Learn · Business AI

Employees using ChatGPT at work

Short answer. Employees are likely already using ChatGPT and other AI tools, often with personal accounts. Banning it rarely works. A better response is a clear policy, an approved account, rules for what data may be used, and a governed way to connect AI to company information.

Last reviewed 24 September 2026

The situation most organisations are in

In many organisations, some staff already use ChatGPT, Claude, Copilot or similar tools for work: drafting emails, summarising documents, checking spreadsheets, researching. Often they use personal accounts, because that was quickest. Management may know this in general terms but not in detail.

This is not a reason to panic. It is a reason to take a decision, rather than letting habits form by default.

The real risks

  • Data on the wrong terms. Personal accounts may have different data-handling terms from business plans. Check your provider’s current terms and settings.
  • Confidential information. Client files, personal data or commercially sensitive material pasted into a chat has left your control.
  • Inaccurate output. AI can produce plausible errors. Work that is not checked can reach clients.
  • No record. If something goes wrong, there may be no way to know what was shared or produced.
  • Fragmentation. Useful work sits in individuals’ private chats, invisible to colleagues.

Why banning rarely works

Outright bans are hard to enforce, especially when AI tools are available on personal phones. They also push use out of sight, which makes the risks harder to manage, and they deny the organisation real benefits. Most organisations are better served by making the safe route the easy route.

A practical response

1. Find out what is happening

Ask staff, without blame, which tools they use and for what. An anonymous survey often gets more honest answers.

2. Write a short AI policy

Cover which tools are approved, which account types must be used, what data may and may not be entered, how output must be checked, and who to ask. Keep it short enough to be read.

3. Provide an approved option

Give staff an approved business account for the AI tools they need. If people have a sanctioned route that works, most will use it.

4. Classify your data

Staff need a simple rule of thumb: what is public, what is internal, what is confidential and what must never go into an AI tool without a specific control.

5. Connect AI to company data properly

Pasting and uploading is where most leakage happens. Connecting AI to company systems through a governed layer, with permissions and a record, is safer than copies scattered across chats.

6. Train and review

Short, practical training on what good use looks like. Review after a few months.

UK context

Where personal data is involved, UK GDPR applies to how it is processed, including by AI tools. The ICO publishes guidance on AI and data protection. For regulated firms, professional confidentiality obligations continue to apply whatever tool is used. This is general information, not legal advice.

How Kroy approaches it

PolicyHQ can help you write the policy. Kroy puts it into practice. Staff connect the AI tools you approve to Kroy; Kroy decides what each person’s AI may see and do, requires approval where the policy says so, and records every request. Define the rules with PolicyHQ. Put them into practice with Kroy.