Blog

Nearly half of employees use personal AI for work: make what happens visible first

The Alert Online 2026 behavioural study shows many employees use personal AI for work and few know which tools are permitted. Start with visibility, not a ban.

· By

A daylit desk with a closed work laptop and folders on the left, a separate personal phone on the right, and a blank printed sheet and coffee cup between them.
Nearly half of employees use personal AI for work; start by making visible which tools are permitted.Image: IamVera.ai — original editorial illustration

The Alert Online 2026 behavioural study shows nearly half of employees use personal AI accounts for work, more than a third do so without the organisation's knowledge and few know which tools are permitted. Start with visibility: record which services are allowed, which data is forbidden and offer a usable approved alternative.

The finding was described in late September/early October 2026 in reporting on the Alert Online 2026 cybersecurity behavioural study. According to that reporting, nearly half of employees sometimes, often or always use a personal AI account or a private app for work, more than a third use AI tools without the organisation's permission or knowledge and fewer than two in five know which AI tools are permitted at work.

Our assessment: the core of this news is not that employees use AI, but that they adopt it into their daily work faster than organisations put policy, training and visibility in order. For a sizeable group of employees, personal AI has in practice already become work infrastructure, while the organisation often does not know which tools are being used or which data passes through them.

What exactly does the Alert Online 2026 behavioural study establish about personal AI at work?

According to the described results of Alert Online 2026, nearly half of employees sometimes, often or always use a personal AI account or a private app for work, more than a third use AI tools without the organisation's permission or knowledge and fewer than two in five know which AI tools are permitted at work. The exact percentages come from the reporting on that study and cannot be found directly in the available primary publications; we therefore present them rounded and attributed to that reporting.

This line is not new. The Nationaal Cyber Security Centrum already published in 2025 on a comparable Dutch trend: significant use of generative AI among employees, with only a quarter reporting clear organisational guidelines and a portion unable to judge whether such guidelines existed. Those figures concern an earlier study and do not confirm the specific 2026 results, but they do confirm the same pattern.

Why is unauthorised AI use a concrete security and privacy risk?

In our analysis the risk lies not in the use itself, but in the loss of control over which information is processed via which account. If employees paste confidential documents into a public AI service via their own account, the organisation cannot easily demonstrate which data category, which consent and which human oversight applied.

International research points in the same direction, although countries, samples and question framing differ and the figures may not be merged. PagerDuty reported, based on a Wakefield Research survey of 1,250 non-IT and non-technology office professionals at organisations with at least 500 million dollars in revenue in Australia, Japan, the United Kingdom and the United States, that 66% of respondents who had used AI for work had done so while believing this was not permitted under company policy. In its accompanying analysis, PagerDuty characterises AI adoption as growing faster than the policies intended to govern it, and reports that customer data, financial information and confidential company documents have entered public tools.

In our analysis, using public AI services through personal accounts can make it difficult for an organisation to demonstrate which data was processed, under which account and controls, and with what human oversight. The applicable GDPR accountability requirements should be assessed for the specific workflow and role of the organisation. Assessing the terms of use of AI providers is part of that, because training defaults and retention rules differ per service and per subscription.

Which concrete measures increase visibility and control over AI use?

Start with a short, usable set of rules rather than an abstract ban that is ignored anyway. The reporting shows that unfamiliarity with the rules is precisely the problem; in our analysis a workable, approved alternative lowers the incentive to resort to personal accounts. This is a practical recommendation from our editorial team, not a prescription from the study.

  • Make a short list of permitted AI services and state explicitly which data may never be entered, such as customer data, medical or financial information and confidential documents.
  • Offer an approved alternative that is genuinely usable, so employees do not fall back on their own account.
  • Record which personal accounts, mobile apps and browser extensions fall outside the organisation's control and therefore may not be used for work.
  • Train staff on concrete examples from their own work, not only on general prohibitions.
  • Apply least privilege as runtime control for AI where tools do run within the work environment.

These steps belong to a broader overview of AI governance and policy choices, in which policy, training and oversight connect rather than exist in isolation.

How do I measure whether employees actually know and follow the AI rules?

Measure periodically whether employees know the rules, not whether they exist. The study points to a gap between use and knowledge: rules only help once people know they are there and what they mean. A short recurring test and a low-threshold reporting point for borderline cases give better insight than a one-off policy announcement.

  • Ask on a sample basis which AI tools employees think are permitted and compare that with the official list.
  • Keep track of which approved service, which data category and which human oversight apply per sensitive workflow.
  • Ensure that for decisions with impact it is demonstrable that human oversight of AI decisions took place.

The final judgement on acceptable use remains with the organisation and its professionals. The value of measuring lies in closing the gap the behavioural study exposes: between what employees do and what the organisation thinks it can demonstrate.

Sources and references

  1. Aanzienlijk gebruik van generatieve AI onder medewerkersNationaal Cyber Security Centrum · 2025-09-29
  2. PagerDuty Report Finds Two-Thirds (66%) of Office Professionals Use AI at Work Despite Company PoliciesPagerDuty · 2026-06-11
  3. Shadow AI Is Happening Within Your OrganizationPagerDuty · 2026-06-11

Sources: The article relies on the Alert Online 2026 cybersecurity behavioural study, a 2025 publication from the Nationaal Cyber Security Centrum and two research publications from PagerDuty.

← All articles in this topic ← All articles