Somewhere in your organisation, this week, someone pasted something into an AI tool that would make your security lead wince. A customer email. A contract clause. A snippet of the codebase. This is not a prediction, it is the base rate: every organisation of any size has AI usage it did not sanction and cannot see.
The instinctive response is a ban. It is also the worst available option. Bans do not stop usage, they relocate it: from accounts you could govern to personal ones you cannot see, on personal devices, with no audit trail. You keep the risk and lose the visibility, and you forfeit the upside your competitors are quietly collecting.
The productive response starts with a distinction most policies miss: not whether your people use Claude, but which Claude they use.
The account type is the risk
Since Anthropic's 2025 consumer terms update, personal accounts (Free, Pro, Max) have model training switched on by default. Unless the individual opts out, their conversations can be used to improve future models, with retention of up to five years. Your employee's personal account, the one they signed up for with a private email address, likely falls in this category.
Anthropic's commercial tiers work the other way round, by contract. Customer Content on Claude for Work (the Team and Enterprise plans) and the API is excluded from model training. Retention is a configurable setting rather than a default, down to zero-retention arrangements on the API. The organisation controls the data; Anthropic processes it. Access runs through your own single sign-on, and an audit log shows what happened.
Read that asymmetry again, because it is the whole picture: the same prompt, typed by the same employee, is either contractually excluded from training or retained for years and eligible for it, depending on nothing but the account it was typed into.
What a governed rollout looks like
Three moves, one quarter.
First, give people the sanctioned path. A managed workspace with SSO, audit logging and sensible retention costs less than the meeting series about the risk. The sanctioned tool must be at least as good as the shadow one, which, given what the shadow one is, is not a high bar.
Second, write a usage policy someone can actually follow. Three categories: what is fine (drafting, summarising, reasoning over material already cleared for the tool), what needs care (anything identifying a customer or colleague), what never goes in (credentials, anything under NDA you would not put in an email to an external party). One page. Reviewed with legal once, then owned by whoever owns the workspace.
Third, close the personal-account gap explicitly. Tell people why the company workspace is different, in one paragraph, using the training and retention facts above. Most shadow usage is not defiance, it is the absence of a better option and nobody having explained the difference.
Governance is the floor, not the point
Everything above makes Claude safe. None of it makes Claude valuable. The same managed foundation is what lets you take the second step, connecting Claude to the systems where your work actually lives, with the permissions you already maintain, so it reasons over your records instead of guessing. That is where experiments end and capability starts, and it is a design decision, not an upgrade you buy later.