Your team may already be using ChatGPT out of sight. Map the tools, inputs and account types with a simple inventory before writing a policy.

By Jason Sibley
The first sign of AI use in a small firm is rarely a formal project. It is more likely to be a browser tab. Someone pastes a difficult customer email into ChatGPT before lunch. Someone else asks Claude to tidy a proposal. A third person drops a spreadsheet extract into another tool because the formula will not behave.
Most of this starts with good intent. People are trying to get through the day. The problem is that the owner may have no idea which tools are in use, what has been copied into them, or which answers now shape work sent to customers.
That hidden use is often called shadow AI. The phrase sounds dramatic. In a small team, it is usually ordinary behaviour that has grown faster than the rules around it. The right first move is not a ban. It is a short, honest inventory.
Some owners assume that staff will wait for an approved company AI account. They will not always wait if a free tool solves a problem in five minutes. A policy stored in a folder does little if nobody can remember it when a customer complaint lands.
Others treat every AI product as if it handles data in the same way. Product tier and settings matter. OpenAI says content from services for individuals may be used to train its models, with opt-out controls available, while business products are excluded from training by default. Those are vendor statements, not a substitute for your own checks. Read the current OpenAI explanation of how data is used and its business data commitments before choosing an account type.
The largest mistake is to begin with surveillance. If the first question sounds like an investigation, staff will give careful answers rather than useful ones. You need to know where the work goes, not who to blame for finding a quick route through it.
There is also a false choice between allowing everything and blocking everything. A small firm can set sensible boundaries without building a compliance department. The Information Commissioner's Office says its AI and data protection guidance is under review following changes in law, so treat it as a live reference and check it again when your use changes.
Run a 20-minute team conversation. Ask where people already use AI to draft, summarise, research or analyse. Those verbs produce better answers than “Who uses ChatGPT?” because people may not think of a feature inside another product as AI.
Keep the tone practical. Try: “We want to make the useful work safer and easier. Which tasks have you tried, and what did you put in?” Write down the task, the product, the account type and the sort of information entered.
Do not demand old chat transcripts. The inventory is meant to show patterns. It is not a search of personal history.
Give every current use one of three plain labels:
The labels should reflect your firm and its contracts. They must also match your legal duties. They are not legal categories. Their job is to make the next decision obvious. Open material may be fine in an approved tool. Restricted material needs a much firmer review and may need to stay out altogether.
This is where small details matter. Removing a customer name does not always make a record anonymous. An address, order history or unusual complaint may still point to a person. The ICO's guidance puts responsibility on organisations using AI to consider data protection across the system's life. It does not turn responsibility over to the tool provider.
For each product, note whether the person is using a free personal account, a paid individual account or a company workspace. Then check the vendor's current terms and data controls.
Do not rely on a colleague's memory of a setting they changed last year. Capture a link to the relevant vendor page and the date you checked it. If you use Claude for commercial work, for example, Anthropic says it does not use commercial inputs or outputs for training by default unless a customer opts in through specified routes. Its commercial data training explanation sets out the detail and exceptions.
A vendor promise still does not answer every question. You may also need to consider retention, access, subprocessors or where information is stored. The depth of review should match the data and the consequence of getting it wrong.
An AI draft may contain a false fact, a bad assumption or wording that you would never knowingly send. Add a “checked by” step for anything that affects a customer, a payment, a contract or a material business decision.
Name the person who is responsible for the finished work. “The AI wrote it” is not an approval route. If nobody would be comfortable signing their name to the output, it is not ready to leave the firm.
Your first version can be short. List the approved tools and account types. State what must never be pasted. Name the work that requires a human check. Give people a route for requesting a new tool.
Add two real examples from your own work. “Do not paste customer records” is clear, but “Do not paste a support ticket containing a name and order details into a personal AI account” is easier to act on at 4.45 pm.
Review the page once a quarter, and when a tool or use changes. The inventory will date quickly if it becomes paperwork rather than a working habit.
Book one 20-minute session with the whole team. Leave with a four-column list: task, tool, input type and account. Pick one owner to check the top two tools against their current vendor terms and your data duties.
Do not try to write the final policy in that meeting. Your aim is a truthful map. Once you have it, choose one risky use to stop or move into an approved company setup, and one useful use to support properly.
If the inventory shows ten different experiments and no shared way of working, our SMB AI sessions give the team space to agree practical boundaries around the work they really do. You leave with decisions people can follow, rather than a thick policy nobody opens.