
The Workflow Edit
Your AI Account Type Changes the Data Rules
“We use ChatGPT” is not enough information for a data policy. The account type matters.
Dear Suzannah
Can employees use the same AI tool for work if they already have personal accounts?
That depends on your policy and the product terms. Managed business accounts can have different data protections, administrator controls, retention options, and visibility than consumer accounts. Confirm the account type before deciding what information is appropriate to use.
Here’s the deal
OpenAI documents that ChatGPT Business workspace data is excluded from model training by default, and managed accounts can be subject to administrator controls. Google Workspace and Microsoft 365 also document enterprise data protections and admin-controlled access for their AI services. The product name is only part of the answer.
What this actually helps you do
For a 25-person professional-services firm where employees already use AI for email, research, and document drafting, this review turns a vague “AI is allowed” rule into an account-aware policy.
Exactly three benefits
- Reduce accidental use of sensitive business data in the wrong account type.
- Give employees a simple rule for choosing approved work accounts.
- Help administrators align AI access with existing identity and security controls.
Infographic: Before work enters AI
Personal or managed?
What information is involved?
What does the admin allow?
Step-by-step
- List the AI products employees use for business work.
- Record whether each use happens in a personal account or a company-managed account.
- Read the official privacy, data-use, and admin-control documentation for the applicable plan.
- Define which information may be used in each approved account type.
- Tell employees where to switch accounts and how to recognize the managed workspace.
- Review access when employees change roles or leave the organization.
Tips and tricks
- Put the approved account name and login method directly in the SOP.
- Teach employees that familiar branding does not mean identical data handling.
- Use existing identity groups when the AI platform supports group-based controls.
Common mistakes
- Writing one policy for every plan and account type.
- Assuming administrators can see everything, or nothing, without checking the actual product documentation.
- Allowing sensitive work before confirming whether the account is managed.
Infographic: Account review scorecard
| Company-managed identity | Confirmed |
| Training/data-use terms | Reviewed |
| Admin access and controls | Documented |
| Approved data classes | Written |
| Offboarding process | Assigned |
Human review checklist
- Do we know which account employees are using?
- Did we review the terms for that exact business plan?
- Are sensitive data rules written in plain language?
- Do admins know what they can control and access?
- Is offboarding included?
How to measure success
- Percentage of AI users on approved managed accounts
- Number of policy exceptions involving personal accounts
- Time required to remove AI access during offboarding
FAQ
Does a business plan mean employees can upload anything?
No. Vendor protections do not replace your internal rules about confidential, regulated, or customer information.
Can an administrator see employee chats?
Capabilities vary by product and plan. Check the official managed-account and admin documentation for the service you use.
Should personal AI accounts be banned?
That is a business policy decision. At minimum, define what work may and may not be performed in them.
Glossary
Managed account: An account controlled by an organization through its business or enterprise workspace.
Data controller: The party that determines how and why personal data is processed under applicable privacy rules.
Sources and further reading
- OpenAI: Managing data, sharing, and privacy in ChatGPT Business
- Google: What controls Gemini’s access to Workspace data
- Microsoft: Enterprise data protection in Microsoft 365 Copilot
- Anthropic: Commercial data processor and controller roles
Related: How to Build an AI Permission Map for Your Inbox.
Practical closing note
Before you write an AI rule, identify the account. “Which version are we actually using?” is a governance question, not a technicality.
