Blog
For Employers

My Employees Are Using AI Without Telling Me. What Should I Do?

You discover that someone on your team has been using ChatGPT or another AI tool to write emails, summarize documents, research topics, or help with everyday work.

You did not approve the tool.

You did not ask them to use it.

And you are not even sure what information they have been putting into it.

What should you do?

The first step is not necessarily to ban AI.

First, find out how your employees are using it, what risks that creates, and whether your company has given them clear guidance in the first place.

Employees may already be using AI at work

For many employers, the question is no longer whether employees will use AI.

It is whether they are using it in ways the company knows about.

A September 2026 Deloitte survey of 25,000 UK workers found that 63% had used generative AI for work. Among those users, 31% said they used GenAI without their employer’s knowledge. Deloitte calls this “shadow AI.”

The most common uses were not necessarily high-risk activities. Employees reported using AI for tasks such as searching for information, drafting emails, and creating summaries.

That distinction matters.

An employee using AI to turn rough notes into a clearer email is very different from an employee uploading a confidential customer document to an AI tool they found online.

The employer needs to know the difference. The same attention to detail matters when employers evaluate candidates, particularly when reviewing applications for remote roles. Common problems with applications and interview preparation are covered in Why You're Not Getting Remote Job Interviews: 7 Mistakes That Could Be Holding You Back.

Why employees may not tell you

An employee may not be hiding their AI use deliberately.

They may simply assume it is allowed.

If someone uses AI to improve grammar, brainstorm ideas, summarize information, or save time on repetitive work, they may see it as no different from using a search engine or productivity app.

The problem is that not every AI tool works in the same way, and employees may not know what happens to the information they enter.

There may also be no company policy to follow.

Deloitte found that fewer than half of UK GenAI users said their company has a GenAI policy. Only 28% said their company has a policy that they know where to find, understand, and believe is clear and up to date.

If employees have not been told what is allowed, it is difficult to treat every unauthorized use as deliberate misconduct.

AI Workplace

Start by asking what they are actually using AI for

Before creating new restrictions, find out how AI is already being used across the company.

Ask employees:

  • Which AI tools are you using?

  • What tasks are you using them for?

  • Are you using free or paid versions?

  • Are you entering company, customer, or employee information?

  • Are you checking AI-generated information before using it?

  • Which tasks would you like to use AI for but currently cannot?

You may find that employees are using AI for simple tasks that create little risk.

You may also discover uses that need immediate attention.

For example, an employee using an AI tool to brainstorm headlines is one thing.

Uploading a customer database, financial information, unpublished product plans, or confidential contracts is another.

The first goal is to understand the situation rather than assume all AI use carries the same risk.

Not every AI use needs the same rules

A useful AI policy does not have to say simply “AI is allowed” or “AI is banned.”

Different tasks can require different rules.

Low-risk uses

These might include:

  • brainstorming ideas

  • improving grammar

  • creating first drafts

  • summarizing publicly available information

  • generating non-confidential outlines

  • helping with routine administrative tasks

Even here, employees should still check the output before using it.

Uses that need more caution

These could include:

  • analyzing internal documents

  • working with customer information

  • creating business reports

  • generating code for company systems

  • preparing content containing confidential information

  • using AI to make decisions about customers or employees

These activities may require an approved tool, additional review, or restrictions on what information can be entered.

Uses that should not be left to individual judgment

Some activities involve sensitive information or significant consequences.

For example, an employee should not decide on their own whether it is acceptable to upload personal employee records, confidential legal documents, passwords, financial information, or sensitive customer data to an AI service.

Those decisions should be covered by company policy and, where appropriate, legal or security guidance.

Should employees have to disclose when they use AI?

This is one of the questions employers need to answer clearly.

If an employee uses AI to correct spelling in an email, requiring a formal disclosure every time may create unnecessary work.

But disclosure can make more sense when AI has substantially contributed to a work product or when the use could affect accuracy, confidentiality, or accountability.

There is currently no universal workplace standard.

ISACA’s 2026 AI Pulse Poll, based on more than 3,400 digital trust professionals worldwide, found that only 18% said disclosure of AI use was both required and enforced when AI was used to create or substantially assist with work products. Another 20% said disclosure was required but not consistently enforced, while 32% said no disclosure requirement existed.

That suggests many organizations are still deciding where the line should be.

A company does not necessarily need employees to report every use of AI. It does need to decide when disclosure matters.

Make the rules simple enough to follow

An AI policy that is 30 pages long and nobody reads is unlikely to solve the problem.

Employees should be able to answer a few basic questions:

Which AI tools can I use?

If the company provides approved tools, name them.

What information can I enter?

Be specific about confidential, personal, customer, financial, or proprietary information.

When do I need to check AI output?

AI can produce incorrect information, so employees should know when human review is required.

When do I need to disclose AI use?

Set clear examples instead of leaving the decision entirely to employees.

Who should I ask if I am unsure?

Give employees a person or team they can contact.

The goal is to make responsible use easier, not to create another policy employees are afraid to read.

Train employees instead of relying only on rules

A policy tells employees what they should do.

Training helps them understand why.

This matters because many employees are learning to use AI on their own.

A 2026 study from the University of Konstanz found that 38% of surveyed employees in Germany were using AI at work, but only 55% of AI users said the tool they used most often had been officially introduced by their employer. The study also highlighted gaps in governance, secure infrastructure, and workforce training.

The same study found a particularly large gap in smaller organizations: only 11% of employees in small organizations reported receiving AI training, and just 10% reported having binding rules for AI use.

That is important for smaller and remote companies.

You do not necessarily need a large AI governance department.

You do need employees to know what is expected of them.

AI Workplace

Do not punish employees for a policy that did not exist

Suppose you discover that an employee has been using an AI tool without permission.

Before treating it as a disciplinary issue, ask a basic question:

Did the employee know it was prohibited?

If the company had no AI policy, no approved tools, and no guidance about confidential information, the situation may be partly a management problem.

That does not mean every use should be ignored.

If an employee knowingly shares confidential information after being clearly told not to, that is a different situation.

The important thing is to establish clear expectations going forward and apply them consistently.

AI use should not become a secret

The bigger problem is not necessarily that employees are using AI.

It is that employers may not know how it is being used.

The 2026 ISACA research found that 90% of surveyed digital trust professionals believe employees are using AI in their organizations, while only 38% said their organization has a formal, comprehensive AI policy.

That gap creates unnecessary uncertainty.

Employees may be experimenting with useful tools.

Managers may be worried about risks they cannot see.

IT teams may not know which services are being used.

And nobody has a complete picture of what is happening.

A better approach is to make AI use visible enough to manage.

So, what should employers do?

If employees are already using AI without telling you, the answer does not have to be an immediate ban.

Start with five questions:

  • What are employees using AI for?

  • Which tools are they using?

  • What information are they putting into those tools?

  • Which uses create genuine business, privacy, or security risks?

  • What rules and training do employees need?

Then create a simple policy based on the answers.

Allow useful, low-risk applications where appropriate. Restrict uses that could expose sensitive information. Require human review where accuracy matters. Decide when AI use needs to be disclosed.

Most importantly, give employees a way to ask questions before they make a mistake.

AI is already becoming part of everyday work. The employers that manage it well will not necessarily be the ones that use the most AI.

They will be the ones that understand how their employees are using it, where the risks are, and what rules make responsible use possible.

Looking for the right remote talent?

Build your remote team with candidates whose skills and experience match what your business needs.

Find Remote Talent on Online.jobs

Sources