Enterprise AI is moving from controlled technology deployment to distributed organisational behaviour. That changes what leaders need to govern.
For several years, enterprise AI programmes have concentrated on encouraging adoption.
Give employees access. Run training. Launch pilots. Identify use cases. Build confidence.
That problem is rapidly changing.
New UK workforce evidence suggests that employees are no longer waiting for organisations to decide whether AI belongs in their work. Many have already made that decision themselves.
Deloitte UK’s new survey of 25,000 workers found that 63% knowingly use generative AI for work. Nearly a third of those users — 31% — are doing so without their employer’s knowledge. One in six users is paying personally for at least one AI tool used for work, contributing to an estimated £958 million of employee-funded AI expenditure each year.
That should change the executive conversation.
The emerging challenge is no longer simply AI adoption.
It is whether the organisation can turn distributed, employee-led adoption into a governed operating capability that creates measurable enterprise value.
The business leakage is already visible
Shadow AI is frequently described as a cybersecurity problem.
It is one.
Employees using unsanctioned tools can create obvious risks around confidential information, intellectual property, data residency, retention and regulatory obligations.
But treating shadow AI purely as misconduct misses an important economic signal.
People generally do not spend their own money on workplace technology unless they believe it helps them accomplish something their existing environment does not.
Deloitte found that workers using GenAI report saving an average of 70 minutes per week. Most say that released time is being used to perform more work for the same employer. Yet roughly half of AI users report receiving no formal training, while 65% report insufficient leadership on how AI should be used.
That creates a peculiar enterprise condition.
The workforce is identifying value.
The employee is sometimes funding the technology.
The workflow is changing.
But the organisation may have little visibility into any of it.
That is not merely shadow IT.
It is shadow transformation.
And shadow transformation creates leakage because the organisation struggles to capture what employees are learning.
A useful prompt remains personal rather than institutional knowledge. A successful workflow improvement stays with one employee. Productivity gains are not necessarily reflected in process design or capacity planning. Controls vary by individual. Good practices are not standardised. Poor practices may remain invisible until something fails.
The organisation gets pockets of acceleration without necessarily acquiring the capability that produced them.
Formal governance does not solve this by itself
The obvious response is governance.
But another study published this week shows why policy alone is insufficient.
EY surveyed senior AI decision-makers at large US public companies and found that 98% report having formal AI governance policies.
That sounds reassuring.
Yet 47% acknowledge that their organisation has previously bypassed its AI governance process for an urgent deployment. Among organisations using agentic AI, almost half say their governance framework has not yet been updated specifically for agentic risks. More significantly, 36% report having experienced an AI incident or failure that produced materially negative organisational consequences.
The gap is not the absence of governance.
It is the distance between governance as documentation and governance as organisational behaviour.
A policy can say that sensitive information must not be exposed to an external model.
An operating model determines which systems an agent can access.
A policy can require human oversight.
A workflow determines where that human decision actually occurs, what evidence the reviewer receives and whether they have authority to stop the process.
A policy can establish accountability.
An operating model identifies the owner when an AI-enabled workflow crosses Technology, Operations, Risk, Legal and a business function.
This distinction becomes more important as organisations move from assistants that produce content to agents capable of taking actions.
NIST’s current work on agent identity and authority illustrates where the governance problem is heading. Its work explicitly considers identification, authorisation, auditing and non-repudiation for software agents — essentially asking how organisations establish what an agent is, what authority it possesses and what it has done.
These are operating-model questions expressed through technology.
The economic opportunity lies beyond personal productivity
There is another reason leaders should address this now.
Citi Institute’s latest research finds that nearly 60% of surveyed organisations remain in exploration or pilot, while only around 40% have reached production or scaling.
Among those reaching production or scale, however, 60% report transformational value creation exceeding 15% through combinations of productivity, cost efficiency and revenue improvement. Citi also finds that business-model transformation has overtaken operational efficiency as the leading objective for AI investment.
Those figures should be interpreted carefully. They are survey findings rather than audited ROI measurements.
But the direction is important.
The economic prize appears increasingly unlikely to come from simply giving more employees an AI assistant.
It comes from redesigning how work happens.
That means identifying where value is currently lost in a workflow; deciding which tasks should remain human, which should be AI-assisted and which can be delegated; defining decision rights; connecting appropriate organisational data; embedding controls; changing measures; and enabling the workforce to operate the redesigned process.
The tool is one component.
The transformation is the workflow.
This is where many AI programmes invert the sequence
A common enterprise sequence is:
buy the technology → distribute licences → encourage experimentation → establish policy → search for measurable value.
The more durable sequence runs in the opposite direction.
Start with the outcome.
Understand the workflow producing it.
Identify the friction, delay, cost, rework or lost opportunity.
Determine where AI genuinely changes the economics or quality of that workflow.
Define human and machine responsibilities.
Build governance into those responsibilities.
Then select and configure the technology required.
That approach has been central to TFx’s experience of enterprise AI transformation.
In an anonymised Fortune 500 environment, operating-model redesign, workflow integration, governance, enablement and measurement accompanied AI adoption across approximately 15,000 users. Adoption moved from 15% to 68%, alongside measured improvements including 38% operational efficiency, 73% lower resolution time and 63% lower compliance effort, with $10–12 million in annualised ROI.
Those outcomes did not come from access to a model alone.
They required the organisation around the technology to change.
The same principle matters even more as agents gain authority to execute work rather than simply advise people performing it.
The next phase is controlled decentralisation
Centralising every AI decision will not scale.
Allowing every employee and agent to operate independently will not scale safely.
The practical enterprise model sits between those extremes.
Organisations need enough central control to establish standards, permissions, assurance, observability and accountability, while giving functions enough autonomy to redesign the workflows they understand.
That requires an operating system for AI adoption: clear ownership, governed experimentation, role-based enablement, reusable patterns, measurable use cases, human accountability and a mechanism for converting local discoveries into organisational capability.
The organisations that build this layer will not necessarily be those with the most AI tools.
They will be those that become better at turning distributed intelligence into repeatable organisational performance.
Deloitte’s findings suggest employees are ready.
EY’s findings suggest governance has not caught up.
Citi’s findings suggest the economic value increases materially when organisations move beyond experimentation into production and scale.
The opportunity is therefore not to suppress the behaviour already occurring.
It is to capture it, govern it and convert it into capability.
The executive question
The executive question is no longer “How do we get our people to adopt AI?”
It is: if they already have, how much of that activity can your organisation actually see, govern, learn from and turn into measurable value?
Leave a Reply