Putting company data into ChatGPT hands it to a service outside your organisation, and on a personal account you lose control of it. The risk lies less in the tool than in unmanaged use. The answer is not a ban: approve specific tools, list data that must never be entered, and offer a permission-controlled internal assistant for sensitive work.
What staff actually paste into ChatGPT
A salesperson pastes a quotation — customer name, discount and product list included — to polish the wording. A developer asks about a failing function, connection string and all. Someone in HR hands performance reviews to an AI to "make them sound kinder". None of them means any harm; they are all trying to work faster.
The problem comes together in three places:
- The account is personal. Conversations in an account opened with a private email address are outside company control, and they stay there when the employee leaves.
- Nobody knows the settings. Whether conversations are retained or used to improve models depends on the product tier and account settings. Most users have no idea where those settings are.
- Data types are not distinguished. Customer data, trade secrets, source code and public information go into the same window with the same ease.
Tools used without the organisation's knowledge or approval are known as shadow AI. It is shadow IT in a new form, and it spreads far faster.
What shadow AI costs
This is no longer a fringe activity. According to Verizon's 2026 Data Breach Investigations Report, 45% of employees are now regular AI users on corporate devices, up from 15%, and 67% of users access AI services with non-corporate accounts. The same report found that source code was the most common data type submitted to unauthorised generative AI tools.
There is a breach bill attached. In IBM's Cost of a Data Breach Report 2025, one in five organisations reported a breach due to shadow AI, and those with high levels of shadow AI faced $670,000 in higher breach costs. In the same study, 63% of breached organisations had no AI governance policy or were still developing one.
The worry is not confined to security teams. Eurostat's statistics on AI use in enterprises show that 48.83% of EU businesses that considered AI but did not adopt it cited data protection and privacy concerns (2025). Unmanaged use creates risk and, at the same time, blocks managed use.
The data protection angle: GDPR and Türkiye's KVKK
When an employee enters text containing a customer's name, phone number or health details into an AI service hosted abroad, the organisation — not the employee — is the data controller for that processing. Under the EU GDPR this raises questions of lawful basis, transparency and international transfers.
The same applies in Türkiye under the KVKK (Law No. 6698 on the Protection of Personal Data). Article 9, amended in 2024, now ties transfers abroad to conditions broadly similar to the GDPR's — adequacy decisions, appropriate safeguards such as standard contracts — and a transfer made through an employee's private account rests on none of them. Article 12 requires controllers to take the necessary technical and organisational measures; having no written policy and no access control is a weak position to defend. We explain the transfer routes and standard contract notification in KVKK cross-border data transfer.
Even without personal data, trade secrets, quoted prices and source code engage the confidentiality clauses in your contracts.
That is why the risk of data leaking through ChatGPT should not be handled in isolation but as part of your KVKK compliance programme: AI services are added to the data inventory, privacy notices are updated and the transfer assessment is put in writing. For the organisation's own AI projects, our guide to AI and personal data protection in Turkey covers legal basis, transfers and automated decisions.
ChatGPT and company data security: an eight-step framework
- Classify your data. Four classes are enough: public, internal, confidential and personal data. Staff should be able to see on one page which class may go into which tool.
- Publish an approved-tools list. Which AI tools, which tier and which settings are allowed? Anything not on the list is not used. How these rules become a structured written document is covered separately in our company AI acceptable use policy guide; the focus here is preventing data leakage.
- Require company accounts. Business data should never be processed on a personal account. Company accounts can be opened and closed centrally, and linking them to single sign-on makes that easier.
- Write down what must never be entered. Customer identity and contact details, health data, passwords and access keys, unsigned quotation prices, sensitive parts of your source code. Our article on business password security covers how credentials should be handled.
- Offer a safe alternative for sensitive work. A ban alone does not work; staff need an answer to "so where can I do this?". An assistant that works from company documents with permission-based access fills that gap; we explain the architecture in retrieval augmented generation for the enterprise.
- Add technical controls. Use web filtering, data loss prevention (DLP) rules and endpoint management to spot sensitive data being uploaded to unapproved tools.
- Require human review of output. AI output should be checked by a person before it reaches a customer, a contract or official correspondence; reducing AI hallucinations explains why. If an assistant reads email or documents, see prompt injection security for how hidden instructions can leak data.
- Train people and manage leavers. Give short training with real examples, and when someone leaves, close their company AI accounts along with email and file access. See our guide to offboarding email access.
Most of these steps are simply a general SME cyber security checklist applied to AI, and can be added to your existing security policy as a single page.
How we approach this at Digital Bridge
Rather than banning AI, we aim to move its use into a safe channel:
- We make current use visible. Through our cyber security consultancy we map which AI tools are in use, on which accounts and with which kinds of data, then write the data classification and use policy with your team.
- We settle the data protection questions. Our data protection compliance service reflects AI use in your privacy notices, data inventory and transfer assessments, whether under the KVKK, the GDPR or both.
- We build the safe alternative. We deploy an enterprise LLM assistant that works from your documents, cites a source in every answer and responds only from documents the user is authorised to see. Where data must not leave the organisation, it can run entirely on your own servers using open-source models.
- We connect it to what you already use. Through AI integration the assistant is added to your ERP, help desk or intranet, so nobody needs to go looking for another tool.
Managed AI in daily work: SmartMail and SmartFiles
The two jobs staff most often turn to AI for are summarising email and making sense of documents. Smart360, our own product family, does both inside the company account and under administrator control:
- SmartMail offers message summaries, automatic categorisation, asking questions of a message, writing assistance and translation into 30 languages. Each mailbox has nine separate permissions, two of which are "AI reinterpretation" and "AI chat" — so who uses AI is decided mailbox by mailbox.
- In SmartFiles, AI is one of eight independent permissions and is granted to a person or a department. Each uploaded document gets a four-part report, and you can ask questions of a document or a folder. There is a monthly AI allowance, and an administrator can switch the feature off entirely.
Each organisation's data is held in a separate database for each product. Because every product sits behind a single identity (SmartID), a leaver's access closes in one step; sessions are listed with device details and can be ended remotely.
Next step
Run a quick, no-blame survey this week: which AI tools does the team use, on which accounts and for what? Map the answers against the four data classes. Then get in touch: we will write your AI use policy with you and scope a secure assistant for sensitive work. For where managed AI adoption should begin, read AI in business: where to start; for related topics, browse our complete Artificial Intelligence guide.