Your Team Is Already Using AI. The Only Question Is Whether You Can See It.
• 7 min read
Part 1 of 2: What owners and managers need to decide before buying a single seat.
Most small and mid-sized companies are approaching AI subscriptions backwards. They start with “which vendor” and end up with a mess of personal ChatGPT logins, an untracked Copilot pilot, and no idea what customer data has left the building.
The buying decision is the last decision, not the first. Here are the four that come before it.
First, accept the baseline: this is a visibility purchase
The research is consistent and uncomfortable. BlackFog’s 2026 workforce data found 86% of employees use AI tools for weekly work tasks — and 58% of them prefer unapproved public apps over whatever their company sanctioned. More telling is the attitude behind it: 65% believe using unvetted tools is acceptable, and 60% consider it worth the risk if it helps them hit their targets.
Verizon’s 2026 Data Breach Investigations Report put numbers on the consequence. Shadow AI detections rose fourfold in a single year, making it the third most common non-malicious insider action found in breach investigations.
The practical conclusion, and the one most governance advisors have landed on: a ban without a sanctioned alternative doesn’t reduce usage. It reduces visibility. People keep using the tools at roughly the same rate; you just stop being able to see it.
So the real comparison isn’t “spend on AI vs. don’t spend on AI.” It’s “$20–30 per person per month for a controlled data path vs. an uncontrolled one you’re already exposed to.” That reframe changes who needs to approve the budget and how you justify it.
Decision 1: Company-wide vs department-first
Both defensible. The tradeoff in productivity, cost, roll-out and morale requires serious consideration.
Department-first is the better default for constrained teams. Pick the function with the clearest, most repetitive bottleneck — sales follow-up, customer response, finance reconciliation, marketing production — and run a scoped 60–90 day deployment there. You get a measurable before/after, a small enough group to train properly, and an internal case study before you commit a budget across the org.
The cost of this approach is speed and optics. You leave productivity on the table in other functions, and you create a two-tier situation where the sales team has tools and operations don’t. Manage that by announcing it as a sequenced rollout with dates, not as a privilege.
Company-wide makes sense when your primary driver is risk containment rather than productivity. If you already know people are pasting client data into personal accounts, a narrow pilot doesn’t solve your actual problem. It only covers one department’s exposure.
A middle path most mid-market companies land on: broad low-cost access for everyone as the sanctioned default, plus a small number of premium seats for identified power users. It caps risk immediately and concentrates spend where usage is real.
One caution on the phased approach: a well-documented SMB failure mode is what advisors call “surface-level AI” — a scattered collection of subscriptions and feature checkboxes with no end-to-end workflow behind any of them. Sequencing works only if each phase is tied to a specific workflow you intend to change.
Decision 2: Individual accounts vs company accounts
This one isn’t close. Company-administered accounts, on business or team tiers, under a company domain. Personal accounts expensed back are the single most common structural mistake.
What you lose with personal accounts:
- Data terms. Consumer tiers and business tiers carry different default training, retention, and processing terms. You cannot negotiate what you didn’t contract for.
- Offboarding. When someone leaves, their work history, prompts, and any uploaded company documents leave with them, in an account you don’t control and can’t revoke.
- Audit and admin. No usage visibility, no seat management, no ability to answer an enterprise customer’s security questionnaire honestly.
- Enterprise sales. If you sell to larger companies, their vendor security review will ask how your staff handle AI. “Everyone expenses their own subscription” is a losing answer.
Practical license hygiene to set up on day one, while the deployment is small enough to do it cheaply:
- SSO and domain-managed identity wherever the tier supports it. Provisioning and deprovisioning should follow the same path as email.
- A named license owner — one person accountable for the seat list, not a shared finance inbox.
- A documented request path so someone who needs a tool has somewhere to go other than their own credit card.
- A quarterly seat review with a defined inactivity threshold. Ninety days is the common default.
- A revocation playbook — the ability to cut access to a tool or an integration quickly, and a known answer to who does it. ISACA’s 2026 data found 56% of professionals don’t know how long it would take to halt an AI system during a security incident. That’s a five-line document, and it’s the cheapest credibility item you can produce.
Decision 3: The company proprietary data line
This is where most policies fail, because they’re written in the abstract. “Use good judgment with confidential information” is not a rule. Research on enterprise AI incidents makes the point directly: without explicit classification, judgment varies wildly across the company — marketing treats customer demographics as non-sensitive; legal sees regulated personal data.
Write the list instead. A workable policy names, explicitly:
Never enters any AI tool: government ID numbers, dates of birth, bank and payment details, health information, employee records, customer payment data, credentials and API keys, and anything covered by a customer NDA or DPA.
Approved tools only, and never public/free tiers: customer names and contact data, pricing and contract terms, unreleased product information, financials, internal strategy documents.
Fine anywhere: public marketing copy, general research, published information, anything you’d be comfortable seeing on a competitor’s screen.
Then add the three controls that carry most of the weight:
- Tool tiers, not a single approved tool. Tier 1 sanctioned and contracted; Tier 2 permitted for non-sensitive work; Tier 3 prohibited. A binary list gets ignored the moment someone needs something not on it.
- Human review on anything that leaves the building. Customer-facing, financial, legal, or HR output gets a named reviewer. No exceptions, and no “the AI wrote it” as a defense.
- Agent and integration controls. This is the fastest-growing gap and the least covered by existing policies. Employees are wiring AI features in automation platforms into workflows that process business data and send external communications, often with persistent OAuth access to CRM, email, and calendar. Those connections need to be approved and inventoried the same way you’d approve a new vendor — because functionally, that’s what they are.
Decision 4: Who owns this, and what does it look like in practice?
The deliverable is four short documents, not one long one:
- The policy itself
- A tiered approved-tool list, with the request path
- A one-page employee acknowledgment they sign
- A manager FAQ, because your managers will be asked first
This takes about a week. Do it before you buy seats — partly because it’s the right sequence, and partly because you will need it anyway the first time a serious customer sends you a vendor security questionnaire.
The governance gap here is genuinely wide, and that’s the opportunity. Only around 22% of UK businesses have provided AI-specific governance training to staff involved in AI deployment, and a 2026 Founder Reports survey found 59% of workers at companies under ten employees say their employer has no clear AI policy. Being in the minority that has one is a low-cost differentiator in enterprise sales.
Part 2 covers the money: which vendor and which plan mix, what the seats actually cost once you account for utilization decay, how to monitor usage without building a surveillance program, and the lightweight KPIs that hold up in front of a board or an investor.
A note on the data above: much of the published survey research on AI adoption comes from vendor-adjacent sources with an interest in the adoption story. Treat the directional trends as reliable and the specific percentages as soft.