← Back to blog
    6 min readBy Gene Ishchuk

    How do you govern AI use across ChatGPT, Copilot and Gemini?

    Most 50-200 person companies run three or four AI assistants at once. Here is the tiering model I use to decide which tool touches which data, with 2026 prices and the retention guarantees worth checking.

    aigovernanceshadow-aicost-control

    TL;DR

    Tier every AI tool by data sensitivity, not by vendor: consumer tiers touch public data only, business tiers with contractual no-training clauses get internal data, and regulated data stays out of external tools entirely. Then buy the right business seats, federate them through your identity provider, and block consumer endpoints only after people have a managed replacement.

    How do you tier AI tools by data sensitivity?

    Sort every AI tool in your company into three buckets by what data it is allowed to touch: public data, internal data, or regulated data. Consumer and free tiers get public data only. Business tiers with contractual no-training clauses get internal data. Regulated data (payroll, health, legal, anything under NDA or GDPR special categories) gets no external tool at all until someone signs off. That is the whole model. The rest of this piece is about making it stick across ChatGPT, Copilot, Gemini and whatever niche tool marketing just bought.

    I set this up for a 60-person media-buying agency in June 2026. Took one afternoon once we stopped trying to write policy and just drew the buckets on a whiteboard. The hard part was not the framework, it was admitting that half the company was already pasting client campaign data into personal ChatGPT accounts.

    What does each vendor's business tier actually guarantee?

    Prices below, all dated, because this moved three times in 2026.

    ChatGPT Business (the renamed Team plan) is $20 per seat per month on annual billing, $25 monthly, two-seat minimum, per OpenAI's pricing page. The reason to pay it over stacking personal Plus accounts: workspace prompts and outputs are excluded from model training by default. ChatGPT Enterprise is quote-only, 2026 procurement reports converge on roughly $60 per seat, 150-seat minimum, 12-month commitment. Below 150 people, Business is your tier. Resellers occasionally discount below the floor, but do not build a plan on a negotiation you have not had.

    Microsoft 365 Copilot is $30 per user per month as an add-on, and it requires a qualifying base license (E3, E5, Business Standard or Business Premium). EPC Group's 2026 licensing guide has the full matrix. What smaller Microsoft shops often miss: Copilot with commercial data protection (the successor to Bing Chat Enterprise) ships inside many existing M365 licenses at no extra cost. It is web-grounded only, no SharePoint access, but it covers the "can I Google things with it" use case safely. Microsoft said in August 2024 it would begin retaining prompts for compliance and audit, so "no retention" claims in older blog posts are stale. Check the current terms.

    Google removed the standalone Gemini add-on on January 15, 2025 and bundled Gemini into Workspace tiers. Business Standard at $14 per user per month (annual) is the lowest tier with the full Gemini side panel across Gmail, Docs and Sheets. Google states plainly that Workspace data is not used to train Gemini models or for ads targeting. Fine print: reviewer Marie Haynes noted trial-period data can be treated differently than in a paid plan. Buy the seat before the pilot.

    What does consumer-tier AI actually cost you in risk?

    Here I need to be honest about how bad the numbers look. LayerX's 2025 workplace report found 77 percent of employees paste data into generative AI prompts, and 82 percent of those pastes come from personal accounts outside company oversight. Cyberhaven's 2025 AI Adoption and Risk Report put 34.8 percent of corporate data entering AI tools as sensitive, roughly triple their figure from two years earlier. And IBM's Cost of a Data Breach 2025 report attributed one in five organizational breaches to unsanctioned shadow AI, adding about $670,000 to the average incident.

    Those are big-vendor numbers and I treat them with a squint. Surveys of self-reported behaviour undercount; browser-telemetry numbers like Cyberhaven's only cover the companies they instrument. The direction of travel is not in dispute though. Netskope's Cloud and Threat Report tracked the share of genAI users on personal apps falling from 78 percent in October 2024 to 47 percent in October 2025, which tells you companies that manage this pull usage onto managed accounts, and companies that do not, leak.

    One detail almost nobody quotes: IBM found 97 percent of AI-related breaches lacked proper AI access controls. Not model alignment, not prompt injection. Access controls. Boring identity work, the same stuff your IT person already does for SaaS.

    How do you enforce tiering without annoying everyone?

    Do not start with blocking. Start with giving people a better tool than the one they smuggled in.

    If you want it compressed into a week: Monday, pull the expense report and list every AI line item, that is your shadow census. Tuesday and Wednesday, buy and federate seats for the top 20 percent of users. Thursday, publish the one-page policy. The following Monday, once people have a managed tool that works, block the consumer endpoints.

    The sequence in full: first, buy business seats for the 20 percent of staff who actually use AI daily and move their accounts over. Second, federate those accounts through your identity provider, Entra ID if you are a Microsoft shop, Google Workspace admin if not, so access is provisioned and deprovisioned with employment, not with a credit card. ChatGPT Business includes an admin console; Copilot inherits your M365 permissions model; Workspace admin console handles Gemini natively. Third, publish the buckets as a one-page policy, which I covered separately in my post on AI acceptable-use policy, and maintain the approved-tool list as a registry rather than an email thread.

    Then, and only then, block the consumer endpoints at the firewall or DNS layer. By that point you are taking away nothing without a replacement. Skipping step one and jumping to blocking is how you get employees using AI on their phones, which no filter of yours will ever see.

    I do a usage audit maybe once a quarter, someone always asks. Export the admin consoles, count active seats versus licensed seats, kill the dormant ones, list the unmanaged SaaS that expense reports surface. Takes two hours. My post on building an approved AI tools registry has the vendor-vetting checklist.

    Which tools should a 100-person company actually pay for?

    My opinionated answer for a typical 100-person company on Microsoft 365: Copilot with data protection for everyone (already included, zero marginal cost), Microsoft 365 Copilot licenses for the 15 to 25 people whose work lives in Outlook and Teams, ChatGPT Business seats for the 10 to 20 people doing heavy analysis and drafting across tools, and whatever Workspace tier covers the Google-native holdouts. Do the math yourself: 20 Copilot seats at $30 plus 15 ChatGPT Business seats at $20 is $12,600 a year, and a full-holdout scenario lands somewhere in the $15-20k range once you add the Google seats. That sounds like a lot until you compare it with one $670k breach-class incident from IBM's 2025 data, which for a firm doing $20M in revenue is three or four points of margin gone.

    The niche tools are where the governance fails. Every second SaaS product now ships an "AI-powered" module with its own data terms, sometimes on by default. Two rules cover it: no niche tool touches regulated data without a signed DPA, and no auto-renewal on any AI feature nobody has logged into for 60 days. Your expense report is your shadow-AI census.

    One digression, because it matters: the multi-tool problem is partly an illusion created by vendors. ChatGPT, Copilot and Gemini overlap on maybe 80 percent of daily use. Most companies I work with do not need three assistants, they need one well-governed one plus the platform-native add-on they already own. Consolidation is a governance strategy, not just a cost one.

    If you want a second pair of eyes on which buckets your toolset lands in, book a call and we will draw it on a whiteboard in 45 minutes.

    Frequently asked questions

    Can employees use personal ChatGPT accounts for company work?
    No. Personal accounts offer no contractual protection against your data being used for training, no admin oversight, and no audit trail. IBM's Cost of a Data Breach 2025 report attributed one in five organizational breaches to unsanctioned shadow AI. Move daily users onto ChatGPT Business seats, which exclude workspace data from training by default.
    What does Microsoft 365 Copilot cost in 2026?
    $30 per user per month as an add-on, on top of a qualifying base license such as E3, E5 or Business Premium. Note that Copilot with commercial data protection is already included in many Microsoft 365 licenses at no extra cost for web-grounded queries; the paid add-on adds grounding in your own files, email and meetings.
    Is Gemini for Google Workspace included or a paid add-on?
    Google removed the standalone Gemini add-on on January 15, 2025 and bundled Gemini into Workspace tiers. Business Standard at $14 per user per month (annual) is the lowest tier with the full Gemini side panel in Gmail, Docs and Sheets. Google states Workspace data is not used to train Gemini models.
    How many AI tools should a small company actually license?
    Usually one general-purpose assistant plus whatever is bundled with your office suite. A 100-person Microsoft shop typically needs Copilot with data protection for everyone, paid Copilot licenses for 15-25 heavy users, and ChatGPT Business for a smaller drafting and analysis group. Every additional niche tool needs its own data review before it touches internal data.

    Keep reading