AI adoption looks like a hundred small choices. Which tool, which team, which use case first. Underneath all of it, every organization is really only working through three decisions, and most haven't made any of them on purpose.
Your team is already moving, and that part is good news: adoption solved itself. In a 2025 survey of 1,000 U.S. workers, 78% said they use AI tools their employer didn't provide. The open question isn't whether AI gets used. It's what happens next: who decided any of this was okay, and on what terms.
The three decisions
What can go in. What data, documents, and client information are people allowed to put into an AI tool, and what's off-limits. Not a vibe. A specific, written answer: which data is green and fine to use, which is yellow and needs a check first, and which is red and never goes in.
Who owns the answer. A named person who owns AI use inside the organization, and who people actually go to when they're not sure. Not a committee that meets quarterly. A name.
Who's accountable when it's wrong. When AI produces something wrong and it goes out the door anyway, whose job was it to catch it. Decided in advance, not sorted out afterward in a hallway conversation.
Ask these three questions inside most companies and you get silence, or five different answers, or a confident answer that contradicts what's written down somewhere. The same survey that found 78% using unsanctioned tools also found 51% of employees get conflicting guidance on how they're supposed to use AI at all.
When the answer is unclear, people don't stop working. They guess, and they guess in the direction of getting the work done.
A policy is not the same as a decision
Almost every organization makes the same move. AI use spreads, someone gets nervous, and a policy gets written. Now there's a document. The box is checked.
Look one layer down and the document is usually thin on two of the three decisions. Three-quarters of organizations report having an AI usage policy, but far fewer have a named owner, a way to monitor what's happening, or a plan for when something goes wrong. The first decision got made. The other two didn't.
That's the tell. A policy is a paragraph. A decision names a person, draws a line someone can act on, and survives contact with a Tuesday afternoon when an account manager wants to paste a client's contract into a chatbot to summarize it.
The gap that costs the most is the one nobody sees
You'd expect the most exposed companies to be the ones that did nothing. Often it's the ones that did just enough to feel covered.
An organization that knows it hasn't made these decisions is at least watching for the risk. One with a policy nobody owns, nobody checks, and nobody can answer questions about has something more expensive: confidence it hasn't earned. It moves fast, assumes someone upstream is handling it, right up until something lands somewhere it can't be pulled back from.
That's not hypothetical. In IBM's 2025 breach research, unsanctioned AI use was a factor in roughly one in five breaches, adding about $670,000 to the cost where it ran high. Most of those organizations either had no AI governance policy or were still "working on one." The gap between the paragraph and the decision is where the cost shows up.
Start by seeing where you actually stand
You can't make a decision you don't know is unmade. Before any policy gets rewritten, get an honest read on where AI already lives in your organization, what data is exposed, and which of these three decisions are genuinely made versus only assumed.
That's what the AI Readiness Assessment does: five questions, about two minutes, and a structured look across the five dimensions that decide whether your AI use is a working system or a pile of guesses. It's also the front door to how we work. We build your governance system, your team runs it, and we never pick or resell tools, so what you get is a clear picture of which decisions you've actually made, not a pitch.
Every AI rollout comes down to three decisions. Find out which ones you've actually made.
Keep reading
Part of a series on AI governance, the structure underneath the tools.
- What's Safe to Paste Into ChatGPT?. The data-classification question in its most literal form.
- The 4 Stages of AI Governance Maturity. The framework, and which stage you're actually in.