IT Blog » AI » AI defence or offence: which posture is your business in?

AI defence or offence: which posture is your business in?

Ask a room of business leaders whether they are early or late with AI and almost everyone says late. They are wrong, but the anxiety is telling.

Key takeaways

  • Recognise that nobody is ahead: across organisations of every size, no one considers the job finished, which makes this a starting line rather than a race you have lost.
  • Audit your defensive posture first: an AI usage policy, a shadow AI audit and AI security training are the three visible parts most security-minded firms already have.
  • Build the offensive posture deliberately, because impactful adoption and targeted applications do not arrive as a by-product of good governance.
  • Understand that a defence-only position feels like caution from the inside and reads as waiting from the outside.
  • Treat the gap that matters as habits rather than models, since the difference between the best model and a good enough one has narrowed for everyday business work.

At the first ramsac AI Summit in September 2026, the opening session was called four reasons not to adopt AI, which is an awkward way to start an AI summit. The reasoning was that the objections businesses raise are more honest, and usually more interesting, than the arguments made in favour. Underneath all four sat a single question that leaders ask constantly and rarely out loud.

Am I early or am I late?

The answer given to the room was that nobody is ahead. Across organisations of every size and sector, no one considers the job finished. Some have moved further than others on a particular process, but no one has arrived.

That reframes the anxiety usefully. The race most people believe they are losing, which model is smartest, has quietly stopped being the race that matters, because the distance between the most capable model and a good enough one has narrowed for most everyday business work. A different gap is opening in its place: between organisations building working habits with AI now, imperfectly, and those waiting for a cleaner moment to begin.

If that is the real gap, the useful question is not how advanced your technology is. It is what posture your organisation has actually adopted.

Defence: the posture most organisations already have

Security-minded businesses tend to arrive at AI defensively, and they tend to do it well. Defence has three visible parts, and you can check for all of them in a single meeting.

  • A written AI usage policy. Something that states what staff may and may not put into which tools, and who to ask when the answer is unclear.
  • A shadow AI audit. A deliberate look at which AI tools are already in use across the business, sanctioned or otherwise.
  • AI-specific security training. Not general security awareness with a paragraph added, but training that addresses what goes wrong with these tools specifically.

This is genuinely good work and worth having. At ramsac, as a business whose day job is cybersecurity, this is the posture we had established first, and we would expect most organisations that take their obligations seriously to recognise themselves in it.

The difficulty is what tends to come next, which is nothing.

Offence: the posture most are missing

Offence has two parts, and neither appears as a by-product of good governance.

The first is impactful adoption across the business: people in different functions genuinely working differently, not a pilot in one enthusiastic corner. The second is targeted applications aimed at the objectives the organisation already cares about, chosen because they serve the business plan rather than because they were technically interesting.

Both require somebody to decide what the organisation is trying to achieve and then go after it. A policy cannot do that work, because a policy is a boundary rather than a direction. This is the honest gap we found in our own organisation before we did any of this work with customers: strong defence, and an offensive posture that had to be built on purpose.

It matters that the two postures are not sequential. Waiting until governance is complete before considering adoption means governing an organisation that is not yet doing anything, which produces rules written in the abstract and a business that has learned nothing.

Doing it to ourselves first

There is a reason we are willing to be specific about this. A technology business is also an operational business, with a commercial team, an operations team and a finance team whose days look much like anyone else’s. The useful experiment was to treat our own organisation as the first customer: to find where the administrative weight actually sat, take some of it off, and learn what that required.

What that exercise teaches is mostly unglamorous. It is much easier to write a policy about AI than to change how a team works on a Tuesday. The obstacles are rarely technical, and the things that move are rarely the things the strategy document predicted. That is exactly why doing it before advising anyone else seemed like the minimum standard.

The other lesson is about sequencing. Defence bought the permission to experiment safely, which meant the offensive work could start without a separate argument about risk every time. Organisations that have already done the governance work are better placed than they think.

Common questions

What is the difference between an AI policy and an AI strategy?

A policy sets the boundaries of acceptable use: what staff may put into which tools and who decides. A strategy sets a direction: which business objectives AI is meant to serve and which applications are being pursued to serve them. Most organisations have the first and assume it covers the second.

Are we behind if we have not started yet?

No. The consistent picture across organisations of every size is that nobody considers the job finished. The gap that is opening is between those building working habits now and those waiting for a clearer moment, so the useful comparison is against your own position six months ago.

Does moving to offence mean relaxing our controls?

No. Good governance is judgement applied where risk and sensitivity are genuinely high, rather than a brake applied evenly across everything. A strong defensive posture is what makes it possible to experiment quickly, because the boundaries are already agreed.

Moving to offence without dropping your guard

If you recognise your organisation in the defensive posture, the next step is smaller than it sounds. It is not a transformation programme. It is choosing one part of the business where the administrative weight is heaviest, and deciding to take some of it off within an agreed boundary you have already drawn.

For organisations still building the defensive side, our best practices for your AI governance framework is the sensible starting point, and the work is worth doing properly rather than quickly. For those who have that in place and know the offensive half is missing, our AI readiness assessment gives a high-level view of where you stand across both postures and what a credible first application would be. Both sit within the wider AI transformation and strategy work we do with organisations across professional services, charity and regulated sectors.

Book an AI readiness assessment with ramsac to find out which posture your organisation is actually in, and what the other half would take.