What the NCSC Actually Says About Using ChatGPT and Copilot With Sensitive Business Data
The NCSC published clear guidance on large language models and sensitive data, but the majority of UK businesses have either over-reacted with blanket bans or under-reacted by ignoring the risks entirely. This article walks through what the NCSC actually said — including that prompt injection may never be fully fixed, that queries are visible to service providers, and that data classification is the real starting point — and debunks six myths that keep circulating. It compares ChatGPT Enterprise, ChatGPT Business, and Microsoft 365 Copilot on data residency, training opt-outs, and UK data processing, and provides a practical eight-point checklist for getting your AI data policy right.