Guide · Governance · 7 min read

Can our staff put company information into ChatGPT?

Yes, with rules, and the rules are shorter than you fear. Most New Zealand businesses have staff using public AI tools today with no guidance at all, which means company and customer information is already being pasted into systems the business has never assessed. The fix is not a ban. It is a decision about which tools, which information and which checks, written down and told to everyone.

The short answer

Public AI tools on a personal or free account may be used for work that involves no confidential, personal or client information: drafting a generic email, summarising a public article, tidying wording. Company information, customer details, financials, contracts, source code and anything a client gave you in confidence must only go into a tool the business has approved, on a business account, with the data settings checked.

That is the whole policy for most businesses, and it takes a fortnight to write, approve and tell people. The rest of this guide explains why the line sits there and what “approved” should mean.

What actually happens to the text you paste

When someone pastes a paragraph into a public AI tool, it leaves your business and lands on a server run by the tool’s provider. What happens next depends on the account and the settings. On many free and personal accounts, the provider may keep the conversation and may use it to improve its models. On business accounts, the terms usually promise that your data is not used for training and is deleted on a schedule, and you can often turn retention off entirely.

The point is that the same tool behaves differently depending on which door you walk through. A business that has never looked at the account type is trusting whichever door its staff happened to pick. Nobody in that business can currently answer a customer who asks “did you put my information into an AI?”, and that question is coming.

The information that must never go into a public tool

Everything else is generally fine, and being clear about that is what makes the policy workable. A policy that bans all use is ignored; a policy that names the five categories is followed.

  • Personal information about customers, staff or anyone else: names with details attached, contact information, health, financial or employment details. The Privacy Act 2020 applies to this whether the recipient is a person or a model.
  • Anything a client gave you in confidence, and anything covered by a contract, a non-disclosure agreement or professional privilege.
  • Financial information that is not public: pricing, margins, forecasts, payroll.
  • Credentials of any kind: passwords, API keys, tokens, connection strings. These get pasted more often than anyone admits, usually inside a log or a script.
  • Source code, product designs and anything else that is the business’s own intellectual property.

What “approved” should mean

An approved tool is one somebody in the business has checked. The check is short: what account type are we on, does the provider train on our data, where is the data stored, how long is it kept, can we delete it, and who can log in. Copilot inside a Microsoft 365 tenancy, an enterprise ChatGPT plan, a business Gemini plan and several others can all pass that check; the same products on personal accounts cannot.

The second half of “approved” is access. An AI assistant connected to your files sees whatever the person using it can see, including the folders that were shared with everyone years ago and never tidied. Before switching on any tool that reads your documents, check permissions. It is the single most common reason a Copilot rollout is paused after a week.

The one-page policy

Write down, in plain language: the approved tools and how to get access to them; the five categories of information that never go into a public tool; the rule that AI output is a draft until a person has checked it; who owns the policy and who to ask; and what to do if something has already gone in that should not have. Have a director sign it. Put it where people will find it, and mention it in inductions.

Then pair it with the thing most policies forget: give people a good approved tool. A ban with no alternative sends usage underground. An approved tool with a business account, permissions checked and a two-line rule set, gets used in the open, where you can see it.

If something has already gone in

It probably has. Find out what, from the person, without blame; they were trying to do their job faster. Check the account settings and delete the conversation history where the tool allows it. If personal information was involved, consider whether the Privacy Act’s notification rules apply, and get advice if you are unsure. Then finish the policy, because the next paste is next week.

Three situations, and what the rule says

A marketing coordinator pastes a draft press release into a public tool to tighten the wording. Nothing in it is confidential; it is about to be published. That is fine on any account, and telling people so is part of the policy, because a rule that seems to forbid the obvious gets ignored for the important cases too.

An accounts administrator pastes a supplier statement into the same tool to ask which invoices are overdue. The statement carries names, bank details and amounts. That is personal and financial information leaving the business, and it belongs only in an approved tool on a business account, if it belongs anywhere; the better answer is the automation that reads statements inside your systems.

A developer pastes an error log into a chat to ask what it means, and the log contains a live API key. This happens more than any other category and it is the most urgent: the key is now in a third party’s history. The rule is to rotate the key the same hour and report it, without blame, so the next person does the same.

What to tell customers who ask

A customer, an auditor or an insurer will ask whether their information has been put into an AI tool. The answer you want to be able to give is a sentence: which approved tools the business uses, on what terms, with what information excluded, and that staff are trained on it. The policy is what makes that sentence true. Without it, the honest answer is “we do not know”, and that answer is remembered.

Where to go from here

The AI Governance service on this site writes the policy, the approved-tool list and the training for you, sized to your business, and hands you something a director can sign in a fortnight. If you would rather see first how exposed you are, the AI Opportunity Score below flags shadow AI and the permissions question in five minutes.

Published 12 September 2026 · Be AI

Read enough? Find out where your business actually stands.

Twelve questions, five minutes, and a score you can put in front of your leadership team.