An effective AI rollout gives employees clear direction, approved tools, role-specific guidance, and a safe way to share what they learn. However, when AI use stays hidden, leaders should investigate gaps in trust, workflow fit, and policy clarity while enforcing data protections. Measure changes in work quality and cycle time, not just logins.
Here's a number worth considering: 61% of surveyed employees who use AI at work said they had avoided revealing that use at least rarely. That's from the University of Melbourne and KPMG's 2025 global study. The wider survey included 48,340 people across 47 countries and jurisdictions. The finding is a warning about visibility, not a headcount of hidden AI users at your company.
The instinct for most leaders when they hear this? Tighten up. Write a policy. Add it to the employee handbook. Make it clear that AI use needs to be disclosed.
That instinct is understandable, but tighter rules alone won't solve it.
The KPMG finding isn't proof that your people have an honesty problem, and it doesn't prove a single cause for hidden AI use. My view is that leaders should investigate alignment before defaulting to discipline. People may be unsure where AI adds value or whether their experiments line up with what leadership wants. So they stay quiet. They experiment privately. They get results they can't explain, from tools they weren't officially given.
That's not a discipline failure. It's what happens when you launch a capability without a shared framework for what success looks like.
What Is the AI Adoption Gap?
The AI adoption gap is the difference between the AI use an organization expects or measures and the AI use happening in employees' work. It includes approved tools that go unused, useful experiments that stay invisible, and workarounds that introduce risks leadership cannot see.
Most organizations have framed AI adoption as a technology deployment. Buy the licenses, roll out the tools, track the logins and token use, but access and adoption are not the same thing, and the data makes that gap impossible to ignore.
Deloitte's 2026 State of AI in the Enterprise research, based on 3,235 business and IT leaders across 24 countries, reported that around 60% of workers in surveyed organizations had access to sanctioned AI tools. Yet only 30% of organizations were redesigning key processes around AI. These are different measures, not a calculation of an adoption rate. They underline the distinction between providing access and changing how work gets done.
And here's the part that makes the visibility problem harder to ignore: in the KPMG study, 56% of surveyed employees who use AI at work said they had used it without knowing whether it was allowed, at least rarely. That does not establish whether their employer lacked a policy or failed to communicate one. It does show why leaders need to check what employees understand, rather than assuming a policy document has settled the question.
The real gap isn't between employees who use AI and employees who don't. It's between what's actually happening and what leadership can see.
Shadow AI is the use of AI tools or accounts outside an organization's approved processes or visibility. Not all undisclosed AI use involves an unapproved tool, but both situations can create gaps in oversight.

The AI adoption gap: the difference between leadership expectations and everyday behavior is a signal about rollout design.
Why Do Employees Experiment with AI Privately?
There's another layer to this worth naming. People may keep AI use private because they're worried about getting in trouble. Others may still be figuring out whether what they're doing even matters. The survey doesn't tell you which explanation applies to your team.
This is an important distinction. Using AI to reformat a spreadsheet or draft a quick email is easy to measure. Using AI to genuinely change how work gets done, to find leverage in a process that used to take days, to unlock something that wasn't possible before? That's harder to articulate. And if you can't articulate it, you're not going to raise your hand and say "hey, I've been experimenting with this."
The challenge employees face isn't just autonomy. It's a lack of alignment. They want to know whether the way they're using AI lines up with where the organization is trying to go. Without clear alignment signals, they default to private experimentation. Which means the organization loses the learning and context.
Who Should Own AI Adoption and Governance?
Assign an accountable executive sponsor for AI direction and outcomes, supported by business-process owners, IT or security, and the people responsible for employee enablement. A small company may combine these responsibilities. The important point is that decisions, data boundaries, and escalation paths have named owners.
This is the question underneath all of it, and most organizations haven't answered it clearly: who has authority around AI? Who sets the direction? Who owns the outcome when something goes wrong?
In the absence of a clear answer, everyone fills in the blank themselves. And they fill it in differently.
That's not a failure of leadership. It's a predictable result of how fast this technology moved into the workplace. But it creates a real problem: you can't build shared accountability for something when no one agrees on who's accountable.
The authority question matters for a few reasons:
Direction-setting: Without someone owning the "where are we going with AI" question, teams optimize for their own local problems. That's not inherently bad, but it means the organization doesn't accumulate learning in any coherent way.
Risk ownership: In the same KPMG study, 48% of surveyed employees who use AI at work reported uploading company information into a public AI tool at least rarely. Someone needs to own the data boundaries, approved-tool decisions, and response to an exposure.
Outcome measurement: You can't improve what you're not measuring. And you can't measure AI outcomes if there's no agreed-upon definition of what a good outcome looks like.
The answer doesn't have to be a formal AI governance committee with a charter and quarterly reviews. For most small and mid-market companies, that level of structure would be overkill. But someone needs to hold the question. Someone needs to be the person other people can orient toward when they're trying to figure out whether what they're doing makes sense.
Without that, you get the pattern that's showing up everywhere right now: usage that's real but invisible, experimentation that's valuable but isolated, and a leadership team that's either overestimating or underestimating what's actually happening on the ground.
Why Is AI Adoption Uneven Across Teams?
Here's something most AI rollout plans get wrong from the start: they assume a level of consistency that was never going to happen.
The org chart suggests a kind of symmetry. Everyone in the same department, using the same tools, under the same manager, moving at roughly the same pace. That's not how AI adoption actually works. Not even close.
What you're more likely to see looks something like this:
One team moves fast on using AI for drafting and internal documentation, but refuses to let it anywhere near anything customer-facing.
One person uses AI extensively and tells no one, quietly finding faster ways to complete parts of their work.
An entire function looks like it's lagging on your usage dashboard while doing its best work of the year through a personal account that IT can't see.
Uneven adoption is not automatically a compliance failure, but using unauthorized tools or exposing confidential data can be. Leaders need to distinguish variation in how people learn from actual policy violations, then address both workflow fit and risk.
Adoption being uneven isn't a sign that your rollout failed. It's a sign that your rollout is normal.
The question isn't how to make adoption uniform. That's a fantasy. The question is how to make the unevenness visible, so you can learn from the parts that are working and support the parts that aren't.
Four AI Adoption Personas and What They Need
One reason a single rollout strategy rarely works is that your workforce isn't a single type of person. The following four personas are a practical planning framework, not categories measured by the studies cited here:
On smaller screens, swipe across the table to read all columns.
Persona | Behavior | What They Need |
|---|---|---|
The early adopter | Already using AI extensively, often outside official channels | Recognition, structure, a way to share what's working |
The cautious experimenter | Curious but uncertain about where AI fits their work | Clear use cases, permission to try, low-stakes starting points |
The passive observer | Has access, rarely uses it, waiting for a reason | Concrete examples from peers, visible wins nearby |
The skeptic | Doubts the value or worries about the implications | Direct engagement, honest conversation about risks and limits |
The same data-protection rules should apply to everyone. What changes is the support. A training program designed for the passive observer won't challenge the person who's already three steps ahead. Designing your rollout as if everyone needs the same guidance is how you end up with a lot of activity and not much to show for it.
How Can Leaders Make Hidden AI Use Visible?
When reported AI usage doesn't match what's actually happening, most leaders treat that as a problem. They want to close the gap, usually by pushing for more disclosure or tightening the rules.
Here's a different way to look at it: the gap is data.
If a team's usage dashboard looks flat but their output quality has quietly improved, that tells you something. If someone is running everything through AI and not mentioning it, that tells you something too. If an entire function hasn't touched the sanctioned tool but is clearly finding leverage somewhere, that's worth understanding rather than penalizing.
The gap between reported usage and real usage is a signal about where your rollout may not be working. It can reflect uncertainty, fear of judgment, workflow mismatch, or deliberate rule-breaking. Don't assume which one. When you treat the gap as information, you start asking different questions:
Where is real usage happening that we can't see?
What's driving the silence? Fear of judgment? Uncertainty about policy? A lack of context for what "good use" looks like?
Where are people getting genuine value, and how do we surface that so others can learn from it?
This reframe matters because it changes what you do next. Alongside clear rules, you create the conditions for transparency. Instead of measuring only logins, you look for outcomes. Instead of assuming the quiet teams are behind, you investigate whether they're finding value elsewhere.
Five Principles for a Human-Centered AI Rollout
A rollout designed for how people actually behave looks different from the standard playbook. It starts with a few honest assumptions:
Unevenness is the default. Some people will move fast. Some won't move at all yet. Both are fine, as long as you're paying attention to why.
The gap between reported and real usage is diagnostic information. Investigate what it reveals about alignment and workflow fit, while addressing unsafe or unauthorized use.
Autonomy and guidance aren't opposites. People want room to experiment. They also want to know if what they're doing matters. You can give them both.
The org chart won't predict who leads. Your most valuable AI insights might come from someone three levels down who's been quietly solving a problem for six months. Build ways to find that.
Policy without context doesn't work. Rules about AI use only land when people understand the "why" behind them. Without context, they just become another thing to work around.
The plan that assumes everyone will behave the same way is the plan that misses. Not because people are difficult, but because that's not how new capabilities spread through organizations. They spread unevenly, through early adopters and informal networks, through personal experimentation and peer observation, through trial and error that rarely shows up in a usage report.
How to Design an AI Rollout That Works
The rollout worth building combines clear boundaries with room to learn. Strict policies alone cannot tell you where employees are getting value, what they are struggling with, or which workflows need redesign. Leadership needs to pay attention to the work, not just the dashboard.
That means a few things in practice.
1. Name an owner and define the outcome
Not every decision, not every tool choice, but the "where are we going with this and why" question. Without that, you get a hundred individual experiments with no shared learning.
2. Make responsible experimentation safe and useful
Give people a low-friction way to share approved experiments, ask questions, and report mistakes. Explain which tools and data are allowed, where human review is required, and what happens when someone discloses a problem. Sharing needs to feel safe and useful, without waiving security or compliance obligations.
3. Measure outcomes alongside adoption
Logins and token counts can help track access, cost, and usage, but they do not establish business value. Compare the same workflow before and after an AI change, using a consistent definition of quality. Review gains alongside error rates, rework, and data-handling risks.
4. Tailor support to roles and readiness
Don't design for the average employee. Design for a range of people at different stages, with different comfort levels, different use cases, and different definitions of value. Give them all a way to participate that makes sense for where they are.
The KPMG finding is a signal, not a diagnosis of your team. It is a reason to investigate what people need to use AI openly and responsibly. The right response isn't simply to make them feel worse about it. It's to make expectations clear, protect sensitive information, and understand what's getting in the way.
That's the rollout worth building.

Steps of AI Adoption: AI Adoption is about designing based on how people work. Never lead with technology first.
How Should You Measure AI Rollout Success?
Choose measures for a specific workflow before expanding access. The examples below are a measurement framework, not reported results or promised improvements.
On smaller screens, swipe across the table to read all columns.
Measure | What to compare | Quality or risk check |
|---|---|---|
Cycle time | Time to complete the same type of task before and after AI assistance | Include human review and correction time |
Output quality | Work accepted without revision against the same rubric | Track errors, omissions, and rework |
Business outcome | The workflow outcome, such as resolved requests or completed proposals | Do not attribute every change to AI without considering other factors |
Responsible use | Use of approved tools and completion of required reviews | Track data-handling incidents and unresolved exceptions |
Frequently Asked Questions About AI Rollouts
What is the difference between AI access and AI adoption?
AI access means employees can use a tool. AI adoption means the tool is used appropriately in real work. A rollout should evaluate workflow fit, output quality, and business outcomes alongside usage, rather than treating a license or login as evidence that the organization is getting value.
Should companies require employees to disclose AI use?
Companies should define when disclosure is required, particularly for sensitive data, customer-facing work, and decisions that need human review. Explain what must be reported, to whom, and why. Clear disclosure rules work best alongside approved tools, practical examples, and a safe way to ask questions or report mistakes.
How can a small or mid-market company start an AI rollout?
Start with one defined workflow, a named owner, approved tools, and clear data boundaries. Record a baseline for speed and quality, give employees role-specific guidance, and review results together. Expand only after the workflow shows useful outcomes and its risks are understood.
How should leaders support employees who are skeptical of AI?
Ask what drives the skepticism: workflow relevance, output accuracy, data privacy, or concern about roles and skills. Use concrete peer examples, low-risk practice, and honest discussion of limitations. Keep human judgment and data-protection expectations explicit rather than treating skepticism as a lack of discipline.
Put the Rollout Into Practice
For the broader foundation, read what AI enablement means and the phases of AI adoption. If your team needs help connecting direction, governance, and everyday work, explore OneSpring's AI enablement services.
Sources and Research Notes
University of Melbourne and KPMG: Trust, attitudes and use of artificial intelligence: A global study 2025. Survey of 48,340 people across 47 countries and jurisdictions. The workplace-behavior figures above concern surveyed employees who use AI at work. Figure 44, printed page 76 (PDF page 78), separates “rarely” from “sometimes to very often”; the figures quoted here include both.
Deloitte: The State of AI in the Enterprise, 2026. Survey of 3,235 business and IT leaders across 24 countries, conducted August–September 2025. The access and process-redesign figures describe the surveyed organizations, not all employers.
The rollout principles, personas, and measurement framework are practical recommendations. The studies document reported behavior and adoption patterns; they do not establish one cause for hidden AI use.

