AI on an internship or apprenticeship: what’s allowed, what isn’t
Career9 min read · 27 September 2026
First day of your internship. You’re asked for meeting minutes, a summary of some documentation, a fix in a piece of code. Your student reflex: open an AI assistant or an online translator and paste the document. That exact move gave Samsung one of the most cited leaks of the generative AI era. Here’s what you can do, what you must never do, and how to talk to your supervisor about it before it becomes a problem. The examples come from France and the EU, but the reasoning travels to any workplace.
In short: you can use AI during an internship or apprenticeship, within the rules set by the company: its AI policy, its approved tools, your internship agreement or employment contract. The golden rule, spelled out by France’s data protection authority (CNIL) and its national cybersecurity agency (ANSSI): never paste company data (internal documents, code, customer files, minutes) into a consumer AI tool, even with training switched off. The EU AI Act doesn’t stop you from getting help with an email; it mainly targets high-risk uses such as recruitment tools. For your internship report, your school’s rules apply: AI can coach you, not write it for you, and you declare how you used it.
The real risk: pasting company data
The Samsung case
In 2023, according to the Korean outlet The Economist Korea, as reported by Engadget, Samsung employees sent sensitive information to ChatGPT on three occasions: database source code to check for errors, code to optimize, and a recorded meeting to turn into minutes. Samsung then restricted generative AI tools on its devices and internal networks, noting that data sent to an external service is hard to retrieve and delete (TechCrunch).
Nobody hacked Samsung. Engineers wanted to save time with a handy tool. That’s what makes the story useful to you: the most likely leak during an internship is you, acting in good faith.
Why it matters, even without a hacker
ANSSI puts it in one sentence: sending information (text, images, documents) to a consumer generative AI service amounts to depositing that information in a storage space that belongs to the provider (ANSSI, April 2024). Its recommendation R34: ban these tools for any professional use involving sensitive data. It names ChatGPT, Gemini, Copilot, Perplexity and DeepL: online translators count too.
And the provider itself isn’t infallible. In March 2023, a bug let some ChatGPT users see the titles of other users’ conversations (OpenAI). In July 2025, conversations shared via link showed up in Google and other search engines; OpenAI ended the experiment that made this possible (TechCrunch).
“I turned off training, so it’s fine”: no
Consumer plans often let you choose whether your conversations train the models: the “Improve the model for everyone” setting at OpenAI (OpenAI); at Anthropic, since 28 August 2025, Claude Free, Pro and Max users make that choice, with five-year retention if they opt in and 30 days otherwise (Anthropic). Business plans work differently: OpenAI says “We do not train our models on your data by default” for ChatGPT Business, Enterprise, Edu and its API (OpenAI).
But switching off training doesn’t solve the core issue: the data still leaves the company, for a service it didn’t choose and has signed nothing with. It isn’t your call to decide that’s acceptable.
What counts as “company data”?
More than you think. A few examples by field:
| Field | Never in a consumer tool | Risk-free version |
|---|---|---|
| Engineering, manufacturing | Drawings, specifications, test results, quality reports | A textbook question: “how do I read a fatigue curve?” |
| Computing | Proprietary code, logs, API keys, database schema | A minimal example you rewrote yourself, with no internal names |
| Marketing, sales | Customer files, unpublished campaign figures, strategy | A method, such as structuring an A/B test, on made-up data |
| Healthcare (placement in a hospital or clinic) | Anything about a patient, even without a name | A fictional or published case |
| Design, communications | Confidential client mockups, embargoed press releases | A fictional brief, your own non-confidential drafts |
| Everywhere | Minutes, internal emails, org charts, screenshots of internal tools | An empty minutes template |
What your contract, the AI policy and the CNIL say
You’re bound by the company’s rules
In France, an intern isn’t an employee but must follow the host organization’s rules, and the internship agreement lists the internal regulations that apply (Service-public.fr). An apprentice signs an employment contract (Service-public.fr): you’re an employee, with the same internal rules as your colleagues. Interning in another country? The logic is the same: your agreement and the company’s policies set the rules. For pay in France, see our article on internship stipends and apprentice wages in 2026.
The CNIL recommends AI policies, and one simple rule
In its Q&A on generative AI published on 18 July 2024, the CNIL recommends that every organization frame these tools with internal policies or charters that clearly define authorized and prohibited uses (CNIL). For users, the rule fits in one line: submit only information you are authorized to share. The CNIL cites personal data and company data, especially data covered by trade secrets, as information never to share in a consumer service.
Two more points in that text concern you directly. First, the CNIL advises never reproducing these systems’ outputs as they are. Second, it notes that the organization generally bears legal responsibility when its staff misuse AI. That’s why your company has rules: it pays for the damage.
For your personal use, in May 2026 the CNIL and its South Korean counterpart published a six-question poster: check training settings, use temporary mode, avoid sharing private information, double-check important answers (CNIL).
The reality on the ground: bring your own AI
According to Microsoft and LinkedIn’s 2024 Work Trend Index, which surveyed 31,000 people in 31 countries, 75% of knowledge workers use AI at work, and 78% of those users bring their own AI tools (Microsoft). That’s exactly what company policies try to rein in. You arrive with student habits: now is the time to adjust them.
The AI Act, briefly and without the myths
The EU regulation on AI entered into force on 1 August 2024 and has applied since 2 August 2026, with exceptions (European Commission):
- since February 2025, some practices are banned, including emotion recognition in workplaces and educational institutions;
- AI tools used for employment and worker management, such as CV sorting, are classed as high-risk; following the agreement on simplifying the text (the “AI Omnibus”), their obligations apply from 2 December 2027;
- transparency rules come into effect in August 2026: some generated content, such as deepfakes, must be clearly labelled.
What this means for you: the AI Act doesn’t forbid you from asking an assistant to help draft an email. Your day-to-day rules come from the company policy, your agreement or contract, the GDPR and confidentiality. If you work in communications or marketing and publish generated visuals, ask which labelling rule your team follows.
Good uses, with your supervisor’s agreement
- Writing an email: structure, tone, sign-off, follow-up. The mail-pro skill offers several tones; strip out any internal detail first.
- Rephrasing your own non-confidential writing for clarity.
- Summarizing public documents: a published standard, a tool’s official documentation, a scientific article.
- Learning a tool: a spreadsheet formula on made-up data, a Git command, a CAD or statistics concept.
- Coding, if allowed: with the tool the company provides, never with keys or credentials in a prompt, and reviewing everything you merge.
- Preparing what’s next: practice interviews with simulation-entretien, update your profile with profil-pro or prepare your next application with lettre-alternance.
Bad uses
- Pasting an internal document, a customer spreadsheet, proprietary code, minutes or a screenshot of an internal tool into a consumer tool.
- Translating an internal document with an online translator.
- Having a consumer app transcribe or summarize a meeting.
- Handing in generated work you haven’t reread and checked.
- Using your personal account for work: the CNIL advises against accounts created with personal email addresses.
- Hiding that you had help.
Talking to your supervisor or apprenticeship mentor
Many people don’t dare: according to the same Microsoft report, 52% of people who use AI at work are reluctant to admit using it for their most important tasks. Yet supporting you is your supervisor’s job: in France, the internship supervisor guarantees the learning objectives set in your agreement (Service-public.fr), and the apprenticeship mentor is directly responsible for your training (Service-public.fr).
In your first week, ask four questions:
- Is there an AI policy or charter?
- Which tools am I allowed to use, and with which account?
- Which data is off-limits, even in the approved tool?
- Should I flag when a deliverable was prepared with AI help?
A phrasing that works: “I sometimes use an AI assistant to structure an email or understand a tool, never with internal documents. Is that OK with you, and are there rules I should know about here?” You come across as careful, not as someone cutting corners.
The internship report: AI as a coach, not a ghostwriter
Your report is graded work: your school’s rules apply on top of the company’s. The University of Angers policy is a good example: agreement from the teacher or supervisor, no sharing of the host company’s internal data, a dedicated section declaring how AI was used, and no fabricated data (Université d’Angers). We compare other policies in our article on academic integrity.
A method that holds up:
- Keep an internship log: what you did, learned, got wrong, in your own words, with no confidential information.
- Build your outline yourself, then ask the AI to challenge it.
- Write, then get feedback: the AI asks questions (“what concrete result?”, “for whom?”), you make the fixes.
- Have your supervisor approve what can go in the report: it may contain information the company doesn’t want circulating.
- Declare your AI use following your school’s instructions.
That’s how the rapport-de-stage skill works: a standard outline, an internship log, feedback on your draft, and never the report written for you.
What this changes for you, concretely
- On day one, ask for the AI policy and the list of approved tools.
- Nothing internal in a consumer tool, translators included, even with training off.
- Unsure about some data? Ask before, never after.
- Reread and check everything AI produces before passing it on.
- Tell your supervisor how you use it.
- For the report: your log, your outline, your words; AI rereads and questions, and you declare it.
FAQ
Am I allowed to use ChatGPT during my internship?
No law bans it as such, but the company sets the rules: AI policy, approved tools, internal regulations that apply through your agreement. Ask your supervisor early on, and never use a consumer tool with internal data.
If I switch off training, can I paste company documents?
No. The data still leaves the company for a third-party service it didn’t choose. ANSSI recommends banning consumer generative AI tools for any professional use involving sensitive data.
Can AI write my internship report?
No, it’s graded work. AI can help you structure, review and question your draft, but the writing is yours and the use is declared according to your school’s rules. Don’t give it any of the company’s internal data.
Does the AI Act forbid me anything as an intern?
Not for everyday use like an email. It bans certain practices, such as emotion recognition at work, and regulates high-risk systems such as recruitment tools. Your daily rules mostly come from the company, the GDPR and confidentiality.
What’s the risk if I paste confidential data?
For the company, a leak it may not be able to undo, as Samsung pointed out. For you, whatever your agreement or contract and the internal regulations provide for, and above all a loss of trust with your team. When in doubt, ask first.
Further reading
- The rapport-de-stage skill: outline, log and feedback, without writing the report for you.
- Internship stipends and apprentice wages in 2026: the official French amounts, with worked examples.
- The mail-pro skill: clean professional emails, in several tones.
- AI and academic integrity: what university policies really say.
Sources
- Three Samsung employees reportedly leaked sensitive data to ChatGPT — Engadget · accessed 27 September 2026
- Samsung bans use of generative AI tools like ChatGPT after April internal data leak — TechCrunch · accessed 27 September 2026
- Recommandations de sécurité pour un système d’IA générative — ANSSI · accessed 27 September 2026
- March 20 ChatGPT outage: Here’s what happened — OpenAI · accessed 27 September 2026
- Your public ChatGPT queries are getting indexed by Google and other search engines — TechCrunch · accessed 27 September 2026
- Data controls in ChatGPT — OpenAI Help Center · accessed 27 September 2026
- Updates to Consumer Terms and Privacy Policy — Anthropic · accessed 27 September 2026
- Enterprise privacy at OpenAI — OpenAI · accessed 27 September 2026
- Stage d’un étudiant en milieu professionnel — Service-public.gouv.fr · accessed 27 September 2026
- Contrat d’apprentissage — Service-public.gouv.fr · accessed 27 September 2026
- Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative — CNIL · accessed 27 September 2026
- Generative AI and privacy: a poster jointly produced by the PIPC and the CNIL — CNIL · accessed 27 September 2026
- AI at Work Is Here. Now Comes the Hard Part (2024 Work Trend Index) — Microsoft and LinkedIn · accessed 27 September 2026
- AI Act — Shaping Europe’s digital future — European Commission · accessed 27 September 2026
- Charte d’utilisation de l’IA générative — Université d’Angers · accessed 27 September 2026






