Guides

Using ChatGPT, Claude and Copilot at work lawfully, in a UK business.

By Zain M · 14 September 2026 · 14 min read

ChatGPT, Claude and Copilot can be used lawfully in a UK business if personal data goes only into business or API accounts whose terms exclude training, staff follow a written policy, and a DPIA is done. Only 5% of AI-using UK businesses have a written policy, and the Upper Tribunal says uploading confidential documents to a public tool waives privilege.

UK adults using AI tools54%, from 31% (Ofcom, Apr 2026)
AI-using businesses with a written AI policy5% (DSIT, Jun 2026)
Upper Tribunal on public AI toolsUpload waives privilege, [2026] UKUT 00081 (IAC) para 60
Half-day staff session£1,200, fixed

How much of this is already happening in your business

Whatever your policy says, your staff are already using these tools. Ofcom’s 2026 adults’ media survey, 7,533 UK adults interviewed between 29 September and 28 November 2025, found that 54 per cent now say they use AI tools such as ChatGPT, Copilot or Gemini, up from 31 per cent a year earlier; among 25 to 34 year olds it is 74 per cent and among 16 to 24 year olds 79 per cent. Among those who use AI, 47 per cent say they do so to support work or study.

Businesses have not caught up with their employees. DSIT’s UK Business Data Survey 2026, 4,450 businesses interviewed between October 2025 and January 2026, found that 41 per cent of businesses handling digitised data use AI, but only 17 per cent of those had any policy on its use, formal or informal. Just 5 per cent had a formal, written policy; 12 per cent had informal guidance. Among micro businesses 8 per cent had a formal policy, among sole traders 3 per cent. Only 53 per cent had even heard of AI regulatory guidance, and of those, 19 per cent found it clear.

MIT’s 2025 study of large organisations describes the same gap from the other side: while only 40 per cent of companies said they had purchased an official LLM subscription, workers from over 90 per cent reported regular use of personal AI tools for work. The report calls it a shadow AI economy. The practical consequence for a UK firm is that the question is not whether to allow these tools but which accounts, which data and which rules.

What the ICO says applies

There is no separate law for generative AI in the UK. UK GDPR and the Data Protection Act 2018 apply whenever personal data goes into a tool, and the ICO’s guidance on AI and data protection, last updated on 15 March 2023, sets out how the principles apply: accountability and governance, transparency, lawfulness, accuracy, fairness, security and data minimisation, and individual rights. The ICO also publishes an AI and data protection risk toolkit and separate guidance on explaining decisions made with AI.

The sentence a small business should read first is in the accountability chapter: in the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for a DPIA. Where you assess a particular use as not high risk, you still need to document how you made that assessment. A DPIA for pasting a client email into a chatbot is a page; a DPIA for a tool that screens applicants is not.

The Data (Use and Access) Act 2025 changed the rules on automated decisions. Per the ICO, all of the Act’s data protection provisions are now in force, and it opens up the full range of lawful bases, including legitimate interests, for significant automated decisions, so long as safeguards remain and special category data is not involved. If a tool in your business makes or materially shapes a decision about a person, the safeguards, telling them, letting them contest it, getting a human to look, are the design requirement.

Consumer terms and business terms are different products

The same name, ChatGPT, Claude or Gemini, covers two products with opposite defaults on training. The consumer version may use what you type to improve the model unless you opt out; the business or API version does not by default. The two look identical on screen, which is why a policy that names the account rather than the tool is the only kind that works. Read on the providers’ pages in September 2026, the position is this.

ProductTrains on your content?Retention and controlsSource, date
ChatGPT for individuals (Free, Plus, Pro)Yes, unless "Improve the model for everyone" is turned off in Data Controls, or Temporary Chat is usedConsumer privacy policy; feedback you give may still be usedOpenAI help centre, Sep 2026
ChatGPT Business, Enterprise, Edu, and the APINo, by defaultWorkspace admins control retention; deleted conversations removed within 30 days; DPA availableOpenAI enterprise privacy, Sep 2026
Claude consumer (Free, Pro, Max)May be used unless you opt out in settingsUp to 5 years de-identified if you allow training; deleted chats gone from back-end within 30 daysAnthropic privacy policy, effective 10 Sep 2026; retention article 1 Jul 2026
Claude Team and Enterprise, and the APINo model training on your content by default; commercial terms say Anthropic may not train on Customer ContentPer customer agreement; Team seats $20 to $25 a monthclaude.com pricing; commercial terms effective 17 Jun 2025
Gemini Apps, personal accountYes, when Keep Activity is on; a subset of chats is reviewed by humansAuto-delete at 18 months by default; 72 hours when Keep Activity is off; reviewed chats kept up to three yearsGemini Apps Privacy Hub, Sep 2026
Gemini API, paid tierNoLogged for a limited period solely for abuse detectionGemini API terms, effective 23 Mar 2026
Gemini API, unpaid tierYesUsed to provide, improve and develop Google productsGemini API terms, Sep 2026
Microsoft Copilot and Copilot Chat, work accountNo: prompts, responses and Graph data not used to train foundation modelsCovered by the Microsoft DPA; your tenant’s retention, labels and audit applyMicrosoft Learn, 29 May 2026

Vendor statements on the vendors’ own pages, read 14 September 2026. The rule that follows is simple: personal or confidential data goes only into an account whose terms are in the "No" rows.

The Upper Tribunal ruling on privilege

In UK and R (on the application of Munir) v Secretary of State for the Home Department [2026] UKUT 00081 (IAC), promulgated on 17 November 2025, a three-judge panel of the Upper Tribunal dealt with legal representatives who had used generative AI in case preparation. At paragraph 60 the Tribunal said: "Uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege", adding that such conduct might warrant referral to the regulator and should in any event be referred to the Information Commissioner’s Office.

The Tribunal drew a distinction that matters for every business, not only law firms: closed-source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks. The line it drew is between a public tool on personal terms and an enterprise tool inside a controlled environment, which is the same line the training table above draws.

Two cautions. The Tribunal was describing an immigration case and its observation is guidance rather than a full judgment on privilege, and it did not address a public tool used with its privacy or training settings changed. Until an appellate court does, the safe assumption for any business that holds legal advice, contracts under negotiation or client confidences is the one the Tribunal made: a consumer AI account is the public domain.

When a DPIA is triggered

A DPIA is a written assessment of the risks of a processing activity and how you will reduce them. The ICO’s AI guidance says most AI use of personal data will need one. For generative AI tools in a small business the triggers below are the ones that arise in practice; if none applies, write down why, because the ICO expects the assessment to be documented either way.

01Personal data about customers, staff, patients or applicants is entered into any AI tool, including in a pasted email or an uploaded document.
02The tool is used to evaluate, score, rank or profile people, for example to shortlist applicants, assess credit or prioritise complaints.
03Special category data is involved: health, ethnicity, religion, sexual orientation, trade union membership, biometrics, or criminal records.
04The tool makes or materially shapes a decision that has a legal or similarly significant effect on a person, which brings the automated decision-making safeguards into play.
05Data leaves the UK, which is a restricted transfer requiring adequacy, the IDTA or the Addendum.
06The tool is connected to internal systems, such as a mailbox, drive or CRM, so that it can read data nobody individually pasted in.
07A new tool or provider is adopted, or an existing one changes its terms on training or retention.

A one-page AI use policy, as a list

A written policy is what 95 per cent of AI-using UK businesses do not have. It does not need to be long. Each line below is a rule, and a policy that fits on one page will be read; one that runs to twelve will not. Adapt the account names to the tools you actually buy, and keep the rules about data and accounts even if you change every tool, because they are the part the law cares about.

01Approved tools are listed by name and account type: for example, the company ChatGPT Business workspace, Claude Team, and Copilot on a work account. Personal accounts on any AI service are not used for work.
02Personal data about clients, staff, candidates or anyone else is entered only into approved tools, and only where the task needs it.
03Confidential documents, contracts, legal advice, financial information and anything covered by a non-disclosure agreement are never uploaded to a personal or public AI account.
04Special category data, such as health information, is not entered into any AI tool without a completed DPIA and the data protection lead’s written approval.
05AI output is a draft. A named person checks facts, figures, citations and legal or regulatory statements before anything leaves the business, and remains responsible for it.
06AI is not used to make decisions about people, such as hiring, discipline, credit or pricing, without a human reviewing the decision and a route for the person to challenge it.
07Where AI has materially produced content or a decision that affects a person, and the law or the context requires it, we tell them.
08Training and model-improvement settings are off on every approved account, and the settings are checked when a provider changes its terms.
09Connectors and integrations that let an AI tool read a mailbox, drive or system are enabled only by the administrator, after the DPIA covers them.
10Anyone who suspects personal or confidential data has been entered into an unapproved tool tells the data protection lead the same day, so the 72-hour breach clock can be met if needed.
11The policy owner, the approved tool list and the date of last review are printed at the foot of the page, and the page is reviewed every six months or when a tool changes.
12Breaches of this policy are handled under the normal disciplinary and data protection procedures.

What to tell staff

A policy nobody understands is a document, not a control. The briefing that makes it work is short and concrete, and it answers the questions people actually have rather than the ones the regulator asks. In our experience it takes about an hour, and the most useful part is the demonstration, because most people have never seen the difference between a work account and a personal one on the same screen.

01Which account to use, with a demonstration of the difference between logging into the work workspace and a personal one, because the two look the same on screen.
02What counts as personal data, with examples from your own business: a client’s name in an email, a candidate’s CV, a patient’s appointment, a colleague’s absence record.
03What to do with a document before uploading it: remove names and identifiers where the task does not need them, and use the approved tool when it does.
04Why the output must be checked, with an example of a confident, wrong answer, ideally one from your own trade.
05That the Upper Tribunal has treated a public tool as the public domain, so a contract or advice letter pasted into a personal account is, in law, published.
06Who to tell if something goes wrong, and that telling them quickly is what protects the business, not what gets anyone into trouble.
07That the rules are about accounts and data, not about whether AI is allowed, and that the approved tools are there to be used.

A worked example: the cost of doing it properly

A twenty-person professional services firm currently has staff using personal ChatGPT and Claude accounts, some paid for on expenses. Client emails, draft contracts and the occasional CV are going into them, which after the Upper Tribunal’s observation is a risk the firm’s insurer would want to know about. The change is a set of accounts, a page of policy and a morning of training, and it can be priced from published figures.

Accounts: a business tier at each provider staff already use. Anthropic lists a Claude Team standard seat at $25 a month billed monthly or $20 on an annual plan, so twenty seats are $500 a month, or $4,800 a year on the annual plan, in dollars plus VAT; OpenAI’s business tier and Microsoft’s Copilot licences are priced on their own pages and should be read there on the day. Against this, the personal Pro subscriptions being expensed at $20 a month each are already $400 a month for twenty people, on terms that may train on the content. The business tier is not much more expensive; it is a different contract.

Policy and training: the one-page policy above takes an afternoon to adapt. A half-day training session with us is £1,200 fixed, and it ends with the policy, the approved-tool list and a working prompt library the team keeps. A DPIA for the common uses is a short document if drafted alongside. Total for the year, at the assumptions above: about $4,800 to $6,000 in seats and £1,200 in training, for a business that is now inside the "No" rows of the training table rather than outside them.

LinePublished figureTwenty people, one yearTrains on content?
Claude Team standard seat, monthly billing$25 a seat a month$6,000No, by default
Claude Team standard seat, annual billing$20 a seat a month$4,800No, by default
Claude Pro, personal, expensed$20 a month$4,800May, unless each person opts out
ChatGPT Business or Enterprise; Microsoft CopilotPriced on the vendors’ pages; read on the dayNot stated hereNo, by default
One-page policyAn afternoonNilNot applicable
Half-day training session, Augustova£1,200 fixed£1,200Not applicable
DPIA for the common usesA short document, drafted alongsideNilNot applicable

Seat prices from claude.com/pricing on 14 September 2026, in US dollars excluding VAT. The consumer row is the cost most firms are already paying without the contract.

What Augustova’s half-day session covers

The £1,200 half day is built for a whole team at once, and it is practical rather than theoretical: the accounts to use and why, live demonstrations of the tools on your own documents with the personal data removed, the checking habits that catch confident errors, and the policy, finished in the room and left with you. Leadership sessions add the DPIA and the automated decision-making safeguards; developer sessions add the API terms, regions and cost controls. Every session ends with an artefact the team owns, because a workshop with nothing left behind decays in a fortnight.

A full day is £2,000 and a multi-day programme up to £6,000, fixed, delivered within three weeks of booking. Sessions are aimed at one audience at a time, because a mixed room produces material too shallow for the builders and too technical for the decision makers. If the honest recommendation is that a policy and a business subscription are all you need this year, that is what we will say.

Method and sources

Every figure and legal statement above was read on its source page on 14 September 2026. Adoption figures are Ofcom’s Adults’ Media Use and Attitudes Report 2026 and DSIT’s UK Business Data Survey 2026, with fieldwork dates given in the text; the shadow AI figures are from MIT NANDA’s 2025 report of large organisations. The ICO material is its guidance on AI and data protection, the accountability chapter on DPIAs, the AI guidance hub, and its Data (Use and Access) Act page as updated on 19 June 2026. The Upper Tribunal decision was read on the National Archives case law service; the quotation is paragraph 60 verbatim.

Provider positions on training and retention are from the providers’ own legal and help pages, with effective dates where stated; they change without notice. The ICO’s AI guidance hub, as read on 14 September 2026, lists no separate generative AI guidance, so this guide relies on the general AI guidance and the DPIA chapter. Prices are in the currency each vendor bills in, excluding VAT. Nothing here is legal advice.

Ofcom, Adults’ Media Use and Attitudes Report 2026 (2 Apr 2026) →DSIT, UK Business Data Survey 2026 (18 Jun 2026) →MIT NANDA, The GenAI Divide: State of AI in Business 2025 (Jul 2025) →ICO, Guidance on AI and data protection (upd. 15 Mar 2023) →ICO, What are the accountability and governance implications of AI? (read Sep 2026) →ICO, Artificial intelligence guidance hub, including the AI and data protection risk toolkit (read Sep 2026) →ICO, The Data (Use and Access) Act 2025: what does it mean for organisations? (upd. 19 Jun 2026) →ICO, International transfers: a guide (read Sep 2026) →Upper Tribunal (IAC), UK and R (Munir) v SSHD [2026] UKUT 00081 (IAC), promulgated 17 Nov 2025 →OpenAI Help Centre, How your data is used to improve model performance (read Sep 2026) →OpenAI, Enterprise privacy (read Sep 2026) →Anthropic, Privacy Policy for consumer products (effective 10 Sep 2026) →Anthropic Privacy Centre, How long do you store my data? (1 Jul 2026) →Anthropic, Commercial Terms of Service (effective 17 Jun 2025) →Anthropic, Claude pricing, API and plans (read 14 Sep 2026) →Google, Gemini Apps Privacy Hub (read Sep 2026) →Google, Gemini API additional terms of service (effective 23 Mar 2026) →Microsoft Learn, Enterprise data protection in Microsoft Copilot and Copilot Chat (29 May 2026) →

Common questions

Is it legal to use ChatGPT at work in the UK?

Yes, provided UK GDPR is followed whenever personal data is involved: an account whose terms do not train on your content, a lawful basis, a DPIA where the ICO’s high-risk test is met, and a written policy staff actually follow. DSIT found only 5 per cent of AI-using UK businesses have a formal written policy, so most are using the tools without the controls.

Does ChatGPT train on what my staff type?

On personal accounts, it may, unless the user turns off "Improve the model for everyone" in Data Controls or uses Temporary Chat, and feedback given on a response can still be used. On ChatGPT Business, Enterprise, Edu and the API, OpenAI states it does not train on inputs or outputs by default. The fix is the account type, not a memo.

Does Claude train on my conversations?

On consumer Claude (Free, Pro and Max), Anthropic’s privacy policy effective 10 September 2026 says it may use inputs and outputs to train unless you opt out in settings, and may keep de-identified data for up to five years if you allow it. On Claude Team, Enterprise and the API, Anthropic states there is no model training on your content by default.

Can uploading a document to ChatGPT waive legal privilege?

The Upper Tribunal said so at paragraph 60 of [2026] UKUT 00081 (IAC): uploading confidential documents into an open-source AI tool such as ChatGPT places the information in the public domain and waives legal privilege. It contrasted closed enterprise tools such as Microsoft Copilot, which it said can be used for summarising without those risks.

Do we need a DPIA to use AI tools?

The ICO says the vast majority of AI uses of personal data will trigger the legal requirement for a DPIA, and that where you decide a use is not high risk you must document how you reached that view. For a small business the common uses can be covered in one short document written alongside the policy.

Is Microsoft Copilot safe for confidential business data?

Microsoft states that for work accounts, prompts, responses and data accessed through Microsoft Graph are not used to train foundation models and are covered by its Data Protection Addendum with Microsoft as processor. Web search queries are handled separately under consumer terms, and Anthropic models within Copilot are currently excluded from the EU Data Boundary, so check the settings.

What should an AI use policy for a small business contain?

Named approved tools and account types, a ban on personal accounts for work, rules on personal and confidential data, a human check on every output, no automated decisions about people without review, training settings off, connectors only by the administrator, a same-day reporting rule, and an owner and review date. One page is enough.

How many UK businesses have an AI policy?

Among businesses that handle digitised data and use AI, DSIT’s 2026 survey found 17 per cent had any policy, 5 per cent a formal written one and 12 per cent informal guidance. Large businesses were at 56 per cent for a formal policy, micro businesses 8 per cent and sole traders 3 per cent.

What does AI training for staff cost?

Our half-day session is £1,200 fixed, a full day £2,000 and a multi-day programme up to £6,000, delivered within three weeks of booking and ending with a policy and prompt library the team keeps. Of the UK firms that publish training prices, Hartz AI lists a private half day from £1,500 plus VAT and a full day from £2,500.

Should we stop staff using AI tools altogether?

No. Ofcom found 54 per cent of UK adults already use them and MIT found workers at over 90 per cent of organisations using personal tools for work. A ban moves the use onto personal accounts you cannot see. Approved accounts, a page of rules and a morning of training are cheaper than the alternative and the Tribunal’s distinction between public and closed tools is exactly the one to build on.

Read next

AI consultancy in London →Your data when a supplier builds your software →What an AI readiness audit should contain →UK AI statistics, every number sourced →Our prices, in full →

Get the policy written and the team trained

Tell us which tools your team already uses. We will tell you which accounts to buy, draft the one-page policy with you, and run the half day that makes it stick.

Start a conversation →