AI Academy · Book
Executives & Directors · Module 01 · Chapter 008

AI Is Already Inside Your Organization

Many organizations start their AI program in the middle, not at the beginning. AI already runs inside software they bought, in tools they licensed and in tools their people brought themselves. The first leadership task is to see it and give it owners; buying comes after.

≈ 17 min read

After this chapter you can

  • Recognize that AI use usually begins long before a formal AI strategy or program.
  • Distinguish the visible AI people talk to from the embedded AI that ranks, scores, forecasts and routes.
  • Sort the AI already in use into three buckets - embedded, official and informal.
  • Explain why AI now arrives by software update and why first counts of AI use run low.
  • Expect a named internal owner for every system that shapes customers, money or people, including bought ones.

Picture an ordinary Monday in an organization much like yours. At six in the morning the email filter quarantines a phishing message before anyone is awake. At half past seven the planning system refreshes the demand forecast that will drive this week’s orders. At a quarter past eight the recruiting platform ranks the people who applied overnight. At twenty to nine a manager drafts a client proposal in a personal AI account, because it is quicker than the approved route. At nine the leadership team meets and agrees that it is time to start with AI.

Before leaders agree at nine to start with AI, AI has already blocked phishing, updated a forecast, ranked applicants and drafted a proposal.06:00Email filterBlocks phishing07:30PlanningsystemUpdates forecast08:15Recruiting toolRanks applicants08:40Personal AIaccountDrafts a proposal09:00LeadershipAgrees to startwith AI
Figure 1.8.1 An illustrative morning. By the time leaders agree to start, four AI systems have already done a day’s first work.

The morning is invented, but nothing in it is unusual. The point is the order of events. In many organizations the AI program began years before the meeting that announced it. Nobody called it a program, because nobody had to approve it as one.

Three ways AI gets in

The argument of this chapter fits in one sentence. Your AI transformation may have started before your organization called it one, so the first leadership question is not what to buy but what is already running, and who answers for it.

AI reaches an organization through three routes, and it helps to name them, because each one hides in a different place.

AI arrives in three buckets - embedded in software bought for other reasons, official tools licensed as AI, and informal tools employees bring - and only the official bucket reliably has a named owner.BucketHow it arrivedWho usually knowsNamed ownerEmbeddedInside software bought foranother reasonBuying teamOften not for the AI partOfficialLicensed as AI,through procurementIT and leadershipInformalBrought in by employeesThe user
Figure 1.8.2 Three buckets of AI. Leadership usually sees the official one; the embedded and informal buckets hold the surprises.

Embedded AI arrived inside software the organization bought for another purpose: the planning system that forecasts, the security filter that scores messages, the routing engine that plans deliveries, the applicant-tracking system that ranks candidates. The team that bought the software knows it exists. Whether anyone owns the AI inside it is a separate question, and often the answer is no.

Official AI is what the organization licensed as AI: an enterprise assistant, a coding helper, a platform with a contract, an owner and a usage policy. This is the bucket leadership knows best, because it passed through procurement and usually through a board paper.

Informal AI is what employees brought themselves: personal accounts, browser extensions, a subscription paid on a departmental card. As The Speed of AI Adoption showed, this bucket is large. Among employees who use AI at work, about 70 percent rely on free public tools, against 42 percent who use tools their employer provides1.

Executive conversations tend to be about the official bucket. The other two are where surprises live.

Much of the AI at work never announces itself

Much of the AI inside an organization does not look like a conversation. It looks like a result. A shopper sees “you may also like” and never sees the model behind it. A cardholder sees a fraud alert, not the score that triggered it. A driver sees a route, not the prediction of traffic that produced it. A recruiter sees a ranked list of applicants and does not always see why one name is above another.

The AI people talk to is the small visible part; search ranking, recommendations, fraud scores, forecasts, routing and screening already work quietly underneath.WHAT PEOPLE SEE AND TALK TOAssistants · Drafting helpersWHAT ALREADY WORKS QUIETLYSearch rankingRecommendationsFraud scoresDemand forecastsRoute planningApplicant screening
Figure 1.8.3 The assistants people talk to are the visible part. Much of the AI that shapes money and customers works out of sight.

This quiet layer is not new. Ranking, scoring, forecasting and routing have been built into enterprise software for years, usually without the label. Mature technology disappears into the products that use it, which is a blind spot. A leadership team whose picture of AI contains only assistants is looking at the newest and most visible part, and missing much of the AI that already makes decisions.

AI now arrives by software update

The embedded bucket is growing for a simple reason: software vendors are adding AI to the products their customers already use. In 2024 Gartner told finance leaders it expected about 80 percent of independent software vendors to have embedded generative AI in their enterprise applications by 2026, up from less than 1 percent in 20232. That is a forecast for this year, not a count, but it shows where vendors said they were heading.

Gartner expected the share of software vendors with generative AI embedded in enterprise applications to rise from under 1 percent in 2023 to about 80 percent by 2026.<1%Software vendors in 2023With generative AI embedded in enterprise apps80%Expected by 2026A forecast, across 13 application marketsSource: Gartner, reported by Accounting Today · Sep 2024 forecast
Figure 1.8.4 AI increasingly arrives as a feature in software you already pay for, not as a new purchase.

When AI arrives this way there is no purchase order, no business case and often no announcement beyond release notes. The organization does not decide to adopt it; it finds that it has.

Customers of the workplace messaging service Slack found this out in May 2024. A widely shared post pointed out that Slack’s privacy principles said its systems analyzed customer data, including messages, content and files, to develop machine-learning models for features such as channel and emoji recommendations and search results. The use was on by default, and a workspace owner who wanted out had to email Slack to ask3. Slack responded that these were not generative models, that customer data was not used to train large language models, and it later explained that the models rely on derived signals rather than reading message content4.

The lesson of the episode is not that the vendor behaved badly. It is that many organizations had been running AI features in a tool they used every day without knowing it, and learned the terms from social media rather than from their own records. The question for any buyer of software is whether it finds out from its own review or from someone else’s post.

Even a mandated count keeps growing

If any organization should know where its AI is, it is one that is legally required to list it. Since an executive order of December 2020, US federal agencies have had to publish inventories of their AI use cases.

Reported AI use cases at US federal agencies rose from about 1,200 in GAO's 2023 review to 2,133 in the 2024 inventory and 3,611 in the 2025 inventory.2023 (GAO count,different basis)1,200 use cases2024 inventory2,133 use cases2025 inventory3,611 use casesSource: GAO; OMB federal AI use case inventories · 2023-2026
Figure 1.8.5 The more carefully the US government looked, the more AI it found. Part of the growth is new use; part is better counting.

In December 2023 the Government Accountability Office reviewed the inventories agencies had published. Twenty of 23 large agencies reported about 1,200 current and planned uses of AI, and three reported none. Only five of the twenty provided complete information; the other fifteen had incomplete or inaccurate entries5. The 2024 consolidated inventory listed 2,133 use cases from 41 agency submissions6. The 2025 inventory, published in 2026, listed 3,611 individually reported use cases at all stages of development. OMB counts submissions, not agencies: 41 submissions reported individual use cases, out of 56 in all, the rest filing only common commercial tools or confirming no AI use. It also added a separate, consolidated category for common tasks that rely on commercial off-the-shelf AI products, the embedded bucket by another name7.

Some of that growth is genuinely new use. Some is better counting under clearer rules, and the rules changed between rounds, so the years are not strictly comparable. Both readings carry the same message for a private organization with no legal duty to look. When people start counting seriously, the number goes up, and the first list is rarely the full one. The US National Institute of Standards and Technology makes the same point in its voluntary AI Risk Management Framework: one of its basic governance expectations is that mechanisms exist to inventory AI systems8. How to build that inventory is the work of AI Inventory and Risk Classification, in Module 07.

Unseen AI creates three problems at once

AI that leadership cannot see does not stop working. It keeps forecasting, ranking and drafting, and it leaves three problems behind.

Unseen AI creates three leadership problems at once - no map, duplicated spend and uneven rules.No mapNobody holds the full listDuplicated spendTwo tools bought for one jobUneven rulesOfficial tools have rules; the restmay not
Figure 1.8.6 Unseen AI is not idle. It keeps working while leadership lacks a map, pays twice and applies rules unevenly.

The first is no map. Different functions use different tools, and nobody holds the full list. When a board member asks where the organization uses AI, the honest answer is that nobody knows, and the federal experience suggests that even a careful first answer will be low.

The second is duplicated spend. Two departments buy two tools to summarize the same kind of document. Nobody compares their quality, and neither team learns from the other. The waste is small in any one case, large in total and invisible until someone looks across functions.

The third is uneven rules. Privacy, security, accuracy and accountability are handled differently in every corner. The official assistant has a policy; the personal account has none. The old fraud model has an owner and a review cycle; the ranking feature switched on in last quarter’s software update may have neither.

None of these is solved by buying another platform. A fourth tool does not fix an unseen third, and a strategy that ignores the systems already in production is a wish list.

Bought is not the same as owned

The most important consequence of embedded AI concerns accountability. Buying a system from a vendor does not move the responsibility for what it decides to the vendor. A forecast that sets staffing levels is a people-and-money decision. A model that ranks applicants is a fairness-and-law decision. Neither has to call itself AI to matter.

The clearest current illustration is a lawsuit, Mobley v. Workday, in federal court in California. A job applicant alleged that the AI screening tools in a widely used hiring platform rejected him for more than 100 jobs because of his age, race and disability. The vendor argued it was not the employer and made no hiring decisions. In July 2024 the judge allowed the case to proceed on the theory that the employers had delegated to the vendor’s tools their traditional function of rejecting candidates or advancing them to interview9. In May 2025 the court allowed applicants aged 40 and over to join as a nationwide collective10.

In June 2026 the court let most of the claims in an amended complaint go forward, and as of October 2026 the case was still in pretrial proceedings, with no finding of liability11. The claims are unproven, but the lesson does not depend on the outcome: the employers bought a hiring system, and AI inside it was shaping who got an interview. How many could have named the owner of that screening step?

When an embedded system makes a bad call, without a named owner the outcome is still yours, and with one someone acts by Monday; anything that shapes customers, money or people needs an owner.A bad call on FridayNo named ownerThe outcome is still yoursA named ownerSomeone acts by MondayNEEDS AN OWNER IF IT SHAPESCustomersMoneyPeople
Figure 1.8.7 Invisibility does not reduce accountability; it hides it. Anything that shapes customers, money or people needs a named owner.

A practical test is to ask, of any system that shapes customers, money or people: if it made a bad call on Friday, whose name would come up in Monday’s meeting? If the honest answer is nobody, the vendor still does not own the outcome. You do. Who that owner should be, and how accountability is divided, is the subject of AI Roles, Ownership and Accountability in Module 07.

The law increasingly says the same thing, and it addresses the organization that uses the system, not only the one that built it.

Seeing takes curiosity, not blame

Whether leaders get an honest picture depends on how they ask. There are two ways to get it wrong.

Between looking away and banning, the stance that works is to see without blame and ask what problem people were trying to solve.Look awayAssume nothing is runningBan and punishUse moves out of sightSee without blameAsk what problem people were solving
Figure 1.8.8 Between looking away and cracking down sits the only stance that produces an honest map.

One is to look away and assume that, because nothing was approved, nothing is running. The other is to announce a crackdown and go looking for culprits. As The Speed of AI Adoption showed, a ban stops the organization’s learning without stopping the use; it mainly moves the use out of sight. People who fear confiscation name only the approved systems, and leadership governs the official stack while the real one keeps running.

The stance that works sits between the two. Assume some informal use exists. Ask what problem people were trying to solve, because that is real demand the organization has not yet met. Ask the owners of every major business system what their software now decides on its own, because they may not have asked their vendors. Treat what comes back as information rather than confession. Leaders who handle the first disclosures calmly tend to get a second round that is more complete.

Story: a sports league that thought it was starting

The following is an illustrative composite, not a real organization. Its parts are common ones.

A national professional sports league runs the competition for its member clubs: the fixture schedule, central ticketing for its biggest matches, the broadcast and sponsorship deals, and the integrity of the game. Its board asks for an AI strategy, and the leadership team does what many teams do. It books vendor demonstrations, drafts a shortlist and writes a steering paper with the word transformation on the cover.

Meanwhile, AI is already at work. The scheduling software has used its vendor’s optimization engine to build the fixture list for years. The ticketing platform’s demand-pricing feature, switched on in a vendor update, now sets the price of every section of the stadium. An integrity service scores betting patterns for signs of match fixing. Office staff draft documents with a licensed assistant. The commercial team pastes draft sponsorship terms into personal AI accounts to write proposals faster. Two departments pay separately for two meeting-summary tools.

Then, before a long holiday weekend, the demand-pricing feature pushes the price of family seats for the big holiday match far above what the league had promised, and fans complain loudly and in public. Nobody can say who owns the pricing rule or who is allowed to change it. A month later the league learns that confidential sponsorship terms have been sitting in personal accounts that no one had listed. The league thought it was starting. It was already in the middle.

Before, the league starts with vendor demos while an unowned pricing feature prices fans out and sponsor terms sit in personal accounts; after, it maps what runs, names an owner, sets a data rule and drops a duplicate tool.Before - starts with vendorsDemos and a shortlistPricing with no owner; fans priced outSponsor terms in personal accountsAfter - starts with a mapEach function says what already runsPricing gets an owner; data rule for dealsOne summary tool kept, one stopped
Figure 1.8.9 Illustrative. The league did not become more ambitious; it changed the order of work, seeing first and buying second.

A few months later the chief operating officer pauses the vendor tour and changes the first move. Leadership tells every function, in writing, that nobody will be penalized for tools they disclose, and asks one plain question: what already ranks, scores, forecasts, routes, prices or drafts in your work?

The answers fall into the three buckets. Embedded: the scheduling engine, the demand-pricing feature and the integrity scores. Official: the licensed office assistant. Informal: the personal accounts in the commercial team and the two summary tools. The pricing feature gets a named owner with authority to set limits before the next big match. The commercial team gets an approved assistant and a clear rule that confidential deal terms never go into personal accounts. The league keeps the better summary tool and stops paying for the other.

Only then does it return to the vendors, and the conversation is much shorter, because it knows which problem is still unsolved. Nothing about the league’s ambition changed. What changed was the order of work: see, then choose.

What this means for leaders

The practical consequence is a change in the first question. Before asking which AI to buy, ask where AI already works and who answers for it. That question is cheaper and more revealing than a vendor tour, and it improves the eventual purchase, because it shows which problems are already solved, which are solved twice and which are not solved at all.

It also changes what leaders should expect of the people who own business systems. The owner of the planning system, the hiring platform or the customer database now owns whatever AI those systems contain, whether or not they chose it. Many have not been told. Telling them is a leadership act, not an IT task.

The first round of looking will be incomplete. How leadership reacts to it decides whether there is a second.

Check yourself

  1. If nobody in the organization uses a chat assistant, the organization is not using AI.
  2. New AI features often reach organizations through updates to software they already pay for.
  3. When an organization is required to list its AI, the first list is usually complete.
  4. If a vendor supplies an AI hiring tool, the duties around its use fall only on the vendor.
  5. Banning unofficial AI tools gives leadership an accurate picture of AI use.
  6. AI inside software the organization bought still needs a named internal owner.

Reflection: find the quiet systems

What comes next

AI may already be everywhere in your organization, including in systems that never say its name. That raises a fair question. If AI has been working quietly for years, why does this moment feel so different? Something changed about the part people can see. The next chapter, Generative AI Changes the Game, explains what changed and what did not.

Laws referenced

NYC Local Law 144 (automated employment decision tools) · US - New York City

NYC Local Law 144 of 2021; DCWP rules

An automated tool that substantially assists hiring or promotion decisions needs an independent bias audit within the past year, a published summary of results, and notice to candidates at least ten business days before use. Penalties USD 500 to 1,500 per violation.

  • 2023-07-05 — Enforcement began

Last verified 2026-10-06 · official text

EU AI Act · EU

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.

  • 2024-08-01 — Entered into force
  • 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
  • 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
  • 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
  • 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
  • 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
  • 2028-08-02 — High-risk obligations for AI in products regulated under Annex I

Last verified 2026-10-06 · official text

References

  1. Nicole Gillespie, Steve Lockey, Tabi Ward, Alexandria Macdade and Gerard Hassed. Trust, attitudes and use of artificial intelligence: A global study 2025. The University of Melbourne and KPMG International. 2025.
  2. Accounting Today (reporting Gartner research). 80% of software vendors to offer gen AI by 2026, up from 1% last year, says Gartner poll. Accounting Today. 2024.
  3. The Register. Users upset by Slack using customer data in model training. The Register (20 May 2024). 2024.
  4. Slack Technologies. How Slack protects your data when using machine learning and AI. Slack blog (7 April 2025). 2025.
  5. US Government Accountability Office. Artificial Intelligence: Agencies Have Begun Implementation but Need to Complete Key Requirements (GAO-24-105980). GAO (December 2023). 2023.
  6. US Office of Management and Budget. 2024 Federal AI Use Case Inventory (consolidated). OMB, GitHub repository ombegov/2024-Federal-AI-Use-Case-Inventory. 2025.
  7. US Office of Management and Budget. 2025 Federal Agency AI Use Case Inventory (consolidated). OMB, GitHub repository ombegov/2025-Federal-Agency-AI-Use-Case-Inventory. 2026.
  8. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
  9. Seyfarth Shaw. Mobley v. Workday: Court Holds AI Service Providers Could Be Directly Liable for Employment Discrimination Under "Agent" Theory. Seyfarth Shaw (July 2024). 2024.
  10. Davis Wright Tremaine. AI Screening Tools Under Scrutiny: Federal Court Preliminarily Certifies ADEA Collective Action. Davis Wright Tremaine (May 2025). 2025.
  11. Duane Morris (Class Action Defense Blog). California Federal Court Grants In Part And Denies In Part Workday's Motion To Dismiss In Mobley v. Workday. Duane Morris LLP (24 June 2026). 2026.
  12. NYC Department of Consumer and Worker Protection. Automated Employment Decision Tools (Local Law 144 of 2021) - revised proposed rules. City of New York. 2022.
  13. European Union. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689. Official Journal of the European Union. 2026.
  14. Khari Johnson. State claims there's zero high-risk AI in California government - despite ample evidence to the contrary. CalMatters. 2025.
  15. Khari Johnson. California admits using high-risk AI - including systems it failed to report last year. CalMatters (republished by KQED). 2026.

Further reading

Sources last verified 2026-10-09.