In short: Your staff are already using AI on company data through personal accounts, they are hiding it deliberately, and a ban makes it invisible rather than absent - so the fix is to supply a sanctioned tool and a standard, fast.
You have not approved an AI tool. There is no line for it in the budget and no policy in the handbook.
Last Tuesday your bookkeeper pasted a payroll spreadsheet into ChatGPT to get a summary for a meeting. On Thursday someone in sales dropped three signed client contracts into a free AI tool to draft a renewal template. Nobody did anything malicious. Nothing broke. Nobody mentioned it.
That is shadow AI, and the reason it is dangerous is not that your staff are careless. It is that the usage is real, the data movement is real, and your visibility is zero.
Most advice on this ends at “write a policy” or “block the sites”. Both fail, and the research on why is unusually clear. Here is what the numbers actually show, and the plan we run with clients instead.
1. It is already happening in your business, and it is worse at your size
Microsoft and LinkedIn’s Work Trend Index (8 May 2024, 31,000 people across 31 countries) found that 78% of AI users bring their own AI tools to work - and that figure rises to 80% at small and medium-sized companies. Big enterprises procure. Smaller businesses improvise.
It has not settled down since. Netskope’s Cloud and Threat Report 2026, drawn from telemetry rather than a survey, found 47% of workplace generative-AI users reach those tools through personal, unmanaged accounts, and that the rate of AI-related data policy violations doubled over the year. The average organization now logs 223 such violations a month.
The gap, in one line
MIT’s State of AI in Business 2025 found that while only 40% of companies had bought an official LLM subscription, workers at over 90% of the companies surveyed reported regular use of personal AI tools for work. Treat the exact figures with care - the sample was 52 organizations and 153 leaders - but the shape of the gap matches everything else in this section.
Note what that means for your own estimate. If you asked your team today how many use AI on work tasks, you would get a number. The evidence says that number is low, and the next section explains why.
2. Why your staff hide it, and why that is not laziness
The largest study on this is KPMG and the University of Melbourne’s global AI trust research (April 2025, over 48,000 people across 47 countries). It found that 57% of employees admit hiding their AI use from managers and colleagues, with many presenting AI-assisted work as entirely their own. Only 47% had received any formal AI training.
Microsoft’s 2024 index found the same shape independently: 52% of people who use AI at work are reluctant to admit using it on their most important tasks.
This is a rational response to an incentive, not a character flaw. If nobody has told you AI is allowed, and your value at work is your output, then disclosing that a machine helped is pure downside. Microsoft’s 2026 index (5 May 2026, 20,000 knowledge workers) puts a finer point on it: 45% of workers say redesigning their own work with AI feels unsafe, and only 13% report being rewarded for doing it.
Your staff are not hiding AI use because they are reckless. They are hiding it because nobody told them it was safe to admit.
Which means the first thing a ban achieves is a stronger reason to conceal. You do not get less usage. You get less reporting.
3. What actually leaves the building
Cyberhaven’s 2025 AI Adoption and Risk Report is the most useful source here because it observes real usage across roughly 7 million workers rather than asking them. Published 23 April 2025, it found that 34.8% of the corporate data employees put into AI tools is sensitive - up from 27.4% a year earlier and 10.7% two years before that. The largest categories were source code and R&D material.
Harmonic Security analyzed 22,458,240 enterprise AI prompts across 2025 (published 15 January 2026). Around 2.6% contained sensitive data, and 16.9% of all those exposures flowed through personal free-tier accounts. ChatGPT accounted for 71.2% of sensitive data exposure, simply because it is where people go.
Cost of getting it wrong
IBM’s Cost of a Data Breach Report 2025, researched independently by the Ponemon Institute across 600 breached organizations, found that 20% had suffered a breach involving shadow AI, and that organizations with high levels of shadow AI faced $670,000 in additional breach costs against a global average of $4.44m. Of organizations reporting an AI-related breach, 97% lacked proper AI access controls.
The detail that matters most to a business owner is not in any of those reports, though. It is in the vendor’s own terms.

Does ChatGPT train on your business data?
It depends entirely on the account, not the tool. On consumer plans - Free, Plus and Pro - model training is on by default, and a user has to actively opt out under Settings, Data Controls. On business tiers, OpenAI’s stated policy is that it does not train on inputs or outputs by default, and workspace owners can set a retention policy and get admin controls, audit logging and single sign-on.
So the same employee, pasting the same contract into the same product, creates a completely different exposure depending on which account they happened to be signed into. That is the whole ball game, and it is invisible from the outside. It is also fixable for roughly the price of a phone contract per person.
4. Why a ban is the most expensive option available
Software AG surveyed 6,000 knowledge workers in the US, UK and Germany (published 22 October 2024). Half used AI tools their company had not issued. 46% said they would carry on using personal AI tools even if their organization banned them outright. A third said their IT department simply did not provide the tools they needed.
BlackFog’s January 2026 survey of 2,000 workers at companies with 500+ staff found something more damning: 34% use free versions of unapproved tools even though approved tools exist, and 60% said speed outweighed the security risk. Risk tolerance was highest at the top, with 69% of C-suite respondents finding shadow AI acceptable.
The best-documented worked example is Samsung. It allowed generative AI in its semiconductor division in March 2023. Within weeks came reported leaks including proprietary source code and an internal meeting transcript, and on 2 May 2023 Samsung banned external generative AI on company devices. But the ban is not the interesting part - six months later, in November 2023, Samsung launched its own internal model, Gauss. The ban bought time. Supplying an alternative was the actual fix.
JPMorgan followed the same arc. It restricted ChatGPT in February 2023, then built LLM Suite and rolled it out to roughly 140,000 employees by August 2024, since reported at over 200,000. Its stated reason was that it did not want its data training someone else’s model. Note that the bank did not decide AI was too risky. It decided consumer accounts were.
The strongest argument against us
“We are 30 people. Samsung and JPMorgan are not a useful comparison.” Fair - but the asymmetry runs the wrong way. They had security teams, audit logging and legal departments and still could not see it. You have a shared drive and a WhatsApp group. The response scales down cleanly, though: one sanctioned business-tier account per person, one page of rules, one afternoon of training. That is a week of work, not a program.
5. The compliance clock is closer than you think
Two dates matter. The EU AI Act’s AI literacy obligation has applied since 2 February 2025, and it is worth reading plainly: organizations deploying AI must ensure a sufficient level of AI literacy among the staff who use it. That is a training-and-awareness duty, and it is already live. A further tranche of transparency obligations applies from 2 August 2026.
On data protection, the point owners most often miss is that when staff paste customer or employee details into a third-party AI tool, your business remains the data controller. The employee’s personal account does not move that responsibility.
Now the honest counterweight, because we would rather you heard it from us. The Italian regulator’s headline €15m fine against OpenAI (December 2024) was annulled by the Court of Rome in March 2026 on jurisdictional grounds, and we found no enforcement action anywhere to date against an employer specifically for staff use of a consumer AI tool. So this exposure is untested rather than proven. “Untested” is not the same as “safe”, and it is a poor thing to be the test case for.
Myth vs Facts
Myth: “Our people are sensible, so this is not really an issue here.”
Fact: Sensibility is not the variable. Observed telemetry across roughly 7 million workers found 34.8% of data put into AI tools was sensitive, and 47% of AI users go through personal unmanaged accounts. Careful people using the wrong account still create the exposure.
Myth: “We would know if staff were using AI on client work.”
Fact: 57% of employees say they hide AI use from managers, and 52% will not admit to it on their most important tasks. Any usage figure gathered by asking is an undercount by design.
Myth: “Blocking the sites solves it.”
Fact: 46% of shadow users say they would continue anyway, and 34% use free tools even where approved ones exist. Blocking moves the activity to personal phones, which is the one place your logs will never reach.
Myth: “A policy document covers us.”
Fact: IBM found 97% of organizations that suffered an AI-related breach lacked proper AI access controls, and 63% of breached organizations either had no AI governance policy or were still writing one. A policy nobody has been trained on is documentation, not control.
The four shadow-AI behaviors, and what to do about each
| What staff are doing | Why it is a problem | What to do instead |
|---|---|---|
| Personal free account for work tasks | Training is on by default; no retention control, no audit trail | Issue business-tier accounts. This one change removes most of the risk. |
| Pasting customer or employee data in | You stay the data controller, whatever account was used | Name the data classes that must never be pasted, with examples, on one page |
| Pasting code, pricing or contracts in | Largest observed categories of sensitive leakage | Sanctioned tool plus a rule that IP goes only through it |
| Hiding AI use in delivered work | You cannot review quality you cannot see, and errors reach clients | Make disclosure explicitly safe and expected, then review output not usage |
| Connecting AI tools to work systems unasked | Unvetted third party gains standing access to live data | One named approver for anything that connects to email, files or CRM |
What this means if you are running AI in your business
Shadow AI is a demand signal. Your team has found work that AI genuinely helps with, and has been doing your evaluation phase for free, in the wrong accounts, without telling you. The mistake is treating that as a discipline problem when it is a supply problem.
The order matters. Supply the tool first, because that is what stops the bleeding. Write the rules second, because rules without an alternative just teach people to hide better. Train third, since that is both the thing that changes behavior and the thing the EU’s literacy obligation actually asks for - and it is why we treat AI skills training as the entry point rather than an afterthought.
- Week 1: Ask, without blame, what people already use and for what. Frame it as “we are buying the right tool”, not an audit.
- Week 1: Buy business-tier accounts for everyone who needs one. Cheaper than one incident, and it flips training off by default.
- Week 2: Write one page: what data must never go in, what tasks always need human review, who approves new tools.
- Week 2: Name the approver. Shadow AI thrives wherever a request has no obvious destination.
- Week 3: Run one training session on the two failure modes that actually cost money - leaking data, and trusting output nobody checked.
- Week 4: Make disclosure normal. Ask where AI helped in review, so quality gets checked instead of concealed.
- Ongoing: Revisit quarterly. Tools and vendor terms change faster than handbooks do.
None of that requires a governance committee, and it is the same discipline that keeps deliberate AI deployments safe - the difference between an agent you control and one you do not is the subject of how AI agents get hacked in production, and the output-quality half is covered in what AI hallucinations really cost a business.
How much shadow AI risk are you carrying?
Tick each one that is true today.
- We have no approved AI tool, but we are confident people use AI anyway
- Staff use personal accounts for work tasks involving customer or financial data
- We have no written rule about what data must never go into an AI tool
- Nobody is named as the person who approves a new AI tool
- We have never run any AI training for staff
- An AI tool has been connected to our email, files or CRM without a review
- Someone would feel awkward telling their manager they used AI on a client deliverable
If this were your business, here is our first move
We would not start with a policy, and we would not start by blocking anything. We would spend an afternoon finding out what your team already does, then buy the right accounts before the week was out.
That sequence sounds too simple to be a strategy, which is exactly why so few businesses do it. Samsung needed a ban and six months of engineering to arrive at the same conclusion. JPMorgan needed an internal platform and 200,000 seats. You need a card payment and a conversation.
The businesses that get burned are not the ones whose staff use AI. They are the ones who found out what their staff were using from an incident report. If you want help running that conversation and setting a standard your team will actually follow, get in touch.