Skip to content
Blog

Governance

Two thirds of your team use a banned AI

66 % of office professionals used an AI they believed was banned, and over a third entered client data into it. Banning harder only moves the usage.

By providing an approved tool that does the work at least as well as the one you want to ban. It is the only measure that reduces the volume rather than hiding it, and every other option comes down to deciding whether you prefer a risk you can see or a risk you cannot.

The figure that frames the subject comes from a survey run in April 2026 among 1,250 office professionals at companies with revenues above 500 million dollars, excluding technical roles. 66 % had used an AI tool at work they believed their own company had banned, and over a third had entered client data into it.

What the number actually says

It does not say two thirds of employees are undisciplined. It says the rule did not hold against the gap between what the work demands and what the company supplied, and that gap is documented in the same survey: 72 % believe they understand how to use AI for their job better than the team responsible for managing it at their company.

The most instructive detail sits elsewhere, in an answer rarely quoted. Nearly half say they would rather use an AI without telling anyone than risk being refused, which means the request for approval is perceived as a rejection mechanism rather than an arbitration mechanism.

That perception has a methodological consequence worth holding on to before commissioning an internal audit. An organisation where people prefer not to ask is an organisation where people also prefer not to answer a questionnaire honestly, so your internal figures understate the phenomenon, systematically and by an amount you cannot estimate.

Why banning fails, mechanically

Because a rule written in natural language is worked around with a sentence in natural language, which is exactly the reasoning we apply to agents. A limit that holds is a right not granted, an action that does not exist, a validation written into the product, never an instruction however well drafted.

Network blocking looks like the technical version of that limit, and it is not one. It prevents access from the workstation, prevents nothing from the personal phone sitting next to the keyboard, and turns usage you could see in your logs into usage that leaves no trace at all. The volume does not fall, your visibility disappears.

There are cases where blocking is the right decision, and they should be named so as not to sound naive. A workstation handling health data, a client environment under regulatory constraint, a due diligence phase: there, the cost of circumvention is high enough for a ban to produce the intended effect. As the general policy of a thirty-person staffing firm, it produces only a blind spot.

The real risk, for a staffing firm

It is not moral and it is not theoretical: it is a confidentiality clause you signed. A consultant profile, a specification, a client architecture or a rate card pasted into a consumer tool leaves the perimeter you guaranteed in writing, and the liability is yours whoever did the copying.

The second risk concerns personal data, and it is broader than people think. A CV carries a name, a career, often an address and sometimes a great deal more. Processing it in a service whose location and reuse terms you have not checked is a transfer you have neither documented nor entered in your register.

The third is more insidious and connects to a subject we have already covered. An employee who pastes a document into a consumer tool also pastes what that document contains, including what they have not read, and a text can carry instructions aimed at the model that will read it. Clandestine use removes precisely the partitioning that made such a manipulation harmless.

What works, in three decisions

Provide an approved tool before you write the rule. The order matters more than the content. A policy published without an alternative creates a choice between disobeying and working worse, and you already know how that choice goes.

Write the list of what never leaves, in three lines at most. Candidates’ personal details, documents carrying a client’s name, financial figures. A short list is remembered and applied; a twelve-page document is filed and forgotten the day it is published.

Make requesting an exception easy and fast. If approval to try a tool takes three weeks and goes through a committee, you have built the clandestine-use machine described above. A forty-eight-hour turnaround with a reasoned answer changes behaviour far more than an announced sanction.

These three decisions share one property: none rests on surveillance. That is deliberate, because a surveillance policy on this particular subject has a high social cost, a low return, and it puts you in the position of having to consult the works council on a monitoring system before you have even fixed the original problem.

How to measure usage without watching people

The question always comes up, because a management team discovering the subject first wants to know where it stands. There is an honest way to do it, and it does not involve reading browsing logs.

Start with what your information system already tells you at no cost. The domains contacted from the company network, aggregated and not attributed to individuals, give you a picture of the volume and variety of tools in use without naming anybody. That is enough to size the problem and to choose which tool to approve first, which is the only decision the measurement has to inform.

Follow with a question asked frankly, explaining that it will not be used to sanction anybody. “Which tool would you use if everything were allowed” gets answers where “do you use banned tools” gets none, and the two questions seek the same information. The first also gives you the reason, which is to say what is missing from what you provide.

What to avoid deserves naming, because the temptation is real. An attributed system for monitoring employees’ tool usage requires informing and consulting the works council before it is put in place, and triggering that procedure for a problem you were going to solve by providing a tool anyway is a poor trade. Measurement is there to choose, not to establish individual responsibility.

Article 4 of the AI Act has required a sufficient level of AI literacy since 2 February 2025 from people using it on the company’s behalf, and it is an obligation of result with no prescribed format. That frame changes how the subject reads, because it moves the question from discipline to competence.

An organisation where two thirds of staff use tools nobody has approved is not merely exposed to a data leak: it is unable to demonstrate that it trained anyone, since it does not know on what. The obligation and the risk are therefore addressed by the same move, which is rare and worth exploiting.

It is also the most effective internal argument when a management team has to be convinced the subject deserves a budget. Shadow AI is not a staff-handbook problem, it is proof that your teams have a real need nobody answered, and the only plan that works consists of answering it.

Frequently asked questions

Should access to consumer tools be blocked technically?

Network blocking moves the usage to the personal phone, where you see nothing at all. It makes sense on highly sensitive workstations and is counterproductive as a general policy, because it turns visible usage into invisible usage without reducing the volume.

What does a staffing firm actually risk?

Breach of a client confidentiality clause, which is a contractual obligation rather than a principle. A consultant profile, a specification or an architecture pasted into a consumer tool leaves the perimeter you guaranteed in writing, and the fault is yours whoever did the copying.

Is a policy document enough?

It is necessary and never sufficient on its own. A policy that bans without offering an alternative produces clandestine use; a policy that accompanies an approved tool, training and a clear list of what never leaves produces compliance. The difference is in what you give, not in what you write.

How does this connect to the AI Act training duty?

Article 4 has required a sufficient level of AI literacy since 2 February 2025 from people using it on the company’s behalf. An organisation where two thirds of staff use tools nobody has approved does not meet that duty, and cannot demonstrate that it tried either.

Sources

  1. PagerDuty, Shadow AI survey 2026 (Wakefield Research, 1,250 office professionals, April 2026)pagerduty.com
  2. PagerDuty, Shadow AI is happening within your organizationpagerduty.com
  3. Cloud Security Alliance, Shadow AI apps: the enterprise attack surface that outpaces monitoring, May 2026labs.cloudsecurityalliance.org

Read next

€100 in credits when you sign up

Join the waitlist.

Leave your email address and we will let you know as soon as Balt can join your team.

Already 247 staffing firms on the waitlist