We use cookies

We use essential cookies to run this site, and, with your permission, analytics and advertising cookies to understand how it is used and improve our marketing. Cookie Policy

All news

News

Is it safe to let your staff use ChatGPT and Copilot at work?

By Daniel RosieOctober 20266 min read
Is it safe to let your staff use ChatGPT and Copilot at work?

In short

Most staff already use AI at work, approved or not. The rules, policy and training that make ChatGPT and Copilot safe to use.

Yes, it can be, as long as staff use tools your organisation has approved, keep personal and confidential data out of anything that isn't, and check every output before it's used. In our experience, banning AI rarely works, because people tend to use it anyway. Clear rules and practical training are what make it safe.

This is general information rather than legal advice, and your own data protection lead should have the final say on your policies. But the basics are much the same for most organisations, from a ten-person firm to a council department.

Are your staff already using AI?

Probably, whether you've approved it or not. Microsoft and LinkedIn's 2024 Work Trend Index, which surveyed 31,000 people across 31 countries, found that 75% of knowledge workers use AI at work and that 78% of AI users bring their own AI tools to work. Plenty of people are pasting work into whatever free tool they've found, without anyone checking what goes in.

The UK picture looks similar. The ONS reported in July 2026 that 55% of employees say they use AI for work or education. Yet only 11% of businesses with 10 or more employees say more than half their workforce has received AI-related training. Staff are picking up AI faster than their employers are training them to use it.

What are the real risks?

Most of them come down to three things.

The first is data. When someone pastes a client email, a payroll spreadsheet or a draft contract into a consumer AI tool, that information has left your control, and depending on the tool and its settings it may be stored or used in ways your organisation never agreed to. Your organisation is still responsible for the personal data it handles, and the ICO's guidance on using AI and personal data from 2022 makes the point that working with an outside supplier doesn't remove your data protection responsibilities.

The second is accuracy. AI tools write fluently and confidently, even when they're wrong. A made-up figure, a misread policy or a summary that drops the key caveat can slip into a client letter or a board paper if nobody checks.

The third is judgement. AI is good at drafting and summarising. It shouldn't be deciding who gets hired, which supplier wins or how a complaint is resolved. When decisions affect people, a person needs to make them and be able to explain them.

Is Copilot safer than ChatGPT?

The tool matters less than how it's set up and who approved it. Business versions of AI tools, such as Microsoft 365 Copilot inside your organisation's own Microsoft setup or a business ChatGPT plan, usually come with business data terms and admin controls that free personal accounts don't have. Your IT team or supplier can tell you exactly what applies to your licences.

So the first rule in most policies is a simple one: for work, use the tools we've approved, signed in with your work account, and nothing else.

What should an AI policy for staff include?

It doesn't need to be long. A one or two page policy that people actually read beats a twenty-page document nobody opens. Most good ones cover the same ground:

  • Which AI tools are approved, and how to ask for a new one
  • What must never go into any AI tool, such as special category data, passwords and bank details
  • What can go into approved tools, and what still needs care
  • Who checks outputs before they're used outside the organisation
  • Which decisions always stay with people
  • Who to ask when you're unsure.

The same ICO guidance takes a risk-based approach and is clear that "You must complete a DPIA when your processing is likely to result in high risk to people." If you're planning to use AI on personal data in a bigger way, that's a conversation to have with your data protection lead before you start.

Why does training matter as much as the policy?

A policy tells people what not to do. Training shows them what to do instead, and that's what changes behaviour. If staff don't know how to get a useful answer from the approved tool, they'll drift back to the free one that seemed to work.

Most organisations aren't there yet. The Work Trend Index found only 39% of AI users had received AI training from their company.

Good training puts safe use inside every exercise rather than on a slide at the end. People practise on realistic versions of their own work, learn what to strip out before they paste anything and build the habit of checking what comes back. Once that's routine, AI stops feeling risky and starts saving time.

Where should we start?

With the people most likely to handle sensitive information: HR, finance, customer service and anyone working with client files. Then widen it out to everyone else.

Our AI training for staff is hands-on and built around your own tasks and policies, for groups of up to 12, at your premises anywhere in the UK, at a venue or online. Our AI training for finance teams and AI training for HR teams go further on data protection, because those teams hold some of the most sensitive information in any organisation. Teams with Copilot licences usually start with Microsoft Copilot for Business.

DLR Media has committed to the Responsible AI Use Campaign's 10 principles, which include human oversight, transparency, privacy, security, fairness and accuracy, and we're registered with the ICO as a data controller. We hold ourselves to the same standards we teach.

Frequently asked questions

Can staff use ChatGPT at work?

Yes, if your organisation approves it and staff follow clear rules on what data goes in. Many organisations prefer a business plan, or Copilot within Microsoft 365, over free personal accounts.

Should we ban AI tools at work?

Usually not. Research suggests most staff who use AI bring their own tools, so a ban risks pushing that use out of sight. Approved tools, a short policy and training work better.

What should staff never put into an AI tool?

Personal or special category data, passwords, bank details and confidential client or commercial information, unless the tool is approved for it. Your policy should spell this out.

How long does safe AI training take?

A half day covers the essentials for most teams, with safe use built into every exercise. A full day or a short series gives more time to practise.

Get your team using AI safely

Want a session your team will actually use? Tell us which tools you have and which teams handle sensitive data. Call +44 1382 699595 or tell us about your team.

Share