Guides / AI reality

Is ChatGPT safe for company data?

It's not really a question about the tool. It's about which account the data goes into, and about the people already using their own because nobody gave them one. Here's the straight version, including what changes if you touch controlled work.

The honest answer is that it depends on which account the data goes into, and the gap between the answers is enormous. The same sentence typed into a personal free account and into a properly configured business account is two completely different decisions. If you've never sorted out which account people are using, the worry never turns into a decision.

I'm not your lawyer or your compliance officer, and this isn't settled ground. What follows is how I set this up for manufacturers and where I tell people to stop and get a real opinion.

Consumer account or business account

Consumer accounts and business accounts are governed by different terms. That's the whole thing in one line. On the consumer tiers of most AI tools, the default handling of what you type is more permissive, and the settings that change it live in a menu nobody on your staff has opened. On business and enterprise tiers, the vendor is contractually on the hook: your content isn't used to train the models, your administrator controls how long it's kept, and you get an audit trail.

There's no single answer. Ask these instead:

The exposure you already have, whether you approved it or not

If your company hasn't provided a sanctioned AI tool, some of your staff are already using their own. Not out of malice. Somebody has a long email to write, or a spec to summarize, or a spreadsheet formula that won't behave, and there's a free tool one tab away that helps.

That's the real leak, and a company-wide ban doesn't close it. Bans push the usage somewhere you can't see, so now you can't see it at all. The people writing the policy find out how much of it was happening only when somebody mentions it casually months later.

Giving people a sanctioned account is a security measure, not a convenience. It's the only version of this where you know what's being used, under what terms, by whom. The companies that handled this well didn't decide whether AI was safe in the abstract. They gave people a better option than the free tab they were already using.

What manufacturers specifically shouldn't paste anywhere

Two things in this industry get their own rule, because getting them wrong isn't just a business problem:

There's a government-cloud option for the controlled work that keeps it inside the boundary. And most of what would actually help your office is nowhere near that line anyway. Quote follow-ups, vendor emails, summarizing a procedure, finding what you already wrote down. You can get a long way without the controlled material ever entering the picture.

How I set it up

It's the same setup every time:

I'm not tied to one vendor. Most often that's Claude set up around your business; if you already run Microsoft or Google, it fits to that instead. The point was never the brand on the tool. It's that your data stays in your hands and the thing actually knows your business.

From the work
Set up by a manufacturer who has sat through the audits

I spent my career in manufacturing, including a decade running a machine shop, so the documentation discipline behind this is familiar territory rather than something read about. The AI setups I stand up are configured around how a regulated operation actually has to work, and I'll tell you plainly when the honest answer is that a piece of your work should stay out of these tools entirely.

How the AI setup works →

Common questions

If we use a business tier, can our data still end up training a model?

On the business and enterprise tiers of the major vendors, no, and that commitment is in the contract rather than in a settings toggle. The thing to verify is that everyone is actually on that tier. One person still logged into a personal account undoes the arrangement for whatever passes through it.

Is a locally hosted model the safer answer?

Sometimes, and it's genuinely the right call for some controlled work. It isn't automatically safer, though. You take on running it, patching it, and controlling access to it, and a poorly administered local system isn't more secure than a well administered hosted one. It's a real option with a real operating cost attached, not a shortcut around the question.

Our customers ask whether we use AI. What do we tell them?

Tell them the truth, including which tier and what the terms say. Increasingly customers are writing AI clauses into their agreements, and being able to answer the question specifically is turning into a small competitive advantage. The companies that will struggle are the ones who have to answer that they don't know.

Where should we start?

Find out what's already being used. Not to discipline anybody, but because you can't write a sensible policy about a situation you haven't measured. From there it's a sanctioned account, a one-page rule about controlled material, and putting your own knowledge into it so it's genuinely more useful than the free tab people are using now. That last part is what makes anybody switch, and it's covered in an AI knowledge base that knows your business.

Contact

Want a straight answer for your own operation?

First call's free. About 30 minutes, a straight conversation about what your people are already doing and what your customer agreements actually require, not a demo. If there's something worth setting up, I'll say so; if there isn't, I'll say that too.

Email Jason How the AI setup works →