ModelCharter
ModelCharter Team

ChatGPT at Work: Safe Use and Team Rules

Person typing on a laptop representing ChatGPT at work and productivity

Photo: Kaboompics / Pexels

Key takeaways

  • ChatGPT at work is a fact, not a decision - someone on your team is already using it, sanctioned or not.
  • Free and Plus are consumer tiers where inputs can train OpenAI's models by default; Team and Enterprise exclude training and add admin controls.
  • Three rules cover most teams: use the company workspace, keep client and personal data out, and review AI output before it goes external.
  • Personal ChatGPT accounts shouldn't be banned outright, but they shouldn't be used for company work either.
  • A written policy plus staff acknowledgement is the fastest way to turn scattered ChatGPT use into something you can actually stand behind.

ChatGPT in the workplace is now a fact rather than a decision. Someone on your team is using it today, whether IT approved it or not. The question is whether that use is safe, sanctioned and productive, or a source of data leakage that becomes a liability the moment a client asks who's handling their information. A short, clear policy is the difference between those two outcomes, and it starts with understanding which ChatGPT tier your team is actually on.

The tier problem: not all ChatGPT is equal

There are four ChatGPT tiers relevant to business use. Free accounts and Plus subscriptions are consumer products: by OpenAI's own documentation, inputs from these tiers may be used to improve models unless a user manually opts out, and most never do. ChatGPT Team is the first tier that excludes your data from training by default and adds an admin console. ChatGPT Enterprise goes further with SSO, longer context windows and negotiable data-retention terms - see OpenAI's enterprise privacy overview for the specifics. For any work involving client data, sensitive internal information or personal data, Team is the minimum safe tier. It's worth checking which tier is actually on the company card, too - plenty of teams assume they're on Team when the account was actually set up as an individual Plus subscription years ago and never migrated.

Does ChatGPT train on your data by default?

On Free and Plus, yes, unless the setting is turned off in the account's data controls, under Settings then Data Controls, where "Improve the model for everyone" needs to be switched off manually. Most people never open that menu. On Team, Business and Enterprise, no - training is excluded by default as part of the plan terms, not something an admin has to configure. If you don't know which tier your team is actually using, that's the first thing to check, because the answer changes the entire risk picture, and it's a five-minute look at the billing page rather than a guess.

Three rules that cover most teams

Keep the rules short. Three lines cover the main risks: use the company ChatGPT Team workspace, not personal accounts. Don't enter client data, financial data, confidential plans or personal data into ChatGPT. Review any AI-generated content before it goes to a client or goes out publicly. Put those three lines in your AI usage policy, get everyone to acknowledge them, and you've covered the principal risks without a lengthy governance project. Longer policies aren't automatically safer - a rule nobody reads protects nobody.

What to do about personal accounts

Some staff will have personal ChatGPT accounts they've used for months, sometimes longer than the company has had a view on AI at all. Your policy doesn't need to ban personal AI use in general, but it should say plainly that personal accounts aren't for company work. If someone wants to use ChatGPT at work, the company account is the approved route. This keeps data from crossing between personal and corporate environments, which is where most AI data-leakage incidents actually start - not from a malicious act, usually just from someone pasting a client brief into the tool they already had open.

Does this apply to ChatGPT plugins and custom GPTs too?

Yes, and it's often overlooked. Custom GPTs and third-party plugins can introduce their own data flows on top of whatever ChatGPT tier you're on - a plugin might send data to a completely different vendor with its own retention terms, its own training defaults, and no relationship at all to the Team or Enterprise agreement you signed. Treat any plugin or custom GPT your team wants to use as a fresh vendor to check, not an extension of the ChatGPT approval you already gave. Our AI Tool Risk Directory covers ChatGPT's core plans; for anything bolted on top, run the same questions again before rolling it out to the wider team.

Getting leadership buy-in

The most common blocker to good AI governance isn't the staff - it's senior managers who think a policy is either unnecessary, because they trust the team, or counterproductive, because they don't want to slow anyone down. The useful framing: a policy protects the business from the real cost of unmanaged AI use - data breaches, GDPR exposure, an awkward SOC 2 finding when an auditor asks which AI tools are in scope - and setting one up takes a morning, not a quarter. A 12-person design studio going through this got a signed policy live in under two hours once a partner actually sat down with the generator instead of debating it across three separate meetings.

Where ChatGPT fits next to other tools

Most teams don't stop at ChatGPT. Once a written policy exists, it's worth extending the same checks to whatever else has crept in - Microsoft 365 Copilot, Notion AI, or note-takers like Otter.ai. Comparing tiers across tools is easier once you've already done it once for ChatGPT; see is ChatGPT safe for work for a deeper look at the tier-by-tier risk breakdown, and treat each new tool request as a five-minute check rather than a special case.

Next step

You don't need a governance overhaul to get ChatGPT under control - you need a tier check, three rules, and a way to prove staff read them. ModelCharter's policy generator gets you from a blank page to a signed, attestable policy in under an hour, built around exactly the tiers and risks covered here, and it extends cleanly to whichever tool comes up next.

TierTrains on your data by default?Admin console / SSOBest used for
FreeYes, unless opted out manuallyNoPersonal use only - not for company work
PlusYes, unless opted out manuallyNoPersonal use only - not for company work
TeamNo, excluded by defaultAdmin console; no SSOSmall teams handling routine business data
EnterpriseNo, excluded by defaultAdmin console with SSOClient data, sensitive material, regulated sectors
ChatGPT tiers compared for workplace use
For ChatGPT Enterprise, Business, and Edu customers, and API customers via the Business Data plan, we do not use conversations or content to train our models by default.
OpenAI, Business Data privacy documentation

Frequently asked questions

Is ChatGPT safe to use for work?
It depends entirely on the tier. Free and Plus carry real data-leakage risk because inputs can train the model by default. Team and Enterprise exclude training and add admin controls, making them the safer baseline for anything involving client or confidential data.
Does ChatGPT Team really stop OpenAI training on our data?
Yes, by default, as stated in OpenAI's own business data documentation. This is a plan-level setting, not something an individual user has to remember to switch off, which is exactly why Team is the minimum recommended tier for company use.
Should we ban personal ChatGPT accounts at work?
An outright ban is hard to enforce and often ignored. A clearer rule works better: personal accounts are fine for personal use, but company work goes through the company workspace, where data controls actually apply.
What happens if an employee pastes client data into ChatGPT by mistake?
Treat it like any other data incident: identify what was entered, check which tier was used and whether training was on, and inform anyone required by your DPA or regulatory obligations. This is exactly the scenario a written policy and prior tier decision are meant to prevent.
Do ChatGPT plugins and custom GPTs carry the same risk as the base product?
Not automatically - they can introduce entirely separate data flows to third-party vendors. Each plugin or custom GPT worth adopting should be checked on its own terms, not assumed to inherit ChatGPT's plan-level protections.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator