The pattern is familiar. Someone bought seats. A few people got good at prompting (writing the instruction the tool receives). Leadership asks what has changed. The honest answer is: drafts come back faster, and nothing in the operating rhythm has moved.
That is not a failure of the tools. It is what happens when AI is treated as a side application rather than a process you own.
What these words mean
- Generative AI: software that drafts text, images or code from a prompt, rather than retrieving a stored answer.
- LLM (large language model): the model underneath ChatGPT, Claude, Gemini and Copilot.
- Prompt / prompting: the instruction you type. Prompting guidelines are the rules for what staff may put in that instruction.
- Consumer plan: a personal ChatGPT, Claude or Gemini subscription, including Plus and Pro. Work or Team plans are the business contracts.
- Training: the vendor using chats to improve future models. Consumer plans often allow this unless you turn it off. Work plans usually do not, by default.
- Pilot vs production: a trial on a few people's laptops, versus a named process the business owns, with an owner and a human check.
- Agentic AI: tools that take a sequence of actions, not only a single reply.
- Prompt injection: hidden instructions in a webpage, email or file that try to override the prompt.
- Shadow AI: staff using personal AI accounts for work because the business never issued a work login.
What "in use" usually means
- Briefs and client notes pasted into a public chat because that is what people were given.
- No owner for which work is allowed to be automated.
- No list of processes, only a hope that productivity will appear in the next report.
- A pilot deck (a trial on a few people's laptops) that never had a production environment attached (a named process the business owns).
Why most digital strategies die in the first 90 days is the same failure in different clothes. Nobody owns the next step, so the work stays in the trial.
The numbers, with sources
This is not a Perth-only pattern. Gartner predicted in June 2025 (opens in a new tab) that more than 40 per cent of agentic AI projects (tools that take a sequence of actions, not only a single reply) will be cancelled by the end of 2027, citing cost, unclear value and weak risk controls.
MIT Project NANDA's July 2025 report, The GenAI Divide (opens in a new tab), reviewed more than 300 public AI initiatives and interviewed leaders across 52 organisations. It put 95 per cent of organisations at zero measurable profit-and-loss return from generative AI (software that drafts text, images or code from a prompt). The split was not the model. It was whether anything left the pilot.
Consumer subscriptions share data. Work plans usually do not
The plan on the credit card matters more than the logo on the tab. A personal Plus or Pro seat (a consumer plan) is not a private environment, even if the business reimburses it.
- OpenAI: consumer ChatGPT can use content to improve models (training) unless you opt out. ChatGPT Team, Enterprise, Edu and the API do not train on business inputs by default (opens in a new tab).
- Anthropic: Claude Free, Pro and Max can use chats and coding sessions to improve models if that setting is on (opens in a new tab). Claude for Work, Education, Government and the API sit under commercial terms and are not used for model training (opens in a new tab).
- Google: on a personal account, Gemini Apps Activity (opens in a new tab) can be used to train generative models when Keep Activity is on. Workspace Gemini is not used to train models outside the domain without permission (opens in a new tab).
- Microsoft: Microsoft 365 Copilot does not use prompts, responses or Graph data to train foundation models (opens in a new tab). The consumer Copilot app is a different product with different terms.
If staff are pasting client names, unpublished strategy or staff records into a personal chat, that is an overseas disclosure question under the Australian Privacy Principles as well as a vendor-training question. Pay for the work plan, or do not put the work in the tool.
Other ways this leaks
- Browser extensions and "AI sidecars" that read the page you are on. The chat vendor is not the only party seeing the brief.
- Meeting bots that join the call and send the transcript to a consumer account.
- Staff using personal Gmail or a phone app because the work login was never issued. That is shadow AI (personal AI accounts used for work). That is still the business's data.
- Outputs that go to a client with no human check. Models invent sources, numbers and case law. The brand is on the email, not the model.
- Prompt injection (hidden instructions in a webpage, email or file that try to override the prompt) when a tool is allowed to read the open web or a shared inbox. Treat untrusted text as untrusted, the same way you treat an unexpected attachment. OWASP's LLM Top 10 (opens in a new tab) is the current list of those failure modes for an LLM (large language model: the software underneath ChatGPT, Claude, Gemini and Copilot).
Prompting guidelines that belong in the policy
A use policy that nobody can follow is decoration. Put the prompting rules (what staff may put in the instruction) in the same document, short enough to read on a phone.
- Do not paste personal information, client files, unpublished numbers or staff records into a consumer tool. If the work needs the file, it needs the work plan.
- Name the task, the audience, the format and the constraint. "Write a LinkedIn post" is not a brief.
- Ask for sources and then check them. If the model cannot point to a page you can open, do not publish the claim.
- A person signs the output. The tool drafts. It does not send.
- Keep a short log of which process uses which tool. If one person leaves, the work has to survive.
The AI use policy starter is the version I use with Australian businesses. Add the prompting rules to it. Do not make a second document that nobody opens.
The order of work
- Name the processes. Pick one that is repetitive, low-risk, and already eating hours.
- Put a private environment around the data so confidential work stops going into a public tool.
- Ship that one workflow with a human check on the output. Not five. One.
- Write a policy the team will read, covering what is allowed, what is not, and who owns it. The AI use policy starter is the version I use with Australian businesses.
After that, AI strategy and agentic operations is the work of scaling what already runs, not buying another seat. If you want to know whether assistants even name you, the AI visibility checker is the 60-second version of that question.
Access is not adoption. Adoption is a process with an owner, in production, with a check on the output.