The AI tool your company has not approved is the one you are using

Most organisations now have a policy about AI tools. Most of those policies are being routinely ignored, not out of defiance but out of ordinary friction.

The mechanism

It is worth being precise about how this happens, because the usual framing gets it wrong.

Somebody has a document to rewrite at 4pm. The approved tool requires a VPN connection, a separate login, and produces worse output. The unapproved one is a browser tab that is already open. They paste the document in, get a better result in less time, and go home.

They were not thinking about data governance. They were thinking about the document. Nothing in that sequence involves a decision to violate a policy; the policy simply never came to mind, because policies are not present at the moment of a small convenient action.

What actually leaves

The leaks that follow this pattern are rarely dramatic. They look like:

In every case the sensitive part is incidental. Nobody wanted to share the revenue figures; they wanted the formula fixed and the figures were attached to it.

Why more prohibition does not work

A ban converts a visible behaviour into an invisible one. People do not stop pasting; they stop mentioning it, which means the organisation loses the ability to see what is happening, and the person who does leak something significant now has a reason to keep quiet about that too.

Enforcement is also largely impractical. The action is a paste into a browser tab on a device that may not be managed, and it looks identical to any other paste.

What helps

Make the sanctioned path faster than the unsanctioned one. This is most of the problem. If the approved tool is genuinely quicker to reach, usage moves without any enforcement at all, because people optimise for effort rather than compliance.

Be specific about what matters. "Do not paste confidential information" is unusable, because everything feels a bit confidential at 4pm and nothing feels catastrophic. "Never paste customer records, credentials, or unreleased financials" is a rule someone can actually apply while looking at a document.

Give people a redaction step. The realistic choice is not between pasting and not pasting; it is between pasting raw and pasting scrubbed. A tool that takes ten seconds and removes the keys and addresses fits inside the moment where the decision is made. A policy document does not.

Make disclosure survivable. If someone realises they pasted a live key, the organisation wants to hear about it within the hour so the key can be rotated. That only happens if reporting is treated as good practice rather than an admission of misconduct.

For the individual

If you are the one with the document at 4pm, the practical version is short:

  1. Know which account you are pasting into, personal or corporate. The terms differ.
  2. Scrub credentials and personal data before pasting. It costs seconds.
  3. Read the text once for names, figures and code names, which no tool will catch.
  4. If you paste a credential by mistake, rotate it immediately and tell someone. Both parts matter.