ChatGPT at Work: Safe Use and Team Rules

Photo: Kaboompics / Pexels
Key takeaways
- ChatGPT at work is a fact, not a decision - someone on your team is already using it, sanctioned or not.
- Free and Plus are consumer tiers where inputs can train OpenAI's models by default; Team and Enterprise exclude training and add admin controls.
- Three rules cover most teams: use the company workspace, keep client and personal data out, and review AI output before it goes external.
- Personal ChatGPT accounts shouldn't be banned outright, but they shouldn't be used for company work either.
- A written policy plus staff acknowledgement is the fastest way to turn scattered ChatGPT use into something you can actually stand behind.
ChatGPT in the workplace is now a fact rather than a decision. Someone on your team is using it today, whether IT approved it or not. The question is whether that use is safe, sanctioned and productive, or a source of data leakage that becomes a liability the moment a client asks who's handling their information. A short, clear policy is the difference between those two outcomes, and it starts with understanding which ChatGPT tier your team is actually on.
The tier problem: not all ChatGPT is equal
There are four ChatGPT tiers relevant to business use. Free accounts and Plus subscriptions are consumer products: by OpenAI's own documentation, inputs from these tiers may be used to improve models unless a user manually opts out, and most never do. ChatGPT Team is the first tier that excludes your data from training by default and adds an admin console. ChatGPT Enterprise goes further with SSO, longer context windows and negotiable data-retention terms - see OpenAI's enterprise privacy overview for the specifics. For any work involving client data, sensitive internal information or personal data, Team is the minimum safe tier. It's worth checking which tier is actually on the company card, too - plenty of teams assume they're on Team when the account was actually set up as an individual Plus subscription years ago and never migrated.
Does ChatGPT train on your data by default?
On Free and Plus, yes, unless the setting is turned off in the account's data controls, under Settings then Data Controls, where "Improve the model for everyone" needs to be switched off manually. Most people never open that menu. On Team, Business and Enterprise, no - training is excluded by default as part of the plan terms, not something an admin has to configure. If you don't know which tier your team is actually using, that's the first thing to check, because the answer changes the entire risk picture, and it's a five-minute look at the billing page rather than a guess.
Three rules that cover most teams
Keep the rules short. Three lines cover the main risks: use the company ChatGPT Team workspace, not personal accounts. Don't enter client data, financial data, confidential plans or personal data into ChatGPT. Review any AI-generated content before it goes to a client or goes out publicly. Put those three lines in your AI usage policy, get everyone to acknowledge them, and you've covered the principal risks without a lengthy governance project. Longer policies aren't automatically safer - a rule nobody reads protects nobody.
What to do about personal accounts
Some staff will have personal ChatGPT accounts they've used for months, sometimes longer than the company has had a view on AI at all. Your policy doesn't need to ban personal AI use in general, but it should say plainly that personal accounts aren't for company work. If someone wants to use ChatGPT at work, the company account is the approved route. This keeps data from crossing between personal and corporate environments, which is where most AI data-leakage incidents actually start - not from a malicious act, usually just from someone pasting a client brief into the tool they already had open.
Does this apply to ChatGPT plugins and custom GPTs too?
Yes, and it's often overlooked. Custom GPTs and third-party plugins can introduce their own data flows on top of whatever ChatGPT tier you're on - a plugin might send data to a completely different vendor with its own retention terms, its own training defaults, and no relationship at all to the Team or Enterprise agreement you signed. Treat any plugin or custom GPT your team wants to use as a fresh vendor to check, not an extension of the ChatGPT approval you already gave. Our AI Tool Risk Directory covers ChatGPT's core plans; for anything bolted on top, run the same questions again before rolling it out to the wider team.
Getting leadership buy-in
The most common blocker to good AI governance isn't the staff - it's senior managers who think a policy is either unnecessary, because they trust the team, or counterproductive, because they don't want to slow anyone down. The useful framing: a policy protects the business from the real cost of unmanaged AI use - data breaches, GDPR exposure, an awkward SOC 2 finding when an auditor asks which AI tools are in scope - and setting one up takes a morning, not a quarter. A 12-person design studio going through this got a signed policy live in under two hours once a partner actually sat down with the generator instead of debating it across three separate meetings.
Where ChatGPT fits next to other tools
Most teams don't stop at ChatGPT. Once a written policy exists, it's worth extending the same checks to whatever else has crept in - Microsoft 365 Copilot, Notion AI, or note-takers like Otter.ai. Comparing tiers across tools is easier once you've already done it once for ChatGPT; see is ChatGPT safe for work for a deeper look at the tier-by-tier risk breakdown, and treat each new tool request as a five-minute check rather than a special case.
Next step
You don't need a governance overhaul to get ChatGPT under control - you need a tier check, three rules, and a way to prove staff read them. ModelCharter's policy generator gets you from a blank page to a signed, attestable policy in under an hour, built around exactly the tiers and risks covered here, and it extends cleanly to whichever tool comes up next.
| Tier | Trains on your data by default? | Admin console / SSO | Best used for |
|---|---|---|---|
| Free | Yes, unless opted out manually | No | Personal use only - not for company work |
| Plus | Yes, unless opted out manually | No | Personal use only - not for company work |
| Team | No, excluded by default | Admin console; no SSO | Small teams handling routine business data |
| Enterprise | No, excluded by default | Admin console with SSO | Client data, sensitive material, regulated sectors |
“For ChatGPT Enterprise, Business, and Edu customers, and API customers via the Business Data plan, we do not use conversations or content to train our models by default.”