İşStrateji
0

Should You Tell Your Boss You Use AI? The Workplace Disclosure Question, Answered

Two colleagues having an open conversation at a sunlit office desk

TL;DR: This is one of the most asked and least answered questions in working life right now, and there is real evidence on it. The 2025 global study by the University of Melbourne with KPMG surveyed 48,340 people across 47 countries and found that 57 percent of employees admit to using AI in non-transparent ways, including presenting AI-generated content as their own; 56 percent have used AI tools at work without knowing whether it is allowed; and 48 to 49 percent have uploaded sensitive company information into public AI tools. Buried in the same report is the finding that reframes the whole question: uploading sensitive information is most common among employees whose organisation has banned generative AI, at 67 percent, versus 56 percent where a policy exists, 38 percent where employees are unsure, and just 33 percent where there is no policy at all. Bans correlate with roughly twice the risk behaviour of no policy. Below: the verified evidence, an original disclosure decision matrix for the four policy regimes, a three-tier disclosure ladder separating tool from method from artifact, and the two provisions of the EU AI Act that make disclosure run in the other direction too.

There is a conversation happening in almost every workplace that never gets spoken aloud. Someone drafts a proposal in forty minutes instead of four hours, edits it carefully, sends it, and says nothing about how it was made. Then they wonder, quietly, whether that was fine or whether it was something else.

Most advice on this question is written by people with an interest in the answer. Employers publish guidance saying disclose everything. Productivity accounts imply nobody needs to know. Neither position is grounded in evidence about what actually happens or what actually goes wrong.

There is evidence. It is unusually good evidence, and it points somewhere neither camp expects.

What people actually do

The University of Melbourne, working with KPMG, ran what is currently the largest study of public trust and use of AI: 48,340 people completed the survey across 47 countries, with fieldwork running from November 2024 to mid-January 2025 and results published in 2025. The workplace section is the most revealing part of it.

Table 1. What employees report about their own AI use at work (University of Melbourne and KPMG, Trust, attitudes and use of artificial intelligence: A global study 2025, n=48,340 across 47 countries)

Reported behaviour Share of employees
Used AI in non-transparent ways, including presenting AI content as their own or avoiding revealing its use 57 percent
Used AI tools at work without knowing whether it is allowed 56 percent
Uploaded sensitive company information into public AI tools 48 to 49 percent
Used AI in ways that could be considered inappropriate 47 percent
Have seen or heard other employees using AI tools inappropriately 63 percent
Relied on AI output at work without critically evaluating it 66 percent
Made mistakes in their work because of AI use 56 percent
Put less effort into their work because of AI 72 percent
Concerned about being left behind if they do not use AI at work 48 percent
Report any AI training or education at all 39 percent

The authors add a caveat that matters and that most coverage of the study drops. The survey was anonymous specifically to encourage honest answers, and even so they judge that these figures probably understate the real extent, because social desirability bias runs in one direction here. Treat every number above as a floor.

Read the table as a whole and a pattern appears that has nothing to do with dishonesty. A majority is using AI without knowing whether they are allowed to. A majority is not disclosing. Only two in five have had any training. These are not primarily ethical failures. They are the predictable output of an information vacuum, and the vacuum belongs to the employer.

The finding that reverses the usual advice

Now the part that changes the answer to the question in the title.

The study broke the sensitive-information-uploading rate down by what kind of AI policy the employee’s organisation has. The result is not what almost any employer would predict.

Table 2. Risky AI behaviour by policy regime, with relative risk indexed to the no-policy baseline (CEOtudent editorial framework; uploading rates and regime shares as published by University of Melbourne and KPMG 2025; the relative-risk column is derived by dividing each rate by the 33 percent no-policy rate)

Employer policy regime Share of employees in this regime Uploaded sensitive company information into public AI tools Relative risk versus no policy
Generative AI is banned 6 percent 67 percent 2.03 times
A policy guides generative AI use 34 percent 56 percent 1.70 times
Employee does not know if a policy exists 19 percent 38 percent 1.15 times
No policy exists 41 percent 33 percent 1.00 baseline

Employees under an outright ban report uploading sensitive company data at roughly twice the rate of employees whose employer has said nothing at all.

Two honest cautions before anyone builds a strategy on that. First, this is correlation, not causation: organisations that ban generative AI may be ones already handling more sensitive data, and employees operating under an explicit ban may simply be more aware that what they did crossed a line, and therefore more likely to report it. Second, these are self-reported behaviours in a single cross-sectional survey.

Even with both caveats, the direction is the important part, and the study’s own authors draw the conclusion plainly: outright bans may be ineffective, and simply having a policy does not guarantee compliance. What is needed is clear guidance and education on responsible use.

For an individual employee, that translates into something concrete. A ban does not stop AI use. It removes the ability to ask questions about it. And an employee who cannot ask questions is the employee most likely to make an expensive mistake, because 66 percent are already relying on AI output without critically evaluating it and 56 percent have already made mistakes because of it.

That is the real risk you are managing when you decide whether to disclose. Not embarrassment. Exposure without a support structure.

Disclosure is not one decision

Most people treat this as a single binary: tell or do not tell. That framing is why the question feels impossible. There are actually three different things you could be disclosing, and they carry completely different obligations.

Table 3. The three-tier disclosure ladder (CEOtudent editorial framework)

Tier What is disclosed When it is genuinely required What happens if you skip it
Tier 1: Tool That you use AI tools in your work at all When a policy asks, when a client contract requires it, when you are proposing a new workflow or timeline based on it You lose the ability to ask for training, budget, or approved tooling; you carry the risk personally
Tier 2: Method Which parts of a specific deliverable AI touched and how it was checked When the deliverable will be relied on by others, when accuracy is someone else’s problem, when you are being credited for judgment rather than output Nobody knows which parts were verified, so the error surface is invisible to reviewers
Tier 3: Data What information you put into which system Always, wherever the information is not already public This is the tier that produces actual legal and commercial harm, and it is the one 48 to 49 percent of employees have already breached

The ladder resolves most of the anxiety, because the tier people agonise over is Tier 1 and the tier that actually matters is Tier 3.

Nobody reasonable expects you to announce that you used a spellchecker. They do expect that customer records did not leave the building. The reason the question feels fraught is that people are applying the emotional weight of Tier 3 to a Tier 1 decision.

The decision, by situation

Combining the regime data with the ladder gives a usable answer rather than a principle.

If your employer has a policy that guides use (34 percent of employees). Read it, then work inside it and say so. Disclosure at Tier 1 costs nothing here because permission already exists. The specific risk in this group is different: at 56 percent uploading rate, having a policy is clearly not the same as following one, so the discipline to build is Tier 3, not Tier 1.

If your employer has no policy (41 percent). This is the largest group and the lowest-risk one by the data. Silence from the employer is not permission, but it is also not prohibition. The useful move is not a confession, it is a question: ask what the expectation is, in writing, for the specific category of work you do. You will usually be the first person to ask, which is a positioning advantage rather than a confession. Handle Tier 3 as if a strict policy existed, because that is the tier that creates real harm.

If you do not know whether a policy exists (19 percent). Find out before you disclose anything. Nearly one in five employees is in this position, and it is the worst one to make decisions from, because you cannot calibrate a disclosure without knowing the rule you are disclosing against.

If generative AI is banned (6 percent). This is the hardest case and the data says the honest thing about it. This group reports the highest rate of risky behaviour, which means bans push use underground rather than ending it. If you are here, the choice is not disclose or hide. It is comply, or make the case to change the rule through whatever channel exists. Quiet non-compliance in a ban regime is the single worst risk position in the whole matrix, because there is no policy cover, no training, and no one to ask.

The obligation runs the other way too

One thing almost entirely missing from this conversation: in the European Union, some of the legal disclosure duty points from the employer toward you.

Article 4 of the EU AI Act, applicable since 2 February 2025, requires that providers and deployers of AI systems take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. Against the finding that only 39 percent of employees report any AI training, that is a live gap rather than a formality.

Article 26(7) goes further and is directly about workplace transparency: before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers’ representatives and the affected workers that they will be subject to the use of the high-risk AI system. That provision applies from 2 August 2026.

The practical consequence is that “should I tell my employer” is only half a question. In the EU, an employer deploying high-risk AI that affects you owes you notice, and an employer of any kind owes you a reasonable effort at AI literacy. If you work in the EU and have had no training, you are not the only party with an unmet obligation.

What to actually do

Ask the question instead of making the disclosure. In a no-policy organisation, which is 41 percent of them, requesting written guidance for your specific work category converts a personal risk into an organisational one, which is where it belongs. It reads as diligence, not as confession.

Disclose method on anything anyone else will rely on. Not the tool, the checking. One line at the point of handover, saying what was AI-drafted and how it was verified, protects the reader and demonstrates the judgment you are actually paid for. This is the same discipline as knowing which decisions to delegate to AI and which to never automate applied to output rather than choices.

Treat Tier 3 as non-negotiable regardless of policy. Customer data, financial data, unreleased material and third-party copyrighted content do not go into public tools. This holds in every regime and is the only rule in this article with no situational nuance. If you need context in the tool without exposing the source, that is exactly the problem a properly built context file is designed to solve.

Keep a private record of what AI touched. Not for confession, for reconstruction. When something is questioned six months later, the person who can say precisely what was generated and what was verified is in a completely different position from the person who cannot. It also gives you evidence of contribution when output volume rises and credit gets ambiguous, which connects to what actually compounds as career capital in the AI era and to how knowledge work output gets measured at all.

Do not let the fear of disclosure become a reason to stop learning. Forty-eight percent of employees already worry about being left behind. The response to that anxiety should be visible skill, not hidden usage. Hidden usage produces neither training nor trust, and it leaves you carrying every risk personally.

Frequently asked questions

Is not disclosing dishonest?
It depends entirely on tier. Not announcing your tools is normal professional practice and always has been. Presenting AI output as verified work you did not verify is a different act, and that is what the 57 percent figure captures: it combines presenting AI content as one’s own with actively avoiding revealing that AI was used. The line is not the tool. The line is whether someone is relying on judgment you did not actually apply.

Will disclosing make me look less capable?
The data offers indirect comfort here. With 66 percent of employees relying on AI output without critically evaluating it and 56 percent reporting AI-caused mistakes, the scarce and visible skill is not avoiding AI, it is checking it. Disclosure framed as method, meaning here is what I generated and here is how I verified it, signals exactly the capability that is in short supply.

My employer banned it. Should I just use it quietly?
The evidence says this is the highest-risk position available. Employees in ban regimes report the highest rate of uploading sensitive company data at 67 percent, roughly double the no-policy rate. Under a ban you have no policy cover, no training, and nobody to ask when something goes wrong, so the cost of a mistake lands entirely on you. Either comply or work to change the rule.

What if my company has no policy at all?
That is the most common situation, at 41 percent of employees, and by the survey data it is also the lowest-risk one. Ask for written guidance rather than assuming. Meanwhile apply the strictest possible standard to Tier 3, because absence of a rule is not absence of consequences.

Does the law require me to tell my employer?
Not in the general case. The disclosure obligations in the EU AI Act point at providers and deployers, meaning organisations, not at individual employees. Article 4 obliges deployers to ensure staff AI literacy from 2 February 2025, and Article 26(7) obliges employers to inform workers before putting a high-risk AI system into service at the workplace, applicable from 2 August 2026. Your own duties come from your employment contract, your client agreements and your professional obligations, not from the AI Act.

How do I disclose without making it awkward?
Attach it to the work rather than to yourself. A single sentence in a handover note, describing what was drafted with AI assistance and what was checked against what, is a status update rather than a confession. The awkwardness people fear comes from framing it as a personal admission instead of a normal note about process.

Sources

  • University of Melbourne and KPMG, Trust, attitudes and use of artificial intelligence: A global study 2025, 48,340 respondents across 47 countries
  • Regulation (EU) 2024/1689 of the European Parliament and of the Council, the Artificial Intelligence Act, Article 4 on AI literacy, applicable 2 February 2025
  • Regulation (EU) 2024/1689, Article 26(7) on obligations of deployers who are employers, applicable 2 August 2026
  • Organisation for Economic Co-operation and Development, work on artificial intelligence in the workplace
  • International Labour Organization, research on generative AI and the world of work

This content was compiled with the support of AI following in-depth research, then written and prepared for publication by the CEOtudent editorial team.

This post is also available in: Türkçe Français Español Deutsch

Benzer içerikler