Governing AI: How to ensure only approved tools access your corporate data
The conversation around AI has moved beyond theoretical roadmaps and straight into the daily workflows of your users. Whether they are using a smartphone in the field or a browser at a desk, the way employees interact with corporate data is changing.
For IT admins and Chief Information Security Officers (CISOs), this shifts the focus to a high-stakes question of: when a user interacts with an AI tool, how do you ensure they are only using approved, enterprise-vetted platforms that protect your corporate data?
Understanding the distinction between on-device AI and cloud-based AI, and the management guardrails available to secure them, is the fundamental pillar of 2026 risk management.
Mapping the data path
To evaluate risk, we can look at where the data processing takes place:
- Cloud-based AI: Data is transmitted to remote servers for processing. Whilst this provides the scale needed for complex agentic workflows (where AI proactively executes tasks across applications independently), it requires a robust trust model. Enterprise-grade AI tools mitigate this risk by ensuring prompts are strictly isolated by policy and excluded from training global models.
- On-device AI: Processing happens locally via hardware accelerators (NPUs) built directly into the device. This virtually eliminated the risk of data being intercepted in transit or stored on a third-party server. It’s a hardware-enforced wall providing a zero egress environment for sensitive information.
Security considerations across the ecosystem
We’ve previously explored user desire paths - the natural, unplanned routes users take to achieve their goals. AI is the ultimate desire path. If IT makes it too difficult to use securely, users will turn to unmanaged points of access. The key is to utilise the safeguards across the ecosystem to enforce these boundaries without hindering the user experience.
-
Android Enterprise:
Data risk across the fleet is mitigated by the setup of your deployment:
- Device Trust by Android Enterprise: For organisations moving toward Zero Trust, particularly with unmanaged or BYOD devices, the focus shifts to real-time verification. Device Trust by Android Enterprise allows you to verify the security posture of a device in real-time before allowing it to touch AI-powered corporate resources. It ensures that data only enters a trusted environment, even if you don’t manage the hardware itself.
- The Android Work Profile: Provides a containerised boundary that siloes work-related AI prompts from personal apps, preventing data bleed. Regardless of device ownership, your organisation retains the ability to enforce app allow-lists within the Work Profile, ensuring only vetted AI tools are accessed within this secure, managed container.
- Fully managed devices: This is the broadest scope for policy enforcement. Beyond enforcing app allowlists to eliminate shadow AI, every aspect of the device including cloud-based data transit, could be governed by your managed configurations.
-
Chrome Enterprise:
Because the browser is the primary workspace for modern AI agents, it’s also where the wait-and-see approach to security is most risky. By utilizing browser management solutions like Chrome Enterprise Core and Chrome Enterprise Premium, moving to a proactive defense allows you to bridge the gap between user innovation and corporate security:
- Shadow IT detection: Integrated reporting tools now allow you to identify exactly where users are interacting with unsanctioned AI sites. This visibility helps you identify security blind spots and offer sanctioned alternatives that include enterprise-grade data protections.
- Governance by Policy: You can manage AI behaviour directly through the console, ensuring that automated workflows, such as an AI agent inputting data across tabs, are governed by the same Data Loss Prevention (DLP) rules that protect the rest of your fleet.
This ensures you can safely empower your workforce with built-in tools like Gemini in Chrome, to gain instant AI-powered insights, explanations, and answers directly from your active tab.
-
ChromeOS:
ChromeOS integrates artificial intelligence directly into the operating system and hardware. This allows for a more responsive user experience while maintaining the platform's signature "secure-by-default" architecture:
- On-device AI & silicon: Chromebook Plus devices utilize advanced processors to handle tasks like Live Caption and Noise Cancellation locally. This minimizes cloud data transmission, significantly reducing the attack surface for sensitive audio and video.
- Managed productivity: Tools like "Help me write" are integrated directly into the UI. IT admins maintain granular control via the Google Admin Console, enabling or disabling generative features at the Organizational Unit (OU) level.
- Enterprise privacy: Native AI features follow a "Privacy First" model. For enterprise users, prompts and generated data are not used to train LLMs, ensuring corporate intellectual property remains confidential.
-
Cameyo by Google:
Legacy Windows applications often house an organization’s most sensitive data but lack modern AI privacy protections. Cameyo addresses this by virtualizing delivery:
- Clean room environment: Apps are delivered via a virtualized sandbox, ensuring sensitive data stays entirely within the cloud session under your direct control.
- Zero local footprint: As a rule, because data is never cached on the local device hardware, it remains invisible to unmanaged AI agents or Shadow IT tools scanning local storage.
- Browser-enforced security: By leveraging Chrome Enterprise controls, you can further harden this environment by restricting screenshot capture, ensuring that sensitive information viewed within the virtualized app cannot be easily exfiltrated.
- Simplified management: Organizations can deploy and manage legacy software more easily while maintaining a superior security posture against modern threats.
The enterprise safeguard
While hardware determines the path of your data, the Terms of Service determine who owns it. This is where the distinction between consumer and enterprise-grade AI becomes critical. For a CISO, the enterprise label represents a shift from a consumer environment to a governed one, including commitments to data residency and EU hosting that are essential for regulated industries.
| Feature | Consumer AI | Enterprise-grade AI |
| Model training | Prompts may be used to train future models | Strictly excluded from training global models |
| Data ownership | Governed by general consumer terms | Your organisation owns 100% of the data |
| Data transmission | Prompts travel to vendor cloud | Zero transmission options for on-device tasks |
| Admin controls | Often user-controlled | Centralised toggles by Group or Organisational Unit |
Maximum privacy
The most effective way to ensure data never leaks is to keep it off the network entirely. The latest on-device models, including the Gemma 4 family, allow you to access sophisticated AI entirely offline.
Why this is a breakthrough: By running these tasks locally, you get the benefit of advanced reasoning without the privacy risks of cloud transit. Whether you are using a compact edge model for mobile tasks or a more capable variant for workstation-level analysis, the data remains on the device.
Bridging innovation and integrity
Deploying AI safely is about understanding the path data takes. By centering your strategy on data sovereignty, choosing between on-device and cloud processing based on risk, and enforcing boundaries through modern device management, you move from locking down data, to building infrastructure that is resilient enough to handle whatever the next wave of innovation brings.
Next steps:
- Centralize your controls: If you haven't already, migrate your Android Enterprise deployment to a Managed Google Domain. This will help unify AI governance, allowing you to manage Gemini and other enterprise services from one dashboard
- Stay ahead of the curve: Join the Android Enterprise Insiders to help us continue to build secure foundations for enterprise AI.
How is your organisation approaching AI deployment? Are you prioritising on-device privacy, or focusing on Enterprise-tier cloud solutions?
For more information on the latest innovations in this space, explore Google’s latest update on securing the AI-powered enterprise.

