AI being used on a laptop
For years, organisations have approached governance in a familiar way. They introduce new technology, identify risks and respond by building policies, deploying controls and training employees. Organisations now apply this same approach to AI. They define approved tools, set usage frameworks and introduce compliance measures, expecting people to follow clear rules in their day-to-day work.

AI usage continues to accelerate across organisations and employees engage with these tools as part of their normal workflows. In 2025, Redflags analysed behaviour across 44 organisations and more than 21,000 users and recorded a 91% increase in the number of companies tracking AI usage, showing how quickly adoption is expanding. At the same time, 45.5% of organisations reported employees actively visiting AI tools, placing this activity among the most common risky workplace behaviours.

This points to a deeper issue in how organisations approach governance. AI governance depends on how people behave in real situations and how they make decisions in the moment.

The dopamine effect behind AI adoption

To understand why AI governance is struggling, we need to look closely at why people use AI in the first place. Novelty plays a significant role. The human brain actively seeks new experiences, and when a tool promises greater efficiency or speed, it triggers dopamine, the neurochemical linked to reward and motivation.

AI tools amplify this effect. They reshape workflows and change how people complete tasks, which makes them highly compelling in everyday work. Behavioural data reflects this clearly. Among the organisations analysed, a small subset of users, just 3.1%, generated 18% of AI-related activity and used these tools six to seven times more frequently than average users. These users signal how quickly working patterns are evolving and how strongly certain behaviours take hold. This has important implications for governance. Organisations need to account for how people respond to these tools and how consistently they return to them in their daily work.

Why policy alone will always fall short

Traditional governance assumes that people make rational decisions. It follows a simple logic: if employees understand the risks and know the rules, they will behave accordingly. But behavioural science and real-world data show that this is not how decisions are made.

People operate in busy, high-pressure environments. They are dealing with deadlines, distractions, and competing priorities. In these conditions, decisions are rarely the result of careful deliberation. Instead, they are driven by habit, instinct, and cognitive shortcuts.

This is why:

  • Training delivered months earlier is difficult to recall in the moment
  • Policies that sit outside workflow are rarely consulted
  • Awareness does not reliably translate into action

In fact, the Redflags data shows that risk consistently concentrates around a small number of everyday behaviours. For example, 93.2% of organisations track users clicking or hovering over links from unknown senders, and 56.8% track users entering credentials after clicking links, classic behaviours driven not by lack of knowledge, but by habit and context.

The same behavioural patterns are now playing out in AI usage. Employees are not ignoring governance because they do not understand it. They are making decisions in the moment based on what feels efficient, useful, or urgent.

AI is amplifying human risk, not creating it

AI has not introduced entirely new categories of human risk. It has intensified existing ones.

The same drivers behind phishing susceptibility, including curiosity, urgency and trust, are now shaping how people use AI tools. AI feels productive and helps people complete their work more quickly, which makes risky behaviour easier to justify in the moment.

For example, an employee may upload sensitive data into an AI tool to speed up a task. Even when they are aware of the policy, the perceived benefit can outweigh the perceived risk. This reflects how people make decisions in practice and shows how quickly judgement can shift under pressure.

The scale of this challenge is considerable. In 2025, Redflags delivered over 29 million behavioural nudges across its customer base, highlighting how often employees face moments of potential risk in their daily work. These situations occur regularly as part of normal workflows and they form a consistent pattern of exposure.

From governance to behaviour design

If AI risk is behavioural, governance needs to evolve alongside it. Organisations need to move beyond static policies and periodic training and focus on influencing behaviour in real time. Risk emerges in the flow of work, in the moments where people make decisions and act on them.

Behavioural approaches support people at those moments of action. Organisations can design interventions that fit naturally into workflows and respond to the context in which decisions happen. Nudging offers a clear example. A well-timed prompt can interrupt automatic behaviour and encourage a brief pause for reflection, which can shift the decision that follows.

Why nudging works (and traditional training doesn’t)

The effectiveness of behavioural interventions lies in their alignment with how people actually behave. Most risky actions happen in “autopilot” mode. When people are busy, they rely on fast, intuitive thinking. Nudges work by interrupting that autopilot and triggering more deliberate thought. Over time, these small interventions reinforce safer habits.

The impact is measurable. Redflags data shows:

  • Up to 34.8% reductions in risky link-clicking behaviour
  • 27.9% increases in cautious behaviours like hovering over links before clicking

These are not awareness metrics. They are behavioural outcomes and importantly, they demonstrate something critical: behaviour can be changed, but only when it is addressed in context.

The future of AI governance

AI governance will not be solved by more detailed policies or more sophisticated tools. It will be solved by organisations that understand how people actually behave.

That means:

  • Accepting that most decisions are made under pressure.
  • Recognising that novelty and reward drive adoption.
  • Designing interventions around real moments of risk.

The organisations that succeed will move beyond measuring behaviour to actively shaping it. They will use behavioural data to understand where risk concentrates, when it occurs, and how it can be influenced.

Because ultimately, the challenge is not controlling AI. It is understanding the human decisions that sit behind it. AI governance is not an IT problem. It is a behaviour problem, and until we start designing for how people actually behave, not how we expect them to behave, AI risk will remain fundamentally unmanaged.