Somebody on your team is already using AI at work. They did not ask, and they were not wrong to try. It made a slow task faster, so they kept doing it.
That is not the problem. The problem is what happens around it: company information sitting in accounts nobody controls, and output nobody checked.
This is shadow IT with a better interface
Every few years a category of tool arrives that is useful enough that people adopt it before anyone approves it. Dropbox did this. So did WhatsApp for client messages, and personal Gmail for work files.
The pattern is always the same. A person solves their own problem, the tool spreads sideways through the team, and by the time anyone above them hears about it, business information is already in an account the business does not own and cannot close.
AI tools follow the same path, with two differences. They take in far more context than a file-sharing app ever did, because people paste in whole documents to get a useful answer. And they produce confident output that looks finished, which makes it easy to skip the checking step.
Start by finding out what is actually in use
Not what is allowed. What is happening. Three questions get you most of the way:
- Which tools has anyone signed up for? Ask directly and without consequence attached, because you want an honest list rather than a tidy one.
- What company information has gone into them? Client names, contracts, pricing, employee records, anything under an NDA.
- Whose account is it? A personal login that leaves with the person is a different risk from a company account you can revoke.
Most of what you find was never approved by anyone. It just started happening, usually for a good reason.
The account is the control, not the policy
A written policy that says “do not paste confidential information into AI tools” is worth having and will not, on its own, change behaviour. People follow the path that gets the work done.
What actually changes the situation is boring and structural:
- Accounts on your own domain rather than personal logins, so access ends when employment does.
- Business or team tiers where the provider does not train on your input by default, rather than free tiers where it may.
- Permissions that match the job, so the tool sees what that person already sees and nothing more.
- One plain sentence everybody can remember about what never goes in. Not a three-page document nobody opens.
The goal is that the easy path and the safe path are the same path. Policies that fight convenience lose.
Everything it produced still needs a person
AI writes confidently, plausibly, and sometimes wrongly. The failure mode is not gibberish you would catch instantly. It is a sentence that reads perfectly and is not true.
The places this has actually cost businesses money are predictable:
- Website copy stating a service, a price or a guarantee the business does not offer.
- Configuration and scripts pasted from a chat window into a live server without being read.
- Legal and compliance wording that sounds authoritative and cites nothing real.
- Customer replies that invent a policy on the spot, which you then have to honour or retract.
None of that is an argument against the tool. It is an argument for the same rule you would apply to a new junior hire: useful from day one, and nothing goes out under the company name without somebody who knows the subject reading it first.
A reasonable position, in four lines
- Assume it is already in use, because it almost certainly is.
- Move it onto accounts you own.
- Be specific about what must never be pasted in.
- Nothing it produces ships without a human reading it.
That is most of the risk handled, and none of the benefit given up.
We are not trying to talk you out of it
We use these tools ourselves. They are genuinely good at the first draft, the repetitive pass and the thing you have done fifty times before.
The point is that using them should not quietly cost you a data leak, or a page of confident nonsense with your name at the top of it. That is a setup problem, and setup problems have answers.