Cybersecurity

Your team is already using AI. The account type is the problem.

A document icon with an arrow leading into a chat bubble, representing business information being pasted from a file into a public AI chatbot

Twenty-one per cent of UK businesses told the government last winter that they had adopted some AI tools. That figure is accurate and close to useless, because it counts the tools a business decided to adopt. It does not count the free ChatGPT tab somebody in accounts has had open since March.

Nobody raises a purchase order to paste a supplier's remittance advice into a chatbot and ask what it actually says. They just do it, on a Tuesday, because it is faster than reading it properly. And the thing that decides whether that mattered is not the model, the vendor or the prompt. It is which account they were signed into at the time.

What the government's own survey found

The Cyber Security Breaches Survey for 2025/2026, run for DSIT and the Home Office with fieldwork between August and December 2025, added a section on AI for the first time. Across 2,112 businesses: 21 per cent had adopted some AI tools, 4 per cent were mid-adoption, 6 per cent were actively considering it, and 45 per cent said AI was not relevant to their organisation at all. Medium businesses were at 39 per cent adoption, large at 45.

Then the number that should bother you. Of the businesses that were using AI, adopting it or considering it, only 24 per cent had any security practice or process in place to manage the risk. Another 38 per cent said they planned to within a year. And 31 per cent had no plans at all.

Nearly a third of the businesses that have consciously decided to use this stuff have consciously decided not to think about it. That is the group with a decision behind them. Everybody in the 45 per cent who said AI is "not relevant" has the same staff, the same phones and the same free accounts, minus the decision.

What actually happens to the text you paste

Start with the fear that is mostly wrong, because it gets in the way of the one that isn't. Plenty of people assume that typing your customer list into a chatbot means the next person to ask will be handed your customer list. NCSC addresses this directly: a model does not automatically add information from queries to itself for others to query, and including something in a prompt will not result in that data being incorporated into the model.

So relax about that. Now worry about the rest of it.

NCSC's actual point is that the query is visible to the organisation providing the service. Those queries get stored, and will almost certainly be used for developing the service or the model at some point, which may mean the provider's staff, researchers, partners or contractors can read them. Stored queries can also be hacked, leaked, or, more likely, accidentally made publicly accessible. And there is the slow one nobody plans for: the operator may later be bought by an organisation with a different approach to privacy than the one that applied on the day your bookkeeper typed it in.

There is also aggregation. One prompt about a supplier dispute tells a provider very little. Forty prompts from the same login, over six months, describe your business in a level of detail you would never publish.

NCSC's two recommendations are short enough to put on a wall. Do not include sensitive information in queries to public models. Do not submit queries that would cause you problems if they were made public.

The second is the more useful test, and it is the one worth teaching. "Is this sensitive?" invites a judgement call from somebody in a hurry. "Would I mind if this appeared on our website?" does not.

The free account and the business account are different products

This is the whole article in one section, so if you skim, skim slower here.

OpenAI's own help page splits its services in two. For the ones aimed at individuals, including ChatGPT itself, the wording is that they may use your content to train their models, and that ChatGPT improves by further training on the conversations people have with it, unless you opt out. For business users, meaning ChatGPT Business, ChatGPT Enterprise and the API, the wording flips completely: by default, they do not train on any inputs or outputs.

Same brand. Same box on the screen. Opposite default.

Two details worth carrying with you. Opting out does not cover feedback, because if somebody clicks thumbs up or thumbs down, the entire conversation attached to that feedback may be used for training anyway. And Temporary Chat is a genuinely different mode: it does not appear in history, does not create memories, and is not used for training.

Which means the fix here is not a security project. It is a purchase, a login change and a five-minute conversation. That is a rare thing in this trade and it is worth taking.

If you are on Microsoft 365, look at what you already have

Most of the businesses we look after in Dagenham and across East London are already paying Microsoft every month. Microsoft's documentation, updated on 18 August 2026, sets out what organisational use of Copilot and Copilot Chat actually sits under: the Products and Services Data Protection Addendum and the Product Terms, with Microsoft acting as a data processor. Prompts, responses and the data reached through Microsoft Graph are not used to train foundation models.

Copilot also inherits the things you have already set up. It respects your identity model and permissions, picks up your sensitivity labels, applies your retention policies, and supports auditing of the interactions. If your file permissions are a mess, that is not a Copilot problem, but Copilot will show you the mess faster than you would like.

One naming note, because it will confuse somebody in your business this year: Microsoft 365 Copilot is now just Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. Microsoft's own page says there is no change to security, compliance or privacy behind the rename.

Whether Copilot is worth the money is a separate conversation, and it runs into the Business Standard against Business Premium question we have written about at length. What matters here is narrower. If your staff are going to use something, using the thing your tenant already governs beats the thing nobody bought.

The part of the safe option that isn't covered

Here is the paragraph you will not find on a vendor's marketing page, taken from Microsoft's own documentation.

When Copilot needs current information from the web, it turns your prompt into a short search query and sends it to Bing. Your user and tenant identifiers are stripped, it is not shared with advertisers, and it is not used to train the foundation models. So far, fine. But the Bing search service runs separately from Microsoft 365 with different data-handling practices, covered by the Microsoft Services Agreement and Privacy Statement rather than the Data Protection Addendum. Microsoft's own word for its role there is controller, independent of you, rather than processor acting on your instructions. The EU Data Boundary does not apply to them either.

That is not a scandal and it is not hidden. It is written down plainly by the vendor. But it is the difference between telling your board "we are covered" and telling them "we are covered for the part that matters most, and here is the bit that sits under different terms".

The same page adds a line about agents, which is where this is all heading: if you are using agents inside Copilot, check that agent's own privacy statement and terms of use. The governance you set up for the chat box does not automatically extend to everything you can bolt onto it.

The four risks the ICO actually names

The ICO ran a conference session on putting an AI policy in place, aimed at employers and employees rather than at people building models. They polled the room first. Of 524 responses, 271 said they did not feel confident using AI technologies in the workplace. Another 168 were slightly confident but would need significant guidance or support. That is more than eight in ten people who are already using these tools and would rather somebody told them the rules.

They name four risks. The first is confidential information going into prompts, and their example is Samsung banning employee use of ChatGPT after concerns about code.

The second is function creep, and it deserves reading twice. Their scenario: a company buys an AI tool to record and take notes at internal meetings. Staff start using it at external meetings too. During a meeting with an external partner, sensitive information is shared in a presentation, the tool records it, and it goes back to the developer for training. Nobody broke a rule, because there wasn't one. The tool did exactly what it was bought for, somewhere it was never bought for.

Third is automation bias, which the ICO defines in both directions. Users who rely on the output and stop applying their own judgement, and users who assume the output is always wrong and stop reading it. Both produce bad decisions.

Fourth is hallucinations, and their observation is the practical one: they are hard to spot because they arrive presented plausibly.

What an "AI policy" means when you have nine staff

The phrase makes people picture a twelve-page document with a version-control table. Do not write that. Nobody in your business will read it, and the ICO does not require it: their own position is that data protection law is technology-neutral and does not mention AI policies at all.

What a policy does is give you something to point at when you compile a data protection impact assessment, evidence that you took a data-protection-by-design approach, and a genuine reduction in the security risk. The ICO's four mitigations are the whole shape of it. Make sure staff know that what they share can be seen by people outside your business. Configure the most privacy-enhancing settings available. Define clearly what AI can and cannot be used for. Make sure people know the limits of what comes back.

On one page, that looks like this. Name the tool and the account everyone should use. Name three or four things that never go in: client personal data, anything under an NDA, anything covered by a contract you have not read recently, anything you would not put on the website. Say who to ask when it is not obvious. And say what happens when somebody gets it wrong, which should be nothing punitive, for the same reason we argue against punishing people who click a phishing link. A business where a bad paste gets reported in ten minutes is in a far better position than one where it gets reported never.

Put a review date on it. Six months is fine. This field moves faster than your policy will.

Where this touches UK GDPR, and where we stop

If the text contains personal data, and a customer complaint, a candidate's CV or an employee's sickness note all do, then pasting it into somebody else's service is processing. Your business is accountable for that. The tool being free does not change it, and neither does the fact that nobody signed anything.

What we are not: a law firm, and not your data protection officer. We do not write your privacy notice, we do not run your DPIA, and we do not report anything to the ICO on your behalf. If a paste turns into something that might need declaring, that decision is yours, and it is worth taking proper advice if it is a close call. The seventy-two hour clock is unforgiving about hesitation but it does not care who does the deciding.

What we can do is the technical half. Which accounts your staff actually hold, as opposed to the ones you think they hold. What your Microsoft 365 tenant already permits. Whether your file permissions would survive a tool that reads everything a user can read. That last one catches people out.

An honest note on our own side: none of our managed plans has an AI line item. Essential is £50 per user per month, Professional £77 and Complete £108, all excluding VAT, and none of them says "AI" anywhere. Our free ten-question IT health check asks about backups, MFA, patching, offboarding and phishing training, and does not ask about AI either. That is a gap in our own material rather than a considered position, and it is being fixed. Until then, the tenant and account questions above get covered as part of the free check whether or not it is on the form.

Do these four things this week

None of this needs a budget round.

  1. Ask what people are already using, and make it explicitly not a disciplinary conversation. You will get honest answers once, and only if the first one is not punished.
  2. Check the account, not the app. Free personal login versus a business subscription is the single biggest lever available, and it is a purchasing decision.
  3. Look at what your Microsoft 365 tenant already includes before you buy anything new. Some businesses are paying for governed AI and using an ungoverned free one instead.
  4. Write the one page. An afternoon, not a project. Then put a date on it.

If you want the technical half checked properly, our free perimeter check is remote and takes one signed form, and you get the findings whether or not you hire us.

Frequently asked questions

Should we just ban AI tools at work?+

You can, and the ICO's own material cites Samsung doing exactly that after confidential code went into ChatGPT. The trouble with a ban in a nine-person business is that you cannot see whether it is holding. People have phones. What tends to work better is naming one approved tool on a business account, saying plainly what must never go into it, and making that the easy path. A ban you cannot observe is a document, not a control.

Does ChatGPT train on what I type into it?+

It depends entirely on the account, and OpenAI's own help page is clear about the split. For services aimed at individuals, they may use your content to train their models, and ChatGPT improves by further training on conversations unless you opt out. For ChatGPT Business, ChatGPT Enterprise and the API, they do not train on inputs or outputs by default. Two things survive an opt-out, though. If somebody hits thumbs up or thumbs down, the entire conversation attached to that feedback may be used for training. And Temporary Chat is separate again: it does not go into history and is not used for training.

Are we legally required to have an AI policy?+

No. The ICO's position is that data protection law is technology-neutral and does not explicitly mention AI policies at all. What they say is that one helps you do things the law does expect: identify risks when you compile a data protection impact assessment, show you took a data-protection-by-design approach, and cut some of the security risk. Their own closing line is that there is no one-size-fits-all here.

Is Microsoft Copilot safe to use with client information?+

Safer than a free consumer chatbot, and Microsoft's documentation says why: organisational use sits under the Data Protection Addendum with Microsoft acting as a data processor, prompts and responses are not used to train foundation models, and Copilot inherits your existing permissions, sensitivity labels and retention policies. There is a carve-out worth knowing. Web search queries generated from your prompt go to Bing under a different agreement, and Microsoft's role for those is independent controller rather than your processor. Different arrangement, same chat box.

Does Cyber Essentials cover AI tools?+

No. The five technical controls are firewalls, secure configuration, security update management, user access control and malware protection. Nothing in that list is about what staff type into a chatbot, and you can certify without ever having thought about it. Alpha IT does not hold Cyber Essentials or Cyber Essentials Plus and is not an assessor, so treat that as a reading of the published scheme rather than a ruling.

Someone has already pasted a client list into ChatGPT. What now?+

Find out which account it was, whether training was switched on, and whether the conversation still exists so it can be deleted. Then work out whether personal data was involved, because if it was, this is a potential personal data breach and the seventy-two hour clock in UK GDPR may apply. We have written about that clock separately. What we will not do is decide for you whether it is reportable. That call belongs to whoever is accountable for the data in your business, with proper advice if it is close.

What about AI note-takers in meetings?+

This is the ICO's own worked example of function creep, and it is a good one. A business buys a tool to record and take notes at internal meetings. Staff start using it at external ones. A partner shares something sensitive in a presentation, it gets recorded, and it goes back to the developer for training. Nobody did anything malicious. The tool did exactly what it was bought to do, somewhere it was never bought for. There is also the question of whether everyone in the room agreed to be recorded, which is a separate problem with a longer history.

Could we run our own model instead, so nothing leaves the building?+

Technically yes. NCSC's own wording is that self-hosted models are likely to be highly expensive and should only follow a proper security assessment. For a business with nine or fifteen staff, the honest answer is almost always that the money is better spent on a business subscription and an afternoon writing the rules down. Self-hosting solves a problem most small firms do not have, and creates several they do not want.

Call usFree consultation