Skip to content

Should you ban ChatGPT?

[PUBLISHED_DATE] 2026.10.08
[READ_TIME] 8 MIN
[AUTHOR_ID] TECH INNOVATION

No. Banning ChatGPT at a bank, credit union, insurer or hospital rarely stops people from using AI. It pushes the use onto personal phones and free accounts, where you can't see it. What works is enterprise accounts your organization manages, a short policy on what data can go in, shutting down personal accounts, and role-based training, in that order.

If your team already uses AI, and it almost certainly does, the question isn't whether to allow it. It's whether customer or patient data is leaving through a channel nobody manages.

What is shadow AI?

It's any use of artificial intelligence your organization hasn't approved. The usual suspects:

  • Free or personal accounts on ChatGPT, Claude, Gemini or similar tools, opened with a personal email or the work one.
  • Browser extensions that read the page you have open to summarize it or draft a reply.
  • AI features inside tools you already use: meeting software that transcribes, CRMs that draft emails, platforms that summarize documents. Many arrive with a routine update and nobody reviews them.

It's not a fringe habit. In Microsoft and LinkedIn's 2024 Work Trend Index, a survey of 31,000 people in 31 countries, 78% of AI users said they bring their own AI tools to work. Closer to home, an ABA survey of 116 bank marketers (March 2026) found that 15% of those using AI still don't have an employer-provided subscription.

Why doesn't banning AI work?

Three practical reasons:

  1. Phones don't use your network. You can block a site on the office network, not on every employee's cellular plan.
  2. One address serves both. With several tools, the personal and business versions live on the same website, so a URL block also stops the approved use.
  3. A ban hides the problem. Someone who needs to summarize an 80-page procedure manual will still do it. They just won't mention it. And you can't govern what you can't see.

What's the real risk for a regulated organization?

There's no single US "AI law" for banks, credit unions or hospitals yet. Existing rules already cover the risk:

Who The rule that applies Why shadow AI touches it
Banks Interagency guidance on third-party relationships (OCC Bulletin 2023-17) A free AI account is a third party nobody vetted, holding data nobody tracked
Credit unions NCUA says it has no AI-specific rules: existing regulations are technology-neutral, and examiners review internal controls and third-party due diligence The same expectations apply to an AI tool as to any vendor
Health organizations HIPAA. An impermissible disclosure of PHI is presumed to be a breach unless a risk assessment shows a low probability of compromise A consumer AI account has no business associate agreement. Anthropic, for one, doesn't offer a BAA on its consumer plans

In remarks published May 1, 2026, Federal Reserve Vice Chair for Supervision Michelle Bowman said the revised model risk guidance doesn't apply to generative AI, which should be governed by other risk management practices. Supervisors look at whether a use case is material, how broadly employees can access it, and whether it directly affects customers. Broad employee access is exactly what shadow AI is.

What should you do instead of a ban?

Five steps, in this order:

  1. Give people enterprise accounts. A platform your organization manages, with a contract, central administration and logs. Never personal accounts, even paid ones. The two we implement at Andes are Claude Enterprise and Gemini in Google Workspace. Anthropic's commercial terms bar it from training models on customer content, and Google says Workspace doesn't use customer data to train models without permission and that Gemini interactions stay within your organization. To vet the vendor itself, see what a bank or hospital should require from a technology partner.
  2. Write a short policy. Which enterprise accounts are approved, that no personal account is ever used for work, which data never goes in, and who approves a new use. One page people read beats 30 pages nobody opens.
  3. Shut down personal accounts. Single sign-on with company credentials, and no personal accounts on the work email. In Claude Enterprise, admins verify the company domain, block new personal accounts on it, and claim existing ones to migrate them into the organization's account. In Google Workspace, admins decide who can use the Gemini app and can turn it off.
  4. Find out what's already in use. An anonymous survey, a review of installed browser extensions, and a list of the AI features your current vendors have turned on. Without an inventory, the policy stays on paper.
  5. Train by role. A teller, a nurse and a marketing coordinator need different examples. Fold AI into the security awareness training you already run; HIPAA's Security Rule, for one, already requires a workforce security awareness and training program.

A quick guide for the policy. All of it happens inside the enterprise account; nothing from the organization goes into a personal account, not even a draft:

Never, not even in the enterprise account Only with approval, in restricted spaces Normal use in the enterprise account
Passwords, credentials and access keys Customer or member data, account numbers, PHI, exam reports, audit findings Internal procedures, vendor contracts, public information, general drafts

What if someone already pasted customer data into a public AI tool?

First, make it safe to report. If the person fears punishment, they'll hide it, and you lose time that matters.

  1. Document what was shared, when, in which tool and from which account.
  2. Delete the conversation and check that tool's terms. On a personal account, deleting doesn't guarantee the provider didn't keep the data.
  3. Bring in compliance, privacy and security to decide whether it's a reportable incident under your rules, from GLBA-driven customer notice to a HIPAA breach assessment.
  4. Fix the cause. It's almost always that the person had no enterprise account for that task. Give them one and close the personal one.

An honest caveat: no set of controls removes the risk entirely. Anyone can photograph a screen. What an enterprise account changes is that the work happens where there's a contract, a log and someone accountable.

How do we handle it at Andes?

Our team builds software with AI under a secure development policy: approved tools only, no customer personal data in prompts, human review and static analysis before every deployment. We work with Claude every day, in our own development and in client projects, and this is how we roll it out for a company. We're also a registered Google Workspace partner: we set who can use Gemini and train the team.

For regulated organizations we run a shadow AI review: which AI tools your staff use without approval, and how secure the apps built with AI outside IT really are. You get the risks and the fixes, with a fixed scope and price.

Do you know which AI tools your organization uses today?

If the answer is "none, I think," it's probably several. Let's talk about your case and start with the inventory.


Sources

  • OCC Bulletin 2023-17, Third-Party Relationships: Interagency Guidance on Risk Management: https://www.occ.gov/news-issuances/bulletins/2023/bulletin-2023-17.html
  • NCUA, Artificial Intelligence (AI): https://ncua.gov/regulation-supervision/regulatory-compliance-resources/artificial-intelligence-ai
  • Federal Reserve, Michelle W. Bowman, Artificial Intelligence in the Financial System (published May 1, 2026): https://www.federalreserve.gov/newsevents/speech/bowman20260501a.htm
  • HHS, Breach Notification Rule: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
  • Anthropic Privacy Center, I need to sign a BAA with Anthropic. What should I do?: https://privacy.claude.com/en/articles/8956058-i-need-to-sign-a-baa-with-anthropic-what-should-i-do
  • Microsoft and LinkedIn, 2024 Work Trend Index: https://news.microsoft.com/source/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/
  • ABA Banking Journal, Bank marketers are all in on AI (June 2026): https://bankingjournal.aba.com/2026/06/bank-marketers-are-all-in-on-ai/
  • Anthropic, Commercial Terms of Service: https://www.anthropic.com/legal/commercial-terms
  • Claude Help Center, Claim and migrate accounts on your domain: https://support.claude.com/en/articles/14625619-claim-and-migrate-accounts-on-your-domain
  • Google Workspace, Generative AI in Google Workspace Privacy Hub: https://knowledge.workspace.google.com/admin/gemini/generative-ai-in-google-workspace-privacy-hub
Direct_Answers

Frequently asked questions

Shadow AI is any use of artificial intelligence your organization has not approved: free ChatGPT, Claude or Gemini accounts, browser extensions, or AI features that switched on inside tools you already use. The risk is that data leaves without a contract, a log or anyone accountable.

No. Staff keep using AI on their phones over cellular data, and with several tools the personal and business versions share the same web address. Blocking mostly makes the use invisible. Enterprise accounts your organization manages, with personal accounts shut down, work better.

No. A personal AI account has no business associate agreement, and removing the name is usually not enough: HIPAA de-identification requires removing 18 identifiers or an expert determination. Work with PHI only in the enterprise account your organization configured for it, and ask your privacy officer first.

An enterprise account your organization manages, such as Claude Enterprise or Gemini in Google Workspace. Never personal accounts, free or paid. With an enterprise account you decide who gets in and which features they use, and, under its commercial terms, the provider doesn't train its models on your content without your permission.

READY FOR THE NEXT DEPLOYMENT?

Start a Technical Consultation