Many organisations can now point to two signs of progress with AI: they have bought AI licences for their people and introduced a policy covering how AI should be used.
Both are useful steps. But neither tells you whether AI is actually working well inside the organisation.
Licence counts tell you how much access has been provisioned. Policies tell you what the organisation expects. To understand whether adoption is working, you need to look at what happens when people use AI in real work.
How do you know whether AI adoption is working?
AI adoption is working when people can use approved tools effectively in worthwhile work, the organisation's controls operate in practice, and there is evidence of useful outcomes compared with how the work was done before.
At AI Body of Knowledge, we look beyond access and policy documents to understand whether people can use AI effectively, whether safeguards operate in practice, and whether the work produces worthwhile outcomes. The following four checks are practical starting points for examining adoption in everyday work.
What evidence should you look for?
-
Access
Do the right people have approved AI tools, and are those tools actually being used for worthwhile work?
-
Capability
Can people use AI effectively, safely and with enough judgement to know when an output is good enough to rely on?
-
Controls
Do the organisation's rules, checks and escalation points operate when AI is used in real situations?
-
Outcomes
What changed compared with the previous way of working, and was the change actually worthwhile?
These four checks provide a practical starting point for understanding AI adoption, but they don't tell the whole story. A broader assessment can help identify the organisational capabilities, gaps and development priorities that influence effective and sustainable AI adoption. AI Body of Knowledge's six-dimensional GenAI Maturity Model provides one structured approach to understanding these factors.
Access is not the same as capability
Giving people access to an approved AI tool is important. It can provide a safer and more supported alternative to unmanaged use of consumer AI tools. Without an approved option, employees may turn to their own personal ChatGPT, Claude or Google Gemini accounts for work, contributing to what is often described as shadow AI.
Approved access also gives people the opportunity to start learning where AI may be useful in their work. But it is only a first step.
Access alone does not mean people know how to use AI effectively, safely or securely. It does not tell you whether they understand where AI is useful, how to apply it to their role, how to check its outputs or when not to use it.
In September 2026, the University of Sydney announced a staged rollout of ChatGPT Edu combining broad access with training, support and a responsible AI framework. The university said success should ultimately be measured by what AI helps its people achieve, rather than simply by how much AI is adopted.
The rollout shows what supported access can look like, but it is not yet evidence that particular productivity or other outcomes have been achieved.
One professional services firm we worked with had no approved AI tool, policy or formal guidance, yet multiple staff were already using personal AI tools for work, creating a data-handling risk outside company controls. We highlighted the unmanaged-use risk and recommended basic governance and a safer company-managed option.
When we spoke again a few months later, the company had introduced a policy and company-managed AI licences with appropriate privacy and security settings, giving staff a safer governed option. But the team was still barely using the AI tools because they had not yet built the practical capability to apply them to day-to-day work.
Looking at these four areas, the pattern was clear: approved access had improved, practical capability remained low, controls had been introduced but we did not yet have evidence they were operating consistently, and worthwhile outcomes had not yet been established.
Buying the licence solves the access problem. It does not automatically solve the capability problem.
A written policy does not show whether controls work
An AI policy can be valuable. It can explain what is acceptable, what is not, what people are responsible for and where the boundaries are.
But writing the policy is only one part of governance. The important question is whether the intended controls operate when AI is actually being used.
A September 2026 EY US survey illustrates one version of that gap. It surveyed 202 senior AI executives at large US organisations with at least US$1 billion in annual revenue. Almost all respondents, 98%, said their organisation had formal AI governance policies, while 47% said their organisation had previously not followed its AI governance process for an urgent deployment.
That is not evidence that employees routinely ignore AI policies in everyday work, and the organisations surveyed are very different from Australian small and medium businesses. But it demonstrates a narrower point: having a formal governance process does not guarantee that the process will operate when pressure is applied.
Research also highlights the gap between confidence in AI governance and what organisations are doing in practice. The Australian Responsible AI Index 2025, sponsored by the National Artificial Intelligence Centre, surveyed 418 AI strategy decision-makers in Australian organisations with 20 or more employees that were using or deploying AI, with fieldwork conducted in April and May 2025. It identified a gap between confidence in performance against the Voluntary AI Safety Standard guardrails and the responsible-AI practices actually implemented. The report specifically highlighted human oversight and testing and monitoring.
The studies examine different organisations and questions, but together they reinforce the same practical point: policies and governance structures matter, and leaders still need evidence that the intended controls are operating in real work.
For everyday AI use, leaders should look for whether people understand the rules, can apply them to the work they actually do, complete the required checks, and know when something needs to be escalated.
Look at one real piece of work
You do not need to measure every AI use case across the organisation at once. Choose one important task or business process where AI is already being used, or where the organisation expects it to be useful, and examine what is actually happening.
Useful evidence might include:
- Access: assigned licences compared with meaningful use of approved tools for the task.
- Capability: whether people can explain how they use AI, where it helps, and how they check the result.
- Controls: sampled evidence that required review, approval, privacy or quality checks are taking place.
- Outcomes: a before-and-after comparison of turnaround time, rework, quality, capacity, error rates or another outcome that matters for that piece of work.
A baseline matters. Without some view of how the work was performed before AI was introduced, it is difficult to distinguish real improvement from activity that simply looks faster or more automated.
And if AI saves time, ask what happens to that time. Faster completion is useful only if the organisation can point to what improved as a result: greater capacity, better service, higher-quality work, less rework, faster turnaround, or another worthwhile outcome.
What to do if the answers are unclear
Licence counts and policies are useful foundations. If approved access is not turning into capability, controls do not work reliably, or the organisation cannot point to a meaningful change in how work is performed, buying another AI product may not solve the problem.
The next step may be to strengthen the practical capability and confidence of the people using the tools the organisation already has. Helping organisations build that capability, confidence and judgement is central to the training and enablement work we do at AI Body of Knowledge.
Practical takeaway
Pick one real piece of work where AI is already being used. Establish what happened before AI, then check four things together: whether people have approved access, can use the tool effectively, apply the required controls, and can point to a worthwhile outcome. If one of those is missing, licence counts and policy documents alone are not evidence that adoption is working.