← All FAQs
AI

Is it safe for my staff to use ChatGPT or other AI tools at work?

It can be, but "safe" depends entirely on what's being entered into these tools, which specific tool or account tier is being used, and whether there's any policy or oversight governing that usage at all. Right now, in most businesses, the honest answer is that staff are already using these tools extensively with essentially no governance, which is the actual risk, not AI itself.

What Actually Happens to Data Entered Into Free AI Tools

Free, consumer-tier accounts on many popular AI tools may use conversation data to further train the underlying model, meaning information entered isn't necessarily kept confidential to your business, it can potentially inform how the model responds to entirely unrelated users later. Business or enterprise tiers of the same tools frequently offer different, more restrictive data handling terms, explicitly excluding conversations from model training, but this distinction is easy to miss if staff are simply using whatever free consumer version they've personally signed up for.

The Categories of Data That Are Genuinely Risky to Enter

  • Client personal information, names, contact details, account numbers, anything identifying a real person, pasting this into an ungoverned AI tool raises real POPIA concerns around lawful processing and cross-border data transfer
  • Confidential business information, financial data, strategic plans, unreleased product information, contracts
  • Credentials and access details, passwords, API keys, system configuration details, occasionally pasted into AI tools when troubleshooting technical issues, a genuine and surprisingly common risk
  • Anything covered by a client confidentiality or NDA obligation, where using a third-party AI tool at all may itself breach the terms of that agreement

What's Generally Lower Risk

Using AI tools for genuinely generic tasks, drafting a template email structure, brainstorming ideas, general research, summarising publicly available information, carries considerably less risk than entering specific, identifiable business or client data. The distinction that matters is what data is actually entered, not simply whether AI is used at all.

Why "Just Tell Staff to Be Careful" Doesn't Work

Without a clear, specific written policy defining what's approved and what isn't, individual staff members are left making judgment calls inconsistently, and often incorrectly, about what's genuinely sensitive. A clear policy with specific examples removes ambiguity and gives staff a genuinely usable, practical guide rather than a vague "use good judgment" instruction that inevitably gets applied differently by different people.

A Practical Starting Point

At minimum: identify which AI tools are actually approved for business use (ideally business/enterprise tiers with appropriate data handling terms, not free consumer accounts), document specific categories of data that should never be entered into any AI tool, and communicate this clearly to staff with concrete, realistic examples rather than abstract policy language.

Our Approach

As part of GovernAI, we help identify which AI tools are already in use across your business (often a genuine eye-opener for leadership), assess the actual data handling terms of each, and build a specific, practical acceptable-use policy your staff can actually follow day to day, rather than a generic policy document that sits unread.