There is no neutral position when it comes to AI in organizations
Two weeks ago, I stood in front of a room of HR executives in the “Leading with AI” workshop and asked them to pull out their phones. Each had to answer 14-questions touching on: (1) whether AI is permitted where they work, (2) whether it’s guided, and (3) whether anyone has told them what good looks like. I put their own answers on screen as a live dashboard, sorted into four quadrants.
Figure 1: The quadrants organizational typically fall into when it comes to AI adoption
Perhaps unsurprisingly most of the room was sitting in ‘Chaos’ while a smaller but significant cluster sat in ‘Underground’. Just two slipped into the Ideal quadrant, but with a slim margin.
No Neutral Position
That’s worth sitting with. Nobody in that room chose ‘Chaos’ on purpose. They simply hadn’t chosen anything when it came to official AI use, and the absence of a decision turned out to be a decision anyway.
A second chart I showed them made the point sharper, it showed their own AI use plotted against the guidance their employer’s policy provides, one dot per person, sorted by the size of the gap. The widest gap ran a full four points on a five-point scale, and it wasn’t one outlier skewing the average, it was the vast majority in the room. They were three or four points ahead of what their own organisation had sanctioned, HR leaders included. PagerDuty found the same pattern at scale this year: 66% of office professionals admit to using AI tools their employer never approved. So regardless of what your company policy says, this tech is already inside your house.
There simply is no longer any neutral position on AI adoption. There is only the position you’ve taken…perhaps unwittingly.
The Three Levers
Most organization tend to hand the AI problem either to IT or to Compliance. I understand that instinct because AI arrives as a login and/or a data breach risk. But look at what actually goes wrong once it’s in. Trust erodes when too many manager email reads as inauthentic. A deluged of confident sounding “AI slop” lands in inboxes and costs workers hours to fix. A critical decision rests on something an AI quietly hallucinated or assumed. Someone produces excellent work but cannot explain it in front of a client. I could go on.
None of that is a technology failure. Every one of those is a behaviour, and there are only three levers that reliably change behaviour at scale: friction (like policies or rules), incentives, and capacity building. IT and Legal can pull the first. But with a technology that is so readily available and which use is so easy to hide, enforce is always a struggle. Neither can make anyone feel safe enough to disclose their use honestly either and they have no mandate to build capacity. That toolkit has sat with HR long before anyone called for AI adoption.
The Cost of Being Careful
I use four stories in the workshop to make the quadrants concrete, and the one that lands hardest is never “Chaos”. It’s “Constrained”, or the one built by people trying to do everything right. A utility’s board asks for an AI position after a supplier incident makes the news. Nine months later they have one: a hundred-and-thirty-four-page policy, a governance committee, and a single approved AI model, ring-fenced but two generations behind whatever’s already on everyone’s phone. Access needs a business case and sign-off. The average wait…five weeks. Of 11,000 staff, fewer than 650 get approved in the first year. An even smaller fraction of those uses it more than twice.
Nothing goes wrong, and everyone says so, often. In fact, nothing much happens at all. The work still gets done, because a contractor not covered by the policy uses AI anyway, and a young engineer quietly builds and runs a game changing solution from his personal account which later gets him into trouble. The company’s integrated AI report describes a mature, well-governed AI posture. It goes on to describes an organisation that spent nine months and a great deal of goodwill building a very safe way of getting nothing more out of AI than if they had never adopted it at all.
The One Meeting
The fourth story starts exactly like the first with a a board paper, a licence, an implementation plan owned by IT until one meeting changes it. The HR Director asks for the rollout to be pushed back a quarter: handing a powerful new tool to nine thousand people who’ve been told nothing about what it will be heard only as one thing in the current climate: “we are being replaced.” Carry that into the training and the resistance will be palpable.
So, the quarter goes on the story instead. Roadshows run by functional managers, not IT. One message used correctly: this gives you back hours and frees up your time to do innovative things. A second, more unusual focus: here’s what it’s bad at and what to look out for, confident wrong answers, communication that sounds like you and isn’t, data analysis gone wrong. Everyone gets exploration credit, nobody is told which tool to use, and the only thing asked in return is that people say when they used it. No shaming…ever. Eighteen months later, that organisation’s HR function (and indeed many other functions) writes their own campaigns, drafts their own contracts before Legal sees them, and builds their own dashboards without joining the IT queue. The team is the same size it was. It’s simply doing work it used to buy in.
More Than a Breach
The instinct is to treat AI adoption as a subset of cybersecurity honestly doesn’t work. MIT researchers tracking enterprise AI projects this year found that 95% failed to produce any measurable return. This not because the models were bad, but because organisations kept buying tools and skipped the harder work of changing how people use them. That would be like getting hyper focused on the tennis racket brand you are buying the team but forgetting to actually teach anyone to play tennis.
Besides the lost innovation this results in, there is a significant impact on workplace morale and trust. Get this right and you unlock a productivity multiplier that emerges on its own, because people who feel safe experimenting find uses nobody in a steering committee could have anticipated. Get it wrong (by ignoring it or by locking it down) and you get a workplace measurably worse to work in than if the technology had never arrived: less trusted communication, more unexplained work, more fear nobody will name, a sense that you are being left behind.
People function leaders need to step up to the AI moment, because ownership was never about who bought the tool. It’s about who’s accountable for what a few thousand people do with it once they have it.
Does you organization have an AI policy? Is it enforceable? What happened to the first person when they openly admitted to using it? Because the latter speaks to the real policy while the former is likely just tick-boxing.







