There’s a moment that plays out in corporate and home offices across the country every weekday morning. Emails load, coffee is poured, and increasingly, an AI tool is opened alongside them. It’s become part of the morning ritual, as habitual as checking the calendar or scanning overnight messages.
The data backs this up. Across the organisations Redflags monitored in 2025, the peak times for visiting AI sites were remarkably consistent: Tuesday, Wednesday, Thursday, Friday, and Monday at 9am – the start of the working day, every working day. No other time window came close.
This is not what “novelty behaviour” looks like. Novelty is sporadic, unpredictable, scattered across the day and week. What we’re seeing instead is something more significant: AI has embedded itself into the rhythm of how people actually work. It’s one of the first tools many employees reach for when they sit down. That’s a profound shift and it carries implications that security teams cannot afford to overlook.
A 91% increase in visibility and what it means
Between 2024 and 2025, the number of organisations using Redflags to track AI usage behaviour grew by 91%. That figure reflects more than growing concern; it reflects a profession waking up to a new reality. AI adoption among employees isn’t a future consideration but a present-tense operational fact, playing out across devices and departments every single morning.
Among users tracked across 21,377 individuals in 2025, visits to AI sites rose by 43.2% on average compared to the previous year. OpenAI tools accounted for 93.21% of all AI site visits, with Gemini at 4.51%, Copilot at 0.72%, and others including Claude, Perplexity, and DeepSeek making up the remainder. The dominance of one platform shouldn’t obscure the broader picture: employees are actively seeking out whichever tools they find most useful, often without waiting for official guidance on which ones are sanctioned.
Within that population, a small but significant group stands out. Roughly 3.1% of users, those we’d classify as heavy or “outlier” users, generated 18% of all AI-related activity. Their average event count was 234.6, compared to 34.8 for non-outlier users. They’re using AI six to seven times more frequently than their colleagues.
These aren’t rogue actors. They’re likely your most tech-forward employees, the ones actively exploring what AI can do for their work, finding new ways to automate, draft, analyse and problem-solve. But from a data governance and security standpoint, they also represent a concentration of risk that most organisations currently have no visibility into and no targeted way to support.
Why this is a human behaviour story, not just a tech story
The human brain is drawn to novelty – new tools trigger dopamine responses associated with reward and excitement. That’s partly why AI adoption spread so rapidly in the first place. But the 9am data tells us something subtler and more important: for many employees, the novelty has already worn off. AI isn’t as exciting in the way it once was. Now it’s just useful. It’s just work and that’s exactly when security risk becomes harder to manage. When a behaviour becomes habitual, it moves from conscious decision-making, what behavioural scientists call System 2 thinking, into automatic, instinctive action. System 1. People aren’t pausing to consider whether they’re using an approved tool, whether they’re logged into a corporate account, or whether the file they’re about to upload contains sensitive data. They’re just getting on with their morning.
This is the same dynamic that makes phishing so persistent.
In our 2025 data, Monday and Tuesday at 9am also emerged as the peak times for employees clicking links in external emails from unknown senders – the exact same window as peak AI usage. People arriving at their desks and working through their inboxes on autopilot, instinct and habit taking the wheel before deliberate thinking has had a chance to kick in.
The behaviours are different, but the underlying mechanism is identical.
The gap traditional training cannot close
This is where the limits of conventional security awareness approaches become visible. A module completed months ago does not interrupt a habitual behaviour at 9am on a Tuesday. Awareness that lives in memory is no match for a behaviour that has become instinctive. As one CISO we spoke to put it: when someone is hit with a convincing phishing attempt, or reaches automatically for an unapproved AI tool, training done nearly a year earlier simply isn’t enough. It’s unreasonable to expect people to recall the details when they’re acting on autopilot.
The solution isn’t more training, but better-timed support. A well-placed nudge, delivered at the exact moment the decision is being made, can interrupt automatic behaviour and prompt a more considered choice without pulling people out of their workflow or adding friction to their day. That’s what behavioural science tells us, and it’s what Redflags’ data consistently demonstrates in practice.
What security leaders should be asking
If the 9am pattern holds true in your organisation, and the evidence suggests it will, then your employees are making dozens of AI-related decisions every week that currently fall outside direct oversight. The questions this raises are practical ones: Which AI tools are your people actually using? Approved, unapproved, or a mixture of both? Are employees uploading files or inputting sensitive data into tools that sit outside your governance framework? Do you have visibility into usage patterns across departments and roles, granular enough to allow you to target interventions where and when they’re most needed?
For the security teams Redflags works with, the goal isn’t to restrict AI use or to treat employees as a problem to be managed. It’s to ensure that as these tools become a permanent fixture in working life, as routine as opening email, people are supported to use them safely. That means timely, contextual guidance at the point of decision, not retrospective policy delivered after the risk has already materialised.
The 9am peak is a reminder that human behaviour moves faster than governance. But it’s also an opportunity. If you know when and how your people are engaging with AI, you can meet them there, at the exact moment the decision is happening, with the nudge that makes the difference.
That’s what people-centred security looks like in practice. And in 2026, it matters more than ever.
