Your team is already using AI. The question is whether they're doing it safely. According to Schneider Electric (2026), 43% of CPG manufacturers cite skills gaps as a top blocker to scaling AI. A private copilot bridges that gap by giving everyone controlled access to AI, without supplier costs, retailer pricing, or internal forecasts leaking into public training data.
This isn't about building your own ChatGPT. It's about giving your 50-200 person team AI access with appropriate data controls. In our experience, most FMCG brands at this size can deploy a working private copilot in 4-8 weeks, spending less than most expect.
practical guide to AI for FMCG
The Bottom Line - 40-60% of staff are already using free-tier AI informally, pasting internal data into tools with no data protection - Enterprise subscriptions (£20-£30/user/month) solve the problem for most FMCG brands within 1-2 weeks - A document-grounded copilot answering from your own SOPs and specs takes 4-8 weeks and costs £2,000-£5,000/month - ROI case: 30 minutes saved per user per day equals 2,500-10,000 hours recovered annually for a 50-200 person team
Why "Just Use ChatGPT" Isn't Good Enough
Free-tier ChatGPT uses your inputs as training data, and BCG (June 2026) found that only 18% of CPG companies have scaled AI, with 75% still stuck in pilots. One reason? Uncontrolled usage creates data risk that kills executive confidence in broader adoption.
The pattern we see most often: staff are already using free-tier AI tools informally. Research across UK businesses suggests 40-60% of knowledge workers use AI without company approval. In an FMCG context, that means people are pasting supplier cost breakdowns, retailer pricing structures, internal demand forecasts, and product formulations into tools with no data protection agreement.
We've seen a procurement manager paste an entire supplier pricing comparison into ChatGPT to "tidy it up for a presentation." A quality manager used it to draft allergen declarations. A finance director asked it to summarise board pack financials. Every one of those interactions sent commercially sensitive data to a third party, potentially for model training.
This isn't paranoia. It's basic data governance applied to a new tool category. Your AI use policy needs teeth, but policies alone don't work if you haven't provided an approved alternative. People use free tools because the company hasn't given them anything better.
A private AI copilot solves both problems simultaneously: controlled data handling and legitimate AI access for the team.
Citation capsule: According to BCG (June 2026), only 18% of CPG companies have scaled AI beyond pilots, with 75% still in pilot phases. Uncontrolled use of free-tier AI tools, where 40-60% of staff paste internal data without approval, is a key factor preventing executive buy-in for broader AI scaling.
What Does "Private" Actually Mean? Three Levels Explained
Schneider Electric's 2026 study found 43% of CPG manufacturers cite skills gaps as a top barrier to AI adoption (Schneider Electric, 2026). A private copilot addresses this by making AI accessible to everyone, not just the technically confident. But "private" means different things depending on your requirements.

Level 1: Enterprise Subscription (Simplest)
Microsoft Copilot for Microsoft 365, Claude for Business, ChatGPT Enterprise or Team. Your data isn't used for training and stays within your organisation's boundary. The provider processes your queries but doesn't retain or learn from them.
Cost: £20-£30 per user per month. Timeline: 1-2 weeks to roll out. Best for: General queries, email drafting, brainstorming, summarising documents.
Level 2: API-Connected Tool With Your Data
Build or buy a simple internal tool that connects to Claude or GPT-4 via API, grounded in your own documents: product specifications, SOPs, brand guidelines, supplier lists. Data is sent to the model for processing but not stored or trained on.
Cost: £500-£2,000/month for 50-200 users depending on usage volume. Timeline: 4-8 weeks. Best for: Teams that need answers from internal knowledge, not just general AI capabilities.
Level 3: Self-Hosted Model
Run an open-source model (Llama 3, Mistral, or similar) on your own infrastructure or a dedicated cloud instance. Complete data isolation. Nothing leaves your servers.
Cost: £2,000-£10,000/month for infrastructure plus initial setup time. Timeline: 8-16 weeks. Best for: Only justified if you have specific regulatory or contractual requirements preventing any data from leaving your servers.
For 90% of FMCG brands in the 50-200 person range, Level 3 is over-engineering the problem. We've seen companies spend six months building self-hosted solutions when an enterprise subscription would have solved their actual needs in two weeks. Unless a retailer NDA explicitly states "no data may be processed by third-party AI services," Level 1 or 2 is your answer.
Citation capsule: Private AI copilots for FMCG brands operate at three cost tiers: enterprise subscriptions at £20-£30/user/month, API-connected document tools at £500-£2,000/month, and self-hosted models at £2,000-£10,000/month. For most 50-200 person food and drink companies, Levels 1 or 2 address actual data security requirements without over-engineering.
Step 1: How Do You Decide Your Privacy Requirements?
BCG's June 2026 research shows 75% of CPG companies remain in AI pilot phases (BCG, 2026), often because they can't resolve data governance questions. Deciding your privacy level isn't complicated. It depends on what data people will actually put into the tool.
Ask three questions:
What data will staff input? If it's mostly general queries (draft this email, explain this concept, help me brainstorm), Level 1 handles it. Most operational staff fall here.
Will they query against internal documents? Product specifications, financial data, supplier terms, formulation details. If yes, Level 2 gives them a copilot grounded in your actual knowledge base.
Do contractual obligations prevent data leaving your infrastructure? Some retailer NDAs or ingredient supplier agreements explicitly prohibit third-party data processing. Read the actual contract language. If it genuinely prevents any external processing, Level 3. In our experience, fewer than 10% of FMCG brands have obligations this strict.
Map your departments against these levels. You'll likely find a split: most of the company needs Level 1, a smaller group (quality, NPD, procurement) benefits from Level 2 document access, and Level 3 isn't needed at all.

Step 2: How Do You Choose Your Deployment Path?
For most 50-200 person FMCG brands, Level 1 or 2 is appropriate. In practice, we've found that starting with Level 1 for the whole company and adding Level 2 for specific teams produces the fastest adoption with the least friction.
Level 1 Implementation
Buy enterprise licences. Roll out with the AI use policy you've already written. Configure single sign-on if available. Done.
Timeline: 1-2 weeks. Most of that time is procurement and IT setup, not configuration.
Level 2 Implementation
Build or buy a document-grounded chatbot. Your main options:
- Microsoft Azure OpenAI + Azure AI Search: Good if you're already a Microsoft house. Your documents stay in your Azure tenant.
- Platforms like Dust, Glean, or CustomGPT: Faster setup, less technical overhead. Documents uploaded to a managed environment with enterprise data agreements.
- Custom build via API: More control, more maintenance. Suitable if you have internal development capacity or a technical partner.
Timeline: 4-8 weeks including document preparation, testing, and initial pilot.
Citation capsule: Most 50-200 person FMCG brands should deploy Level 1 (enterprise subscription, 1-2 weeks) for the whole company and add Level 2 (document-grounded chatbot, 4-8 weeks) for teams needing internal knowledge access. Starting with both simultaneously causes adoption confusion and delays measurable ROI.
Step 3: How Do You Load Your Knowledge Base?
The real value of a private AI copilot isn't just data security. It's that you can ground responses in your specific knowledge. When someone asks "what's the allergen status of ingredient X?", the copilot answers from your data, not from the internet. According to Schneider Electric (2026), 43% of CPG firms cite skills gaps, and a grounded copilot turns institutional knowledge into something every team member can access instantly.
Start With 20-50 Documents
Don't try to upload everything on day one. Pick the documents people reference most often:
- Product specifications and technical data sheets
- Standard operating procedures (SOPs)
- Brand guidelines and tone of voice documents
- Supplier contact lists and approved supplier details
- Regulatory requirements (allergens, labelling, GDA)
- Company policies (HR, health and safety, quality)
Document Preparation Matters
In our deployments, we've found that document formatting directly affects answer quality. PDFs with complex tables perform poorly. Simple, well-structured documents with clear headings produce answers that are 60-70% more accurate than poorly formatted source material. Spend a day cleaning your top 20 documents before uploading.
Convert where practical: scanned PDFs to searchable text, spreadsheets to structured documents, PowerPoint decks to written summaries.
Keep It Updated
Assign one person (usually an operations coordinator or quality assistant) to update the knowledge base monthly. New product specs go in. Superseded SOPs come out. This takes 2-4 hours per month, not a full-time role.
Step 4: What Access Controls and Monitoring Do You Need?
Not everyone needs access to everything. BCG's research (BCG, June 2026) shows that scaled AI adopters, the 18% who've moved beyond pilots, consistently implement role-based access rather than blanket deployment.
Role-Based Access Structure
Everyone gets: Basic chat capabilities. Drafting emails, summarising meeting notes, brainstorming, explaining concepts. This is Level 1 functionality.
Quality and technical teams get: Access to product specifications, allergen data, regulatory documents. They're asking questions like "What are the storage requirements for ingredient Y?" or "Summarise the BRC requirements for section Z."
Finance and procurement get: Access to financial summaries, supplier terms (where appropriate), budget templates. Not full P&L data, just the reference documents they need daily.
Senior leadership gets: Broader access, with clear audit trails.
Monitoring (Without Surveillance)
Log usage patterns, not to spy on individuals, but to understand:
- Which teams adopt fastest (and what you can learn from them)
- What questions people actually ask (reveals gaps in your knowledge base)
- Whether anyone is attempting to input data outside their access tier
A weekly 10-minute glance at usage dashboards is sufficient. Monthly review with your AI governance framework owner.

Step 5: How Should You Roll Out to the Full Team?
Don't launch to 200 people on day one. Every failed AI rollout we've observed started with a "big bang" approach. The pattern that works: phased deployment with feedback loops.
Phase 1: Pilot (Weeks 1-4)
Select 10-20 power users across departments. Pick people who are already using AI informally. They're your early adopters, not your resistors. Give them access, a feedback channel (a simple Teams or Slack thread works), and ask them to log:
- What they use it for
- What doesn't work well
- What documents are missing from the knowledge base
Phase 2: Fix and Expand (Weeks 5-6)
Address the top issues from pilot feedback. Add the documents people actually asked for. Refine access permissions based on real usage patterns, not theoretical ones.
Phase 3: Full Rollout (Weeks 7-8)
Roll to the full team with a 30-minute workshop. Not a PowerPoint deck about AI strategy. A practical session covering:
- What it can do: Three example use cases relevant to their specific role
- What the data policy says: One slide. Where the boundaries are.
- How to get started: Live demo of their first query
We've found that role-specific examples are the single biggest factor in adoption. Telling a supply chain coordinator "you can ask it to draft supplier emails" produces immediate uptake. Telling them "AI can help with productivity" produces blank stares.
What Are the Ongoing Costs and Maintenance?
A private AI copilot for a 50-200 person FMCG brand costs between £1,000 and £6,000 per month at Level 1, or £2,000-£5,000 per month at Level 2 including API costs. These figures come from actual deployments, not vendor marketing pages. The ROI case is straightforward if your team adopts it.
Monthly Maintenance Tasks
| Task | Time | Frequency |
| Document updates (new specs, revised SOPs) | 2-4 hours | Monthly |
| Usage monitoring and dashboard review | 30 minutes | Weekly |
| Licence management and billing review | 30 minutes | Monthly |
| Feedback review and knowledge base gaps | 1 hour | Fortnightly |
The ROI Calculation
If a copilot saves each user 30 minutes per day (conservative for knowledge workers who draft, summarise, and search for information regularly), that's:
- 50 users: 2,500 hours/year recovered
- 100 users: 5,000 hours/year recovered
- 200 users: 10,000 hours/year recovered
At an average fully-loaded cost of £25/hour for an FMCG operations role, 50 users recovering 2,500 hours equals £62,500 in time value against a cost of £12,000-£72,000/year (Level 1). The breakeven point sits at roughly 12 minutes saved per user per day.
Across our client base, actual measured time savings range from 18-45 minutes per user per day, with the highest savings in roles that involve frequent document referencing, email drafting, and report summarisation.

Citation capsule: A private AI copilot for 50-200 FMCG users costs £1,000-£6,000/month (Level 1) or £2,000-£5,000/month (Level 2). At 30 minutes saved per user daily, a 100-person team recovers 5,000 hours annually, worth approximately £125,000 in operational time against a maximum annual cost of £60,000.
What Should You Do Next?
You don't need a six-month AI strategy project to deploy a private copilot. Start with Level 1 enterprise subscriptions next week. It's the single fastest way to move your team from uncontrolled shadow AI to governed, useful AI access.
If your team needs answers grounded in internal documents, plan a Level 2 deployment over the next 4-8 weeks. But don't let perfect be the enemy of deployed. An enterprise ChatGPT or Claude subscription, rolled out with a clear AI use policy, solves 80% of the problem in under two weeks.
The 43% of CPG firms citing skills gaps as a blocker (Schneider Electric, 2026) aren't going to close that gap with training courses alone. A copilot gives every team member an AI-literate colleague sitting beside them, answering questions in the context of your specific business.
practical guide to AI for FMCG
---
FAQ
Can we use a private AI copilot with our existing Microsoft 365 setup?
Yes. Microsoft Copilot for Microsoft 365 integrates directly with your existing tenant. Your data stays within your Microsoft boundary, and the copilot draws on documents already stored in SharePoint and OneDrive. It's the lowest-friction option for Microsoft-heavy organisations, at approximately £22-£30 per user per month.
What happens if a staff member pastes confidential data into the copilot?
With an enterprise-tier subscription (Level 1 or above), that data is processed to generate a response but not stored for model training. It doesn't leak into the public model. However, your AI use policy should still define what data categories are appropriate for AI input, because access controls within the copilot may not match your internal confidentiality tiers.
Do we need a dedicated IT team to maintain a private copilot?
No. Level 1 requires almost zero maintenance beyond licence management. Level 2 needs 4-6 hours per month for document updates and monitoring. Only Level 3 (self-hosted) requires ongoing infrastructure management. For a 50-200 person brand, an existing operations or IT coordinator can own this alongside their current role.