Judging AI governance

Should a company ban AI at work?

Short answerNo. A ban does not stop AI. It hides it. Give people an approved way to use AI, set clear rules for customer data, apply those rules before a request leaves, and keep a record of what happened.

A ban is a policy instruction. It says what employees may do, but it does not show which tools they use or what they send. When use continues outside the approved path, the company loses the chance to apply its rules and keep a record. That hidden use is shadow AI.

The practical problemA ban does not stop AI. It hides it.

What the published survey found

PagerDuty published its Shadow AI Survey on June 11, 2026. Among surveyed office professionals who had used AI as part of their work responsibilities, 66% said they had used AI tools or services at work even though they believed company policy did not permit it. Across the survey, 34% said they had entered customer data or information into public AI tools.

The sample matters. Wakefield Research surveyed 1,250 office professionals in non-IT and technology roles at companies with at least $500 million in annual revenue. The respondents were in the United States, United Kingdom, Australia, and Japan. The survey ran from April 9 to April 20, 2026. These figures describe that sample, and the 66% figure applies to respondents who had used AI for work.

Why a ban hides the risk

A written ban depends on every person following it every time. The survey shows that workplace AI use continued among people who believed it was prohibited. Once that use moves outside an approved path, the company cannot rely on the ban to reveal which tool received a prompt or whether customer data went with it.

The gap is the same one behind the question Are your AI controls enforced, or just written down? A policy tells people what should happen. An operating control can check a request before it leaves and produce a record that someone can review.

What to do instead

  • Give employees an approved way to use AI for work.
  • State which customer and company information may be sent, and which information must be removed.
  • Apply the rule at the point where an AI request leaves the device or company environment.
  • Keep a record of the request, the rule applied, and what was sent onward.
  • Test the path with made-up customer data so employees and reviewers can see what the AI receives.

Questions to ask about an AI policy

  • Which AI tools are people already using for work?
  • What happens before customer data reaches those tools?
  • Can the company show where a prompt went?
  • Can a reviewer see which rule was applied and what the AI received?
  • Can an employee follow the approved path without waiting for a sales or IT process?

Sources

  1. PagerDuty, Shadow AI Survey press release, published June 11, 2026. Survey by Wakefield Research among 1,250 office professionals in non-IT and technology roles at companies with at least $500 million in annual revenue, fielded April 9 to April 20, 2026.

Reviewed