ChatGPT im Unternehmen: Mitarbeitende nutzen KI für Texte, Ideen und Präsentationen im Arbeitsalltag

ChatGPT in the Workplace: What Employees Can – and Can’t – Do

It’s Monday morning at the office: one employee asks ChatGPT to draft an email to a client. The marketing team uses a few prompts to come up with ideas for its next campaign. A manager uses AI to prepare for a difficult feedback conversation. And someone in recruiting has the idea of uploading a CV and asking ChatGPT to assess the candidate.

It’s all practical and efficient – but is all of it a good idea?

Using ChatGPT in the workplace is no longer a question for the future. Employees are already using AI because it saves time, generates ideas and can produce a first draft in seconds. For start-ups and SMEs in particular, the potential is enormous. At the same time, this creates a new task for managing directors and HR teams: there needs to be clarity around what AI can be used for, what information should never be entered into it, and who is responsible for the results.

Because in many cases, ChatGPT itself is not the real risk. The real risk is using it without clear rules.

Can Employees Use ChatGPT in the Workplace?

The first step is to define which AI tools are approved for which purposes. Different uses of ChatGPT can involve very different levels of risk.

Asking for ten alternative headlines for a LinkedIn post is entirely different from entering employee data, confidential client information or complete application documents into an AI system.

That is why blanket statements such as “AI is allowed in our company” are not particularly helpful. A much more useful question is: Which AI tools can be used by whom, for which tasks, and with what information?

If a company can answer that question clearly, it has already taken an important step towards a structured approach to AI.

Employees use ChatGPT in the Workplace to support everyday tasks

When ChatGPT Is Already Being Used: Shadow AI

Many companies never formally introduce AI. At some point, it simply becomes part of everyday work.

Employees experiment with ChatGPT and other AI tools because they make their jobs easier. They improve texts, prepare presentations, summarise information or generate ideas – sometimes without anyone having a clear overview of which applications are being used or what information is being entered into them.

The term shadow AI has become established for this kind of unregulated or unofficial use of AI. If no one knows which AI tools are being used within the company, it becomes difficult to manage data protection, confidentiality, responsibilities and the handling of sensitive information.

A blanket ban does not necessarily solve the problem. It may simply mean that employees continue using AI outside the processes the company has put in place. In practice, a small number of clear and easy-to-understand rules are usually more helpful.

What Can Employees Use ChatGPT For?

ChatGPT can be useful for many workplace tasks. Examples include brainstorming and initial ideas, outlines and first drafts, alternative wording, preparing presentations, general checklists and summarising non-sensitive information.

The key requirement is that the output should not simply be accepted without review. Generative AI can sound convincing while still being wrong, misinterpreting information or making up details.

A useful principle for internal AI use is therefore:

AI provides a suggestion. The human remains responsible for the result.

This is particularly important when content leaves the company, is used to prepare decisions or affects other people.

Not Every Process Needs AI

With AI currently being discussed everywhere, it is easy to get the impression that as many processes as possible should be automated. For SMEs, that is rarely the best place to start.

A more practical approach is to focus on areas where there are genuinely repetitive, time-consuming tasks or where information regularly needs to be found, structured and prepared. In HR, for example, this could include preparing onboarding processes, creating initial drafts or producing standardised internal communications.

Instead of asking where AI could potentially be used, it is therefore worth asking a different question: What specific problem do we want AI to solve more effectively? This helps prevent companies from introducing a new tool when the underlying process was never clearly defined in the first place.

What Shouldn’t Simply Be Entered into ChatGPT?

Employees do not need a 20-page paper on data protection to use AI responsibly. They need rules they can quickly apply in their day-to-day work. A simple traffic-light system can help.

Green: Generally Low-Risk Use Cases

This could include publicly available information, general brainstorming or neutral text drafts. A prompt such as “Give me ten ideas for a summer party for a company with 40 employees” is very different from entering specific employee data.

Amber: Check First

When internal information is involved, employees should first check whether the relevant AI tool has been approved for that purpose and what internal rules apply. This includes internal processes, projects that have not yet been made public and other information that is not intended for external audiences.

Red: Do Not Enter Without Prior Review

Particular caution is required when it comes to personal data, health and salary information, confidential client information, trade secrets or sensitive business know-how.

A simple rule of thumb is often more useful than complicated policies:

If you wouldn’t readily send the information to an external third party, you shouldn’t copy it into an AI tool without checking first.

Traffic light guide for ChatGPT in the Workplace with green, yellow, and red use cases

HR Needs to Take a Closer Look at ChatGPT

Few areas of a business handle as much sensitive information as HR. CVs, salaries, absences, feedback conversations, performance reviews and personal data are all part of everyday HR work. That is exactly why ChatGPT is both particularly interesting and particularly sensitive for HR teams.

AI can, for example, help create an interview guide, make a job advertisement easier to understand or generate ideas for onboarding. Uploading a complete CV and asking ChatGPT, “Is this person a good candidate for us?”, is an entirely different matter.

At that point, clear boundaries and defined processes become essential.

ChatGPT in Recruitment: Where Support Ends

In recruitment in particular, there is a strong temptation to use AI not only as a support tool but also for pre-selection. After all, it sounds efficient to have large numbers of applications analysed automatically and supposedly suitable candidates filtered out.

But this changes the role of AI: instead of being a practical assistant, it becomes a tool that can influence employment decisions. The European AI Act therefore also distinguishes between AI systems based on how they are used. Certain AI systems designed, for example, to analyse or filter applications or evaluate candidates fall into a particularly regulated category.

For HR teams, this leads to a simple practical guideline:

AI can support HR processes. Employment decisions should remain with people.

ChatGPT can, for example, help develop interview questions or structure a job advertisement. Decisions about who is hired or promoted, or how an employee is assessed, should not simply be delegated to a chatbot.

ChatGPT in the Workplace: HR uses AI to support recruiting processes

An Often Overlooked Factor: The Quality of Information

When people talk about AI, much of the discussion focuses on the tool itself. But what the tool is working with is just as important. Incomplete, outdated or incorrect information does not automatically become better simply because AI is involved.

Especially when AI accesses internal information or supports business processes, it is worth reviewing data quality, responsibilities and existing workflows first. Before using AI to make a process faster, companies should check whether the process itself actually works properly.

Even More Important Since 2026: AI Literacy Belongs on the HR Agenda

Another issue has become particularly relevant for companies: the AI Act.

Companies that use AI systems need to consider the AI literacy of the people who use those systems in a business context. This does not mean that every employee has to become an AI expert, nor does it automatically require an extensive training programme or a dedicated AI department.

Employees should, however, understand which AI systems are used within the company, where typical errors and limitations lie, what information should not be entered, and why AI-generated results need to be reviewed.

The appropriate scope of these measures depends on how AI is actually being used. A marketing team using ChatGPT to generate ideas needs different guardrails from an HR team using AI within recruitment or other HR processes.

AI literacy does not have to be complicated. It needs to fit the company and the way AI is actually being used.

Does Every Company Now Need an AI Policy?

Not every company needs a 30-page “AI Governance Framework”. But once AI is regularly used in day-to-day work, clear rules make sense. A practical policy should answer five key questions:

1. Which tools can be used?
Which AI applications are approved for business use?

2. What data can be entered?
Where are the boundaries when it comes to personal, confidential or business-critical information?

3. What can AI be used for?
Which use cases are permitted, and which are particularly sensitive?

4. Who reviews the results?
Who is responsible for the output that is ultimately used?

5. Who can employees contact if they are unsure?
Depending on the company, this could be HR, IT, data protection or management.

The easier these questions are to answer, the more likely it is that the rules will actually work in everyday practice.

What If Something Goes Wrong?

Even with good rules in place, mistakes can happen. An employee may accidentally copy sensitive information into a prompt, use a tool that has not been approved, or send an AI-generated text without reviewing it first.

In these situations, having a clear internal process helps: Who needs to be informed? Do IT or data protection need to be involved? Can the information that was entered still be deleted? Does the incident require further investigation?

Any legal consequences arising from a specific case should, where necessary, be clarified with the relevant specialist teams or appropriate legal counsel. For HR, the key is to establish clear responsibilities and communication channels in advance so that the company does not have to improvise when something goes wrong.

ChatGPT in the Workplace: 7 Rules SMEs Can Start With

For small and medium-sized businesses, getting started does not have to be complicated:

1. Define approved AI tools.
Employees should know which applications can be used for work.

2. Introduce a simple data traffic-light system.
What can be entered? What needs to be checked first? What should stay out?

3. Start with specific use cases.
Instead of “We are introducing AI”, define a concrete goal such as: “We want to make preparing our onboarding process easier.”

4. Ensure human oversight.
Anyone using AI remains responsible for the result they ultimately use.

5. Take a closer look at HR use cases.
The closer AI gets to decisions involving applicants, employees or performance, the more carefully its use should be reviewed.

6. Equip employees with the right knowledge.
A short training session using examples from the company’s own day-to-day work can be more effective than a lengthy policy.

7. Review AI use and internal rules regularly.
New tools and use cases emerge quickly. Internal guardrails should therefore keep pace with how AI is actually being used.

The 5-Minute Check for Managing Directors

How well prepared is your company when it comes to AI? Five questions provide a useful starting point:

1. Do we know which AI tools our employees are using?

2. Have we defined which of those tools are approved for work?

3. Do our employees know which data they should not enter?

4. Is AI already being used in recruitment, HR processes or decisions involving employees?

5. Have our employees received a clear introduction to the opportunities, risks and limitations of the AI systems they use?

If you answer several of these questions with “No” or “We’re not really sure”, you probably do not need less AI – you need more clarity first.

Conclusion: ChatGPT Isn’t the Problem – Unregulated Use Is

Banning ChatGPT in the workplace simply because mistakes might happen misses the point. AI can relieve employees of routine tasks, make ideas available more quickly and simplify everyday processes. But allowing it to be used without any oversight makes just as little sense.

For start-ups and SMEs in particular, a practical approach often lies somewhere in between: clear rules, suitable tools, defined responsibilities and employees who understand what they can use AI for – and what they should avoid.

There is no need to introduce a complex AI management system straight away. To begin with, it is enough to be able to answer three key questions: What do we allow? Where do we draw the line? And do our employees know about it? Once those points are clear, a great deal has already been achieved.

How Well Prepared Is Your HR Team for AI?

Clear rules for AI do not have to be complicated. What matters is that they fit your HR processes, responsibilities and the way AI is actually used within your company. We support start-ups and SMEs in setting up pragmatic HR structures and processes and embedding them into everyday working practices.

Frequently Asked Questions About ChatGPT in the Workplace

Can Employees Use ChatGPT at Work?

Companies should define which AI tools employees are allowed to use in their day-to-day work and which use cases they are approved for. It is also important to consider what information is being processed and how the results will be used.

What Data Should Employees Not Enter into ChatGPT?

Personal data, health and salary information, confidential client information, trade secrets and other sensitive company knowledge should not be entered into an AI system without prior review.

Do SMEs Need an AI Policy?

A short, practical AI policy is useful once AI is being used regularly. In particular, it should define approved tools, data and use cases, as well as responsibilities and points of contact.

Do Employees Need Training on How to Use AI?

Under the AI Act, companies using AI systems need to consider the AI literacy of the people who use those systems on their behalf. The appropriate measures depend on the specific use case, the employees’ existing knowledge and the risks involved.

Can ChatGPT Be Used in Recruitment?

AI can support recruitment processes by helping with brainstorming, structuring information or preparation. It becomes more sensitive when AI is used to analyse, filter or evaluate applicants. Employment decisions should not simply be delegated to ChatGPT.

What Should Managing Directors Do First When Introducing ChatGPT?

The first step is transparency: Which AI tools are already being used, and for what purposes? From there, companies can define approved tools, rules for handling data, responsibilities and appropriate AI literacy measures.