
It happens in every wealth manager, law firm, and finance team. Someone copies a client note from Outlook or the CRM, opens ChatGPT, and pastes it in with a quick "tidy this up". The domain is allowed because an outright ban killed productivity last quarter. Network DLP sees HTTPS traffic to OpenAI. It does not see the client name.
Blocking chatgpt.com does not stop the paste. It stops you seeing it.
You already know it is happening. The question is what actually stops it.
Three things teams try that fail
Ban chatgpt.com
An acceptable use policy
Microsoft Purview prompt protection
What each approach actually stops
| Approach | Stops the paste? | What it misses |
|---|---|---|
| Domain block | No, it blocks the tool | Phones, other models, home Wi-Fi |
| Policy PDF | No | Everything |
| Purview / Edge DLP | Yes, in Edge on enrolled Windows | Chrome, Mac, BYOD, anyone without E5 |
| Browser extension DLP | Yes, in Chrome and Edge | Native desktop apps (Claude desktop, Copilot in Word) |
The last row is worth being honest about. A browser extension like Fendr sees what happens in the browser tab. It does not see Claude desktop or Copilot inside Word. If those are risks in your environment, you need endpoint coverage alongside the browser control.
What to do this week
A sensible rollout for a 50-500 person UK firm looks like this:
Week 1: visibility only
Deploy the extension via MDM to Chrome and Edge. Run in monitor mode. See which AI tools are in use and whether pastes include client identifiers, account numbers, or source code. Do not block yet. You are building evidence, not a wall.
Week 2: block the data, not the tool
Stop pastes that look like client data, account numbers, or proprietary code into unsanctioned AI. Allow general questions and approved tools. The aim is to prevent the specific leak, not to ban AI.
Week 3: redirect to the approved tool
When someone opens ChatGPT with client data, redirect the tab to ChatGPT Enterprise or Copilot with a short explanation. A dead tab teaches workarounds. A redirect teaches the right tool.
Keep the audit log
Every blocked paste, redirect, and policy trigger should be logged. That log is what turns your policy into evidence. Fendr's compliance product produces immutable, export-ready AI usage logs, and our guide to evidencing your AI policy explains how to present them.
The GDPR piece is already covered
If the legal risk is the question, read our piece on shadow AI and UK GDPR. This page is the control. The two belong together: one explains why the paste is a problem, the other explains how to stop it.
Get started
If you are an IT manager or CISO at a UK SME, the fastest way to close the gap is a short audit. Fendr maps active AI usage across your organisation in under five minutes, with no infrastructure change.
Run a free AI audit to see which tools are in use and where client data is leaking, or book a demo to see the controls in action.
Ready to see what your team is actually using?