CultureAI
New research. Coming October 2026

The AI Interaction Report 2026

1 million +

AI interactions analysed

For eleven months we looked at how people in real organisations use AI at work. Which tools, which accounts, and what they share once they think nobody is watching.

Join the waitlist to get the report when it lands in October.

Join the waitlist

The research

Observed across approximately 45 organisations between October 2025 and August 2026. Not a survey, and not a record of what people say they do.

1,015,462

interactions analysed in total

11 months

of continuous observation

~45

organisations observed

1,065,146

prompts analysed

106,817

file uploads observed

979

AI applications discovered

01

What we looked at

Most research into AI usage asks people what they do. We looked at what they actually did.

1,015,462 interactions.

Eleven months of real workplace AI use, not a survey.

Every tool, not just the obvious ones.

The approved platforms, the AI quietly embedded in SaaS, and the long tail nobody has on a list.

The interaction itself.

The risk sits in what gets typed, pasted and uploaded, not in the name of the tool.

02

Three things we were not expecting

We are not giving the findings away yet. Here is what they are about.

01

Where the usage actually sits.

The AI rollout your organisation approved and the AI your organisation uses are two different things. The distance between them is the finding.

02

What people share without thinking.

Credential leaks get the attention. They are not the thing that will cost you.

03

The question compliance cannot answer.

Ask most organisations a simple question about their AI usage and watch what happens next. We asked it of the data instead.

payments webhook is returning 401, fix using API key EXAMPLE_KEY_0000_NOT_A_REAL_SECRET

summarise the attached grievance file for the ops team lead

from the Q3 board pack, summarise our revenue figure total of £4.2m

find information on client Helen Thomas, address: 63 Chalfont St, London, W2 6CV

AI adoption is already established and broad. Enterprise control is not.
Research written byOliver SimonnetLead Cybersecurity Researcher at CultureAI
03

Who it is for

Security, IT and privacy leaders who have stopped arguing about whether to allow AI and started working out how to allow it safely.

If you are being asked for AI assurance by a board, an auditor or a regulator, this is your evidence base.

Be first to read it

Join the waitlist and it reaches you first.

Join the waitlist