profile

Dan Cumberland

Why I tell clients not to ban ChatGPT


Hi Reader,

An IT director messaged me this week in a panic.

He'd just run an audit to see who at his company was using AI, and the answer was everyone. Proposals, project files, client emails, all of it moving through personal ChatGPT accounts his firm had never approved and couldn't see into.

No one had broken a rule, because there were no rules!

His company had no position on AI at all.

The problem is that he's the one who answers for data security, and he'd just found out it had been going out the door for months. He asked me how to get caught up safely, and he wanted it fast. He knew that the longer he waited, the worse it was going to get.

This isn't new. I've seen it often.

Cyberhaven (a company that sells software that watches where company data goes) published a 2026 AI Adoption and Risk Report in February. It found that 32.3% of ChatGPT usage runs through personal accounts.

This is key: personal accounts.

It's not intentional. Folks are just trying to get their work done. But it's a problem.

The person pasting a client spec into a free chatbot has no idea that it's a problem (and you might not either— but we'll fix that in a moment). They're trying to get a submittal turned around by Friday, and AI can help them hit that deadline without breaking a sweat.

Next, leadership finds out and bans it. You send the memo and tell everyone to wait until leadership decides something.

Most of your team will follow it. But in the face of a tough deadline, are people really going to stop using the one thing that's helping them not drown in work? Of course not. They have the AI apps on their phones and personal computers. The IT department can't see it anymore. And then I come in and learn that the proposal manager has been drafting the RFP response at home, on a personal account, on a tool nobody vetted.

It's a catch-22. If you're even aware that it's happening.

Consumer vs. Enterprise

Most leaders don't know the difference between personal and team/enterprise/corporate AI accounts. The free tool and the business tool look the same. Same box, same answers, same models, same look and feel. But the accounts behind them work very differently.

On a free account, your protection comes down to a toggle that tells the vendor not to train on what you type. As far as we know, that toggle does what it says. OpenAI's current consumer terms say they don't promise your content will be secure, or that it won't be lost or altered. That's about all you get.

Not training and keeping company secrets are very different things.

In January 2026 a federal judge affirmed an order requiring OpenAI to hand over 20 million consumer ChatGPT conversations in the New York Times copyright case. OpenAI says the sample leaves out Enterprise, Edu, Business, and API accounts. Whether your conversations could have been included came down to the tier you were on.

And that's just the case I know about. Have there been others? What else is happening to your data?

A business account is different. Business tiers give you control of your data. You get audit logs, so when a client asks who touched their files, you can answer. You get single sign-on, which means people log in with their company account and IT can shut off access the day someone leaves. You get an admin console, one place to see every seat and every setting. And you set how long the vendor keeps what your team types. On the bigger agreements you can ask for zero data retention, where the vendor doesn't hold onto your team's conversations at all. And if you handle medical information, you can ask for a Business Associate Agreement, the contract HIPAA requires before an outside company can touch patient records.

Personal accounts have none of that.

Your First Two Steps

The thing about all of this is that it's quite easy to navigate, once you're clear on the what and why behind it. I lead clients through two simple steps:

  1. Name which tools are approved for company data, and be specific about what data. It can be as simple as a single page policy. Your team just needs to know that the company account is fine for proposal drafts and project emails, and that a client's financials, signed contracts, and any trade secrets have to stay out of AI.
  2. Give everyone a clear path to a license. People take that path of least resistance. If the approved tool is hard to get access to, people go back to the free one and you're back where you started.

Firms skip this part constantly.

They write the policy, stop there, and the policy turns into something people completely ignore.

A while back I wrote about how few people it actually takes to build a company's AI infrastructure— 1 AI Builder Per 20 People. Most Have Zero. But most firms never build these kinds of leaders because no one made it simple enough.

Something I hear from leadership all the time in discussions about the change management I'm helping them with is, "This is important, but we all have full time jobs."

It turns out that the same is true for the team. They're busy. Your path to approved and successful AI use needs to be easy for them.

The two ways this fails

Most firms I talk to have taken one of the steps above and stopped. Rarely both.

  1. Policy without access creates shadow AI— people using tools you never approved outside the company network. It's what happens when they're given rules without an easy way to follow them.
  2. Access without policy creates confusion. Everyone has a license, nobody knows what's allowed in it or what to do with it.

I've walked teams through this in engineering, mental health, pharma, and financial services. The specific needs are different for each, but the broad strokes are the same.

Remove the ambiguity

I built Pacemark, my AI maturity model, to solve this (and many other) issues. Two of the six dimensions cover exactly this.

Technology Infrastructure asks whether you have a sanctioned platform or personal-account sprawl. Governance and Ethics asks whether your AI rules hold when a deal is on the line. That's the access half and the policy half, scored separately.

The other four came out of the same research across more than 300 companies.

I built a self-assessment. 25 questions to give you a quick understanding of where your company is, and what you need to address next. It takes about eight minutes. And it's free.

At the end there's a short form (your name, work email, firm, and role) and then your results come up on screen right away. You get your firm's maturity level, the dimension holding you back, and one specific first move. There's no call to sit through.

If it feels like there's meaningful work to be done, I'd love to help you map out your path to the next level of maturity.

Let's talk about your next steps

I work with companies on exactly this— naming the approved tools and getting everyone a legitimate way to use them. One hour a week. Your actual workflows. Let's connect.

Hit reply and tell me whether your firm has an AI policy. I'm curious how many can answer that without going to look.

Keep building,

-Dan

PS - If you'd like a policy review, I'd be happy to take a look. Hit reply and let me know!

Dan Cumberland

Weekly AI strategies to reclaim 15+ hours/week— without sounding like a robot. Real systems. Real results. Your voice intact. Join 14,000+ founders.

Share this page