Thriving in Times of AI

AI Business Transformation

AI is changing every business, without anyone ever making a decision. A company that goes slow or "no" on AI will still have AI tools coming in as part of the software and equipment it uses, and by employees running AI chats on their devices without authorization, training and documentation. For some companies, competitors suddenly might have an edge because they embrace the technology. Escaping AI is impossible - the only choice is how to engage. How a company responds to the AI exposure it already has defines its AI Identity - and with it, its AI Strategy.

“Sir, my need is sore.
Spirits that I’ve cited
my commands ignore.”

The Sorcerer’s Apprentice, Johann Wolfgang von Goethe (1797/98)

Your AI Identity: beyond AI strategy

9senses has defined three archetypes of AI identities companies can have. Learn more by opening one of the tiles below, or take our 5-minute test to find out where your company stands.

AI Hesitant

The AI Hesitant does not actively engage in AI, but AI is still creeping in through third-party tools and unauthorized AI use by employees.

3

AI Sprinter

The Sprinter embraces AI without hesitation - and might reap some short-term benefits but might endanger control over the business long term.

3

AI Wise

An AI Wise company finds the right balance between adopting AI and maintaining control. Its foundations are sound, and its investments are targeted.

3

From the inside, the Hesitant position feels safe. No budget is burned on hyped AI that is more likely to fail than to succeed, no risky projects are started, and employee use of AI chats is blocked.

Unfortunately, the defining property of AI is that it does not wait for an invitation. It just arrives. The software you already pay for adds AI features release by release, and your people are ahead of you: in the largest global study on workplace AI to date, only 40% of employees said their workplace has any policy or guidance on generative AI, while almost half admitted to using it in ways that break company rules, including feeding sensitive company information into free public tools. 57% said they hide their AI use altogether.

There isn't a "no-AI" option

While it is possible to decide nothing on AI or even actively say "NO", you are still fully exposed. The EU AI Act is in place, and a purchased product or an illegitimately used chatbot can put you in scope for rules you never read.

If you contacted us tomorrow, our advice would not be an AI project. It would be to build the AI Foundation and AI Baseline to cover you. It would mean training your senior management to build some basic understanding of AI. It would mean an inventory of what is already in your company, estimating the exposure, defining rules and boundaries, and setting up minimal training and support for employees who are very likely already using AI behind your back.

Take the AI Identity test and find out which company type yours is - or schedule a 15- minute call to learn more about how we can help.

The price
AI Hesitants pay

You carry the exposure without most of the benefits. You pay for AI inside your tools whether it is governed or not.

One pasted contract, one confidently wrong answer sent to a customer, and the incident lands on an organization with no rules, no owner and no routine. But full responsibility. And when engaging becomes unavoidable, you start under pressure instead of by choice.

FAQs for AI Hesitants

We deliberately decided against AI. Isn't that a valid strategy?

Deciding against your own AI applications is entirely legitimate, and we often advise companies to do just that. Deciding against AI, while it creeps in through tools and illegitimate use by employees, is impossible. The exposure exists whether you engage or not; the only choice is whether it is covered.

Can't we just block the tools?

Blocking is the worst possible decision. It doesn't remove tool use, it just shifts it outside the visible area. Teams or individuals that are under pressure to deliver output will simply switch to AI on private devices, which often means lower-quality models, privacy and confidentiality issues, and a complete loss of control over what is going on.  Approved alternatives, combined with training and clear rules, reduce unauthorized use far more effectively than a ban.

What is the very first step?

The first step is learning about AI in order to understand what it can do, and what it cannot. This is followed by measuring: creating an inventory of where AI already lives in your organization and how it is governed. This takes days, not months. Everything else builds on this.

The Sprinter is visibly the innovator, ahead of the curve, using the latest technology and possibly scoring some quick wins. Some of those gains are real; maybe well-used AI increases staff efficiency and reduces hiring needs.

But still, a large number of generative AI pilots produce no measurable return, and, increasingly, companies are abandoning AI initiatives. The pattern behind these numbers is always the same: applications are added faster than the foundations that keep them controllable, ranging from appropriate testing to governance.

Sprinters often steal from their own future

The deeper cost compounds: in a 2026 BCG study, C-level interviewees observed deskilling among their employees who heavily rely on AI-generated output and complained about glossy work that was shallow in content. That's a key AI feature. Managing this, while steering the company towards efficient AI use, is hard work.

At the same time, some savvy companies reduce entry-level hiring, while managing AI use productively. They will pay the price in the future, when nobody in the organization has learned how to do things at the core of the business, and how to review and judge AI outputs. We call it the AI Apprenticeship Debt Curve. Quick gains now, losses arriving later.

If an AI Sprinter contacted us tomorrow, our advice would be to pause new AI rollouts, bring the AI Foundation up to strength before the next launch, and establish a sound AI Baseline that guides everyday AI use and adoption.

The price
AI Sprinters pay

Every AI-based application added on this footing raises exposure faster than oversight and control can catch up. Incidents land on an organization that is fast but unprepared.

The risks include a high cost for abandoned AI projects, uncertainty about AI impact on the business, and possibly a loss of human capability through deskilling. 

Questions AI Sprinter might ask

We are seeing real productivity gains. Why change anything?

The gains are not the problem, but the uncovered exposure underneath is. Reducing that exposure doesn't mean giving anything up; it means being able to keep what you have gained and build a solid foundation that outlasts the short-term wins.

Won't governance slow us down?

The evidence points the other way. Only a scarily small number of AI initiatives generate measurable long-term value: the scoped ones with a defined purpose, clear success criteria, early fail gates, and good governance. Building the harness that doesn't let you cede control to AI is a small cost compared to the risk you're otherwise taking.

Which of our running applications should we review first?

The highest risk lies in generative AI and Machine Learning applications where the output doesn't undergo regular human validation, and where continuous testing isn't a built-in feature. That is precisely where AI confidently makes the errors nobody discovers.

Being AI Wise doesn't mean a choice on how much AI a company adopts. It rather means that it is prepared for AI. The starting point is to ensure that all employees - from top management to everyone with potential exposure - understand AI well enough to see its benefits, limitations, and risks.

Further, it means understanding where AI already lives, understanding the risks and managing them, particularly when it comes to general use of generative AI to solve business problems or agents that process data and make decisions. It is better to provide solid tools rather than have employees use AI anyway under the table, with all the risks this entails. Lastly, there is a solid governance layer required, ensuring that AI can't quietly damage the business, and that AI applications are tested the way they should be - continuously.

Balance is maintained, not reached

Being AI Wise has no finish line. AI models change, vendors add features, their prices and terms move, regulations change, people come and go. With each of those changes the exposure drifts, so coverage has to be re-measured and grown with every new application. That is why we describe AI transformation as a control loop rather than a journey. An AI Wise company is staying in that loop.

Let us know if you want to become AI Wise - it's easier than you think.

What AI Wise companies win

AI Wise companies engage with Artificial Intelligence, but in a way that ensures their business foundation and their long-term success are never in danger.

By laying a solid AI foundation and defining a baseline for AI use, they ensure proper adoption and governance, making most AI initiatives fail early or succeed.

It is based on knowledge about AI, its benefits and risks, and a clear governance framework around it.

Questions we get asked

Is AI Wise just a polite word for slower?

AI Wise says nothing about adoption speed. A company can deliberately introduce AI in places where it is meaningful or stay away from AI outside of generic employee support. Both can be wise. It's the choice you have.

Do we need a Chief AI Officer?

Not necessarily. But you need AI literacy on all management levels, and you need clear decision-making authority about AI initiatives across the organization. The setup is secondary, but competence and agility matter.

How do we stay on top of AI change?

This is challenging, as AI models change almost daily under the hood, and AI capabilities are introduced in more and more products, from software to equipment. These changes need monitoring and regular reviews, as well as a completely different testing approach: with AI, every day is "release day".

To become AI Wise, where you're neither run over by AI changing your reality nor among those who aimlessly engage, it is imperative to develop a thorough understanding of Artificial Intelligence, its benefits and its limitations, and begin applying it cautiously and methodically, with the necessary guardrails and a way to rapidly adjust as it changes. 

AI Wise building blocks

Three layers of engaging with AI. The first two are essential for all organizations, even if they don't start their own specific AI initiatives. The third one - AI Substance - is optional.

AI Foundation

The AI Foundation keeps you on solid ground. It defines your strategic position, governance and ownership, rules and boundaries, and the evaluation of your AI exposure and risk.

3

AI Baseline

The AI Baseline makes everyday AI use manageable across the organization. It defines approved tools, AI literacy, usage rules and oversight, including ongoing risk management as AI use and conditions change.

3

AI Substance

AI Substance is entirely your choice. It consists of the specific AI applications you introduce into products or business processes. These initiatives are selected one by one, where AI can create measurable value.

3

Four key elements are at the core of an AI Foundation.

AI Strategy

This decides where AI belongs in your organization and where it doesn't. It is built based on the AI literacy of senior management and defines what strategy the company wants to follow on AI, and how this strategy is continuously revised as the technology evolves. It defines the guiding principles of AI adoption.

Governance and ownership

This mandatory layer defines the rules for engaging with AI on an organizational level. It defines where the decisions about "yes" and "no" sit, and how they are managed. There is no hiding behind "the AI did it." Courts have already confirmed that.

Rules and boundaries

The regulatory framework - for example the EU AI Act and data protection laws - is only the floor of what matters. Most boundary decisions are business decisions: which data may go into what tools, which AI uses and decisions need to be documented; what is off-limits.

Risk evaluation

Risk evaluation starts with understanding exposure - an inventory of the AI that has quietly entered your business without you asking for it - and a basic assessment of what each finding could do to the business and its risk profile. This evaluation is what the strategic position and the boundary rules are built on.

The 9senses
AI Foundation Program

We have developed a comprehensive, structured approach to building a company's solid AI foundation in less than two months. 

It consists of 3 distinct elements:

  1. An AI inventory with AI exposure review - identifying all current visible and hidden exposure and evaluating its potential impact on business and risk.
  2. The AI Foundation Day - a structured off-site meeting for senior leadership that aims at the following:
    • AI education on potential, limitations and risk of AI;
    • AI strategy definition, formalizing the current adoption strategy of the business;
    • AI roadmap outline: based on identified strategy and current exposure, define the specific next steps to complete the AI Foundation and start developing the AI Baseline;
  3. A written report outlining the agreed next steps, including proposals for governance, ownership and boundary rules, together with the findings of the risk evaluation and the roadmap towards the AI Baseline.

AI Foundation FAQs

Is this a big compliance project?

No. At the core of a working AI Foundation are education, an AI inventory, a strategic position, boundary rules and a risk overview. For most companies that can be completed in less than two months.

We already have IT governance. Isn't that enough?

AI is fundamentally different from traditional IT, which is deterministic: its decisions can be traced and reproduced. AI is built on the opposite promise, reacting flexibly without a fully reproducible logic. That breaks the assumptions your existing governance typically relies on, which is why AI needs its own rules and testing protocols.

What does the EU AI Act require from us right now?

As of today, you have to refrain from the prohibited practices, including emotion inference at the workplace, even inside products you bought. From December 2027 onwards, you have to follow all high-risk obligations if your AI uses fall under them.

How do we find the AI already in use?

First, you can just assume it happens like in most other companies. Then you ask, without blame, so people answer honestly. Your vendors' release notes tell you how much of your AI arrived through updates to software you already use. This inventory is a living structure and changes frequently, so it needs an update process.

Is this only for large enterprises?

No. The AI Foundation takes roughly two months at any size, because the pace is mostly set by scheduling and reporting. What changes is the workload and with it the cost of inventories, interviews and documentation.

The AI Baseline defines tools and rules that apply to the entire organization. While you theoretically can refrain from providing AI tools, doing so risks employee use in a way that poses much greater risk to your organization. It is thus highly recommended to reduce unauthorized use by providing a high-quality alternative.

Approved tools

This defines a toolset employees can use with confidence, curated for your actual work and your data protection needs. This is the single most effective control there is: people reach for unauthorized tools far less once a meaningful approved alternative exists. It is important to continuously evaluate these tools to not fall behind, and to have clean upgrade and testing paths as they change on their own. Often, these tools can be self-hosted and don't need a cloud-based model, removing many of the risks and compliance issues created by sending data outside of the organization. 

AI literacy

Employees who don't know how AI works and how to use it are bound to produce glossy but shallow content. This is about knowing how to use these tools, but even more about understanding their failure modes: answers that are confidently wrong exactly where you cannot check them, or evaluations that change every time you ask. People in the know create better results with AI and stay in control.

AI usage rules

With a solid AI toolset in place, enforceable rules are typically accepted by employees. These define what may go into where, what is off-limits, and how AI use is checked and documented.

The last two are important above all. Wherever important business output is created - no matter if used for internal decision-making or in a customer-facing role - this use must be documented and the findings must be independently validated, not simply shipped into any decision-making process relying on it. For those elements, the final judgment typically has to stay with a human. This doesn't just protect you legally, but it also maintains the skills an organization needs in the long run.

Oversight

A current inventory of the AI in use, including what individual employees adopted on their own, and visibility into adoption, quality, incidents and change. It also carries the ongoing risk management: what happens if a critical provider changes its models, terms or pricing - or you had to switch a tool off tomorrow - and how the organization develops and maintains its skills as AI use grows. Not surveillance, but bookkeeping. You cannot cover what you cannot see.

The 9senses
AI Baseline Program

The AI Baseline Program is the next step once the AI Foundation is sound. It consists of the following elements that will be evaluated and defined through a series of cross-functional workshops:

  1. An approved AI toolset for general use, available to most employees who are otherwise prone to use unauthorized tools. This may include cloud-based LLM access, but can equally be one or more locally hosted models that ensure critical data never leaves the premises.
  2. AI rules and procedures, defining how AI should and should not be used, and what declaration obligations and guardrails exist for AI-generated or -augmented outputs.
  3. An AI literacy training approach that ensures a light touch on a regular basis and keeps pace with tool developments and growing adoption.
  4. Governance and oversight that provide visibility into AI use, quality, incidents and change, manage ongoing AI risk, and ensure compliance with internal and external rules.

Typically, this phase can be completed within 2-3 months, followed by a 3-6-month rollout phase for tool enablement and training.

AI Baseline FAQs

Which tools should we approve?

The ones that match your data protection requirements and the work your people actually do. We are vendor-independent and take no commissions, so our answer can differ per company, and often the answer is "fewer than you think", and large language models in the cloud are optional.

How much training is enough?

Since tools change rapidly, a base training with short re-trainings every few months is the best format. Everyone who touches AI needs to learn how to use its current capabilities, how to prompt it, but most importantly what it can do and where it fails.

Substance is where AI is supposed to create value specifically, in a product or a business process. This layer is completely optional, but in many cases, it offers great promise. No matter if this relates to customer interactions, operations or data and knowledge management, AI can actually bring benefits.

Select carefully, case by case

The most important aspect is to design people, process, traditional IT and the AI solution as one interwoven flow. That flow needs early gates that avoid what many companies experience: prototypes that should never have gone into production, releases that don't hold up beyond a carefully curated set of test cases, solutions quietly deteriorating after their launch.

Testing isn't a gate, it's a loop

Contrary to regular IT applications, where testing typically is part of a release process, AI solutions have no final stable state. They constantly need to be evaluated against their objectives whenever something changes. And changes are manifold - a new model or changing context windows on the vendor side, or different inputs from newly ingested data, just to name a few.

9senses AI Audit and Testing Services

9senses has significant capabilities in implementing complex AI-based solutions, which typically come into play when the normal approach fails. But this isn't our key focus. Our primary support comes through auditing and testing, where we have the right toolset for successfully managing AI, ranging from our GenAI auditing framework to continuous testing approaches that help you keep track of changes in AI system output quality.

Questions we get asked

How many AI initiatives should we run?

As many as your coverage supports and your portfolio justifies. For most companies the right number is smaller than the ambition, and the initiatives that remain are the ones that reach production.

Build or buy?

Case by case, and we have no stake in the answer. What we do insist on is building in testing from the beginning, together with a clear path for human review and intervention. That is what we see working reliably in production.

When should an application be retired?

When the case that admitted it no longer holds: the model changed, the price changed, the workflow changed, or the results never met the criteria. Monitoring exists so that this is noticed, not discovered.

AI transformation starts before you choose it

AI is already entering through the tools the business uses, employees who adopt it and management decisions. The first question is therefore not whether you are becoming an AI company, but what AI Identity that creates.

AI enters through tools
Employee use
Management decisions
Every company is becoming an AI company AI is already here

01AI arrives anyway

Every company is becoming an AI company.

  • AI enters through tools - AI capabilities arrive through software and equipment used by the business.
  • Employee use - People adopt AI directly, with or without authorization and direction.
  • Management decisions - Managers and teams decide to introduce AI solutions.

The 9senses AI playbook is different

The large transformation consultancies have arrived at two conclusions we agree with: most of the work in transforming a business is always related to people and processes, not just technology, and that transformation has no end state. Their own research adds a third: the overwhelming majority of AI pilots never produce a measurable return.

Where we part ways is the goal. Our primary objective is AI resilience, not adoption. Many assume that more AI is the destination. Our destination is balance: coverage that tracks your real exposure, and exactly as much AI as you deliberately choose. Sometimes that is a lot, but sometimes this can be very little. A vendor-independent advisor can say that without hesitation.

Find your AI Identity

Answering the 14 questions of our AI Identity test takes about 5 minutes and is completely anonymous. The result gives you a clear starting point. Once you see it, you can decide what to do with it (download it, share it with us for a conversation, or stop there). It is free without any obligation.

AI Identity Test

What is your AI Identity?