Employees use ChatGPT at work. Learn what company, customer and personal data needs proper controls, and how a practical AI policy can reduce business risk.
The GDPR still applies when AI is involved
An employee needs to summarise a document. They paste it into an AI tool, get the answer in seconds and move on. But the document may contain a customer name, employee details, a confidential contract or commercially sensitive information.
For many businesses, the biggest everyday AI risk is not a complex high-risk system. It is employees placing information into a third-party tool without knowing the processing arrangements or the rules that apply.
Where personal data is involved, the GDPR still applies. Ireland's Data Protection Commission says organisations should understand what personal data an AI product uses, how it uses it, where the data goes when a third party is involved, whether the provider retains or reuses it, and whether the organisation can meet its GDPR duties.
Depending on the use, the business may be a controller and should consider whether a formal risk assessment or Data Protection Impact Assessment is needed. The answer depends on the data, purpose, scale and likely effect on people.
Not all company information is personal data. Confidentiality, security, contractual duties and trade-secret protection may still apply even where the GDPR is not the main issue.
What information deserves particular caution?
Employees should not assume that an easy-to-access AI tool is suitable for every task. Particular caution is needed before placing the following information into a public or unapproved AI service.
The right rule depends on the product, its settings, the organisation's contract, the purpose of the processing and the controls in place. An approved enterprise tool may change the risk, but it does not make every input automatically appropriate. That is why 'be careful with ChatGPT' is rarely enough.
- Customer or employee personal data.
- CVs, candidate records and interview notes.
- Health information or other special-category personal data.
- Confidential contracts, client documents or legal advice.
- Commercially sensitive, financial or strategic information.
- Passwords, credentials, security configurations or incident details.
- Trade secrets, proprietary source code or unpublished product information.
There is another risk: the answer
Information going into AI is only half the problem. The DPC also highlights that large language models can produce inaccurate or biased information. Relying on those outputs without critical human analysis can introduce further risk, particularly when an output influences a decision.
Staff should know when factual claims, calculations, citations, customer communications and consequential recommendations must be checked before they are relied upon or shared.
This connects with Article 4 of the EU AI Act. Providers and deployers must take measures supporting the development of AI literacy among staff and others using AI on their behalf. The rule has applied since 2 February 2025, and its enforcement framework began applying on 2 August 2026. Following the July 2026 amendment, organisations do not have to guarantee a specific level of literacy for every individual.
An effective AI policy therefore needs rules for both sides: what may go into AI, and what may be trusted coming out of it.
Four things businesses can do now
- Define prohibited inputs. State clearly which information must not be entered into public or unapproved AI tools.
- Approve specific tools. Employees should know which systems the organisation has assessed and authorised, and for which purposes.
- Require verification. Important AI-generated information should be checked before it influences a decision or reaches a customer.
- Train with real examples. 'Never upload a candidate CV into an unapproved AI tool' is more useful than 'use AI responsibly'.
Blanche perspective
Most employees are not trying to create a compliance problem. They are trying to save time. Banning AI outright is often unrealistic, while having no rules is increasingly difficult to defend.
The better approach is practical: give employees useful AI tools, clear boundaries and enough knowledge to use them safely. A good AI policy makes the safe option the easy option.
The policy should distinguish approved tools from unapproved services, explain what information may be used, and give staff a simple route to escalate a useful but unusual AI use before taking the risk themselves.
Blanche AI Essentials helps businesses establish an AI Usage Policy, practical staff rules, AI literacy guidance, verification requirements and a clear incident process. Or start with the Blanche AI Risk Check.
Sources
Primary and authoritative sources used for this Insight.