Your teams already use ChatGPT (even if you don't know it)
Is ChatGPT at the office a risk for a Luxembourg business? Yes, but not the risk most people imagine: the problem is not productivity, it is confidentiality and compliance. According to Microsoft and LinkedIn's Work Trend Index 2024, 75% of knowledge workers already use AI at work, and 78% bring their own tools without their employer's approval (80% in SMEs). This phenomenon has a name: shadow IT. Shadow IT is the use of digital tools that the company has not vetted, adopted by employees because they make them more effective. With or without your authorisation, your teams have found a tool that speeds up their work, and they are using it.
In practice, it looks like this. Your accountant uses ChatGPT to rephrase a sensitive email to a client. Your sales rep pastes a tender into it to draft a faster response. Your assistant asks it to summarise a 40-page contract. Your developer submits code to find a bug. This is not science fiction: it is the daily reality of most businesses in 2026.
So the real question is not "do my employees use ChatGPT?". It is "what are they putting into it, and where does that data end up?". This article reviews the real risks for a Luxembourg SME, and the three options in front of you: ban, channel or provide a private AI.
What really happens when an employee uses ChatGPT
When your accountant pastes a client email into ChatGPT to rewrite it, the text of that email (the client's name, the amounts, the transaction details) is sent to the servers of the company that operates the model. The language model processes the request and returns a response. The rewritten email comes back on your accountant's screen.
On the surface, everything went fine. Behind the scenes, your client's confidential data has just been handed to a third party, often with no contractual framework between your company and the AI provider. Unlike an email sent to a supplier you have signed a contract with, this transfer is outside your control.
And it is not an isolated case. Here is what employees routinely copy and paste into public AI tools:
- Client emails containing names, amounts and contractual details
- Contracts and legal documents with confidentiality clauses
- Financial data: balance sheets, projections, cash flow reports
- HR data: appraisals, payslips, disciplinary procedures
- Proprietary company source code
- Meeting minutes with strategic decisions
Every prompt is a transfer of data to an external service. The question of where that data is stored, and above all which jurisdiction it falls under, then becomes central.
The concrete risks for your business
The GDPR risk
As soon as personal data (client names, emails, phone numbers) is sent to an AI tool whose processing sits outside the European framework, Articles 44 to 49 of the GDPR apply. Transferring data outside the Union is subject to strict conditions. If your employee uses the free version of ChatGPT from their browser, those conditions are probably not met. The maximum fine under the GDPR reaches 20 million euros or 4% of annual worldwide turnover.
The risk to professional secrecy
In Luxembourg, many professions are bound by professional secrecy (Article 458 of the Criminal Code): lawyers, notaries, doctors, chartered accountants, statutory auditors. If a lawyer pastes a client file into ChatGPT to prepare their pleadings, they are passing information covered by professional secrecy to a third-party service. That is a potential breach of their ethical obligations, regardless of where the data is stored.
The risk of leaking strategic data
What you send to a public AI no longer belongs to you in the same way. The terms of use of most free versions provide that data may be used to train the models. Your commercial strategy, your financial projections, your innovations: all of it can in theory feed a model that others can access. According to IBM's Cost of a Data Breach 2024 report, the average global cost of a data breach reaches 4.88 million dollars. For a Luxembourg SME, a single incident can be fatal.
Data residency in Europe does not mean legal sovereignty
This is the point many executives miss. Since 2025, OpenAI has offered data residency in Europe for ChatGPT Enterprise and its API: data at rest can be stored on servers located within the Union. That is real progress, and it deserves recognition. But European hosting does not settle everything.
OpenAI remains a company incorporated under US law. As such, it is subject to the CLOUD Act, a 2018 US federal law that allows the United States authorities to require the disclosure of data held by a US provider, including when that data is physically stored in Europe. In other words: the data can be hosted in Frankfurt or Dublin, and a US court order can still reach it. Server location does not create legal sovereignty. To understand how the AI Act, the CLOUD Act and the GDPR fit together for a business in Luxembourg, this point deserves to be stated clearly before any tool decision.
The risk tied to models outside the European Union
The subject is not limited to the United States. Models developed outside the Union, including in China, are multiplying and growing in popularity. China's National Intelligence Law, for example, requires companies to cooperate with the country's intelligence services. Data sent to those services falls under a legal framework incompatible with the GDPR and with Luxembourg professional secrecy. The CNPD has warned on several occasions against the use of AI services hosted or operated outside the Union. The logic stays the same whatever the country: what matters is the jurisdiction the provider depends on.
|
Criterion |
ChatGPT free |
ChatGPT Plus (personal account) |
ChatGPT Enterprise |
European private AI |
|---|---|---|---|---|
|
Data used to train the model |
Yes |
Yes (can be disabled) |
No |
No |
|
Where data is stored |
United States |
United States |
Europe possible (data residency) |
Europe (EU) |
|
Legal sovereignty (outside the CLOUD Act) |
No |
No |
No |
Yes |
|
DPA / GDPR contract |
No |
No |
Yes |
Yes |
|
Control by the company |
None |
None |
Partial |
Yes |
|
Training on your internal documents |
No |
No |
Limited |
Yes (RAG) |
|
Multilingual FR / DE / LB / EN |
Partial |
Partial |
Partial |
Optimised |
|
Compliant with LU professional secrecy |
No |
No |
Debatable |
Yes |
💡 Good to know: the real dividing line is not "data in the United States" versus "data in Europe". It is "provider subject to an extraterritorial jurisdiction" versus "data processed by an actor that falls under European law alone". It is this second case that genuinely protects professional secrecy and lets you protect your clients' sensitive data with a private AI.
Why banning does not work
Many executives' first reaction is to ban. "Nobody uses ChatGPT at the office." Move along, problem solved. Except it does not work. Many studies show that a high proportion of employees keep using these tools, even where they have been formally banned.
The workaround is immediate. The employee opens ChatGPT on their personal phone, connected over 4G. No network filter detects it. They copy the text from their work computer to their phone, ask their question, then copy the answer back. The data flow is completely invisible to your IT department.
You have to understand why employees do this. It is not disobedience, it is productivity. An employee who summarises a 50-page document in a few seconds instead of spending an hour on it is not cheating: they are working more intelligently. Taking that tool away without offering an alternative is asking them to become less effective again.
The real problem is not that your teams use AI. It is that they use it without a framework, without control, and with tools that expose your data to a foreign jurisdiction.
The solution: channel, don't ban
The right approach is not to ban AI, but to channel it. In practice, that means three things.
1. Give your teams an AI tool approved by the company
If your employees use ChatGPT in secret, it is because they need it. The solution is to give them a tool that is just as capable, but whose data stays under your control. Private AI solutions hosted in Europe exist, where no data leaves European soil and where processing falls under European law alone.
The principle is simple: instead of each employee using their own ChatGPT account, the company provides an internal AI. Staff have access to it, ask all the questions they want, but the data stays in a controlled environment.
2. Feed this AI with your knowledge base
The advantage of a private AI is not limited to security. You can feed it with your own documents: internal procedures, business guides, technical documentation, client history. Instead of generic answers, your AI gives answers grounded in the reality of your company. A new hire asks a question about a procedure? The AI answers by drawing on your documentation, not on information found at random on the internet.
Comparing the different approaches to enterprise AI helps you choose: understanding what sovereign AI means for a Luxembourg SME lays the groundwork.
3. Set clear rules
Even with an approved tool, you need a framework. Which data may be submitted to the AI? Are there forbidden categories (health data, court files)? Who has access to which level of information? A simple usage charter, fitting on one page, is enough to set the basics. For an overview of the road ahead, the four steps of a controlled AI rollout give a framework for implementation.
What it changes for an SME in Luxembourg
Luxembourg is not a market like the others. Several features make this subject particularly sensitive.
The economy rests on trust
Luxembourg is an international financial centre. Trust companies, family offices, fund managers and business law firms thrive because their clients entrust them with extremely sensitive data. A leak through an AI tool can destroy years of reputation. The same stake applies to an AI phone agent whose data path is documented or to a website chatbot whose data stays in Europe.
Multilingualism makes the problem harder
Your teams work in French, German, English and Luxembourgish. They use ChatGPT in all four languages. A private AI deployed in Luxembourg must understand and answer in these four languages at the same level of quality.
State aid lowers the cost of entry
The SME Package AI programme lets Luxembourg SMEs finance up to 70% of their AI project, capped at 17,500 euros (source: guichet.lu). The two schemes, SME Package Digital and SME Package AI, can even be combined across separate projects. The cost of moving from wild ChatGPT use to a private enterprise AI is therefore far lower than most executives imagine. We break down how the SME Package AI grant covers much of a private AI investment, aid included.
The regulatory framework is tightening
The EU AI Act is coming into force in stages. The AI training obligation (Article 4) has applied since February 2025: any organisation that deploys AI must ensure its teams have a sufficient level of literacy. The next major milestone is 2 August 2026, the date on which most of the regulation's obligations become applicable. The CNPD, tipped to be one of the AI supervisory authorities in Luxembourg, is stepping up its controls. Better to anticipate than to endure.
Conclusion
Your employees use ChatGPT. It is neither a surprise nor a disaster: they do it because the tool makes them more productive, and that is a good thing. The problem is the framework. Without an approved tool, every employee sends confidential data to external services, from their personal account, with no control at all.
And beware of false comfort: data residency in Europe is useful, but it is not enough. As long as the provider falls under an extraterritorial jurisdiction such as the CLOUD Act, the legal sovereignty of your data is not guaranteed.
Banning does not work. The solution is to channel this use by providing a private enterprise AI, hosted and processed in Europe, falling under European law alone and fed by your own knowledge base. It is a matter of GDPR compliance, professional secrecy and common sense. Your clients entrust you with their data: it is up to you to decide where, and under which law, it is processed.
Request a free AI audit to take stock of how ChatGPT is really used in your organisation and to frame a sovereign alternative.
FAQ
Does the paid version of ChatGPT (Plus or Enterprise) solve the problem?
ChatGPT Enterprise offers real additional guarantees: data is not used to train the model, a DPA is available, and since 2025 OpenAI offers data residency at rest in Europe. But OpenAI remains a company incorporated under US law, subject to the CLOUD Act. For a Luxembourg business bound by professional secrecy, the exposure to an extraterritorial order remains, even with a paid version and European hosting.
My employees only use the free version of ChatGPT, is that serious?
The free version is the most problematic. The terms of use provide that conversations may be used to train the models. There is no DPA, no contractual guarantees, and the data is processed outside the GDPR framework. If your employees paste client data into it, that is a real and immediate risk.
How can I tell if my employees use ChatGPT at work?
Simply ask them, without any threat. Employees talk about it openly when the environment is supportive. You can also check your company's network logs, but remember that an employee can use their personal phone over 4G, which escapes any network control. Shadow IT is not just measured, it is channelled.
How much does a private AI cost to replace ChatGPT internally?
The cost depends on the number of users, the integrations and the level of support you want. It is often close to that of a few ChatGPT Enterprise licences, with the advantage that data stays in Europe and the AI can be trained on your internal documents. The SME Package AI programme can cover up to 70% of the initial investment, capped at 17,500 euros (source: guichet.lu).
Do employees need training before deploying a private AI?
Yes, and it has been a legal obligation since February 2025 (Article 4 of the EU AI Act). The training does not need to be complex: a short session is enough to explain the basics, namely how to frame a good question, which data must never be submitted, and how to get the most out of the tool. The most important thing is to give clear rules and a secure tool.
Keywords
ChatGPT risk business Luxembourg, shadow IT ChatGPT, private AI Luxembourg, GDPR generative AI, professional secrecy AI, CLOUD Act data Europe, OpenAI data residency, SME Package AI, EU AI Act 2 August 2026, SME data sovereignty



