You can't prevent it with a policy alone. You need three things working together: a data classification system that removes guesswork, a written policy with specific examples your team can follow under pressure and a sanctioned AI tool that makes the safe option easier than the unsafe one.
Your Team Is Already Using ChatGPT With Company Data
Before you write a single rule, accept one uncomfortable fact: your employees are almost certainly already pasting sensitive business data into ChatGPT, and most of them don't think they're doing anything wrong.
According to Cyberhaven's AI data exposure research, 4.2% of workers have pasted company data into AI tools, with confidential data representing 11% of what gets pasted. That's telemetry data from enterprise DLP deployments, not a self-reported survey, which would likely make the real number much larger.
The consequences aren't hypothetical. In April 2023, Samsung engineers pasted proprietary source code and internal meeting notes into ChatGPT. Samsung responded by banning the tool company-wide. The engineers weren't acting maliciously. They were trying to work faster. A sales rep drafts a follow-up email. A project manager summarizes a client call. The data goes with the task.
Every AI policy article on the internet tells you to "establish clear guidelines." That's like telling someone to "drive carefully" and handing them the keys to a forklift.
This matters more than most people think for businesses holding proprietary process data, customer pricing and supplier contracts without a dedicated security team watching for this kind of exposure. The answer is not to ban AI. Govern it with a policy your team will follow and infrastructure that makes the policy enforceable.
Step 1: Audit What Your Team Is Already Doing With AI
You cannot govern what you haven't mapped. The first step is a simple audit of how your team is currently using AI tools, before you write a single rule.
Send a short internal survey or hold a 15-minute team meet. Ask three questions: which AI tools people use, what they use them for and what kinds of information they typically include in prompts. You don't need a formal assessment.
After the audit, you'll have a map of which tools are in use (ChatGPT free, Plus, Team or Enterprise; Claude; Gemini; Copilot), which workflows involve AI and which data types are being included. That map is what your policy gets built on.
One gap to watch for: mobile usage is invisible to network-level controls. Employees who use ChatGPT on personal phones won't show up in any IT dashboard. The audit should ask about device usage, not just desktop tools.
Step 2: Classify Your Data Before Employees Have to Guess
Employees paste sensitive data into ChatGPT because nobody ever told them what "sensitive" means at their company. A four-tier data classification framework gives employees a reference they can check before pasting anything. This single asset reduces the judgment burden on individuals.
Here is an example of what the classification can look like:

Step 3: Write a Policy With Specific Examples, Not Just Rules
A policy that says "do not use AI with sensitive data" will fail the first time an employee has to make a judgment call under pressure.
Here's the difference between an unclear policy and a useful one:
Unclear: "Employees should not share confidential information with AI tools."
Specific: "Do not paste customer names, contract terms, pricing agreements, financial data or employee information into any AI tool that is not on the approved list below."
Your policy should include four things: a list of approved tools and tiers, a list of data types that are off-limits in consumer AI tools, a concrete example of a compliant prompt vs. a non-compliant one and a path for questions.
One objection worth addressing directly: "We use ChatGPT Enterprise, so we're covered." Most employees use free or Plus accounts, not enterprise tiers. Even ChatGPT Team and Enterprise require a signed Data Processing Agreement and proper configuration to be compliant. Per OpenAI's own usage policies, free and Plus accounts may use conversations to improve models unless users opt out, and most don't know to opt out.
Data sent to OpenAI may be used for training on free and Plus tiers. Data stored in conversation history is accessible to anyone with account access. Different problems, different controls.
Get HR or legal to review the policy before distributing it. A 30-minute review with whoever handles your employment agreements is enough.
Step 4: Give Your Team a Sanctioned Alternative
If you tell employees they can't use ChatGPT for a task they rely on, you need to give them something better. Otherwise they'll use ChatGPT anyway, on a personal phone, where you can't see it.
Enterprise-Tier Tools With a Data Processing Agreement
ChatGPT Team and Enterprise, Microsoft Copilot for M365 and Google Gemini for Workspace all offer enterprise tiers with DPAs that contractually limit data use for training. These are a significant step up from free or Plus accounts and are appropriate for many mid-market businesses.
The tradeoff: they cost more per user and still send data to a third-party server.
A Private AI Environment Built on Your Own Data
For businesses with genuinely sensitive data (proprietary processes, customer contracts, regulated information), a private AI deployment means the model runs on your infrastructure or a private cloud. Your data never leaves your environment.
In practice, employees use an internal tool that looks and feels similar to ChatGPT but is connected only to your company's approved data sources. No data goes to OpenAI or any third-party server.
A private AI tool built on your company's data produces better outputs than a generic model because it knows your products, your customers and your processes. When thinking about which processes to connect, it helps to understand how to automate your small business and where AI fits into existing workflows.
Step 5: Monitor Without Becoming the AI Police
The goal of monitoring is to close the gap between what the policy says and what happens in practice, before an incident forces your hand.
For businesses without a dedicated IT team, practical options include browser extension policies, periodic spot-checks of AI tool usage logs (available in enterprise tiers) and quarterly policy reviews with team leads.
Address the cultural resistance directly. Managers who don't want to be seen as anti-AI often avoid enforcing AI policies. Frame monitoring as protecting the team. A data incident affects everyone, not just the person who caused it.
FAQs
ChatGPT Enterprise does not train on your data by default and includes a Data Processing Agreement, which is a meaningful step up from free or Plus accounts. It still sends data to OpenAI's servers, requires proper configuration to be compliant and doesn't protect you if employees use personal free accounts on the side. Enterprise tier reduces risk; it doesn't eliminate it.
At minimum: customer names and contact information, contract terms and pricing agreements, employee records, financial statements, proprietary processes or formulas and any data covered by HIPAA, GDPR or other regulations. If you wouldn't post it on a public forum, it shouldn't go into a consumer AI tool.
You can block it on company-managed devices and networks, but this doesn't stop employees from using ChatGPT on personal phones or home networks. Network blocking is a useful layer, not a complete solution. It works best when paired with a written policy and a sanctioned alternative employees want to use.
A private AI tool runs on your own infrastructure or a private cloud, meaning your data never leaves your environment. It's appropriate for businesses with genuinely sensitive data (proprietary processes, customer contracts, regulated information) where even enterprise-tier third-party tools carry too much risk. It also tends to produce better outputs because it's trained on your business data.
At minimum: a list of approved AI tools and their permitted uses, a data classification reference showing which data types are off-limits in consumer tools, at least one concrete example of a compliant vs. non-compliant prompt and a clear escalation path for questions or incidents. The policy should be reviewed by HR or legal before distribution.




