AI Tools at Work: How to Use ChatGPT and Copilot Without Leaking Company Data
William “BJ” Pote
CEO, eTop Technology
Here’s a pattern that shows up in audit logs at business after business. The controller is hitting ChatGPT every afternoon for about an hour, using it to draft client emails and clean up financial summaries. Productivity-wise it’s fantastic. Security-wise it’s a disaster waiting to happen, because what’s getting pasted in is actual client account balances, employee names, and internal financial commentary, all going into a free consumer tool that explicitly states it can use submitted content to train its models.
Nobody involved thinks they’re doing anything wrong. They’re just trying to get their work done faster.
This is happening in every business right now. Employees are using AI tools to write emails, summarize meetings, generate code, and analyze spreadsheets. Most of them have no clue where that data actually lives once they paste it in. And almost no small business has a policy that addresses it.
You can’t ban AI. The productivity gains are real, and your competitors are using these tools whether you like it or not. What you can do is make sure your team gets the upside without handing over your client list, your contracts, and your financials to a model training pipeline.
The Three Things Most Businesses Get Wrong
1. Treating All AI Tools the Same
There’s a big difference between ChatGPT.com on a personal account and Microsoft 365 Copilot tied to your tenant. Same underlying technology. Completely different data handling.
The free consumer version of ChatGPT, by default, may use your prompts to improve future models. Anything pasted in is potentially training fodder. The team and enterprise versions of ChatGPT, the API, and Microsoft 365 Copilot operate under different terms. Your data stays inside the boundary, isn’t used for training, and inherits the security and compliance posture of the platform it sits on.
Most businesses tell employees “don’t use ChatGPT.” Employees use it anyway because nothing else is available. The right move is to provide a sanctioned option with enterprise data terms and make it the easier path.
2. No Policy, or a Policy Nobody Reads
Half the businesses we work with have no AI policy at all. The other half have a policy buried in the employee handbook that nobody has looked at since onboarding. Neither approach changes behavior.
A useful AI policy is short, specific, and answers the questions employees actually have. Which tools are approved. What data can go into them. What data absolutely cannot. Who to ask if you’re not sure. That’s it. Two pages, not twenty.
3. Ignoring the Sharing Problem on the Microsoft 365 Side
Here’s the one almost nobody is ready for. Microsoft 365 Copilot is brilliant at finding information across your tenant. SharePoint, OneDrive, Teams, email, all of it. The problem is it can only respect the sharing permissions you already have set up. If your finance folder was technically shared with the entire company because someone got lazy with permissions five years ago, Copilot will happily surface salary spreadsheets to anyone who asks the right question.
Copilot is a magnifying glass on your existing permissions hygiene. If that hygiene is bad, Copilot makes it visible fast. Here’s the scenario that should worry you: a 60-person team rolls out Copilot, and within a week an account manager innocently asks “what does the senior leadership team make?” Copilot answers. Accurately. From a misshared HR file nobody has looked at since 2022.
The cleanup is doable, but it has to happen before you turn Copilot on, not after.
The Five Categories of Data and Where They Can Go
We use this framework with clients to make AI policy decisions concrete. Sort your data into five buckets and decide which AI tools each one is allowed to touch.
Public data. Marketing copy, press releases, public website content, published case studies. This can go into any AI tool, including consumer ChatGPT. There’s no risk because it’s already public.
Internal non-sensitive. Generic process documentation, internal memos that aren’t strategic, training materials. Approved enterprise tools only. No consumer tools, even if it feels boring. The principle is consistency, not paranoia.
Confidential business data. Pricing, customer lists, financial summaries, strategic plans, internal performance data. Microsoft 365 Copilot inside your tenant or other enterprise AI with a signed Data Processing Agreement. Never consumer tools, never personal accounts.
Regulated data. PHI (protected health information), PII (personally identifiable information), financial records subject to FTC Safeguards or WISP requirements, anything covered by HIPAA. Stricter still. Only AI services that meet your applicable compliance framework. For HIPAA that means a signed BAA (business associate agreement). For Microsoft Copilot in a properly configured tenant, the BAA already exists. For random AI tools, it doesn’t.
Privileged or trade secret data. Attorney-client privileged communications, source code that’s a trade secret, M&A discussions, board materials. Many businesses choose to exclude these from AI tools entirely, even sanctioned ones, because the risk-reward math doesn’t work.
If your team can answer “which bucket is this data in” before they hit paste, you’ve solved most of the problem.
What to Actually Do This Quarter
Step 1: Survey What’s Already Happening
You almost certainly have shadow AI usage right now. Microsoft Defender for Cloud Apps and similar tools can show you exactly which AI services your network is talking to. Most clients are surprised by what they find. ChatGPT, Claude, Gemini, Perplexity, half a dozen note-takers, AI meeting recorders attaching themselves to Teams calls, code assistants. The list is long.
You can’t write a policy that matches reality if you don’t know what reality is. Start with visibility.
Step 2: Pick One Sanctioned Stack
For Microsoft 365 shops, the path of least resistance is Microsoft 365 Copilot for Business or Copilot for Microsoft 365, depending on licensing. It runs inside your tenant, respects your existing security controls, has the BAA in place if you have one, and integrates with the apps your team already uses.
For specific use cases like coding or research, you might add a second sanctioned tool with appropriate enterprise terms. The key is having a clear answer when an employee asks “can I use AI for this?” The answer should be “yes, here’s the tool we pay for.”
Step 3: Clean Up Permissions Before You Roll Out Copilot
Before you turn on Copilot for Microsoft 365, audit oversharing. Run the SharePoint Advanced Management or equivalent reports. Find sites and files shared with “Everyone” or “All employees.” Restrict them to the actual audience that needs them. This is the single most important pre-Copilot project, and it’s the one most rollouts skip.
While you’re in there, apply sensitivity labels to confidential and regulated content. Copilot respects labels. A document marked Confidential won’t be summarized for someone who can’t read it. Without labels, Copilot uses raw permissions, which is exactly the problem.
Step 4: Write the Two-Page Policy
The policy should cover, in plain language:
- Approved AI tools and how to access them
- Data categories and which tools each can touch
- Specific prohibitions (regulated data into consumer tools, anything privileged into any AI, etc.)
- What to do if data was already sent somewhere it shouldn’t have been
- Who to contact for questions or new tool requests
Make it easy to read. Make it part of onboarding. Update it every six months because the AI landscape moves that fast.
Step 5: Train Specifically for AI Risk
Generic security awareness training does not cover this. The training that works walks through real examples. Here’s a good prompt. Here’s a prompt that just leaked client data. Here’s how to rewrite the second one to get the same answer without exposing anything sensitive.
The goal isn’t to make people afraid of AI. It’s to make them think for one second before they paste.
The Compliance Angle You Cannot Ignore
If you’re in a regulated industry, AI usage is increasingly showing up in audits and breach assessments. Staff pasting PHI into a consumer AI tool is exactly the kind of unauthorized disclosure HHS fines covered entities for. Cyber insurance applications now ask about AI governance directly. Some carriers are starting to deny claims where uncontrolled AI usage played a role in the incident.
If you’re working on HIPAA compliance, FTC Safeguards, or any state data protection requirement, AI tool governance has to be part of the program. The regulators are not waiting for you to figure it out.
The Bottom Line
AI tools are not going away, and you don’t want them to. The productivity gains for a 50-person company are real. The threats are also real, and they don’t look like the cyberattacks you’re used to defending against. The leak doesn’t come from an attacker. It comes from your most productive employee trying to do her job a little faster.
Get visibility into what’s actually being used. Pick a sanctioned enterprise stack. Clean up permissions before turning on Copilot. Write a short, useful policy. Train specifically for the patterns that matter.
We help businesses across the Inland Empire roll out Copilot the right way, including the unglamorous permissions cleanup that nobody else wants to do. If you want to see where your AI exposure stands, reach out — qualifying businesses receive our $2,500 IT Risk Assessment complimentary — and we’ll show you what your team is using, where the data is going, and what to do about it.
William “BJ” Pote
CEO, eTop Technology
eTop Technology has spent over 15 years in IT and over 12 years serving the Inland Empire as a trusted managed IT provider. We host the Business Tech Playbook podcast and are passionate about helping business leaders make smarter technology decisions.