£958 million. That is what Deloitte estimates British workers spend every year out of their own pockets on generative AI tools they use for work. Nobody asked them to. Nobody reimbursed them. And if you run a small business, a fair share of that money is probably being spent by your team.
Deloitte’s GenAI Workforce Survey is the largest of its kind in the UK, with responses from 25,000 workers collected between 7 May and 10 June 2026. Our view is simple: this is not mainly a story about cost. It is a story about where your business data is going while you are not looking.
What the Deloitte research actually found
Start with the headline. Deloitte puts annual personal spend by UK workers on GenAI for work at £958 million. That is people choosing to pay for a subscription because the tool helps them get through the day and their employer has not provided one.
Then the uncomfortable part. Nearly a third (31%) of GenAI users say they use it without their employer’s knowledge. Almost one in ten UK workers has used an AI tool that their employer bans or would disapprove of. Those are not people trying to cause harm. They are people trying to clear an inbox faster.
If you have a team of eight, treat those figures as a prompt for a conversation rather than a prediction. The survey cannot tell you what is happening in your office. It can tell you the odds are not zero.
Why a personal account is a different product
When someone uses a free or personal plan for work, the business data they paste in goes through a product built for individuals. The terms differ from the business version of the same tool, and the difference matters.
Take ChatGPT as one example. OpenAI states that business plans, including Business and Enterprise, do not use your business data to train its models by default. On consumer plans, conversations may be used to improve the models unless the user opts out in their data settings. You can read OpenAI’s own wording on its enterprise privacy page. Other vendors draw similar lines, and the details change, so check the current terms of whichever tool your team uses rather than relying on us or anyone else’s summary.
Two caveats, because we would rather name them than hide them. First, “not used for training” is not the same as “not stored”. Business plans still process and retain conversations for a period. Second, a business account does not make a bad habit safe. Pasting a customer’s full record into any tool you have not thought about is still a decision someone should have made on purpose.
The legal point owners tend to miss
If a member of staff pastes customer names, emails or notes into an AI tool, that is personal data being processed on behalf of your business. The Information Commissioner’s Office is clear in its guidance on AI and data protection that there is no AI exemption from data protection law. You are the one responsible for that data, whichever login was used to share it.
That is the real risk with the £958 million. It is not the money. A £20 subscription is trivial. A customer list sitting in a personal account that you cannot see, cannot audit and cannot close when that person leaves is not trivial at all.
What we would tell a client to do this week
We would not start with a ban. A ban is the thing that produces the 31%. When people are told no and the tool still saves them an hour, they carry on quietly. Here is the sequence we would suggest instead.
- Ask, without blame. At your next team meeting, say you would like to know which AI tools people already use for work and what for. Make it clear nobody is in trouble. You will learn more in ten minutes than from any policy.
- Pick one approved tool and pay for it properly. If most of the team already likes one assistant, put the whole team on its business plan. You are buying the data terms and the admin controls as much as the software. Check the current price per user on the vendor’s own page before you decide, because it changes often.
- Write down three rules on one page. What can go in (public information, your own drafts), what cannot (customer personal data, bank details, anything under a confidentiality agreement) and who to ask when unsure. Three rules people remember beat a twelve page policy nobody reads.
- Move the tool onto a company login. Use a work email address so you can switch someone off when they leave. Personal logins stay with the person.
- Review it after a month. Ask what is working and what people still go around you to get. The gaps tell you what to buy next.
Notice what is not on that list: buying more AI. The point is to bring existing use out into the open and put it on terms you have chosen.
The trade-off to be honest about
Paying for business seats costs money you are not spending today, and it will not stop every pasted customer record. Some people will still use a personal account on their phone. Rules without a conversation behind them drift quickly. What a business plan gives you is a sensible default, an off switch and a paper trail, and those are worth having. They are not a guarantee.
There is also a benefit worth saying out loud. Staff who are paying for these tools themselves are telling you something: the tools are useful enough that they will spend their own money. That is a signal about where your processes are slow, and you can use it.
Where this leaves a small business
Deloitte’s number is big because it is the sum of thousands of small decisions made by people who were trying to do their jobs better. Your team is probably in there somewhere. The sensible response is not alarm and not a crackdown. It is to find out, pick a tool, set three rules and move the use onto an account you control.
If you would like help working out which tools fit your business and what a sensible one-page policy looks like, talk to us about a free consultation. And a question for the comments: do you know which AI tools your team is using today, or would you be guessing?