Deloitte surveyed 25,000 workers through Ipsos and found that two-thirds had tried tools including ChatGPT, Claude, Google Gemini and Microsoft Copilot. Nearly one in four respondents said they used generative AI daily at work, while 31% said they used it without their employer’s knowledge. Deloitte calls that shadow AI; in practical IT terms, it is employee-led software adoption using accounts, terms of service and data controls that the employer may neither select nor be able to audit.
The £1 billion headline deserves one important qualification. Deloitte and Reuters have not published the calculation behind the annual total: the survey material available so far does not state respondents’ average subscription spend, whether usage is weighted to the whole workforce, or how personal subscriptions shared between home and work were counted. The broad direction is clear even if the estimate moves with those assumptions: workers are treating AI subscriptions as a routine work expense because approved alternatives, access or training have not kept pace.
For Windows and Microsoft 365 administrators, the result is less a referendum on whether employees value Copilot than an indication that a licence assignment is only one part of an AI rollout. Workers will seek the model, plan or interface that helps them finish a task now. If the sanctioned option is absent, slow to approve, poorly explained or deliberately restricted, an individual £20-per-month subscription is a much easier decision than waiting for a procurement cycle.
The usage is real, but much of it remains basic
Deloitte’s respondents said their most common workplace uses were searching for information, drafting emails and producing summaries. The survey estimates an average saving of 70 minutes a week. Those are tasks where a general-purpose consumer chatbot can appear immediately useful, and where a staff member can begin working without an API key, corporate tenant, training session or manager approval.
That also puts the reported productivity figure in perspective. It is self-reported time saved, not a measured increase in business output or a validation that generated material was accurate enough to use. A worker may spend less time making a first draft while spending more time fact-checking it, reconciling it with a client document or correcting an invented source. Deloitte partner Paul Lee’s conclusion that much deployment remains centred on search and drafting rather than complex work is therefore more informative than the headline time-saving estimate.
The survey nevertheless shows a sharp shift from Deloitte’s own 2024 UK research, which estimated that more than four million people had used generative AI for work. In 2026, personal use of AI applications is commonplace enough that a company policy saying “do not use unapproved tools” is unlikely to describe actual behaviour by itself. It may instead describe an unmeasured exception process happening across personal logins and browser tabs.
For software developers, that gap is especially consequential. A paid personal plan may offer coding assistance, document upload, larger context windows, connectors or faster access to new models than the organisation’s approved stack. The temptation is obvious when a developer is trying to interpret a log, refactor a module or write a test suite. So is the risk if source code, production errors, customer configuration, security findings or credentials move into an account that corporate identity, retention and incident-response teams cannot govern.
Personal subscriptions sever the audit trail
The principal issue with shadow AI is not that all outside AI services are inherently unsafe. It is that the employer has little assurance about what data was submitted, what contractual terms applied at the time, where conversation records reside, or whether an employee used the same account for personal and work activity.
Government guidance for UK civil servants makes the basic rule plain: users should never put sensitive information or personal data into web-based generative-AI tools, because the government has no oversight over what happens to data once it has been entered. Private-sector organisations face the same practical question, even when the legal and contractual details differ: is the input necessary, is the recipient approved, and can the organisation explain the resulting processing?
UK data-protection law has not been displaced by AI adoption. The Data (Use and Access) Act 2025 amended parts of the UK framework but did not replace the UK GDPR or the Data Protection Act 2018. That matters for HR records, customer data, health information, financial material and other sensitive inputs. It also matters for a much more mundane reason: once a user pastes a sales proposal, internal roadmap or software defect report into a personal account, the organisation may be unable to retrieve, preserve, delete or search that interaction when a legal hold, data-subject request or breach investigation arrives.
This is where the distinction between consumer Microsoft Copilot use and an organisation’s managed Microsoft Copilot deployment becomes operationally significant. Microsoft says its commercial Copilot and Copilot Chat offerings with enterprise data protection are covered by the Microsoft Products and Services Data Protection Addendum and Product Terms. Within that environment, Microsoft says prompts and responses receive contractual protections comparable to those for commercial Microsoft 365 data, while existing identity, sensitivity-label, retention, audit and administrative controls apply.
That is not an argument that every company must buy Microsoft Copilot licences. It is a reminder that “Microsoft Copilot” is not a single uniform security posture. An employee using a consumer account, a personal paid plan, a web chatbot from another vendor or a tool incorporated through an unapproved browser extension may be operating outside the controls an administrator expects. The service name is not enough; tenant, account type, licence, data-protection terms and configuration determine what IT can actually manage.
Blocking everything will drive the problem underground
The easy response to Deloitte’s figures would be to block the main AI sites. That may be necessary for some high-risk roles, regulated workloads or unmanaged environments. It is not a complete strategy when employees can use personal phones, home devices, copied text and personal accounts—especially if they believe AI saves them more than an hour a week.
Microsoft’s current administration guidance reflects the more realistic approach. Microsoft Purview and Defender for Cloud Apps can help organisations discover, monitor and in some cases block generative-AI services. Purview can apply data-loss-prevention policies to AI interactions in Microsoft Edge, create audit events for AI activity and capture supported AI prompts and responses for retention and eDiscovery purposes. Microsoft also supports policies for other AI applications, including ChatGPT, Google Gemini and consumer Microsoft Copilot, rather than assuming users will stay inside one approved product.
Those controls have boundaries. Browser-based DLP is not a substitute for defining approved use cases, making corporate access available and teaching workers what should never be pasted into a prompt. It also creates an employment-data issue of its own: UK government guidance says employers must be able to justify staff monitoring and tell employees what monitoring occurs and why. Deploying discovery tools silently as a punitive trap may create a second governance failure while trying to address the first.
The better response is to treat this as unmanaged demand, not simply misconduct. IT and security teams should find out which capabilities staff are buying personally and for what work. If workers are paying for transcription, document comparison, code assistance or research features, the organisation has evidence of a missing service requirement. Some requests will still need to be denied; others can be met with a managed option, approved data boundary and a clear escalation route.
The procurement signal employers should not ignore
Deloitte’s headline number is a private expense, but it represents an implicit transfer of business technology costs onto staff. Employers benefit from faster drafts, quicker summaries and more rapid research while workers take the subscription cost, account-management burden and, potentially, policy risk. The survey does not show whether companies reimburse those payments, whether workers have approval for them, or how the £1 billion is distributed across sectors and job types. Those omissions matter before using the number as an estimate of enterprise AI spending.
It also demonstrates why a polished “AI acceptable use” document is insufficient. A policy that tells staff not to upload confidential data while providing no sanctioned tool, no usable workflow and no explanation of permitted alternatives will compete against immediate results from consumer services. Deloitte’s finding that 31% use AI without employer knowledge indicates that the policy-versus-practice gap has already become large enough to measure.
The immediate task for Microsoft 365 and Windows administrators is to inventory AI access before buying more licences or writing more rules: identify approved models and account types; classify the data that cannot leave controlled services; turn on logging and appropriate DLP for the channels already in use; and give staff a short, concrete route to request a missing capability. Deloitte’s survey suggests that British workers have already made their choice to use AI. The remaining decision for employers is whether that work happens inside an accountable environment or on employees’ personal bills and personal accounts.