Guide

ChatGPT at work: the clear-eyed guide

What ChatGPT does well at work, which plan sends which data where, what the law says, and the minimal charter before letting your teams use it.

Published July 18, 2026

Yes, you can use ChatGPT at work. Your teams probably already do, with or without your blessing: according to IDC (2025), 86% of French companies send sensitive data to non-sovereign AI tools. So the useful question is not "should we allow it" but "within what framework", and that question deserves clear eyes: what the tool does well, where the data goes depending on the plan, and what stays your responsibility no matter what.

This guide covers all of it, without a prosecution and without an advert.

What ChatGPT does well at work

Start with the part the warnings leave out: the tool is genuinely useful. Writing and rewording, summarising long documents, preparing a presentation outline, getting oriented on an unfamiliar topic, everyday code, clean translation. On these tasks the time saved is immediate, and your teams understood that before you did; that is exactly why spontaneous use keeps growing.

The right frame is augmentation: the tool prepares, the human checks and decides. An assistant's answer is a first draft, not a source.

The plans, and where the data goes

This is the part almost nobody reads, and the most important one.

Consumer plans (the free account and individual subscriptions) may use conversations by default to improve the models. A setting turns this off, but it relies on each employee's discipline, on a personal account, outside your control. Client data in a free personal account: that is the scenario your governance must make impossible.

Business plans (team and enterprise) exclude training on your data by default, add centralised administration and contractual commitments, and offer European data residency.

Two questions must be kept apart, though marketing likes to blur them. Training: does your data improve the models? Business plans settle that. Jurisdiction: who can compel access to your data? No subscription settles that one, because the operator remains American, and therefore subject to the Cloud Act, wherever the data resides. Upgrading fixes the first question, never the second.

What the law says

The GDPR does not mention ChatGPT, but it points at you: as soon as your teams process personal data there, you are the data controller, with everything that implies about legal basis, information and risk analysis. The CNIL publishes general guidance on AI but no framework dedicated to generative AI at work yet: the analysis is yours to carry. The AI Act adds obligations in waves, including a deadline on 2 August 2026.

For regulated professions, professional secrecy comes on top of the GDPR and cannot be negotiated by contract. We cover it in a dedicated guide for law firms.

The real risk: the usage you cannot see

The main risk is not the tool, it is shadow AI: spontaneous use, on personal accounts, with no rule and no trace. Banning without an alternative does not remove it, it makes it invisible: teams carry on from their phones, and you lose both control and visibility.

What works takes two moves: govern the usage, and provide a company-sanctioned tool at least as convenient as the workaround.

The minimal charter

Six decisions take you from suffered usage to governed usage:

  1. Inventory what exists: who uses what, on which account, for which tasks. Without judgement; the goal is to see.
  2. Ban personal accounts for any professional use: if the company allows the tool, the company provides the account.
  3. List the forbidden data: identifiable client data, health data, trade secrets, anything covered by professional secrecy. A short list, postable, unambiguous.
  4. Lock the settings: training excluded, centralised administration, European residency where offered.
  5. Require human review: any output headed for a client, a court, an administration or a decision goes through a review that commits its author.
  6. Revisit every six months: plans, models and your own usage move too fast for a charter carved in stone.

When ChatGPT stops being the right answer

A subscription, even well configured, reaches its limit in three situations: when the data at stake must not depend on a foreign jurisdiction, when your governance requires knowing who did what with which data, and when you expect AI to carry out work inside your tools rather than answer in a chat window.

Those three needs define another category of tool: the sovereign alternatives, up to the instance you own, with agents working on your data and your tools, in France.

Frequently asked questions

Is ChatGPT dangerous for a company?

The tool is not dangerous in itself; ungoverned usage is. The real risks are well identified: sensitive data sent from personal accounts, unchecked outputs reused as-is, and dependence on an operator under foreign jurisdiction. Each one is handled by a rule, not by a blanket ban.

Can an employee use ChatGPT without permission?

No law forbids it; setting the rule is the employer's job, as with any tool. As long as the rule does not exist, the usage exists anyway, unframed: the worst of both worlds. A short charter and a professional account change the situation within a week.

Has the CNIL banned or regulated ChatGPT?

Neither, to date. The CNIL publishes general AI guidance and handles complaints, but has issued no framework specific to generative AI at work. The absence of doctrine does not protect you: the GDPR already applies, and it points at you.

Which ChatGPT plan should a small company choose?

If you stay on ChatGPT, the minimum is a business plan: training excluded by default, administered accounts, contractual commitments. Plan details change fast and are best read on the vendor's site. Keep the criterion in mind: the subscription settles training, not jurisdiction.

Can a company ban ChatGPT?

Yes, the employer sets the rules for its tools. But a ban alone almost always fails: usage moves to personal phones and becomes invisible. If your constraints justify ruling out ChatGPT, the logical conclusion is to offer better, not to offer nothing: let's talk.