By Lynn Räbsamen, CFA | Advisory Board Member, CFA Institute | Author, Artificial Stupelligence
Ask whether employees in regulated industries are less productive with AI, and the uncomfortable answer is probably yes.
I am by no means saying they are worse at their jobs. But picture two analysts of equal skill, one at a marketing agency and one at a bank, neither firm offering a sanctioned AI tool of its own. The agency analyst connects a consumer AI tool to her spreadsheet and finishes in a fraction of the time. The bank analyst cannot, because her firm has closed every door that would let her do the same.
The gap is architectural, not personal. Regulated staff are every bit as capable as their peers. They are simply on the other side of a wall their firms built to satisfy regulation, and the wall is doing exactly what it was designed to do.
This piece lays out that asymmetry, and what regulated firms can actually do to catch up.
Where productivity actually happens
The corporate world struggles to prove genuine AI adoption and real productivity gains. One likely reason is that the largest real gain in most firms is unprocured and invisible.
Most of the real gain happens on the personal layer. The countable wins are dull single workflows.
The everyday face of this is mundane. An accountant connects a consumer AI tool to her spreadsheet. A marketing executive connects it to her slide decks. A salesperson exports CRM data into a public model to come up with an outreach strategy.
Shadow AI is the only productivity gain in a company that is both real and entirely off the books.
39.7% of AI prompts carry sensitive data
In the 2025 global study by KPMG and the University of Melbourne, which surveyed more than 48,000 people across 47 countries, 58% of employees said they intentionally use AI at work, and nearly half admitted using it in ways that break company policy.
The split between what firms bought and what staff actually use is starker still. MIT’s State of AI in Business 2025 found that employees at more than 90% of the companies it surveyed regularly use personal AI tools for work, while only 40% of companies had purchased an official subscription.
The sanctioned tool exists in 40% of firms. The unsanctioned habit exists in 90%. The distance between those two numbers is the productivity nobody procured.
Cyberhaven, which monitors actual data flows rather than asking people what they do, reported in early 2026 that 39.7% of AI interactions involve sensitive data, and that a large share of usage runs through personal accounts. This is not a fringe habit. It is the workflow.
Why the bank cannot follow
Connecting a consumer tool to internal files and pushing client data into a public model are exactly what a regulated firm is obliged by law and regulation to stop. Understandably, the response is a set of hard technical blocks. Download restrictions keep the installer off the machine. Plugin and extension whitelisting keeps the connector out of the sanctioned software. Browser policy closes the open web. Data loss prevention watches the exits.
But this creates an uncomfortable asymmetry.
The control that prevents the leak is the same control that prevents the productivity gain.
There is no setting that blocks one and permits the other. The controls are legitimate. That is the whole problem. A legitimate control has a price, and this one is invisible.
Most firms have policies, not guardrails. So the high shadow AI numbers in the headlines describe the loosely governed majority, not the locked-down bank. Where the controls are real, the containment is real. And that is the uncomfortable finding.
If the controls work exactly as designed, it means the productivity that shadow AI delivers elsewhere is not seeping in at the edges. In firms with hard technical restrictions, it is simply absent.
The firms with the best controls are losing the most productivity they cannot see.
The answer is not to ban
The market is already voting. In Cisco’s 2026 benchmark, outright bans on generative AI collapsed from 28% of organizations to 7% in a single year, as firms swapped blanket prohibition for governed access. Banning does not recover the gain. It only locks in the loss.
However, the sector is spending heavily without much to show for it yet.
In Grant Thornton’s April 2026 banking survey, only about a third of banks reported revenue growth from their AI deployments (32%) or lower costs (36%), and just 2% said AI was fully embedded in operations. Half named governance and compliance as the barrier holding performance back.
The free tool an employee reaches for wins because it fits the actual workflow and runs at the speed of the newest public model. The sanctioned one rarely does.
The data points in a direction, not a settled number. But it points one way. A regulated firm’s staff cannot close the gap informally, so whatever the firm chooses is the only AI its people will ever touch. That makes the choice more important, not less.
The move is to bring the sanctioned tools inside the walled garden.
Doing that well is harder in a regulated firm than almost anywhere else. It takes people who understand the workflows, the models and the regulatory obligations in equal measure.
Large institutions can source the capability in-house. Small ones often cannot, and their real choice is narrower than it looks: an unselected tool, or an outsourced selection. That is a governance conclusion, and it is where this piece stops. What the right tool looks like is a different article.
The question for the board
The reflex question in the boardroom is: how do we control it? For a regulated firm, that question is already answered. The guardrails work. The leak is closed.
The better question is quieter and more expensive.
What did our competitors’ staff choose, and why was it never on our list?
Compliance can tell you what your people are not allowed to do. It has nothing to say about what that costs. The number is real. It is simply filed under nothing.
Parts of this article were drafted by AI and reviewed and edited by a human.
For more insights about what AI can or cannot do, check out my book “Artificial Stupelligence: The Hilarious Truth About AI“.
Subscribe here to be the first to receive my insights.







