Can I use ChatGPT at work?
It is not forbidden. But it is a decision an organisation should take explicitly and put in writing — with an acceptable use policy, a choice of which version is permitted, and a clear statement about which data must not go in. Without that, staff will use ChatGPT anyway, just without any oversight.
The question is not “whether”, but “on what terms”
There is no law that forbids using ChatGPT in a company. What there are, are obligations to be met along the way — data protection, professional confidentiality, works constitution law, and since 2024 the EU AI Act's requirements on AI literacy.
In practice that means: the riskiest option is not use, but unregulated use. An organisation that decides nothing does not have “no AI project” — it has an uncontrolled one.
What an acceptable use policy has to settle
A workable policy fits on two pages and answers five questions:
1. Which tool is approved? A named company account, not “some AI service”. The personal ChatGPT account is explicitly not part of it.
2. What may go in — and what may not? Concrete examples work better than abstract categories: no names of clients, patients or staff, no draft contracts, no credentials, no log extracts containing personal data.
3. Who checks the result? Responsibility for accuracy stays with the person who uses an answer. That needs saying out loud, because otherwise nobody takes it on.
4. What happens if the rules are broken? Not as a threat, but so that the rule is taken seriously at all.
5. Who answers questions about it? A named contact lowers the barrier to asking when in doubt, rather than just going ahead.
Works council, liability, AI Act
Co-determination: as soon as a system is capable of monitoring the conduct or performance of employees, section 87(1) no. 6 of the German Works Constitution Act applies. With a logging AI assistant, that threshold is quickly met. Bringing the works council in early is considerably cheaper than dismantling a solution already in use.
Responsibility for results: a language model can produce false statements that sound right. Anyone who passes such an answer unchecked into a quote, an expert opinion or a piece of advice is liable for it as for any other statement of their own. No provider takes that on.
EU AI Act: since February 2025, organisations have had to ensure a sufficient level of AI literacy among their staff (Art. 4). That is not a certification but a training obligation — whoever deploys AI has to enable their people to use it properly.
Why a ban does not work
The obvious reflex is to forbid it. In practice that produces shadow use: the work gets done anyway, just on the personal account, on the personal device, with no record and no data processing agreement. A manageable risk becomes an invisible one.
The reason is mundane: the need is real. Anyone who answers enquiries, drafts text or searches through documents all day saves noticeable time with an assistant. A ban takes away the benefit, not the need.
What reliably works is an internal alternative that is at least as convenient. If the approved tool is closer to hand than the detour via a personal account, shadow use sorts itself out.
Where KOSMO comes in
KOSMO is the option where most of the questions above never arise in the first place: processing happens on-premise or in our German data centre, no model is trained on your data, and group permissions let you control who gets to see which sources at all.
The acceptable use policy is still needed — it just gets shorter, because the hard parts are settled technically rather than organisationally.
What you would actually be handing over to ChatGPT is set out under What does ChatGPT do with my data?; the legal assessment for customer data under ChatGPT, Claude & Co. with customer data.
Last checked: 13 August 2026. This page sorts through the questions that typically come up and is no substitute for legal advice. Whether and how you may use AI depends on your sector, the data you process and your internal agreements.
Frequently asked questions
Is using ChatGPT at work forbidden?
No. There is no blanket ban. There are obligations, though — data protection, professional confidentiality, co-determination, AI literacy under the EU AI Act — that have to be met when using it.
Do we need a written acceptable use policy?
Strongly advisable. Without one, every individual effectively decides for themselves what to type in — and the organisation can neither trace nor limit what goes out.
Does the works council have to agree?
As soon as a system is capable of monitoring conduct or performance, there is a right of co-determination under section 87(1) no. 6 of the Works Constitution Act. With logging AI assistants that is regularly the case.
Who is liable if the AI produces something false?
Whoever uses the answer. A language model produces plausible-sounding statements that can be wrong; checking them stays the user's job. No provider takes that responsibility on.
Should we simply ban ChatGPT?
That usually just shifts use to personal accounts and personal devices — with no record, no data processing agreement, no way to delete. An approved alternative that is at least as convenient works better.
What does the EU AI Act require of us?
Since February 2025, organisations have had to ensure a sufficient level of AI literacy among their staff (Art. 4). That is an obligation to train and enable, not to certify.
An assistant that gives nothing away
KOSMO runs on-premise or in our German data centre. Your content is used to answer your question — and never to train a model.







