In most small businesses the people who have worked out how to use AI well are the quietest about it. Not because they are hiding anything, but because nobody has said out loud that it is allowed, and the safest reading of silence is that it is not. The result is that the business carries the full cost of AI being in the building and collects none of the learning. The fix is a conversation, not a purchase, and it starts with an amnesty rather than a policy.
Why would anyone hide using AI at work?
Put yourself on the other side of it.
You have a job to do, you use a tool, and it takes forty minutes instead of three hours. Now you have to decide what to say about it. Saying nothing is free. Saying something invites a question you cannot answer safely: if that was so much quicker, what exactly is the rest of your week?
In a large organisation this gets formalised as an approval queue, and at least the queue is visible. A small business usually has no queue at all, which sounds like the opposite problem but produces the same silence. Nothing has been permitted, so nothing has been declared.
Add a second pressure. Most small business AI policies, where they exist, were written out of worry rather than intent. They read as a list of things not to do. A person who has already been quietly doing one of those things now has a reason to keep quiet permanently.
None of this is a discipline problem. It is an accurate reading of what feels safe to say out loud, and people are usually right about that.
What does the silence actually cost?
Three things, and only one of them is obvious.
The good uses stay private. Somebody has built a way of drafting your quotes, or checking your invoices, or turning a site visit into a written report. It works. Nobody else in the business will ever see it, so you pay for one person's productivity instead of five.
The bad uses stay private too. This is the half that should bother an owner more. A mistake nobody can talk about is a mistake nobody can fix. Client information pasted somewhere it should not have gone, a number accepted without checking, a document sent out with a confident error in it. None of that surfaces in a culture where the first response to an admission is a new rule.
Your estimate of adoption is wrong, and wrong in a predictable direction. Owners estimate from what people volunteer, which is always the lowest available number. Then they make buying decisions on that estimate, usually deciding the team is not ready. Meanwhile half the team has been ready for a year.
Should I write an AI policy first?
This is the instinct, and we would not start there.
A policy written before anyone has said what they actually do is a policy written against an imaginary business. It will cover risks you do not have, miss the ones you do, and read as a list of prohibitions, which confirms the exact fear that produced the silence. You will have spent effort making the problem slightly worse.
Policy is a good second move. It is a poor first one, because you do not yet know what you are writing about.
The same logic shows up wherever adoption stalls. We wrote about it from a different angle in why AI projects fail: the failure is rarely technical, and it is rarely the tool that was bought.
What to do instead: run an amnesty
Here is the move, and it costs nothing but nerve.
Ask the team what they already use AI for, and say clearly before they answer that nothing said in the conversation becomes a rule. Then hold to that. If the first honest answer is met with a new restriction, you will not get a second one, from anyone, ever.
A few things that make it work:
- Ask about jobs, not tools. "What have you tried it on?" gets further than "which apps are you using?", which sounds like an audit.
- Go first. Say what you have used it for, including something that did not work. An owner admitting a dud attempt does more for candour than any assurance.
- Do it in a group, once, rather than one to one. People calibrate off each other. The second person to speak is the one that matters.
- Write down what you hear, not what you think of it. Judgement can come later, and should.
You will usually surface two or three uses better than anything you would have thought to specify, and one that needs to stop today. Both are worth more than the policy would have been, and now you can write the policy, about your actual business.
Then pick one person, not the whole team
Adoption spreads by imitation of something visible and credible. It does not spread by announcement, and an all staff email declaring that the business is now doing AI reliably produces nothing but a quieter kind of silence.
So take the best thing the amnesty surfaced and ask that person to do their next job that way in the open. Not a presentation. The actual work, where colleagues can see the messy middle as well as the tidy result, including the bits where it went wrong and they fixed it by hand.
One person working visibly beats a mandate, because a mandate asks people to trust a claim while a demonstration lets them watch. And the messy middle is the important part: it is what tells everyone else that competence here is learnable rather than innate.
The pattern we keep landing on at Handiwork is that the constraint is almost never the tool, and almost never the people. It is whether the business has made it safe to be seen learning. Get that right and the tool questions answer themselves. Get it wrong and no amount of licensing fixes it.
Once things are out in the open, the useful next questions become answerable: what it actually costs to run, covered in what AI costs to run, and what you should be measuring, covered in how to measure AI ROI. Both are much easier once people will tell you what they are doing. If you want the broader adoption picture, our pillar on the next step, not more tools sets it out, and how we work shows where this sits in a Handiwork engagement.
Ready to find out where you stand?
Our free AI Readiness Check takes about five minutes and gives you an outside read on where your team actually is, before you write a policy or buy anything: start the AI Readiness Check.
Frequently asked questions
Is it really true that my staff are using AI without telling me?
Assume it is likely rather than certain, and find out rather than guess. The point of an amnesty is that it replaces your estimate with an answer, and your estimate is almost always low.
What if the amnesty turns up something genuinely serious?
Then you have found it, which is the good outcome. Deal with the specific issue on its merits and keep the promise about the conversation. Breaking that promise costs you every future disclosure.
Does this mean we should not have an AI policy at all?
No. It means write it second. A policy grounded in what your business actually does is enforceable and useful. One written in advance is neither.
Our team says they are not interested in AI. Is that different?
Sometimes, and it is worth testing. "Not interested" and "not willing to say so here" look identical from the outside, which is the whole problem.
How long does the amnesty conversation take?
Half an hour, once. The follow through, one person working in the open, is where the time actually goes, and it is time they were spending on the work anyway.
Ready to find out where you stand?
Take the free five-minute AI Readiness Check. There is no pitch at the end of it.
Take the AI Readiness CheckSources
- Your people get AI. Get out of their way. — Dan Maccarone, UX Collective, https://uxdesign.cc/your-people-get-ai-get-out-of-their-way-131370c157f8



