Insights
Your team is already using AI. You just don't know about it.
Ask a mid-market executive whether AI has "arrived" at their company, and most will say not yet, still evaluating vendors, still waiting on IT. Picture what's probably happening down the hall anyway: someone in sales pasting a client contract into a free chatbot to summarize before a call, someone in finance dropping a margin spreadsheet into the same tool to sanity-check a forecast. It's not a stretch. According to KPMG and the University of Melbourne's global study of more than 48,000 employees across 47 countries, 48% of employees who use AI have uploaded sensitive company information, financial, sales, or customer data, into public AI tools. Not company tools. Public ones, on personal logins, with no visibility into where that data lands.
The tools are already in the building
Treating AI adoption as a purchasing decision, something you approve, budget for, and roll out on a timeline, misreads what's actually happening. Employees aren't waiting for permission. Microsoft and LinkedIn's Work Trend Index 2024, a survey of 31,000 knowledge workers across 31 countries, found that 78% of employees who use AI bring their own tools to work rather than anything issued by their employer, a practice researchers call BYOAI. At small and mid-sized companies, the kind without a dedicated IT security function watching for it, that figure rises to 80%. The caveat that matters here: those numbers describe AI users, not your whole headcount. But if a meaningful share of your team already uses AI daily, most of them are doing it on tools you've never seen, under accounts you don't control.
Banning it makes the problem worse
The instinct after reading that paragraph is usually to lock it down: block the domains, write a policy that says no, treat this like any other unauthorized software. The KPMG and Melbourne research is unambiguous about why that backfires. Policy-violating AI use is most common at companies that have banned generative AI outright, where 67% of employees use it in ways that break the rules anyway. Companies with an actual usage policy fare only a little better, at 56%. Companies with no policy at all, no rule to break, sit lowest, at 33%. A ban doesn't remove the behavior. It removes your ability to see it, and it removes any incentive employees have to pick a sanctioned tool over a free one. You keep the same risk and lose the visibility.
What's actually happening on the ground
Security firm Cyberhaven's telemetry across 222 companies, published in its AI Adoption and Risk Report 2026, puts numbers on the shape of that risk: roughly a third of employees access AI tools through personal, non-corporate accounts, and 39.7% of AI interactions involve sensitive data, which works out to roughly the average employee sending proprietary company information into an AI tool once every three days. That's not a rogue-employee problem. That's a normal Tuesday, multiplied across the org chart, invisible to whoever owns data security.
Ownership, not control, is the fix. A few things separate companies that have this handled from companies that are quietly exposed:
- A short list of sanctioned AI tools, provisioned under company accounts rather than personal logins, so usage is visible and data stays inside your boundary
- A policy that's actually usable: what's fine, what's not, and why, written in plain language instead of legal boilerplate nobody reads
- Basic training on what "sensitive data" means inside an AI prompt, since most employees genuinely don't think of a customer list or margin sheet as something they just handed to a third party
- A human-in-the-loop habit, so AI output gets checked before it becomes a decision, not because the tool is untrustworthy, but because unchecked output is how small mistakes scale
None of this requires banning anything. It requires deciding, deliberately, what "sanctioned" looks like, then making that path easier than the personal-account workaround. It's the same pattern we keep running into across AI adoption: the problem is rarely the technology, it's the absence of ownership around it (see why most AI pilots fail to move the P&L).
We built the AI Ownership Scorecard partly for this. Its Ownership dimension asks the question most leadership teams haven't asked themselves: do we actually know what AI tools our people are using. If the honest answer is no, an AI audit is the fastest way to find out what's already running through your company, and to turn shadow use into something governed instead of something you hope never shows up in a headline.
Source: KPMG and the University of Melbourne, "Trust, attitudes and use of AI: A global study 2025" (48,000+ respondents, 47 countries); Microsoft and LinkedIn, "Work Trend Index 2024" (31,000 knowledge workers, 31 countries); security firm Cyberhaven's telemetry across 222 companies, "AI Adoption and Risk Report 2026." See how we approach this in our AI audit and the Ownership Scorecard.