Signing into your ChatGPT or Claude account on a work laptop feels private, but the monitoring software lives on the device and keeps watching wherever you carry it. You have likely already consented, through the employment contract, the IT induction and the compliance training you clicked through without reading. The larger risk is not being watched but what you might be caught doing: pasting confidential data into an unauthorised AI account can turn a privacy grievance into a misconduct case.
What Wocult found?
The habit is almost invisible. A summary here, a rewritten email there, a difficult message softened before it goes to a manager. Most people reaching for ChatGPT or Claude during the working day are not being reckless. They are being efficient, and they are using the tool they already know rather than the sanctioned one their employer quietly rolled out. That instinct is the whole problem.
Why does a personal account feel so private?
Because signing in feels like closing a door. The account is yours, the password is yours, the history sits under your name. But privacy at work has never turned on whose account you use. It turns on whose machine you use, and increasingly on whose network. A company laptop is the decisive factor, because the monitoring software lives on the device itself and keeps watching wherever you carry it, including your own home broadband. The network matters as a second layer: route your traffic through the company VPN and the employer can see more, work on a personal device over your own home wifi and they can usually see far less. The personal login changes none of this. It only changes how protected you feel while the same systems watch.
What can an employer actually see?
More than most staff assume. Company devices increasingly run data-loss prevention tools and web proxies that can read what passes through the browser, and some run screen or keystroke logging on top. To that software, a personal chatbot tab is simply another window. In India, the older statutes have long permitted this. The Information Technology Act allows monitoring of information transmitted, received or stored on a company device where there is a legitimate business purpose, and the practical rule is that anything done on a work computer can be reached by the employer.
So is any of this legal?
Largely, yes, but the rules have tightened. The Digital Personal Data Protection Act now treats employee data as personal data, which means monitoring has to be disclosed, tied to a defined purpose and kept proportionate. Covert keystroke logging without notice creates real legal exposure. Indian employees also hold a fundamental right to privacy under Article 21, confirmed by the Supreme Court in the Puttaswamy judgment, though that right is not absolute at work. The pattern across 2026 is consistent: monitoring is permitted when it is declared and reasonable, and risky when it is secret or sweeping. For anyone whose work touches American or European systems, the American ECPA and the European GDPR add their own notice and proportionality demands.
But how is any of this disclosed?
Usually long before the monitoring starts, and rarely in a form you remember. The disclosure is almost never a pop-up on the day your chats are read. It is buried in the things you clicked through when you joined, or during a training module you rushed to finish. The employment contract you signed on day one very likely contained a monitoring or acceptable-use clause. The online IT induction had an 'I agree' button at the end. So did the annual compliance training your employer nudges you to complete every year, the one you clicked through between meetings. Many companies also place a consent gate on the network itself, so that sharing data with an external site produces a quiet 'I agree' the moment you proceed. Each of these is legally treated as your notice and, often, your consent. By the time you paste something into a personal chatbot, you have usually agreed to be watched several times over, without ever feeling like you did.
And the confidential data you paste in?
This is the half of the story that outlives the privacy worry. The sanctioned tool your company issued exists for a reason. Enterprise AI is meant to keep prompts out of the training pool and inside a contractual boundary. A personal account carries no such promise. When you paste a client contract, a salary sheet or an unreleased plan into a consumer chatbot, that information leaves the perimeter the enterprise licence was built to hold, and there is no clean way to pull it back. Employers know how valuable that human input has become. Meta has publicly confirmed that it tracks staff keystrokes, clicks and screen activity to train its own AI agents, on the reasoning that models learn best from watching people work. The lesson for everyone else is simpler: what you feed a chatbot is rarely as disposable as it feels.
Could this get you sacked?
It could, and this is where the risk turns sharper than the surveillance worry that opens the story. Sharing confidential data through an unauthorised AI account usually breaches the confidentiality clause, the acceptable-use policy and often a data-protection undertaking all at once, and an employer does not need the leak to have caused visible harm. The act of exposing the data is generally enough. What tends to decide a warning from a termination is the sensitivity of the data, whether it was a first slip or a pattern, the employee's seniority and any sign of intent. For staff who qualify as workmen under the Industrial Disputes Act, a domestic inquiry and a chance to respond are usually expected before dismissal, so the outcome is rarely instant. But the reframing matters: being watched feels invasive, yet it seldom ends a career, whereas handing confidential data to an unsanctioned tool can, because it casts the employee as the one who breached an obligation.
What should a sensible employee do?
Use the tool the company sanctioned, even when the personal one is faster, because that is where the data boundary sits. Read the acceptable-use policy and the employment contract, since they usually spell out exactly what is monitored. Keep genuinely personal thoughts off the work machine altogether. And treat any AI window on a company device the way you would treat a work email, which is to say, never quite private.
The reassuring click of a personal login is the trap. On a company laptop, that login protects far less than it promises, in both directions at once. It does not keep your confidential work inside the walls, and it does not keep your private words out of view.
The legal view
Everything above is Wocult's reporting: what employers can reach in practice, what the statutes permit, and where the industry is heading. On the narrower legal question of what a company may lawfully see, use or share once an employee's use is genuinely private, we put two questions to counsel. The answers draw the line more tightly than practice does.
Wocult : When an employee uses their own ChatGPT or Claude account on a company laptop, how much privacy do they realistically have under Indian law, and what is the single thing you would advise them to change about that habit?
Ajay Veer Singh, Advocate, Supreme Court of India : The missing detail here is the arrangement between the employee and the company. Generally, the company monitors and carries out surveillance of communication on the company laptop to protect the company's data. That should only allow the company to see the output mediums, such as pen drive activity, emails and Bluetooth transfers. But if company personnel venture into monitoring private usage from the laptop, there is no way to know they are doing it.
The right to privacy is a fundamental right protected by Articles 21, 14 and 19 of the Constitution of India. The nine-judge bench of the Supreme Court in K.S. Puttaswamy v. Union of India held that privacy is essential for human dignity, individual autonomy, freedom of thought and expression and the freedom to make personal choices.
Legally, the company cannot see, use or share the private information of the employee, as it is protected by the Constitution under Articles 21, 14 and 19.
My advice to employees and to the corporate world is to avoid this situation by using company laptops strictly for official purposes, since they are monitored by the company as a policy to protect its data. Employees should use their personal laptops for their private work.
Wocult : On a work laptop, does logging into a personal AI account give an employee any real privacy, and if they paste confidential data into it, can that lawfully cost them their job?
Ajay Veer Singh, Advocate, Supreme Court of India : There is no real privacy if an employee uses a personal AI account on a company laptop, and there is no way even to know it.
But an employee cannot put confidential data into the AI because it then comes onto a public platform and can be accessible to anyone through the AI service.
That would be a violation of the data protection law and may cost the employee their job, depending on the circumstances.
Sources
- The Constitution of India, Articles 21, 14 and 19. Fundamental right to privacy.
- K.S. Puttaswamy (Retd.) v. Union of India, Supreme Court of India, nine-judge bench, 2017. Right to privacy held to be intrinsic to Article 21.
- The Information Technology Act 2000. Monitoring of information transmitted, received or stored on a company device for a legitimate business purpose.
- The Digital Personal Data Protection Act 2023. Rules notified 13 November 2025, with enforcement phased through to 13 May 2027. Treatment of personal data, disclosure, purpose limitation and proportionality.
- The Industrial Disputes Act 1947. Domestic inquiry and an opportunity to respond, usually expected before the dismissal of a workman.
- The Electronic Communications Privacy Act (United States) and the General Data Protection Regulation (European Union), for work that touches those systems.
- Reuters, April 2026, first reporting on Meta's Model Capability Initiative, with subsequent coverage by CNBC and Fortune. Meta tracking employee keystrokes, clicks and screen activity to train AI agents.
- Legal opinion: Ajay Veer Singh, Advocate, Supreme Court of India and Managing Partner, BSJ Legal Law Offices, in conversation with Wocult.




%20(1).png)

.png)






