
Right now, someone in your business is probably pasting client data into ChatGPT.
If that data includes anything personal or commercially sensitive, you could be looking at a UK GDPR breach.
The ICO doesn’t care that you didn’t know it was happening.
Most employees are already using AI tools regularly. ChatGPT, Copilot, Gemini, Grammarly, AI coding assistants. They’re using them because they’re useful and because nobody has told them not to. Or told them how.
That space between “everyone’s using it” and “we have no rules around it” is where the risk sits for you.
AI use at work and data protection
When an employee enters client information or personal details into a third-party AI tool, that data may be stored externally.
Some tools use inputs to train their models, which means that your confidential business information could end up embedded in a system you have zero control over.
Under UK GDPR, you are the data controller. You’re responsible for how personal data is processed, even when it’s your employee doing the processing through a tool you didn’t authorise.
The quality and reputation risk
AI is confident. It’s also frequently wrong.
If someone on your team is using AI to draft client emails or reports without reviewing the output properly, those errors go out under your name.
The client doesn’t know AI wrote it. They just know that your business sent something inaccurate.
The IP and ownership question
If an employee uses AI to produce a piece of work, who owns it?
Your employment contracts almost certainly don’t address this. That’s fine until there’s a dispute and then it isn’t.
The disciplinary gap
If an employee uses AI to write something and passes it off as entirely their own work, what’s your position on that?
If you don’t have a policy, you probably don’t have a position. And, without a position, you’ll struggle to take any disciplinary action that would hold up at a tribunal.
What a proportionate AI policy looks like
You don’t need a 30-page document. A clear one-page policy is enough to start with.
It should cover:
- Which AI tools are permitted and for what types of work
- What data must never be entered into AI tools, including client data, personal data, financial information and anything commercially sensitive
- How AI-generated output should be reviewed before it goes anywhere
- When and how AI use should be disclosed, particularly in client-facing work
- What happens if someone misuses AI or breaches the policy
Also, if you deal with vendors or suppliers, you should consider auditing or assessing their AI use. Not doing so could leave you exposed through your supply chains without you even realising.
This isn’t about banning AI
A blanket ban is unenforceable. People will use these tools whether you like it or not and pretending otherwise just pushes the behaviour underground where you can’t see it.
The point is to set proportionate boundaries so your team can use AI where it genuinely helps, without putting your business at risk.
How we can help
We can draft a proportionate AI use policy tailored to your business, covering your data protection obligations and giving your team clear, practical guidance on what’s acceptable.
If you don’t have an AI use policy yet, now is the time.
Get in touch and we’ll help you to put one in place quickly.



