Your Team Is Already Using AI. They're Just Not Telling You.
Eighty percent of HR professionals at small companies now use AI in their daily work. Twenty-three percent of their companies have a formal policy that says anything about it. Those two numbers come from the same survey, published this February.
That's not a technology gap. It's a management gap — and it's widest at exactly the kind of company I work with. SHRM's 2026 workplace data shows 56% of large organizations have AI policies. Small organizations? 36%. A separate April survey of 2,000 U.S. workers found that at companies under ten people, 59% say there's no clear policy — or they're not sure one exists.
If you run a 25-to-300-person company and you're waiting until AI "settles down" to deal with this, here's the number that should change your mind: 57% of employees who use AI at work hide it and present the output as their own. That's from a 48,000-person global study. Your team didn't wait for permission. They just stopped mentioning it.
The problem isn't the using. It's the hiding.
The risk isn't where most owners think.
When AI use is hidden, three things happen. First, nobody reviews the output — and the same global study found roughly two-thirds of AI users rely on results without checking them. Second, the productivity gains stay private. Research out of HEC Paris found that "shadow adoption" of AI benefits the individual employee, not the company — the person gets faster, and the learning never spreads. Third, your data walks out the door: Netskope's 2026 telemetry puts 47% of workplace AI use on personal accounts your company can't see.
And banning it doesn't fix anything. When companies prohibit AI outright, a large share of employees simply keep using it on personal devices — the ban eliminates your visibility, not the behavior. SHRM's own data shows 30% of workers have knowingly violated their employer's AI rules.
The failure cases aren't hypothetical. This January, Slate collected reader stories of AI at work going sideways: an AI meeting notetaker that recorded a confidential grievance meeting and auto-emailed the notes to every calendar invitee — including the union reps. Another that sent interview evaluations to the candidates being evaluated. And in one widely shared account, an employee received a performance review that praised her as a "pillar of consistency" while rating her lowest for being "inconsistent" — her manager had generated it with ChatGPT, and the muddle froze her raise for a year.
Every one of those disasters happened at a company without a working policy. Here's the kicker most owners miss: without a policy, you can't even discipline cleanly. Basic employment-law hygiene says discipline generally requires a rule the employee actually had a copy of. No policy means every AI mess becomes an improvised judgment call — inconsistent, unfair, and legally wobbly.
Why you don't have one yet
Because everything you find when you google "AI policy" is written for a company ten times your size. The top results tell you to form an AI oversight committee, engage diverse stakeholders, commission annual bias audits, and consult legal counsel. SHRM's template sits behind a member login. Lattice's mandates an oversight committee, complete with whistleblower provisions. You have forty employees. There is no committee. There is no counsel on staff.
So it goes on the someday list — as the small-business HR shop ClarityHR puts it, building an AI strategy is a task most owners "never had on our bingo card." Meanwhile, your team ships AI-assisted work every day.
The one-page policy that actually fits
Skip the nine-section template. At your size, a policy your people can remember beats a policy your lawyer would admire. One page, five elements:
- One data rule. Never put client information, employee records, financials, credentials, or anything under NDA into an AI tool — with a test anyone can apply: would I be comfortable posting this publicly? If not, it doesn't go in the prompt.
- One accountability rule. You own what you ship. AI drafted it, you signed it — the errors are yours. Disclose AI use on anything consequential.
- A starter list of approved tools — including the AI that's already embedded in software you pay for: meeting notetakers, Zoom summaries, email drafting. (That grievance-meeting fiasco wasn't a rogue chatbot; it was an ordinary meeting notetaker.)
- One named owner. Not a committee — a person who fields the "can I use this?" questions and updates the list.
- A review date. Six months out, on the calendar. This will need revising; say so up front.
If you want a running start, AdeliaRisk publishes the best free template I've seen — it's the rare one that scales its guidance down for companies under 50 — and the "traffic light" pattern (green: encouraged / yellow: allowed with disclosure / red: never) is a memorable way to structure the page.
Then make the move nobody suggests: amnesty
Here's what none of the template articles will tell you, and it's the step that matters most. Your rollout has to deal with the AI use that already exists — the 57% presenting AI work as their own. If your policy arrives as an enforcement document, that use stays hidden. You'll have a policy and shadow AI.
So open with a disclosure window: two weeks, no consequences, one question — what are you already using, and for what? Treat every answer as free product research. What surfaces becomes your approved-tools list, your training agenda, and an honest map of where AI is actually saving your team time. After the window closes, enforcement is a gradient — conversation, then retraining, then discipline — not straight to termination.
Where to start this month
Week 1: Draft the one-pager. Adapt a good free template; it's an afternoon, not a project.
Week 2: A 30-minute all-hands: here's the page, here's why, amnesty window opens today.
Week 3: Turn the disclosures into your approved list. And look at what they surfaced about your data: if employees can't tell what's confidential because everything lives in folders shared with everyone, your data rule is unenforceable. A basic permissions cleanup is part of AI readiness.
Week 4: Collect sign-offs, name the owner, calendar the six-month review.
You don't need a committee. You need a page, a conversation, and one person who owns it.
This is the pattern with almost everything AI in HR right now: the gap between the companies getting value and the companies getting burned isn't budget or headcount — it's whether anyone made it somebody's job. A policy is the cheapest possible place to start.
Sources
- HR Partner — The State of AI in Small Business HR 2026 (80% use / 23% policy; top concerns)
- SHRM — Navigating AI in the Workplace 2026 (36% vs 56% policy adoption; 30% knowingly violated rules)
- KPMG / University of Melbourne — Trust, Attitudes and Use of AI: Global Study 2025 (57% hide AI use; reliance without checking)
- Netskope — Cloud and Threat Report 2026 (47% of workplace genAI use via personal accounts)
- Founder Reports — AI in the Workplace 2026 (policy clarity at small companies)
- HEC Paris — Shadow Adoption of ChatGPT Benefits Employees, Not Firms
- Slate — Reader stories of AI chaos at work (Jan 2026)
- Redactprompt — Why blocking ChatGPT at work backfires
- ClarityHR — AI Policies for Small Businesses ("never had on our bingo card")
- AdeliaRisk — AI Acceptable Use Policy Template (best free template for small companies)
- SHRM — discipline requires a policy the employee had a copy of