If you use an AI account your employer set up, the vendors' own documentation says the people who administer it can reach what you type. OpenAI states that administrators of a managed ChatGPT account may access the prompts, uploaded files and outputs, along with conversation history and usage metadata, and can export, audit, retain or delete them. Microsoft stores Microsoft 365 Copilot prompts and responses in a hidden folder in your mailbox, where compliance administrators can search them with eDiscovery tools. A personal account you opened yourself is a separate thing on OpenAI's pages, but the vendor pages cannot tell you what your employer's devices and network record around it. In the UK the ICO's guidance expects employers to tell workers about monitoring, and a policy you have never seen is a reason to ask.
The answer, in one line
If you use an account your employer administers, the vendors' own documentation says yes. OpenAI states that administrators of a managed ChatGPT account may access prompts, uploaded files and outputs, plus conversation history and usage metadata.
Definition#
Managed account: an AI account created and administered by an employer or school, in which an administrator, and not only the user, controls the workspace settings and can reach the content held in it. The term is OpenAI's, from its help documentation for a managed ChatGPT account. It is a contrast with a personal account, which the user opened and controls alone.
Two accounts that look identical on screen#
The chat window on a work login and on a personal login is the same. What differs is who owns the account behind it. On a managed account the employer is the administrator; on a personal account you are. OpenAI's help article on data access for a managed account says that if you sign into a managed account and a personal account they remain separate, so the administrator's reach covers the managed workspace and nothing in the personal one. Everything else on this page depends on which of the two you were typing into.
What OpenAI says an administrator can reach#
OpenAI's help article on data access lists what an administrator may access: the content you submit, meaning prompts, files you upload and outputs, plus conversation history, usage metadata and security settings. Administrators can, in its words, export, audit, retain, delete and opt in to share data tied to the account. The article says users are given a Managed ChatGPT Account Notice when the account is set up.
OpenAI's enterprise privacy page describes the mechanism. Within an organisation end users can view their own conversations, and workspace administrators can access an audit log of conversations and custom GPTs through the Enterprise Compliance API. Administrators control how long data is kept. Deleted conversations are removed from OpenAI's systems within 30 days unless the company is legally required to keep them, and business data is not used to train models by default. The last two points are about OpenAI's own handling, and say nothing about what your employer keeps once it has exported the log.
What Microsoft says happens to a Copilot prompt#
Microsoft's retention documentation says data from generative AI messages is stored in a hidden folder in the mailbox of the user who runs the AI app. The folder is not designed to be directly accessible to users or administrators, but stores data that compliance administrators can search with eDiscovery tools. Messages in it remain searchable until permanently deleted, and the page adds that what you can see in an AI app is not an accurate reflection of whether messages are retained.
The separate audit log page describes a narrower record. An audit record typically holds a prompt and response pair, flags whether a message is a prompt, flags a detected jailbreak attempt, and lists the files, sites and other resources Copilot accessed to answer. That page does not say the audit record stores your wording, and this page does not claim it does. The retention page is the one that puts searchable text in a mailbox.
In the UK, the employer is meant to tell you#
The ICO's guidance on monitoring workers covers technologies such as tracking internet activity and keystrokes. It says employers must make workers aware of how and what personal information they collect during monitoring, must tell them in a way that is accessible and easy to understand, and apart from very exceptional cases of justified covert monitoring must inform workers about any monitoring. An employer needs a lawful basis, and a data protection impact assessment is required before processing likely to cause high risk to workers. Chat logs of AI use are personal information about a worker, so the guidance bears on them directly.
That is the UK position, and the guidance is the regulator's account of the law and no substitute for advice on a specific case. Other countries differ, and this page is not legal advice.
What these pages cannot tell you#
- They describe capability, not practice. Each vendor page says what an administrator can do. None reports how many employers actually read staff conversations, and no study cited here measures it.
- Two vendors out of many. OpenAI and Microsoft are widely used and were the two whose documentation was read. Other tools have their own terms, and a tool you use through a third-party app has a different chain of custody again.
- Vendor pages are the vendors' own account. They can change, and the OpenAI pages were re-read on 29 September 2026 only.
- The account is only part of the picture. Company laptops, networks and endpoint software are set by your employer, and neither vendor page speaks to them.
- Settings vary by organisation. Retention periods and who holds administrator rights are choices an employer makes, so the answer for your workplace has to come from your workplace.
A work prompt is a work record#
This section is interpretation, kept apart from the evidence above.
Microsoft's own design makes the working rule easy to state: a prompt in a work Copilot is stored where your email is stored, in your mailbox, for a compliance team to search. Nobody would type an unguarded aside into a work email expecting it to vanish, and the same discipline fits the prompt box. It is a record made in the course of employment.
Rahim Hirji listed the reverse failure in AI Habits of 2025 That Will Get You Sued, Fired, or Embarrassed on 23 November 2025. Habit 10 is "Just Upload The Spreadsheet", where salary, health and customer records are dragged raw into assistants because anonymising takes time. Habit 13 is shadow AI: teams use personal accounts for work because approvals are slow, and, as he puts it, "Security finds out during an audit, not before." Read beside the vendor pages, the two habits pull in opposite directions. The managed account is visible to the employer, and the personal account escapes that visibility by moving the same client data outside anything the employer governs. Deloitte UK's 2026 survey of 25,000 workers found 31 per cent of users say they use generative AI without their employer's knowledge, so the move is common.
Escaping the log does not make the content private. It puts confidential material where neither your employer nor you can say what happens to it, which is the worse trade.
Before you type the next prompt#
- Find out which account you are in. If you were given a work login or a workspace, treat everything in it as readable by your organisation, and look for the account notice you were given at set-up.
- Ask IT or the data protection lead three plain questions: who can read conversations, how long they are kept, and whether any monitoring of AI use is covered by a notice you have seen. In the UK you are entitled to be told about monitoring.
- Keep client, HR and health data in the tool your organisation has approved, and out of personal accounts. If the approved tool is too slow to be usable, raise that with the organisation and do not route around it.
- If you run a team, publish a one-page statement of what is logged and who can read it. In the experiments on disclosing AI use, people who expected a penalty said they would keep quiet, and a clear statement of what is and is not seen removes one reason to.
Key sources
- OpenAI. Data access for your managed ChatGPT account. OpenAI Help Center. Read 29 September 2026. Graded entry.
- OpenAI. Enterprise privacy at OpenAI. Read 29 September 2026. Graded entry.
- Microsoft. Learn about retention for Copilot and AI apps. Microsoft Learn, page dated 26 September 2025. Read 29 September 2026. Graded entry.
- Microsoft. Audit logs for Copilot and AI applications. Microsoft Learn, page dated 26 August 2026. Read 29 September 2026. Graded entry.
- Information Commissioner's Office. Data protection and monitoring workers. Read 29 September 2026. Graded entry.
- Deloitte UK (2026). British workers spend one billion pounds of their own money on gen AI for work. 16 September 2026. Graded entry.
- Hirji, R. (2025). AI Habits of 2025 That Will Get You Sued, Fired, or Embarrassed. Box of Amazing, 23 November 2025. Argument, cited as interpretation rather than evidence.
Related SuperSkills research#
On whether to mention your AI use to a manager, should I tell my boss I used AI. On what to do when staff use personal tools, what to do when people work around the AI policy. On writing the rules down, how to write an AI use policy that works. On honest description of your own use, how to be honest about using AI in your work.
About this research#
Rahim Hirji is the author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company. Every vendor and regulator statement on this page was read at source on 29 September 2026 and is graded in the evidence base. Managed account is OpenAI's term and not a SuperSkills coinage. This page is general information and not legal advice.
Evidence review · SS-2026-370 · Graded against the published rubric
Hirji, R. (2026). Can my employer see what I put into AI?. The SuperSkills evidence base, SS-2026-370. https://thesuperskills.com/research/can-my-employer-see-what-i-put-into-ai. Last reviewed 29 September 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work