A small group of power users is generating a disproportionate share of your AI activity. Are they your most innovative employees or your most significant data risk?
Every CISO we speak to is grappling with the same question right now: what are my people actually doing with AI tools? Not what the policy says. Not what employees report in surveys. What is really happening on their devices, day to day, at scale.
The data from our latest Redflags Behavioural Report, drawn from behavioural telemetry across 44 organisations and over 21,000 users, gives us a clearer picture than most. And buried within it is a statistic that we think deserves far more attention than it has received.
3.1% of users account for 18% of all AI site activity. These outliers are visiting AI tools six to seven times more often than their colleagues.
That is not a rounding error. It is a structural pattern in how AI is being adopted inside organisations, and it has significant implications for how security leaders should be thinking about risk, policy, and intervention.
The Numbers Behind the Pattern
Across our analysed customer base, visits to AI sites increased by an average of 43.2% in 2025 compared to 2024. The number of organisations actively tracking AI usage nearly doubled, up 91% year on year. The direction of travel is unmistakable.
But the aggregate figures mask something important. When we look beneath the surface at individual user behaviour, the distribution is far from even. The average non-outlier user generated around 34.8 AI-related events over the tracking period. The outlier group, that 3.1%, averaged 234.6 events each. They are not slightly ahead of the curve. They are in a different category entirely.
Key figures from our 2025 dataset:
- 1% of users account for 18% of all AI site activity.
- Outliers averaged 234.6 AI events vs 34.8 for standard users – a 6–7x difference.
- AI site visits increased 43.2% on average across our customer base in 2025.
- The number of organisations tracking AI usage rose 91% between 2024 and 2025.
- Data drawn from 44 organisations, 21,377 users.
The question this raises is not simply a technical one. It is a behavioural and organisational one: who are these people, and what should you do about them?
Two Possible Explanations – Both Matter
When we see extreme usage patterns in behavioural data, the instinct is often to frame them as a problem to be managed. But the truth is more nuanced. Power users of this kind tend to fall into one of two camps, and the distinction between them has very different implications for how you respond.
The first camp is what we might call the enthusiastic innovator. These are employees who have genuinely integrated AI into their daily workflow. They are using it to draft documents, analyse data, write code, summarise research. They are more productive, probably more satisfied in their roles, and crucially they represent an early signal of where the rest of your organisation is heading. Suppressing their activity without understanding it is not risk management. It is organisational friction that benefits nobody.
The second camp is more concerning. These are users whose high volume of AI activity may reflect poor data governance habits, uploading sensitive files, pasting client data, using unapproved tools outside corporate account controls, or sharing information that should never leave the organisation. Our data shows that the behaviours organisations most wanted visibility on in 2025 included file uploads to AI sites, use of AI tools while not logged in with corporate credentials, and access to unapproved AI applications. Any of these, repeated at six to seven times the average frequency, represents a meaningful concentration of risk.
The same behavioural profile – high frequency AI use – can indicate either your most innovative employee or your highest data egress risk. You cannot tell from volume alone.
Why Traditional Controls Miss This
Most organisations are responding to AI adoption with policy. Approved tools lists. Acceptable use guidelines. Training modules on responsible AI. These are not wrong, but they address the average case. They do not account for the tail of the distribution, where the real concentration of risk lies.
The CISO Guide to Human Risk we published alongside this data makes the point clearly: traditional awareness approaches tend to plateau. They deliver information at scale, but they do not change behaviour at the individual level, in the moment, when a specific decision is being made. A policy document read during onboarding does not interrupt someone who is, at 9am on a Tuesday, about to paste a client contract into an AI prompt.
Our behavioural science research reinforces this. People making decisions under time pressure, and power users of AI tools are often highly task-focused, deadline-driven individuals, are operating largely on System 1 thinking. Automatic. Habitual. The policy exists in System 2. There is a gap between knowing the rule and applying it in the moment.
What Behavioural Telemetry Changes
The value of on-device behavioural tracking is precisely that it closes this gap. Not by surveying employees about what they think they do, not by reviewing logs after an incident, but by generating real-time visibility into actual patterns as they emerge and using that data to intervene at the point of risk.
For the outlier population specifically, this creates three meaningful opportunities:
- Identification without assumption. Behavioural data lets you locate your power users before an incident, not after. It removes the need to guess based on role, seniority, or department. The pattern reveals itself in the telemetry.
- Contextual nudging. A user visiting an AI site for the fifty-third time this month does not need the same intervention as someone visiting for the first. Real-time nudges can be tailored to usage level, surfacing relevant guidance about approved tools, data handling, account management at precisely the moment it is needed.
- Differentiated response. Once you understand who your outliers are and what they are actually doing, you can make intelligent decisions. Some will warrant a conversation about policy, some will surface a need for better-approved tooling, and some may be caught in a simple workflow problem, using a personal AI account because the corporate licence has not been provisioned correctly. Others may need a more direct conversation about data governance.
The Broader Implication for 2026
AI adoption is not slowing down. Visits to AI sites across our customer base rose 43.2% in a single year, and the tools are becoming more capable, more integrated, and more embedded in daily work. The outlier population we can observe today is almost certainly a leading indicator of where mainstream usage will sit in twelve to eighteen months.
That means the organisations that use 2026 to understand their power users to distinguish the innovators from the risk concentrations, and to build the kind of contextual, behavioural intervention infrastructure that can support both, will be considerably better placed than those who respond with blanket restriction or generic training.
The 3% problem is not a reason to restrict AI. It is a signal to understand it better.
