“I have read and agree to the terms and conditions” has long been the biggest lie on the internet. We all know this from decades of users clicking through, and therefore accepting, terms and conditions for software and SaaS. The same lie now sits at the heart of shadow AI, as staff paste company data into AI tools through personal accounts whose terms nobody has read.
Interesting analysis from UK cyber security firm Bridewell, here, suggests that the average privacy policy of LLMs takes 20 minutes to read. They looked at the 20 most popular large language models and found an average word count of 4,600 and Flesch reading ease score of 40.2, which equates to difficult academic-like texts.
How much shadow AI runs through personal accounts?
LayerX’s 2025 enterprise report, based on browser telemetry rather than a survey, found that 77% of employees paste data into generative AI prompts, and that 82% of those pastes come from unmanaged accounts.
Other sources put the personal-account figure lower, but none of them put it at zero. Netskope’s 2026 Cloud and Threat Report found 47% of workplace generative AI users relying on personal accounts, down from 78% the year before.
Cyberhaven’s 2026 research found 32.3% of ChatGPT usage running through personal accounts, and that 39.7% of AI interactions involved sensitive data.
In short: rather unsurprisingly, users are not reading the terms of how the AI they might be using at work treats data, and many are uploading company data. A meaningful share of your organisation’s data is flowing into AI tools under terms your organisation never agreed to. The same AI product often comes with two very different sets of terms depending on whether you signed up with a Gmail address or your company tenant.
Same product, two sets of terms
Chris Linnell, Associate Director of Data Privacy at Bridewell, makes the point that enterprise AI agreements typically bar providers from training on inputs and outputs, and give organisations oversight of what is shared. Consumer tiers often don’t.
The practical effect is that the same employee, using the same product, doing the same task, can create two entirely different risk positions depending on which account they happen to be logged into.
Why ITAM should own AI terms review
AI terms review sits naturally beside the work ITAM already does on EULAs and SaaS entitlements. ISO/IEC 19770-1 frames IT asset management as governing the assets and the rights attached to them. ISO/IEC 42001 adds supplier controls for AI specifically. Between them, the case for ITAM owning AI terms review is stronger than the case for leaving it with whoever happened to sign up first. (For a wider view, see our eight steps towards AI governance.)
Five steps to manage shadow AI and personal accounts
You can’t fix shadow AI by asking users to read the terms, because most of them can’t, and the policies aren’t written for them anyway.
- Discover: make sure your discovery tooling can tell a corporate tenant from a personal login to the same service. If it can’t, you’re blind to the risk.
- Record the terms as attributes, not just the licence: does the provider train on your data, how long it keeps it, whether there’s an opt-out, who has admin visibility, and which jurisdiction applies. Record these for the consumer tier and the enterprise tier separately.
- Offer a sanctioned route: blocking without an alternative just pushes people back to Gmail signups. The Netskope drop from 78% to 47% suggests managed options do work.
- Watch for changes: AI terms change far more often than EULAs, so treat a terms change like a licence change and review it.
- Tie it to ISO/IEC 19770-1 and 42001: the rights attached to the asset are exactly what’s at stake here.