The £150-a-month AI decision that changes your data risk

An MD at a desk reading a printed report with a laptop open beside her, a notepad with handwritten figures and a calculator on the desk
TL;DR

The most consequential AI procurement decision for an SME is whether to allow free public LLM tiers for work tasks. Free tiers from OpenAI, Google, and Microsoft default to training on user inputs and ship without a Data Processing Agreement. Paid commercial tiers, at roughly £15-30 per employee per month, include the DPA, training opt-out, and contractual data privacy commitments. For a 10-person business where 3-4 people use LLMs regularly, the cost is £45-120 per month. The cost is small. The absent decision is the issue.

Key takeaways

- Free tiers of ChatGPT, Gemini, and Microsoft Copilot default to training on user inputs. Anything an employee enters becomes training data. No Data Processing Agreement. - Paid commercial tiers (typically £15-30 per user per month) provide DPA, training opt-out, and contractual data privacy commitments. - For a 10-person business with 3-4 active LLM users: £45-120 per month. For full coverage: £150-300 per month. Cost is small relative to the data risk it removes. - Anthropic Claude is the partial exception: the free tier does not train on inputs by default, but commercial Business Agreements give the same protections plus formal contractual position. - The free tier is fine for genuinely public inputs (brainstorming, generic templates, public-data analysis). It is not fine for personal data, client confidential information, or proprietary content. - One sentence in the policy does most of the work: "Personal data and confidential information may only be processed by tools with a DPA, training-disabled options, and UK GDPR compliance."

The MD of a 12-person law firm is reading the compliance officer’s report on AI tool use within the firm. Five paralegals are using free ChatGPT. Two solicitors are using Claude on the free tier. One trainee is using Gemini on the free tier. Total firm AI spend: zero. The compliance officer’s note at the bottom: “I cannot currently confirm whether any client matter information has been entered into these tools, but the policy does not specifically forbid it.” The MD now has a decision to make that costs the firm £180 a month and removes a category of professional risk she had not realised was sitting there.

This is the highest-leverage governance decision most owner-led SMEs face on AI. The free-tier-versus-paid-tier choice. It is also the one most often left unmade, because the cost feels too small to be material and the risk feels too abstract to be urgent. Both feelings are wrong.

What do free LLM tiers actually do with your data?

Free tiers from OpenAI, Google, and Microsoft default to training on user inputs. Anything an employee enters into free ChatGPT, free Gemini, or the free version of Microsoft Copilot becomes part of the training data and may be synthesised into responses to other users. None of the free tiers ship with a Data Processing Agreement. The Samsung 2023 incident, where employees used free ChatGPT to handle confidential semiconductor work, illustrates the failure mode at scale.

Anthropic Claude is the partial exception. The free tier does not train on user inputs by default. Documentation on data residency and retention is thinner than the commercial offering, and any SME that wants a formal contractual position needs the commercial Business Agreement.

What does the paid commercial tier actually buy?

Three things. A Data Processing Agreement, the legal contract for processing personal data under UK GDPR. Training opt-out, so user inputs are not absorbed into the model and cannot resurface in another user’s response. Clearer data residency, with UK or EU storage options available on enterprise plans. The paid commercial tiers usually include all three plus contractual breach-notification commitments, and any one of them would materially change the firm’s data risk position.

Beyond the contractual position, the paid tier typically includes audit logs, admin controls, and the ability to manage employees centrally. For a 10-50 person firm, the admin layer matters less than the contract; for a 50-100 person firm, it starts to matter quite a lot.

How does the cost actually break down?

The 2025-2026 pricing for the four major LLM providers sits in a similar band. ChatGPT Plus runs £15-20 per user per month with Enterprise pricing on negotiation. Gemini Business in Google Workspace runs £12-20 per user per month depending on the plan. Microsoft Copilot for Microsoft 365 runs £20-30 per user. Anthropic Claude for Work pricing is comparable and available via direct quote.

For a 10-person business where 3-4 people use LLMs regularly, the monthly cost is £45-120. For a 10-person business where every employee uses LLMs occasionally, the cost scales to £150-300. Compare against the cost of a single client confidentiality breach, one ICO investigation, one professional indemnity claim, or one ASA enforcement letter. The financial case is straightforward.

Where is the free tier still appropriate?

For genuinely public inputs. Brainstorming with no client or personal data. Drafting generic templates that contain no specific names or details. Summarising publicly-available information that is already on the open internet. Public-data analysis where both the dataset and the question are non-sensitive.

The free tier has a real role for these uses. The pattern that breaks SMEs is not the existence of free tiers; it is the assumption that the same tier handles every kind of input the firm needs to process. The fix is the data classification rule that maps which tier of input goes into which tier of tool.

How does the policy actually express this?

One sentence does most of the work. “Personal data and confidential information may only be processed by tools that have a Data Processing Agreement, have committed contractually not to use data for model training, and are UK GDPR compliant.” Everything else flows from that sentence.

In practice the rule means the firm pays for the paid commercial tier of one or two tools (ChatGPT Enterprise plus Claude for Work, for instance) and provides them to the employees who actually use LLMs in their work. The free tier remains available for genuinely public uses, with the policy and the data classification reference explaining which inputs belong where.

What about the mixed-fleet reality?

Most SMEs end up with a mixed fleet. Some firms run paid tiers for everyone, paying for the whole team to have access. Others run paid tiers for the staff who handle confidential data (paralegals, accountants, advisers) and free tiers for the staff who do not. A few run a single licensed enterprise tool that everyone routes through, often integrated with the firm’s existing Microsoft 365 or Google Workspace.

All three configurations are defensible. What matters is that the policy explicitly names which tier is approved for which class of data, and that the named tool is the one employees actually use day-to-day. A policy that approves a paid tier nobody has logged into has the same defect as a policy that bans a free tier everyone uses anyway.

What should you do this week?

Three actions. First, find out which AI tools your team is actually using. The amnesty + survey approach surfaces this without driving it underground. Second, decide which of those tools you are going to officially approve and pay for. Third, write the one-sentence rule into the policy.

If you are in the position of having a compliance officer’s report telling you what your firm is doing, and you are not sure what to do about it, book a conversation.

Sources

- OpenAI Data Processing Addendum. https://openai.com/policies/data-processing-addendum - OpenAI Enterprise privacy. https://openai.com/enterprise-privacy - Google Workspace Gemini Business overview. https://workspace.google.com/learning/content/gemini-business-overview - Microsoft Copilot for Microsoft 365 privacy. https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy - Anthropic commercial terms. https://www.anthropic.com/legal/commercial-terms - ICO contracts and Data Processing Agreements. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/contracts-and-data-sharing/

Frequently asked questions

Do free LLM tiers train on user inputs?

ChatGPT free tier (OpenAI) trains on user inputs by default. Gemini free tier (Google) uses inputs for model improvement. Microsoft Copilot free tier has variable terms by jurisdiction. Anthropic Claude free tier does not train on inputs by default, though it has limited data privacy documentation. The practical rule for SMEs is to assume any free tier may train unless the vendor's commercial agreement explicitly says otherwise.

What does the paid commercial tier actually buy?

Three things. A Data Processing Agreement, which is the legal contract for handling personal data under UK GDPR. Training opt-out, meaning user inputs are not absorbed into the model. Clearer data residency, with UK or EU storage available on enterprise plans. One of the three is enough to materially change the firm's data risk position; the paid tiers usually include all three.

How much does it cost to put an SME on a defensible footing?

For a 10-person business where 3-4 people use LLMs regularly: £45-120 per month. For a 10-person business where every employee uses LLMs occasionally: £150-300 per month. Compare to the cost of one client confidentiality breach, one ICO investigation, or one professional indemnity claim. The cost is small relative to the risk it removes.

Is the free tier ever appropriate for work use?

Yes, for genuinely public inputs: brainstorming with no client or personal data, drafting generic templates, summarising publicly-available information, public-data analysis. The free tier has a real role for these uses. The rule that needs to be in the policy is which class of input goes into which tier of tool, not a blanket ban or a blanket allow.

This post is general information and education only, not legal, regulatory, financial, or other professional advice. Regulations evolve, fee benchmarks shift, and every situation is different, so please take qualified professional advice before acting on anything you read here. See the Terms of Use for the full position.

Ready to talk it through?

Book a free 30 minute conversation. No pitch, no pressure, just a useful chat about where AI fits in your business.

Book a conversation

Related reading

If any of this sounds familiar, let's talk.

The next step is a conversation. No pitch, no pressure. Just an honest discussion about where you are and whether I can help.

Book a conversation