← Back to IT & AI Insights
Security· October 4, 2026· 6 min read

Before You Turn On the AI Feature Your Vendor Just Added

A new AI button inside email, files, or practice software can see more than the demo shows. Here is a practical checklist Florida owners can use before they enable it.

Many Florida businesses are not starting a formal AI project. A vendor they already pay — for email, file storage, billing, an electronic health record, or practice-management software — is adding an AI feature and asking someone to turn it on. That switch can let the tool read messages, files, calendars, or client and patient records. It may save time. It is also a security decision, and it should be treated like one.

What enabling the feature can allow

A demo usually shows a tidy summary. It rarely shows how far the feature can reach. Before you agree, get a plain answer: which mailboxes and folders it can open, whether it can see records limited to certain staff, whether it can send or change anything, and where notes and transcripts are kept after the session ends. A line such as “we do not train on your data” is not the whole picture. You still need to know who can view prompts and results, and how long those copies remain.

Questions worth asking before you click enable

  • Which systems can it read — email, files, chat, calendars, billing, the electronic health record, or practice-management software?
  • Can it see shared mailboxes, old matters, or records that only certain people should open?
  • Does it create new copies, such as meeting notes, transcripts, or drafts, and where are those stored?
  • Who at the vendor can access what staff type in, and how long is that information kept?
  • Can you limit it to a small pilot group instead of the whole office?
  • Can you turn it off later, and what happens to the notes it already saved?
  • Does your current contract cover this feature, or is the only description on a webpage no one has reviewed?
  • For a healthcare practice: is a business associate agreement in place for this use of patient information?
  • For a law firm: could a summary pull client material into a place staff outside that matter can see?

Start with work that is safe to share

A practical first step is a short pilot with a few people and a narrow set of folders or mailboxes that do not hold your most sensitive matters. Use it for ordinary internal work: turning a long office policy into a shorter checklist, sorting non-confidential follow-ups, or drafting an internal memo a person will review. Do not start by connecting the tool to every client file or patient chart just because the button is available.

Controls that matter more than the product name

  • Keep access tied to the job. If a person should not open a file, the AI feature should not open it for them.
  • Require the same sign-in protections you already trust, including multi-factor authentication, before anyone uses a connected AI feature.
  • Leave off connectors you are not ready to supervise. An unused connection is still a path to data.
  • Decide who may approve a new AI connection. It should not be whoever happens to click first.
  • Review what the tool saves. A transcript or chat history can hold more detail than the original email.
  • Tell staff what they may paste into any AI tool, including tools they open in a browser on their own.
  • Keep a simple list of which AI features are on, who approved them, and which systems they can reach.

Healthcare practices and law firms

Patient privacy duties and client confidentiality do not pause because a feature is convenient. If the tool can see those records, treat that as handling sensitive information, not as a side option in software you already own. Ask the vendor, in writing, how the information is used, who can access it, and whether your existing agreement covers this feature. If the answer is vague, leave it off until it is clear. This is an operational checkpoint, not a substitute for advice from your own counsel.

Where AI can still help

AI can be useful when the source material is appropriate for that tool and a person checks the result before it goes to a patient, client, insurer, or court. Staff can draft routine internal notes, pull action items from a meeting that was safe to record, or search policies the whole team is allowed to see. The goal is not to avoid AI. The goal is to know what it can see before it is connected to the business.

If you want a clear look at which AI features are already available in the systems you use — and which ones are reasonable to pilot — contact IT Network Solutions Group (ITNS) for a free consultation. We help Florida healthcare practices, law firms, and other small businesses adopt useful tools without exposing client or patient data.

Let's talk about what this means for your business

Whether you are exploring Copilot, writing an AI policy, or hardening security after reading our Threats Log — ITNS is here with practical, honest advice. No obligation, no pressure.