the ban did not stop the pasting. it moved it to accounts you cannot see.
77% of employees now paste content into ai chatbots, and roughly 82% of the risky pastes go through personal, unmanaged accounts. that is client data, pricing, contract language, and code sitting in a consumer account tied to someone's personal email: outside your retention policy, outside legal hold, and out the door with them when they leave. 68% of security leaders report an ai-linked data leak while only 23% have any policy written down, which tells you the leaks are running well ahead of the paperwork. the move everyone reaches for is the blocklist and the annual training module, and it produces exactly one measurable outcome: the same work, done on a phone, in a tab you have no visibility into.
do the version that holds: stand up one sanctioned account with retention and admin controls on, tell people plainly it is there and why, then write the policy in three lines, use the company account, never paste client or employee data, one named person owns exceptions. sequence matters here, a rule written before the sanctioned tool exists is a rule that teaches people to hide.