Your staff are already using generative AI. A 30-day plan for managers
Somewhere in your organisation this week, a member of staff pasted a supplier’s email into ChatGPT and asked for a polite reply. Another used it to summarise a contract. A third asked it to rewrite a performance review. None of them asked permission, because there was no one to ask and no rule that said they should.
This is not misconduct. It is what happens when a useful tool is free, easy and faster than the alternative. The term “shadow AI” makes it sound sinister; in practice it is the same pattern as staff using personal phones for work email a decade ago. The tool arrived before the policy, and people got on with their jobs.
The OECD’s December 2025 discussion paper on AI adoption by SMEs found that among SMEs using generative AI, only 29 percent use it in their core activities; the rest use it for peripheral tasks that aid operations without reshaping them. That is a reasonable description of what is happening in most Mauritian offices: low-stakes, useful, unmanaged.
The manager’s job is not to stop it. It is to find out what is going on, remove the two or three practices that are actually dangerous, make the rest official, and train the team to do it well. This article sets out a plan for doing that in four weeks, with the actions, the people, and what “done” looks like for each.
The plan in one table
| Week | Focus | Owner | Done when |
|---|---|---|---|
| 1 | Find out what is in use and stop the dangerous practices | Line manager | You have a list of tools and tasks, and the three prohibited practices have been communicated in writing |
| 2 | Decide what is allowed and pick approved tools | Manager with MD or senior sponsor | A one-page rule set and a short list of approved tools exist and have been signed off |
| 3 | Train the team on the organisation’s own tasks and adopt the policy | Manager, with the most capable users | Every team member has completed a session using real work, and has acknowledged the policy |
| 4 | Measure, adjust and hand ownership to a named person | Manager, then the named owner | A named owner is in place, a simple measure is being tracked, and the first adjustment has been made |
Week 1: find out what is in use and stop the dangerous practices
The first week is about facts, not rules. You cannot manage what you have not seen, and if you open with a prohibition you will simply push the use out of sight.
Actions. Hold a short team conversation, using the script below, to find out which tools people use and for what. Ask people to show you rather than tell you. Write down every tool named (ChatGPT, Copilot, Gemini, Claude, translation tools, meeting summarisers, browser extensions) and every task. Then, separately, identify the two or three practices that must stop immediately.
Who. The line manager. This is not an HR or IT exercise at this stage; it is a conversation between a manager and the people they manage.
Done when. You have a written list of tools and tasks, and you have told the team, in writing, which practices are prohibited from now on and why. A short email is enough.
The three things that must never go into a public tool
Best practice. Public generative AI tools, meaning any tool used on a free or personal account where the provider may retain and reuse what is typed, should never receive:
- Personal data of customers or staff. Names, contact details, identity numbers, salaries, health information, performance records, or anything that identifies a living person. The Data Protection Act 2017 is the legal backdrop: it requires that personal data are processed lawfully and for the purposes for which they were collected (section 21), and that controllers implement appropriate security measures against unauthorised disclosure (section 31). Pasting a customer’s record into a public tool is, at minimum, a disclosure the organisation cannot control.
- Confidential business information. Pricing strategy, unpublished financials, tender submissions, supplier terms, product plans, board papers. Once entered into a public tool the organisation has no way to retrieve or restrict it.
- Anything covered by client confidentiality. For firms in professional services, financial services, legal, medical or advisory work, client material is protected by contract and often by professional rules. The client did not consent to their affairs being processed by a third-party AI provider.
Everything else, meaning the drafting, summarising, translating and brainstorming that make up most real use, is a training question, not a prohibition.
The conversation script
Managers often delay this conversation because they are not sure how to open it without sounding either accusatory or naive. The following script works. Adapt the words, keep the sequence.
“I want to talk about AI tools, and I want to be clear at the start that nobody is in trouble. I assume most of you are using ChatGPT or something like it for some part of your work, and honestly, I have too. What I need is to understand how, so that we can make it official and make sure we are not putting the company or our customers at risk.
So, first question: which tools are you using, and for what? Just tell me what you actually do. Show me if it is easier.
[Listen. Write it down. Do not comment on whether each use is good or bad.]
Second: has anyone put customer details, staff details or anything confidential into one of these tools? I am asking because that is the one thing we have to stop, today, and I would rather know than guess.
[Listen. If the answer is yes, thank them for saying so. Note what was entered and where, for the follow-up.]
Here is what happens next. From today, three things do not go into any public AI tool: customer or staff personal data, confidential company information, and anything covered by client confidentiality. I will put that in writing this afternoon. Everything else, keep doing, and over the next few weeks we will agree which tools we use and I will make sure everyone gets time to learn to use them properly on our actual work. Questions?”
The script does three things. It removes the fear that makes people hide their use. It gets you the inventory. And it draws the one line that matters before anything else is decided.
If someone discloses that personal data has already been entered into a public tool, treat it as a potential data incident and check with whoever handles data protection in your organisation. Section 25 of the Data Protection Act 2017 deals with notification of personal data breaches; whether a given incident meets that threshold is a judgement that should be made deliberately, not ignored.
Week 2: decide what is allowed and pick approved tools
With the inventory in hand, week two is about decisions. The aim is a one-page rule set, not a policy manual.
Actions. Review the list of tasks from week one and sort each into three columns: allowed, allowed with human review, not allowed. Most drafting and summarising sits in the first column. Anything that goes to a customer, a regulator or a court sits in the second. Decisions about people (hiring, discipline, appraisal outcomes) sit in the third, not because AI cannot help with the drafting, but because the decision must be demonstrably human.
Then choose the tools. The question is not which tool is best but which the organisation can use on business terms. Paid business accounts from the major providers typically offer contractual commitments on data use that free accounts do not. Choose one or two, not six; fewer tools means simpler training and rules that are easier to follow.
Who. The manager drafts; the managing director or a senior sponsor signs off. Tool selection may need whoever manages IT spending. If the organisation has any data protection responsibility assigned, that person should see the draft.
Done when. A one-page rule set exists covering approved tools, prohibited data, allowed tasks, review requirements and who to ask. The tool subscriptions are in place. The founder’s article on ChatGPT for businesses in Mauritius, linked in the sources, sets out a simple policy structure and a list of safe use cases that can serve as a starting point for both.
Consultaix recommendation. Keep the rule set to a page. A policy that nobody reads is not a control. If the organisation later moves to a fuller governance framework, this page becomes one section of it rather than being thrown away.
Week 3: train the team on the organisation’s own tasks and adopt the policy
Generic AI training fails because it teaches people to write poems and holiday itineraries. Staff already know the tools can do that. What they do not know is how to use them for the specific tasks on their desk, safely and to a standard the organisation would put its name to.
Actions. Run one or two working sessions, no longer than ninety minutes each, in which people bring real tasks from their week: the monthly report, the supplier reminder, the tender summary, the customer FAQ update. For each task, work through the same sequence: what goes in (and what must not), how to instruct the tool, how to check the output, and what human review is required before it is used. Use the organisation’s own documents, with confidential and personal content removed. Give the two or three most capable users from week one a role in the session; they become the internal reference points afterwards.
Close the session by walking through the one-page rule set and asking each person to acknowledge it. An emailed acknowledgement is sufficient.
Who. The manager leads, supported by the capable users. If outside help is brought in, this is the week it earns its fee, because the sessions must be built on the organisation’s real tasks.
Done when. Every team member has attended, has worked through at least one real task, and has acknowledged the policy. A list of the tasks covered exists, because it becomes the basis for the measure in week four.
Why this matters for readiness
Consultaix assesses AI readiness across five dimensions: strategy, governance, data, capability and execution. Week three is where the capability dimension moves. Capability is not whether the organisation has bought licences; it is whether the people who do the work can use the tools on that work, know the boundaries, and can tell a good output from a plausible-looking bad one.
An organisation whose staff are using generative AI unmanaged is typically at the Aware or Exploring rung on capability: usage exists but is individual, uneven and unrecorded. Three weeks of the plan above, done properly, is usually enough to reach Adopting for the team involved: a defined set of tasks, trained people, a written rule, a named owner. Reaching Scaling, where this is standard across every function, is what a Capability Programme is designed to do over a longer period.
The OECD paper is direct about the skills point. It identifies skill shortages as a major barrier to AI adoption, consistently named by SMEs as one of the main hurdles they face, and notes that SMEs in Canada, Germany and the United Kingdom were twice as likely to say that their use of generative AI increased their skills needs as to say it decreased them. The tools do not remove the need for capable people. They raise it.
Week 4: measure, adjust and hand ownership to a named person
The plan fails if it ends with the manager as permanent owner of AI use. Week four is about making it somebody’s job and giving them something to measure.
Actions. Pick one simple measure and start tracking it. Sensible candidates: the number of tasks from the week-three list that are now done with AI as standard; the time saved on one recurring task, estimated by the person who does it; the number of outputs that needed significant correction at review. Do not build a dashboard. A line in a monthly report is enough.
Hold a fifteen-minute review at the end of the week. What is working, what is being avoided, what question keeps coming up. Make one adjustment to the rule set or the approved tool list based on what you hear.
Then name the owner. This is the person to whom staff bring questions, who keeps the rule set current, who tracks the measure, and who raises anything that looks like a risk. In an SME it is often the manager who ran the plan, formally, or one of the capable users from week three with time allocated. The point is that it is written down.
Who. The manager, then the named owner from the point of handover.
Done when. A named owner exists and has been told, in writing, what they own. One measure is being tracked. One adjustment has been made and communicated. The manager can step back.
Best practice. Put a review date on the rule set, three or six months out. Tools change quickly, and the practices that were safe in September may need revisiting by March.
What this plan does not do
It does not build an AI strategy, assess whether the organisation’s data is ready for larger uses, or address the governance questions that arise when AI moves from drafting into decisions affecting customers or staff. Those are separate pieces of work, better done once the basics are in place. What it does is convert an unmanaged reality into a managed one in a month, at almost no cost, with the people you already have.
Where Consultaix fits
The four-week plan above is something a capable manager can run alone. Where an organisation wants it run across several teams, built on its own documents and processes, and carried through to the Scaling rung, that is the work of the Consultaix Capability Programme in AI Training and Change Management. Where the question is broader than one team’s use of generative AI, an AI Readiness Assessment places capability alongside the other four dimensions so that training effort goes where it will make the most difference.
Sources
- AI adoption by small and medium-sized enterprises: OECD discussion paper for the G7, OECD, December 2025: https://www.oecd.org/en/publications/2025/12/ai-adoption-by-small-and-medium-sized-enterprises_9c48eae6.html
- The Data Protection Act 2017, Republic of Mauritius, 2017: https://www.fscmauritius.org/media/105843/the-data-protection-act-2017.pdf
- Data Protection Office, Republic of Mauritius: https://dataprotection.govmu.org/
- ChatGPT for Businesses in Mauritius: Safe Use Cases, Policies, and Practical Workflows, Faaleh M. Sookye, faaleh.com, 2026: https://faaleh.com/insights/chatgpt-for-businesses-mauritius