You are reading Chapter 9 of 36 in the AI Bootcamp, AI Central's free course for professionals who want to use AI in their own work. The chapters build on each other, so if this is your first one, Chapter 1 is the place to start. All of them sit on the AI Bootcamp page, and three more arrive every week.

Using AI at work without breaking your company's policy comes down to one question almost nobody asks: which account you were signed in to when you typed. A personal account and a company seat show you the same screen and sit under two completely different contracts.

This guide covers the two accounts and what separates them, where the training and retention settings live in ChatGPT, Claude, Gemini and Copilot, a four-word test for what never goes in the box, and what you actually own when something comes back out.

We publish AI systems like this for 300,000+ senior professionals at AI Central, and more of them live in the AI Central Library.

Almost nobody who gets into trouble here was careless

They were doing company work in a personal account, because nobody told them there was another option and nobody told them the rules.

The largest study on this so far covered 48,000 people across 47 countries, and almost half of employees admitted using AI in ways that break their own company's rules. More rules were not the missing ingredient. A rule you can apply in 4 seconds was.

You arrive here carrying an assistant you already use on real work, your own documents from Chapter 7, and the verification habit from Chapter 8. What this chapter adds is the account all of that should be running on.

Which tasks are worth handing to AI in the first place is a separate question, and Chapter 3 answers it. This chapter is about where you are typing, not what you are typing about.

It depends which account you use

A personal account is a contract between you and a technology company, agreed by you, on terms you clicked past. Your employer is not a party to it and never saw it. So nothing you paste into that box is covered by anything your company negotiated, because your company negotiated nothing.

A company seat is a different product wearing the same interface. All four vendors sell business tiers, and on all four the contract says close to the opposite of the consumer one: your content is not used to train their models, by default, with no setting for you to hunt down. ChatGPT Business, Enterprise and Edu. Claude for Work. Google Workspace with Gemini. Microsoft 365 Copilot when you are signed in with your work account rather than a personal one.

The seat also brings a data processing agreement, and on business tiers a copyright indemnity. What you give up is privacy from your own employer: conversations on a company seat are logged and your employer can retrieve what you typed.

So the most useful thing you can do this week is not to memorise a policy. It is to find out what your organisation already provides. A great many companies bought seats across 2024 and 2025 and never announced it clearly, so a meaningful number of people are pasting work into a free personal account in the same building as a paid licence nobody mentioned.

Ask two things, and both fit in one message to IT. What are we licensed to use, and what does our policy actually say. If the answer to the second is that no written policy exists, that is worth knowing too.

In Europe there is a further nudge. Since February 2025 the AI Act has required organisations deploying AI to make sure the people using it on their behalf have adequate AI literacy, with the enforcement machinery due from August 2026.

What happens after you press send

Three separate things can happen to a message. It gets stored, it gets used to improve the product, and a person may read it. They are not the same thing, and they are not controlled by the same switch.

On personal accounts the four vendors differ in the details and agree on the shape. Here is where each one keeps the setting.

1. ChatGPT

Settings, then Data Controls. The switch is called Improve the model for everyone, and on personal Free, Plus and Pro accounts it starts on.

2. Claude

Privacy settings. Claude asked every consumer user to make an explicit choice in late 2025: allow training and conversations can be kept for 5 years, decline and retention stays at 30 days.

3. Gemini

Gemini Apps Activity. Chats are kept 18 months by default, and you can change that to 3 months, 36 months, or off. A sample of chats is read by human reviewers.

4. Copilot

Privacy, then training on conversation activity. Signed in with a work account it is a different product entirely.

Google is the bluntest of the four about the consequence, and it is worth quoting because it sits on their own help page: do not enter confidential information that you would not want a reviewer to see, or Google to use to improve its services. That is not a warning about hackers. It is a warning that a subset of conversations is read by people, deliberately, as part of how the product gets better.

Turning the setting off is worth doing and does less than people assume. It applies going forward, not backward, and it does not stop the conversation being stored.

Stored is its own category of risk. In 2025 a court order in a copyright case required OpenAI to preserve consumer chat logs it would otherwise have deleted. That order was lifted in October 2025, and the lesson outlives it: what a company promises to delete and what a court can later require it to keep are two different questions.

Temporary and incognito chats sit in the same gap. They stay out of your history and out of training, and they are still retained for a period, typically around 30 days.

A company seat closes most of that, and opens one thing worth saying plainly because no vendor will volunteer it. On business tiers your conversations are logged, exportable and discoverable. ChatGPT Enterprise ships a compliance interface built for exactly that. Microsoft 365 Copilot activity lands inside your own tenant's audit and eDiscovery. Claude's Team and Enterprise plans expose the same, incognito chats included. The seat protects the company from the vendor. It does not make you private from your employer, and it was never sold as doing so.

Go and look at your own setting now rather than assuming it. It takes under a minute, and our setup guide for ChatGPT, Claude and Copilot puts the privacy settings side by side if you want to check more than one.

Four words for what never goes in the box

You will never read a confidentiality policy in the 4 seconds between copying something and pasting it. So the rule has to be four words long.

People, promises, passwords, plans. If what you are about to paste contains any of those, it does not go into a personal account at all, and on a company seat it goes in only where your own policy says that category is allowed. Any one of the four is enough to stop you.

1. People

Anything that identifies a named individual: a customer list, a CV, a patient record, a performance note, a call transcript with real names in it. In Europe this is the sharpest of the four, because putting a client's personal data into an account your employer has no processing agreement with becomes your employer's exposure under GDPR. North American privacy law is more fragmented and the direction of travel is the same.

2. Promises

Anything confidential because you agreed it would be: material under an NDA, a client's documents, a partner's roadmap, code you do not own. You cannot promise confidentiality to one party and then decide on your own to share it with a second.

3. Passwords

Credentials, keys and tokens. This ought to be obvious and still gets pasted regularly, because the key happened to be sitting in the middle of the log file someone asked you to explain.

4. Plans

Anything true but not yet public: unreleased results, a deal in progress, a restructuring, pricing that has not shipped. For a listed company that last category has another name and a regulator attached to it.

The well-known version of this is Samsung in 2023. Engineers pasted source code and a meeting transcript into ChatGPT to get help with their actual jobs, and within weeks the company had banned the tools on its own devices. Nobody in that story was acting badly, and that is the part to take from it.

Write your own four in your company's own nouns, naming the actual documents, systems and categories of person you handle in a normal week. That is one of the three exercises at the back of the guide, and all three take about 15 minutes.

Two different questions get answered with the same word, which is how careful people end up surprised. What the vendor gives you and what the law protects are separate things.

The contract half is settled and generous. All four providers hand you whatever rights they have in what the model produced for you. OpenAI's terms assign it to you outright, and Anthropic's say the customer owns its outputs. You owe no fee, no credit and no attribution, and you are not borrowing the words on licence.

The copyright half is narrower, and it has been tested rather than assumed. The US Copyright Office concluded in January 2025 that prompting alone, however long and careful the prompt, does not make you the author of what comes back. What can be protected is the human contribution around it: your selection, your arrangement, your edits. In March 2026 the Supreme Court declined to take up the case that would have challenged the human authorship requirement, so this is now the settled position rather than a live argument.

In practice that means the more you cut, rewrite and shape, the more of the result is genuinely yours. A draft you accepted unchanged is a draft nobody owns. That matters a great deal for anything you intend to license, defend or sell, and not at all for an internal memo. Know which one you are producing before you worry about it.

Two more things worth knowing. An output is not exclusive, so a similar question from someone else can produce a very similar answer. And if you produced it in the course of your job, your employer almost certainly owns it whatever the vendor's terms say, exactly as with everything else you write at work.

The one real asymmetry is worth carrying into your next budget conversation: the major vendors offer copyright indemnity to business customers and not to consumers. Whether it covers your particular situation is a question for whoever signed the agreement, which is the honest answer to a lot of this chapter. Read your own contract, or go and ask the person who has.

What actually changes

Before: you do company work in whichever account happens to be open, you have never looked at your own training setting, and you would have to guess at what your employer allows.

After: you know what your organisation already provides and what its rules say, you have looked at your own data settings instead of assuming them, you carry a 4-word test for what never goes in the box, and you can say plainly what you do and do not own when you use the output.

Two things carry into Chapter 10: the answer from IT about what your company provides, and the setting you found in your own data controls. Chapter 10 has you feeding the assistant samples of your own writing so it stops sounding like a press release, so it matters that you know where that writing goes. If you want a one-page reference to keep beside you while you work, start with our free AI cheat sheets, and the rest of the syllabus lives in the AI Central Library.

Frequently Asked Questions

Can I use ChatGPT at work?

It depends which account you are signed in to and what your employer allows. On a company seat under a business contract your content is not used to train the model by default, and a data processing agreement covers it. On a personal account your employer is not a party to the terms at all. Ask two things: what are we licensed to use, and do we have a written policy.

Does ChatGPT train on what I type at work?

On personal Free, Plus and Pro accounts the switch called Improve the model for everyone starts on, in Settings under Data Controls. On ChatGPT Business, Enterprise and Edu your content is not used for training by default. Claude for Work, Google Workspace with Gemini and Microsoft 365 Copilot say the same on their business tiers.

Does turning off AI training delete my chats?

No. It applies going forward, not backward, and it does not stop the conversation being stored. Temporary and incognito chats stay out of your history and out of training, and they are still retained for a period, typically around 30 days.

What should you never paste into an AI chatbot?

People, promises, passwords, plans. Anything that identifies a named individual, anything confidential because you agreed it would be, any credential or key or token, and anything true but not yet public. Any one of the four is enough to stop you.

Do you own what an AI tool writes for you?

Under the vendor's terms, yes. All four major providers assign you whatever rights they hold in the output, with no fee, credit or attribution. Copyright is narrower: the US Copyright Office concluded in January 2025 that prompting alone is not authorship, and only the human selection, arrangement and edits are protected. Work you produce in the course of your job belongs to your employer, as it always did.