Deloitte surveyed 25,000 workers on shadow AI: the value depends on what the tools can reach

Generative AI saves the UK workforce 70 minutes a week on average, and the number is low because most of the tools cannot reach the company's systems or data. There is a wave of application rebuilding and replacement going on. At Eli5, we review articles about software modernization every week to find real value for CTOs, PMs, and POs who have to deal with the modernization of legacy software.
Deloitte asked 25,000 UK workers how they use generative AI. A third of the users do so without their employer knowing, and workers spend an estimated £958 million a year of their own money on the tools. We read the spending and the time saved together. The spending shows that workers want the technology enough to pay for it themselves. The time saved shows what the technology delivers when it can reach nothing inside the company. In the same month, 404 Media reported that contractors read real ChatGPT conversations to improve OpenAI's models, which shows what can happen to company data typed into a personal subscription.
Technology investment alone does not create value.
Sources: Deloitte UK, GenAI Workforce Survey 2026, and 404 Media, Joseph Cox
Abstract
Deloitte's GenAI Workforce Survey 2026 asked 25,000 UK workers how they use generative AI at work, which makes it the largest study of its kind in a single country. Its central finding is that use is widespread and shallow. Nearly two thirds of the workforce has used generative AI for work, mostly to search for information, draft emails and summarize documents. A third of those users do so without their employer knowing, and one in six pays for a tool personally, together close to a billion pounds a year. Around half have had no formal training. The time saved averages 70 minutes a week, and many users save nothing at all. Deloitte recommends governance that balances innovation with risk, with training and guidance ahead of stricter rules. Alongside the survey we read 404 Media's investigation into Project Lily, in which contractors read real ChatGPT conversations to rate the responses. We reviewed both with Kishan Chamman, our CTO.
Our reading of the bases: 31 of the 63 percent who used generative AI for work report no time saved, so about half of all generative AI users in the UK save nothing with it. Deloitte does not state whether the 70-minute average includes the 37 percent who never used it. The 21 percent who prefer their own tool are a share of the self-paying and unapproved group, which comes to under 5 percent of all generative AI users.
Review and insights
The AI tools employers hand out are a generation behind. Shadow AI grows where the sanctioned tool is older, slower or more restricted than what an employee can buy in a minute with a personal card. Kishan's read from the field is that many organizations still run older AI tools or older models, or provide no current subscriptions at all. Employees work around that gap the way they worked around managed IT a decade ago, when the name for it was shadow IT. Deloitte's financial services figures support him. In financial services 28 percent of generative AI users have an in-house tool against 17 percent nationally, and self-paid subscriptions there still stand at 19 percent, above the national average. A sanctioned AI tool that falls short loses to a personal one. Kishan added a second motive. Some employees keep their AI use invisible because they do not want their employer to see how they work, and a personal account is the one environment where only the model provider can see it. Deloitte's press release backs this up: 23 percent see a stigma in using generative AI at work, and 64 percent of weekly users worry that their managers will think the technology can do their jobs.
Seventy minutes a week is what a chatbot is worth. The time saved by workplace AI is low because an individual subscription cannot reach anything the work depends on. When Floris called Deloitte's 70 minutes disappointing, Kishan explained that personal AI use stays superficial. A personal tool has no link to the work environment or the company data, and often none to the device either, which is locked down. Without that access the tool is a chatbot, and the person carries every input in and every output back by hand. That matches the uses Deloitte found, which are search, emails and summaries, the tasks that fit inside a chat window. It also explains the least flattering finding in the survey. Of the 63 percent of the UK workforce who used generative AI for work, 31 percentage points saved no time, which means about half of all users save nothing with it.
Buying an AI tool and announcing it is where adoption stalls. Floris asked what Kishan would do first as CTO of a 500-person company looking at Deloitte's numbers. His answer was to talk to the people who work around the official tools. Shadow AI appears when the tools provided deliver no value to the person using them. In Kishan's experience that follows from top-down implementation: an organization buys a product and tells people to use it, without saying how, where, or with what access. Bottom-up implementation improves adoption and value together, because it starts from the tasks people already found AI useful for. We saw the same pattern in Meta's AI second brain, which sat almost unused for two months until one internal post showed people what it could do. The workers paying for their own AI tools have already done that discovery work for their employer, and Deloitte's survey treats them as a risk before it treats them as information.
Deloitte prescribes training and governance and leaves access out. Deloitte's recommendations address the person and never the systems the person works in. AI literacy, the knowledge needed to use AI systems competently and to judge their risks, matters, and Kishan was blunt about it. Without knowing what a prompt does, how context works or how much structure a model needs, people freewheel and get simple answers to simple questions. Everyone at Eli5 has taken the courses on Anthropic Academy, while around half of Deloitte's respondents have had no formal training at all. A trained employee with a chatbot still has a chatbot, though. Deloitte's financial services figures already show that providing tools did not reduce self-paid use, and nothing in the recommendations asks what those tools can read. Institutional AI is AI embedded in an organization's shared processes, data and systems, as opposed to individual productivity tools. In our review of institutional versus individual AI we argued that the step between the two depends on redesigning the factory floor around the technology. A training programme leaves the floor as it is.
Connected to company knowledge, the AI time saving is measured in days. The same models deliver a different order of value once they can read what the company knows. Floris's read of Eli5's own tender work, first given in our article on our second brain, is that the time spent on a proposal has at least halved. Kishan puts the gain at hours or days per task, far from 70 minutes a week. Most of that gain comes from two changes. Nobody at Eli5 skims tender notices by hand anymore, and most tender questions ask for information that already sits in our knowledge base, where it used to be rewritten or copied each time. Both figures are impressions from inside the work, and neither is a measurement. Kishan supplied the counterweight himself. The gain is largest on greenfield projects, where we structure the knowledge from the start. On existing codebases many human hours still go into reading what is there before anything can be improved. The time saved also does not turn into free time, as Deloitte found for the UK workforce, because new work arrives.
A personal AI subscription is paid for partly in data. Consumer AI plans are cheap because they are subsidized, and part of the price is the conversations. Kishan describes the deal as a low price in exchange for using what goes in for training, with only part of that open to opt-out. An employee on a personal plan sits outside every agreement the employer could have negotiated. 404 Media's reporting on Project Lily shows what the deal involves in practice. Hundreds of contractors read real ChatGPT prompts, sometimes with a summary of the user's memories and location attached, and rate the responses on a scale of one to seven. The ChatGPT setting that allows this is on by default on the Free, Plus and Pro plans and off by default on Business, Enterprise and Edu. Kishan was not surprised. Reinforcement learning from human feedback (RLHF) is how these models improve, because a model cannot judge its own answers. What bothers Kishan is the reviewers. They work outside OpenAI, in unknown locations, in environments nobody has checked. 404 Media notes that Meta stopped working with Mercor, the company that pays the reviewers, in April after a large data breach.
Between a consumer subscription and an API contract stands a promise nobody outside can check. In Kishan's words, the only difference between a consumer AI plan and a business or API agreement is the promise that the data will not be used for training. OpenAI's enterprise privacy page confirms both halves of that. Data from ChatGPT Business, Enterprise, Edu and the API Platform is not used for training by default. Access to API data stored on OpenAI's systems remains open to authorized employees and to specialized third-party contractors who review for abuse and misuse. The conversations have to be stored somewhere, since they reappear in the browser the next day, and what happens to them there is invisible from outside. The mathematician Tristan Buckmaster of New York University ran into exactly this, according to his statement. He paid for OpenAI's Codex from his own research funds and put every draft of his work on the equations of fluid flow into it. On 6 September 2026, OpenAI described an internal model's proof on the forced Navier-Stokes equations to him. He asked whether that model had been trained on his Codex sessions or had access to them. On access, he was told the model did not look up user data. His question about training went unanswered. OpenAI has since stated that Buckmaster's prompts could not have influenced its result. Buckmaster writes that he is accusing no one, and we cannot settle it either, which is Kishan's point: from outside, the question cannot be answered.
The link to software modernization
Raising the value of workplace AI above 70 minutes a week means connecting it to the systems where the work happens, and in most organizations those are legacy systems. An AI tool can only save hours on a process it can read. The processes that matter sit in applications built to be read only through their own screens, with data whose business rules nobody wrote down. Exposing that data through interfaces an agent can call, and documenting the processes around it, is modernization work. It is the same sequence we followed for our own second brain.
Once a legacy system becomes readable, a second decision follows: which part of its data may cross the wire to a model provider. Kishan sees three options. The first is a read-only source in which names, addresses, phone numbers and other identifiers are encrypted or pseudonymized. The second is a local model. The third is keeping the data out entirely. Even a local model runs inside a harness that may send telemetry home, a caveat we underplayed in our review of local LLMs. That classification belongs in the assessment, before any connection is built.
Our own knowledge base shows the classification at a small scale, including where we accept risk ourselves. Outline connects to Claude on a Team plan, one of Anthropic's commercial products, and Anthropic states that it does not use their inputs and outputs for training by default. The same page records one exception: a conversation rated with the thumbs up or down button is stored for up to five years and may be used for training, and plan owners can switch that rating off. We accept the remaining risk because of what the base holds. It is mostly company information that is public in another form, together with professional profiles of our own team of the kind that appear in any proposal. It holds no identity documents, no customer personal data and no research or pending patents. Unpublished work that needs attribution, like Buckmaster's, is a different class of material, and the calculation changes with it.
Concluding remarks
Deloitte's GenAI Workforce Survey is large and carefully based, and it is honest about its least flattering result: about half of the people using generative AI at work save no time with it. It explains the shadow use well and the low value poorly, because it looks for the cause in the person, meaning training, confidence and guidance, and never in what the tools can reach. The recommendations fit that reading. They also fit the services offered through the contact form at the bottom of Deloitte's page. The transferable point for a CTO, PM or PO is that the £958 million is a demand signal, and the 70 minutes is what that demand gets when it is met with a chat window.
Two moves are worth avoiding. Banning personal AI subscriptions without offering a connected alternative is the first, because the path people made shows where the value is, and closing it leaves the need in place. Buying company-wide chatbot licences and calling that the institutional step is the second, because a licence without access to company systems buys the same 70 minutes at the employer's expense.
Questions we kept coming back to
What is shadow AI? Shadow AI is the use of AI tools at work without the employer's knowledge or approval, usually through a personal or free account. It succeeds shadow IT, the applications and data stores employees set up outside managed IT to get their work done. Deloitte's 2026 survey puts shadow AI at 31 percent of generative AI users in the UK, and 17 percent of users pay for their own tools. The risk sits in what passes through the tool, since the employer cannot see what data went in or where it went.
What is Project Lily? Project Lily is the codename, in internal material seen by 404 Media, for a program in which contractors read real ChatGPT prompts and rate the chatbot's responses to improve OpenAI's models. 404 Media reported it on 14 September 2026. Reviewers read a user's prompt and summarize what the user wants. They then score four generated responses from one to seven and write a rationale. Prompts arrive without usernames and pass through OpenAI's Privacy Filter model, which OpenAI itself says can miss uncommon identifiers. Some tasks also show a summary of the user's memories, including approximate location. The contractors were recruited through Crossing Hurdles and paid through Mercor.
Why does generative AI save so little time at work? Most workplace AI runs through a chat window with no access to company systems or data, so it saves time only on tasks that fit inside that window. Deloitte found that the top uses are searching for information, drafting emails and creating summaries. The UK workforce reports saving 70 minutes a week on average, and about half of generative AI users save no time at all. Connected to company knowledge, the same models save far more. In Eli5's own experience the time spent on a tender proposal has at least halved, an impression from inside the work and not a controlled study.
Do ChatGPT and Claude train on company data? Consumer plans can, and business plans do not by default. On ChatGPT Free, Plus and Pro the setting "Improve the model for everyone" stays on unless the user turns it off, and OpenAI told 404 Media that switching it off applies only to new conversations. Conversations used this way can reach human reviewers. OpenAI states that data from ChatGPT Business, Enterprise, Edu and the API Platform is not used for training by default. Anthropic states the same for its commercial products, such as the Team and Enterprise plans and the API, except for conversations a user rates with the feedback buttons. An employee paying for a personal plan works outside all of those agreements.
Is AI literacy training a legal requirement in the EU? Yes, as an obligation of effort. Article 4 of the AI Act has applied since 2 February 2025 to every provider and deployer of AI systems, with no size threshold. The Digital Omnibus, Regulation (EU) 2026/1744, rewrote the article with effect from 27 July 2026. It now requires measures to support the development of AI literacy among staff and others operating AI systems on the organization's behalf, and it no longer requires a sufficient level of literacy in any individual. The Commission and the Member States are tasked with supporting those efforts, with particular regard to small and medium-sized enterprises. An effort obligation is evidenced by the measures taken, and an organization where half the AI users have had no formal training has few measures to show.
Can sensitive data be used with a frontier model at all? It can, if everything that must not leave has been stripped from what reaches the model. Kishan's approach is a read-only data source in which first names, last names, addresses, phone numbers and other identifiers are encrypted or pseudonymized before any model sees them. The alternatives are a local model, with the caveat that its harness may still send telemetry, or keeping the data out altogether. The choice follows from a classification of the data made before anything is connected.
Where to start
The first question for an organization with shadow AI is what its AI tools could reach if it connected them, and which of that data may leave the building. Our modernization assessment maps the application landscape and scores each system on how readable and how sensitive its data is. It then sets the sequence: what to connect, what to pseudonymize, and what to keep inside.
The first step to start the modernization journey
Software modernization and architectural rebuilds lie at the heart of Eli5. We solve complexity to deliver direct business value by focusing on pragmatic, cloud-native transitions.
Before deciding whether to wrap the legacy system, buy a new SaaS product, or use AI to build custom tools, total visibility into the current tech landscape is essential.
A free brainstorm to discuss the legacy stack is available to book. It is the essential first step to turning technical debt into a scalable, modular future.
Full video episode
Floris Schoenmakers

