Overcoming the practical barriers to safe and productive AI adoption
For many organisations, the first barrier to adopting AI is not access to the technology. Tools such as ChatGPT, Microsoft Copilot and Claude are readily available, and employees can already see how they could help with research, summarisation, drafting, analysis and routine administration.
The barrier is confidence.
Employees want to know, do I have permission to use AI at work? Leaders need to know, how can we enable its use while retaining control and keeping our data safe?
These are two sides of the same problem. Employees do not want to breach organisational policy or expose sensitive information. Leaders cannot approve the use of external tools without understanding what data will be shared, where it will go, how it will be retained and what protections apply.
Yet many organisations have not answered either question clearly. Employees receive general warnings about the risks of AI but little practical guidance about what they are allowed to do. Leaders recognise its potential but remain concerned about security, compliance and loss of control.
The result is uncertainty on both sides. Employees are uncertain whether they can use AI, while leaders are uncertain whether they can allow it.
Resolve both questions and the organisation has the foundation it needs to take the first step. Leaders can maintain appropriate oversight, while employees can begin using AI within clear and understood boundaries.
AI adoption does not wait for organisational policy
Preventing access to AI tools does not necessarily prevent their use.
If employees can see that AI could help them complete work more quickly, some will find ways to use it. They may open personal accounts, use free versions of commercial tools or transfer information to devices and systems outside the organisation’s control.
This creates shadow AI – the use of AI tools without formal approval, visibility or oversight.
The organisation may not know:
- Which tools are being used
- What information employees are entering
- Where that information is processed or retained
- Whether prompts or outputs are used to train external models
- What decisions are being influenced by AI-generated content
- Whether outputs are being checked before they are used
An outright ban can therefore create a false sense of security. Leaders may believe they have removed the risk when, in practice, they have merely removed their visibility of it.
The alternative is not to allow unrestricted use. It is to create a controlled route through which employees can experiment safely.
The aim should be to replace uncertainty with clear permission, supported by proportionate controls.
The first rung of the AI ladder
AI adoption is often discussed as if every organisation should be developing bespoke agents or training its own models.
That is not where most organisations need to begin.
The first level of Catapult’s AI capability pyramid is the use of general-purpose productivity assistants by individual employees and teams. These tools can support tasks such as:
- Drafting and refining documents
- Summarising information
- Conducting initial research
- Producing meeting notes and actions
- Assisting with software development
- Generating ideas or exploring possible approaches
- Reformatting and organising existing material
Enterprise AI assistants are now available from major providers at a relatively low entry cost, making controlled experimentation possible without a substantial initial technology investment. Organisations can begin learning without committing to a major AI programme or changing core systems.
However, easy access does not mean there are no prerequisites.
Even at this first level, the organisation must decide which tools are acceptable, which version or account tier is required, and what information employees can use with them.
The technology is simple to access. Establishing the conditions for using it responsibly is the more important task.
Start with the data, not the tool
Before approving an AI assistant, an organisation needs to understand its own information.
That means knowing:
- What data it holds
- Where that data is located
- Who owns it
- How it is classified
- Who is permitted to access it
- Whether contractual or statutory restrictions apply to its use
- Whether it can be shared with an external technology provider
This should not require an entirely separate system of AI governance.
The basic principle is the same as it would be for any other technology – information should only be shared with a system when its classification, intended use and protections make that appropriate.
Regulated and certified organisations may already have an advantage. Existing requirements around data classification, access, security and auditability provide much of the foundation needed to make decisions about AI use. They should already have a basis for determining whether information is public, internal, sensitive, personal or classified, and what restrictions apply to each category. The challenge is to apply those established controls to a new category of tool.
Where those foundations are weak, AI exposes the problem. Employees cannot be given useful guidance if the organisation itself cannot say which information is safe to use.
This is one reason AI readiness cannot be separated from data readiness. AI adoption depends on data that can be found, understood, trusted and governed appropriately.
For public-sector organisations, these considerations sit alongside existing security classifications, data protection obligations and information-sharing arrangements. The AI Playbook for the UK Government reinforces the need for lawful, ethical and secure adoption, while the Information Commissioner’s Office guidance explains how existing data protection principles apply when AI systems process personal information.
The obligation to understand and control the data does not disappear because an AI tool is easy to purchase.
Assess the provider, not just the product
Once an organisation understands the information it wants employees to use, it can assess potential AI providers.
The visible features of competing assistants may appear similar, but their underlying contractual and technical arrangements can differ significantly. Protections available through an enterprise agreement may not apply to a free or consumer account.
A supplier assessment should consider questions including:
- Where will organisational data be processed and stored?
- How long are prompts, files and outputs retained?
- Will the provider use organisational data to train or improve its models?
- What identity and access controls are available?
- Can usage be monitored through appropriate audit logs?
- What contractual protections and liabilities apply?
- Which other systems can the tool access?
- What permissions will integrations require?
- Can organisational data be removed or transferred if the service changes?
- What happens if the organisation needs to move to another provider?
There may also be external restrictions to consider. An organisation cannot assume it has permission to enter information belonging to a delivery partner, supplier, citizen or another public body into an AI service. Existing data-sharing agreements may need to be reviewed or amended.
This work should be proportionate to the proposed use. An assistant being trialled with public or low-sensitivity information does not require the same level of control as an agent connected to operational systems.
The level of scrutiny should increase as the depth and consequences of AI use increase.
Give employees an answer they can use
Completing the governance and supplier work is only half the task.
The outcome must be translated into practical guidance for employees. A long policy stored somewhere on the intranet is unlikely to change behaviour if people cannot find it or understand how it applies to the task in front of them.
Employees need five things.
1. An acceptable-use policy they can find
The policy should explain the purpose and boundaries of AI use in direct language. It should cover checking outputs, protecting information, respecting intellectual property and maintaining human responsibility for the work produced.
It should not assume that every employee understands how an AI model works.
2. A named list of approved tools
Employees should know which tools and account types they may use.
That list should also state which tools are not approved. ‘Use AI responsibly’ is not meaningful guidance if employees are left to decide for themselves whether a free personal account is acceptable.
3. A traffic-light guide to data
A simple classification can turn a broad policy into an everyday decision tool:
- Green. Information that can be entered into an approved AI tool.
- Amber. Information requiring additional checks or approval.
- Red. Information that must not be entered.
The categories should be based on the organisation’s existing data classifications and the protections provided by the approved tool.
4. Somewhere to ask questions
There should be a named person, team or channel employees can approach when they are unsure.
There should also be a clear process for requesting an exception or proposing a new use. Otherwise, unusual but potentially valuable applications will either be abandoned or pursued outside the formal process.
5. Explicit permission to experiment
Leaders need to state whether controlled experimentation is permitted.
Without that message, employees may continue to interpret governance as a warning not to use AI at all. The organisation will have completed the work required to manage the risk but may see little adoption or benefit.
Permission should come with clear boundaries – use the approved tools, follow the data guidance, check the outputs and remain accountable for the result.
Measure learning as well as usage
The initial objective should not be to maximise the number of prompts submitted or licences activated.
It should be to understand where AI creates genuine value without introducing unacceptable risk.
A controlled first phase can examine:
- Which tasks employees use AI to support
- How much time it saves
- Whether the quality of work improves
- Where outputs require significant correction
- Which use cases employees repeatedly request
- Where policy or technical controls create unnecessary friction
- Whether any security, accuracy or compliance incidents occur
This evidence helps the organisation improve its guidance and decide where to invest next.
It also prevents productivity assistants from being mistaken for an AI strategy. Saving time on drafting and summarisation can be worthwhile, but it does not necessarily change how services operate or how outcomes are delivered.
It is the first rung of the ladder, not the destination.
Moving up the AI capability pyramid
As organisational confidence and capability increase, AI can move progressively deeper into processes, services and technology.
Source: Catapult CX
The dependency on data, integration, orchestration and governance increases at each level. So do the cost, operational responsibility and potential consequences of failure.
Organisations do not need to reach the top of the pyramid to demonstrate maturity. Building a bespoke model when an established service would meet the need can create significant cost without corresponding value.
The right question is not; how advanced can our AI become?
It is; what level of AI capability is justified by the outcome we need, and are our data, technology and governance ready to support it?
An organisation can also become stuck at any level. Leaders may treat employee productivity gains as the full strategy. Departments may purchase overlapping process tools that fragment working practices. Operational teams may become heavily dependent on an external supplier without an exit plan. Bespoke agents may be developed before the organisation is ready to operate and govern them.
Progress requires deliberate decisions, not simply the accumulation of more tools.
Govern enough to begin
Organisations do not need to resolve every future AI question before employees can start learning.
They do need enough visibility and control though, to make the first step safe:
- Understand and classify the information
- Decide what can be used
- Assess and approve appropriate providers
- Publish clear rules
- Give employees somewhere to ask questions
- Permit controlled experimentation
- Measure what happens
- Strengthen the controls as adoption develops
This gives leaders confidence that organisational data is being protected and gives employees confidence that responsible AI use is permitted.
It also brings experimentation into the open, where the organisation can learn from it, govern it and identify the use cases that may justify moving further up the AI capability pyramid.
Getting started with AI is not simply a licensing decision. It is a readiness decision.
The organisations that make progress will not be those that remove every possible risk before beginning. They will be those that understand the risks, establish proportionate controls and give their people a safe route to start.
Understand where to begin
If you are unsure where AI could create meaningful value, Catapult CX’s AI Diagnostic assesses your existing systems, data and workflows to identify practical AI opportunities and establish clear priorities for moving forward.
Our approach helps you understand your current readiness, identify what is holding adoption back and focus investment on the opportunities that can deliver real value without introducing unnecessary risk.
