AI at work: a governance gap, not a discipline problem
UK workers spend an estimated £958 million a year of their own money on AI tools for work – usually because nobody has told them what good looks like.
In short
- Two thirds of UK staff who use AI at work say leadership hasn't given them convincing guidance. Around half have had no training.
- So when people use AI tools their employer doesn't know about, it's usually a gap in guidance – not bad intent.
- Good intentions don't reduce the risk. The fix: find out what's in use, decide what's allowed, and give people a safe option.
Deloitte's new research on AI at work has a headline figure: UK workers are spending an estimated £958 million a year of their own money on AI tools for work.
The more telling numbers sit underneath. Two thirds of people using AI at work say their leadership hasn't given them convincing guidance. Around half have had no training on using it safely.
It's easy to read that as staff going behind their employer's back. I read it the other way round. The tools arrived before most organisations had worked out a position on them. With no position in place, people made their own reasonable calls.
That's not a discipline problem. It's a governance gap – and it sits with the organisation, not the individual.
What the research found
Deloitte UK published its GenAI Workforce Survey on 16 September 2026. Deloitte describes it as the largest study of workplace GenAI use in a single country: 25,000 UK workers, surveyed by Ipsos in May and June 2026.
63%
of UK workers knowingly use GenAI for work – and 24% use it every day.
46%
of users rely on free tools, 34% use tools their employer pays for and 17% use tools built in-house.
17%
pay for at least one tool themselves – around £958 million a year in total.
31%
say they use GenAI without their employer's knowledge.
The industry already has a name for that last figure: shadow AI. I'd be careful with it. The term borrows from "shadow IT", which carries an assumption of bad intent – the rogue laptop, the unauthorised file share. The Deloitte data doesn't support that reading, and starting from it leads to the wrong response.
Why the gap opens
Deloitte measured what people do, not why they do it. But put the 31% next to the 65% without convincing guidance and the half with no training, and the most likely explanation is simple: nobody has told them what good looks like. In my experience, the gap usually takes one of three forms.
No position at all
Nothing has been written or said. Staff are left to guess the rules from silence – and they tend to guess generously.
A position nobody can follow
A one-line "don't use AI" rule doesn't survive a deadline. If a policy bans something useful and offers no approved alternative, usage doesn't stop. It moves to personal devices and accounts, where you can't see it or support it.
A position that was never scoped
This is the one to watch, because it's common in organisations that think they've already dealt with it. A sensible policy exists, but nobody has done the work underneath it: deciding which uses are appropriate, for which information, with which tools.
Without that risk assessment, the policy asks staff to make judgements the organisation hasn't made itself. So they make their own.
Good intentions don't reduce the risk
None of this makes the exposure any smaller. When someone pastes a client contract, employee records, source code or financial figures into a consumer AI tool the business never chose, the same things are true whether they meant well or not:
No contract with the provider
Nothing controls how it uses, keeps or trains on that content.
No data protection groundwork
The processing isn't in your records, and any required impact assessment (DPIA) hasn't been done – UK GDPR Articles 30 and 35.
No supplier check
For ISO 27001-certified organisations, that's a nonconformity against the supplier controls (5.19–5.23).
No control over deletion
You can't guarantee the content is deleted, or respond properly to a data subject request that involves it.
No good answer
Not if a client, an auditor or the ICO asks what happened to their information.
Intent matters when you decide how to respond to the individual. It makes no difference to whether you have a reportable incident.
What to do about it
Order matters here. You can't write a sensible policy for usage you haven't measured. And you won't get honest answers if people expect to be disciplined for giving them.
Find out what's in use – without blame
Larger organisations can use discovery tools to get a picture within a couple of weeks. For most SMEs, a frank conversation, a look at expense claims and a review of sign-in activity gets you most of the way. Be clear that the aim is to build the policy, not to catch anyone out.
Decide which uses are in scope, and for which information
This is the risk assessment, and it's the step most often skipped. It doesn't need to be long: what must never leave your systems, what can be used externally with care, and what's fine – mapped against the handful of tasks people actually want AI for.
Give people an approved tool worth switching to
If the easiest option is a personal account, that's what people will use. A good business-grade alternative removes most unsanctioned use on its own.
Write a policy people can follow – and explain why
Keep it short and specific, and say what's allowed as well as what isn't. People follow rules they understand, and the reasoning helps them handle cases you didn't foresee.
Train people, and keep a simple record
A short session on what's safe to put into a prompt closes most of the practical risk. The record doesn't mean logging every prompt. It means knowing which tools are in use, what data they touch, who owns each decision and when it was last reviewed. That's exactly what auditors, insurers and client questionnaires ask for.
Where we stand
HowTech helps UK organisations get ahead of this, rather than find out after an incident. That means AI readiness and risk assessments, practical policy and governance, staff training, and making sure the tools your team wants to use are ones you've assessed and approved.
Shadow AI – if we're going to use the term – isn't really a technology problem. It's what happens when demand for a tool outpaces an organisation's plan for it. At £958 million a year, that gap is already open for most of us.
If you're not sure which AI tools your people are using today, start there – and ask in a way that gets you an honest answer.
Next in this series
Where AI actually pays off – it's the task, not the industry
Part two is on its way – we'll link it here as soon as it's published.
Jan Wolf is Compliance Lead at HowTech (Howell Technology Ltd), working with UK organisations on ISO 27001, information governance and security operations.
Source: Deloitte UK, "British workers spend nearly £1bn of their own money on GenAI for work, landmark Deloitte research finds", 16 September 2026 – deloitte.com. Fieldwork by Ipsos UK, 7 May – 10 June 2026, 25,000 UK workers aged 18–70.
Which AI tools are your people using today?
We help UK organisations find out what's in use without blame, do the risk assessment most policies skip, and give teams an approved tool worth switching to.
Related insights
What the Five Eyes warning on frontier AI models means for your business.
Why the Cyber Security and Resilience Bill reaches into ordinary supply chains.
A pragmatic, phased roadmap for small businesses adopting AI.