Our people already put client files into ChatGPT — ban it, frame it, or supply a tool?

78% of employees bring their own AI tools to work, but 92 percent of AI breaches occur without model access controls. Traditional security tools cannot detect AI-specific data leakage, leaving organizations blind to unquantifiable data visibility risks.

· Counsel verdict · AIssential

The question

Staff are already using consumer AI tools on client documents, and we are bound by confidentiality obligations to those clients. We can ban it and enforce the ban, write a usage policy and trust people to follow it, or provide a sanctioned tool and route the work through it. What does each option actually cost, what does it do to the confidentiality exposure we would have to answer for, and which one survives contact with people who are already used to these tools?

Counsel's position

Provide a sanctioned, secure AI tool to channel existing staff behavior, minimizing confidentiality exposure and ensuring compliance.

Verdict

The verdict: Provide a sanctioned, secure AI tool to channel existing staff behavior, minimizing confidentiality exposure and ensuring compliance.

How the criteria decide

3 of 3 criteria resolved on cited evidence.

CriterionFavoursEvidence
Confidentiality exposure we would have to answer forProvide a sanctioned tool

Enterprise AI services do not train models on customer data

Major enterprise AI services explicitly distinguish between processing customer data and using it to train shared foundation models.

HackerNoon

92 percent of AI breaches occur without model access controls

an eye-watering 92 percent of AI-related breaches occurred at companies with zero access controls placed on their models.

Dataconomy

Traditional security tools cannot detect AI-specific data leakage

Traditional security tools can’t detect many AI attacks.

Artificial Intelligence on Medium

Whether staff actually complyProvide a sanctioned tool

78% of employees bring their own AI tools to work

78% of employees who use AI at work bring their own tools to do it.

The AI Journal

Cost and effort to operateWrite a usage policy

78% of employees bring their own AI tools to work

78% of employees who use AI at work bring their own tools to do it.

The AI Journal

Traditional security tools cannot detect AI-specific data leakage

Traditional security tools can’t detect many AI attacks.

Artificial Intelligence on Medium

78% of employees bring their own AI tools to work

Relying on acceptable use policies and firewall blocks fails because employees simply switch to personal devices and accounts to maintain productivity.

Enterprise AI services do not train models on customer data

The primary confidentiality risk of employee AI use is the unpredictable blast radius of data they submit, not the inherent nature of machine learning.

92 percent of AI breaches occur without model access controls

Ungoverned AI adoption exposes organizations to multi-million dollar breach costs and regulatory penalties.

Traditional security tools cannot detect AI-specific data leakage

Standard firewalls and endpoint protection fail to monitor or block sensitive client documents pasted into unsanctioned AI chatbots.

Opaque AI features create unquantifiable data visibility risks

Built-in AI assistants often route prompts and documents to external services, stripping institutions of their ability to prove control over sensitive data.

Read another verdict

Get Counsel for your own decisions →