The Vote Already Happened

Personal AI · Evidence

The Vote Already Happened

Nobody is waiting for permission to have their own AI. At more than nine in ten companies surveyed, workers were already using personal tools to do the job. What is missing is not the will. It is the architecture.

John RectorEssay · about 10 minutes

The finding usually filed as a compliance problem 57% of employees say they hide their use of AI and present AI-generated work as their own.

From a global study of 48,340 respondents across 47 countries by the University of Melbourne and KPMG, fielded from November 2024 to mid-January 2025 and published in April 2025. Read as a policy failure, it is a headache. Read as a census, it is the more important fact: a majority of working people have already established a private intelligence relationship and are protecting it from their employer.

Contents
  1. The seat nobody opened
  2. What the numbers actually say
  3. The gap, inside one sample
  4. Why people hide it, and what hiding costs
  5. The three things a secret cannot do
  6. The right to leave has a ceiling
  7. Why the employer should want to be the node
  8. The ledger
  9. What I left out

01The seat nobody opened

A company buys an AI environment. Central administration, a seat for every employee, a training session on a Thursday, a policy document nobody finishes. Six weeks later the dashboard shows light use, and management concludes that adoption is hard, that people resist change, that perhaps the next release will land better.

Any weekday · 2:15 p.m.

The company’s assistant is open in a tab, because someone can see whether it is open. The work is happening on a phone, face-up beside the keyboard, in an account that belongs to the person holding it — the one that knows how he writes, what the customer said last spring, which two approaches already failed.

He reads the answer off the phone and types it into the company’s tool in his own words. The artifact arrives correct and on time. Nobody asks how. He would not be able to explain, in a meeting, why he does it this way, and he would rather not be asked.

That scene is a composite. I have not filmed it. But the behaviour in it is measured, repeatedly, at scale, and it is not a fringe. Nearly half of employees in the Melbourne–KPMG study admit to using AI in ways that contravene company policy, including uploading sensitive company information into free public tools. Only 40% said their workplace had any policy or guidance on generative AI at all.

The standard reading of this is a discipline problem with a training solution. That reading has the arrow backwards. Nobody smuggles a tool into a building at personal risk because they are undertrained. They do it because the tool on the other side of the wall serves them and the tool inside the wall does not.

The employee did not fail to adopt the company’s AI. The employee adopted his own, and declined to mention it.

So here is the argument, and I want to make it from the record rather than from the future: the case for a personal AI is no longer a proposal. It is a description. The question in front of a working adult in 2026 is not whether to have an intelligence relationship of their own. They have one. The question is whether it stays a secret — undocumented, ungoverned, unportable, carrying all of its risk personally — or becomes a center, with rules.

02What the numbers actually say

This subject has produced some of the most abused statistics in business writing, and I am not going to build on numbers I cannot stand behind. Three of the four figures everybody quotes are misstated, and each one is misstated in the direction that makes it more dramatic. Here is what each measures, who published it, and what it cannot tell you.

Figure 01 The four numbers this argument gets made with — and what each one is actually about
FigureWhat it actually measuresHow it is usually misquotedWhat it cannot tell you
95% Organizations in the sample getting zero measurable return from generative-AI investment. MIT Project NANDA working paper, July 2025. As “95% of AI pilots fail.” The report’s funnel is a separate finding: 60% of custom tools evaluated, 20% piloted, 5% reaching production. Whether the tools worked. It measures whether organizations could see a return on their own books six months out.
90% Companies whose workers reported regular use of personal AI tools for work. Same paper, same sample. As “90% of employees use personal AI tools.” The denominator is companies, not people. How many employees, or how often. It says the behaviour is present nearly everywhere, not how deep it runs.
40% Companies in that sample that said they had purchased an official large-language-model subscription. Rarely misquoted, and rarely quoted at all — though it is the number that makes the 90% mean something. Seat utilization. A purchased subscription is not an opened one.
78% AI users bringing their own AI tools to work. Microsoft and LinkedIn Work Trend Index, 31,000 knowledge workers across 31 markets, published 8 May 2024. As a current figure. Microsoft has not refreshed it: neither the 2025 nor the 2026 Work Trend Index reports a bring-your-own-AI number at all. Anything about 2026. Two years is a long time in this. Cite it as history or not at all.
Sources named in full in the references below. The NANDA paper is a non-peer-reviewed preliminary working paper from an MIT Media Lab initiative, its 95% headline has been publicly criticized on methodology, and the MIT-hosted link no longer resolves to the PDF — I use it for the 90/40 contrast within a single sample, not as a verdict on enterprise AI. The third and fourth columns are my framing, not the publishers’.

Notice what survives that scrubbing. The dramatic claim — everything fails — does not, and I am content to let it go. The structural claim does, and it is the one that matters: inside one sample, taken at one time, personal tools were in use at more than twice as many companies as had bought an official subscription. The intelligence arrived in the building in people’s pockets, ahead of procurement, without a budget line.

03The gap, inside one sample

Figure 02 Three questions, one survey: where the intelligence came from
Companies whose workers report regular personal-AI use for work 90%
Companies that purchased an official LLM subscription 40%
Custom enterprise AI tools that reached production 5%
  • What people brought
  • What the company bought
  • What the company built
All three figures come from the same source: MIT Project NANDA, The GenAI Divide: State of AI in Business 2025, July 2025, based on a review of more than 300 publicly disclosed AI initiatives, structured interviews with 52 organizations, and survey responses from 153 senior leaders gathered January to June 2025. The first two bars are company-level counts; the third is a tool-level production rate, so these are not three slices of one denominator. The report’s own chart label and its body text disagree on whether the 90% counts employees or companies; I use the body text, which says companies. Bar lengths are the reported percentages — nothing is interpolated. The key labels are mine.

A gap that size is not an adoption curve. It is a topology. The individual is at the center of the useful intelligence and the institution is at the edge of it — which is the exact inversion of how the org chart, the license agreement and the security review all assume the world is arranged.

04Why people hide it, and what hiding costs

Return to the 57%: employees who hide their AI use and present the output as their own. The obvious explanation is fear of policy, and in a workplace where roughly half the staff are technically in breach and only 40% of employers have written any guidance, fear of policy is entirely rational.

But policy does not explain the second half of that sentence. Concealing that you used a tool is caution. Presenting the work as your own is something else. It is the defence of an identity.

Most people do not merely perform their work; they are their work in a specific and load-bearing way. I write the proposal. I answer the customer. I reconcile the spreadsheet. Those sentences look like descriptions of tasks, and they are quietly doing the far heavier job of telling a person what they are for. Saying out loud that the proposal was drafted in ninety seconds threatens something much older and more personal than a compliance rule.

So the hiding is doing two jobs at once, and only one of them is about the employer. This is the part of the transition that productivity language cannot reach, and it is where the genuine difficulty lives. What is being asked for is not the surrender of a tool. It is the surrender of the sentence I am the things I personally execute, and its replacement with something less flattering in the moment and far more durable: I am the one who decides what should become actual, and who answers for it.

Execution can be delegated. Authorship cannot, and does not need to be. But nobody arrives at that distinction while the whole arrangement depends on no one finding out about it. A secret cannot be governed, examined, improved or defended. Which brings the cost of hiding into view.

05The three things a secret cannot do

A hidden personal AI is a real personal AI in roughly the way a jerrycan of petrol in the garage is a real energy system. It works. It is also the version with all of the exposure and none of the engineering. Three capabilities are missing, and they happen to be the three that convert a private habit into a sovereign arrangement.

  1. Selective disclosure

    A governed personal AI may understand the whole person and still give each relationship only the aperture it needs. The employer does not receive the medical history. The doctor does not receive the sales pipeline. A secret arrangement has no aperture control at all — which is exactly why “uploading sensitive company information into free public tools” shows up in the same survey as the concealment. The leak and the hiding are the same missing feature.

  2. The artifact / cognition boundary

    An institution can legitimately require an output: the visit record, the proposal, the compliance form, the ticket. It does not thereby acquire every rehearsal, doubt, draft and private reflection that produced the output. Stated plainly, that boundary is defensible to a manager and to a regulator. Kept as a secret, it is indistinguishable from evasion.

  3. An exit that preserves you

    The point of a personal operating environment is that leaving a job, a vendor or a model does not erase what you have accumulated. A workflow living in a personal account nobody knows about survives your employer — but not the loss of that account, and not the next provider. Portability you never designed is portability you do not have.

Figure 03 The reversal, in the order it actually occurs
  1. Node

    The person exists as an instance inside each institution’s system: employee, patient, account, seat, reservation. Continuity lives with the institution. This is the inherited arrangement, and it is a matter of record.

  2. Shadow

    General intelligence becomes personally available and cheap. The individual quietly routes real work through a tool that belongs to them. Measured, widespread, and already the present tense.

  3. Center

    The arrangement is named and governed. Identity, memory, permissions and tools belong to the person, and each institution becomes a connection entered under rules the person understands and can revoke.

  4. Published interface

    Institutions stop buying seats and start publishing what they need — policies, schemas, required artifacts, permission scopes — so that any competent personal AI can enter the domain safely.

Steps 1 and 2 are record: the node architecture is observable in any portal login, and step 2 is what the surveys in Figures 01 and 02 describe. Steps 3 and 4 are argument — my claim about where this goes, not a finding. None of it is a timeline; the stages overlap, and one person can occupy three of them before lunch.

06The right to leave has a ceiling

It is tempting to assume portability will arrive as a regulatory gift. Some of it has. It is worth knowing precisely how far it goes, because the shortfall is the whole reason this has to be architected rather than awaited.

The EU Data Act — Regulation 2023/2854, applicable since — obliges providers of cloud and edge services to remove the obstacles to switching, to offer open interfaces, to export a customer’s data in a commonly used machine-readable format, and, from , to stop charging for switching and data egress entirely. That is a real and underappreciated change. It also governs the plumbing: services, contracts, egress fees.

The GDPR’s Article 20 right to data portability is narrower than almost everyone assumes. It covers the personal data you provided to a controller — which the European regulators’ own guidance reads broadly enough to include observed data such as search history, location traces and a wearable’s heart rate. And it stops there. That guidance is explicit that the right should exclude inferred and derived data, meaning personal data created by the service provider. Profiles. Scores. Model outputs. Conclusions drawn about you. Those sit outside portability altogether, and the right only applies where the processing rests on consent or a contract to begin with.

The law will hand back what you typed. It will not hand back what the system concluded.

That ceiling lands exactly on the part that matters most. The value of a long intelligence relationship is not the transcript. It is the accumulated understanding — the preferences, the corrections, the working model of how you think and what you are trying to do. That is derived data by construction, and nobody is obliged to give it to you. If you want your accumulated self to survive a provider change, the only reliable route is to hold the environment yourself and treat the model as replaceable. Not because any provider is untrustworthy, but because a dependency whose exit you have never tested is not a dependency you have chosen.

07Why the employer should want to be the node

An institution usually hears this reversal as a loss of control, which is why it gets resisted by people whose actual job is to protect the organization. I think it is the opposite trade, and that the current arrangement is the one that should frighten a security officer.

Compare them honestly. In the seat model, the company owns an environment most employees use shallowly, pays for capacity that goes unopened, and has its sensitive data pasted into consumer tools it cannot see, by people who will not say so. In the connector model, the company publishes what it requires and what it forbids, receives better artifacts than it gets today, pays for far less idle licensing, and — this is the part that ought to close the argument — gains the standing to say what may cross this boundary to the intelligence that is actually doing the work.

  • Fewer unopened seats
  • Artifacts, not retyped screenshots
  • A boundary someone will actually declare
  • Policy aimed at the tool being used
  • No pretence that the institution owns the person

An institution has every right to define its domain: required records, security limits, permitted access, compliance obligations. Nothing here contests that. What it cannot legitimately claim, and cannot in practice hold, is the entire intelligence relationship of a human being who happens to work there for a while. The roofing company does not need every employee to use the company’s AI. It needs every employee’s AI to know how to work with the company.

08The ledger

What is load-bearing
One claim, and it is empirical: personal AI tools are already in use for real work at the large majority of organizations, at a rate roughly double official purchasing, and a majority of employees conceal that use. If those findings are wrong, this essay is a preference rather than an argument.
What is convention
The vocabulary — node, root entity, connector, selective disclosure, private cognition, the right to leave. These are my names for distinctions I believe are real. Someone could accept every finding here and carve the parts differently.
Where the shorthand breaks
“The employer becomes a node” describes topology, not law or power. Your employer still signs the cheque, owns its records, and can set conditions on what you use. Reversing the architecture changes where continuity lives. It does not change who holds the leverage in an employment relationship, and any essay implying otherwise is selling something.
The strongest objection, at full strength
All four headline figures are self-reported, and two come from a non-peer-reviewed working paper whose methodology has been publicly criticized, whose internal numbers disagree with each other, whose authors were simultaneously promoting an infrastructure standard as the remedy for the problem they diagnosed, and which is no longer hosted where it was published. Survey answers about rule-breaking are also exactly the kind of answer people give inaccurately, in both directions. The fair reading is that the direction of these findings is well supported and the precision is not. I have tried to write only what the direction supports.
Where I am probably wrong
Step 4 — institutions publishing machine-readable interfaces for personal AI instead of buying seats. Enterprise software is sold to procurement, not to people, and the incentive to keep it that way is enormous. I expect the reversal anyway, because it is already happening without anyone’s permission. But I would not bet on the timeline, and if this piece is wrong, it will be wrong there.

09What I left out

Two things I wanted and could not stand behind. First, a clean 2026 figure for the share of employees using AI tools their employer did not provide. It does not appear to exist: Microsoft’s 78% is from 2024 and was not refreshed in either annual report since, and the Melbourne–KPMG study describes the pattern qualitatively — most employees using free public tools rather than employer-provided ones — without publishing the split in its text. I could have estimated it. An estimate placed in that sentence would have looked exactly like a measurement.

Second, anything about what this does to employment. The honest answer is that I do not know, that the confident answers on both sides are marketing, and that a piece about where sovereignty resides is not improved by a forecast it cannot support.

What remains is narrower and, I think, harder to argue with. The decision has already been made by most of the people reading this — in private, without a framework, at some personal risk. The only open question is whether it gets to be a considered arrangement with a boundary, a disclosure rule and an exit, or stays a phone face-up beside the keyboard.

The question was never whether you would have an intelligence of your own. You already do. The question is whether it will be a secret or a center.

Sources

  1. Gillespie, N. & Lockey, S., Trust, attitudes and use of artificial intelligence: A global study 2025, University of Melbourne & KPMG. 48,340 respondents across 47 countries, fielded November 2024 to mid-January 2025, published April 2025. Source of the 57% concealment figure, the policy-contravention finding, and the 40% workplace-policy figure. Report
  2. Challapally, A., Pease, C., Raskar, R. & Chari, P., The GenAI Divide: State of AI in Business 2025, MIT Project NANDA, July 2025. Preliminary and non-peer-reviewed. Source of the 95% zero-return figure, the 90% / 40% personal-versus-purchased contrast, and the 60/20/5 production funnel. Mirror of the PDF
  3. Raynovich, R. S., “Why We Don’t Believe MIT NANDA’s Weird AI Study,” Futuriom, August 2025 — the methodological criticism referenced in the ledger. Article
  4. Microsoft & LinkedIn, 2024 Work Trend Index Annual Report: AI at Work Is Here. Now Comes the Hard Part, 8 May 2024. 31,000 knowledge workers across 31 markets, fielded 15 February to 28 March 2024. Source of the 78% bring-your-own-AI figure, cited here as history. Report
  5. Regulation (EU) 2023/2854 (Data Act). In force 11 January 2024, applicable from 12 September 2025; switching charges including data egress removed from 12 January 2027. Official Journal text
  6. Regulation (EU) 2016/679 (GDPR), Article 20. Official Journal text
  7. Article 29 Data Protection Working Party, Guidelines on the right to data portability, WP 242 rev.01, adopted 13 December 2016, last revised 5 April 2017 — the source of the exclusion of inferred and derived data. Guidelines

Related

Author: John Rector

John Rector is a Charleston-based entrepreneur, author, and AI strategist. He co-founded E2open, the supply-chain software company acquired for $2.1 billion in 2025, and in 2026 opened Charleston AI, a 3,000-square-foot lab that helps people and organizations understand and use artificial intelligence. He is the creator of The Reality Equation — a lecture series, book, and curriculum exploring attention, prediction, and how reality is experienced — and the author of more than two dozen books. He writes and speaks widely on artificial intelligence, attention, and the future of human work.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from John Rector

Subscribe now to keep reading and get access to the full archive.

Continue reading