40% of companies bought the official subscription. Workers at more than 90% of them were already using something else.
Shining some practical light on the shadow tools and processes that really define your enterprise operations.
Here are two numbers from the same study.
MIT’s Project NANDA, in The GenAI Divide, found that 40% of companies had bought an official large language model subscription. In the same survey, workers at more than 90% of those companies were already using personal AI tools to do their jobs.
Read that again. The organization made a procurement decision. The workforce had already made a different one.
That gap is the subject of this post, and I want to argue something that will sound wrong at first: the gap is not only a security problem. It is also the most accurate readiness data your organization has ever collected — and nobody is reading it.
The scale of it
The consistency across independent studies is what makes this hard to dismiss.
81% of employees and 88% of security leaders report using unapproved AI tools (UpGuard, 500 security leaders and 1,000 employees globally)
66% of office professionals have used AI at work while believing it was against policy (PagerDuty / Wakefield Research, 1,250 professionals in non-IT roles at companies above $500M revenue, across Australia, Japan, the UK and the US)
45% of workers find workarounds when applications are blocked (UpGuard)
60% of business leaders lack confidence they could even identify unapproved AI tools in their own environment (Cisco Cybersecurity Readiness Index, 8,000 leaders across 30 markets)
Blocking and policy alone do not resolve it. In one survey, 40% of employees who recalled receiving AI training still used unapproved tools daily to complete their work tasks. And this is not a new phenomenon limited to the AI era, as you will see.
The part nobody puts on the slide
Now the finding that should stop the conversation about frontline compliance.
Senior decision-makers are more than twice as likely to use unapproved AI tools as the people they manage: 65% against 31% (TrustedTech / Censuswide, 2,001 UK and US employees, March 2026).
A separate survey found 69% of presidents and C-suite members, and 66% of directors and senior vice presidents, are comfortable with employees doing it (BlackFog).
And 81% of office professionals believe leadership operates under a different set of rules — rising to 85% at the largest organizations (PagerDuty).
⭐ The governance risk is running out of the offices of the people writing the governance. Which tells you something important: this is not indiscipline. When the executive and the analyst and the junior buyer are all doing the same thing, you are not looking at a behavior problem. You are looking at a system that does not meet the work.
Why they do it, in their own words
The reasons are not exotic. 53% say they prefer the independence. 33% say IT does not offer what they need. And 80% of American office workers use AI in their roles while only 22% rely exclusively on employer-provided tools.
Official tools arrive slowly, or arrive too limited for real work. So people use what works, and do not mention it.
We have seen this exact film before
None of this is new. It is at least the fourth time around the same loop.
The personal computer. In 1979 VisiCalc shipped on the Apple II, and finance people started buying Apple IIs on expense accounts to run it — because the MIS department could not give them what they needed and the approval cycle was measured in quarters. IT called them toys. The machines arrived anyway, one department at a time, paid for out of budgets nobody thought to police. By the time policy caught up, the question was no longer whether to allow them.
BYOD. IT fought it and lost, because employees had already decided. Policy arrived afterward to regularize what was happening anyway.
Amazon did not just teach people to buy online. It taught them what buying feels like — and once that became the baseline, the corporate purchasing system stopped feeling normal and started feeling broken.
Which produced the question a member put to me in April 2008, and which I have never stopped thinking about: why can’t we buy at work the way we buy at home?
That question was never really about the interface. It was about who holds the authority to act. At home you decide. At work you request.
And in May 2007, four days into this blog, I wrote that organizations usually modified their operations to accommodate the technology being implemented — and that practitioners named this as the main reason for lack of compliance.
Nineteen years later, the workforce has stopped modifying itself and started routing around the software instead.
What the shadow is actually telling you
Here is the reframe.
Every organization treats shadow usage as a risk to be fenced. Almost nobody treats it as a measurement.
But that is exactly what it is. When someone uses a personal tool for a specific task, they have told you — accurately, unprompted, at their own inconvenience — that the sanctioned system does not serve that task. They are not reporting an opinion in a survey. They are voting with the only currency they control, which is their own time.
Sometimes the sanctioned system could have served the task and the person did not know it — the capability exists, buried four menus down. That is still evidence about the system, not about them: a capability nobody can find is a design failure, not a training gap.
⚠ It is not clean data in the compliance sense, and it should not be read as an instruction to approve every tool someone has found. The confident and vocal are overrepresented. Silence does not mean the sanctioned system works — it can mean people are afraid to say otherwise. And a workaround that reveals a broken workflow can create a new exposure at the same time.
What it is, is unusually clear behavioural data about the gap between the work people have to do and the system they have been given. That still has to be read, investigated and placed in context. It is a signal, not a verdict.
I learned this in 1998, on a defence maintenance contract delivering next-day parts 51% of the time against a 90% requirement. The technicians were holding parts orders until late afternoon, which looked exactly like resistance. It was not. They were measured on call response, so they cleared calls first and submitted orders afterward — and that single behavior produced a chain that ran through purchasing, supplier selection, the border and into finance.
Nobody needed it explained to them better. The behavior was the most accurate information available about how the system actually worked.
Delivery moved from 51% to 97.3% in three months, and held for seven years, once those operating relationships were exposed and realigned. The technology came afterward.
Shadow AI is the same signal, arriving twenty-eight years later with a subscription attached.
What to do with it
Not a policy. A reading.
Every conventional response to shadow usage carries an assumption about who is at fault. Change the assumption and you get a different question.
The usual response
What it assumes
The better question
Block unapproved AI
The worker is the problem
What task is the worker trying to complete?
Retrain employees
They do not understand the policy
What stops the sanctioned route from serving the work?
Increase monitoring
More detection produces compliance
What would reporting reveal about process, authority and tool failure?
Standardize on one platform
Tool choice is the issue
What decision, workflow and evidence standard does the tool have to support?
Escalate policy violations
Fear corrects behavior
What operating condition is producing the workaround?
The column on the right costs nothing to collect and is more honest than any process map you own.
And notice who is doing it. If your executives are the heaviest users, the problem is not awareness.
Then ask what happens to the person who tells you. Which is the whole thing.
⚠ Detection and disclosure serve different purposes. Detection may be necessary to manage risk, and in regulated environments it is an obligation. But if the only response to a discovered workaround is punishment, people will hide the work from you — and you will lose the evidence you needed to fix the system that produced it.
The technicians in 1998 were not caught. They were understood.
The uncomfortable conclusion
If 90% of your people are already using tools you did not select, then your organization has run a distributed, unfunded, entirely voluntary readiness assessment and thrown away the results.
The consumer mindset is not encroaching on the business world. It arrived years ago, it is already setting the standard, and the only real question is whether you are going to read what it is telling you or keep trying to fence it.
If you use it at home, you will use it at work.
The organizations that understand this will stop asking how to stop it and start asking what it reveals.
-30-
Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™
Jon W. Hansen, FCIPS — Procurement Insights | Hansen Models™
Once you can see which tasks the unsanctioned tools are actually doing, you still have to decide how to work with a model on those tasks — without simply asking it for the answer.
On 25 September I am running a free 30-minute lab on the linchpin version of that question: how to select, work with and progressively engage AI models so the output gets more accurate rather than just more polished. A working session, not a presentation.
Friday, 25 September, 9:30 AM ET, and again Wednesday, 30 September, at 1:00 PM ET.
Everyone who attends receives a copy of Thinking With the Machine. Fifteen days later they also receive 90 days of free access to the consumer version of ARA™ RAM 2025™ — because the most useful way to understand what a technology could mean inside an enterprise is to work with it personally first.
When a Consumer Mindset Serves the Business World
Posted on September 16, 2026
0
40% of companies bought the official subscription. Workers at more than 90% of them were already using something else.
Shining some practical light on the shadow tools and processes that really define your enterprise operations.
Here are two numbers from the same study.
MIT’s Project NANDA, in The GenAI Divide, found that 40% of companies had bought an official large language model subscription. In the same survey, workers at more than 90% of those companies were already using personal AI tools to do their jobs.
Read that again. The organization made a procurement decision. The workforce had already made a different one.
That gap is the subject of this post, and I want to argue something that will sound wrong at first: the gap is not only a security problem. It is also the most accurate readiness data your organization has ever collected — and nobody is reading it.
The scale of it
The consistency across independent studies is what makes this hard to dismiss.
Blocking and policy alone do not resolve it. In one survey, 40% of employees who recalled receiving AI training still used unapproved tools daily to complete their work tasks. And this is not a new phenomenon limited to the AI era, as you will see.
The part nobody puts on the slide
Now the finding that should stop the conversation about frontline compliance.
Senior decision-makers are more than twice as likely to use unapproved AI tools as the people they manage: 65% against 31% (TrustedTech / Censuswide, 2,001 UK and US employees, March 2026).
A separate survey found 69% of presidents and C-suite members, and 66% of directors and senior vice presidents, are comfortable with employees doing it (BlackFog).
And 81% of office professionals believe leadership operates under a different set of rules — rising to 85% at the largest organizations (PagerDuty).
⭐ The governance risk is running out of the offices of the people writing the governance. Which tells you something important: this is not indiscipline. When the executive and the analyst and the junior buyer are all doing the same thing, you are not looking at a behavior problem. You are looking at a system that does not meet the work.
Why they do it, in their own words
The reasons are not exotic. 53% say they prefer the independence. 33% say IT does not offer what they need. And 80% of American office workers use AI in their roles while only 22% rely exclusively on employer-provided tools.
Official tools arrive slowly, or arrive too limited for real work. So people use what works, and do not mention it.
We have seen this exact film before
None of this is new. It is at least the fourth time around the same loop.
The personal computer. In 1979 VisiCalc shipped on the Apple II, and finance people started buying Apple IIs on expense accounts to run it — because the MIS department could not give them what they needed and the approval cycle was measured in quarters. IT called them toys. The machines arrived anyway, one department at a time, paid for out of budgets nobody thought to police. By the time policy caught up, the question was no longer whether to allow them.
BYOD. IT fought it and lost, because employees had already decided. Policy arrived afterward to regularize what was happening anyway.
Amazon did not just teach people to buy online. It taught them what buying feels like — and once that became the baseline, the corporate purchasing system stopped feeling normal and started feeling broken.
Which produced the question a member put to me in April 2008, and which I have never stopped thinking about: why can’t we buy at work the way we buy at home?
That question was never really about the interface. It was about who holds the authority to act. At home you decide. At work you request.
And in May 2007, four days into this blog, I wrote that organizations usually modified their operations to accommodate the technology being implemented — and that practitioners named this as the main reason for lack of compliance.
Nineteen years later, the workforce has stopped modifying itself and started routing around the software instead.
What the shadow is actually telling you
Here is the reframe.
Every organization treats shadow usage as a risk to be fenced. Almost nobody treats it as a measurement.
But that is exactly what it is. When someone uses a personal tool for a specific task, they have told you — accurately, unprompted, at their own inconvenience — that the sanctioned system does not serve that task. They are not reporting an opinion in a survey. They are voting with the only currency they control, which is their own time.
Sometimes the sanctioned system could have served the task and the person did not know it — the capability exists, buried four menus down. That is still evidence about the system, not about them: a capability nobody can find is a design failure, not a training gap.
⚠ It is not clean data in the compliance sense, and it should not be read as an instruction to approve every tool someone has found. The confident and vocal are overrepresented. Silence does not mean the sanctioned system works — it can mean people are afraid to say otherwise. And a workaround that reveals a broken workflow can create a new exposure at the same time.
What it is, is unusually clear behavioural data about the gap between the work people have to do and the system they have been given. That still has to be read, investigated and placed in context. It is a signal, not a verdict.
I learned this in 1998, on a defence maintenance contract delivering next-day parts 51% of the time against a 90% requirement. The technicians were holding parts orders until late afternoon, which looked exactly like resistance. It was not. They were measured on call response, so they cleared calls first and submitted orders afterward — and that single behavior produced a chain that ran through purchasing, supplier selection, the border and into finance.
Nobody needed it explained to them better. The behavior was the most accurate information available about how the system actually worked.
Delivery moved from 51% to 97.3% in three months, and held for seven years, once those operating relationships were exposed and realigned. The technology came afterward.
Shadow AI is the same signal, arriving twenty-eight years later with a subscription attached.
What to do with it
Not a policy. A reading.
Every conventional response to shadow usage carries an assumption about who is at fault. Change the assumption and you get a different question.
The column on the right costs nothing to collect and is more honest than any process map you own.
And notice who is doing it. If your executives are the heaviest users, the problem is not awareness.
Then ask what happens to the person who tells you. Which is the whole thing.
⚠ Detection and disclosure serve different purposes. Detection may be necessary to manage risk, and in regulated environments it is an obligation. But if the only response to a discovered workaround is punishment, people will hide the work from you — and you will lose the evidence you needed to fix the system that produced it.
The technicians in 1998 were not caught. They were understood.
The uncomfortable conclusion
If 90% of your people are already using tools you did not select, then your organization has run a distributed, unfunded, entirely voluntary readiness assessment and thrown away the results.
The consumer mindset is not encroaching on the business world. It arrived years ago, it is already setting the standard, and the only real question is whether you are going to read what it is telling you or keep trying to fence it.
If you use it at home, you will use it at work.
The organizations that understand this will stop asking how to stop it and start asking what it reveals.
-30-
Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™
Jon W. Hansen, FCIPS — Procurement Insights | Hansen Models™
Once you can see which tasks the unsanctioned tools are actually doing, you still have to decide how to work with a model on those tasks — without simply asking it for the answer.
On 25 September I am running a free 30-minute lab on the linchpin version of that question: how to select, work with and progressively engage AI models so the output gets more accurate rather than just more polished. A working session, not a presentation.
Friday, 25 September, 9:30 AM ET, and again Wednesday, 30 September, at 1:00 PM ET.
Everyone who attends receives a copy of Thinking With the Machine. Fifteen days later they also receive 90 days of free access to the consumer version of ARA™ RAM 2025™ — because the most useful way to understand what a technology could mean inside an enterprise is to work with it personally first.
Register: https://www.linkedin.com/events/7504567838724997120/
Share this:
Like this:
Related