on
Council Post: Half Your Workforce Already Bypassed Your AI Policy
Keegan Crage | Owner, TechBrain AU — ISO 27001 certified, cyber security & AI governance partner.

getty
Nine in 10 organizations claim to have an AI policy in place, yet 70% of IT leaders have already caught their staff using unapproved AI at work. Telemetry from one of the largest annual breach studies has found employee use of AI on business devices has tripled in the last 12 months.
In fact, almost half of employees are using AI on their work-issued devices, and it was never approved by the business.
Written AI policies aren't hard to find these days, but the real issue is that only about half of them actually enforce or monitor that policy. And among the organizations breached last year, one in five traced the breach to an AI tool no one had signed off on.
The Most Consistent Users Sit At The Top
These statistics are not unique to any one country, and they show that employee use of unapproved AI is becoming the norm.
A survey of large organizations in the U.K. and U.S. found that 49% of employees were using unapproved AI tools. A more recent academic study of 48,000 employees across 47 countries found that 48% were doing the same. And of the C-suite employees surveyed, 69% would trade security for speed, against 37% of administrative staff. Senior management are more likely both to write the policy and to work around it.
I watched this play out with a mining-sector client who was sure their AI use stopped at one approved tool. Discovery turned up numerous others in active use, the heaviest being a director pasting contracts into a free service. They had expected a few curious team members; the habit was most entrenched at the top.
Banning the use of unapproved AI is a common approach, and it usually fails. Typically, users carry on at the same level of risk, simply moving to an AI tool that has not been banned. One study found that seven out of 10 people kept using AI after their employer blocked a tool. Banning unapproved AI merely moves the same risk out of view.
Make The Sanctioned Path The Better One
Most of the problems with AI use in organizations can be solved with proper management rather than enforcement: Give people an approved way to do something that is faster and better than the rogue tools they currently reach for.
But you first need to know what they are using, and most organizations have no idea. In one documented healthcare rollout, a few sanctioned tools that actually did the job reduced unauthorized use of other AI by 89%. On average, an enterprise runs dozens of AI tools and logs hundreds of AI-related policy violations a month, yet only a tiny fraction ever reach anyone who can act on them.
Most of the controls you need for good AI governance are already part of ISO 27001, the information security standard many organizations already run. The 2022 version even added a control specifically for consuming software as a cloud service, which is exactly what most AI tools are.
Then, in 2023, the first international standard for managing AI, ISO 42001, was published. It sits as an AI-specific layer on top of ISO 27001, and an organization already certified to 27001 is well over halfway there. There is a matching framework in the U.S., published by NIST.
The Board's Question Has Changed
A dedicated head of AI governance is an expensive hire that few mid-market firms can justify. That work can usually sit with the fractional security leadership a business already retains, at a fraction of the cost.
AI governance is also, slowly but surely, becoming a matter of regulation. The U.S. Federal Trade Commission has been calling out the discrepancy between what companies say their AI does and what it actually does, and in December, Australia's first AI-inventory obligation arrives through privacy law.
So, it’s no longer that relevant to ask whether a company has a policy. The more relevant question I’ll ask is what AI is touching your data right now? A policy that no one monitors or enforces is no policy at all, and until a breach forces the conversation, the business has been carrying that risk the whole time.
It is worth noting, too, that having a governance framework does not mean a business is actually governing. In many cases, people work around the framework, which is why what you really want is an approved path your employees will acknowledge as better than the rogue tools they're reaching for today.
The main thing you want to be able to say, when something goes wrong, is that we knew what was running and we can prove it.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?