Articles  /  Data & trust

Your staff are already pasting client data into ChatGPT

Not out of carelessness. Out of diligence — someone had a difficult email to write, a contract to summarise, a complaint to answer well, and the fastest way to do a good job was to paste the whole thing in. This is the live risk in most small companies, and it predates every line of AI regulation.

SmarterWorld · Vienna6 min read

It has a name now — shadow AI — but the shape is familiar. It is the same pattern as personal Dropbox accounts fifteen years ago, or WhatsApp groups for client work. Tools arrive through the people doing the work, because the sanctioned option is slower or does not exist.

The instinct is to ban it. That reliably fails: the work still has to get done, so use moves to personal phones where you cannot see it at all. The better move is to make the safe path the easy one, and to be specific about the line nobody crosses.

A client document Personal account FREE TIER · NO CONTRACT Outside your control NO RECORD · NO DELETION Business account TERMS · DPA · ADMIN Still your data CONTRACTED · AUDITABLE SAME DOCUMENT · SAME EMPLOYEE · SAME MINUTE
The difference is not the technology. It is whether a contract exists between your company and the vendor — which decides whether you can answer a client asking where their data went.

Why the free tier is the problem, not the AI

Under the GDPR you are the controller of your clients' personal data. When an employee pastes it into a tool you have no agreement with, you have made a transfer to a processor you never appointed. There is no data processing agreement, no record, and no reliable way to have it deleted.

Business and enterprise tiers of the major AI tools exist precisely to close that gap: contractual terms, a data processing agreement, administrative control, and commitments about training on your content. The same model, the same interface — a completely different legal position.

You are not deciding whether staff use AI. You are deciding whether they use it on an account with your name on the contract.

The line worth drawing

Vague rules produce vague compliance. "Be careful with sensitive data" means nothing at 5pm on a deadline. Name the categories instead:

That last one does most of the work. People cannot classify data reliably, but they can imagine a conversation.

The clause most policies forget

Say explicitly that mistakes reported early will not be punished. Without it, an employee who realises they pasted a client contract into a personal account will say nothing — and you lose the one chance to contain it. A policy that punishes honesty is a policy that guarantees silence.

A workable sequence

  1. Ask, without consequences, what people already use. Frame it as tooling research, not an investigation. You cannot govern what you cannot see.
  2. Provide one sanctioned tool on a business tier. One. Choice is what pushed people to personal accounts in the first place.
  3. Write the line down in plain language, on one page, and actually send it.
  4. Say what happens when someone slips — who to tell, and that telling is the right move.
  5. Revisit in six months. The tools will have changed; the policy should be boring to update.

This is an afternoon of work. It is also, for most small firms, a far better use of attention than the regulatory reading everyone is doing instead.

We'll write the page for you.

Five questions about your size, sector and how you handle client data, and you get the policy described above — tailored, one page, yours to send.

Write my policy

Keep reading

The EU AI Act and your small business Which tier you are actually in, and what it means. Execution got cheap. What are you paying for now? What survives when making things stops being the hard part.