Your team is already using ChatGPT. Here is how to make that safe
Banning it drives it underground and you lose all visibility. What should never be pasted anywhere, and the one-page fix that actually works.
Your team is already using ChatGPT. Here’s how to make that safe.
Somewhere in your business, right now, someone is probably using ChatGPT. Not because you rolled it out. Not because anyone approved it. Because it’s useful, it’s free to start, and nobody told them not to. They’re drafting an email, summarising a document, tidying up a report — and at some point, without much thought, they’ve pasted in something with a client’s name on it, or a date of birth, or a set of figures from an invoice.
This is shadow AI: staff quietly using consumer AI tools on personal accounts because the tools help and there’s no approved alternative. It’s not malicious. It’s not even reckless, in the way people usually mean that word. It’s just what happens when a genuinely useful tool is one tab away and nobody has said anything either way.
Banning it doesn’t work
The instinct, when a business owner first realises this is happening, is to send a firm email: no AI tools, full stop. It feels responsible. It isn’t, for one simple reason — it doesn’t stop the behaviour, it just stops you knowing about it. People who were pasting things into ChatGPT at work will keep pasting things into ChatGPT, just from their phone, on their own data, where you have no visibility and no way to ask what went in. A ban you can’t enforce doesn’t reduce risk. It moves the risk somewhere you can’t see it, and it teaches your team this is a subject they shouldn’t raise with you.
The businesses that manage this well don’t ban the behaviour. They redirect it.
Why the free tier is the specific risk
Not all AI use carries the same risk, and this is the distinction most workplace conversations skip entirely. How a provider handles what you type — whether it’s stored, whether it’s used to improve their models, what happens on a free personal account versus a paid or business one — differs by provider and by tier, and it changes over time as terms get updated. Staff on their own personal, free accounts are very unlikely to have read any of that, and there’s no reason they should have — it’s not a document anyone hands you when you sign up out of curiosity on a Tuesday afternoon.
This is the actual problem, and it’s narrower and more solvable than “AI is dangerous”. The risk isn’t the technology. It’s personal accounts, on free tiers, with nobody having looked at the terms, being used for anything that involves someone else’s information.
What should never be pasted anywhere
Regardless of which tool, which tier, or how good the terms look, a short list of things shouldn’t go into any AI tool that isn’t specifically set up and approved for that purpose:
- Anything that identifies a client — full names alongside other details, contact information, account numbers.
- Health information, in any form, about anyone.
- Financial records: bank details, tax file numbers, income figures, invoices with identifying information attached.
- Anything covered by a confidentiality obligation — a contract, an enquiry made in confidence, a matter someone asked you to keep quiet.
- Passwords, login details, or anything else that gets someone into a system.
A useful shorthand for staff: if you wouldn’t paste it into a public forum, don’t paste it into a free AI account either. The tool feels private because it’s just you and a text box. It isn’t private in the way a conversation with a colleague is private.
The practical fix
Telling people what not to do, on its own, just recreates the ban that doesn’t work. The actual fix has three parts, and they need to happen together.
First, give people an approved tool to use — one on a business account, with terms you’ve actually looked at, so there’s no reason left to reach for a personal login. If the only option is a personal free account, that’s what people will use, because the alternative is not using AI at all, and for most tasks that’s not a trade-off busy staff are going to make on your behalf.
Second, write it down — one page, plain language, no legal jargon. What’s approved, what isn’t, and why. A policy nobody can find or understand isn’t a policy, it’s a document that existed once so a box could be ticked.
Third, and this is the part most businesses skip: say what people can do, not just what they can’t. “Don’t use AI for client work” is a rule people will quietly ignore because it’s unworkable. “Use the approved tool for drafting and summarising, keep identifying details out, check anything that goes back to a client” is a rule people can actually follow, because it still lets them do their job.
Having the conversation without making anyone feel caught out
If you’ve just realised this is already happening in your business, resist the urge to open with “I know what you’ve been doing”. Nobody set out to create a risk. They set out to get their work done faster, and they used the tool in front of them. Frame the conversation as giving people a better option, not catching them at something. Something like: “A few of us have probably been using ChatGPT for drafting — that’s fine, it’s genuinely useful, let’s just make sure we’re doing it on the right account and keeping client details out of it” does the job without anyone feeling like they’ve been called into the office.
That framing matters practically, too. If staff feel judged, they go quiet and go back underground. If they feel like you’ve noticed a real problem and fixed it sensibly, they’ll actually tell you when something doesn’t fit the policy — which is the whole point of having one.
Where the Privacy Act fits in
If your business handles personal information — and most businesses with clients, patients, students or members do — you remain responsible for that information even when a third-party tool is the one processing it. Handing something to an AI tool doesn’t hand off your obligations along with it. This isn’t a reason to avoid AI tools altogether; it’s a reason to be deliberate about which tools touch personal information and which don’t. If you’re not sure where your business sits on this, it’s worth a conversation with someone who knows your obligations specifically, rather than guessing.
A one-page acceptable-use note, an approved tool, and a conversation that doesn’t feel like a telling-off — that’s the whole fix. It costs an afternoon, and it turns an invisible risk into an ordinary, manageable part of how your business works.