“We Don’t Use AI” Is a Claim, Not a Control

3 min read
July 24, 2026 at 1:53 PM

A question we hear often from clients sounds simple on its face: Our company says it doesn’t use AI, and our acceptable use policy says the same. How do we actually prove our employees aren’t using it? It is a fair question, and the honest answer is uncomfortable. A written policy states an intention. It is not, by itself, evidence that the intention is being met. The gap between “we have a policy” and “we can demonstrate the policy is followed” is exactly where risk lives.

A Policy Prohibits; It Does Not Prevent

Blocking the best-known services, such as ChatGPT, Claude, Gemini, Copilot, at the firewall or web proxy is a reasonable first step, but it is not proof of anything. There are now hundreds of AI-enabled tools, new ones appear weekly, and AI features are increasingly baked into the everyday business applications organizations already run. You cannot block your way to certainty. Worse, employees on personal devices, home networks, or mobile phones sit entirely outside the corporate perimeter. The absence of blocked-traffic alerts is not the same as the absence of use.

The Data Says the Use Is Already Happening

The assumption that “we don’t use AI” usually does not survive contact with telemetry. According to the Verizon 2026 Data Breach Investigations Report, 45% of employees are now regular users of AI on corporate devices, authorized or not up from just 15% the prior year. Roughly 67% reach those tools through personal, non-corporate accounts on company devices, and unauthorized “shadow AI” use has become the third most common non-malicious insider action showing up in data-loss-prevention data, a fourfold jump year over year. The most common data type employees paste into external AI models is source code, followed by images and other structured business data.

Independent browser-telemetry research from LayerX points the same direction: organizations have effectively zero visibility into roughly 89% of AI activity, the large majority of it flowing through unmanaged personal accounts that never touch corporate single sign-on. In that study, generative AI had already become the single largest channel for data moving from corporate to personal control,  ahead of personal email and personal cloud storage. The lesson is not that these tools are uniquely dangerous. It is that the activity has outrun the policy, and most organizations cannot see it.

Why a Strict Ban Can Make the Problem Worse

A blanket prohibition feels decisive, but it often backfires the same way banning consumer file-sharing did a decade ago. Employees still have work to finish, so they route around the block using things like personal laptops, phones, home accounts, and the activity moves into places where the organization has no ability to log, govern, or investigate. A ban that is not enforceable simply converts visible, manageable risk into invisible, unmanageable risk. The organizations that prohibited public AI tools in 2023 still show up prominently in today’s shadow-AI figures.

What “Proof” Actually Requires

If an organization genuinely intends to operate without AI, or to permit only sanctioned use, the policy has to be backed by controls that produce evidence. At minimum, we would expect to see:

  • A clear, written policy prohibiting employees, contractors, and consultants from using unauthorized AI tools, with the scope and definitions spelled out.

  • Defined, communicated consequences for violations, giving the policy teeth and employees understand them.

  • Logging and monitoring of web traffic and application usage capable of surfacing AI activity, including access via non-corporate accounts where technically feasible.

  • Data-loss-prevention controls tuned to detect sensitive content, such as source code, customer PII, regulated data, and moving toward AI destinations.

  • Enforcement of single sign-on and restriction of personal-account access on managed devices, to close the visibility gap that shadow AI exploits.

  • Periodic audits, access reviews, and awareness training to verify compliance rather than assume it.

Notice that every one of these is a detective or verifying control. That is the point: you cannot demonstrate a negative (“no one is using AI”) with a policy document alone. You demonstrate it with monitoring that would have caught the behavior if it were occurring.

A More Durable Approach: Govern, Don’t Just Forbid

For most organizations, the practical path is not an unenforceable ban but managed adoption. That means selecting an approved, enterprise-grade AI platform with appropriate data protections; defining clearly what information may and may not be entered; training staff on acceptable use; prohibiting all other tools; and monitoring for compliance. This gives employees a sanctioned, productive option thereby removing the incentive to go around IT while keeping AI activity inside a perimeter the organization can actually see and control. As the research consistently concludes, banning AI outright is not a durable strategy in an increasingly AI-driven economy; adaptive, contextual controls that enable safe use are.

The Bottom Line

“We don’t use AI” describes an aspiration. Whether it is true is an empirical question and answering it requires visibility the organization may not currently have. Before certifying a no-AI posture to a customer, an auditor, a regulator, or your own board, confirm that the monitoring exists to back the claim. In our experience, once that visibility is switched on, the more useful conversation is rarely how do we prove no one uses AI? It is now that we can see it, how do we govern it well?

Contact Us

Get Email Notifications

No Comments Yet

Let us know what you think