Quantum Technologies — AI in a Box
AIOctober 2, 2026Quantum Technologies5 min read

Is ChatGPT Safe for Work? Shadow AI and What Your Team Is Already Pasting Into It

Your staff are almost certainly using ChatGPT, Gemini or Claude on their own, often on free personal accounts. That is shadow AI. The risk is not the tool, it is what goes into it. Here is how to bring it into the open without banning it.

Short answer: ChatGPT can be safe for work, but not the way most people are using it. The risk is a staff member pasting a customer list, a contract or a patient note into a free personal account, where the business has no control over what happens to it and no record that it happened.

That is shadow AI: AI tools used for work without the company knowing or setting any rules. Surveys keep finding that a large share of employees use AI at work and many do not tell their employer. In a ten-person office, assume someone already is.

Why personal accounts are the problem

  • Free and personal plans may use conversations to improve the provider's models unless the person changes a setting, and most people never do.
  • The account belongs to the employee. When they leave, the history of everything they pasted leaves with them.
  • There is no way for the business to see what was shared, set retention, or answer a customer who asks where their data went.
  • Logins are often a personal Gmail and a reused password, with no multi-factor authentication.

Business plans from the major providers (ChatGPT's business tiers, Microsoft Copilot with a work account, Google Gemini in Workspace, Claude's Team and Enterprise plans) do not train on your data by default and give an administrator control over accounts. The difference between safe and unsafe is usually the account, not the tool.

What should never go into a public AI tool

  • Customer or patient names together with anything about them: health details, account numbers, balances.
  • Social Security numbers, dates of birth, driver's license numbers, bank or card details.
  • Passwords, API keys or anything that unlocks a system.
  • Contracts, pricing and bids that are not public yet.
  • Employee records: pay, reviews, discipline, medical leave.

Why banning AI does not work

A ban pushes the same use onto phones and home computers where you have even less visibility. People use these tools because they save real time on writing, summarizing and research. The better move is to give them a sanctioned tool with a business account and three or four clear rules, so the safe way is also the easy way.

Five steps to bring AI into the open

  • Ask. A short anonymous survey of which tools people use and for what tells you where to start.
  • Pick one approved tool on a business plan and move people onto it.
  • Write a one-page acceptable use policy: approved tools, what never goes in, and that a person checks every output before it is used.
  • Turn on multi-factor authentication and single sign-on for the approved tool so accounts are the company's, not the employee's.
  • Train for thirty minutes with real examples from your own work, and revisit it every year.

How we help

We help Northeast Wisconsin businesses do exactly this: find out what is in use, choose and set up the right business plan, write the policy and train the team. Our free AI acceptable use policy template is on the Guides page and is a good first step on its own. When you are ready to roll out Copilot or another assistant properly, our Copilot and Secure AI Readiness service covers the whole job.

Not sure where your business stands on this?

We’ll walk through how you handle it today and tell you straight whether it needs attention.

AIBusiness Technology

Let's talk about your technology.

A quick conversation about where you are, what's not working, and whether we're the right fit. No pressure, no jargon.

No obligation. No sales pressure. Just an honest conversation.

CallSchedule a Call