What is actually happening inside companies right now
Strip away the specific tool and the pattern repeats across very different industries. A sales team at a vehicle dealership group used to wait on a monthly report to see which models, regions, or salespeople were driving margin. Now someone pastes the week's sales figures into a chatbot and has a dashboard-style breakdown in minutes. A financial services firm used to route a risk or compliance summary through an analyst who understood the underlying data and the regulatory context around it. Now a junior team member with a strong prompt and a spreadsheet produces something that looks, on the page, indistinguishable from what the analyst would have delivered a day later. Marketing teams do the same with attribution and campaign performance. Strategy teams do it with competitive summaries and market sizing.
None of this is a story about laziness or shortcuts. It is a story about a real productivity gain that most companies have not yet built the surrounding structure to handle safely. The person who gets good at this fast, often informally, sometimes formally, becomes the one everyone routes requests to. In more than one conversation this year, that person has ended up with a new title along the lines of "AI analyst," doing far more of the company's day-to-day reporting than their original job description ever described. That specific career pattern is not something a formal labor market study has measured yet, so it belongs in this article as an observed trend, not a cited statistic. But the underlying behavior it depends on, feeding company and client data into AI tools to produce fast output, is measured, and the numbers are larger than most leadership teams assume.
The part nobody centrally approved
This is where the productivity story runs into a governance problem. According to Wakefield Research's June 2026 survey of 1,250 office professionals across the United States, United Kingdom, Australia, and Japan, commissioned by PagerDuty, 88% of respondents have shared work-related information with a public AI platform. 34% specifically entered customer data. 31% shared financial information or confidential company documents and strategies. 66% of respondents said they use AI tools they believe violate their company's own policy (PagerDuty, 2026).
A separate report from Cyberhaven, published February 5, 2026, put a number on how often this happens rather than just whether it happens: 39.7% of all data movements into AI tools, including prompts and copy-paste actions, involved sensitive data, and employees entered sensitive information into an AI tool once every three days on average (Cyberhaven, 2026). This figure comes from Cyberhaven's own product telemetry across its customer base rather than an independent survey, which is worth naming plainly and is addressed further below.
Companies ordinarily strict about who can see which slice of client data have, without anyone deciding this on purpose, been routing that same information through a public AI tool with none of those controls attached.
Neither figure is industry specific. Both are aggregated across sectors, not measured separately for a vehicle dealership group's customer database or a financial firm's client file, so treat them as a general pattern rather than a claim about any one industry. But the pattern maps directly onto the concern raised by the executives in the conversations this article is responding to: companies that are ordinarily strict about who inside the building can see which slice of client or customer information have, without anyone deciding this on purpose, been routing that same information through a public AI tool with none of those internal access controls attached to it. This is not a hypothetical compliance question in any of the markets these industries operate in. In the United States, there is still no single federal privacy law, only a growing patchwork of state laws, led by California's CCPA and CPRA, alongside sector rules that already apply directly to the industries above: the FTC's Safeguards Rule under the Gramm-Leach-Bliley Act binds financial institutions, and specifically covers auto dealers that arrange financing, to strict rules on who may access a customer's financial information. In the European Union and the UK, GDPR sets one of the strictest global standards for exactly this kind of unauthorized data movement. And in South Africa, the Protection of Personal Information Act (POPIA) governs the same question directly. Across all three, it is the exact scenario these rules exist to prevent, arriving through a door nobody was watching.
Why the shareholders are right to be nervous, and why scaling back is the wrong lesson
The executives who pushed back, and the shareholders who went further and asked for AI use to be scaled down, are responding to a real risk. The data above supports their instinct. Where the instinct needs a correction is in the proposed fix. Pulling back on AI use broadly treats the tool as the problem. The World Economic Forum's Global Cybersecurity Outlook 2026, published in January 2026 around the Davos meeting, points at a more specific cause: only 40% of organizations conduct periodic security reviews before deploying AI, 24% do a one-time assessment, and roughly a third deploy AI systems into their operations with no security validation at all (WEF, 2026). 87% of surveyed leaders already identify AI-related vulnerabilities as the fastest-growing category of cyber risk, and data leak concerns rose to 34% of leadership security priorities this year, overtaking fears about adversarial AI attacks for the first time (WEF, 2026).
Read alongside Workiva's 2026 MidYear Executive Benchmark Survey, fielded with Ascend2 in May 2026 across more than 2,200 finance, risk, sustainability, and legal professionals (including 847 C-level executives and 367 institutional investors), in which 26% said an audit had caught an AI-generated error only after it reached the board or an external audience (Workiva, 2026), a clearer picture forms. The failure is not that people used AI to move faster. The failure is that almost a third of deployments happened with no review at all, and even where reviews exist, they are catching mistakes on the way out the door rather than before the door opens. Scaling back AI use addresses the symptom. It does nothing about the missing review step, which will still be missing the next time someone opens a new AI tool on a personal account, which is already happening: separate reporting shows 32% of ChatGPT use in workplace settings runs through personal, not company-managed, accounts. A retreat from AI does not close that gap. It just removes some of the productivity while leaving the actual hole exactly where it was.
The missing layer: a human who actually knows the data
The second concern raised by the shareholders in this conversation, that no one from the relevant department is checking the AI-produced numbers before they are treated as fact, is the more fixable of the two problems, and arguably the more urgent one. Every major AI system carries some version of the same disclosure: it can make mistakes, and its output should be checked. Most people are not checking it. A separate May 2026 survey of 2,127 US adults by Clear Spark Digital found that only 17.4% of AI users say they always verify the information AI gives them, a figure that drops to 14% among people who use AI daily. That gap has a real cost, and it is landing on the people above the person who produced the report: Founder Reports' April 2026 survey of 2,078 US workers found 57% of managers and above, 61% of VPs, and 62% of C-suite executives have personally fixed or redone a colleague's work after it relied too heavily on AI without enough checking. 44% of the same respondents said their company either has no clear AI policy or they are not sure whether one exists.
That is the actual shape of the risk the shareholders named. It is not that a junior team member learned to use a powerful tool well. It is that the report the tool produces is being treated, by everyone downstream of the person who made it, as a finished fact rather than a first draft that still needs someone with real domain knowledge to check the numbers, the assumptions, and the framing before it reaches a client, a board, or an investor.
The same discipline, one layer inward
Aingworth's own frameworks describe a related failure that happens externally, when an AI system fills a gap in what it knows about a brand with a plausible-sounding guess and states it with total confidence.
Brand Hallucination
Brand Hallucination is when an AI system confidently describes a brand inaccurately because the brand has not given it clear, consistent, verifiable signals to draw on. It happens specifically when a brand has not given AI systems clear, consistent, verifiable signals about itself.
What is happening inside these companies is not the same phenomenon; it has a different mechanism and a different audience. But it rhymes. In both cases, an AI system produces a confident, well-formatted answer, and the people receiving it treat the confidence as evidence of accuracy. The fix is also the same discipline in both directions: never treat an AI-generated claim, about your brand or about your own numbers, as settled until it has been checked against a primary source by someone qualified to know the difference. That is the standard Aingworth holds itself to when it publishes research: a statistic without a source and a date does not go on the page, and an external claim is a lead to verify, never a fact to quote, until it is confirmed. There is no reason that standard should stop at the edge of a marketing department. The full framework sits on the frameworks page.
Where AI reporting risk concentrates, by function
| Function | What commonly gets fed into AI tools | Where the exposure sits |
| Sales (e.g., a vehicle dealership group) | Customer names, deal terms, finance and insurance details | Individual customer records shared with a public tool outside dealership systems |
| Finance | Revenue figures, forecasts, unpublished results | Market-sensitive information before it is authorized for release |
| Risk and compliance | Client risk ratings, incident data, regulatory correspondence | Information a data protection or financial regulator specifically restricts internally |
| Investment | Portfolio positions, client holdings, due diligence notes | Client-level financial detail with strict need-to-know rules |
| Marketing | Campaign data, customer segments, performance numbers | Lower sensitivity, but frequently the least reviewed before publication |
| Strategy | Competitive analysis, pricing plans, unreleased plans | Information that is commercially sensitive even without being personal data |
Sources: PagerDuty/Wakefield Research, 2026; Cyberhaven, 2026; Workiva, 2026. Function categories reflect the industries discussed above; company names are not used.
What this does not prove
Several honest limits belong here.
- Cross-industry data. The survey data cited above is cross-industry and was not run separately for vehicle sales or financial services, so the specific numbers should be read as a general pattern, not a claim about any one sector.
- Vendor incentives. Some of these reports come from vendors who sell AI security or governance tools into the exact problem they are measuring, and Cyberhaven's figure specifically comes from telemetry across its own customer base, not a random-sample survey, which may skew toward companies already concerned enough about the problem to buy a monitoring tool for it. That is a real incentive and a real methodological limit worth naming. It does not automatically make the numbers wrong, but it is a reason to weight the independently fielded methodology (Wakefield Research ran PagerDuty's survey; Founder Reports and Clear Spark Digital are not security vendors) more heavily than any single vendor's own framing of how large the problem is.
- The "AI analyst" pattern is anecdotal. The promotion pattern described at the start of this article is an observed trend from direct conversations, not a labor market statistic, and it should be treated that way until someone runs the study.
- The verification-rate figure is general, not workplace-specific. The Clear Spark Digital figure measures general AI users, not specifically employees checking workplace reports, so it is used here as a directional indicator of how rarely people verify AI output at all, not as a workplace-specific figure.
We are not claiming AI causes data breaches on its own. We are saying the survey data shows verification and governance are lagging adoption, and that gap, not the technology, is what is producing the outcomes executives are worried about.
To be clear, this is not an argument against using AI for this work
Is the answer to stop letting sales, finance, risk, or marketing teams use AI to build these reports? No. The productivity gain described at the start of this article is real, and pulling it back does not fix anything the data above points to. The answer is a small number of specific, unglamorous controls, the same discipline a mature department already applies to a spreadsheet export or a CRM report, extended to cover this new channel too.
That means using a controlled enterprise AI account, not a personal one, so the data handling terms a company actually agreed to are the terms in force. It means a team knowing, in writing, what data is and is not allowed to go into a public AI tool, rather than finding out after the fact. It means checking the AI tool's own account settings, not just its marketing, since several major AI products default to using submitted data to help train future models unless an account owner turns that off, and a company's internal rule against sharing client data for third-party learning is worth nothing if the account setting says otherwise. None of this is new territory. It is the same access and confidentiality discipline most companies already run for client and customer data everywhere else, applied to the one channel that has been growing faster than anyone has been watching it.
What to do this week
- Write down which data classes may go into which tools, by name. 44% of employees report no clear policy exists or are not sure one does (Founder Reports, 2026); that ambiguity is doing a lot of the damage above.
- Move reporting work off personal AI accounts and onto tools with an actual data processing agreement. A third of workplace ChatGPT use already happens through personal accounts with no enterprise controls attached.
- Check the AI account's own settings, not just its marketing. Confirm whether submitted data is being used to train the model, and turn that off if company policy says client data does not get used for third-party learning.
- Name one accountable, qualified reviewer per report type, someone who understands the underlying data well enough to catch an error before distribution, not an auditor who finds it afterward.
- Treat every AI-generated report as a draft, not a finding, until a named person confirms it. State the method, the data pulled, and the date, the same discipline any credible research applies to itself.