AI in your business: managed or unmanaged is the only real choice

July 2026

The question is not whether your people are using AI. In every business we sit with, they already are. Personal ChatGPT accounts, individually purchased Copilot subscriptions, browser extensions, workflow automation tools. The question is whether that adoption is managed or unmanaged, and whether you have a plan to move from the second state to the first.

Staff adoption precedes policy everywhere

The pattern repeats across sectors. An accountant discovers that ChatGPT can draft engagement letters in two minutes instead of thirty. A business development manager finds that Claude writes better tender responses than they can produce under deadline pressure. A facilities coordinator realises that Copilot can summarise three years of maintenance logs and surface the recurring faults nobody had time to analyse.

The productivity is real. The time savings are measurable. The problem is that nobody signed off on any of it, nobody documented what data went where, and nobody checked whether the subscription was paid on a personal credit card or a business account. By the time leadership hears about it, adoption is already widespread.

This is not malice. It is pragmatism. People have work to do, they have found a tool that helps them do it faster, and they are using that tool because the alternative is falling behind. Telling them to stop is both futile and counterproductive. The answer is not prohibition. It is managed adoption.

What unmanaged adoption costs you

Unmanaged AI creates three categories of risk. The first is data leakage. Every time someone pastes client data into a personal ChatGPT account, that data leaves your environment. The terms of service vary by tool and by subscription tier. Some retain data for training, some do not. Some offer business agreements with data protection guarantees, some do not. Unless you know what tools are in use and under what terms, you do not know where your data is going.

The second risk is cost leakage. If ten people have individually purchased Copilot subscriptions at consumer pricing, you are paying more than you would under a business agreement with proper licensing. If thirty people are paying for ChatGPT Plus out of their own pockets, you have no budget line, no usage visibility, and no control over whether those subscriptions continue when someone leaves the business.

The third risk is quality and consistency. A well-constructed prompt produces useful output. A poorly constructed prompt wastes time or, worse, produces plausible nonsense that gets used because nobody checked it. Without training, without examples, without a shared understanding of what good looks like, you get variable results and no systematic improvement.

The amnesty-based discovery model

The first step is finding out what is actually happening. We call this Shadow AI detection, and it starts with an amnesty. You announce that for the next two weeks, staff can declare what AI tools they are using without fear of being told off or having access revoked. The goal is discovery, not discipline.

Technical detection runs in parallel. Firewall logs show traffic to OpenAI, Anthropic, Google AI endpoints. Endpoint telemetry shows which browser extensions are installed. Licensing audits show which individual subscriptions are active. Email and calendar analysis sometimes surfaces SaaS tools with AI features nobody remembered signing up for. By the end of the process, you have a list.

The list is usually longer than leadership expected and shorter than IT feared. In a typical hundred-person business, we find between eight and fifteen distinct AI tools in active use. Some are productivity-focused, some are creative, some are quite niche. Some turned out to have been purchased years ago and are still renewing. Most are legitimate attempts to get work done faster.

The policy-first fix

Once you know what is happening, you can decide what should keep happening. The answer is not usually a blanket ban. It is a policy that separates permitted use from prohibited use, names the tools that are approved for business use, and explains what to do when someone finds a new tool they think would help.

A sensible policy covers data classification, so people know which information can and cannot be put into an AI tool. It covers approved tools and subscription tiers, so everyone moves to the business-grade versions with proper data protection agreements. It covers prompt discipline, because a poorly written prompt wastes time and a well-written one saves it. It covers output review, because AI drafts and humans decide.

The policy does not need to be fifty pages. It needs to be clear, practical, and written in language that non-technical staff can follow. We provide a plain-English template as part of our Advisory service, and most businesses adapt it in a day. The hard part is not writing the policy. The hard part is making sure people know it exists and can find it when they need it.

Moving from unmanaged to managed

Managed adoption means provisioning the right tools, training people to use them properly, monitoring usage to make sure policy is followed, and reviewing the results to see whether the promised productivity gains are real. It does not mean micromanagement. It means clarity about what is permitted, support for people using the permitted tools, and consequences for people who route around the policy without good reason.

In most businesses, the transition takes between one and three months. Discovery and policy happen in the first two weeks. Tool procurement and account provisioning happen in the second two weeks. Training happens in weeks three and four. Usage monitoring starts immediately and continues indefinitely. Within three months, adoption is widespread, usage is visible, and leadership can answer the question of whether AI is helping with evidence rather than anecdote.

Why this matters now

The difference between managed and unmanaged adoption is the difference between a capability you control and one that controls you. Unmanaged adoption grows in the gaps. It routes around oversight. It creates technical debt, compliance risk, and cost that nobody budgeted for. Managed adoption gives you visibility, control, and the ability to make informed decisions about where to expand and where to pull back.

If you have not yet done a Shadow AI audit, the likelihood is that adoption is already more widespread than you think. The people using these tools are not doing anything wrong. They are doing their jobs. Your job is to make sure they can keep doing them safely, within a framework that protects the business and supports them properly. That is what moving from unmanaged to managed means, and it is the only sensible choice.

Find out where you stand

Our AI Readiness Score includes Shadow AI detection, policy review, and a prioritised roadmap. Take the free assessment in ten minutes, or book a discovery session to discuss your specific situation.