back_to_insights

// IN THE PRESS · AI READINESS

The growing risks of DIY AI

Shadow AI is appearing faster than organisations can govern it. A five-step framework for assessing whether you are actually ready.

Over the past few years, AI has moved from something that technical teams experiment with to an everyday workplace tool. Not only are many employees using generative AI tools to support their day-to-day output — developers, product teams and even entire business units are increasingly building their own AI tools using publicly available models and low-code platforms.

While this democratisation of AI has accelerated take-up and innovation, it has also created a new challenge: DIY AI systems are appearing faster than organisations can properly govern them. Recent Microsoft research revealed that over half of UK employees use unapproved AI tools at work every week.

This means AI tools are now being used in workplaces around the world with zero formal guidance or oversight. Without strong foundations in data quality, infrastructure, security and governance, these tools can quickly introduce operational risks — from unreliable outputs and fragile production systems to uncontrolled compute costs and exposure to sensitive data leaks and security breaches.

// THE PROBLEMThe AI gap

This growing prevalence of shadow AI means many organisations are now inadvertently running a vast, decentralised AI experiment without the proper foundations in place to support it. While executives are still in the boardroom debating organisational AI strategy, employees are already integrating these technologies into their day-to-day work.

This non-governed experimentation is also often the starting point of a cycle that eventually leads organisations into ‘pilot purgatory’ — endless experimentation without any meaningful deployment. Research from Gartner found that 30% of AI projects don't progress beyond proof of concept.

"The biggest AI challenge organisations face isn't access to the technology — it's operational readiness."

In this purgatory, projects that initially show promise can't move into widescale adoption because the underlying conditions needed for scale — reliable data, security controls, governance frameworks and clear ownership — weren't set up in the first place.

// THE FRAMEWORKA 5-step readiness framework

To avoid pilot purgatory, before they even start playing around with AI and allocating budget to it, organisations should first assess their readiness across five core areas.

01Data maturity

AI systems are only as good as the data behind them, and many projects fail due to a lack of usable, well-instrumented, labelled or representative data. There is a notable confidence gap here: while the majority of business leaders believe their data ecosystem is ready to deploy AI at scale, few technologists report confidence in their organisation's data readiness, controls and quality.

Assessing data quality should be the first step. Organisations should be working out:

  • Whether their data is accurate, structured and accessible
  • Whether there's enough historical data to train useful models
  • Whether data pipelines are reliable and updated regularly

02Security and regulatory compliance

While many AI initiatives can appear promising during early trials, they often stall when organisations realise they cannot meet the security, legal or regulatory standards needed to run them at scale. For organisations that want to deploy AI more formally, security teams typically need to ensure that systems meet internal standards around data protection, identity management, system monitoring and model access.

That can involve questions such as where data is stored, how models are trained, who can access outputs, and how AI systems interact with core business infrastructure. If these controls are not designed early on, even the most promising pilots often can't progress.

03Engineering and deployment capability

Building an AI model is relatively easy in the grand scheme of things — it's running it reliably inside an organisation that tends to be hard. To run reliably, AI systems require a robust engineering backbone: good data pipelines, models that integrate easily into existing systems and workflows, and monitoring that tracks performance once models are live, tweaking things where necessary.

04Appropriate governance

Governance holds an entire AI programme together — policies, principles and guardrails are needed to enable safe, compliant AI use across the enterprise. However, the increasing use of shadow AI means being able to govern systems properly is becoming increasingly difficult. In the simplest form, organisations need to be asking themselves a set of fundamental questions: who is responsible for AI, what rules does it need to operate within, and how should it be monitored over time, from both a risk and a quality perspective?

// WHY NOW

With regulatory frameworks such as the EU AI Act increasing expectations around data governance, risk management and human oversight — and therefore making informal AI experimentation a bigger risk — it's more important than ever that organisations get this right.

05Workforce skills and adoption

Skills gaps, siloed teams, poor stakeholder communication and change management issues can all impact the effectiveness of AI programmes and lead to stalled projects. Almost every organisation currently using AI is dealing with some form of skills gap. Government research revealed that 97% of companies report at least one skills gap, while lack of expertise is cited as the top barrier to AI adoption among UK businesses. It's safe to say that AI adoption is now happening faster than sufficient skills are coming into the workforce.

So organisations need to look realistically at the skills they have, and not bite off more than they can chew. Many would be better starting small and growing the scale of projects as AI resource improves.

// THE POINTSetting up for success

Many companies are running before they can walk when it comes to AI. The technology itself is rarely the problem — the failure to set up robust enterprise infrastructure is. Ultimately, overlooking the right foundations puts organisations at risk of significant reputational damage, regulatory non-compliance and strategic missteps.

AI has the potential to deliver genuine business value. But for that to happen, the foundations need to be in place to enable organisations to adopt it securely, at scale, and in compliance with emerging regulation. The organisations that do this will be less likely to end up in pilot purgatory, or to waste money on AI programmes before they are really ready.

This article first featured in AI Journal.

// PRODUCT · AXIOINTELLIGENCE

Turning AI into competitive advantage.

The five areas in this article are exactly what AxioIntelligence assesses. A focused engagement that benchmarks your readiness across data, security, engineering, governance and workforce — then gives you a phased roadmap to scale safely.

WHAT YOU GET

01
AI readiness report

Your current adoption against our industry benchmark.

02
Opportunity map

Where AI delivers highest value, aligned to your objectives.

03
Governance framework

Policies, principles and guardrails for safe, compliant use.

04
Transformation roadmap

Phased plan: quick wins, foundations, then enterprise scale.