Your staff are already using AI. Finding out is the easy part
In most SMEs, AI arrived through the staff rather than the owner. Banning it drives it onto personal phones. Here is a more useful approach.
A conversation I have had several times this year, with variations. The owner says they have not adopted AI yet and are still thinking about it. Then somebody mentions that the office manager has been using ChatGPT to write the customer emails since about February.
This is the normal state of affairs, not a failure of management. AI arrived through people's phones and personal accounts, the way spreadsheets and WhatsApp groups did before it. The useful question is not whether it is happening but what to do now that it is.
Why it happens this way round
Because it works and it is free. Someone with a tedious task tried the thing everyone is talking about, it saved them forty minutes, and they carried on. No approval process was ever going to be faster than that.
And they usually do not mention it. Partly because it feels like it might be cheating, partly because they suspect the answer would be no. That instinct is the actual problem: it means the business has AI in use and no visibility of it.
What the real risk is
Worth being precise here, because the risk is not what most people assume.
Personal accounts, not the tool itself. ChatGPT on a business tier with training switched off is a reasonable place to draft an email. The same conversation typed into a free personal account on someone's own phone is a different matter, and that is where most SME AI use currently happens. The data privacy post covers the distinction properly.
What goes in, not what comes out. Customer names, health information, employee grievances, draft accounts, tender pricing, a supplier contract. Pasted into a free consumer account, that is a data protection problem you do not know you have.
Nobody checking the output. Someone sending AI-drafted advice to a client without the knowledge to spot when it is wrong. In a regulated trade this is the one that ends badly.
Single points of failure. One person quietly running half their job through a personal AI account and a set of prompts nobody else has seen. When they leave, so does the method.
Finding out without an inquisition
The instinct is to audit. The problem with auditing is that it tells people this is a matter you get in trouble for, and they will simply stop telling you.
What works better is asking openly, with the amnesty stated up front. Something close to: nobody is in bother for this, I want to know what people are already using so we can pay for the proper version and stop anyone getting caught out.
Ask three things at a team meeting.
- Who has used an AI tool for anything work-related in the last month?
- What did you use it for, and did it actually help?
- Whose account was it on, yours or the business's?
The third question is the one that matters and the one people find easiest to answer honestly, because it is a practical question rather than a moral one.
What to do with the answers
Pay for the business tier for the people already using it. This is the single highest-value thing on the list. It moves the usage somewhere with data controls, an audit trail and training switched off, and it costs less than the coffee budget.
Write down what must not be pasted in. Not a policy document, a short list on one page. Customer personal data, anything health-related, anything about a named employee, anything commercially sensitive. The one-page policy template is built for exactly this and takes an afternoon.
Name who checks the output. For anything going to a customer or carrying professional advice, someone competent reads it before it leaves. This should be a named role, not a general hope.
Collect the prompts that work. The person who has quietly worked out how to draft your quotes well has done real work. Get it written down and shared, and thank them for it. This turns your biggest single point of failure into your best internal training material.
Why banning it does not work
A ban does not remove AI from your business. It moves it onto personal phones, out of sight, with no ability to tell anyone what the rules are. You end up with all of the risk and none of the visibility.
There are narrow cases where a genuine prohibition is right, usually where a client contract or a regulator requires it. Those are specific and you will know if you are in one. For everyone else, a ban is a way of feeling in control while being less in control.
The order to do it in
- Ask the three questions, with the amnesty stated first.
- Buy business-tier accounts for whoever is already using AI regularly.
- Write the one-page list of what must never be pasted in.
- Name who reviews customer-facing output.
- Get the good prompts written down where everyone can find them.
That is a fortnight of small jobs, and it takes a business from unmanaged AI use to managed AI use without anybody having to be told off. The risk register post is the next step if you want to record this properly.
If you would rather have someone run that conversation with your team, that is the kind of thing a discovery call can scope.