A Canadian firm writes an AI policy, circulates it, and considers the governance question addressed. The best-controlled finding in this material says the policy is not the variable that determines whether anyone tells the firm what they are actually doing.

Key Takeaway

A 2026 study of 604 employees who use AI daily is reported to have found that 47 percent of workers in the lowest quartile of organisational trust had intentionally hidden AI knowledge from coworkers or employers, against 14 percent in the highest quartile, with the finding holding after controlling for job insecurity, internal competition, age, gender, industry, tenure and whether the organisation had an official AI policy. Separately, a study of 1,107 professionals is reported to have found user proficiency accounting for roughly 38 percent of AI implementation difficulties against about 16 percent for purely technical issues. Surveys report 78 percent or more of employees using unapproved tools, with 36 percent doing so with confidential data. For a professional firm the consequence is not primarily a security matter: concealed use defeats the logging, lineage, review, inventory and insurance disclosure that every preceding article in this series depends on.

The Trust Finding

The single most useful result in this material, and the one worth reporting carefully.

One source reports a 2026 study of 604 United States employees who use AI daily, in which 47 percent of workers in the lowest quartile of organisational trust had intentionally hidden AI knowledge from coworkers or employers, compared to just 14 percent in the highest trust quartile. It states that the finding held even after controlling for job insecurity, internal competition, age, gender, industry, tenure, and whether the organisation had an official AI policy, and concludes that organisational trust is the single strongest predictor of whether employees disclose or conceal their AI use, stronger even than the presence of formal AI policies or approved tool lists[1].

We report this at second hand from a commercial security publication, having not accessed the study itself, and note we cannot verify its methodology or its control specification.

Taken at face value it is nonetheless the strongest evidential claim in this article, for reasons the next section explains.

The headline ratio is that concealment was more than three times as common in the least trusting quartile as in the most trusting. That is a large effect on a behaviour most firms assume is governed by rules.

Why That Result Is Unusual

The methodological point that makes this finding worth acting on, and our own reading of it.

Most survey findings in this area are bivariate: a proportion does something, another proportion reports a belief, and the connection is asserted. This one reports a relationship that survived controls, and the control list includes the alternative explanations a sceptical reader would raise.

Job insecurity is controlled, so this is not simply people fearing redundancy. Internal competition is controlled, so it is not simply people protecting an advantage over colleagues. Tenure and industry are controlled, so it is not a compositional artefact.

And most consequentially for a firm's likely response, the presence of an official AI policy is controlled.

That last inclusion is what makes the result actionable rather than merely interesting. It means the finding is not that policies fail to be followed. It is that whether a policy exists does not account for the variation in disclosure, while trust does.

So a Canadian firm's natural response to discovering concealed AI use, which is to write or tighten a policy, addresses a variable the research suggests is not doing the work. That is an uncomfortable conclusion and it is the article's organising point.

Change Problem, Not Technology Problem

The proportional finding that frames where effort should go.

One source reports a study of 1,107 professionals in which user proficiency, described as the human side of learning, prompting and training, accounted for roughly 38 percent of all reported AI implementation difficulties, while purely technical issues accounted for about 16 percent. Its summary is that the models are capable and the organisations are the bottleneck, and it adds a reported figure that only 13 percent received any employer training[2].

We report these at second hand and did not access the underlying study.

A ratio of more than two to one is the substance. It says the dominant category of implementation difficulty is human proficiency, by a factor of roughly two over technical difficulty.

The two figures do not sum to a hundred, so other categories account for the remainder, and the source does not enumerate them. That is a limitation of the reporting rather than a defect in the point.

For a Canadian firm the budgetary implication is direct and rarely followed. If human proficiency is the dominant difficulty, then a programme whose budget is overwhelmingly technology and integration, with training as a residual line, is allocated inversely to where the difficulty lies. The total cost article in this series found training and change management grouped inside the 60 to 70 percent of spend that vendors do not quote, and this suggests that share is not merely large but concentrated.

How Widespread

The scale, reported with attention to the spread across sources.

One source reports a survey finding that 78 percent of employees admit to using AI tools their employer never approved, with at least 45 percent in the past 30 days[2]. Another states that between 78 and 86 percent of employees now use unapproved tools depending on the study, adding that security professionals are among the highest at nearly 90 percent[3]. A third reports that 25 percent of organisations have no active AI policy at all[4].

The consistency across the range, being roughly four in five, is more informative than any single figure, and the direction is unambiguous: unsanctioned use is the majority condition rather than an exception.

The observation about security professionals being among the highest users deserves a note. Whatever else it indicates, it undermines the assumption that this behaviour reflects ignorance of the risks. The people best positioned to understand the exposure are reported as among the most likely to accept it.

One source frames the motivation bluntly, reporting that a majority of employees say they are willing to accept security risks to meet deadlines, and characterising the behaviour as feeling more like desperation than rebellion[3].

That framing matters for how a firm responds, and it is developed below.

The Number For A Professional Firm

The figure that should concern a Canadian accounting or advisory practice most, and it is not the headline one.

The same survey reporting 78 percent unapproved use reports that 36 percent did so with confidential data[2].

For a general business that is a data protection concern. For a professional firm it is something else, and this is our own analysis.

Confidential data in a professional practice is client information held under professional obligations and, in some engagements, under statutory confidentiality or in circumstances engaging privilege. A law firm publication in this area names data integrity, privilege and compliance as the exposures[5].

The procurement article in this series raised a question on the firm's own side of the arrangement: whether the firm is entitled to disclose client information to a third-party processor, which turns on its engagement terms rather than on the vendor's. Where a partner considers that question before adopting a tool, the answer may be yes.

Where an individual staff member pastes a client document into a consumer service on a personal account, nobody asked the question at all, no agreement governs the processing, no data terms exist, and the firm cannot identify what left.

That is the specific shape of the exposure for this publication's readers, and it is materially worse than the generic one, because the obligation breached is the firm's own rather than a regulatory standard applying to everyone equally.

This Defeats Every Control In This Series

The synthesis that makes this article the necessary companion to the preceding twenty-three, and it is our own.

Consider what the controls recommended across this series require in order to function.

The incident response article required prompt logs, model state, retrieval context and tool call history, none of which exist for a tool the firm does not know about. The lineage article required a correlation identifier carried across systems the firm controls. The oversight article required review designs applied to workflows the firm designed. The professional liability article required an accurate answer to an insurer's question about AI use. The protocol article required knowing which components are connected.

Every one of those presumes visibility.

So concealed use is not one risk sitting alongside the others in a register. It is the precondition failure for the entire governance programme. A firm with excellent controls over its sanctioned workflows and four-fifths of its actual AI activity occurring outside them has controls over a minority of its exposure.

The uncomfortable corollary is about sequencing. This publication has placed change management last, as most treatments do, and on this evidence it belongs closer to first, because it determines whether anything else applies to the work that is actually being done.

The practical version is that a firm's AI governance maturity is bounded by its visibility, and its visibility is bounded, per the trust finding, by something a policy does not reach.

Rational, Not Irrational

The reframing that the sources make and that a Canadian firm should take seriously.

One source puts it directly: your AI transformation is not failing because of the technology, it is failing because you are treating employee resistance as an irrational response to change instead of a rational response to how you are managing that change[3].

It elaborates that employees are not afraid of the technology but of leaders who treat AI transformation as a technology project rather than a restructuring of how work happens, who demand adoption without providing support, and who use efficiency gains to pile on more work rather than create space for people to adapt[3].

A law firm publication reaches a similar diagnosis from a legal risk perspective, stating that resistance rarely stems from dislike of technology but from unmanaged uncertainty about job security, performance evaluation and data use, and that such uncertainty can lead to shadow use and even sabotage[5].

The word rational is doing the work and deserves defending rather than accepting as rhetoric.

If an employee believes that disclosing a productivity technique will result in the technique being prohibited, or in more work being assigned, or in their role being reassessed, then concealing it is a correct calculation given those beliefs. The question for a firm is not whether people are behaving reasonably but whether those beliefs are accurate, and if they are, the behaviour will not change until the underlying facts do.

The Decision That Fails Three Ways

A convergence across this series that identifies one management choice as unusually costly. This section is our own analysis.

The source above names using efficiency gains to pile on more work rather than creating space to adapt[3]. That single decision appears in three separate articles in this series, each identifying a different failure.

The offloading article found that the benefit case for AI is conditional on the human remaining actively engaged in interpreting and evaluating, so capacity reinvested in volume rather than in evaluation does not satisfy the condition under which the benefit was demonstrated.

The deskilling article found that routine work is the substrate maintaining a practitioner's familiarity with normal, and that increased throughput accelerates rather than offsets capability erosion.

And this article's sources find that it generates the resentment and concealment documented above.

One decision, three independent failures, each identified by a different literature.

The measurement article recommended that firms state what they are buying, because speed, tolerability and capability extension are all legitimate purchases evaluated differently. This adds a sharper version: if a firm buys capacity and immediately spends it on volume, it has bought throughput and should expect none of the quality, capability or engagement benefits, and should expect the cost documented here.

Fear Of Becoming Obsolete

The specific anxiety the sources identify, which differs from the one most firms address.

Two sources name it: the dominant employee anxiety in 2026 is not job displacement but the fear of becoming obsolete, and the distinction matters for how a firm responds[6][3].

The distinction is worth drawing out because the two require different answers.

Fear of displacement is fear of the role disappearing, and it is answered by information about headcount intentions.

Fear of obsolescence is fear that one's accumulated expertise is becoming worthless, which is a fear about identity and standing rather than about employment, and it is not answered by job security assurances.

The deskilling article in this series identified exactly this through a different literature, reporting Bainbridge's observation that skill level is a major aspect of a worker's status and that reduction of a job to monitoring is difficult for individuals to come to terms with.

So a Canadian firm assuring experienced staff that their jobs are safe may be answering a question nobody asked. The concern of a senior practitioner is more likely to be whether the thing they spent twenty years becoming good at still counts, and the only credible answer is one that shows where their judgment remains load-bearing.

That is an argument for the constitutive design patterns the oversight article recommended, where senior judgment sets the criteria the system applies, rather than for reassurance.

The Two-Tier Claim

A set of figures that would explain a great deal if accurate, reported with strong caution about their source.

One vendor's survey reports that 75 percent of executives admit their company's AI strategy is more for show than actual internal guidance, that 48 percent call adoption a massive disappointment, that 92 percent of the C-suite are cultivating a new class of AI elite employees while 60 percent plan to lay off those who cannot or will not adopt, and that only 35 percent of employees say their manager is an AI champion[7].

We flag this source strongly. It is published by a vendor, the article moves from these findings to a claimed return figure for its own product from a commissioned study, and we did not access the survey instrument or methodology. The figures should be treated as characterising a vendor's narrative rather than as established.

Reported as stated, though, the pairing of 92 percent cultivating an elite with 60 percent planning to remove non-adopters describes an environment in which the concealment findings above are unsurprising.

And the 35 percent figure on managers connects to the manager variable discussed below, which is the intervention point.

The 75 percent admitting the strategy is for show is the item we would most want verified, because if accurate it means most stated AI strategies are not the thing employees are responding to. They are responding to what they observe, which is a different artefact.

Two Directions Of Concealment

A distinction the trust finding invites and which matters for the remedy. This section is our own analysis.

The reported finding concerns hiding AI knowledge from coworkers or employers[1], which are two different behaviours with different motives.

Concealment from the employer is protective. The employee fears that disclosure results in prohibition, in additional work, in scrutiny of prior work produced the same way, or in their being assessed differently. The tool is producing value and disclosure risks losing it.

Concealment from colleagues is competitive. If capability with these tools is rewarded, then a technique that makes one person faster is an advantage relative to peers, and sharing it dissipates the advantage.

The study reportedly controlled for internal competition and the trust effect held[1], which suggests competition does not fully explain the pattern, so the protective motive is likely doing substantial work.

The remedies differ. Competitive concealment responds to how contribution is recognised, and to whether sharing a technique is rewarded or merely dilutes advantage.

Protective concealment responds only to changing the consequences of disclosure, and the most direct intervention available to a Canadian firm is an explicit, credible amnesty: a stated period in which disclosing prior unsanctioned use carries no consequence, paired with a commitment about what will and will not happen afterwards.

That is uncomfortable to offer and it is the only mechanism we can see that addresses the stated mechanism directly.

The Policy Reflex

Why the standard response is reported to worsen the problem.

One source reports that a 2026 professional body publication documented rigid, top-down AI policies often backfiring precisely because they treat shadow AI as a control problem to be solved rather than a cultural signal to be interpreted. It states that when employees perceive the culture as open and psychologically safe they surface what they discover, and when they perceive it as punitive and extractive, shadow use becomes not just a productivity hack but a form of self-protection. It adds that blocking the consumer tools employees already trust only pushes the behaviour further out of view[1].

Another states that the fix is not blocking a consumer service at the network level[3].

The mechanism is not mysterious and it is familiar from other governance contexts. A control that raises the cost of a behaviour without removing its motivation displaces the behaviour rather than eliminating it, and displacement in this case means moving it to personal devices and personal accounts, where the firm has no visibility at all.

Note the asymmetry that creates. Before a block, the firm has an unsanctioned tool it can at least discover. After a block, it has an unsanctioned tool on a personal device it cannot discover, doing the same thing to the same client information.

We are not arguing against having a policy. A firm needs one, and the article below reports evidence that a policy paired with a genuinely adequate sanctioned tool works. The argument is that the policy is not the operative variable on its own, which is precisely what the controlled finding reported.

What Actually Reduces It

The intervention the sources identify, with its mechanism, which is the part that matters.

One source states that when approved tools are provided with clear policy, unauthorised use drops substantially, and gives the reason: not because employees are forced to comply, but because they no longer have the productivity incentive to use unauthorised tools, since employees adopt shadow AI when approved alternatives are absent or inferior[6].

The specific magnitude that source reports is large and unsourced, and we have not repeated it as a figure because we cannot support it.

The mechanism is the useful part and it is checkable by any firm against its own experience. Unsanctioned use is a symptom of the sanctioned alternative being absent or worse, and people do not accept friction and personal risk for no gain.

That produces a diagnostic a Canadian firm can apply immediately: for each instance of unsanctioned use it discovers, ask what the sanctioned alternative was and why the employee did not use it. The answers will generally be that there was none, that it was slower, that access required a request, or that it did not do the thing.

The same source adds a sequencing point worth adopting: the acceptable use policy must exist before the tool launches, rather than weeks later when a data incident prompts a reactive response[6].

The Inventory, For The Third Time

A recommendation that has now arrived from three unrelated directions.

One source states that the first week of an adoption programme is not about the technology but about understanding what is already happening, being the shadow AI inventory, and what people actually fear, being listening sessions, and that organisations skipping this and going straight to training are solving the wrong problem[6].

This publication reached the same requirement twice already for different reasons.

The professional liability article argued that a firm cannot answer an insurer's renewal question about AI use without an inventory covering deployed tools, features enabled inside existing software, and what staff use independently, and that the third category is the one most likely to be missing.

The protocol article argued that a firm cannot bound the blast radius of connected components without knowing which are connected and who enabled them.

Three separate problems, being insurance disclosure, security scope, and change management, produce the same first action.

The observation we would add is about how to conduct it. An inventory gathered by asking people to declare unsanctioned use, in an organisation where the trust finding predicts concealment, will produce an inventory of the sanctioned tools. Which is why the amnesty framing above is not a soft touch but a methodological requirement for getting an accurate answer.

Nobody Knows How To Stop It

A finding that connects directly to the incident response article and which we found striking.

One source reports that 56 percent of professionals do not know how long it would take to halt an AI system during a security incident, and recommends that documented and tested shutdown playbooks be an immediate priority for security and audit teams[4].

We report the figure at second hand from a governance platform vendor citing a professional association survey.

The incident response article in this series argued that containment for an AI workflow is usually suspension rather than repair, because the alternative is continuing to generate defective work while diagnosis proceeds, and that the decision needs a named owner and pre-authorisation because asking permission is a delay measured in the same units as the damage.

This finding says that for a majority, the mechanical question of how long suspension would take is unanswered.

And for shadow use the position is worse than unanswered. A firm cannot suspend a workflow running on a personal account through a service it has no relationship with. There is no control to exercise, and the only available action is asking the person to stop.

That is the containment consequence of the visibility failure, and it is the point at which a governance gap becomes an operational one.

The Manager Variable

The intervention point the sources converge on.

One source states that trust in direct managers is the strongest predictor of whether people engage with organisational change, and that such trust is built by managers who understand what their people are experiencing and address it specifically[3]. Another reports that only 35 percent of employees say their manager is an AI champion[7].

Sources also caution against undifferentiated training, one describing a uniform company-wide course or all-hands demonstration as the training equivalent of giving everyone the same size shoes, and reporting differing confidence trajectories across age cohorts[6].

For a mid-sized Canadian professional firm the manager finding has a specific reading, and this is our own.

The people occupying the manager role in a practice are the senior practitioners whose position this series has documented most uncomfortably. They are the ones the deskilling article identified as losing capability while retaining accountability, whose residual work is enriched for difficulty, whose status is bound to expertise the technology appears to commoditise, and who are least likely to have been asked what they think.

Expecting that cohort to champion the change, without addressing their own position in it, is asking the people with the most to lose to advocate for the loss.

Which suggests the sequence runs the other way. A firm that resolves what senior judgment is for under the new arrangement acquires credible champions; one that announces a rollout and asks managers to support it does not.

The Obligation Does Not Distinguish

The point that should end any debate about whether this is a priority, and it is our own analysis.

A Canadian professional firm's confidentiality obligations to its clients do not contain an exception for tools the firm did not sanction. The duty is the firm's, it attaches to the information, and it is indifferent to which application a staff member happened to use.

The same is true of privacy obligations where personal information is involved, and of the firm's own contractual commitments to clients about how their information is handled.

So the reported 36 percent using unapproved tools with confidential data[2] does not describe a policy compliance issue. It describes potential breaches of obligations the firm owes and cannot delegate.

Three consequences follow for a Canadian practice.

The exposure is the firm's regardless of who acted, so treating this as an individual conduct matter misidentifies where the liability sits.

The firm cannot assess or remediate a disclosure it cannot identify, which returns to the inventory.

And the professional liability article's warning applies with force: the firm's response to an incident, and the accuracy of what it told its insurer, both depend on knowing what was in use.

A Worked Case: The Tool Nobody Mentioned

A Canadian practice that has deployed an AI capability with appropriate controls. The reconstruction illustrates the mechanisms rather than reporting a specific engagement.

The sanctioned workflow is well governed: logged, evaluated on a schedule, reviewed under a constitutive design, and covered by a contract with notice provisions. Everything this series recommended has been done.

Meanwhile a manager under deadline pressure uses a consumer service on a personal account for drafting, because the sanctioned tool does not cover that task and requesting one takes two weeks. That is the reported pattern of shadow use arising where the approved alternative is absent or inferior[6].

They do not mention it. Trust in the firm's handling of such disclosures is low, and the reported finding is that concealment is roughly three times as likely in that condition[1].

Client information is involved, which the survey suggests is the case in about a third of such use[2]. No agreement governs it and the firm's confidentiality obligation applies regardless.

None of the firm's controls touch this. There is no log, no lineage, no review, and nothing to suspend[4].

At renewal the firm answers its insurer's question about AI use by describing the sanctioned workflow, accurately as to what it knows and incompletely as to what occurred.

The firm's governance is excellent and covers a minority of its activity, and nothing in its policy would have changed that.

What To Do

Build the inventory before anything else. Deployed tools, features inside existing software, and what people use independently. Three separate problems in this series produce this same first action.

Offer a credible amnesty to get an accurate one. An inventory collected by asking for declarations, in conditions the research says produce concealment, returns a list of the tools you already knew about.

Ask what the sanctioned alternative was. For every instance found. Unsanctioned use is reported to arise where the approved option is absent or inferior, and that is a diagnosable, fixable condition.

Do not respond by blocking. Displacement moves the behaviour to personal devices, where the same client information is processed with less visibility than before.

Do not expect the policy to do the work. The controlled finding held after controlling for whether an official policy existed. Have one, and do not treat it as the intervention.

Address obsolescence, not displacement. The dominant anxiety reported is that accumulated expertise stops counting, which job security assurances do not answer.

Resolve what senior judgment is for before asking managers to champion anything. Otherwise you are asking the cohort with most to lose to advocate for the loss.

Do not spend the capacity on volume. One decision that this series has now found fails three separate ways.

Know how to halt a workflow, and time it. A majority reportedly cannot answer that, and for shadow use there is nothing to halt.

Treat confidential data in unsanctioned tools as an obligation breach, not a compliance issue. The duty is the firm's and does not distinguish by application.

The Limits Of This Analysis

Several caveats matter. Every finding here reaches us at second hand through commercial publications reporting studies we did not access, including the trust study, the implementation difficulty study, the prevalence surveys and the professional association figures; we cannot verify their instruments, samples or control specifications. The trust study is reported as controlling for a substantial list of alternative explanations, which is what gives it weight, and we have not seen that specification. One source is published by a vendor whose article moves from survey findings to a claimed return figure for its own product, and its figures should be treated as characterising a vendor narrative. The reported reduction in unauthorised use following provision of approved tools is unsourced and we have declined to repeat the figure. Reported prevalence ranges vary between sources. All surveys cited concern United States or unspecified populations, not Canada, and Canadian professional and privacy obligations differ from those in the jurisdictions studied. The argument that concealed use is the precondition failure for the governance programme, the two directions of concealment, the amnesty as a methodological requirement, the convergence identifying capacity-to-volume as a triple failure, the manager cohort argument and the Canadian obligation analysis are our own. This article is not legal or employment advice; monitoring of employee tool use raises privacy and employment law considerations in Canada on which a firm should take advice before acting. Nothing here substitutes for professional guidance.

Frequently Asked Questions

Will an AI policy stop concealed use?
On the reported evidence, not on its own. A study of 604 daily AI users found concealment at 47 percent in the lowest organisational trust quartile against 14 percent in the highest, with the finding holding after controlling for whether the organisation had an official AI policy. Have a policy; do not treat it as the intervention.
Why does this matter more than the security risk?
Because it is the precondition failure for everything else. Logging, lineage, review design, insurance disclosure and component inventory all presume the firm knows what is in use. A firm with excellent controls over sanctioned workflows, and four-fifths of its actual AI activity outside them, has controls over a minority of its exposure.
Should we block consumer AI tools?
Sources advise against it. Blocking tools employees already trust is reported to push the behaviour further out of view, onto personal devices and accounts where the firm has no visibility. Note the asymmetry: before a block you have an unsanctioned tool you might discover; after, the same client information is processed somewhere you cannot see at all.
What actually reduces unsanctioned use?
Providing an approved tool that is genuinely adequate, alongside clear policy. The reported mechanism is that employees lose the productivity incentive, because shadow use arises where the approved alternative is absent or inferior. The diagnostic is to ask, for each instance found, what the sanctioned alternative was and why it was not used.
What are our people actually afraid of?
Sources report the dominant anxiety is not job displacement but becoming obsolete, meaning accumulated expertise ceasing to count. That is a fear about standing rather than employment, and job security assurances do not answer it. The credible answer shows where their judgment remains load-bearing.
Is unsanctioned use with client data a policy breach or something worse?
Worse. A firm's confidentiality obligations to clients contain no exception for tools the firm did not sanction. The duty attaches to the information and is the firm's regardless of who acted, so treating it as individual conduct misidentifies where the liability sits. A reported 36 percent of unapproved use involved confidential data.
IB

About The Insight Bureau Research Desk

The Insight Bureau is GSH Financial's research publication, written for Canadian business owners and the students who will eventually advise them. This article declines to repeat an unsourced headline figure, flags a vendor survey as a vendor narrative, and states that this subject probably belonged earlier in the series than it appears. See References below.

References

  1. Adaptive Security. (2026, July 10). Why Do Employees Use Shadow AI, reporting a 2026 study of 604 United States employees who use AI daily in which 47 percent in the lowest organisational trust quartile had intentionally hidden AI knowledge against 14 percent in the highest, with the finding holding after controlling for job insecurity, internal competition, age, gender, industry, tenure and the presence of an official AI policy; and reporting a 2026 professional body finding that rigid top-down policies backfire by treating shadow AI as a control problem rather than a cultural signal, with blocking pushing behaviour further out of view. Note: a commercial security publication; the underlying studies were not accessed. adaptivesecurity.com/blog/why-do-employees-use-shadow-ai
  2. Digital Applied. (2026, June 14). Change Management for AI Adoption: A 2026 Playbook, reporting a study of 1,107 professionals in which user proficiency accounted for roughly 38 percent of AI implementation difficulties against about 16 percent for purely technical issues, a survey finding 78 percent of employees using unapproved tools with at least 45 percent in the past 30 days and 36 percent doing so with confidential data, and a reported figure that only 13 percent received employer training. Note: a consultancy publication; underlying studies not accessed. digitalapplied.com/blog/change-management-ai-adoption-2026
  3. People Managing People. (2026, February 20). Employee AI Fears in 2026: What Actually Kills Adoption, on reported unapproved tool use between 78 and 86 percent with security professionals among the highest, a majority reportedly willing to accept security risks to meet deadlines, the characterisation of the behaviour as desperation rather than rebellion, the naming of fear of becoming obsolete as the dominant anxiety, the argument that resistance is a rational response to how change is managed, the criticism of using efficiency gains to add work rather than create space, and trust in direct managers as the strongest predictor of engagement with change. Note: a trade publication. peoplemanagingpeople.com/workforce-management/ai-fears-2026
  4. Optro. (2026, June 2). Shadow AI Stats for 2026, reporting professional association findings that 25 percent of organisations have no active AI policy and that 56 percent of professionals do not know how long it would take to halt an AI system during a security incident, with the recommendation that documented and tested shutdown playbooks be an immediate priority. Note: published by a governance platform vendor citing a professional association survey not accessed by us. optro.ai/blog/shadow-ai-stats
  5. Taft. (2026, July 28). When Employees Don't Trust AI: Sabotage, Shadow AI, and What In-House Counsel Should Know, on employee resistance stemming from unmanaged uncertainty about job security, performance evaluation and data use rather than dislike of technology, on that uncertainty leading to shadow use and potentially sabotage, on the threats to data integrity, privilege and compliance, and on reframing AI risk management as a legal rather than an IT function. Note: a United States law firm publication; general commentary rather than advice, and not Canadian. tafttechlaw.com/2026/07/when-employees-dont-trust-ai
  6. AI Buzz. (2026, May 31). AI Change Management Plan 2026, on the reported reduction in unauthorised use when approved tools are provided with clear policy and the mechanism that employees lose the productivity incentive because shadow use arises where approved alternatives are absent or inferior, on the acceptable use policy needing to exist before launch, on the first week being about the shadow AI inventory and listening sessions rather than technology, on the criticism of undifferentiated training, and on the naming of fear of becoming obsolete. Note: a commercial governance publication; the reduction figure is unsourced and we have not repeated it. aibuzz.blog/ai-change-management-for-beginners
  7. Writer. (2026, May 1). Enterprise AI Adoption in 2026, reporting survey findings that 75 percent of executives admit their AI strategy is more for show, 48 percent call adoption a massive disappointment, 92 percent of the C-suite are cultivating an AI elite while 60 percent plan to lay off non-adopters, and only 35 percent of employees say their manager is an AI champion. Note: published by a vendor; the article proceeds to a claimed return figure for its own product from a commissioned study, and these figures should be treated as characterising a vendor narrative rather than as established. writer.com/blog/enterprise-ai-adoption-2026

This article discusses organisational research and is provided for general informational purposes. Every finding reaches us at second hand through commercial publications reporting studies we did not access, one source is a vendor whose figures should be read as a vendor narrative, and all surveys concern non-Canadian populations. Monitoring of employee tool use raises Canadian privacy and employment law considerations not addressed here. Nothing here is legal, employment or professional advice.