← Latest papers
💻 computer science

Chat First, Worry Later: Understanding Individuals' Privacy Perceptions Using ChatGPT in a Work Context

A user study of 224 professionals reveals that while organizational policies positively correlate with ChatGPT proficiency, overall proficiency remains low, and heightened privacy concerns significantly reduce both the frequency and diversity of ChatGPT usage, particularly in organizations lacking specific GenAI guidelines.

Original authors: Christoph Nirschl, Magdalena Glas, Gerhard Messmann, Günther Pernul

Published 2026-08-24
📖 4 min read☕ Coffee break read

Original authors: Christoph Nirschl, Magdalena Glas, Gerhard Messmann, Günther Pernul

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the modern workplace, a new kind of helper has arrived, one that can write emails, summarize reports, and draft code with a speed that feels almost human. This helper is a generative artificial intelligence tool, a type of computer program trained on vast amounts of text from the internet. These programs, often called large language models, work by predicting what word should come next in a sentence, allowing them to generate coherent and useful responses to almost any question. While these tools promise to make work easier and faster, they come with a hidden cost: the information you type into them might not stay private. Because these systems are trained on data that includes personal details, there is a real risk that sensitive information about patients, customers, or colleagues could be accidentally revealed or stored in ways that compromise security. This creates a difficult situation for workers who want to use these tools for efficiency but fear the consequences of sharing too much.

To understand how people navigate this tension, researchers at the University of Regensburg in Germany conducted a study with 224 professionals from various industries, including IT, healthcare, and education. They wanted to see how three specific things influenced whether people used these tools and how they used them: the rules set by their employers, their own personal worries about privacy, and how well they actually understood how the tool handled their data. The researchers found that when organizations had clear guidelines about using these tools, their employees knew more about how the technology worked. Specifically, workers in companies with policies were better at answering questions about how the tool stored and processed information. However, even with these rules, the overall level of understanding among all participants was quite low, with most people getting only about one-third of the facts right.

The study revealed a clear pattern in how people behaved. Those who were deeply worried about privacy used the tools less often and stuck to a narrower range of tasks. This hesitation was most pronounced among workers whose companies had no rules at all; in the absence of official guidance, these individuals relied entirely on their own fears and knowledge to decide what was safe. In contrast, for workers in organizations with established policies, their personal level of worry did not seem to change how often they used the tool or what they used it for. The rules themselves seemed to provide a sense of structure that allowed them to use the technology more broadly, regardless of their personal anxiety. Interestingly, the researchers found that the specific type of rule—whether it restricted who could use the tool or how it could be used—did not make a significant difference in behavior. The mere presence of a policy appeared to be the most important factor in shaping how employees engaged with the technology.

One of the most striking findings was a widespread misunderstanding about how these tools protect data. Nearly all the participants in the study believed that the information they typed into the chat was automatically hidden or anonymized to protect their identity. In reality, the tool's standard settings do not guarantee this, and the data can be used to train future versions of the system. This gap between what people think is happening and what is actually happening suggests that many workers are using these powerful tools while operating under false assumptions about their safety. The researchers concluded that while organizational policies help people understand the technology better, they do not automatically fix the underlying lack of knowledge. Without clear, accurate information, even well-intentioned workers may continue to expose sensitive data, not because they are careless, but because they simply do not know the risks are real.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →