AI enablement · Adoption and governance
AI is only worth what people actually use
We set clear rules on acceptable use, agree which models and tools are approved, decide on disclosure and human oversight, train your people, and measure whether the benefits actually arrived. This organisational work determines the return on everything else. Regulatory controls are covered separately by AI security.
Where this starts
People are already using AI without approval
By the time an organisation writes its first AI policy, its people have usually been using AI tools for a year. They use personal accounts, work with real company information and leave no record. A policy that ignores this is untrue from the start. What works is to provide an approved option that is genuinely better than the unapproved ones, and then be clear about what can and cannot be done with it.
What we usually find
- Company information pasted into personal accounts, with no record kept
- A policy that simply bans AI, which people find ways around within a week
- No guidance on what must be disclosed to customers
- Licences bought per user, with no measure of use or benefit
- An approval process so slow that teams avoid it
- No named owner, so every question ends up in a recurring meeting
Our position
A policy that people work around is worse than having no policy. It creates a written record that says one thing while the organisation does another.
What the work covers
Permission, ability and proof
Three things need to be true at the same time. People are allowed to use AI, they know how to use it well, and someone can show that it made a difference.
Acceptable use in plain language
We set out what information can go into which tools, written so that people can follow it without interpretation. It is short enough that they will actually read it.
Approved models and tools
We agree which AI models and products are approved for which types of work. There is a quick way to request a new one, which is easier than going around the process.
Disclosure and human oversight
We decide when customers must be told that AI is involved, and which decisions need a person to review them. These decisions are based on your obligations and your appetite for risk, not copied from a template.
Training that changes behaviour
We provide training for each role, based on the work people actually do, rather than a general session. People are rarely short of enthusiasm. What they lack is knowing what good use looks like in their own job.
Ownership
A named person owns AI decisions and has the authority to make them. Otherwise, every question goes to a committee and nothing is ever settled.
Measuring the benefits
We measure results against the starting point recorded at the beginning, and are willing to record that an idea did not pay off. That record is what makes the next business case credible.
How it stays real
A position you can see and check
If nobody can see whether a control is working, it is only an intention. These measures make the organisation’s position visible, without monitoring individuals.
- Approved option
- An approved tool that is genuinely better than the unapproved alternatives does more for compliance than any amount of policy writing.
- Register
- An up-to-date register of AI use across the organisation, including tools a team bought on a company card without telling anyone.
- Requests
- A simple way to get a new tool or use approved, with a response time short enough that people use it rather than working around it.
- Usage
- Usage is measured by team and by process, so a licence nobody uses is spotted well before the renewal date.
- Benefits
- Results are reported against the original starting point on a regular schedule, including the ideas that did not deliver, because those teach the most.
What you are left with
- An acceptable use policy short enough to be read and followed
- A list of approved models and tools, with a quick way to add new ones
- Training for each role, based on the work people actually do
- An up-to-date register of AI use across the organisation
- Benefits reported against the starting point, including what did not pay off
Ask your teams which AI tools they already use
Their answer is the real starting point, and it almost always covers more than anyone expected.
