Can I put official or unpublished information into public tools like ChatGPT?

Contrasting

Do not put unpublished official information into public AI tools. Follow department policy. Free/public services may reuse what you submit; paid enterprise tools with DPAs may handle sensitive data — but that is not a green light for public ChatGPT-style tools. Prefer departmental systems and never put personal/identifiable content into unsuitable tools.

Warning Conflicting or tensioned advice across sources

Playbook bans unpublished official info in public AI apps. Insights emphasises org policy and provider reuse. Knowledge Hub how-tos say follow department policy, avoid personal/identifiable content, and note that paid enterprise tools with DPAs can often handle sensitive information — creating scope tension across public vs assured tools.

How to navigate this: Playbook ban for public/unassured tools; department guidance for assured enterprise tools; do not conflate the two.

From the guidance

Primary (how) AI Knowledge Hub: Using AI ethically and sustainably

Use systems provided by your department for government work, and do not include any content with personal or identifiable information.

Contrasting AI Playbook for the UK Government

Position: Must not enter official information into public AI applications unless published or cleared for publication.

When using public AI applications, you must not enter official information unless it has been published or is cleared for publication.

Section: Public AI applications and web services

Read this in AI Playbook for the UK Government (opens in new tab)

Contrasting AI Insights: Generative AI

Position: Act in line with organisation policies; information provided to free services may be used by the provider.

you must make sure you’re acting in line with the policies of your organisation … while the use of these services may be free of charge, you should be aware that any information provided to these services may be used by the provider

Section: Public generative AI applications and web endpoints

Read this in AI Insights: Generative AI (opens in new tab)

Contrasting AI Knowledge Hub: Using AI at work

Position: Paid enterprise tools with DPAs can often handle personal and sensitive information safely — check departmental guidance.

paid versions of tools (such as, Copilot Enterprise, or Gemini Pro) have data protection agreements. This means they can often handle personal and sensitive information safely. Check your department's guidance to understand what each tool can handle.

Related questions