financial information — the kind of data that Florida Bar Rule 4-1.6 requires you to protect — are exactly the kind of content people reach for when they want help drafting something faster.

The answer isn’t to ban AI. That ship has sailed, and the firms trying to hold the line with an outright prohibition are mostly just ensuring their people use it without telling anyone. The answer is a shadow AI audit: understand what’s actually in use, then build a policy around reality instead of a policy that ignores it.

Step 1: Discover What’s Actually Being Used

Start by finding what’s running in your environment. This means DNS query analysis, browser extension inventories, and a review of OAuth-connected apps against your M365 tenant.

Consumer AI tools that employees use at their desks will often show up in DNS logs — ChatGPT, Claude.ai, Gemini, Perplexity, and a long tail of AI-powered writing and productivity tools. Your M365 admin center shows you third-party applications with active OAuth connections, including which users authorized them and what permissions they were granted.

The picture that emerges is usually more extensive than management expects. People have been practical about productivity even when policy lagged.

Step 2: Map AI Use to Actual Workflows

Knowing which tools are in use is only half the picture. You need to know what work they’re being applied to.

A direct conversation with department leads is often the most efficient path here. Not a compliance interrogation — a practical conversation about how people are using AI day-to-day and what problems they’re trying to solve. In most environments, you’ll find a handful of high-use patterns: drafting client communications, summarizing documents, generating first drafts of routine correspondence, and research.

For law firms, the workflows that warrant the most scrutiny are anything involving client matter details, opposing party information, or internal financial data. An associate pasting a client’s settlement offer into ChatGPT to help draft a response has just fed privileged information into a third-party system with unclear data retention practices. That’s a Rule 4-1.6 issue, not a hypothetical one.

Step 3: Classify Data Risk Against Actual AI Tool Practices

Not all AI tools handle data the same way. Microsoft Copilot for M365, for example, operates within your M365 tenant boundary under your existing data governance agreements. It doesn’t train on your data by default and the data stays within your Microsoft agreement. Consumer ChatGPT — unless your firm has subscribed to ChatGPT Enterprise or Team with the appropriate data settings — may retain conversation data for model training.

For each AI tool your audit surfaces, the relevant questions are: where does the data go, how long is it retained, is it used for training, and what’s the contractual basis for data handling? Answers vary significantly and change as these services evolve. The due diligence that made sense in 2023 may not reflect current terms.

Step 4: Triage by Risk Level

After mapping what’s in use and how data is handled, you can triage. Most tools in use will fall into one of three categories:

Sanctioned: Approved for use with appropriate data. Microsoft Copilot for M365, Copilot for Word, and properly configured enterprise AI agreements typically land here.

Conditional: Permitted for use with non-confidential data only. Consumer ChatGPT, Gemini, and similar tools used for generic drafting assistance — things that don’t involve client-specific information — may be acceptable with explicit guidelines.

Blocked: Not appropriate regardless of use case. Tools with no enterprise data agreement, tools with unclear retention practices, tools that have been fed confidential data without appropriate protections.

Step 5: Build Policy That Reflects Reality

A policy that says “no AI tools except what IT approves” and nothing else will fail. People will work around it. A policy that acknowledges existing use, gives clear guidance on what’s approved and under what conditions, and provides an approved alternative for legitimate AI productivity needs is one people can actually follow.

For M365 environments, Microsoft Copilot provides a governed path to AI productivity that keeps data within your existing agreement. For firms that aren’t ready for Copilot licensing, setting clear guidelines around what data can and cannot be put into consumer AI tools — with examples specific to your practice — is a practical interim step.

The goal is a policy that your team will actually use, backed by technical controls that enforce the lines that matter most.

If you want help running the discovery phase — DNS analysis, M365 OAuth audit, or a structured conversation about AI use across your team — that’s something we can support as part of our managed services engagement.