Your employees are already using AI at work. That's not a guess — research from Gartner found that 68% of employees use unauthorized AI tools on the job, up from 41% just two years ago, and a separate BlackFog study puts the number at 49%. If you haven't written an AI usage policy yet, your team isn't waiting for permission. They're pasting customer emails into ChatGPT, running reports through free AI tools, and making judgment calls about your business data with no guardrails at all.
The gap between what employees are doing and what leadership thinks is happening is wide. Roughly 90% of executives say they're confident in their visibility into AI tool use at their company, even though more than half of knowledge workers admit to using AI without approval — and 24% say they do it regularly. Employees aren't hiding this out of malice. Slack's survey of 17,000 office workers found many feel uneasy telling their boss they used AI, worried it'll be seen as "cheating" or make them look less capable. The result is a lot of AI use happening quietly, with no policy shaping how it's done.
The exposure isn't the technology itself; it's ungoverned use of it. Sensitive information now makes up roughly a third of what employees paste into tools like ChatGPT, up sharply from just a few years ago. Of employees using AI tools their employer hasn't approved, the majority are on free consumer versions with no enterprise-grade data protection, and a large share admit to feeding those tools customer details, employee records, or internal documents. For a small business, that's client confidentiality, employee PII, and proprietary information sitting inside a tool you have zero contractual control over.
71% of employees using unauthorized AI tools admit to entering sensitive data into them — customer details, employee records, and internal documents — most often through free tools with no enterprise data protections.
An AI policy doesn't need to be a 20-page legal document. For a small business, it needs to answer four questions clearly enough that any employee can follow it without asking:
The Slack finding about employees hiding their AI use matters more than it might seem. A policy that only lists rules, without addressing the culture of secrecy around AI, will just push usage further underground. Tell your team directly that using AI isn't something to hide — using it without knowing the ground rules is the actual risk you're trying to fix. That framing gets you honest conversations instead of guesswork.
You don't need perfect answers to every edge case before you publish a policy — you need something in writing that your team can actually follow. Start with a one-page document: list the tools you approve, the data categories that are off-limits, and one sentence making clear that disclosure is welcomed, not punished. Walk through it in a team meeting rather than just emailing it out, and revisit it every quarter as tools and use cases change. A short policy your team actually reads beats a thorough one that sits in a shared drive unopened.
Need hands-on support? Explore fractional HR consulting for growing businesses.
ValuedHR helps small and growing businesses build the HR systems they need without the overhead of a full-time hire.
Let's Talk