Skip to main content
Orion Five Engineering
Book a scoping call

10 Jalan Kilang #04-05, Singapore 159410
+65 6100 5505

AI governance

Shadow AI is already inside your organisation

MIT's enterprise research puts personal AI tool use among employees above 90 percent. Prohibition does not remove that risk. It removes your visibility into it.

Terence Kok · 2026-06-20 · 4 min read

A sealed matte white machined enclosure with a thin red glow escaping from one hairline seam along its edge.

MIT's most recent research on enterprise AI found that more than 90 percent of employees already use personal AI tools for work — regularly, not occasionally, and largely irrespective of whether a policy exists.

The governance risk is not the AI. It is confidential material leaving your systems with no contract behind it, no audit trail, and no control over what happens to it next.

Why a ban makes it worse

A prohibition does not reduce usage among people getting real productivity from it. It makes them discreet. You lose the one thing still working in your favour, which is knowing roughly what is happening.

The 90 percent figure reads better as evidence of demand and readiness than as a compliance failure. The workforce has already decided this is useful. The open question is only whether it happens inside a boundary you control.

The governed alternative

Four moves, in this order:

  1. Provide a sanctioned tool good enough that the unsanctioned one is not worth the friction.
  2. Put it behind your own boundary, with logging and retention you specify.
  3. Classify what may and may not go into it, in language an operator can apply without a lawyer.
  4. Publish the rule, then enforce it. A policy nobody has read is indistinguishable from no policy.
All insights