PAI-DOC-19
2026-07 · Questions
ChatGPT at work: what really leaves, and who answers for it.
In most SMEs, employees already use ChatGPT or an equivalent assistant, often on personal accounts: a French Odoxa survey finds 12% use it at work, and nearly one in two employees have never been trained for it.
Every question leaves with its context, and often with the document it concerns, towards servers outside any company contract; if something goes wrong, the employer answers for it.
The fix comes down to two moves: configured company accounts, and a signed one-page usage policy.
01
Your employees already use ChatGPT, and it is not their fault.
In most SMEs, generative AI arrived through employees, not through a management decision. A French Odoxa survey finds that 12% of employees already use AI at work, and nearly one in two have never been trained for it.
It is not their fault: these tools save time, and no one told them where the limit was. The problem is not the use, it is its setting: personal accounts, free or paid, outside any company contract.
This page describes what actually leaves in these uses, who answers for it, and the fix, which comes down to two moves.
02
What leaves is broader than the question asked.
Every question put to a public assistant leaves with its context: the text pasted to reword an email, the table pasted to summarise some figures, the contract pasted to check a clause. The document leaves with the question, towards servers the company does not control.
On a personal account, that transfer escapes any company contract: consumer terms, default settings, history retained, and depending on the plan and the configuration, content that may be used to improve the provider's models.
That is the blind spot: the company knows neither what left, nor when, nor from which account. There is nothing to audit, because nothing was logged.
03
If something goes wrong, the employer answers for it.
Customer data falls under the GDPR, documents under a confidentiality agreement bind the company, and trade secrets are only protected if you can demonstrate protective measures. In all three cases, the responsibility lies with the employer, not with the employee who pasted the text.
On top of that comes the EU AI Act (Regulation (EU) 2024/1689): since February 2025, it requires any company whose teams use these tools to have demonstrable AI-literacy measures. A verbal instruction cannot be proven; before a customer, an insurer or an inspection, only the written record counts.
04
The fix comes down to two moves, doable in a month.
First move: configured company accounts. The same tools, on a professional plan, with the settings that protect your content, and a list of approved tools kept by a designated owner. You do not take away a tool that saves time without providing the equivalent.
Second move: a signed one-page usage policy, presented in person by management. Accounts, data, verification, transparency, tools, doubt, signature: the full template is published openly on this site.
Backed by documented training, these two moves cover the essential AI-literacy measures required since February 2025, and roll out in a few weeks. This is the Scoping & compliance stage of our protocol.
05
For sensitive documents, the alternative is private AI.
Properly configured, on company accounts and for the right uses, public assistants remain legitimate tools: nothing justifies banning them, and the policy defines precisely what is open to them.
For what must never leave (contracts, customer data, management records), the alternative exists: a private AI, a self-hosted model on your servers or a French sovereign cloud, that answers from your documents without anything travelling outside.
The default channel then becomes a channel that lets nothing out, and public assistants find their proper place: generic uses, without any company data.
06
Continue
Go further
- The AI policy, with templateThe second move of the fix: the full one-page template, ready to sign.
- Private AI in detailThe channel that lets nothing out: a self-hosted model on your documents.
- The four-week AI auditKnowing what already leaves at your company: AI-usage register, inventory of flows, policy.
07
Commitments
Four commitments, on every engagement
These commitments are set out in our presentation deck. They hold for every engagement, from the diagnostic to managed operations.
- Contact
- Dedicated, end to end
- Progress point
- Weekly
- Environments
- Permanent access
- Reply
- Within 24 working hours
08
Decide
Two minutes to know where you stand.
A straight answer: what applies to you, and whether a project makes sense. If the answer is no, you leave with the answer.
Regulation (EU) 2024/1689 · PAI-DOC-19