Roughly half is the number worth planning against, and it has been stable across several independent measurements rather than resting on one survey. Gartner found 69% of organizations suspected or confirmed staff use of prohibited public generative AI, and Harmonic Security's telemetry put close to three quarters of enterprise ChatGPT usage on personal rather than corporate-licensed accounts. Different questions, same conclusion: sanctioned tooling does not cover the work.

The number is best read as a measurement of governance lag rather than of employee behavior. Unsanctioned is defined against what the employer has approved, so the figure rises both when staff adopt something new and when the organization has not gotten around to classifying a tool already in use. Both are governance gaps and both close the same way, which is by producing an inventory.

That is why every AI governance framework starts in the same place. NIST AI RMF, ISO 42001, and the EU AI Act each assume you can enumerate the AI systems in use and say what each one does with what data. An organization that writes an acceptable-use policy before it can produce that list has governed a population it cannot see.