If you haven't rolled out AI at work, your staff have done it for you. Usually on the free tools, sometimes with data that shouldn't be anywhere near them.
Somewhere in your business this week, someone pasted something into ChatGPT that they probably shouldn't have. A customer list, to tidy up the formatting. A supplier contract, to make sense of the awkward clause. A half-written appraisal, a page of figures, a chunk of code. Not out of carelessness. Out of the very ordinary wish to get a fiddly job done before lunch.
This is the part most business owners miss. You can decide not to "do AI" yet, but your staff have already decided for you. The tools are free, they are one browser tab away, and they are good at exactly the small jobs that eat people's afternoons. Telling yourself the business hasn't adopted AI does not make it true. It means the adoption is happening somewhere you can't see it.
That would be fine if the free tools kept your data to themselves, but that’s is not always the case.
Where the words go
When someone types into a free, personal AI account, the default settings tend to work against you.
OpenAI is plain about it: "ChatGPT... improves by further training on the conversations people have with it, unless you opt out." Anthropic, the maker of Claude, will "train new models using data from Free, Pro, and Max accounts when this setting is on," and when it is on, it keeps that data for up to five years. Google's Gemini can send a share of chats to human reviewers, including outside contractors, and hold on to them for up to three years, even after the user deletes the conversation.
Your instinct might be that there is an opt-out, and you would be right. All three let you turn training off. However, opting out of training is not the same as your data staying in-house. It has still left your company, landed on someone else's servers, which might be in another country, and in most cases sits there for a while whatever the toggle says.
There is a pattern underneath all this. These companies treat personal accounts and business accounts very differently. On the paid business tiers, the same providers say plainly that they do not train on your data by default. OpenAI again: "By default, we do not train on any inputs or outputs from our products for business users." The protection you actually want already exists. It just lives on the side of the product your staff aren't using.
Why banning it makes things worse
The obvious reaction is a stern email. No AI tools. Please and thank you.
It won't work, and it will cost you the little visibility you had. People who have found something that saves them an hour a day do not stop. They move it onto their phone, a personal account, the laptop at home, somewhere your email cannot reach. You have not removed the risk. You have pushed it into the dark and given away any chance of managing it. That is what people mean by "shadow AI," and a ban is the surest way to grow it.
The businesses handling this well are doing the opposite of banning. They are making the safe way the easy way.
How to bring it in without the exposure
You do not need a committee or a six-month programme. You need a few sensible moves, in order.
- Assume it is already happening, and ask your team what they're using and what they are using it for.
- Give people a proper tool. Put a paid business or team account in front of them, set up so the provider does not train on your data. When the sanctioned tool is as good as the free one, the reason to reach for a personal account disappears.
- Write the boundary down in plain English. What it is fine to use it for, and what never goes in, e.g. customer and staff personal details, anything covered by a contract or an NDA, passwords, figures you would not email to a stranger.
- Set it up once, properly. Turn training off, set retention sensibly, keep the accounts under company control rather than personal logins. It is an hour of admin that removes most of the exposure.
- Show them how, briefly. A short session on what these tools are good and bad at does more for safety than any policy document. Most mistakes come from not understanding the tool, not from bad intent.
There is a data protection angle too. If you handle customer or employee information under UK GDPR, putting that data into a consumer AI account, with no agreement in place over how it is stored or used, is the sort of thing that gets uncomfortable if anyone ever asks. It's worth a conversation with whoever owns data protection in your business before it becomes a problem rather than after.
None of this is about being first with AI, or clever with it. It is the same thing the rest of running a business comes down to: knowing what is actually going on, and putting a sensible line around it. The tools are already in the building. The only real choice is whether you manage them or carry on pretending they aren't there.
Disclaimer: AI helped write this article, but the thoughts and experiences are my own.
