Answer · AI in the team · Guardrails

Our team uses ChatGPT without any rules — what now?

In short: don't punish it — govern it. The fact that your people use ChatGPT of their own accord is initiative, and initiative is valuable. Without guardrails, though, it is a liability risk: customer data ends up in third-party systems, data protection rules get broken, false statements go out in the company name. The fix has two parts — clear rules and real skill. A one-day workshop on site delivers both, and satisfies the training obligation under Article 4 of the EU AI Act along the way.

Porträt von Matthias Eger — Experte für KI & IT im Mittelstand, Weiden in der OberpfalzAuthorMatthias EgerCertified Manager for Applied AI Transformation (IHK)
Last reviewed17 Jul 2026
To the verification record

The good news first: your team is further along than most.

In many businesses the boss is fighting to get anyone to touch a new tool at all. In yours, people try things unprompted — that is the fastest route to improvement and a sign that your team thinks for itself. Punish it now, or ban it across the board, and you drive usage underground: private phones, private accounts, zero visibility. You then have exactly the same risks — only without knowing about them.

The bad news: without rules, you are liable for every prompt.

Unmanaged use is not a motivation problem. It is a liability risk, on three levels:

  • Customer data in third-party systems. Whatever an employee types into a public chatbot leaves your building — onto servers whose location and purpose you do not control. Names, costings, contract details: once entered, they cannot be pulled back.
  • Data protection. Processing personal data in a third-party system without a legal basis is a GDPR breach — and you as the owner answer for it, not the employee who meant well.
  • False statements in the company name. AI models invent facts when they are missing them. If an unchecked text goes out to a customer, a supplier or an authority, your company name is on it — not “ChatGPT said so”.
And the obligation already applies

Since 2 February 2025, Article 4 of the EU AI Act has required deployers of any size to ensure AI literacy in their team — including the five-person business where people “only” work with ChatGPT. Anyone letting their team use it without training is already in breach of that obligation today. What Article 4 actually requires →

Immediate measures

Three rules you can apply from tomorrow.

No 40-page document, no working group. These three sentences stop the biggest risks — you can announce them at today's morning briefing.

01

No customer data in public chatbots.

Names, addresses, costings, contracts — none of it goes into systems whose servers you do not know. Anonymise it or leave it out. What may go in, and which tools have been vetted, is something you sort out in the second step.

02

Nothing goes out unchecked.

AI delivers drafts, not results. Whoever creates something with AI checks it before it reaches customers, suppliers or authorities — and puts their name to it. That is exactly the rule my own business runs on.

03

One person wears the hat.

Name a person where questions, tools and borderline cases come together. Not automatically the youngest — but whoever knows the business and can say no. Without someone accountable, rules stay on paper.

These three rules are the emergency brake — they prevent damage, but they do not build any skill yet. For your team to use AI safely and productively rather than merely cautiously, you need the second part.

The solution

Guardrails plus skill.
Not bans.

One day on site, on your real work: the AI Day shows what AI can do and where it lies, produces a one-page set of rules in plain language — and documents content and attendance as evidence for Article 4. Unmanaged use turns into skill with rules, and your people keep their initiative.

Are employees allowed to enter customer data into ChatGPT?

No — not into public chatbots. Whatever is entered ends up on third-party servers outside your control; with personal data that is usually a data protection breach, and you as the owner answer for it. Customer data belongs in anonymised form, or in systems that have been vetted for it. How to do that without risk →

Should I simply ban ChatGPT in my business?

No. A ban pushes usage into private hands — private phones, private accounts, the same risks, only now you never hear about them. Clear rules about what may go into which AI are better, plus training so the team can work with it safely.

Which rules do we need straight away?

Three are enough to begin with: no customer data in public chatbots, no AI output leaves the building unchecked, and one named person owns the topic. Everything else belongs in a short set of rules written in plain language — that is what comes out of a workshop day.

End the free-for-all. Keep the initiative.

One day on site: rules and skill for the team · evidence for Article 4 included

Request a workshop
Get in touch