Dear Board Director,
When I visit an organisation, I ask people a simple question: do you use AI in your work?
The answer is almost always the same, and it is almost never an answer. People tell me: "We are only allowed to use Copilot."
I have heard this in banks, in listed companies, and in professional firms. It is offered helpfully and without hesitation. And it should give any board pause, because the question was about what people do, and the reply was about what they are permitted to do. Those are not the same thing, and the difference is where governance quietly fails.
That difference has a name. Shadow AI is the use of AI tools, features and services inside an organisation without approval, inventory or oversight. This letter is about why prohibition tends to widen that gap rather than close it — and why a board that responds to AI with a restriction may end up knowing less than one that does not.
The Answer That Is Not an Answer
"We are only allowed to use Copilot" is a statement about policy. It is not a statement about behaviour. It does not say what tools are open in a browser tab, what is being used on a personal phone during a deadline, or what a colleague pasted into a free chatbot last Thursday.
People answer this way because they have learned to hear the question as an audit. In an organisation where using anything else is a breach of policy, the only safe reply is the permitted one — whether or not it is complete. Nobody is being dishonest. They are answering the question they believe is being asked.
The same substitution happens one level up. When a board asks whether AI use is under control, management can answer, entirely truthfully, that staff are permitted to use only one approved tool. The board hears an assurance about practice. It has received a description of policy. The gap between the two is never discussed, because nobody notices it opened.
Permission is not practice. A board that accepts the first as evidence of the second has not been misled. It has simply stopped asking.
What the Permitted Tool Actually Measures
There is now data on this. Recon Analytics, drawing on more than 150,000 respondents between July 2025 and January 2026, examined what happens when employers provide AI tools with and without alternatives.
68%
Where Copilot is the only platform an employer provides, 68% of workers adopt it as their primary tool.
Where both Copilot and ChatGPT are available: Copilot's share falls to 18%.
Where all three major platforms are available: 8% choose Copilot.
The same tool, the same people, three very different numbers. What changes is not the software but the presence of a choice. An adoption figure of 68%, presented to a board as evidence that the approved tool is working, may be measuring nothing more than the absence of alternatives.
Two further findings are worth noting. Among workers who tried Copilot and stopped using it, 44.2% cited distrust of its answers — the highest figure of the three major platforms. And more than half of those who have Copilot available at work also have ChatGPT available, which suggests that "only Copilot" is frequently a statement of policy rather than a description of the environment.
A restriction that channels people toward the tool they trust least, in an environment where alternatives are a browser tab away, is not a stable control. It is a queue forming behind a door that does not lock.
A Ban Is a Control That Produces No Evidence
Prohibition is an attractive response to an unfamiliar risk. It is quick, it costs nothing, it can be minuted, and it signals seriousness. For a board under pressure to demonstrate that AI is being taken seriously, a restrictive policy is the cheapest available proof.
It is also, in governance terms, close to worthless — because it generates nothing a board can review. There is no inventory of what is in use, no log of incidents, no record of which business processes now depend on a model, and no data on where information is travelling. A prohibition cannot be reported on. It can only be asserted.
The control removed the evidence. Not the risk. An organisation that has banned AI tools does not have less AI in use than one that has not. It has less knowledge of the AI in use.
Three Ways Prohibition Increases the Exposure
Beyond the loss of visibility, a ban tends to make the underlying risk worse in three specific ways.
What the Breach Data Suggests
IBM's 2026 Cost of a Data Breach Report, published 29 July 2026 and based on breaches at 602 organisations, offers a useful corrective to the assumption that AI risk is principally about models.
More than one in five organisations reported a breach targeting AI models or applications. The most common causes were not the models themselves. They were weaknesses in the surrounding systems: compromised APIs, applications or plug-ins (27%), and cloud misconfigurations affecting AI workloads (27%).
That distribution matters. The exposure sits in the connective tissue around AI — the integrations, extensions and configurations that accumulate without a procurement decision and are rarely inventoried. A policy restricting which chatbot staff may open does not address any of it.
Questions Worth Raising at Board Level
The following are framed so that they cannot be satisfied by a statement of policy. Each asks for evidence rather than permission.
A Final Observation
This pattern is not new. Organisations met consumer file-sharing and personal devices with prohibition a decade ago, and learned that restriction without a credible alternative produces invisible adoption rather than no adoption. Those that moved quickest to provide a sanctioned, genuinely usable option regained the visibility they had lost. Shadow AI is the same problem with a shorter fuse and a wider blast radius.
None of this argues for permissiveness. It argues for controls that produce evidence.
The question is not whether your organisation has a policy on AI. It is whether that policy tells you anything you could take to a board meeting.