by Jelena Relić
What Is Quiet Quitting? Signs, Causes, and How HR Teams Can Respond in 2026
Quiet quitting did not start with lazy workers. It started with people who quietly stopped trying, and most companies never saw it coming. The term...
Bring your own AI, or BYOAI, describes employees using personal AI tools and accounts to complete work without formal company approval or management. An employee may use a personal ChatGPT account to summarize documents, Claude to research a topic, or a coding assistant carried over from a previous job.
The company never selected the tool, assigned the account, or defined how employees should use it. The tool simply became part of the employee’s daily workflow.
BYOAI may already be happening across your team, even when nobody has formally discussed it.
BYOAI means employees choose and use their own AI tools for work instead of relying on tools provided or approved by the company. The practice can help employees work faster, but it also leaves the company with limited visibility into tool usage, data sharing, access, and spending.
The pattern closely resembles bring your own device, or BYOD. Employees once began using personal phones and laptops for work because their own devices were familiar, convenient, and often easier to use than company-issued hardware.
Companies initially tried to prevent personal device use. Many later learned that banning personal devices was less effective than creating clear rules and managing access.
| BYOD | BYOAI | |
| What employees bring | Their own phone or laptop | Their own AI tool or account |
| What companies worry about | Lost devices, unsecured networks, and unauthorized access | Company data entered into tools that were never reviewed |
| The initial response | Ban personal devices or manage them centrally | Ban personal AI tools or manage them centrally |
| What worked better | Managing devices instead of trying to eliminate them | Giving employees approved AI tools and clear usage rules |
BYOAI is following the same path. Employees have already adopted useful technology, while company policies and access systems are still catching up.
The practical goal is to give employee AI use a clear structure.
Employees adopt personal AI tools because they’re useful, easy to access, and available long before most companies establish an official AI program. Creating a personal account takes minutes, while receiving approval for a company tool may take weeks or never happen at all.
A 2026 Founder Reports survey found that 59% of workers at companies with fewer than 10 employees said their employer had no clear AI policy, or they were unsure whether a policy existed. The figure dropped to 34% among employees at companies with more than 1,000 workers.
Smaller companies often have fewer formal technology policies and approval processes. Employees fill the gap by choosing tools for themselves.
A new employee may arrive with an AI tool they already used at a previous company or at home. The employee continues using the tool because it is familiar and produces useful results. Managers may never ask which AI tools the employee uses, and the employee may see no reason to raise the subject.
The same process happens across multiple teams. Engineering adopts one coding assistant. Marketing uses several research and content tools. Sales employees connect personal AI accounts to their daily work. Finance may avoid AI entirely.
The company gradually begins operating through a collection of personal tools that nobody selected or evaluated on behalf of the organization.
Convenience drives most BYOAI adoption. Employees are usually trying to work efficiently rather than bypass company rules. The problem is often that no clear rules exist.
Unmanaged AI use creates three main risks: sensitive information can enter tools the company never reviewed, leadership cannot see which tools employees use, and subscription costs become scattered across personal accounts and expense reports.
Established AI vendors such as ChatGPT and Claude may have serious security programs. A company still carries risk when employees use personal accounts outside the company’s access controls, contracts, retention settings, and data policies.
Technologist Brian Solis, who helped popularize the term BYOAI, has described the practice as spreading through workplaces while company policy struggles to keep pace.
The risk often appears as a visibility gap rather than a dramatic security incident.
An employee may paste a client contract into a personal AI account to produce a summary. Another employee may enter internal revenue figures into a chatbot to create a report. Both employees may believe they are using AI responsibly because nobody has explained which information is restricted.
The company cannot manage data exposure when leadership does not know which tools are active or how employees use them.
BYOAI also creates unnecessary spending.
A dozen employees may each expense a separate $20 monthly AI subscription. The company could be paying for overlapping tools, duplicate features, and accounts that former employees no longer use.
Scattered subscriptions also prevent the company from negotiating an enterprise agreement, consolidating vendors, or determining whether the tools produce enough value to justify the cost.
The central risk is unmanaged usage. Leadership cannot protect data, control access, or optimize spending without a reliable view of employee AI activity.
BYOAI is probably already happening when employees mention tools the company never approved, submit unfamiliar AI subscriptions, or cannot identify which AI products colleagues use.
Common signs include:
One signal does not automatically indicate a serious incident. Several signals usually show that personal AI use has become part of normal operations.
BYOAI should then be treated as a current management issue rather than a future possibility.
AI training can teach employees how to use tools more carefully, but training cannot show leaders which products are active, who has access, what the company is paying, or what information employees have entered into personal accounts.
Employees should understand which data they can share, how to verify AI-generated answers, and when human review is required. Training can reduce careless behavior and improve the quality of AI-assisted work.
Training still leaves several operational questions unanswered:
A company can train every employee and still have no reliable inventory of active AI tools.
Training improves how people use AI. Visibility shows leadership what AI use is actually taking place. A growing company needs both capabilities.
Companies make BYOAI harder to manage when they ban personal tools, underestimate the scale of adoption, assign the issue only to IT, or wait for a serious incident before responding.
An outright ban rarely eliminates employee AI use. Employees who find the tools valuable may continue using them without mentioning them.
The company then loses the limited visibility it previously had.
A more practical policy gives employees at least one approved option and explains which information cannot be entered into unapproved tools.
BYOAI often spreads before leadership notices it. By the time a founder sees an unfamiliar subscription or hears a tool mentioned in a meeting, several teams may already be using different AI products.
Leaders should map current usage before estimating the size of the problem.
BYOAI affects data protection, software spending, employee productivity, vendor management, legal exposure, and the way work gets completed.
IT may manage access and security reviews, but company leadership must decide which tools support the business, which risks are acceptable, and who is accountable for employee AI use.
A company does not need to wait for a data leak, client complaint, or unexpected expense before addressing BYOAI.
Early action may require a few employee conversations, a short approved-tool list, and basic data rules. Delayed action can require account audits, contract reviews, data investigations, subscription cleanup, and changes across several teams.
Clear rules are easier to establish before unmanaged AI use becomes deeply embedded in daily workflows.
BYOAI is one piece of a bigger picture. For the full framework, see our guide to AI governance for growing companies.
Companies can manage BYOAI by identifying current usage, approving a focused list of tools, assigning access according to employee roles, and communicating clear rules for sensitive information.
The objective is to bring AI use into view while preserving the productivity employees already gain from the tools.
Start with direct conversations rather than assumptions.
Ask employees across engineering, marketing, sales, operations, finance, and customer support which AI tools they use during a normal workweek. Ask what tasks each tool supports and whether the account is personal or company-managed.
Employees should understand that the goal is to create a workable system, not punish people for using useful technology.
The answers will usually reveal more than expense reports or software inventories.
Employees do not need dozens of approved options. They need access to at least one reliable tool that supports their work.
A short approved list simplifies security reviews, contracts, account management, training, and support. The list can expand when employees identify a strong business case for another product.
Providing an approved alternative also reduces the incentive to rely on personal accounts.
Different roles require different AI capabilities.
Developers may need coding assistants. Marketing employees may need research and content tools. Sales teams may need prospecting or call-analysis products. Finance teams may require stricter controls and tools designed for sensitive business data.
Role-based access gives employees the tools relevant to their work while reducing unnecessary accounts and spending.
Employees need simple guidance on the information they may enter into AI tools.
The AI usage policy should address customer names, personal data, financial information, contracts, source code, strategic plans, credentials, and other confidential material.
The rules should identify approved tools, restricted data, required review steps, and the person or team employees should contact when they are uncertain.
A short message can establish the initial rules without turning the announcement into a formal compliance exercise.
For example:
“Quick note on AI tools. We know many people are already using ChatGPT, Claude, or similar products to support their work. For now, [approved tool] is the AI product the company officially supports. Please do not enter customer names, financial details, contract terms, credentials, or other confidential information into personal or unapproved AI accounts. If another tool is working well for your role, let [name or team] know so we can review it.”
The message acknowledges existing behavior, gives employees an approved path, and creates a way to request additional tools.
Thrivea’s AI Workforce module helps companies replace scattered personal AI accounts with visible, approved, and role-based access. The module addresses the three main BYOAI management needs: visibility, centralized administration, and controlled access.
Thrivea’s AI Visibility gives companies a view of AI usage across the workforce.
A founder may discover that most developers already use a coding assistant every day, two marketing employees have selected different research tools, and the finance team has not adopted AI at all.
The usage data helps leadership understand the company’s actual AI environment before creating policies or purchasing additional software.
AI Administration allows a company to connect an approved provider, such as an Anthropic or OpenAI account, at the organization level.
Employees can then access approved tools through company-managed accounts instead of paying for personal subscriptions or using private accounts for work.
Central administration gives the company greater control over accounts, spending, access, and vendor relationships.
AI Access Management gives employees access according to their responsibilities.
Developers can receive coding tools, marketing employees can receive research and content tools, and other teams can receive access based on their specific workflows.
Role-based assignment reduces unnecessary subscriptions and removes the need to negotiate access separately for every employee.
Together, AI Visibility, AI Administration, and AI Access Management replace disconnected personal accounts with an AI environment the company can see and manage. Employees keep access to useful tools, while leadership gains control over data, spending, and permissions.
Employees are already bringing personal AI tools into the workplace, just as they once brought personal phones and laptops. Companies gain more control by managing employee AI use directly instead of assuming a ban will eliminate it.
Start by identifying the tools already in use. Approve a short list of reliable products. Replace personal accounts with company-managed access where possible. Assign tools according to employee roles and communicate clear rules for sensitive information.
Thrivea helps companies see which AI tools employees use, centralize approved accounts, and assign access by role. Explore Thrivea’s AI Governance module to bring BYOAI under control without taking useful tools away from your team.
What does BYOAI stand for?
BYOAI stands for bring your own AI. The term describes employees using personal AI tools or accounts for work instead of products provided or approved by their employer.
Should companies ban personal AI tool use?
Companies should generally avoid relying on a total ban because employees may continue using useful tools without disclosing them. A more effective approach is to approve a short list of products, provide company-managed accounts, and establish clear rules for sensitive information.
How is BYOAI different from shadow AI?
BYOAI refers specifically to employees choosing and bringing personal AI tools into the workplace. Shadow AI is a broader category that covers any AI product used without company visibility or approval, including personal accounts, unofficial team tools, and unsanctioned software integrations.
BYOAI is one common form of shadow AI.
Is BYOAI a security risk?
BYOAI can create a security risk when employees enter confidential or regulated information into tools the company has not reviewed. Personal accounts can also prevent the company from controlling access, retention settings, offboarding, and data use.
The broader management problem is the lack of visibility into which tools are active, who uses them, what they cost, and what information employees share through them.
What is the first step in managing BYOAI?
The first step is identifying which AI tools employees already use. Leaders should speak with people across several teams, document the tools and account types, and understand which tasks each product supports.
Once the company has an accurate inventory, leadership can approve a focused list of tools, define data rules, and provide access based on employee roles.
by Jelena Relić
Quiet quitting did not start with lazy workers. It started with people who quietly stopped trying, and most companies never saw it coming. The term...
by Jelena Relić
Losing employees is normal. Losing them faster than you expected, or losing them in patterns you never noticed, is a problem. Attrition rate is the HR...
by Jelena Relić
Bad onboarding costs you twice: once to hire, again to replace. This guide covers the 4 phases of employee onboarding, a complete checklist, 30-60-90 ...