top of page

Deloitte UK AI Survey Finds Workers Hiding AI Use From Their Bosses

2 hours ago
13 min read

Deloitte found that almost one in ten UK workers have used an AI tool their employer banned or would disapprove of. The Deloitte UK AI survey turns workplace adoption into a conflict about permission, security, and professional trust. Employees want faster ways to search, summarize, and draft. Their employers often lack approved alternatives, clear rules, or credible training.

The findings come from 25,000 workers surveyed across the UK between May 7 and June 10, 2026. Ipsos conducted the online fieldwork for Deloitte. The results suggest that generative AI has entered ordinary work faster than many organizations can govern it.

That gap creates the article’s central tension. Workers see AI as a practical tool for completing routine tasks. Employers see unmanaged services, sensitive prompts, uncertain outputs, and possible compliance failures. Meanwhile, employees also fear that visible AI use could make managers question their value.

This is not simply another adoption survey. It shows employees privately solving a productivity problem while employers publicly debate how much AI use they should permit. The result is a workplace where organizations may depend on gains they cannot see, measure, or safely manage.

The Deloitte UK AI Survey Reveals a Hidden Workforce

Generative AI is already common at work, but a meaningful share of its use remains outside employer oversight.

The workforce survey found that 63% of UK working adults had knowingly used generative AI for work. Generative AI means systems that create text, images, audio, or other content from prompts.

The research covered workers aged 18 through 70 across 22 industries. Deloitte describes it as the largest workplace generative AI study conducted within one country. Its broad sample provides a stronger view than surveys focused only on executives or technology teams.

Adoption was not limited to occasional experimentation. Almost one-quarter of the UK workforce used generative AI for work every day. Twelve percent used it several times daily, although rates varied substantially among industries and roles.

Workers mainly applied the technology to familiar tasks. Searching for information and drafting emails each accounted for 43% of reported use. Creating summaries followed at 31%.

Those activities help explain why adoption can remain invisible. A worker can paste notes into a chatbot, refine an email, or summarize a document without changing an official workflow. The finished work returns to familiar software, while the AI step disappears from view.

Nearly half of workers said they used free AI tools for work. Another 34% used external tools paid for by employers, while 17% used internally developed systems. These categories show that employer-approved deployment is only one part of the market.

Deloitte also found that 17% of generative AI users paid personally for at least one work-related tool. It estimated that British workers collectively spend £958 million annually on these services.

Self-funding matters because it changes who controls the purchasing decision. An employee can adopt a consumer tool within minutes, without waiting for procurement, security review, or internal deployment. The employer may receive the output without knowing which system processed the underlying information.

Almost one-third of generative AI users said they used the technology without their employer’s knowledge. This form of Deloitte shadow AI covers tools brought into work outside formal visibility or approval.

Bloomberg highlighted a narrower and more confrontational measure. Almost one in ten workers had used a tool that was banned or would draw employer disapproval, according to its survey coverage.

The distinction is important. Using an unknown tool does not always mean violating an explicit rule. Some employers have no clear policy, while others have one that employees cannot find or interpret.

However, both figures describe the same governance failure. Employees have already made AI part of their work, yet many organizations cannot reliably identify the tools involved. That uncertainty turns routine assistance into an unmanaged business process.

Why UK Workplace AI Has Outrun Company Policy

The adoption gap persists because workers can access useful AI faster than employers can approve, deploy, and explain it.

Consumer AI products require little setup and already feel familiar to many employees. A worker can use the same assistant for a personal question and a workplace draft. That convenience encourages adoption before formal systems arrive.

Deloitte found that 65% of generative AI users did not hear leaders discuss the technology with a clear understanding. Thirty percent described leadership messages as incoherent, while 18% heard no leadership communication.

A policy gap sits behind that communication problem. Fewer than half of users reported that their company had a generative AI policy. Thirty-four percent said no policy existed, and 23% did not know whether one existed.

Only 28% said their organization had a policy that they could find, understand, and regard as current. A rule cannot shape behavior if workers do not know it exists or cannot apply it.

Training has fallen behind as well. Half of generative AI users had received no formal instruction, while only 20% had completed mandatory training. That leaves millions of workers teaching themselves how to prompt, verify, and handle information.

The gap is particularly consequential because the first adopted tasks look harmless. Drafting an email or summarizing notes seems less risky than automating a financial decision. Yet an ordinary prompt can contain customer details, internal plans, source code, or confidential meeting records.

Other research points in the same direction. An autumn 2025 survey from the Chartered Institute of Personnel and Development found AI use in 76% of UK organizations. It also found free tools in 54% of workplaces.

However, permission remained uneven. The CIPD later reported that 61% of organizations allowed generative AI use for work. Another 25% neither allowed it nor planned to do so, according to its employer findings.

Formal governance was improving, but from a low base. Thirty-one percent of employers had worked on a generative AI policy during the previous year. That figure had risen from 16% two years earlier.

The mismatch reveals why UK workplace AI becomes hidden. Employees experience the technology as an immediately available productivity aid. Their employers experience it as a procurement, security, legal, and organizational change program.

Approval processes also move at different speeds. Security teams must assess data retention, model training practices, account controls, integrations, audit records, and contractual safeguards. Workers only need a browser or personal account.

Some organizations respond by blocking public tools. That action may reduce obvious access, but it does not eliminate demand. Employees can switch devices, use personal accounts, or move information manually between systems.

A ban also fails when the approved alternative performs poorly or remains unavailable. Microsoft research from 2025 found that 28% of UK employees using unapproved AI said their employer offered no approved option. Another 41% chose familiar tools from their personal lives.

Those results came from a different sample and methodology, so they are not directly comparable with Deloitte’s figures. Still, both studies identify the same mechanism. Employees route around friction when they believe an outside tool helps them work.

The problem is therefore larger than enforcement. Employers must offer an acceptable path for legitimate use, clearly define prohibited data, and teach workers how to judge uncertain cases. Without that combination, policy becomes paperwork rather than operational control.

Workers Want Productivity, While Employers See Exposure

The main conflict is not enthusiasm versus resistance; it is employee speed versus employer accountability.

Deloitte’s respondents reported saving an average of 70 minutes each week through workplace AI. Most said they used the recovered time to perform more work for the same employer.

That finding complicates a simple misconduct narrative. Hidden users are not necessarily avoiding work or delegating entire jobs. Many are using AI for search, email drafts, and summaries, then returning the saved time to their organizations.

The productivity gains also appear uneven. Across the full survey, 7% reported saving at least five hours per week. That share rose to 21% in information and communications but fell to 5% in healthcare and social work.

Around 30% said AI saved them at least some time. Another 31% had used it without saving any time. Adoption alone therefore does not establish productivity.

An employee may spend time correcting hallucinations, rewriting generic output, or checking facts. Hallucinations are confident outputs that lack reliable support. Poorly chosen tasks can shift work rather than reduce it.

Employers carry risks that individual users may not see. A prompt can transfer information to an external service under terms the company never reviewed. A generated summary can omit qualifications that mattered in the original document.

Outputs can also inherit bias, invent citations, or expose protected information when shared. If the final work affects a customer, employee, or regulated decision, the organization remains accountable.

The UK National Cyber Security Centre treats unapproved technology as part of the broader shadow IT problem. Its shadow IT guidance warns that unknown services can create weak oversight and data-handling risks.

AI increases that concern because users actively send information through prompts and file uploads. Traditional unauthorized software might store a contact list. An AI assistant can receive strategy documents, customer conversations, code, or entire datasets.

Yet excessive restriction has costs too. It can push experimentation further underground and prevent teams from sharing effective practices. Employers then lose both visibility and opportunities to standardize useful workflows.

That tradeoff explains why the primary opponent is employee-led adoption versus employer-controlled adoption. One side prioritizes immediate usefulness. The other must protect data, meet legal duties, and maintain consistent quality.

The best response is neither unrestricted consumer use nor a blanket prohibition. Organizations need an approved environment that matches real worker needs. They also need clear boundaries around data, tasks, and human review.

For example, an employee might be permitted to brainstorm generic presentation structures but prohibited from uploading confidential client material. Another policy might allow email editing while requiring independent verification of factual claims.

Those distinctions make governance usable. A rule saying “use AI responsibly” offers little guidance during a deadline. A task-based policy can tell workers what they may enter, which service they may use, and who reviews the output.

Employers should also examine why workers choose outside systems. The reason may be better output quality, fewer access barriers, stronger integrations, or a missing approved capability. Blocking the tool does not resolve the underlying workflow problem.

The Deloitte UK AI survey therefore pressures executives as much as employees. Leaders must decide whether their systems are practical enough to compete with consumer products. Security teams must make approved behavior easier to recognize and follow.

The Stigma Around AI Encourages Concealment

Workers hide AI use not only because tools lack approval, but because disclosure can threaten how managers judge their competence.

Deloitte found that 23% of UK workers believed workplace AI carried a stigma. Among weekly users, 64% worried managers might conclude that AI could perform their jobs.

Bloomberg reported the same 63% figure across its description of respondents concerned about managerial judgment. The precise survey base deserves attention, but the broader fear is clear. Workers associate disclosure with possible replacement.

That anxiety creates a difficult incentive. Employers may ask staff to find productivity gains while also discussing automation and reduced headcount. Employees can respond by using AI privately, keeping both the method and saved time invisible.

CIPD’s employer survey illustrates why those fears are plausible. Seventeen percent of organizations expected AI to reduce headcount during the following 12 months. Only 6% anticipated an increase.

Expectations were higher among large private employers. Twenty-six percent expected lower headcount, compared with 7% of small and medium-sized businesses. Finance, insurance, technology, legal, accounting, and consulting also reported above-average expectations.

Those figures describe employer expectations, not confirmed job losses. They nevertheless shape workplace behavior. Employees listen when leaders describe AI as both an assistant and a route to cost reduction.

A worker who reveals a highly effective workflow may fear proving that fewer people can complete the same task. Another may worry that colleagues see AI assistance as evidence of weaker writing, analysis, or technical skill.

This perception problem can undermine quality controls. Employees are less likely to request review when disclosure feels professionally risky. Managers then see polished output without learning where AI contributed or what verification occurred.

Concealment also prevents organizations from identifying strong use cases. A useful workflow remains personal knowledge rather than becoming a documented, tested process. Risks remain hidden while benefits remain difficult to reproduce.

Leadership messages matter here. Workers need to know whether the organization values AI-assisted performance, independent expertise, or both. Vague encouragement paired with replacement language creates conflicting incentives.

Managers also need training. They must distinguish responsible assistance from careless delegation. Editing a draft with AI is different from accepting an unsupported analysis or automating a high-impact decision.

Disclosure should therefore focus on risk rather than ritual. Requiring a label on every minor grammar correction can produce administrative noise. Requiring disclosure for sensitive data, consequential decisions, or externally published facts serves a clearer purpose.

The UK Information Commissioner’s Office has argued that blanket bans are unlikely to work. Its workplace AI analysis emphasizes lawful access, effective oversight, and practical deterrents.

That approach acknowledges both sides of the conflict. Employers cannot ignore data protection obligations. They also cannot assume a written prohibition will erase tools that workers already find useful.

Trust must work in both directions. Employers need confidence that staff will protect sensitive information and verify outputs. Workers need confidence that responsible disclosure will not automatically damage their reputation or job security.

Without that bargain, Deloitte shadow AI becomes a cultural signal. It indicates that employees do not trust formal channels to meet their needs or protect their interests.

What the Numbers Do Not Prove

The survey documents a large governance gap, but it does not establish how much hidden AI use causes real harm or lasting productivity.

Deloitte used an online survey with a representative quota sample of 25,000 employees and self-employed workers. The results were weighted across demographic, employment, regional, educational, and social categories.

That methodology provides substantial breadth. It still depends on respondents remembering and honestly describing their own behavior. Hidden activity is especially difficult to measure through self-reporting.

The meaning of “without employer knowledge” also varies. One respondent may violate a direct prohibition. Another may use a public tool where no policy exists. A third may work for a company whose managers tolerate informal experimentation.

Bloomberg’s “almost one in ten” measure better isolates use involving a ban or expected disapproval. Even that category combines an explicit rule with the worker’s prediction about how an employer might react.

The survey does not identify how often workers entered confidential information. It does not quantify resulting data leaks, flawed decisions, customer harm, or regulatory action. Hidden use represents exposure, not proof of an incident.

Likewise, reported time savings do not equal measured output gains. Workers estimated their own savings, and the average does not reveal output quality. Time recovered through a fast draft may later be lost during review.

The survey’s task profile also suggests shallow adoption. Search, email writing, and summarization dominate. Those activities can help individuals, but they do not necessarily redesign processes or improve organization-wide productivity.

Deloitte itself describes workplace use as widespread but shallow. Only a minority reported frequent daily use, while nearly one-third had tried AI without saving time.

Comparisons with other shadow AI surveys require caution. Microsoft reported much higher unapproved-use rates in 2025. Other vendors have published still different estimates based on office workers, security leaders, or selected markets.

Definitions often explain part of that spread. Some studies count any consumer AI use as unauthorized. Others count only banned tools, unknown tools, personal accounts, or services handling company data.

Vendor incentives also matter. Companies selling enterprise software or security products benefit when shadow AI appears urgent. Their findings can still be informative, but readers should examine samples, definitions, and sponsorship.

Deloitte also advises organizations on AI adoption and governance. That commercial role does not invalidate a 25,000-person survey. It does make transparent methodology and future replication particularly important.

The planned six-month repetition should help. A second wave can reveal whether training, policy awareness, and daily use are changing. It can also show whether employees continue paying for tools as employers expand official access.

The strongest conclusion today is narrower than some headlines suggest. UK workers are adopting generative AI faster than many employers can govern or communicate about it. A measurable group hides that use, sometimes against expected employer wishes.

It is not yet clear whether tighter controls, better tools, clearer policies, or changing attitudes will close the gap. The answer will likely differ among regulated industries, smaller businesses, and technology-intensive roles.

Three Signals Will Show Whether Employers Catch Up

The next phase depends on whether companies convert hidden individual experimentation into visible, supported, and measurable work.

The first signal is policy awareness, not policy publication. Deloitte found that only 28% of users knew where their company’s policy was, understood it, and considered it current.

That measure should rise when organizations improve communication and make rules task-specific. If it remains low, more policy documents will not meaningfully change behavior.

A stronger result would include fewer workers who say no policy exists or who cannot answer. That change would support the view that employers are building operational governance. Continued confusion would weaken it.

The second signal is the balance between personal tools and approved systems. Workers currently use free services, personally funded subscriptions, employer-paid products, and internal platforms.

Employers should watch whether approved tools gain share without reducing useful adoption. Growth in official use would suggest that organizations offer credible alternatives. Persistent self-funding would show that internal systems still fail important needs.

This signal cannot be judged through licenses alone. A company may buy an enterprise assistant that employees rarely use. Usage, task completion, user satisfaction, and exception requests provide a more accurate picture.

Organizations should also study rejected tools and blocked workflows. Frequent attempts to access the same outside service reveal unmet demand. That evidence can guide procurement or explain why a service remains unsuitable.

The third signal is whether training changes behavior and outcomes. Deloitte found that half of users had received no formal instruction. Fifty-one percent of the wider workforce said training would encourage more frequent use.

Effective training should improve more than adoption. It should reduce sensitive-data sharing, strengthen fact-checking, clarify disclosure, and help employees select appropriate tasks.

Mandatory slide presentations will not be enough. Workers need examples tied to their actual roles, approved systems, and information categories. Managers need guidance on reviewing outputs and responding to disclosed use.

Deloitte plans to repeat its survey roughly every six months. The next wave should provide a direct test of these three signals. Readers should compare policy awareness, tool sourcing, and training coverage with the first results.

Daily use deserves attention too, but it should not become the only success measure. More usage can increase risk if governance stays weak. Less usage can reflect either successful restriction or failed access.

The better question is whether organizations can see and evaluate AI-assisted work. That includes knowing which tools process company information, which tasks produce value, and where humans remain accountable.

For knowledge workers, the immediate lesson is practical. Treat prompts and uploads as information transfers, not private thoughts. Check company rules, remove sensitive details, verify factual outputs, and disclose consequential assistance when required.

For employers, the challenge is equally direct. Give workers an approved route that competes on usefulness, explain the boundaries in plain language, and separate responsible AI assistance from careless substitution.

The Deloitte UK AI survey shows that waiting is no longer a strategy. Employees have already chosen where AI fits into their work, even when employers have not. The open question is whether organizations can replace secrecy with useful governance before a preventable failure forces the issue.

Ask one concrete question inside your team this week: which AI tools are people actually using to complete real work? Compare those answers with approved systems, written policy, and available training. Any gap is not merely an enforcement problem. It is evidence that the organization’s official workflow no longer matches employee behavior. Closing it requires safer tools, clearer rules, credible management, and a culture where workers can discuss AI use without automatically threatening their professional standing.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page