Which AI maturity level are you really on
Halfway through the Boston agencies' AI panel I asked the room to put themselves on a five-level AI maturity model. Going by the questions they'd sent in beforehand, most of them were on level one or two, which surprised me a little. The reason didn't.
What is actually happening inside most agencies right now is that the staff are experimenting with AI on their own personal ChatGPT accounts, and they are putting client material into them. Usage nobody can see or audit, client data sitting in consumer accounts the agency doesn't control, work product created under terms of service nobody has read, and if any of those clients are in a regulated industry, a compliance problem that gets serious very quickly. I described it to the room as a business killer, and I chose the phrase carefully.
The uncomfortable part is that this isn't a discipline problem. Nobody is being reckless. They found something that makes their job easier and nobody gave them a sanctioned way to use it, so they used it anyway. Bans don't help; they push it further underground. The agencies that have got on top of this have done three things: given people a defined level to climb to, written a policy someone can actually follow, and put in tooling that's better than the thing their people were sneaking.
In my experience most owners are one level lower than they think.