Everyone Has a Prompt. Nobody Has a Method.

The numbers show use. They do not show adoption.

Three in four UK financial services firms are using AI. In a 2024 review, the Bank of England and FCA found that 46% of firms using it only partly understood the technologies they were running. Across the wider economy, 72% of businesses cite marketing as an application area, yet 77% of adopters had seen no change in revenue, and fewer than half of staff in adopting firms actually use the tools. Licences issued, active users, prompts shared, time reportedly saved: these are reassuring signs of movement. They reveal almost nothing about whether the team has changed how it works.

That gap is an operating-model problem, and it is what this field note is about. The prompt matters, but it is one component of a system. Quality can still depend on who wrote the prompt. Sensitive data can still be handled six different ways. Review effort can quietly move downstream and never appear in the productivity number. A tool can improve the first stage of a task without improving the workflow, and a person can get faster without the team getting more capable.

You can download the full field note as a PDF, or read the argument in three parts below.

Activity is not capability

Adoption is best understood as a transfer of ownership: individual, then team, then organisation. There are six levels, from tool access to measured transformation, and the first three need almost no leadership. Someone who finds that an hour of rewriting now takes twenty minutes does not need a programme to keep doing it.

The step to level four is different. It means converting one person's tacit judgement into an explicit method, and deciding which parts of their approach transfer and which depend on expertise no template captures. This is where most organisations stall: the prompt is visible, so it gets the focus, while the surrounding judgement stays private with the individual.

We go deeper on this in Activity is not capability: the six levels of AI adoption.

Task shape decides suitability, and cost of error decides control

The useful question is not what AI can do. It is what uncertainty the organisation will accept in exchange for speed, scale or creative range. Generative AI earns its place where inputs are unstructured, several answers are acceptable, and output is reviewed before it matters. It is weaker where the same rule must hold every time. Many processes do not need intelligence; they need consistency, and a rule, template or deterministic automation is easier to test, explain and maintain.

Frequency and time saved get used to prioritise use cases. Neither tells you whether the task is suitable. That is set by the consequence of a wrong answer, how easily an error is detected, whether it can be reversed, and whether you can explain how the output was produced. A five-minute task done thousands of times is only an obvious automation target if its errors are cheap and visible.

More on this in Where AI earns its place, and where a rule is safer.

Governance has to change the workflow, not the policy binder

Many AI policies read as if risk enters when an employee opens a tool. It enters when an output moves to the next stage of work: a summary becomes a recommendation, a draft becomes a client communication, a classification changes how someone is treated. A prompt library cannot carry an operating model. It records an instruction, not which source was approved, what the output must contain, how failure is detected, or who may change the method.

Control happens when approved inputs, review points, access, testing, escalation and records shape the sequence before the output has consequences. Controls are engineered to what the output can do, not copied from a checklist. A governed workflow is one the organisation can inspect, reproduce, challenge and stop.

The full picture is in Governed workflows: the eight stages that make a method repeatable.

The whole thing on one page: seven decisions

Seven decisions separate visible AI activity from an owned, measurable capability. Each needs a leadership question answered and credible evidence of readiness before the work scales.

  • Purpose. What business outcome should improve? Evidence: a named owner and a credible baseline.
  • Method. Why is AI preferable to a rule, existing automation or manual judgement? Evidence: a comparative advantage specific to the task.
  • Data. Which inputs are permitted, reliable and appropriately accessible? Evidence: approved sources, permissions and data boundaries.
  • Control. How will weak output be detected before it creates a consequence? Evidence: testing, review, thresholds, escalation and fallback.
  • Ownership. Who owns the workflow, the final output and technical change? Evidence: named working roles, not only executive accountability.
  • Value. What improves once review, correction and operating cost are included? Evidence: a balanced scorecard against the baseline.
  • Scale. Can another team reproduce the result? Evidence: replication without weaker quality or controls.

Most programmes can answer the first two. The last three are where the honest gaps usually sit. If one is missing, that is the next piece of work.

Why this connects to the company brain

An operating model tells you how a single workflow should be selected, controlled and measured. The reason the second workflow costs less than the first is a separate idea: a context layer the firm owns, so knowledge does not reset every time a new tool arrives. If the method is how you build one workflow well, the company brain is what makes the next one cheaper.

How we apply it

We deliver this operating model as an engineering engagement rather than a programme. A gated path from assessment to production, where each gate answers one of the seven decisions with evidence rather than a slide: assess whether it is worth building, build the controlled workflow inside your stack, then prove it against the process it replaces before it spreads. The frameworks tell you what has to be true. The build makes it true and leaves the proof behind. Regulated by design, not by policy document, and the firm keeps the software.

Want a second opinion on an AI workflow before it scales? Download the field note, or send us the use case and we will tell you plainly whether it passes.

Adapted with permission from Beyond the Prompt: A Practical Operating Model for Using AI in Marketing, Will Tisdall, July 2026.