ChatGPT at Work: Privacy Worry vs. Real Usage

Using ChatGPT in the workplace can feel safe—until you realize how privacy perceptions and knowledge gaps shape real usage. New research (N=224) shows many worry, but many misunderstand data handling and often can’t cite GenAI policies.
The finding Privacy worry doesn’t match privacy competence—many employees misjudge what’s safe when using ChatGPT at work.
The driver Organizational GenAI policies and employees’ knowledge of them influence how privacy concerns affect actual usage frequency and use cases.
The takeaway Workplace guidance should focus on concrete prompt-handling rules (e.g., de-identification) because awareness gaps are common.
1st MONTH FREE Basic or Pro • code FREE
Claim Offer

The Short Answer

Employees often feel privacy concerns at work, but the study shows many don’t correctly understand ChatGPT’s data-handling implications—driving real differences in usage. It also finds many workers either lack GenAI policies or aren’t aware of them.

For practitioners, this means you can’t assume “worry” equals safe behavior; training and clear, known policies (especially around de-identification) matter for reducing risky prompt practices and guiding consistent usage.

A key caveat is that the findings are based on a survey sample (N=224), so they reflect reported perceptions and behaviors rather than direct measurement of what was pasted into prompts.

ChatGPT at Work: Privacy Worry vs. Real Usage

Using ChatGPT in a work context can feel low-stakes—until you realize how much sensitive information can end up in the prompt box. New research from the original paper digs into a really practical question: how do people’s privacy perceptions (and their knowledge) actually shape how they use ChatGPT at work? The study is based on a user survey with N = 224 participants across multiple European employment sectors who already use ChatGPT for work tasks.

What makes the findings especially interesting is that they don’t just look at whether people are “privacy concerned.” They also examine whether employees work in organizations with GenAI policies, and whether users are actually proficient about how ChatGPT handles data—at least as far as OpenAI’s stated policies go. Spoiler: many people worry, but fewer people really understand the details. And that mismatch changes usage behavior in measurable ways.

Why This Matters: The Privacy “Mental Model” Gap Is Now a Workplace Risk

This research is significant right now because GenAI adoption at work has moved past the “should we try it?” phase. In many teams, ChatGPT is already used for email drafting, brainstorming, translation, and code help—often as an invisible step in the workflow. That means privacy risk isn’t just an IT problem; it’s becoming a day-to-day behavior problem.

A concrete scenario: imagine an employee in HR or customer support pasting anonymized-but-still-identifiable complaint details into ChatGPT to “speed up responses.” Even if they feel careful, their actual mental model might be wrong—for example, believing that personal data is automatically anonymized (the study found this misconception in 90% of participants). Without good guidance, people can unintentionally create privacy exposure while thinking they’re safe.

This builds on earlier AI research that studied privacy concerns at a general level (often linked to adoption intentions), but it goes further. Instead of stopping at “users are worried,” this work connects privacy perceptions to usage frequency and variety of use cases—and it shows that organizational policies can change how strongly privacy concerns shape behavior. In other words: workplaces can actively steer both privacy competence and real usage patterns, not just compliance paperwork.

What the Study Looked At (And Why Policies Might Change Everything)

The researchers focused on three key factors that shape ChatGPT usage behavior in work:

  1. Organizational policies: Do employees’ workplaces have rules or guidance around GenAI?
    This could include restrictions, training, or awareness measures.
  2. Integrated privacy concerns: How strongly employees feel privacy risk when personal data might be collected, misused, or shared without clear permission.
  3. ChatGPT proficiency: Practical knowledge about how ChatGPT stores/processes data, evaluated using questions based directly on OpenAI’s policies.

The outcomes they measured were:
- Frequency of use (how often participants used ChatGPT at work)
- Use cases (how many different work tasks they used ChatGPT for)

The actual policy reality: half the participants didn’t know

In the sample of N = 224, 54% (n = 121) reported that their organization had no GenAI policies (or they weren’t aware of them). Among the remaining 103 people who did report policies, the most common selected option was de-identification/anonymization of input data (46% of that subgroup). This already hints at a major practical issue: policies exist only if employees know they exist and understand them.

Policy types mattered, but not the way you might expect

When participants had policies, the most frequently selected options included:
- De-identification or anonymization of input data (47)
- Explicit prohibition of including personal information (43)
- Limiting use to documents up to a confidentiality level (41)
- Restricting sharing/external use of generated content (36)
- Restricting use to certain departments/users (33)
- Training/awareness required for authorization (12)

In terms of how people used ChatGPT, the most common work use cases were:
- Language translation & communication assistance (49.6%)
- Brainstorming and idea assistance (141 selections)
- Content polishing (83)
- Email assistance and code assistance (both 74)

A useful analogy: think of ChatGPT usage like driving a car in traffic. Privacy concerns are your “brake sensitivity,” but organizational policies are the “road design.” If road design is missing, drivers rely on personal judgment—which can be inconsistent.

How Proficiency Was Measured (And Why It Came Back Low)

A major strength of the paper is that it doesn’t treat “knowledge” as vague self-confidence. The researchers created a ChatGPT proficiency score from 11 true/false items, plus an “unsure” option treated as incorrect. These questions were sourced from OpenAI’s security and privacy policies, meaning the test was aligned with what OpenAI actually claims.

The proficiency results were blunt:

  • Only 36% of statements were answered correctly on average (SD = 18%).
  • Two standout misconceptions were extremely common:
    • 90% incorrectly believed that their personal information would be anonymized.

      (But the policy mentions aggregation/anonymization possibilities—not a blanket guarantee.)
    • 84% incorrectly assumed OpenAI ensures security of online communication channels.

This is the privacy “mental model” problem the workplace can’t afford. If employees think the system guarantees anonymization or channel security when it doesn’t, they may upload sensitive information with false reassurance.

Importantly, the study also found that having organizational policies was associated with better proficiency—but not fully fixing it. In the paper’s results, policy-linked proficiency was higher, yet still far from “competent for real-world privacy.”

What the Researchers Found About Usage Behavior (Privacy Worry Had a Concrete Impact)

The study’s correlations and path models connect the dots between perceptions and behavior.

Correlation patterns across the whole sample (N = 224)

For the entire cohort, these relationships appeared:

  • Integrated privacy concerns ↘ frequency of use: r = -0.14 (p < .05)
  • Integrated privacy concerns ↘ number of use cases: r = -0.16 (p < .05)
  • Frequency of use ↗ number of use cases: r = 0.42 (p < .01)

So the more privacy-concerned participants were, the less they used ChatGPT, and the fewer kinds of tasks they used it for. That’s consistent with a “self-restriction” pattern: people don’t want to risk privacy loss, so they limit usage and scope.

The bigger question: do policies change the rules of the game?

The path models (a more controlled statistical approach) tested the study’s main research questions. The key findings:

  • RQ1: Organizational policies → ChatGPT proficiency (positive effect)
    The effect was significant: β = 0.15 (p < .05).
    Translation: policies are linked to employees learning more about data handling and privacy implications.

  • RQ2: Policies + privacy concerns + proficiency → usage behavior

    • Organizational policies → more use cases
      β = 0.23 (p < .001)
    • Privacy concerns → less frequency of use and fewer use cases
      • Frequency of use: β = -0.14 (p < .05)
      • Use cases: β = -0.17 (p < .01)
    • ChatGPT proficiency → no significant effect on usage behavior (in organizations overall)

This last point is counterintuitive at first. You’d expect that knowing more would lead to more confident, responsible use. But the study suggests that proficiency alone doesn’t automatically translate into higher usage—especially when privacy concerns are steering behavior.

When Privacy Concerns “Take Over”: The Moderation Effect of Having Policies

The most revealing part of the study is RQ3, where the researchers split participants into two groups:
- organizations with GenAI policies (n = 103)
- organizations without GenAI policies (n = 121)

Comparison: how privacy concerns and proficiency shape usage when policies are absent vs present

Group Integrated privacy concerns → Frequency of use Integrated privacy concerns → Use cases ChatGPT proficiency → Frequency of use ChatGPT proficiency → Use cases
No organizational policies (n=121) β = -0.23 (p < .01) β = -0.26 (p < .01) β = 0.20 (p < .05) β = 0.15 (p < .10)
With organizational policies (n=103) No significant effects observed No significant effects observed No significant effects observed No significant effects observed

What this means in plain terms:
- If there are no policies, employees lean heavily on their own privacy concerns to decide whether and how to use ChatGPT. Privacy worry directly suppresses both how often they use it and what they use it for.
- If there are policies, those personal factors stop being the main drivers—policies provide structure that reduces reliance on individual intuition.

It’s like putting guardrails on a mountain road: when the road is engineered with safety features, drivers don’t have to compensate using “guesswork.”

Do Different Policy Types Actually Lead to Different Outcomes?

For RQ4, the researchers tested whether different policy styles mattered—specifically two categories:
- usage constraints (how employees may use ChatGPT)
- user constraints (who is allowed to use it / authorization requirements)

They found little evidence of strong differences. The one signal was:
- a marginally significant positive effect on the number of use cases when the policy type was a usage constraint.

Otherwise, the existence of policies seemed more important than the exact policy flavor. That implies organizations may not need to over-optimize wording—they mainly need to implement guidance employees actually follow.

Key Takeaways

Key Takeaways

  • Many employees misunderstand ChatGPT privacy basics. In the study, only 36% of ChatGPT proficiency statements were answered correctly on average, and 90% wrongly believed personal information is automatically anonymized.
  • Privacy concerns reduce real usage behavior. Higher integrated privacy concerns were linked to lower frequency of use (r = -0.14) and fewer use cases (r = -0.16) across N = 224 participants.
  • Organizational policies improve proficiency and encourage broader use. Policies were significantly associated with higher ChatGPT proficiency (β = 0.15) and more diverse work use (β = 0.23).
  • Policies change what drives behavior. In organizations without policies, privacy concerns strongly suppressed usage (β = -0.23 for frequency, β = -0.26 for use cases). In organizations with policies, these effects disappeared—suggesting policies reduce reliance on individual privacy judgment.
  • Policy “type” mattered less than policy “presence.” The study found minimal differences between usage constraints vs user constraints on usage behavior.
  • Practical for workplaces today: don’t rely on “privacy worry” alone. Provide targeted training that fixes misconceptions, and pair it with clear, enforceable guidance on what employees can (and can’t) paste into ChatGPT.

If you want, I can also rewrite the “practical recommendations” from the paper into a ready-to-use internal policy checklist (e.g., what to include in training, example do/don’t prompts, and how to structure role-based guidance).

Sources Used

This article is a plain-English breakdown of the following peer-reviewed preprint. Read the original for full methodology and results:

Where To Go Next

Generative AI vs Real Intro OOP Exams: What Improved (2026)

Carbon Cost per ChatGPT Query: The Real Hidden Price in 2026

Real vs “On-Point” Legal Citations: Can AI Check Support?

Browse the free Prompt Database or tune your own prompts with the Prompt Optimizer.

Frequently Asked Questions

Limited Time Offer

Unlock the full power of AI.

Ship better work in less time. No limits, no ads, no roadblocks.

1ST MONTH FREE Basic or Pro Plan
Code: FREE
Full AI Labs access
Unlimited Prompt Builder*
500+ Writing Assistant uses
Unlimited Humanizer
Unlimited private folders
Priority support & early releases
Cancel anytime 10,000+ members
*Fair usage applies on unlimited features to prevent abuse.