Should I Tell My Boss I Use AI at Work? Check Policy First
Whether you need to tell your boss you're using AI at work comes down to two separate questions: is the tool approved for the task, and does your employer's policy require you to say so. SHRM published an "Ask HR" column addressing this exact question last year, written by Johnny C. Taylor Jr., SHRM-SCP, according to SHRM. The sources cited here don't add up to a universal disclosure rule that fits every workplace. What follows is a way to work through the two questions using your own employer's policy.
What the research does and does not show

That SHRM devoted a formal column to this question confirms it's a live HR concern, not evidence of what any particular company's own AI policy says, according to SHRM.
Microsoft's 2025 Work Trend Index, built on a survey of 31,000 professionals across 31 countries conducted with LinkedIn, found that 67% of leaders reported familiarity with AI agents compared with 40% of employees, and separately, 79% of leaders believed AI would accelerate their careers versus 67% of employees, according to Microsoft. Those numbers describe familiarity with AI agents and career optimism. They don't measure whether employees disclose AI use to a manager, and nothing in the report ties the gap to concealment.
Gartner's data is older and narrower in scope. In a survey of 249 senior enterprise risk executives conducted in 2023, more than three years ago, generative AI ranked as the second most frequently cited emerging risk, appearing in the top ten for the first time, according to Gartner. That reflects how risk executives were thinking about generative AI early in its adoption, not a current read on 2026 workplace policy.
Why policy language matters

Once it's clear no outside source hands down a universal disclosure rule, the practical task is reading an employer's own policy, in order.
Check permission first. Does a written AI or acceptable-use policy name the tool as approved for the specific task at hand? A policy might approve a chatbot for brainstorming while restricting that same tool for customer data or client deliverables. That distinction, tool versus use case, is worth checking before assuming either way.
Check disclosure separately. Does that same policy, a client contract, or a deliverable requirement call for a note that AI was involved? Confirming permission doesn't answer this question. A tool can be fully approved for a task and still carry a disclosure requirement tied to the deliverable, or not, depending entirely on what's written down.
Data sensitivity is where this distinction carries the most weight. Ran Xu, a director in Gartner's Risk & Audit Practice, said information entered into a generative AI tool can become part of its training set, meaning sensitive material could end up in another user's output, and that using AI-generated content could inadvertently infringe someone else's intellectual property, per Gartner. Both risks are framed as possibilities, not guarantees, and that hedging matters. Whether a specific tool retains inputs for training is a detail to confirm with IT or security directly, since it depends on the product, the account type, and the terms an employer has signed.
Should you disclose AI use at work? Check the policy first

The answer changes depending on the tool, the task, the data involved, and who receives the final work.
Approved internal use, like drafting an outline or summarizing meeting notes with a tool already cleared for that purpose, is usually the simpler case on the permission side. Disclosure is separate. A policy may or may not require a note for internal work, so it's worth checking rather than assuming either answer.
Client-facing work deserves a closer look at both the client contract and the internal policy, since the two documents can set different expectations. A tool cleared for internal use isn't automatically cleared for anything a client will see. Disclosure requirements for client deliverables are one possibility to check for, not a documented industry pattern, and they may show up in the contract, the internal policy, both, or neither.
Work touching confidential, proprietary, customer, or regulated data calls for the closest look at authorization, regardless of how reputable the tool is. Gartner's warning gives employees a reason to check how their employer handles different types of data before using AI on anything sensitive, rather than a rule about how any given policy is written.
If no written AI policy exists yet, or one exists but doesn't mention a specific tool or task, raise that gap with HR or IT before proceeding. Silence in a policy isn't the same as approval. If AI was already used for something before that question got asked, the employer's own escalation process, where one exists, is the process to follow. Pausing further use of that tool for sensitive or client-facing work and keeping a record of what was used and for what task are reasonable starting points, but how any specific instance gets handled is a determination the employer makes.
A manager or client asking directly how a piece of work was produced is a different situation from the permission-and-disclosure framework above. Follow the employer's process for responding, and avoid making claims about what a policy permits without checking it first.
How to talk to your manager about AI tools

A written policy, where one exists, is worth reading closely enough to see whether it treats an approved tool and an approved use case as the same thing. A useful checklist covers five points: the specific tool, the task, the type of data involved, who will see the final output, and whether a disclosure note is required for that combination.
Who to ask about each point varies by employer. A manager may speak to workflow and deliverable expectations. HR may address workplace-practice questions. IT or security often controls which tools are technically approved and how they handle data, and a compliance or legal contact may be worth involving for regulated data, client contracts, or intellectual-property questions. Which one applies depends on the specific issue, so it helps to ask before assuming any single contact owns the whole answer.
Two questions, asked separately, cover the two checks above. On permission: "I'd like to use [tool] for [task]. Is that tool approved for this kind of work, and are there any data restrictions I should know about?" On disclosure, asked only once permission is confirmed: "Now that I know this use is approved, does our policy or the client agreement require me to note that AI was used in this deliverable?"
What to do next
Before the next AI-assisted task comes up, locate the written AI or acceptable-use policy, or ask for one if it doesn't exist. Check whether it names the specific tool for the specific task, then check separately whether it, a client agreement, or the deliverable itself calls for a disclosure note. Bring one concrete example, the tool, the task, the data, and the audience, to the contact most likely to know, and treat the policy as the primary source for the situation, not general guidance like this one.