HIPAA Compliance Checklist for 2025
In May 2023, Samsung banned ChatGPT and other generative AI tools on company devices after engineers pasted internal source code into the chatbot. Three years later, it approved ChatGPT, Gemini and Claude across the group, after a pilot and mandatory AI training.
The company that made the ChatGPT ban famous now governs the tools instead. That shift is the lesson: blocking ChatGPT was never the same as controlling ChatGPT risk. A domain block stops employees opening chatgpt.com on the corporate network; it doesn't stop a phone, a personal account or a third-party wrapper.
The controls that work sit on the account, the data and the access path. Here are seven of them.
Why Doesn't Blocking ChatGPT Reduce the Risk?
A ChatGPT block is a network control. The risk it targets is a data governance problem, and three gaps follow from that.
- The block targets a URL; the risk lives in the account. The same website serves a free personal account, an employee-paid Plus subscription and an Enterprise workspace, each with a different security posture. The real question is which ChatGPT account receives the company's data, and a domain block can't tell.
- Workarounds move usage out of sight. In Blind threads about corporate blocks, employees suggest switching to a phone, using an extension that reaches ChatGPT through another backend, or turning on DNS over HTTPS. Each route sits outside the proxy, DLP or endpoint controls the block relied on.
- ChatGPT no longer lives at one URL. Employees reach it through desktop and mobile apps, browser extensions, connectors and Apple Intelligence on iOS and macOS. The ways in grow faster than a blocklist can follow.

Where Does ChatGPT Data Exposure Actually Come From?
AI risk lists bundle hallucinations, prompt injection, training and leakage together; our breakdown of ChatGPT enterprise security covers the full register. The urgent problem is narrower: sensitive data entering accounts the organisation can't govern. Harmonic Security's analysis of 22 million enterprise AI prompts found ChatGPT accounted for 71.2% of sensitive data exposure across 665 AI tools.
Four patterns drive most of it:
- Personal accounts. Cyberhaven's 2026 AI Adoption & Risk Report found 32.3% of ChatGPT usage ran through personal accounts, often because they let employees bypass token limits on company plans.
- Copy-paste. LayerX found 77% of AI users paste data into prompts, and 22% of those pastes contain personal or payment card data. File-based DLP rarely sees a browser text box.
- New features. OpenAI removed a sharing option in August 2025 after shared conversations appeared in Google results. Memory, connectors and custom GPTs can open new data paths without any deployment on your side.
- Stolen credentials. Group-IB found more than 225,000 infostealer logs containing ChatGPT credentials. For a personal account, the company controls neither the password nor the history.

Our take: the biggest ChatGPT problem is whether you can govern the account, data and access path your data enters, not what the model does with it.
7 Best Practices to Reduce ChatGPT Risk Without a Ban
The alternative to a blanket block isn't "let everyone use ChatGPT." It's putting controls closer to the account, data and action that create the risk.
1. Find Every ChatGPT Account
Build the inventory before enforcing anything. Look for:
- Enterprise seats and Business subscriptions
- Plus subscriptions paid with company cards
- personal accounts used on managed devices
- browser extensions, connectors and API keys
SSO shows sanctioned users only. Finance, browser, endpoint and network signals fill in the rest.
2. Make the Approved Workspace Worth Using
MIT's State of AI in Business 2025 research found only 40% of companies had bought an official LLM subscription, while workers at more than 90% used personal AI tools. If the approved workspace lacks a model or feature people need, a policy won't remove the demand; the shadow AI economy is a signal of what the sanctioned stack is missing.
3. Write a Policy That Answers Three Questions
- Which accounts are allowed: company workspaces, personal accounts, logged-out sessions, unmanaged devices?
- Which data classes are allowed, allowed with a warning, redacted or blocked?
- Which features are approved: connectors, custom GPTs, actions, API keys and agents, each with an owner and a revocation process?
Every line should map to a control and an evidence trail. If you can't say where a rule is enforced, it's still a document.
New to this? Start with what AI policy enforcement is.

4. Restrict Personal Accounts on Managed Devices
OpenAI's Corporate Network Controls let Enterprise customers restrict access to their own workspace IDs, and Apple MDM can limit the built-in ChatGPT extension to your workspace. That allows the approved workspace instead of allowing or blocking ChatGPT outright. It only covers managed devices, which is why the next control sits on the data.
5. Inspect the Prompt When the Paste Happens
Browser-level controls can check a prompt before it reaches an AI service. Match the response to the risk: warn on lower-risk data, redact the sensitive field to keep the workflow moving, and block only restricted information. Graduated responses are harder to route around than a flat no.

6. Treat Connectors, GPTs and API Keys as Identities
A ChatGPT connector to Google Drive is an access path into company data, and so is a custom GPT with an action or an API key in a script. Give each an owner, a defined scope, monitoring and a revocation step in the same offboarding workflow used for employees.
7. Test the Control, Not Just the Policy
IBM's 2025 Cost of a Data Breach report found one in five organisations had a breach tied to shadow AI, adding about $670,000 to costs where shadow AI use was high. Only 34% of organisations with an AI governance policy audited regularly for unsanctioned AI.
The test is simple. Paste a synthetic customer record into a personal ChatGPT account from a managed laptop. If nothing detects it, the policy isn't working yet.
When Is Blocking ChatGPT Still Useful?
Narrow blocks still work when you know exactly what you're protecting:
- personal ChatGPT workspaces or logged-out use on managed devices
- specific sensitive data classes, such as code, legal documents, financials and M&A material
- unmanaged devices reaching regulated systems
- unapproved AI apps with no legitimate business use
Block the risky path, not the whole category of AI use.
How Does CloudEagle.ai Enforce ChatGPT Policies Across Accounts?
ChatGPT's admin controls govern your own workspace. They don't show the Plus subscription an employee pays for, the personal account on a contractor's laptop, or an API key still active after someone leaves. CloudEagle.ai closes that gap in four ways.
- Discovery: CloudEagle.ai correlates SSO, finance and card spend, firewall and endpoint logs, and its browser plugin with EagleIQ, its AI application inventory, so sanctioned seats appear next to personal and expensed accounts.
- Enforcement at the paste: AI policy enforcement monitors or blocks sensitive content and detects PII sent to AI vendors. Unsanctioned tools redirect users to the approved one, so the work still gets done.
- AI identities: non-human identity management tracks service accounts, API keys and AI agents across Okta, Entra and connected apps, with owners, permissions and revocation for orphaned credentials.
- Offboarding: zero-touch offboarding removes ChatGPT seats with evidence for the audit trail, and usage data flags inactive seats to reclaim.
In 2023 the question was how to stop employees using ChatGPT. In 2026 it's how to govern the ChatGPT use you can't eliminate.
Book a demo to see every ChatGPT account in your environment in 30 minutes.
Frequently Asked Questions About ChatGPT Risks
Should Companies Ban ChatGPT?
A blanket ban misses personal devices, personal accounts and third-party apps. A targeted model allows approved use while controlling accounts, sensitive data, connectors and other access paths.
Does ChatGPT Train on Company Data?
Not by default on Business, Enterprise or Edu workspaces. Consumer accounts can use conversations to improve models unless the user turns that setting off.
Can Companies Block Personal ChatGPT Accounts but Allow ChatGPT Enterprise?
Yes, on managed devices. Corporate Network Controls restrict access to your workspace IDs, and Apple MDM can restrict the ChatGPT extension. Unmanaged devices need data-level controls.
How Can Companies Monitor ChatGPT Usage?
Don't rely on SSO alone. Combine identity, finance, browser, endpoint and network data with an AI application inventory, then use prompt-level controls to stop sensitive data reaching unsanctioned tools.




.avif)




.avif)
.avif)




.png)




.avif)
.avif)
.avif)

