The short version

Find out how staff use ChatGPT and other AI tools before setting the policy. Client records, contracts, source code and financial information may be entered to solve ordinary work problems. The exposure depends on the data, service, account, retention and contractual terms. Do not assume every tool or subscription handles information in the same way.

Some data or uses should be prohibited, and a managed block can be appropriate. Pair restrictions with a practical approved route where the business has a valid use case. Explain what is allowed, configure the relevant controls and make it easy to ask for help or report a mistake.

  • The risk is staff pasting sensitive data into public models, not the existence of AI.
  • A ban needs communication and enforceable controls; consider how unmanaged devices or unapproved accounts could bypass it.
  • Policy, a sanctioned tool, and a handful of technical controls together are what reduce the risk.

What staff are actually pasting in

To control the risk you have to be honest about what it looks like day to day. It is rarely malicious. It is a busy person trying to save time, and not thinking about where the text ends up. The common cases are worth naming plainly.

  • Client and customer data. Pasting a list of contacts to draft a mail merge, or a support ticket full of personal details to get a tidier reply. That may be an unauthorised disclosure or incompatible use of personal data; check the actual permissions, processing arrangement and UK GDPR obligations.
  • Contracts and commercial documents. Dropping in a supplier agreement or a tender response to summarise it or check the wording. Confidential and often covered by a non-disclosure agreement.
  • Source code. Developers pasting proprietary code to debug it or write tests. Your intellectual property, handed to a third party.
  • Financial and board material. Management accounts, forecasts, or a sensitive email, pasted in to rewrite or analyse.
  • Internal documents. Strategy notes, HR cases, and anything marked confidential, used to draft a quick summary.

There are two separate risks: unsuitable handling of the input and unsafe reliance on the output. Consumer-service training and retention settings vary, as do business contracts. If sensitive information has been entered into an unapproved service, record what happened, contain the exposure where possible and assess the incident rather than assuming deletion or a no-training setting resolves it.

Why a ban on its own fails

The instinct to block the lot is understandable, and on a managed work device you can do it. The problem is what happens next. The tools save people real time, so a hard block without an alternative does not remove the demand, it just moves it somewhere you cannot see.

Consider routes outside your managed environment, including personal devices, browser extensions and personal accounts. Those limits make staff guidance and reporting important alongside technical blocking. Decide which uses are prohibited and which can operate under an approved, monitored process.

What actually works

Reducing this risk is a layered job. No single control does it. The combination below is what we put in place for clients, in roughly the order that gives the fastest return.

1. An acceptable use policy people will actually read

Start with a short policy that says what staff may and may not put into AI tools. Not a ten page document nobody opens, but a one page rule: never paste client data, personal data, contracts, code, credentials, or anything marked confidential into a public AI tool, and here is the sanctioned tool to use instead. Name the approved tools, name the banned behaviours, and say who to ask when someone is unsure. A policy people understand changes behaviour. One they never see does not. This sits inside your wider policy frameworks, alongside your acceptable use and data handling rules.

2. Give them a sanctioned tool with data controls

Choose an approved product for the intended data and use case. ChatGPT Business and Enterprise offer no model training on business data by default; Microsoft’s commercial Copilot products provide their own protections. A paid consumer subscription is a different proposition, and eligible Copilot Chat work accounts can have enterprise data protection without an additional Copilot licence. Review retention, access, subprocessors, agents and location requirements as well as training. Sources: OpenAI enterprise privacy (opens in new tab) and Microsoft enterprise data protection (opens in new tab).

3. Turn on Microsoft 365 data loss prevention and sensitivity labels

Microsoft Purview can classify information and audit, warn or block supported data-sharing actions. Endpoint/browser coverage depends on the licence, enrolled device, browser and policy configuration. For example, Microsoft’s browser paste-control guidance (opens in new tab) describes how to restrict sensitive paste actions in supported scenarios. Test the actual apps and accounts staff use; this is not universal inspection of everything they type.

4. Add browser and network controls

On managed devices you can go further. Browser management can restrict risky extensions and apply policies in the browser itself, which is where most of this activity happens. Network and web filtering can block the consumer AI sites you have not sanctioned while allowing the approved one, and a secure web gateway can inspect and limit what leaves the network. These controls are blunt on their own, which is exactly why they pair with a sanctioned alternative rather than replacing it. They sit naturally alongside your email and endpoint security.

5. Train people, briefly and concretely

Most leaks are honest mistakes, so a little awareness goes a long way. Keep it short and specific. Show the examples above, explain why an unauthorised client-list disclosure can be a data incident, and point everyone at the sanctioned tool. People follow a rule far more readily when they understand the reason behind it, and when the safe option is easier than the risky one.

The governed alternative

The controls above reduce exposure. For a purpose-built assistant, agree the data sources, access, logging, human approval points and shutdown controls before development. UK-hosted deployment options can be explored where required, but the full processing chain, including models, telemetry and support, must meet the location requirement too.

Done this way, you do not have to choose between productivity and control. Staff get a capable assistant for the work they are paid to do, and you get a record of what the assistant did and what it was allowed to do. If you want to use AI, make the data handling and residual risks an explicit part of the decision. See how we approach AI adoption, governance included as standard.

FAQ

Common questions

Should we just ban ChatGPT at work?

A restriction may be appropriate for a specific service, data type or use. Pair it with clear staff guidance, enforceable controls and a suitable approved alternative where there is a valid business use. Review unmanaged-device and personal-account routes rather than assuming a block covers everything.

Is it a data breach if an employee pastes client data into ChatGPT?

It can be a personal data breach if the use involves an unauthorised disclosure, but it is not automatically reportable simply because AI was involved. Record the data, recipients, terms and likely effect on individuals; take containment steps and assess reporting duties promptly. The ICO breach guidance (opens in new tab) explains the risk threshold and reporting timetable.

Do the paid versions of AI tools train on our data?

Some business products commit not to train on customer data by default, including ChatGPT Business and Enterprise and Microsoft’s commercial Copilot offerings. Paid consumer plans and other products may have different terms or settings. Confirm the exact product, account, retention and training arrangement; price alone does not establish privacy.

How does Microsoft 365 help stop AI data leaks?

Microsoft Purview provides information protection and DLP capabilities with licence and deployment requirements. Supported policies can audit, warn or block specific sharing, upload and paste actions. Confirm the licence, device and browser coverage, then test those actions. Do not assume every Microsoft 365 plan includes every endpoint or browser control.

What should an AI acceptable use policy cover?

Keep it to a page. Say plainly what staff must never paste into a public AI tool, such as client data, personal data, contracts, source code, credentials, and anything marked confidential. Name the sanctioned tool they should use instead, and say who to ask when they are unsure. A short policy people understand changes behaviour far more than a long one nobody reads, and it should sit inside your wider data handling and acceptable use frameworks.

Can we use AI safely at all then?

AI can be appropriate when the use case, data and controls are acceptable to the business. Start with approved tasks, suitable product terms, access controls and human review. Logging and shutdown controls can support governance, but neither they nor a UK hosting option remove every risk.