Your Employees Are Already Using AI. Does Legal Know What Data They’re Giving It?
The biggest AI-related legal exposure inside a company may not come from the system that went through six months of procurement, security review and contract negotiation.
It may come from an employee opening a browser.
Employees are already using AI to summarize documents, analyze spreadsheets, rewrite emails, review contracts, generate code, research competitors and prepare presentations.
Most of this is ordinary productivity work. Much of it is useful.
The problem starts when company information goes with it.
Research from Open Future Forum suggests this is becoming harder for companies to ignore. In its September 2026 research, 25% of senior security leaders identified shadow AI as a concern. The percentage concerned about data leakage into AI models rose from 20% to 38% during August.
For General Counsel, the important question isn’t whether employees use AI.
They already do.
The question is what information they are giving it.
Shadow AI Is Really a Data Problem
Shadow AI is usually defined as the use of AI systems that have not been formally approved by an organization.
That can mean a consumer chatbot, but the category is becoming much broader.
Browser extensions have AI features. Meeting applications record and summarize conversations. Coding tools process source code. Research products ingest documents. Existing enterprise applications are adding AI capabilities that employees may start using without thinking of them as separate AI products.
Trying to maintain a list of every possible AI tool will become increasingly difficult.
A more durable approach is to start with the data.
Companies should know which categories of information employees can use with approved AI systems and which should never be entered into an unapproved system.
Depending on the business, restricted information might include customer data, employee records, source code, financial information, trade secrets, board materials, M&A documents, privileged communications and unreleased product information.
There is another category that can be overlooked: other people’s confidential information.
Companies routinely receive sensitive information from customers, suppliers, investors, partners and acquisition targets.
An employee uploading that material into an unapproved AI system can potentially create a contractual problem even if the company’s own information is not involved.
Security Leaders Are Already Seeing the Problem
The concern is not theoretical.
Open Future Forum’s CISO research has consistently shown security executives wrestling with the gap between the speed of AI adoption and the controls around it.
Caroline Wong, a cybersecurity executive who has participated in Open Future Forum’s CISO programming, has emphasized the importance of understanding AI risk in the context of the systems, data and people around it.
That distinction matters.
A company can spend months assessing the security architecture of an approved enterprise AI product while employees independently send sensitive information to completely different systems.
The security of the approved product does not solve the second problem.
This is one reason shadow AI increasingly belongs in conversations between the CISO and General Counsel rather than being treated solely as an IT-policy violation.
A One-Line AI Policy Isn’t Enough
Many companies initially responded to generative AI with a straightforward rule:
Don’t put confidential information into public AI tools.
As an emergency measure, that made sense.
As a permanent operating policy, it leaves too much interpretation to the employee.
Consider the difference between these situations:
A salesperson asks an AI system to summarize a company’s publicly available annual report.
An engineer submits proprietary source code for debugging.
A marketer uses AI to brainstorm headlines.
A finance employee uploads an internal forecast.
A lawyer submits correspondence relating to a potential dispute.
All involve AI. They do not involve remotely equivalent risks.
A useful policy needs to help employees distinguish between them without asking the legal department for permission every time they open an AI application.
Privilege Deserves Particular Attention
Legal departments have an additional problem because they routinely handle some of the most sensitive information in a company.
They investigate disputes, advise executives, review transactions and work with material that the company expects to remain confidential.
AI can clearly help with that work.
But before privileged or highly sensitive material is submitted to an external AI system, legal teams should understand how that information is processed.
Is it retained?
Can humans at the provider access it?
Can it be used to improve the service?
Does information pass to another model provider?
What contractual protections apply?
How is it deleted?
Calling a product “enterprise AI” does not answer those questions.
The terms and technical architecture do.
M&A Is an Obvious Stress Test
Deal work shows why this matters.
M&A processes can involve financial information, customer data, intellectual property, employee information, board discussions, commercial negotiations and information belonging to the acquisition target.
AI can make diligence substantially more efficient. It can summarize documents, identify clauses, compare contracts and help teams process large amounts of information.
That usefulness is exactly why employees will want to use it.
But a deal team uploading acquisition material into an AI system the company has never assessed is not merely experimenting with productivity software.
It may be moving some of the most sensitive information available to the company into an environment nobody has reviewed.
AI diligence therefore increasingly applies to the buyer’s own processes, not only to the target’s technology.
The Same Question Applies to Outside Counsel and Advisers
The information does not stop at the company’s boundary.
Businesses routinely share sensitive material with outside counsel, accountants, consultants, investment bankers, insurers and other advisers.
Those firms are adopting AI as well.
That does not mean companies should prohibit their advisers from using it. Responsible AI use could make professional work faster and, in some cases, better.
But for particularly sensitive information, companies should understand the controls.
Which systems are being used?
What information is submitted?
Under what contractual terms?
Can the data be retained or reused?
Which third parties process it?
These are increasingly reasonable vendor-management questions.
The company can have excellent internal AI controls and still lose visibility when the same information leaves for an adviser.
General Counsel and CISO Need to Compare Notes
Shadow AI exposes an organizational problem.
Legal may know which information is subject to confidentiality, privacy or contractual restrictions.
Security may know which AI applications employees are actually accessing.
Those are two halves of the same picture.
This is where Open Future Forum’s cross-functional research becomes useful.
Its General Counsel AI Report interprets enterprise AI adoption through issues such as accountability, contracts and governance. Its CISO AI Leverage research looks at the same environment through access, security, shadow AI and data leakage.
Neither legal nor security can solve the resulting problem independently.
Legal cannot govern a system it doesn’t know employees are using.
Security cannot determine the legal significance of every category of information moving through it.
They need a shared map.
What the Executive Data Adds
The broader executive perspective matters because shadow AI rarely stays inside one department.
Wickey Wang, CFO of Owlet, has previously highlighted the value of practical executive data rather than relying only on broad AI narratives.
That distinction is useful here.
At the aggregate level, the story is that enterprise AI adoption is accelerating.
Inside an individual company, the situation can be much messier. Employees can adopt tools faster than procurement, security and legal processes can assess them.
Marketing may start using a new research tool.
Finance may experiment with analysis.
Engineers may adopt a coding assistant.
Employees may connect meeting assistants to conversations containing sensitive information.
Each decision may appear relatively small.
Together they can create a data-governance problem that nobody explicitly decided to create.
Discovery May Be More Useful Than Another Policy
Companies can write excellent AI policies and still have a shadow-AI problem.
A policy describes what employees are supposed to do.
Discovery tells management what they are actually doing.
That distinction matters.
If management believes employees are using three approved AI systems while employees are actually accessing thirty, the policy is describing a company that does not exist.
Companies need enough visibility to identify material AI use, establish approved systems and investigate applications that present higher risks.
That doesn’t require monitoring every employee prompt.
It means treating AI applications as enterprise technology rather than assuming a policy alone creates control.
Give Employees a Safe Yes
There is also a practical reason prohibition tends to fail.
People use AI because it saves them time.
If the approved alternative is dramatically slower or less capable than a product an employee can access in seconds, some people will find a way around the process.
A workable policy therefore needs an approved path, not just restrictions.
Employees should be able to answer four basic questions:
Which AI tools can I use?
What information can I use with them?
What information must stay out?
Who can approve something new?
A clear “yes” for ordinary, low-risk AI use makes the important “no” easier to understand and enforce.
Five Questions for General Counsel
For legal teams trying to understand their exposure, I would start here:
Do we know which AI tools employees are actually using?
Have we defined the information that cannot be submitted to unapproved systems?
Do our approved AI vendors provide contractual protections appropriate for the information employees give them?
Can security identify material unauthorized AI use?
Have we given employees a practical approved alternative?
If several answers are no, writing another policy probably isn’t the immediate priority.
Understanding actual behavior is.
AI Policy Is Becoming Data Governance
The longer-term issue is bigger than ChatGPT or any individual AI product.
Companies have spent years deciding which employees and applications can access sensitive information.
AI introduces another category of access:
Which external intelligence systems can see that information, and what are they allowed to do with it?
That question will become harder to answer as AI disappears into ordinary software.
Employees will not always consciously decide to “use AI.” AI capabilities will increasingly sit inside browsers, productivity tools, development environments and enterprise applications they already use.
That makes the underlying principle more useful than maintaining an endless blacklist of products:
Know what information matters.
Know which systems can access it.
Know what those systems can do with it.
And give employees a practical way to use AI without guessing where the boundary is.
For General Counsel, that is increasingly part of protecting the company’s information.
About the Research
This article draws on the Open Future Forum General Counsel AI Report, September 2026 and CISO AI Leverage Report, September 2026.
The General Counsel AI Report is a synthesis report for General Counsel, Deputy General Counsel and legal operations leaders. It interprets Open Future Forum’s underlying enterprise AI research through the legal seat and does not claim a separate General Counsel survey sample.
Open Future Forum’s September research reports that 25% of senior security leaders identified shadow AI as a concern and that concern about data leakage into AI models rose from 20% to 38% during August.
This article is general business commentary and does not constitute legal advice.
