← Research
Research

What to do when people work around the AI policy

At nine in ten companies people use their own AI tools for work; at four in ten the company has bought one. The workaround is information about the policy, and the useful response is an amnesty rather than a crackdown.

Last reviewed: 18 September 2026

MIT NANDA found workers at over 90 per cent of surveyed companies using personal AI tools for work while 40 per cent of companies had bought an official one. When people work around the AI policy, the workaround is information about the policy. Why a crackdown loses the information, what a shadow-AI amnesty is, and the three things it produces. An evidence review by Rahim Hirji; every figure resolves to a graded entry in the evidence base that says what it does not show.

Question this page answersAll 811 questions this research covers

When people work around the AI policy, the workaround is information about the policy. MIT NANDA's 2025 report found workers at over 90 per cent of the companies it surveyed using personal AI tools for work, while 40 per cent of companies had bought an official one; the sample is small and the report says so, but nobody who runs an organisation doubts the direction. The instinctive response is a crackdown, and a crackdown loses the one thing the workaround was telling you: what the work actually needs, which tools fit it, and where the official programme has failed to reach. The useful response is to collect that information before deciding what to block, which is what a shadow-AI amnesty is for.

The answer, in one line

Because the policy was written about a programme and the people are running their own. MIT NANDA's 2025 report found workers at over 90 per cent of surveyed companies using personal AI tools for work while only 40 per cent of companies had bought an official one.

Share as a card

What the workaround says#

Three things, usually. The official tool does not fit the task, so people use one that does. The official route is slower than the result is worth, so people take the short one. Or the policy exists and nobody can find it, or read it, or tell whether the thing they are doing is covered, so they guess. MIT's report locates enterprise failure in the gap between a tool and the workflow it is dropped into; the shadow use is people closing that gap on their own initiative, with tools the organisation has not examined and data it has not protected. That is a real risk. It is also the most accurate map of where AI is useful in the organisation, drawn by the people doing the work, and a leader who blocks it first has burned the map.

Why the crackdown fails on its own terms#

A blanket block moves the use to personal phones and personal accounts, where the organisation can see none of it and protects none of the data. It also tells the people who found the useful tools that finding useful tools is punished, which is a message an organisation in the middle of an AI programme should be careful about sending. Duolingo's chief executive learned in May 2025 what a public backlash does to a policy announced without a boundary underneath it; an internal workforce reacts the same way, more slowly and less visibly. The block should come, aimed at the tools that put data or consequential decisions at risk, and it should come after the organisation knows what it is aiming at.

The amnesty#

A defined period, say a month, in which anybody can declare the AI tools and prompts they use for work, without penalty and with the explicit promise that the declaration will not be used against them. Rules Before Tools put it in the first-quarter list in August 2025, alongside the consent register and the incident drill. It produces three things. A map of actual use, by team and task, which no policy review produces. A shortlist of tools that people chose because they fit, from which the organisation can standardise. And a list of the places where the official programme has not reached, which is the programme's own feedback, delivered free. The prompts people declare are often the most valuable item, because they encode how the work is actually done.

Then the three decisions. Standardise the safe tools and pay for them, so that the shadow use becomes official use with the data protected. Block the risky ones, with the reason stated, aimed at the specific risk. And share the best prompts and patterns across the organisation, with credit to the people who found them, which turns the people who worked around the policy into the people who wrote the next one.

What the policy has to become#

A policy that people work around is usually a list of prohibitions. The one that survives is a list of decisions: which work a machine may draft, which it may decide, which it may never touch, and what must be checked by a person before it leaves. Written at that level, a policy can be applied to a tool nobody has heard of yet, which is the test of whether it will still make sense after the next model release. Six elements that hold across releases are at how do you write an AI use policy that works. The workaround is the policy's first user test. Fail it in public rather than pretending it passed.

16 September 2026: the workaround measured across the UK workforce#

The MIT figures above came from 52 organisations. On 16 September 2026 Deloitte published an Ipsos survey of 25,000 UK workers: 63 per cent use generative AI for work, 31 per cent of them without their employer’s knowledge, 23 per cent perceive a stigma around using it, and 64 per cent of weekly users worry that their manager will decide the tool can do their job. About half have had no training in using it safely and 65 per cent say leadership guidance is not convincing. Bloomberg, reporting it, added that almost one in ten had used tools their employer had banned. The National Cyber Security Centre had written nine days earlier that shadow AI is unlikely to disappear and that the response is to understand why people reach for the tools and provide secure alternatives, which is the amnesty’s logic in a government agency’s words.

What the survey adds to this page is the reason for the workaround that the MIT data could not see. The three reasons above are about fit, speed and clarity. Deloitte’s figures point at a fourth: fear. People hide the tool because they believe it is evidence for their own redundancy, and no amnesty will produce a map while that belief stands. The commitment that has to come first is on headcount; what it contains is set out at what should we tell employees about AI and headcount. The figures are self-reported and Deloitte advises on the adoption it measures.

What nobody has measured#

The 90 and 40 per cent figures rest on MIT NANDA's interview and conference sample and should not be quoted as population rates. No study measures the effect of an amnesty on subsequent risk or adoption; the practice is a proposal from the August 2025 essay, and its logic is that information is worth more before a block than after one. Whether it changes outcomes is untested. That it changes what the organisation knows is not.

Key sources

On writing the policy that people will not need to work around, how do you write an AI use policy that works. On the difference between licences activated and work changed, how do you measure AI adoption properly. On what a CHRO does first, the CHRO guide to AI. On the decisions underneath the policy, AI leadership.

About this research#

Rahim Hirji is the author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company. He has run, grown, bought and advised businesses with AI in them. Findings are attributed to the studies and statements that produced them and kept separate from the interpretation. This is a living reference, reviewed and updated as significant new evidence appears.

How this research works  ·  Reviewed quarterly  ·  Found an error? Tell me and it is corrected on the page.

Evidence review · SS-2026-248 · Graded against the published rubric

Cite this page

Hirji, R. (2026). What to do when people work around the AI policy. The SuperSkills evidence base, SS-2026-248. https://thesuperskills.com/research/what-to-do-when-people-work-around-the-ai-policy. Last reviewed 18 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

Why do people work around the AI policy?

Because the policy was written about a programme and the people are running their own. MIT NANDA's 2025 report found workers at over 90 per cent of surveyed companies using personal AI tools for work while only 40 per cent of companies had bought an official one. The workaround is usually a better-fitting tool, a faster route to a result, or a policy nobody can find. Each is information about the policy rather than about the people.

What is a shadow-AI amnesty?

A defined period in which staff declare the AI tools and prompts they already use, without penalty, so the organisation can standardise the safe ones, block the risky ones and share the best. It appears as a first-quarter action in Rules Before Tools (August 2025). It produces the map of actual use that no policy review produces.

Should we block unauthorised AI tools?

Block the ones that put data or decisions at real risk, after the amnesty rather than before it, so that the block is aimed. A blanket block before the map exists drives the use out of sight and loses the information, and the same people keep working around it on their phones.

In this hub

Definitions

The terms this field uses, defined against their primary sources.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

An amnesty produces the map. Turning the map into a policy written as decisions rather than prohibitions, with the people function, is the engagement. AI advisory for CEOs and boards.

This is the argument HR audiences push back on hardest, which is why it works on stage. There is the HR and CHRO version, and the full range of topics and audiences.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.