Write an AI-use policy before we let staff use ChatGPT at work?

Shadow AI now accounts for all data breaches, with 42% of enterprise data leaks in 2024 traced to public AI services. Without a formal policy, 71% of knowledge workers using AI outside governance frameworks expose the organization to severe data leakage and prompt injection risks.

· Counsel verdict · AIssential

The question

Our employees are already using ChatGPT and similar tools for work, with no formal policy. Do we write and roll out an acceptable-use policy now — covering what data can go in, which tools are approved, and what is off-limits — or is a formal policy premature for a company our size?

Counsel's position

Implement an acceptable-use policy now to mitigate critical data security and compliance risks from unmanaged AI usage.

Verdict

The verdict: Implement an acceptable-use policy now to mitigate critical data security and compliance risks from unmanaged AI usage.

How the criteria decide

4 of 5 criteria resolved on cited evidence. 1 had none either way.

CriterionFavoursEvidence
data securityWrite and roll out policy

Shadow AI now accounts for all data breaches

Organizations that suffer violations often lack a formal AI governance policy in place. This is not just a compliance issue; it’s an indicator that leadership has not laid the necessary groundwork for secure AI operations.

AI on Medium

Public AI services caused 42% of enterprise data leaks in 2024

And 42% of enterprise data leaks in 2024 were traced directly back to the use of public AI services with sensitive information.

HackerNoon

Unapproved AI usage creates severe data leakage and prompt injection risks

78% of organizations now use AI in at least one business function.

Artificial Intelligence on Medium

tool approvalWrite and roll out policy

71% of knowledge workers use AI outside organizational governance frameworks

By mid-2025, an estimated 71% of knowledge workers were utilizing AI tools outside of organizational governance frameworks.

Pascal’s Substack

Employees default to unapproved public AI when formal policies lag

Employees often use public tools outside official systems when formal workflows are too slow or restrictive. This creates governance problems.

The Digital Transformation Playbook

compliance riskWrite and roll out policy

Shadow AI now accounts for all data breaches

Organizations that suffer violations often lack a formal AI governance policy in place. This is not just a compliance issue; it’s an indicator that leadership has not laid the necessary groundwork for secure AI operations.

AI on Medium

Public AI services caused 42% of enterprise data leaks in 2024

And 42% of enterprise data leaks in 2024 were traced directly back to the use of public AI services with sensitive information.

HackerNoon

Unapproved AI usage creates severe data leakage and prompt injection risks

78% of organizations now use AI in at least one business function.

Artificial Intelligence on Medium

employee productivityDo not write and roll out policy

Employees default to unapproved public AI when formal policies lag

Employees often use public tools outside official systems when formal workflows are too slow or restrictive. This creates governance problems.

The Digital Transformation Playbook

administrative burdenNo evidence either way

Shadow AI now accounts for all data breaches

Employees using free AI tools via personal accounts inadvertently expose sensitive organizational data to external platforms.

Public AI services caused 42% of enterprise data leaks in 2024

Employees regularly share internal company data with generative AI tools without authorization, creating massive data liabilities when centralized platforms process the requests.

71% of knowledge workers use AI outside organizational governance frameworks

The proliferation of unauthorized AI tools represents a fundamental collapse of traditional IT management and directly correlates with costly security breaches.

Unapproved AI usage creates severe data leakage and prompt injection risks

Traditional security tools cannot detect AI-specific threats, making shadow AI a critical vulnerability for organizations without dedicated policies.

Employees default to unapproved public AI when formal policies lag

A lack of clear governance and approved tools forces employees to use public AI systems, creating hidden risks and data exposure.

Read another verdict

Get Counsel for your own decisions →