
For Hong Kong businesses, the AI question is no longer whether employees will use generative AI. Many already use it to organise a first draft, summarise a report, prepare meeting notes, write code or explain a difficult concept in clearer language. The more important question is whether the company has given them a reliable and responsible way to do so.
That distinction matters in Hong Kong. ChatGPT remains outside OpenAI’s published list of supported countries and regions at the time of writing. Some users may turn to a VPN or overseas account, but a business cannot sensibly build a core workflow around an access route that may be inconsistent, unsupported or difficult for IT to manage.
A company that relies on informal workarounds may end up with the worst of both worlds: employees still use AI, but through personal accounts, unapproved browser extensions and disconnected tools that leave management with little visibility over data, security or quality.
The stronger approach is to start with the work that needs improving, select a platform the organisation can support, and put the appropriate controls around it. That may mean Microsoft 365 Copilot, Google Workspace with Gemini, GitHub Copilot for development teams, or a separately governed AI environment for higher-risk work.
A VPN is not automatically insecure. Many businesses use a managed corporate VPN to protect remote employees connecting to internal systems. The problem is different when a VPN is used to make an unsupported service appear to be accessed from another territory.
OpenAI states that accessing or offering access to ChatGPT or its API from an unsupported country may result in an account being blocked or suspended. Its support guidance also notes that VPN use can trigger a security block because the original IP address is masked. OpenAI’s supported-region guidance and blocked-access guidance make the business implication clear: a VPN may be an individual workaround, but it is not a dependable deployment model.
For a company, the better answer is to use a corporate account on an approved platform, connected through managed identity, compliant devices and documented data controls. Remote staff can still use a corporate VPN or zero-trust access solution to reach internal systems. Their web-based AI tools should be accessed through the same managed security, monitoring and data-protection environment as other approved cloud services.
MJPM’s guide to ChatGPT, Google And Gemini Availability In Hong Kong explains the access landscape in more detail. This article addresses the next decision: how businesses should move from informal AI use to a workflow that can be maintained.
“Which AI tool should we buy?” is often the wrong first question.
A sales team preparing client follow-ups, a finance team reviewing internal documents and a developer working on a legacy application do not need the same AI capability or the same level of control. The organisation should begin by identifying a defined, repeatable task and then choose the technology around it.
For knowledge-work teams, useful early tasks may include:
For developers, the task may be different: understanding unfamiliar code, generating test cases, documenting a routine change or investigating an error in a non-production environment.
The common principle is the same. Start with work that is useful, repeatable and low enough in risk that a person can check the result. Do not begin by giving an AI system unrestricted access to client files, mailboxes or production systems simply because it can connect to them.
A broader comparison of platforms, including tools that are accessible in Hong Kong, is available in MJPM’s article on AI Tools Available In Hong Kong. The business decision should be based on the company’s existing systems, data sensitivity and operating requirements rather than on the latest viral product launch.
For most organisations, the strongest option is not to introduce another standalone AI account. It is to use a governed tool within the productivity or development environment employees already use.
Microsoft 365 Copilot is usually the most natural route for a business already running its email, documents, meetings and collaboration through Microsoft 365. It works across applications such as Word, Excel, PowerPoint, Outlook and Teams, while operating within the organisation’s existing Microsoft identity and permissions model.
This does not mean it can solve poor data management. If employees already have access to files they should not be able to see, AI may make that oversharing easier to discover. Permission clean-up, information classification and data-loss-prevention policies should be reviewed before a broad rollout.
Microsoft states that its enterprise data protection framework applies to customer data in Microsoft 365 Copilot and Copilot Chat, and that the service respects existing identity, access, compliance and data-protection controls. Microsoft’s Copilot security guidance provides a useful starting point for IT and compliance teams.
Businesses using Gmail, Drive, Docs, Sheets and Meet should consider Google Workspace with Gemini as the more coherent option. The value is not simply the chat interface. It is the ability to bring AI assistance into the collaboration environment that employees already understand, with administrator controls around access, retention and data handling.
Google’s Hong Kong enterprise plans list Gemini assistance in Gmail, Docs and Meet, as well as endpoint management, DLP, security reporting and investigation tools. Higher-tier plans add further controls for organisations with stronger security and compliance requirements.
For a company using Google Workspace, this route is more practical than asking employees to switch between personal accounts, browser plugins and VPN connections. It gives IT a clearer view of who is using the service and which controls apply.
Coding teams should assess AI coding assistants separately from general workplace chat tools. GitHub Copilot Business and Enterprise provide organisation-level licence and policy management, which makes them more appropriate than an individual developer’s subscription where source code, retention and access rules need to be controlled.
GitHub states that it does not use Copilot Business or Enterprise data to train its models, while administrators can manage access and organisation policies. Its documentation also makes clear that retention can vary by access method, so technical and legal teams should review the relevant terms before enabling CLI, web and agent-based features.
Codex can also be useful for software work, but companies should assess the exact product, access method and data flow they intend to use. “AI coding tool” is not a sufficient security review. The relevant questions are which code is available as context, where prompts and outputs are processed, who may approve changes and how code is tested before release.
Financial institutions should be especially careful about treating AI as an ordinary productivity subscription.
The Securities and Futures Commission has observed that licensed corporations are using generative AI for client enquiries, information summaries, research, investment signals and software development. It supports responsible use, but its guidance is risk-based: the controls should match the materiality and risk of the use case.
For example, the SFC identifies investment recommendations, advice and investment research provided to clients as higher-risk uses. In those circumstances, a firm should not let an AI output go directly to a client without appropriate validation and human review. A convincing paragraph is not necessarily an accurate one.
The practical controls expected in a well-governed financial-services environment include:
This does not mean every financial firm requires the same technology stack. It means a personal AI account and a VPN are not an adequate answer when the work involves regulated activity, sensitive client information or material decisions.
A reliable AI setup does not require a special “AI network”. It requires the company’s existing network and identity design to be mature enough for cloud services.
In an office, that usually means a stable corporate internet connection, secure Wi-Fi and LAN, managed endpoints, strong identity controls and a secure web gateway or SASE service that can apply company policy to approved cloud tools. For remote staff, corporate VPN or zero-trust network access can protect connections to internal resources. The same users should sign in to AI tools through company-managed accounts with multi-factor authentication.
The purpose is not to hide the business’s location from a provider. It is to ensure that access is attributable, controlled and auditable.
A practical AI-readiness review should ask:
This is where technology decisions meet the physical workplace. MJPM Workplace Technology Integration considers network, AV, access and collaboration requirements alongside office design and fit-out planning.
For dedicated implementation and ongoing support, TechSpace is part of MJPM Design & Build and focuses on workplace IT, AV and video conferencing, security systems and cloud technology. A company introducing AI does not need technology for its own sake. It needs a workplace where systems, people and processes work together without creating avoidable operational friction.
The most credible AI programme begins with evidence, not an announcement.
In the first week, select one department and one low-risk workflow. Define the business problem, the approved tool, the information employees may use and the person accountable for checking the output.
In the second week, prepare the operating conditions. Confirm corporate accounts, access rights, device requirements and the review process. Give employees simple guidance on what they may not enter into the tool, including confidential client material, personal data and credentials.
In weeks three and four, test the workflow with a small user group. Measure more than time saved. Review whether the output is useful after editing, whether staff understand the rules, whether unexpected information has appeared in prompts, and whether the existing approval process remains workable.
At the end of the pilot, management should decide whether to stop, adjust or expand. A successful pilot may lead to a second use case. It does not automatically justify unrestricted adoption across every department.
ChatGPT, Codex and other AI tools can help Hong Kong businesses reduce routine work and improve the first stage of a task. But the organisations that gain the most will not be those that simply give staff the newest app.
They will be the ones that choose a supportable tool, match it to a real business workflow, protect the information that matters and keep people accountable for the final outcome.
For a company considering its next move, the best starting point is straightforward: identify one useful task, select an approved platform, test it in a controlled environment and make sure the office technology can support the way the team needs to work.
Choosing an AI platform is only the first step. To make it work in day-to-day operations, businesses also need reliable connectivity, secure access, managed devices and meeting technology that supports modern collaboration.
MJPM can help align these workplace requirements with your office design, fit-out or technology-upgrade plans.Talk To MJPM About Workplace Technology Integration Now.