AI for Business
Your Employees Are Already Using ChatGPT (Whether You Know It or Not): A Guide to Company AI Policy
Quick guessing game: how many people at your company are using ChatGPT, Gemini, or Claude to get their work done right now? If your answer is "not us, we don't allow that," here's the uncomfortable part. A 2025 study by KPMG and the University of Melbourne, covering more than 48,000 employees acr...

Quick guessing game: how many people at your company are using ChatGPT, Gemini, or Claude to get their work done right now? If your answer is "not us, we don't allow that," here's the uncomfortable part. A 2025 study by KPMG and the University of Melbourne, covering more than 48,000 employees across 47 countries, found that 57% of workers hide their AI use from their employer and pass the output off as their own. So the real question is what your team is feeding it when they use AI, under which account, and with whose data.
This piece lays out the reality of workplace ChatGPT use in numbers, pulls the lessons from Samsung's three-year journey from outright ban to full enterprise rollout, and hands you something you can actually use today: a nine-part skeleton for a company AI policy you can draft this week.
What Is Shadow AI, and Why Does Your Company Already Have It?
Shadow AI is employees using AI tools without IT's or management's approval or knowledge. It isn't the exception, it's the default: Microsoft's Work Trend Index found 78% of knowledge workers bring their own AI tool to work, and Gartner found unapproved AI tool use among employees jumped from 41% to 68% in a single year.
Cisco's 2025 readiness study of 8,000 decision-makers across 30 countries found that 81% of organizations have no visibility into how their employees are actually using AI. Whether you ban it or ignore it, it's already there, running quietly on personal phones and free accounts, invisible to whoever is supposed to be managing the risk.
The gap shows up everywhere you look for it. Official adoption surveys tend to report cautious, single-digit percentages of companies formally using AI, while employee-level surveys report the opposite: most knowledge workers already use it daily, policy or no policy. The two numbers describe the same workplace. One measures what leadership approved. The other measures what's actually happening on people's laptops.
We see the same pattern in nearly every company we talk to about an AI project: before the project even starts, it turns out at least one department has already built its own mini-automation with a free ChatGPT account.
Samsung's Three-Year Lesson: Ban It, Regret It, Embrace It
Samsung's story is the clearest proof that outright bans don't hold. After a 2023 data leak, Samsung banned ChatGPT company-wide. In June 2026, it reversed course entirely and rolled out enterprise ChatGPT access to roughly 125,000 employees. The three-year arc boils down to one lesson: uncontrolled use created the risk, and the tool caught the blame for it.
The origin story is almost a textbook case. In April 2023, within about 20 days, three separate incidents saw Samsung semiconductor engineers paste source code, test sequences, and confidential meeting notes into ChatGPT. In May 2023 the company banned external generative AI tools on all company devices. Apple, JPMorgan, and Goldman Sachs introduced similar restrictions around the same time.
Then, in June 2026, Samsung partnered with OpenAI to roll out ChatGPT Enterprise and Codex to its entire Korean workforce and its global device division, something OpenAI called one of its largest enterprise deployments to date. Samsung didn't lock itself into a single vendor either. It's building a multi-vendor setup that also includes Gemini and Claude.
Even the company that banned it outright ended up, three years later, adopting the "enterprise account plus written rules plus oversight" model. The difference: in 2023 employees used it secretly on free accounts. In 2026 they use it openly, backed by contractual data guarantees.
What Are Employees Actually Typing Into AI Tools?
Harmonic Security analyzed more than a million prompts and over 20,000 uploaded files and found that roughly one in five files employees upload to AI tools contains sensitive company data, led by source code (30%), legal documents (22%), and M&A or financial data. KPMG's research found that 48% of employees admit to entering sensitive company data into public AI tools.
The critical detail is where that sensitive input comes from: overwhelmingly, free personal accounts. That matters because on free ChatGPT, unless you've turned the relevant setting off, your conversations can be used to train the model. Enterprise plans block that contractually, more on that below.
The risk isn't theoretical. In the summer of 2025, roughly 4,500 ChatGPT conversations that users had marked as "shared and discoverable" got indexed by Google search, exposing names, emails, and resumes. OpenAI pulled the feature and had the links scrubbed. To be clear, conversations that were never shared didn't leak. But the incident showed exactly how much a single employee clicking "share" can expose.
Where Does the Law Stand on Workplace AI Use?
Workplace AI use touches two areas of law almost everywhere: data protection and employment law. Regulators across the EU, UK, and beyond have started issuing explicit guidance on generative AI and personal data, some of it naming "shadow AI" directly. The days of "there's no rule yet, so we're fine" are over.
Data protection authorities are increasingly explicit that a tool like ChatGPT, with servers and processing outside your jurisdiction, can turn a simple prompt into a cross-border transfer of personal data the moment you paste in a customer's name or a colleague's details. Under GDPR-style frameworks, that triggers requirements around lawful basis, transfer safeguards, and in many cases a formal risk assessment before the tool is used with real data at all. "I just asked it a question" is, legally, often a data transfer.
Employment law adds its own layer. Entering confidential company or client data into an unauthorized AI tool can be treated as a breach of the duty of loyalty or confidentiality that most employment contracts carry, and in serious cases, trade secrets or client personal data, it can support disciplinary action or termination for cause. But the other side of that coin is what actually matters to employers: to enforce any of this, you typically need a written, distributed policy that predates the violation. No rule, no case.
Why Banning It Doesn't Work
A ban doesn't reduce AI use, it just makes it invisible. Block the tool on the company laptop and an employee opens it on their phone instead, outside IT's view, on a free account, in the riskiest possible way. KPMG's 57% concealment figure is basically a snapshot of exactly this dynamic.
Banning also carries an opportunity cost. The same research shows employees use AI because it genuinely saves them time. A company that bans it pushes the risk underground and gives up the productivity gain in the same stroke. Even government bodies have shifted position: the UK's Department for Work and Pensions dropped its ChatGPT ban in favor of an "acceptable use policy," which tells you which way the wind is blowing even in the public sector.
Here's the pattern we keep seeing in client work: ban something people genuinely need and it goes underground; allow it with clear rules and it stays manageable.
How to Write a Company AI Policy: A 9-Part Framework
A good company AI policy should fit on a single page but still cover nine areas: purpose and scope, definitions, approved tools, prohibited data types, prohibited uses, verification requirements, data and IP terms, a violation process, and a training calendar. This structure lines up with NIST's AI Risk Management Framework and the acceptable-use controls in ISO/IEC 42001.
Here's how to fill in each section:
- 1. Purpose and scope: Who does this cover? Full-time staff, contractors, interns, agencies, list everyone. Which systems are in scope: chatbots, coding assistants, image generators?
- 2. Definitions: Define "generative AI," "sensitive data," and "approved tool" so nobody can argue about it later.
- 3. List of approved tools: Name the tool and account type together: "ChatGPT Business account, approved. Free personal ChatGPT account, not approved." Keep the list a living document and revisit it quarterly.
- 4. Prohibited data types: government ID numbers and any customer personal data, financial statements, source code, contracts, health data, trade secrets. The sentence "none of this goes into any AI tool" should be impossible to misread.
- 5. Prohibited uses: a clear "never" list. Never let AI make a hiring or firing decision. Never send AI output straight to a customer unreviewed. Never let AI draft a client contract that goes out for signature without a human reading it first.
- 6. Verification requirement: which outputs can never leave the building without human review? Anything customer-facing, legal text, financial calculations. Remember KPMG's finding that two-thirds of employees never verify AI answers at all.
- 7. Data and IP terms: get a contractual guarantee from your vendor that your inputs aren't used for model training, and clarify who owns work product created with AI assistance.
- 8. Violations and enforcement: a graduated process, notify, correct, escalate to discipline on repeat. The point is practical: make "I accidentally pasted this in" something an employee can report without fearing punishment, not something to hide out of fear.
- 9. Training and review: at least one training session a year, a policy review every six months. KPMG's data backs this up too, fewer than half of employees have had any formal AI training.
Enterprise Account or Personal Account? What the Numbers Say
Enterprise AI accounts cost less than most people assume, and what actually sets them apart from a free account is the contractual data guarantee that comes with the plan. ChatGPT Business runs roughly $25 to $30 per user per month, Google Workspace plans that include Gemini start around $14, and Claude's enterprise plans sit in a similar range.
All three come with something free accounts don't: a contractual guarantee that your inputs aren't used to train the model.
Run the numbers and a 10-person team on ChatGPT Business comes out to roughly $3,000 a year. Compare that to the cost of a single customer data leak, regulatory fines, reputational damage, lost clients, and the enterprise account stops looking like a luxury and starts looking like insurance.
Frequently Asked Questions
Can employees use ChatGPT at work?
Yes, within a written policy set by the employer. Without one, usage sits in a gray zone: employees risk disciplinary consequences, employers risk unmonitored data leaks. A clearly bounded permission fixes that far more reliably than an outright ban.
Is it safe to put company data into ChatGPT?
Not on a free personal account. Depending on settings, that data can be used for training, and the 2025 indexing incident showed exactly what sharing features can expose. Enterprise accounts come with a contractual "not used for training" guarantee, but data on the prohibited list, personal data, trade secrets, shouldn't go into any account, ever.
Who should write the policy?
Ideally three people: a manager who knows the workflows, legal counsel for the data protection angle, and someone technical who actually knows the tools. It's not a massive project. A first draft can come together in a week using the framework above. Don't wait for perfect: a policy that exists and gets updated beats a flawless one that never gets written.
So What Should You Actually Do?
Five steps you can start this week:
- Take a snapshot first: run an anonymous survey asking your team which AI tools they use and for what. Curious tone, not punitive, the goal is to make the shadow usage visible.
- Announce the red lines immediately: while the full policy is in progress, publish a one-line interim rule: "Customer data, personal data, and source code never go into any AI tool."
- Write your policy using the nine-part framework above and have every employee sign off on it. That's the step that actually strengthens your position under employment law.
- Move your most-used tool to an enterprise account: $25 to $30 per person per month is cheap insurance against the data risk of free accounts.
- Put an annual training session and a six-monthly policy review on the calendar now. Tools keep changing, your policy has to keep up.
In short: your employees are already using AI. The only question is whether it happens under your rules or by chance. Samsung needed three years to reach that conclusion. You can get there in three weeks.

Written by
Muhammet Fatih Batman
Founder & Editor
Founder of YZ Uzman, with 20+ years of experience in web design and software development.
Comments
No comments yet. Be the first to comment!