ChatGPT Use Policy for Employees: Rules, Examples and a Short Template
ChatGPT and similar AI assistants are the tools employees use most. A focused policy for them answers the everyday question: can I use this for my work, and how?
Short answer
A ChatGPT use policy for employees should state whether ChatGPT and similar assistants may be used, which versions are approved (typically enterprise versions with contractual data protections rather than personal consumer accounts), what information must never be entered, which uses are acceptable, that users must check outputs and remain responsible for their work, when to disclose AI use, and how to report problems. The same rules usually apply to similar assistants such as Claude, Gemini and Copilot.
Key takeaways
- Distinguish approved enterprise versions from personal consumer accounts.
- Personal and confidential data rules are the most important part.
- Give concrete do and don't examples.
- Apply the same rules to all similar AI assistants.
Consumer versus enterprise versions
| Personal consumer accounts | Approved enterprise versions | |
|---|---|---|
| Contract with employer | No | Yes |
| Data used to train models | May depend on user settings and provider terms | Typically excluded by contract |
| Admin controls and logging | No | Yes |
| Suitable for confidential data | No | Only as defined by policy |
Check the current terms of any provider; they change over time.
Do and don't examples
| Do | Don't |
|---|---|
| Draft an email to a customer without including their personal details, then edit it | Paste a customer complaint containing names and account numbers into a personal account |
| Summarise a public report | Upload a confidential board paper to an unapproved tool |
| Brainstorm interview questions for a role | Paste candidates' CVs into a consumer chatbot to rank them |
| Ask for an explanation of a concept | Rely on an AI answer about law or policy without checking the source |
| Improve the clarity of your own writing | Submit AI-generated work as entirely your own where disclosure is required |
Short ChatGPT policy template
Use of ChatGPT and similar AI assistants. You may use [approved tools] for work purposes. Do not use personal accounts for work. Never enter personal data about colleagues, candidates or customers, confidential business or client information, or passwords into any AI assistant unless the tool is approved for that data. Check all outputs for accuracy before use; you remain responsible for your work. Disclose AI assistance where it matters to the recipient or where required. Do not use AI assistants to make decisions about individuals' employment. Report any data incident or harmful output to [contact]. This guidance forms part of our [AI policy].
For the complete policy, see the AI acceptable use policy template. For prompt guidance, see ChatGPT prompts for HR.
This is general information and a starting template, not legal advice. Adapt it to your organisation, jurisdictions, works council or union agreements and sector rules, and have it reviewed by qualified counsel.
Related guides
- AI Policy for Employees: Why You Need One and What It Should Cover
Why an employee AI policy is essential, what it covers and who owns it.
- Generative AI Acceptable Use Policy Template for Employees
A copy-ready 15-section AI acceptable use policy template to adapt for your organisation.
- Generative AI for HR: Uses, Risks and How to Get Started
What generative AI is, where it helps HR, what can go wrong, and how to start safely.
- AI and Employee Data Privacy: A Guide for HR
How AI changes the privacy picture for employee data, the principles that apply and practical safeguards.
Frequently asked questions
Can employees use ChatGPT at work?
That depends on your organisation's policy. Many organisations permit approved enterprise versions with clear data rules and prohibit personal consumer accounts for work.
Is ChatGPT safe for confidential information?
Consumer accounts should not be used for confidential or personal data. Enterprise versions with contractual protections may be approved for defined categories of data under company policy.
Should we ban ChatGPT at work?
Blanket bans tend to push use into unapproved tools. Providing an approved version with clear rules and training is usually safer and more productive.
Does a ChatGPT policy apply to other AI tools?
It should. Apply the same rules to similar assistants such as Claude, Gemini and Microsoft Copilot, ideally within one general AI policy.
