A few months ago I was working with the senior team of a regional business. I asked how many of them had used a generative AI tool in the previous seven days. Almost every hand went up. I asked how many had used one for work. Two hands came down. Then I asked how many of those tools were sanctioned by the organisation’s IT and security policy. About a third of the remaining hands disappeared.

The room gave the small, nervous laugh people make when they have just learned something true about themselves. The organisation was discussing how to introduce AI to a group that had already introduced it to itself.

Your brief is not to introduce AI. Your people have already done that. Your brief is to make the current use safer, more useful and more consistent.

The adoption curve turned inside out

Most workplace technologies moved from the centre outward. The organisation chose the system, IT provisioned it, people were trained and use spread from there. Generative AI arrived in the opposite direction. Individuals found the tools first. They tried them at home, opened personal accounts and brought useful habits back into work before the organisation had agreed what official adoption should look like.

That inversion matters because a conventional rollout starts from an inaccurate picture. It assumes a clean baseline, a workforce waiting to learn and a platform that will create the behaviour. In reality, capability is uneven, useful experimentation is partly hidden and formal policy may lag several steps behind practice.

Licences can make the picture more confusing. A dashboard can show activation and weekly use without revealing whether any important work changed. Training attendance can show that people entered a room. Neither tells you what they now do differently on a Tuesday afternoon.

Diagnose before you announce

The sensible response is a short period of organisational reconnaissance. Find out where AI is already helping, where it is creating risk and where employees have stopped sharing what they are trying. Look for the gap between public statements and private behaviour. Pay particular attention to managers, because they decide whether experimentation has time and permission to become part of the work.

  • Where are people already using AI on real work?
  • Which experiments remain private because the rules feel unclear?
  • Who do colleagues ask when they get stuck?
  • Which tasks have changed, rather than merely become faster?

Those questions produce a better starting point than a generic maturity assessment. They describe this organisation, with its own patterns of trust, hesitation and initiative. That is the organisation the programme must serve.

Treat hidden use as a signal

Unapproved use cannot simply be celebrated. Sensitive data, weak verification and unclear accountability are real concerns. A blanket crackdown, however, removes the evidence you most need. People stop talking while the behaviour continues elsewhere.

Create a route for employees to surface experiments without being punished for asking. Separate curiosity from misconduct. Give people a clear data frame, a human-review rule and somewhere to bring an uncertain case. The aim is to move useful practice into the open, where it can be improved and governed.

AI adoption did not begin when the enterprise programme launched. It began when the first employee used a model to change a piece of work. Leadership starts by seeing what happened next.

This essay draws on Marc’s forthcoming field guide, The Missing Piece: How HR and L&D Turn AI Strategy into Everyday Practice.