Your organisation may not have adopted AI. Your employees have. AI-generated illustration.

Your organisation may not have adopted AI. Your employees have.

Outside a bookshop recently, someone had made a joke about post-apocalyptic fiction being relocated to current affairs. It worked because, frankly, the categories are getting difficult to distinguish.

AI at work has acquired some of the same quality. There are still organisations discussing whether, when and how they should “introduce” artificial intelligence as though it were sitting politely in reception waiting for a visitor badge. Meanwhile, their employees may already be using it. Not theoretically. Not someday. Now.

Deloitte’s latest UK GenAI Workforce Survey, based on 25,000 workers surveyed between May and June 2026, found that 63% had knowingly used generative AI for work. Almost a third of GenAI users said they were using it without their employer’s knowledge, and half said they had received no formal training. [1]

That creates a rather awkward management question. If an organisation has decided that it has not adopted AI, but its employees have adopted it anyway, who exactly is in control?

Download the full report

The employees got there first

There is a temptation to tell this as a security story. Employees are using unauthorised tools. Data is leaking out of carefully controlled systems. Artificial intelligence is generating unchecked work. Someone from IT appears carrying a clipboard and everybody feels suitably chastened.

That story is not entirely wrong, but it is incomplete. Employees generally do not wake up in the morning thinking, “How can I introduce an exciting new governance problem before lunch?” They are trying to do their jobs. They have something to research, an email to draft, a document to summarise, a problem they are struggling to untangle, a blank page, a spreadsheet they do not understand or a presentation due tomorrow morning. Then they discover a tool that helps.

Deloitte found the most common workplace uses remain strikingly ordinary: searching for information, drafting emails and creating summaries. Seventeen per cent of GenAI users are even paying for at least one tool themselves for work. Deloitte estimates that British workers are collectively spending nearly £1 billion a year of their own money on them. [2][3]

That is not merely a compliance problem. It is also evidence of demand. People are effectively telling their employers, through their behaviour and sometimes through their own credit cards, that existing tools or processes are not meeting every need. Management can choose not to listen, but the behaviour does not therefore disappear.

Not adopting AI is still an AI decision

A company may reasonably decide that it is not yet ready for broad AI adoption. The technology is moving quickly. Tools have different terms, security models and capabilities. Some information should plainly never be sent into public systems, and outputs can be wrong. Those are sensible concerns.

But there is a difference between deciding not to deploy something formally and assuming that therefore it is not being used. The second is much more dangerous.

Microsoft and LinkedIn spotted the pattern internationally back in 2024. Their Work Trend Index found that 78% of AI users surveyed were bringing their own AI tools into work. That study covered 31 countries and knowledge workers, so it is not directly comparable with Deloitte’s current UK workforce research, but the direction was already clear: employees were not waiting for organisational strategy to catch up. [7]

Two years later, the UK evidence suggests the gap is still very real, and unmanaged use creates a peculiar inversion. The organisation that delays AI adoption because it wants more control can end up with less of it.

If the organisation does not know which systems are being used, what information employees are putting into them, what comes back out or where AI-generated material enters normal workflows, then it does not really have control. It has absence of visibility wearing a sensible jacket.

What exactly is going into the box?

The risk becomes less theoretical when you ask what employees actually give these tools. A useful AI assistant needs context, often quite a lot of it, so people paste things in: emails, notes, customer information, internal documents, financial numbers, meeting transcripts, draft contracts, performance information and commercial questions.

Most of the time this is not malicious or reckless. It is simply the fastest way to make the tool useful. But useful context can also be sensitive context.

Research published by KPMG and the University of Melbourne in 2025 found that 39% of the UK workers surveyed had uploaded company information, such as financial, sales or customer data, into a public AI tool. The same study found 58% had relied on AI-generated output at work without evaluating its accuracy. [4]

Those figures come from a smaller UK worker sample than Deloitte’s latest research, so they should not be treated as a census of British business. They should, however, make anybody responsible for information governance sit up slightly straighter.

The National Cyber Security Centre has been saying for some time that leaders need to understand where responsibility for AI security sits, how AI fits existing governance and what happens when systems fail. Its guidance also points to familiar weaknesses in generative AI: convincing inaccuracies, bias, prompt injection and risks around sensitive data. [5]

None of those problems require science fiction. They merely require someone to copy the wrong thing into the wrong box on an otherwise ordinary Tuesday.

The other thing going into the box is authority

Information gets most of the attention, but there is another question underneath it: what are employees actually allowed to delegate?

If AI drafts an email, that may be perfectly reasonable. If it summarises research, that may also be useful, provided somebody checks it. But the issue changes when AI recommends which supplier to choose, writes part of a customer proposal, evaluates a candidate, produces a financial assumption that flows into a forecast or quietly becomes part of the reasoning behind a decision nobody realises involved AI at all.

At some point, the issue stops being simply whether the tool was used. The issue becomes what authority travelled with the task.

That is why the useful dividing line is not human versus AI. It is delegation versus abdication.

Delegation says: use the machine. Give it useful room to work. Let it remove drudgery, accelerate research, challenge thinking, explain unfamiliar subjects and help humans attempt work they could not previously have attempted as easily. But keep permissions explicit, keep accountability explicit, keep review proportional to consequence and keep a human owner of the outcome.

Abdication is different. Abdication is where a task goes into a system and responsibility somehow evaporates on the way back out. “The AI said so” is not governance. It is barely even an excuse.

A ban looks simpler than it is

At this point the obvious response is prohibition. If unauthorised AI creates risk, ban unauthorised AI. There are workplaces and activities where restrictions will be entirely appropriate. Some data should not go near general-purpose public tools, and some decisions demand far tighter controls than others.

But blanket prohibition has a practical weakness: people already know the tools are useful.

Deloitte’s latest study found employees are using them for ordinary work and, in some cases, paying for access themselves. Nearly a quarter of the UK workers surveyed said they use GenAI every day. [2]

A rule that conflicts persistently with obvious utility does not necessarily stop behaviour. Sometimes it merely makes behaviour less visible, and hidden AI use is harder to govern than acknowledged AI use.

If employees believe using AI is frowned upon, embarrassing or career-threatening, they have fewer reasons to say when they used it, fewer opportunities to ask whether a task was appropriate and fewer incentives to seek help when something goes wrong. Deloitte found 23% of respondents thought there was stigma attached to using GenAI at work, while 64% of weekly users worried managers might conclude AI could do their jobs. [2]

So silence may not indicate non-use. It may simply indicate silence.

Training has not caught up

This may be the most uncomfortable part. Organisations are already benefiting from employees using systems many of those employees have never formally been taught to use.

Half of GenAI users in Deloitte’s 2026 UK survey said they had received no formal training. Only 35% said they heard leaders discuss the technology with what they regarded as a good understanding of it. [1][8]

That does not mean everybody needs to become an AI engineer. They do need to understand enough to recognise what kind of tool they are dealing with. They need to know what information can go in, what cannot, when an output requires checking, what kinds of mistakes these systems are prone to making, when they should stop and ask somebody, which tools the organisation has approved and why, and who owns the final decision.

The UK Government’s own guidance to civil servants takes a relatively pragmatic position: be curious about generative AI, but do not put sensitive or personal information into the tools, and check outputs because plausible answers can still be wrong. [6]

That is considerably more useful than pretending curiosity can be prohibited.

Shadow AI is also market research

There is another way to look at all this. Imagine discovering that hundreds of employees had independently bought the same kind of software because it helped them work. Management would normally regard that as information.

Perhaps existing systems are inadequate. Perhaps processes are unnecessarily slow. Perhaps employees need better research tools. Perhaps they want help writing, analysing or learning. Perhaps there is an unmet capability sitting in plain sight.

Shadow AI therefore contains two signals at once. One is risk. The other is product discovery.

Employees are showing organisations where AI is useful before many organisations have finished deciding where AI might theoretically be useful. That is valuable intelligence.

The interesting management response is not simply to stamp out the behaviour. It is to investigate it: what are people using, why are they using it, which tasks improve, which do not, where is time genuinely being saved, where are people producing better work, where are they creating new risks, and what tool or capability would they use if the organisation provided something safer and more suitable?

There will also be places where the answer should simply be no. But that decision is stronger when it is based on understanding rather than assumption.

That starts to look less like an AI policy and more like management, which is probably healthy.

Control does not mean doing everything yourself

Organisations will understandably want control as AI moves deeper into work, but control is easily confused with restriction. They are not the same thing.

Real control means knowing what is happening. It means deciding what authority can be delegated and what cannot. It means giving people tools they can use without improvising around the organisation. It means teaching enough AI literacy that employees understand both capability and failure. It means putting stronger review around higher-consequence work instead of treating a meeting summary and a strategic decision as though they carry identical risk.

It also means accepting something slightly inconvenient: the starting gun has already gone off.

For many organisations, the question is no longer whether employees should begin experimenting with AI. They already have. The useful question now is whether management will bring that behaviour into the open, understand it and shape it, or leave employees to construct the organisation’s AI operating model one browser tab at a time.

Because there is one form of AI strategy that requires no meetings, no budget approval, no training programme and no governance committee whatsoever: everybody quietly chooses their own.

If that becomes the strategy, the organisation has not avoided adopting AI. It has merely abdicated the adoption.


References and source notes

  1. Deloitte UK, GenAI Workforce Survey 2026. https://www.deloitte.com/uk/en/issues/generative-ai/genai-workforce-survey.html
  2. Deloitte UK, British workers spend nearly £1bn of their own money on GenAI for work, 16 September 2026. https://www.deloitte.com/uk/en/about/press-room/british-workers-spend-one-billion-pounds-of-their-own-money-on-gen-ai-for-work.html
  3. Deloitte UK, Productivity | GenAI Workforce Survey. Use-case base: working adults who used GenAI for work (15,768). https://www.deloitte.com/uk/en/issues/generative-ai/genai-workforce-survey-productivity.html
  4. KPMG UK / University of Melbourne, UK attitudes to AI. UK sample 1,029 people including 617 workers; fieldwork November 2024-January 2025. https://kpmg.com/uk/en/insights/ai/uk-attitudes-to-ai.html
  5. National Cyber Security Centre, AI and cyber security: what you need to know. https://www.ncsc.gov.uk/guidance/ai-and-cyber-security-what-you-need-to-know
  6. GOV.UK, Guidance to civil servants on use of generative AI. Updated 29 January 2024; page now marked superseded, but the cited principles remain explicit on the source page. https://www.gov.uk/government/publications/guidance-to-civil-servants-on-use-of-generative-ai/guidance-to-civil-servants-on-use-of-generative-ai
  7. Microsoft + LinkedIn, AI at Work Is Here. Now Comes the Hard Part, 2024 Work Trend Index. Global knowledge-worker survey: 31,000 people across 31 countries. https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
  8. Deloitte UK, Leadership & training | GenAI Workforce Survey. https://www.deloitte.com/uk/en/issues/generative-ai/genai-workforce-survey-leadership-training.html

Research cut-off: 30 September 2026.

Download the full report

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *