Zendoric
← Back to the day · July 25, 2026

The employee's dilemma: use AI with sensitive files or comply with IT policy

🕒 Published on Zendoric: July 25, 2026 · 00:23

The email, framed as a teaser for a paid post, raises a conflict Nate has been observing in the corporate world: employees receive two contradictory orders, both presented as job requirements. On one hand, the manager demands doing more with AI and meeting ever-tighter deadlines.

🎧 Listen to the analysis

By Nate from Nate's Substack.

The email, formatted as a teaser for a paid post, lays out a conflict Nate has been observing in the corporate world: employees receive two contradictory orders, both presented as requirements of the job. On one hand, the manager demands doing more with AI and meeting ever-tighter deadlines. On the other, the IT department bans uploading certain files or using certain tools for privacy reasons. In practice, Nate writes, people obey the manager, because that is who evaluates their performance and decides promotions, whereas the consequence of skipping a privacy policy seems more abstract and distant.

Nate brings his own experience of nearly twenty years attending IT presentations on data privacy: they were serious sessions, but most of the room lived them with resignation, as one more obligation to fulfill before getting back to real work. According to him, that has changed over the last two years: now every IT administrator he talks to is worried about 'shadow IT'—that is, about the adoption of AI tools in day-to-day work faster than the organization can evaluate or approve. At the same time, he argues that employees themselves no longer take the risk lightly, but instead feel considerable stress at receiving contradictory instructions from different parts of the same company.

The result, according to the author, is that the individual employee is left in the crosshairs: if they use the most powerful tool on the real material, they may be violating a rule they were asked to follow; if they avoid doing so, or reduce the task to something generic, they may fail to achieve the productivity gains their manager already expects. In either case, they lose. Nate states that, at most companies, it is the employee themselves who ends up deciding, file by file, what information can be moved, what must be left out and which tool is acceptable, thus becoming, de facto, the designer of a privacy process the company never formalized.

As a concrete example, the email cites the case of an auditor who raised this question with other accountants late last year. Conferences and webinars insisted on using AI to speed up the work: a capable model could read client process documents, internal control manuals, checklists and summaries, and help find gaps or translate the material into more understandable language. The problem was that this useful material lived inside client files, and uploading them would have been, in the auditor's own words quoted by Nate, 'a game changer,' but it also clashed with the responsibility to protect those clients' data. The alternatives that seemed safer turned out to have 'much less intelligence' or to be 'astronomically priced,' leaving the auditor unwilling to sacrifice either quality or security, and therefore with the work stalled.

Nate closes that reflection with the sentence that sums up the article's thesis: 'don't upload the file' is good advice, but it is not an answer to the question of how to get the work done.

The body of the email, being a teaser for a paid post, previews the table of contents of the full article without developing it: it mentions 'Airlock,' described as a Mac app Nate has built to automate the repetitive part of the process (without detailing here exactly what it does or what it refuses to touch); a section on why 'the empty chat box' stopped being enough, because useful work with AI is now done on real material, which turned privacy into a file-by-file decision; a section with answers from real operators who reportedly built routing systems, access tiers and local pipelines rather than trusting themselves to remember a rule at 11 p.m.; a 'two-minute test' to assess a company's privacy system, comparing the time of the approved path against the consumer route; and a reflection on why there is no single 'clean' version of a document, since relevance depends on the question being asked, so a sanitized copy cannot serve as valid permission for any future task.

The email ends by noting that paid subscribers get access to the full analysis and the guide, as well as membership in Nate's Slack community. As this is content behind a paywall, the body received does not include the actual development of those points (what Airlock does exactly, what the specific routing or tiers used by the cited operators are, or the detail of the 'two-minute test'), so this summary is limited to what appears explicitly in the email.

🔗 Related on Zendoric

Sources & references