ChatGPT for Business: Creating a Clear AI Policy

Photo: Julia M Cameron / Pexels
Key takeaways
- The tier your team uses matters more than any other line in the policy: Free and Plus may train on inputs by default, Team and Enterprise don't.
- Name the approved tier explicitly in the policy - 'ChatGPT Team accounts only' - rather than leaving it to individual judgement.
- List what's off-limits even on the approved tier: client PII, source code, unreleased plans, legal or financial data.
- Add a disclosure rule for AI-drafted content that reaches customers, regulators or the public.
- A policy nobody has signed is a policy that doesn't exist - attestation is what makes it enforceable.
ChatGPT is already in use somewhere on most teams, usually before anyone decided it should be. Whether that's an asset or a liability comes down to two things: which tier the account is on, and whether a policy exists explaining the rules. We've covered whether ChatGPT is safe for work in general terms before; this is the version aimed squarely at writing the policy itself. Neither takes long to fix. A clear ChatGPT for business policy is a few hours of work, not a compliance project, and it's the difference between a useful tool and an unmanaged one.
Free, Plus, Team, Enterprise: what actually changes
ChatGPT Free and Plus are consumer products. By default, OpenAI may use what you type in to improve its models unless the setting is turned off in the account's data controls - and on a personal account, nobody at your company controls that setting. ChatGPT Team and ChatGPT Enterprise don't train on your data by default, and they add workspace admin controls, single sign-on and retention settings that a personal account simply doesn't have. The API sits alongside these as a fifth path many teams use through other software rather than the chat interface itself, and it follows the same no-training default as Team and Enterprise.
Why the tier decision is most of the policy
Once you've picked the tier, the rest of the policy is mostly detail. Get the tier wrong - leave staff on personal Free or Plus accounts for work - and no amount of careful wording about 'appropriate use' changes the fact that inputs may be feeding a training set you have no visibility into. Get the tier right and the remaining rules are about scope, not damage control. It's the same pattern we see across most AI vendors: the gap between consumer and business tiers matters more than which specific vendor you pick, so getting this one decision right does most of the heavy lifting for the whole policy.
What to put in writing
Name the approved tier explicitly: 'ChatGPT Team accounts only, not personal Free or Plus accounts.' List what's off-limits even on the approved tier - client PII, source code, unreleased product plans, legal or financial data - and say whether staff need manager sign-off before using ChatGPT output in anything client-facing. Vague guidance like 'use good judgement' tends to produce inconsistent judgement across a team of any size, and it's the line an auditor will single out first if the policy ever gets reviewed.
Can staff use their personal ChatGPT account for work?
The honest answer is: not for anything sensitive, and ideally not at all once a Team account exists. Personal accounts have no admin oversight, no guaranteed DPA, and - on Free and Plus - inputs may train the model by default. If budget is the blocker, ChatGPT Team's per-seat pricing is usually cheaper than the risk it removes, and it's worth saying that plainly in the policy rather than leaving staff to weigh it up themselves. Offboarding matters here too: when someone leaves, a personal account and whatever they pasted into it leaves with them, with no way for the company to review or delete it.
A worked example: a support team at a growing startup
A support lead at a Series A startup we've seen go through this had four agents using personal ChatGPT accounts to draft replies to customer tickets - pasting in customer names, order numbers and the occasional complaint verbatim. Moving the team to a single ChatGPT Team workspace took an afternoon of setup and cost less per month than one hour of the support lead's time. The policy line that followed was one sentence: draft replies in the shared Team workspace only, never in a personal account. Nobody complained about the change; most of the team hadn't realised the personal account was a problem in the first place.
Disclosure: when AI-drafted content needs a human sign-off
Where ChatGPT produces something that reaches customers, regulators or the public, decide upfront whether it needs a disclosure or an editor's review before it goes out. Some B2B contracts and most regulated sectors expect a human review step before AI-drafted material is sent externally. Make that a written rule rather than something each employee decides for themselves under deadline pressure. A simple threshold works well: anything going to more than one external recipient, or anything with legal or financial consequence, gets a human read-through first.
Does ChatGPT comply with GDPR?
It can, but compliance sits with how you use it, not just which tool you pick. If personal data of EU residents goes into ChatGPT, you need a lawful basis for that processing and, for the Team, Enterprise or API tiers, a data processing agreement with OpenAI. Free and Plus accounts don't offer a DPA, which is itself a reason to keep personal data off them. The ICO's guidance on AI and data protection is worth a read if EU or UK personal data is a regular part of your use case.
What if the budget doesn't stretch to Team accounts yet?
If cost genuinely rules out an upgrade for now, the policy still needs to say something firmer than 'be careful.' Restrict ChatGPT use to non-sensitive tasks only - drafting, brainstorming, generic copy - and explicitly prohibit anything involving customer data, source code or unreleased plans until the tier is upgraded. A temporary restriction that's actually followed beats a permissive rule that assumes good judgement will fill the gap.
Plugins, browser extensions, and keeping up as terms change
The policy conversation usually stops at 'which tier', but ChatGPT shows up in more places than the main website: a browser extension that reads the current page, the mobile app with its own data settings, third-party plugins and custom GPTs that pipe data to yet another vendor behind the scenes. Each of these can behave differently from the core account even under the same subscription, so it's worth a line in the policy limiting use to the approved workspace app or web login, with sign-off required before installing any extension or plugin that connects to it. Vendor terms move faster than internal policy reviews, too - OpenAI has adjusted data controls and default settings more than once, so put a six-monthly check on the calendar to re-read the current tier names and defaults on OpenAI's enterprise privacy page and business data page, rather than assuming the policy you wrote a year ago is still accurate.
Write it once, then make sure people read it
A tier decision and four rules on a page do most of the work, but only if staff actually see and acknowledge them. Set up your policy with our free AI usage policy generator, check ChatGPT's full data-handling profile on our tool directory, and send the policy out for attestation today rather than leaving it as a draft in someone's inbox.
| Tier | Trains on inputs by default? | DPA available? | Admin controls |
|---|---|---|---|
| Free | Yes, unless turned off in settings | No | None |
| Plus | Yes, unless turned off in settings | No | None |
| Team | No | Yes | Workspace admin, SSO, retention controls |
| Enterprise | No | Yes | Full admin console, SSO, audit logs |
“OpenAI does not use business data - including prompts and outputs - from ChatGPT Team, ChatGPT Enterprise, or the API to train its models by default.”