Your team is already using AI. The question is whose account.

by Ross Gordon, Founder, Assist IQ

Ask a room of business owners whether their company uses AI and most say "not yet, we're looking at it." Ask whether anyone on their team has pasted something into ChatGPT this month and the room goes quiet.

That gap is the real state of AI adoption in small business. The company has no AI policy, no AI accounts and no AI plan, and meanwhile the quote template, the awkward customer email and the draft contract have all been through somebody's personal free account on a phone.

What that actually exposes

Not what the scary LinkedIn posts say. Pasted data does not get published, does not become searchable, and does not leak to your competitors. Neither OpenAI nor Anthropic states that it sells your data to third parties. If someone is selling you AI governance with those claims, they are selling fear.

The real exposure is duller and more serious: a personal account gives your business no contract with the vendor, no data processing agreement, no admin visibility, no audit trail, and no way to see or delete what was pasted. And on ChatGPT's personal tiers specifically, conversations are used to train future models by default unless that individual remembered to switch it off. You cannot check whether they did. That is not a data breach. It is a governance hole, and it is entirely fixable.

The fix takes about a week

Give the team a sanctioned business-tier account, where neither vendor trains on your data by default and a data processing agreement comes with the contract. Write a one-page policy: company data goes in the company account, nowhere else. Then make the sanctioned route genuinely more useful than the personal one, so the policy enforces itself.

That last part is where most businesses stop, and it is the part we spend our days on. A business account nobody uses protects nothing. An AI employee wired into the actual workflow gets used, because it does the work.

If you want the full picture first, we keep two plain-English guides current: Is AI safe for my business data? and ChatGPT and Claude: free vs business vs enterprise vs API. Both are written from the vendors' own published policies, dated, and free to lift for your own staff policy.

More from the blog

Claude Code for business: what a real deployment involves

Deploying Claude Code across a company is eight decisions, not an install. Here is the deployment decision document we use, the security questions a client will ask you, and what Anthropic assesses before it issues its Claude Code partner badge.

Read more

Claude certification: what Anthropic actually tests

The Claude Certified Associate exam is proctored, closed book and scored out of 1000. The surprise is what it weights most heavily: not writing prompts, but knowing when the answer is wrong and when a human has to check it.

Read more

Start with a free enquiry

Not a discovery call. Not a pitch with a calendar link. Five questions about how your business actually runs, and it costs nothing. Ross reads every enquiry himself and replies within one working day with a straight first answer: what looks worth automating, and what doesn’t.

If it looks like we can genuinely help, the next step is the AI Operations Day: one working day inside the business, followed by a written Opportunity Map. It shows what is hurting, what should stay human, and the best one or two jobs to prove first. That part comes later, and only if it makes sense for you.

Tell us what is slowing you down

Free to ask. No obligation. Ross replies personally within one working day.