AI · · 10 min read

THEY BOUGHT AI AND THE WEEK LOOKS THE SAME

The licences are paid. People paste briefs into a browser. The week looks the same as it did last quarter.

The short version
  • Buying a consumer AI plan (a personal ChatGPT, Claude or Gemini subscription, including Plus and Pro) is not adoption, and it is often a data-sharing decision you did not mean to make.
  • ChatGPT Plus, Claude Pro and the consumer Gemini app can use chats to improve models (training) unless you turn that off. Team, Enterprise, API and Workspace plans do not, by default.
  • Adoption is one process in production (a named process the business owns), with an owner, a human check, and prompting rules (what staff may put in the instruction) the team will actually follow.
  • A policy belongs in from the start. The AI use policy starter is the working document.

The pattern is familiar. Someone bought seats. A few people got good at prompting (writing the instruction the tool receives). Leadership asks what has changed. The honest answer is: drafts come back faster, and nothing in the operating rhythm has moved.

That is not a failure of the tools. It is what happens when AI is treated as a side application rather than a process you own.

What these words mean

  • Generative AI: software that drafts text, images or code from a prompt, rather than retrieving a stored answer.
  • LLM (large language model): the model underneath ChatGPT, Claude, Gemini and Copilot.
  • Prompt / prompting: the instruction you type. Prompting guidelines are the rules for what staff may put in that instruction.
  • Consumer plan: a personal ChatGPT, Claude or Gemini subscription, including Plus and Pro. Work or Team plans are the business contracts.
  • Training: the vendor using chats to improve future models. Consumer plans often allow this unless you turn it off. Work plans usually do not, by default.
  • Pilot vs production: a trial on a few people's laptops, versus a named process the business owns, with an owner and a human check.
  • Agentic AI: tools that take a sequence of actions, not only a single reply.
  • Prompt injection: hidden instructions in a webpage, email or file that try to override the prompt.
  • Shadow AI: staff using personal AI accounts for work because the business never issued a work login.

What "in use" usually means

  • Briefs and client notes pasted into a public chat because that is what people were given.
  • No owner for which work is allowed to be automated.
  • No list of processes, only a hope that productivity will appear in the next report.
  • A pilot deck (a trial on a few people's laptops) that never had a production environment attached (a named process the business owns).

Why most digital strategies die in the first 90 days is the same failure in different clothes. Nobody owns the next step, so the work stays in the trial.

The numbers, with sources

This is not a Perth-only pattern. Gartner predicted in June 2025 (opens in a new tab) that more than 40 per cent of agentic AI projects (tools that take a sequence of actions, not only a single reply) will be cancelled by the end of 2027, citing cost, unclear value and weak risk controls.

MIT Project NANDA's July 2025 report, The GenAI Divide (opens in a new tab), reviewed more than 300 public AI initiatives and interviewed leaders across 52 organisations. It put 95 per cent of organisations at zero measurable profit-and-loss return from generative AI (software that drafts text, images or code from a prompt). The split was not the model. It was whether anything left the pilot.

40%agentic AI projects Gartner expects cancelled by 2027
95%organisations with no measurable GenAI P&L return (MIT NANDA, 2025)

Consumer subscriptions share data. Work plans usually do not

The plan on the credit card matters more than the logo on the tab. A personal Plus or Pro seat (a consumer plan) is not a private environment, even if the business reimburses it.

If staff are pasting client names, unpublished strategy or staff records into a personal chat, that is an overseas disclosure question under the Australian Privacy Principles as well as a vendor-training question. Pay for the work plan, or do not put the work in the tool.

Other ways this leaks

  • Browser extensions and "AI sidecars" that read the page you are on. The chat vendor is not the only party seeing the brief.
  • Meeting bots that join the call and send the transcript to a consumer account.
  • Staff using personal Gmail or a phone app because the work login was never issued. That is shadow AI (personal AI accounts used for work). That is still the business's data.
  • Outputs that go to a client with no human check. Models invent sources, numbers and case law. The brand is on the email, not the model.
  • Prompt injection (hidden instructions in a webpage, email or file that try to override the prompt) when a tool is allowed to read the open web or a shared inbox. Treat untrusted text as untrusted, the same way you treat an unexpected attachment. OWASP's LLM Top 10 (opens in a new tab) is the current list of those failure modes for an LLM (large language model: the software underneath ChatGPT, Claude, Gemini and Copilot).

Prompting guidelines that belong in the policy

A use policy that nobody can follow is decoration. Put the prompting rules (what staff may put in the instruction) in the same document, short enough to read on a phone.

  1. Do not paste personal information, client files, unpublished numbers or staff records into a consumer tool. If the work needs the file, it needs the work plan.
  2. Name the task, the audience, the format and the constraint. "Write a LinkedIn post" is not a brief.
  3. Ask for sources and then check them. If the model cannot point to a page you can open, do not publish the claim.
  4. A person signs the output. The tool drafts. It does not send.
  5. Keep a short log of which process uses which tool. If one person leaves, the work has to survive.

The AI use policy starter is the version I use with Australian businesses. Add the prompting rules to it. Do not make a second document that nobody opens.

The order of work

  1. Name the processes. Pick one that is repetitive, low-risk, and already eating hours.
  2. Put a private environment around the data so confidential work stops going into a public tool.
  3. Ship that one workflow with a human check on the output. Not five. One.
  4. Write a policy the team will read, covering what is allowed, what is not, and who owns it. The AI use policy starter is the version I use with Australian businesses.

After that, AI strategy and agentic operations is the work of scaling what already runs, not buying another seat. If you want to know whether assistants even name you, the AI visibility checker is the 60-second version of that question.

Access is not adoption. Adoption is a process with an owner, in production, with a check on the output.

COMMON QUESTIONS

Is ChatGPT Plus safe for client work?

Not as a default. Plus is a consumer plan (a personal subscription, not a business contract). OpenAI may use that content to improve models unless the user has opted out. Client work belongs on Team, Enterprise or the API, or it stays out of the tool.

We turned off training in settings. Is that enough?

Training means the vendor using chats to improve future models. Turning that off is better than leaving the default. It is not a contract. Settings change, people share logins, and extensions still see the page. The work plan is the control that survives a setting being flicked back on.

We already use ChatGPT. Does that count?

It counts as people finding a shortcut. It does not count as the business owning a process. If the work disappears when one person leaves, it was never in production (a named process with an owner and a human check).

Will this replace the team?

Unlikely. A team using these tools well will replace a team that is still pasting the same brief into a browser. I train people to speed the work up, not to disappear.

Where do we start if everything feels like a candidate?

Start with the process that is already a weekly grind and does not touch live customer money. Get that into production, a named process with an owner and a human check. Then look at the next one.

Recognise any of this?