TAPP Co., Ltd. (Headquarters: Minato-ku, Tokyo; President and CEO: Manabu Yaji; hereinafter 'TAPP'), which primarily focuses on investment real estate sales, has fully deployed Google Cloud's enterprise AI 'Gemini Enterprise' across the company, achieving 100% employee adoption in just three weeks (※1). This success was made possible by four security design principles that do not rely on employee vigilance, but instead create a company-wide system ensuring that even accidental input of sensitive information will not result in data leakage. This press release discloses the details of these four implemented security measures.
※1 From the July 15, 2026 announcement: 'TAPP Achieves Full Employee AI Adoption in 3 Weeks, Spawning Approximately 500 AI Agents from the Frontlines'
Background: The Barrier to AI Adoption Was Not Functionality, But 'Fear'
Many people already know that generative AI is convenient. Yet, many organizations hesitate to adopt it due to the fear that 'important information might be unintentionally entered and leaked outside.'
According to a May 2026 survey by Teikoku Databank, only 34.5% of companies are currently using generative AI (※2). Despite recognizing its benefits, the majority of businesses have yet to take the leap toward full-scale adoption.
Our employees shared the same concerns. Particularly in the real estate industry, where TAPP operates, personal customer information is routinely handled, requiring high levels of awareness and caution. Therefore, rather than leaving the decision of 'what can be safely entered' to individual employees, it became a critical challenge for the company to establish an environment where AI could be used with confidence.
To change this situation, we realized that relying on employee caution was insufficient—instead, the company itself needed to build protective systems. With this in mind, TAPP began preparing its security infrastructure ahead of the full company rollout of 'Gemini Enterprise' on June 15, 2026.
※2 Source: Teikoku Databank (May 2026) https://www.tdb.co.jp/report/economic/20260514-genai/
Implemented Security Measures
Our solution was simple: instead of merely asking employees to 'be careful,' we decided to proactively build a system that ensures safety even if information is accidentally entered.
This design was led by the AI Strategy Unit under the Office of the President, which established information security and access controls prior to the full deployment. This philosophy is realized through the following four systems:
① A System That Constantly Monitors Inputs and Outputs (Model Armor)
Instructions given to AI (inputs) and AI-generated responses (outputs) are continuously monitored by a separate, independent layer outside the AI itself. This is particularly effective against the primary concern—accidental input of personal information.
・If employees accidentally input personal or sensitive data, the system automatically detects and redacts it.
・Malicious prompts designed to trick the AI into performing harmful actions are automatically blocked.
・'Invisible malicious instructions' hidden within documents or URLs are also included in the inspection scope.
② A System That Precisely Controls 'Who Can See What' (Access Control)
We clearly define the scope of information accessible based on each employee’s role. Furthermore, the data the AI can reference is strictly limited to what each employee is authorized to view. This prevents incidents where 'asking AI reveals information the employee should not have access to.'
③ A Wall That Blocks the 'Pathways' for Data to Leave the Company (Data Boundary)
We have established perimeter defenses that prevent company data from being exfiltrated, even if credentials are compromised. Specifically, we use Google Cloud’s 'VPC Service Controls' to restrict data egress pathways.
④ A System That Logs 'Who Used What and When' for Later Review (Logging and Oversight)
We log which employee used which AI function and when. These logs not only allow us to trace incidents if they occur but also serve as a deterrent—knowing that usage is recorded helps prevent inappropriate use before it happens.
These four layers are designed to provide overlapping protection: if one layer is breached, others remain intact. This 'defense in depth' approach is a fundamental principle in cybersecurity.
Results: Fear Disappeared, Adoption Reached 100%
By implementing these four security measures, the primary barrier—'fear of inputting confidential information'—was completely eliminated. Even if sensitive data is accidentally entered, our security systems detect and conceal it, so employees no longer need to hesitate before each input. With this solid foundation in place, we revised our previously strict AI usage guidelines to be more user-friendly. As a result, employees who had been观望 (observing cautiously) began using AI in daily operations, achieving 100% adoption across the entire company.
Crucially, this was not achieved through top-down mandates, but as a natural outcome of removing employee anxiety. Employees began using AI voluntarily. Robust protection is the prerequisite for confident usage—this is the insight we gained through practice. Investment in security is not merely a cost to reduce risk, but also an investment to expand adoption.
Future Outlook
TAPP will continue refining this design and redirect the time saved toward deeper engagement with each client’s asset formation journey. We will also continue strengthening information security, access management, and AI usage training for employees.
The dilemma of 'wanting to use AI but fearing data input' is common across many enterprises. TAPP hopes that the design principles we have developed through practice can serve as a reference for companies aiming to advance AI adoption across their organizations.
From Kondo Yuki, Head of Business Strategy Office and AI Strategy Unit
'The real reason AI adoption stalls isn’t the AI itself. It’s the fear that employees might leak customer personal information through their inputs—that fear has been holding frontline teams back. That’s why we insisted on designing 'protection' before pushing for adoption. Instead of asking employees to 'be careful,' we built a system that ensures safety even without constant vigilance. Once the foundation is solid, AI spreads naturally across the organization. Of course, systems aren’t foolproof. We will continue monitoring security closely and, without becoming complacent, remain committed to ongoing AI training for every employee.'
About TAPP Co., Ltd.
The name 'TAPP' is an abbreviation of 'Turn A Profit Partner,' reflecting the company’s mission to be a partner that generates profit for its customers.
FACT BOX
- Source: PR TIMES
- Category: News
- Organizations: Google Cloud
- Products / services: Gemini Enterprise