Fendr Blog
Insights, guides, and best practices for secure AI adoption in the enterprise.
Start here for IT leaders
The practical guides we send to CIOs, compliance leads and security teams first.
How to Stop Employees Pasting Client Data into ChatGPT
You already know staff paste client data into ChatGPT. Blocking the website just moves them to Claude, Gemini, or their phone. Here is what actually stops the paste.
ChatGPT DLP Without Microsoft Purview E5
Purview prompt protection is real, and it lives behind E5, Edge for Business, and enrolled Windows. Here is the gap, and what a growing UK firm can deploy instead.
Who Owns AI Tool Risk at a Sub-500-Person Firm?
A logistics firm with 450 staff has a CISO, a written AI policy, and nothing enforcing it. Across four conversations this summer, everyone agreed AI tool use was a risk and nobody owned it.
AI Audit Trails: What a ChatGPT Activity Log Should Contain
ChatGPT does not give IT an exportable activity log. Here is what an AI audit trail should contain for ISO 27001, the ICO and the board, and how to produce one without Purview E5.
Latest Articles
Who Owns AI Tool Risk at a Sub-500-Person Firm?
A logistics firm with 450 staff has a CISO, a written AI policy, and nothing enforcing it. Across four conversations this summer, everyone agreed AI tool use was a risk and nobody owned it.
AI Audit Trails: What a ChatGPT Activity Log Should Contain
ChatGPT does not give IT an exportable activity log. Here is what an AI audit trail should contain for ISO 27001, the ICO and the board, and how to produce one without Purview E5.
ChatGPT DLP Without Microsoft Purview E5
Purview prompt protection is real, and it lives behind E5, Edge for Business, and enrolled Windows. Here is the gap, and what a growing UK firm can deploy instead.
How to Stop Employees Pasting Client Data into ChatGPT
You already know staff paste client data into ChatGPT. Blocking the website just moves them to Claude, Gemini, or their phone. Here is what actually stops the paste.
Enterprise Browser vs Browser Extension: Securing AI in Small to Medium Sized Businesses
Enterprise browsers promise total control, but most small to medium sized businesses do not need that level of complexity. A browser extension inherits the browser staff already use and closes most shadow AI exposure for a fraction of the effort.
AI Prompt Logging: What IT Teams Need to Record
Prompt-level logging promises complete visibility, but for most IT decisions it captures far more than necessary. Here is what to record instead.
Your AI Policy Covers Five Tools. Your Employees Are Using Twenty.
Across companies monitored by Fendr, employees actively used more than 20 distinct AI tools in the past six months. Most of those policies specify only up to three tools.
Securing DeepSeek and Emerging AI Models: A Browser-Level Guide for IT Teams
DeepSeek and the next wave of low-cost AI models are already inside your organisation. Here is how to identify the data leak risks - and how browser-level controls shut them down.
Evidencing Your AI Policy: Answering the Due Diligence Question
Clients want to know which technical controls enforce your AI policy. Here is how to answer that due diligence question with evidence, not vague reassurance.
Microsoft 365 E7 and AI Security: A Factual Breakdown for IT Directors
Microsoft 365 E7 launches 1 May 2026 with AI security capabilities included. What those capabilities cover, where the scope boundaries are, and how they compare.
AI Security for UK Regulated Industries: What IT Directors Need to Know
FCA, ICO and SRA compliance obligations around AI are already active. Learn what regulators require, how tool categories compare, and how to evaluate AI security solutions.
Shadow AI and UK GDPR Breach: Pasting Client Data into ChatGPT - A Breach Waiting to Happen?
Shadow AI is everywhere, and pasting client data into ChatGPT may be a UK GDPR breach. A practical guide for compliance, IT and business owners.
Data Loss Prevention in 2026: A Practical Guide for IT Managers
Your perimeter has moved. This guide covers what DLP actually means in practice today, where the real vulnerabilities are, and how to build a policy that works.
Shadow AI: The Hidden Risk Lurking in Your Organisation
71% of employees use AI tools without IT approval. Here's why that's a problem - and what you can do about it.
How to Track the ROI of Your Microsoft Copilot Licenses
Not sure if your Copilot licences are delivering value? A practical guide for IT managers — adoption, productivity, and the hidden data risk most teams ignore.
AI Governance for SMEs: A Practical Guide for 2026
A practical AI governance guide for SMEs (10–500 employees). Sensible, proportionate framework you can stand up in 60 days — without enterprise overhead.
Building an AI Governance Framework That Works
A step-by-step guide to creating AI policies that protect your organisation without killing productivity.