AI for Business
Is ChatGPT safe for business?
It depends entirely on which account you are using and what you put into it. Here is what actually changes between the free tier, the business tier and a private environment.
This question usually arrives after somebody has already been using it. The honest answer is that the safety of ChatGPT for business work depends on three things: which account it is being used on, what information is being put into it, and whether anybody in the business can find out afterwards.
The account type matters more than the tool
The same interface behaves quite differently depending on the subscription behind it. This is the single most misunderstood point, and it is where most of the risk sits.
- Free and personal paid accounts: content may be used to improve the provider’s models unless the user has changed a setting. The business has no visibility over that setting, and no record of what was submitted.
- Business and enterprise accounts: providers generally commit that business data is not used for training, with administrative controls and retention settings. This is a real improvement, and it is the minimum position for company work.
- Any account signed up personally by an employee: the business is not a party to the agreement and has no rights over the data, whatever the tier.
An employee using a personal account for company work has, in effect, disclosed company information to a third party under terms nobody at the company has read. That is the situation most businesses are actually in, and it is different from the situation they think they are debating.
Where the data goes
On a business account with training disabled, the practical risks are narrower but not zero. Data still leaves your environment and is processed on infrastructure you do not control, most often outside Australia. It is retained for some period. It is reachable by the provider’s staff under their own controls. If your obligations to a customer, a regulator or an insurer include knowing where information is held, those are questions you now have to answer on somebody else’s behalf.
What it is genuinely fine for
There is a version of this conversation that overstates the risk, and it is worth avoiding. Public AI tools are safe and useful for a large amount of ordinary work, on a properly licensed business account.
- Explaining a general concept, a standard or a piece of legislation
- Improving the wording of something that contains nothing confidential
- Drafting from a brief that carries no customer, pricing or people detail
- General research and background reading
- Code, formulas and technical help that contain no business data
Where it stops being appropriate
- Customer pricing, margin, cost models and rate cards
- Contracts, tenders and negotiation positions
- Board papers, strategy documents and anything market-sensitive
- Employee, remuneration and personal information
- Anything a customer contract says must stay in a particular jurisdiction
The difficulty with this list is not writing it. It is that the work people most want AI help with — the contract, the price increase, the board paper, the tender — sits almost entirely on the wrong side of it.
The work people most want help with is the work they are least able to paste into a public tool.
The problem nobody mentions: it does not know your business
Security dominates this conversation, but there is a second issue that costs businesses more day to day. A public model has never seen your P&L, your contracts, your cost model or your commercial history. Ask it where you are losing margin and it will give you a competent general answer about manufacturers, which is not an answer about you.
People compensate by pasting in more context, which is exactly the behaviour the security policy is trying to prevent. The tension is structural: a general model becomes useful on specific work only when you feed it specific information.
What a reasonable position looks like
- Provide a properly licensed business account, so nobody has a reason to use a personal one
- Write down what must never be submitted to a public tool, in language people will actually follow
- For work that involves company information, use a private AI environment where the data stays inside your control
- Check what your own customer contracts say about processing location before deciding anything
- Keep a person accountable for the output. Neither tool removes that.
The realistic destination for most Australian businesses is both. A public tool for general work, and a private environment for anything that touches company information. What does not work is a policy that forbids the second category without providing anywhere else to do it, because that policy has already been quietly overtaken in most businesses that have one.