Nobody approved that AI tool. Your team is using it anyway.
Most companies have a policy about which AI tools are allowed. Most employees have already ignored it - and a lot of them have pasted real customer and financial data into tools nobody ever vetted.
Two-thirds of office workers are already doing it
PagerDuty surveyed 1,250 professionals at companies with more than $500 million in revenue and found that 66 percent had used an AI tool at work they believed wasn't permitted under company policy. Eighty-eight percent had shared real work information with a public AI tool like ChatGPT or Gemini - 43 percent pasted in emails, 40 percent meeting notes, 34 percent customer data, 31 percent financial or confidential documents. That's not a handful of rule-breakers. That's the default behavior of people who found a tool that makes their afternoon shorter and didn't wait for anyone's permission.
The bill never has 'AI' written on it
IBM's 2025 Cost of a Data Breach Report found that 21 percent of the breaches it studied involved shadow AI, and those breaches cost an average of $670,000 more than the ones that didn't. They also leaked more sensitive data than average - personal information showed up in 65 percent of shadow AI breaches versus a 53 percent global average, intellectual property in 40 percent versus 33 percent. Nobody budgets a line item for 'the tool someone tried last Tuesday.' It shows up months later, folded into an incident response invoice, looking exactly like a security failure instead of what it actually was.
A policy nobody checks isn't a policy
In that same report, 63 percent of breached organizations either had no formal AI governance or were still building one, and even among those with a written policy, only 34 percent actually audited for unauthorized use. Banning a tool that saves someone two hours a day doesn't stop them from using it - it just stops them from telling anyone. The problem was never that people want to use AI. It's that almost nobody can say which tools are touching company data right now, today, in this exact moment.
The ACS approach
We don't treat a written policy as the control - visibility is the control. Before client data goes near any AI tool on a project we build or run, we know which tool it is, what it does with the input, and whether it trains on it. 'We have a policy' isn't an answer to 'where did that data go.' If we can't answer the second question, the first one was just decoration.