Most employees know their company has an AI policy, but use their own tools anyway to get the work done faster.

86% of office professionals work somewhere they believe has an AI policy. Two-thirds have used AI at work anyway, believing it wasn’t permitted.

Informal AI use, often called shadow AI, is whatever an employee finds on their own: a personal account, a browser extension, a free tier with no contract behind it. A formal AI program is provisioned tools, defined limits on what data can go in, a named owner, and a record of what’s running.

Almost no organization is choosing between the two; both are already operating, but leadership can usually see only one.

How much informal AI use is happening

Two-thirds use AI they believe is off-limits. 66% of office professionals say they’ve used AI tools at work despite believing the tools weren’t permitted, rising to 72% at organizations with 1,500 or more employees, according to PagerDuty’s 2026 Shadow AI Survey of 1,250 non-IT professionals at companies with $500 million or more in revenue.

Policy adoption has outrun the controls behind it. Formal AI policies nearly doubled year over year, from 38% to 68%. But only 55% of employers have a review or approval process for AI tools and use cases, and only 54% restrict what information employees can enter, per Littler’s 2026 Annual Employer Survey.

Leaders suspect prohibited use but can’t see it. Gartner found 69% of cybersecurity leaders suspect or have evidence that employees are using prohibited public GenAI tools. Yet only 25% of organizations report comprehensive visibility into employee AI use, according to Optro’s The AI Oversight Gap.

What it costs

The cost is measurable. Shadow AI incidents rose from 20% to 43% of breached organizations year over year. Those organizations averaged $5.39 million per breach against a $4.99 million global average, and roughly one in five shadow AI incidents drew a regulatory fine, according to IBM’s 2026 Cost of a Data Breach Report.

Most AI users have had no training. 58% of workers using AI have received no training on its security or privacy risks, and 43% have shared sensitive workplace information with AI tools without their employer’s knowledge, per the Oh Behave! 2025-2026 report from the National Cybersecurity Alliance and CybSafe, covering 6,500 respondents across seven countries.

What separates the two

The tool is rarely the difference. An employee using Claude through an enterprise account and an employee using the same model through a personal login are doing similar work. But everything around the tool differs.

Informal (shadow) AI use Formal AI program
Access Personal accounts, browser extensions, whatever the employee finds Provisioned enterprise accounts with SSO and admin controls
Data handling Employees paste company and customer data into public models with no contract terms Data processing agreements, retention limits, and training opt-outs in place
Accountability No one owns the decision to use the tool A named owner and approval workflow for new use cases
Visibility IT can’t see what’s running or what data left the building Usage is logged, reviewed, and auditable
Training Employees learn by trial and error The company trains employees on what’s approved and why
Policy A blanket ban that employees quietly ignore A risk-tiered policy that matches oversight to the stakes

Why the difference matters

Access is where the money is. Among organizations that suffered an AI-related breach, IBM found that 92% lacked proper AI access controls, and only 32% had an AI governance policy at all, down from 37% the year before.

Data handling is what Littler’s split exposes. 68% of employers have a policy; 54% restrict what data can go into a tool. So a policy that never names off-limits data governs the tool rather than the risk.

Accountability usually has no clear owner. Optro found that no single function owns more than 25% of AI governance: IT at 25%, risk management at 18%, cross-functional arrangements at 17%. As a result, informal use fills the space nobody claimed.

Visibility is what turns a suspicion into a finding. Gartner’s 69% who suspect prohibited use, set against Optro’s 25% who can confirm what’s running, leaves most security leaders holding a belief they can’t document.

Training moves with exposure. The 58% of AI users who’ve had none and the 43% who’ve shared sensitive information without their employer’s knowledge are largely the same population.

Why banning AI backfires (and what to do instead)

PagerDuty’s data undercuts the assumption that awareness is the problem. Employees who said they understood the AI security rules used the tools more often than employees who said they didn’t. And 48% of employees who used unauthorized tools faced formal discipline, with no change in the behavior that triggered it.

Banning AI doesn’t stop employees from using it. It stops the company from seeing it. PagerDuty also found that 77% of employees believe company AI restrictions limit their professional growth, and 75% would consider leaving for an employer offering better AI skills development. So restriction without a usable alternative creates a retention problem on top of a security one.

Two-thirds of employers already have the policy document. What makes it a program is what sits behind the document: provisioned access, data limits, a named owner, logging, training, and an approved path fast enough that employees take it without being told to.

Compensation teams carry more risk than most

Merit matrices, pay equity analyses, and long-term incentive models hold the most sensitive employee data in the organization, and they’re exactly the work people are most tempted to shortcut with a fast, unsanctioned tool.

The way to keep that data in place is to put the AI inside the system that already holds it. HRSoft Intelligence works within the compensation lifecycle platform, on data already governed by the customer’s roles, permissions, and approval workflows. A comp analyst modeling a merit budget or testing a proration rule for mid-year hires gets that help where the data lives, with no paste into a public model. Recommendations assist the person deciding, and they move through the same approvals a manual decision would. For a comp team, the sanctioned path and the fast path become the same path, which is the only version employees reliably follow.

See how HRSoft handles compensation data across the full compensation lifecycle: book a demo.