Almost every leadership team I talk with wants an AI assistant, but few agree on what it should do. Some want a chatbot for customers, while others want help drafting documents. Before you build or buy anything, decide what problem you are solving and what data the tool will touch.
Start with the job, not the tool
An assistant is only useful if it saves real time on real work. So begin by listing the tasks your staff repeat most. For example, drafting proposals, summarizing meetings, answering policy questions, or searching old files.
Next, rank those tasks by volume and risk. A tool that drafts internal emails is low risk. However, a tool that answers customers or touches financial data needs much more care.
This step also prevents a common mistake. Leaders often buy a tool first and then hunt for a use case, which rarely ends well.
The case for buying an AI assistant
For most organizations with 20 to 200 employees, buying is the right first move. Commercial tools are ready now, they are maintained by the vendor, and they come with security controls you do not have to build.
Microsoft 365 users may already have one
If you use Microsoft 365, check what you already own. According to Microsoft’s Copilot Chat documentation, Copilot Chat is available at no extra cost to users who sign in with a work account on a qualifying Microsoft 365 subscription. It includes enterprise data protection when users sign in that way.
The paid Microsoft 365 Copilot license goes further. It adds grounding in your organization’s work data, along with more advanced agents. That means the free tier is a good pilot, and the paid tier is a decision to make with data.
The downsides of buying
Off-the-shelf tools are general by design. They may not know your processes, your terminology, or your line-of-business systems. Also, you depend on the vendor’s roadmap and pricing.
Still, those limits matter less than they seem at first. Most staff need help with writing, summarizing, and searching, and general tools handle those tasks well. So test the commercial option before you assume it falls short.
The case for building
Building makes sense when the task is specific, high volume, and tied to your own systems. For example, an assistant that answers questions from your internal knowledge base, or one that drafts quotes from your pricing rules.
Today, “building” rarely means writing a model from scratch. Instead, it usually means connecting an existing model to your data through a platform, with guardrails you control.
However, custom tools need owners. Someone has to test answers, update the data, watch costs, and fix it when a vendor changes an API. In my experience, that ongoing care is what organizations underestimate most.
Also, budget for usage. Many AI platforms charge by volume, so costs can climb quietly as adoption grows. Set spending alerts from the start.
Data access decides more than features
The biggest risk with any AI assistant is what it can see. An assistant grounded in your files will surface whatever permissions allow. If a salary spreadsheet sits in a folder shared with everyone, the assistant can find it.
So clean up permissions before you connect a tool to company data. Review shared links, overshared SharePoint sites, and old Teams. Then apply sensitivity labels to the files that matter most.
Also, watch for shadow AI. When the approved tool is missing or clumsy, staff paste company data into free personal tools instead.
A decision checklist before you commit
Work through these questions with your leadership team:
- What specific task will the assistant handle, and how often does it happen?
- What data will it read, and who can see that data today?
- Does a tool you already license cover most of the need?
- Who will own the tool, test its answers, and handle updates?
- What happens if the tool gives a wrong answer to a customer or employee?
- How will you measure time saved after 90 days?
- Does your acceptable use policy cover AI tools and data entry?
Rolling out an AI assistant to staff
Even the right tool fails if nobody uses it well. So plan the rollout as carefully as the purchase.
First, start with a pilot group of five to ten people who do the target task every day. Give them a few weeks, and ask them to track what worked and what did not.
Next, write short, task-based guidance. For example, “how to summarize a client meeting” is more useful than a general AI training session. People learn faster when the examples match their own work.
Then set clear rules about checking output. An assistant can produce confident, polished answers that are simply wrong. Staff should review anything that goes to a customer, a regulator, or a financial record.
Finally, share results openly. If the pilot saved time, show the team how. If it did not, say so, and adjust before a wider rollout.
Use a framework to manage the risk
You do not need to invent your own AI governance. The NIST AI Risk Management Framework organizes the work into four functions: Govern, Map, Measure, and Manage. NIST also published a Generative AI Profile in July 2024 that addresses risks specific to tools like these.
For a smaller organization, the practical version is simple. Write a short policy, assign an owner, test before you roll out, and review results on a schedule.
How WEBIT approaches this
We usually recommend starting with tools you already license, then building only where a clear gap remains. Our AI and automation services begin with a permissions review, because data exposure is the risk that catches people off guard.
For clients worried about unapproved tools, our Shadow AI protection add-on helps identify and control where company data goes. We also take no vendor commissions, so our advice is not tied to any AI product. For more background, browse our whitepapers.
Key takeaways
- Define the job first, then choose the AI assistant.
- Buying is usually the right first step, especially inside Microsoft 365.
- Build only for specific, high-volume tasks with a named owner.
- Fix file permissions before connecting any tool to company data.
- Use the NIST AI RMF as a lightweight governance guide.
Related from WEBIT: vCIO and strategic IT services and IT Budget Planner for 2027.
Want a practical read on where AI fits in your business? Talk to an owner.





