Is your team using banned AI tools?

AI, Cyber Security, SMEs

A conversation I’m having with business owners more and more often starts with a reassuring statement:

“We don’t really use AI yet.”

A few questions later, a very different picture usually emerges.

Someone is using ChatGPT to help write emails.

Another employee is summarising meeting notes with an AI tool.

A member of the sales team has discovered a browser extension that helps create proposals more quickly.

Someone in finance is using AI to analyse spreadsheets.

The business may not have formally adopted AI, but AI has arrived anyway.

And that’s exactly what’s happening across organisations worldwide.

According to Microsoft’s 2024 Work Trend Index, 75% of knowledge workers are already using AI at work, and almost half started using it within the previous six months. Perhaps more importantly, many employees are bringing their own AI tools into the workplace rather than waiting for their employer to provide them.

The reality is simple: people are curious. If a tool helps them work faster, save time, or reduce repetitive tasks, they’re naturally going to try it.

In many cases, the motivation is entirely positive.

The problem isn’t that people want to be more productive.

The problem is that businesses often have no visibility over what’s happening.

The Productivity Trap

Imagine a member of your team receives a lengthy customer email.

They paste it into a public AI chatbot and ask it to draft a response.

The reply comes back in seconds and saves them fifteen minutes of work.

The next day, they do it again.

A week later, they upload a proposal because they want a summary.

A month later, somebody else is using another AI tool to analyse financial data.

At no point does anyone feel they’re doing something dangerous. In fact, they probably feel they’re doing exactly what the business wants: finding better ways to work.

That’s what makes AI adoption different from many other technology risks.

There is no malicious intent.

No attempt to bypass security.

No desire to break company policy.

Employees are simply solving problems.

Unfortunately, that’s often how risk is introduced.

Customer information, financial data, contracts, proposals, HR records, and commercially sensitive documents can all find their way into tools that have never been reviewed, approved, or assessed by the business.

By the time leadership becomes aware of it, those workflows may already be deeply embedded into the way people work.

Why AI Spreads Faster Than Other Technology

Most business software follows a predictable path.

A new accounting package is evaluated before it’s purchased.

A new CRM system goes through budget approvals and implementation planning.

Security reviews, procurement processes, and stakeholder discussions happen before the technology is adopted.

AI doesn’t behave like that.

AI is often discovered by individuals in the middle of the working day.

Someone sees a LinkedIn post.

A colleague shares a prompt.

A free trial appears online.

Within minutes, a new workflow exists.

That means AI adoption can spread organically throughout a business long before leadership has discussed strategy, governance, or policy.

Microsoft’s research found that employees are increasingly choosing their own AI tools to help them work more effectively. This is creating what many organisations now refer to as “shadow AI” – the use of AI systems without formal oversight or approval.

The challenge isn’t stopping people from using AI.

It’s understanding where it’s being used, what data is being entered, and whether appropriate safeguards are in place.

The Hidden Risk Isn’t AI. It’s Lack of Visibility.

Many conversations around AI focus on dramatic scenarios such as job displacement, robots replacing workers, or futuristic technology risks.

In reality, the biggest risk for most organisations today is far less exciting.

It’s a lack of visibility.

If you don’t know:

  • Who is using AI
  • Which tools they’re using
  • What information they’re entering
  • Where that information is being processed
  • Whether it complies with your regulatory obligations

…then you can’t effectively manage the risk.

This becomes particularly important in sectors such as legal, financial services, healthcare, and professional services, where confidentiality, compliance, and data protection obligations are critical.

Employees may assume that because a tool looks professional, it must be safe to use.

Unfortunately, that’s not always the case.

The responsibility sits with the organisation to provide guidance, approved alternatives, and clear expectations.

The Answer Isn’t Banning AI

One of the biggest mistakes businesses can make is treating AI as something that needs to be stopped.

That approach rarely works.

If employees believe a tool genuinely helps them do their job better, telling them not to use it without offering an alternative often creates frustration rather than compliance.

Instead, organisations should aim to create an environment where innovation and governance work together.

That means having open conversations about AI.

Understanding how teams are already using it.

Providing approved tools where appropriate.

Defining clear rules around what information can and cannot be shared.

Educating staff about the risks without creating fear.

Done well, this approach allows businesses to capture the productivity benefits of AI whilst maintaining control over security, compliance, and data protection.

Start With One Simple Question

Many business leaders are spending time debating whether AI will impact their organisation.

In reality, that question has already been answered.

It has.

The more important question is whether it’s happening under your control.

If you’ve never asked your team which AI tools they’re currently using, the answers may surprise you.

It’s one of the simplest and most valuable conversations you can have.

Because before you can govern AI, secure AI, or benefit from AI, you first need visibility.

And visibility starts with asking the question.

If you’d like help understanding how AI is already being used across your business, identifying potential risks, and putting practical governance measures in place, we’d be happy to help.