Back to the Archive

LibraryFoundational AI: Do's and Don'ts10 min read

Your Team Uses Personal AI Accounts. Ban It Or Buy It?

Twelve people on a paid AI workspace runs about $2,880 a year. Twelve people on their own logins runs zero, and what that zero buys is a set of data terms somebody on your payroll agreed to on their phone.

Twelve employees use AI on personal phones; one scrolls past sharing terms as a manager eyes an unused $2,880 dashboard.

Twelve people on a paid AI workspace runs about $2,880 a year. Twelve people on their own logins runs zero, which is what you are paying today. What that zero buys you is a set of data terms somebody on your payroll accepted on their phone in about four seconds, applied to your customer list, your pricing, and the contract your lawyer marked up last spring. You probably found out the way most operators find out, which is over a shoulder. Somebody had a customer's email pasted into a chat window, getting help with a reply, and they were not hiding it, because it never occurred to them that it was the kind of thing you hide.

So now you are holding the question. Do you ban it, or do you pay for it.

The answer: buy the workspace first, then run an amnesty

Pay for it. Buy the cheapest real workspace on whichever tool your people are already using, before you write a single line of policy. Then tell the whole team, out loud, that nothing anybody did up to this point is a problem, and ask them what they have been using it for.

That order matters more than the decision itself. If you announce a policy before you have somewhere legitimate to put the work, you have not stopped anything. You have just taught everyone that the honest answer to "are you using AI for this" is no.

A ban is the wrong instrument here, and not because it is harsh. It is the wrong instrument because it is unenforceable on a personal device and because it destroys the only useful information you have. Your people are not doing this to be reckless. They are doing it because it removed a step from a task they cared about, which means every one of those chat windows is a free report on where your workflows are slow. Ban it and the behavior moves to a phone. The report stops.

The account type is the contract, not the feature list

Here is the part almost nobody explains to an owner, and it is the whole thing.

The free ChatGPT account and the paid business account are running the same model through the same box. What differs is which agreement governs what goes in. OpenAI's own documentation says that on Free, Plus, and Pro in a personal workspace, data sharing for model training is on by default, and that the person holding the account can turn it off under Settings. On ChatGPT Business, Enterprise, Edu, and the API, the same page says the default runs the other way: inputs and outputs are not used for training unless somebody deliberately opts in.

Anthropic drew the same line and drew it publicly. In its update to the consumer terms, new and resumed chats on the consumer plans became eligible for model training by default, with retention stretching to five years for anyone who leaves that on and thirty days for anyone who does not. The update states plainly that none of it applies to Claude for Work, the API, Bedrock, or Vertex. Those run under commercial terms.

Read those two documents next to each other and the actual situation resolves. The question was never which AI tool is safe. The tools are the same tools. The question is who holds the setting, and right now the answer is that a setting governing your customer list is sitting inside an account you do not administer, owned by somebody who may leave in March.

That is also the practical half of it. A personal account has no admin console, so you cannot see usage, cannot enforce sign-on, cannot set retention, cannot run an export, and cannot recover any of the work when the person who built it walks out. Cyberhaven's telemetry puts the scale of that at roughly a third of all ChatGPT usage happening through personal accounts, which by their reading bypasses single sign-on, central logging, and retention policy in one move. Treat vendor telemetry as directional rather than as a census. The direction is not in dispute.

How much of this is already inside your building

A survey of 500 employed US adults run through Pollfish on July 8 of this year, commissioned by a California business litigation firm, found that 38 percent had entered at least one category of work information into a personal AI account their employer does not control. Twenty three percent had pasted internal emails, memos, or documents. Just under twelve percent had put in customer or client information, and about the same share had put in contracts or legal documents.

Two numbers from that survey matter more than the headline. Sixty four percent did not know that doing it could, in some circumstances, be illegal. And only about 36 percent said their employer had any clear written policy on what could be shared with an AI tool at all.

Sit with the second one for a second. In roughly two thirds of workplaces, nobody has ever told anybody what the rules are, and then the same employers are surprised to learn the rules were being broken. There is no failure of character in that data. There is a failure to say anything.

Five hundred respondents on a panel is a small sample and it is a law firm's marketing research, so hold the decimal points loosely. The order of magnitude is the usable part, and the order of magnitude says that if you employ more than about ten people, this is already happening in your shop and you have a decent chance of not knowing which ten it is.

The part of this that is not a security problem

Most of the advice you will find frames this as data leakage, which makes it sound like a breach notification waiting to happen. For a company your size, that is probably not where it bites you.

Where it bites you is the day you try to stop somebody from taking your customer list to a competitor. Trade secret protection in the US turns on a specific element: that the owner took reasonable measures to keep the information secret. Litigators have spent this year writing about what generative AI does to that element, and the argument they keep making is uncomfortable and straightforward. Handing confidential information to an outside platform under consumer terms, with no confidentiality agreement in place, looks a great deal like voluntary disclosure, and voluntary disclosure is the thing that kills the reasonable measures argument before you ever get to the merits.

Nobody needs to have stolen anything for that to hurt. You bring the claim, and the other side asks, in discovery, where else your customer list has been. If the honest answer includes three personal chat accounts on consumer terms with training left on, your reasonable measures argument now has to survive that answer.

The second bite is contractual. If you do work for clients under an agreement with confidentiality terms or a named list of subprocessors, and your account manager is running client material through a personal AI account, you have an undisclosed subprocessor. That is not a theoretical problem. That is a clause you signed.

Neither of these shows up next week. Both show up in the year you can least afford them.

What the amnesty actually looks like

The mechanics are smaller than the problem sounds.

Buy the seats quietly, a week or two before you say anything. ChatGPT Business is twenty dollars per user per month on annual billing, twenty five monthly, with a two seat minimum. For a twelve person shop that is the $2,880 from the first paragraph, and you should not buy twelve seats on day one anyway. Buy for the people who are already doing it, which you are about to find out.

Then hold one twenty minute meeting and say three things. Nobody is in trouble for anything that has already happened. Tell me what you have been using it for, because I want to pay for the good version of it. And from today, here are the categories that do not go into any AI account, sanctioned or not.

Name categories, not tools. Tools change every six weeks and a list of banned product names is stale before the meeting ends. Four categories cover most small businesses: anything identifying a specific customer or patient, anything under a signed confidentiality agreement, anything about a specific employee, and credentials of any kind. That list fits on one page and a new hire can actually remember it.

Then do the boring part, which everyone skips. The useful prompts do not migrate. Whatever your best estimator worked out over four months of fiddling lives in a personal chat history that no admin console can reach, and the only way it moves into the workspace you now pay for is if somebody sits down and pastes it across. Put that on a calendar or it will not happen, and in eight months the workspace will be a line item nobody opens while the real work is still happening on a phone.

The honest take

A business plan does not make the data safe. It makes it contractual, which is a genuine improvement and a much smaller one than the vendor will imply.

The model still sees the content. It is still stored on somebody else's infrastructure, subject to a retention window and to legal process. Your workspace admins can generally read it, which is worth telling the team before they discover it themselves. And "we do not train on this" is a sentence in a policy document, not a law of physics. Anthropic's consumer terms changed in 2025 and users were given a checkbox and a deadline. The setting you are relying on is a setting. It can move, and if it moves you will hear about it the way you hear about everything, which is late.

There is a real tension with the cost argument too. The free tier has become a genuinely capable deployment target, and for plenty of small-company work it is the right call. But free is a consumer account, and the account type is the contract. Free is fine for rewriting a paragraph of your own marketing copy. It is not fine for a customer email, and the reason has nothing to do with the quality of the answer.

If you are in a regulated line, health, financial advice, legal work, the workspace is the floor and not the answer. You still need the signed agreement that covers the data, you still need to check your own client contracts for subprocessor language, and you need to do that before the amnesty meeting rather than after it, because you are about to learn things you will then have an obligation to act on.

And the uncomfortable one. Most of that 38 percent were trying to do their jobs well. The customer email ended up in a personal account because a reply that took forty minutes took eight, and nobody was offered a sanctioned way to get that eight. If your response to finding out is disciplinary, you will not stop the behavior. You will stop hearing about it, and you will keep paying the $2,880 while the real work continues somewhere you cannot see, which is the worst of every available outcome: the cost of the workspace, and none of the visibility you bought it for.

The seat was never buying a better model. It was buying back the right to know what your company has already said out loud.

Sources

Every claim above traces back to one of these. Go read them yourself.

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05
    2026 AI Adoption and Risk Report

    Cyberhaven / cyberhaven.com / retrieved Sep 15, 2026

  6. 06
    Is Your AI Tool Quietly Destroying Your Trade Secrets?

    Troutman Pepper Locke / troutman.com / retrieved Sep 15, 2026