Across companies monitored by Fendr, employees actively used more than 20 distinct AI tools in the past six months. Most of those companies had an AI acceptable use policy. Most of those policies specify only up to three tools.
Employees choose tools by task, not by policy. The tool changes. The behaviour does not.
The gap is not unusual. It is the norm.
ChatGPT appears in activity data across every monitored organisation. Claude and Gemini appear in most. Microsoft Copilot, Perplexity, Grok, Notion AI, DeepL appear regularly across different companies. So do coding tools like Replit, presentation tools like Gamma, transcription tools like Otter.ai and writing assistants like Quillbot and Grammarly. That list covers tools for six different job functions, from developers to finance teams to operations.
The pattern holds regardless of what the IT policy says, because employees choose tools by task, not by policy. ChatGPT handles general writing. Perplexity works better for research that needs citations. Developers use Replit or GitHub Copilot. DeepL beats general models for translation. These tools are not interchangeable, and employees have worked out which one does which job.
Why Consolidation Has Not Happened
The common assumption is that the AI market will settle, the same way the cloud storage market settled on a handful of providers. That has not happened. New tools launch monthly. Established productivity tools add AI features without employees installing anything new. Copilot appears inside Microsoft 365. Gemini appears inside Google Workspace. An employee using their normal spreadsheet tool may be submitting data to an AI model without thinking of themselves as "using AI" at all.
Fendr telemetry shows the number of distinct web domains employees visit growing month on month. July 2026 is tracking above every previous month in the dataset. The scope of what needs governing keeps expanding.
Growth indexed to February baseline · Absolute figures not disclosed
The Data Gets Shared Regardless
Paste events account for the large majority of AI interactions Fendr monitors, significantly outnumbering file uploads. Employees copy from internal documents, spreadsheets, email threads and client records, then paste directly into whichever AI tool they are using. The tool changes. The behaviour does not.
A policy that restricts file uploads to approved tools leaves the paste vector untouched, across every tool on the list.
What This Means for Your Policy
The answer is not to block AI outright. Teams that try, find employees move to personal devices or mobile connections, and usage becomes invisible rather than stopped.
The more practical approach is to define which tools are approved, specifically those with Data Processing Agreements in place, and redirect employees toward those when they try to use something outside that list. Employees still get to use AI. The organisation retains control over which tools handle its data and under what terms.
That requires knowing which tools are already in use. Most IT teams find the list longer than expected. Fendr's free audit maps active AI tool usage across your organisation in under five minutes, with no infrastructure change required.
Ready to see what your team is actually using?