Before any formal AI strategy, one thing is already certain: employees are already using generative AI tools at work. They paste text into a chatbot, ask for summaries of internal documents, draft proposals. They do it with good intentions and no policy to guide them.
The risk disguised as productivity
An employee who pastes customer data into a public chatbot to ask for an analysis is, without realising it, exposing sensitive information to a system outside the company's control. It isn't bad faith. It's the absence of judgement.
This risk doesn't show up in quarterly reports. It only becomes visible once it has already caused an incident: a data leak, a decision made on a model hallucination, a misread contract clause.
Why banning it doesn't work
Banning generative AI doesn't eliminate the risk, it just hides it. Employees keep using the tools, without leadership visibility and without any safety criteria. The ban turns a managed risk into an invisible one.
What a mature criterion requires
- A clear policy on what data can, or can't, be shared with external AI tools.
- Practical training, not a document nobody reads, on how to use these tools safely.
- A named owner responsible for making sure the policy is followed and kept current.
- Leadership visibility into which tools are actually being used across the organisation, not just the ones on the official list.
Preparing teams to use AI with judgement isn't about slowing down productivity. It's the difference between managing a risk and being blindsided by it.