That client brief you just dropped into ChatGPT already counts
You paste the notes, get a cleaner draft, hit send. Four minutes. Under the EU AI Act that professional use can make your whole team a deployer – especially when the output touches people in the EU. No hiring model. No credit scorer. Just ordinary generative tools and the quiet data paths they open.
Worst-case fines hit €35 million or 7% of worldwide turnover for prohibited practices (Art. 99 enforcement overview). Most small-team misses sit lower, but missing inventories and skipped disclosures still create real exposure. GDPR sits underneath any prompt that carries personal data. You need lightweight evidence of control, not a compliance department.
Free-tier training is the hole teams discover too late
Consumer ChatGPT (Free, Plus, Pro) may train on inputs by default. Turn off “Improve the model for everyone” under Settings → Data Controls or the chats can feed the model. Business, Enterprise, Edu, and API default to no training. Paste customer PII or internal code into a personal free account and you have created an untracked transfer with no DPA and no audit line.
OpenAI’s Data Controls FAQ (as of 2026) draws that line clearly. Paid workspace plans flip the default and give you admin visibility. That single switch matters more for beginners than any Annex III checklist.
Call it a spice rack, not a vault. You do not need every jar certified for a Michelin audit. You do need to know what is on the shelf before someone asks. Inventory first; paperwork later.
Five moves that fit a real week
Skip the 40-page policy. Do these in order.
- 30-minute inventory. List every AI surface people actually open: ChatGPT (personal or team), Copilot, Claude, Gemini, Notion AI, browser extensions, CRM side panels. Ask three people in different roles what they used last week. Shadow AI loves personal logins.
- Flag what goes in. Customer PII? Employee data? Confidential IP? Source code? If yes, check the vendor training default and whether a real DPA exists.
- Rough risk bucket. Prohibited (manipulative or social-scoring uses – stop). High-risk style (employment, education, essential services). Limited (customer-facing bots that need disclosure). Minimal (internal brainstorming). Most daily drafting lands limited or minimal.
- One-page acceptable-use note. Approved tools and tiers. Never-paste list (passwords, full customer records, unredacted contracts). Human review required for external content. Who to ping when unsure. Literacy is already required; this doubles as the aid.
- Easy technical controls. Prefer business tiers for anything sensitive. Add one plain disclosure line on customer-facing AI output. Keep the inventory spreadsheet with owner and last-reviewed date – that file is your first evidence artifact.
Shadow AI does not care about your SSO dashboard
SSO logs miss browser extensions, personal email logins, and phone apps. Inventory built only from corporate IdP data is incomplete, which means no reliable trail when a regulator or customer asks who used what. Pair any tech scan with a short anonymous survey. Turns out the gaps are usually human, not architectural.
“We only use it for drafts” is not a shield. Professional context plus outputs that affect people in the EU is enough. A marketing mail drafted with AI and sent to EU customers can trigger transparency duties that started 2 August 2026 (Art. 50).
GDPR and the AI Act often hit the same chatbot. Art. 50 wants AI-interaction disclosure and synthetic-content labels; GDPR Arts. 13-14 and 22 still care about personal data and automated decisions. Write one combined notice instead of two separate homework piles. Most single-framework guides never connect those two.
Would your current shared drive survive a calm “show me every AI tool and its data path” request next Monday? If the answer is a shrug, the work is still inventory – not ISO language.
Frameworks without the sales pitch
NIST AI RMF 1.0 (Govern, Map, Measure, Manage) plus the July 2024 Generative AI Profile is free and enough for pure internal productivity tools with no personal data and no consequential decisions. Start there. NIST’s AI RMF page is the practical entry.
ISO/IEC 42001:2023 adds certifiable structure. Useful once enterprise buyers put it in an RFP or you build higher-risk systems. Costly and heavy on day one for a 20-person team.
The EU AI Act is not optional if you have an EU nexus. Official implementation timeline: literacy and prohibitions from 2 Feb 2025, GPAI duties from 2 Aug 2025, transparency Art. 50 from 2 Aug 2026, many stand-alone high-risk Annex III duties deferred by the Digital Omnibus to 2 Dec 2027 (embedded Annex I to 2 Aug 2028). Map inventory and literacy first, then transparency only where outputs actually face people. That order stops you overbuilding.
| Framework | Type | Best first move for beginners |
|---|---|---|
| EU AI Act | Binding (phased) | Inventory + literacy + disclosures where public |
| NIST AI RMF | Voluntary | Govern + Map current tools |
| ISO 42001 | Certifiable | After customers ask or risk rises |
Later, when the basics stick: a tighter acceptable-use policy, vendor DPA checks for generative tools, prompt hygiene that also cuts leakage.
FAQ
Does using free ChatGPT at work put us under the EU AI Act?
Yes – if the use is professional and you or the outputs have an EU link. Purely personal non-work use by one individual is exempt.
What’s the fastest way to stop free ChatGPT from training on our data?
Every user: Settings → Data Controls → switch off “Improve the model for everyone”. New chats stop feeding training. One debugging dump of customer notes into a personal Plus account is enough to burn the week; move the team to a business plan when sensitive work is routine so the default and the admin logs sit on your side.
Do we really need ISO 42001 certification as a 20-person company?
Almost never on day one. People hear “AI management system” and assume a certificate is the entry ticket. It is not. NIST gives the risk language free. Deployer duties for limited-risk generative use are mostly inventory, literacy, and disclosure. Certification starts to pay when a large buyer writes it into the RFP or when you yourselves ship higher-risk systems. Plenty of teams stay NIST-only for years and still clear basic customer reviews.
Open the AI tool your team used most this week. Check the training toggle. Drop every AI app anyone touched in the last month into one shared doc with an owner name. That beats another unread policy.