OpenLot Book audit
Compliance

ChatGPT at a Dealership: Fine Here, Not There

OpenLot 9 min read

ChatGPT is already in use at most dealerships, usually without a policy. The useful division is three zones: internal work with no customer data, which is fine; customer-facing output, which needs review; and customer data in a prompt, which is where your Safeguards Rule obligations start.

Three-zone diagram showing safe, review-required and prohibited uses of ChatGPT at a car dealership based on customer data exposure

This guide covers the three usage zones, which dealership tasks fall into each, what must never enter a prompt, why the consumer version is the specific problem, and the policy a store needs in writing.

Why does a dealership need a position on this at all?

Because staff are already using it, and the default state — no policy, no approved tool, no stated boundary — is the one that creates exposure.

A salesperson pasting a customer's email into a consumer chatbot to get help with a reply has made a decision about where your customer's data goes. They made it without guidance, under time pressure, with no idea that the FTC Safeguards Rule treats your customer information as something you are accountable for protecting wherever it ends up.

The answer is not a ban. Bans in this category are not observed, they are just unwritten. The answer is three zones and an approved tool.

What are the three zones?

Zone Rule Examples
Green — internal, no customer data Use freely Drafting a job post, summarising a vendor contract, writing a process doc, explaining a DMS error message
Amber — customer-facing output, no customer data in Use, but a person reviews and sends Vehicle description drafts, ad copy, a template follow-up sequence, an objection-handling script
Red — customer data in the prompt Only in an approved, contracted tool Anything containing a name, phone, email, address, VIN tied to a buyer, credit or payment information, or a deal structure

The boundary between amber and red is not what the output looks like. It is what went in. Drafting a generic follow-up template is amber. Pasting the actual thread with the customer's name and the numbers you discussed is red, and it is red even if the output is identical.

The question that resolves most cases

Could I read this prompt aloud in the showroom without identifying a customer?

If yes, it is green or amber. If no, it is red and belongs in a tool your store has a contract with.

Which tasks fall where?

Green — genuinely useful and low risk. Explaining an error message, drafting internal process documentation, summarising a long vendor proposal, producing a first draft of a training outline, writing a spreadsheet formula, rewriting a policy for clarity. This is most of the value staff get from it, and none of it touches a customer.

Amber — useful, needs a human before it ships. Vehicle description drafts, marketing copy, a follow-up sequence template, scripts for common objections. The review is not optional, for two reasons: generic AI copy reads as generic AI copy to customers, and claims about a vehicle need to be true.

Red — do not do this in a consumer tool. Pasting a customer thread for help replying. Summarising a credit application. Analysing a deal structure with real numbers. Uploading a CRM export "to find patterns." Each of these transmits customer information to a third party your store has no agreement with.

The red zone is not theoretical. A CRM export pasted into a chat window is a transfer of exactly the kind of data the Safeguards Rule obligates you to inventory, control access to, and contract for when a service provider handles it. It is also worse than it looks, because a CRM export carries the free-text notes nobody remembers writing.

Why is the consumer version specifically the problem?

Three differences that matter, and they are contractual rather than technical.

No agreement covering your data. A business account with appropriate terms establishes a relationship in which the provider handles data under conditions you agreed to. A personal account, logged in with someone's own email, does not. Your obligations do not transfer; they simply go unmet.

No access control or audit trail. You cannot answer who put what customer information where, which is a question you may be required to answer. Personal accounts are invisible to you by design.

No retention control. You do not determine how long anything is kept, and you cannot delete it on request.

None of this makes the technology unsafe. It makes an unmanaged consumer account unsafe as a place to put customer data, which is a narrower and more fixable claim.

The practical remedy, in order

  1. Approve a tool with business terms, administered accounts and retention settings your store controls. This converts most red-zone usage into something defensible.
  2. Write the three zones down on one page, with examples from your actual workflows rather than generic ones.
  3. Name the prohibited items explicitly — customer name, contact details, address, VIN tied to a buyer, credit or financing data, deal numbers, CRM exports.
  4. Say what to do instead. "Describe the situation without the customer's details" is a usable instruction. "Do not use AI" is not, and will be ignored.
  5. Mention it in onboarding and once a quarter. A policy circulated once is a policy nobody remembers.

The tool approval is the step that does the real work. Everything else is documentation around it.

Where do dealership policies go wrong?

1. A ban with no approved alternative. Staff have a task and a deadline. If the sanctioned path does not exist, the unsanctioned one gets used and you lose visibility as well as control.

2. The policy is about the technology, not the data. "Do not use AI for customer communication" is the wrong axis. The risk is what enters the prompt, not what the output is used for.

3. Nobody distinguished the agentic case. A system that sends on your behalf is a different question entirely, governed by scope and escalation rules rather than by a usage policy — see where agent autonomy should end.

4. Amber output ships unreviewed. Vehicle descriptions generated and published without a human check produce claims about units nobody verified, which is an advertising problem before it is an AI problem.

5. The policy exists and nobody knows it. Written, filed, never circulated. Same practical effect as no policy, with the addition of documented awareness.

What should you put in writing?

Element Minimum content
Approved tool Named product, business terms, who administers accounts
The three zones With examples drawn from your own workflows
Prohibited data list Explicit field names, not "sensitive information"
Review requirement Who reviews amber output before it reaches a customer
Reporting What to do if customer data was pasted somewhere it should not have been
Review cadence Who revisits this, and how often

The reporting row matters more than it looks. Mistakes in this category are recoverable if they are disclosed quickly and unrecoverable if people are afraid to mention them.

Frequently asked questions

Can car dealerships use ChatGPT?

Yes, for a substantial range of internal work: drafting documentation, summarising vendor proposals, explaining system errors, writing training material and producing first drafts of marketing copy. The constraint is not the tool but the data — customer information should only go into a tool your store has a business agreement with, not a personal consumer account.

Is it safe to paste customer information into ChatGPT?

Not into a personal or consumer account. That transmits customer data to a third party your dealership has no contract with, no access controls over and no retention settings for, which conflicts directly with Safeguards Rule obligations to inventory and control customer information. In an approved business tool with appropriate terms, it becomes a managed arrangement.

What customer data should never go into a prompt?

Names, phone numbers, email addresses, physical addresses, a VIN tied to an identified buyer, credit or financing information, payment details, deal structures with real numbers, and any CRM or DMS export. The practical test is whether the prompt could be read aloud in the showroom without identifying a customer.

Should a dealership ban ChatGPT?

No, because bans without an approved alternative are not observed — they simply move usage out of sight and remove whatever visibility you had. The effective approach is to approve a tool with business terms, define three usage zones, name the prohibited data explicitly, and tell staff what to do instead of what not to do.

What is the difference between using ChatGPT and deploying an AI agent?

A usage policy governs what staff put into a tool and what they do with the output. An agent sends messages and takes actions on the dealership's behalf, which is governed by scope limits, escalation triggers and audit logging instead. The two need separate documents because the controls have nothing in common.

Can we use it to write vehicle descriptions?

Yes, as drafts, with a human review before publishing. Two reasons: generic AI copy reads as generic to shoppers and performs accordingly, and any specific claim about a unit has to be true, which means someone who can verify the vehicle needs to check it before it goes live.

Who should own the AI usage policy at a dealership?

Whoever owns compliance, typically the GM at a single store or the operations lead in a group, with input from whoever administers IT. The policy needs a named owner with a review cadence, because the tools and the terms change frequently enough that an unreviewed policy becomes inaccurate within a year.

What should an employee do if they already pasted customer data somewhere?

Report it immediately to the policy owner, which requires that the policy says so and that reporting is treated as the correct action rather than as an admission. Early disclosure allows deletion requests, account review and an assessment of what was exposed. Mistakes in this category are recoverable when disclosed quickly and much less so when discovered later.

Conclusion

  • Staff are already using it. No policy is a policy, and it is the worst one available.
  • Three zones, divided by what goes in, not by what the output is used for.
  • Approve a tool with business terms. That single step converts most of the risk into a managed arrangement.
  • Say what to do instead. A ban with no sanctioned path produces invisible usage rather than less usage.
  • Make reporting safe. A pasted CRM export is recoverable if someone says so the same day.

Last updated: