Blane Canada

Related question

Is sending an AI usage memo to staff enough?

Short answer

No. A memo assumes a level of understanding that usually does not exist yet, and it assumes leadership already knows what is happening. Firms that handle this well start with a diagnostic of what is in use, what the capability range looks like, and where the risk sits. Then they write guidelines that match reality.

A memo that says "more to come" buys time. It does not buy confidence.

The right concerns in the wrong order produce a specific failure. Staff read the memo, most of them cannot fully act on it, the compliant ones become slightly more cautious, the ones already deep in these tools continue exactly as before, and leadership now believes the issue has been addressed. That last part is the expensive one, because it closes the topic.

An honest baseline surfaces four things a memo cannot. What tools are actually in use across the company. What the real capability range looks like, which typically spans from people who have never opened one to people building applications. What is being considered by people who have not raised it yet. And what the governance exposure looks like in practice rather than in policy.

Those are different pictures and they rarely match. Guidelines built on the real one are enforceable. Guidelines built on the assumed one are decoration.

Go deeper