The Brief · August 3, 2026

Two-thirds of your office already uses AI you never approved. The executives lead the way.

A new survey of professionals at large companies found most use AI tools they believe are against the rules — and think their own judgment beats the team that sets those rules. Banning the tools didn't end the behavior. It just moved it somewhere you can't see.

A vast dark open-plan office at night, empty desks receding into shadow, cool teal and steel-blue light from distant windows falling across a faintly reflective floor

The office is empty, but the work isn't finished. Somewhere in most companies, the most-used AI tool is one nobody signed off on — running quietly, after hours and during them, on data that never asked permission to leave.

What happened

A survey of 1,250 office professionals in non-technical roles — all at companies earning $500 million or more a year, across the US, UK, Australia, and Japan — asked a blunt question about how they actually use AI at work.

Two-thirds of them, 66%, said they had used AI tools that they believed were not permitted under company policy.

The finding isn't that people use AI at work. It's that most of them do it knowing it breaks the rules — and do it anyway.

This is what's now called "shadow AI": tools an employer never sanctioned, running on company work, invisible to the people meant to govern them. It has gone from a niche IT worry to ordinary workplace behavior in under two years.

What makes the number land is where it was measured. These aren't scrappy startups without a rulebook — they're large, established companies, exactly the kind most likely to have a written AI policy in the first place. The policy exists. It's simply being outvoted.

The detail almost everyone will miss

The easy conclusion is that this is a discipline problem — junior staff cutting corners while the grown-ups follow the policy. The data points the other way.

81% of respondents said they believe leadership operates under a different set of rules than everyone else when it comes to AI.

And the confidence runs deep. 72% think they understand how to use AI for their job better than the team responsible for managing it — a number that climbs to 80% at billion-dollar firms.

The tools didn't arrive through procurement, either. Nearly nine in ten first met the AI they now use for work in their personal lives, then carried it across into the office.

Shadow AI isn't a rule being broken at the bottom of the org chart. It's a rule that stopped matching how people — including the people who wrote it — actually work.

Glass-walled corporate offices at night lit from within with cool teal light, dark corridor and polished reflective floor between them

Every glass wall is a rule about who can see in. Shadow AI is what happens when the people behind the nicest walls quietly decide the rules are for someone else — and the rest of the floor takes the hint.

Why this matters if you run a business

The exposure here is not hypothetical. Among those who used AI at work, 88% said they had put work-related information into public tools — and 31% had entered financial data or confidential documents.

Most of that goes into consumer versions with no enterprise data controls. In plain terms: your contracts, customer records, and numbers can leave the building through a browser tab, with no log of where they went.

Every unapproved tool is an unmonitored door your data walks out of — and a blanket ban is what jams that door open, because it pushes the usage somewhere you can't see.

A policy nobody follows is worse than no policy. It hands you the paperwork of control and none of the reality — and it's the version a regulator or an acquirer will hold you to when something goes wrong.

A dark corridor lined with server cabinets at night, cool teal-mint light glowing from the far end, faint reflection on the floor

Data rarely leaves through the front door. It slips down the quiet corridor — one pasted paragraph, one uploaded spreadsheet at a time — toward a system your security team was never told to watch.

What to do about it

The instinct is to tighten the ban. The evidence says the opposite works better: make the safe path the easy one, so the behavior people are already doing has somewhere legitimate to land.

  • Sanction a good default. Give people one enterprise-grade AI tool with real data controls, so the thing they're already doing has a legal, logged home instead of a hidden one.
  • Ask where it's happening — without blame. A no-fault survey of your own team surfaces the tools already in use faster than any audit, because people will tell you what they'll never confess to a policy.
  • Fix the example at the top. If leadership visibly plays by different rules, the policy reads as theater — and everyone below treats it exactly that way.
  • Remove the friction. Shadow AI thrives wherever the approved option is slower or clumsier than the free one. Close that gap and most of the problem closes with it.

Your people have already chosen AI. The only decision left to you is whether they use it somewhere you can see — or somewhere you can't.

Signal check

Also worth knowing today

AI News

The approved wave is arriving as fast as the unapproved one.

Gartner projects that 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from less than 5% in 2025. The operator read: even if you lock down consumer AI, agents are being built into the software you already pay for — so the governance question isn't whether AI runs in your business, but whether it runs on terms you set.

2026 forecastSource →
AI News

Governed AI ships roughly three times faster than the ungoverned kind.

A July survey of 639 senior enterprise AI leaders found that organizations with fully integrated AI governance were far likelier to report improved delivery velocity (about 75%) than those where governance lagged (about 23%). The tie to today's story: the answer to shadow AI isn't a heavier ban — it's governance that makes the sanctioned path the faster path.

Jul 21, 2026Source →