The sanctioned tool that cannot see anything
Most organizations now have an enterprise AI agreement. The interesting question is not whether the tool is approved. It is whether the approved route can do the work — and how you would know if it isn't being used.
A defensible decision, with a consequence nobody priced
The pattern is consistent enough to be worth naming.
An organization signs a proper enterprise agreement with a major AI provider. Legal reviews it. Security reviews it. And because both of those reviews are competent, the models end up deliberately walled off from internal data, from production systems, and from proprietary research.
That is a defensible decision. In many cases it is the right one, and the people who made it are not being timid — they are correctly unwilling to put the organization's most valuable material into a system whose data handling they cannot fully characterise.
But it has a consequence, and the consequence is rarely priced into the decision.
The sanctioned tool cannot do the work people actually need done. It can draft an email. It cannot answer a question about the data, because it cannot see the data. And the work does not stop simply because the approved route cannot carry it. It moves to whatever can see the data, which is usually an account the organization does not manage.
The number that makes this concrete
Independent and vendor research consistently puts a large minority of workplace AI use on personal accounts. The best-documented recent estimate is about a third of employees, with roughly 40% of the material involved being sensitive.
Cyberhaven's 2026 AI Adoption and Risk Report, 222 companies, method disclosed. Vendor data, and we label it as such — but the sample is large, the method is published, and no independent researcher has better instrumentation on this particular question.
Read that number next to the enterprise agreement and the picture is uncomfortable. The contract governs a route people are not using for the work that matters. Spend is being recorded against one channel while exposure accumulates in another.
About a third of employees reach AI where the contract does not.
- Sanctioned
- Personal-account employees
Why this is a governance problem and not a security problem
The instinct is to treat this as leakage, and to respond with monitoring or with a stricter prohibition.
Both responses fail for the same reason: they address the symptom of a routing problem. The person pasting a document into a personal account is not circumventing a control. They are completing a task that the approved route cannot complete, under a deadline that did not move.
A prohibition therefore does not reduce the behaviour. It reduces your visibility of the behaviour, which is strictly worse — you now have the same exposure and less evidence of it.
The governable version of this question is different, and it has three parts:
- Can the approved route reach the work that actually needs doing?
- If not, where is that work going instead?
- What would tell us, without surveillance, that the answer changed?
Those are answerable. They are also uncomfortable to answer, which is why the assessment usually stops at "we have an agreement."
What an honest assessment looks like
Start from the work, not from the tool. Which tasks genuinely require reaching internal data, and how often. That list is almost always shorter than feared and more specific than expected.
Then ask what the approved route can actually reach today. Not in principle — in the configuration that is deployed, with the controls that are switched on.
The gap between those two is the whole finding. Everything that sits in it is either work that is not getting done, or work that is getting done somewhere you cannot see.
Then the decision is a real one: extend the sanctioned route to reach some of that material with controls on it, or accept that a category of work stays manual and say so out loud. Both are legitimate. What is not legitimate is a policy that assumes the first while funding the second.
What this costs to find out
Less than the alternative, which is discovering the answer through an incident.
The assessment is a matter of weeks, not quarters, and its output is an evidence pack: what the approved route reaches, what the work requires, where the difference is going, and which of those gaps is worth closing.
We do not sell any of the tools involved, and we have no position in the outcome.
Start a conversation about the decisions in front of you.
Start a conversation