September 3, 2026 · AI

What an AI Acceptable-Use Policy Should Actually Say

A rule that everyone ignores is not a policy, it is a liability with a letterhead, and most AI policies fail for the same reason: they are written to say no.

Forty-nine percent of employers now have a written policy governing how employees use AI at work, according to SHRM's State of AI in HR 2026 report, a survey of nearly 1,900 HR professionals. Of the companies with a policy, only about a quarter believe it will still hold up a year from now. The rest already know it is going to need a rewrite.

Meanwhile, 78 percent of employees say they use AI tools their employer never approved, and 51 percent say they get conflicting guidance about when they are even allowed to use AI at all, per a survey of 1,000 working adults that WalkMe commissioned from Propeller Insights. Only 7.5 percent of workers report getting real training on how to use AI at work. Nearly a quarter got none.

Put those two numbers together and the picture is plain. Companies are writing policies, and employees are ignoring them. That is not a compliance problem. It is a design problem: most AI policies are written as a list of things employees cannot do, and a rule that stands between an employee and a tool they already find useful gets worked around, not obeyed.

Here is the steelman for the opposite approach, because it deserves one. IBM's 2026 Cost of a Data Breach report, a study of 602 breached organizations across 17 industries, found that the share of breaches involving unsanctioned "shadow AI" more than doubled year over year, from 20 percent to 43 percent, and that average breach costs rose 12 percent to $5 million. More than two-thirds of the breached companies had no process in place to even see what AI tools their people were using. A security lead reading those numbers has a fair case for locking things down hard: block the consumer AI apps at the firewall, ban personal accounts, make the policy strict and mean it.

I think that reading gets the diagnosis backwards. The IBM number that matters is not the 43 percent, it is the two-thirds with no visibility. Those breaches were not caused by employees having too much freedom to use AI. They were caused by employees using it anyway, with nobody watching, because the policy told them to hide it instead of asking them to be careful with it. The WalkMe number confirms this is already happening under existing rules: most employees are using unapproved tools right now, today, under whatever ban their employer already has on the books. A stricter version of a policy that 78 percent of people already ignore is not going to be the exception. Prohibition does not remove the demand. It removes your ability to see where it goes.

Cyberhaven's 2026 AI Adoption and Risk Report found that 39.7 percent of AI interactions its customers monitor involve sensitive company data, from source code to financial figures. Cyberhaven sells data-loss-prevention software, so it has an obvious interest in that number being alarming, and I would not treat it as a neutral estimate. But directionally it lines up with IBM's finding that shadow-AI breaches exposed personal data at a high rate. The traffic is happening either way. The only real choice a company has is whether it happens through a sanctioned account it can audit, or a personal one it cannot.

So write the policy to be followed, not to look thorough in a drawer. Name the specific tools you approve, by name, not "AI" as a category. Spell out what data classes can never be pasted in: client and customer PII, unreleased financials, source code under an NDA, anything a regulator would ask about later. Require a human to check AI output before it ships, and say plainly that the employee owns that output regardless of what wrote the draft. Build a reporting path for AI incidents that does not punish the person who reports one, since a policy people are afraid to admit breaking teaches them to hide the next mistake too. And actually train people, since the 7.5 percent figure suggests almost nobody has.

None of this requires new tools or a big budget. It requires someone willing to sit down, look at what your people are actually already doing, and write the policy around that reality instead of around what you wish were true. That is most of what an AI readiness engagement is, in practice: figuring out where the AI use already is before you try to govern it. If you want a second set of eyes on yours, that conversation starts at mojoaiservices.com/ai, or just reach out.

Sources

Every factual claim above is drawn from these independently published sources, linked inline where first referenced.

Let's talk

Tell us what's on your mind.

You don't need a polished brief to reach out. A two-line email about what's bugging you is plenty; we'll tell you straight if we're the right fit, and what we'd tackle first.

We'll scope the work around your workflow, goals, and timeline before quoting anything, so you know what's included before committing.

LocationBoca Raton, Florida
CoverageSouth Florida + remote nationwide
Status Now accepting clients