AI on Corporate Devices: Where is Your Data?
AI is now part of the corporate device in Australia as employees increase access to AI through productivity platforms, operating systems, smartphones and applications.
The company-wide roll-outs of Microsoft 365 Copilot and Google Workspace AI are only part of a much broader shift towards AI being embedded into the everyday technology that employees use.
For businesses in Australia, that creates a new question.
When an employee uses AI on a corporate device, do you know where the data actually goes?
The answer is not always straightforward.
Some AI processing can happen directly on a device while other capabilities rely on cloud infrastructure. Some combine the two depending on the task, application and information involved.
That distinction matters for security, privacy, compliance and corporate device management.
On-Device and Cloud AI Are Not the Same
On-device AI processes information locally using the computing capability of the device itself. This can reduce the need for certain information to leave the endpoint and can improve responsiveness.
Meanwhile, cloud AI sends information to remote infrastructure where more computationally intensive models and services can process it.
Neither approach is inherently secure or insecure.
What matters is understanding what information is being processed, where that processing occurs, what data is transmitted, how long it is retained and which controls apply throughout the process.
The challenge for IT teams is that employees rarely think in those terms. They see a feature but IT needs to see the data flow behind it.
This becomes particularly important on corporate smartphones, which is fast becoming the enterprise endpoint.
Mobile devices can contain emails, messages, documents, customer information, authentication credentials, photos, meeting information and access to business applications.
AI adds another layer of interaction with that information which is why organisations must change how they think about mobility.
In critical industries underpinned by data, this is notably important. AI features may interact with commercially sensitive, confidential or personal information, making device governance part of the wider data governance conversation.
“Businesses must treat the smartphone as another enterprise endpoint that requires the same lifecycle management rigour as a PC. As AI becomes more deeply integrated across devices and applications, that becomes even more important. Organisations need visibility across the device lifecycle – from deployment and security through to ongoing management and eventual retirement – rather than treating mobility as a standalone telecommunications service.”
AI Policies Must Reach the Device
In response, many organisations are developing enterprise AI policies.
But those policies cannot stop at approved models and applications. They should also address the devices through which employees access AI.
IT and procurement leaders must understand which AI capabilities are enabled across the corporate fleet, whether those features can access enterprise information and what controls are available through device management platforms.
That requires better questions of technology vendors:
Which AI functions operate on-device and which require cloud processing?
What information is transmitted when cloud AI services are used?
Is enterprise data retained or used beyond the immediate request?
Which applications and information can AI capabilities access?
Can individual AI features be restricted or disabled centrally?
What auditing and administrative visibility is available?
What happens to enterprise information when a device is replaced, lost or retired?
The answers should influence device selection, configuration and lifecycle policy – not be discovered after deployment.
This issue will become more significant as AI, devices and networks converge.
Otherwise known as a shift towards ‘connected intelligence’ – where connectivity, AI and security increasingly operate together rather than as separate technology decisions.
Therefore, AI on corporate devices should not become another isolated technology discussion. It sits at the intersection of endpoint security, identity, data governance, connectivity, procurement and employee experience.
“The convergence of networks, security and AI is changing the role of enterprise mobility. Businesses want better connected experiences regardless of device or location, but that also creates new security and management requirements. The opportunity is to bring mobility into the wider technology strategy – combining connectivity, device management, security and AI around the business outcome rather than managing each component separately.”
Know Your AI Exposure
The objective is not to disable every new AI capability. Instead, to understand the environment before deciding what should be enabled.
At OneStep Group, that means looking across the entire enterprise mobility lifecycle – from device procurement and zero-touch deployment through security, connectivity, fleet management, support and retirement – while drawing on wider capabilities across cyber security, networking, data and AI.
For IT leaders, the immediate priority is visibility.
What AI capabilities are already operating across your corporate fleet, what enterprise information can they interact with and do your existing policies account for them?
Because as AI becomes another standard capability of the corporate device, managing the device increasingly means managing its AI exposure too.
Book an OSG Enterprise Mobility Strategy Session to review your existing environment and start planning your enhanced fleet strategy.
Contact us here