A recent conversation with a colleague who frequently uses artificial intelligence (AI) for both personal and professional tasks has sparked questions about the use of autonomous AI agents on work computers. These AI agents can improve productivity by accessing files, emails, and internal company systems, but they also raise concerns about data security and who has the authority to install such software. The main issue is whether the employer or the employee has the right to install these tools on company devices. In most companies, an IT charter typically outlines the rules for software installation, often requiring approval from the IT department. Even without a formal charter, labor laws require both employees and employers to act in good faith when fulfilling contractual obligations. Installing software that could expose company data without proper authorization may be seen as a violation of these principles. The French data protection authority, CNIL, has pointed out the growing risks associated with AI agents in a report published in July 2026. These risks include cybersecurity threats and data processing issues under the General Data Protection Regulation (GDPR). Sending personal or company data to AI services like ChatGPT or Claude can create legal obligations for both employees and employers, especially regarding confidential business information protected by French commercial law. While companies like OpenAI, Anthropic, and Google claim that data from organizations with Business or Enterprise contracts is not used to train their AI models, this protection does not apply to employees using free versions or personal accounts, which are more commonly used. The risk of data leaks is well-documented, with incidents like Samsung engineers accidentally sending sensitive information to ChatGPT in 2023. In response, Samsung banned the use of generative AI tools on its internal networks. The phenomenon of "shadow AI," where employees use AI tools without IT department knowledge, has grown significantly, with many professionals using unauthorized accounts, according to the Verizon report on data breaches. Despite these risks, running AI models locally on a computer can reduce the chance of data being sent outside the device. However, even in this case, the software must still comply with internal rules on authorized programs. The decision on who to consult about AI tool use depends on the level of risk involved. For everyday use, a direct supervisor may be sufficient, but for activities involving sensitive data, consultation with the IT department, the information system security officer (RSSI), or the data protection officer (DPO) is necessary. The French National Agency for Information Systems Security (ANSSI) has issued security recommendations for generative AI systems that technical teams can use as a reference. Risks range from technical issues like software restrictions to potential disciplinary actions or personal liability in the case of data leaks. Despite the launch of the national plan "Osez l'IA," many French employees still lack clear written guidelines on AI tool usage. Unions are urging for clear agreements that specify which AI tools are allowed and what data can be entrusted to them, as such frameworks are currently missing in most organizations. For the colleague considering installing an AI agent, the lack of written approval should be treated as a clear "no," especially if the agent has access to sensitive files, emails, or customer data. A lack of response from management does not constitute authorization. Companies aiming to prevent the hidden use of AI should establish clear rules on which tools are permitted, what data can be entrusted to AI, and what data should never be shared with these systems.