Our people already put client files into ChatGPT — ban it, frame it, or supply a tool?
78% of employees bring their own AI tools to work, but 92 percent of AI breaches occur without model access controls. Traditional security tools cannot detect AI-specific data leakage, leaving organizations blind to unquantifiable data visibility risks.
The question
Staff are already using consumer AI tools on client documents, and we are bound by confidentiality obligations to those clients. We can ban it and enforce the ban, write a usage policy and trust people to follow it, or provide a sanctioned tool and route the work through it. What does each option actually cost, what does it do to the confidentiality exposure we would have to answer for, and which one survives contact with people who are already used to these tools?
Counsel's position
Provide a sanctioned, secure AI tool to channel existing staff behavior, minimizing confidentiality exposure and ensuring compliance.
Verdict
The verdict: Provide a sanctioned, secure AI tool to channel existing staff behavior, minimizing confidentiality exposure and ensuring compliance.
How the criteria decide
3 of 3 criteria resolved on cited evidence.
| Criterion | Favours | Evidence |
|---|---|---|
| Confidentiality exposure we would have to answer for | Provide a sanctioned tool | Enterprise AI services do not train models on customer data Major enterprise AI services explicitly distinguish between processing customer data and using it to train shared foundation models. 92 percent of AI breaches occur without model access controls an eye-watering 92 percent of AI-related breaches occurred at companies with zero access controls placed on their models. Traditional security tools cannot detect AI-specific data leakage Traditional security tools can’t detect many AI attacks. |
| Whether staff actually comply | Provide a sanctioned tool | 78% of employees bring their own AI tools to work 78% of employees who use AI at work bring their own tools to do it. |
| Cost and effort to operate | Write a usage policy | 78% of employees bring their own AI tools to work 78% of employees who use AI at work bring their own tools to do it. Traditional security tools cannot detect AI-specific data leakage Traditional security tools can’t detect many AI attacks. |
78% of employees bring their own AI tools to work
Relying on acceptable use policies and firewall blocks fails because employees simply switch to personal devices and accounts to maintain productivity.
Enterprise AI services do not train models on customer data
The primary confidentiality risk of employee AI use is the unpredictable blast radius of data they submit, not the inherent nature of machine learning.
92 percent of AI breaches occur without model access controls
Ungoverned AI adoption exposes organizations to multi-million dollar breach costs and regulatory penalties.
Traditional security tools cannot detect AI-specific data leakage
Standard firewalls and endpoint protection fail to monitor or block sensitive client documents pasted into unsanctioned AI chatbots.
Opaque AI features create unquantifiable data visibility risks
Built-in AI assistants often route prompts and documents to external services, stripping institutions of their ability to prove control over sensitive data.
Read another verdict
- Start with a small test, or take on the whole process at once?
- Our competitors advertise AI and we don't — match them, or hold the line?
- Our most experienced person retires in two years — how do we keep what they know?
- We can't hire the experienced people we need — automate, train up, or outsource?
- Slow our EU AI Act prep now the deadline's moved to 2027?
- Use AI to flatten middle management this year?
- Let an AI agent act on its own — or keep a human in the loop?
- Invest in pre-build costing or post-deployment ROI tracking?