An interview reflection by Sukhi Dhillon Alberga
AI Adoption Is Moving Faster Than Readiness
I recently joined Robin Ayoub on the Localization Fireside Chat for a conversation about a question I believe more organizations need to ask: as artificial intelligence becomes part of everyday work, are our governance, systems and people keeping pace? The discussion ranged from AI adoption and shadow AI to privacy, accountability, vendor risk and the practical realities of using generative AI inside established organizations.
What stayed with me most was the difference between adopting AI and being ready for it. Organizations can introduce tools quickly, and employees may already be using them independently, but responsible adoption requires more than access to technology. It requires clarity about how AI is being used, what information is entering these systems, who is accountable and how the organization will measure whether the technology is actually creating value.
AI Adoption and AI Readiness Are Not the Same Thing
AI adoption is no longer a future issue. McKinsey’s 2025 State of AI survey found that 88% of respondents said their organizations were regularly using AI in at least one business function. Yet widespread use does not mean AI is fully integrated, governed or scaled. In the same research, most organizations were still experimenting or piloting rather than operating AI at enterprise scale.
That gap matters because AI can enter an organization in several ways at once. Leadership may approve a formal platform while individual teams test other tools, and employees may use public generative AI services simply because they help them work faster. The result is that AI use can develop faster than the policies, training, controls and accountability structures intended to govern it.
Shadow AI Changes the Governance Conversation
One of the issues Robin and I discussed was shadow AI: the use of AI tools outside an organization’s formally approved technology environment. The employee using an unapproved tool may not be acting recklessly at all. They may be trying to summarize a document, draft a response or analyze information more efficiently. The risk arises when confidential, client, employee or other sensitive information is entered into a system without the organization understanding how that data will be processed, stored or used.
This is why I do not think organizations can manage AI simply by deciding whether they officially ‘allow’ it. Some level of AI use may already be occurring. A more useful starting point is to understand where AI is being used, why employees are turning to it and what practical guidance they need. Governance becomes stronger when it reflects real behaviour instead of assuming technology use begins only after a formal implementation project.
Governance Needs to Follow the Information and the Decisions
AI governance is broader than having an AI policy. It should connect privacy, security, legal obligations, operations, vendor management and accountability. Canada’s Office of the Privacy Commissioner has emphasized that organizations using generative AI remain responsible for privacy compliance and should establish clear internal governance, defined roles and appropriate safeguards. That principle is important because introducing a new technology does not remove existing responsibilities.
For established organizations, existing contracts also deserve attention. Client agreements may already define how information can be stored, processed, transferred or accessed, and those commitments do not disappear when a new AI tool is introduced. Vendor decisions therefore become business decisions: leaders need to understand where data goes, how long it is retained, whether it can be used for model training, what security controls exist and what happens when a vendor relationship ends.
Moving From Experimentation to Responsible Adoption
Governance should not be about slowing innovation. I am optimistic about what AI can help organizations achieve, particularly when it reduces repetitive work, improves access to information and gives professionals more time for higher-value judgment and client service. The objective is to create enough structure around AI that people can use it with confidence rather than leaving every employee to make their own assumptions about what is safe or appropriate.
That also means moving beyond the idea that adoption equals success. Faster drafting or research may show an immediate efficiency gain, but leadership eventually needs to ask whether AI is improving quality, reducing operating costs, increasing capacity, strengthening the client experience or creating measurable business value. Responsible adoption combines governance with change management and performance measurement; otherwise an organization can become faster without necessarily becoming better.
What I Hope Leaders Take From the Conversation
For me, the most important takeaway is that AI readiness is an organizational capability, not a software purchase. It requires people across legal, privacy, technology, operations, finance and leadership to understand their respective responsibilities and work from a common framework. Organizations do not need every future AI question answered before they begin, but they do need enough visibility and accountability to understand what is happening today and to adapt as the technology evolves.
We have explored the same broader issue in our article on Canada’s AI readiness strategy and what it means for firms. The recurring theme is that the tools may be available, but sustainable adoption depends on governance, literacy, clear processes and thoughtful implementation. That is the difference between experimenting with AI and building an organization that is genuinely ready to use it.
Why This Work Matters to Me
My own work has long sat at the intersection of law, business, governance and practical problem-solving. As AI adoption accelerated, I kept seeing organizations struggle to connect the technology with existing obligations, operational processes, risk management and measurable outcomes. That gap is one of the reasons we are building this multidisciplinary work at BLS Consulting. The goal is not simply to help organizations add another technology platform, but to help them understand where AI can genuinely create value and what needs to be in place around it.
I am grateful to Robin for the opportunity to have this conversation. AI should be something organizations are curious about rather than afraid of, but curiosity works best when it is paired with informed judgment. The human element still matters: relationships, accountability, critical thinking and integrity remain central to how we use technology well. I hope the interview gives leaders a useful starting point for assessing not only how much AI their organization is using, but how ready the organization is to use it responsibly.