Company data in public AI tools: where the line is
Your team already uses ChatGPT — the question isn't whether, it's with what data. A three-category rule anyone can remember, without blocking the work.
Your team is almost certainly already using ChatGPT or its equivalent, whatever the company policy says. The useful question isn’t “who uses it”, because the answer is “everyone, quietly”. The useful question is with what data.
Most companies react in one of two ways, both bad. Either they ban everything — and people use AI from their personal phone, where you see nothing. Or they say nothing — and a signed contract ends up in a public chat because someone wanted a summary.
The rule below has three categories, because four don’t get remembered.
- A blanket ban doesn’t work: it moves AI use onto personal devices, where you have no visibility at all.
- Three data categories — green, amber, red — are enough. Anyone in the company should be able to classify a document in five seconds.
- What actually makes the difference is which account people use, not which model. A company account with a contract changes the whole conversation.
- The rule fits on one page and gets tested on three real documents from your company, not on textbook examples.
Three categories, not a list of rules
- Green
Goes anywhere
Information that is already public, or could be public without bothering you: site copy, product descriptions, press releases, marketing material, general professional questions. You don't want friction here — you want people using AI as much as possible.
- Amber
Company account only
Internal data that isn't secret but isn't public either: processes, template quotes, training material, aggregated sales figures, ordinary correspondence. It can go into an AI, but only through the organisation's account with its contract — not from a personal address.
- Red
Doesn't go up anywhere
Identifiable personal data of customers or employees, signed contracts, credentials, anything under NDA, unpublished financials, anything tied to a live case. If someone genuinely needs AI on that data, it gets solved with a hosted setup, not a public chat.
The account, not the model
| How the team uses AI | What control you have | Verdict |
|---|---|---|
| Free personal account, on a phone | None. You don't know what went up and you can't prove anything. | Green only |
| Paid personal account | Individual settings you don't administer. | Green only |
| Organisation account, with a contract | Central administration, contractual terms, control over data retention. | Green + amber |
| Model hosted in your own infrastructure | Complete — the data never leaves your perimeter. | Including red, with controlled access |
Vendors' default settings on retention and training change often. That's why the rule is tied to account type and contract, not to a particular toggle in a menu.
Two decisions for this week
Decide whether you pay for company accounts
It's the cheapest security measure available to you this quarter. The per-person cost is below an hour of a lawyer's time, and the effect is that work moves off personal accounts, where you see nothing, onto accounts you administer.
Test the rule on three real documents
Take three documents circulating in the company right now — a quote, a contract, a report — and ask three different people to classify them green / amber / red. If they don't agree, the rule isn't clear enough and needs rewriting before you publish it.
Questions we got on this edition
Wouldn't a blanket ban be simpler?
Simpler to write, yes. Safer, no. A blanket ban doesn't stop AI use, it relocates it to personal devices, where you have no visibility, no contract and no way to prove anything. The companies that tried found this out about six months in, usually through an incident.
How do we know whether a tool trains on our data?
It's in the terms of use and the business contract, and it differs between the free plan and the organisation plan. Because those terms change, our recommendation is to tie the internal rule to the account type — which you control — rather than to a setting the vendor can change between quarters.
Where does customer personal data fit?
Red, by default. Processing it through an external vendor raises GDPR questions — legal basis, processing agreement, transfers outside the EU — that get resolved before, not after. If you have a genuine business case for it, it's worth building properly, with a hosted setup and your DPO in the conversation from the start.
The one-page rule, written for your company.
We write it with your team, test it on real documents and fold it into the internal AI policy — alongside the register of systems and the transparency obligations.