ChatGPT and client data: the one-page AI policy
Banning does not work, letting go does not either. Here is the template I use, to copy as is and adapt in an hour. Guide published on 13 September 2026.
Why one page, not a rulebook
More than half of Swiss SMEs already use AI, often without management knowing what leaves the company. A twelve-page rulebook will not be read; a ban will be worked around on a personal phone. One page, ten rules, signed by everyone, pinned near the coffee machine: that is what holds. The text below is the complete template. Replace the brackets, delete what does not apply.
The template
Policy on the use of artificial-intelligence tools · [Company name] · version of [date]
- What never leaves. No data that identifies a client, patient, beneficiary, employee or supplier (name, address, number, file, named amount) is entered into an AI tool not listed under point 3. An anonymised extract, yes; a file, no.
- Professional secrecy comes first. What the law or a contract obliges us to keep confidential stays confidential, AI included. When in doubt, ask [responsible person] before, not after.
- The approved tools are: [tool 1, business account], [tool 2, business account]. They are configured not to train on our data and not to retain it beyond [duration]. Any other tool, including a free version from the same vendor, is reserved for text containing no company data at all.
- One account per person, never shared, with two-factor authentication. The account is closed on the day of departure.
- AI suggests, a person decides. No text produced by AI goes to a client, an authority or a partner without review by a human who takes responsibility for its content. Figures, dates, legal references and quotations are checked at the source.
- We say when AI helped if the recipient could reasonably want to know: a report, an expert opinion, published content.
- No automated decision about a person (hiring, credit, health, sanction) without a documented human review.
- Outputs are kept like any other document: in our tools, not in the AI's history. The history is cleared every [frequency].
- Incidents are reported: data entered by mistake, a wrong answer sent, a doubt, are told the same day to [responsible person]. Nobody is sanctioned for reporting.
- This policy is reviewed every [six months] by [responsible person], and whenever a new tool arrives.
Read and accepted: name, date, signature.
How to get it signed without a meeting
- Fill in the brackets. Point 3 is the only one requiring a decision: which tools, with which accounts. If you have not chosen yet, write "no tool approved for company data before [date]"; it is honest and temporary.
- Send the page by email with three sentences: why, what changes for each person, the return date. No twelve-page attachment.
- Signature on return, paper or electronic, filed in the employee's record. Newcomers sign it on arrival, with the rest.
- Pin it up. A policy people see is a policy people apply.
The three mistakes I see most
- Banning everything. Staff then use their personal account, on their phone, with company data, and nobody knows. The policy must provide an approved tool, not only a prohibition.
- Believing the business account settles everything. It settles training and retention, not professional secrecy nor the duty to verify. Points 1, 2 and 5 remain.
- Forgetting the tools already there. Copilot in Word, Gemini in Gmail, the assistant in the accounting software: they are often on by default. The IT Audit Express inventory lists them.
The legal frame in three lines
Swiss data-protection law applies to any personal data entered into an AI tool, whatever the vendor. Switzerland will have no AI law of its own before 2028; the Federal Council is preparing a draft for late 2026. If you serve clients in the European Union, part of the EU AI Act applies since August 2026: in that case, have the policy reviewed by your legal adviser. This guide is not legal advice.
Frequently asked questions
Which tools go under point 3?
It depends on your data. For general use with sensitive data, a tool hosted in Switzerland or Europe (Infomaniak AI, Mistral); for advanced drafting and analysis, a US tool in a properly configured business edition. Never a free version for company data.
Should it be attached to the employment contract?
A signed policy filed in the employee's record is enough for most SMEs. If you want it to count as a directive under employment law, have it validated by your legal adviser or HR accountant.
What about freelancers and interns?
Same policy, same signature. They are often the ones using the most tools, with the least perspective.