Can You Be Fired for Using It? Should You Stop If Your Company Has No AI Policy?
Need to simply draft or rewrite an email?
ChatGPT.
Need to summarise a 50-page document before a meeting?
ChatGPT.
Need ideas for a presentation?
ChatGPT.
Translate something? Draft a report? Fix an Excel formula? Prepare meeting notes?
You already know the answer.
In many workplaces, using generative AI has become so ordinary that nobody even talks about it anymore.
Your colleague uses it.
Your manager may use it.
Someone in HR probably uses it.
Someone in finance probably uses it.
And perhaps you have been using your own personal ChatGPT account at work for months.
Nobody has stopped you.
Nobody has told you not to.
So what’s the problem?
Maybe there isn’t one.
But there is a question worth asking:
What exactly are you putting into it?
There is a big difference between asking: “Can you make this sentence sound more professional?” and uploading:
- a client’s contract;
- an employee spreadsheet;
- an internal investigation;
- customer information;
- unpublished financial figures;
- confidential correspondence;
- business strategy;
- source code;
- a document containing names, addresses or identification numbers.
The first may be an ordinary productivity task.
The second may involve information that does not actually belong to you personally.
And suddenly, “everyone at work uses ChatGPT” doesn’t answer the important question.
“But I Pay for ChatGPT Plus Myself.”
That is increasingly common too.
An employee pays for their own subscription because it helps them work faster.
It feels even safer because it is a paid account.
But there is an important distinction:
A personal paid account is still a personal account.
The company does not automatically turn it into a company-governed environment simply because you happen to use it for company work.
OpenAI itself distinguishes between its individual services and business offerings.
For individual ChatGPT services, content may be used to improve models depending on the user’s settings, although users can opt out through Data Controls.
For business offerings such as ChatGPT Business and Enterprise, OpenAI states that business inputs and outputs are not used to train its models by default.
That doesn’t mean a business account magically solves every compliance issue.
But it illustrates something important:
Personal AI use and organisation-managed AI use are not necessarily the same thing.
Can You Be Fired for Using ChatGPT at Work?
The answer isn’t a simple yes or no.
Using ChatGPT itself does not automatically mean you have done something wrong.
But what you do with it matters.
For example, the situation becomes very different if an employee:
- uploads confidential company or client information;
- processes personal data without appropriate authority or safeguards;
- breaches an existing confidentiality, cybersecurity or acceptable-use policy;
- uses AI for something the employer has expressly prohibited;
- submits inaccurate AI-generated work without checking it;
- discloses trade secrets or commercially sensitive information.
And importantly:
A company doesn’t necessarily need a policy called “AI Governance Policy” before other workplace rules can apply.
An existing employment contract, confidentiality agreement, IT security policy, privacy policy, client obligation or professional duty may already restrict what an employee can do with company information.
So Should You Stop Using ChatGPT at Work?
Not necessarily.
That may be the wrong conclusion.
AI can save enormous amounts of time.
It can help employees draft, research, structure ideas, translate, analyse and perform repetitive work faster.
Trying to pretend employees aren’t using it may be less realistic than learning how to use it properly.
The better questions are:
Does your company know you’re using it?
Has it told you what you can put into it?
Has anyone explained what you should never upload?
Do you know whether confidential or personal information needs to be removed first?
Does your company have an approved AI platform?
Or has everyone simply opened their own account and started experimenting?
That last situation is becoming particularly interesting.
Ten Employees. Ten Personal AI Accounts.
Imagine a company with 50 employees.
10 regularly use ChatGPT for work.
One uses it to summarise contracts.
One prepares HR communications.
Another analyses customer feedback.
Someone in finance uses it to organise figures.
A manager uses it to prepare reports.
Everyone becomes more productive.
Great.
But all 10 are using their personal accounts.
Now ask management:
Which employees are using AI?
They may not know.
What information are employees putting into it?
They may not know.
Which AI services are being used?
They may not know.
What happens to work-related conversations when an employee leaves?
They may not know.
And perhaps the most uncomfortable question:
If the company already knows everyone is using AI but has put no controls around it, who owns the risk?
Now we are no longer talking only about employee behaviour.
We are talking about AI governance.
We Have Been Here Before
In our earlier article, “Everyone Talks About AI Productivity. Almost Nobody Talks About AI Accountability,” we looked at what happens when businesses celebrate the efficiency AI brings without asking who remains responsible when something goes wrong.
AI may produce the draft.
But somebody still has to decide whether that draft is accurate, appropriate and safe to use.
Read: Everyone Talks About AI Productivity. Almost Nobody Talks About AI Accountability.
Then we looked at another workplace reality in “Just Use ChatGPT”: When Companies Push Compliance Work Onto Untrained Employees.
There, the problem was different.
Employees with little compliance or legal training were being expected to prepare policies, analyse sensitive documents and deal with governance tasks, sometimes with AI being used to fill the expertise gap.
Read: “Just Use ChatGPT”: When Companies Push Compliance Work Onto Untrained Employees.
This brings us to the next problem.
What if nobody is pushing employees to use ChatGPT at all?
They are simply already using it.
Every day.
On their own accounts.
If Management Knows, Doing Nothing Doesn’t Remove the Risk
Suppose a company knows that its employees regularly use generative AI.
It doesn’t want to ban it because productivity has improved.
That is understandable.
But there is a huge space between:
BAN CHATGPT
and
DO WHATEVER YOU WANT.
An organisation can instead decide:
- which AI tools are approved;
- whether work must be conducted through company-managed accounts;
- what information can and cannot be entered;
- when personal data must be removed or anonymised;
- which tasks require human review;
- which high-risk uses require approval;
- who is responsible for AI-generated output;
- how employees should handle confidential information;
- how AI use fits existing privacy, cybersecurity and records-management requirements;
- what happens when an employee leaves.
That isn’t about stopping innovation.
It is about putting some boundaries around something employees are already doing.
Should Companies Just Buy ChatGPT for Everyone?
That can be part of the answer.
If employees genuinely need generative AI for their jobs, companies should at least consider whether an approved business AI environment is more appropriate than allowing work to spread across employees’ personal accounts.
For example, ChatGPT Business provides an organisational workspace and OpenAI states that business workspace data is excluded from model training by default.
Organisation-managed ChatGPT accounts can also provide administrative controls that simply don’t exist when every employee independently decides how to use a personal account.
But buying licences is not the same thing as having AI governance.
A company can buy ChatGPT Business tomorrow and still have employees:
- uploading information they shouldn’t;
- relying on inaccurate output;
- failing to check generated documents;
- entering unnecessary personal data;
- using other unapproved AI tools;
- making decisions nobody has authorised AI to assist with.
Technology is only one part of the control environment.
Policy, people and process still matter.
Perhaps Employees Shouldn’t Be Asking, “Can I Use ChatGPT?”
Maybe the better question is: “If we’re all already using AI for work, shouldn’t the company have a proper way for us to use it?”
That is a conversation worth having with management.
Not:
“Please ban ChatGPT.”
But:
“Can we have an approved AI tool, clear rules and some basic training so we know where the boundaries are?”
That protects employees too.
Because the worst time to discover that something should never have been uploaded into an AI system is after something has gone wrong.
And If You Are the Company Reading This…
Perhaps you already know your employees are using ChatGPT.
Maybe you use it yourself.
The question isn’t whether AI exists in your workplace anymore.
It already does.
The question is whether its use is visible, controlled and understood.
Before spending thousands building an elaborate AI governance programme, even a smaller business can start with some fundamentals:
What AI do we use?
What data can employees enter?
What is prohibited?
Who checks AI output?
What happens with confidential information?
Do employees use personal or company-managed accounts?
Who is accountable?
If your organisation cannot answer those questions yet, that is the gap to address.
The answer does not necessarily have to begin with a complicated AI governance programme.
For smaller organisations, it can start with something much more practical: clear rules on approved AI use, what employees should never upload, how confidential and personal data should be handled, when human review is required, and who is responsible for the final output.
For organisations requiring more tailored support, LexMesos Solutions also provides AI Governance & Compliance Support, including internal policies, risk assessments and governance implementation.
Because the solution to unmanaged AI use may not be:
“Stop using ChatGPT.”
It may simply be:
“If everyone is already using it, it’s time to govern it.”
Keywords: ChatGPT at work, personal ChatGPT account, AI workplace risk, employee AI use, shadow AI, AI governance, AI compliance, company AI policy, ChatGPT Business, workplace data protection, confidential information, generative AI, AI risk management, AI Governance & Compliance Toolkit
This article provides general information only and does not constitute legal advice. Organisations should assess their own regulatory, contractual, confidentiality, data-protection and security requirements when adopting AI tools.
12 August 2026

