An AI acceptable use policy for small businesses — what staff may paste into ChatGPT and Copilot, and what they must not

Staff are already using ChatGPT, Copilot and Gemini at work. The real risks, what the ICO and NCSC say, how consumer and business tiers differ on training and retention, and a ten-point policy you can adopt.

Search the blog

Someone in your business is already pasting things into ChatGPT. The Office for National Statistics reported on 20 July 2026 that self-reported AI use among UK businesses with ten or more employees has risen from around 12% to around 35% since late 2023, and that 28% of businesses with fewer than ten staff now use at least one AI technology. Those figures count the businesses that know they are using it; personal accounts on personal phones do not show up in a survey.

So the question for a firm of 2 to 500 people is not whether to allow AI tools, but what the rules are. Left unwritten, the rules are whatever each employee guesses on the day: a paralegal drafting a letter with a client's medical history in the prompt, a sales manager uploading the customer list "to tidy the formatting". A short, plain policy fixes most of this. Here are the risks, what the regulators say, how the tiers differ, and a ten-point policy you can adopt as written.

The risks that actually matter

Confidential business data in prompts. Whatever you type into a chatbot leaves your building. The NCSC's guidance on large language models says the query "will be visible to the organisation providing the LLM" and, for public services, stored queries "will almost certainly be used for developing the LLM service or model at some point". Pricing, contracts, source code and unpublished accounts all count.

Client personal data and UK GDPR. Pasting a customer's name, complaint or health details into a third-party tool is processing personal data. The ICO's guidance on AI and data protection is explicit that whether you are training a system or simply using one, "you must have an appropriate lawful basis to do so". You also need a contract in your company's name saying what the provider may do with it. A consumer account has none.

Copyright and licensing of outputs. Vendor terms differ, and none settles the legal question for you. OpenAI says you "own any output you rightfully receive from our services to the extent permitted by law"; Anthropic's commercial terms assign its rights in outputs to the customer. Neither promises the output is original, free of third-party material or protectable. Treat generated text, images and code as usable, not necessarily defensible as yours.

Hallucinated facts in client work. Language models produce plausible text, not verified text. The ICO's accuracy guidance says records of AI inferences about people should "indicate that they are statistically informed guesses rather than facts". The small-firm version: nothing generated reaches a client, a court or HMRC without a human checking every number, name, date and citation.

Shadow AI on personal accounts. When staff use a personal ChatGPT or Gemini login for work, the business has no control over retention, no audit trail, no way to delete the data when they leave, and no contract. It is the most common gap we see, and it is usually caused by the absence of an approved alternative, not malice.

Training and retention settings. The same brand name can mean two entirely different data arrangements depending on the tier. See the table below.

What the ICO says

The ICO's AI guidance (2023, currently under review following the Data (Use and Access) Act) treats AI as ordinary processing to which every principle applies. Three points matter most:

  • You are still the controller. If you decide what data goes into the tool and why, "you are a controller", and "overall accountability for data protection compliance lies with the controller". The ICO adds that "you cannot delegate these issues to data scientists or engineering teams" — nor, by extension, to the vendor.
  • A DPIA is usually required. The ICO's view is that AI use is likely to be high-risk processing and "will therefore trigger the legal requirement for you to undertake a DPIA". For Copilot summarising email this can be two pages; for anything that profiles or decides about individuals it must be more.
  • Accuracy applies to outputs. The accuracy principle "applies to all personal data, whether it is information about an individual used as an input to an AI system, or an output of the system". A wrong fact Copilot writes about a customer into your CRM is yours to fix.

What the NCSC says

The NCSC's advice, published 14 March 2023, is to avoid including "sensitive information in queries to public LLMs" and to avoid queries "that would lead to issues were they made public". The concern is not only training: stored queries "may be hacked, leaked, or more likely accidentally made publicly accessible". The NCSC also notes LLMs are prone to "injection attacks", where content the model reads — a web page, an email — carries hidden instructions that hijack it. An assistant that reads inbound email is a new attack surface. For sensitive data the NCSC's steer is towards cloud services with proper data-handling agreements, or self-hosted models, not public chatbots.

Consumer tools versus business tiers

The table records only what each vendor states on its own pages.

Table 1. Training use and retention, consumer versus business tiers, as stated by the vendors (OpenAI, 2026; Microsoft, 2026; Google, 2026; Anthropic, 2025).
Product and tierUsed to train the vendor's models?Retention of prompts and responses
ChatGPT for individuals (Free/Plus/Pro)Yes by default: "we may use your content to train our models". Opt-out via the privacy portal ("do not train on my content"); Temporary Chats are not used for training.Kept in chat history unless deleted.
ChatGPT Business / Enterprise / APINo by default: "we do not train on any inputs or outputs from our products for business users".Deleted conversations removed "within 30 days"; API inputs and outputs retained "for up to 30 days" for abuse monitoring.
Microsoft 365 CopilotNo: "prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs". Only surfaces data the user can already see.Stored as Copilot activity history, encrypted, under the same commitments as other Microsoft 365 content; EU traffic stays within the EU Data Boundary.
Gemini for Google WorkspaceNo without permission: content "is not human reviewed or otherwise used for Generative AI model training outside your domain without permission".Gemini in Workspace apps: "90 days to indefinite, as determined by admins"; Gemini app: up to 36 months, admin-set.
Consumer Gemini appNot covered by the Workspace Privacy Hub; separate consumer terms apply.Not covered.
Claude (commercial terms)No: "Anthropic may not train models on Customer Content from Services".Governed by the commercial terms.

Three things follow. The free tier of the most popular tool trains on your prompts unless someone changes a setting in a personal account you do not control. The business tiers of all four vendors promise contractually not to train, which is what you need to meet the ICO's controller obligations. And "not used for training" is not "not stored": Copilot and Gemini keep interaction history, and that history is discoverable, subject to access requests, and belongs in your retention schedule.

A ten-point AI use policy you can adopt

Keep it to one page; staff will read one page.

  1. Approved tools only. Name them. For Microsoft 365 firms that is usually Copilot; for Google Workspace, Gemini; add a business-tier ChatGPT or Claude account if there is a need. Personal accounts are not used for company work.
  2. Company logins only. Every approved tool is accessed through the company identity with multi-factor authentication, so access ends with employment and administrators can delete history.
  3. Never enter these. Personal data beyond what the task strictly needs; health or criminal-record data; passwords and keys; bank and card details; anything under an NDA; source code or documents marked confidential. If in doubt, take the names out first.
  4. Check everything before it leaves the business. Every fact, figure, quotation, legal citation and line of code is verified by a named person before it goes to a client, a regulator or into production.
  5. Say when it matters. Where a client, tender or contract asks whether AI was used, answer truthfully. Professional advice is owned by the professional, however it was drafted.
  6. No decisions about people. The tools do not decide on recruitment, performance, discipline or credit without documented human review and, where required, a DPIA.
  7. Do not paste in what you do not own. Third-party reports, licensed images, competitors' documents and paywalled material stay out of prompts.
  8. Assistants do not read the inbox unsupervised. Features that let a tool act on email, browse the web or run tasks are enabled only by IT after reviewing what they can reach.
  9. Retention is set and documented. Administrators set the interaction-history retention period, record it in the retention schedule, and include AI history in subject access request searches.
  10. Report mistakes without blame. If personal or confidential data goes into the wrong tool, staff tell IT or the data protection lead the same day so it can be deleted and, if needed, reported. Nobody is disciplined for reporting.

Sign it, date it, put it in the staff handbook and revisit it every six months; vendor terms change more often than that.

What to do this week

Find out what people are actually using; a two-question survey is enough. Decide on the approved tools — if you already pay for Microsoft 365 Business or Google Workspace you may be paying for a business-tier assistant that is not switched on. Turn it on, turn the consumer ones off, set retention, write the one-page policy, and brief the team in fifteen minutes. If you use Copilot, tidy SharePoint and Teams permissions first: Copilot "only surfaces organizational data to which individual users have at least view permissions", so a badly shared folder becomes a badly shared answer.

If you would like us to review your Microsoft 365 or Google Workspace tenancy, tell you which AI features are on and under what data terms, and set retention and permissions properly, that is a fixed piece of work we will put in writing. See our cloud services and business IT support pages, or get in touch. The companion piece is our phishing article: a chatbot cannot be phished, but the person using it can.

Sources

Want this handled for your business?

A short conversation with an engineer — not a salesperson — is the fastest way to find out what you actually need.

Vision House, 3 Dee Road, Richmond TW9 2JN Registered UK company no. 09064078 No cookies, no trackers on this site