Follow it, and then help change it. A company ban on AI is usually a decision about data, often made in a hurry: in one large 2024 survey, more than a quarter of organisations had banned generative AI at least temporarily over privacy and security. Using it in secret is common, and the risk of doing so falls on you rather than the company, because you are the one who put the information in and the one who answers for the output. The better move is to find out what the ban is protecting and propose one narrow, checkable use that protects the same thing. A ban written about data can usually be answered with a proposal about data.
The answer, in one line
Follow the ban, find out what it is protecting, and propose one narrow, checkable use that protects the same thing. Using AI in secret puts the risk on you, because you are the one who entered the information and the one who answers for the output.
Why companies ban it#
Cisco's 2024 Data Privacy Benchmark surveyed 2,600 privacy and security professionals across twelve countries. Twenty-seven per cent said their organisation had banned generative AI at least temporarily, 63 per cent had set limits on what data could be entered, and 61 per cent had limits on which tools employees could use. The reason is visible in the same survey: 48 per cent admitted entering non-public company information into these tools themselves.
The case that made bans respectable was Samsung. The Register reported in May 2023 that the company had reimposed a ban on ChatGPT and similar tools for staff in one of its largest divisions after source code was entered into a public chatbot, with an internal memo citing growing concerns about the security risks. That is the template most bans follow: a fear about where information goes, a blanket rule because a careful one takes longer, and a promise to revisit.
Why using it anyway is a bad bet for you#
Plenty of people do. In Deloitte's 2026 UK survey, 31 per cent of workers who use generative AI said they use it without their employer's knowledge, and Microsoft and LinkedIn's 2024 Work Trend Index found 52 per cent of AI users reluctant to admit using it for their most important tasks. Common is not the same as safe, for three reasons.
The first is information. If you paste a client document into a personal account, the breach is yours. Stopping that is what the ban was written for. The second is visibility. Company systems often record more than people assume, and where an approved tool exists its administrators may see what you submit; the detail is at can my employer see what I put into AI. The third is the output. If the tool is wrong and the work goes out under your name, using a banned tool to produce it makes the mistake harder to defend, not easier. Whether an employer can act on it is covered at AI, discipline and dismissal, and the question of disclosure at should I tell my boss I used AI.
Find out what the ban is protecting#
Most bans are broader in wording than in intent. Before proposing anything, ask a few plain questions of whoever owns the rule. Does it cover all AI, or public chatbots on personal accounts? Is the concern personal data, client data, or any company information at all? Does it cover AI features already built into software the company licenses? Is an approved tool being evaluated, and on what timetable? Is there a named person who can grant an exception? The answers usually show that the ban is protecting one or two specific things, and that a use which never touches them was not the target.
Make a proposal they can say yes to#
A good proposal is small and specific. One task, described in a sentence. No confidential, client or personal information involved, and a statement of how you will make sure of that. An approved tool or an enterprise account where the terms protect the company's data, rather than a personal account. A rule for how the output gets checked, and by whom. A review date. And one measure of whether it helped, something other than how much faster it felt, since people consistently overrate that; the reasons are on how to measure adoption properly.
That shape is the same one a good company policy uses, set out at how to write an AI use policy that works. A proposal written that way gives the person who made the ban a way to relax it without losing what it protects.
Keep your own judgement moving#
A ban at work does not stop you learning outside it. Use the tools on your own time with public material and your own data, and practise the part that will matter when the ban lifts: telling when the output is wrong. That skill is described at how do I know when AI is wrong. Keep doing the core of your job yourself, too. People who rely on AI for work they can no longer do unaided are the ones least able to catch its errors.
If you are the one who made the ban#
A blanket ban stops the visible use and pushes the rest out of sight, which is the opposite of what a data rule is for. Deloitte's survey found about half of UK users had no formal training in using AI safely. Untrained, unseen use is the riskiest combination available. The alternative is to decide, in advance, which decisions a machine may make, who can stop each one, what people must remain able to do, and how anyone would know if it went wrong; that is Rules Before Tools. What to do when people are already working around the rule is covered at what to do when people work around the AI policy.
What this does not show#
It does not show that bans are always wrong. Some work, under some contracts and regulators, should not touch a public AI tool at all, and a narrow ban there is the right control. The survey figures are self-reported, sponsored by companies that sell into the problem, and the Cisco figure is from 2024; the share of organisations with bans may have changed since. Nothing here is legal or employment advice. Your contract, your company's policy and your regulator govern what you may do, and a proposal is a request, not a permission.
Essay · SS-2026-414 · 2 vendor studies and 1 institutional survey
Hirji, R. (2026). My company banned AI. What should I do?. The SuperSkills evidence base, SS-2026-414. https://thesuperskills.com/research/my-company-banned-ai-what-should-i-do. Last reviewed 5 October 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work