Shadow adoption runs ahead of sanctioned adoption
Your programme does not start at zero. People were already using consumer tools for work, and if you do not measure that baseline first you will spend a year taking credit for behaviour you did not cause.
- Your baseline is not zero. Staff were using consumer AI for work long before procurement started.
- Traffic moving from an unsanctioned tool to a sanctioned one is a governance win. It is not the productivity gain being booked against it.
- Measure the baseline with an anonymous survey first. Reaching for network logs as the opening move turns measurement into surveillance, and then your numbers only show what people will be seen doing.
- Report two numbers, not one: total assisted work, and the share of it running on sanctioned tooling.
Every enterprise rollout is measured against an implied baseline of zero. Before the tool existed, nobody was doing this. After it existed, usage climbed. The climb is the programme working.
The baseline is not zero. Staff have had capable general purpose assistants on their phones since well before your procurement cycle started, and a meaningful share of knowledge work has been passing through them. When the sanctioned tool arrives, some of that traffic moves onto it. That movement looks identical to new adoption on a chart and means something quite different.
Why it matters beyond the vanity of the number
- You will over-attribute. A migration from an unsanctioned tool to a sanctioned one is a governance win, and it is worth having, but it does not create the productivity effect you are booking against it.
- You will mis-target enablement. Heavy shadow users need permission and integration. People who have never used one need something else entirely, and a single onboarding programme serves neither well.
- You will misread a plateau. If your ceiling is roughly the size of the pre-existing shadow population, the programme has converted the willing and has not yet reached anyone else. That is a specific problem with a specific fix, and it looks like general apathy on the dashboard.
Measuring the baseline without turning it into an investigation
The instinct is to go to logs. Resist it as a first move. Network and endpoint telemetry can tell you a lot about which domains people reach, and reaching for that data as the opening step converts a measurement exercise into a surveillance exercise. Once staff believe the programme is watching them, your adoption numbers become a measure of what people are willing to be seen doing.
Run an anonymous survey first, with a sample large enough that nobody can be identified, and ask about task categories rather than tools. People will tell you. The answer is usually higher than the leadership team expects and lower than the security team fears.
Where you do use technical telemetry, disclose it plainly, aggregate it before anyone sees it, and never report it at individual level for an adoption purpose. The measurement is worth having. It is not worth the trust it costs to take it quietly.
The restatement
Report two numbers from the start: total assisted work, and share of it running on sanctioned tooling. The first is the productivity story. The second is the governance story. Collapsing them into one adoption percentage hides both.