The Floppy Disk Lesson for Modern AI Governance

A relic of early computing has lessons for companies about the new era of shadow AI.

In the early 1980s, a small square of plastic and magnetic film became both the emblem of progress and the bane of IT departments. The floppy disk was portable, cheap, and ubiquitous. It was also a Trojan horse: employees could smuggle software, trade files, and shuttle sensitive data across organizational boundaries, bypassing the mainframes and minicomputers that defined “official” corporate computing. To managers, it was chaos; to workers, it was liberation.

Four decades later, something similar is happening with artificial intelligence.

Rethinking the Numbers: What “27 Percent” Really Means

OpenAI’s recent report, which analyzed 1.5 million conversations from more than 130,000 users between May 2024 and July 2025, shows a striking shift in how people use ChatGPT. In June 2024, nearly half of all messages sent by consumer-plan users (Free, Plus, Pro) were work related. By June 2025, that share had dropped to 27 percent.

At first glance, that sounds like work use is declining. But the reality is the opposite.

  • In June 2024, consumer accounts generated about 451 million messages per day. Nearly half (roughly 213 million daily messages) were work related.
  • By June 2025, consumer accounts were generating 2.6 billion messages per day. Even though the share of work dropped to 27 percent, that still amounts to about 716 million daily work messages.

In simple terms: the percentage went down, but the total number of work-related messages on consumer accounts more than tripled in a single year.

And there’s another wrinkle. The dataset excludes enterprise accounts - the very channels where sanctioned, IT-protected AI use happens. As companies have rolled out Enterprise, Business (Teams), and Education accounts, some portion of work queries has been rerouted into those safer systems. That shift doesn’t show up in the report, which means the “missing” work activity hasn’t vanished; it’s just happening elsewhere. Industry analysts have noted strong uptake of ChatGPT Enterprise among Fortune 500 firms, suggesting a growing migration from shadow use into formal, governed environments.¹

The implication is twofold:

  1. Enterprise adoption is rising - a positive development, since it reduces risk around data leakage and intellectual property.
  2. Unsanctioned work use is still massive - hundreds of millions of queries daily, occurring in consumer channels where messages may be used for training unless users opt out.

In other words: what looks like a decline in workplace AI is actually a redistribution. Some of it is moving into safer, enterprise-grade lanes. But the sheer volume that remains in unsanctioned channels is still large enough to pose serious governance challenges.

Just as floppy disks once coexisted with corporate servers as both an indispensable and unmanageable business reality, consumer AI accounts are running parallel to enterprise AI deployments. Workers are using whatever tool is at hand, sanctioned or not.

The Floppy Disk Lesson

The history of the floppy disk offers a cautionary tale. In the 1980s, companies tried to ban them outright, only to find employees quietly buying their own drives or swapping disks outside the office. Bans failed because the floppy disk met a need that enterprise systems had neglected: flexibility, portability, and speed. The lesson was clear then, and it applies now: prohibition doesn’t work when a tool is too useful and easily available.

If organizations today attempt to suppress public AI tools without providing viable alternatives, they will likely face the same outcome. Workers will continue to route around barriers, exposing sensitive intellectual property to consumer platforms not designed with corporate governance in mind.

What Companies Can & Should Do

Three strategies emerge from the analogy.

Offer real alternatives.

The most effective way to curb risky, unsanctioned AI use is not through restriction but substitution. Enterprise-grade AI accounts (where data isn’t used for training, where access controls are stronger, where usage logs are transparent) can compete only if they match or exceed the capabilities of consumer versions. Just as corporate networks eventually incorporated file-sharing and portable storage, companies must provide AI access that feels as frictionless as ChatGPT on a smartphone.

Train for data literacy, not just compliance.

Traditional corporate training often treats employees as potential liabilities to be managed: “don’t click phishing links,” “don’t upload confidential files.” But in the age of AI, compliance alone is insufficient. Workers must be trained to think like custodians of data. They need to understand the difference between editing a draft locally and sending it to a global AI service, or why inputting proprietary code into a consumer model is not just careless but potentially catastrophic. This shift is less about rules than about cultivating judgment.

Move from control to “trust, but verify.”

The dream of policing every query on every device is a fantasy. Companies should instead establish clear guidelines for responsible use, then back them with targeted monitoring of anomalies: large-scale data transfers, repeated uploads of sensitive categories, or unusual patterns that suggest systemic risk. The goal is not surveillance for its own sake but safeguarding core intellectual assets, much as network intrusion detection became a norm in the 2000s.

The takeaway is unmet needs, not disobedience.

The OpenAI report shows that AI at work is already a reality, but much of it is happening outside the safety net of enterprise governance. Workers are improvising. They are using consumer tools for writing, translation, and content creation - tasks that feel low-risk but, at scale, can expose valuable data. The longer companies delay in addressing this gap, the deeper the shadow usage will become.

The floppy disk eventually disappeared, replaced by more secure, integrated storage systems. But it left behind a lesson: when employees reach for unsanctioned tools, it’s a sign of unmet needs, not disobedience. If history is any guide, AI will follow the same arc. The question is whether companies will repeat the mistakes of the past or whether they will learn from a square of plastic that once seemed trivial, but quietly changed everything.

Footnotes

  1. Business Insider, OpenAI’s Enterprise Push Shows Corporate AI Adoption Is Accelerating, 2025. https://www.businessinsider.com/new-openai-report-chatgpt-use-nber-2025-9
  2. OpenAI, How People Are Using ChatGPT, September 2025. https://cdn.openai.com/pdf/a253471f-8260-40c6-a2cc-aa93fe9f142e/economic-research-chatgpt-usage-paper.pdf

Tell Us What You Think

Stay informed.

Be the first to get insights, invites, and updates.
EGS@EminenceGrowthSolutions.com
© Copyright - Eminence Growth Solutions. All Rights Reserved.