Someone pastes a piece of text into a chat window to get a summary, a translation, or a draft text more quickly. The window is free, the account is personal, and no one asked for permission because no one knew permission was needed. This is the most common form of AI use in an organization, and at the same time the least visible.
A free chat window requires no approval from IT, no budget, no procurement process. It requires only a browser. Anyone who wants to do a task faster opens the window, pastes in the text, and gets an answer. The data entered in the process can be anything: a customer file, a draft text with commercially sensitive figures, an email with personal data. What happens to that data after it is pasted is usually unknown to the user. What the organization has agreed to is nothing — there is no contract, no data processing agreement, no arrangement regarding retention periods.
This does not happen through carelessness. It happens because the window works, is faster than the official alternative, and no one has ever explained where the line lies. The same dynamic underlies a browser extension with access to your email: a tool that is functionally useful, gets installed entirely out of sight, and processes data without anyone having assessed it.
A chat window does not disappear because a policy document is issued. It does not disappear because IT publishes a list of approved tools. As long as the free window works faster than the alternative, it will keep being used — only then without anyone reporting it. A ban without an alternative drives usage underground; the work does not disappear, only the visibility.
This pattern repeats itself in multiple places within an organization. A team that has had good experiences acquires its own subscription without anyone outside the team knowing. A pilot that started as a trial keeps running because no one was tasked with shutting down a trial setup that was never switched off. The IT list of approved software is, in none of these cases, a reliable reflection of what is actually happening. Anyone who wants to know what is going on has to ask — not as a control measure, but as an inventory.
The difference between an organization that gains insight and one that does not lies in the manner of asking. Anyone who asks with the threat of sanctions in the background gets no answer — or an answer that is not accurate. Anyone who asks without repercussions, with the message that the goal is to gain a picture and not to punish, gets honest information.
That picture has to land somewhere. Not in a list that is outdated after a month, but in a structure that records what is running, who uses it, what data goes into it, and what risk applies to it. How you build an AI inventory describes how that inventory process works without a witch hunt: as an ongoing process, not as a one-off action that is then forgotten again.
Every application that surfaces should come with a fixed set of information: what it does, who uses it, what data goes into it, and on the basis of what agreement that happens. Without that record, a chat window remains a gamble rather than an assessed choice. What you need to record per application describes that fixed set, regardless of whether the application is a free window, a paid subscription, or a tool that came in through a supplier. A supplier, incidentally, can also be the trigger itself: a supplier that built AI into its product changes the nature of an existing contract without there always being a new agreement to match.
A free chat window is not a problem by definition. It is a signal: there is a task someone wanted to do faster, and the existing offering did not provide for that. The question is not only whether the use stops, but whether the organization offers an alternative that does fit within the agreements — and whether it knows what data has since been processed through a channel over which it had no control.
Those two questions together — what is running, and what could replace it — lead almost naturally to a third question: which part of the work that now runs through a loose chat window is actually a task that can be taken over by AI in an assessed manner. That is precisely what the work scan from FTE TO AI was built for: it calculates, per task, which part of the work can be taken over by AI, so that the answer to a free chat window is not only a ban, but also a view of what is possible instead.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.