Can Employees Use ChatGPT With Company Data?
Someone in your business is already using it. That is not a guess — surveys consistently find that the share of companies where staff use AI tools is far higher than the share that have approved any. The gap between those two numbers is where the problem lives.
Can employees use ChatGPT with company data?
With a personal account, no — you cannot see what was pasted, you have no retention terms, and client information disclosed to a third party without authorisation is your liability, not the employee’s. With a business tier and a one-page policy, yes, and it is usually worth doing. The tool is not the risk; the account is.
We ran this check on ourselves first
Before offering this to anyone, we audited our own Microsoft 365 tenant to see which AI tools already held access to our data. We found ChatGPT holding permission to read every file we owned and every SharePoint site.
Nobody had done anything wrong. One person had signed in with their work account and clicked Accept, months earlier, and the permission simply sat there. There was no alert, no expiry, and nothing in any dashboard that would have surfaced it. We revoked it and tightened the consent policy the same day.
We mention it because it is the honest version of this conversation. This is not a story about reckless employees. It is a story about a default setting that lets any user grant a third party access to the whole business in two clicks.
The three questions worth answering this month
1. Can any of your staff grant an app access to company data without asking?
In most Microsoft 365 tenants, out of the box, yes. This is the finding that matters more than any individual app, because if self-consent is open then whatever list you produce today is only today’s list. Tomorrow’s is unknown.
There are three states, not two: fully open, limited to low-impact permissions from verified publishers, or locked so an administrator approves everything. Most small businesses are in the first and assume they are in the third. Limited is a reasonable place for most businesses to land.
2. What already holds access?
Not just the obvious chatbots. Meeting recorders are the ones that surprise people — a note-taker joined a call once, was granted calendar access, and is still there. Automation tools count too. Ask for the actual list, with the permissions each one holds and who granted it.
Changing the policy does not revoke what was already granted. Existing permissions survive, and have to be removed deliberately. That catches people out.
3. Is there one page telling staff what is allowed?
Which tools are approved, which categories of information may never go into a prompt, which account tier is required, and who to ask when a new tool appears. One page. A policy nobody finishes reading is not a control, and a policy that just says “do not use AI” is ignored rather than followed.
Why the honest answer is not “ban it”
Bans push usage onto personal accounts and personal devices, where you have no visibility at all. That is strictly worse than the situation you started with. The workable position is a short approved list, a business tier where the terms are on your side, sensible defaults, and a review that happens more than once.
The businesses that get value out of AI in the next few years will be the ones that made it safe to use rather than the ones that pretended it was not happening. That is genuinely the more commercially interesting half of this, and it is where we would rather spend the time.
What we do about it
We run an AI exposure audit against your Microsoft 365 tenant. It reports facts rather than adjectives: whether users can self-consent, which AI-related applications hold permissions, exactly what each can reach, and who approved it. It takes about ninety seconds to run and rather longer to talk through.
If it comes back clean, we will say so plainly. That happens, and an audit that only ever finds problems is not an audit. If it does not come back clean, the fixes are usually configuration rather than purchases — which is why we are comfortable leading with it.
There is also a short readiness assessment you can work through yourself, and more on how we approach AI consulting. If you would like the audit run against your tenant, get in touch — (321) 221-7117, Monday to Friday, 8am to 6pm.
General information, not legal advice.
Related: is it legal to use an AI note-taker in Florida? — the same consent problem, with a state statute attached.

