Illustration: AI-generated, art-directed by the author. Yes, the irony is intentional.
TL;DR · 20 seconds
- Most employees already use AI at work and over half hide it; bans do not stop usage, they stop visibility.
- Of professionals surveyed, 34% have entered customer data into a public chatbot and 31% have entered financials or confidential documents.
- The fix is a gate, not a wall: sanctioned tools, safe disclosure, and training before policing.
In March 2023, Samsung's semiconductor division lifted its internal ban on ChatGPT. Engineers had been asking for it. Leadership decided to trust them.
Within about three weeks, three different engineers had pasted things into ChatGPT that should never leave a building: proprietary source code, equipment optimization code, and the transcript of an internal meeting. By May, Samsung had banned generative AI on company devices entirely (Forbes, May 2023).
Most executives I talk to know this story. Here is the part they get wrong: they think the lesson is "ban it." The data from the three years since says the ban is where the problem starts.
The gap, in numbers
Nobody has one clean number for shadow AI, and the spread itself tells the story:
- 78% of AI users bring their own AI tools to work instead of using what the company provides (Microsoft and LinkedIn Work Trend Index 2024, 31,000 workers surveyed).
- 57% of employees say they hide their AI use and present AI-generated work as their own (KPMG and University of Melbourne, 48,000 people across 47 countries, 2025).
- 66% of office professionals have used AI tools they believed were not permitted under company policy (PagerDuty survey, June 2026).
- 45% of US workers say they have used explicitly banned AI tools at work. A quarter of them did it within the past week (Anagram survey, 2025).
Four studies, four methodologies, one direction. Usage is not the exception. Concealed usage is the norm.
Concealed AI use is the norm, not the exception
Four studies, four methodologies, one direction. Share of workers, by measure.
Bring their own AI tools to work instead of what the company provides
Have used AI tools they believed were not permitted under policy
Hide their AI use and present the work as their own
Have used explicitly banned AI tools at work
View as table
| Measure | Share | Source |
|---|---|---|
| Bring their own AI tools to work instead of what the company provides | 78% | Microsoft & LinkedIn Work Trend Index, 31,000 workers, 2024 |
| Have used AI tools they believed were not permitted under policy | 66% | PagerDuty Shadow AI Survey, June 2026 |
| Hide their AI use and present the work as their own | 57% | KPMG & University of Melbourne, 48,000 people across 47 countries, 2025 |
| Have used explicitly banned AI tools at work | 45% | Anagram survey, 2025 |
Four separate surveys, shown together because they point the same way. Sources: Microsoft/LinkedIn Work Trend Index (2024); PagerDuty (2026); KPMG/University of Melbourne (2025); Anagram (2025).
And what goes into those chatbots is not trivia. In the 2026 PagerDuty data, 43% of professionals had pasted work correspondence into public AI tools, 34% had entered customer data, and 31% had entered financial information or confidential documents. Security telemetry backs it up: LayerX found 77% of enterprise AI users paste data into chatbots, and 82% of those pastes come from personal accounts the company cannot see.
It is not trivia going into the chatbot
What employees say they paste, and what telemetry actually sees.
Pasted work correspondence into a public AI tool
Entered customer data
Entered financial information or confidential documents
Enterprise AI users observed pasting data into chatbots
Of those pastes, share coming from personal accounts
View as table
| Measure | Share | Source |
|---|---|---|
| Pasted work correspondence into a public AI tool | 43% | PagerDuty Shadow AI Survey, June 2026 |
| Entered customer data | 34% | PagerDuty Shadow AI Survey, June 2026 |
| Entered financial information or confidential documents | 31% | PagerDuty Shadow AI Survey, June 2026 |
| Enterprise AI users observed pasting data into chatbots | 77% | LayerX enterprise telemetry, via The Register, Oct 2025 |
| Of those pastes, share coming from personal accounts | 82% | LayerX enterprise telemetry, via The Register, Oct 2025 |
Self-reported categories and observed paste behaviour come from different studies and are not shares of the same base. Sources: PagerDuty Shadow AI Survey (June 2026); LayerX enterprise telemetry via The Register (October 2025).
Count the hidden chatbot tabs in your office. That number is your official stack's approval rating.
The policy mirage
Here is the number that should worry leadership more than any leak story: in ISACA's 2026 poll of digital trust professionals, 90% believe employees at their organization are using AI. Only 38% of organizations have a formal, comprehensive AI policy.
And even where a policy exists, it mostly exists as a document, not as behavior. In the KPMG global study, only 40% of employees say their organization even has a policy or provides guidance on generative AI use, and only 47% have received any AI training.
So the average company today looks like this: most employees using AI, half of them hiding it, a policy that most employees do not even know exists, and training that half the workforce never got. That is not a technology gap. That is a management gap wearing a technology costume. Nobody was made responsible for fitting AI to the actual jobs people do, so the company bought one generic assistant for everybody and called it a strategy. The fitting then happened anyway, in private, on personal phones, done by the employees themselves.
Why bans fail
The incentives are not mysterious.
AI makes individual workers faster, and workers know it. In Microsoft's data, 52% of people who use AI at work are reluctant to admit using it for their most important tasks, and 53% worry that using it makes them look replaceable. Read those two numbers together: employees believe AI is valuable enough to use and dangerous enough to hide. The hiding is rational. Admitting you used AI feels like confessing either laziness or replaceability.
Add the fairness problem: in the PagerDuty survey, 81% of professionals believe AI rules apply differently to leadership than to everyone else.
A ban does not remove any of those incentives. It removes visibility. The usage continues on personal phones and personal accounts, exactly where your security team cannot see it, cannot log it, and cannot coach it. Samsung's leak happened when usage was sanctioned and visible. The next one happens where nobody is looking.
A ban does not remove the risk. It relocates it.
The dashed line is the edge of what your security team can see.
Inside the company’s view
Outside it
If you ban the tool
The usage continues, exactly where security cannot see it, log it, or coach it.
If you gate the tool
Everything else just runs, and the risk stays in view.
Illustrative, not to scale. Samsung’s 2023 leak happened while ChatGPT use was sanctioned and visible; the ban that followed moved the next risk to personal devices, where nobody is looking.
A ban does not remove the incentives. It removes visibility.
What I do instead
I run AI agents daily. They draft my content, watch my businesses, and answer my phone. And the single most important thing I ever built into that system is not a capability. It is a gate: nothing outward-facing happens without a human tap. My AI can draft anything; it can publish nothing.
That is the model I would offer any leader worried about shadow AI:
- 01Sanction a real tool, then make the sanctioned path the easiest path. People go around policy when policy is slower than the alternative. If the approved tool is worse than what is in their pocket, your policy is a suggestion.
- 02Bring the AI to your data instead of letting your data leak to the AI. The reason employees paste confidential material into public chatbots is that the public chatbot is the only place the intelligence lives. It does not have to be. A private deployment changes the equation: models running in your own cloud, answering from your own knowledge base, with role-based access deciding who can retrieve what, and every query logged. When the sanctioned assistant already knows your documents and never ships them to someone else's servers, the incentive to smuggle data outside simply dissolves. This is not enterprise-giant territory anymore; mid-sized companies run this today. (The full version of this argument, including how retrieval actually works and what the providers contractually promise, is bringing the AI to your data.)
- 03Replace the ban with a gate. Define the small set of actions that need human review: anything leaving the building, anything touching customer data, anything with a price on it. Let everything else run. A gate people respect beats a wall people climb.
- 04Make disclosure safe. 57% hide their AI use because hiding is the rational move. Flip the incentive: the person who shows how they used AI to do the work faster should be the person who looks best in the room, not the one who looks replaceable.
- 05Train before you police. You cannot hold people to a standard half of them were never taught. Training is cheaper than the incident.
Here is the quiet part, said plainly: shadow AI is not an employee discipline problem. It is a scoreboard, and it is public. Every hidden chatbot tab in your office is a vote of no confidence in your official stack. Fifty-seven percent of your people are already voting. You do not win that election by banning voters.
And look again at that 57%, because it is secretly the most hopeful number here. It means adoption already happened. The thing companies are burning millions to manufacture, willing, daily AI usage, already exists inside your walls, self-taught and free. The only part that failed is that it happened in hiding, which is the one configuration where you inherit all of the risk and none of the compounding.
So the real project was never "stop them." It is "surface them." Give the usage a sanctioned home, make the home better than what is in their pocket, and the shadow evaporates on its own. Ban-first companies will spend the next two years discovering their policy was fiction. Gate-first companies will spend the same two years compounding a workforce that stopped hiding its best tool.
One diagnostic question tells you which company you are: do you know what your team pasted into a chatbot this week, or do you just have a PDF that says they didn't?
Sources (7)
- 01Microsoft & LinkedIn, 2024 Work Trend Index (78% BYOAI; 52% reluctant; 53% replaceable): microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
- 02KPMG & University of Melbourne, Trust in AI global study 2025 (57% hide; 40% policy access; 47% trained): kpmg.com/xx/en/media/press-releases/2025/04/trust-of-ai-remains-a-critical-challenge.html
- 03PagerDuty Shadow AI Survey, June 2026 (66%; 81%; 43/34/31% paste types): pagerduty.com/blog/ai/shadow-ai-workplace-survey-2026/
- 04Anagram survey via HR Dive, Aug 2025 (45% banned tools; 26% past week): hrdive.com/news/workers-use-banned-ai-tools-at-work/757481/
- 05LayerX report via The Register, Oct 2025 (77% paste; 82% personal accounts): theregister.com/2025/10/07/gen_ai_shadow_it_secrets
- 06ISACA 2026 AI Pulse Poll (90% use; 38% comprehensive policy): isaca.org/about-us/newsroom/press-releases/2026/ai-use-accelerates-while-governance-and-roi-lag-says-new-isaca-research
- 07Samsung incident: Forbes (Siladitya Ray, reporting Bloomberg), May 2 2023 [series-canonical source, see SERIES_BIBLE]






