Is it safe to put client data into ChatGPT?
Short answer
Not in the free or personal versions. Consumer AI tools can keep what you type and may use it to improve their models, and you have no contract covering it. Business versions, such as Microsoft 365 Copilot or ChatGPT Business and Enterprise, don't train on your data and come with commercial terms. Even then, a written policy should say what data is allowed.
Draft · pending expert review
The risk isn't that AI is dangerous. It's that a personal account is a place your organization doesn't control, with terms your organization never agreed to.
Personal and free versions
- Conversations can be stored and, unless someone turns it off, used to train future models
- There's no business agreement, so there's nothing to point to if a client asks where their data went
- When the employee leaves, the history leaves with them
Business versions
Microsoft 365 Copilot, Copilot Chat signed in with a work account, and ChatGPT Business or Enterprise don't use your prompts to train models, and they're covered by commercial terms. Copilot also stays inside your Microsoft 365 tenant and respects the permissions you already have.
What to do this month
- Pick an approved tool and make it easy to get to
- Write a one-page policy: approved tools, and data that never goes in (passwords, client financials, health information, anything under NDA)
- Tell people why, not just what
Watch how
All video tutorialsHOW TO Enable ONEDRIVE on startup2023 How to Create a Rule in Outlook to Delete Emails2016 · recorded on an older version; menus may look different How to Select All Emails in Outlook2016 · recorded on an older version; menus may look different