ChatGPT at Work: Practical Do's and Don'ts for Your Team
Almost a Year Into ChatGPT: Why Your Team Needs Ground Rules
It has been almost a year since OpenAI released ChatGPT to the public on November 30, 2022, and just three days ago the company held its first DevDay, announcing GPT-4 Turbo and custom "GPTs". Here is the uncomfortable part for Philippine SME owners: somebody on your team is almost certainly using ChatGPT for business work already — customer replies, product descriptions, job ads — and nobody has told them what is off-limits. The question is no longer whether to allow it. It is whether they are doing it safely.
The timing matters: teams are stretched by the ber-month and 11.11 rush, and 2024 IT budgets are being drafted now — the moment to set house rules. Closer to home, the PhilHealth public notice of October 2, 2023 confirmed that the September 22 ransomware attack exposed names, addresses, birth dates and phone numbers — the same records a 15-person company keeps in a shared spreadsheet. We drew the lessons from the PhilHealth ransomware attack last month.
In September we covered the future of artificial intelligence in business and how virtual assistants are changing modern business — the what. This is the how. A chatbot is also only one piece of a larger business process automation picture, not the strategy itself.
Our position in three words: rules, not bans. Samsung banned generative AI — software that produces new text, images or code on demand — outright after a leak this year. But for a 10- to 50-person company, a one-page policy everyone has read beats a ban you cannot enforce on personal phones.
The Do's: Getting Real Value from ChatGPT for Business
Used properly, it saves real hours on the writing chores every small company accumulates.
Do #1 — Use it for first drafts, never final copy
Emails, job postings, product blurbs for the 11.11 listing rush, SOP outlines, meeting recaps — it takes you from blank page to workable draft in seconds. It kills the blank page, not the thinking.
Two limits keep it there. The first is hallucination: the underlying large language model — software trained on huge volumes of text to predict the next word — invents things with total confidence, from a statistic to a law that does not exist. The second is the knowledge cutoff, the date its training data stops: even GPT-4 Turbo, announced at DevDay three days ago, only knows the world up to April 2023. So a human edits everything before it ships, and nobody trusts it on current prices, rules or news.
Do #2 — Know which model your team is actually on
"ChatGPT wrote it" says nothing about quality: two very different products share the name. The free tier runs GPT-3.5, while GPT-4, released on March 14, 2023 — which also accepts images, not just text — is only for paying ChatGPT Plus subscribers.
So if your marketing officer's drafts are sharper than your admin's, the tier may be the explanation. Record which accounts and tiers you use and who pays, and check OpenAI's current pricing before budgeting.
Do #3 — Use business-grade options for anything sensitive
OpenAI launched ChatGPT Enterprise on August 28, 2023, promising it will not train its models on business or usage data, with conversations encrypted in transit and at rest.
For most Philippine SMEs that is overkill today, but the principle stands: consumer and business products make different privacy promises. Match the tool to the sensitivity of the work.
Do #4 — Write the rules down before the habit hardens
An unwritten "use common sense" expectation is not a policy. It is a hope. One page naming what is allowed, what is not, and who settles borderline cases is enough. Write it during this Q4 crunch, because tools adopted under deadline pressure become habits by January.
The Don'ts: ChatGPT Data Privacy Risks That Can Cost You
The ChatGPT data privacy risks that actually hurt SMEs are not exotic — they are ordinary staff pasting ordinary work files into a chat box on a deadline.
Don't #1 — Never paste confidential data into the chat box
The cautionary tale of the year: in April 2023 Samsung employees accidentally shared sensitive internal data with ChatGPT, and by May the company had temporarily banned generative AI tools on its devices. One of the largest tech firms on earth, tripped up by copy-paste.
At SME scale that means your customer list, payroll files, signed contracts, source code and unreleased pricing. The test is simple: if you would not email it to a stranger, do not paste it into a consumer chatbot.
Don't #2 — Don't assume the consumer version is private by default
Read OpenAI's Enterprise pitch again: it promises not to train on business data — a promise that exists because the consumer product makes none. Treat anything typed into free or Plus ChatGPT as having left your control.
The habit that works is anonymizing before prompting: client names become "Client A," amounts become round placeholders, phone numbers and addresses come out. The model does not need the real name to write a good reply.
Don't #3 — Don't forget the Data Privacy Act applies to AI tools too
There is no Philippine AI-specific law today, and there need not be: the Data Privacy Act of 2012 (RA 10173) and the National Privacy Commission already govern how you handle personal data. Feeding a customer's information to a third-party chatbot is a disclosure you answer for.
Look again at what PhilHealth listed — names, addresses, birth dates, phone numbers. The exact fields in your CRM export. If a national insurer can be burned, so can a 15-person company in Biñan. That is the ground our cybersecurity services for Philippine businesses cover: what data you hold and who may move it.
Don't #4 — Don't ship AI output straight to clients
Unreviewed AI text gets facts, prices and tone wrong, and clients can tell — one invented specification in a proposal undoes months of trust. The gate: everything client-facing has a named human owner who approves it. Not "the team" — a person.
A Simple AI Policy for Employees: Six Rules You Can Adopt This Week
Copy this, adjust the names, circulate it. A workable AI policy for employees fits on one page:
- Classify your data. Public, internal, confidential — only public or fully anonymized content goes into consumer AI tools.
- Human review before anything ships. Nothing AI-assisted reaches a client, supplier or the public without a named approver.
- Company-designated accounts only. Decide who gets a paid seat; evaluate a business-grade plan if you handle sensitive data.
- No personal data, ever. Names, addresses, birth dates, contact numbers, IDs, payroll details — none of it goes into a prompt.
- Verify every fact, figure and citation. The model's knowledge stops months in the past, and it invents confidently.
- Review the policy quarterly. DevDay just proved how fast the ground moves: GPT-4 Turbo and custom GPTs were announced on November 6.
Put it in writing, have everyone sign an acknowledgment the way you handle your code of conduct, and name one person as the AI point of contact.
Free, Plus, or Enterprise: Which ChatGPT for Business Makes Sense Right Now?
| Tier | Model | Best for |
|---|---|---|
| Free | GPT-3.5 | Brainstorming and generic drafting, anonymized inputs |
| Plus (paid) | GPT-4, since March 14, 2023 | Staff whose output quality matters: marketing, proposals |
| Enterprise (since August 28, 2023) | Business-grade | Teams needing the no-training promise and encryption |
We are not printing prices: they change, and they are billed in dollars. Check OpenAI's current pricing before committing a budget line.
GPT-4 Turbo and custom "GPTs" were announced at DevDay on November 6 and are rolling out — not settled ground your policy can assume. ChatGPT is not the only option either — Google Bard, Bing Chat, Microsoft 365 Copilot, Anthropic's Claude 2 and GitHub Copilot are all in the mix, and every rule above applies to them.
Start Small: Your Team's First Month with ChatGPT
Do not roll this out company-wide. Pick one team — customer service or marketing is easiest — and run a 30-day pilot under the six rules, tracking one number: hours saved on drafting. By month's end you will know whether to buy paid seats, and for whom.
Almost a year in, ChatGPT is no longer a novelty, and pretending your staff are not using it is not a strategy. Treat it like any other business tool: give it an owner, a policy and a review date.
If you want help drawing the line between what an AI chatbot should touch and what needs purpose-built systems with proper security, book a free call with us. You will walk out with a working AI usage policy and a shortlist of what to automate first.