You have seen it on someone's screen
It usually comes out by accident. Someone in accounts shares their screen on a call and there is a ChatGPT tab open with a customer's aged debt list pasted into it. A project manager mentions that they "ran the contract through ChatGPT" to find the break clause. A new starter asks which AI account the company uses, and the honest answer is: everyone's own.
None of these people are being careless on purpose. They found a tool that saves them half an afternoon, nobody told them what was allowed, and the free or personal version was one browser tab away. The problem is that client names, salaries, contract terms and health details are now sitting in accounts the business does not control, cannot audit and cannot close when someone leaves.
Why a policy on its own does not fix it
Most businesses respond by writing an AI policy, and a policy is worth having. But a policy that says "do not paste confidential data into public AI tools" without offering an alternative asks staff to go back to the slow way. People comply for a fortnight and then quietly drift back, often onto their phones where you have even less visibility.
The real cause is that the approved route either does not exist or is worse than the unapproved one. If the sanctioned tool needs a ticket to access, has no memory of the last conversation, or cannot read a PDF, the personal account wins every time. You are competing on convenience, and the fix has to win on convenience too.
What the current habit is exposing
| Where the data goes | What that means for you |
|---|---|
| Personal consumer accounts | Terms you have not agreed to, and settings each person chose themselves |
| Accounts tied to personal email | Access continues after the person leaves the business |
| No central log | You cannot answer a client who asks what was shared, or when |
| Mixed personal and work chats | Work material sits alongside holiday plans in one history |
| Copies of attachments | Files uploaded for a quick summary stay in someone else's system |
There is also a quieter cost. Because nobody talks about it openly, the people who have worked out genuinely useful ways of using AI keep them to themselves. The good prompts, the clever uses, the time saved: none of it spreads across the team.
How we set up an approved AI workspace
What we build is a company AI workspace that staff actually prefer to their personal accounts. The pieces are:
- A chat interface on your own domain, signed in through Microsoft 365 or Google Workspace, so access starts and ends with the employee's work account.
- Model access through business agreements, using the OpenAI API, Azure OpenAI or Anthropic Claude, where the published terms say your inputs are not used to train models by default. We check the current terms with you rather than assuming.
- A redaction step that spots common personal data (National Insurance numbers, bank details, card numbers, dates of birth, email addresses) and masks it before the text leaves your environment, with a clear message to the user when it does.
- Document upload that works properly, so the reason people used a personal account ("I needed it to read the PDF") goes away.
- Shared prompt templates for the jobs your team already does, such as summarising a tender, drafting a chaser email or turning meeting notes into actions.
- A usage log that records who used which template and when, stored in your tenancy, so you can answer questions from clients and auditors.
Where there is data that should never go to an external model at all, we mark those sources as out of bounds or route them to a model hosted inside your own cloud account. We also write a one-page policy that points to the new workspace, so the rule and the alternative arrive together.
What changes for the team
Staff keep the thing they liked about ChatGPT: a quick way to draft, summarise and think out loud. What changes is where it happens. The work sits under a company login, the obvious personal data is masked before it goes anywhere, and when someone leaves, their access goes with their account.
Managers get something they did not have before: a view of what AI is actually being used for. That tells you which tasks are worth building into proper tools next, and it makes the policy conversation factual rather than a guess about who might be doing what.
Is this your situation?
- You know, or strongly suspect, that staff use personal AI accounts for work.
- You have client contracts or NDAs with confidentiality clauses that nobody has checked against AI use.
- Your AI policy exists but nobody can tell you whether it is followed.
- Staff have asked for an approved tool and been told "soon".
- A leaver may still have work conversations in a personal AI account.