Contact us

Home / ITRM Insights / Blog / ChatGPT at Work? What Businesses Need to Know About AI and GDPR

Use ChatGPT at Work? What Businesses Need to Know About AI and GDPR

Artificial intelligence has moved from novelty to necessity remarkably quickly. A year or two ago, tools such as ChatGPT were something people experimented with out of curiosity. Today, they're being used to draft emails, summarise meetings, analyse documents, generate content and support decision-making across organisations of all sizes.

For many businesses, the benefits are obvious. Employees can complete tasks more quickly, reduce the time spent on repetitive administration and improve productivity without increasing headcount. It's no surprise that AI adoption has accelerated at such a pace.

The challenge is that governance hasn't always kept up.

While employees are increasingly incorporating AI into their daily work, many organisations still haven't established clear guidance around how these tools should be used. In some cases, business leaders are unaware that staff are already using AI to support customer communications, prepare reports, draft proposals or create internal documentation.

As a result, a common question is emerging: can employees use ChatGPT at work without creating GDPR issues?

The answer is yes, but it's not quite that simple.

AI itself is not a GDPR violation. The real question is how employees are using it, what information they're sharing and whether appropriate safeguards are in place to protect sensitive data. Organisations that approach AI responsibly can unlock significant productivity benefits. Those that don't may be introducing risks they don't yet realise exist.

Why AI Has Created a New Compliance Challenge

Most new technologies arrive through a controlled implementation process. A business identifies a need, evaluates potential solutions, carries out due diligence and formally rolls out the chosen platform with the appropriate training and governance.

AI has been different.

Many employees began using tools such as ChatGPT before organisations had developed strategies around them. Someone discovered it could help write emails more quickly. Someone else realised it could summarise meeting notes in seconds. Before long, AI had become part of day-to-day operations without any formal discussion about acceptable use, security or compliance.

That speed of adoption is what makes AI unique from a governance perspective.

The challenge isn't that people are intentionally breaking rules. More often than not, they're simply trying to work more efficiently. We've found that employees usually start using AI for relatively harmless tasks such as drafting emails, summarising documents or generating ideas. The difficulty is that productivity gains often arrive long before governance catches up. This is where data protection concerns begin to emerge.

Organisations remain responsible for how information is handled, regardless of whether it's processed through a traditional application or an AI platform. The arrival of AI doesn't remove those responsibilities. It simply introduces a new technology that businesses need to understand and manage appropriately.

Can Employees Use ChatGPT at Work?

In many situations, using ChatGPT at work presents very little risk.

An employee might use AI to improve the wording of an email, brainstorm ideas for a presentation, create a draft social media post or summarise information that's already publicly available. These types of activities generally involve little or no sensitive information and can help improve efficiency without creating significant compliance concerns. However, there is a substantial difference between asking AI to improve a paragraph and uploading a spreadsheet containing customer records.

A marketing manager using ChatGPT to generate campaign ideas is unlikely to raise any eyebrows. A project manager asking AI to create a meeting agenda presents little cause for concern. Yet when customer information, employee records or commercially sensitive data start being entered into public AI tools, businesses need to pay much closer attention.

This is often the point where business leaders begin to feel uneasy. Using AI to improve the wording of an email is one thing. Uploading customer information, confidential contracts or employee records into a public AI platform is something entirely different. The technology may be the same, but the level of risk certainly isn't.

The issue is rarely the use of AI itself. It's the information being shared with the tool.

For business leaders, this means moving beyond the question of whether AI should be allowed and focusing on how it can be used safely and responsibly.

Understanding the GDPR Considerations

When discussing AI and GDPR, many people immediately assume the topic is highly technical or legal. In reality, the principle is relatively straightforward. GDPR is concerned with how personal data is collected, processed, stored and protected.

The challenge is that personal data is often broader than people realise. Names, email addresses, telephone numbers, payroll information, customer account records and employee information may all fall within the scope of GDPR. If employees are entering this information into an AI platform, organisations need to understand how it is being handled and whether appropriate safeguards are in place.

This is where many businesses encounter uncertainty.

Employees may see AI as simply another workplace tool. They may not stop to consider where information goes once it leaves their screen. In much the same way that organisations would evaluate the security of a new software platform before introducing it into the business, they should apply similar scrutiny to AI solutions.

A useful rule of thumb is this: if you wouldn't feel comfortable posting the information publicly online, you should think carefully before entering it into a public AI tool.

That doesn't mean businesses need to avoid AI altogether. It simply means they need to understand the distinction between low-risk activities and situations where sensitive information may be involved.

The Rise of Shadow AI

One of the biggest challenges facing organisations today isn't AI itself. It's what has become known as Shadow AI. Shadow AI occurs when employees use AI tools without formal approval, oversight or governance from the organisation.

In many cases, this happens with the best intentions. An employee discovers a tool that helps them work more efficiently and begins using it regularly. They aren't trying to bypass security controls or create compliance risks. They're simply solving a problem and getting work done.

One trend we're seeing across organisations of all sizes is employees experimenting with AI tools independently, often before the business has formally discussed AI adoption. That's hardly surprising. These tools are easy to access, offer immediate value and require very little training to get started. The problem is that many organisations have little visibility over which platforms are being used and what information is being shared.

Leaders may not know which AI tools are being used, what information is being shared or how much reliance is being placed on AI-generated outputs. Decisions that should be governed at an organisational level become individual choices made by employees with varying levels of understanding.

Over time, this can create significant challenges. Different teams begin using different tools. Sensitive information is handled inconsistently. Outputs are trusted without verification. Before long, AI becomes embedded within daily operations despite never being formally approved or assessed.

For many organisations, Shadow AI represents a greater risk than AI itself. Not because the technology is inherently dangerous, but because unmanaged AI introduces uncertainty. It becomes difficult to know where risks exist, who is responsible and what controls should be in place.

Why Businesses Need Clear Rules Around AI

One of the most effective ways to reduce risk is surprisingly simple: establish clear expectations.

Most organisations already have policies covering internet usage, password management, cybersecurity and acceptable use of company systems. AI should increasingly be viewed in the same way.

Employees need practical guidance. They need to understand which tools are approved, what information should never be entered into AI systems and when AI-generated outputs should be reviewed by a human before being used.

One of the most common conversations we have with business leaders starts with a familiar phrase: "We know people are using AI, we just don't know how much." In many cases, the solution isn't introducing tighter restrictions. It's providing clearer guidance. Most employees want to use AI responsibly, but they also want to know where the boundaries are.

An effective AI policy doesn't need to be lengthy or restrictive. In fact, the most successful policies tend to strike a balance between encouraging innovation and reducing unnecessary risk. They provide employees with the freedom to benefit from AI while ensuring data remains protected and organisational responsibilities are maintained.

As AI becomes more deeply embedded within everyday business operations, having clear governance is becoming less of a future consideration and more of a present-day requirement.

Is Microsoft Copilot Different?

As organisations explore AI, many are evaluating enterprise-focused platforms such as Microsoft Copilot alongside public AI tools. While every business should conduct its own assessment, there are important differences between consumer AI services and solutions designed specifically for business environments. The key distinction is often governance and control.

Public AI tools are generally designed for broad, individual use. Enterprise platforms, on the other hand, are typically designed to integrate with existing business security frameworks, user management processes and compliance requirements. This can make them a more attractive option for organisations seeking to balance innovation with control.

When organisations speak to us about AI, they're rarely searching for the most powerful tool on the market. More often, they're looking for a solution they can introduce confidently without creating unnecessary security, compliance or governance concerns. That's why discussions often focus as much on control and oversight as they do on functionality.

However, it's important not to view any technology as a silver bullet. Even the most secure AI platform can create challenges if employees have not been trained, governance is weak or usage expectations are unclear. Technology forms part of the solution, but responsible adoption always requires a combination of people, processes and policies.

The Future of AI in the Workplace

The organisations seeing the greatest value from AI are not necessarily those using it the most. They're the ones implementing it thoughtfully. Rather than rushing to deploy every new capability, successful businesses are taking the time to understand where AI can add value, where risks exist and what governance measures are required to support adoption.

They're creating policies instead of hoping for the best. They're training employees instead of simply giving them access. Most importantly, they're treating AI as a business capability rather than a standalone piece of technology. That approach not only reduces risk but also increases the likelihood of achieving meaningful business outcomes.

The question isn't whether AI belongs in your business. For many organisations, it's already here. The real question is how to adopt it in a way that delivers value while maintaining security, compliance and control.

The Takeaway

AI is already changing how people work.

From drafting content and summarising documents to supporting research and improving productivity, tools such as ChatGPT are helping employees work more efficiently across almost every department.

However, successful adoption requires more than simply giving people access to AI. Organisations must understand how information is being shared, what risks exist and whether employees have the guidance they need to use these tools responsibly.

Arguably, the biggest AI risk facing businesses today isn't ChatGPT, Microsoft Copilot or any other AI platform. It's the assumption that employees can start using these tools without any guidance, oversight or governance. The organisations seeing the greatest success aren't necessarily those adopting AI the fastest. They're the ones adopting it with a clear strategy and framework in place.

Businesses don't need to fear AI, nor should they attempt to ban it outright. Instead, they should focus on understanding where it adds value, establishing clear expectations and ensuring governance evolves alongside technology.

Those that get this balance right will be best positioned to benefit from everything AI has to offer while avoiding many of the risks associated with unchecked adoption.

Ready to Make AI Work for Your Business?

Whether you're just starting to explore AI or looking to integrate advanced AI capabilities across your organisation, having the right strategy, governance and security measures in place is essential.

AI can help improve productivity, streamline operations and unlock new opportunities for growth, but successful adoption requires more than simply choosing a tool and hoping for the best. Organisations need to understand where AI can deliver genuine value, how to manage potential risks and what controls should be in place to support long-term success.

At ITRM, we help businesses at every stage of their AI journey. From developing AI policies and governance frameworks to implementing Microsoft Copilot and exploring more advanced AI solutions, our team can help you approach AI with confidence.

Whether you're taking your first steps into AI or looking to accelerate an existing AI strategy, we'll help you identify opportunities, address challenges and build a practical roadmap aligned to your business goals.

Book a discovery call with our team to discuss your current challenges, objectives and AI ambitions. Together, we'll explore how AI can support your organisation securely, responsibly and effectively.

Speak to our team today and start building your AI roadmap.