Write an AI-use policy before we let staff use ChatGPT at work?

Public AI services accounted for 42% of enterprise data leaks in 2024, and shadow AI breaches add an average of $670,000 to incident costs, creating immediate governance and data visibility gaps.

· Counsel verdict · AIssential

The question

Our employees are already using ChatGPT and similar tools for work, with no formal policy. Do we write and roll out an acceptable-use policy now — covering what data can go in, which tools are approved, and what is off-limits — or is a formal policy premature for a company our size?

Counsel's position

Implement a phased acceptable-use policy now, focusing on data security and approved tools, to mitigate immediate risks and establish guardrails.

Verdict

The verdict: Implement a phased acceptable-use policy now, focusing on data security and approved tools, to mitigate immediate risks and establish guardrails.

How the criteria decide

3 of 5 criteria resolved on cited evidence. 1 had none either way.

CriterionFavoursEvidence
data securityWrite and roll out policy

Public AI services accounted for 42% of enterprise data leaks in 2024

42% of enterprise data leaks in 2024 were traced directly back to the use of public AI services with sensitive information.

HackerNoon

Shadow AI breaches add an average of $670,000 to incident costs

breaches involving high levels of Shadow AI add an average of $670,000 to the total cost of a data breach.

Pascal’s Substack

Shadow AI causes 1 in 5 organizational data breaches

according to the most recent IBM cost of a data breach report, 1 in 5 organizations have reported that they've experienced the data breach caused by shadow AI.

IBM Technology

tool approvalWrite and roll out policy

Unapproved AI usage creates immediate governance and data visibility gaps

When employees use AI without approved tools, clear policies, or proper controls, organizations may gain speed while losing visibility.

The Digital Transformation Playbook

Automated governance controls prevent AI experimentation from becoming financial liability

You’ve got to let folks have a playground but put a fence around the playground

AI – SiliconANGLE

compliance riskWrite and roll out policy

Unapproved AI usage creates immediate governance and data visibility gaps

When employees use AI without approved tools, clear policies, or proper controls, organizations may gain speed while losing visibility.

The Digital Transformation Playbook

Automated governance controls prevent AI experimentation from becoming financial liability

You’ve got to let folks have a playground but put a fence around the playground

AI – SiliconANGLE

employee productivityNot resolved
administrative burdenNo evidence either way

Public AI services accounted for 42% of enterprise data leaks in 2024

Given your employees are already using AI tools informally, delaying a formal policy leaves you exposed to immediate data exfiltration risks.

Shadow AI breaches add an average of $670,000 to incident costs

Formalizing an acceptable-use policy mitigates the severe financial penalties associated with unapproved, unmonitored employee AI usage.

Unapproved AI usage creates immediate governance and data visibility gaps

Waiting to establish a formal policy allows employees to embed unmonitored AI tools into their daily workflows, accelerating risk.

Shadow AI causes 1 in 5 organizational data breaches

Given your lack of a formal policy, defining approved tools and data limits is critical to preventing inadvertent data leakage.

Automated governance controls prevent AI experimentation from becoming financial liability

While establishing your acceptable-use policy for data, you must also define financial guardrails to prevent runaway costs from decentralized AI usage.

Read another verdict

Get Counsel for your own decisions →