What happened
Deloitte UK's GenAI Workforce Survey, which the firm describes as the largest study of workplace generative AI use conducted in a single country, questioned 25,000 working adults across 22 industries between May 7 and June 10, 2026. It will be repeated every six months.
Two findings carry the compliance weight. Almost a third of generative AI users bring their own tools to work and use them without their employer's knowledge, the practice usually called shadow AI. Nearly half of the employees using generative AI at work had no formal training on how to use it safely.
Adoption itself is now mainstream. Sixty three percent of UK working adults said they knowingly use generative AI for work, and two thirds have used generative AI tools at work at some point. Of those who described their tools, 46 percent use free tools at work, 34 percent use external tools paid for by their employer, and 17 percent use in house tools.
The cost is landing partly on employees. Workers are spending close to GBP 1 billion a year of their own money on generative AI tools for work. Reporting on the survey separates the shadow cohort further: 31 percent of generative AI users had used tools at work without their employer's knowledge, and of those, 22 percent believed their employer would approve and 9 percent believed it would not.
The compliance concerns named are cyber risk, copyright exposure, and audit trails, the last because work produced and stored outside an approved system leaves no reliable record of what was asked, what was used, and what was checked.
Why this is a GRC story
Shadow AI is a data flow you did not approve. Every unapproved tool is an unassessed processor of company and customer data. Without an entry in the vendor register and a contract behind it, there is no processor obligation, no breach notification path, and no answer when a client or regulator asks where the data went.
Training is the cheapest control available. Almost half of users working with no formal guidance is not a technology failure. It is a governance gap that a short mandatory programme closes faster and cheaper than any tooling purchase.
Employees paying for tools is a signal, not a saving. When staff spend their own money to do the job, it usually means the sanctioned option is slower, harder to access, or does not exist for their role. Prohibition without an alternative route tends to produce more shadow use, not less.
What to watch
Watch whether the next wave of the survey shows training and approved tool access closing the shadow gap, or whether the numbers hold as the tools get better and cheaper. In the near term, watch how privacy and financial services supervisors treat unapproved AI tooling in examinations.
The practical takeaway: run a short anonymous check on which tools your teams actually use, compare it against the approved list, and fix the friction that produced the difference. Then make the safe route the fastest one.
Attribution: Analysis based on Compliance Week and related public reporting. This article is original commentary, not a repost of the source material.
