A third of GenAI users are hiding it from their employer
Deloitte UK's inaugural GenAI Workforce Survey, reported by Compliance Week, asked 25,000 UK workers how they actually use generative AI at work. Sixty-three per cent of working adults aged 18 to 70 say they knowingly use it for work, and almost a quarter use it daily. Nearly a third of those users bring their own tools and use them without their employer's knowledge. Fieldwork ran from 7 May to 10 June 2026, which makes this among the largest single-country pictures of the problem available.
The numbers
- 63% of UK working adults aged 18–70 knowingly use GenAI for work; 24% use it every day.
- Nearly a third of GenAI users bring their own tools and use them without the employer knowing.
- Nearly half of employees using GenAI at work have had no formal training on using it safely.
- £958 million a year is spent by UK workers, out of their own pockets, on GenAI tools used for work. 17% pay personally for at least one external tool.
- 65% say there is no convincing leadership position on how GenAI should be used in their organisation.
- Sample
- 25,000 UK workers, fieldwork 7 May to 10 June 2026.
- The headline
- A third of users are deliberately not telling their employer.
- The tell
- £958m of personal spend — usage that never touched procurement.
Why the personal spend figure matters most
The hidden-usage number gets the headlines, but the money is the more diagnostic finding. When an employee pays for a tool themselves, several things are true at once, and none of them are good:
- There is no contract. No data processing agreement, no confidentiality terms, no agreed security posture, no ability to audit. Under the GDPR, a supplier processing personal data on your behalf needs a written arrangement under Article 28. A personal subscription has none.
- There is no consumer-versus-business distinction. Business tiers of most AI services have different default settings for using content to improve models. A personal account typically does not.
- There is no identity link. It sits outside SSO, so it survives the leaver process. Someone who left in March may still have the work they pasted in February.
- There is no log. If you are asked what was disclosed, the honest answer is that you cannot know.
That last point is the compliance problem in one line. A breach you cannot characterise is one you cannot notify accurately, and "we do not know what was sent" is a poor position in front of a regulator.
The training gap is a governance failure, not a user failure
Half of the people using these tools at work have had no training on doing so safely, and two-thirds say leadership has not given a convincing line on it. Those two findings explain the first one. People are not hiding usage because they are reckless; they are hiding it because the tools make them faster and nobody has told them clearly what is allowed.
Which means a ban is the least effective available response. We have written before about why prohibition moves usage to personal devices rather than stopping it — and this survey is what that looks like measured at national scale.
What to do with this
- Measure before you legislate. A policy written without knowing your actual usage will target the wrong things. Find out which tools are in use and for what.
- Provide a good sanctioned option. The most reliable way to end personal subscriptions is a business-tier tool that is genuinely better and easier to reach.
- Say something definite. "Approved for X, never for Y, ask about Z" beats a long policy nobody finishes. Two-thirds of workers are waiting for exactly this.
- Train at the moment it matters. An annual module is weaker than an intervention at the point someone is about to paste a customer record.
- Put the control where the data leaves. Inspection at the egress point covers the tools you have not approved and have not heard of, which is the category this survey says is largest.
See what is actually leaving your workspace for AI tools, approved or not.
Explore AI Data Leak ProtectionCommon questions
From 25,000 UK workers surveyed between 7 May and 10 June 2026: 63% of working adults aged 18-70 knowingly use GenAI for work and 24% use it daily; nearly a third of users bring their own tools without the employer's knowledge; nearly half have had no formal safe-use training; and UK workers spend an estimated £958 million a year of their own money on work-related GenAI tools.
Because it sits outside every control you rely on. There is no data processing agreement under Article 28 of the GDPR, no business-tier settings governing whether content trains models, no link to your identity provider so access survives the leaver process, and no log of what was disclosed if you are later asked.
A ban alone tends to move usage onto personal devices where you have no visibility at all. The combination that works is a sanctioned tool good enough to prefer, a clear and short statement of what is allowed, training at the moment of risk, and technical inspection at the point data leaves your environment.
Sources
- Deloitte survey exposes compliance gaps as a third of employees admit using shadow GenAI at work — Compliance Week, 23 September 2026
- GenAI Workforce Survey — Deloitte UK, 22 September 2026
