CultureAI
All blog posts
AI UsagePlatform ReportsResearch

Early Q1 Snapshot: Real-World AI Usage

Ria ManzaneroHead of Marketing
PublishedRead time4 min readShare

In brief

  • More than 1 in 6 risky AI interactions include internal strategy or planning details, a type of exposure that rarely matches traditional high-risk classifications.
  • Personal identifiers appear in over half of sensitive AI interactions, making everyday context, not extreme behaviour, the main driver of risk.
  • Free-tier consumer tools such as Google Gemini are growing fastest, even where approved enterprise AI is already in place.
  • Managing this requires AI security and governance: guardrails applied at the data and interaction level rather than app-level allowlists.

AI is no longer a fringe productivity experiment inside organisations, it is embedded, habitual, and increasingly invisible.

This snapshot from CultureAI’s early Q1 usage data highlights how AI is actually being used across everyday workflows, and where risk is forming as a result. Rather than focusing on hypothetical threats or model-level concerns, the findings below surface behavioural signals from real interactions: prompts, file uploads, and context accumulation.

What emerges is a consistent pattern: AI risk is not driven by exotic misuse or rogue tools, but by ordinary work carried out at scale, faster than traditional governance controls can adapt.

Top 3 Findings From January

  1. More than 1 in 6 risky AI interactions include internal strategy or planning details, exposing commercially sensitive context through routine AI use.
  2. Personal identifiers account for over 50% of sensitive AI interactions, making them the most common trigger for policy risk.
  3. Fastest-growing assistant after ChatGPT: free-tier Google Gemini, highlighting continued AI usage outside enterprise controls even where approved tools exist.

AIUC Interactions Table

Finding #1: Internal Strategy Is a Silent Exposure Vector

More than 1 in 6 risky AI interactions include internal strategy or planning details.

Strategy documents, planning context, and commercially sensitive reasoning are increasingly being introduced into AI interactions to improve output quality, particularly during summarisation, brainstorming, and decision support tasks.

These data types rarely match traditional “high-risk” classifications, yet their exposure carries material competitive and regulatory impact.

This is significant because strategy leakage typically occurs incrementally, across multiple prompts or through document uploads, rather than as a single, obvious violation.

The problem? Legacy tools optimised for static data patterns struggle to detect this form of contextual drift, leaving a blind spot precisely where business risk concentrates.

AIUC Interactions Table_Pop-Out

Finding #2: Identity Data Dominates AI Risk

Personal identifiers account for over 50% of sensitive AI interactions.

Names, email addresses, and other basic identifiers are the most common data elements detected in risky AI interactions, outweighing credentials or source code. This reflects how AI is actually used: employees routinely add just enough personal context to make outputs more relevant, accurate, or actionable.

The implication is clear: AI risk is driven by everyday context, not extreme behaviour.

Identity data acts as the tipping point where otherwise benign usage crosses policy boundaries, often unintentionally.

The problem? Static DLP rules and app-level approvals are poorly suited to this reality, as they lack the ability to understand why data is being shared and how risk accumulates over time.

AIUC Dashboard

Finding #3: Free AI Tools Are Scaling Faster Than Enterprise Controls

The fastest-growing AI usage occurs outside enterprise accounts, even where approved AI tools are already in place.

While enterprise copilots continue to gain traction inside productivity suites, the fastest relative growth is coming from consumer-accessible, free AI tools.

This signals a widening gap between where organisations believe AI is being used and where adoption is actually accelerating.

The problem? The risk here is not the tool itself, but the absence of consistent policy guardrails and visibility guarantees across free and consumer-grade services. By the time these tools appear on approval lists, usage patterns and associated data flows are already well established.

Conclusion

Taken together, these findings reinforce a consistent theme: AI risk forms through behaviour and context, not through tools alone. Sensitive data enters AI systems incrementally via everyday identifiers, internal strategy, and routine task switching between enterprise and consumer tools, often across thousands of applications that change faster than approval lists can keep up.

Addressing this requires a different control model. Effective AI governance depends on understanding what data is being shared, in what context, and under which conditions, rather than relying on app-level allowlists or static classifications. This means applying guardrails at the data-type and interaction level, building context-aware policies that evaluate behaviour over time, and distinguishing between enterprise and consumer AI usage even within the same application. It also requires discovery driven by actual usage patterns, not predefined lists, to keep pace with the long tail of AI-enabled tools embedded across SaaS.

This is the shift toward AI security and governance. It treats AI as a managed workflow rather than a binary access decision, enabling organisations to scale AI adoption while retaining confidence in how data is used.

This is exactly the problem CultureAI is built to solve. Visibility, context-aware policy control, and real-time guidance, applied where AI is actually used.


📖 Join the waitlist

In March 2026, CultureAI releases new research: The State of Enterprise AI Usage: The Illusion of Control.

Based on insights from 300 senior leaders in regulated industries, this report exposes where perceived control breaks down, and where real AI risk actually lives.

Join the waitlist here to read it first

Uncover hidden AI risk

Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.