Why banning ChatGPT isn‘t enough

Many companies first ban AI, then quietly tolerate it, and finally discover that everyone is using it anyway – just without rules. That‘s the worst possible scenario.

An employee needs to quickly translate an email or draft a reply to a customer. They open a public tool and paste the entire communication, including names, prices, and conditions. They send the data to a server outside the EU. Without a processing agreement. Without the company‘s knowledge.

You won‘t prevent that with a ban. You‘ll prevent it with clear boundaries.

5 rules for safe use of AI in the company

This checklist should hang on every notice board and be part of the onboarding package. It‘s the minimum you can implement within a week:

  • Don‘t enter sensitive personal data without a legal basis: Client names, national ID numbers, health data, or addresses do not belong in public models. Ever.
  • Don‘t enter contracts and know-how without assessment: Price offers, technological processes, trade secrets – that‘s the family silver. Public AI will remember it and may use it in a response to someone else.
  • Verify every output: AI hallucinates. It makes up numbers, paragraphs, and names. Treat it like a capable intern whose every sentence you check.
  • Have clearly defined responsibility: Every generated text, suggestion, or decision must have its human guarantor. “ChatGPT wrote it” is not an argument for an auditor or a court.
  • Consider a local model for sensitive processes: If you process internal directives, technical manuals, or customer support with sensitive data, a model that runs directly at your site and doesn‘t let data leave the company is worth the investment. More on that in our separate article.
ithope.cz
Preview of the ITHOPE.cz website — IT services, AI training, and data recovery in Brno
ITHOPE.cz — we write about AI on our own website and train companies; the same rules you're reading about, we use daily in practice.

Public vs. private AI: where the line is

Imagine two scenarios from a typical company.

First: a marketing specialist is writing a blog post and gets AI to suggest an article structure and check the stylistics. The topic is general, the input data are publicly available. A cloud solution is perfectly fine.

Second: a sales manager needs to analyze ten client offers, compare margins, and propose a pricing strategy. They upload a spreadsheet to a public tool and hope nothing happens. That‘s a disaster waiting to happen.

The difference isn‘t in the technology. The difference is in the data. If you‘re putting something into AI that you wouldn‘t pin on the company notice board, it doesn‘t belong in a public model either.

What awareness looks like in practice

The cheapest and most effective measure is for the team to understand the basic principles. No memorizing directives, but practical examples from your field.

We‘ve seen it repeatedly – one two-hour AI training for a company and the number of security incidents drops practically to zero. People learn to recognize what belongs in AI and what doesn‘t, how to verify outputs, and where the red line is.

For service companies, inspection technicians, or manufacturing plants, we address specific situations: a technician writing an inspection report, an accountant processing documents, a salesperson preparing a proposal. The rules take a slightly different form for each role.

AI doesn‘t replace responsibility. The person, not the tool, is always accountable for the final output. That‘s not a legal loophole. That‘s a principle for survival.

What you risk when you have no rules

Without internal rules, you risk three things:

  • Leak of sensitive data: Once data is put into a public model, you‘ll never get it back. And you don‘t know who all might access it.
  • Legal penalties: According to the Czech Trade Inspection Authority (ČOI) and the Office for Personal Data Protection (ÚOOÚ), the responsibility lies with the company that entered the data into the tool. Not the AI provider.
  • Reputational damage: In a field where clients value confidentiality (IT services, electrical inspections, accounting), one leak means losing clients for years to come.

Our websites confirm that companies address IT and AI practically – not theoretically. The ITHOPE.cz website recorded a 278% year-on-year increase in search impressions precisely thanks to expert content that answers customers‘ real questions. Similarly, the new SOHE.cz website reached the first page of Google within 4 weeks of launching content – because we wrote about what technicians and operators actually care about.