Is it safe to use ChatGPT at work? What never to paste in
Using ChatGPT at work can be safe. Whether it is safe in your case depends on three things: which version of the tool you use, what your organisation permits, and what you type into it. Most problems come from the third.
What happens to what you type
When you use a consumer AI tool, your messages are sent to the provider's servers and stored there, at least for a period. Depending on the product and your settings, they may also be used to improve future models. Business and enterprise versions usually offer stronger terms, such as excluding your data from training and giving the organisation control over retention. Settings and terms change, so check the current privacy policy of the specific product you use rather than relying on what was true last year.
The practical rule is simple. Treat anything you paste into an unapproved tool as information you have shared outside your organisation.
Never paste in
- Personal data about other people: names with contact details, health information, performance reviews, customer records, identity numbers.
- Confidential business information: unreleased financial results, pricing strategy, contracts, merger plans, anything under a non-disclosure agreement.
- Passwords, access keys and security details of any kind.
- Source code or documents that your employer has not cleared for external tools.
- Anything you would not be comfortable seeing in an email forwarded to the wrong person.
How to use it anyway
Much useful work needs none of the above. Remove names and identifying details before pasting, and replace them with placeholders such as "Client A" or "Employee 1". Describe a situation in general terms rather than pasting the original document. Ask for a structure, a template or a first draft that you then complete with the real details yourself, outside the tool.
If your organisation provides an approved AI tool, use that one for work material, even if you prefer another tool at home. The approved tool has usually been reviewed for exactly these risks.
Find out your organisation's rules
Many organisations now have an AI policy. If yours does, read it. If it does not, ask your manager or IT team which tools are permitted and for what, and keep the answer in writing. In regulated fields such as healthcare, finance, law and education, the rules are often stricter, and privacy law may apply to personal data regardless of internal policy.
The output needs care too
Safety also concerns what comes out. AI tools can produce confident errors, so anything you send, publish or act on still needs checking. The responsibility stays with you. The guide to why ChatGPT makes things up explains what to check.
Module 8 of the free Course Parse course covers privacy in practice, with exercises in removing identifying details from real-looking work material.
Put this into practice
Upload a lecture and Course Parse builds the flashcards, quizzes, and spaced-repetition schedule for you.
Try Course Parse free