It is already happening

People paste customer emails, contracts, and spreadsheets into whatever tool is open, because it saves them an hour. Assuming otherwise is not a policy, and a ban mostly converts visible use into invisible use.

The real exposure is the paste

The risk is not that someone used a model; it is what left the building — customer data, unreleased plans, contract terms. That is the same question as what a system is allowed to see, except nobody scoped it.

A ban doesn’t reduce the pasting. It reduces your knowledge of the pasting.

Provide a sanctioned route

The most effective control is a tool people are allowed to use, with terms you have checked. Usage follows convenience, so an approved option that is as easy as the unapproved one wins on its own — which is what an internal assistant provides.

Write rules about data, not about tools

Tool lists go stale monthly. Categories don’t: never customer personal data, never contract terms, never credentials, never anything under a client confidentiality obligation — the professional-services constraint generalised.

Say who checks the output

Work produced with assistance still needs the same review as any other work, and the person publishing it remains accountable. Making that explicit prevents the “the AI wrote it” defence appearing after a mistake.

Ask what they’re using it for

The tasks staff quietly automate are a free prioritisation exercise — they have already identified the work worth removing, which is the ranking most AI roadmaps are missing.