CPS-276 · Impact

The Pain of Employees Using AI With Company Information Nobody Is Governing — and the Financial, Privacy and Security Risk

AI can remove real work. It can also create an uncontrolled information path when employees paste customer, employee, commercial or internal data into tools the business has never assessed.

Mellorca Impact·Artificial Intelligence, AI Agents & Governance·1 September 2026

The problem is not that employees are curious about AI

Employees use tools that help them work faster. That behaviour is predictable. The governance problem begins when the organisation cannot answer which AI services are being used, what information is entered, what outputs influence business decisions, or who is accountable when the output is wrong.

A blanket ban may push useful experimentation underground. Uncontrolled adoption does the opposite: it treats every tool and data type as if the risk were the same. Both approaches are weak operating models.

Why uncontrolled AI use becomes normal

Generative AI is easy to access, useful for drafting and analysis, and often adopted faster than procurement, security and policy processes can respond. Employees therefore solve immediate problems before the business has designed an approved path.

NIST's Generative AI Profile, updated in April 2026, is a companion to the AI Risk Management Framework and identifies governance, measurement and risk-management actions for generative AI. NIST's AI Resource Center also emphasises testing, evaluation, verification and validation. The implication for ordinary businesses is practical: useful AI still requires ownership, data rules and controls proportionate to the use case.

How the pain becomes money

  • Data exposure: confidential information may enter services whose handling terms have not been assessed.
  • Rework: inaccurate or unsuitable outputs can create corrections when employees trust them without sufficient review.
  • Compliance effort: the business may need to investigate where regulated or personal information was processed.
  • Tool sprawl: departments can accumulate overlapping AI subscriptions without measuring value.
  • Decision risk: AI-assisted recommendations can affect customers, employees or money without clear accountability.
  • Integration risk: AI agents with action permissions can expand the consequence of weak access design.
The commercial signalIf management cannot state which AI tools are approved, what company information may enter them and which outputs require human review, adoption is ahead of governance.

Quantify what you can actually observe

Do not invent a hypothetical “AI breach cost.” Measure the operating footprint first.

AI subscription exposure
monthly AI spend by tool × 12, separated into approved and unapproved or duplicate services
AI rework exposure
verified AI-related correction incidents × average correction hours × loaded hourly cost

For privacy or security exposure, use scenario analysis tied to the type of information and the organisation's actual legal, contractual and incident-response obligations. Risk is not the same as realised loss.

Governance should not kill useful adoption

The unpopular but important point is that excessive control can create its own cost. If approved tools are unusable or access takes months, employees will either avoid valuable AI or seek workarounds. Good governance creates a safe lane: approved services, clear data classifications, usable guidance and escalation for higher-risk cases.

When this becomes commercially urgent

Act when employees enter customer or employee data into public AI services, departments buy tools independently, AI outputs are sent to customers without review, agents can change records or send messages, or the business has no inventory of AI use. The risk increases sharply when AI moves from generating text to taking actions in connected systems.

What good looks like

The organisation maintains an AI use inventory, defines approved tools, maps permitted data classes, assigns owners, controls access, tests important use cases and defines where human review is mandatory. Higher-risk uses receive stronger governance than low-risk drafting or brainstorming.

Practical next actions

  1. Survey teams for AI tools and use cases already in operation.
  2. Classify the data being entered and the actions AI is allowed to take.
  3. Publish a short approved-use policy employees can actually understand.
  4. Provide approved tools so governance does not depend on prohibition alone.
  5. Require review for customer-facing, financial, legal or high-impact outputs.
  6. Measure subscriptions, incidents, rework and realised productivity gains.
  7. Review agent permissions before connecting AI to operational systems.

Bottom line

AI governance is not a choice between innovation and control. The commercial objective is to capture useful productivity without creating invisible information flows, duplicate spend or unowned automated decisions. When adoption is visible, the business can govern risk and value at the same time.

Sources and further reading

Related InsightYour AI strategy has an integration problem examines the systems foundation beneath AI adoption.