22 Jun ChatGPT, PII, and Data Protection: What Your Business Needs to Know
Using ChatGPT feels convenient, and that’s exactly the problem. It’s easy enough that employees use it without stopping to think about what they just typed into it, and increasingly, what they type in includes information it should never see.
Recent research puts a number on this: sensitive data now shows up in roughly a third of all ChatGPT inputs, about three times the rate seen back in 2023. That includes personally identifiable information (PII), protected health information, source code, and financial details. One in five organizations has already reported a breach connected to unauthorized AI use, and most don’t have a policy in place to manage it.
This isn’t a reason to ban AI tools outright. It’s a reason to understand exactly where the risk sits and put real guardrails around it.
Why ChatGPT and PII Don’t Mix by Default
ChatGPT is not a conscious decision-maker. It’s a tool that generates responses based on patterns in its training data, and it has no way of knowing whether what you just typed puts someone’s personal information at risk. It simply answers.
In a business context, that means using ChatGPT for everyday tasks, drafting emails, summarizing customer records, cleaning up a spreadsheet, can put PII in front of a system your business doesn’t control and has no visibility into. Names, addresses, social security numbers, health records: all of it normally lives behind firewalls, network segmentation, and access controls. Paste it into a public AI tool, and none of those protections apply anymore.
Free and personal-tier ChatGPT accounts use conversation data to train future models by default. Only Enterprise and API-tier accounts with zero data retention are built to keep your inputs out of that pipeline. If your employees are using personal ChatGPT accounts for work tasks, and most businesses have no way of knowing if they are, that data may not be staying as private as anyone assumes.
The Human Error Problem
Even with the right account tier, the bigger risk is usually the simplest one: an employee pastes something they shouldn’t. A customer email with a full name and account number. A spreadsheet with salaries attached. A support ticket with a patient’s medical history.
This is often called shadow AI: employees using AI tools without IT’s knowledge or approval, usually because it’s faster, not because anyone means harm. But without visibility into what’s being used and how, a business has no way to manage the risk at all.
Regulatory Exposure Is Growing, Not Shrinking
ChatGPT and similar tools aren’t exempt from data protection law. HIPAA, PCI DSS, and GDPR all still apply to how PII and other regulated data get handled, and ChatGPT is not a party to any agreement your business has with its customers about how their data is used. Data handed to it is effectively handed to an outside party your compliance program has no contract with.
The regulatory picture is also getting more specific, not less. The EU AI Act reaches full application for high-risk AI systems in August 2026, and it explicitly covers AI used for things like screening job applicants or making credit decisions. If your business operates in a regulated industry or handles EU resident data, that’s a compliance deadline worth knowing about now rather than after the fact.
How to Actually Manage This Risk
Set a real AI usage policy. Define what tools are approved, what data can never be entered into them, and who’s responsible for enforcing it. Bytagig’s vCISO and compliance services can help build a policy that maps to the specific frameworks your business is accountable to, whether that’s HIPAA, CMMC, or SOC 2.
Move to enterprise-tier accounts with zero data retention, not free or personal ChatGPT accounts, for any work involving customer or employee data.
Get visibility into shadow AI. You can’t govern tools you don’t know are in use. An [IT and cybersecurity audit] can identify what AI tools are already active across your business before you write a policy for them.
Train your team on what not to paste. Most PII exposure isn’t malicious, it’s someone trying to save time. A short, specific training on what counts as PII and why it can’t go into a public AI tool prevents more incidents than a policy document nobody reads.
Keep data anonymized where you can. If a task doesn’t require real customer data to get useful output, don’t use real customer data.
Get Ahead of This Before It’s a Problem
The risk with ChatGPT isn’t the tool itself, it’s using it without a plan. If you’re not sure what AI tools are already active in your business or whether your current policies would hold up under a compliance review, schedule a free consultation or call (833) 465-5913.
For more on managing AI risk across your organization, see our guides on best practices for using AI tools safely and 7 ways AI can cause problems at work.
Share this post: