British workers are spending £958 million of their own money per year on AI tools their employers won't buy them.
That's the headline from Deloitte's largest-ever single-country study of workplace AI use — 25,000 UK workers surveyed. But the number that should actually keep enterprise leaders up at night is the one underneath it: 31% of workers using AI at work are doing it without their employer knowing.
Shadow AI is not a future risk. It is a present reality.
The study found that 63% of UK workers have used generative AI, but half have received no training for it, and 65% say their leaders discuss AI without a clear understanding of what it actually does. Workers report saving 70 minutes a week on average — but nearly a quarter still sense a stigma attached to using it at work.
The pattern that emerges: GenAI use is widespread but shallow. People have tried it. Few use it daily. Most stick to familiar tasks like writing emails and searching for information rather than rethinking how work is done.
The implication for enterprise marketing and B2B teams is direct. If your employees are spending their own money on AI tools because your company hasn't provided sanctioned ones, two things are true simultaneously. Your people are motivated enough to self-fund productivity tools. And you have no visibility into what data is going into those tools, what outputs are being used, or what liability you're accumulating.
The technology investment conversation has shifted. The question is no longer whether your team is using AI. It's whether they're using yours.
https://www.deloitte.com/uk/en/issues/generative-ai/genai-workforce-survey.html#AIGovernance#B2BMarketing…more
Hundreds of people are reading ChatGPT conversations (and you probably agreed to it)
After last week's math controversy, this is the second time in a week the question has come up: what actually happens to what you type into a chatbot?
Do you paste your blood test results into ChatGPT to ask what the values mean, or rehearse the conversation with your GP in advance? Then a hired reviewer may read that conversation and give the answer a score. That's according to internal documents and real user conversations obtained by tech site 404 Media. The setting that makes this possible is on by default for every free, Plus and Pro account.
What's going on?
Internally, the program is called Project Lily. OpenAI, the company behind ChatGPT, hires hundreds of people through intermediaries who open a real conversation in a dashboard, summarize in one sentence what the user wanted, and rate four possible ChatGPT answers on a scale of 1 to 7. They watch for flattery, unnecessary emojis and what the instructions call AI talk. The goal is a chatbot that sounds less sycophantic, a problem that has dogged OpenAI for some time.
The reviewers don't see a username. They do sometimes see a summary of the memory: what the user previously used ChatGPT for and, in some cases, roughly where that person lives. A filter is supposed to remove personal data before a conversation reaches a human. OpenAI's own description of that filter says it makes mistakes, especially with short texts. In some of the conversations 404 Media saw, the user explicitly asked ChatGPT to keep the contents to itself.
When asked where OpenAI has told users that people can read their conversations, no answer came. After publication, the company pointed to a help page. The setting "Improve the model for everyone" was updated, with a better explanation of how to turn it off. That humans read along is still not mentioned. …more
Humans are reading your AI chats — not just OpenAI.
Anthropic & Google confirm they review chats too. What's new is the intimacy: people use chatbots as therapist, coach, rehearsal space. "Private" rarely is. Set a policy first.
https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/#AIGovernance#InfoSec
Human reviewers reading your AI chats: it's not just OpenAI
Anthropic, the maker of Claude, confirmed to 404 Media that it also has people read along, but only for users who have turned on the training setting themselves. Google simply puts it in Gemini's fine print: "Humans review some saved chats to improve Google AI."
The practice isn't new. In 2019, it emerged that Apple and Amazon employees were listening to Siri and Alexa recordings, including accidentally recorded conversations in bedrooms. What's new is the intimacy. An AI chatbot feels like a private one-on-one conversation, and people use it as a therapist, as a coach and as a place to practice what they're going to say to their boss.
This summer's pattern
It's the third time in a few months that "private" turns out to mean something different with AI chatbots than users think.
In July, a Reddit user found hundreds of shared Claude conversations in Google, including résumés with names and phone numbers and an unpublished blog post about a company project. Anyone who clicks "share" creates a public web page. That the page can end up in a search engine isn't mentioned. Grok, Elon Musk's chatbot, had the same problem a year earlier with more than 370,000 conversations.
And last week there was the math controversy: OpenAI could "not rule out" that a mathematician's use of its tool, stripped of his name, improved the model that then solved that very same problem.
Nearly half of managers are typing real employee names into public AI chatbots before difficult conversations. Barely any of their companies have a policy for it.
This is the AI governance story that's not getting enough attention.
Korn Ferry research published this week found that middle managers are already using AI to rehearse firing conversations, performance reviews, and pay discussions. The practice is spreading faster than the policy to govern it — and most of these conversations are happening in tools that aren't covered by any enterprise data agreement.
The productivity case is clear. Rehearsing a hard conversation reduces anxiety and often produces a better outcome for everyone in the room.
The governance gap is equally clear. Real employee names, salary figures, and performance details typed into public AI tools are data that don't belong there, full stop. Most enterprise AI policies don't address this use case because they were written before managers started doing it.
For B2B marketing teams, the parallel is direct. If your content team is using public AI tools to draft campaigns with real customer data, competitive intelligence, or unreleased product details, you have the same exposure.
The technology is ahead of the policy everywhere. Close the gap before someone closes it for you.
https://aibusinessweekly.net/p/managers-ai-coaching-difficult-conversations#B2BMarketing#AIGovernance…more
Half of managers type real employee names into public AI before hard conversations.
Barely any companies have a policy for it.
Productivity case: clear.
Data governance gap: clearer.
Close it before someone does it for you.
https://aibusinessweekly.net/p/managers-ai-coaching-difficult-conversations#AIGovernance
"Frontier AI's Disconnect" https://www.axios.com/2026/09/02/openai-anthropic-fable-astra-ipo
1 big thing:
☑ The two biggest AI labs are now playing completely different games — and B2B buyers are caught in the middle
OpenAI and Anthropic are both racing toward IPOs. But their strategies heading into those listings have diverged sharply — and the difference matters to anyone buying or building on their models.
Why it matters: Enterprise AI procurement is no longer just about capability. It is about who you trust with your data, your workflows, and your governance posture as these companies transition from startups to public companies.
Driving the news:
Anthropic launched Fable 5.1 with a commercially friendly tone — 25% cheaper, 60% fewer cybersecurity refusals, 85% fewer medical intervention blocks, and a new zero-data-retention option for enterprise customers.
→ OpenAI launched Astra with a cautious safety posture — limiting its most powerful capabilities to trusted testers and flagging it as its first "critical" cybersecurity threshold model
Zoom in:
OpenAI's head of strategic futures published an essay predicting that future AI agents will seek to become sovereign from human control — paying their own compute bills and answering to humans only partially.
→ Anthropic, meanwhile, paused its highest-risk training environments and invited independent safety evaluators
Yes, but: Both companies need investors and regulators to believe them simultaneously. That tension will only increase as IPO pressure builds.
Be smart: Watch what each company does with enterprise data policies over the next 90 days. That behavior — not the press releases — is what tells you which lab is actually building for your long-term interests.
The bottom line: OpenAI is getting cautious. Anthropic is courting customers. Both are heading to Wall Street. Choose your vendor accordingly.
https://www.axios.com/2026/09/02/openai-anthropic-fable-astra-ipo#AIStrategy#B2BMarketing…more