
By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer
TL;DR The SAS and IDC Data and AI Impact Report found that 65% of organizations are currently using AI and 32% plan to begin within twelve months, meaning the AI experimentation window is effectively closed and the accountability window is now open. Chuck Gallagher, business ethics keynote speaker and AI speaker and author, argues that for small and medium-sized businesses, the most consequential leadership decision of the next three years is not which AI tools to use — it is whether to build the ethical governance that makes those tools trustworthy before failure makes it mandatory.
There is a predictable arc to how organizations adopt powerful new technologies. First comes the experiment — a pilot program, a trial subscription, a department-level initiative. Then comes the scaling, often faster than anticipated. Then comes the failure — not always dramatic, sometimes quiet and cumulative — that reveals the accountability gaps left open during the experiment phase. Then comes the remediation, which costs three to ten times more than prevention would have. I have watched this arc play out across industries for three decades. AI is following it with unusual speed.
The SAS and IDC Data and AI Impact Report documented where organizations currently stand on this arc. Sixty-five percent are already using AI in some form. Thirty-two percent plan to begin within the next twelve months. Generative AI adoption has eclipsed traditional AI, with 81% of AI-using organizations deploying it compared to 66% for traditional machine learning. Agentic AI — systems that act autonomously — already has 52% adoption. The experiment phase is not coming. For most businesses, it is over. The question now is what kind of accountability infrastructure was built during the experiment, and what kind of ethical leadership will govern the scaling.
As an AI Speaker and Author, Here Is What the Transition Requires
As an AI speaker and author, I spend considerable time in boardrooms and at leadership retreats with organizations that are trying to figure out what responsible AI use actually looks like in practice. The SAS and IDC report offers a framework that I find useful as a starting point. Their Trustworthy AI Index measures the degree to which organizations have invested in governance, explainability, ethical safeguards, risk management, and compliance — the practices that make AI systems reliably ethical, not just theoretically so. The report found that organizations with stronger Trustworthy AI Index scores consistently achieve higher Impact Index scores, meaning better measurable business results.
For SMBs, the actionable insight is this: trustworthy AI practices are not a cost center. They are a return driver. The report’s data makes clear that the organizations seeing the strongest AI returns are not the ones who adopted the technology most aggressively. They are the ones who adopted it most responsibly. Ireland and Australia/New Zealand, for example, combine high trustworthiness scores with strong impact scores — proof that governance and performance are not in tension. They are correlated.
The trust dilemma — where perceived confidence in AI exceeds its actual trustworthiness — affects 46% of organizations globally. According to the report, it is slightly more pronounced in North America (47%) and Asia Pacific (47%), and even Europe, with its stronger regulatory environment, still sees 46% of organizations falling into this gap. The geography does not matter as much as the pattern: most organizations have more confidence in their AI than their governance practices justify. SMBs are not exempt from this pattern. They are arguably its most common expression.
What Does Moving From Experiment to Accountability Actually Look Like?
The first element of the transition is documentation. Every AI tool in active use within an SMB should be documented in plain language: what it does, what data it uses, what decisions it influences, and what the review process is before its outputs affect people. This is not a compliance exercise. It is a leadership discipline. If a business leader cannot describe how an AI tool works in terms a non-technical employee would understand, that tool has not been adequately evaluated for responsible deployment.
The second element is accountability assignment. The SAS and IDC report found that only about 25% of organizations have a central group dedicated to AI governance. For an SMB, a central group is not realistic or necessary. What is necessary is a named individual with explicit responsibility for each AI tool in use. Not collective responsibility — individual responsibility. When outputs cause harm, diffuse accountability is functionally equivalent to no accountability. Someone needs to be the person who answers the question: “When did you know, and what did you do?”
The third element is the feedback loop. Responsible AI use requires mechanisms for detecting when outputs are wrong, biased, or harmful. For large organizations, that might mean automated monitoring systems. For SMBs, it might mean a monthly review of AI-assisted decisions that affected customers, flagging anything that produced complaints, anomalies, or outcomes that surprised the human reviewers. The sophistication of the feedback loop should match the scale of the organization. But the loop has to exist. AI without feedback is not a learning system. It is a risk that compounds over time without correction.
The Leadership Responsibility That Technology Cannot Substitute
The SAS and IDC report closes with an observation that I want to put plainly for every SMB leader reading this: solving the trust dilemma is not optional. The researchers write that it is “the prerequisite for sustainable impact.” Organizations that do not resolve the gap between their confidence in AI and the actual trustworthiness of their AI systems will find that gap closing in the worst possible way — through a failure that makes the cost of governance look trivial by comparison.
I have spoken to audiences about choices and consequences for more than twenty years. The consistent lesson is this: the rationalizations that feel most reasonable in the moment are usually the ones with the highest long-term cost. The decision to defer AI governance because current tools seem to be working fine is a rationalization. The assumption that AI vendors have built sufficient ethics into their systems so you do not have to is a rationalization. The belief that your organization is too small to face the consequences that larger organizations face is a rationalization.
As a business ethics keynote speaker and AI speaker and author, the single most important thing I want SMB leaders to understand from the SAS and IDC research is that every choice has a consequence. AI adoption without intentional governance is a choice. It is made every day that accountability structures are deferred. And it will have consequences — not because the technology is inherently dangerous, but because every powerful tool used without adequate oversight eventually reveals the cost of that oversight’s absence. The organizations that build trust intentionally will not just avoid those costs. They will outperform the ones that did not. The data from SAS and IDC says so.
Frequently Asked Questions
Q: How widely has AI been adopted, and is the experimentation phase over?
A: According to the SAS and IDC Data and AI Impact Report, 65% of organizations globally are currently using AI, and 32% plan to begin adoption within the next twelve months. Generative AI is in use at 81% of AI-adopting organizations, making it the dominant form in active deployment. Agentic AI — systems that take autonomous action — has reached 52% adoption. These figures suggest that for most businesses, the experimental phase of AI adoption has concluded and organizations are now managing live, consequential deployments.
Q: What is the Trustworthy AI Index, and why should SMBs care about it?
A: The Trustworthy AI Index, introduced by SAS and IDC in their Data and AI Impact Report, measures how much an organization has invested in the practices that make AI systems reliable and ethical — including data governance, responsible AI frameworks, compliance, explainability, and risk management. The report found a direct correlation between Trustworthy AI Index scores and Impact Index scores, meaning organizations with stronger governance practices consistently achieve greater measurable business results from AI. Chuck Gallagher, business ethics keynote speaker and AI speaker and author, describes this as proof that ethical AI governance is a return driver, not a cost center.
Q: What are the three minimum accountability practices every SMB needs for AI?
A: Based on the principles in the SAS and IDC Data and AI Impact Report, every SMB using AI should implement three baseline accountability practices. First, document every AI tool in plain language — what it does, what data it uses, and what decisions it influences. Second, assign named individual accountability for each tool’s outputs — not collective or departmental responsibility, but personal ownership. Third, build a feedback loop that regularly reviews AI-assisted decisions for errors, anomalies, and harm. These three practices do not require a compliance team or a technology budget. They require leadership commitment.
Q: What does the trust dilemma look like in practice for a small business?
A: In practical terms, the trust dilemma at SMB scale looks like this: a business owner deploys an AI tool that performs well in initial trials, concludes that it is reliable, and integrates it into consequential processes without building review mechanisms or governance structures. Over time, the tool produces outputs influenced by data biases, system limitations, or context mismatches that were never tested for. The organization discovers the problem only after it has affected customers or produced a compliance issue. The SAS and IDC report found that 46% of organizations globally face this exact pattern — and at SMB scale, recovery from the resulting damage is significantly harder than at enterprise scale.
Q: Is it possible to use AI ethically as a small business without a dedicated ethics or compliance team?
A: Yes. Ethical AI use does not require a dedicated compliance infrastructure — it requires intentional leadership. The SAS and IDC report found that organizations that invest in governance, explainability, and ethical safeguards outperform those that do not, regardless of organizational size. For SMBs, the practical equivalent of an enterprise governance team is a named individual with documented accountability for AI tool performance, a plain-language description of how each tool works and what it affects, and a regular review process that catches errors before they compound. These practices are accessible to any organization willing to prioritize them.
Share Your Thoughts
Here is the question I want you to answer honestly before you close this article. At this moment, in your organization, is AI adoption ahead of AI accountability? If the answer is yes — and for most SMBs it is — what is the first specific step you will take to close that gap? Share it in the comments below. I read every comment and I will respond to yours. The five questions below are an invitation to keep the thinking going past the point where most business conversations stop.
Five Questions for Further Thought and Consideration
1. If you had to defend your organization’s current AI governance practices to a customer who was directly affected by an AI error, what would you say?
2. What is the difference between using AI responsibly and feeling like you are using AI responsibly? Which one do you currently have?
3. The SAS and IDC report found that resolving the trust dilemma is “the prerequisite for sustainable impact.” What would it cost your business if AI performance plateaued or reversed because the trust foundation was never built?
4. Who in your organization would detect an AI error first — and would they have both the awareness and the authority to act on it?
5. If every choice has a consequence, what are the likely consequences of your current level of AI accountability — and are you comfortable owning them?
