What your employees actually use — and how to govern it safely
30–50% of your employees use AI tools without your knowledge. Most Swiss SMEs have already paid for the governance tools. They're just not activated.
Book a free consultationYou're paying for governance tools — that were never turned on
Defender for Cloud Apps, Purview DLP, Sensitivity Labels, Conditional Access — all already in your M365 license. But activated? Rarely. Configured? Almost never. The result: your employees send customer data to ChatGPT while you assume everything is secure.
"We had no idea that 14 different AI tools were connected to our Microsoft accounts."IT Manager, Fiduciary firm, Eastern Switzerland
What we do for you
Shadow AI Audit
We examine your Entra ID app registrations, analyze Defender logs, and conduct an employee survey. You receive a complete inventory of all AI tools in use — including unauthorized ones.
Copilot Governance Setup
Clean up SharePoint permissions, configure Sensitivity Labels, create DLP rules, enable audit logging. Copilot then runs FADP-compliantly — without oversharing risk.
AI Policy & Training
A practical AI usage policy with a traffic light system (green/yellow/red) plus employee training. Your staff will know what's permitted — and use AI more productively.
Swiss-hosted AI for critical data
For sensitive processes (fiduciary, healthcare, legal) we evaluate and implement Swiss-hosted AI solutions. Data never leaves Switzerland. 100% FADP-compliant.
Microsoft for productivity. Swiss-hosted for sovereignty. Governance for both.
We don't force you to switch away from Microsoft. Most Swiss SMEs have M365 — and that's fine. We help you run it securely and add Swiss-hosted solutions where it truly matters.
Microsoft Stack (use what you have)
- Entra ID — App registration audit
- Defender for Cloud Apps — Shadow AI monitoring
- Microsoft Purview — DLP & Sensitivity Labels
- Conditional Access — Access control
- Copilot — FADP-compliant configuration
Swiss-hosted (for critical data)
- Infomaniak-hosted AI models
- n8n on Swiss servers
- Data never leaves Switzerland
- Full control & transparency
- FADP-compliant from day one
4 weeks: from 'no idea' to 'under control'
Inventory
Entra ID app audit + employee survey. Result: complete picture of all AI tools in use and data flows.
Policy
Create and communicate AI usage policy with traffic light system. Clear, understandable, no blanket bans.
Technical controls
Configure Defender, DLP rules, Conditional Access. The guardrails that prevent mistakes — even without perfect employees.
Approved alternatives
Set up Copilot FADP-compliantly, evaluate Swiss-hosted solution for critical data, train the team.
Frequently asked questions
Do we need to switch away from Microsoft?
What does a shadow AI audit cost?
How long until everything is under control?
Do I need a DPIA for Microsoft Copilot?
Ready to know what your employees actually use?
15-minute consultation, free of charge. Find out how shadow AI is uncovered in your organisation — and what the first step costs.
Book a free consultation