What should we do if staff are getting good results from an AI tool that has not been approved?

10 October 2026

What should we do if staff are getting good results from an AI tool that has not been approved?

Treat this as a useful discovery and a governance gap, not automatically as misconduct. Within one working day, ask the employee to stop entering personal, confidential or commercially sensitive information, document what the tool does, and identify what data, accounts and integrations it has touched. Then complete a proportionate review covering value, data protection, security, ownership, cost and exit options before making a written decision.

Start with containment, not punishment

Your first response sets the tone. If you accuse the employee of recklessness before you know what happened, other staff will learn to hide their AI use. If you praise the result and ignore the approval gap, they will learn that useful output excuses uncontrolled access to company information. The practical middle ground is to contain the risk while preserving the evidence of value.

Ask the employee to demonstrate the workflow using invented or anonymised information. Record the tool name, plan type, account owner, login method, browser extensions, connected services and the exact task it performs. Ask what was uploaded or pasted, whether conversation history is retained, whether outputs were sent to customers, and whether the tool can read email, files, a CRM or another business system. Do this as a fact-finding conversation, not an interrogation.

Put an immediate temporary boundary around the use. No client files, personal data, financial records, passwords, confidential contracts, source code, health information or live credentials should enter the tool until it has been reviewed. Disconnect unnecessary integrations and revoke exposed credentials rather than merely changing a prompt. Preserve relevant screenshots, dates and account details if an incident may have occurred.

This caution is proportionate. The UK Government's Cyber Security Breaches Survey 2025 found that 43% of businesses identified a cyber breach or attack in the previous 12 months, rising to 67% of medium businesses and 74% of large businesses. The objective is not to suggest the AI tool caused a breach. It is to avoid adding an unrecorded supplier and an unknown data path to an already real business risk.

Work out whether the results are genuinely valuable

A polished demonstration is not the same as a dependable business process. Define the job the employee was trying to complete, the previous method and the result that improved. Measure at least ten representative examples if the task is frequent enough. Record minutes saved, corrections required, missed information, customer impact and how often a human must intervene. Include difficult and unusual cases, not only the examples that worked.

Put a value on the improvement. If a £25-per-hour team member saves 20 minutes on a task completed 40 times each month, the gross time value is about £333 per month. Subtract the subscription, review time, rework, integration maintenance and training. If the tool saves £333 but creates £250 of checking and correction work, the case is much weaker than the headline time saving suggests. If it releases scarce staff capacity during a busy period, the operational value may still be worthwhile.

Check output quality against a simple acceptance standard. For a document summary, that might mean every material date, amount and obligation is captured with a source reference. For suggested customer replies, it might mean no invented promises, an appropriate tone and mandatory human approval. For data extraction, compare the output with a manually checked answer set and define an acceptable error rate before relying on it.

Unapproved use is common partly because employees are finding real utility. Microsoft's 2024 Work Trend Index reported that 78% of people using AI at work brought their own AI tools, rising to 80% in small and medium-sized organisations. It also found that 52% were reluctant to admit using AI for their most important tasks. Those figures came from a global study, not a UK-only sample, but they show why a blanket ban can push valuable work out of sight. Your review should separate a strong use case from an unsuitable product.

Review the data, account and supplier risks

Now review the product as a supplier. Start with the account. A personal or free account gives the business weak control over ownership, offboarding, audit history and settings. A business plan may offer an administrator, single sign-on, defined retention, contractual commitments and controls over whether submitted data is used to improve models. Do not assume a paid plan is safe. Read the current terms, privacy notice, security documentation and data processing agreement.

Map the data flow in plain English: what goes in, where it is stored, who can access it, what comes out and which other systems receive the output. Confirm the supplier's retention period, deletion process, subprocessors, hosting locations, international transfer safeguards, training settings and response to account closure. For integrations, list the permissions requested. A writing assistant that asks to read an entire inbox, modify files and access contacts deserves a different decision from a standalone tool receiving redacted text.

The ICO's data protection principles require lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability. In practice, an employee getting good results does not create a lawful basis for processing personal data, and convenience does not satisfy data minimisation. You need to be able to explain and demonstrate the decision.

The NCSC's identity and access management guidance says policies should cover who has access, to which systems and data, why and under what circumstances. It also says policies should cover online services created with work email addresses and should support access removal when someone leaves. That makes company-controlled accounts, least privilege, multi-factor authentication and a named owner practical requirements, not enterprise luxuries.

Choose one of three clear outcomes

At the end of the review, choose approve, replace or stop. Avoid the vague fourth outcome where everyone agrees to be careful and the tool continues without an owner. Approval should be conditional and recorded. State the permitted task, authorised users, acceptable data, banned data, required review, account type, budget owner, renewal date and review date. Add the tool to a simple AI register and provide a short written workflow.

Replace the tool when the use case is sound but the product is not. For example, an employee may have proved that summarising long client documents saves two hours each week, while using a free personal account that offers inadequate control. Move the workflow to an approved business workspace, a feature already included in Microsoft 365 or Google Workspace, or a managed tool with suitable contractual and administrative controls. Re-test the workflow because outputs can differ between products.

Stop the tool when the benefit is trivial, risks cannot be controlled, the supplier will not answer basic questions, permissions are excessive, or the task should not be delegated to AI. Final disciplinary decisions, legal conclusions, payment approvals and safety-critical instructions should not become automated merely because a demonstration looked impressive. The NCSC warns that generative AI can hallucinate, reflect bias, respond to prompt injection and reveal confidential information in poorly controlled systems.

The UK's AI Cyber Security Code of Practice sets baseline principles for organisations developing and deploying AI. Its practical message is that security belongs throughout the AI lifecycle. For a small business, that means somebody owns the decision before launch, monitors the workflow during use and can disable it without losing the underlying business process.

Handle the employee fairly and fix the process that failed

The employee may have broken a clear rule, or they may have filled a gap the business left open. Those are not the same situation. Check whether the business had an accessible AI policy, named approved tools, a quick request route and role-specific training. If the only instruction was 'do not use AI' while managers praised faster output, the organisation helped create the ambiguity.

Recognise the useful discovery without rewarding concealment. A fair conversation sounds like this: the workflow appears valuable, using an unapproved supplier created risks, and both facts matter. Explain the temporary controls and the date by which a decision will be made. Give the employee a role in documenting and testing the workflow, but keep the approval decision with the relevant manager, data protection contact and technical adviser.

Create a lightweight request process that staff can actually use. Ask for the business problem, expected saving, example inputs, data involved, requested integrations, proposed users and monthly price. A low-risk writing tool using public information might receive an initial decision within two working days. A tool connecting to customer records, email or accounts software needs a deeper review. Publish the service level so staff do not bypass approval because the official route feels endless.

Finally, update the AI policy with the lesson. List approved tools and accounts, banned data, tasks requiring human review, who can approve integrations and how to report mistakes without fear. The NCSC says AI security depends as much on organisational culture, process and communication as technical measures. A culture that surfaces experiments early is safer than one that discovers them months later through an invoice, customer complaint or data incident.

When this does not apply

This measured review is not appropriate when there is an immediate and serious risk. Stop access first if the tool has received passwords, API keys, banking details, special category personal data, highly confidential client material or information covered by a strict contractual restriction. Revoke tokens and integrations, preserve evidence, contact the supplier where necessary and activate your incident response process. Do not wait for a scheduled governance meeting.

It also does not apply when the employee used the tool to impersonate someone, evade a deliberate control, make a decision they were not authorised to make, or conceal harmful conduct. Those circumstances may require HR, legal, regulatory or law enforcement advice. Keep the facts separate from the wider debate about whether AI is useful.

At the other end of the scale, do not turn every harmless experiment into a six-week procurement exercise. Asking a public chatbot to improve the wording of a generic meeting agenda with no business-sensitive information is not equivalent to connecting an autonomous assistant to the CRM. Use tiers. A simple red, amber and green classification based on data sensitivity, system access, customer impact and reversibility is usually enough for a small business.

The test is proportionate control. The higher the consequence of an error or disclosure, the stronger the evidence, approval and human review you need. If you want to map your current AI use and turn useful experiments into controlled workflows, start with a short inventory and risk review. If you would value an independent view, book a conversation with Precise Impact AI. There is no pitch or pressure, just a practical discussion about what to approve, replace or stop.

Is This Right For You?

This approach is right for a UK small business that has discovered useful but unapproved AI use and wants to keep the benefit without accepting unmanaged risk. It works particularly well when the workflow is repeatable, saves measurable time and can be tested with non-sensitive or anonymised data while the review takes place.

It is not a reason to keep the tool running unchanged. If passwords, payment data, special category personal data, confidential client files, legal advice or live system credentials may have been shared, stop that use immediately and follow your incident process. If personal data may have been exposed, involve whoever is responsible for data protection and assess whether the incident must be reported. This article is practical guidance, not legal advice.

Frequently Asked Questions

Should we discipline an employee for using an unapproved AI tool?

Not automatically. Establish what policy existed, what the employee knew, what data was used, whether they concealed the activity and whether harm occurred. Apply your normal HR process consistently and seek professional advice for serious cases.

Do we need to report unapproved AI use to the ICO?

Unapproved use alone is not automatically reportable. Assess whether personal data was breached and whether that breach is likely to risk people's rights and freedoms. Record the assessment and seek data protection advice if the facts are unclear.

Can we approve the tool temporarily while reviewing it?

Yes, for a tightly limited pilot using public, synthetic or properly anonymised data. Set named users, a fixed end date, no live integrations and mandatory human review. Do not call it temporary approval if sensitive live use continues unchanged.

Is a paid business account always safer than a free AI account?

No. Business plans often provide better administration, retention and training controls, but you still need to verify the terms, security, permissions, data locations, subprocessors and deletion process for that specific product.

How quickly should a small business review an AI tool request?

Aim to triage it within one working day. A low-risk tool using non-sensitive information may be decided within two working days. Tools touching personal data, customer communications or business systems need a fuller review.

What should go in a simple AI tool register?

Record the tool, owner, business purpose, users, account type, data used, integrations, permissions, supplier terms, cost, approval status, required human checks, incidents and next review date.

What if the unapproved tool is better than our approved one?

Test both against the same real tasks and acceptance criteria. If the unapproved tool delivers materially better value and can meet your security, data protection and ownership requirements, approve it properly or change supplier.