visibus
←Back to the blog

visibus Blog

Why your company needs its own AI access

Fabian Schmid

by Fabian Schmid · September 27, 2026 · 8 min read

Whether AI is used in your company is no longer your decision. That decision was made long ago - in accounting, in sales, in administration, usually without anyone asking. The KPMG study 2025 shows for Switzerland: 77 percent of the workforce use AI in a professional context, well above the global average.

What you can still decide is the how: uncontrolled through private accounts - or controlled through an access that belongs to your company. This article sorts out the situation: which risks you carry if you decide nothing, which opportunity gets lost along the way, which options exist - and where we stand with visibus. We say that openly at the end.

The risks when nobody decides

According to the same KPMG study, more than half of Swiss AI users admit to using AI against company policy - for instance by uploading sensitive data to freely available tools. In Germany, Bitkom paints the same picture: four in ten companies assume their employees use private AI tools at work - while only around a quarter offer official access.

In concrete terms, that means three things:

Data leaves the company uncontrolled. Customer names, contracts, HR data and figures end up in private accounts - often on free-tier terms under which the inputs are used to improve the models. Without a contract with your company, without a log, stored in accounts you have no access to.

There is no place where you would notice. Fifty private browsers are fifty blind spots. You know neither which tools are in use nor what is being entered there.

You cannot prove anything. Data protection law requires you to show which precautions you have taken. The revised Swiss Data Protection Act provides for fines of up to CHF 250,000 for intentional violations - against the responsible person, not the company. Anyone who, in the event of an incident, can show neither what happened nor that there was a regulated path, is in a poor position.

That is shadow AI, and it is not an HR problem: the tools are good, immediately available and save real time. As long as the company offers no official path, employees fill the vacuum themselves. We have written this up in detail in Shadow AI.

The opportunity that gets lost in the noise about risk

The reason your employees use AI in secret is the same reason you should introduce it officially: it works. Letters and quotes get written faster, evaluations no longer take half a day, scanned receipts read themselves out, translations are no longer a bottleneck. For an SME facing a skills shortage, this is the rare lever that lets the existing team get more done - without a new hire.

Risk and opportunity therefore share the same root. Whoever manages only the risk and bans AI loses the opportunity - and keeps the risk anyway, as we will see in a moment. Whoever sees only the opportunity and lets everything run carries the risk blindly. The task of management is not to choose between the two, but to create a framework in which both go together.

Three questions every option can be measured against

Before we go through the options, it is worth setting the bar. From our point of view, there are three questions:

  1. Where is your data - and on what contractual basis? History, documents, user accounts: with the company or in private accounts? Business contract with data processing agreement or consumer terms? Are your inputs used for training?
  2. Who is in control - and who can prove it? Can you create and block users, see costs and budgets, and demonstrate in an audit that there was a controlled path?
  3. How dependent do you make yourself? Are you tied to one provider and its choice of models, or can you switch when a better model appears next month?

The options compared

Option 1: Ban it

The first reflex of many management teams - and the worst option. A ban does not eliminate usage, it relocates it: from the company computer to the private phone, from the company network to the mobile network. You lose the last chance to exert influence, and the opportunity along with it. All three questions above end up answered worse than before.

Option 2: Policy without technology

The most common option: AI is allowed, but a policy regulates what may be entered. That is better than nothing - but a policy is not a technical control. It shifts the responsibility onto the individual employee in a moment of stress, and it works exactly until someone under time pressure makes an exception. In the event of an incident, the policy documents one thing above all: that the company knew about the risk. Why that does not hold up is explained in detail in Allowed is not protected.

Option 3: Individual subscriptions per tool and team

The company buys official licenses: a chat subscription here, a writing tool there, plus the Office add-on. To be fair: the business versions of the major providers are usually fine contractually, including the commitment not to train on your data. But a subscription zoo emerges: several contracts, several per-user flat rates that run whether the AI is used or not, history and files spread across the accounts of several providers - and no central place where usage, costs and rules come together. What that looks like in everyday work is shown in Four AI tools for one job, and what it costs in What does AI really cost?

Option 4: The Microsoft default

Anyone already running on Microsoft 365 gets AI directly in Word, Excel and Outlook with Copilot - and when it comes to data handling, Microsoft is solidly positioned. If that is exactly what you need, Copilot is a legitimate choice. The limits lie elsewhere: the model pool is Microsoft's purchasing, not yours. You can override only within that pool, and depending on the app only to a limited extent. Licensing is per user, at prices someone else sets. And there is no layer that replaces personal data before it reaches the model - the protection is contractual and rule-based, not anonymization in front of the model. For Swiss and EU companies, the fine print on the EU Data Boundary comes on top. The detailed comparison is in Copilot is not the only answer.

Option 5: Build it yourself

The building blocks for your own, company-controlled AI platform exist - that is how we built visibus Chat ourselves. But it is not a one-off effort, it is continuous operation: updates, security, model integrations, monitoring, ownership. For an SME with one or two people responsible for IT, that is rarely the best use of the scarcest resource in the company.

The resolution: a company-owned, managed access

What remains is the category that answers all three questions: an AI platform that belongs to the company and is operated for it. That is exactly what visibus Chat is.

Question 1 - data and contract: Your instance runs in data centers in Germany, the EU or Switzerland. History, documents and user accounts stay there - with you, not in private accounts. Contractually, you work with a data processing agreement, and the models are connected through business interfaces whose inputs are not used for training by default. To be honest about it: the large cloud models compute at the respective provider, and visibus does not change that. But only the individual request goes out - and on request, an anonymization layer kicks in beforehand that detects and replaces names, addresses and account numbers before the request leaves your instance. A technical protective layer instead of a rule of conduct - as an additional level on top of the controlled access, not a miracle cure. Anyone who wants to keep processing in Europe chooses a European model such as Mistral.

Question 2 - control and proof: Users are created and blocked centrally, e.g. when someone leaves. You see usage and costs at a glance and set a hard monthly budget - the most expensive bill is the one you set in advance. Instead of a policy you hope will be followed, you have a place where the rules apply technically.

Question 3 - dependency: The leading models from Anthropic, OpenAI, Google and Mistral sit side by side in one interface. On request, the system automatically picks the appropriate model for each task - and you can override it at any time. When a better model appears, it is simply there, without a new account and without migration. Billing is usage-based instead of a flat rate per user.

And because very few SMEs are looking for another IT project: visibus operates, updates and monitors the instance. You get a finished tool, not a project.

The point

The question is not whether your company uses AI - it already does. The question is whether there is a place for it that you can take responsibility for. Deciding nothing is also a decision, just the most expensive one: you give up control and keep the responsibility.

If you want to know what a company-owned AI access looks like for your business - write to us. We will look at it together.

Your free AI check

In the AI check, we look together at where controlled AI delivers the most value in your company: which tasks and departments benefit right away, which models fit, and what level of data protection you need. You walk away with a clear assessment - no strings attached.

Free and non-binding. An open conversation, no sales pressure.