Most bosses believe they know which AI tools their staff use. The surveys say they are usually wrong, and that customers’ details are going into those tools every day.
Picture a shop. A customer sends an angry WhatsApp message with her name, phone number and order number. A member of staff copies all of it into free ChatGPT on their own phone to help write a polite reply. The reply may be good. But the customer’s details are now on another company’s computers, and the owner has no idea it happened.
What the surveys found
Every survey below was run or paid for by a company that sells a fix for the problem it found. UtilForge makes tools too. That is why each row says who paid, so you can weigh the figures yourself.
| Survey | Who they asked | What it found |
|---|---|---|
| Okta, published May 2026. Okta sells tools that control access to company systems. The research firm Apprize360 ran it. | 292 bosses and 492 office workers in the US, UK, Australia, Canada, Japan, France and Germany, March 2026 | 52% of workers had used AI tools their employer never approved, and 24% did so regularly. 90% of bosses were confident they could see which tools were in use. |
| KPMG and the University of Melbourne, 2025. KPMG sells advice on AI. | More than 48,000 people in 47 countries, including South Africa, Nigeria and Egypt, November 2024 to January 2025 | Almost half of workers admitted using AI against their employer’s rules, including putting financial, sales and customer information into free public AI tools. 57% hide their AI use. |
| CybSafe and the National Cybersecurity Alliance, September 2024. CybSafe sells staff security training. | More than 7,000 people in the US, UK, Canada, Germany, Australia, India and New Zealand | 38% of workers who use AI had shared sensitive work information with it without their employer knowing. 52% of working people had received no training on using AI safely. |
| LayerX, October 2025. LayerX sells browser security. | Browser activity inside companies that use its product | 71.6% of AI use happened through personal accounts, not company ones. Copying and pasting was the main way information left. |
| Harmonic Security, January 2026. Harmonic sells AI data protection. | 22.4 million prompts sent to AI tools by staff in companies using its product, during 2025 | It found 579,113 cases of sensitive information. Legal documents made up 35%, computer code 26.5% and financial information 16.6%. 16.9% went through personal, free accounts. |
| Microsoft and LinkedIn, May 2024. Microsoft sells AI tools for work. | 31,000 people in 31 countries | 78% of people who use AI at work bring their own AI tools. |
What this means for a small business
Telling staff not to use AI does not work: most of them already do, and many do it where nobody can see. The useful question is not whether staff use AI. It is what they paste into it.
Data protection laws in many countries, such as POPIA in South Africa, make the business responsible for what happens to its customers’ information, including information a member of staff pasted somewhere on their own phone. None of the tools below makes a business compliant with any law. They make one specific thing safer.
Four things to do this week
1. Assume it is already happening. Ask your staff, without blame, which AI tools they use and what for. You will learn more in ten minutes than any policy tells you.
2. Give them a safe way to do it. Swap and Return swaps the names and numbers in a message for labels before it goes to the AI, then puts them back into the reply. It is free and runs on the phone itself.
3. Put the rule where they work. Print the free staff card and put it up beside the till or the phone.
4. Check documents before they are shared. A document can carry more than it shows. Did the black boxes work? tells you what is still hidden inside one, and the ChatGPT check shows what is in anything you are about to paste.
Sources
- The Register on the Okta survey, 27 May 2026
- Cybersecurity Dive on the Okta survey, 28 May 2026
- KPMG and the University of Melbourne: Trust, attitudes and use of AI, 2025
- CybSafe: almost 40% of workers share sensitive information with AI tools, September 2024
- eSecurity Planet on the LayerX report, October 2025
- Harmonic Security: what 22 million enterprise AI prompts reveal, January 2026
- Microsoft and LinkedIn: 2024 Work Trend Index
Free
Swap the details.
Keep the customer.
Swap and Return runs on your own phone or computer. Nothing you paste into it goes anywhere.