Blog · Data custody

38% of US workers have put company data into personal AI

More than a third of US workers have put company information into a personal AI account their employer does not control, and most of them did not know it can break the law. That is the finding of a survey of 500 employed US adults commissioned by the California law firm Kolmogorov Law and run through Pollfish in July. The problem is rarely bad intent. People are trying to get their work done with the best tool they have.

What the survey found

  • 38% had entered at least one type of work information into a personal AI account.
  • 23% had pasted internal emails, memos or documents.
  • 12.4% had entered financial or sales figures, and 11.8% customer or client information.
  • 64.4% did not know that doing this can, in some circumstances, be illegal.
  • Only 35.8% said their employer had a clear, written AI policy.

Security teams see the same thing from the other side. In Darktrace's State of AI Cybersecurity 2026, a survey of 1,500 security professionals, 92% said they were concerned about AI agents in their organisations, 61% named sensitive data exposure as their main worry, and only 37% had a formal AI policy.

Why banning it rarely works

The instinct is to ban personal AI tools. It usually fails for a simple reason: the work still has to be done, and the personal tool is faster than the approved route, if there is an approved route at all. A ban without a better option moves the problem out of sight.

What helps is making the safe way the easy way:

  • A sanctioned tool that is actually good. If the approved option is slower or weaker, people will go around it.
  • Clear rules people can remember. What may go into AI, what may not, and who to ask.
  • Keys and logins that stay with the organisation. Not copied into a dozen browser tabs. See where your AI keys and logins should live.
  • Knowing what is sent. Most people have never been told what leaves their computer when they ask an AI a question. What actually gets sent to an AI provider explains it.

What Prism Labs is doing

We are building Prism Desktop, a workspace where people and AI agents work together, designed around that last list.

  • Your own accounts. Each agent signs in with its owner's own AI account; Prism never holds that login, and keys stay in the computer's keychain.
  • Only the prompt leaves. The app and your agents run on your machines, and only the prompt goes to the AI provider you chose.
  • A person decides. Agents propose; people approve a merge, an email or an install, and decisions are recorded.

It is not a legal compliance product, and nothing here is legal advice. It is a way to give people a good AI tool that keeps the organisation's data where it belongs. Early access is by waitlist. For the idea behind it, read what is data custody in AI.

Sources

Keep reading