Intelligence in vCISO

How Employees Are Using AI Without Telling You 

By Lindsay Grossman
Posted on Oct 08 / 2026

As AI becomes a more integral part of our everyday lives, it becomes increasingly intertwined with our personal and professional lives. While many organizations believe they are properly managing AI usage, the statistics show otherwise. Unsanctioned AI use in the modern workplace is tangible and complex, yet addressable, and it starts with having a clear AI acceptable use policy in place before employees find their own way around the gap. Shadow AI is the use of AI tools, models, or AI-enabled features that IT and security teams haven't reviewed, approved, or configured. The real issues arise when people find ways to solve problems or improve efficiency before policies and training can keep up. The gap between what leaders believe and what is actually happening is now showing up in surveys and reports. 

What's Happening When Employees Use AI Without an Acceptable Use Policy in Place?

The scale of unsanctioned AI usage is large and poses a threat to IT's visibility of its own risks and threats. Unsanctioned AI use takes several forms: 

  • Employees pasting data directly into public LLMs like ChatGPT or Gemini 
  • Unapproved browser extensions and plugins that route data through third-party AI 
  • AI features already embedded in approved tools (Microsoft Copilot, Zoom AI Companion, Slack AI, Salesforce Einstein) that get switched on by default or by an individual user without IT's knowledge

That last category is the one most likely to catch employees off guard, since they may not realize a familiar tool now has AI processing data behind the scenes. 

This use threatens an employer's ability to understand data exposure and maintain compliance with regulatory frameworks. Teramind's 2026 Shadow AI Report cites similar findings: 89% of workplace AI use occurs outside enterprise-governed channels, and 86% of organizations lack visibility into how data flows to/from AI tools. Not only are IT departments losing visibility into their own environments, but many employees are inputting sensitive data into AI resources beyond what IT can see.  

Some employers have attempted to resolve the issue by banning AI altogether, but this does not dissuade all employees. In fact, according to the Teramind report, 48% of employees have stated they would continue to use AI even if their organization banned it. This means that banning AI does not fully eliminate the risk. Instead, risk reduction means providing employees with enterprise-approved AI tools, governed by a clear AI acceptable use policy, as well as training to ensure employees understand what kinds of data are permitted to be sent to the tool. 

What Are the Risks Without a Clear Policy in Place?

The most direct and persistent risk is data leakage. Once employees accidentally or intentionally send sensitive data to the AI model, it cannot be taken back. These leaks can reveal proprietary information, intellectual property, and/or sensitive data stored about customers and employees. Employees typically aren't trying to cause harm, rather they're pasting a contract to summarize, uploading a spreadsheet to speed up review, or asking AI to debug code, and the leak happens the moment that data leaves the corporate boundary, regardless of whether the AI vendor mishandles it afterward. 

For example, Samsung employees disclosed confidential information while using ChatGPT for assistance with tasks, after the company had permitted semiconductor division engineers to use it for source code troubleshooting, and workers ended up inputting confidential source code and internal meeting notes covering hardware data, with three documented leak instances in under a month. This can create serious consequences for organizations both financially and reputationally. 

There's a second, less visible risk beyond the initial leak: many consumer-grade AI tools retain conversation history and may use it to improve or train future models. That means data an employee assumed was a one-time query can persist indefinitely and, in some cases, resurface in another user's output. 

This kind of unsanctioned use also presents a threat to your organization's ability to meet compliance standards, including but not limited to GDPR and HIPAA requirements, both of which place strict requirements on how personal and health data is collected, stored, and shared, requirements that most public AI tools aren't built to satisfy. Without a defined AI acceptable use policy, the organization loses the ability to demonstrate the safeguards these frameworks require, turning a productivity shortcut into a compliance liability. It is also difficult to track what data left the environment, when, and where it went. When software is not sanctioned or monitored by IT, it becomes very difficult to understand where, how, and why your data is moving. 

What Should an AI Acceptable Use Policy Include?

Unsanctioned AI use is not a minority behavior, and its victims are not organizations who completely neglect cybersecurity practices. Providing sanctioned, monitored tools that allow employees to leverage AI as a tool in their work can make a huge difference in IT's ability to track and understand how AI is being used. This significantly improves visibility and reduces risk. 

Training employees on proper AI use, including what data can and cannot be sent, is an integral part of building an effective and secure AI program. But an effective program starts with the policy itself. A strong AI acceptable use policy covers five core components: 

Component What It Covers
Data boundaries Clear rules on what data can and cannot be shared with AI tools
Tool inventory An up-to-date list of approved AI tools and features already in use
Review process A vetting process for evaluating new AI tools before they're adopted
Monitoring Detection capabilities tuned to catch AI-related data flows
Incident response A plan for when sensitive data is sent somewhere it shouldn't be

Avoiding AI use altogether is not the solution in a workplace demanding high efficiency; rather, an AI acceptable use policy backed by real tooling and training is much more likely to keep your organization secure and compliant. Echelon Risk + Cyber's AI Governance practice helps organizations build the policies, tooling, and training programs that make secure AI adoption possible. Learn more about AI governance here.

Are you ready to get started?