Guide

How to See and Control Gen AI Use Across Your Business

A practical NZ guide to finding Shadow AI and backing policy with endpoint visibility, sensitive-data controls, and harmful-prompt protection.

The AI risk leaders cannot see

Employees can open a browser-based Gen AI tool, use a personal account, or encounter an assistant embedded in software they already use. That adoption can happen faster than procurement, policy, or leadership reporting. The result is Shadow AI: business activity that exists without reliable visibility or control. The customer problem is not simply that people use AI. It is that leadership may be unable to see which tools are in use, stop sensitive information leaving in a prompt or upload, or detect a harmful prompt before it affects an AI-assisted workflow.

Why policy alone cannot stop a prompt

A clear policy is necessary, but it works through memory and judgement. It cannot see a new AI tool opened in a browser, inspect what someone is about to paste, or block an unsafe instruction at the moment it is entered. That gap matters because useful work happens quickly. The safe path needs to be clear, but the policy also needs technical controls where AI is actually used: on the work endpoint.

  • Policy says which tools and data are approved
  • Endpoint visibility shows which tools are actually used
  • Detect-or-block controls intervene when a prompt creates risk
  • Reporting gives the policy owner evidence to review

Control one: see Gen AI use and find Shadow AI

Acronis documents Gen AI usage visibility and Shadow AI discovery across protected endpoints. This provides a practical starting point: see which Gen AI tools are being used, understand usage patterns, and give the policy owner reporting to review. Visibility does not make every use safe, but it replaces assumption with evidence. It helps leaders find unapproved tools before they become a recurring data problem and identify where policy or technical controls need attention.

  • Discover Gen AI tools used on protected work endpoints
  • Report on usage trends and potential Shadow AI
  • Compare actual use with approved-tool policy

Control two: stop sensitive information leaving

The Office of the Privacy Commissioner warns organisations to consider privacy before entering personal or confidential information into Gen AI. Acronis documents endpoint controls that detect sensitive content in prompts and file uploads and can block it from being shared with public or unapproved AI tools. This is the difference between asking someone to remember a rule and applying a control when the risky action occurs. The policy still defines what matters; the endpoint control helps enforce it.

  • Define the sensitive business and personal information in scope
  • Choose detect, warn, or block policy appropriate to the risk
  • Apply the control consistently across relevant managed endpoints
  • Review detections so recurring behaviours can be addressed

Control three: detect and block harmful prompts

A harmful prompt can try to manipulate AI behaviour, bypass intended instructions, or introduce unsafe content into an AI-assisted workflow. Acronis documents endpoint protection that detects and blocks harmful prompts, including prompt-injection attempts. This control acts before the prompt creates downstream risk. Human review remains important for AI output, but protection begins earlier—at the point where the unsafe instruction is entered.

What a managed service changes

Buying a control is not the same as operating it. Coverage has to include the relevant work endpoints. Policy needs to match the business information and tools in scope. Detections and reports need an owner who can review them and act. Tier1 Managed GenAI Protection combines the Acronis endpoint capability with managed policy and reporting. The aim is to help a business keep control without needing to build its own AI security team.

Start with the blind spot, not the product

Before selecting controls, establish what leadership can currently see and enforce. Tier1’s six-question exposure assessment looks at tool visibility, approved-tool enforcement, sensitive-data controls, harmful-prompt controls, managed endpoint coverage, and named ownership. You see a preliminary exposure band and three practical priorities before any contact form appears. The result is self-reported, not an audit, and it stays in your browser unless you explicitly choose to share it with Tier1.

  • See the result before sharing contact details
  • Keep the draft and scoring in the browser session
  • Focus on the three highest-priority gaps
  • Share the result with Tier1 only with explicit consent

Frequently asked questions

Can endpoint visibility find every form of AI use?

No control should be treated as universal. Acronis documents visibility across protected endpoints and supported Gen AI use. Confirm the current product coverage, the devices in scope, and any work performed outside managed endpoints before relying on the reporting.

Why is an AI policy not enough?

Policy explains expected behaviour, but it cannot see tool use or intercept a risky prompt on its own. Endpoint controls help turn the rules into visibility and detect-or-block action during real use.

Can sensitive-data controls replace privacy assessment?

No. Technical controls can reduce the chance of information leaving through a prompt or upload, but organisations still need to assess purpose, necessity, provider terms, retention, disclosure, and their Privacy Act obligations.

Who should review the reporting?

A named business leader should own the policy and risk, with Tier1 helping manage the technical controls and reporting. Privacy, legal, HR, and operational owners should be involved when a use case touches their responsibilities.

Is the exposure assessment a formal audit?

No. It is a preliminary self-assessment based on six plain-language answers. It does not replace a security, privacy, compliance, or legal review.