The AI You Never Deployed Is Already at Work in Your Organisation: Governing Default Adoption
TokenShift Executive Note

As the new term begins, your teams are reopening overflowing inboxes and Slack channels that have been active all summer. An AI summary button is waiting for them, already enabled, in Gmail, Outlook and Slack. No one in your organisation approved this rollout in committee; yet it has happened. This is default adoption, and it has become the main route by which AI enters the enterprise.
Default adoption, the third route for AI to enter the enterprise
Executive teams traditionally manage two adoption paths: enterprise projects (use cases, POCs, tool-enabled deployments) and sponsored business-function initiatives. A third path has emerged without them, through two channels.
The first channel is software vendors. On 8 January 2026, Google announced Gemini integration in Gmail for its more than 3 billion users: automatic conversation-thread summaries, an AI-prioritised inbox and writing assistance. The critical point: some of these features are enabled by default, and users must opt out if they do not want them (Google, CNBC, January 2026). Microsoft follows the same approach with Copilot in Outlook (thread summaries, priority sorting), while Slack offers channel summaries and natural-language search. Your employees no longer adopt AI; they return from holiday to find it switched on.
The second channel is employees themselves. According to the Microsoft and LinkedIn Work Trend Index (2024), 75% of knowledge workers already use generative AI at work, and 78% of users bring their own tools without employer approval. The same study found that 60% of leaders believe their organisation lacks a deployment vision. In other words: usage is widespread, while oversight remains limited.
The implication is structural: your AI exposure no longer depends on your roadmap. It depends on vendors’ release cadence and your teams’ habits.
What the AI Act timetable changes this autumn
On 2 August 2026, the AI Act’s transparency obligations (Article 50) became applicable and enforceable: informing people when they interact with AI, labelling generated content and disclosing deepfakes, with a grace period until 2 December 2026 for systems already on the market (European Commission; Norton Rose Fulbright analysis, July 2026).
At the same time, the European digital omnibus package (EU Regulation 2026/1744, which entered into force in late July 2026) postponed obligations relating to high-risk systems: until 2 December 2027 for standalone Annex III systems, and until 2 August 2028 for AI embedded in regulated products (Gibson Dunn, 2026).
The interpretive trap would be to focus only on the postponement. Three sets of requirements already apply: prohibited practices (including emotion recognition in the workplace) and the obligation to ensure staff AI literacy, since 2 February 2025; and transparency, since 2 August 2026. Article 99 penalties are calibrated accordingly: up to €35 million or 7% of worldwide turnover for prohibited practices, and up to €15 million or 3% for most other infringements, including transparency. The GDPR, meanwhile, has never ceased to apply to data flowing through these tools.
Default adoption does not wait for your compliance deadlines: today, it already creates data processing activities and AI interactions covered by these rules.
An ordinary Monday after the summer break
On Monday morning, a relationship manager at a regional bank returns from three weeks of holiday to find 600 messages. The AI summary feature in her corporate email, covered by the vendor contract, saves her an hour; so far, so good. Then, to speed up work on a sensitive complaint, she pastes the full history of the customer exchange into the consumer AI tool she uses personally—the one she knows best.
The result: customer data on a service with no contract, no logging and no trace in the incident register. The 2024 IT policy does not mention this situation. No one has acted wrongly under the existing rules; the rules themselves have a blind spot. Multiply this scenario by the number of employees returning this week: that is the real surface area of your exposure.
Taking back control: a five-step approach
- Inventory what is already running. On the vendor side: extract from administration consoles (Google Workspace, Microsoft 365, Slack) the list of enabled AI features, by user group. On the employee side: conduct a self-reporting survey that is explicitly non-punitive, because you need the truth, not a reassuring number.
- Decide feature by feature. For every identified feature: allow, govern or disable it. Each business domain (customer relations, HR, finance) has a named owner who decides jointly with IT and legal or the DPO, within a maximum timeframe set between vendor activation and the internal decision.
- Document controls where data are sensitive. Customer data, HR data, trade secrets: controls must live in configuration (DLP rules, data scopes, logging), not in a signed PDF. This is also the moment to verify that the information required by Article 50 is provided when AI interacts with, or generates content for, third parties.
- Turn successful individual uses into redesigned processes. Asking AI a question does not complete the work end to end: inbox triage, customer summarisation and monitoring become explicit workflows, with rules, responsibilities and measured gains. This is where value is created: according to McKinsey (The State of AI, November 2025), 88% of organisations use AI, but only around one third have deployed it at scale, and barely 6% achieve a significant impact on operating results.
- Establish a quarterly executive-committee review. The agenda should cover: new features enabled by vendors, declared uses, incidents, decisions made and decisions pending. Default adoption is a continuous flow; governance must be continuous too.
Mistakes to avoid
- A blanket ban. Prohibition drives usage underground: BYOAI continues, but without visibility or control. You lose information without reducing risk.
- Treating postponement as a pause. Confusing the postponement of high-risk obligations (2027–2028) with requirements already in force (prohibitions, training, transparency) creates exposure to immediate penalties.
- Leaving governance to IT alone. Without a business owner, decisions always arrive after vendor activations, and trade-offs remain technical when they are operational and legal.
- Retrofitting controls. Documenting after the fact what has been running for six months costs more and provides less protection than integrating controls at the point of each activation.
- Mistaking a policy for a control. A signed policy detects nothing and prevents nothing; only configuration, logging and measurement count in an audit.
Indicators that control has genuinely been regained
You will know the approach is working when you can demonstrate, with data: 100% of AI features in office suites covered by an explicit, dated decision; a median time between vendor activation and internal decision of less than 30 days; an increase in declarations of personal use in the first quarter (a sign that people can speak freely), followed by a measurable shift towards provided tools; zero customer data detected outside the contractual perimeter during DLP testing; a growing share of redesigned processes with gains documented in hours or processing time; an up-to-date Article 50 transparency register.
Where to start this week
Three actions fit within the next ten days: ask IT for an extract of AI features enabled by default in your office suites; appoint the single owner of the topic, with decision-making authority; add default adoption to the agenda of the next executive committee, with one decision per feature—not an information update. A company that discovers its AI uses in an audit discovers them too late.
TokenShift supports executive teams in regulated European companies as they move AI from pilot projects to governed production.
Sources
- Google, “Gmail is entering the Gemini era”, January 2026: https://blog.google/products-and-platforms/products/gmail/gmail-is-entering-the-gemini-era/
- CNBC, “Google is unleashing Gemini AI features on Gmail. Users will have to opt out”, January 2026: https://www.cnbc.com/2026/01/08/google-adds-gemini-features-to-gmail-message-summaries-proofreading-.html
- Microsoft and LinkedIn, Work Trend Index 2024: https://news.microsoft.com/source/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/
- McKinsey, The State of AI, November 2025: https://www.mckinsey.com/capabilities/operations/our-insights/the-state-of-ai
- Norton Rose Fulbright, Data Protection Report, “The EU AI Act: when does it become enforceable now?”, July 2026: https://www.dataprotectionreport.com/2026/07/the-eu-ai-act-when-does-it-become-enforceable-now/
- Gibson Dunn, “EU AI Act Omnibus Agreement”, 2026: https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- AI Act, Article 99 (penalties): https://artificialintelligenceact.eu/article/99/ ; Article 50 (transparency): https://artificialintelligenceact.eu/transparency-rules-article-50/