Do not ban it. Your team using ChatGPT on personal accounts is handing you free research: they have already located the two or three parts of their job where an AI assistant pays off, and they cared enough to do it on their own time. A ban does not remove that work. It moves it to a phone screen you will never see. The play that actually works at small business scale has three parts and fits inside two weeks: name the two or three workflows people are already running that way, publish a one page rule on what data goes where, and give those exact workflows an owned, approved path inside the business.
Here is the falsifiable version of that position. Ban personal accounts, and ninety days from now you will not be able to name a single workflow your team runs on AI. Run this play, and ninety days from now you can name them, so can the people doing them, and each one has an owner.
A ban does not stop the work, it deletes your evidence
Enforcement requires detection, and you cannot detect a personal account on a personal phone over home internet. That is the whole mechanism. Your IT controls end at the edge of equipment you own, and the tool in question is one browser tab away on a device you do not manage. So the ban does not change behavior. It changes what people tell you about the behavior.
Watch what a ban actually produces. The account manager who used to say "I drafted this with ChatGPT, can you check the second paragraph" now says nothing and sends the draft. The bookkeeper who pasted a formula into a chat window still pastes it, but never asks whether that spreadsheet had customer names in column D. The exact failure mode you are worried about, a client contract pasted into a consumer chat by someone who did not think about it, becomes more likely under a ban, not less, because now it happens with no rule in front of it and no one to ask. You traded a visible risk you could shape for an invisible one you cannot.
There is a second cost that shows up later. The person who figured out how to cut a proposal draft from a morning to twenty minutes has just learned that sharing that discovery gets them in trouble. That knowledge stays in their head, leaves with them when they leave, and never becomes something the business owns.
Step one: name the workflows, with a two week amnesty
Open a two week window where the only question is "what did you use it for last week," and nothing said in that window counts against anyone. Say that out loud, in writing, from the owner. Then ask specifically, because "do you use AI" gets you shrugs and "did you use it to write anything a customer read" gets you answers.
At a small business the answers cluster fast. Rewriting a customer email so it lands right. Turning site visit notes into the first draft of a proposal section. Summarizing a forty message thread before a call. Cleaning up a messy spreadsheet export. Writing a first pass at an SOP nobody ever had time to write. Getting unstuck on a formula. You will hear four or five, and two or three will be doing most of the work.
Write each one down as a verb and an object, not a category. "Draft the follow up email after a site visit" is a workflow. "Email stuff" is not. The name matters because everything downstream, the owner, the rule, the approved path, attaches to a named workflow. Voltage Control's guide to AI change management makes role architecture and phase by phase sequencing the spine of adoption rather than an afterthought, and naming the workflow is what lets you assign a role to it at all.
Then stop at three. The temptation is to catalog everything. Resist it. Three workflows with owners beat fifteen on a list nobody maintains.
Step two: one page on what data goes where
The rule has to fit on one page, use three buckets, and name a person to ask. If it needs a lawyer to read, nobody reads it, and you are back to invisible.
Green goes anywhere, including a personal account: your published service descriptions, generic how-to questions, public job postings, your own writing with no client identifiers in it, anything already on your website. Amber goes only in the approved tool: internal notes that mention a customer by name, draft proposals, meeting transcripts, anything about an active deal. Red never goes into any AI tool without the named owner saying yes first: customer records with personal information, payroll and personnel files, anything covered by a signed confidentiality agreement, credentials and API keys, health information, and anything a client handed you under an NDA.
Give people one sentence they can apply without the page in front of them. Ours is this: if it would be bad on the front page of the local paper with your customer's name attached, it does not go into a chat window we do not control. That sentence does more work than three pages of policy, because it runs in the two seconds before someone hits paste.
Add one line about what happens when someone gets it wrong: they tell the named owner, and nothing else happens the first time. Write that down too. A rule with a punishment attached and no amnesty converts every mistake into a cover up, which is the failure you just spent two weeks climbing out of. McKinsey's guidance on change management in the gen AI age puts employee trust and empowerment at the center of adoption, and a rule people are afraid of does not produce either.
Step three: build the approved path, and make it better than the personal account
Owned means four concrete things. A business account you administer, so access ends when employment ends. A named owner for each of the two or three workflows. The prompts and instructions living somewhere shared instead of in one person's history. And a check step: who reads the output before a customer sees it, on which workflows.
The approved path has to beat the personal account on the day it launches, or people quietly go back and you will not find out for a year. That means same day access, not a request form with a three day queue. It means the same quality of model they were already using on their own, because a downgrade reads as punishment. And it means you are not asking anyone to log in through something that expires every morning.
Then add the thing a personal account can never do. Load your proposal templates, your past scope documents, your service catalog, your actual house style into the approved path. The personal account writes generic; yours writes like your business. That is the moment adoption stops needing a mandate, because the approved tool is now the better tool. Andesphere's guide to AI for professional services SMBs is built around the same distinction, where custom agents pay off against what to avoid, with delivery framed in a four to six week window.
One thing to skip: buying a platform before you have named the workflows. The comparison guides will happily sell you an orchestration layer for two workflows that a shared account and a written check step would cover.
The review that keeps this honest is not surveillance
Put thirty minutes on the calendar each month. The owner of each workflow shows what it produced, what got corrected before it went out, and what surprised them. That is the whole meeting.
Do not build the version of this that reads chat logs and scores people. The instant review looks like monitoring, you have rebuilt the incentive to hide, and you are paying for tooling to recreate the problem you started with. What you want is a standing, boring, safe place to say "this workflow drifted" or "I found a new one."
A ninety day sequence you can actually run
Days 1 to 30: run the amnesty, name the workflows, publish the one page, stand up a business account for one team. Days 31 to 60: take one workflow end to end, saved instructions, named owner, a check step before anything reaches a customer, and measure the time it takes now against what it took before. Days 61 to 90: bring the second and third workflow across, retire the personal account path for those specific ones, and train by role rather than in one all hands session.
On measurement, calibrate for your deployment rather than borrowing anyone's numbers. Suppose, for illustration, the proposal drafting workflow gives back 2.5 hours per week for the two people who do it. That is the figure to test in your own shop over a month, and the one that tells you whether workflow four is worth naming.
What it looks like when it worked
Nobody asks permission to use AI on green items, because the rule answered it. The red list is short, specific, and people can recite two items from it without looking. Two or three workflows have a named owner and a check step. And when someone discovers a fourth use, they bring it to you within a week, because telling you is now the fast path to a better version of it instead of the slow path to a no.
Your team already ran the pilot. They did it on their own accounts, on their own time, and they picked the workflows where it works. The only decision left is whether that pilot belongs to the business or stays on somebody's phone.
