Businesses are signing more contracts that require client information to stay inside approved systems. The harder question is whether they can prove that it did.
The complication is AI.
Writing assistants, coding tools and chatbots entered daily work faster than many companies updated their software policies. Some of that adoption happened through normal procurement. Much of it did not.
Employees may test AI tools before security teams review them. A developer may use a coding assistant. A manager may summarize a document. A team member may paste part of a client file into a chatbot without realizing the contractual risk. In many cases, the company may have no clear record that the tool was used at all.
That makes the exposure contractual before it is purely technical. Confidentiality clauses and data-processing agreements often identify the systems permitted to handle client material. An unapproved AI tool is usually not one of them.
If a client or auditor asks which services touched its data over the past year, a company without visibility may not be able to answer.
A PagerDuty survey published in June 2026 found that 66% of office professionals had used AI tools at work while believing company policy did not permit it. In the same research, 34% said they had entered customer data or information into public AI tools such as ChatGPT, Claude or Gemini.
Why shadow AI is hard to track
Security teams can usually account for sanctioned accounts, licensed software and managed devices. Shadow AI often sits outside that view.
An employee may use a personal browser profile, a free account tied to a personal email address or a tool that was never submitted for review. The activity can be useful, but still create problems if it involves client information, confidential documents or regulated data.
This is why some companies are starting to look at the visibility tools they already have. For example, employee monitoring software used for time, productivity or application reporting can show which websites and apps are opened on tracked work devices.
That kind of record does not solve the entire AI governance problem. It does not determine whether a tool is approved, read the contents of a prompt or stop data from leaving the organization. But it can give managers and security teams a clearer picture of which AI tools are appearing in day-to-day work.
Turning usage into a policy question
One software development agency with roughly 100 employees asked WebWork Time Tracker whether AI tool usage could be separated from ordinary application activity. The goal was to see which AI tools developers were using and how much tracked time flowed through each one.
WebWork later published its approach to identifying which AI tools a team is using. The view lists AI tools by name, hours and share of tracked time, giving businesses a way to compare actual usage against internal policy.
That distinction matters. Visibility is not the same as permission. A company may discover that employees are using tools that should be blocked, or it may discover that a tool is already useful enough to evaluate properly and move into an approved environment.
Either way, the company is no longer guessing.
Bans alone may not work
The same PagerDuty research suggests why a simple ban may have limited effect. Across respondents, 77% said their company’s AI restrictions were limiting their professional growth or career mobility, and 75% said they would be likely to look for a job offering better AI skills development.
That leaves companies with a practical choice.
A strict ban may push AI use onto personal devices and personal accounts, where the activity is harder to see and no less likely to happen. A more realistic approach starts by identifying what employees are already using, then deciding which tools should be approved, restricted or replaced with enterprise versions.
That can also help companies align policy with contract obligations. If employees are using AI to summarize customer files, draft code, analyze transcripts or process support records, the organization needs to know whether those workflows match its promises to clients.
The real issue is accountability
For most organizations, the question is no longer whether staff are using AI tools. Many already are.
The real question is how much of that activity the company can account for.
AI governance does not begin with a policy document that nobody follows. It begins with visibility: which tools are being used, by whom, on what devices and under what rules.
From there, companies can make better decisions about approved tools, training, client data, security review and audit readiness. Without that visibility, they may be making contractual assurances they cannot prove.
Shadow AI is not only a productivity issue. It is a data-accountability issue. As AI becomes a normal part of work, companies will need records that show where client information can go, and where it should not.
©2026 Cox Media Group







