The AI Vampire: Why Productivity Gains Without Governance Create New Risk

QL Security
ai-vampire ai-burnout ai-productivity-risk ai-governance workforce-ai-adoption

Most organisations treat AI adoption as a wellbeing question when their best people stop logging off. It is a security question. The AI vampire, the pattern where high-performing AI adopters cannot stop working, is a human governance gap that shows up on your risk register long before it shows up in an HR survey. When AI recovers time and nobody sets the rules for how that time gets used, the recovered hours flow back into more work, more output and more unreviewed material leaving the building at 4am.

This post is for the people who own AI adoption risk: CISOs, CTOs, Heads of Compliance and HR Directors running adoption programmes. The argument is straightforward. Ungoverned productivity creates ungoverned risk, and the surface area grows with every output your workforce generates faster than anyone can review it.

What is the AI vampire?

The AI vampire is the phenomenon where AI tools raise individual output so much that adopters work longer rather than less, feeding an appetite that never settles. Engineer Steve Yegge, writing on Medium, has described how AI-assisted work tends to expand to consume whatever time it frees. The vampire label was applied to that pattern by Marina Danilevsky in her Mindstone session at HumanX SF.

That session put a practitioner’s enterprise observations behind the concept. As Danilevsky described it, the highest AI adopters were not the ones reclaiming their evenings. They were the ones producing far more volume and reviewing a fraction of it, because the tool made starting the next task cheaper than finishing the last one properly. On that account, the vampire does not make people lazy. It makes them relentless, which is the harder problem to spot and the more dangerous one to leave alone.

The evidence: more work, not less

UC Berkeley research found that AI tools can increase workload and burnout rather than reduce them, acting as a drag on long-term efficiency. The pattern is recurring: adopters take on more tasks, feel more pressure and report higher burnout, even as their per-task speed improves.

A second effect sits alongside this. BCG’s “AI brain fry” findings point to cognitive fatigue, the drain that builds when people supervise a constant stream of machine-generated output. Reviewing AI work is itself demanding, and decision fatigue sets in faster than most leaders expect. A tired reviewer approves what a fresh one would query. That is where the productivity story stops being an efficiency story and starts being a control story.

Why this is a security problem, not a wellness one

More AI output means more surface area for errors, hallucinations and data leakage. A fatigued workforce reviews less of it. This is the core divergence between QL Security’s position and most coverage of the topic, which frames the vampire as a wellbeing concern to be managed with encouragement to disconnect.

Consider what ungoverned productivity actually produces. Client-facing documents drafted by AI and sent without a second read. Prompts containing confidential data pasted into tools nobody sanctioned, often outside working hours when unsanctioned use tends to rise and oversight thins. Decisions made at the edge of decision fatigue, where the reviewer is too tired to catch the hallucinated figure or the fabricated citation. Each of these is a compliance exposure and a data protection risk, not a morale dip.

The volume compounds the danger. When one person generates ten times the material, your existing review controls, designed for human-paced output, silently fall behind. The gap between what gets produced and what gets checked is where incidents live.

The leadership expectation gap

If you do not set the rules for how recovered time is used, the vampire sets them for you. This is the expectation gap, and it is a leadership failure rather than an employee one.

Staff take their cues from what the organisation rewards. When AI-driven volume earns praise and nobody defines what good governed AI use looks like, people optimise for output and quietly drop the review steps that slow them down. Setting the rules means being explicit: which tools are approved, what must be reviewed before it leaves the organisation, when AI use is expected to stop and how recovered time should be reinvested. Guardrails for people, in other words, alongside guardrails for systems.

Responsible AI adoption governs both. A policy that secures your models and data but ignores how your workforce actually behaves under AI-accelerated pressure has a hole in the middle of it.

Building guardrails for people as well as systems

Governing the human side of AI adoption starts with acknowledging that behaviour is part of your control environment. The practical work sits in three areas: sanctioned tooling with clear boundaries, review controls sized for AI-paced output rather than human-paced output and explicit expectations about working patterns and time reinvestment.

This is the terrain our AI governance advisory covers. We help organisations set adoption rules that treat the workforce as part of the risk surface, so recovered time strengthens the business instead of feeding the vampire. The aim is adoption that scales output without scaling exposure.

Key questions on governing AI-driven overwork

Who owns the AI vampire problem inside an organisation?

It sits across security, compliance and HR, which is why it often falls through the gaps. Security owns the data leakage and unreviewed-output risk, HR owns burnout and working patterns and compliance owns the regulatory exposure. Effective governance names a single accountable owner and gives them authority across all three functions rather than leaving it unowned.

How do we spot the vampire before it becomes an incident?

Watch the gap between output volume and review coverage, not just wellbeing signals. Rising after-hours activity, spikes in unsanctioned tool use and a growing backlog of unreviewed AI outputs are earlier indicators than burnout surveys. Monitoring these patterns lets you intervene while it is still a governance adjustment rather than a breach investigation.

Does governing AI use slow productivity down?

No. Ungoverned adoption produces volume that cannot be trusted, which means rework, incidents and eroded confidence in AI output. Governance sizes review to the pace of production and sets clear boundaries, so the output your workforce generates is usable the first time. Trusted output at a slightly lower rate beats unchecked output nobody can rely on.

When should we put these guardrails in place?

Before adoption scales, not after an incident. The vampire takes hold quietly during the enthusiastic early phase, when leaders are celebrating productivity gains and controls have not caught up. Building human-side guardrails into the adoption programme from the start is far cheaper than retrofitting them once behaviours and exposures are established.

If your AI adoption programme governs the technology but not the people using it, the exposure is already growing. Book a conversation with our advisory team to close the human governance gap before it becomes an incident: talk to us about AI governance.

This post is for information only and does not constitute legal or regulatory advice.

Close the human governance gap

If your AI adoption programme governs the technology but not the people using it, the exposure is already growing. Talk to our advisory team before it becomes an incident.