AI AI at work: policies, tools and what to watch
Can my employer see what I type into ChatGPT or Copilot?
Work account or personal, work laptop or your own phone: what your employer can see of your AI chats, from Copilot's mailbox copy to paste blocking in ChatGPT.
The short answer
- On a work account, yes: Microsoft stores Copilot prompts and responses in a hidden folder of your work mailbox, where compliance staff can search, hold and export them with eDiscovery.
- Deleting a Copilot chat does not delete the compliance copy, which stays searchable until the employer's retention period ends, and a legal hold stops deletion entirely.
- ChatGPT Enterprise and Claude Enterprise can be connected to the same Microsoft compliance tools, so a work login to any enterprise assistant puts you in the same position.
- On a personal account your employer cannot read your history at the provider, but on a work laptop it can log AI site visits, block pasting card numbers into ChatGPT, and in Edge capture the prompts themselves.
- On your own phone the office network typically sees only the name of the site, and at home on your own device your employer sees nothing.
- None of this is switched on by default for every employer, and the UK regulator says covert monitoring is unlikely to be justified in usual circumstances.
On a work account, yes, and by design. When you use Microsoft 365 Copilot signed in with your work login, Microsoft says your prompts and Copilot's responses are stored in your own work mailbox, where your employer's compliance team can search them, export them and keep them after you delete the chat. ChatGPT Enterprise and Claude Enterprise can be connected to the same Microsoft tooling. On a personal account the picture changes: your employer cannot open your chat history at OpenAI or Google, but on a work laptop it can see that you visited an AI site, warn you or block you when you paste something sensitive such as a card number, and, if it has set this up in the Edge browser, capture the prompts you type. Which of those applies depends on the account you sign in with and the device you type on. The app does not decide it.
Account and device decide it, not the app
Search this question and you find two confident answers: your employer can see everything, or the AI company keeps your chats private. Both are accurate, about different situations. A provider's privacy policy describes what the provider does with your text. It cannot describe software your employer has installed on the laptop you typed on, or the copy your employer keeps of work account conversations in its own systems.
The table below uses Microsoft Purview, the compliance suite that comes with Microsoft 365, because Microsoft documents in detail what it can capture. Every "yes" is something the employer can switch on, not something guaranteed to be running.
| Your setup | That you used it | What you pasted | The full conversation |
|---|---|---|---|
| Work account on a work device | Yes, logged automatically where auditing is on | Yes | Yes, stored in your work mailbox and searchable |
| Personal account on a work device | Yes, if the device is onboarded and AI site detection is on | Sensitive items can be detected, warned about or blocked | Not your history at the provider. Prompts and responses typed in Edge can be captured if a content capture policy is set |
| Personal account, your own device, work wifi | Usually the name of the site, like any site you visit | No, the connection is encrypted | No |
| Personal account at home on your own device | No | No | No |
Two edge cases move you between rows. A work account follows you: open Copilot Chat on your own phone signed in with your work login and the conversation still lands in your work mailbox, so the first row applies. And if you have enrolled your own laptop in your employer's device management or installed its security agent, treat it as a work device, because that is what the onboarding step does.
On a work account, your prompts are kept like email
Copilot interactions are recorded in the audit log automatically as part of Microsoft's standard auditing, with no extra setup once auditing is enabled. Each record says which user interacted with Copilot, when, in which app (Word, Outlook, Teams, the Copilot Chat page and so on), and which files, emails or sites Copilot opened to answer.
The words themselves sit somewhere else. Microsoft says data from these messages is stored in a hidden folder in the mailbox of the user who runs the AI app. Neither you nor administrators are meant to browse it. It exists so compliance staff can search it with eDiscovery, the tool used to collect email for legal cases, then hold or export the results. In the compliance dashboard, the prompts and responses themselves are shown only to people in a specific viewer role,, so your manager is not reading your Copilot chats on a whim. But the text is retrievable.
This is the main way a work account differs from the consumer picture in what an assistant keeps about you. Your visible chat history and the copy your employer retains are separate stores, and clearing one does nothing to the other. The general rules for what deleting an AI chat actually removes describe your side. On a work account, the retention policy your employer sets decides the other side.
ChatGPT Enterprise and Claude Enterprise
Microsoft lists ChatGPT Enterprise and Anthropic Claude (Enterprise) among the "enterprise AI apps" its compliance tools can manage. For ChatGPT Enterprise, Microsoft's page sets out what that means once connected: the employer runs a connector scan, turns on a policy to capture prompts and responses, and can then audit them, run them through conduct monitoring, retain them, and search and export them with eDiscovery. These connections need setup and pay as you go billing, so an enterprise workspace is not automatically linked to the company's Microsoft tools. But the capability exists.
Signing in to the company's workspace puts you in the first row of the table, whichever assistant it is. How the provider itself handles the same text, including retention on its own servers, is a separate question covered in where your prompts go when you press send.
A personal account on a work laptop
This is where the "they can't see it" answer goes wrong. Your employer has no access to your ChatGPT or Gemini account and cannot scroll through last month's conversations. What it controls is the laptop and the browser, and Microsoft groups sites such as ChatGPT, Google Gemini, the consumer version of Microsoft Copilot and DeepSeek under a category called "Other AI apps", detected through browser activity.
On a Windows computer onboarded to Purview, with Microsoft's browser extension installed, the employer can do three things that matter here:
- Record visits. A ready made policy detects when users visit AI sites, and reports show total visits and interactions over time.
- Stop sensitive pastes. Endpoint data loss prevention can warn you or block you when you share sensitive information with an AI site in the browser. Microsoft's own example is a user being prevented from pasting credit card numbers into ChatGPT, or shown a warning they can override. A separate policy applies block with override to pastes and uploads by users flagged as elevated risk, in Edge, Chrome and Firefox.
- Capture the prompts. With a collection policy set to capture content, prompts and responses can be retained and searched with eDiscovery. Microsoft restricts that to the Edge browser, for ChatGPT, consumer Copilot, Gemini and DeepSeek.
The employer does not need your chat history if it can capture the text on the way out of its own machine. Audit records of these third party AI interactions are kept for 180 days, and they need pay as you go billing turned on, which is one more reason not every employer has them. The safer habit is the one in what a chatbot does with the personal data you type: treat anything typed on a work machine as visible to the company that owns the machine.
Your own phone on the office wifi
Here the employer is just the network operator. The connection to the AI site is encrypted, so the content of your prompts is not readable on the wire. What the network typically still sees is the name of the site you connect to, because that is visible in the lookup and in the opening handshake, as explained in what a DNS resolver can see about you. A record that your phone reached chatgpt.com is possible. The words you typed are not.
At home on your own device with a personal account, your employer is not in the path at all. A VPN changes nothing in the first two rows, since the capture happens in the browser on the laptop.
What the law requires your employer to tell you
No employer is obliged to use any of these features, and monitoring law differs by country. This is general information, not advice.
In the UK, the Information Commissioner's Office says data protection law does not prevent monitoring workers, but employers must tell workers how and what personal information they collect, and the monitoring must be necessary and proportionate. Covert monitoring is unlikely to be justified in usual circumstances. The exception is suspected criminal activity or gross misconduct, with senior management authorization and a data protection impact assessment. The ICO also says that when workers use their own devices for work, employers should not capture their private use. And monitoring data falls under a subject access request, so in the UK you can ask for what was collected about you.
In the US there is no single federal notice rule, and the position is set state by state. New York is a clear example: employers that monitor email, internet access or usage must give written notice on hiring, have the employee acknowledge it, and post the notice where staff can see it, with civil penalties of $500, $1,000 and then $3,000 for repeat offenses.
What to do before you type
- Check which account you are signed into. The work login is the one that makes text retrievable, on any device.
- Read the acceptable use or monitoring section of your company's AI policy. If AI tools are approved, use the approved one for work, since quietly using a personal account for work is exactly what these controls are built to find.
- Keep anything personal off the work laptop: health questions, job hunting, disputes with your employer. Use your own phone on mobile data.
- If you are in the UK and want to know what was captured, make a subject access request in writing.
Common questions
Can my boss read my ChatGPT history if I use my personal account at work?
Not from OpenAI. Your employer has no login to your personal account and cannot browse your past conversations. What it can do, on a laptop it manages, is record that you visited the site, block or warn on sensitive pastes, and in Microsoft's Edge browser capture the prompts and responses you type during that session if a content capture policy is in place.
Does incognito or private browsing hide ChatGPT use from my employer?
No. Private browsing stops the browser keeping local history and cookies after you close the window. Monitoring on a managed laptop works at the device and browser level, and the network still sees which sites you connect to. Private mode hides your activity from the next person using that browser, not from the organization that runs the computer.
Can IT see my Microsoft 365 Copilot chats?
Not casually, but the text is retrievable. The prompts and responses sit in a hidden folder in your work mailbox and can be searched and exported with eDiscovery. In Microsoft's compliance dashboard the content is shown only to people in a specific viewer role, so an ordinary help desk technician should not have access to it.
Will my employer know if I paste company data into ChatGPT?
If data loss prevention is set up on your work computer, probably yes. Microsoft's tools can detect sensitive information such as card numbers being pasted into AI sites and either warn you, letting you override and proceed, or block the paste outright. Either way the attempt is usually recorded. On your own device on mobile data, the employer has no view of it.
Is it legal for my employer to monitor my AI chats?
Generally yes on work systems, with conditions that depend on where you are. In the UK the employer must tell you about monitoring and keep it proportionate, and covert monitoring needs exceptional grounds. In the US, rules are set by state; New York, for example, requires written notice of electronic monitoring on hiring that you acknowledge.