Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

AI privacy & governance

Do you need an AI policy before employees use ChatGPT?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

Yes. Before employees use ChatGPT or any generative AI tool, you should have a written AI policy that states which tools are approved, what data may and may not be entered, and how outputs must be reviewed. Without one, staff routinely paste client records, source code, or personal information into consumer tools whose default settings can use that data to train models — creating privacy, confidentiality, and contractual exposure you cannot easily undo.

On this page

Why do you need an AI policy before employees use ChatGPT?

You need an AI policy because, without one, employees will use generative AI anyway — and they will make reasonable-sounding decisions that quietly create real risk. The question is not whether your team uses ChatGPT, but whether they do so under rules you set or under assumptions you never made.

The core problem is data flow. Anything typed into a consumer AI tool leaves your control and travels to a third-party provider. Depending on the product tier and settings, that input may be retained, reviewed by people, or used to train future models. When the input is a client's personal information, a patient record, unreleased financial data, or proprietary code, a single prompt can breach confidentiality obligations, contractual commitments, or privacy law — quietly, and at scale.

A policy converts vague worry into clear permissions. It tells people which tools are approved, what they may enter, what they must never enter, and who to ask when they are unsure. That clarity protects the organization and protects employees, who otherwise carry the judgement call alone.

What are the real risks of unmanaged ChatGPT use?

The real risks of unmanaged AI use fall into a few predictable categories. Naming them helps you write a policy that addresses what actually goes wrong rather than abstract fears.

  • Data leakage: staff paste personal information, health data, customer lists, contracts, or source code into a tool whose default settings may retain or train on it. On the consumer tiers of ChatGPT (Free, Plus, Pro), inputs are used to improve the models by default unless the user turns off the setting in Data Controls — most employees never check.
  • Confidentiality and contract breaches: many enterprise, healthcare, and government contracts restrict where data may be processed and prohibit unapproved sub-processors. Feeding their data into an unvetted AI tool can violate those terms.
  • Privacy-law exposure: entering identifiable personal information into a third-party tool is a disclosure. Under PIPEDA, Quebec's Law 25, PHIPA, and similar regimes, that disclosure needs a lawful basis, appropriate safeguards, and often a documented assessment.
  • Inaccurate or fabricated output: generative models confidently invent facts, citations, and figures. Acting on unreviewed output can produce wrong advice, biased decisions, or reputational harm.
  • Shadow AI: when no approved path exists, people quietly adopt free tools and browser plug-ins, and you lose all visibility into where your data is going.
  • Bias and fairness: AI used in hiring, lending, or service decisions can produce discriminatory outcomes that create legal and ethical liability.

What should an AI acceptable-use policy cover?

A practical AI acceptable-use policy should be short enough to read and specific enough to follow. It should answer the questions an employee actually has at the moment they are about to paste something into a chatbot.

  • Approved tools: a named list of permitted AI tools and tiers (for example, a paid or enterprise tier with training-on-input disabled and a data-processing agreement in place), plus a simple route to request new ones.
  • Data classification rules: explicit categories of information that must never be entered into AI tools — personal and health information, client confidential data, credentials, source code, and anything covered by a non-disclosure or vendor contract — plus what is generally safe.
  • Human-in-the-loop review: a requirement that a person verifies AI output for accuracy, bias, and confidentiality before it is used, shared, or published, with stricter review for customer-facing or decision-making uses.
  • Disclosure and transparency: when and how to disclose AI use to clients, in deliverables, or to individuals affected by an AI-assisted decision.
  • Prohibited uses: high-risk applications (such as automated decisions about people, or processing of sensitive data) that require sign-off or are banned outright.
  • Accountability: a named owner for AI governance, a way to report problems or near-misses, and the consequences of policy breaches.
  • Training and acknowledgement: confirmation that staff have read the policy and understand how to apply it.

How do you roll out an AI policy without blocking productivity?

The goal is to enable safe AI use, not to ban it — a policy that simply says "no" pushes usage underground and forfeits real benefits. The most effective rollouts pair clear rules with an approved, easy path to get work done.

Start by giving people a sanctioned tool. Providing an enterprise or paid AI tier with training disabled and contractual protections in place removes the main reason employees reach for unmanaged consumer apps. Pair it with plain-language do's and don'ts and a few concrete examples for each team — what a marketer, a developer, and a client-services lead can and cannot paste in.

Then make the policy a living document. AI tools, settings, and laws change quickly, so assign an owner, review the policy on a set cadence, and keep a lightweight process for approving new tools. Reinforce it with short, role-specific training so the rules are understood, not just published. For uses that touch personal or sensitive data, a focused assessment of the tool and data flow turns the policy from words into evidence you can show clients and regulators.

When does a policy need to be backed by a formal AI assessment?

A policy is the right starting point for everyday productivity use, but some uses warrant a formal assessment on top of it. The trigger is the nature of the data and the decision: the more sensitive the information or the more consequential the output, the more you need documented diligence rather than a general rule.

An AI privacy impact assessment (AI-PIA) examines a specific AI use — what data goes in, where it is processed, what the model does, and what could go wrong for individuals — and documents the safeguards. It is increasingly expected when AI touches personal or health information, when it informs decisions about people, or when enterprise, healthcare, or government buyers ask how you govern AI. The same methodology that public bodies use for privacy impact assessments is becoming best practice in the private sector, even where it is not strictly mandated.

In short: use an AI acceptable-use policy to set the baseline for all staff, and layer an AI-PIA or broader governance framework onto the specific, higher-risk uses. Privacy Horizon helps organizations write the policy, assess the high-risk uses, and train teams so AI adoption stays fast and defensible.

Frequently asked questions

It can be. Entering identifiable personal or health information into a consumer AI tool is a disclosure to a third party, which under laws like PIPEDA, Law 25, and PHIPA requires a lawful basis and appropriate safeguards. Using a properly configured enterprise tool under a clear policy, with sensitive data kept out, sharply reduces that risk.

By default, yes. On the consumer ChatGPT tiers (Free, Plus, Pro), inputs are used to improve OpenAI's models unless the user turns off the training setting in Data Controls, and most employees never do. Enterprise, Business, and Edu tiers, plus the API, exclude inputs from training by default and offer contractual data protections, which is why an approved, properly configured tool should be part of your policy.

Banning rarely works. It pushes employees to unmanaged personal accounts and browser plug-ins, so you lose all visibility into where company data goes. A clear policy plus a sanctioned, well-configured tool is far safer and lets your team capture the productivity benefits.

A focused acceptable-use policy can usually be drafted and approved in a matter of weeks, depending on how many teams and use cases you need to cover and your approval process. Higher-risk uses that need a formal AI-PIA take longer because they involve assessing specific data flows and safeguards.

An AI policy is a concise set of rules telling staff how to use AI safely day to day. An AI governance framework is broader — it covers roles, risk assessment, approvals, monitoring, and accountability across the organization. Most teams start with a policy and grow into a framework as AI use expands.

AI privacy & governance

When do you need an AI Privacy Impact Assessment (AI-PIA)?

When do you need an AI Privacy Impact Assessment (AI-PIA)? The triggers, timing, and how an AI-PIA differs from a standard PIA — explained in plain language.

Read
AI privacy & governance

Does a small business need an AI governance framework?

Does a small business need an AI governance framework? Yes if it uses or builds AI. Learn what to put in place, when, and how to keep it proportionate.

Read
Enterprise sales & vendor reviews

How do you assess the privacy and security risk of an AI vendor?

How do you assess the privacy and security risk of an AI vendor? A framework covering data use, training, hosting, contracts, and security evidence.

Read
AI privacy & governance

Can you use AI scribes in healthcare while protecting PHI?

Can you use AI scribes in healthcare while protecting PHI? Yes, with patient consent, vendor due diligence, an AI-PIA, and the right safeguards. Here's how.

Read
Privacy & security assessments

What's involved in a Privacy Impact Assessment: inputs, timeline, and cost?

What's involved in a Privacy Impact Assessment — the inputs, timeline, and cost drivers of a PIA, and how to scope one for your project or product.

Read
Privacy & security assessments

When should you do a Privacy Impact Assessment in the product development lifecycle?

When should you do a Privacy Impact Assessment in the product development lifecycle? Start at design, finish before launch, and refresh when data handling changes.

Read

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.