Plainstart Back to the kit

Article

How to Stop Staff Putting Company Data into ChatGPT

Your team is already using AI. Someone pasted a client's email into ChatGPT to draft a reply. Someone dropped last month's figures in to get a quick summary. Someone uploaded a contract to have it explained. None of them meant any harm, and most businesses cannot see it happening at all.

That is the real risk with AI at work. Not robots. People quietly feeding business information into tools no one has checked.

Here is how to get it under control without banning AI outright, which never works anyway.

Why banning it fails

The instinct is to say "no AI tools." Staff then use them on their phones, on personal accounts, with zero oversight, and you have made the problem invisible instead of solving it. A ban does not remove the risk. It removes your ability to see it.

The goal is not to stop AI use. It is to make it safe and open.

Step 1: Tell people the one rule that matters

Most data leaks come down to a single missing habit. Give your team one clear line:

Do not put anything into an AI tool that you would not email to a stranger.

That covers the big ones: customer details, financial figures, passwords, contracts, anything confidential. It is simple enough that people actually remember it, which a three-page policy is not.

Step 2: Say which tools are allowed

Staff are not trying to be reckless. They usually just do not know which tools are safe. So tell them. Pick the AI tools your business approves, on business-tier accounts where the provider does not train on your data, and make that the list. Using anything off the list for work is not allowed. This one step removes most of the uncertainty that leads to bad choices.

Step 3: Write it down, once

A short written policy turns "we should be careful" into something staff can actually follow and you can actually enforce. It does not need to be long. It needs to cover:

  • the one rule above,
  • what data must never go in,
  • which tools are approved and how to request a new one,
  • who is accountable for checking AI output before it goes out, and
  • what to do if someone slips up.

That last point matters more than it looks. If people are afraid of getting in trouble, they hide mistakes, and a hidden mistake is the expensive kind. Make early reporting the safe, expected thing.

Step 4: Make checking the output non-negotiable

AI gets things wrong confidently. The rule that protects you: a human reads anything AI-assisted before it reaches a customer or drives a decision. The person who sent it owns it, exactly as if they had written it themselves.

You do not have to write the policy from scratch

The fastest way to do all of this is to start from a policy that already exists and adapt it to your business. We made one you can use for free.

[Download the free AI Usage Policy template.] It is editable, plain-language, and covers everything above. Adapt the bracketed parts to your business and it is ready to hand to your team this week.

If it is useful, the full Plainstart AI Adoption Kit gives you the rest of the system: how to vet a tool before your data touches it, how to roll AI out across the business in 90 days, and how to prove it actually paid off.

This is general guidance, not legal advice. Check your final policy against your local employment and privacy law.

Free download

The AI Usage Policy your team can actually follow

One page, plain language, ready to put in front of staff today. No cost, no catch.

Get the free policy