# Our staff are using AI tools we cannot see

> Justas Butkus is the founder of AINORA, MB – the company behind the Ainora and Impetora brands – based in Vilnius, Lithuania, and a graduate of Vilnius University.

AINORA, MB builds and operates AI systems for companies from Vilnius, Lithuania. It designs company brains: shared internal systems that hold an organisation's own knowledge, connect to the tools it already runs, and carry out the jobs its people repeat, with access rights enforced per person and hosting in the EU.

**They are using them because those tools make a specific task faster, and they are usually right about that. The real exposure is narrower than it feels: it is material leaving your control, and output nobody checked being used as though it were checked. Prohibition moves the same activity onto personal devices where you can see none of it. The workable sequence is to find out what they are actually doing, give the two or three legitimate uses a sanctioned route, and write one page of rules people can follow.**

Canonical: https://justasbutkus.com/answers/staff-using-ai-tools-we-cannot-see/
Last updated: 2026-08-23

---

## Why it is happening

It is worth being clear-eyed about this before deciding what to do, because the response most companies reach for assumes bad judgement, and bad judgement is rarely the cause.

Somebody has a task that takes forty minutes and is mostly mechanical: summarising a long document, drafting a reply in a language they are slower in, restructuring a spreadsheet, writing the first version of something that will be edited anyway. A tool their own phone can reach does it in two. They are not making a considered decision about data governance; they are getting their work done in the time available.

That distinction determines which responses can possibly work. This is not a discipline problem. It is a queue of unmet demand that found its own supply.

## What the actual exposure is

The imagined exposure and the real one differ, and conflating them produces a response aimed at the wrong risk.

**Sorting the real risks from the assumed ones**

| The worry | How real it is | What actually reduces it |
| --- | --- | --- |
| Material pasted into a tool leaves our control | Real, and the main one | A sanctioned route with terms you have read, plus a rule about what never gets pasted anywhere |
| Output nobody checked gets used as though checked | Real, and underrated | A rule about which work requires a named human reviewer, regardless of how it was produced |
| Personal data handled without a lawful basis | Real where it applies | Naming the categories of material that are off limits, in one sentence people remember |
| A customer receives something inaccurate | Real, but not new | The same review you already apply to work produced any other way |
| Staff will stop thinking for themselves | Mostly a proxy for other worries | Nothing technical. This is a management conversation |
| Our material trains somebody else's system | Depends entirely on the terms | Reading the terms of one sanctioned tool rather than none of the terms of twelve |

The first two rows carry almost all of the practical risk, and both of them are addressable with a page of rules and one approved route. Neither requires selecting a platform this quarter.

## Why prohibition fails

A ban is attractive because it can be issued on Monday and it looks like a decision. Its actual effect is well established and worth stating plainly.

- **The activity moves to personal devices** – The same material, the same tools, with none of the visibility and no route for anyone to ask a question about it. You have not reduced the exposure, you have stopped measuring it.
- **The people who tell you are the compliant ones** – A ban selects against exactly the staff who would have flagged a problem. The remaining users are the ones who were never going to ask.
- **It ages badly and in public** – These tools are being built into the software your company already runs. A prohibition written against a category has to be revised repeatedly, and each revision costs credibility.
- **It answers the wrong question** – The demand that produced the behaviour is still there on Tuesday. Nothing in a ban addresses the forty-minute task.

## What to do in the first fortnight

None of this requires choosing a supplier, and all of it is useful regardless of what you decide later.

1. **Ask, without consequences attached** – A short anonymous question to the teams: what are you using, for what task, how often. The answers are consistently more mundane and more useful than expected, and you will not get them if the question arrives attached to a warning.
2. **Write down the two or three tasks that dominate** – They are usually drafting, summarising and translating. This list is the actual requirement, and it is worth more than any vendor assessment you could commission.
3. **Sanction one route for those tasks** – One tool, with terms somebody has read, reachable by everyone who needs it. The purpose is to make the compliant path the easy path, because the alternative path has already proved how easy it is.
4. **Write one page of rules, not ten** – What never gets entered anywhere, what always needs a named reviewer before it leaves, and who to ask when it is unclear. A policy people can recall in the moment beats one that is thorough and unread.
5. **Name who owns the question** – One person people can ask. Most of what looks like risky use is somebody guessing because there was nobody to ask.

## What changes if you build a shared internal system

This is where the two problems connect, and it is worth being honest that a shared system solves part of this rather than all of it.

The reason people paste company material into an outside tool is that the outside tool does not know anything about the company, so they have to tell it. A system that already holds your material, reads from the systems you run and enforces who is entitled to what removes the reason for the pasting rather than forbidding it. It also produces answers that cite their sources, which addresses the second real risk directly.

What it does not do is remove the need for the page of rules or the named owner. Staff will still reach for whatever is fastest for the task in front of them, and a sanctioned system that is slower or harder to reach than the alternative loses, correctly.

That is the whole design constraint, and most internal rollouts fail it. The approved route has to be the convenient one. Anything else is a policy that describes behaviour rather than shaping it.

## Frequently asked questions

### Should we block these tools on the network?

It rarely achieves what it appears to. The same work continues on personal devices, and you lose both the visibility and the chance to hear about a problem early. Blocking is defensible for a specific tool with terms you have read and rejected, and weak as a general posture.

### What should the one page of rules actually say?

Which categories of material never get entered into any external tool, which work requires a named human reviewer before it leaves regardless of how it was produced, and who to ask when a case is unclear. Three things, on one page. Longer policies are not followed more closely.

### Does the EU AI Act require us to do something about this?

The obligations that most often apply here concern transparency, record keeping and human oversight, plus taking measures to support AI literacy among staff. It does not require you to appoint a particular officer or role, and it does not prohibit ordinary internal use of general tools.

### How do we find out what is being used without starting a witch hunt?

Ask about tasks rather than tools, anonymously, and separate it entirely from any disciplinary process. People answer honestly about what is slow in their job. They do not answer honestly about what they might be in trouble for.

### Is a shared internal system the answer to this?

It removes the main reason people reach outside, which is that an outside tool knows nothing about your company until they tell it. It does not remove the need for rules, an owner, or the requirement that the approved route be genuinely convenient. Treat it as addressing the cause rather than closing the question.

## Related

- [It is all in their heads](/answers/knowledge-is-in-peoples-heads/) – What to do when the company's know-how has never been written down.
- [What a company brain is](/company-brain/) – The definition, the three things it holds, and when it is the wrong thing to build.
- [Who can see what](/company-brain/permissions/) – Role-based access on a system the whole company shares, and what it cannot promise.

## About the author

**Justas Butkus** – the founder of AINORA, MB – the company behind the Ainora and Impetora brands – based in Vilnius, Lithuania, and a graduate of Vilnius University.

## The first move is finding out, not deciding

A fortnight of asking what people are actually doing produces a better requirement than any assessment. If you want a second opinion on what the answers mean before choosing anything, that is a short conversation.

Contact: justas@ainora.lt · [LinkedIn](https://www.linkedin.com/in/justas-butkus/)
