ChatGPT at work: what you as an employee may and may not do
Can you use ChatGPT at work? A plain guide for employees: three questions to ask, what is safe, what to avoid, and your rights under the EU AI Act.
An article for you, not about you
Most articles about AI at work are written for managers, HR people or compliance officers. For you, the employee who still has three emails to write at four in the afternoon and no energy left, something clear is rarely written down. This is that article. Not a cautionary tale, not a ban, not a "think carefully before you type". Instead, an honest look at what you may do, what you may not do and how to make the right call yourself.
Can your employer see what you ask ChatGPT?
This is the question people ask most often and the one that most rarely gets a plain answer. It depends on two things: which account and which device.
Personal account on your own laptop or phone. Your employer cannot see your chats.
Personal account on your work device or over the company network. Ordinary network logging usually makes it visible *that* you are visiting the service, but not what you type in an encrypted chat. Be aware: on a managed work device, additional corporate software can technically see more, for example tooling that prevents data loss or manages the browser.
Monitoring is not a free-for-all. An employer must have a legitimate purpose, go no further than necessary and have announced the monitoring in advance. Individual monitoring of content is subject to strict conditions. For the private sector in Belgium this is worked out further in collective labour agreement no. 81; the underlying data protection principles apply more widely, including within a local authority.
Work account. Here the answer is: in principle yes. With ChatGPT Business or Enterprise, Copilot in Microsoft 365 and Gemini in Workspace, an organisation can reach chat history depending on the configuration. That does not happen through an administrator reading along live, but through compliance and retention functions, usually in the context of a formal investigation, an audit or a legal dispute.
The practical conclusion is simple. Assume that on a work account it *can* be visible. That is no reason not to use it, because that is exactly what your employer is paying for. It is a reason not to type anything into it that you would not say in a team meeting.
First, the reality
This stopped being only about ChatGPT a long time ago. There is Copilot in Microsoft 365, Gemini in Google Workspace, Claude on a growing number of workplaces and, alongside all that, almost everyone occasionally uses something off their own bat. In knowledge work, AI use is now the rule rather than the exception and in a large share of those cases it happens without formal permission, without policy and without clear agreements.
We call that shadow AI: AI use that stays under the radar. We researched how big the problem really is in our whitepaper on shadow AI in SMEs. The finding in one sentence: the first person to suffer when it goes wrong is you, not the board. Which is why it matters that you know the rules yourself, even if nobody has explained them to you.
Start with your own organisation's rules
Before you get to the questions below: check whether your organisation has an AI policy, an IT acceptable use policy or staff regulations that say anything about this. That always takes precedence over general tips from an article, including this one.
Two things people commonly get wrong. The fact that your organisation has rolled out a corporate AI account does not mean every use of it is permitted. And the absence of a policy does not mean anything goes: the confidentiality obligation in your employment contract simply continues to apply.
Nothing there at all? That is not unusual. We wrote two pieces you can forward to whoever does own this: a two-page AI policy template that can be filled in today, and an article on why an AI policy on paper does not yet steer behaviour. Not sure whether your organisation really needs one? Then run through the 5 signs an organisation needs an AI policy.
The three questions to always ask yourself
Question 1: whose information is this? This is the most important question and it is less simple than it looks. An email you wrote yourself feels like your information, but it can be full of client data, prices or internal agreements. Notes from a client conversation are somebody else's information. A letter of application, a patient record, a citizen's file: very definitely somebody else's.
Think wider than privacy alone. Professional secrecy, trade secrets, contractual confidentiality and third-party copyright fall under this question just as much. A draft contract may contain no personal data at all and still be the last thing you should paste into a public model.
Question 2: which account am I on, and does this belong there? A work account runs under a contract your employer has signed, with agreements on training and retention. That makes it safer. It does not automatically make every use permitted; purpose, content and internal agreements remain decisive. On a personal or free account those agreements do not exist at all, so the threshold is far lower.
Question 3: how would I feel if my employer, client or colleague were looking over my shoulder? Not a moralising question, but a practical one. If the answer sits somewhere between "uncomfortable" and "panicked", that is a sign you should approach it differently.
What is generally safe
That it is allowed does not mean you will get good results from it, mind you. The gap between a mediocre and an excellent answer lies rarely in the model and almost always in how you frame the request, as we explain in Most people use AI the wrong way. If you want to get that under control systematically, our short course Effective AI at Work is built for exactly that.
Where you should think twice
If you work in healthcare, education or for a local authority, sector-specific considerations apply on top of the above. Those are set out for healthcare organisations, for schools and educational institutions and for local authorities.
And now there are AI agents too
Until recently, AI was something that answered. Increasingly it is something that *acts*: an agent that drives your browser, fills in forms, drafts and sends emails or carries out tasks while you do something else. The difference between the two is bigger than it looks, as we describe in The chatbot checks with you. The agent just does it.
That is a different kind of risk and most policy documents are behind on it. Three rules you can apply yourself.
Never let an agent send anything under your name that you have not read yourself. A draft is a draft. Sending is an act with your name on it.
Be aware that an agent can pick up instructions from what it reads. A web page or an incoming email can contain text designed to make the agent do something other than what you asked. This is called prompt injection and it is not a theoretical scenario. So do not give an agent more access than the task requires.
No agents on money, contracts or irreversible steps. Payments, orders, deletions, signatures: you do those yourself.
Already working with these tools without any agreements in place? AI Agents is the shortest route to a shared understanding across the team.
What you should never do
Entered something sensitive anyway? Report it
Everyone at some point pastes something and thinks a second later: I should not have done that. The reflex is to close the window and hope nobody notices. Do not do that.
Report it to your manager, IT, security or the data protection officer, following whatever procedure your organisation has for this. Reporting quickly limits the damage and, in the case of a genuine data breach, is even mandatory for your organisation, with short deadlines. Staying quiet turns a slip into a problem you face alone.
Does your organisation not have such a procedure? Then you are welcome to use ours as an example: our own AI Incident Procedure is published openly on this site, as is our AI Usage Policy.
What the law says about this
Briefly, and only the part that affects you.
Your employer has to do something about AI literacy. Since 2 February 2025, Article 4 of the EU AI Act has applied: whoever deploys AI must take measures so that the people working with it understand it well enough. That obligation sits with the organisation, not with you. What it means in practice is set out in our article EU AI Act Article 4: what does it mean in practice for your organisation.
That obligation was rewritten this summer. With the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, Article 4 has been reformulated. Organisations must now "take measures to support the development of AI literacy" and it says explicitly that they do not have to guarantee any specific level of knowledge for any individual. More mildly worded, then, but not optional. There is no prescribed course length, no mandatory curriculum and no mandatory certificate; what is appropriate depends on the organisation, the systems and the risks. What else shifted is explained in The Digital Omnibus changes the EU AI Act. But not in the way you think.
Article 4 has no European fine band of its own. The heaviest fines in the AI Act attach to the prohibited practices in Article 5, not here. Member States can, through their national penalty regimes, provide for administrative fines and other enforcement measures. On what exactly changed on 2 August 2026 we wrote a separate piece.
The heavy requirements for high-risk AI have been postponed. The core obligations for the high-risk systems in Annex III apply from 2 December 2027, for AI embedded in regulated products from 2 August 2028, and for certain systems intended for use by public authorities until 2 August 2030. AI deployed to filter applications or assess candidates falls in principle within that high-risk category. Having a job advert rewritten does not. Postponement is not cancellation, incidentally, and it changes nothing about the GDPR: that applies in full today.
Transparency rules have applied since 2 August 2026. Article 50 requires among other things that people know when they are dealing directly with an AI system and that synthetic content is machine-readably marked, with separate rules for deepfakes. It is not a general duty to visibly label every AI-generated email or text as AI. When it *is* required is worked out situation by situation in Do I need to label AI? 7 everyday situations from Article 50.
The rules keep moving. If you want to keep up without chasing it yourself, we track it daily in the EU AI Act Monitor.
What if your employer has no policy?
That is the situation of most people reading this. And no, it is not your job to write that policy. But there are two things you can do yourself.
You can raise it with your manager or HR. Not as criticism, but as a practical question: "I sometimes use AI to improve my emails. Is there a line on that?" Many managers are more open to it than you would think, because they use it themselves and feel uneasy about it. Take our free EU AI Act Compliance Checklist along if you like, then the conversation has an agenda straight away.
And you can ask what is being arranged on AI literacy. Your organisation has had to take measures on this since February 2025. What form those take is up to them, but asking the question is entirely normal.
Finally
AI at work is not a luxury problem and not a debate for insiders. It is in your browser, in your office environment and soon in tools that do things independently for you. It shortens your working day and it can land you in trouble if you use it wrongly.
The good news: you do not need to become a lawyer to get this right. Know whose information you are entering, know your own organisation's rules, read back what carries your name and report it straight away if something goes wrong. That is all it takes to stay on the right side.
Want your organisation to sort this out properly so you can work with AI without hesitating? Share this article with your manager or HR. We help organisations put AI literacy into practice and document it, with short AI literacy training of twenty to thirty minutes for staff, managers, HR and IT. Finding out where you stand is free with the AI Adoption Scan. And if you would rather talk it through first, just get in touch.
Written by Rob Ummels in collaboration with Claude (Anthropic). Final editorial responsibility: AIAdopt. Updated 7 August 2026.
Want to know where your organisation stands?
Download our free EU AI Act Compliance Checklist or view our AI literacy training.