Team using ChatGPT without any rules?
Sprawl is not a motivation problem, it is a liability risk — here is what helps now.
Answer · Self-built AI solutions
The short answer: an Operator Review. An independent check of your self-built AI solutions covering data protection, maintainability and risk — with an honest verdict on what can stay and what has to go. And that uneasy feeling? It is a good sign: something is running that nobody fully oversees any more.
Because it means something has grown in your business. Your people built instead of waiting — that is the fastest route to improvement, and plenty of companies sleep through exactly this moment.
The problem is not that something was built. The problem is that nobody holds the whole map any more: which tools are running, which data they see, who maintains them — and what happens when one of them produces nonsense. That is precisely the feeling nagging at you. Listen to it.
Not the AI itself — but what has grown up around it unchecked: customer data in other people's systems, processes that hang on one person, results that go out unchecked in the company's name. Each one an annoyance. Together, a liability case.
Three levels, one written result:
At the end you get an honest verdict in plain English: what can stay, what needs safeguarding — and what has to go. Even if someone built it with real dedication. The review is the way into the Operator — the ongoing support with accountability for the judgement. But it also stands on its own: having it checked does not mean having to book.
“What holds up, stays. What endangers the business has to go — no matter who built it.”
Checklist
Five signs from real projects. One on its own is a hint — two or more are an appointment.
The apprentice built it, the contractor is gone, the colleague is on holiday — and nobody else knows how it works. If a process hangs on a single head, your business hangs with it.
Customer names, costings, perhaps health data — which tools do they end up in, on whose servers, under whose terms? If the answer is a shrug, the review is due.
Passwords in people's heads, accounts on private email addresses, no overview of what runs where. That is not a state of affairs — that is a bet on the next staff change.
AI texts, answers or figures leave the building in the company's name without a human approving them. One wrong statement is enough — and you answer for it.
A new tool every week, a new automation — but no rule about who is responsible for what. Sprawl scales too. That is exactly where the uneasy feeling comes from.
Recognised two or more of these? Then let's talk for 30 minutes — free of charge
Frequent questions
Three levels: data protection (which data flows into which systems — and is that allowed?), maintainability (does it keep running once the person who built it leaves? documentation, access, dependencies) and risk (what happens when the AI gets it wrong, and who checks before anything goes out?). The result comes in writing.
Usually not. Most self-built work is well thought out and only needs guardrails: rules, documentation, properly managed access. Only what seriously endangers data protection or operations has to go — and I will tell you that plainly rather than talk around it.
First a free 30-minute initial assessment, then the check of the solutions running in day-to-day operations: data flows, access, documentation, responsibilities. After that you have it in writing — what stays, what has to go, what comes first. Where it goes from there is your decision.
Review · Data protection, maintainability, risk · Result in writing