Skip to main content

AI / KMO / EU AI Act / compliance / operations

Your business tools already use AI. Do you know which ones?

Ben Heijlen ·
NL / EN Lees in het Nederlands →

Last month, Microsoft quietly added a toggle to turn off AI features mid-meeting in Teams. Not because they wanted to. Because users were furious.

Copilot, Facilitator, and Recap had been listening to meetings, generating summaries, and even answering questions in chat, sometimes without participants realizing AI was in the room. The backlash was loud enough that Forbes called it “a major AI U-turn.”

The fix is welcome. But it highlights a bigger problem that I see in almost every SME I work with.

AI is already in your stack

Most business owners think of AI adoption as a deliberate choice. You evaluate a tool, you buy it, you roll it out. But that is not how it works anymore.

AI features are being activated inside tools your team already uses, often through a routine update. Microsoft 365 Copilot features showing up in Word, Excel, and Outlook. Google Workspace rolling out Gemini-powered suggestions in Docs and Gmail. CRM platforms adding AI-generated lead scores. Accounting software auto-categorizing invoices with machine learning.

None of these required you to sign a new contract. None of them asked for a separate decision. They just appeared.

The problem is not the AI. It is the gap.

I am not saying these features are bad. Many of them are genuinely useful. The problem is the gap between what your tools do and what your team knows about.

When I ask a management team which of their tools use AI, the typical answer covers maybe 20–30% of the actual list. The rest is invisible. No one chose to enable it, no one evaluated it, and no one documented what data it processes.

This matters for three reasons.

Data flows you did not approve

AI features often process the content you put into them. Meeting transcripts, email text, document contents, customer records. Some of that data may leave your environment, feed into training models, or be stored in regions you did not select. If you handle personal data, this creates GDPR exposure you may not even know about.

EU AI Act obligations as a deployer

Under the EU AI Act, companies that use AI systems in their operations can qualify as “deployers,” even if they did not build the AI themselves. Deployers have obligations around transparency, human oversight, and risk documentation. If you do not know which AI systems are active in your business, you cannot meet those obligations.

Shadow decisions without governance

When AI features operate without a policy, individual team members make their own choices. One person enables Copilot summaries. Another uses an AI writing assistant in the browser. A third lets their CRM auto-score leads without understanding the model. The result is a patchwork of AI decisions with no central visibility and no consistency.

A practical shadow AI audit

The good news is that this is fixable in an afternoon. Here is a straightforward process I walk clients through.

Step 1 — List your tools

Write down every software tool your team uses. Include the obvious ones (Office, email, CRM, accounting) and the less obvious ones (project management, communication, file sharing, design tools). A typical SME with 10–50 employees uses 15–30 tools.

Step 2 — Check for AI features

For each tool, check the settings or admin panel for AI-related toggles. Look for terms like “AI,” “Copilot,” “assistant,” “smart suggestions,” “auto-complete,” or “insights.” Google the tool name plus “AI features” to catch what the settings page does not make obvious.

Step 3 — Decide per tool

For each AI feature you find, make a simple keep-or-disable decision. Does it add value? Does the data flow make sense? Is your team aware it is active? If you cannot answer all three, disable it until you can.

Step 4 — Document it

Create a simple register: tool name, AI feature, status (enabled/disabled), data processed, date reviewed. This takes maybe two hours for a mid-sized SME and gives you a baseline you can reference for compliance, onboarding, and future evaluations.

Why this matters now

The Microsoft Teams backlash is not an isolated incident. It is a pattern. Vendors are embedding AI deeper into their products because the market rewards it. That trend will accelerate, not slow down.

For SMEs, the practical risk is not that AI will do something catastrophic. It is that you will be held accountable for AI decisions you did not know were being made. The EU AI Act is already in effect, and enforcement will tighten. GDPR authorities are increasingly looking at AI-driven data processing.

A simple inventory is the first step toward being in control rather than reacting to the next headline.

Start with what you have

Even without external help, the four steps above will put you ahead of most companies in your sector. The AI features are already there. The question is whether you know about them.

Virada’s AI impact assessment helps you map your AI exposure, evaluate compliance gaps, and build a practical governance baseline.

Further reading

Ready?

Ready to find out where AI fits in your business?

Book a free 30-minute discovery call. We'll discuss your operations, identify potential quick wins, and determine if an AI Value Scan makes sense for you. No obligation, no sales pitch.

Book your free discovery call →