Skip to main content

Author: Jess

ChatGPT Outlook Add-In Risks: What Every Business Needs to Know Before Installing It

Updated August 2026: Essential guidance for UK businesses using or considering the ChatGPT Outlook add-in

The ChatGPT Outlook add-in is one of the fastest-adopted AI tools in UK workplaces right now. It promises to help employees draft emails faster, summarise long threads, and manage their inboxes more efficiently. For busy teams handling high volumes of correspondence, the appeal is obvious.

But here is the problem: most businesses that have staff using it have no idea what data it is accessing, where that data goes, or whether it complies with UK GDPR. This guide sets out what every UK business owner and IT decision-maker needs to understand before this tool goes any further in your organisation.

What Does the ChatGPT Outlook Add-In Actually Do?

The ChatGPT Outlook add-in integrates OpenAI’s large language model directly into Microsoft Outlook. Once installed, it can read email content, suggest replies, summarise conversations, and assist with drafting. It operates within the Outlook interface, which means it runs with whatever permissions the user has granted.

Employees typically install it because it genuinely saves time. AI-assisted email is useful. The issue is not the functionality — it is the data implications of that functionality, and whether your business has properly assessed them before deployment.

What Data Can It Access?

⚠️ Important: The ChatGPT Outlook add-in can access substantially more than just the email you are currently drafting. When granted full permissions, it can read incoming and outgoing email content (including historical messages), attachments and files within those emails, calendar data and meeting details, contact information and distribution lists, and any documents uploaded or shared via connected Microsoft 365 services. In practice, this means a single staff member installing the add-in could expose client correspondence, internal financial discussions, HR communications, and strategic documents to an external AI service — without your knowledge or explicit sign-off.

This is not a hypothetical risk. The permissions are real, the data transfer happens in real time, and the implications for your business depend entirely on which account type your employees are using.

The Critical Distinction: Personal vs Business/Enterprise Accounts

This is the most important thing to understand, and it is the point that most IT teams miss. The data handling rules for ChatGPT differ significantly depending on whether your staff are using a personal OpenAI account or a Business/Enterprise subscription.

“By default, we may use content you provide us to train our models. You can opt out of model training at any time from your account settings. If you use the API or are on a ChatGPT Enterprise or Team plan, we do not train on your content by default.”

— OpenAI Privacy Policy (August 2026)

What this means in practice: if your employees install the ChatGPT Outlook add-in using their personal OpenAI accounts (which the majority do, because it is free and quick to set up), the email content they process through it may be used to train OpenAI’s AI models — unless they have manually opted out. Most users have not opted out, because they do not know the setting exists.

If your business has a ChatGPT Team or Enterprise subscription, training on your data is off by default. But if individual employees are using free personal accounts — as is extremely common — you have no such protection, and you almost certainly have no data processing agreement in place with OpenAI either.

Four Key Risks Every Business Must Address

1. Uncontrolled Personal Account Use by Employees

The most common scenario we see is employees installing the add-in on their own initiative using personal free accounts. They do this because it is useful, not because they intend to cause harm. But from a data governance perspective, this represents unmanaged data egress. Your business data is leaving your controlled environment and being processed by a third-party service under terms you have not reviewed and did not agree to on behalf of your organisation.

2. UK GDPR Data Processing Obligations

Under UK GDPR, your business is a data controller. When you use a third-party service to process personal data — including client emails, employee details, or any personally identifiable information — that third party becomes a data processor. You are legally required to have a Data Processing Agreement (DPA) in place with them, and you must ensure their security measures are adequate.

If employees are using personal ChatGPT accounts to process business data, you almost certainly have no DPA with OpenAI. If OpenAI processes or stores that data in the US (which it does), you need to ensure the transfer meets UK international data transfer requirements under the UK GDPR framework. Most businesses using the add-in informally have not addressed any of this.

3. AI Model Training Using Company Data

As OpenAI’s own policy confirms, personal account data may be used for training. This means confidential client correspondence, business strategy discussions, financial information, and sensitive HR communications could, in theory, become part of the data used to improve OpenAI’s models. Even if specific data is anonymised during training, the fact that it has been transmitted to and processed by an external service is itself a compliance issue under UK GDPR.

4. Shadow AI and Unmanaged Usage

Perhaps the greatest long-term risk is not any single incident but the broader pattern of shadow AI adoption. When employees discover useful tools independently and use them without IT or compliance oversight, you lose visibility into where your data is going. Shadow AI is the AI equivalent of shadow IT — and it is growing rapidly in UK workplaces. Without a clear policy and technical controls, the ChatGPT Outlook add-in is just the start.

High-Risk Data Categories to Watch

🔴 Client & Customer Data

  • Client email correspondence
  • Case details and personal information
  • Contract and agreement content
  • Complaint and dispute records

🔵 Financial & Commercial Data

  • Invoice and payment discussions
  • Pricing and margin information
  • Budget and forecast data
  • Bank and account references

🟡 HR & People Data

  • Employee personal details
  • Salary and benefits correspondence
  • Performance and disciplinary records
  • Recruitment communications

🟢 Internal & Strategic Data

  • Business strategy discussions
  • Supplier and partner negotiations
  • M&A and investment conversations
  • Intellectual property and trade secrets

Any of these categories passing through a personal ChatGPT account represents a data breach risk, a UK GDPR compliance failure, or both.

Pre-Deployment Checklist: Before You Allow the Add-In

If you are considering officially deploying the ChatGPT Outlook add-in — or if you want to get control of employees who are already using it — work through the following checklist.

Action Required Details Priority
Audit current usage Identify which staff are already using the add-in and which account type (personal vs Enterprise) Critical
Review OpenAI’s DPA Obtain and review OpenAI’s Data Processing Agreement; ensure it covers your use case Critical
Disable personal account use Use Microsoft Intune or Group Policy to restrict add-in installation to approved accounts only Critical
Upgrade to ChatGPT Team/Enterprise Enterprise plan disables model training on your data by default and includes a DPA High
Update privacy policy and ROPA Add AI tool usage to your Record of Processing Activities; update client-facing privacy notices High
Conduct a DPIA Data Protection Impact Assessment required if processing special category or high-risk data with AI High
Train staff on AI data risks Ensure all employees understand what they can and cannot process through AI tools Medium
Publish an AI usage policy Document approved AI tools, permitted use cases, and prohibited data types Medium

How Pro Business Helps

The ChatGPT Outlook add-in is a genuine productivity tool — but only when deployed correctly, with the right controls in place. The problem is that most businesses do not have the internal expertise to assess the data protection implications, configure Microsoft 365 correctly to restrict personal account use, or draft the policies required to remain UK GDPR compliant.

Pro Business works with UK businesses to make AI adoption safe and compliant. Our security solutions include AI readiness assessments, Microsoft 365 configuration reviews, UK GDPR compliance support, and staff training on AI data risks. We help you get the productivity benefits of tools like ChatGPT without the legal and reputational exposure that comes from unmanaged adoption.

We can audit your current Microsoft 365 environment, identify whether the ChatGPT add-in is already in use across your organisation, assess your data protection obligations, and implement the technical controls needed to protect your business — all without disrupting the tools your staff are already using.

If you are not sure whether your business is exposed right now, that uncertainty is itself a risk. Get in touch for a straightforward conversation about where you stand.

Is Your Business Exposed Right Now?

If you have staff using the ChatGPT Outlook add-in — or any AI tool — without a formal policy or data processing agreement in place, you may already be in breach of UK GDPR. We can assess your risk and implement the controls needed to protect your business.

Call: 0161 519 0764 | Email: info@pro-business.co.uk

View Our Security Solutions →


Related reading: If your business is using Microsoft Copilot, the data access and compliance questions are similar — and in some respects more significant given Copilot’s deeper Microsoft 365 integration. Read our guide: Microsoft Copilot: What Every UK Business Owner Needs to Know Before You Switch It On.

Microsoft Authenticator: The Complete Guide for Business Users

Passwords alone are no longer enough. With phishing attacks, credential stuffing and brute force attempts hitting businesses every day, relying on a password is a bit like locking your front door but leaving the window wide open.

That is where multi-factor authentication (MFA) comes in. And Microsoft Authenticator is one of the simplest, most reliable ways to get it set up across your organisation.

This guide covers everything business users need to know: what it is, how it works, how to use it day to day, what to do when things go wrong, and how to stay safe from a growing threat called MFA fatigue.

What Is Microsoft Authenticator?

Microsoft Authenticator is a free app for iOS and Android that adds a second layer of security to your Microsoft 365 account (and many other services). When you log in, you are not just asked for your password. You also have to prove it is really you by approving a notification or entering a short code from the app.

That second step is what makes it so effective. Even if someone gets hold of your password, they still cannot get into your account without your phone.

The numbers are stark: Microsoft’s own research shows that enabling MFA blocks more than 99.9% of automated account compromise attacks. For any business using Microsoft 365, enabling it is not optional. It is essential.

How Microsoft Authenticator Works

There are two main ways the app proves your identity:

  • Push notifications: When you sign in, a notification pops up on your phone. It shows you the app you are signing into, your location and a two-digit number that matches what is shown on your screen. Tap Approve and you are in.
  • One-time codes (TOTP): The app generates a six-digit code that refreshes every 30 seconds. You type this code into the sign-in screen. Useful when you do not have mobile data or if push notifications are unavailable.

Both methods are far more secure than SMS codes, which can be intercepted. The Authenticator app works offline and is tied to your specific device, making it much harder to spoof.

Setting It Up

Getting started takes about five minutes. The short version:

  • Download the Microsoft Authenticator app from the App Store or Google Play
  • Sign into your Microsoft 365 account at mysignins.microsoft.com/security-info
  • Add a sign-in method and select Authenticator app
  • Scan the QR code shown on screen
  • Approve a test notification to confirm everything is working

For a full walkthrough with screenshots, see our step-by-step setup guide.

If you are rolling MFA out across a team, your IT admin can enforce it through Azure Active Directory Conditional Access policies, so users are prompted to set it up automatically on their next sign-in.

Using It Day to Day

Once it is set up, Microsoft Authenticator mostly stays out of the way. You will typically only see it when signing into a new device, after a period of inactivity, or when accessing something sensitive.

Here is what a normal sign-in looks like:

  • Enter your email and password as usual
  • A notification appears on your phone
  • Check the two-digit number matches what is on your screen
  • Tap Approve
  • Done. You are in.

The whole thing takes about five seconds. Once you get used to it, it becomes second nature.

Managing Authenticator: New Phone and Backup Methods

The biggest gotcha with any authenticator app is: what happens when you get a new phone, lose your device, or it breaks?

The good news is Microsoft has thought about this.

  • Cloud backup: Enable the backup option in the app settings. On Android this uses your Google account; on iOS it uses iCloud. If you get a new phone, you can restore your accounts during setup.
  • Add a backup sign-in method: Go to mysignins.microsoft.com/security-info and add a secondary method, such as a backup phone number or email. This gives you a fallback if you cannot access the app.
  • Temporary access pass: If your IT admin has enabled it, they can generate a short-term passcode that lets you sign in and re-register your new device without needing the old phone.

The biggest mistake people make is waiting until they are locked out to think about this. Set up your backup methods now, while you still have access.

Common Issues and How to Fix Them

  • Notification did not arrive: Check your phone is connected to the internet and that notifications are enabled for the app. You can also use the one-time code as a fallback.
  • Code says it is invalid: Make sure your phone’s clock is set to automatic time sync. TOTP codes are time-sensitive and drift of even 30 seconds can cause failures.
  • App is not showing accounts: If you reinstalled the app without restoring from backup, you may need to re-add your accounts. Contact your IT admin if you are unable to sign in.
  • Locked out completely: Your IT admin can reset your MFA registration in the Azure portal, or issue a Temporary Access Pass to get you back in.

MFA Fatigue: A Real and Growing Risk

There is one attack you need to know about: MFA fatigue, sometimes called MFA prompt bombing.

Here is how it works. An attacker has already obtained your password (perhaps from a data breach or phishing). They then attempt to sign in repeatedly, sending a flood of approval notifications to your phone. The hope is that you will eventually tap Approve out of frustration or confusion.

Several high-profile breaches have happened this way.

How to protect yourself:

  • Never approve a notification you did not initiate. If a request appears and you are not actively signing in, deny it immediately.
  • Check the number match. Microsoft now shows a two-digit code that must match between the app and the sign-in screen. This means you cannot accidentally approve a request from an attacker.
  • Report unexpected requests. If you start receiving repeated sign-in requests you did not trigger, tell your IT team straight away. It likely means your password has been compromised and needs changing.

Why Businesses in Manchester and Beyond Need This Now

Cyber attacks on small and medium businesses are increasing every year. Ransomware, business email compromise and account takeovers are not just problems for large corporations. They hit local businesses hard, often with no warning.

Enabling Microsoft Authenticator across your team is one of the most cost-effective security steps you can take. It costs nothing (the app is free), takes minutes to set up, and stops the vast majority of automated attacks in their tracks.

Need Help Rolling It Out?

If you would like support setting up MFA across your business, migrating to Microsoft 365, or reviewing your overall cyber security posture, the team at Pro Business are here to help.

Get in touch at support@pro-business.co.uk or give us a call. We work with businesses across Manchester and the North West, and we will get you sorted without the jargon.

How to Set Up Microsoft Authenticator: Step-by-Step Guide

If your IT team or Microsoft has prompted you to set up multi-factor authentication (MFA), this guide will walk you through the whole process in plain English. It takes about five minutes and you will only need your phone and a computer.

What You Will Need

  • Your smartphone (iPhone or Android)
  • A computer or laptop signed into your Microsoft 365 account
  • Your Microsoft 365 email address and password

Step 1: Download the Microsoft Authenticator App

On your phone, open the App Store (iPhone) or Google Play Store (Android) and search for Microsoft Authenticator. It is free and published by Microsoft Corporation. Download and install it.

Once installed, open the app. You will be shown a welcome screen. You do not need to do anything in the app just yet.

Step 2: Go to Your Microsoft Security Settings

On your computer, open a browser and go to:

mysignins.microsoft.com/security-info

Sign in with your work Microsoft 365 account if prompted. You will see a page called Security info showing your current sign-in methods.

Step 3: Add the Authenticator App

  • Click Add sign-in method
  • From the dropdown, choose Authenticator app
  • Click Add
  • Click Next on the screen that explains what the Authenticator app does
  • On the next screen, click Next again. Microsoft will now show you a QR code on your screen.

Step 4: Scan the QR Code

Now switch to your phone:

  • In the Microsoft Authenticator app, tap the + button (top right on iPhone, or the add icon on Android)
  • Choose Work or school account
  • Choose Scan a QR code
  • Point your phone camera at the QR code on your computer screen

The app will scan it automatically and add your account. You will see your name and email address appear in the app.

Step 5: Allow Notifications

When prompted on your phone, allow the Microsoft Authenticator app to send you notifications. This is how it will notify you when you need to approve a sign-in. Without notifications enabled, the app will not be able to send you approval prompts.

On iPhone: tap Allow when iOS asks about notifications.

On Android: tap Allow when prompted.

Step 6: Approve the Test Notification

Back on your computer, click Next. Microsoft will send a test notification to your phone to confirm everything is working.

  • A notification will appear on your phone
  • It will show a two-digit number. Check that number matches what is shown on your computer screen
  • Tap Yes or Approve on your phone

Your computer will confirm that the app is set up. Click Next and then Done. That is it. You are set up.

Using Microsoft Authenticator Day to Day

Once it is configured, here is what happens each time you sign in:

  • Enter your email and password as normal
  • A notification appears on your phone with a two-digit number
  • Check the number matches what is on your screen
  • Tap Approve
  • You are signed in

If you do not have mobile data or the notification does not arrive, open the Authenticator app and use the six-digit code shown under your account. Type that code into the sign-in screen instead. The code refreshes every 30 seconds.

Getting a New Phone

Before you get a new phone, do two things:

  • Enable cloud backup in the Authenticator app settings (Google account on Android, iCloud on iPhone)
  • Add a backup sign-in method at mysignins.microsoft.com/security-info, such as an alternative phone number

When you set up your new phone, install the Authenticator app and restore from your backup. Your accounts will be transferred. If you get stuck, your IT admin can reset your MFA registration so you can start fresh.

Need Help?

If you ran into any problems during setup, or if your business needs help rolling out MFA across the whole team, the Pro Business team are here for you.

Drop us an email at support@pro-business.co.uk and we will get you sorted. We support businesses across Manchester and the North West with Microsoft 365, cyber security and IT support.