Why it matters now
Your people are almost certainly using AI already, with or without permission. The risk is not that they use it. It is that they use it with company or customer data in tools you do not control, and that the company learns nothing from it. I would rather give people a safe, approved route and a clear rule than pretend a ban is working.
- 54% of employees say they would use AI tools even if their company had not authorised them.BCG, AI at Work 2025 ↗
- Only 30% of employees say their organisation has AI guidelines or policies.Gallup, AI use at work, 2025 ↗
Common mistakes
- Blanket bans that push use underground.
- No approved alternative, so people use whatever is free.
- Long policies nobody reads instead of a few clear rules.
- Punishing people for past use, so nobody tells you what is working.
What to do instead
- Provide approved tools fast. Give people secure, sanctioned AI tools that are good enough that they do not need to look elsewhere.
- Write a one-page policy. Say what is allowed, what is not, and which data must never go into which tools.
- Train on data. Show people concrete examples of what not to paste, and why.
- Offer an amnesty. Ask people how they already use AI, without blame. You will find risks to close and ideas worth scaling.
- Bring the best ideas in. Turn the most useful unofficial uses into supported projects with an owner.
Your first step this week
Ask your teams, without blame, which AI tools they use for work and what for. Use the answers to decide which tool to approve first.
Related guides
- How do we govern AI risk and use AI responsibly?
- How do I get my people to actually use AI?
- Should we mandate AI use or tie it to performance reviews?
All AI leadership principles and guides · 100 AI use cases by function