What is the real security risk of staff using free AI tools at work?

17 August 2026

What is the real security risk of staff using free AI tools at work?

Free AI tools can be useful for harmless, general tasks, but they become a security risk when staff use them with identifiable, confidential or commercially sensitive information. For a UK SME, the biggest issues are data protection compliance, loss of control over company information, prompt injection, fake tools and browser extensions, account ownership, and staff relying on AI outputs for decisions they are not qualified to make.

What is the actual risk?

The honest answer is that free AI tools create risk when they become part of your business process without being treated as business software. If an employee uses a personal account to summarise a client contract, rewrite a complaint, analyse a spreadsheet, draft an HR letter or troubleshoot a customer issue, they may be copying sensitive information into a service the business has not approved.

That matters because the business still owns the outcome. Under UK GDPR, you need to know what personal data is being processed, why it is being processed, what lawful basis applies, who the processor is, where the data may go, and whether people have been told clearly enough. The ICO says its AI guidance is for public, private and third sector organisations and explains how UK GDPR principles apply to AI systems. If staff are using free tools informally, you may not even know enough to answer those basic questions.

The risk is not limited to model training. OpenAI says ChatGPT conversations may be used to improve models unless users opt out. Google Gemini Apps has a detailed privacy notice covering information users provide, saved activity, connected apps, uploads and human review. Microsoft explains that Copilot in Microsoft 365 apps for home is different from business use, and that the home version is for personal Microsoft accounts. The terms, controls and admin visibility change depending on account type.

For a small business, the immediate danger is loss of control. You cannot protect what you cannot see. You cannot delete what you do not know was uploaded. You cannot audit a decision if the prompt and answer sit inside a staff member personal account.

What information should never go into free AI tools?

Start with a simple rule: if the business would not paste it into a public web form, staff should not paste it into a free AI tool. That includes client names, contact details, employee records, payroll information, contracts, board papers, legal advice, medical or financial information, unpublished proposals, passwords, API keys, source code that contains secrets, pricing strategy and anything covered by a non-disclosure agreement.

There are grey areas. A staff member might think a customer email is harmless because it is only a draft. But if that email contains a complaint, account number, address, health issue, financial difficulty or contractual dispute, it is personal data and possibly sensitive context. A manager might paste a spreadsheet into an AI tool to ask for trends, forgetting it contains names, salaries, absence notes or customer values. A salesperson might ask an AI assistant to improve a proposal, including margin assumptions and a competitor strategy. None of those examples looks dramatic at the keyboard. They are ordinary work moments, which is why the risk is easy to miss.

The Department for Science, Innovation and Technology reported in the Cyber Security Breaches Survey 2025/2026 that 43% of UK businesses identified a cyber breach or attack in the previous 12 months. Phishing was experienced by 38% of businesses and remained the most common breach or attack type. Free AI use does not replace those threats, but it gives attackers and careless insiders more places for data to leak, more fake tools to imitate, and more ways to make risky messages look credible.

A workable staff rule should give examples, not abstract categories. Ban identifiable client data, confidential commercial data, credentials and regulated decisions from personal AI accounts. Allow harmless uses such as rewriting generic text, brainstorming public content, summarising public information, creating Excel formulas with dummy data, and learning concepts without exposing live business material.

Are paid business AI tools safer?

Usually, yes, but only when they are configured properly. The useful distinction is not free versus paid. It is personal account versus business-controlled account. A business account can give you admin control, user management, data retention settings, contractual terms, audit logs, single sign-on, permission boundaries and clearer support if something goes wrong. A personal free account gives the employee convenience, but the business may have no practical control.

Microsoft says prompts, responses and file contents in Copilot in Microsoft 365 apps for home are not used to train foundation models, but the same Microsoft page also says it applies to home use when someone is signed in with a personal Microsoft account. That is exactly the point. Account context matters. A staff member using personal Copilot, personal Gemini or a free chatbot in a browser is not the same as using an approved business tenant with controls switched on.

For UK SMEs, the cost difference is often smaller than the risk suggests. A managed business AI account might cost around £20 to £35 per user per month for mainstream tools, depending on plan and vendor. A basic policy and configuration review might cost £750 to £2,500 if you use external support. A fuller AI governance and workflow review might cost £2,500 to £7,500. Those numbers are not trivial, but they are modest compared with a data incident involving clients, regulators, insurers and lost trust.

Paid tools are not magic. Staff can still upload the wrong file, rely on a bad answer, install a risky extension or share confidential data with a tool that is not approved. But business tools let you set boundaries. That makes training enforceable rather than hopeful.

What about prompt injection, fake AI tools and browser extensions?

Data privacy is only one part of the risk. The NCSC warns that current large language models do not enforce a robust security boundary between instructions and data inside a prompt. Its prompt injection guidance explains that malicious content can be treated as an instruction by an AI system. That matters most when AI is connected to files, email, CRM records, browsers or business systems, because the tool may be able to read, summarise or act on information.

For a free public chatbot used only for generic drafting, prompt injection risk is limited. For a browser extension that reads web pages, email or documents, the risk becomes more serious. Staff often install browser add-ons because they look convenient: summarise this page, write this reply, extract this invoice, check this contract. The business may not know what data the extension can read, where it sends content, or whether it is operated by a reputable provider.

Fake AI tools are another practical problem. Attackers follow attention. When staff search for free AI helpers, PDF summariser tools, meeting note takers or spreadsheet assistants, they can run into copycat sites, malicious extensions and phishing pages. The DSIT survey found phishing was the most prevalent breach or attack type for UK businesses, experienced by 38% of businesses. AI branding gives phishing a believable disguise because employees expect to sign into new AI services.

The safest first rule is narrow access. Staff should not install AI browser extensions or connect AI tools to email, cloud storage, CRM, accounts software or project systems without approval. If an AI tool needs access to business systems, treat it like any other supplier integration: check permissions, retention, data processing terms, owner, rollback process and whether least privilege is possible.

What should a small business do this week?

Do not start with a 30-page AI policy. Start with a practical control that staff can understand. First, decide which AI tools are approved. Second, write a banned data list. Third, give safe examples. Fourth, require manager approval before AI is connected to any business system. Fifth, create a simple incident route for accidental sharing.

A useful one-page policy can say: use approved accounts only for business work; do not enter client data, employee data, contracts, credentials, financial records or confidential plans into free tools; use dummy data when experimenting; check every AI output before using it with customers; do not use AI for HR, legal, finance, medical, regulated or customer-impacting decisions without human approval; and report accidental disclosure immediately. That is plain enough for daily use.

Then make it real. Ask each team where they already use AI. Do not punish honest answers, because you need visibility more than blame. Move useful use cases into approved tools. Block risky extensions. Add AI to onboarding and leaver processes. Review shared prompts, uploaded files and connected apps where the platform allows it. Put one person in charge of approvals, even if that person is the owner or operations manager.

If you are already using free tools without rules, budget time rather than panic. A light internal audit can be done in two to four hours: list tools, users, data types, connected apps and risky workflows. A more formal review may take one to two weeks if you have several systems and client data flows. The goal is not to stop your team using AI. The goal is to stop invisible risk becoming normal.

Is This Right For You?

This applies if your team is already using ChatGPT, Copilot, Gemini, Claude or browser AI extensions without a written rule set. It is especially relevant if staff handle client files, quotes, contracts, invoices, HR documents, customer messages, passwords, CRM data or commercially sensitive plans.

It is less urgent if your staff only use approved business accounts, you have admin controls switched on, confidential data is blocked, and managers already review AI-assisted work. Even then, it is worth checking the rules, because informal AI use tends to spread faster than policy.

The practical next step is not a ban. It is a one-page AI acceptable use policy, approved tools, examples of banned data, and a named person who can approve exceptions.

Frequently Asked Questions

Should I ban staff from using free AI tools completely?

Usually no. A blanket ban often drives usage underground. A better first step is to ban confidential, personal and commercially sensitive data from free tools, approve safe use cases, and move regular business use into controlled accounts.

Can staff use ChatGPT, Gemini or Copilot for harmless tasks?

Yes, if the task uses public or dummy information. Examples include explaining a concept, rewriting a generic paragraph, creating sample spreadsheet formulas, or brainstorming public marketing ideas without client data.

Is anonymising client data enough?

Sometimes, but staff often miss indirect identifiers such as job title, location, project value, rare circumstances or account history. Use dummy data where possible, and keep high-risk or sensitive context out of personal AI accounts.

Who should approve AI tools in a small business?

A named owner should approve them, usually the business owner, operations lead, data protection contact or external IT adviser. Anything touching personal data, customer decisions, integrations or finance needs senior sign-off.

What should we do if someone already pasted sensitive data into an AI tool?

Record what was shared, when, by whom, with which tool and account. Check whether deletion or opt-out controls exist. Assess whether personal data was involved, whether clients need to be told, and whether ICO reporting advice is needed.

Are browser AI extensions riskier than normal chatbots?

Often yes, because they may read pages, documents, email or tabs automatically. Treat any AI extension with access to business content as a software supplier, not a harmless productivity shortcut.

What is the minimum AI policy a small business needs?

At minimum, list approved tools, banned data, safe examples, uses requiring approval, output-checking rules, who owns decisions, and what staff should do if they accidentally share sensitive information.