Someone on your team is three times faster than they were eighteen months ago. They are not going to tell you why. Not because they're doing anything wrong — but because we have built, quite carefully, a world in which telling you would be irrational.
Call them cyborgs: knowledge workers who have folded AI into their craft so completely that it's no longer a tool they occasionally reach for, it's how they work. They exist in every profession right now, in far greater numbers than any organization believes. Almost none of them are visible. And the reason isn't cowardice. It's arithmetic.
Two rules, and no way to win
Look at what a knowledge worker actually faces the moment they consider being open about it.
Rule one: using AI is still read as cheating. Nobody writes this down, but the trade knows. Part of the disdain is aesthetic — real professionals write their own first drafts. Part is territorial — if a machine can do this, what was my training for? And part is plain fear wearing the costume of principle. The effect is identical regardless of the motive: admitting you used AI to produce good work invites a quiet reassessment of the work, and of you.
Rule two: the moment management hears about it, it gets forbidden. Not always. But often enough that betting the other way is foolish. Disclosure rarely opens a policy conversation; it produces a ban, a blocked domain, and a colleague who now has to route around it as well.
Put the two together and you get the incentive structure we have actually built: you are shamed if you're honest, and blocked if you're overheard. There is no version of coming forward that leaves the cyborg better off than staying quiet. So they stay quiet. They deliver excellent work on impossible timelines, say nothing about the method, and the organization concludes that nobody here really uses AI.
That conclusion is false in every organization I have ever looked at. It is also, precisely, what the system was designed to produce.
The ban isn't stupid either
It's tempting to write this as a story about brave workers and dim management. It isn't one, and the piece falls apart if you tell it that way.
When a firm blocks AI tools, it is usually responding to something real: confidentiality clauses in every client engagement, data protection obligations that make it the controller of any onward transfer, sector regulators, professional insurers, and a genuine inability to answer the question “what has already left the building?” A blanket ban is a crude instrument, but it is a rational response to an unbounded flow you cannot see.
So you have two parties, both behaving sensibly, jointly producing an outcome that is worse for both of them. The cyborg hides capability that the firm is paying for. The firm writes policy for a behaviour it cannot observe. Nobody is being dumb. The information is simply asymmetric, and the incentives are pointed the wrong way.
That matters because problems of this shape are never solved by asking people to be braver. They are solved by changing what disclosure costs.
“Efficiency always wins” — but not on its own
There's a comforting version of the argument at this point: nobody digs a foundation with a shovel when there's an excavator parked next to it. Convenience and efficiency win, they always have, and so this whole shame-and-hide equilibrium is a transitional state that will pass on its own.
Mostly right. But be careful, because the shovel argument is weakest in exactly the professions where this matters most. Law, medicine, audit and engineering have spent a century deliberately refusing efficiency: licensing, restrictive practice, mandatory process, personal liability. A lawyer who is ten times faster gains nothing at all if the bar association decides the output is unattributable.
So the mechanism isn't “efficiency wins.” It's narrower, and much more useful: efficiency wins once the accountability question has an answer.
Look at the AI scandals that have actually hit the professions so far — the fabricated case citations, the filings referencing authorities that don't exist, the reports full of confident nonsense. Then read the sanctions. Not one of them punished the use of a machine. Every single one punished a missing signature: a person who put their name on output they had not checked. The profession was not objecting to the tool. It was objecting to unowned work, which it has always objected to, and should.
That's the unlock. Not “AI is fine now.” Something far more specific: someone has to be answerable, and that someone has to be a person.
What the next stage looks like
Three things change together. None of them works alone.
1. Use is disclosed, not confessed
The shaming ends — and it should, because it was aimed at the wrong target from the beginning. The instinct behind it was never crazy. Anyone who has been handed a fluent, confident, entirely wrong draft that nobody read before sending knows exactly what the trade is defending against. But the offence was never the tool. It was unreviewed work leaving the building under someone's name.
Punish that instead. It's a sharper rule, it's easier to apply, and it catches plenty of people who have never opened an AI tool in their lives.
| What gets punished today | What should get punished |
|---|---|
| Using AI at all | Sending work nobody reviewed |
| Being fast in a way that's hard to explain | Being unable to defend the output |
| Telling your manager | Not knowing what left the building |
2. The deliverable stops being the content
This is the real shift, and it's the uncomfortable one. If a machine can produce the draft, then producing the draft is no longer what you are paid for. What you are paid for is being the one who says I stand behind this — and who has something to lose if it's wrong. We've written before about why a machine can never be responsible for anything: it has no stake to forfeit. You do. That asymmetry isn't going to be closed by a better model, because it isn't a capability gap. It's structural.
Taking responsibility becomes the deliverable. And that is not a demotion — it's a harder job than the one it replaces, for a reason worth being blunt about: you cannot review work you couldn't have done yourself. Catching the plausible-but-wrong clause, the citation that doesn't exist, the figure that's off by an order of magnitude — that takes more expertise than producing the draft did, not less. The genuinely 3x cyborg is not someone who stopped being a professional. They're someone whose professional judgment now covers ten times the surface area.
The common fear — that AI turns experts into button-pushers — has it backwards. It makes expert judgment the only part that still matters, and it quietly ends the careers of people who were coasting on production volume.
3. Compliance becomes possible for the first time
Here's the part organizations consistently miss. Almost every AI data-protection policy written today is fiction. Not badly drafted — fiction, because it governs a flow that nobody can see. You cannot apply a control to a behaviour that is, by design, hidden from you. Undisclosed AI use is unprotectable AI use. That's definitional, not rhetorical.
Disclosure is what makes protection possible at all. And once use is in the open, the interesting question stops being “should we allow this?” and becomes “what exactly is leaving the building?” That one has a practical answer: strip the identities out of the document before the text goes anywhere, keep the substance, map the result back locally afterwards. The AI doesn't need to know your client's name to analyse their contract — and what you're risking when it does is not theoretical.
Which is the whole reason these two things arrive in that order. Accepted use first, then protected use. Nobody can secure a workflow that officially doesn't exist.
The trap in the middle
There is one way to get this badly wrong, and it happens to be the default way.
An organization accepts AI in principle, then routes it through an approval queue: a form, a ticket to legal, a two-week review, and at the end of it an approved tool that is worse than the one everybody was already quietly using. That doesn't end shadow use. It recreates it, with paperwork. If the compliant path is slower than the hidden path, you have handed people a shovel and explained that the excavator requires a permit. They will keep using the excavator. They will simply keep not telling you.
The most honest evidence we have for that is our own numbers. The channel that works for us is a browser extension — not the enterprise conversation, not the procurement cycle. An extension is the one thing a knowledge worker can add to their day without asking anybody's permission. The demand we actually observe isn't for better AI governance. It's for protection that doesn't require a meeting first.
Make the safe path the fast path, or nothing has changed.
Monday morning
If you're the cyborg: stop shipping only the output. Ship the method alongside it, once, to one person who won't punish you for it. I used AI for the first pass; here's what I checked, and here's what I changed. You're not asking permission. You're demonstrating the thing that actually ends this argument — that a person reviewed it, and the person is you.
If you manage cyborgs: start from the assumption that it's already happening, because it is. Then do the two things that move it. Declare an amnesty and mean it — say plainly that nobody is punished for telling you what they use, and understand that you get exactly one attempt at that promise. And make sure what you offer next is faster than what they were doing in secret. If disclosure costs a person anything at all, you will get silence, and you will have earned it.
The alternative is where most organizations are sitting right now: your best-performing people are the ones you understand least, your AI policy governs a behaviour you cannot observe, and confidential data you are legally responsible for is being pasted into a chat window by someone who would genuinely like to tell you about it.
They're waiting for it to be safe to say.
Common questions
Why do employees hide that they use AI?
Because the incentives are built that way: admitting it invites the charge of cheating, and being overheard often produces a ban. Staying quiet is the only move that leaves the person better off, which is why undisclosed use is so widespread.
Can an AI policy work if the use is undisclosed?
No. A control cannot be applied to a behaviour nobody can observe, so most AI policies govern a flow that is invisible to them. Disclosure is the precondition for protection, not the reward for it — and it changes the question to what exactly is leaving the building.
What should a manager do first?
Declare an amnesty and mean it, then make the sanctioned path faster than the hidden one. An approval queue that is slower than the shadow tool recreates shadow use with paperwork. Our map of how companies protect personal data covers where each option fits.