The81%
How AI Use Is Escaping Enterprise Control
Nearly 1.7 million
AI interactions across 40 organisations · Q2 to Q3 2026
An analysis of how AI is really used at work: which tools people reach for, which accounts those tools run through, and the categories of information they receive.
Built on anonymised, aggregated data from the CultureAI platform.
Join the waitlist
Headline figures
What the data showed
81%
of all interactions originated from non-enterprise and personal accounts
93%
of analysed prompt activity was concentrated in five applications
113
AI applications explored by employees in the average organisation
1 in 7
prompts carried a sensitive data disclosure
Methodology
Drawn from anonymised, aggregated data across 40 organisations over six months spanning Q2 and Q3 2026.
1,668,999
prompts
161,599
file uploads
1,064
AI applications
40
organisations
252,480
sensitive data detections
Q2 to Q3 2026
time period
What we looked at
Most research into AI usage asks people what they do. This study measures what was actually done.
Nearly 1.7 million interactions.
Measured activity across 40 organisations, not a survey of opinions.
Every tool, not just the obvious ones.
Approved platforms, AI embedded in everyday SaaS, and the long tail that rarely reaches an inventory.
The interaction itself.
Exposure depends on what is typed, pasted and uploaded, not on the name of the tool.
Three things the data makes clear
Three of the findings the report sets out in full, with the underlying data.
01
Sprawl and exposure are different problems.
1,064 AI applications were in use, around 113 in the average organisation. Only five of them carried 93% of all prompt activity, so the long tail and the real exposure are not the same thing and do not respond to the same fix.
02
Enterprise accounts are the exception.
Fewer than one in five interactions ran through an enterprise account. Most AI policies and controls therefore apply to a small minority of the activity they were written for.
03
The quiet categories dominate.
Credentials, the exposure most people think of first, accounted for under 1% of detections. The rest sat in strategic, financial, HR, health and legal information, which pattern-based tooling is far less able to recognise.
payments webhook is returning 401, fix using API key EXAMPLE_KEY_0000_NOT_A_REAL_SECRET
summarise the attached grievance file for the ops team lead
from the Q3 board pack, summarise our revenue figure total of £4.2m
find information on client Helen Thomas, address: 63 Chalfont St, London, W2 6CV
AI adoption is already established and widespread. Enterprise control is not.
Research written byOliver SimonnetLead Cybersecurity Researcher at CultureAIWho it is for
Security, IT and privacy leaders who have stopped arguing about whether to allow AI and started working out how to allow it safely.
If you are being asked for AI assurance by a board, an auditor or a regulator, this is your evidence base.
Be first to read it
Join the waitlist and it reaches you first.
Join the waitlist