Dr.Hani Tiếng Việt
Applied Knowledge Market Notes

How Should Businesses Govern AI on Work Devices?

4 min readAssoc. Prof. Nguyen Hai Ninh
Nhóm quản lý trao đổi về triển khai công nghệ trong doanh nghiệp

In release notes dated 1 September 2026, OpenAI states that ChatGPT for Intune is available to Enterprise accounts and requires organisational onboarding. This is a provider product update, not evidence that one implementation model will suit every business. It nevertheless signals an important management shift: as AI moves into everyday work, deployment is no longer only about granting accounts and offering usage guidance; it is increasingly connected to devices, access policy, and the responsibility of the information-technology function.

Many AI programmes begin with a pilot group, a few safety guidelines, and a tool for employees to explore. This can be an appropriate way to learn quickly. But when a tool is used for customer records, project material, sales processes, or internal reporting, operating questions emerge: which devices may access it, which accounts sit under which policies, where data travels, how incidents are recorded, and who may change configuration. These questions do not make AI less useful; they define the conditions under which benefits can scale without creating additional unmanaged risk.

From “enabling access” to designing a safe path

Enterprise management of mobile devices and computers is often treated as technical background work. With AI, this layer becomes part of the work experience. If employees must move through several sign-in methods, do not know which tools are approved, or are unclear about which material should not enter a prompt, they will either abandon the tool or find their own workaround. Both outcomes weaken the original objective of the programme.

A safe path need not be complicated. It needs clarity on four matters: which user groups may use it, which work situations are prioritised, which types of information have limits, and where users receive support when they encounter difficulty. These rules need to be expressed in the language of work rather than existing only in long IT policies.

Deployment layer Question to settle Operating signal to monitor
Users and devices Who has access from which device, and who approves exceptions? Denied access requests, non-compliant devices, and time to grant access.
Data and use situations Which information may be processed, and which work requires human review before external sending? Blocked prompts, data-use errors, and recurring situations.
Support and learning Where do users ask questions, and who updates guidance when a process changes? Support resolution time, repeated questions, and correct-path usage.
Evaluation and expansion Which criteria permit an additional user group or integration? Output quality, time to complete work, incidents, and cost.

Administrative authority must accompany work responsibility

A common mistake is to hand the entire AI programme to IT, or conversely to let each business unit choose and configure its own tools. IT needs responsibility for identity, devices, connections, and infrastructure controls. The business unit needs to define the use case, the standard of output, and the decisions for which people remain accountable. The programme owner connects the two: ensuring that technical rules do not become detached from work needs, while ensuring that convenience does not precede necessary control.

This division is particularly important when one tool is used across functions. A sales assistant may touch marketing content, price terms, customer data, and delivery-capacity information. No single unit understands all limits in full. The implementation group needs a short meeting rhythm to review real cases, decide adjustments, and record the agreed principles.

Example: expanding an AI assistant for a consulting team

After a trial, a service company wants its consulting team to use an AI assistant on company devices. The group does not enable everyone at once. It selects one consulting group and prioritises three jobs: summarising meeting notes, drafting proposal outlines, and retrieving internal knowledge. IT confirms the approach to device and account management; the business leader defines which data must not be entered into the tool; and one coordinator records recurring questions and errors. After four weeks, the group reviews preparation time, draft quality, support requests, and any incidents. Those results, rather than the number of accounts provisioned, determine whether to expand.

Three things managers should do now

First, make a short list of active use cases and connect each to its data type, device, and approver. Second, inspect the path that users actually experience: do they know which tool is permitted where, when to check again, and how to receive support? Third, agree a signal table to determine whether the programme is creating value or merely increasing visits. This table should combine work results, quality, support time, incidents, and cost.

OpenAI’s notes do not provide a complete template for enterprise AI governance, and the suitability of Intune also depends on each organisation’s existing device environment. Even so, this update is a reminder that AI is moving closer to working infrastructure. Businesses will need to design experience and control together: convenient enough for users to do the right work, and clear enough for the organisation to know who is accountable when a tool enters consequential decisions.

References

OpenAI. (2026, September 1). ChatGPT Enterprise & Edu release notes. https://help.openai.com/en/articles/10128477-chatgpt-enterprise-edu-release-notes

Continue reading

Related insights