← Latest reporting

A shadow-AI inventory should map unmet tasks before it maps offenders

New legal analysis combines two 2026 signals of unmanaged workplace AI: personal identities and prohibited-tool use. A punitive user list will miss the operational demand, data routes and sanctioned alternatives that governance must address.

Policy, Standards and GovernanceWork and Role Change
A rough cardboard task map sends hidden black-thread routes into one open inventory frame with removable cork gates.
Conceptual illustration generated with AI under editorial direction; it does not depict a real event.

What happened

A Reuters Legal analysis published 7 October cited Akamai data that 47.11% of enterprise AI conversations used personal identities and a PagerDuty survey in which 66% of respondents reported using AI they believed was not permitted.

Why it matters

The figures come from different methods and populations, but both point to a visibility problem. Treating the symptom only as misconduct can push use further underground without fixing the tasks employees are trying to complete.

A Reuters Legal analysis published on 7 October argues that employers should assume generative-AI use already exists and begin with visibility and task-level risk classification. It cites Akamai’s Enterprise AI Usage Risk Report, based on LayerX browser data, which says 47.11% of enterprise AI conversations occurred through personal identities. It also cites PagerDuty’s survey of 1,250 non-technology office professionals in Australia, Japan, the UK and US; 66% said they had used AI at work despite believing policy did not permit it.

These are not interchangeable prevalence estimates. One observes browser activity from a vendor dataset; the other is self-report from large-company workers. Neither proves harm or represents every workplace.

Inventory the task and data route

Ask teams which task they attempted, which data entered the tool, why the approved route failed, what output influenced work and whether a record remains. Group findings by use case and data sensitivity, not employee name. Then provide a sanctioned alternative, explicit prohibition or documented exception for each recurring pattern.

Monitor at an aggregate level consistent with privacy and labour rules. Pair technical signals with confidential self-report so the inventory includes invisible mobile, personal-account and embedded-vendor use. Measure migration to approved routes and unresolved task demand.

The counterargument is that non-punitive discovery tolerates policy breaches. It does not remove accountability. It sequences it: first establish the real workflow and give a usable path; then enforce clear boundaries for sensitive data and consequential decisions.

Use a time-bounded discovery window and publish the purpose, access rules and deletion schedule before collecting telemetry. Representatives from security, privacy, legal, employee relations and frontline teams should jointly classify patterns. An approved alternative is credible only if it matches the latency, integration and usability that drove the workaround; otherwise apparent non-compliance may simply move to a channel the inventory cannot see.