Summary
Most organisations did not decide to adopt AI. An employee opened ChatGPT. What that means for your data, your oversight, and who actually owns the decision.
Contents8 sections
- 01The unofficial AI programme
- 02Banning AI does not automatically solve the problem
- 03AI literacy is more than knowing how to prompt
- 04The problem may be bigger than staff behaviour
- 05Someone still needs to own the decision
- 06Five questions worth asking your team this week
- 07The goal is not to stop AI
- 08How ready is your organisation?
For many organisations, AI adoption did not begin with a strategy meeting.
It began with an employee opening ChatGPT.
Someone needed to rewrite an email. Someone else wanted to summarise a document. A manager needed help analysing a spreadsheet. A team discovered an AI feature inside software they were already using.
No project was approved.
No budget was allocated.
No one announced an “AI transformation programme”.
But AI entered the organisation anyway.
That changes the conversation.
The question is no longer simply:
Should we allow our employees to use AI?
A better question is:
Do we understand how they are already using it?
The unofficial AI programme
Nobody set out to create exposure. They set out to save half an hour.
Most employees are not trying to create risk.
They are trying to get work done.
Imagine an employee has a long customer complaint to respond to. Instead of spending 30 minutes drafting the reply, they paste the customer's message into an AI tool and ask for help.
It saves time.
But what was in that message?
Now imagine the same behaviour happening across finance, HR, operations, marketing and customer service.
One employee may be using AI responsibly.
Another may be uploading information they should never have shared with an external tool.
Leadership may have visibility of neither.
This is sometimes called shadow AI, but the label matters less than the practical problem:
AI use can spread faster than an organisation's ability to manage it.
Banning AI does not automatically solve the problem
A prohibition can buy silence rather than safety.
One response is to prohibit public AI tools completely.
For some activities, that may be appropriate.
But a policy saying “do not use AI” does not necessarily mean employees have stopped using it.
It may simply mean they have stopped talking about it.
That can make the organisation less informed, not more secure.
A better starting point is understanding what people are actually doing.
Ask:
- Which AI tools are employees already using?
- What are they using them for?
- What information are they entering?
- Which activities are genuinely useful?
- Which activities create unacceptable risk?
- When must a human check the output?
- Who should employees speak to when they are unsure?
These are not questions for the technology team alone.
They involve leadership, people, data and governance.
AI literacy is more than knowing how to prompt
The most valuable skill is knowing when not to reach for the tool.
A lot of AI training focuses on getting better answers from tools.
That is useful, but it is incomplete.
An AI-capable employee should also understand when not to use AI.
They should know that a confident answer can still be wrong.
They should recognise when information is sensitive.
They should understand that generating content is different from approving it.
And they should know when a decision requires human judgement.
The goal should not be to create employees who use AI everywhere.
The goal should be to create employees who can make sensible decisions about where AI helps and where it does not.
That distinction matters.
The problem may be bigger than staff behaviour
Heavy AI use is often a symptom of something further upstream.
Suppose leadership discovers that employees are frequently using AI to locate information scattered across documents and folders.
The immediate reaction might be:
We need an internal AI assistant.
Maybe.
But why are employees struggling to find the information in the first place?
Are documents duplicated?
Is ownership unclear?
Are files outdated?
Are access permissions inconsistent?
Is important knowledge sitting inside individual inboxes?
AI may help solve part of the problem.
But it may also reveal a deeper data and information-management issue.

The AI question usually sits on top of an information question. What people are reaching past is often the part that needs the work.
That is why starting with the technology can be misleading.
Sometimes the question is not:
Which AI tool should we deploy?
It is:
What is making people reach for AI in the first place?
Someone still needs to own the decision
Governance, described as authority rather than paperwork.
There is another question many organisations eventually encounter:
Who is responsible for AI?
The answer will differ between organisations.
What matters is that responsibility is clear.
Someone needs to decide which tools are acceptable.
Someone needs to understand what information can be used.
Someone needs to consider suppliers and data handling.
Someone needs to define where human oversight is required.
And someone needs the authority to stop an AI use case when the risk outweighs the benefit.
That is governance in practical terms.
Not paperwork for the sake of paperwork.
Clear decisions, clear ownership and clear boundaries.
Where we stand
Gen3Block treats governance as part of organisational readiness rather than something added after technology has already been selected.
Five questions worth asking your team this week
A conversation you can have before any strategy exercise begins.
You do not need a six-month AI strategy exercise to begin understanding the situation.
Start with five questions:
- 01Which AI tools are you using for work?You may learn more from this question than from reviewing the organisation's official software list.
- 02What tasks are you using them for?Drafting, research, analysis, coding, customer communication and document summarisation carry different implications.
- 03What information are you entering into them?This is where data protection, confidentiality and security become real rather than theoretical.
- 04How do you check whether the output is correct?If nobody can answer this, human oversight may already be weak.
- 05What would help you use AI more safely and effectively?Employees often know where the uncertainty is.
Listen to them.
The goal is not to stop AI
What has to be true for adoption to be a decision rather than an accident.
It is to understand what the organisation is ready to support.
Used well, AI can remove repetitive work, improve access to information and help people work more effectively.
But organisations need more than access to powerful tools.
Without those things, AI adoption can happen accidentally.
With them, it becomes a deliberate organisational decision.
How ready is your organisation?
Evidence you already have, and a structured way to read it.
If your staff are already experimenting with AI, that does not automatically mean your organisation is ahead.
It does not mean you are behind either.
It means you have evidence worth understanding.
Gen3Block's free AI Readiness Assessment looks across four areas:
- Strategy and Leadership
- Skills and Culture
- Data and Infrastructure
- Governance and Risk
It is designed to help organisations see where they are strong, where the gaps are and what should happen next. The assessment produces a scored report and a personalised 90-day roadmap.
There is no requirement to speak to Gen3Block afterwards.
Before you add more AI to the organisation, understand the AI that may already be there.