Your employees are already using AI. The only question is where the data goes.
This isn't a hypothetical risk you're deciding whether to take on. It's already happening, on devices and accounts you can't see, and the evidence for that is now well documented. The only real decision left is what happens to the data once it leaves.
The usage is already universal
Multiple independent surveys converge on the same picture: most employees use AI tools at work whether or not IT has approved them. WalkMe's 2025 survey put the figure at 78% of employees using unauthorized AI tools, and UpGuard's 2025 AI risk research reached a comparable figure of just over 80%. Cyberhaven Labs, analyzing real enterprise network traffic, found that 73.8% of ChatGPT accounts used from workplace networks were personal, non-corporate accounts, meaning the enterprise had no visibility into what was typed into them and no contractual protection over what happened to that data. A Salesforce survey of over 14,000 workers across 14 countries found more than half of generative-AI adopters at work use unapproved tools, and, tellingly, many of them said they recognized the need for a company-approved option but proceeded anyway because none existed.
Separately, CybSafe and the National Cybersecurity Alliance's 2025 research found that roughly 38% of employees admit to sharing confidential work information with AI tools without their employer's permission. This isn't a rogue minority. It's the median employee, using the same tools they use at home, for the same reason: those tools are fast and good at their job.
Why the risk is real, not theoretical
The reference case is Samsung's, and it's worth restating precisely because it's often exaggerated in retelling. In March 2023, within weeks of Samsung's semiconductor division lifting an internal ban on ChatGPT, three separate incidents occurred at its Device Solutions unit in Hwaseong: an engineer pasted the source code of a confidential database into ChatGPT and asked it to check for errors, another shared code for optimization, and a third uploaded a recording of an internal meeting and asked ChatGPT to turn it into minutes. None of that data was extracted by an attacker, it was handed over voluntarily, by employees trying to do their jobs faster, into a consumer product whose data-handling terms weren't written with a semiconductor manufacturer's IP in mind. Samsung's response, reported by Forbes and others, was to ban generative AI tools company-wide by May 2023 and open disciplinary reviews into the three employees involved.
Regulators have been paying attention to the same gap between consumer AI products and the obligations that apply to data run through them. Italy's Garante ordered OpenAI in March 2023 to stop processing the personal data of Italian users pending an investigation into transparency and legal-basis failures under GDPR, a suspension it lifted in April 2023 once OpenAI made changes, and which was followed in December 2024 by a €15 million fine from the same authority over how ChatGPT handles personal data. None of that concerned a leak or a breach; it concerned the default terms consumer AI products operate under, which is exactly the layer an employee pasting a customer list or a contract into ChatGPT is exposed to.
Why blocking it doesn't work
The instinctive response, block the domain at the firewall, doesn't hold up, and it's worth being precise about why. Personal devices, mobile hotspots, home Wi-Fi, and DNS-over-HTTPS all sit outside the corporate network perimeter that a firewall rule controls, so the block simply doesn't apply to them. A VPN does the same from inside the office, making traffic look like it originates from a home connection. And even where the network block does hold, it only kills one destination: employees who were using ChatGPT move to Claude, Gemini, or Copilot on a personal account instead, because the underlying need, get this written, summarized, or debugged faster, hasn't gone away.
The practical effect of blocking, in other words, is not less AI use. It's the same AI use, moved further from IT's visibility and further from any device you control, onto a personal phone, a personal laptop, a personal account with no admin console, no audit log, and no way for you to know what was pasted into it. IBM's 2025 Cost of a Data Breach Report found that breaches involving this kind of unsanctioned "shadow AI" cost organizations an average of $670,000 more than the global average cost of a data breach, a difference plausibly explained by exactly that loss of visibility.
The policy that actually works: give people somewhere sanctioned to go
The pattern across the surveys above is consistent: employees don't want to hide their AI use, and a majority say they'd use a sanctioned tool if one existed. Salesforce's respondents said as much directly. The lesson isn't "monitor harder", it's that prohibition without an alternative just pushes usage somewhere you can't see, while an approved, genuinely useful replacement gives people no reason to reach for their own phone. A workable policy has a few concrete pieces:
- Provide a sanctioned AI tool before you restrict anything. A ban issued without a replacement is a ban on visibility, not on usage.
- Make the sanctioned tool at least as fast and capable as what people already use. If it's slower or worse, the policy will be ignored exactly like the network block was.
- Keep the data path contractually and technically closed. Know, in writing, whether prompts are used for training, how long they're retained, and where they're processed, for the exact plan your organization is actually on, which often differs from the vendor's headline enterprise product.
- Cover personal accounts explicitly. Most of the exposure Cyberhaven found was personal accounts used on company time and company networks; a device policy alone misses all of it.
- Write down what can and can't go into any AI tool, sanctioned or not. Source code, customer PII, contracts, and unreleased financials belong on a short, explicit list, not left to individual judgment under deadline pressure.
- Explain the reasoning, then the rule. The Samsung engineers weren't malicious; they were solving a real problem the fastest way they knew. A rule without the reasoning behind it gets worked around the first time it's inconvenient.
- Revisit the policy as usage shifts. Shadow AI moves fast, new tools, new browser extensions, new defaults in productivity suites, so a policy written once and left alone drifts out of date within a year.
Where a private, EU-hosted assistant fits
The reason "provide a sanctioned tool" is the load-bearing item on that list is that it's the only one that actually competes with the convenience employees are already voting for. A dedicated, self-hosted assistant closes the specific gap the surveys above describe: it gives people the same chat-style interface they already reach for, but running on infrastructure your organization controls, in the EU, with no prompts leaving the building to train someone else's model. That's what a private ChatGPT alternative is for, the same day-to-day usefulness, minus the account you can't see into. For teams that want the full picture of what running models on owned or dedicated hardware looks like, cost, performance, and governance, see our guide to private LLM hosting.