Insights
AdaptationPerformYou Can't Govern AI You're Not Really Using
11 September 2026
Over the last couple of weeks I’ve been talking with a wide range of people about AI adoption in their businesses. At one end are small business owners who don’t know where to start, or whether they should. At the other are large corporates that have been working with AI, and the governance of it, for years. In between, everything from pockets of unstrategised use to genuinely stunning work.
One thing has become obvious. The size of an organisation tells you very little about its AI maturity, and neither does whether it has an AI policy.
83% adoption. 13% policy.
A recent EMA survey of more than 300 of its member businesses produced a statistic worth sitting with. 83% said they were already using AI. Only 13% had an AI policy.
A policy isn’t governance, of course, but it’s a useful proxy for how formally an organisation has thought about the issue.
The EMA’s own reading was that the next challenge for AI is not adoption but governance: businesses have run ahead, and now the rules need to catch up. That’s half right.
There’s another way to read the same number, though: governance without meaningful adoption isn’t worth much either. I’ve watched organisations pour effort into AI governance while almost no AI is being used to change how the work gets done. You can stand up a committee, write a policy, build a risk matrix, define approved and prohibited uses. All sensible. But at some point somebody has to use the stuff. Or, as engineers say, use it in anger: real users, real deadlines, real data, real consequences. That’s when you find out what actually needs governing.
And here’s the uncomfortable part. An AI policy is a cheap thing to produce; you can have one by Friday, and it photographs well in a board pack. Real adoption, the kind that moves cost lines and cycle times, is slow, uneven and occasionally embarrassing. An anxious organisation reaches for the cheap one first.
“So we just let everyone loose?”
There’s an obvious objection here. “So we let everyone run wild with AI until someone pastes the customer database into a chatbot and we’re on the front page?”
No.
There’s a difference between guardrails and governance, and you need the guardrails from day one. Putting customer data, IP or commercially sensitive material into an AI service you know nothing about is a bad idea, and a free consumer account is not an approved enterprise one: retention, training and privacy terms vary by product and account type. None of this is new. Twenty years ago we wouldn’t have uploaded the customer list to a random website, and AI doesn’t repeal information security. So set the boundaries: know which tools people use, what data is off limits, who’s accountable for consequential decisions, and what access an agent actually needs.
Guardrails first.
But guardrails aren’t the same as governance, and this is where “govern first, adopt later” starts to fall apart.
You don’t know what you don’t know
The problem with designing full governance before serious adoption is that you don’t yet know how people will use the technology, and the best use cases won’t come from the steering committee. They come from the people doing the work. A salesperson preps for a client meeting in ten minutes, not an hour. Finance automates a reconciliation that used to eat a day a week. A project manager interrogates two years of correspondence in an afternoon. A developer stops treating AI as autocomplete and hands whole chunks of work to a coding agent. A small business owner wires a few systems together and deletes a process they’d been paying someone to run by hand for years.
You won’t predict those from a policy document. And when people start doing them, the real governance questions arrive on their own. Where does the model hallucinate? Who owns the outcome when the answer is wrong? What changes when AI stops recommending an action and starts taking it? What happens when a core process quietly becomes dependent on an agent? Those are governance questions, and they’re far easier to answer attached to something real than in the abstract.
Shadow IT is here again
There’s another reason “govern first” won’t hold: your people aren’t waiting. We’ve been here before. A decade ago it was personal Dropbox accounts, unsanctioned SaaS and company data walking out of the building one convenient shortcut at a time, and the lesson from that round was that a policy saying don’t didn’t make it stop. It just made it invisible.
This time the barrier is even lower. Generative AI has one of the lowest adoption thresholds we’ve ever seen: no IT project, just a browser. Someone opens ChatGPT, someone else prefers Claude, a developer installs a coding assistant, someone finds an AI feature buried in a SaaS product the company already pays for. Five minutes later a task that took an hour takes ten, and they’ll do it again, whether or not they tell anyone.
This is shadow IT with the friction removed. The organisation with no approved AI tools is often not the one with no AI use. It’s the one where nobody’s talking about it.
Govern what you learn
So “adoption first or governance first” is the wrong argument, because neither can get too far ahead of the other. Adoption without governance creates exposure. Governance without adoption creates bureaucracy: rules built around behaviour nobody’s exhibiting yet.
The workable model is a loop. Put guardrails around experimentation, let people find real uses, watch what happens. Find where the value is and where the risk is, tighten governance around what turns out to matter, and go again. As adoption moves from one person on ChatGPT to teams redesigning workflows, governance matures with it. When agents start taking actions in business systems, it matures again. Governance isn’t a gate you clear before the journey. It’s part of the journey.
Maybe we’re measuring the wrong thing
So back to 83% versus 13%. It sounds alarming, but I wouldn’t assume the 13% with a policy are the mature ones and everyone else a laggard. I’ve met small businesses doing sophisticated things with AI, learning fast, changing how they operate. I’ve seen much larger organisations with far more governance, far more PowerPoint, and far less actually happening.
The useful measure isn’t whether you have an AI policy. It’s whether you’re learning to use AI to make the organisation better while understanding and managing the risk that creates. That’s a moving target: the technology won’t hold still, and it’s too powerful to leave as a free-for-all.
So maybe the sequence is simpler than we’re making it. Put the guardrails up. Start using it. See what happens when it’s used in anger. Govern what you learn. Then do it again.
The risk isn’t just using AI without governance. It’s building governance around an AI organisation that doesn’t yet exist.
Are you governing real AI use, or governing what you imagine people might eventually do with it?