A conversation I’m having more often with business owners starts like this:
“We don’t really use AI yet.”
Then you ask a few more questions.
Someone is using ChatGPT to help write emails.
Another person is using AI to summarise meeting notes.
Someone else has found an AI-powered browser extension that makes part of their job quicker.
Suddenly, it turns out the business is using quite a lot of AI.
It just hasn’t formally decided to.
AI can arrive before the policy does
That’s understandable.
If someone discovers a tool that saves them time or makes their job easier, they’re naturally going to experiment with it.
The problem starts when nobody has agreed where the boundaries are.
Imagine someone receives a long email from a customer.
They paste it into an AI tool and ask it to draft a response.
Within seconds, they have something useful and have probably saved themselves 15 minutes.
So they do it again tomorrow.
Next week, they upload a proposal because they want it summarised.
Then someone else discovers another AI tool that can analyse a spreadsheet.
Nobody feels like they’re doing anything wrong.
They’re just trying to get their work done more efficiently.
But without clear guidance, customer information, financial data, internal documents or commercially sensitive information could be shared with AI tools the business has never reviewed or approved.
And that can happen with the best intentions.
AI is different from traditional business software
AI has also arrived in businesses differently from most other technology.
A new accounting system normally goes through a buying process.
Someone usually approves a new CRM before the business starts putting customer information into it.
AI tools can be different.
An employee can discover one in the morning and be using it for real work by lunchtime.
By the time the business starts thinking about an AI policy, employees may already have their favourite tools and established ways of using them.
Simply telling everyone to stop isn't necessarily the answer either.
If someone has found a tool that genuinely makes their job easier, they may struggle to understand why the business suddenly doesn't want them using it.
From their perspective, they're solving a problem - not creating one.
Find out what's already happening
A better starting point is understanding how AI is actually being used across your business.
Which tools are people using?
What are they using them for?
What information are they sharing?
Which tools are approved?
And does everyone understand what business or customer data should never be entered into an unapproved AI system?
Once you know what's happening, you can start putting sensible boundaries around it.
That might mean agreeing which AI tools employees can use, introducing an AI policy, reviewing security and privacy, looking at access to company data, and helping employees understand how to use AI responsibly.
The aim isn't to stop people benefiting from AI.
It's to make sure your business gets the benefits without introducing risks nobody has thought about.
If you've never asked your team which AI tools they're already using, it might be worth asking.
The answers could surprise you.
And if you'd like help reviewing how AI is being used across your business and putting the right security, policies and controls around it, get in touch.