Who should own AI in your business?
The CEO or C-suite should own it. In aibl's survey of 755 UK mid-market leaders, companies with an executive...
Read more
A policy on the intranet that nobody enforces creates false confidence. In aibl’s survey of 755 UK mid-market leaders, HR teams with a defined-but-inconsistent policy report just 16% measurable ROI, against 33% with no policy at all. The document itself is the problem.
The comparison sounds wrong until you sit with it. In aibl’s survey of 755 UK mid-market leaders, HR functions applying a written AI policy inconsistently show just 16% measurable ROI. HR functions with no policy at all show 33%. The inconsistent policy scored lower than none.
That’s not a fluke in one function. In tech and IT, informal guidelines score 40% against 33% for a defined-but-inconsistent framework. The pattern holds at C-suite level too, where the bottom three governance rungs sit flat at 25%, 29% and 34% before the real jump happens.
The reality is that a policy nobody follows is worse than nothing. No policy at least keeps everyone alert. A policy that exists on paper closes the conversation down.
The cause is false confidence, not bad intentions. A framework on the intranet feels like the job is done, so the budget to enforce it, monitor it and chase down exceptions never gets approved. Most policies stop at the document and never reach the behaviour.
Meanwhile the actual behaviour drifts. Different team leads describe the AI governance process three different ways. Nobody’s lying. Nobody’s checking either.
Frankly, this is the finding leaders push back on hardest. It feels counterintuitive that having something written down could cost you more than having nothing. But a document without enforcement removes the pressure to build the real thing, and the real thing is what pays.
A working policy has three features a poster on the wall doesn’t. Someone owns it by name, not by job title. The approved route is faster than the workaround, so people actually use it. And an enforced version doubles the return compared with one that merely exists on paper.
That last point matters most. Across the governance ladder, the largest single jump in measurable ROI comes from moving a policy out of “defined but inconsistent” and into “enforced”. Half the market never makes that move. They stop at “we wrote one down” and call it finished.
If you want the full climb from no governance to mature and embedded governance, and the 63-point gap between the two ends, read our piece on AI governance ROI. This finding sits inside that same ladder. It just isolates the one step where a document alone actively hurts you.
Ask three team leads how AI gets approved in your business. If you get three different answers, you’re in the trap: a policy exists, but nobody’s following the same one. The document will always read fine on the intranet. Three different answers is the finding.
That test is more honest than reading the policy document itself. The document will always look fine. The behaviour is what tells you the truth.
If the answers line up and someone can point to who enforces exceptions, you’ve likely cleared the trap. If they don’t line up, the fix isn’t a better-written policy. It’s enforcement, ownership, and a faster approved path, which our AI governance framework piece sets out step by step.
Don’t start by rewriting the policy, because the document was never the real problem. Start by asking those three questions and writing down what you actually hear. The honest answer tells you whether you have a working policy or just a poster on the intranet.
Then name one owner for AI approvals, someone whose job includes chasing exceptions, not just filing the document. Make the approved route quicker to use than asking a colleague to run something through an unapproved tool.
That’s the whole fix. It costs far less than the current situation, where a document sits unread while measurable return stalls below a third of what mature companies achieve.
Yes, but only if you’ll enforce it. A policy with no enforcement performs worse than no policy in aibl’s survey of 755 UK mid-market leaders, because it creates false confidence that the job is done. Write one only if you can name who enforces it and how exceptions get handled.
Yes. In HR, a defined-but-inconsistent policy scores 16% measurable ROI, against 33% with no policy at all, in aibl’s survey of 755 UK mid-market leaders. The document persuades people the work is finished, so nobody funds the enforcement that would have made it real.
Cover three things: who owns enforcement by name, what counts as an approved tool, and how fast a new tool gets approved. Speed matters most. If the approved route is slower than the workaround, people quietly use the workaround, whatever the policy says.
Someone senior enough to enforce it and close exceptions, not just someone who drafted it. In HR specifically, pairing that owner with Central IT works best, because HR’s AI use depends on technical controls IT already runs day to day.
This finding is one line from a much bigger governance story. The full report shows the complete ladder from no governance to mature, embedded governance, function by function, plus the four moves that close the gap for good.
The CEO or C-suite should own it. In aibl's survey of 755 UK mid-market leaders, companies with an executive...
Read more
Lead with the number your CFO already trusts, not the tool a vendor is selling. Write the success metric and the...
Read more
Readiness for AI is not about the tools you buy. It comes down to two things the survey shows decide the return:...
Read moreGet ahead with the most actionable insights, playbooks and real-world AI use cases you can adopt right now, in your inbox every week