Write an AI-use policy before we let staff use ChatGPT at work?
Shadow AI now accounts for all data breaches, with 42% of enterprise data leaks in 2024 traced to public AI services. Without a formal policy, 71% of knowledge workers using AI outside governance frameworks expose the organization to severe data leakage and prompt injection risks.
The question
Our employees are already using ChatGPT and similar tools for work, with no formal policy. Do we write and roll out an acceptable-use policy now — covering what data can go in, which tools are approved, and what is off-limits — or is a formal policy premature for a company our size?
Counsel's position
Implement an acceptable-use policy now to mitigate critical data security and compliance risks from unmanaged AI usage.
Verdict
The verdict: Implement an acceptable-use policy now to mitigate critical data security and compliance risks from unmanaged AI usage.
How the criteria decide
4 of 5 criteria resolved on cited evidence. 1 had none either way.
| Criterion | Favours | Evidence |
|---|---|---|
| data security | Write and roll out policy | Shadow AI now accounts for all data breaches Organizations that suffer violations often lack a formal AI governance policy in place. This is not just a compliance issue; it’s an indicator that leadership has not laid the necessary groundwork for secure AI operations. Public AI services caused 42% of enterprise data leaks in 2024 And 42% of enterprise data leaks in 2024 were traced directly back to the use of public AI services with sensitive information. Unapproved AI usage creates severe data leakage and prompt injection risks 78% of organizations now use AI in at least one business function. |
| tool approval | Write and roll out policy | 71% of knowledge workers use AI outside organizational governance frameworks By mid-2025, an estimated 71% of knowledge workers were utilizing AI tools outside of organizational governance frameworks. Employees default to unapproved public AI when formal policies lag Employees often use public tools outside official systems when formal workflows are too slow or restrictive. This creates governance problems. |
| compliance risk | Write and roll out policy | Shadow AI now accounts for all data breaches Organizations that suffer violations often lack a formal AI governance policy in place. This is not just a compliance issue; it’s an indicator that leadership has not laid the necessary groundwork for secure AI operations. Public AI services caused 42% of enterprise data leaks in 2024 And 42% of enterprise data leaks in 2024 were traced directly back to the use of public AI services with sensitive information. Unapproved AI usage creates severe data leakage and prompt injection risks 78% of organizations now use AI in at least one business function. |
| employee productivity | Do not write and roll out policy | Employees default to unapproved public AI when formal policies lag Employees often use public tools outside official systems when formal workflows are too slow or restrictive. This creates governance problems. |
| administrative burden | No evidence either way |
Shadow AI now accounts for all data breaches
Employees using free AI tools via personal accounts inadvertently expose sensitive organizational data to external platforms.
Public AI services caused 42% of enterprise data leaks in 2024
Employees regularly share internal company data with generative AI tools without authorization, creating massive data liabilities when centralized platforms process the requests.
71% of knowledge workers use AI outside organizational governance frameworks
The proliferation of unauthorized AI tools represents a fundamental collapse of traditional IT management and directly correlates with costly security breaches.
Unapproved AI usage creates severe data leakage and prompt injection risks
Traditional security tools cannot detect AI-specific threats, making shadow AI a critical vulnerability for organizations without dedicated policies.
Employees default to unapproved public AI when formal policies lag
A lack of clear governance and approved tools forces employees to use public AI systems, creating hidden risks and data exposure.
Read another verdict
- Start with a small test, or take on the whole process at once?
- Our competitors advertise AI and we don't — match them, or hold the line?
- Our people already put client files into ChatGPT — ban it, frame it, or supply a tool?
- Our most experienced person retires in two years — how do we keep what they know?
- We can't hire the experienced people we need — automate, train up, or outsource?
- Slow our EU AI Act prep now the deadline's moved to 2027?
- Use AI to flatten middle management this year?
- Let an AI agent act on its own — or keep a human in the loop?