New Study: Workplace AI Rules Often Backfire on Developers
Your company's AI ban might be pushing workers to use it in secret.
Companies are scrambling to write rules about how employees can use AI chatbots and coding assistants. The worry is real: workers pasting confidential code, customer data, or company secrets into tools like ChatGPT can leak information in seconds. So IT and legal teams write policies — sometimes outright bans, sometimes approved-tools-only lists.
A team of researchers interviewed 19 software developers to see whether those rules actually work. The honest answer: it depends. Policies that came with clear reasons and practical alternatives helped developers do their jobs safely. Policies handed down without explanation mostly got ignored, worked around, or quietly violated. One recurring theme was that a blanket ban didn't stop AI use — it just moved it underground, where nobody was watching for risks anymore.
That matters far beyond the tech industry. The same dynamic shows up in law firms, hospitals, marketing teams, and schools: if a rule feels disconnected from how work actually gets done, people route around it. Managers end up with a policy that looks good on paper while the real risks — data leaks, wrong answers, unreviewed AI output — keep growing unnoticed.
The researchers' recommendation is simple and cheap: involve the people who use AI daily when writing the rules. Ask what they actually need, set clear boundaries about what data can never be shared, and explain the reasoning. Rules built that way get followed. Rules dropped from above mostly get ignored. For anyone whose boss just announced an AI crackdown, this study suggests the crackdown may change less than expected.
- Researchers interviewed 19 software developers about their employers' AI rules — and found many rules get ignored or quietly worked around
- Policies that ban AI outright often just push usage underground, where companies lose visibility and control over real risks
- The fix is simple: include the people who use AI every day when writing the rules, and explain the reasons behind them
Why It Matters
If your workplace bans or restricts AI, expect mixed compliance — and ask whether the rules actually solve the problem.