The AI Strategy No One Sees:
What quiet AI experiments reveal before formal strategy catches up
January, 2026
Many organisations may already have the beginnings of an AI strategy. It may simply be taking shape somewhere leadership has not looked yet.
It is sitting in browser tabs, AI note-takers, unofficial prompt libraries, pasted documents, personal subscriptions and small workarounds people are using to get through the day.
In one team, someone uses ChatGPT to summarise a policy because the internal search is hopeless. In another, an AI note-taker appears because meeting actions keep disappearing. A useful prompt library starts circulating in Teams before the official training arrives. A personal tool sits open beside the approved one because, awkwardly, it gives the better answer.
That does not mean the organisation is full of reckless rule-breakers. Usually, it means people are trying to solve the work in front of them.
Quiet AI use is not always the problem. Sometimes it is evidence of where the problem sits.
The strategy may already be forming
The capability here is not one platform.
It is the easy availability of copilots, public generative AI tools, meeting assistants, research tools, prompt templates and lightweight automations that people can use before formal strategy catches up.
That changes the starting point for leaders.
AI strategy no longer begins when the board approves a roadmap, IT selects a platform or the steering committee signs off an acceptable-use policy. By then, the organisation may already have developed a shadow operating model around the work.
These workarounds are rarely random. They tend to appear where the organisation is slow, unclear or poorly supported.
Weak knowledge access creates unofficial summarising. Too many meetings create silent note-takers. Slow review pathways encourage AI-assisted drafts. Confusing policy creates personal judgement calls. Limited training produces prompt libraries built by whoever happened to work it out first.
Some of this activity will be valuable. Some will be risky. None of it should remain invisible to leadership.
Start with the risk, but do not stop there
Leadership often encounters quiet AI use through the risk lens.
That is reasonable.
Customer data entered into a public tool is not a charming innovation story. A meeting bot recording a sensitive conversation without consent is not evidence of cultural progress. An unofficial prompt library containing unreviewed legal, HR or customer language can scale poor judgement very efficiently.
But if leaders stop at enforcement, they miss a more useful question:
What problem was the workaround trying to solve?
If people are pasting documents into public AI tools, the internal knowledge environment may not be doing its job. If employees are using personal subscriptions beside approved enterprise tools, the approved tool may not support the work particularly well. If teams are building their own prompt libraries, capability may be forming faster than the organisation can recognise and support it.
The issue is not simply that people are using tools without permission. It may also be that the organisation is learning about AI faster than its formal processes are.
Much of that learning is happening in places leaders do not routinely see.
Quiet adoption reveals the operating model
Informal AI use can be a useful mirror, though not always a flattering one.
It shows where systems are difficult to use, where work moves too slowly, where policy is unclear and where the official process is technically correct but practically avoided.
It also shows where the approved tool exists, but the real work has moved somewhere else.
The right first response is neither panic nor applause. It is curiosity with clear boundaries.
The useful question is not only:
Who is breaking the rules?
It is:
What are people trying to get done that the current operating model is not helping them do safely?
That does not weaken governance. It gives governance something real to work with.
A useful AI policy should help people understand which tools are approved, what information can go where, when human judgement must remain involved and who to ask when the work falls into a grey area.
In practical terms, governance needs to spend less time defaulting to no and more time setting clear conditions for yes.
That still requires control, but it gives people a clearer way to use AI responsibly.
Map the behaviour before writing another policy
Before tightening AI governance or adding another framework, leaders should understand what people are already doing.
Not as a witch-hunt. Good luck getting honest answers that way.
Treat it as an operating scan.
Choose a small number of teams and ask straightforward questions:
Which AI tools are you using?
What work are you using them for?
What information are you entering?
What problem is the workaround solving?
What remains unclear?
What would you be reluctant to disclose because you are unsure how leadership would respond?
That final question may tell you more than the policy document.
Then sort what you find into four practical categories.
Stop now
The activity creates unacceptable data, privacy, legal or control exposure.
Govern better
The behaviour is useful, but it needs clearer rules, approved tools, stronger data boundaries or better oversight.
Legitimise
The workaround is solving a real organisational problem and should no longer be treated as unofficial.
Scale carefully
The experiment is useful, understandable and narrow enough to govern with confidence.
The point is not to endorse every quiet experiment. Some should stop immediately.
It is to recognise that the formal AI strategy may not be the only strategy operating inside the organisation.
A small, regular review can help. Bring together technology, risk and a business owner close to the work. Review actual examples rather than abstract scenarios.
Thirty minutes is probably enough.
The leadership decision
The real AI strategy may already be forming through the workarounds.
Leaders can wait until those behaviours appear as an incident, an audit finding or an awkward discovery during procurement. Or they can treat them earlier as signals of weak tools, unclear rules, accumulating risk or useful capability beginning to emerge.
The aim is not to reward unauthorised behaviour.
It is to govern from reality rather than from the assumption that policy has already shaped the work.
Quiet AI experiments can become liabilities. They can also reveal where better tools, clearer rules, stronger knowledge access and more practical training are needed.
It is worth understanding the difference before useful learning disappears underground or walks out the door.
Executive note for leaders
Before tightening AI governance, ask:
What are people already using AI for, and what is that behaviour trying to tell us?
Quiet experiments can reveal risk. They can also reveal poor knowledge access, slow systems, unclear policy, weak training and useful capability forming before the organisation has named it.
Map the actual use first.
Then decide what to stop, govern, legitimise or scale.
The aim is not permission without control.
It is governance that starts from reality.
Subscribe
You can subscribe for free. Every edition is delivered directly to your inbox and published here on Substack.
If a piece raises a question, surfaces a pattern, or helps you think more clearly about a decision, I’d value the conversation.
Thanks for reading,
Stuart Gonsal MAICD
With occasional help from Springsteen, my Border Collie, who reminds me that clarity comes from movement 🐾.
Connect
LinkedIn – Follow for practical leadership on AI-era opportunity. ↗
Disclaimer
Everything shared in The Ripple Effect reflects my personal views and does not reflect those of my current or past employers, clients or partners. Any examples are illustrative, drawn from publicly known patterns or anonymised experience.


