An empty meeting room in the evening, a blank sheet of paper and a pen on the table, like a memo about to be written

AI banned at work: what to do when your employer says no

"So what am I supposed to do now?" The question comes up the day after the memo. For months, you had been writing your meeting notes, follow-ups and summaries with a consumer AI tool, and saving an hour a day. Management has just banned it, without offering anything in its place. Colleagues are whispering that you can simply use your phone.

This guide answers the questions people ask at that point: what the rule really targets, what you risk by working around it, and how to get a tool your employer can accept.

AI banned at work: what the rule really targets

Why is my employer banning consumer AI tools?

Because it is responsible for data it no longer controls once that data is pasted into an outside service. A client email, a contract or a payroll spreadsheet sent to a consumer AI tool goes to a provider nobody chose, which may keep the history and with which the company has signed no commitment. For personal data, both the GDPR and the Swiss Federal Act on Data Protection (FADP) require knowing where it goes and why. Then there are trade secrets, the confidentiality clauses signed with clients and, for the big American services, the CLOUD Act, which allows the authorities of their country to demand access to the data these companies hold.

In other words, your management is not banning AI out of distrust of the technology: it is banning a data leak it can neither measure nor stop.

Does the ban cover all AI tools, or only some?

Read the exact wording. Some memos name consumer tools specifically, others ban "any AI service not approved by the IT department", others still only forbid sending internal data. The difference matters: in the first case, the door stays open to an approved tool; in the second, nothing can be used until it has been approved, including a confidential tool. If in doubt, ask your manager or the IT department in writing. A written answer protects you.

Can I use AI on my personal phone?

Not for work. The rule is about the company's data, not the device: retyping a client email on your phone to submit it to a consumer AI tool is exactly the same as pasting it from your work computer, with a copy on a personal device thrown in. It is in fact the use management fears most, because it is invisible. On your phone, for your shopping or your holidays, you do as you please; for a work file, the memo applies.

What do you risk by ignoring it?

Disciplinary action, first of all. An IT policy or staff handbook that forms part of your employment terms is binding on employees; in Switzerland, the Code of Obligations places a duty of loyalty on employees and requires them to follow the employer's instructions, confidentiality included. Depending on how sensitive the exposed data is, the sanction can range from a warning to dismissal.

Next, personal liability when a secret is at stake: professional secrecy, medical confidentiality or official secrecy, whose breach is a criminal offence in Switzerland (Swiss Criminal Code Art. 321 and Art. 320) as in many other countries. Finally, trust: a colleague who works around the rule makes it harder to get an approved tool adopted for everyone.

The alternatives when consumer AI is banned

What options are there, in practice?

Three, realistically. Wait for an in-house tool, if the company is preparing one: it is the simplest route, but it can take months. Work without AI on sensitive tasks, and keep the assistant for texts with no internal data at all, if the rule allows it. Propose a confidential tool to your management, designed so that no company data goes to a third party without an explicit decision.

The third route is the one that most often unblocks the situation, because it answers the original objection instead of sidestepping it.

How do you propose a tool to your management?

By answering in advance the questions they will ask: where is the data processed, what is kept and by whom, which law applies, what can go outside and on whose decision. A factual one-page memo is worth more than a sales pitch. AI can even help you write it, from a general description:

Write a one-page memo for my IT department. Context: consumer AI tools have just been banned in our customer service team, which writes around sixty written replies a day. Suggest evaluating a confidential AI tool. Structure: the need in three lines, the risks that led to the ban, the guarantees to require from a tool (where processing happens, retention, sending to third parties), a proposal for a two-week trial using fictitious data. Neutral tone, no sales arguments.

Reread it, adapt it to your company's vocabulary, and send it through the usual channels.

What does a confidential AI change for the company?

It answers those questions one by one. With IA Confidential, the application and the confidential models are hosted in Switzerland, under the Swiss Federal Act on Data Protection, outside the reach of the CLOUD Act. By default, your questions are handled by open models installed on these servers, which pass nothing on to third parties.

Conversations are not kept on our side: the history stays in the browser of the person using it. Even if we were asked for it, we would have nothing to hand over. Your personal profile also stays in your browser; you can view and edit it, and it is never sent to external models.

Your management will probably keep requirements of its own, such as a list of approved tools or a trial beforehand. That is normal, and the decision is theirs.

What if you need a more powerful model?

The tool offers three families of models: local and specialised, both confidential, and external. The choice is made automatically or by hand. External models are never imposed: they are the user's choice, and they always sit behind the Confidentiality filter.

This filter detects sensitive data before anything is sent to an external model. It then offers to answer with a confidential model, your message untouched, to send an anonymised version that you can review and correct, or to send it as it is if you are comfortable with that. The default choice remains the confidential model. In the Privacy panel, you can add your own anonymisation rules: your clients' names, a project code name, an internal reference, anything no detector can guess on its own. If your management accepts the tool but rules out external models entirely, simply stick to the confidential models.

Can you attach company documents?

Yes, if your internal rules allow it. Attachments (text, PDF, Word, images) are read in the browser, and no file is stored on our servers. If a question has to go to an external model, only pseudonymised extracts are sent: names are replaced with markers, then restored in the answer. When a document is still too identifying, the assistant tells you: it is then handled by a confidential model, or only your question is sent.

Pseudonymising is not anonymising: the difference, which matters to your legal department, is explained in our guide anonymisation or pseudonymisation.

What should you do while waiting for the green light?

Follow the memo, and prepare the ground. You can try the tool at home, on an entirely fictitious case, so you know what you are proposing. And many tasks can be done without any internal data: describe the structure of a problem rather than pasting the file, as explained in our list of data you should never paste into AI. For example:

I need to reply to a client who is disputing a maintenance invoice: they believe the work was not covered by their contract, when in fact it was. Suggest a short, courteous and firm reply that restates the principle without quoting a specific clause, and leaves the door open to a phone call. Two versions: one formal, the other warmer.

If your memo bans all AI tools, even for this kind of request, wait for your management's answer.

Can a confidential AI get things wrong?

Yes, like any AI. It can misunderstand an instruction, or invent a reference, a clause or a figure with great confidence. Confidential does not mean accurate: reread every text, check every fact, and never send a reply you would not have signed. What goes out under your name remains your responsibility, and that is also a point to make to your management: the tool assists, it does not decide.

What stays confidential

With a confidential model, your questions, your attachments and the answers are processed on servers located in Switzerland, and nothing is kept on our side: the history stays in your browser.

With an external model, nothing goes out without passing through the Confidentiality filter, and you choose between the anonymised version, pseudonymised extracts or sending the message as it is. Your personal profile is never sent to an external model.

One precaution remains in your hands: since the history is in the browser, anyone who uses the same session on the same computer can read it. On a shared computer, keep a personal session and log out when you leave. And your employer's rules come before any tool, confidential or not.

Further reading

The basic habits are gathered in our guide to using AI at work safely. The plans are described on the plans page.

To try it on a fictitious case before talking to your management: open the chat.