Plainstart Back to the kit

Article

The Real Risks of Using ChatGPT at Work (and What to Do About Each One)

Most businesses are already using ChatGPT. Most have no rules in place.

That gap is where the problems start.

This article covers the specific risks that matter for small and medium businesses, what causes each one, and the practical controls that reduce them. It is general business guidance, not legal, compliance, or professional advice. For anything regulated, speak to the relevant professional.


What the Risk Actually Is

The risks of using ChatGPT at work fall into four categories.

  1. Data sent to a third party
  2. Outputs that are wrong
  3. Outputs that are confidential to someone else
  4. Staff using it inconsistently, with no audit trail

Each one is manageable. None of them disappear by ignoring the tool.


Risk 1: Data Leaving Your Business

What happens. When someone pastes a client name, a contract clause, a payroll figure, or a medical record into ChatGPT, that text is sent to OpenAI's servers. By default, OpenAI uses conversations to improve its models unless you opt out. Even with opt-out enabled, the data has left your network.

What goes wrong. A team member pastes a client's full name, address, and complaint into ChatGPT to draft a response letter. That data now sits outside any confidentiality obligation your business holds. If your business operates under GDPR, the UK Data Protection Act, HIPAA, or any sectoral privacy regulation, this is a live compliance issue, not a theoretical one.

What the risk depends on.

  • Whether you are using the free consumer version, ChatGPT Plus, or the API
  • Whether your OpenAI account has conversation history and training opt-out enabled
  • Whether you have a Business Associate Agreement or Data Processing Agreement with OpenAI (available for API and ChatGPT Enterprise, not the consumer tiers)
  • What category of data is being pasted in

The controls.

Block classes of data by policy. Tell staff specifically what must not go into any AI tool. The list should include: full client names combined with any other identifier, financial figures tied to individuals, health or medical information, passwords or credentials, unreleased product information, and contract terms with named counterparties.

Use anonymisation before prompting. Teach staff to replace names and identifiers with placeholders before drafting with AI. "Draft a response for a customer called Alex who complained about delivery" instead of the full record.

Use the right tier for the work. ChatGPT Enterprise and the OpenAI API offer data processing terms. The consumer free tier does not. If your work involves sensitive data, account tier matters.

Check your agreements. If you handle personal data on behalf of clients, your data processing obligations may require you to list and control sub-processors. An AI tool that handles that data is a sub-processor. This is an area where you need legal advice specific to your situation.


Risk 2: Outputs That Are Wrong

What happens. ChatGPT produces text that is confident, well-structured, and sometimes factually incorrect. It cites sources that do not exist. It gives numbers that are plausible but fabricated. It describes regulations in ways that were accurate for an earlier version of the law. It writes code that looks correct and contains bugs.

The technical term is hallucination. The business impact is staff trusting output without checking it.

What goes wrong. A manager uses ChatGPT to draft a staff handbook section on statutory redundancy pay. The output quotes a figure that applied before the most recent uplift. The handbook goes out unchecked. Staff later rely on that figure.

A bid writer uses ChatGPT to summarise a competitor's certifications. The summary includes a certification the competitor does not hold. The bid references it. The client notices.

What the risk depends on.

  • Whether the task requires factual accuracy or just a reasonable draft
  • Whether someone with domain knowledge reviews the output before it is used
  • Whether the output goes to an external party or informs a decision

The controls.

Set a review rule, not a hope. Any AI output used externally or used to make a decision needs human review by someone who can actually check it. This should be a stated step, not an assumption.

Define tasks where AI is suitable. AI is reliable for structure, tone, rewriting for clarity, and brainstorming. It is unreliable for current statistics, current law, current prices, and anything requiring real-world verification. Write that line in plain language for your team.

Teach the confidence problem. ChatGPT does not signal uncertainty in a way that matches how uncertain the output actually is. Staff need to understand that fluent writing is not the same as accurate writing. This is a specific training point, not a general disclaimer.

Prompt for sources. Ask the model to state where a fact comes from. If it cannot name a verifiable source, treat the claim as unverified.


Risk 3: Copyright and Confidentiality in the Output

What happens. ChatGPT is trained on a large corpus of text from the internet, published books, and other sources. When it generates text, it may reproduce passages that are substantially similar to copyrighted material. In most jurisdictions, AI-generated content also has uncertain copyright status, meaning your business may not own what it produces.

What goes wrong. A marketing team uses ChatGPT to draft a product description. The output is a close paraphrase of a competitor's copy. The team publishes it. The similarity is noticed.

A developer uses ChatGPT to write a function. The output contains a segment licensed under GPL. The product ships with it. The licensing obligation is now active.

What the risk depends on.

  • Whether the output goes to market or stays internal
  • Whether your sector has specific IP sensitivities
  • Whether the output is code, which carries licence considerations specific to software

The controls.

Run external copy through a plagiarism or similarity check before publishing. Tools exist for this. Make it a step in the publication process, not an optional extra.

Treat AI output as a draft, not a finished product. Editing the output reduces similarity risk and usually improves quality.

Do not paste your own proprietary work into ChatGPT for rewriting if that work is itself commercially sensitive or under confidentiality obligations to a third party.

Know where your IP boundaries are. If you work in software, publishing, design, or any sector with strong IP norms, get a professional view on your specific workflow. This is general guidance, not legal advice.


Risk 4: Inconsistent Use With No Audit Trail

What happens. Different people in the same business use AI in different ways. One person is cautious. One is not. There is no log of what was sent, what was produced, or what was used. When something goes wrong, there is no way to reconstruct the decision.

This matters for regulated businesses. It also matters for any business where quality consistency, client confidentiality, or accountability is a real requirement.

What goes wrong. A complaint arrives about advice given to a client. The advice was partly drafted with ChatGPT. There is no record of what prompt was used or what the output said. The investigation goes nowhere useful.

A new staff member copies a prompt from a colleague that contained a client's data. Neither knew it was a problem. The original sender did not think they were creating a template.

What the risk depends on.

  • How many people are using AI tools in your business
  • Whether you are in a regulated sector with record-keeping requirements
  • Whether your clients or contracts place specific obligations on your handling of information

The controls.

Write a usage policy. A policy does several things: it tells staff what is and is not acceptable, it gives managers a reference point for conversations about misuse, and it demonstrates to auditors or clients that the business takes this seriously. The policy should cover what data can go in, what outputs must be reviewed, and who is responsible for what.

Create a simple prompt library for common tasks. Shared, reviewed prompts reduce the chance of someone improvising a prompt that pulls in sensitive data. They also improve output quality.

Log significant AI use in regulated workflows. This does not need to be elaborate. A column in a project tracker noting "AI-assisted, reviewed by [name] on [date]" creates a basic audit trail.

Brief staff on the policy before they need it. Training after an incident is too late.


The Controls in Summary

RiskMain Control
Data sent to third partyData classification policy, anonymisation rule, correct account tier
Inaccurate outputHuman review requirement, task scope definition, source prompting
Copyright or IP exposureSimilarity checks, editing step, no pasting of confidential IP
Inconsistent use, no audit trailWritten usage policy, shared prompt library, basic logging

A Note on Sector-Specific Rules

Some sectors carry additional rules that interact directly with AI use.

Healthcare businesses handling patient data face specific obligations under HIPAA in the US and equivalent regimes elsewhere. Legal practices face professional conduct rules about confidentiality and competence. Financial services firms face obligations around record-keeping and advice documentation. Schools and universities handling student data face additional data protection rules.

If your business operates in a regulated sector, the controls above are a starting point, not a complete picture. Take specific advice from a professional familiar with your regulatory environment. This article is general guidance only.


Why Most Businesses Do Not Have These Controls

Three reasons come up consistently.

First, the tools arrived faster than the policies. ChatGPT became widely used in months. Policy development in most businesses takes longer than that.

Second, it does not feel urgent until it is. Data sent to a third party is invisible. An inaccurate output that does not get caught is invisible. The feedback loop on AI risk is slow.

Third, "AI policy" sounds like a large, complicated thing. It does not have to be. A one-page document that says what staff can and cannot do, and what needs review, is a significant improvement over nothing.


Start With a Written Policy

A written AI usage policy is the foundational control. Everything else builds on it. It defines the boundaries, sets the review expectations, and gives your team a shared reference point.

We have written a plain-language AI Usage Policy template for small and medium businesses. It covers data rules, acceptable use, review requirements, and a short explanation staff can actually read and understand.

It is free to download.

[Get the free AI Usage Policy at Plainstart]

If you want the full toolkit, including the data governance checklist, 90-day adoption plan, tool scorecard, prompt libraries, and ROI tracker, the AI Adoption Kit is available for $149.

AI adoption, done properly.

Free download

The AI Usage Policy your team can actually follow

One page, plain language, ready to put in front of staff today. No cost, no catch.

Get the free policy