MiAI Law

First published in Herald Sun: Two-thirds of Aussies are hiding their AI use at work

New research has found more than two-thirds of Australians are secretly using AI at work in breach of company policy, with experts warning the practice could lead to them getting sacked.

More than two-thirds of Aussies are using AI tools at work in breach of company policy, with many hiding their usage to avoid scrutiny and judgment from others.

Exclusive research reveals workers are deliberately breaking office AI rules, with almost half saying they would rather use the technology without telling anyone than risk being told it’s prohibited.

But the consequences of using unauthorised AI can be severe, with experts warning workers caught out could have their jobs terminated.

Despite this, most office professionals believe they understand how to use AI for their job better than the teams managing the technology, with three-quarters of Australians complaining their employer’s AI restrictions are limiting their career growth, according to the research from PagerDuty.

Justifying unauthorised AI

Given the productivity gains associated with AI, it was not surprising so many workers were using it – even without their company’s approval, said lawyer Laina Chan, founder and chief executive officer of AI risk management system MiAI Law.

“Many important innovations enter institutions because practitioners identify a better way of working before formal policies exist,” Ms Chan said.

“In many organisations, if employees ask for permission to use emerging technology, the answer is often ‘no’ because decision-makers themselves do not yet understand the technology.

“As a result, innovation can become trapped.”

But Ms Chan said innovation and productivity did not justify every unauthorised use of AI and there was “a world of difference between… responsible experimentation and reckless concealment.”

“The more important question is not whether someone sought permission first,” she said.

“It is whether the use was responsible, whether confidentiality was maintained, whether outputs were verified and whether there was transparency once the benefits and risks became clear.”

She said workers using unauthorised AI could put their company at risk of data leakage, inaccurate reporting and poor governance.

“Organisations cannot manage risks they cannot see,” she said.

“When employees operate outside approved systems, organisations lose visibility over what tools are being used, what data is being processed and how outputs are being generated.”

False confidence

Ms Chan believed workers typically over-estimated their expertise in AI and said while most Australians could use the technology, many did not understand how it worked, its limitations or the associated risks.

“Employees often know enough to use the tool but not enough to understand where it can fail,” she said.

“Many users do not appreciate that large language models are probabilistic systems.

“They generate likely outputs rather than verified facts. They may also struggle to distinguish fluency from accuracy.

“A confident sounding answer can still be completely wrong.”

Depending on the nature of the unauthorised AI use, worker sanctions could include additional training, warnings, disciplinary action or even dismissal, Ms Chan said.

“Employees should remember that many organisations view the disclose of sensitive information into external AI systems in the same way they would view disclosure to an unauthorised third party,” she said.

Breaching confidentiality

PagerDuty vice president Callum Eade said employer concern about AI use was justified, with the research showing two in five workers had entered sensitive customer data into public AI tools and more than a quarter had disclosed confidential documents or strategies.

But like it or not, Mr Eade said AI was revolutionising Australian workplaces and was keenly embraced by workers who recognised its benefits.

Rather than use AI covertly, he encouraged workers to demonstrate to their employer how the technology could be used to the company’s advantage and seek permission to further their AI skills.

“This has to be very much about the employees working hand-in-hand with leadership in the organisation,” Mr Eade said.

“(AI) is our future. But we are going to have to drive this (workplace adoption of AI) ourselves – it’s not necessarily going to be led by the top (management).”

Risks too great

Technology communications consultant Christos Tzortzis said using unauthorised AI was not worth the risk.

Mr Tzortzis said part of his work involved analysing cyber security threats – many of which came from worker use of unauthorised technology.

“If you’re using ChatGPT and you’re not entering sensitive or confidential information then maybe it’s OK,” said Mr Tzortzis, who has a decade of experience in his field.

“But if you’re dealing with client information and you’re putting sensitive contact details or whatever into one of the AI models that is not locked (secure within the workplace) then it’s just not worth it.

“You’re opening yourself up to a whole range of issues, whether it’s legal action, it’s getting fired or it’s reputational – either way, it’s not worth the risk.”

Mr Tzortzis believed all companies needed clear policies that allowed for the safe use of AI, especially given the research showed most workers would “use it anyway”.

The secrets we keep: hiding AI use at work

– 70 per cent of Australian office professionals use AI tools or services at work despite not being allowed to under company policies.

– 75 per cent think they understand how to use AI for their job better than the teams managing AI.

– 36 per cent who have used AI for work hide their AI use to dodge scrutiny from their superiors.

– 45 per cent would rather use AI for work without telling anyone than risk being told they cannot use it.

– 40 per cent have entered customer data or information into public AI tools and 28 per cent have input financial information or disclosed confidential company documents or strategies.

– 53 per cent have faced formal consequences, such as warnings or disciplinary action, due to unauthorised AI use.

Please see the original article: Here