The situation most organisations are in
In many organisations, some staff already use ChatGPT, Claude, Copilot or similar tools for work: drafting emails, summarising documents, checking spreadsheets, researching. Often they use personal accounts, because that was quickest. Management may know this in general terms but not in detail.
This is not a reason to panic. It is a reason to take a decision, rather than letting habits form by default.
The real risks
- Data on the wrong terms. Personal accounts may have different data-handling terms from business plans. Check your provider’s current terms and settings.
- Confidential information. Client files, personal data or commercially sensitive material pasted into a chat has left your control.
- Inaccurate output. AI can produce plausible errors. Work that is not checked can reach clients.
- No record. If something goes wrong, there may be no way to know what was shared or produced.
- Fragmentation. Useful work sits in individuals’ private chats, invisible to colleagues.
Why banning rarely works
Outright bans are hard to enforce, especially when AI tools are available on personal phones. They also push use out of sight, which makes the risks harder to manage, and they deny the organisation real benefits. Most organisations are better served by making the safe route the easy route.
A practical response
1. Find out what is happening
Ask staff, without blame, which tools they use and for what. An anonymous survey often gets more honest answers.
2. Write a short AI policy
Cover which tools are approved, which account types must be used, what data may and may not be entered, how output must be checked, and who to ask. Keep it short enough to be read.
3. Provide an approved option
Give staff an approved business account for the AI tools they need. If people have a sanctioned route that works, most will use it.
4. Classify your data
Staff need a simple rule of thumb: what is public, what is internal, what is confidential and what must never go into an AI tool without a specific control.
5. Connect AI to company data properly
Pasting and uploading is where most leakage happens. Connecting AI to company systems through a governed layer, with permissions and a record, is safer than copies scattered across chats.
6. Train and review
Short, practical training on what good use looks like. Review after a few months.
UK context
Where personal data is involved, UK GDPR applies to how it is processed, including by AI tools. The ICO publishes guidance on AI and data protection. For regulated firms, professional confidentiality obligations continue to apply whatever tool is used. This is general information, not legal advice.
How Kroy approaches it
PolicyHQ can help you write the policy. Kroy puts it into practice. Staff connect the AI tools you approve to Kroy; Kroy decides what each person’s AI may see and do, requires approval where the policy says so, and records every request. Define the rules with PolicyHQ. Put them into practice with Kroy.