Write an AI-use policy before we let staff use ChatGPT at work?
Public AI services accounted for 42% of enterprise data leaks in 2024, and shadow AI breaches add an average of $670,000 to incident costs, creating immediate governance and data visibility gaps.
The question
Our employees are already using ChatGPT and similar tools for work, with no formal policy. Do we write and roll out an acceptable-use policy now — covering what data can go in, which tools are approved, and what is off-limits — or is a formal policy premature for a company our size?
Counsel's position
Implement a phased acceptable-use policy now, focusing on data security and approved tools, to mitigate immediate risks and establish guardrails.
Verdict
The verdict: Implement a phased acceptable-use policy now, focusing on data security and approved tools, to mitigate immediate risks and establish guardrails.
How the criteria decide
3 of 5 criteria resolved on cited evidence. 1 had none either way.
| Criterion | Favours | Evidence |
|---|---|---|
| data security | Write and roll out policy | Public AI services accounted for 42% of enterprise data leaks in 2024 42% of enterprise data leaks in 2024 were traced directly back to the use of public AI services with sensitive information. Shadow AI breaches add an average of $670,000 to incident costs breaches involving high levels of Shadow AI add an average of $670,000 to the total cost of a data breach. Shadow AI causes 1 in 5 organizational data breaches according to the most recent IBM cost of a data breach report, 1 in 5 organizations have reported that they've experienced the data breach caused by shadow AI. |
| tool approval | Write and roll out policy | Unapproved AI usage creates immediate governance and data visibility gaps When employees use AI without approved tools, clear policies, or proper controls, organizations may gain speed while losing visibility. The Digital Transformation Playbook Automated governance controls prevent AI experimentation from becoming financial liability You’ve got to let folks have a playground but put a fence around the playground |
| compliance risk | Write and roll out policy | Unapproved AI usage creates immediate governance and data visibility gaps When employees use AI without approved tools, clear policies, or proper controls, organizations may gain speed while losing visibility. The Digital Transformation Playbook Automated governance controls prevent AI experimentation from becoming financial liability You’ve got to let folks have a playground but put a fence around the playground |
| employee productivity | Not resolved | |
| administrative burden | No evidence either way |
Public AI services accounted for 42% of enterprise data leaks in 2024
Given your employees are already using AI tools informally, delaying a formal policy leaves you exposed to immediate data exfiltration risks.
Shadow AI breaches add an average of $670,000 to incident costs
Formalizing an acceptable-use policy mitigates the severe financial penalties associated with unapproved, unmonitored employee AI usage.
Unapproved AI usage creates immediate governance and data visibility gaps
Waiting to establish a formal policy allows employees to embed unmonitored AI tools into their daily workflows, accelerating risk.
Shadow AI causes 1 in 5 organizational data breaches
Given your lack of a formal policy, defining approved tools and data limits is critical to preventing inadvertent data leakage.
Automated governance controls prevent AI experimentation from becoming financial liability
While establishing your acceptable-use policy for data, you must also define financial guardrails to prevent runaway costs from decentralized AI usage.
Read another verdict
- Which process should we point AI at first?
- Put one person in charge of AI — or is a Head of AI premature for us?
- Buy a tool for this process, or build around our own knowledge?
- Centralize AI strategy under CEO or distribute ownership?
- Adopt new AI ROI tools or refine existing methods?
- Invest in pre-build costing or post-deployment ROI tracking?
- Our documents are a mess. Clean them up before AI, or after?
- How do we measure the return on an AI workflow — and what baseline is honest?