You Don’t Just Need AI. You Need a REASON to Use AI.

Your AI use cases are already in the business. They just haven’t been written down yet.

If your organisation has decided it needs to “do something with AI” but couldn’t yet tell you exactly what, you are in very good company. It is, by a wide margin, the most common conversation I have.

It usually arrives dressed as a governance question. A board member, a client, or a nervous general counsel asks what the organisation’s AI position is, and someone picks up the phone. But within ten minutes of talking it’s clear that governance isn’t the real problem. The problem is that nobody in the room can say what the business is actually trying to do with AI.

Nobody is being evasive. They simply haven’t worked it out yet, and very few organisations have. What they do know, with real conviction, is that everyone else appears to be doing something, and that standing still feels dangerous. So the brief becomes “we need an AI strategy,” which in practice often means “we need to be seen to be moving.”

That’s an honest place to start, and it’s where most organisations genuinely are today. It just isn’t a use case.

The fear of being left behind is not a strategy

Being left behind is a legitimate commercial concern. Competitors who automate the tedious 40% of a process really do end up with better margins and faster turnaround. But “don’t get left behind” tells you nothing about what to build, where it will pay off, or what could go wrong. It’s a motivation, not a direction.

The predictable result is what I’d call adoption theatre. A licence gets bought for the whole organisation. A pilot gets announced. A chatbot appears on the website. Six months later, usage is patchy, nobody can point to a number that moved, and the only thing that has definitely increased is the amount of company data sitting in tools nobody formally approved.

Meanwhile, the actual risk has quietly grown. Staff who weren’t given a sanctioned tool found their own. Customer information has been pasted into services with unclear terms. Nobody wrote any of it down, because officially none of it is happening.

The organisation has managed to acquire all of the risk of AI adoption and almost none of the value.

You’re already using AI. You just don’t know where.

This is the part that catches leadership teams off guard. Every discovery exercise I’ve run has surfaced AI that was already in the business and had never been approved, assessed, or written down.

It’s rarely dramatic. It’s the analyst running board papers through a free summariser. The marketing coordinator with a personal subscription on the company credit card. The recruiter using a screening tool bundled into a platform the organisation bought for something else entirely, and never realised was making recommendations about people. The developer with an AI assistant enabled by default.

None of these people are doing anything malicious. They’re solving a real problem with the only tool they were offered, which is exactly what capable staff do. But collectively it means the honest answer to “do we use AI?” is almost always yes, and the honest answer to “where?” is almost always unknown.

So the first benefit of asking where AI could help is finding out where it already has been. You can’t govern a system you haven’t identified, and you can’t build a strategy around capability you didn’t know you had.

The question that’s missing

Shadow AI is rarely malicious. It is capable staff solving a real problem with the first tool they came across.

Here’s the uncomfortable part: technology-led AI adoption skips the question that every other capital decision has to answer. Nobody buys a new ERP because competitors have one. They buy it because finance close takes eleven days and it should take four.

AI deserves the same discipline. Not more, not less. The starting question isn’t “how do we use AI?” It’s “where does our work hurt?”

Where do people spend hours on something repetitive and low-judgement? Where does a customer wait three days for an answer that exists somewhere in the business? Where does quality depend entirely on which staff member happened to pick up the job? Where do we have data we’ve never been able to use because reading it all was impossible?

Those are the seams where AI creates value. And notice that you can identify every one of them without knowing a single thing about large language models. That’s the point. Use cases live in the business, not in the technology.

Discover, Decide, Deploy

The way out of this is not complicated, but it does need to happen in order. I take clients through three steps.

Discover. Map the work, not the technology. Sit down with the people who actually do the job and find the friction: the manual handoffs, the rekeying, the backlogs, the bottleneck that’s one person’s head. Ask the same people what they’ve already tried, and do it without blame, because that’s how the unsanctioned tools come out of the shadows. Out of a session or two you’ll usually surface fifteen to thirty candidate use cases and a handful of live ones nobody had on a register. Most organisations are surprised by how many they had and never named.

Decide. Now turn candidates into a strategy, which mostly means choosing what not to do. Score each candidate on three axes: the value if it works, the feasibility given your data and systems, and the risk if it goes wrong. Value tells you what’s worth doing. Feasibility tells you what’s possible this year rather than in three. Risk tells you what governance each one will need, and it’s here that a use case touching employment decisions or customer eligibility separates itself sharply from one that drafts internal meeting notes. Anything you found already running goes through the same filter, and it usually sorts into three piles: keep it and govern it properly, replace it with something safer, or stop it today. What comes out is a short, sequenced list with an owner and a success measure attached to each item. That’s an AI strategy. It fits on a page.

Deploy. Build governance into the rollout rather than bolting it on afterwards. Because you’ve already assessed risk in the previous step, this is far lighter than people expect. High-risk use cases get human oversight, documented decision logic, and a monitoring regime. Low-risk ones get sensible guardrails and a place on the register. Everything gets an accountable owner. Align it to ISO 42001 or the NIST AI RMF if that suits your maturity, and you have a structure that scales as you add the next use case.

Three steps, in that order. The order is the whole trick. Governance designed for a use case you’ve properly understood is proportionate and cheap. Governance retrofitted onto a tool you’ve already deployed to 300 staff is expensive, resented, and usually too late.

What this looks like when it works

The organisations getting real value from AI are rarely the ones with the biggest platforms. They’re the ones who picked two or three genuinely painful problems, solved them properly, measured the result, and moved on to the next. Their AI register is short. Their governance is boring. Their staff know exactly what they’re allowed to use and why.

It also puts you in a much stronger position externally. With the Commonwealth’s Office of Artificial Intelligence now standing up and the Voluntary AI Safety Standard shaping procurement expectations, the ability to say “here is our AI register, here is what each system does, here is who owns it and what controls apply” is becoming a commercial asset. You cannot produce that document retrospectively for a technology you adopted without deciding why.

Where to start

If your organisation is at the “we should probably be doing something with AI” stage, the next step isn’t a platform trial. It’s a discovery workshop.

Governance Works runs facilitated AI use case discovery sessions with Australian organisations. We work with your team to map where your work actually hurts, surface the AI already in use across the business, and hand you a prioritised shortlist with the risk profile of each candidate already assessed. Most clients get two things out of it they weren’t expecting: a credible list of things worth building, and their first honest inventory of what’s already running. From there, building the strategy and the governance around it is straightforward, because you finally know what you’re governing.

You don’t just need AI. You need a reason to use AI. Let’s find yours.

Book a discovery conversation — governanceworks.com.au/contact


.

DEWR’s default answer is No

Since September 2025, eleven providers have applied to use AI in DEWR service delivery. As at Senate estimates in June 2026, none had been approved. The framework’s default position is no, and that costs you whether your application is weak or excellent. Here’s what boards need to ask this quarter.

Read More »

You Don’t Just Need AI. You Need a REASON to Use AI.

If your organisation has decided it needs to “do something with AI” but can’t yet say what, you’re in very good company. The problem usually isn’t governance — it’s that nobody has identified a use case. Here’s how to find yours, build a real AI strategy, and govern it from day one.

Read More »