There is a conversation that happens in a lot of boardrooms, roughly quarterly, about whether the business should start using AI.
It is a slightly unreal conversation, because the business started using AI about eighteen months ago. Not as a decision. As a series of individually sensible choices by people trying to get their work done.
How it actually arrives
Nobody announces it. It turns up like this:
Someone in accounts discovers that pasting a messy supplier statement into a chatbot produces a tidy summary in four seconds. They tell one person. That person tells two more.
Someone in sales starts drafting proposals with it, because the first draft was always the slow part. The proposals get better. Nobody asks why.
Someone books a meeting-notes bot into a recurring client call. It works well enough that other people start booking it into theirs.
Somebody's phone updates and now the keyboard has an AI button on it.
None of that is a policy violation, because there is no policy. None of it is reckless. Every one of those people made a reasonable call with the information they had, which was none.
The actual exposure
The risk is not that staff are using AI. The productivity is real and the businesses refusing to touch it are losing ground to the ones that are.
The risk is that nobody can answer three questions.
Which tools hold your data right now? Not which are approved. Which have been used. A free-tier account signed up with a work email address is a contract nobody read, with retention terms nobody checked, holding whatever got pasted into it.
What went into them? This is usually the uncomfortable one. Most businesses discover their worst case after the fact: a client contract uploaded whole for summarising, a spreadsheet of staff details pasted in for tidying, a chunk of source code.
Who would you have to tell? If the answer to the first two is bad enough, that becomes a notification question. Working that out under pressure, without a record of what happened, is a bad afternoon.
Why the ban does not work
The instinct is to prohibit it and move on. It is the wrong move for a reason worth understanding.
A ban removes the sanctioned option while leaving the incentive completely intact. The work is still hard, the deadline is still real and the tool still helps. What changes is that it moves to a personal account on a personal device, where you have no visibility, no retention control, no logging and no chance of finding out.
You have not reduced the exposure. You have converted a manageable one into an invisible one.
What to do instead, in about a fortnight
Ask, without consequences attached. A short anonymous survey, or a straight conversation in a team meeting where you say plainly that nobody is in trouble. The answers will be more extensive than you expect. That is the point.
Look at what the tenancy already knows. If you are on Microsoft 365, sign-in logs and app consent grants will show you a good deal about what has been connected to work accounts.
Approve two tools quickly. Whatever your people are already using, if there is a business tier of it. Speed matters more than getting the choice perfect, because the gap between the ban and the alternative is where the risk lives.
Write the one-page policy. Three lists, six answers, a named person to ask.
Say the amnesty out loud. Whatever anybody has already put into a chatbot, tell us this week, nothing happens. This single sentence surfaces more real exposure than any amount of monitoring.
The reframe
The question was never whether to allow AI in your business. That was decided for you, by your own staff, doing their jobs.
The question is whether you find out what is going on before somebody outside the business does.