Your team is
already using it.
The only question is how.
Most organizations are still deciding whether to allow AI at work. That decision was made for them some time ago, by the people who work there, one useful afternoon at a time. The interesting question is no longer whether it is happening. It is what is being pasted, into whose systems, and under what terms.
This page is the evidence rather than the enthusiasm. What employees actually do, what the tools actually do with the input, what has actually gone wrong in court, what the productivity research actually found, and the short list of things that are legally required of a Puerto Rico business. It ends with a policy starter you can fill in this week.
What people are
actually doing.
↳ read the denominators carefully, they matter
The best evidence available is a 2025 University of Melbourne study with KPMG covering 48,340 people across 47 countries, with an employee sub-sample of 32,352. It is academically led, nationally representative, and has the least commercial interest of anything in this field. Fieldwork ran November 2024 to January 2025.
Bans are associated with twice the risky behavior of no policy at all.
In the same study, among surveyed AI users, policy-contravening use was reported twice as often where AI was banned as where respondents said no policy existed: 67% where generative AI was banned outright, 56% where a policy existed, and 33% where there was no policy at all. This is a cross-sectional survey, so the association does not establish that the ban caused the difference.
Read that carefully, because it is not an argument against governance, and it is not proof that bans backfire. The study did not randomize policies and cannot tell you which way the causation runs: organizations that already had a problem may have been likelier to ban. What it does say is that a ban is not by itself evidence of lower risk, and the mechanism people usually propose (a rule does not remove the tool, it removes your visibility of the tool) is a hypothesis this data is consistent with rather than one it demonstrates.
IBM and Ponemon’s Cost of a Data Breach 2025, published 30 July 2025 and covering 600 breached organizations, found that one in five breaches involved shadow AI, that only 37% of organizations had policies to manage or detect it, and that organizations with high shadow-AI presence saw roughly $670,000 in additional average breach cost. The denominator is one in five breached organizations, not one in five companies. Note also that the 2026 edition contains no shadow-AI findings at all, so nothing here should be attributed to it.
Microsoft’s Work Trend Index reported that 78% of AI users bring their own AI tools to work. That is 78% of AI users, not of employees, and it is a 2024 snapshot that has not been refreshed in the 2025 or 2026 editions.
A useful counterweight: Netskope’s 2026 telemetry shows personal AI app use falling to 47% of generative-AI users from 78%, with organization-managed accounts rising from 25% to 62%. Source code accounts for 42% of their observed data-policy violations. Their sample is their own customers, which means already-governed organizations, so read it as a direction of travel rather than a population estimate.
You will hear about Samsung banning ChatGPT after employees leaked source code. The underlying report is single-sourced to one Korean newspaper article, and a Samsung official told that reporter it was difficult to confirm because it was an internal company matter. We are not going to repeat unconfirmed specifics.
What is on the record makes the same point without them: Samsung restricted generative AI on company devices in May 2023, and had built its own internal model within seven months. That is the actual lesson. The serious response to shadow AI is not prohibition, it is provision.
What happens to
what you paste.
↳ as of August 2026, from each vendor’s own pages
Two corrections before the table, because they undo most of what people believe. Paid is not private. The line that matters is consumer versus commercial, not free versus paid: ChatGPT Plus and Pro, and Claude Pro and Max, are consumer tiers. And an opt-out may not remove data from training already completed or already underway. Check each vendor’s current terms rather than assuming. Anthropic states the point most plainly of anyone: your data will still be included in model training that has already started and in models that have already been trained.
| Tier | Trains on your input by default? | Where the setting lives | Retention |
|---|---|---|---|
| ChatGPT Free / Plus / Pro | Yes | Settings › Data Controls“Improve the model for everyone” | Until deleted, then a 30-day purge |
| ChatGPT Business / Enterprise / Edu / API | No | Administrator | Workspace policy |
| Gemini consumer | Yes | Gemini Apps Activitymyactivity.google.com/product/gemini | 18 months by default. 72 hours even when the setting is off, and up to 3 years if a chat was human-reviewed |
| Google Workspace / Vertex | No | Administrator | Administrator-set |
| Meta AI | Yes, and it feeds ad targeting | No opt-out exists | Meta’s consumer documentation does not give a single deletion or retention period covering every downstream use; check the current privacy centre |
| Claude Free / Pro / Max | Depends on a choice made in 2025 | Settings › Privacy“Help Improve our AI models” | Standard deleted consumer chats removed from back-end systems within 30 days if off, 5 years if on. Exceptions: policy-violation records up to 2 years, safety-classifier results up to 7 years, feedback data up to 10 years |
| Claude Team / Enterprise / API / Bedrock / Vertex | No | n/a | Enterprise default retention is indefinite |
| Consumer Copilot | Yes, in some markets | Profile › Privacy“Training on conversation activity” | 18 months |
| Microsoft 365 Copilot (Entra) | No | n/a | Exchange and Purview |
Compiled from each vendor’s own policy and help pages, August 2026. These change quickly. Several of the pages consulted had been revised within days, so treat this as a snapshot and re-check the vendor’s page before relying on any row.
Anthropic, August 2025.
On 28 August 2025 Anthropic announced a change to consumer data handling, giving users until 8 October 2025 to make a choice. Retention moved to 30 days if training is off and five years if it is on, and the scope covers chats and coding sessions, meaning Claude Code as well. Commercial tiers were excluded.
Anthropic’s own two documents describe the mechanism differently: the privacy policy frames training as happening unless you opt out, while the help centre frames it as training only when you choose to allow it. We are not going to assert a flat default when the vendor’s own pages disagree. The mechanism is what matters: users were required to make a choice once, and that choice now persists silently.
The reason this is the proof case rather than a complaint: a vendor widely associated with no-training commercial commitments changed its consumer data terms with about six weeks of notice. If it can move there, it can move anywhere, which is why a policy that names approved tools is worth more than a policy that names a trusted brand.
Meta has no opt-out. Its AI terms, effective 13 May 2026, state that Meta uses your interactions with AIs to personalize your experiences and ads, and improve AI at Meta. The UK and European exclusion is real and verifiable structurally, because Meta’s separate UK and European terms omit the advertising clause.
Turning Gemini activity off does not mean nothing is kept. Seventy-two hours are retained regardless, and human-reviewed conversations persist for up to three years.
On OpenAI, submitting feedback donates that entire conversation even when you have opted out of training. Also note the rename: what used to be ChatGPT Team is now ChatGPT Business.
Zero-data-retention does not necessarily mean nothing at all is retained. Anthropic’s current ZDR documentation says covered inputs and outputs are not stored except where required for legal or abuse-control purposes, while safety-classifier results may still be retained. It does not describe a universal copy of prompts and outputs. Confirm the exact product and agreement rather than reasoning from the label. Anthropic · ZDR scope
The defaults arrive
quietly.
↳ and three of the famous scandals never happened
This section is as much about reading the news as about AI. Three of the most-shared “vendor secretly switched on AI training” stories were substantially false, and knowing which ones is more useful than any policy clause, because the same shape of story will run again next quarter.
Microsoft 365, Nov 2024
The claim that Microsoft had silently switched on AI scraping of Word and Excel documents originated in an anonymous Tumblr post and was run as fact by mainstream outlets.
Microsoft, 27 November 2024: “Microsoft does not use customer data from Microsoft 365 consumer and commercial applications to train large language models.” The setting in question had been on by default since April 2019 and governs Editor, PowerPoint Designer and Translator.
Gmail and Gemini, Nov 2025
Google, 22 November 2025: “we have not changed anyone’s settings, Gmail Smart Features have existed for many years, and we do not use your Gmail content for training our Gemini AI model.”
Three false premises inside one viral claim, which is roughly the hit rate in this genre.
WeTransfer, July 2025
The alarming clause was scoped to content moderation, which almost no coverage mentioned. WeTransfer’s response: “We don’t use machine learning or any form of AI to process content.”
They rewrote the clause within about 48 hours anyway, which tells you how these cycles resolve regardless of the facts.
It is not training. It is defaults and friction. The durable pattern across every genuine case is a setting switched on for you, with an opt-out that is harder to reach than it needs to be. And regulatory intervention in these specific consumer-training-default cases has been thin: the UK’s ICO and Ireland’s DPC are the two that moved on the cases described below. That is a statement about this narrow set of cases, not about AI and privacy enforcement generally.
Slack
The 2024 panic was wrong: the models were classical machine learning for channel recommendations, search ranking and emoji suggestions, and the pre-May-2024 page contained no occurrences of the word “generative.”
What never got fixed is the part nobody covered. Global-model training is on by default, and opting out still requires a workspace owner to email feedback@slack.com with the subject line “Slack Global model opt-out request.” There is no self-serve toggle.
The clearest “shipped before the terms” case on record. The setting was enabled by default on 18 September 2024, before the updated user agreement dated 20 November 2024 took effect. The UK’s ICO intervened and LinkedIn suspended UK training on 20 September 2024.
It was extended to the EEA, Switzerland and the UK effective 3 November 2025, again on an opt-out basis. LinkedIn’s own wording: “Opting out does not affect training that has already taken place.” The path is Settings › Data Privacy › Data for Generative AI Improvement.
Grammarly
The clearest illustration of the whole pattern, with no scandal attached. Free, Premium and single-user Pro are on by default. Business, Enterprise and Education are off by default.
Same company, same product, opposite default, decided entirely by which contract you are on. That is the consumer-versus-commercial line drawn in a single vendor.
Meta announced on 1 October 2025 that from 16 December 2025, AI chat interactions would feed ad and content targeting. Keep that separate from model training, because they are different things. Sensitive categories are excluded and there is no dedicated opt-out. Thirty-six advocacy organizations asked the FTC to investigate on 30 October 2025.
X and Grok ship a default-on training toggle with a web-only opt-out. This is the one place with real enforcement pressure: Ireland’s DPC opened a statutory inquiry on 11 April 2025, with no outcome yet.
HubSpot introduced pooled data sharing on an opt-out basis in July 2026 and reversed it in four days. Its CTO: “Sorry. You are right. We made a mistake and are reversing that decision.”
AI notetakers carry a risk that is not about you. Privacy class actions against Otter.ai were consolidated on 22 October 2025 in the Northern District of California, alleging recording of non-customers on calls. There has been no ruling. The distinctive exposure of a notetaker is everyone else who joined the meeting and never agreed to anything.
And two that were genuinely resolved: Zoom restructured its terms in August 2023 and the current terms still state that Zoom does not use your customer content to train its own or third-party AI models, unchanged three years on. Adobe rewrote its terms in June 2024 after a clause about accessing content, which was in fact about abuse moderation; a separate, older content-analysis setting remains on by default.
When it goes wrong,
it goes wrong like this.
↳ four cases, each usually told incorrectly
There is now a public database of court cases involving AI-fabricated citations. It listed 1,890 cases as of 15 August 2026, 1,314 of them in the United States, growing from 16 in 2023 to 59 in 2024, 830 in 2025 and 985 in the first seven and a half months of 2026. Its maintainer describes it as an undercount by design.
Mata v. Avianca
The canonical case, and the popular version gets two things wrong. The penalty was $5,000 imposed jointly and severally on both lawyers and their firm, not $5,000 each. And the sanction was not for using AI.
Judge Castel: “there is nothing inherently improper about using a reliable artificial intelligence tool for assistance. But existing rules impose a gatekeeping role on attorneys to ensure the accuracy of their filings.” He found bad faith based on acts of conscious avoidance and false and misleading statements to the court. The sanction was for the cover-up.
The line worth carrying into a business context: “The client may be deprived of arguments based on authentic judicial precedents.” The lawyers were not disbarred or suspended.
Lnu v. Blanche
The strongest 2026 case, and much harsher than Mata: $2,500 each, a six-month suspension, a two-year AI-disclosure certification requirement for the entire firm, and a State Bar referral. The court tied the severity to “this repeated failure of candor.”
The holding is the single most useful sentence in this whole area, and it generalizes well beyond law:
“the rules are not violated at the point of research and drafting, but at the point of signing and filing.”
Nobody is in trouble for asking a model a question. They are in trouble for putting their name on the answer.
Moffatt v. Air Canada
A customer relied on the airline’s chatbot describing a bereavement-fare policy that did not exist, and won C$812.02 in total.
Two corrections. The famous line about the chatbot being a separate legal entity is not a quotation of Air Canada. It is the tribunal member’s own paraphrase, explicitly flagged with “In effect,” before he called it a remarkable submission. And this was probably not an AI hallucination at all: the tribunal noted that Air Canada provided no information about the nature of its chatbot, so it may have been a scripted bot.
The genuinely useful line is the other one. Air Canada “does not explain why customers should have to double-check information found in one part of its website on another part of its website.” If your tool says it, you said it.
Salesloft Drift
The best small-business example, because nothing here required anyone to be careless with a chatbot. Attackers stole OAuth tokens from Drift, an AI sales chat agent, and used them to export Salesforce data from hundreds of companies, including Cloudflare, Palo Alto Networks and Zscaler.
Google Threat Intelligence assessed the intent as harvesting credentials: AWS keys, passwords and tokens that people had pasted into support tickets. Cloudflare found 104 of its own API tokens sitting inside customer support cases.
This was not a Salesforce breach. It was an AI add-on with broad permissions, which is the shape of most AI risk in a small organization: not the model, the integration.
Exposure is not the same as attack. In January 2025, researchers found a DeepSeek ClickHouse database open with no authentication at all, containing more than a million log lines including chat history and API keys. Nobody hacked it. It was simply left open.
And a vulnerability is not a breach. The Microsoft 365 Copilot issue known as EchoLeak, published June 2025 and rated critical, was a zero-click flaw fixed server-side with no action required from users. Microsoft’s records show it was never exploited. It is worth knowing for the shape of the risk, not as an incident.
Does it actually
work?
↳ yes, unevenly, and not where you would guess
The honest answer has a shape, and the shape is more useful than any single number. Gains are best documented for less-experienced people on bounded, routine tasks. The evidence is weak or negative for experts working in complex systems they already know well.
The support-desk study
Brynjolfsson, Li and Raymond studied 5,172 customer-support agents and found a 15% average increase in issues resolved per hour.
The published version describes a skill gradient rather than a single headline: less experienced and lower-skilled workers improved in both speed and quality, while highly skilled workers saw modest speed gains and minor quality declines. If you have seen a much larger figure quoted for novices, that came from the earlier working paper.
The one that should worry you
METR ran a randomised controlled trial with 16 experienced open-source developers across 246 real tasks, in codebases they knew well.
They forecast a 24% speedup. They were 19% slower. Afterwards, they still believed they had been 20% faster. For scale, economists asked to predict the result guessed 39% faster and machine-learning experts guessed 38%.
The finding to take from this is not that AI does not work. It is that the gap between how fast AI feels and how fast it is can run in the wrong direction, precisely where people are most confident. METR’s own caveat is worth carrying: they do not claim their developers or repositories represent a majority or plurality of software development work.
In a study of 758 consultants across 18 tasks, participants using AI completed 12.2% more tasks and worked 25.1% faster on work that sat inside the model’s competence. On a task deliberately placed outside it, AI users were 19 percentage points less likely to reach the correct answer.
That is the whole management problem in one result. The tool does not announce which side of the line a task falls on, and the failure mode on the wrong side is not visible slowness, it is confident wrongness. Which is exactly what the human-review clause in your policy is for.
Supporting evidence: a 2023 study in Science of 453 professionals on mid-level writing tasks found average time down 40% and quality up 18%, with the gap between weaker and stronger writers narrowing. A GitHub Copilot trial found 55.8% faster completion of an HTTP-server task, though its authors were from Microsoft and GitHub. And Danish administrative data found precise null effects on earnings and hours, ruling out effects larger than 2% two years after ChatGPT launched, with employers absorbing AI through task reorganisation rather than pay.
If someone tells you 95% of AI pilots fail, ask them for the report. The paper that figure comes from is no longer publicly posted, was never peer-reviewed, and its methodology was contested while it was up. It is the single most-shared statistic in this field and it should not be in your deck.
What the law
actually requires here.
↳ less than you fear, in narrower places
Start with the finding that saves most of the anxiety. As of 15 August 2026, we found no general cross-sector Puerto Rico statute imposing AI-specific duties on a private company simply because it uses AI. That is not an absence of evidence: the complete indexes of all 185 laws of 2025 and all 174 laws of 2026 were read to confirm it. No AI-specific PR statute obliges an ordinary business to disclose AI use, run a risk assessment, conduct a bias audit, or take on deployer obligations. Generally applicable law still governs what you do with a tool, whatever the tool is: consumer protection, privacy, employment, discrimination and contract law all continue to apply.
Two things do bind you, though, and one of them is two weeks old.
Ley 163-2026
Since 2 August 2026, Puerto Rico’s right-of-image law expressly covers likenesses and voices generated, cloned, simulated or altered by generative AI. Unauthorized commercial, mercantile or advertising use of an identifiable person’s AI-generated or cloned likeness may fall inside Ley 139-2011 as amended by Ley 163-2026, which provides statutory damages of $750 to $20,000 per violation, and up to $100,000 where the conduct is intentional. Consent and the statutory exceptions are essential elements: a documented authorization changes the analysis entirely.
Add injunctive relief and attorney’s fees, and note that heirs may sue for 25 years after death. The exceptions cover news, public interest, satire and parody, and incidental appearance. Unauthorized advertising use is the exposure to plan around.
For a studio or a marketing team, this is the one to internalize. It arrived quietly, it is in force now, and it reaches a common commercial use of generative AI.
$750–$20,000 per violationLey 111-2005
Breach notification. Notify affected individuals “de la manera más expedita posible,” and notify DACO within a non-extendable ten days, after which DACO announces publicly within 24 hours. Fines run $500 to $5,000. The individual-notice analysis turns in part on whether the covered data was unencrypted or insufficiently protected, so not every security incident produces the same duty.
The reason it belongs on an AI page: covered personal information includes system credentials, and employment evaluations. If someone pastes a performance review or a set of credentials into a public tool and that tool has an incident, you are inside this statute.
$500–$5,000 · 10 days to DACOFTC Section 5 applies in Puerto Rico. Two of its live positions matter here. The FTC has warned since February 2023 to keep AI claims in check, and in February 2024 published guidance that quietly changing your terms of service could itself be unfair or deceptive. Both remain live as of August 2026, as does its Operation AI Comply sweep from September 2024.
And the one most relevant to anyone doing marketing: 16 CFR Part 465, effective 21 October 2024, bans fake reviews and testimonials and expressly covers AI-generated ones, on the reasoning that AI tools make it easier for bad actors to pollute the review ecosystem. Generating a testimonial is not a grey area.
Two useful negatives. Ley 116-2026 requires disclosure before an AI interaction and a right to a human, but it binds only Puerto Rico government agencies and public corporations. Private businesses are not covered, though it is a clear signal of legislative direction and it matters if you contract with the government. And California’s SB 942, as amended by AB 853, in force since 2 August 2026, binds only providers with more than a million monthly users, meaning the AI vendors themselves rather than a studio using their tools. AB 853 is what sets that date; SB 942’s original bill record reads earlier and is not the operative one.
The EU AI Act’s Article 50 transparency duties began to apply on 2 August 2026, even though the AI Omnibus in force from 27 July 2026 delayed the high-risk obligations to December 2027 and August 2028. Note the transition: Regulation 2026/1744 gives certain existing systems transitional treatment on the machine-readable marking duty through 2 December 2026, so which duty and which cohort you mean matters. Article 50 reaches a Puerto Rico studio only if it places a system on the EU market or its output is used in the Union.
Colorado rewrote its AI law in 2026. SB26-189, signed 14 May 2026, repealed and replaced the 2024 Act; the new duties apply to employment decisions made on or after 1 January 2027, and the Attorney General’s implementing rules are still in draft with comment open to 26 October 2026. A federal court order currently bars the Attorney General from opening enforcement actions or investigations while a constitutional challenge proceeds. Any tracker still saying “effective June 30, 2026” is out of date.
New York City’s Local Law 144 has been enforced since July 2023: an independent bias audit valid for one year, a published summary including impact ratios, and notice at least ten business days before use. It covers screening, not just final decisions, and reaches remote roles tied to an NYC office. Illinois has required notice and consent for AI analysis of recorded video interviews since 2020, and since 1 January 2026 it is a civil rights violation there to use AI with discriminatory effect, to use ZIP codes as a proxy for protected classes, or to fail to notify employees of AI use. Texas, also from 1 January 2026, prohibits developing or deploying AI with intent to discriminate, and states expressly that disparate impact alone is not sufficient to demonstrate that intent.
And the EEOC framing that matters most. Both EEOC AI guidance documents have been removed and now return 404. An April 2025 executive order directs agencies to deprioritize enforcement of statutes to the extent they include disparate-impact liability, citing Title VII by section number. But an executive order is enforcement policy. It does not repeal Title VII, the ADA or the ADEA, and disparate-impact liability is statutory. Private plaintiffs are entirely unaffected. The risk did not disappear. It moved from regulators to plaintiffs. The EEOC’s $365,000 iTutorGroup settlement, over software programmed to auto-reject women over 55 and men over 60, remains citable and its press release is still live.
On Mobley v. Workday, which you will hear about: no court has found that Workday discriminated against anyone. Every ruling so far is procedural, about whether claims can proceed and who gets notified. A preliminary nationwide ADEA collective was certified in May 2025 for applicants aged 40 and over, an interlocutory appeal was denied in July 2026, and a class-certification motion is due in September 2026. The lesson is not about Workday. It is that using a vendor’s tool does not move the legal risk off you, and it may pull the vendor in alongside you.
A policy your team
might actually follow.
↳ nine elements, one afternoon
Start from the evidence at the top of this page: the organizations with the least risky behavior were not the ones with the strictest rules. A policy that people route around is worse than no policy, because it removes your visibility without removing the behavior. So write the shortest document that answers nine questions, name an owner, and revisit it quarterly.
One practical note before the list: a policy naming which tools are allowed is only as good as the control that enforces it. On Google Workspace, third-party applications are permitted by default until you say otherwise, and on Microsoft 365 the consent policy is worth confirming rather than assuming. The admin-console side of this is item four here →
Each element below is anchored to a subcategory of the NIST AI Risk Management Framework, which is voluntary and not law. We include the anchors because they give you a defensible structure and a vocabulary your auditors and larger clients already recognize.
An approved-tools list
Which tools are allowed, for what, and who can add one. This is the clause that does the most work, because it is what makes the rest enforceable and what survives a vendor changing its defaults.
Which laws reach you
Write the short list for your actual footprint. For most PR businesses that means the right-of-image statute, breach notification, FTC Section 5, and anything sector-specific.
What may never be pasted
A plain data-classification line. Client identifiers, credentials, unreleased financials, health information, anything under NDA. Name the categories in the words your team actually uses.
A named owner
One person accountable for the tools list and the questions, with an executive sponsor. Not a committee, and not “IT” in the abstract.
Training that is not a slide deck
Thirty minutes on what the tools do with input, what the jagged frontier means for their own work, and how to ask for a tool rather than route around the list.
Human review before anything ships
The Lnu holding, generalized: nothing goes to a client, a regulator or the public without a named person having checked it. That is where the liability attaches.
How to report a problem
A no-blame route for “I pasted something I should not have.” You want to hear about it in an hour, not in a deposition.
Vendor and contract clauses
What your AI vendors may do with your data, what your clients’ contracts already say about it, and who is notified when either changes. Salesloft Drift is the reason this one is not optional.
How a tool gets retired
Accounts closed, data exported or deleted, integrations revoked. The AI equivalent of offboarding, and it is skipped just as often.
The NIST AI Risk Management Framework was released in January 2023 with a generative-AI profile added in July 2024, and NIST’s own site now states that it is being revised as part of the White House AI Action Plan. That plan directs NIST to revise the framework to eliminate references to misinformation, diversity, equity and inclusion, and climate change. The AI Safety Institute was renamed CAISI in June 2025.
We are pointing at the GOVERN subcategories because they are a stable, sensible skeleton for a small organization, not because they carry legal force. If the numbering shifts under a revision, the nine questions above still need answering.
Three things, in order.
1. Ask your team, without consequences attached, which tools they already use. You cannot write a useful approved-tools list against an imagined baseline, and the evidence at the top of this page suggests you will be surprised.
2. Check the two vendor settings that matter most for whatever they name: whether the tier is consumer or commercial, and where the training toggle sits today.
3. Write the nine answers on one page. Page 12 of our workbook is that page, laid out to be filled in by hand and taken into a meeting.
This is education, not legal advice. Mutiny Labs is a technology studio, not a law firm. Legal statements here are as of 15 August 2026 and several of the items described are weeks old or actively being revised. Vendor behavior in particular changes without notice, and several of the pages consulted for the table above had been revised within days. Confirm anything you intend to rely on with your own counsel, and re-check the vendor’s own page before you act on a row.
