IT Support, Security & Managed IT Services Blog - iCorps

Choosing an AI Model Is the Easy Part. Governing It Is What Matters

Written by Jeffery Lauria | 9/1/26, 2:00 PM

Every week, I sit down with a business owner or an IT director who wants to talk about artificial intelligence, and the conversation almost always starts the same way. Which one should we use, Copilot, ChatGPT, or Claude? It is a fair question, and it deserves a real answer. But in my experience, it is also the second most important question these organizations should be asking. The first, which almost nobody leads with, is what happens to our data once we turn this on and who is actually watching it.  

I want to address both because you genuinely need to understand the tools before you can govern them properly, and you need to govern them before you should use them for anything that touches client data, financial records, or intellectual property. Let me walk through what I tell clients on both fronts.  

Starting with the tools themselves, since that is usually the entry point.  

Copilot vs. ChatGPT vs. Claude for Business  

Microsoft Copilot

For most small and mid-sized businesses already running on Microsoft 365, Microsoft Copilot is the most natural starting point, and there is a good reason for that. Copilot is not a separate destination you have to navigate to use. It lives inside Outlook, Word, Excel, Teams, and PowerPoint, and it draws context directly from your existing environment, including your emails, documents, calendar, and organizational data in SharePoint. If someone asks it to summarize a thread, draft a proposal based on last quarter's numbers, or pull talking points from a set of meeting notes, it can do that because it already has permissioned access to where that information lives.

The tradeoff is that Copilot's reasoning and general-purpose capabilities, while genuinely useful, tend to be narrower in scope than what you get from a dedicated frontier model used directly. It is built to be an assistant embedded in a workflow, not necessarily the deepest thinking partner for open-ended, complex reasoning tasks.

ChatGPT

ChatGPT is OpenAI's product and is the most widely recognized name in this space, and for good reason. It is capable and fast, and the ecosystem around it, including plugins, custom instructions, and a large user base sharing techniques, means there is a lot of collective knowledge on how to get value from it. Businesses often gravitate toward it because their employees have likely already used the consumer version at home, so the learning curve is shorter.

Where I see some inconsistency is in the depth of output for complex, nuanced business writing or analysis. It will typically get you a competent answer quickly, but for longer-form work that requires holding a lot of context and nuance across an entire document, some clients find they need to do more follow-up prompting to get the thoroughness they were looking for the first time.

Claude

Claude, from Anthropic, is the one I tend to point to when a client's use case involves heavier reasoning, longer documents, or work that benefits from a model thinking through nuance rather than giving a fast, compressed answer. In my own use and in feedback from clients who have adopted it, Claude tends to produce more complete, more carefully reasoned output, particularly for policy writing, contract review support, technical documentation, or long-form analysis, where missing a caveat actually matters. It is more verbose by nature, which is a strength when the task calls for thoroughness, and occasionally requires a minor adjustment in prompting when you specifically want something short.  

How to Choose an AI Tool for Your Business 

So, which one is right for your business? Honestly, for most SMBs, the answer isn't one tool. Organizations already standardized on Microsoft 365 should absolutely turn on Copilot because the integration value is real and immediate, particularly for day-to-day productivity tasks. Many of the same organizations also benefit from having access to Claude or ChatGPT for deeper reasoning tasks, research, drafting, and analysis that go beyond what an embedded assistant is optimized for. This is not an either-or decision nearly as often as vendors would like you to believe.

What Is AI Governance and Why Does It Matter?

But here is where I want to shift the conversation, because this is the part that actually protects your business, and it is the part almost nobody asks about until something has already gone wrong.  

Before you roll out any of these tools organization-wide, you need a governance framework in place, and that framework needs to exist before you sign a contract, not after you discover a problem.

AI Security Risks Businesses Should Consider Before Adoption 

Start with data handling. Every AI vendor has different policies on whether your prompts and the documents you share are used to train their models, how long they retain that data, and where they process it. This is not boilerplate to skim past. If your employees are pasting client contracts, financial data, or personal information into a consumer-grade version of any of these tools, you may be creating exposure that your compliance obligations, whether those are client contractual requirements, industry regulations, or data privacy laws, do not permit. The business tier of these products typically includes contractual commitments around data use that the free or personal tier does not. That distinction alone should influence your purchasing decision as much as raw capability does.

AI Security Risks Businesses Should Consider Before Adoption

Look at access controls and identity. AI tools should sit behind the same identity and access management discipline as everything else in your environment. That means single sign-on, multi-factor authentication (ideally the phishing-resistant variety I have written about elsewhere), and role-based access so the finance team's AI usage and the marketing team's AI usage aren't operating under the same blanket permissions. If an employee's credentials are compromised, you want to know exactly what that account could reach inside your AI tools, the same way you would want to know what it could reach in your file server.  

Then there is the question almost nobody plans for: what these tools can see once they are connected to your other systems. A growing number of AI platforms now support connectors and plugins that link directly to your email, your CRM, and your document storage. That capability is powerful, but it also significantly expands your attack surface if it is not deliberately scoped. From a security standpoint, a connector that gives an AI assistant broad read access to a mailbox or shared drive is functionally similar to handing out a new set of credentials. It deserves the same scrutiny you would apply to any new integration touching sensitive systems, and it deserves a documented decision about what data that connector should and should not be able to access.

What Data Should Employees Never Put into AI Tools? 

Put a usage policy in writing before you roll anything out broadly. Employees need clear guidance on which categories of information are acceptable to enter into these tools and which are off-limits, such as client data, employee personal information, unreleased financial results, and legal matters. Without that guidance, you are relying on individual judgment across an entire organization, and judgment varies widely under deadline pressure. A short, clear policy, reinforced through actual training rather than a document nobody reads, closes most of this gap on its own.  

None of this is meant to slow your adoption of these tools. AI genuinely delivers the productivity gains marketing promises, and businesses that use it well are pulling ahead of those that do not. My point is narrower than that. The organizations that get the most value from AI and avoid becoming a cautionary case study are the ones that treat governance as the first step of adoption rather than an afterthought bolted on once legal or a client asks an uncomfortable question.

What Data Should Employees Never Put into AI Tools?

If you are evaluating Copilot, ChatGPT, or Claude for your organization right now, I suggest that you pause before you sign anything and ask three questions. What happens to our data under this vendor's business terms? Who inside our organization can access this tool, and what can it see once it is connected to our systems? And do our people actually know what they should and should not be putting into it? If you cannot answer all three with confidence, that is the conversation to have first. We have this conversation with clients regularly, because getting it right from the start is far less expensive than fixing it after the fact.

Choosing a model is the easy part. Building the governance around it is what protects your business, and it is where I encourage any organization serious about adopting AI to focus its first real effort.

AI can create real business value, but only when it’s introduced with the right strategy and guardrails. Talk with the iCorps team about creating a practical AI governance approach that protects your business, supports your people, and helps you get more value from the tools you choose.