About this story: This is a fictional composite based on common SME situations. It is not a named client engagement.
“We only use ChatGPT occasionally.”
That was the first answer from the managing partner of a 16-person accountancy firm in Cork. The firm was not building AI. It had no data scientists. As far as management knew, a few employees used ChatGPT to improve the wording of emails.
A short tool review told a different story. Microsoft Copilot features were available in the company’s software. The CRM scored leads. An AI meeting assistant produced notes. The marketing team used an image generator. One employee had pasted part of a client email into a personal, free AI account to draft a reply.
None of this was malicious. The tools had arrived quietly, one useful feature at a time. The problem was that nobody had the complete picture.
Why that created risk
The firm could not explain which AI systems it used, what information went into them, who approved them or how long providers kept the data. That made ordinary questions difficult:
- Could staff enter a client’s financial information?
- Were meeting attendees told that an AI assistant was recording them?
- Could the firm delete personal information from a provider if somebody asked?
- Who checked an AI-generated answer before it reached a client?
The Irish Data Protection Commission advises organisations to understand what personal data an AI product uses, where it goes, whether a provider retains or reuses it and how people can exercise their rights. The EU AI Act also requires providers and deployers to take measures to ensure suitable AI literacy among staff.
The practical fix
The firm did not ban AI. It created a one-page inventory with six columns: tool, purpose, owner, people affected, data entered and provider. Every department spent 20 minutes checking subscriptions, browser logins, connected apps and software features.
Next came three simple rules:
- Do not put client or employee information into an unapproved AI account.
- A named person must check important AI output before it is used.
- New AI tools must be added to the inventory before business use.
The firm moved approved work to business accounts with clearer controls, removed an unused meeting bot and gave staff short training using examples from their own jobs.
What could have happened if they ignored it?
The most likely problem was not an overnight regulatory fine. It was a client-data incident, an inaccurate answer sent under the firm’s name, or an inability to respond properly when a client asked where their information had gone. Each could cause lost trust, urgent investigation and expensive rework.
Compliance reduced that operational risk. Management could finally answer a basic question: “Where are we using AI, and who is responsible for it?”
Plain-English takeaway
You cannot manage AI you have not found.
Start with an inventory. Include AI features inside software you already pay for—not just standalone tools such as ChatGPT.
Your first three actions
- Ask every team which AI tools and built-in AI features they use.
- Record whether personal, client or confidential information enters each system.
- Choose an owner and an allowed-use rule for every tool.
Official guidance: EU AI Act, Article 4 ↗ · Irish DPC guidance on AI and data protection ↗