Corporate conundrum: Why guidance and guidelines are needed for AI usage among employees


As employees embrace AI, a new concern is emerging: what happens when they bring their own AI tools into the workplace without their employer’s knowledge and approval? — Image by Magnific

As Malaysia works towards becoming an artificial intelligence (AI) nation by 2030, the technology is already seeing increasing adoption, from ­recreation in people’s personal lives to boosting productivity in the workplace.

But as employees embrace AI, a new concern is emerging: what happens when they bring their own AI tools into the workplace without their employer’s knowledge and approval?

This appears to be a grey area in many businesses, with a Microsoft report published at the end of June this year ­highlighting that Malaysian employees are outpacing their employers in adopting AI.

The report, titled the 2026 Work Trend Index, found that 24% of Malaysian respondents are ­categorised as “Frontier Professionals”, which Microsoft describes as being the most advanced AI users. By contrast, this sits higher than the global figure of 16%.

The study – which ­surveyed 2,000 full-time employed and self-employed knowledge workers in Malaysia – also notes that only 32% of AI users believe their corporate leadership is clearly and consistently aligned on AI.

Meanwhile, an Amazon Web Services (AWS) study titled “Unlocking Malaysia’s AI Potential 2026” – involving 1,000 businesses and 1,000 members of the public in Malaysia – found that while 38% of businesses use at least one AI tool, only 19% of them have a formal strategy to expand their use across other roles in their company.

The Malaysian Employers Federation (MEF) observed a similar trend among companies in Malaysia with its 2025 Survey on the Adoption of AI in Business.

According to MEF president, Datuk Dr Syed Hussain Syed Husman, the survey found that 65.8% of Malaysian employers have seen a positive impact in terms of productivity and ­efficiency with AI, but this does not come without caveats.

“Many employees are ­independently using publicly available AI platforms before their employers have established formal AI governance frameworks, approved tools, policies or training ­programmes.

Syed Hussain explains that many employees may not realise that information entered into public AI tools could potentially be retained, analyse or used to further train AI systems. — MEF
Syed Hussain explains that many employees may not realise that information entered into public AI tools could potentially be retained, analyse or used to further train AI systems. — MEF

“While such initiative reflects employees’ willingness to innovate and improve productivity, it also creates significant governance, legal and operational challenges.

“Organisations may find themselves exposed to risks involving confidential information, personal data protection, cybersecurity, ­intellectual ­property ownership, misinformation, bias and compliance obligations,” he says.

This is further underlined by another data point from the MEF survey, involving 129 local ­companies and 76 multinational ­corporations operating in Malaysia, which found that only 4.5% of them have a formal ­written AI strategy.

Potential risks

The studies highlight a key point: there is a mismatch between how employers and employees approach the use of AI tools.

From the perspective of Jess O’Reilly, Asean general manager at human resources services provider Workday, some employees may be too quick to assume that AI-generated ­output is ready to use.

“A common mistake is ­treating AI output as finished work. Without the right context and oversight, deploying AI simply shifts the productivity bottleneck.

“Time saved generating an output is then spent checking, correcting or rewriting it. In Malaysia, 53% of respondents to a Workday productivity study said they spend between one to two hours each week reworking AI output.

“For employees, unverified AI output that reaches a client or a colleague carries reputational cost, and the rework erodes the productivity gain they were promised,” she says.

O'Reilly notes that high adoption does not necessarily mean effective adoption. Employees need the skills and confidence to work with AI, interpret its outputs and apply their own judgement. — Workday
O'Reilly notes that high adoption does not necessarily mean effective adoption. Employees need the skills and confidence to work with AI, interpret its outputs and apply their own judgement. — Workday

Cloudflare APAC field chief technology officer Volker Rath shares similar thoughts, pointing out that giving too much weight to an AI tool and treating it as an authoritative source is a critical mistake.

“The most critical mistake is treating generative AI as a search engine or an absolute source of truth rather than an assistant that requires continuous validation.

“When employees put too much trust on outputs for financial, legal, or customer-facing decisions, they introduce severe operational risk.

“Employees should keep in mind that they own the AI ­output they use for their work and are fully responsible for incorrect content,” he says.

Shadow AI

This is on top of the risk ­introduced when employees use AI tools without their employer’s knowledge. This is known as “shadow AI”, ­referring to the use of AI without company oversight or approval.

One such case was widely reported back in 2023, when South Korean tech company Samsung banned the use of ChatGPT by employees after an incident where sensitive code was uploaded to the AI ­platform.

Business Insider also reported in 2024 that Amazon warned employees not to use generative AI models for work.

Rath says shadow AI is a major concern for organisations, as it can contribute to data breaches and the violation of privacy laws.

Rath says the most critical mistake is treating generative AI as a search engine or an absolute source of truth rather than an assistant that requires continuous validation. — Cloudflare
Rath says the most critical mistake is treating generative AI as a search engine or an absolute source of truth rather than an assistant that requires continuous validation. — Cloudflare

“On the employer side, organisations should look out for two major risks when it comes to internal AI adoption: Shadow AI and non-compliant use of ­sanctioned AI tools.

“These risks are all related but require different controls to manage. With shadow AI, employees feed sensitive ­corporate data, source code, or customer information into unapproved, third-party AI tools to get their jobs done faster.

“In a ‘gold rush’ environment, speed often trumps security and compliance. An example for non-­compliant use is when employees ­consume large amounts of tokens for non-­approved or personal use cases,” he says.

Syed Hussain says such ­practices could breach local ­legislation, such as the Personal Data Protection Act 2010 (PDPA), if employees upload personal data, employee records, ­customer information, or other ­confidential business information to public ­platforms without proper ­safeguards, authorisation, or consent.

“From an employee’s ­perspective, unauthorised ­disclosure of confidential information may constitute misconduct, particularly where employees have been informed of company policies regarding confidentiality, information security and AI use.

“Depending on the circumstances, employees may be subject to disciplinary action if their actions result in serious breaches of company policy, confidentiality obligations or legal requirements.

“Importantly, many employees may not ­realise that information entered into public AI tools could ­potentially be retained, ­analysed or used to further train AI systems.

“This creates risks that extend well beyond the ­individual user and may affect the entire ­organisation,” he says.

Syed Hussain adds that ­public AI systems often use external servers to process information, further moving what could be confidential corporate data out of an employer’s direct purview.

“For these reasons, AI ­governance can no longer be treated as purely an IT issue. It has become an employment, legal, risk management and ­business governance issue,” he says.

Despite such issues, Rath stresses that employees should not bear the burden of risk ­during what is a major foundational shift in work processes.

“When leadership fails to provide safe, secure tools, employees will naturally default to personal, unvetted AI applications to keep up with productivity demands.

“Any major technology change, from mobile technologies to cloud computing, has proven this. While employees must exercise basic judgment, the core responsibility lies with executive leadership and security teams.

“Governance teams cannot wait months to draft policy frameworks while the business and industry move ahead,” he says, adding that clear boundaries must be set, where staff can safely experiment with new technologies with guardrails rather than a complete ban.

For O’Reilly, this means the ball is in organisations’ court to develop policies and perform the groundwork beforehand when it comes to AI use.

“Organisations need to ­establish and enforce clear guardrails around what information can be shared with AI and how employees are permitted to use the respective AI tools.

“Once information is entered into an external AI tool, organisations will have less visibility or control over how that information is processed, stored or accessed,” she says.

Moving forward

For organisations looking to encourage responsible AI use among employees, Syed Hussain advises establishing clear ­policies and guidelines, including identifying approved AI tools and restricting unauthorised applications.

This should come alongside robust data governance and cybersecurity controls, with employers conducting risk assessments before deploying AI.

At the same time, they should ensure transparency and human oversight when AI is used to assist in decision-­making, while providing ­regular employee training on the legal, ethical and compliance implications of AI.

Employment policies should also be regularly reviewed to address emerging AI-related risks, while organisations stay on top of regulatory developments.

Such measures could help employees make better use of AI in their day-to-day work while ensuring that efforts to manage its risks do not come at the expense of productivity gains, Syed Hussain adds.

O’Reilly adds that beyond just establishing a policy and providing tools for their staff to use, employers should also invest in training and upskilling to ensure AI is used properly.

“Employees need to understand both what AI is capable of and where human judgement remains essential.

“When organisations combine trusted AI with skilled employees and clear accountability, AI can augment people and allow them to focus on more meaningful, higher-value work,” she says.

In cases where there is not yet a formal policy in place, however, Rath says that employees need to take the ­initiative by exercising caution to minimise risks.

This can be done by treating every public-facing AI tool or service as an untrusted third-­party entity, meaning that unless data is explicitly cleared for sharing with the public, it should not be provided to such tools.

“Using AI for abstract tasks – like structuring a presentation, summarising public articles, or brainstorming concepts – is low risk. However, any proprietary code, customer data, internal strategy documents, or financial metrics must strictly remain off third-party platforms,” he says.

Bringing balance

At the same time, Rath says companies developing their own AI strategies and policies can strike a balance between ­maintaining productivity and managing risk.

“Data classification policies should describe very clearly what data is classified as public and what data is considered sensitive. While individual ­diligence – such as stripping sensitive identifiers or double-­checking facts – is essential, relying on employee memory and manual caution is not a strategy.

“Organisations cannot ­govern machine-speed ­interactions with policy ­manuals alone. It is very important to establish ­controls that provide the organisation with organisation-­wide ­visibility and control across all AI usage use cases.

“Data Loss Prevention (DLP) and inline inspection tools (such as an AI Gateway) can help to establish visibility and control and detect non-­compliant behaviours even if an employee inadvertently pastes credentials, proprietary code, or confidential customer files to an external LLM (large language model),” he says.

DLP refers to measures intended to prevent the ­unauthorised sharing or leakage of sensitive information by ­automatically detecting and restricting how data is moved across networks, ­devices and applications ­within an organisation.

Meanwhile, an AI gateway would function as a centralised platform for an organisation’s AI tool use across various ­services, acting as an additional layer that can detect and mask sensitive data before it reaches external service providers.

“Security teams need to move past static blocklists and immediately deploy edge-based visibility tools to discover which AI services are being accessed, establish baseline telemetry, and secure these endpoints to minimise risks,” Rath adds.

O’Reilly highlights that successful AI deployment is also built on trust, clarity and consistent leadership commitment.

“Leaders must set the tone, explain why the change matters and lead by example in using the new tools and adopting new ways of working. Organisations should also treat AI rollouts as an organisational transformation rather than solely a technology deployment.

“High adoption does not ­necessarily mean effective ­adoption. Employees need the skills and confidence to work with AI, interpret its outputs and apply their own ­judgment,” she says.

O’Reilly concludes: “The goal is therefore not to restrict ­employees from using AI. It is to create an ­environment where humans and AI ­complement each other’s strengths.”

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Others Also Read