ChatGPT and your client data: why UK SMBs are switching to Microsoft Copilot Chat

Microsoft Copilot AI assistant interface, the safer alternative to ChatGPT for UK SMBs

The most common AI security incident in UK SMBs in 2026 is not a clever attack by a state actor. It is a junior fee-earner pasting a client contract into the free version of ChatGPT to “tidy it up”, and the contents of that contract ending up on a server outside the firm’s control. The risk is widespread, the remedy is well understood, and a credible Microsoft alternative now exists at no extra cost for firms already on Microsoft 365. As a Microsoft Direct Cloud Solution Provider holding the Microsoft Support Service Designation, Lanmark advises 20 to 500-user firms on how to retire consumer AI use safely and move staff onto Microsoft Copilot Chat without losing the productivity benefit. This guide explains the risk, the structural difference between ChatGPT and Microsoft Copilot Chat, and the steps a firm should take in the next four weeks.

The risk most firms have not seen yet

The conversation in most SMBs has moved past “should we allow AI” and onto “what is everyone already using”. The answer, in nearly every case, is ChatGPT on the free tier, signed in with a personal Google or Microsoft account, accessed on a corporate laptop. Staff are not being reckless. They are being useful. They are drafting client emails faster, summarising long documents that previously sat unread, and producing first drafts of reports they would otherwise have written from scratch on a Sunday evening.

The problem is that everything they paste is leaving the firm’s compliance boundary. On consumer ChatGPT, the default position is that prompts and responses can be retained by the provider and used for model training. The user can disable this in settings; most do not. Where the firm has no enterprise account, the firm has no audit log of what was sent, no data residency commitment, no contractual processor relationship, and no ability to delete data on request. For a UK firm subject to UK GDPR, the SRA Code of Conduct, FCA conduct rules, or simple client confidentiality clauses in engagement letters, this is a recurring data processing incident hiding in plain sight.

The ICO’s guidance on AI and data protection is clear that processing personal data through a generative AI service without a lawful basis, appropriate contracts and a risk assessment is unlikely to meet a firm’s UK GDPR obligations. The risk is not theoretical.

Why ChatGPT is the wrong place for confidential SMB work

Three structural issues make consumer ChatGPT the wrong tool for client work.

The first is data residency. Consumer ChatGPT processes prompts on infrastructure that may sit outside the UK and EU, with no commitment about where a specific firm’s prompts are processed. For any regulated UK SMB, that is the first conversation that fails an audit.

The second is the processor relationship. A firm using consumer ChatGPT has accepted a personal terms of service, not a data processing agreement. When the firm’s auditor, regulator or client asks “who is processing this data and under what contract”, there is no answer.

The third is observability. The firm cannot see what staff are sending. Defender for Cloud Apps and similar tooling can flag traffic to chat.openai.com, but it cannot inspect the content of every prompt. The firm is relying on staff judgement, and staff judgement is being applied at speed against a deadline.

The combined picture is a workflow that is genuinely useful for staff and genuinely unmanageable for the firm.

How Microsoft Copilot Chat is structurally different

Microsoft Copilot Chat is the free generative AI chat experience available to any user with a Microsoft Entra ID work account, included with Microsoft 365 Business Standard, Business Premium, and the equivalent enterprise plans at no extra cost. It is structurally different from consumer ChatGPT in four ways.

Prompts and responses are processed inside the Microsoft commercial data boundary. UK data residency is available, and the firm’s tenant boundary applies. Microsoft does not use this data to train its public foundation models.

A signed-in work account ties every interaction to a named user and the firm’s audit logs. Microsoft Purview, Entra ID logs and Defender for Cloud Apps capture who used Copilot Chat, when, and at what scale.

The terms in place are commercial Microsoft terms covering the firm’s tenant, not a consumer agreement. For most SMBs already paying for Microsoft 365, the data processing relationship is already in place.

Copilot Chat will not access internal SharePoint, OneDrive or Teams content by default; that is what the paid Microsoft 365 Copilot Business tier adds. For an SMB whose immediate need is “stop staff using ChatGPT”, the free Copilot Chat is enough to retire the consumer workflow safely. Copilot Business is the next step when the firm wants the AI to reach across its own data.

A practical switch plan for an SMB

The four-week plan that works for most SMBs runs as follows.

Week one is an acceptable-use update. The firm publishes a short, plain-English policy: confidential client and personal data goes into Microsoft Copilot Chat only, never into consumer AI tools. The policy is paired with a single screenshot showing staff where Copilot Chat sits in the Microsoft 365 launcher.

Week two is enablement. Conditional Access policies, browser-side restrictions and DNS-level controls are configured to block consumer ChatGPT, Google Bard and similar services from corporate devices and network segments. Where Microsoft Edge is the standard browser, the Copilot Chat button is pinned. The firm also runs a 45-minute lunchtime training session per team to show three or four day-to-day prompts that work well.

Week three is monitoring. Defender for Cloud Apps and Entra ID logs are reviewed to confirm that traffic to consumer AI services has dropped and that Copilot Chat usage is rising. Where staff have legitimate workflow needs that Copilot Chat does not cover, they are captured and reviewed rather than left to drift back to ChatGPT.

Week four is governance. Sensitivity labels are reviewed across SharePoint and OneDrive, the firm’s incident response runbook is updated to include “AI data exposure” as a category, and a 90-day review is booked to assess whether the firm is ready for Copilot Business as the next step on the AI Capability Ladder.

For data that has already left the firm into consumer ChatGPT, the practical remedy is a written record of the categories of data exposed, a risk assessment, deletion requests to the provider where possible, and a note in the firm’s processing log. The ICO’s expectation is that firms take reasonable steps and document them, not that they undo what has already happened.

Why work with Lanmark on AI safety and adoption

Lanmark holds the Microsoft Support Service Designation, an accreditation awarded to a small number of Microsoft partners worldwide for the highest standards of cloud expertise, and operates as a Microsoft Direct CSP. The combination matters here: the firm gets direct Microsoft support escalation for Copilot Chat issues, partner-channel licensing if and when an upgrade to Copilot Business makes sense, and a single accountable provider for the whole Microsoft stack.

Around the Microsoft platform sits Lanmark’s managed detection and response service, a 24×7 SOC that monitors Microsoft 365 telemetry including AI usage patterns, and Lanmark’s broader cyber security service line. The NCSC guidance on AI security principles is the reference framework that informs every Lanmark engagement.

Every engagement starts with a free AI readiness and Microsoft 365 licence review, delivered as a written report with no obligation to commit. Contact us to book a review and a switch plan before the next ICO inquiry lands on someone you know.

Frequently asked questions

Is the free version of Microsoft Copilot Chat genuinely enterprise-safe?

Yes, when accessed with a Microsoft Entra ID work account on a Microsoft 365 commercial plan. Prompts and responses are processed inside the Microsoft commercial data boundary, are not used to train public foundation models, and are covered by the firm’s existing Microsoft 365 data processing terms. That is the structural difference from consumer ChatGPT on a personal account.

Do we need to pay for Copilot Business to stop staff using ChatGPT?

No. The free Microsoft Copilot Chat is enough to retire the consumer workflow safely. Copilot Business is the next step when the firm wants the AI to read its own SharePoint, OneDrive and Teams content. Many SMBs sequence the move as “switch to free Copilot Chat now, plan Copilot Business over the next six months”.

What about the client data staff have already pasted into ChatGPT?

The right response is a written assessment of the categories of data exposed, a deletion request to OpenAI where the firm or the user has standing to request it, an update to the firm’s processing log, and a note for the next compliance review. The ICO’s expectation is that firms take reasonable steps and document them; it is not that the firm somehow undoes what has happened.

Can we tell, technically, who has been using ChatGPT on their work laptop?

Yes, in most environments. Microsoft Defender for Cloud Apps, Microsoft Entra ID sign-in logs and Edge browser telemetry will identify traffic to chat.openai.com and similar domains. The firm can usually attribute it to named users. Lanmark’s MDR service includes this monitoring as standard.

Will blocking ChatGPT hurt productivity?

Only if there is no alternative pinned in its place. The firms that switch staff to Microsoft Copilot Chat and run a short training session see productivity hold up or rise. The firms that block consumer AI without an alternative see staff find a workaround, usually on a personal device, which is the worst outcome.

Does Lanmark write the firm’s AI acceptable-use policy?

Yes. The free AI readiness review includes a draft acceptable-use policy tailored to the firm’s sector and regulatory profile, a draft staff communication, and a four-week switch plan. The firm reviews and signs off, then Lanmark configures the technical controls.

More Articles