Someone in your business is using ChatGPT right now. They may be tidying up an email, summarising a long document or asking it to explain a spreadsheet formula. They are probably doing it on a personal account, because that is the one that took thirty seconds to set up. And nobody has told you, because nobody thought it was worth mentioning.
So the question we get asked most about AI is a simple one. Is it safe? Here is our honest answer.
The short answer
ChatGPT itself is not the problem. It is a capable tool, and for most everyday office tasks it is the quickest for people to pick up. The risk comes from two things: which account the information goes into, and whether anyone has agreed what is and is not OK to paste in.
Get those two things right and ChatGPT is as safe as any other cloud service you use. Leave them to chance and you have client data, staff details or a tender answer sitting in a service your business has no agreement with.
Personal accounts and business accounts are not the same thing
This is the bit that catches people out. A free or personal ChatGPT account is a consumer product. By default, what you type in can be used to improve OpenAI’s models, unless the person has found the setting to turn that off. The account belongs to the individual, not to your business, so when they leave, their history and anything they built goes with them.
ChatGPT Business and ChatGPT Enterprise are different. OpenAI states that it does not use business data to train its models by default. The accounts belong to the organisation, you can control who has access, and you can remove someone the day they leave, the same as you would with their email.
In plain terms: a personal account is fine for asking how to write a formula. It is not fine for pasting in a client’s contract, a payroll export or your answers to a security questionnaire.
What we found when we looked
A typical picture from businesses we talk to looks like this. A team of around twenty people. Nobody has been told they can or cannot use AI. When we look at what is actually in use, there are a handful of personal ChatGPT accounts, a couple of browser extensions that summarise web pages, and an AI note taker that someone added to Teams meetings without anyone noticing it was recording. None of it is malicious. All of it sits outside the systems the business has spent money securing.
The people involved were trying to do a good job faster. That is exactly why banning AI outright does not work. People do not stop using the tools. They just stop telling you.
What safe use actually looks like
You do not need a long policy document that nobody reads. You need four practical things.
- A short, clear policy your staff actually know about. What is approved, what is not, and what must never be pasted into any AI tool. Staff are briefed and confirm they have read it.
- Business accounts for anything involving company data. Set up by the business, signed into with your normal work login, and closed when people leave.
- A way of finding the tools nobody told you about. Browser extensions and free sign-ups appear constantly. Somebody needs to be looking.
- A quick check of who can see what. AI tools work on whatever a person already has access to, so old open folders become a bigger problem once AI can search them.
The tool is the easy part. Tidy permissions, a policy people know and a bit of training decide whether AI saves time or creates problems.
What this means for a business with 5 to 50 people
At your size you almost certainly do not have anyone whose job it is to think about this. That is fine, as long as someone does. The honest choice is between doing the four things above yourself, or having them done for you as part of your IT support.
That is what our new Protect & AI package is for. Available from 1 October 2026, it includes everything in our Core and Protect packages, plus an AI Acceptable Use Policy agreed with you and set up across your systems, continuous discovery of AI apps and extensions with unapproved ones blocked on managed devices, a review and tidy-up of who can see what before AI goes near your files, and ChatGPT Business or Enterprise, Microsoft 365 Copilot and Claude set up and managed properly, with access handled through the same joiner and leaver process as everything else. AI is also added to your security awareness training, so people know how to check what AI tells them and how to spot AI-written phishing.
It is £83.50 per user per month. Microsoft 365 Business Premium is required, and the AI licences themselves are bought separately.
One thing to do this week
Ask your team, without making it sound like an interrogation, which AI tools they use and what for. You will learn more in ten minutes than any survey would tell you. Then decide which of those tools you are happy to approve, and get business accounts for them.
If you would rather we did the looking, and put the policy, controls and training in place so your team can use AI without you worrying about where the data goes, take a look at what Protect & AI includes. You will see exactly what is covered and what it costs, with nothing hidden.