Two accounts side by side, one with an open and one with a closed data default.

Why the free tier is a management question and not an IT one: the real bottleneck is that your company is already using it, and nobody decided that. Software AG surveyed 6,000 knowledge workers in the United States, the United Kingdom and Germany between 13 and 25 September 2024 and found that half were using AI tools their employer had not approved, with 48 percent saying they would carry on even if the tools were banned outright. Harmonic Security's quarterly analysis for the first quarter of 2025 puts a sharper edge on it: 45 percent of prompts went through personal accounts, and 21 percent of the sensitive data it observed landed in ChatGPT's free tier, where prompts can be retained for training. So the question is not whether to allow free AI tools. The process, the data access and the approval logic have already answered that. The question is what the free tier costs you, and who owns that answer.

What does a free AI tool actually cost?

It costs you the default setting on your own data, and the defaults differ sharply between vendors. This is the single fact that should drive the decision, and it is checkable in an afternoon.

OpenAI states that content from its consumer plans, Free, Go, Plus and Pro, may be used to train its models unless you opt out, and that ChatGPT Enterprise, Business, Edu and the API are excluded from training by default. Anthropic's privacy documentation, dated 16 March 2026, describes the opposite default for its consumer products Free, Pro and Max: chats are used to improve the models only if you choose to allow it, and Incognito chats are never used even when the setting is on.

Two vendors, two defaults, one consequence. An employee who signs up personally inherits whichever default that vendor set, and your company inherits it with them. Nobody in the company chose it, and in most companies nobody knows which of the two it is.

Which tools are genuinely free, and where does the line sit?

The strong free tiers are the assistant products from the large model vendors, and the line sits at the account type rather than at the feature list. A free consumer account gives you a capable model, a chat interface and, in most cases, file upload. It does not give you an administrator, an audit trail, a data processing agreement or a default that keeps your input out of training.

We deliberately do not publish a ranked list of free tools here. A ranking goes stale in weeks and it answers the wrong question: the model quality gap between the free tiers narrowed to the point where it stopped being the deciding factor for ordinary office work. What did not narrow is the gap between a consumer account and a business account, and that gap is contractual rather than technical.

The practical reading: free tiers are a fine place to learn what the technology does. They are a poor place to put a customer list, a draft contract, a salary band or an unreleased set of figures, and that distinction is one a person can be taught in ten minutes.

What may your employees legally put into a free tool?

Anything that is not personal data and not a business secret, which in practice is a smaller set than people assume. Once the input contains customer names, employee data, health information, pricing that is not public or code that is not yours to share, the free consumer account is the wrong container for it, regardless of how good the model is.

There is a second obligation that is easy to miss because it does not look like a data protection rule. Article 4 of the EU AI Act has applied since 2 February 2025 and requires providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy among the staff who operate them, judged against their knowledge, their training and the context of use. Supervision and enforcement of that requirement start on 2 August 2026.

Read plainly, that turns the informal answer into a formal one. If half your workforce is already using AI, the obligation to make them competent at it applies whether or not anyone has signed a licence.

When does a paid plan pay for itself?

It pays for itself the moment the work being done on the free tier is work you would not want repeated on a public interface, and that threshold arrives much earlier than the budget conversation usually does. The switch buys you four things a free account cannot offer: training excluded by default, an administrator who can see and revoke access, a contract that names a processor, and a single place where the data lives.

Set against the Bitkom finding of 11 March 2026 that 33 percent of companies using AI hit significantly higher costs than they expected, the per-seat price of a business plan is rarely where a budget goes wrong. The overruns come from integration work, exception handling and half-finished pilots, not from licence fees.

The cheap sequence is therefore the opposite of the intuitive one. Buy a small number of governed seats for the people who touch sensitive material, leave everyone else on the free tier for learning, and spend the saved budget on deciding which process you want changed.

How do you get the shadow usage out of the shadow?

Ask, before you audit. The Software AG finding that 48 percent would keep using banned tools tells you what a prohibition achieves: it moves the usage to private phones, where you can neither see it nor improve it. A rule people route around is worse than no rule, because it removes the last chance to shape the behaviour.

What works instead is a short written answer to three questions, published where people actually look. Which tool is sanctioned for which kind of work. What may never be pasted anywhere. Who to ask when a case does not fit. That document is a morning's work, and it converts an invisible risk into a managed one.

The follow-up matters more than the document. Tell people what changed and why, name the approved tool, and make the approved path faster than the unapproved one. Convenience is what created shadow usage, and convenience is the only thing that reliably ends it.

Where does the works council come in?

It comes in earlier than most companies expect, because the trigger is not the tool but what the tool can observe. Section 87 paragraph 1 number 6 of the German Works Constitution Act gives the works council a co-determination right over the introduction and use of technical systems designed to monitor the behaviour or the performance of employees, and that right applies wherever no statutory or collective agreement already covers the matter.

German labour courts have long read that provision broadly: a system that is merely capable of producing performance data can fall under it, whether or not anyone intends to use it that way. An AI assistant inside a ticketing system, a meeting transcriber or an agent that logs who asked what are all worth checking against it before rollout rather than after.

The practical order is therefore governance first, licence second. Agree what is logged, who can see it and what it may never be used for, then buy the seats. A rollout paused three weeks in because nobody asked is more expensive than a conversation held three weeks early, and it is the kind of avoidable delay that turns a sponsor into a sceptic.

What should a CxO actually decide this quarter?

Decide three things and write them down: which tool is sanctioned, which categories of data may never leave the house, and who owns the answer when a new tool appears. Everything else follows from those three, and none of them needs a procurement cycle.

Then check one number against the training defaults above. Take the accounts your people are using today, find out whether the default is opt in or opt out, and if it is opt out, decide whether you are content to leave it that way. That check costs an hour and it settles a question most companies have been carrying unresolved for two years.

Free is the correct price for learning a technology. It is the wrong price for running a process you would have to explain to a customer, an auditor or a works council, and the difference between those two is a management decision that nobody else in the company can take for you.

Which AI tools can you use for free?

The assistant products from the large model vendors have capable free tiers with file upload. What they do not include is administration, an audit trail and a data processing agreement.

Is my input used to train the model?

It depends on the vendor. OpenAI uses consumer plan content for training unless you opt out; Anthropic's privacy page of 16 March 2026 states that consumer chats are used only if you allow it.

What must never go into a free AI tool?

Personal data, health information, unpublished pricing, draft contracts and code that is not yours to share do not belong in a personal account. That line can be taught in ten minutes.

How common is unapproved AI use at work?

Software AG surveyed 6,000 knowledge workers in September 2024 and found half were using tools their employer had not approved. Forty-eight percent said they would continue even if banned.

When does a paid plan pay for itself?

As soon as work happens on the free tier that you would not want repeated on a public interface. The paid plan buys training excluded by default, administration, a contract and one place for the data.

Is there a legal duty to train staff on AI?

Article 4 of the EU AI Act has applied since 2 February 2025 and requires sufficient AI literacy among staff operating AI systems. Supervision and enforcement start on 2 August 2026.