August 17, 2026
Your People Already Use AI, Only Nobody Knows It
Roughly three quarters of office staff use AI tools without official approval. What that means in practice in a mid-sized company, and how you get a handle on it with a short list of approved tools, one named person for approvals and clear data levels.

Friday, 5:40 pm. A quote still has to go out, and the third paragraph reads badly. Your colleague copies the text into a chatbot in the browser, customer name, quantity and volume pricing included, has it rewritten, copies it back and sends the quote. Good work, done fast. And nobody in the company knows that your price tiers now sit with a provider nobody ever chose, under terms nobody ever read.
That is not an exception. That is the normal case.
The number that surprises nobody who hears it
t3n reports that roughly three quarters of office staff use AI tools without official approval. If you have no rule about it in your company, then you do not have an AI-free zone. You have an unknown number of tools in use, and no list of them anywhere.
The interesting question is not whether this happens at your place. The interesting question is which data goes out with it. In practice it is exactly the data somebody is working on right now, and that is rarely marketing copy. It is quotes with the costing behind them, customer emails with names and history, job applications, complaints, supplier prices, now and then a draft contract.
Why a ban only makes it invisible
Your people do not do this out of carelessness. They do it because it works. The half hour for rewriting a paragraph, summarising an email thread, sorting a column in Excel, the machine really does take that off their hands. These tools are used everywhere somebody wants to save time, right out into a farmer's field, where there is no IT department to ask.
A ban changes little about that. It moves the usage onto the private phone, and with that you lose the last bit of overview you had. Ban it and you end up with the same risk plus no chance of ever hearing about it.
Three things, and it really is only three
The sober route is not a 14 page policy. It is three statements that fit on one page.
First, a short list of approved tools. Short means two or three, not twelve. For each one it says what it is meant for and who pays for the access. A tool the company pays for comes with different contract terms than a free account somebody set up privately. That is where the difference lies, not in the model.
Second, a named person for approvals. One person, one name, a short path. If somebody needs a fourth tool, they should be able to ask and get an answer within two days. If approval takes three weeks, the list is fiction again after a month.
Third, a clear statement about which data may go how deep. Three levels are enough in most companies.
- Free to go outside: texts that get published anyway, drafts without names and numbers, general questions.
- Only into a tool with a contract: internal documents, customer correspondence without particularly sensitive content, quotes after checking first.
- Stays in the house: personnel data, health data, complete price calculations, contracts, anything that carries an obligation towards third parties. For that you need a model on your own hardware, or no AI at all.
That way you decide the depth, and not chance, depending on which browser window happened to be open.
And when the tool gets it wrong
The second question next to "who has the data" is "what happens when it goes wrong". There are documented cases for that too. In one of them, an AI agent deleted code and then presented the logs in a way that made the incident look more harmless than it was. You do not have to turn that into the end of the world, but a build instruction does follow from it. A model that is allowed to write and delete with no human in between is a risk whose size you only learn afterwards.
That is why we build it differently. The machine proposes, a human approves. For a quote text that means the draft sits in the system and sales sends it out. For a data change it means the agent shows the proposed change and somebody confirms it. That costs a few seconds per case and saves you the question of who actually decided.
How we handle it ourselves
At Kunst gegen Bares, the platform for a live art stage in Düsseldorf that we built and run ourselves, a cloud AI writes the text suggestions per channel. That is a deliberate decision and not a stopgap. The texts are meant for the public, they belong in the first level. Every post is approved by a human, and for publishing it goes out to the platforms themselves. If you want to post on Instagram, you send data to Instagram, and no architecture changes that. What matters is that every one of these services stays replaceable, because the data and the system belong to us.
Elsewhere it looks different. Cloud, mail server, password manager, Git server and this website run on a server we operate ourselves. That is the third level, and that is where it belongs.
Two levels in the same house, each one chosen on purpose. That is exactly what we mean by sovereignty. Not that nothing leaves the house, but that somebody decided what leaves the house.
If you want to know where you stand right now, ask three people on Monday which AI tool they used last week. Not as a check-up, but as a stock-take. Their answers are the start of your list.
Was this helpful?