Applied AI
The AI Already Inside Your Events Business That Nobody Signed Off

Your account manager is already using ChatGPT on a personal login. Your producer is feeding client calls into a free note taker. This is not a discipline problem, and here is what to do about it this week.
The government thinks it's moving. Ask what your team is already doing
This month the government put out its one year progress check on the AI Opportunities Action Plan. Thirty eight of fifty recommendations met, on their own scorecard. Whatever you make of that number, the direction of travel is clear: this is now infrastructure policy, not a side project.
Most events businesses I sit down with have no policy at all. Not a bad one. None. And in that gap, people have quietly made their own decisions.
That gap isn't unique to events, but it shows up in a particular way here, because so much of what this industry handles is sensitive by nature. Client budgets. Attendee lists. Unreleased programme details. Supplier pricing that would cause a headache if a competitor saw it. When shadow AI use meets that kind of material, the stakes are higher than a rewritten email, even if the rewritten email is where it starts.
The account manager, the producer, the sales exec, the designer
Here is what I actually find when I run a Discovery Lab and start asking people what they do on a normal Tuesday.
- The account manager rewrites client emails through ChatGPT on their own personal login, because the tone comes out better and faster than anything the brand template gives them.
- The producer drops a recorded client call into a free note taking tool to get a summary, because writing up notes after a two hour briefing used to eat their evening.
- The venue sales exec pastes a draft contract into an assistant "just to check it reads properly", not really thinking about what else is on that page.
- The designer generates mood board images because it is quicker than three hours on stock sites, and the client never asks where they came from.
None of this was approved. None of it was hidden, either. Nobody asked, so nobody told.
Why this isn't the telling off you think it is
The instinct, when you find this, is to tighten up. Send a memo. Remind everyone about the acceptable use policy that doesn't exist yet. I'd stop you there.
People didn't go looking for a shortcut because they're lazy. They went looking because the tools you gave them officially are slower than the ones they found themselves. That is not a people problem. That is a systems problem wearing a people costume.
If your approved software is worse than what's free on someone's phone, shadow AI isn't a rebellion. It's a rational choice made forty times a day by people trying to get home for dinner.
Blame doesn't fix that. A better default does. If the sanctioned way of working is genuinely the easiest way of working, most people will take it without being asked twice. Make it the harder option and you'll be fighting this quietly forever, one personal login at a time.
The one hour amnesty conversation
Before you write a single rule, have one conversation. Not an audit, not a disciplinary, an amnesty. Tell the team plainly: nobody is in trouble, I want to know what you're actually using and why, because I'd rather know than guess.
Run it as a straight question round the table or one to one, whichever suits your team. You will hear things you didn't expect. You will also hear the same three or four tools coming up again and again, which is useful, because it tells you where the real appetite is.
Two columns: fine, and not with client data
Once you know what's being used, sort it fast. Two columns on a whiteboard is enough.
- Fine. Drafting internal copy. Brainstorming session titles. Tidying up a rough agenda. Nothing that names a client or carries their numbers.
- Not with client data. Contracts. Attendee lists. Anything with a supplier's pricing on it. Anything the client would be unhappy to learn left your building through a tool you don't control.
That split alone removes most of the actual risk without removing any of the actual usefulness.
Pick one paid team account
Then do the boring, unglamorous thing that fixes the root cause: pay for one proper team account, on one tool, for everyone. It doesn't need to be exotic. It needs to be sanctioned, secure, and no worse to use than what people already found on their own.
This is usually the cheapest decision in the whole business. A single seat licence across a team costs less than one bad week caused by a client contract that went through the wrong window.
Three sentences people can actually remember
Skip the twelve page policy document nobody will read. Write three sentences and put them somewhere people will actually see them.
Something like: use the team account, not your own login. Nothing with a client's name or numbers goes into any AI tool unless it's on the approved list. If you're not sure, ask, you won't be told off for asking.
That's a policy your team can hold in their head on a Tuesday afternoon, which is the only kind that works.
If you want a proper look at what's actually happening inside your team, not what you assume is happening, that's the whole point of a Discovery Lab. And if you want to build a team's confidence with these tools before you write a word of policy, Zoby OS is free.