Everyone’s using AI. Almost nobody’s governing it.
Ask five people at your company which AI tool they use, and you might get five different answers. That's not a small thing. AI has quietly become business infrastructure, and it deserves the same governance as anything else the business relies on daily. Here's how we approach it at GSD®, from choosing a single platform to building a shared knowledge file the whole team works from.
Here’s a question worth asking around the office: if you asked five people which AI tool they reach for, would you get one answer or five?
If it’s five, you’re not alone, but you do have a gap worth closing.
AI has stopped being a novelty tab people open when they’re stuck. For most of us, it’s become part of the daily toolkit, the thing we lean on to write, research, code and think things through. And that’s exactly why it deserves the same care we’d give any other piece of business infrastructure. We wouldn’t let everyone pick their own password manager or install whatever software looked interesting that week. AI shouldn’t be any different.
None of this is about putting AI in a cage. It’s about being able to answer a few simple questions with confidence:
- Which AI platforms are we actually using?
- What information is okay to share with them, and what should never leave the building?
- Who checks AI-assisted work before it reaches a client?
- Who owns the guidance, so it doesn’t quietly go stale?
Get those answers nailed down and everything else gets easier. Skip them, and every person on the team ends up building their own private way of working, not through carelessness, just because nobody told them otherwise. And a team of individual workarounds is a hard thing to quality-check.
For agencies already holding themselves to standards like ISO 27001, this isn’t even new territory. It’s the same thinking you already apply to information security, just pointed at a newer tool.
Why we built a shared knowledge file
One of the smallest changes we’ve made at GSD® has turned out to be one of the most useful: a single shared Markdown (.md) knowledge file that the whole team works from.
Instead of everyone quietly building their own mental list of prompts, preferences and company context, we’ve put it all in one place. Our file covers things like:
- Company background and services.
- Brand personality and tone of voice.
- Preferred writing style, and UK English spelling and grammar.
- Technical development standards and coding conventions.
- Internal terminology and frequently used client information.
- A clear list of what AI should never do on our behalf.
The real win isn’t just consistency, it’s momentum. When we spot a way to improve the file, we make the change once and the whole team is instantly working from the better version. Nobody has to remember to update their own settings, because there’s nothing personal to forget.
It’s a genuinely small thing. But it’s changed how consistent our output feels, day to day, person to person.
Standardising doesn’t mean standing still
None of this means we’ve gone quiet on new technology, quite the opposite. We’re regularly trying new AI models to see where they’re actually better, and where they’re just louder.
The difference is that we do it together, not in a dozen separate directions. Rather than everyone quietly adopting whatever new assistant caught their eye that week, we evaluate anything new as a team, weighing it against:
- Security and privacy.
- Reliability and quality of output.
- Commercial licensing.
- How well it fits our existing workflows, and whether it’ll still make sense in a year.
If something genuinely better comes along, we move as one organisation, together, not as a slow drift into a dozen disconnected tools that nobody quite trusts or fully understands.
Curiosity and control aren’t in tension here. Done well, one makes the other possible.
Which platform, and why it’s worth paying for
We’re happy to be specific about this: we use Claude, from Anthropic. Not because it’s the only option out there, but because it came out on top when we weighed it against our own criteria. Naming it here is really just proof that we did the work we’re recommending you do too.
We’d also encourage any business going down this route to budget for a paid plan from day one, rather than leaving staff on the free tier. It’s a small cost with a disproportionate payoff:
- No mid-project wall. Free tiers come with usage caps, and hitting one halfway through a piece of client work is exactly the moment someone reaches for an unapproved, ungoverned tool instead, quietly undoing everything a governance policy is meant to prevent.
- Real headroom for a working day. Paid plans give meaningfully more usage than free access, which matters when AI is a daily tool rather than an occasional experiment.
- Business-grade data handling. Team and Enterprise plans come with a written guarantee that your data isn’t used for model training, plus centralised billing and admin controls, the sort of assurance clients increasingly ask for, and one you can actually point to.
- The option to grow into more control. As a business scales, features like single sign-on, audit logs and configurable data retention become available on higher tiers, useful to know about even if you don’t need them on day one.
The specific plan matters less than the principle: paying properly for the tool your team relies on daily is itself a form of governance. Free access encourages workarounds. Paid access, sized to your team, keeps everyone inside the guardrails you’ve set.
Five steps to standardising AI in your business
If your organisation is already using AI in some form, here’s a practical place to start:
- Choose a primary AI platform for day-to-day work, rather than leaving it to individual preference.
- Provide paid access, so staff aren’t tempted onto unapproved tools the moment they hit a free-tier limit.
- Build shared company context, a central knowledge file, or equivalent documentation everyone works from.
- Publish an AI usage policy covering approved platforms, data handling and review processes.
- Review new platforms centrally, before they quietly become part of someone’s everyday workflow.
None of this slows innovation down. If anything, it clears the way for it. It gives your team the confidence to use AI properly, so their energy goes into the work itself, rather than into managing an ever-growing pile of tools nobody quite signed off on.
There’s a client-facing benefit here too. More and more, clients ask how agencies handle AI and their data. “We have a governed, deliberately chosen approach” is a far better answer than a shrug.
If you’re working out what this should look like for your own business, it’s a conversation we have often. Get in touch and we’ll happily talk you through how we’ve approached it at GSD®.
More information
Related articles
Why the world’s most digital brands still send things in the post
In luxury and automotive, physical communication is doing something digital can't. A look at why the printed piece survives and what makes it work.
AI at GSD®
GSD® now offers AI as a service- brand, content and product work built on AI. Led by a founder who chairs the global awards that judge AI excellence and qualified at the University of Oxford Saïd Business School in Artificial Intelligence.
2026 Allica Bank Great British Entrepreneur Awards
Professor Graham Shapiro, founder of GSD® and Reggie® Firedrill, has been named a finalist in the 2026 Allica Bank Great British Entrepreneur Awards, shortlisted in the Technology Entrepreneur of the Year category.
University of Leeds Renews GSD® Contract to 2029
The University of Leeds has renewed it’s digital supplier contract with Graham Shapiro Design until 2029.