The Census Bureau's Business Trends and Outlook Survey, covering more than 117,000 firms, found that AI is arriving through two channels that don't always overlap. Some 14.4% of firms report both formal adoption and workers using AI for tasks. But 6.8% report worker-task use without the firm registering as an adopter, and 2.5% report formal adoption with no worker-task use at all.
The 6.8% needs handling with care. It doesn't measure unauthorized use or policy violations. It measures a mismatch between two differently framed survey questions — one asking about the previous two weeks, the other about six months — both answered by a firm respondent rather than by individual employees. The working paper doesn't break the gap down by industry or firm size. What it does establish: bottom-up and top-down adoption are running on different clocks in a measurable share of American firms. Among firms where workers use AI for tasks, only about two-thirds also report formal organizational adoption.
The 2.5% is the inverse mismatch, and harder to explain away with timing, since the worker-task question covers a full six months. If no worker used AI for a task in that window, the adoption probably lives below the workflow: automated processes, backend integrations, purchased capability that hasn't reached anyone's desk. That raises a different question — not whether individual use is outrunning oversight, but whether organizational investment is producing the engagement it was bought to produce.
The shape of the 6.8% will look familiar to anyone who has traced the history of spreadsheet controls. Spreadsheets became ubiquitous in the 1980s; specific governance requirements didn't arrive until the mid-2000s, and only after a run of costly, documented failures made the risk concrete enough to regulate. Individual use outran institutional oversight for about twenty years.
That precedent is useful mainly as a map of where risk collects: in unreviewed outputs that enter decision-making, in data that reaches a critical process without ever being reconciled against its source, in tools that change without anyone tracking the change. Access restrictions, formula review, reconciliation, documentation — every one of those controls was a response to an accumulation of exactly that kind.
The comparison stops working at a point worth being precise about. A spreadsheet sits on a disk. It processes the data someone put into it, using formulas someone wrote, and produces output you can inspect cell by cell. An agent calls external tools, mutates records in systems the firm doesn't own, and varies its behavior with the underlying model, its retrieval context, and whatever the tools hand back. A spreadsheet error stays local until someone copies the output into another process; an agent's action can cross an organizational boundary before anyone has a chance to interrupt it, and no single control terminates an evaluation, revokes credentials, and unwinds downstream effects together. A delegation whose scope drifts when the model is updated has no spreadsheet equivalent at all.
Early responses are already forming. NIST's 2024 Generative AI Profile calls for acceptable-use policies and monitoring. FINRA's 2026 oversight report names agent-specific risks: autonomy, action beyond intended scope, auditability. Australia's financial regulator found governance lagging adoption across the licensees it reviewed. The familiar categories are reappearing — inventory, approved-tool lists, documentation, pre-deployment review, version tracking — but no mandatory cross-industry regime yet treats worker-level AI use the way end-user computing policies treat spreadsheets.
One will arrive. On the spreadsheet evidence, it will arrive after the failures that make it politically necessary, and it will be written by people reconstructing what happened rather than by people who saw it coming. Firms reading the Census numbers can decide now whether they'd rather write their own version first.

