A software adoption strategy for an AI tool is a migration plan, not a launch plan. The usage already exists: 70% of employees who use AI at work reach for free, publicly available tools, while only 42% use anything their employer provides, according to the KPMG and University of Melbourne global study of 48,000 people across 47 countries. You are not creating demand. You are moving demand onto a path you can see.
That single inversion is our position, and it changes every step downstream. Conventional software adoption starts at zero and spends its budget on persuasion: champions, training, nudges, in-app tours. AI software adoption starts above zero, off the books, and spends its budget on substitution — making the sanctioned path good enough that people stop routing around it. Get that backwards and you run a launch campaign for a product your staff have quietly been using for eighteen months.
The failure is visible in public. On Hacker News in June 2026, a commenter posting as al_borland described his employer measuring staff on AI usage and then running out of capacity: "we hit our company AI quota for the month," with "entire teams claiming they're blocked" for the fortnight until reset (item 48585087). Adoption worked. Provisioning didn't. Nobody had modelled what success would consume.
The short answer: Treat AI software adoption as a migration from unsanctioned tools to a sanctioned path, measure sanctioned share rather than logins, and never open with a ban. Employees whose organisations ban generative AI break policy at roughly twice the rate of employees whose organisations have no policy at all.
Last updated: July 30, 2026.
We have not run this rollout inside a customer and cannot show you a first-hand log or a measured before-and-after; every number below is attributed to a published source and every worked figure is labelled as an illustration.
What a software adoption strategy is when the software is AI
A software adoption strategy is the plan for turning a purchase into habitual, workflow-embedded use by the people it was bought for. For AI tools, add one clause: it is also the plan for retiring the unofficial tools the same people are already using for the same jobs. Adoption is not the arrival of usage. It is the arrival of usage you can account for.
The distinction matters because the two definitions produce opposite budgets. Under the conventional definition, the money goes to awareness and enablement. Under the AI definition, most of the money goes to closing the capability gap between the tool people chose for themselves and the tool you chose for them — plus the identity, logging and data-handling work that makes the sanctioned route defensible rather than merely available.
Three things are true at once in most enterprises right now, and any credible software adoption strategy has to hold all three:
| Fact | Figure | Source |
|---|---|---|
| Employees already use AI at work | 52% of U.S. workers use AI in their role; 30% a few times a week or more; 15% daily | Gallup, Q2 2026 |
| Most of that use is on tools you did not buy | 70% use free public AI tools for work; 42% use employer-provided tools | KPMG / University of Melbourne, 2025 |
| Most organisations have not written the rules | Only 34% of employees report a policy guiding generative AI use; 41% report none; 19% do not know | Same study, Figure 41 |
Read those rows together and the job description changes. You are not launching into a vacuum. You are arriving late to a market inside your own company, competing against incumbents your staff already like, and your differentiator is not features; it is that your version is allowed.
That framing also fixes the question everyone argues about in the steering meeting: what counts as success. If adoption means "people use AI", you have already won and the project is pointless. If adoption means "the AI work our people do runs on a path we own", you have a number that starts low, moves, and can be reported honestly. We call that number sanctioned share, and the rest of this guide is built around moving it.
The adoption curve already happened without you
Organisational AI adoption and individual AI adoption have decoupled. Gallup found 47% of U.S. employees said their organisation had integrated AI tools by the second quarter of 2026, up six points in a quarter — while 52% of individuals said they personally use AI in their role. Individual use is running ahead of the institution, and the institution is chasing.
The gap is not a rounding error, and it is not benign. In the KPMG and University of Melbourne study, fielded between November 2024 and January 2025 across 47 countries — roughly half of employee AI users (48–49%) admitted uploading sensitive company information such as financial, sales or customer data, or copyrighted material, into public AI tools. Fifty-seven percent admitted non-transparent use: presenting AI-generated content as their own, or avoiding disclosing that they used a tool at all. Sixty-three percent said they had seen or heard about colleagues using AI inappropriately.
Now the finding that should reorder your plan. The same study measured policy-contravening behaviour against the policy regime employees were working under:
| What the organisation had done | Share of AI-using employees contravening policy |
|---|---|
| Banned generative AI | 67% |
| No such policies at all | 33% |
Those are the two endpoints the report is explicit about; the two intermediate regimes it measured (organisations that permit AI use, and employees who do not know whether a policy exists) fall between them at 56% and 38%, and we have not assigned those two figures to their categories here because the published breakdown does not let us do it unambiguously. The endpoints are the finding that matters. The authors' own conclusion is blunt: outright bans may be ineffective, and simply having policies does not guarantee compliance. Clear guidance and education is what they call for. Read the table as a rollout instruction rather than a survey result and it says something sharper still: the intervention most companies reach for first, the ban, sits at the top of the violation league table. Prohibition does not remove the behaviour. It removes your visibility of it.
Stanford HAI's 2026 AI Index puts organisational adoption at 88% and simultaneously records documented AI incidents rising to 362, up from 233 the year before. Adoption is not the scarce resource. Controlled adoption is.
There is a capacity dimension too, and it is the one that produced our problem card. Microsoft's 2026 Work Trend Index reports active agents in Microsoft 365 growing 15x year over year, and 18x inside large enterprises. If your adoption plan succeeds, consumption compounds — and the plan that never modelled consumption produces exactly the outcome al_borland described: a company-wide quota exhausted mid-month, teams idle, and staff quietly reopening the personal account they were told to stop using. A rollout that succeeds and then rations is a rollout that trains people to keep a backup.
We wrote about the visibility half of this problem in our earlier analysis of why half your company already uses ungoverned AI. This guide is the other half: what you actually do about it, in order.
Why the classic playbook misfires on AI tools
The standard software adoption strategy has a well-worn seven-step shape: set goals, segment users, configure and integrate, onboard in phases, train continuously, monitor usage, collect feedback. None of it is wrong. All of it assumes the starting condition is zero usage and the obstacle is unfamiliarity. For AI, the starting condition is non-zero usage and the obstacle is comparison.
Here is where each conventional move needs rewriting:
| Conventional step | What it assumes | What AI tools actually need |
|---|---|---|
| Set adoption goals | Logins and active users are the target | Sanctioned share: approved-path AI work as a fraction of all AI work |
| Segment users by attitude | Champions, pragmatists, skeptics | Segment by job already being done off-platform, then by data sensitivity |
| Configure and integrate | SSO, data migration, one-time setup | Identity per human and per agent, plus per-connector scoping that survives staff changes |
| Phased onboarding | Teach the interface | Match or beat the personal tool at five named tasks before you ask anyone to switch |
| Continuous training | Feature walkthroughs | Judgment training: what may be pasted where, when output must be checked, how to disclose |
| Monitor usage | Heatmaps and session counts | Monitor what was refused as well as what ran; monitor the residual unsanctioned path |
| Collect feedback | Surveys and NPS | Treat every workaround as a defect report against the sanctioned path |
The user-segmentation row deserves an argument, because segmenting by attitude is the most popular device in adoption writing and it is the weakest one here. Gallup's April 2026 study of 23,717 U.S. employees, fielded that February, found that the strongest differentiators of frequent AI use were structural rather than dispositional: 88% of employees who strongly agreed AI integrates well with the systems and processes they already use were frequent users, against 55% of those who did not strongly agree. Manager support moved the number from 44% to 78%. Permission to experiment moved it from 44% to 72%.
Microsoft's 2026 index reaches the same place from different data, reporting that organisational factors such as culture, manager support and talent practices account for more than twice the AI impact of individual factors. Skeptics are not the bottleneck. Fit and permission are. A software adoption strategy that spends its energy on persuading personalities is optimising the smaller variable.
And there is a barrier the conventional playbook has no step for at all. Among Gallup's non-users of AI at work, 43% cited concerns about data privacy, security and compliance, the same worry named by 38% of infrequent users. That is not resistance to change. That is a governance question asked by a careful employee, and no amount of in-app onboarding answers it. Only a documented, demonstrable answer about what the tool does with their input will.
Prerequisites: seven things to have before day one
Do not start the rollout until these exist. Each one is cheap to build in week zero and expensive to retrofit in month four. If more than two are missing, you are not ready to announce anything.
- A named owner with budget authority. Not a committee. One person who can approve a connector, raise a quota and cancel a workstream. Microsoft's 2026 index found only 26% of AI users say leadership is clearly and consistently aligned on AI; ambiguity at the top becomes stalling at the bottom.
- A written list of the top ten jobs people currently do with AI. In their words, from their teams, not from a vendor's use-case page. This list is the acceptance criteria for the tool you bought.
- A data classification you can say out loud in one sentence. For example: customer records and unreleased financials never leave the sanctioned path; everything else may. If your classification needs a slide deck, staff will not apply it under time pressure.
- Identity that covers non-human callers. Every agent, script and integration needs an owner, a scope and an expiry, the same as a person. We set out why in our analysis of owner, scope and expiry for AI agents. Retrofitting this after agents proliferate is the single most painful item on this list.
- A logging destination that already exists. Decide before launch where prompts, tool calls and refusals land, who can read them, and how long they are retained. Adoption creates evidence; evidence with no home becomes a discovery problem.
- A capacity and cost model with headroom. Estimate consumption per active user per month, multiply by your target sanctioned share rather than your current usage, and add at least 50% headroom. This is the prerequisite that would have prevented our problem card.
- A training obligation you can point to. If you operate in the EU, Article 4 of the EU AI Act has applied since 2 February 2025 and requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among staff and others operating systems on their behalf. Training is not a nice-to-have line in your adoption plan; for deployers in scope it is a legal duty.
A short prerequisite check, in the form of questions you should be able to answer before the kickoff email goes out:
| Prerequisite | The question that proves it exists |
|---|---|
| Owner | Who can approve a new connector today, without a meeting? |
| Job list | Name the five tasks the tool must beat the personal account at. |
| Classification | Which two data types may never leave the sanctioned path? |
| Non-human identity | Who owns the service account that agent runs as, and when does it expire? |
| Logging | Where does last Tuesday's refused request appear? |
| Capacity | What happens to the quota if usage triples in six weeks? |
| Training duty | Which staff are in scope for AI-literacy obligations? |
The Sanctioned-Share Rollout: count, match, move, hold
This is the procedure. Four moves, run in order, each with an exit condition. We call it the Sanctioned-Share Rollout because the number it moves is the share of your organisation's AI work running on the approved path — and because naming the metric in the method stops the programme drifting back to counting logins.
It borrows its sequencing logic from the phased approach our platform takes to gateway deployment: observe first, enforce second, optimize third. You cannot enforce a rule against traffic you have not seen, and you cannot optimise a route you have not enforced.
Move 1, Count: establish the baseline you are actually starting from
Spend two to three weeks measuring current AI usage before you announce anything. The output is one number and one list: your starting sanctioned share, and the ranked jobs people use AI for.
Sources for the count, roughly in order of reliability:
- Network and proxy logs. Requests to consumer AI domains, aggregated by department, never by individual name at this stage.
- Expense and card data. Personal subscriptions reimbursed as expenses. This is the most under-used signal in the exercise and often the fastest.
- SaaS and browser-extension inventory. AI features quietly enabled inside tools you already own count as AI usage.
- An amnesty survey. Ask directly, promise no consequences, and mean it. Given that 57% of employees in the KPMG study admitted non-transparent AI use, expect self-reported numbers to undercount — treat the survey as a source of jobs, not of volume.
Two rules make or break this move. First, no enforcement during counting. The moment counting produces consequences it produces concealment, and you have destroyed your own instrument. Second, count jobs, not tools. "Drafting client emails" and "summarising call transcripts" are jobs; ChatGPT is a tool. Jobs survive the next model release, and your acceptance criteria should be written against them.
If you genuinely cannot see the traffic, unmanaged devices, split-tunnel VPNs, contractors on their own hardware — do not abandon the metric. Build the denominator from expense data and the amnesty survey instead, state it as a range rather than a point, and publish the blind spot alongside the number. A baseline of "somewhere between 40% and 60% of our AI work is on the sanctioned path, and we cannot see contractor devices at all" is a usable starting position. A baseline of 100% because you only measured your own tool is not.
Exit condition: you can state your baseline sanctioned share as a percentage or a stated range, and you have a ranked list of at least ten jobs with a rough volume estimate for each.
Move 2, Match: close the capability gap before you ask anyone to switch
Take the top five jobs from Move 1 and test the sanctioned tool against them side by side with the personal tool people currently use. Not a demo. The actual work, done by the people who do it, scored on output quality and time to result.
You are looking for the gap and its cause, which is almost always one of four things: a missing connector to the system where the work lives, a slower or weaker model, a clumsier interface, or an approval step that adds a day. Each has a different fix and only the second is about the model.
| Gap cause | Typical symptom | Fix that works |
|---|---|---|
| Missing connector | "I have to copy the data in by hand" | Vet and publish the connector, scoped to the actions actually needed |
| Weaker model for this task | "The output needs more editing than before" | Route this job class to a stronger model rather than standardising on one |
| Interface friction | "It takes four clicks to start" | Put the entry point where the work already happens |
| Approval latency | "I need sign-off, so I just do it the old way" | Move the human gate to the commit step, not the request step |
Publish the results honestly, including the jobs where the sanctioned tool loses. A rollout that admits two of five gaps and gives dates for closing them earns more credibility than one that claims parity everywhere and gets contradicted by the first user on day one.
Exit condition: the sanctioned path wins or ties on at least three of the top five jobs, and the remaining gaps have owners and dates.
If you fail this exit condition, stop. Losing four of five is not a reason to push harder on enablement; it is a verdict on the tool or its configuration, and migrating people onto it will produce a rollout that gets reversed in month three. The three responses that work, in order of cost: reconfigure and re-test with the connectors and routing the jobs actually need, narrow the scope to the cohorts whose jobs you do win, or change the tool while your switching cost is still one procurement cycle rather than a company-wide habit. Announcing anyway is the expensive option, and it is the one most programmes take.
Move 3 — Move: migrate cohorts, not the company
Migrate in cohorts defined by job similarity, not by department or enthusiasm. A cohort is a group doing the same work with the same data sensitivity, which means one configuration serves all of them and one set of guidance covers all of them.
Sequence the cohorts by a simple product: value of the job multiplied by ease of the switch, divided by data sensitivity. High-value, easy-switch, low-sensitivity work goes first; it produces a visible win with a small blast radius. Regulated or customer-data-heavy work goes last, once the logging and refusal behaviour has been proven on the easy cohorts.
For each cohort, the move itself is four steps:
- Provision before you announce. Accounts, connectors, quota and access are live before anyone reads the email. Nothing kills a migration faster than an announcement followed by a ticket queue.
- Migrate the artefact, not just the account. People have prompts, saved instructions and small workflows they have refined for months. Moving those over is the difference between switching tools and starting over. Promoting a proven personal workflow into a named, owned company asset is a real piece of work, and we covered the pattern in personal prompts to owned assets.
- Run a two-week overlap. Both paths open. If people voluntarily stay on the personal tool, that is your defect report, and it is far more informative than a satisfaction survey.
- Close the old path last, and only for that cohort. Revoke access to consumer tools for this cohort once the sanctioned path has carried their work for two weeks. Not before. Not company-wide.
That ordering is the whole argument against the ban-first instinct. You are not withdrawing a capability; you are replacing one that already works, and the replacement has to be in place first.
Exit condition: for each migrated cohort, sanctioned share above your target — we would set 80% as a defensible first target, sustained for two consecutive weeks.
Move 4 — Hold: stop the share from decaying
Sanctioned share decays. A better consumer model ships, a team hits a quota wall, a new hire arrives with habits from their last employer, and the residual path reopens. Holding is a standing operation, not a project phase.
Four mechanics do most of the work:
- A monthly re-count. Re-run Move 1's measurement. Any month-over-month rise in unsanctioned traffic is a symptom; go find the job it belongs to.
- A fast-lane request path. When someone needs a tool you have not vetted, they need an answer in days, not a quarter. Slow vetting is the leading manufacturer of shadow AI.
- Quota headroom monitored as a leading indicator. Track consumption against ceiling weekly. Do not let a budget control become an availability outage; that is precisely the trap in our problem card.
- Joiner-mover-leaver hygiene. Access follows role changes and terminates on exit, for agents as well as people.
Exit condition: none. This is the steady state, and the metric that says it is working is a sanctioned share that does not fall when the market ships something new.
Adoption metrics that survive contact with AI
The metric problem is not that companies fail to measure adoption. It is that they measure something that goes green while the programme fails. The commenter posting as placardloop described exactly this in April 2025: AI companion tools "forcibly installed in everyone's browser," followed by a press release celebrating that "100% of people at our company now use AI" (item 43585486). Installation reached 100%. Adoption reached nothing measurable at all.
Here is the metric set we would defend, with the vanity metric each one replaces:
| Metric | Definition | Replaces | Healthy direction |
|---|---|---|---|
| Sanctioned share | Approved-path AI requests ÷ all detectable AI requests | Active users | Rising toward 80%+ |
| Job coverage | Jobs from the Move 1 list now served on the sanctioned path ÷ total jobs listed | Feature adoption | Rising |
| Residual unsanctioned traffic | Requests to consumer AI endpoints per 100 staff per week | Nothing — usually unmeasured | Falling |
| Time to first useful output | Median minutes from access granted to a kept result | Training completion, time to value | Falling |
| Support tickets per 100 migrated staff | Tickets raised about the sanctioned tool, by cause | User engagement scores | Spike in week one, then falling |
| Refusal rate and reason mix | Share of requests blocked by policy, grouped by cause | Nothing — usually unmeasured | Stable, with causes shifting from "misconfigured" to "correctly prevented" |
| Cost per active user per month | Total AI spend ÷ genuinely active users | Total spend | Predictable, with headroom |
| Quota headroom | Ceiling minus peak weekly consumption | Nothing | Never below 30% |
Three of these deserve a note.
Support tickets are a quality signal, not a nuisance. A week-one spike is expected and healthy; it means end users are actually trying the thing. What matters is the cause mix in weeks two to six. Tickets about access and setup mean provisioning ran late; tickets about "how do I get it to do X" mean the job list from the Count phase was incomplete; tickets that stop arriving while unsanctioned traffic stays flat mean people gave up quietly, which is the worst reading on this dashboard and the one that looks best.
Sanctioned share is a ratio with a hard denominator. It only works if you can detect AI traffic that is not on your platform, which is why Move 1 is a network and expense exercise rather than a survey. An organisation that can only measure its own tool will report 100% sanctioned share on day one and be wrong by a factor of two.
Refusal rate is the metric nobody instruments and everybody needs. A record of what the system declined to do is the difference between "we have a policy" and "we can demonstrate the policy operated". It also functions as a live quality signal about your rules: a spike in refusals for one team usually means the classification does not match how that team actually works, not that the team went rogue. We have argued the broader case for treating refusals as first-class evidence in our work on audit trails that prove agent actions.
For the outcome side of the ledger (did the work actually get faster or better), a separate discipline applies, and the usual mistake is borrowing a benchmark rather than measuring your own before-state. We set out how to avoid that in borrow the baseline you already own.
A worked rollout plan, assembled end to end
Below is a complete plan for a hypothetical 1,200-person professional services firm, assembled from the moves above. This is an illustration built from the published survey figures cited in this guide, not a client engagement and not measured data. The baseline percentages are the study averages applied to a headcount; treat them as a template to overwrite with your own Move 1 numbers, not as a benchmark.
Starting position (modelled from the cited studies): 1,200 staff. At Gallup's 52% figure, roughly 624 use AI in their role. At the KPMG study's split of 70% on free public tools against 42% on employer-provided, the sanctioned path carries a minority of that work. The firm's own Move 1 count is the number that replaces this estimate.
Weeks 1–3 — Count
| Activity | Output |
|---|---|
| Proxy log pull, aggregated by department | Requests per week to consumer AI domains |
| Expense review, 12 months, AI keyword scan | Count of reimbursed personal subscriptions |
| Browser extension and SaaS AI-feature inventory | List of AI surfaces already inside owned tools |
| Amnesty survey, no attribution | Ranked list of jobs, in staff wording |
| Deliverable | Baseline sanctioned share, single percentage, plus the top-ten job list |
Weeks 4–6, Match
The top five jobs, tested head to head. An illustrative scoring grid:
| Job | Sanctioned path result | Gap cause | Owner and date |
|---|---|---|---|
| Draft client correspondence | Tie | — | — |
| Summarise call transcripts | Loses | No connector to the meeting platform | Platform lead, week 6 |
| Research and cite source material | Wins | — | — |
| Draft and check spreadsheet formulas | Loses | Slower model on this task class | Routing owner, week 7 |
| Rewrite proposals to a house style | Tie | — | — |
Exit met: three of five won or tied, two gaps owned and dated.
Weeks 7–14 — Move, in four cohorts
| Cohort | Size | Data sensitivity | Sequence rationale | Old path closes |
|---|---|---|---|---|
| Marketing and internal comms | 90 | Low | High value, easy switch, small blast radius | Week 9 |
| Consulting delivery | 420 | Medium | Largest volume, needs the transcript connector first | Week 11 |
| Finance | 110 | High | Waits for logging and refusal behaviour to be proven | Week 13 |
| Client-data and regulated work | 180 | Highest | Last by design | Week 15 |
Each cohort: provision, migrate saved prompts, two-week overlap, then close the old path for that cohort only.
Week 15 onward, Hold
| Cadence | Activity | Trigger for action |
|---|---|---|
| Weekly | Consumption against quota ceiling | Headroom below 30% |
| Monthly | Re-count of unsanctioned traffic | Any month-over-month rise |
| Monthly | New-tool requests and turnaround time | Median above five working days |
| Quarterly | Job list refresh, head-to-head re-test | Any job where the sanctioned path now loses |
The one-page report this produces. Six rows, monthly, to the owner and the steering group: baseline sanctioned share, current sanctioned share, residual unsanctioned requests per 100 staff, job coverage, cost per active user, quota headroom. If your adoption reporting needs more than one page, it has drifted back into activity metrics.
Common mistakes that kill AI software adoption
These are the failure modes we would look for first in any stalled rollout, each traceable to evidence rather than folklore.
Opening with a ban. The KPMG data is unambiguous: policy-contravening behaviour peaked at 67% among employees whose organisation had banned generative AI, against 33% where no policy existed. A ban issued before a working alternative exists converts visible risk into invisible risk. Sequence the ban after the substitution, per cohort, or not at all.
The counterargument, which sometimes wins. General counsel will not always accept "let them keep using the consumer tool for six more weeks", and in three situations they are right. If you have an active incident — data already known to be in a third-party tool, containment outranks adoption mechanics. If a customer contract or a sector rule explicitly prohibits processing certain data outside named systems, the prohibition is not yours to sequence. And if a specific tool has a disqualifying term, such as training on submitted content with no opt-out, blocking that one tool is not the blanket ban the survey data indicts. What the evidence argues against is the general pre-emptive ban issued in place of an alternative. A narrow, named, explained restriction alongside a working sanctioned path is a different intervention with a different result, and it is worth saying so to the reviewer who will otherwise dismiss this entire section.
Measuring installation instead of substitution. The 100%-installed press release is the archetype. If your dashboard cannot show what fraction of AI work is not on your platform, it cannot show adoption at all — it can only show provisioning.
Rationing after you have mandated. Success consumes capacity. A quota exhausted mid-month, with staff measured on AI usage, teaches exactly one lesson: keep a personal account as a backup. That is a rollout actively manufacturing its own shadow AI.
Treating training as feature walkthroughs. Nobody needs a tour of a chat box. What people cannot work out alone is judgment: which data classes may go where, when output must be independently checked, and when use must be disclosed. Given that two in three employees in the KPMG study reported relying on AI output without evaluating it, and over half reported making mistakes at work because of AI, judgment training is the higher-value curriculum by a wide margin.
Segmenting by personality instead of by job and sensitivity. Champions and skeptics make a satisfying slide. Gallup's structural findings, 88% versus 55% on workflow fit, 78% versus 44% on manager support — say the gain is in fit and permission, not in temperament. User adoption follows the path of least resistance, and temperament is rarely what makes a path hard.
Ignoring non-human identity until agents multiply. Agent counts grow fast: Microsoft reported 15x year-over-year growth in active Microsoft 365 agents, and 18x in large enterprises. Every agent that lacks an owner, a scope and an expiry is a permission you cannot revoke on the day someone leaves.
Letting vetting be the bottleneck. If the answer to "can I use this tool?" takes a quarter, staff will stop asking. Fast vetting with a narrow initial scope beats thorough vetting nobody waits for.
Declaring victory at the pilot. A pilot that works proves the tool functions; it does not prove the organisation can run it. The questions that decide the crossing are different from the ones the pilot answered, which we set out in why pilots stall on the way to production.
What non-adoption actually costs
The cost case for a software adoption strategy is usually made with licence waste, and licence waste is real. According to Zylo's 2026 SaaS Management Index, vendor-published data from a SaaS management provider, so read it as directional rather than independent — organisations use only 54% of their SaaS licences, and the average organisation wastes $19.8M a year on unused licences.
| Organisation size | Reported annual waste on unused SaaS licences |
|---|---|
| 1–500 employees | $3.8M |
| 501–2,500 employees | $9.5M |
| 2,501–10,000 employees | $29.8M |
| 10,001+ employees | $80.6M |
For AI specifically the licence line is the smaller half. Three other costs sit behind it:
The data cost. Roughly half of employee AI users have already put financial, sales, customer or copyrighted material into public tools. Every month your sanctioned path does not carry that work, that exposure continues, and it is not recoverable retrospectively.
The evidence cost. Auditors and regulators increasingly ask what your systems did, not what your policy said. NIST's AI Risk Management Framework, released in January 2023 and currently under revision, organises AI risk work around GOVERN, MAP, MEASURE and MANAGE, all four of which assume you can observe the system in operation. Work done on personal accounts produces no record you can hand anyone.
The duplication cost. Teams that cannot find an approved way to do a job build their own. The same summarisation workflow gets rebuilt four times in four departments, on four tools, with four different data paths, and none of them survive the person who built them leaving.
Against those, the rollout itself is not the expensive part. The expensive part is running an unmeasured AI estate for another year and then discovering its shape during an incident. On the broader question of what enterprise AI actually costs once you look past the licence, we have a separate analysis of the costs beyond the licence line.
Where adoption and governance become the same job
Everything above converges on one point: for AI tools, adoption and governance are not sequential phases; they are the same programme viewed from two seats. The thing that makes staff willing to switch — a fast, capable, approved path with clear rules, is the same thing that gives IT and compliance a defensible record. Sanctioned share is simultaneously an adoption metric and a control metric.
That convergence is what our platform is built around: one controlled layer that every AI tool, connector, model and agent points at, so identity, policy, routing, cost and audit are applied on the request path rather than reconstructed afterwards. It is the mechanism that makes sanctioned share measurable in the first place — you cannot compute a ratio when half the numerator is invisible. Our own deployment sequence follows the same logic as this guide's first move: observe first, enforce second, optimize third, starting with one team's traffic in observe mode. To be clear about the boundary, LeapForce is not a digital adoption platform and does not replace in-app guidance, training content or change management, those remain yours to run.
Where this is still uncertain
Several parts of this guide rest on thinner ground than the rest, and it is worth naming them rather than letting confident prose imply otherwise.
The 80% sanctioned-share target is a judgment, not a finding. We chose it as a defensible first target because it leaves room for legitimate edge cases while being high enough to matter. No published study we could reach establishes a threshold at which residual unsanctioned use stops being material. If your regulatory exposure is high, the honest target is higher.
Adoption timelines have no credible universal benchmark. Articles on this topic frequently state a four-to-eight-week window for full adoption. We could not locate a primary source behind any such figure, and we are not going to invent one. What we can say is that our four moves have exit conditions rather than durations, which is the more useful shape when your baseline is unknown.
Self-reported survey data understates the behaviour it measures. The KPMG and University of Melbourne report itself discusses social desirability bias. When roughly half of respondents admit to policy-contravening AI use, the true figure is plausibly higher, not lower. Treat those numbers as floors.
Several expected sources were unreachable. Gartner's press releases returned 403 to every fetch method we tried, and the MIT NANDA State of AI in Business PDF — widely quoted for its shadow-AI findings, was also blocked, so we have excluded both rather than cite them second-hand. Their absence is why the shadow-AI evidence here leans on the KPMG and Gallup datasets we could read directly.
Sanctioned share is harder to measure in some estates than others. Fully remote workforces on unmanaged devices, contractors on their own hardware, and AI features embedded inside third-party SaaS are all places where the denominator gets fuzzy. In those environments the metric is directional rather than exact, and the honest reporting line is a range with a stated blind spot.
This guide assumes you want a sanctioned path at all. For a very small organisation with no regulated data and no audit obligation, the overhead of this programme may exceed the risk it removes. The point at which it flips is somewhere around the first customer contract with a data-handling clause in it, but we cannot give you a headcount number for that, and anyone who does is guessing.
Frequently asked questions
The first honest signal arrives at the end of the Count phase, in two to three weeks: a baseline sanctioned share and a ranked job list. Meaningful movement in that share follows the cohort schedule, so a four-cohort rollout in a mid-sized organisation typically has its first cohort fully migrated somewhere between weeks nine and eleven. Beware the widely repeated "four to eight weeks to full adoption" claim — we could not find a primary source for it, and the number that matters is your exit condition, not a calendar.
Onboarding is the process of getting someone set up and productive on a tool: access, orientation, first successful task. Adoption is the durable outcome: the tool is where that job now happens, by default, without prompting. Onboarding is something you do to a person once. Adoption is a state you have to hold, and for AI tools specifically it can be lost the month a better consumer model ships.
Traditional adoption metrics assume the only way to do the job is your tool, so counting active users approximates the truth. AI breaks that assumption: an alternative is one browser tab away and often free. So the AI metric needs a denominator covering all AI work, not just yours. Sanctioned share — approved-path requests divided by all detectable AI requests, is the version we would defend, supported by residual unsanctioned traffic per 100 staff and by job coverage against the list you built in the Count phase.
We would not answer this in active-user terms at all, because it is the question that produces the 100%-installed press release. Set targets on sanctioned share by cohort instead: baseline at day zero, first cohort above 80% by roughly week nine, and every cohort above 80% before you close its old path. If a governance body insists on user-count targets, pair every one with the residual unsanctioned traffic figure so the two cannot diverge unnoticed.
Because completing a course measures attendance, not capability, and for AI tools the binding constraint usually is not skill at all. Gallup's February 2026 survey found 43% of non-users cited data privacy, security and compliance concerns, and 88% of employees who strongly agreed AI fits their existing systems used it frequently against 55% who did not. A course fixes neither workflow fit nor a governance worry. Time to first useful output is the better proxy, because it measures whether someone got a result they kept.
You need a named owner with budget authority; whether that is a full-time role depends on scale. Below roughly 500 staff, a part-time owner with a platform engineer and a compliance contact is usually enough. Above that, the coordination load across cohorts, connectors and vetting requests justifies a dedicated person. What does not work at any size is a committee without a decision-maker — Microsoft's 2026 index found only 26% of AI users say leadership is clearly and consistently aligned on AI, and that ambiguity is what a single owner exists to absorb.
Separate the two resistances, because they have opposite fixes. Resistance to AI in general shows up as ethical or job-security objections; Gallup found 43% of non-users ethically opposed and 46% preferring their current methods, and that conversation is a leadership one, not a rollout one. Resistance to your tool while people happily use another one is not resistance at all; it is a product verdict. Run the Match step, find which of the four gap causes applies, and fix that.
Not as an opening move. In the KPMG and University of Melbourne study, 67% of AI-using employees at organisations that had banned generative AI reported using AI in ways that contravened policy, against 33% at organisations with no such policies — the highest violation rate sat with the strictest regime. Close the old path per cohort, after the sanctioned path has carried that cohort's work for two weeks. A ban is the last step of a migration, not the first step of a policy.
Bring three numbers to the renewal: cost per genuinely active user per month, job coverage against the Count-phase list, and residual unsanctioned traffic. The first tells you whether you are paying for seats nobody uses, Zylo's 2026 index reports organisations using only 54% of their SaaS licences. The second tells you whether the tool covers the work it was bought for. The third tells you whether people are still routing around it, which is the strongest argument for switching vendors that exists. Note what is deliberately absent: a headline ROI percentage. Estimated ROI on an AI rollout is mostly a function of the assumptions you chose, and a renewal committee that has seen two of them stops believing the third. Job coverage and residual traffic are observable; a projected return is not.
One accountable owner, most often in IT or a platform function, with standing seats for security, legal or compliance, and the business unit whose jobs are being migrated. Security should not own it, because a security-owned programme optimises for restriction and lands on the ban that the data says backfires. The business should not own it alone either, because the identity, logging and data-handling work is invisible to them until it is missing.
Three cost lines: platform and model consumption, which is the one that grows with success and needs headroom; people time for the owner, the head-to-head testing and the cohort migrations, concentrated in weeks one to fifteen; and the connector and logging engineering, which is largely one-off. Model the consumption line against your target sanctioned share rather than today's usage — the most common budgeting error here is pricing the rollout at current volumes and then rationing when it works.
If you are a provider or deployer of AI systems in scope, Article 4 has applied since 2 February 2025 and requires you to take measures to ensure a sufficient level of AI literacy among your staff and others operating AI systems on your behalf, taking account of their technical knowledge, experience, education and the context of use. It does not prescribe a curriculum or a certificate. Practically, that means AI-literacy training belongs in your rollout plan as an obligation with a record, not as an optional enablement track.
Ready to Govern Your AI?
Talk to LeapForce, one controlled layer for every AI tool, connector, model, and agent.
Comments