ChatGPT & Copilot at Work: Banned from August 2026?
"I read that the AI Act goes live in August – do we have to switch off ChatGPT now?" This question comes up in almost every first conversation at the moment. Usually there is a headline behind it suggesting that from 2 August 2026 AI use will be strictly regulated or even banned. The uncertainty is understandable – but the answer is far more relaxed than the panic headlines imply.
The short answer: no, it is not banned
ChatGPT, Microsoft Copilot, Claude, Gemini and co. are not banned by the EU AI Act – neither today nor from August 2026. The AI Act regulates AI by risk, and everyday generative tools do not fall into the prohibited category for typical office work. Only a few narrowly defined practices are prohibited – social scoring, manipulative systems, emotion recognition in the workplace – none of which applies to summarising an email or drafting a quote.
What changes are two manageable duties. And the real hurdle is a different one anyway – it existed before, and it is called the GDPR. One step at a time.
Why the fear of a ban? What actually happens on 2 August 2026
For a long time, 2 August 2026 sat in calendars as the date the AI Act would "really bite" – including the strict obligations for high-risk AI. That is exactly where the worry comes from. Except: that heavy part has been postponed. With the Digital Omnibus adopted in June 2026, the high-risk obligations for stand-alone systems (Annex III) move to 2 December 2027, and for systems embedded in products (Annex I) to 2 August 2028.
For the vast majority of SMEs this is not the crux anyway: you are usually not a provider of high-risk AI, but a deployer of standard tools. The heaviest obligations therefore do not fall on you at all. What genuinely applies to you on 2 August 2026 is manageable – and that is exactly what we will look at now. You will find the full timeline in the guide to the EU AI Act for SMEs.
The two duties that really concern you
1. Transparency (Art. 50) – from 2 August 2026
Anyone deploying AI that people interact with must disclose that it is AI. In practice this means:
- A chatbot on your website? A visible notice that an AI is answering here is usually enough.
- AI-generated or edited content, in particular realistic images, audio or video ("deepfakes"), must be labelled as such.
For most companies this is done with a few clear notices – not a major project, but a point worth actively ticking off.
2. AI literacy (Art. 4) – already in force since February 2025
Companies that use AI systems must ensure their staff have a sufficient level of AI competence. No mandatory certificate, no exam – but a traceable minimum of training: what may the tools in use do, where are their limits, which data must not go into them? A short, documented internal briefing satisfies Art. 4 and at the same time prevents the most common privacy mishaps. What such a training looks like, and why it beats the annual mandatory PDF, is covered in the article on shadow AI in the company.
That was the AI Act part. It is, frankly, the easier one.
The real crux is not the AI Act – it is the GDPR
The decisive question with any AI tool is not "is it allowed?" but: where does my data flow? As soon as personal data – customer names, applications, contracts – ends up in an AI tool, that is a data processing operation that needs a legal basis, a data processing agreement (DPA) and control over the data location. This applies regardless of the AI Act and applied long before it.
And this is precisely where the distinction that many companies get wrong sits – it is not the price of an account that decides, but the contract type:
- Consumer account (ChatGPT Free/Plus/Pro, Claude Free/Pro/Max, the free Copilot): inputs are used for model training by default, and there is no DPA. Even the paid consumer plan is no free pass here – you pay with money and with data.
- Business contract (ChatGPT Team/Enterprise, Claude for Work/Enterprise, Microsoft 365 Copilot): training on your data is contractually excluded, a DPA under Art. 28 GDPR is in place, and processing is controlled.
The rule of thumb for your workforce is therefore not "paid = safe", but: consumer account = potential training data. Business contract with a DPA = controlled processing. The full framework around this – data location, third-country transfer, DPF – is covered in the guide to GDPR-compliant AI for companies.
So: may we use ChatGPT & Copilot? Yes – if these points are in place
The practical permission does not hang on the AI Act, but on your implementation. This checklist gets you into a clean state:
- Business contract instead of consumer account. The approved AI access runs via a commercial plan with training exclusion and a DPA – not via private logins.
- No sensitive data in consumer tools. Personal data, trade secrets and code never belong in a private free account.
- Label chatbots & AI content. Implement the transparency duty under Art. 50 by August 2026.
- Document a short AI training. Satisfies Art. 4 and lowers the mishap risk.
- A policy that fits on one page. Which tools are green (approved), yellow (only without sensitive data), red (off-limits)? And who do you turn to for a new tool – with a response time of days, not months?
- Where it gets sensitive: think local. For confidential data, a self-hosted or EU solution is the calmest path – then the crown jewels never leave the building in the first place. Why local AI is often the more sovereign answer here is set out in the article on local AI vs. cloud dependency.
The sweet spot for many SMEs is the combination: cloud AI with a company contract for the everyday, local AI for the confidential.
Copilot, ChatGPT, Claude, Gemini – briefly and honestly assessed
A "business contract" is half the battle, not the whole of it. With the major providers, a closer look pays off:
Microsoft 365 Copilot is the obvious path for many because it is integrated into Microsoft 365. On the commercial plans, prompts, responses and Graph data are not used to train the foundation models, the EU Data Boundary applies, and the Data Protection Addendum serves as the DPA. Two things you should actively check in 2026, though: since April 2026, a "Flex Routing" is on by default for newly created tenants, allowing EU data to be processed outside the EU during peak demand. And since early 2026 Microsoft uses Anthropic as a subprocessor for certain Copilot features – that processing lies explicitly outside the EU Data Boundary, and the corresponding toggle is often pre-set for newer EU tenants. Both settings belong reviewed in your admin console. The biggest practical stumbling block, however, remains a different one: Copilot shows every user everything they have access to – existing misconfigured shares in SharePoint suddenly become visible. Permission hygiene is mandatory here.
ChatGPT is business-ready in the Team and Enterprise variants: no training on your inputs, EU data residency available, standard contractual clauses as a fallback. Free, Plus and Pro, by contrast, are consumer products with opt-out mechanics – unsuitable for company data.
Claude draws the same line: for Work, Enterprise and the API are subject to the Commercial Terms and excluded from training; the consumer plans (Free, Pro, Max) train by default unless you object.
Gemini is usable via Google Workspace with enterprise commitments; here too the free consumer Gemini is a different world from the licensed Workspace deployment.
The pattern is the same everywhere: the name of the tool decides little, the contract and the configuration decide almost everything.
Conclusion: the AI Act is not a ban, but a reason to set it up properly
You do not have to switch off ChatGPT and Copilot because of the AI Act. But you should use the occasion to set up your AI use cleanly for once: approved tools via business contracts, a clear line between consumer and commercial, a bit of transparency under Art. 50, a short training under Art. 4 – and, for the confidential, a solution where the data stays in-house. Those who sort this now will have the August deadline comfortably under control and will not have to retrofit hectically later.
Note: This article provides professional orientation but does not replace individual legal advice. For a binding assessment of your specific case, please consult qualified legal counsel.
Frequently asked questions
Is ChatGPT banned at work from August 2026? No. The EU AI Act does not ban everyday generative tools such as ChatGPT, Microsoft Copilot, Claude or Gemini. Only a few clearly defined practices are prohibited (e.g. social scoring or emotion recognition in the workplace). For normal use, two manageable duties change from 2 August 2026: transparency (Art. 50) and AI literacy (Art. 4, in force since February 2025).
Can I use Microsoft Copilot at work in a GDPR-compliant way? Yes – with Microsoft 365 Copilot (Business or Enterprise), a Data Protection Addendum as your DPA and the EU Data Boundary enabled. The free consumer Copilot is not suitable for this. Important in 2026: check the "Flex Routing" setting (processing outside the EU during peak demand, on by default for new tenants) and the Anthropic subprocessor toggle in your tenant.
What do I concretely have to do for ChatGPT & co. because of the AI Act? Two things. First, transparency under Art. 50 – disclose when people interact with AI (e.g. a website chatbot) and when content is AI-generated. This applies from 2 August 2026. Second, AI literacy under Art. 4 – a short, documented training for your staff. That has applied since 2 February 2025.
Consumer account or business contract – what is the difference? It is the contract type, not the price. Consumer accounts (ChatGPT Free/Plus/Pro, Claude Free/Pro/Max, Copilot for personal accounts) use inputs for training by default and offer no DPA. Only the commercial contracts (ChatGPT Team/Enterprise, Claude for Work/Enterprise, Microsoft 365 Copilot) exclude training contractually and provide a data processing agreement.
Should I just ban ChatGPT at work? Usually no. An outright ban only pushes usage onto private devices where you have no visibility at all. What works better is an official, usable path (a business contract or a local solution) plus a clear one-page policy.
Do you want to use AI at work without losing control over your data? The Sovereignty Check creates clarity within a week: which AI tools are in use at your company, where data flows out today, what falls under the EU AI Act – and which path (business contract, EU hosting or a local solution) fits your protection needs. → Request a no-obligation initial call now