Your organisation has an AI policy. But does anyone actually know how AI is being used?
AI adoption may already be happening underneath your formal governance arrangements.
More organisations are developing AI policies. That is sensible.
The policy covers approved tools, data protection, confidentiality, accuracy, human oversight, copyright, information security and accountability. The Board approves it. Employees receive it. It is uploaded to the policy library.
AI governance: done.
Except perhaps it is not.
While the organisation has been deciding what its AI policy should say, people may already have been using AI to draft reports, summarise meetings, analyse spreadsheets, prepare Board papers, examine customer feedback, write complaints responses or simply work through a difficult problem.
Some of that may be entirely appropriate. Some may be genuinely useful. Some may not be. The problem is that the organisation may not know which is which.
AI adoption does not necessarily look like a technology project
Think about how organisations traditionally introduce technology: a business case, procurement, a project, a data protection assessment, implementation, training, testing and go-live.
AI can enter an organisation very differently. One person discovers that a tool can summarise meeting notes. Someone else uses it to improve a report. A manager asks it to help draft a policy. A trustee uses it to understand a complicated Board paper.
Nobody formally decided, ‘Our organisation will now adopt artificial intelligence.’ Yet gradually, it has.
The Charity Commission’s guidance recognises this. It advises charities to consider how employees and volunteers may already be using AI and whether an internal policy would help establish how and when it should be used in governance, employment and service delivery.
That distinction matters. AI use may be developing from the bottom up before governance catches up from the top down.
Evidence from the profession responsible for digital trust suggests this is already happening. In its 2025 European research, ISACA found that 83% of IT and business professionals believed employees in their organisations were using AI, while only 31% said their organisation had a comprehensive AI policy.
Those figures do not prove that every organisation has uncontrolled AI use. They do make ‘we do not think people are really using it’ a weak basis for assurance.
Start with a better question than ‘Do we use AI?’
If I asked management whether the organisation uses AI, the answer might genuinely be: ‘Not officially.’
I would ask instead:
Where is AI currently influencing work, information or decisions anywhere in the organisation?
AI use is no longer limited to somebody opening a standalone chatbot. AI features are increasingly built into ordinary workplace products, which makes informal use harder to see. An annual declaration asking employees whether they ‘use artificial intelligence’ may therefore tell you very little unless it also asks what tools and functions they use and for what purpose.
The pattern is also visible in the charity sector. The 2026 Charity Digital Skills Report found that 79% of charities were using AI in some form, but only 38% described their use as active and strategic. It also identified skills and trust as significant barriers.
That gap between use and strategy is important. It is entirely possible for AI to be common in day-to-day work while remaining poorly understood at organisational level.
The governance issue is what AI is being used for
Boards do not need to know every time somebody asks an approved tool for five alternative headings. That would create another bureaucracy around technology intended to reduce bureaucracy.
But the same governance response cannot sensibly apply to all uses. There is a material difference between AI that drafts wording and AI that interprets information or influences a decision.
Lower significance: generating ideas, improving wording, formatting content or summarising public information.
More significant: analysing organisational data, summarising meetings, drafting customer communications, examining complaints, preparing Board papers or drafting policies.
Potentially high significance: processing personal or sensitive information, supporting recruitment, assessing customer risk, informing safeguarding judgements or recommending interventions.
The technology may be similar. The consequences are not. The question is not simply whether people are using AI; it is what they are using it for, what information they provide and what the output influences.
Your organisation may already have ‘shadow AI’
We have long understood shadow IT: employees use software outside approved arrangements because it solves a problem. AI creates the same possibility, but at much greater speed.
An employee has a task that takes three hours. They discover that an AI tool helps them complete it in 45 minutes. From their perspective, they have found a productivity solution. From the organisation’s perspective, immediate questions arise:
· What information did they give it?
· Which system did they use, and was it approved?
· Where is the information processed and retained?
· Was personal, confidential or sensitive information involved?
· Was the output checked by somebody able to identify an error?
· Did the output influence anything consequential?
The employee may have no reason to think they have done anything particularly significant. That is why policy alone is insufficient. Organisations need understanding, safe tools and practical training as well as rules.
Do not assume people recognise when information becomes sensitive
Consider a promising use case: asking AI to analyse 100 complaints and identify recurring issues, service failures or emerging themes.
Now consider what those complaints may contain: names, addresses, health information, financial circumstances, information about employees, safeguarding concerns or details about vulnerable people.
The question is no longer merely, ‘Can AI analyse complaints?’ It becomes, ‘Which system is doing the analysis, what information are we giving it, what is our lawful basis, and what controls apply?’
The ICO’s AI and data protection guidance applies across the public, private and third sectors and includes practical resources for assessing risks to people’s rights and freedoms. The UK Government’s AI Playbook also stresses lawful, secure and proportionate use, meaningful human control and clear accountability.
AI may already be influencing Board information
This is where Boards should become particularly interested.
A Chief Executive asking AI to help structure a report is probably unremarkable. But if management uses it to summarise 500 customer comments, identify principal risks, analyse performance, draft an options appraisal or produce the first version of a recommendation, AI is no longer simply helping somebody write. It is helping to interpret organisational information.
The executive may still review and own the final paper. I would still want to know where the human analysis ended and the AI analysis began. A beautifully written Board paper may contain conclusions generated through a process the Board cannot see.
That does not automatically make the conclusions unreliable. It makes provenance, transparency and human judgement more important.
This is already a live issue in social housing. The National Housing Federation’s housing-association case studies describe AI being explored and applied to improve efficiency, productivity and resident experience. The sector is not waiting for a single formal moment called ‘AI adoption’. Different uses are developing in different parts of organisations, at different speeds and with different levels of maturity.
The same applies to customer voice
AI could help organisations interrogate thousands of complaints, surveys, emails, case notes, open-text comments and resident meeting notes that historically sat unread in spreadsheets. For somebody working in customer experience, that is genuinely exciting. It could help organisations hear voices that disappear inside volumes of unstructured information.
But I would still ask:
· Who decided what the themes mean?
· Could minority experiences have been lost within dominant patterns?
· Was the source information appropriate to use?
· Was the analysis tested against the original evidence?
· What decisions were made because of it?
AI can dramatically increase our ability to analyse customer voice. It does not automatically mean we understand customers better.
‘Human checked’ is not always the reassurance we think it is
Most policies sensibly require human oversight. But what does that mean in practice?
An employee asks AI what the law requires. The tool produces a confident, detailed answer. The employee reads it and thinks it looks sensible. Human oversight complete.
Except the employee may not have enough expertise to recognise that the answer is wrong.
The Charity Commission warns that generative AI can produce inaccurate, biased, plagiarised or copyright-infringing results, and says trustees remain responsible for decisions.
The weakness of human review is also supported by wider research. A University of Melbourne and KPMG study involving more than 48,000 people across 47 countries found that 66% relied on AI outputs without evaluating their accuracy, while 56% reported making mistakes in their work because of AI.
I would therefore distinguish between a human seeing an output and a competent human being capable of challenging it. Those are not the same control.
Do not start with enforcement. Start with discovery.
If I were a Board trying to understand organisational AI use, I would not begin by asking who has breached the policy. That is likely to make people less willing to describe what they are doing.
I would ask employees, ideally through a short and psychologically safe exercise:
· Which AI-enabled tools are you using for work, including features built into existing systems?
· What tasks do they help you complete?
· What information do you put into them?
· Where do they save time or improve quality?
· Where are you unsure whether use is permitted?
· What would you like the organisation to provide safely?
You may discover brilliant innovation. You may discover worrying practice. You will probably discover both. That is useful information, not a reason to punish honesty.
Map the uses that matter
Boards will need a proportionate view of the organisation’s AI footprint, not a register of every prompt. For material uses, record:
· Where: which function or service?
· Purpose: what is AI being used to do?
· Data: what information is involved?
· Influence: does it draft, analyse, recommend or decide?
· Human control: who reviews the output, and are they competent to challenge it?
· System: is the tool approved?
· Risk: what could reasonably go wrong, and who could be affected?
· Value: what benefit is being achieved?
That final point matters. Governance should not become entirely about stopping things. If a use saves hundreds of hours, improves accessibility or helps an organisation understand customer experience more effectively, the Board should know that too.
Seven questions I would want the Board to ask
1. Where is AI actually being used, including informal use and AI features inside existing products?
2. What organisational information is being entered into it?
3. Where is AI analysing or interpreting, rather than simply drafting?
4. Which decisions or recommendations is it influencing?
5. Who checks the outputs, and can they genuinely identify errors or bias?
6. What measurable benefit are we receiving in time, quality, capacity, outcomes or cost?
7. Where are people turning to AI because our existing systems or processes make their jobs unnecessarily difficult?
That last question could reveal more than an AI audit. If employees use AI to summarise 40-page reports, perhaps the reports are too long. If they use it to rewrite policies into understandable English, perhaps the policies are not understandable. If managers use it to analyse spreadsheets because useful performance information is missing, perhaps the organisation has a wider data problem.
Do not only ask, ‘How do we control this?’ Ask, ‘Why did somebody need it?’
Policy should follow understanding, not substitute for it
There is an understandable temptation: AI is moving quickly, risk feels uncertain, so write a policy. That is not wrong. But the policy should sit within a wider cycle:
DISCOVER → UNDERSTAND → ASSESS → ENABLE → CONTROL → TRAIN → MONITOR → LEARN
Then update the policy when reality changes. Not: write policy, assume compliance.
The UK Government AI Playbook provides a useful evidence base for this approach. Its principles include understanding AI’s limitations, lawful and secure use, meaningful human control, accountability, risk-based governance and deciding whether AI is the right tool at all.
The Board question I would ask now
At your next Board meeting, do not start by reviewing the AI policy. Ask the Chief Executive:
Where is AI currently influencing how this organisation works, what it knows or the decisions it makes?
Then ask: ‘How do we know?’
AI adoption does not require a project plan, capital investment or even a conscious decision to adopt an ‘AI product’. It can happen one employee, one task and one prompt at a time.
That does not make AI something Boards should fear. There may be considerable value already being created by people who have found better ways of working. But Boards cannot govern the risks, capture the productivity, spread good practice or make informed investment decisions if nobody understands what is already happening.
So yes, write the AI policy. But do not mistake the existence of the document for understanding the organisation.
Your first AI governance exercise may be much simpler: ask people what they are already doing, then listen carefully to the answers.
Sources and further reading
Charity Digital Skills Report 2026. https://charitydigitalskills.co.uk/report/detailed-findings/artificial-intelligence
AI Use is Outpacing Policy and Governance, ISACA Finds. 2025. https://www.isaca.org/about-us/newsroom/press-releases/2025/ai-use-is-outpacing-policy-and-governance-isaca-finds
Cutting Through the AI Hype: The 2026 AI Pulse Poll. https://www.isaca.org/resources/ai-pulse-poll
Trust, attitudes and use of artificial intelligence: A global study 2025. https://mbs.edu/faculty-and-research/trust-and-ai
Rise in ‘Shadow AI’ tools raising security concerns for UK organisations. https://ukstories.microsoft.com/features/rise-in-shadow-ai-tools-raising-security-concerns-for-uk
Charities and Artificial Intelligence. https://charitycommission.blog.gov.uk/2024/04/02/charities-and-artificial-intelligence
An evolving charity sector. https://charitycommission.blog.gov.uk/2025/08/26/an-evolving-charity-sector
Artificial intelligence. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence
Artificial Intelligence Playbook for the UK Government. https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html
Guidelines for secure AI system development. https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development

