Your Employees Are Not Waiting for Your AI Strategy
Sixty-three per cent.
Parliament is debating how AI should be governed. Boards are deciding how AI should be adopted. Employees, according to the largest UK workforce survey yet published on the subject, are already using it — and nearly a third of those who do are using it without their employer's knowledge.
16 September: Deloitte UK published its GenAI Workforce Survey, conducted by Ipsos among 25,000 UK workers between May and June 2026. It found that 63% of working adults knowingly use generative AI for work. Among those users, 31% say they do so without their employer's knowledge, and one in six of them (17%) pays personally for at least one AI tool in order to do their job, spending that Deloitte estimates at £958 million a year.
The usual name for this is "shadow AI". For an organisation, the more accurate description is a governance gap: a material activity is taking place inside the organisation that its governance does not see.
Adoption Has Already Happened
An organisation may believe it is still deciding whether, or how, to adopt AI. On these figures its employees have decided already. Publicly available tools are reachable through a browser, a personal subscription or a phone, and in hybrid working some of that use may take place outside the managed estate. The consequence is that an organisation cannot assume its formal technology estate shows it how AI is actually being used.
Three questions follow, and none of them can wait for legislation. What organisational information — personal, confidential or commercially sensitive — is being entered into these tools? What work is AI shaping, and is anyone checking the output before it is relied on? And if a decision influenced by AI turns out to be wrong, who is accountable for it, given that the organisation may not know AI was involved?
The Employee Is Usually Trying to Get the Work Done
It would be easy to treat shadow AI as non-compliance: an employee ignores the rules and creates a risk. Sometimes that is what has happened. More often the picture is more ordinary. A junior member of staff has a deadline, a client document and a tool that will produce a first draft in two minutes. They are not setting out to expose confidential information; they are trying to meet a legitimate objective, and the failure occurs in the gap between that objective and their understanding of what the tool does with what they give it.
That distinction matters because it determines the response. Deloitte's findings suggest that prohibition alone will not close the gap. Among those who pay for their own tools or use tools their employer has not approved, 21% say those tools outperform the company's, and 14% say the tool is essential to their job but the employer will not fund it. Even in financial services, where Deloitte found greater use of in-house and company-provided tools, 19% of users pay for their own. Where an external tool allows people to do legitimate work faster or better, a stricter rule suppresses the visible behaviour without addressing its cause.
The governance questions are therefore not only how the organisation stops the behaviour, but why employees are using the tool, whether the approved tools meet the need, what the consequences of permitting and of prohibiting the use would each be, and what safeguards would be proportionate to the information and the decisions involved.
A Policy Nobody Can Apply
Deloitte found that half of GenAI users have received no formal training and only 20% have received any mandatory training. Just 28% say their organisation has a GenAI policy that they know where to find, understand, and regard as clear and up to date.
An organisation can therefore have an AI policy and still have employees who do not know what responsible use looks like at the moment it matters. The moments are ordinary ones. A confidential client document could be summarised in two minutes: can it be uploaded? A name has been removed from a document: is what remains safe to enter into an external service? AI has produced a convincing answer: when can it be relied on, and when must it be verified? An employee realises after the event that sensitive information went into an unapproved tool: what should happen next?
A policy can set boundaries. People still need the judgement to recognise when a boundary is in front of them. For years organisations have accepted that data protection and information security require practical awareness rather than a document to sign; AI now requires the same. For organisations within the scope of the EU AI Act this is already an obligation — since 2 February 2025, Article 4 has required providers and deployers to take measures to ensure, as far as they can, a sufficient level of AI literacy among the staff who operate and use AI on their behalf; it does not prescribe how. For everyone else it is simply good governance.
Awareness Has to Reach the Point of Judgement
Responsible use is not learned by reading rules. It is learned by rehearsing decisions. Put people around a table — physical or virtual — with a realistic problem: the deadline, the tempting shortcut, the information involved and the organisation's constraints. Ask what they would do, and why. The discussion surfaces assumptions about confidentiality, accuracy, authority and escalation before the same decision arrives under pressure in real work.
Technical controls matter as well. An organisation may decide that certain work should take place only in approved enterprise or privately hosted environments, with access controls and information protections. That closes an exposure route. It does not decide what AI is for, what it may and may not do, what employees are authorised to give it, where human review is required, or who remains accountable. Technology can close the route; governance still has to govern the use.
Governance Has to Meet the Organisation That Exists
Training alone will not resolve this either. If people are using external tools because the approved alternatives are inadequate or poorly suited to the work, an awareness programme cannot repair that. The proportionate response will usually combine several things: discovery, a policy people can find and apply, better approved tools, technical controls, a route for reporting and escalation, awareness, and management oversight. The combination differs from one organisation to the next. The first requirement is the same in all of them: visibility of how AI is actually being used, rather than how the organisation assumes it is being used.
The position for a Board is an uncomfortable one. Parliament has not yet decided how AI will be regulated, and the organisation may not yet have settled its AI strategy. Its people have decided. If asked today what AI is being used in the organisation, on what information, shaping which decisions and under whose authority, most Boards could not answer from evidence. That is the gap to close, and closing it does not depend on anything Parliament does next.
Mediajem works with organisations on exactly this question: what is actually happening with AI inside the organisation, and what governance is proportionate to it. If it is a question you are facing, get in touch.
Sources
• Deloitte UK, "British workers spend nearly £1bn of their own money on GenAI for work", press release, 16 September 2026
• Deloitte UK, GenAI Workforce Survey 2026
• Deloitte UK, "What we do in the AI shadows", GenAI Workforce Survey 2026
• Deloitte UK, "Leadership & training", GenAI Workforce Survey 2026
• Regulation (EU) 2024/1689 (the EU AI Act), Article 4, AI literacy, applicable from 2 February 2025