Practical guide · AI data

Company ChatGPT policy: practical rules for data and outputs

A ChatGPT and generative-AI policy should connect account type, entered data, intended use and output verification.

Write for the category, not one logo

Employees often use ChatGPT as shorthand for many generative assistants. A resilient policy governs the use case and data rather than one vendor name, so the rule remains useful as tools change.

Distinguish personal accounts from company-approved configurations. Contract terms, retention, settings and access can change what is acceptable even when the prompt looks identical.

Make data boundaries concrete

“Do not enter sensitive data” is not operational enough. Use company-relevant examples such as customer contracts, candidate CVs, payroll details, source code, strategy and internal documents.

  • public information that may be used
  • internal data allowed only in an approved account
  • personal or confidential data requiring review
  • secrets and credentials that never belong in a prompt

Match verification to consequence

An internal draft and a client recommendation do not carry the same impact. Define who checks facts, calculations, citations, rights and tone before an output affects a decision or external communication.

Give exceptions a route

People need a known place to request a new tool or use case and a different route to report accidental exposure. A rule without a route drives hidden use rather than control.

General educational material. It is not legal advice and does not replace legal, DPO, HR or security review appropriate to your organisation.