When Someone Quits, Does Their Claude or ChatGPT Account Leave With Them?
Every business I work with has an offboarding checklist. Disable the Microsoft 365 account. Revoke VPN and MFA. Collect the laptop. Forward the mailbox to a manager. Transfer file ownership. Change the shared passwords they knew.

Every business I work with has an offboarding checklist. Disable the Microsoft 365 account. Revoke VPN and MFA. Collect the laptop. Forward the mailbox to a manager. Transfer file ownership. Change the shared passwords they knew.
Almost none of them have a line on that checklist for AI.
So when someone gives notice, the account they've been using every day for the last year and a half (the one they signed up for with a personal Gmail address, on a personal credit card, and never told anyone about) just leaves with them. Along with everything they ever put into it.
What's actually in that account
This is the part that tends to land. Think about what a motivated employee has pasted into a chat window over eighteen months of trying to work faster:
Client contracts they wanted summarised. Pricing sheets they were building a proposal from. A spreadsheet of payroll figures they needed reformatted. Draft employment letters. Customer lists they wanted deduplicated. Meeting notes with names and numbers in them. A chunk of your codebase they were debugging. A vendor agreement they wanted the risky clauses pulled out of.
None of that was malicious. Every one of those is someone trying to do a good job. But collectively it's a copy of your business sitting in a system you don't own, can't see into, and have no way to switch off.
Four ways this actually bites
1. You can't revoke it. There is no admin console for you to log into. The account belongs to them. When they leave, for a competitor, on bad terms, whatever the circumstances, you have no mechanism to end their access to what they put in there. Your only real control is asking nicely.
2. You can't prove anything. When a client, an insurer or an auditor asks "what company data has been entered into AI tools?" the honest answer is "we don't know." And they are asking now. It's showing up in cyber insurance questionnaires and SOC 2 and HIPAA reviews, and "we don't know" gets written up as a finding.
3. Consumer tiers aren't built for your data. Business and enterprise plans come with contractual commitments that your conversations aren't used to train models, plus retention controls, admin visibility and audit logging. Free and personal-subscription tiers generally don't, unless an individual employee happens to have found and flipped the right setting. You're relying on a toggle you can't verify, in an account you can't see.
4. The knowledge walks out too, and this is the one people underrate. Your sharpest person didn't just chat with AI. They built things. Saved projects with your context loaded in. Prompts they refined over months that turn a two-hour task into ten minutes. That was a real productivity asset, paid for out of your payroll, and on their last day it disappears completely. The next person starts from zero and nobody ever writes down what was lost.
Banning it doesn't work
The instinct is to block it. Firewall rule, acceptable-use clause, done.
It doesn't hold. AI is on everyone's phone. It's built into the browser, the search bar and half the apps your team already uses. A ban doesn't stop the behaviour. It just pushes it somewhere you have zero visibility, and now nobody will tell you what they're using because they'd have to admit they broke the rule. You end up with all of the exposure and none of the information.
The businesses handling this well went the other direction entirely. They made it easy to do the right thing.
What "doing this properly" looks like
One approved platform, provisioned by the company. Claude for Work, ChatGPT Business or Enterprise, Microsoft Copilot: the specific choice matters less than the fact that the company owns the tenant. Roughly $25–$30 per user per month, which is less than most businesses spend per person on coffee.
Tied to your identity provider. Single sign-on through Microsoft Entra, so AI access is created and destroyed by the same process that handles email. When someone is offboarded, their AI access dies in the same click. That's the whole problem solved, structurally, rather than by remembering.
Admin controls that are actually yours. Retention settings you choose. Audit logs you can pull. The ability to see which teams are using it and for what. Contractual assurance your data isn't training anyone's model.
A written policy people can actually follow. One page. It should cover: which tools are approved, what data classes are permitted (and which are not: client PII, patient data, credentials, source code, financials), what output must be human-reviewed before it goes to a client, that AI use is not an excuse for an error, and who to ask when someone's unsure. Then it needs to be trained on and signed, not filed.
Amnesty on the way in. Tell people plainly: whatever you've been using up to now, no one's in trouble, we're moving everyone onto the company platform. You'll learn more about your real exposure in that one conversation than in any audit.
The resignation test
Here's how to check where you actually stand. Pick your most AI-fluent employee and ask four questions:
- If they resigned this afternoon, could you terminate their AI access in the same step as their email?
- Could you retain the projects, prompts and workflows they built for the business?
- Could you tell a client, in writing, what company data has gone into an AI tool this year?
- Is any of it covered by a contract that says your data isn't training a model?
If the answer to any of those is no, you don't have an AI problem. You have an unmanaged AI problem, and those two are very different things when something goes wrong.
Where to start
You don't need a committee or a six-month project. Start with the conversation: find out what your team is genuinely using today. Then pick one platform, provision it properly through your existing logins, write the one-page policy and move everyone over. For most small and mid-sized businesses that's a couple of weeks of work, not a quarter.
At Methodology IT this is a growing part of what we do, because AI is rapidly becoming the single largest piece of unmanaged IT inside otherwise well-run businesses.
If you want to see where you stand, we'll do a 30-minute AI exposure review: what's in use, where the data is going and what your policy should say. No charge.
Because the worst time to find out that your company's AI account belongs to someone else is the day they hand in their notice.
Keith Parker is the CEO of Methodology IT, a managed IT services provider in Los Angeles that has supported healthcare practices, nonprofits, and growing businesses across Southern California since 1997. His team handles security, compliance, and custom software, and increasingly the AI tools employees are already using.
Ready to make IT work?
No pressure, no sales pitch. A senior tech will walk your environment with you and leave you with a report, whether you hire us or not.
