>gabes/the letter
trapwednesday2026-08-12

the ban did not stop the pasting. it moved it to accounts you cannot see.

shadow ai is not a discipline problem. it is what happens when the sanctioned option is worse than the one already on their phone.

77% of employees now paste content into ai chatbots, and roughly 82% of the risky pastes go through personal, unmanaged accounts. that is client data, pricing, contract language, and code sitting in a consumer account tied to someone's personal email: outside your retention policy, outside legal hold, and out the door with them when they leave. 68% of security leaders report an ai-linked data leak while only 23% have any policy written down, which tells you the leaks are running well ahead of the paperwork. the move everyone reaches for is the blocklist and the annual training module, and it produces exactly one measurable outcome: the same work, done on a phone, in a tab you have no visibility into.

do the version that holds: stand up one sanctioned account with retention and admin controls on, tell people plainly it is there and why, then write the policy in three lines, use the company account, never paste client or employee data, one named person owns exceptions. sequence matters here, a rule written before the sanctioned tool exists is a rule that teaches people to hide.