A managing partner at a 200-person consultancy had endured four vendor demonstrations in a month and still could not explain what AI meant for his firm. He told the last supplier that the firm was already doing it, simply to end the meeting.
The source's story needs confirmation and quotation permission. It expresses a recognisable problem: “AI adoption” can mean private use of a public chatbot, an approved drafting assistant, retrieval across governed knowledge or a high-consequence system embedded in client work. The label says almost nothing about value or risk.
A firm needs a portfolio of defined uses, rather than a declaration that it is “using AI”.
Begin with the task
Do not start by asking which tool to buy. Observe a piece of work and identify:
- The person and affected client or colleague
- Current task, pain and baseline
- Information and systems used
- Judgement and professional responsibility
- Repetition, variation and difficult cases
- Desired result and guardrails
- A non-AI alternative
An AI system may assist one step while making the complete workflow worse through source preparation, review or correction. Measure the whole task.
The source presents three organisational positions, from vague awareness to a board deadline, and calls the vendor-demo middle particularly dangerous. Preserve the warning without the unsupported £150,000 pilot claim: interest without a problem creates procurement momentum before decision criteria exist.
Four practical patterns
Structured and repetitive work
Classification, extraction, routing or administrative drafting may reduce repeated effort when inputs and rules are stable. The consequence of error determines the review and assurance.
The source says associates spend about 15% of time on predictable administration. That anecdote lacks evidence. Measure the team's actual work before building a case.
Pattern and anomaly support
AI may help analysts identify unusual records, themes or correlations. The output is a lead for investigation, not an explanation of cause.
Poor, incomplete or biased data can produce persuasive error. Establish provenance, permissions, comparability and affected groups. In pricing, fraud, eligibility or other consequential decisions, specialist legal, model-risk and sector governance are essential.
Communication assistance
Drafting, summarising, translation and reformatting can reduce blank-page effort. A named professional checks source, context, tone, confidentiality and material omission.
A fluent first draft is not a safe final answer. Client communication needs clear exclusions and accountability.
Knowledge retrieval
Professional services firms hold valuable precedents, research and proposals across systems and people's memory. Retrieval can surface relevant material if access permissions, matter boundaries, currency and source citation are preserved.
“Have we done something like this?” is not answered safely by semantic similarity alone. Users need authoritative sources and the ability to judge applicability.
Avoid a maturity ladder that calls tools low risk
The source proposes three levels: use public tools, integrate workflows, then build custom capability. It describes the first as low risk and encourages broad experience before governance. That is unsafe.
Risk depends on use and information, rather than whether software is off the shelf. Copying client material into a public assistant can be higher risk than a well-governed custom internal tool.
A better sequence is:
- Inventory current use, including unofficial practice.
- Set approved tools, prohibited data and reporting routes.
- Select one bounded task and representative examples.
- Compare assisted and current work.
- Review value, harms and complete cost.
- Integrate or scale only when controls and operating ownership hold.
Custom build is justified by need, differentiation and economics, not arrival at a higher maturity level.
The source's McKinsey adoption and scaling percentages have been removed because they are not linked and say little about this firm's use.
What AI cannot be accountable for
AI does not hold professional duty, understand an entire client context or accept responsibility for a decision. It can support qualified judgement when evidence, limitations and review are explicit.
It also cannot create a trusted relationship merely by producing personalised language. Clients may value faster, clearer service, while a message missing the one fact that matters can damage confidence.
AI does not repair weak information. It can help classify and find records as part of a governed data programme; it cannot infer which obsolete, duplicated or unauthorised record the firm intended to trust.
Finally, it cannot own deployment. People decide purpose, supplier, data, oversight, release, monitoring, incident response and retirement.
Treat the politics as operating evidence
Confidentiality concern may reveal unclear tool boundaries. Fear about junior roles may reveal a real change to training, supervision and career development. Fatigue may reflect previous technology programmes that promised transformation and left additional work.
Do not dismiss these concerns as resistance. Engage the people affected and examine:
- Which tasks change or disappear
- Which judgement juniors currently learn through those tasks
- How review workload shifts
- Whether clients need to know or consent
- What happens to performance and workload expectations
- How staff can report an error without blame
Employment, consultation and professional obligations vary. Involve qualified owners.
The source's Deloitte, Forrester and CFO return figures are unaudited and have been removed.
A controlled first use
Choose a task with a clear owner, sufficient frequency for evidence and consequence low enough for a safe investigation. “Low enough” is a governance conclusion, rather than an assumption about drafting.
Build an evaluation set containing normal, difficult and failure cases. Measure:
- Accuracy and completeness
- Material errors and omissions
- Time including review and rework
- User and affected-person experience
- Data and security incidents
- Variation across work
- Cost and supplier dependency
Set stop conditions. Give users the freedom to reject the output and preserve the current route during the test.
The source's accountancy partner allegedly recovered four hours a week from client-letter drafting. Verify the person, baseline, task, review and permission before publishing the result. The distinctive detail, her annoyance after years of complaining about time, is worth keeping if verified because it sounds like a person rather than a case-study machine.
Governance precedes convenience
At minimum, define:
- Approved uses and environments
- Information classifications and client restrictions
- Human authority and review
- Records and audit
- Supplier, retention and model-change review
- Incident and escalation
- Accessibility and affected-person route
- Stop and retirement
The NIST AI Risk Management Framework offers a voluntary risk structure. The ICO's AI and data-protection guidance is relevant where personal data is involved. Apply current sector and professional requirements to the actual use.
Describe the next decision, not an AI destiny
And if you're in position three - the board wants an AI strategy by Q2 - resist the temptation to produce something ambitious that you can't deliver. A clear-eyed, honest strategy that says "here's where we are, here's where we're starting, and here's what we'll know in six months" is infinitely more valuable than a 40-page document full of promises. I've seen those documents. I've seen what happens to the people who wrote them when the promises don't materialise.
The opportunity is real. The right first step is almost certainly smaller, cheaper, and more useful than whatever the last vendor told you.



