Your team is already using AI tools. If you haven’t explicitly enabled them, they’re using personal accounts on their work devices. A recent survey found 71% of employees at SMEs use AI assistants at work, and fewer than a third say their employer has any policy about it.

The question isn’t really whether to allow AI tools — that ship has sailed. The question is whether you understand what happens to the information that goes into them, and whether you’ve made any decisions about what should and shouldn’t be typed into a chat window.

What actually happens to what you type

The answer varies significantly by tool, by whether you’re using a free or paid account, and by how the account is configured.

ChatGPT (OpenAI)

Free accounts and consumer ChatGPT Plus: By default, OpenAI uses your conversations to improve its models unless you opt out. Conversations are stored and can be reviewed by OpenAI staff for safety monitoring. Even with history disabled, OpenAI retains conversations for 30 days for safety purposes.

To opt out of training: Settings → Data Controls → toggle off “Improve the model for everyone.” This prevents your data being used for training but doesn’t eliminate all storage.

ChatGPT Enterprise and ChatGPT Team: No training on your data by default. Conversations are not used to improve OpenAI models. Conversations are retained for 30 days (configurable). These plans come with a DPA (Data Processing Agreement) that is necessary for GDPR compliance. If you’re a UK or EU business using ChatGPT for anything involving personal data, you need Enterprise or Team, not consumer accounts.

ChatGPT API via OpenAI API: No training by default. Data is retained for 30 days for abuse monitoring, then deleted. The API is what developers use; if you’re accessing OpenAI through a third-party app, that app sits between you and OpenAI and has its own privacy posture.

Microsoft Copilot

Copilot at copilot.microsoft.com (free): Conversations are stored by Microsoft and can be used to improve products. Not suitable for sensitive business data.

Copilot for Microsoft 365 (commercial subscription): Your data is not used to train Microsoft’s foundation models. Conversations and prompts are stored in your Microsoft 365 tenant, subject to your retention policies. Microsoft’s commercial terms include a DPA. This is the version appropriate for business use involving business data.

Copilot+ features within Microsoft 365 apps (Word, Excel, Outlook, Teams): Operate within the Microsoft 365 trust boundary. Your tenant data stays within your tenant unless you explicitly share it.

The distinction that catches businesses out: employees using personal Microsoft accounts (outlook.com, hotmail.com) to access Copilot are using the consumer product, not the commercial one, regardless of what device they’re on.

Claude (Anthropic)

Claude.ai free and Pro (consumer): Conversations may be reviewed by Anthropic staff and used to improve models unless you opt out. Opt-out is in Privacy Settings → “Improve Claude for everyone.”

Claude for Enterprise and Claude Teams: Anthropic does not use your conversations to train models by default. Conversations are stored in your account but not used for training. Includes a DPA for GDPR-covered data.

Claude API: No training on API data. Anthropic processes prompts to provide the service and for safety purposes; standard retention applies per their API data usage policy.

Google Gemini

Gemini (free, personal Google account): Conversations reviewed by human reviewers and used to improve Google AI products. Google’s terms permit this for free services.

Gemini for Google Workspace (Business/Enterprise): Not used to train Google models. Conversations are covered by Google Workspace DPA. Data stays within Google Workspace security perimeter.

Same issue as Microsoft: employees using personal gmail.com accounts to access Gemini are not under Workspace terms.

The GDPR question

If your business handles personal data about EU or UK residents — employees, customers, prospects — and you type any of that into an AI tool, GDPR applies to that processing.

Under GDPR, if you’re using an AI tool to process personal data, the AI provider becomes a data processor and you’re the data controller. That requires:

  1. A Data Processing Agreement (DPA) with the AI provider
  2. Confirmation that processing is limited to what’s necessary
  3. A legal basis for the processing
  4. Appropriate safeguards if data is transferred outside the UK/EU

Consumer AI accounts (free ChatGPT, personal Copilot, gmail Gemini) don’t come with DPAs. Using them to process employee records, customer data, or anything containing personal information creates a compliance gap.

The commercial tiers of ChatGPT Enterprise, Microsoft 365 Copilot, Claude Enterprise, and Google Workspace Gemini all include DPAs. The ICO has indicated that the DPA requirement is not optional — it’s a structural requirement of Article 28 GDPR for any processing by a third party on your behalf.

What you should never type into any AI tool

Some categories of information carry risk regardless of the AI tool’s data handling:

Client data with identifying information: customer names, email addresses, phone numbers, account numbers. If you want AI help drafting a proposal or analysing a situation, anonymise first.

Employee personal data: payroll figures, performance records, disciplinary notes, health information, salary details. AI is useful for HR writing tasks — drafting job descriptions, policy documents, offer letter templates — but strip any personal details first.

Business-sensitive information: pricing strategies, M&A discussions, financial projections before they’re public, contract terms with significant counterparties.

Authentication credentials: passwords, API keys, access tokens. Never. Even if the session is encrypted in transit, once it’s in a training dataset or conversation log it exists somewhere you don’t control.

Legal and regulated data: anything protected by legal privilege, regulated financial information, health records. Even with a DPA in place, processing highly sensitive categories of data through AI tools requires careful thought about legal basis and proportionality.

A practical policy for small businesses

You don’t need a complex policy framework. Something usable and specific works better than a detailed document no one reads:

Permitted use (with commercial accounts only):

  • Drafting emails, documents, and proposals — anonymise any client or employee names
  • Writing code, formulas, or technical content
  • Summarising public information or your own generic business content
  • Generating ideas, outlines, and creative content

Requires caution (commercial accounts, no personal data):

  • Analysing business data — aggregate figures yes, individual records no
  • Reviewing contracts — remove counterparty names and identifying details

Not permitted:

  • Customer data with names, contact details, or account numbers
  • Employee personal records
  • Financial data tied to identifiable individuals or specific clients
  • Any credentials or authentication material

Account requirements:

  • Only business accounts (Microsoft 365 Copilot, ChatGPT Team/Enterprise, Claude Teams/Enterprise, Google Workspace Gemini) for work tasks
  • No personal AI accounts for business content

Setting up your team

The practical steps most small businesses can handle in an afternoon:

  1. Decide on one or two approved tools — don’t try to manage five different AI platforms
  2. Confirm you have the commercial tier that comes with a DPA; check your subscription type
  3. Send a single-page guidance note to your team explaining what’s allowed and what’s not — one page, bullet points, examples
  4. Review browser extensions: many AI browser extensions (Grammarly, various AI writing tools) intercept everything you type across all websites, including in-browser business apps. Review what your team has installed.
  5. Check data retention settings: where your AI tool allows you to adjust retention periods or disable history, configure this per your policy

The risk of doing nothing isn’t just GDPR compliance — it’s business confidentiality. If an employee pastes a client’s contract details into a free AI account where those details can be reviewed by a third party, you may have breached your confidentiality obligations to that client even if nothing is ever used to train a model.

Getting this right doesn’t require expensive consulting. It requires a decision on tools, checking you’re on business-grade accounts, and making your expectations clear to the team.