AI Adoption Archetype
Officially absent, unofficially exposed
At a glance
Officially, nothing's happening. Unofficially, it almost certainly already is, on someone's personal account, with no policy, no visibility and nobody accountable if it goes wrong. This is the one archetype where doing nothing is the risky option.
On paper, the Bystander hasn't really started with AI. In practice, it almost certainly has, just without anyone's knowledge, policy or protection. This is the archetype with the least to show for the most exposure.
Ask leadership about AI adoption here and you'll likely hear that it hasn't really started. Ask an average employee whether they've ever pasted something into ChatGPT and the answer is usually yes. Both things are true at once, and the distance between them is where the risk lives.
Nobody set out to create an ungoverned situation. It happened by default, because nobody was assigned to own it. The absence of a policy isn't neutral, it's a decision by omission, and it has exactly the same consequences as a bad policy would.
Of all six archetypes, this is the one where the first move costs the least and buys back the most risk. A baseline policy and a named owner close most of the gap in weeks, before any of it has had the chance to compound.
Swipe or tap the top card to see the next one.
Swipe or tap the top card to see the next one.
By the numbers
Only 31% of organisations have a formal, comprehensive AI policy in place.
34.8% of all corporate data employees put into AI tools is now classified as sensitive, more than triple the rate two years ago.
Cyberhaven, 2025 AI Adoption and Risk Report (7 million workers, April 2025)
Swipe or tap the top card to see the next one.
Individual employees are quietly experimenting on their own initiative, usually with free tools and personal accounts, with no idea whether that's against any rule because no rule has ever been written.
Leadership genuinely believes AI is not relevant here yet, which is usually the last place shadow use gets discovered, often through a client question or a data incident rather than an internal review.
There's no vendor relationship to speak of, officially, which means there's also no one checking what free-tier terms and conditions employees have already agreed to on the business's behalf.
If there is no official AI initiative or budget line anywhere in the business, but you would not bet against an employee having pasted something into ChatGPT this week, you are almost certainly a Bystander.
It combines the least official adoption with real, unmanaged exposure. Employees are already experimenting on personal accounts with no policy and nobody accountable, the same risk a Sprinter carries without any of a Sprinter's adoption to show for it.
A policy baseline and a single named owner for AI risk, both achievable within a month. Of all six archetypes, this is the one where the smallest effort buys back the most risk.
Recommended engagement
AI Readiness & Risk Baseline: an urgent, lightweight engagement to close the gap between official policy and actual use.
Six archetypes, from least mature to most. See where the others sit and where you could head next.
Hover to preview, click to see everything about it.