AI is already inside your business. Can you see it?
The roundtable was led by Philip James, Partner and Head of UK Data, Privacy & Cybersecurity at Browne Jacobson, and James Derbyshire, Vice President and Founding Executive at Harmonic Security.
Browne Jacobson recently hosted a roundtable at our London offices together with Harmonic Security, focused on what AI adoption looks like inside organisations. Not what a policy says, but what people do. The conversation confirmed something we've been seeing across our client base for months: the question has moved past "Should we allow this?" to "How far behind are we?" and "What have we already exposed?" Both are fair questions. Neither has a straightforward answer.
Four kinds of organisations
Conversations centred on the four types of organisations, defined by their level of adoption and sophistication, extent of use, risk profile, and risk appetite:
- The Blindfolded have very low official AI usage and very high unseen risk. Nothing is sanctioned, so on paper nothing is happening. In practice everything is, just somewhere nobody is looking.
- The Watchful Waiters are playing it safe: minimal risk, low usage, and losing ground each quarter to competitors who aren't waiting.
- The Runaway Adopters are moving at speed with real enthusiasm and no governance underneath it.
- The Disciplined Innovators have high usage and managed risk, having worked out that tiered, controlled, and staggered adoption enhances trust, which, in turn, enables smoother transformation and innovation rather than inhibiting it.
Most boards believe they are the fourth. Often organisations are the first.
What the data actually shows
Harmonic Security helps organisations manage AI transformation at scale, giving it a view of observed behaviour rather than just survey responses. Its ‘Shadow AI Economy’ research, drawn from 22 million enterprise prompts, produced some striking findings.
The average organisation has around 240 AI tools in use. Close to half of that usage runs through personal accounts: no corporate control, no audit trail, and no data processing agreement behind it. Roughly, a quarter of files uploaded into AI tools contain sensitive data. Across 665 tools observed, just six applications accounted for 92% of data loss. The everyday tools are the problem because that’s where the real work goes.
Legal content made up the single largest share of sensitive exposure, ahead of code, financial data, and M&A material. We’re also experiencing more and more firms wanting to apply AI tools to traditional tools and documents – for instance, deal rooms as part of due diligence and M&A transactions – yet many NDAs and confidentiality terms don’t address such usage. Gartner, the business and technology research and advisory company, expects that by 2030 more than 40% of organisations globally will suffer a security or compliance incident caused by unauthorised AI tools. Based on the evidence, that forecast looks cautious.
Blocking has already failed
The instinct to prohibit is understandable. It also doesn’t work. If you block the sanctioned route, people don’t stop. They move to a personal account on a personal device, and a visible risk becomes an invisible one. You haven’t reduced your exposure. You’ve removed your ability to evidence it.
Regulators, counterparties and insurers aren’t primarily interested in your policy document. They’re interested in whether you knew what was happening and what you did about it. An organisation that can show observed usage, applied controls, and a record of intervention is in a very different position from one that can only show a prohibition nobody followed.
GDPR, contractual confidentiality, and EU AI Act
Under UK and EU GDPR, accountability isn’t a passive obligation. Article 5(2) requires organisations to demonstrate compliance with the data protection principles, not merely assert it. Where employees route personal data through unsanctioned AI tools, the controller can’t credibly discharge that duty. Shadow AI usage that bypasses approved systems creates real exposure on lawful basis, data minimisation, and international transfer grounds.
Contractual obligations add a further layer of risk. Uploading client data, deal information, or legally privileged material into a third-party AI tool (or more likely, a commonly used tool, such as a data room, which now includes AI tools) without a compliant data processing agreement is likely to constitute a breach of those obligations, regardless of intent.
In addition, the EU AI Act introduces additional extra-territorial considerations. General-purpose AI tools used in workplace settings may fall within its scope depending on how they are deployed, and the act imposes transparency and risk management obligations on deployers as well as providers. Organisations that can't demonstrate oversight of which AI tools their people are using will find it difficult to satisfy those obligations as the act's requirements come into full effect. In addition, certain tools (e.g. high-risk systems) will need to adhere to specific cybersecurity requirements, governing, for instance, keeping and auditing a SBOM or software bill of materials, identify each constituent element of an AI stack or technology application to identify any supply chain risk, while at the same time managing data access, governance, and security controls as well as potential bias and discrimination (that may result from the use of such tools).
Agents change the analysis
A chatbot answers a question. An agent is instructed to achieve a defined outcome or result independently and autonomously (which in itself comprises a series of 2 or more actions). It reasons about what to do, calls tools and external services, evaluates the result, and then decides its own next step, without a human approving each move. The business case is genuine. McKinsey, the management consulting firm, reports that agents can accelerate timelines by 40 to 50% and reduce costs by more than 40%.
But the incidents are no longer hypothetical: an AI coding tool at a major cloud provider deleted and recreated an environment, taking infrastructure offline for 13 hours; a rogue internal agent at one of the largest AI companies accessed and disclosed company and user data to staff without clearance. Cybersecurity company Snyk audited close to 4,000 agent skills and found critical security issues in 13.4%, including confirmed malicious payloads.
James Derbyshire, Vice President and Founding Executive, Harmonic Security, described a known adoption risk that is described as the lethal trifecta during the roundtable:
- Access to private, confidential, or personal data.
- Exposure to untrusted content.
- The ability to send data out.
Any two of those are manageable. All three together defeats the security model most organisations are still relying on. For legal teams, the harder question is: when an autonomous system acts, who is accountable for what it did, and can you demonstrate the controls that were supposed to prevent it?
What good governance looks like
None of this is an argument for slowing down. It’s an argument for building the rails while the train is moving. The organisations handling this well share a consistent set of foundations:
- A cross-business AI steering committee rather than a security-only working group.
- A full inventory of AI usage based on observed reality, not a questionnaire.
- A policy written to reflect what people actually do and defining the authority of those who are authorised to instruct agents.
- An innovation-led message that brings users with you.
- Guidance in the moment rather than blanket blocks.
- Continuous training because the tools change monthly.
- A defined control plane to manage agentic applications, coupled with human oversight of a dashboard, managed by a central operations team.
- Enforcement and controls that operate at the speed of the business.
Two capabilities underpin all of this: complete visibility of the AI in use, and active guardrails that steer people at the point of work. With both in place, AI governance stops being a compliance cost and starts producing something the wider business values: evidence of where AI is creating value, where the return sits, and which workflows carry genuine risk.
AI isn’t going back in the box, and no sensible organisation wants it to. The work now is making sure you can see what your people are doing with it, and prove it.
We’re looking forward to continuing this conversation with the sector alongside our partners at Harmonic Security as this space develops. If any of this resonates with where your organisation is right now, Browne Jacobson’s International Data, Privacy and Cybersecurity group is available to discuss your situation.
Contact
Philip James
Partner
philip.james@brownejacobson.com
+44 (0)330 045 1022