What is the short answer?
For company work, a company-managed account should normally be the default when one is available. A personal account may sit outside the organisation’s agreements, access controls, retention settings, monitoring, and offboarding process.
That does not mean every personal-account use is automatically dangerous. It means “I used the same product we have at work” is not enough information to approve the use.
Isn’t the product the same either way?
The interface may look the same while the protections differ.
A managed account may let the organisation control who has access, configure how information is handled, remove access when someone leaves, and understand which terms apply. A personal account is controlled by the individual and may use different settings or contractual terms.
The practical policy question therefore needs two parts:
- Is this AI product approved?
- Is this account or access method approved for the proposed information and task?
What if the task contains only public information?
Risk may be lower, but the policy can still require a company account. The organisation may need consistent records, approved integrations, intellectual-property safeguards, or a clear separation between personal and work activity.
For a harmless brainstorming task using invented information, some organisations may permit a personal account. Others may prohibit it because the operational boundary becomes too difficult to explain and enforce. That is a policy choice, not something an employee should have to invent during the task.
Why does governance matter here?
The NIST AI Risk Management Framework recommends identifying risks from third-party AI technology and documenting responsibilities, oversight, and the intended context of use. That is difficult when work happens through accounts the organisation cannot govern. See the NIST AI RMF Core.
Security guidance also consistently warns against placing sensitive workplace information into public AI services. CISA’s generative-AI safety guidance advises users to avoid sharing company-confidential information with AI models.
What should the workplace policy say?
Avoid a vague line such as “only use approved AI.” Give employees a route they can follow:
- name approved products and account types;
- explain which information each setup may receive;
- treat an unknown account as unapproved until checked;
- name the person or team that can approve an exception;
- explain whether outputs may be published, sent to customers, or used in decisions;
- require meaningful human review where the output matters.
What if someone has already used a personal account?
The useful first step is not panic. Ask what information was entered, which service and settings were used, whether files were uploaded, and how the output was used. Then follow the organisation’s privacy or security incident route if the facts require it.
A policy works better when it helps people report uncertainty early instead of encouraging them to hide it.
Create a Can I Use AI? workspace to turn approved tools, account rules, information categories, and escalation routes into a short check employees can use before starting the task.
This article provides general operational guidance, not legal or security advice.