2026-09-02 · 5 min read

My company blocked ChatGPT — what now?

Why did the company block ChatGPT in the first place?

Almost always out of fear of leakage, not hostility to innovation: the moment an employee pastes a contract, code or a customer list into an external tool, the company loses control of that data.

Every CISO knows the precedents: Samsung banned generative-AI tools on company devices in May 2023 after engineers pasted internal source code into ChatGPT (per Bloomberg); major US banks — JPMorgan among them — restricted use in early 2023; Italy's regulator even blocked ChatGPT temporarily in March 2023. Add GDPR fines up to €20M or 4% of global turnover, and blocking looks safe.

The problem your CISO is solving is real — some things should never be pasted into ChatGPT under any policy. The open question: is a blanket ban the right fix, or just the fastest one?

Why is the personal-phone workaround the riskiest move?

Because a workaround doesn't remove the risk — it removes the oversight. That's exactly Shadow AI: the same sensitive data flows to the same tools, with no logs, no enterprise settings, and nobody knowing where it went.

  • It's already the norm: per the Microsoft and LinkedIn Work Trend Index 2024 (31,000 respondents, 31 countries), 75% of knowledge workers already use AI at work — about 78% of them bring their own tools (BYOAI).
  • The exposure becomes personal: a paste from a private account is still a company data leak — except now you can't claim you followed procedure.
  • And the terms are worse: a personal account runs on consumer terms — check the vendor's current policy — with none of the company's contractual protections.

What middle path can you offer IT?

One simple rule: external AI tools get anonymized copies only. Instead of arguing about which tool is allowed, change the question to what is allowed into the tool — once the answer is "only documents after anonymization", most of security's objection disappears.

It also complements blocking controls: DLP stops files at the gate, anonymization cleans the content itself. And when cleaning runs entirely in the browser, the original never reaches any server — the tool adds no new risk of its own.

How do you pitch the CISO? A step-by-step script

  1. Gather a measurable business need — two or three tasks where AI saves real hours weekly, in numbers: "summarizing 20 requirements documents a month", not "everyone uses it".
  2. Acknowledge the risk up front — one sentence showing you understand why the ban exists. A CISO who feels understood listens differently.
  3. Propose one clear rule — external AI tools receive anonymized copies only; originals never leave the organization.
  4. Ask for a bounded pilot — one team, one month, one document type, reviewed at the end. Small pilots are easy to approve.
  5. Bring a draft policy — hand over a ready company AI policy template instead of waiting for someone to write one.
  6. Ask for a decision in writing — even a reasoned "no" defines what would have to be true for a "yes".

What if only Copilot is allowed?

That's the most common outcome: everything blocked, one sanctioned tool left. It beats zero — but one tool never covers every need, and that gap pushes people into Shadow AI. The Copilot-only policy guide covers this scenario in depth — same conclusion: a safe channel beats a wall.

Frequently asked questions

Can I use ChatGPT on my personal phone for work tasks?

If your company blocked AI tools — no. Feeding company data through a private account is Shadow AI: the same leak with zero organizational control, and a direct policy violation. Fully anonymized content lowers the real risk, but the policy still needs approving.

Why block ChatGPT but keep Copilot?

Because an enterprise-purchased tool comes with a contract, admin controls and data-processing commitments — and a free external tool comes with none of that. It's a risk-management decision, not a verdict on which tool is "good".

What can I feed an AI tool once it's anonymized?

A fully cleaned document — names, IDs, customers and amounts replaced with consistent tokens, metadata removed — no longer contains personal data, so most policies can approve sending it even to external tools. That's the core of the CISO pitch.

Should I change jobs over an AI ban?

Try the proposal route first: a measurable business need, an "anonymized copies only" rule, and a small pilot. Per the Work Trend Index 2024, 79% of leaders say AI adoption is critical for competitiveness — management is likely looking for exactly this answer.