This is happening in your organization right now. Published surveys consistently find that large majorities of knowledge workers use AI tools at work, a substantial share without approval, and a meaningful minority have entered sensitive company data.
The question is not whether to allow it. The question is whether the version that happens is the governed one.
Why the instinct to block fails
The productivity benefit is real, which changes the dynamics entirely. People are not pasting contracts into a chatbot to be reckless — they are doing it because it saves them an hour.
Block it at the firewall and three things happen: the work moves to personal phones and home laptops where you have zero visibility, the people most likely to circumvent are your highest performers, and you have converted a manageable governance problem into an invisible one.
The realistic objective is not zero unsanctioned use. It is that the sanctioned path is good enough, and fast enough to get approval for, that working around it is not worth the effort.
Step 1 — Measure honestly
Before policy, find out what is actually happening:
- Network telemetry for traffic to known AI endpoints.
- SaaS discovery tooling for AI applications in use.
- Browser extension inventory — extensions with broad page-content permissions are a large and under-examined exposure.
- Expense and card data for personal AI subscriptions being reimbursed.
- An amnesty survey. Explicitly no-blame. This consistently surfaces more than the tooling does, provided people believe it.
Also audit your existing approved vendors. They have been shipping AI features continuously, often on by default, sometimes under terms you have not reviewed. This is frequently the biggest single exposure and the least visible.
Step 2 — Provide the sanctioned path, fast
This is the part that determines success, and it has to come before enforcement.
Provision an enterprise-tier tool with contractual protection on training use and retention — see protecting data from AI labs. Make it available to everyone who wants it, not just a pilot group. Provision in days.
Two failure modes to avoid. A sanctioned tool materially worse than the consumer alternative will be ignored. And a two-week approval process for new tools guarantees circumvention — publish a pre-approved list and a lightweight path for additions.
Step 3 — Write a policy people can follow
One page. Not "do not use AI." A data classification with concrete examples:
| Data type | Consumer AI tools | Sanctioned enterprise AI | Private / self-hosted |
|---|---|---|---|
| Public marketing content | Fine | Fine | Fine |
| Internal non-sensitive | No | Fine | Fine |
| Customer personal data | No | Only if terms permit | Fine |
| Regulated data (health, financial) | No | Check obligations | Fine |
| Source code | No | Per policy | Fine |
| Client-confidential under NDA | No | Check the NDA | Usually fine |
| Credentials and secrets | Never | Never | Never |
Give real examples from your own business. "A customer's support ticket" is clearer than "personal data."
Add three rules beyond classification:
- Review AI output before it enters work product. Fabricated citations and wrong figures are your liability, not the tool's.
- Use organization credentials, not personal ones, for anything automated — otherwise access is orphaned when people leave.
- Check your client contracts. Many restrict disclosure to third parties or require approved sub-processors. An employee pasting a client document can put you in breach regardless of your internal policy.
Step 4 — Train on reasoning, not rules
People who understand why pasting a client contract is a problem make better decisions in situations your policy did not anticipate. People who memorized a rule list do not.
Fifteen minutes on what happens to data you submit, what the contractual difference between tiers actually is, and two or three real examples of how this goes wrong will outperform an hour of policy recitation.
Where this is heading
Today this is a disclosure problem — people sending information out. As employees adopt tools that act on their behalf, it becomes an authorization problem: agents operating with staff credentials, taking actions nobody reviewed. That is a materially larger risk class, and it is why agent access control is worth getting ahead of now.
Frequently asked questions
Should we block ChatGPT at work?
Blocking alone reliably backfires by pushing use onto personal devices where you have no visibility. Blocking specific high-risk tools while providing a good sanctioned alternative can work. Blocking with no alternative does not, and costs you the productivity benefit your competitors are getting.
What if an employee already pasted sensitive data?
Determine what was sent, to which tool and account tier, and what the applicable terms say about retention and training. Request deletion where the agreement allows. Assess notification obligations if regulated or client data was involved. Then treat it as the trigger to establish the sanctioned path — punishing the individual without fixing the cause changes nothing.
Do we need a separate AI policy?
Usually you extend existing policy rather than creating a parallel one. Your acceptable-use, data-classification, and third-party-disclosure policies already cover most of it. What needs adding is explicit guidance on which tools are approved for which data tier, and a rule about reviewing AI output before use.
How do we monitor compliance without surveillance?
Focus on aggregate visibility rather than individual monitoring: which tools are in use at what scale, whether sanctioned tool adoption is rising, and whether sensitive data classifications are being routed correctly. Heavy individual surveillance damages trust and pushes use further underground.
What about AI features inside tools we already approved?
Audit them specifically, because this is the largest blind spot in most organizations. Review what each feature sends where, what the terms permit, and whether it is on by default. Turn off what you have not assessed, and add AI-feature review to your vendor management process going forward.
