Skip to main content

Can my team use ChatGPT?

Yes, with a business account and rules for your team that fit on one page.

6 min read

Woman working on a laptop in an office

Key points

  • In principle, yes: there is no general ban on using AI tools at work.
  • This takes a business account with a suitable contract, rules on data and a short training session.
  • The rules fit into a one-page AI policy. You will find a template further down.

Yes. ChatGPT, Copilot or Gemini may be used in a company. To keep this safe, your team needs three things: a business account, rules on which data may go in, and people who check the results.

A ban is rarely observed. Without rules, everyone uses their own tool with their own account. A short, binding policy sits between the two and fits on one page.

What is allowed

The limits are set mainly by data protection, trade secrets, contracts with customers and, in some professions, professional secrecy. In addition, Article 4 of the EU AI Act requires you to support the development of your employees’ AI literacy.

Where the risks lie

  • Private accounts: Without a data processing agreement (DPA) under Article 28 GDPR, no personal data may be entered. The company also has no insight into what happens to the prompts.
  • Confidential information in prompts: Customer data, quotes or internal figures do not belong in a freely available tool.
  • Unchecked results: AI writes convincingly even when something is wrong. Someone has to check before anything goes out.

The European Commission also names the third risk: anyone using ChatGPT for advertising copy or translations, for example, should be informed about the specific risks, such as hallucinations. These are invented details that sound plausible, such as a source that does not exist or a figure that appears nowhere.

The second risk is also about protecting your own information. Under the German Trade Secrets Act (GeschGehG), information is only protected as a trade secret if its holder takes reasonable confidentiality measures. A rule on what does not belong in AI tools can contribute to this.

What data can go into a prompt

Most everyday questions are about what you are allowed to enter. You can adopt this decision guide for your team and adapt it to your sector:

  • If the prompt works without any reference to individuals and without internal information, for example an outline for a talk or a draft of a general text, it is fine with the approved account.
  • If it contains names, contact details or other information about people, replace them with placeholders. If that is not possible, use only a tool covered by a data processing agreement, and enter only as much as necessary.
  • If it concerns health information, personnel files or bank details, these do not belong in a general-purpose AI tool.
  • If quotes, calculations or customer contracts are involved, enter them only after approval. Check whether your contracts include confidentiality obligations.
  • If you are bound by professional secrecy, for example in a law firm or tax advisory firm, additional rules apply, see Client data and AI.

A payment reminder shows what this looks like in practice. Before, someone writes: “Write a friendly reminder to Maria Muster, 4 Example Street, customer number 40817. She has not paid invoice 2026-118 since March and told us on the phone that she is going through a difficult time personally.” Name, address, customer number and a piece of personal information end up in the tool, even though the text does not need them.

After, the prompt reads: “Write a friendly second payment reminder to a long-standing private customer. The invoice has been outstanding for six weeks. Tone: courteous and clear, not accusatory, offering payment by instalments. Use the placeholders [Name], [Invoice number] and [Amount].” These details are enough for the text. The employee only adds the real details later, in her own software.

Which account you need

For work in a company, a business account is the better choice than a free version with a private account. Business versions usually offer a data processing agreement and exclude training on your prompts by default. Check this with the provider before you approve a tool, for example with these questions:

  • Is there a data processing agreement under Article 28 GDPR, and where do we sign it?
  • Are our prompts used for training, and can this be excluded?
  • Where is the data processed and how long is it stored?
  • Can we manage accounts centrally and block them when employees leave?

Which tool suits which task is compared in our article ChatGPT, Copilot or your own AI? For what belongs in the contract, see Data processing agreements with AI providers.

What belongs in an AI policy

A good policy fits on one page and answers five questions:

  • Which tools are approved, and with which account?
  • Which data may go in, and which never?
  • Who checks results before they leave the organisation?
  • When do we disclose that AI was involved?
  • Who is the contact person for questions and new tools?

You can use these wordings as a basis and adapt them to your organisation:

  • Tools: “For work, we use only [tool] with the company account. Private accounts are not permitted for work content.”
  • Data: “We replace names and contact details with placeholders. We never enter health information, personnel files or bank details. We enter quotes and calculations only after approval by [role].”
  • Review: “A person checks every result that goes to customers or the public for accuracy, tone and sources. Whoever sends it is responsible for it.”
  • Labelling: “We label images, videos and audio recordings that were generated with AI and appear authentic.”
  • Contact person: “Questions and requests for new tools go to [name]. These rules apply from [date] and are reviewed every year.”
One page of rules is enough for everyone to know what belongs in a prompt.
One page of rules is enough for everyone to know what belongs in a prompt.

Works council and labelling

If there is a works council, you must inform it in good time about the planned use of AI and consult it on the effects on work (§ 90 BetrVG, the German Works Constitution Act). If a tool is capable of monitoring behaviour or performance, the works council also has a right of co-determination (§ 87 BetrVG). If the works council has to assess the introduction or use of AI, calling in an expert is deemed necessary (§ 80(3) BetrVG). So involve it early.

On labelling, Article 50 of the AI Act has applied since 2 August 2026: deceptively realistic images, videos or audio recordings must be labelled. The same applies to texts that inform the public on matters of public interest, unless a person has reviewed them and bears editorial responsibility. For a quote sent to a customer by email, what matters most is that a person checks it and takes responsibility.

Next steps

  • Ask your team who uses which AI tools today, including with private accounts.
  • Choose a tool that offers a business version and sort out the contract.
  • Adapt the wordings above and adopt the policy with a date.
  • If you have a works council, involve it before the roll-out.
  • Train the team so that the rules are understood. Training is also an obvious measure under Article 4, see AI literacy under Article 4.

The policy and a short training session combine well: in our AI training under the EU AI Act, we also work on the rules for your organisation. Which three rules does your team need first?

Frequently asked questions

Is the free version enough?

For companies, better not. Business versions usually offer a data processing agreement and exclude training on your prompts by default. Check this with the provider.

Employees are already using private accounts. What should we do?

A ban alone does little as long as there is no alternative. Provide an approved tool with a company account, set a date from which work content may only go into that tool, and explain the reason.

Do we have to involve the works council?

If there is a works council, you must inform it in good time about the planned use of AI. If a tool is capable of monitoring behaviour or performance, the works council also has a right of co-determination. Involve it early.

Can AI-generated texts go to customers without a notice?

That depends on the content. Above all, a person should check them and take responsibility. Since 2 August 2026, Article 50 of the EU AI Act has applied: deceptively realistic images, videos or audio recordings must be labelled. The same applies to texts that inform the public on matters of public interest, unless a person has reviewed them and bears editorial responsibility. Set this out in your policy.

Do we have to train the team if we only use ChatGPT?

Yes. Article 4 of the EU AI Act also applies to widely available tools. According to the European Commission’s questions and answers, employees should be informed about hallucinations, for example. A short training session together with the policy covers this well.

Sources

  1. EU AI Act, Regulation (EU) 2024/1689, Article 4, consolidated version of 27 July 2026, EUR-Lex
  2. GDPR, Article 28, EUR-Lex
  3. § 87 BetrVG, German Works Constitution Act (in German)
  4. § 90 BetrVG, German Works Constitution Act (in German)
  5. § 80 BetrVG, German Works Constitution Act (in German)
  6. § 2 GeschGehG, German Trade Secrets Act (in German)
  7. European Commission: AI Literacy, Questions and Answers

Updated: . This article is not legal advice.

AI training under the EU AI ActHalf a day · on site or online · certificate of attendance for each participant
See the training

Read next

Questions about your situation?

In a first call we discuss your questions and possible next steps. 30 minutes, no obligation, by phone or video.