By Lisa Ventura MBE FCIIS, Chief Executive and Founder of the AI and Cyber Security Association.
Somewhere in your business this week, someone will paste a customer email into a free AI chatbot to help them draft a reply. They will not mention it to you.
They are not being reckless; they are trying to get their work finished before 5.00pm.
The pattern is a familiar one when it comes to cyber security awareness. A useful technology arrives faster than the rules around it. People adopt it because it makes their day easier. The organisation finds out only when something has gone wrong.
The scale of it is now documented. Research published by the Department for Science, Innovation and Technology found that one in three people in work had used AI in their workplace in the past month, while 84% of those in work had not undertaken any AI related training in the previous 12 months. Separate research commissioned by Microsoft and carried out by Censuswide suggested that 71% of UK workers had used or tried unapproved AI tools for work purposes, with 28% saying they turned to consumer tools because their employer provided no approved alternative.
The instinctive response is to ban it, and I would ask you to resist that. A survey of 200 UK desk-based workers carried out by Red Eagle Tech in February 2026 found that 54.5% said their employer had no clear policy on AI, that around a third had used AI tools without their employer’s knowledge, and that this figure changed little in workplaces where outright bans were in place. A ban does not stop the behaviour, it moves it onto personal devices and phones, where you have no visibility at all.
The risk here is not theoretical. Information typed into a public AI tool leaves your control. Guidance from the National Cyber Security Centre sets out that queries submitted to public services are visible to the provider and may be used to develop the service. If that query contained a client’s contract terms, a patient’s details, your own pricing model or any other information that is deemed confidential or sensitive, you have a problem that your insurer and possibly the Information Commissioner’s Office will want to talk to you about.
What works is simpler and cheaper than most people expect. Write down what is allowed, on one page, in plain English. Name the tools you are happy for people to use and pay for the business versions, where the terms are far better at protecting your data than the free ones. Be specific about what must never go into a public tool, using real examples from your own business rather than abstract categories like sensitive information. Then make it safe for someone to come and ask you, because the person who checks first is the person you want.
There is a regional dimension to this too. The West Midlands economy runs on small firms, family businesses and suppliers to much larger companies. A 20-person engineering business supplying a tier one manufacturer will be asked what its AI policy is, sooner rather than later. Having that page already written is a commercial advantage as much as it is a security control.
If you do one thing this week, make it this. Ask your team, with no suggestion whatsoever that they are in trouble, which AI tools they are already using and what they are using them for. The answers will tell you more about your real exposure than any policy written in isolation ever will. Then write the page.
Lisa Ventura MBE FCIIS, Chief Executive and Founder of the AI and Cyber Security Association
Lisa Ventura MBE FCIIS is Chief Executive and Founder of the AI and Cyber Security Association (AICSA), a not-for-profit trade association for the convergence of AI and cyber security. She has worked in cyber security for more than 16 years, was awarded an MBE in 2023 for services to cyber security and to diversity, equity, inclusion and belonging, and is a Fellow of the Chartered Institute of Information Security. She is the author of Artificial Intelligence in Cybersecurity, published by Kogan Page, and lives in Worcester.
Sources referenced
Department for Science, Innovation and Technology, AI Skills for Life and Work: General Public Survey Findings: gov.uk.
Microsoft UK research conducted by Censuswide, reported by Workplace Insight: workplaceinsight.net.
Red Eagle Tech, The UK AI Permission Gap, February 2026: redeagle.tech.
National Cyber Security Centre, AI and cyber security: what you need to know: ncsc.gov.uk.
