Skip to main content

ChatGPT, Copilot or your own AI?

There are three ways to bring AI into a company. Which one fits depends on the task, and often two are used side by side.

6 min read

Woman working on a laptop by a window

Key points

  • General AI assistants such as ChatGPT are suited to text, ideas and research, with a business account and a suitable contract.
  • With a Copilot licence, Copilot in Microsoft 365 works with your documents, emails and calendar, using the permissions of each individual user.
  • Your own application pays off when a task comes up often and needs your own knowledge.

There are three ways to bring AI into a company: a general AI assistant such as ChatGPT, Claude or Gemini, Copilot in Microsoft 365, or your own AI application for a specific task. Many companies use two of them side by side.

Which way fits depends on the task. How much internal knowledge does it need, how often does it come up and where is the data stored today? Whether an option complies with data protection law then depends above all on the contract, the settings and the rules.

General AI assistants

ChatGPT, Claude and Gemini are versatile: writing drafts, summarising, translating, collecting ideas. They know your company only from what you type into the prompt or upload. To use them in a team, you need a business account with a suitable contract.

For ChatGPT Business, ChatGPT Enterprise and the API platform, OpenAI states that it does not use business data for training by default. For these three, OpenAI offers a Data Processing Addendum, in other words a data processing agreement (DPA) under Article 28 GDPR. According to OpenAI, data from its versions for individuals is also used for training.

Two points need settling before rollout. In ChatGPT Business, workspace admins can view, export and delete users' conversations. Tell your team openly who can do this and for what purpose. Admins also decide how long conversations are retained. According to OpenAI, deleted conversations are removed within 30 days, apart from legal and a few other exceptions.

Copilot in Microsoft 365

If your company works with Microsoft 365, Copilot can access documents, emails and calendar entries with the paid Copilot licence, using the permissions of each individual user. For this, permissions must be set up properly: whatever someone is allowed to see, Copilot will find too. Microsoft states that Copilot only surfaces organisational data to which the individual user has at least view permissions.

On data protection, Microsoft states the following: prompts, responses and data accessed through Microsoft Graph are not used to train the underlying language models. For users in the EU, traffic stays within the EU Data Boundary. Models from Anthropic, which are provided as sub-processors, are currently excluded from this. Administrators decide whether such third-party models are used. Microsoft has since renamed the product “Microsoft Copilot”, and some licences still show the old name.

A simple test before launch: a person without special permissions asks Copilot about salaries, personnel files or dismissals. Whatever comes up is already findable for that person today. Restrict such sharing in SharePoint, OneDrive and Teams before Copilot is rolled out to everyone.

Your own AI application

Your own application is tailored to one task, such as drafting quotes from your templates or answering new colleagues' questions from the staff handbook. It works with your knowledge, can show the source of its answers and can be run in the EU if you wish.

Such an application often combines a language model with a collection of your own documents. The technical term is retrieval-augmented generation, or RAG. The German Data Protection Conference (DSK) published an orientation guide on this in October 2025. According to the guide, established access rights and role concepts can be applied in the document collection, but not in the language model itself. The method can reduce incorrect answers to a certain extent and in many cases makes it possible to run the language model in-house.

If you have such an application developed and use it under your own name, you count as a provider under the EU AI Act. For most applications this means few additional obligations. It still belongs in the planning.

How to decide

General assistantwhen many different tasks come up and little internal knowledge is needed
Copilotwhen you use Microsoft 365, permissions are set up properly and it is clear which models are approved
Your own applicationwhen a task comes up often, needs your knowledge and has to run reliably

How to assign a specific task:

  • If the task needs no internal documents, such as a draft for a specialist article, a general assistant is enough.
  • If the documents you need are already in Outlook, Teams or SharePoint and the permissions are right, Copilot saves you uploading them.
  • If the same task comes up every week, uses fixed templates and the result has to be traceable, consider your own application.
The task decides which tool fits.
The task decides which tool fits.

Example: one quote, three ways

A planning consultancy with 15 employees writes several quotes every week. They are based on an enquiry by email, standard text blocks for services and previous quotes.

With a general assistant, someone copies the enquiry without the customer's name, together with the relevant text blocks, into the prompt and asks for a draft. That works. But the quality depends each time on which blocks the person picks and includes.

With Copilot, the prompt might read: “Draft a quote based on today's enquiry and our ‘Planning quote’ template.” Copilot finds the email and the template itself, provided the person has access to them. The quality depends on how tidy the file storage is.

With your own application, the team selects the enquiry. The application knows all approved text blocks, suggests the right ones and shows which template each paragraph comes from. The development effort can pay off because the task comes up every week.

In all three cases a person checks the draft before it leaves the company.

Checklist before approval

You can put these questions to any provider, whether of an assistant, Copilot or a development partner:

  • Is there a business account that we manage centrally?
  • Has a data processing agreement been concluded, or can one be?
  • Is training on our prompts excluded, by default or through a setting?
  • Where is the data processed, and which models or sub-processors are involved?
  • How long are prompts and outputs stored, and who in our organisation can view them?
  • For Copilot, also: have the sharing settings in SharePoint, OneDrive and Teams been checked?

Record the answers for each tool with a date. When the provider makes changes, you can then see what needs checking again.

Next steps

  • Write down the five tasks your team would use AI for most often and assign each one to an option using the three “if” questions.
  • Work through the checklist for the option you have chosen.
  • If Copilot is an option, run the permissions test with a person who has no special permissions.
  • If a task looks like a case for your own application, describe it on one page: input, documents, desired result, who checks it.

Which data belongs in a prompt is covered in the article AI and the GDPR: which data you may enter. How such a project runs is described in the article How an AI project works. Which task takes up the most time in your company every week?

Frequently asked questions

Which is more secure?

That depends less on the tool than on the contract, the settings and the rules. All three options can be used in line with data protection law.

Do we need all three?

No. Many start with an assistant for everyone and add their own application for the one task that takes the most time.

How long does your own application take?

A first draft that your team can use itself is created in a two-day workshop. Afterwards you know whether the approach holds up.

Is an individual ChatGPT account enough for people in the team?

Not for working with personal data. According to OpenAI, it offers a data processing agreement for ChatGPT Business, ChatGPT Enterprise and the API. OpenAI also uses data from its versions for individuals for training.

Does Microsoft train on our data?

According to Microsoft, no. Prompts, responses and data accessed through Microsoft Graph are not used to train the underlying language models. Microsoft may use optional feedback to improve Copilot.

Sources

  1. Microsoft: Data, privacy and security for Microsoft 365 Copilot
  2. Microsoft: Copilot overview
  3. OpenAI: Enterprise privacy
  4. Orientation guide on generative AI systems using the RAG method, German Data Protection Conference (DSK), October 2025 (in German)

Updated: . This article is not legal advice.

From idea to first applicationTwo days · one of your tasks becomes a draft you can operate yourself
See the workshop

Read next

Questions about your situation?

In a first call we discuss your questions and possible next steps. 30 minutes, no obligation, by phone or video.