OpenAI being used on a mobile phone

When Redflags analysed AI site visits across 21,377 users in 2025, one number stood out above everything else: 93.21%. That’s the share of all recorded AI website visits that went to OpenAI. Gemini came in a distant second at 4.51%. Copilot accounted for 0.72%. Perplexity, Claude, and DeepSeek shared the remaining fraction between them.

At first glance, this looks like a story about market dominance, and it is. But for security teams, it’s also a story about visibility, concentration of risk, and the quietly growing gap between how employees are actually using AI and what most organisations currently have any meaningful oversight of.

An important caveat and why it matters

Before drawing conclusions, it’s worth being precise about what this data is and isn’t measuring. These figures capture website visits – browser-based interactions with AI platforms. They don’t capture usage of AI tools that are deployed at the desktop level, built into enterprise applications, or accessed through integrated software like Microsoft 365 Copilot. That usage tends to be sanctioned, IT-provisioned, and at least nominally within the organisation’s governance framework.

What website visit data captures is something different: the choices employees make independently, in the browser, often in the moment. This is the layer of AI usage that sits outside standard procurement and provisioning processes, not necessarily because employees are deliberately circumventing policy, but simply because browser-based tools are fast, free, and frictionless in a way that enterprise software often isn’t.

So, the picture these numbers paint isn’t purely one of shadow IT in the traditional sense. It’s more nuanced than that. It’s a window into which AI tools employees gravitate towards when they’re self-directing, and OpenAI, by an overwhelming margin, is where they go.

What the concentration tells us

A 93.21% share isn’t a gentle lean towards one platform. It’s near-total dominance. For security teams, that concentration has two implications that pull in opposite directions. On one hand, it simplifies the task of understanding where browser-based AI risk is concentrated. If you want to understand what your employees are doing with AI in the browser, you essentially need to understand what they’re doing with OpenAI. The governance conversation, the data handling policy, the acceptable use guidance; it can be focused. The sprawl is less than you might fear.

On the other hand, concentration at this level creates its own category of risk. When the vast majority of AI activity flows through a single external platform, the potential consequences of misuse – uploading sensitive documents, inputting customer data, sharing proprietary code – are also concentrated there. And with visits to AI sites growing by 43.2% on average year-on-year among tracked users, the volume of activity running through that single channel is rising quickly.

The outlier problem

The aggregate numbers tell part of the story. The distribution within them tells another. Across the 2025 dataset, 3.1% of users generated 18% of all AI site visit activity. These outlier users averaged 234.6 AI-related events, compared to 34.8 for everyone else, meaning they’re engaging with browser-based AI tools six to seven times more frequently than their colleagues.

Who are these people? Almost certainly not bad actors. They’re most likely the early adopters, the technically curious, the employees who have integrated AI tools most deeply into how they work and are getting the most out of them. In many organisations they’re valuable as they’re the ones figuring out what these tools can actually do, and often informally teaching colleagues. But from a security standpoint, they also represent a disproportionate share of the data governance exposure. If sensitive information is finding its way into browser-based AI platforms, the probability is that a significant portion of it is being input by a relatively small number of highly active users. Identifying and supporting those individuals, not penalising them, but ensuring they have the right guardrails and guidance, is one of the highest-leverage things a security team can do.

The tools people aren’t choosing

The gap between OpenAI’s 93.21% and everything else is striking, but the “everything else” column deserves attention too. Gemini at 4.51% represents Google’s foothold in enterprise browser-based AI usage. Copilot at 0.72% is low, but that figure almost certainly understates total Copilot usage, given how much of it happens within the Microsoft 365 environment rather than through a browser visit. Perplexity, Claude, and DeepSeek’s marginal shares reflect tools that are growing in profile but haven’t yet broken through to mainstream workplace adoption.

What this distribution suggests is that, for now, the enterprise browser-based AI landscape is effectively a one-platform story with a long tail. That may change, though. Gemini’s integration with Google Workspace could shift behaviour, and competition in the space is intensifying. But in 2025, if your employees were opening a browser to use AI, they were almost certainly opening ChatGPT.

What visibility actually makes possible

The value of understanding this landscape isn’t just in knowing the numbers. It’s in what you can do with that knowledge. Organisations that have visibility into which AI sites their employees are visiting, when, and at what frequency, are in a fundamentally different position from those operating blind. They can identify whether employees are using unapproved tools alongside or instead of sanctioned ones; spot when usage spikes in ways that warrant closer attention; and target nudges and guidance towards the specific platforms and behaviours that carry the most risk, rather than issuing generic AI policies that employees tune out. And they can bring data to conversations with leadership and the board that goes beyond anecdote, showing actual behavioural patterns, trends over time, and measurable responses to interventions.

The AI landscape is consolidating around a small number of dominant players, at least for now. That’s an opportunity for security teams to consolidate their focus too. The question is whether your organisation has the visibility to act on it or whether your employees’ AI usage remains, for practical purposes, invisible.

In 2025, 91% more organisations decided they needed to find out. That number will only grow.