HR Leads Business Blog
Blogs and Announcements

HR Leads Business

Providing HR professionals with the latest industry news, best practices, and thought leadership to help navigate the ever-changing landscape of human resources.

The AI Tools You Don't Know Your Team Is Using


HR professionals are using AI heavily while getting almost no training in it, and that is where most organizations have real risk to their confidential information. Outside regulation is a smaller part of the story than people assume. We believe you should start with what you can control: discovering the AI tools your people use and what information those tools see.

At a recent HRCI: LIVE event, someone asked a version of a question we hear all the time:

"AI has been used to create powerful programs, often without meaningful government governance. How do you protect your organization around confidentiality and the risk of breach when there's effectively no external governance?"

We believe organizations should focus on things they can control. What’s most likely to expose confidential information is the AI use already happening inside your company that nobody knows about.

When software moved to the cloud, anyone with a credit card and a browser could start using a new tool, and technology departments discovered employees were using applications nobody approved, holding company information nobody had thought about. Technology teams call this phenomenon Shadow Tech. The companies that got through it in good shape began by finding out what was running on their networks, and only then started writing rules about it (policy-based controls) and configuring software to keep information safe (account-based controls). We see similar things with AI. Companies need to create policy-based controls and account-based controls now—not wait for the wheels of legislation to crank out guardrails.

What HRCI Data Shows

In late 2025, HRCI surveyed over 4,500 HR professionals for the 2026 State of HR report. What emerged was a picture of a workforce teaching itself.

Seventy-one percent of HR professionals use AI regularly, and 29% use it daily. Fifty-three percent say their company offers no AI training at all.

Fewer than one in five say what’s available inside their company is moderate or extensive. Only 10% were sent to an outside class, and just 8% were offered any kind of AI credential. Most of the teaching that does happen is homemade through in-house classes and published materials.

People are using these tools every day, but nobody has shown them how to use them effectively or safely. Our survey surfaced a few clear usage themes: HR professionals most often reach for AI to draft communications, look up answers, turn long meetings into usable notes, and summarize documents they don’t have time to read closely. Think about a draft memo describing a reorganization that has not been announced, or a question you can only get a useful answer to by pasting in the policy first. And 54% of respondents say they trust what AI gives back to them, which tells you these are not idle experiments. The most value is derived from AI when it is given company context. When you give it company context, you want safety.

Where the Real Risk Lives

You have a tool in daily use, trusted by the person using it, inside the department that handles the most sensitive information in the building, with no shared understanding of what is permitted or where the information goes once it leaves, or how to use it safely.

Outside research points the same direction. IBM’s Cost of a Data Breach 2026 Report found that two-thirds of the companies studied that had suffered a breach had no AI policy in place, and that incidents involving unapproved AI tools rose sharply over the prior year.

When good employees go around provided tools or strike out on their own, that tells you something useful about what you’ve offered. Sometimes the tools on hand can’t do what the job needs. More often there are no tools and no guidance, so curious people go find something that works.

Start with a List

We like to say that companies cannot protect information they don’t know is leaving. If that’s the crux, this part comes before anything else you might do.

Find out which AI tools your people are using and ask in a way that makes an honest answer safe. Welcome input without judgement. Mark the ones that touch employee or applicant information and note who can get to them. Then sit down with your technology and legal colleagues and decide what the approved option ought to look like for the work, at the volume you found them doing it.

Use this information to create policy-based controls, like AI responsible-use principles. Policy-based controls are necessary because not everything can be locked down through technology or account settings.

Also ask your technology team to configure settings in your AI software, and in the AI features embedded within your SaaS platforms, to keep your information secure while keeping you productive. These are account-based controls, ranging from the most basic—such as ‘Do Not Train Models Using Your Data’—to more advanced options, like permitting certain models to read from business systems without allowing them to write to them.

We don’t believe this slows organizations down. You can move quickly with policy-based and account-based controls while you wait for the legislative fog to clear. Prevention is cheaper than fixing things after an information or security incident.


Related Learning & Resources

HRCI 2026 State of HR report

IBM, Cost of a Data Breach Report 2026

HRCI Pro: AI in HR

HRCI Pro: HR Technology

Artificial Intelligence for HR Professionals

AI + HR Resource Library (free HRCI ENGAGE account required)

HRCI ONE

Share