Nobody in your company set out to leak anything. An account manager pastes a client list into ChatGPT to rewrite it as a clean table. A developer pastes a config file to find a bug faster. An HR assistant pastes three CVs to summarize them. Every one of those people is doing their job well, on a deadline, with a tool that works. That is the whole problem, and it is why ChatGPT data security is now a management question rather than a technical one.
The instinct is to ban the tool. It rarely survives contact with reality. A ban does not remove the AI from your company, it just moves it onto personal phones where you cannot see it at all. The workable answer is narrower and much easier to enforce: decide which account your staff use, and agree on a short list of things that never get pasted anywhere.

ChatGPT data security starts with one question: whose account is this?
The single fact that changes the outcome is which type of account the text was typed into. It is not about the model, the prompt, or the wording. It is about the plan.
On a personal free, Plus or Pro account, conversations are used to help improve OpenAI’s models by default. The user can switch that off in their settings, under data controls, but it is a toggle most people have never opened. On ChatGPT Team, ChatGPT Enterprise and the API, business data is not used for training by default, and the organization has to explicitly opt in for it to be. That is the entire difference, and it costs the price of a business subscription.
Turning the training toggle off is still not the same as the data never leaving. Whatever your employee pasted was transmitted to a third-party company outside Morocco, stored on its servers, and retained for a period under that company’s own policy. For a marketing headline, that is fine. For a client’s national identity card number, a patient record, or an unreleased contract, it is a disclosure you made without noticing.
This is the mechanism worth explaining to your staff, because once people understand it they tend to self-correct. The rule “use the company account” sounds arbitrary. The rule “on your personal account, what you paste can be used to train the model, and on the company account it cannot” is one people remember.

What the evidence actually shows
The reason to treat this seriously is not a hypothetical. IBM’s 2025 Cost of a Data Breach report found that organizations with high levels of shadow AI, meaning staff using unapproved internet-based AI tools, carried an extra 670,000 US dollars on the average cost of a breach. In the same study, 97% of breached organizations that suffered an AI-related incident said they lacked proper AI access controls, and 63% had no AI governance policy at all.
The World Economic Forum’s Global Cybersecurity Outlook 2026, based on responses from 804 executives across 92 countries, found that 87% of respondents named AI-related vulnerabilities the fastest-growing cyber risk of the past year. Their top concern for the year ahead was not clever attackers. It was ordinary data leaks through generative AI.
There is also a well-documented example. In April 2023, engineers at Samsung’s semiconductor division pasted proprietary source code and the transcript of an internal meeting into ChatGPT across three separate incidents in under a month. Samsung banned external generative AI tools on company devices the following month, as Bloomberg reported at the time. The staff involved were not careless people. They were engineers using a tool that made them faster. Source code and configuration files are among the most common pastes of all, and they carry the same exposure we covered in common developer mistakes in cybersecurity.
Why this is a CNDP question in Morocco, not just an IT one
For a Moroccan business, there is a second layer that most international coverage skips entirely. Pasting client data into an AI service is a processing decision, and Moroccan law has something to say about it.
Article 23 of Law 09-08 requires anyone handling personal data to put in place the technical and organizational measures needed to stop that data being damaged, altered, or used by an unauthorized third party. Sending a customer file to an external service on a personal account is difficult to describe as such a measure. The law also requires that when you use a processor, you choose one offering sufficient guarantees on exactly those measures, which is a contractual relationship your employee’s personal account does not have.
Then there is the transfer question. Moroccan law requires prior authorization from the CNDP before personal data is transferred to a foreign country, and transfers are meant to go to countries offering an adequate level of protection. An employee moving a client list to a server abroad, with no contract and no authorization, is not a gray area anyone wants to have to explain later. Our overview of Moroccan cybersecurity laws covers the wider framework these obligations sit in.
A one-page ChatGPT data security policy your team will follow
Long policies get filed and forgotten. Four rules on one page get followed. This is the version that works for a small or mid-sized Moroccan company.
One approved account. Pay for a business plan and put everyone on it. This one decision removes the training question entirely and gives you an admin view of who is using what.
A red-line list. Name the specific things that never go into any AI tool, in any account. Keep it to one short list, phrased in your own business’s language.
Anonymize before you paste. Most real work does not need the real names. “Draft a payment reminder for a client who is 60 days late” produces the same output as the version containing the client’s name, ICE number and outstanding balance.
One named owner. Somebody must own the policy, answer questions, and approve new tools. Without a name attached, it is a document rather than a rule.

How to tell if shadow AI is already in your company
Assume it is, then confirm it without turning the exercise into an investigation. Ask your team directly which AI tools they use and make it explicitly safe to answer honestly, because a punitive framing simply produces a quieter version of the same behavior. Check whether AI subscriptions are appearing on expense claims. Ask your IT provider to report on traffic to the main AI services from the company network.
Browser extensions deserve a specific look. Many AI writing and summarizing extensions request permission to read the content of every page the user visits, which includes your webmail, your CRM and your accounting dashboard. That permission is granted once and then forgotten, and it is a broader exposure than any single pasted prompt. It belongs on the same review list as the rest of your security audit checklist.
Frequently asked questions
Is ChatGPT safe for business use?
It can be, on the right plan. On ChatGPT Team, Enterprise or the API, your content is not used to train models by default. On a personal free or Plus account it is, unless the user has turned that setting off. The tool is not the variable. The account is.
Does turning off training make it private?
No. It stops your content being used to improve the model, which is worth doing, but the text still leaves your company and is stored by a third party under its own retention policy. Sensitive data should stay out regardless of the setting.
Should we just ban AI tools at work?
Rarely. A ban pushes the same activity onto personal devices, where you have no visibility and no recourse. Approving one account and defining a short red-line list gives you far more actual control than a rule people quietly ignore.
Attackers are already using AI to make their own work faster, as we covered in our piece on AI-powered cybersecurity attacks. The defensive side of that story is much less dramatic. It is knowing which account your staff are typing into, and agreeing on the handful of things that never get pasted at all. If you are not sure what is already leaving your network, that is a reasonable place to start a conversation.




