Your teams already use AI. That is not a hypothesis, and it is not a discipline problem either. What is missing is almost never the rule: it is the door. The same model, at the same provider, does not handle your data the same way depending on the account it is called through, and that gap is not fixed by a memo. So this article will not tell you your staff are putting you at risk. It tells you what the six doors are, what each one really does, how to settle any case in one sentence, and what five days are enough to change. It starts with a story.
A story, first
I will call her Nadia. She runs a services firm, eighty people, two offices. One Monday in June, in a team meeting, her best account manager shows how she now puts a commercial proposal together in forty minutes, where it used to take a day. The demo is excellent. Everyone applauds, and Nadia is genuinely pleased.
Then the account manager shares her screen to show how she does it. In the left-hand column of the tool, the conversation history stays up for thirty seconds. Eleven client names. The firm’s largest account. And one conversation whose title is a contract reference.
Nobody hacked anything. There was no breach, no attack, no negligence in the usual sense of the word. There is the most motivated employee in the firm, who did her job faster, in a free personal account, because nobody had ever given her another door.
Nadia’s first instinct is everyone’s: block it. Her IT person stops her, and the argument fits in one sentence: blocking the domain on the office network moves the use onto phones by Wednesday, and from then on she sees nothing at all. What she would lose is not the use, it is the visibility.
What she did is the week I set out at the end of this article. But the result that mattered did not come from an audit. It came from the amnesty week: someone in finance eventually said that six months earlier he had pasted a bank access credential into a conversation, to get help reformatting a file.
It was the only incident in the whole firm that called for something to be done that same day. And it was also the only one no monitoring tool would ever have shown Nadia, because it happened at his home, in the evening, on his phone.
This story is a composite. The people, the sector and the details come from several situations I have met, and nothing in it is identifiable. The mechanism is exact, and it is always the same: the discovery happens by accident, the incident that matters is not the one you can see, and it only surfaces if nobody risks anything by saying it.
Banning it is what costs you most
Let us start with the result that should decide your week, because it contradicts precisely what instinct says to do.
The University of Melbourne and KPMG surveyed more than forty-eight thousand people across forty-seven countries, on samples built to be representative of each national population, with the study designed and analysed by the university. It is, as far as I know, the only work of that scale on this subject not commissioned by someone selling the remedy. Among employees who use AI at work, those whose employer bans generative AI are the most likely to report having put sensitive company information, or copyrighted material, into a consumer tool. Here are the four situations, in the order the study gives them: where AI is banned, 67%. Where there is a policy guiding use, 56%. Where employees do not know whether a rule exists, 38%. And where there is no policy at all, 33%.
Read the column again. The company that took the trouble to ban it is in a position twice as bad as the company that wrote nothing, and the authors draw the conclusion themselves: outright bans may be ineffective, and simply having a policy does not guarantee it is followed.
This is an association and not a demonstration of cause and effect, and that has to be said, because the arrow may well point the other way: a company that bans is often a company that had already seen something. There is a second bias, and it should be stated too: where AI is banned, the employees who use it anyway are no longer the same population as the rest, since they have already decided to work around a rule. So this result does not prove that banning drives data out. It proves, which is already a great deal, that banning does not keep it in.
What does work is measured elsewhere, by a different method, and that is the source carrying this article’s recommendation. Netskope observes its customers’ network traffic rather than asking them questions. Between its last two annual reports, the share of AI use going through personal, unmanaged accounts fell from roughly three quarters to about half, while the share on employer-provided accounts rose from a quarter to nearly two thirds. Over the same period those same customers were blocking more than ever: nine organisations in ten block at least one AI tool, around ten on average, while prompt volume multiplied sixfold. Blocking and shadow use grew together. What moved the line was the other move: nobody was persuaded, people were provisioned.
What these figures are actually worth
I would rather give you the reservations than let you find them. The Melbourne and KPMG study is self-reported: you are asking people whether they did something they know is frowned upon, which pushes toward under-reporting. And the published figure counts everyone who did it at least once, even rarely; keep only those who do it regularly and you land around a third. The ranking between the four situations is the solid result. One last reservation, the most important: fieldwork ran from November 2024 to January 2025, so before the wave of provisioning the next source measures. It describes a world where almost nobody yet had a door.
Netskope, conversely, measures real behaviour rather than statements, but sees only its own customers, that is companies that already bought a network security product, and sells exactly what its conclusions make necessary. The two sources do not corroborate each other: they complement each other because they are wrong in different directions.
A word finally on a figure you will see everywhere and that I do not use. People regularly write that the share of sensitive data pasted into AI went “from 11% in 2023 to nearly 40% today”. Both numbers exist, but they do not measure the same thing: the first is a share of data volume, the second a share of interactions. Chaining them draws a curve that does not exist. On a constant basis, the series published by that same vendor runs from 10.7% in March 2023 to 34.8% in 2025, which is still considerable, and can be said without bending the axis.
Six doors to the same model
Now to the heart of it. The question every executive asks at this point is “does the model train on my data?”. It is the wrong question, and it is wrong for a precise reason: it has a simple answer, it is settled by ticking a box, and it makes you miss the other three. The right questions are: which contract am I under, what stays and for how long, and what happens the day somebody outside asks for it to be handed over?
Those three answers do not depend on the model. They depend on the account you walk in through. The same model, at the same provider, at the same hour, handles your data in six different ways depending on the door. Here are the six, with what each really does, and what each fails to fix.
Six doors to the same models. Move from the most open to the most closed, and watch what changes.
Who it is for
Nobody, at work. It is nonetheless your teams’ default door.
Cost
Zero to about twenty euros a month, paid by the employee
- Training on your data
- Yes, by default. At OpenAI, a personal account, free or paid, has sharing switched on out of the box and the user has to turn it off. At Anthropic, since August 2025, consumer-tier conversations may be used for training, and the box was pre-ticked in the consent dialogue. At Google, activity feeds training when the setting is on.
- What stays, and for how long
- Thirty days after deletion at OpenAI. Up to five years at Anthropic for anyone who leaves the option on. And at Google, the detail nobody knows: conversations reviewed by a human are kept for up to three years, and they are not removed when you delete your activity.
- What you get to see
- Nothing. No admin, no logs, no list. You do not know who uses what, and you cannot find out.
- If an authority asks
- This is the exposed tier. The US preservation order of May 2025 that froze deletions covered consumer accounts; the twenty million conversations since ordered into production come from that same tier. Enterprise offerings were excluded from both.
What this door does not fix
Nothing, and least of all the employee’s departure. The account is theirs: you can neither audit it, nor wipe it, nor close it on the day that person leaves.
As of 30 August 2026.
Three things are worth pulling out, because they contradict what is usually said.
Most of the journey happens at the second step. Moving from a personal account to a team subscription removes training by default, hands you control of the retention period, and ties accounts to the company. That is a credit card and an hour. The steps beyond serve real but particular situations, and many companies will never need them.
The most protective door is not free in capability. This is the 2026 twist and it is almost absent from the conversation: Anthropic’s newest models require thirty days of retention and are not eligible for zero retention. In other words, maximum protection costs you access to the best available. That is not a reason to give up either one, it is a reason to choose per use case rather than by principle.
And the structure is the same everywhere. This is not an article against one provider: all three majors have exactly the same split, a consumer door whose default setting works against you and a business door that reverses it. What changes is the product name to ask procurement for.
ChatGPT
OpenAI
The consumer door
The individual plans, free or paid. On a personal workspace, sharing data for training is on by default, and it is up to the user to switch it off.
The door to open
ChatGPT Business for a team, ChatGPT Enterprise for the company. No training by default on either, and a retention period you set.
What surprises people
At the Business tier, an admin can view, export and delete your employees’ conversations, and third-party contractors may review the content to detect abuse. Neither is true of the tiers above. Announce it yourself rather than letting them find out.
Claude
Anthropic
The consumer door
The Free, Pro and Max plans. Since August 2025, new or resumed conversations may be used for training, and retention then extends to five years. The box was pre-ticked in the consent dialogue.
The door to open
Claude for Work, team or enterprise, or the API. The commercial offerings are expressly excluded from the regime above.
What surprises people
The best illustration in this whole article fits on one line, and it is aimed at your developers. Claude Code launched from a personal subscription puts your codebase into the five-year regime. The same tool, on a commercial key, does not. Same software, same model, two different worlds.
Gemini
The consumer door
The Gemini app on a personal Google account. Activity feeds training when the setting is on, with automatic deletion at eighteen months by default.
The door to open
Gemini in Google Workspace, with the contractual commitment not to train on your data and not to have it human-reviewed outside your domain.
What surprises people
A subset of conversations is reviewed by humans, and those are kept for up to three years. More to the point, they are not removed when you delete your activity: there is no button that reaches them. Google writes it itself, and the sentence deserves quoting as it stands: do not enter data that is confidential, or that you would not want a reviewer to see.
What nobody has told you
Four things I never hear in a board meeting, each of which shifts a decision you are about to take.
It is almost never a hack. It is a Share button. People picture a leak as an intrusion: a theft, a forced server, someone with bad intentions. Look at what actually happened. In July 2025 a journalist finds that shared ChatGPT conversations are showing up in Google results; days later a researcher gathers close to a hundred thousand of them, in which one outlet finds the text of confidentiality agreements and discussions of contracts. In August it is Grok’s turn, and worse: at ChatGPT you had to tick a box labelled “make this chat discoverable”, at Grok pressing Share was enough to publish, uploaded files included. At Meta, the AI app offered a public feed where people published their own conversations, home addresses and medical questions included, believing they were sending them to someone.
None of these episodes is a flaw. They are sharing features that worked exactly as designed, in front of people who read “send” where it said “publish”. And to remove any idea that your teams are too savvy to be caught: a researcher at a well-known artificial intelligence institute was caught out by Grok after the ChatGPT story had gone round the world, while sharing summaries of his own articles with his team.
There is better, and this detail should finish moving your attention. OpenAI published a detailed technical analysis of a March 2023 incident that exposed billing data, for nine hours, for a little over one percent of its paying subscribers. On the sharing feature, which exposed conversation content at a scale outsiders counted in the tens of thousands, it has never published a single figure. The risk that matters is not the one that gets an incident report.
The day your best person leaves, their account leaves with them. Open your offboarding checklist: badge, laptop, mailbox, file access, phone, car. It is all there, except one thing. The personal account in which that person spent two years preparing your proposals, your price lists and your meeting notes is on no list, because it was never yours. You cannot audit it, you cannot wipe it, you cannot even know what is in it. And it will still be there, with its history intact, on the Monday that person starts at your competitor. It is the one hole in your offboarding process that the company door closes completely, and in only one way: by making the account yours.
Your teams hide it for a measured, rational reason. Concealment gets explained by carelessness or bad faith. The research says otherwise. A series of thirteen experiments published in 2025 shows that disclosing you used AI lowers the trust people place in you, and that being found out by a third party lowers it further still than saying so yourself. Another study, on more than four thousand people, finds that those who use AI are judged less competent and less motivated, and that this judgement carries through into hiring decisions.
In other words, the employee who says nothing is not behaving badly: they are avoiding a social penalty the research has measured, and which they read correctly. A policy that asks people to declare themselves is therefore fighting a documented mechanism. Your job is not to demand candour, it is to remove what candour costs. That is the whole point of the amnesty week described below, and it is also why it has to come from you and from nobody else.
What you tell an assistant is covered by no privilege. Here is where you put the coffee down. In February 2026, a federal court in New York held that an executive facing fraud charges could claim neither attorney-client privilege nor work product protection over some thirty exchanges he had had with a consumer assistant, built from what his lawyer had told him, before forwarding them to that same lawyer. The judge notes that the question had never been decided anywhere in the country, and that these documents did not meet the conditions for privilege: they were not confidential, and they were not prepared at the direction of counsel. There was nothing to protect.
It is not an isolated case. In another matter, US prosecutors obtained warrants covering seven of the defendant’s accounts at two AI providers at once, arguing in writing that a conversation with an assistant is not privileged because an assistant is not a lawyer. And a New York judge, in January 2026, wrote that a user’s privacy interest in their ChatGPT conversations is weaker than the interest attaching to a wiretapped phone call, because the user voluntarily disclosed them to the provider. These are American, first-instance decisions, and they should not be turned into settled law. But they are the only case law that exists today, and it all points the same way.
The practical consequence fits on one line, and it is more useful than everything else here: the day an executive has a real problem, legal, employment or financial, the assistant is the last place to discuss it. Not because it is indiscreet, but because the conversation exists, it is retained, and nobody is protecting it.
The legal frame, in three points
One. Your ban changes the legal character of the next incident, and not in the direction you want. When an employee pastes personal data into a consumer tool, instinct says a processing contract is missing. It is not: for the consumer version, the provider is itself a controller, not your processor. So it is not a missing contract, it is a disclosure to a third party. And the Dutch data protection authority drew the distinction with unusual precision: if the employee acted against company rules, it is a personal data breach, with the notification duty that follows; if the company had permitted it, it is not a breach, but it is most often not lawful either. The rule you write should therefore name a door people can actually use rather than closing everything, because a rule that can be followed does not manufacture infringements.
Two. An obligation has bound you since February 2025, and it was not deferred. You read everywhere that Europe pushed back its AI regulation: true, and it does not concern you. What moved, to December 2027 and August 2028, are the obligations on so-called high-risk systems. Everything that binds an ordinary employer stayed on its original date. And among those things, one almost nobody knows about: since 2 February 2025, any organisation deploying AI must take measures to support a sufficient level of AI literacy among the people using it. The July 2026 text in fact softened that wording, which previously required ensuring that level: the obligation remains, it has simply become an obligation of means. The European Commission states itself that this covers a company whose staff simply use an assistant to write advertising copy, and that those staff must be told about the risks specific to these tools, starting with the fact that they make things up.
You will be sold this in the autumn as “mandatory training, or a fifteen million euro fine”. That is false, and knowing it is false will save you a budget line: this obligation appears in none of the regulation’s penalty tiers. Which does not mean it carries no consequence, and I would not want to swap one exaggeration for another: national penalty regimes and market surveillance authorities’ power to order compliance both remain live. So what changed on 2 August 2026 is not an amount, it is that it came under those authorities’ supervision. Half a day of explanation to your teams answers it, and you keep the written record.
Three. In Morocco this is not a fine, it is the criminal code. The European debate turns on administrative penalties, which trains people to think in amounts. Law 09-08 does not work that way: its article 61 punishes by three months to a year of imprisonment and a fine of twenty thousand to two hundred thousand dirhams anyone who, even through negligence, has caused or facilitated the abusive use of processed data, or communicated it to unauthorised third parties. That sentence describes an employee pasting a client file into a consumer tool with uncomfortable accuracy. Add that Morocco has no European adequacy decision, and that data leaving the country requires authorisation from the national data protection commission, and a Casablanca firm serving European clients ends up with two regimes stacking rather than replacing one another.
Let me close with the nuance this kind of section always lacks. To date, no European authority has penalised a company for the use its employees make of a consumer assistant, and I know of no Moroccan prosecution on that basis. The only fine ever issued in Europe over generative AI, fifteen million euros against OpenAI in Italy, was annulled at first instance by the Court of Rome in March 2026, without the merits being decided. The regulator is not your immediate threat, and anyone telling you otherwise is selling you something. What I am describing here is the frame you will be standing in the day a client, an employee or a competitor asks the question.
The sort, to run with your team
None of the above is any use if your teams cannot decide at the moment the cursor is in the box. So let us sort. Six real requests, written the way an employee would write them, and three possible destinations. Do it yourself first, then do it again in a meeting: that is where the figure earns its keep, because your colleagues disagreeing about one case will teach you more than the right answer does.
Six real requests, written the way an employee would write them. For each one: which door is it allowed through?
1 / 6“Improve the job ad we are publishing on Friday.”
Two remarks on this grid. The first is that four cases out of six are allowed through, and that is not indulgence: it is the real proportion. A rule that forbids everything protects nothing, because it loses its credibility on the first obviously harmless case, and once lost it is lost for all the others.
The second is about the question itself. It is about the request, not the document, and that is what makes it better than the usual classification schemes. The UK national cyber security centre put it before me and better than me: the right question is not “is this document confidential”, it is “would this request cause a problem if it became public”. Their example is the chief executive enquiring about the collective redundancy procedure. No document leaves, and yet the request, coming from that person, is the information.
Samsung, from beginning to end
You probably know the shorthand: Samsung engineers pasted code into ChatGPT, so Samsung banned ChatGPT. It gets quoted in every meeting on this subject, and it is wrong on three checkable points. But above all it stops halfway through the story, and it is the ending that holds the lesson.
- 11 March 2023
One division allows it, the other still forbids it
Samsung Electronics’ semiconductor division changes its rule and permits ChatGPT. At that same moment, the division that makes phones and appliances still bans it. Saying “Samsung allowed ChatGPT” without naming the division is already wrong, and it is the first piece the common retelling drops.
- 30 March 2023
Three incidents identified in under twenty days
The Korean outlet Economist Korea reports what the company had spotted: two leaks of equipment information and one of meeting content. In the first, an engineer hits an error running a program that downloads an equipment measurement database, copies the entire offending source code, and pastes it to get the fix. Samsung never confirmed these incidents and declined to comment.
- The third incident
Two tools, and the data leaves at the first
This one deserves telling accurately, because it is the true shape of the risk. An employee records a meeting on a phone, has it converted to text by a transcription service that has nothing to do with ChatGPT, then pastes the resulting text into ChatGPT for minutes. The data left the company at step one, in a tool nobody ever names in these discussions. The usual version, “he asked ChatGPT to transcribe a meeting”, erases precisely the part that matters.
- April and May 2023
There was never a company-wide ban
The two divisions responded differently. The one where the leaks happened capped the size of messages sent, at one kilobyte. The only known restriction document is a 28 April memo to the other division, covering company devices and networks, and it describes itself as temporary, pending measures being made ready. Two divisions, two responses, summarised everywhere in one sentence no source supports.
- December 2023
The in-house model, eight months later
Samsung rolls out its own model internally. Eight months separate the restriction from the alternative, and those eight months are the real subject: they are the gap between a capability becoming useful and a governed version of it existing. That gap, and nowhere else, is where leaks happen.
- June 2026
The road back, all the way
Three years on, the company everyone cites for its ban rolls out the enterprise tier of ChatGPT to all its Electronics staff in Korea and to the whole mobile division worldwide, alongside the business offerings of Google and Anthropic. And access is not thrown open at once: it is placed behind training, first around fifty executives, then some two thousand three hundred people across affiliates, before the whole workforce. The company has never said its restriction failed, and the reading that follows is mine: this is not a reversal, it is the same decision as March 2023, taken this time through the right door, and behind training rather than in front of a block.
Hold on to the interval. Between the moment a capability becomes useful and the moment a governed version of it exists, time passes during which your teams work anyway, with whatever is to hand. At Samsung that gap lasted eight months, and that is where everything happened. At your company that gap is now one hour: the business door already exists, it can be bought, and there is nothing left to build.
One last thing on this chapter, because it always comes up. The list of large companies “that banned ChatGPT” does not survive inspection. Some set usage limits, another settled for a warning from its legal team on its internal messaging, one bank explicitly said this was its routine third-party software control and not a reaction to any incident, another filed it under normal practice toward external websites. Treating them as one wave of bans is the most common error on this subject, and telling them apart is cheap.
The first week
Here is the part you can run without me. Five slots, under three hours in total, nothing needing a budget before day two. The order matters more than the content: the door opens before anything closes, and the amnesty comes before the rule.
Five slots, under three hours in total, and nothing that needs a budget before day two. The order is not decorative: each day is what makes the next one possible.
Look, without announcing
You, with whoever runs the network or the devices.
Ask for a single aggregate number: how many distinct AI services were reached from the company network last month, and from how many machines. No names, no content, no individual list. You are establishing a baseline, not opening an investigation, and the distinction is not mere courtesy: identifying employees one by one would move you into an entirely different legal regime, for information you do not need.
What it changes
Half an hour tells you two things: that the number of tools is higher than you thought, and that some of the traffic falls in the evening and at weekends. That second point tells you the use is already built into how people work, not into their curiosity.
The mistake to avoid
Name nobody, even if the data would let you. The day a team works out that measurement is used to single people out, it moves to personal phones and you lose the visibility for good.
For readers who want the mechanics
One question comes up on day two, and instinct answers it badly. If you can only equip twenty people, who gets the licences? The reflex is to give them to your best. The most rigorous controlled trial on this, run with seven hundred and fifty-eight consultants, points the other way: the performance gain was markedly larger for those starting below average than for those starting above it. That is not a reason to deprive your best people, who will find the door anyway. It is a reason not to stop at them.
A word on what I cannot demonstrate, because I would rather say it than have it said to me. The analogy everyone reaches for, personal phones at the office fifteen years ago, rests on an analyst forecast from 2013 that has never been publicly tested. It is plausible; it is not evidenced. And I found no single-company study measuring unsanctioned use before and after an official tool arrived. This article’s recommendation rests on large-scale telemetry, not on a controlled experiment. That is solid; it is not proof.
What this changes for you
If you have done nothing, do not start with a memo. Open the door for the team that needs it most, write the page, then announce the two together. A restriction that arrives with its alternative is received as a decision. The same one with nothing beside it is received as an obstacle, and an obstacle gets routed around by personal phone.
If you have already banned it, you are in the situation that calls for the most action, and that is not a criticism: it is the decision nearly everyone took. Open a door, say the rule is changing, and run the amnesty. You will discover, as everyone does, that the use never stopped, and you will recover the one thing that genuinely matters: the list of what has already left.
If your data must not leave at all, for regulatory reasons or because your clients require it, the sixth door exists and it is my work: installing models on your own infrastructure, with nothing going to a third party, and training the team that will keep them running. But start with the second door for everything else anyway. The worst possible arrangement is a six-month internal project during which your teams carry on using their personal accounts, for want of anything else in the meantime.
Let us go through your doors
One hour, a clear picture, and the list of what to open. I answer myself, within one working day.
To check for yourself
Every figure here was read at the source on 30 August 2026, not in the retellings, because this subject is saturated with them. Two warnings before the references. First, these policies move on a timescale of weeks: what is written here carries a date, deliberately. Second, three very widely repeated statements are false today, and I flag them because you are going to meet them.
- “ChatGPT has to keep your deleted conversations.” It was true. The US order freezing deletions ended on 26 September 2025. What survives is narrower and more interesting: a frozen April to September 2025 archive from which requests originating in the European Economic Area, the United Kingdom and Switzerland were released, and a targeted, permanent preservation covering accounts tied to about a hundred domains listed in an appendix.
- “The share of sensitive data pasted into AI went from 11% to 40%.” Both numbers exist and they do not measure the same thing: a share of data volume on one side, a share of interactions on the other. On a constant basis the series runs from 10.7% in March 2023 to 34.8% in 2025. That is already considerable, and it is true.
- “Shadow AI adds $670,000 to the cost of a breach.” A figure from the 2025 edition of the report in question, still being copied everywhere in 2026. The edition published on 29 July 2026 gives different numbers, and the gap to the overall average there is smaller, not larger. That report also rests on about six hundred volunteering organisations, with no published margin of error.
The sources, point by point
The effect of bans. N. Gillespie, S. Lockey, T. Ward, A. Macdade and G. Hassed, “Trust, attitudes and use of artificial intelligence: A global study 2025”, University of Melbourne and KPMG, published 2025, fieldwork November 2024 to mid-January 2025, 48,340 respondents across 47 countries. The passage quoted is on page 75. Designed, conducted and reported by the university team, funded by KPMG, published under an open licence.
Personal accounts and blocking. Netskope, “Cloud and Threat Report 2026”, published 7 January 2026, telemetry from 1 October 2024 to 31 October 2025. These are Netskope customers, and Netskope sells the products its conclusions make necessary: the method is observation rather than self-report, and the sample is not representative of companies generally.
Pasting rather than uploading, and the sensitive-data shares. Cyberhaven Labs reports of May 2024, 23 April 2025 and 5 February 2026. The vendor defines “sensitive” as whatever each of its customers’ own rules marks as such, which makes the measure dependent on the internal policies of its sample.
The indexed conversations. Fast Company, 30 July 2025; the removal of the feature announced by OpenAI’s chief information security officer on 31 July 2025; 404 Media, 5 August 2025, for the corpus of close to a hundred thousand conversations; Forbes, 20 August 2025, for Grok; TechCrunch, 12 June 2025, for Meta’s public feed. No official figure has ever been published by the providers concerned.
The doors and their regimes. Providers’ own public pages, read on 30 August 2026: OpenAI’s help centre and enterprise privacy pages, Anthropic’s platform documentation and privacy centre, Google’s Gemini apps privacy hub and Workspace administration pages.
Retention and legal demands. Order of 13 May 2025 and the stipulation terminating the obligation, filed 9 October 2025 and effective 26 September 2025; order of 5 January 2026 on the production of twenty million conversations, from which the wiretap comparison is taken. OpenAI’s and Anthropic’s half-yearly transparency reports for July to December 2025, the most recent published to date.
Privilege. United States v. Heppner, No. 25 Cr. 503, Southern District of New York: ruled from the bench on 10 February 2026, written memorandum of 17 February 2026, in which the judge calls the question one of first impression nationwide. The second matter, warrants of 21 May 2026 covering seven accounts at two providers, appears in a prosecution letter dated 17 June 2026.
Samsung. Economist Korea, 30 March 2023, the original Korean-language article, for the 11 March authorisation, the three incidents and the detail of the third. The internal memo of 28 April 2023 to the division concerned for the restriction. The June 2026 rollout from company communications. Samsung never confirmed the 2023 incidents.
The European frame. Regulation (EU) 2024/1689, article 4 applicable since 2 February 2025 and article 113 for the timetable; the amending regulation adopted 8 July 2026 and in force since 27 July 2026 for the deferral of high-risk obligations; the European Commission’s AI literacy questions and answers. The Dutch data protection authority’s position, published 6 August 2024. The first-instance annulment of the Italian penalty, March 2026.
The Moroccan frame. Law 09-08 on the protection of individuals with regard to the processing of personal data, article 61 for the criminal penalty and articles 43 and 44 for transfers out of Morocco.
The sort and the concealment. The test of the request rather than the document comes from the UK national cyber security centre’s guidance. On the social cost of disclosure: a meta-analysis of thirteen experiments published in 2025 in an organisational psychology journal, and a study in the Proceedings of the National Academy of Sciences covering more than four thousand participants.
Just found out what your teams are using, and unsure where to start? Write to me, I will tell you what I would do in your position.