AI safety for SMEs

How NZ SMEs Can Use ChatGPT Safely

ChatGPT can be a useful draft helper for an SME, but it works best when the team treats it like a fast assistant, not a source of truth. The safe version is simple: use it for structure, rewrite, and brainstorming, then keep private data, final judgement, and factual checks in human hands.

Published Author John Finnerty Reading time 5 min
Illustrated article hero image for how NZ SMEs can use ChatGPT safely.

Use ChatGPT for the right kind of work

The safest use cases are the ones where the tool helps you move faster without deciding anything important on its own. If the output still needs a human to check it, approve it, and send it, that is usually a better fit than asking the model to make business decisions.

Draft first versions

Ask for an outline, a rough email, a checklist, or a first pass at a policy.

Rewrite for clarity

Turn a messy note into plain English, a cleaner reply, or a more consistent tone.

Summarise safe material

Use it on public text, internal notes without sensitive data, or your own draft content.

Brainstorm options

Generate headings, names, agenda ideas, or prompt templates before you choose.

What not to paste into it

A useful rule is simple: if you would not be comfortable seeing the text in a third-party system, do not paste it into ChatGPT. That includes sensitive client details, credentials, and anything that would create avoidable privacy or confidentiality risk.

  • Passwords, API keys, tokens, and login links.
  • Private client records, invoices, contracts, or medical details.
  • Unredacted personal information unless there is a clear and justified reason.
  • Legal, financial, or HR material that needs careful human review.
  • Anything that could expose a client, supplier, or staff member if the prompt were copied into a ticket or screenshot.

If you need the model to help with sensitive work, strip the identifiers first and keep the original source material in a secure system.

Set a simple team policy

The safest SME version is not a long policy document. It is a short agreement that everyone can remember and follow.

  1. List the approved use cases, such as drafting, rewriting, and brainstorming.
  2. List the banned inputs, especially credentials and sensitive client data.
  3. Require a human review step before anything leaves the business.
  4. Decide who can use AI tools and who needs extra approval.
  5. Review the policy whenever a new tool, customer workflow, or risk appears.

If the team can remember the policy without looking it up every time, it is more likely to work in practice.

A safe everyday workflow

The easiest way to avoid mistakes is to use the same sequence every time. That keeps the speed benefits while reducing the chance of a bad prompt or a sloppy copy-paste.

  1. Start with a narrow task, such as "turn these bullet points into a client-friendly email".
  2. Remove anything sensitive before you paste.
  3. Ask for structure or wording, not final judgement.
  4. Check names, dates, numbers, and claims against your source material.
  5. Send only after a human has read it end to end.

That workflow is boring, but boring is good when the goal is to keep useful work moving without creating avoidable risk.

A New Zealand context reminder

If your business handles personal information, treat ChatGPT as another external service in the chain. That does not automatically make it off limits, but it does mean you should be deliberate about what goes in, how it is reviewed, and whether your own privacy obligations are being met.

For many SMEs, the safe path is to keep ChatGPT on the outside edge of the process. Let it help with wording, structure, and idea generation, then keep private data, approval, and final decisions inside the business.

For the current professional context, you can review About John Finnerty and Project work.