← All articles
AI & Software7 min read

Your Staff Are Pasting Company Data Into ChatGPT

There is a good chance that this week, someone in your business pasted something into a chatbot that you would not have wanted to leave the building. A customer email to get help with the reply. A contract clause to have it explained. A spreadsheet of figures to summarise. A block of code from a system you rely on.

The term for this is shadow AI, and the important thing to understand about it is that essentially nobody involved is behaving badly. They're trying to do their job faster with a tool that genuinely helps. That's what makes it invisible — there's no misconduct to detect, no policy being knowingly broken, and often no policy at all.

What the actual risk is

It's worth being accurate here rather than alarmist, because overstating it is how you end up with a ban nobody follows.

  • You lose control of where the information went. Once pasted into a consumer service, it's outside your systems, outside your backups, and outside whatever you promised customers about how their data is handled.
  • Free and personal tiers generally carry weaker data handling terms than business tiers, and staff signing up with a personal email are on those terms by default.
  • It's tied to a personal account. When that person leaves, the history — and whatever business context is in it — leaves with them, and you have no way to reach it.
  • If you handle regulated data, or have contractual confidentiality obligations, the exposure is not merely reputational.

What it usually is not: a hacking risk in the conventional sense. Nobody is breaking in. The data is being carried out voluntarily, one paste at a time, by people trying to be useful.

Why banning it fails

The instinct is to prohibit it. In practice a ban moves the same behaviour onto personal phones and personal accounts, where you have no visibility at all, and it costs you the productivity gain that made people reach for the tool in the first place.

It also puts you in the position of telling capable staff that the obviously useful thing is forbidden, without offering an alternative. That reliably produces quiet non-compliance rather than compliance.

A policy that people will actually follow

It fits on one page, and it should be specific about categories rather than gesturing at judgement.

  • Name what must never be pasted into a public tool: customer personal data, anything covered by a confidentiality agreement, credentials, financial account details, health or employment records, and source code for systems you depend on.
  • Name what is fine: public marketing copy, general questions, drafting help with no identifying detail, explaining a concept, rewriting something you'd happily publish.
  • Provide a sanctioned tool on a business tier, paid for by the company, with sign-in tied to work accounts rather than personal ones.
  • Require a person to check anything customer-facing before it goes out. This is the same rule that already applies to a junior drafting a reply.
  • Say plainly that nobody will be disciplined for having used AI before the policy existed. You want an accurate picture more than you want a culprit.

Start by asking, not auditing

Before writing anything, ask your team what they're already using and what for. You'll get a far more accurate answer from a conversation framed as "we want to make this properly available" than from any monitoring exercise — and the answers usually reveal a couple of genuinely valuable use cases you'd otherwise have banned by accident.

That conversation also tends to surface the real reason people reached for it: some slow, repetitive task nobody had got round to fixing. Which is frequently worth fixing properly.

Where this connects to the rest of your security

Shadow AI is one instance of a broader pattern — people adopting tools faster than the business writes rules for them. The same applies to file sharing, personal devices, and browser extensions. If it's happening with AI, it's worth checking the others.

Our free IT audit covers where a small business is typically exposed, and if you want help deciding where AI genuinely fits — including the honest answer that a piece of software might serve you better than a chatbot — read our take on where AI actually helps or just talk to us. Ongoing policy and control work is part of managed IT support.

Rather have someone handle it? This is part of our managed it support service across Middlesex, Somerset and Mercer County.

Need a hand?

We handle this for New Jersey businesses and homes

Whether it's a one-off problem or ongoing support, we're happy to take a look — and to tell you honestly if you don't need us.

Keep reading