Montro
Shadow AI10 min read

ChatGPT In The Workplace: A Governance Approach That Doesn't Ban It

ChatGPT In The Workplace: A Governance Approach That Doesn't Ban It
AuthorAnkur Arora
Published on4 Jun 2026

Your firm banned ChatGPT in February. Your engineering team uses it through a personal account in March. Your legal team uses it on a phone in April. The ban produced a visibility problem, not a ChatGPT governance problem. The governance problem was always the same: make the sanctioned route easier than the unsanctioned one, and run discovery continuously so you can see which route employees are actually taking.


This piece is the structured alternative to banning. The three OpenAI tiers and what each does with prompt and output data, the data residency picture for European firms, and an AI acceptable use policy template that recognises how employees actually adopt these tools.


Why Bans Fail


The empirical pattern in shadow AI audits is consistent. Firms that ban ChatGPT do not stop ChatGPT use, they stop the visible use. The displaced usage moves to personal accounts, personal devices, and phone-based access. Six weeks after the ban announcement, the firm has the same usage with materially less visibility, and a security team that now has to ask employees to self-report rather than reading the SSO logs.


The asymmetry is structural. The benefit of using ChatGPT for the employee - a faster draft, a clearer summary, a better outline, is concrete and immediate. The cost of being caught is abstract and probabilistic. The ban changes the visibility but not the incentives. The generative AI governance approach that works inverts the asymmetry: makes the sanctioned usage materially easier than the unsanctioned, so the path of least resistance routes through the channels where the firm has visibility and controls.

What Montro Finds After a Ban

When Montro runs discovery for a firm that has already banned the use of ChatGPT, the finding that comes up most consistently is the usage of ChatGPT on personal devices in the weeks after the ban was announced. Not always in marketing. Not always in engineering. Sometimes in the security team itself, the same department that drafted the ban policy. This is not a story of reckless employees. The people who were using it were doing the same work they were doing before the ban, under the same time constraints, with the same deadlines. The ban removed the authorised route, but it did not remove the need that created the usage in the first place. And what it actually removed was the firm's ability to see what was happening.


Discovery after a ban does not find less ChatGPT usage than a discovery before one; it finds the same usage in places the SSO cannot reach.

The Three OpenAI Tiers


OpenAI sells ChatGPT through three architectural tiers, each with different default data handling. The differences are operationally substantial enough that the tier decision is most of the governance work.


Free and Plus (Consumer Tiers)


The consumer tiers are designed for individual users. The default position is that conversations may be used to improve OpenAI's models, with an opt-out available in user settings. Data residency is at OpenAI's discretion within their global infrastructure. There is no Data Processing Agreement available to a controller wishing to bring the consumer tier into Article 28 GDPR-compliant processor-style use, because the tiers are not designed for that purpose.


The practical consequence: the consumer tiers are not suitable for processing personal data of customers, employees, or other data subjects in any meaningful volume. They are suitable only for genuinely personal use. The mid-market firm whose employees use the consumer tiers for work-related tasks is operating outside any defensible Article 30 RoPA position.


Team


The Team tier sits between consumer and enterprise. It offers a higher per-seat plan with administrative controls, the explicit position that Team conversations are not used for model training by default, and a workspace administration model. A Data Processing Agreement is available.


Team is appropriate for mid-market firms whose AI usage is principally productivity-focused - drafting, summarisation, brainstorming - and whose data sensitivity is moderate. It is not the right tier for firms processing large volumes of customer personal data, special category data, or content that requires deeper compliance commitments. The data residency representations are improved over the consumer tiers but the Enterprise tier offers stronger commitments.


Enterprise


Enterprise is the tier designed for compliance-aware deployment. The default position includes commitments that conversations are not used for model training, that the deployment supports administrative controls including SSO and audit logging, that a Data Processing Agreement is available with the appropriate Article 28 representations, and that data residency commitments, including European data residency for EU customers - are part of the standard offering. Output retention and prompt logging are configurable rather than default.


Enterprise is the defensible tier for processing-personal-data use cases. The contracting overhead is real but manageable, and the resulting governance position is materially stronger than any consumer or Team configuration. The cost difference per seat is non-trivial, but the comparison should not be Enterprise versus consumer, it should be Enterprise versus the operational cost of running governance against an inventory the firm cannot see.


Data Residency


The residency picture has three components. Where the prompts are sent, where the inference runs, and where any retention sits.


OpenAI's EU residency offering for Enterprise customers includes commitments that data is processed within the European Union for the storage and inference layers, with the practical implication that prompts and outputs do not transit non-EU infrastructure for European customers electing the residency commitment. The commitment is contractual; the firm should confirm the current published position at the time of contracting because the architecture continues to evolve.


For consumer tier usage, no residency commitment of operational substance applies. For Team, residency is improved but not equivalent to Enterprise. For firms whose regulatory position requires EU residency - financial services under DORA, NIS2 in-scope firms with EU-based customers, firms processing significant European personal data, the practical conclusion is that Enterprise is the only tier that supports the residency requirement defensibly.


The EU-US Data Privacy Framework adequacy decision provides a transfer mechanism for personal data flows where the residency commitment does not apply. Firms relying on the framework rather than EU residency should confirm the current adequacy status before contracting; the framework has been challenged in litigation and the trajectory of EU adequacy decisions has been historically uncertain.


A Pragmatic Policy


The AI acceptable use policy that works in practice is simple and applies the tier decision rather than the per-prompt prohibition.


Sanctioned tier. The firm provides Enterprise (or Team where the use case is appropriate) access to all employees who have a work-related use case. The provisioning is through SSO so that usage is visible to the security team. The seat cost is treated as a productivity investment, not a compliance cost, the cost analysis is operating-cost-of-not-providing rather than savings-versus-banning.


Acceptable use. The policy specifies what employees may and may not put into the sanctioned channel: no special category data, no customer personally identifiable information beyond what the use case requires, no client confidential information from regulated relationships, no content covered by client-specific NDAs that prohibit AI processing. The list is short and operational.


Unsanctioned use. The policy states explicitly that unsanctioned shadow AI use - consumer tier accounts, personal-device use, third-party wrappers around ChatGPT for work tasks, is not permitted. The enforcement is light initially because the goal is migration not punishment; the firm's first response to discovered unsanctioned use is to provision the employee on the sanctioned tier.


Discovery. The firm runs continuous discovery against the sanctioned tier so that usage is visible, and against the broader environment so that unsanctioned channels are surfaced. The sanctioned-versus-unsanctioned comparison is the leading indicator of whether the policy is working: as Enterprise usage grows, free-tier usage should fall.


The shape of generative AI governance that holds up across two years of regulatory change is the one where the firm provides a defensible default and makes that default easier than the alternatives. The ChatGPT case is the clearest test of that principle.


Frequently Asked Questions


Is ChatGPT's consumer tier GDPR-compliant for workplace use?


The consumer tiers have no Data Processing Agreement available for controller use. Without an Article 28 DPA in place, any processing of employee or customer personal data through them is likely to create a significant compliance gap under Regulation (EU) 2016/679, and the opt-out from model training in user settings does not address the absence of a processor agreement.


Does ChatGPT Enterprise satisfy DORA's ICT third-party requirements?


Enterprise is the only tier designed with compliance-aware deployment in mind. Consumer and Team tier subscriptions entered through standard sign-up flows are unlikely to contain the mandatory Article 30 DORA provisions - audit rights, SLAs, data return clauses, that regulated financial entities need in their ICT third-party arrangements. Firms should assess the current OpenAI contractual position against their specific DORA obligations at the time of contracting.


What is the difference between ChatGPT Team and ChatGPT Enterprise for EU firms?


The most significant difference for European firms is the residency commitment. Enterprise includes contractual EU data residency, prompts and outputs processed within EU infrastructure. Team does not offer an equivalent commitment, which means firms with EU residency requirements under DORA, NIS2, or GDPR should carefully assess whether it meets their specific obligations before deploying it for work-related use.

Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.

Blog

Read next

Explore more from our library

View all

Stay informed on EU AI governance

Monthly updates on regulatory changes, compliance trends, and platform releases

By subscribing you agree to our Terms and Conditions and Privacy Policy

Montro AI governance dashboard showing tool risk tiers