← Insights
Governance & shadow AI

Would you know if a staff member pasted a customer contract into ChatGPT last week?

TanX Labs9 min readUpdated 2026

For most businesses, the honest answer is no. Not because nobody would care, but because nothing today tells you when it happens. A staff member pastes a contract, a client list or a pricing sheet into a public AI tool to save twenty minutes, gets a useful answer, and moves on. No log, no alert, no record it ever happened.

This is not a hypothetical. It is the default state of most businesses right now, and the data on how often it happens has become clearer over the past year.

What the current data shows

A run of 2026 workplace surveys converge on the same picture from different angles. PagerDuty found that two thirds of office professionals have used an AI tool at work that was not sanctioned by their employer, and most of them knew it was not permitted when they did it. Cyberhaven's AI adoption research puts a number on the pattern inside that: the average employee now feeds sensitive data into an AI tool roughly once every three working days.

66%

Of office workers have used an AI tool they knew was not approved by their employer (PagerDuty, 2026).

86%

Of organisations have no visibility into how data actually flows to and from AI tools (Reco, 2025).

1 in 3

Working days is roughly how often the average employee pastes sensitive data into an AI tool (Cyberhaven).

Gartner's read on where this goes is blunt: by 2030, more than 40% of enterprises will have a security or compliance incident that traces back to unauthorised AI use. Cisco's 2025 research already found that close to half of organisations had experienced an internal data leak through generative AI. This is not a future risk. It is a present one that most businesses cannot currently see.

Why it happens even in careful teams

Nobody sets out to leak a contract. The pattern is almost always the same: a real deadline, a genuinely useful tool sitting one tab away, and no sanctioned alternative that is as fast. Ban the tool and the behaviour does not stop, it just stops being visible. Say nothing and the exposure compounds quietly, one paste at a time, across every person on the team.

The businesses that close this gap do not do it by winning a policy argument. They do it by giving staff a governed way to get the same speed without the exposure, and by building enough visibility to know when that boundary is being tested.

Three controls that actually close the gap

  1. 1. A governed assistant staff will actually use

    Shadow AI thrives in the absence of a sanctioned alternative. A governed assistant that is as fast as the consumer tool, connected to the systems people already work in, removes the reason to reach for ChatGPT on a browser tab nobody is watching.

  2. 2. Visibility into what is actually happening

    You cannot govern what you cannot see. Basic visibility into which AI tools are in use and what kind of data is moving through them turns an invisible risk into a manageable one, and it is the single control most organisations are still missing.

  3. 3. A written answer to "does this train a public model"

    Every credible AI vendor can answer this in writing. If a tool cannot confirm your data never trains a model outside your control, that is the question to press on before anything else, not after.

"The fix is not another tool. It is a foundation." That is the same principle behind the Org Brain: one governed layer, built on the access you already have, so staff get speed without anyone quietly routing around the business to get it.

Where to start

Start by finding out what is actually happening today, not what policy says should be happening. Most leaders are surprised by the gap between the two. From there, the fix is staged: a governed assistant first, for fast, visible wins, then the connected foundation underneath it.