Your Employees Are Already Using AI. Now What?
← Ramblings

Your Employees Are Already Using AI. Now What?

2026-08-18 · Clara F. & agents

You don't need an official AI policy to have a shadow-AI problem. The data says your team is already using it, policy or not. Here's the honest fix that works.

If you asked the person who answers your phones whether they've ever pasted a customer's details into ChatGPT to write a faster reply, what would they say?

Be honest with yourself about the answer, because the data says you might be wrong either way.

A recent roundup of 2026 workplace surveys puts real numbers on something most owners only suspect. One study found 49% of workers are using AI in ways their employer hasn't approved. A separate survey of 17,000 office workers found 20% describe themselves as "underground" AI users: people who use it regularly and actively deny it if asked. And in a Zapier survey of executives at larger companies, nearly four in five said employees are bypassing whatever AI rules already exist, just to get things done faster.

Notice that last one is about companies with 500+ employees, teams with compliance departments and IT tickets and the works. If they can't stop it, a small office with no AI policy at all isn't going to stop it by simply not mentioning the word "AI." It's already happening. The only real question is whether you know about it.

What "shadow AI" actually looks like day to day

It's rarely dramatic. It's the assistant who pastes a client's draft tax return into ChatGPT to get a plain-language summary out faster. It's the junior team member who runs a supplier contract through an AI tool to check the numbers before a meeting, because it's quicker than interrupting you. Nobody's trying to cause a problem. They're trying to get through Tuesday.

That's exactly why it isn't really an "AI" problem. It's an information problem. Whatever gets pasted into a personal AI account (a client's financial details, a case file, a home address) leaves your control the moment someone hits enter. It sits on someone else's servers, under someone else's terms, and by default a lot of free AI tools use exactly that kind of input to train their next model. I wrote about how to check that for your own account here. The same default applies to whatever your team types, not just what you type.

Why banning it makes this worse, not better

The instinct, once you know this is happening, is to write a policy: no AI, full stop. It won't work, and the numbers explain why. A survey of IT leaders found 86% had at least one negative incident from unapproved AI use in the past year, in companies that already had rules against it. A rule people quietly ignore doesn't remove the risk. It removes your visibility into it, and turns your most capable employee (the one motivated enough to find a faster way to do their job) into someone hiding it from you.

What actually helps, at the size you actually are

You don't need a compliance department for this. You need one plain conversation and one plain rule, and both fit into a slow afternoon.

The conversation: ask each person, without penalty, what they're already using AI for. Not "are you allowed to": that just invites a careful non-answer. Ask what's actually saving them time. You'll usually learn something useful about your own workflow in the process; the tools people reach for quietly are often solving a real problem you hadn't noticed.

The rule, once you've heard the answers: nothing with a client's name, financial details, health information, or anything you wouldn't want printed on a poster goes into a personal AI account. Everything else (drafting, summarising, brainstorming) carries on as before. One line covers most of the real risk without asking anyone to give up a tool that's genuinely helping them.

What this doesn't fix

A five-minute conversation isn't a security audit, and it won't catch someone determined to hide something. If your business handles genuinely sensitive data as a matter of course (health records, financial accounts, anything with real regulatory teeth), this is a floor, not a ceiling. It's worth a proper look at AI tools built for business use, with real data controls, rather than everyone quietly running the same free personal tier in another browser tab. And it only works if "no penalty" is real: the first time someone gets told off for admitting what they use, the visibility you just gained disappears again.

Start this week

Pick one person on your team (the one you'd guess is using AI the most, based on nothing but instinct) and ask them, this week, what they've actually been using it for. Not to correct them. Just to know. Everything else follows from that one honest answer.