Home · Business · IT, Data & Security · Cybersecurity

PARTLY

As of 13 August 2026, AI can only partly check the security of employee devices.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededpower-user

Who has to check ita colleague

What the alternative costsThe supplied tool data gives no price for a professional security assessment.

If this goes wrong: a missed misconfiguration or exposed account remains on an employee device while the report says the estate is secure.

What to actually do

  1. Hand it to a person

    The route this page recommends

    A person who owns the outcome does this end to end, worth it when the failure is dear.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, power-user skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the approved device-management, endpoint-protection and patch-management consoles, and export current device status without including passwords, private keys, personal files or unnecessary employee identifiers.
    2. Gather the organisation's approved security baseline, including supported operating systems, required endpoint protection, firewall requirements, disk-encryption requirements and account-security controls.
    3. Paste the sanitised exports and the approved baseline into a chatbot with the prompt above, keeping each report labelled by source and date.
    4. Ask the chatbot to separate confirmed findings from likely findings and unknowns, then save the resulting triage report with the source exports.
    5. Open the relevant vendor console and documentation for every flagged device or control, and compare each finding against the live status rather than relying on the AI report alone.
    6. Have an IT or security colleague confirm the evidence, decide which findings are genuine, approve remediation and record what was changed in the authorised management system.

    Prompt

    Act as a cautious cybersecurity analyst. I will provide sanitised exports or screenshots from approved company systems that show employee-device security status. Do not claim to have accessed any device, endpoint agent or live network. Do not ask for passwords, private keys, full employee names, personal files or other unnecessary personal data. Analyse only the information supplied.
    
    Produce:
    1. A table of devices or device groups with the evidence supplied, detected gaps and confidence level.
    2. Separate findings into confirmed, likely and unknown.
    3. Check for missing operating-system updates, unsupported systems, inactive endpoint protection, disabled firewalls, weak disk encryption status, stale device records, missing multi-factor authentication evidence and accounts or devices that appear unmanaged. Only report a condition when the supplied evidence supports it.
    4. For each finding, explain the security risk in plain English, the evidence behind it and the safest next investigation step.
    5. Give remediation actions that an IT administrator can carry out, but do not invent commands, settings, product names or policy requirements. If a product-specific check is needed, say which vendor documentation or console screen must be consulted.
    6. List limitations, missing evidence and any conclusion that cannot be made from this data.
    7. End with a short handover checklist for an IT or security colleague to verify before anyone changes a device.
    
    Treat the result as a triage report, not proof that the devices are secure. Keep employee identifiers to the minimum needed. Here is the approved evidence:
    [PASTE SANITISED DEVICE AND SECURITY REPORTS HERE]
    
    Company requirements or baseline, if available:
    [PASTE APPROVED SECURITY POLICY OR BASELINE HERE]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot access every employee device or tell whether an exported status is current unless you provide authorised evidence.
  • AI cannot prove that a device is secure when a report is incomplete, stale or misconfigured.
  • AI cannot safely choose remediation settings without knowing your operating systems, management tools, business requirements and change controls.
  • AI cannot take responsibility for missed vulnerabilities, service disruption or the handling of employee data.
  • AI cannot replace live checks in the endpoint and device-management consoles.

What caps this at PARTLY: private data access, verification cost and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification1
Liability1
Effort delta1
Total5 / 10

FAQ

Can ChatGPT check whether my employees' devices are secure?
Partly. It can analyse approved device and security reports, highlight missing controls and draft a triage checklist, but it cannot inspect the devices or prove that they are secure without reliable evidence and an IT check.
What information does AI need to check device security?
Give it sanitised exports showing device ownership or group, operating-system status, patch status, endpoint-protection status, firewall status, encryption status and management activity. Do not paste passwords, private keys, personal files or more employee information than the check needs.
Is it safe to upload employee device reports to AI?
Only use an organisation-approved service and sanitise the reports first. Check your company policy and the service's data-handling terms, because device inventories and user identifiers can be private company data.
Can AI fix security problems on employee devices?
It can suggest investigation and remediation steps, and help draft scripts for an IT professional to review. Do not let it make untested changes across devices, because an incorrect setting or script can disrupt work or weaken security.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.