Employees Using AI at Work: The Risk Nobody Signed Off On

Table of Contents

There is a reasonable chance that by the time you finish reading this, someone in your organisation will have pasted something into ChatGPT.

That is not alarmism. It is the operational reality for most businesses right now. AI tools are free, fast, browser-based, and already embedded in platforms your staff use every day. There is no procurement gate to pass. No IT ticket to raise. No approval to wait for. The barrier to adoption is essentially zero, and the productivity benefits are obvious and immediate.

The question is not whether employees using AI at work is happening in your organisation. Most of them are, in one form or another. The question is whether you have any visibility or control over how – and whether the absence of that visibility is creating exposure you have not yet had to account for.

How the governance gap opens when employees use AI at work

Traditional IT governance was built on a reasonable assumption: that acquiring new tools required effort. A budget decision. A procurement process. An IT deployment. That assumption gave governance time to operate. By the time a tool was in active use, it had usually passed through some form of review.

AI has changed that assumption completely. A capable AI assistant is available in a browser tab. Microsoft Copilot is already embedded in the Microsoft 365 environment most organisations already run. AI features appear in SaaS platforms through product updates rather than procurement decisions. A member of staff can adopt a genuinely powerful AI tool in the time it takes to make a coffee, and there is nothing in most organisations’ governance architecture that would surface that adoption.

What this means in practice is that organisations now have a growing class of operational tool that sits largely outside their normal visibility and control structures. Nobody approved it. Nobody assessed the supplier. Nobody reviewed what happens to the data. Nobody considered what categories of information are acceptable to put through it. The tool is just in use, embedded in someone’s workflow, because it is useful.

The exposure this creates is often less dramatic than people imagine and more significant than they realise. It is rarely one catastrophic incident. It is usually a slow accumulation of data going to places it should not, decisions being influenced by outputs nobody validated, and governance questions that cannot be answered confidently when they eventually get asked. This is the same underlying pattern behind most shadow AI risk – it just looks mundane from the inside.

What employees using AI at work are actually doing

The most common risks right now are mundane. A sales team member pastes a proposal draft into a summarisation tool to tighten it up before sending. Someone in HR uses an AI assistant to draft a disciplinary letter, including the employee’s name and circumstances. A developer uses a code assistant that has been trained on – and in some configurations may retain – the code it processes. A project manager uploads meeting notes to a transcription service and shares the AI summary directly with a client.

None of these feel like incidents in the moment. The individuals involved are not acting recklessly. They are doing reasonable things under time pressure using the most capable tools available to them. Most of the time, nothing visibly bad happens.

But some of these scenarios involve personal data that should not leave the organisation’s control. Some involve commercially sensitive information reaching a supplier whose terms were never reviewed. Some involve data being processed in jurisdictions that create UK GDPR complications – an area the ICO continues to focus on as generative AI use grows. And some will eventually surface as incidents – not because staff behaved badly, but because the governance structures were not there to prevent it.

Why policy alone does not solve the problem

Many organisations respond to concerns about employees using AI at work by writing an acceptable use policy. That is a sensible step, and eventually every organisation needs one. But a policy written without first understanding what is actually happening inside the organisation tends to create the appearance of governance rather than the substance of it.

A policy that lists approved tools is only useful if the list reflects operational reality. A policy that prohibits certain data categories reaching AI systems is only enforceable if staff know which tools are subject to it and why. A policy that requires approval before using new AI tools only works if the approval process is fast enough and clear enough that staff actually use it rather than working around it.

If the policy was written before anyone asked what tools are actually in use, what data flows through them, or how staff are genuinely working, it is documentation that covers the organisation on paper while leaving the actual exposure untouched.

Visibility comes before policy

Governance starts with an honest picture of current reality. You cannot write a policy that reflects how people work without first understanding how they work. You cannot assess supplier risk without knowing which suppliers are involved. You cannot prioritise remediation without knowing what the actual exposure is.

Getting that picture requires more than asking managers what tools their teams use. Self-reporting reliably surfaces the approved and obvious tools. It rarely surfaces the browser extensions, the personal accounts used for work tasks, the AI features inside existing platforms that nobody formally decided to enable, or the tools that staff quietly continued using after the organisation discouraged them.

The organisations managing this well have invested in actual visibility – a structured review of what is in use, what data it touches, what the supplier relationships look like, and where the governance gaps are. That picture gives them something to govern. Without it, governance is largely theoretical. Working through our AI Governance Gap Assessment is a fast way to see which of these gaps applies to you, and what a proper AI risk assessment should cover if you want to go further.

Most organisations that go through this process are not overwhelmed by what they find. The situation is usually manageable once it is visible. The risk is not the tools themselves. It is operating without knowing what is there.

An AI Exposure Review gives you an independent, structured view of your organisation’s actual AI footprint – tools in use, data exposure, supplier risk, and governance gaps.

If you are not sure what AI tools are in use inside your organisation, an AI Exposure Review gives you a clear, independent picture - what is being used, what data it touches, and where the real risks are.

Related Posts