AI in the Workplace: Are Your Employees Putting Company Information Into ChatGPT?
Your employees may already be using artificial intelligence at work—even if your company has never officially approved it.
AI tools such as ChatGPT can help employees draft emails, summarize documents, brainstorm ideas, analyze information, create reports, prepare presentations, and complete everyday tasks more efficiently.
But there is an important question employers should be asking:
What information are employees putting into these tools?
Without clear guidelines, an employee trying to save a few minutes could unintentionally enter confidential, proprietary, customer, or employee information into an AI platform.
The Convenience of AI Can Create New Risks
Imagine an employee wants help writing a response to a difficult customer. Instead of starting from scratch, the employee copies the customer’s email into an AI tool and asks it to draft a response.
Or a manager wants help preparing a performance review and enters notes about an employee’s performance.
Someone in HR uploads a document and asks AI to summarize it.
An employee asks AI to analyze a spreadsheet containing company information.
In each case, the employee may simply be trying to work more efficiently. But depending on the information involved and the AI tool being used, the employee could be sharing information the organization never intended to provide to a third-party platform.
What Information Should Employers Be Thinking About?
Organizations should consider establishing rules around entering sensitive information into public or unapproved AI tools, including:
- Employee personal information
- Medical or leave information
- Payroll or compensation information
- Customer or client information
- Financial information
- Passwords or login credentials
- Confidential business information
- Proprietary processes or trade secrets
- Contracts or other sensitive documents
- Information protected by confidentiality agreements
The appropriate restrictions will vary by organization, industry, and the AI platforms being used.
Not All AI Tools or Accounts Handle Data the Same Way
Employers should avoid assuming that every AI platform—or every version of the same platform—handles business information identically.
Consumer AI products, business accounts, enterprise platforms, and privately deployed AI systems may have different privacy, security, retention, training, and administrative controls.
That makes it important for employers to determine which AI tools are approved for business use and understand the applicable data-handling terms before employees use them with company information.
“Don’t Use AI” May Not Be a Realistic AI Policy
Some organizations may be tempted to simply prohibit employees from using artificial intelligence altogether.
For many workplaces, that may not be the most practical long-term approach.
AI can provide legitimate productivity benefits. The larger issue is whether employees understand how to use it responsibly.
A useful workplace AI policy can establish boundaries without preventing appropriate use of the technology.
What Should a Workplace AI Policy Address?
An effective AI policy doesn’t necessarily need to be lengthy or complicated. At minimum, employers should consider addressing:
- Which AI tools are approved for business use.
- What types of company information employees may and may not enter.
- Whether confidential or personally identifiable information may be used.
- Whether employees may upload company documents or files.
- Expectations for reviewing AI-generated work for accuracy.
- When human review or approval is required.
- Rules regarding AI-generated content used with customers or the public.
- Intellectual property and confidentiality considerations.
- Who employees should contact when they are unsure whether a particular use is appropriate.
Policies should reflect the organization’s actual operations rather than relying on a generic prohibition copied from somewhere else.
AI Can Be Wrong, Too
Information security isn’t the only concern.
AI-generated content can contain inaccurate, incomplete, outdated, or fabricated information. Employees should understand that an AI-generated answer isn’t automatically correct simply because it sounds polished and confident.
Human review remains important, particularly when AI is being used for HR decisions, legal or compliance matters, financial information, customer communications, or other significant business activities.
Employees should remain responsible for reviewing and verifying the work they produce with AI assistance.
Managers Need Guidance Too
An AI policy won’t accomplish much if employees don’t understand it.
Managers and supervisors should know what AI use is permitted, what information should never be entered into an unapproved system, and when questions should be referred to HR, IT, legal counsel, or another appropriate resource.
Employers may also want to periodically revisit their policies as AI tools and workplace uses continue to evolve.
Don’t Wait Until There’s a Problem
If your organization hasn’t discussed employee AI use yet, now is a good time to start.
Employees don’t necessarily need formal company adoption of AI to begin experimenting with it on their own. Clear expectations can help organizations benefit from useful technology while protecting confidential information, employee data, customer information, and other important business assets.
Does your organization have an AI workplace policy? Consult HR Services can help you develop practical policies and employee guidelines that reflect how AI is actually being used in today’s workplace.