Buried in KPMG’s global AI research is a detail that gets skipped past too quickly: more than half of employees — 57% — admit they hide their AI use and pass the output off as their own work.
By Gareth Redelinghuys, country MD at TrendAI
Not “use AI without telling anyone”. Actively conceal it. Present the work as if a human did all of it, unaided.
Most of the coverage around unsanctioned AI use treats that as a footnote to a bigger story about tools and risk. I think it’s the opposite. The concealment is the story.
Why would someone hide something that helpful?
Sit with the question for a moment, because the obvious answer — “they know it’s against policy” — doesn’t fully hold up. The same research found close to half of employees are using AI in ways that already break company policy, quite openly, uploading sensitive information into free tools. So plenty of people aren’t hiding the use itself. What they’re hiding is that the work wasn’t fully theirs.
That’s a different problem, and a more uncomfortable one. It suggests employees have worked out, correctly or not, that admitting “I used AI for this” costs them something. Credibility, maybe. The appearance of competence.
Nobody sat them down and told them this. They inferred it from how a manager reacted the one time someone mentioned it in a meeting, or from the vague unease every company seems to have about AI without ever actually saying what the rule is.
Why South Africa’s version of this is probably worse, not better
BCG’s fourth annual “AI at Work” report surveyed 503 South African respondents as part of a wider 14-market study, and the local numbers are startling: 79% of South African frontline employees are regular AI users, against a 74% global average. On time saved, South Africa ranked second of all markets surveyed, behind only India. Sixty-six percent of frontline employees and 75% of managers here say AI is saving them a full working day or more, every week — compared with 42% and 56% globally.
Put those two data sets next to each other and the picture gets uncomfortable fast. If South African employees are extracting more value from AI, more often, than almost anywhere else BCG surveyed — and the global pattern shows over half of employees hiding that value from their employers — there’s no reason to assume South Africa is the exception to the concealment problem.
It’s more likely sitting at the sharper end of it. We could be looking at some of the highest, least-disclosed AI-driven productivity anywhere in this research, and nobody’s measured it directly yet, because nobody’s asked the right local question.
The real cost isn’t the tool, it’s blindness.
A security team can build controls around AI use it knows about. Sanctioned tools, unsanctioned tools, even the free version of ChatGPT someone shouldn’t be using — all of it is at least visible, in theory, to someone who goes looking.
Concealment defeats that. If an employee is deliberately presenting AI output as their own, they’re not just skipping a policy step. They’re removing the one signal that would tell anyone, including them, when something’s gone wrong — a hallucinated figure in a client report, a chunk of someone else’s confidential text pasted into a prompt without a second thought. The mistake doesn’t get caught earlier because nobody admitted where the work came from.
The part that’s actually about the law
I’ll keep this short because it’s not a legal column. Under POPIA, the responsible party — that’s the company, not the employee who pasted something into a chatbot after hours — carries the accountability for how personal information gets processed.
Not knowing an employee did it doesn’t change who the Information Regulator holds responsible. Worth getting your own legal or compliance sign-off on exactly what that means for your business, but the general shape of it isn’t in dispute.
What actually changes this
Banning tools doesn’t touch the concealment problem. If anything it makes it worse — you’ve now given people a reason to hide something they’d otherwise have mentioned. What would actually help:
- Say, explicitly, what’s allowed. Most companies haven’t defined this clearly enough for an employee to even know if they’re breaking a rule or just guessing at one.
- Make disclosure the safe option, not the risky one. If someone admitting “I used AI to draft this” feels like a confession, they’ll stop admitting it.
- Separate the tool question from the trust question. An employee using AI well isn’t doing less work. Treat it that way in performance conversations, not just in policy documents.
Given how far ahead South Africa appears to be on adoption, ask this directly, in your own business, rather than assuming the KPMG number is someone else’s problem.
Where this leaves us
The tools were never really the risk, the silence around them is. If South African businesses really are sitting on some of the deepest AI-driven productivity gains BCG measured anywhere, then the businesses that work out how to make that visible, honestly, stand to gain more than most. The ones that don’t are managing a workforce whose real output they can’t see.