The tools nobody approved
The realistic picture
In most organisations, the AI policy is a document and the AI usage is something else. Surveys across several countries consistently find a large fraction of employees using AI tools at work that their employer has not approved, and a substantial share of those saying they have entered company information into them. The people doing it are not reckless. They have a deadline and a tool that helps.
Banning tools has a predictable result: usage moves to personal devices and personal accounts, where the organisation has no visibility, no contractual protection, no retention control and no log. The ban converts a manageable risk into an invisible one.
This lesson is about the version that works instead.
Why the ban fails, mechanically
Three reasons, all structural.
The benefit is immediate and personal; the risk is delayed and institutional. The employee gets an hour back today. The organisation gets an exposure that surfaces in eighteen months, if ever, and not to that employee.
There is no visible boundary. Nothing on the screen distinguishes pasting a public marketing page from pasting an unreleased forecast. Both are text in a box.
Enforcement is impossible on personal devices. A phone is not managed, and a phone can read a screen.
So the policy that works is not a prohibition. It is a supply. Provide an approved tool that is good enough, on business terms with training excluded and retention bounded, and make it easier to reach than the unapproved one. Every organisation that has reduced shadow usage did it this way.
A policy that fits on one page
The useful policy answers four questions concretely, in language a person can apply at speed.
Which tools are approved, for what. Named tools and named data categories. "Approved for internal documents and customer correspondence; not for personal data of customers, financial results before publication, or source code."
What must never go in, anywhere. A short, memorable, absolute list. Credentials and API keys. Special-category personal data. Anything under a third-party NDA. Unreleased financial information. Keep it to five items; a list of thirty is a list nobody remembers.
What to do before pasting. One concrete instruction, such as: replace names and account numbers with placeholders, and if you cannot, use the local tool instead.
Who to tell when something goes wrong, and what happens then. This is the clause that determines whether you ever hear about incidents. If the answer implies discipline, you will hear about none of them.
If you have already pasted something
A short runbook, because this happens to careful people.
Credentials — act today. API keys, passwords, tokens, connection strings. Rotate them now rather than reasoning about likelihood. The cost of rotation is an hour; the cost of the alternative is unbounded. Do not skip this because the conversation was deleted.
Personal data about others — tell someone. Under GDPR, DPDP and similar regimes, an organisation may have notification duties with tight deadlines, and those clocks start when the organisation becomes aware. Your data protection officer, or whoever plays that role, needs to make that assessment, and they cannot make it if nobody tells them.
Everything else — record and reduce. Note what went where and when. Delete the conversation, understanding that this removes it from your view and not necessarily from the abuse store. Check whether the account's training setting was on. If it was, look for the provider's process for requesting removal, which some offer and none guarantee.
The worst response is silence, because the harm from a disclosure is usually much smaller than the harm from a disclosure discovered late by someone else.
For the person setting this up
Measure it. Approved-tool usage against a rough estimate of total usage, and the number of self-reported incidents. A reported-incident count of zero means people are not telling you, not that nothing is happening. This is the same lesson as the override rate in the first module: the metric that looks like success is often the metric that means you have stopped receiving information.
The one thing to keep
Banning AI tools moves usage onto personal accounts where the organisation has no visibility or contract, so the policy that works supplies an approved tool, names a short absolute never-list, and makes reporting a mistake safe.
Before you move on
An engineer realises they pasted a configuration file containing a live database password into a consumer chatbot last week, then deleted the conversation. What is the first thing to do?
Pick the one you would defend. Nobody sees your answer.