Internal copilots and support bots
Where it breaks: prompt injection, policy drift, and accidental data exposure when the bot touches real inboxes and docs.
- Use a governed action boundary: allow, deny, quarantine, reroute.
- Keep a smaller delivery surface so the team actually adopts it.
- Attach decision records so audit questions have receipts.