H Handrail Lesson ~8 min read
Companion · Alternate Module 0 walkthrough

Where Your Firm Actually Stands

A 6-question checklist that places your firm — not any one person — on a 0-to-4 AI-usage ladder, and shows why 'we don't use AI' is not the same thing as 'we're not exposed.'

In one line

Every course on AI safety assumes you know your starting point. Most cautious, non-technical firms get this wrong in the same direction: they assume that because nobody officially 'adopted' AI, there is nothing to worry about yet. That assumption is the single most common reason firms get caught off guard — not because they used AI carelessly, but because they didn't realize their vendors, their inbox, and the people trying to scam them were already using it. This module fixes that before any lesson on 'how to use AI safely,' because you can't manage a risk you've placed on the wrong rung of the ladder.

The short version — what to remember
  • Level 0 ("we don't use AI") is not a safe zone — it just means your risk comes entirely from outside (scams, vendors, cloned voices), not from your own choices.
  • The 6-question checklist places the firm, not any one employee — most firms discover they're a mix of levels, not a single clean number.
  • AI exposure usually arrives through everyday software features and one curious employee, not through a formal "adoption" decision anyone remembers making.
  • Naming your level isn't a demand to change anything today — it's what determines which real-world case studies the rest of the course will show you.
  • The most common gap is between the level a firm assumes it's at and the level it's actually at — and that gap is where real incidents happen.
A real (anonymized) example

A 12-person property management firm was certain it 'didn't use AI' — no staff had ChatGPT accounts, no policy existed. Three weeks after that self-assessment, the office manager received an email that appeared to come from a long-standing maintenance contractor, referencing a real recent job by name, written in flawless, familiar-sounding English, asking for their bank details to be updated for the next invoice. The email had been generated by a scammer using an AI tool trained on publicly available writing samples and the contractor's own leaked email signature. The firm updated the bank details and paid the next invoice — nearly $9,000 — to the scammer's account before the real contractor called asking why they hadn't been paid. The firm's honest self-assessment was correct: they were at Level 0, with zero AI adoption of their own. But Level 0 firms are not attacker-proof — they are simply exposed in a different way, and this is exactly the case the rest of the course opens with.

Reflect

A few open questions — nothing to trip on

These are to think through, not a test — there's no score and no wrong answer. Jot a line if it helps, then open the note to see what a careful answer usually considers. Nothing is saved or shown to your admin.

Question 1 of 4

Your firm has never signed up for ChatGPT or any AI tool, and has no AI policy. What level does that place you at, and does it mean you're safe from AI-related risk?

See what a careful answer considers

A careful answer usually lands on: Level 0 — but you're still exposed, because attackers, vendors, and everyday software already use AI around you. Level 0 describes firms with no AI adoption of their own — but the ladder exists precisely because that firm is still exposed, just from a different direction: AI-generated scams, cloned voices, and AI features already switched on inside vendor software.

Question 2 of 4

One employee occasionally uses an AI chat tool on their own initiative to tidy up emails, with no company guidance. Which level does this usually indicate?

See what a careful answer considers

A careful answer usually lands on: Level 1 — occasional, individual use with no policy. Occasional, self-initiated use by one or two people — without any firm-wide decision or guidance — is the classic Level 1 pattern, and it's the most common way firms move off Level 0 without anyone deciding it should happen.

Question 3 of 4

Why does this module ask you to name your level before teaching any 'how to use AI safely' rules?

See what a careful answer considers

A careful answer usually lands on: Because your level determines which real case studies and lessons the rest of the course shows you. The placement isn't a grade or a formality — it directly sets which case studies and examples come next, so the course can show you risks that match where your firm actually stands, plus one level ahead.

Question 4 of 4

A firm's CRM software has an AI-powered auto-summary feature that was switched on by default when the vendor updated it — nobody at the firm turned it on deliberately. Where does this likely place them?

See what a careful answer considers

A careful answer usually lands on: At least Level 3, because AI is now built into a system the firm relies on, whether or not anyone chose it. Level 3 is about AI embedded inside tools you already use and rely on — vendor-switched-on features count, even without a deliberate choice by the firm. Level 4 would require the system to take actions without a human reviewing or approving them, which a summary feature doesn't do.

Read the full written lesson (~8 min)

The comfortable lie: 'We don't use AI here'

If you asked ten small, careful firms whether they use AI, most would say no — and mean it honestly. Nobody has a ChatGPT subscription on the company card. Nobody was told to use AI. So the firm assumes it sits outside this whole conversation.

That assumption is the single biggest blind spot this course exists to close. Not using AI yourselves does not mean AI isn't already touching your business. Three things are true at the same time, even at a firm that has never typed a prompt:

  • Your email provider, invoicing software, and phone system almost certainly already have AI features quietly switched on — spam filtering, auto-suggested replies, voicemail transcription.
  • Your suppliers, bank, and insurer are using AI on their end, and their AI-generated communications now land in your inbox indistinguishable from a human's.
  • People who want to scam you — fake invoices, fake supplier emails, fake 'urgent' calls from 'head office' — are using AI to make their attempts far more convincing than anything you've seen before.

We call this Level 0 on the ladder: a firm with no AI adoption of its own, sitting inside a world where AI is already being used around it and, sometimes, against it. Level 0 is not the safe end of the scale. It's the starting line — and the reason this course opens here, before any lesson on 'using AI well.'

The six questions that actually place you

Forget the word "adoption" for a moment — it makes people think of a big decision, a rollout, a policy meeting. Real AI exposure creeps in through small, everyday choices nobody remembers deciding. Answer these six questions honestly, as a group, thinking about the whole firm rather than any one person:

  1. Has anyone at the firm ever used a chat tool like ChatGPT, Copilot, or Gemini for work — even once, even for something small like tidying up an email or looking up a phrase?
  2. Do any of your everyday tools already have an "AI" or "smart" feature switched on — auto-reply suggestions in email, meeting summaries, spam/phishing filtering, a chatbot on your website?
  3. Has anyone used an AI voice, photo, or video tool for firm business — even something as ordinary as a phone app that cleans up a photo or generates a voice message?
  4. Does any system take an action on its own, without a person clicking "approve" first — auto-scheduling, auto-replying, automatically approving a routine invoice?
  5. Has anyone here recently received a message that felt oddly polished, personal, or urgent — an email, call, or voicemail that used a name, a voice, or details that made it feel legitimate, but something felt slightly off?
  6. Is there anything written down — even one paragraph — about what staff can and can't do with AI tools at work?

Notice what these questions are not asking: they don't ask whether you have an "AI strategy," a budget, or a training program. They ask what is already true today. Most firms answer "yes" to at least two or three of these without ever having made a deliberate choice to use AI at all.

The ladder, in plain language

Here is what each answer pattern usually means, level by level. You are not trying to get a "good" score — you're trying to see clearly where you stand, because the rest of this course will show you real cases at your level and the level just above it.

  • Level 0 — No adoption, but not immune. You answered "no" to questions 1–4, but recognised something in question 5. Nobody here has chosen to use AI, but AI-generated scams, vendor tools, and spam filters already reach your firm daily. Your risk is entirely about being targeted, not about your own mistakes.
  • Level 1 — Occasional, individual use. One or two people quietly use a chat tool now and then, on their own initiative, with no guidance from the firm. This is the most common starting point once a firm moves off Level 0, and it usually happens without anyone deciding it should.
  • Level 2 — Routine, everyday use. Several people use AI tools regularly for real tasks — drafting quotes, summarising notes, writing emails — as a normal part of how they work, even though it's still informal and undocumented.
  • Level 3 — Built into your systems. AI features are switched on inside the software you already pay for and rely on — your CRM, scheduling tool, or accounting package — whether or not anyone consciously turned them on.
  • Level 4 — Acting without a human click. Some process now runs on its own: an assistant that sends replies, books appointments, or approves routine items without a person reviewing each one first. Very few small firms are fully here, but pieces of Level 4 show up earlier than people expect — inside a single automated workflow, not the whole business.

Most firms are not one clean level — they're mostly Level 0 or 1, with a stray Level 3 feature already switched on inside a piece of software nobody thinks of as "AI." That mix is normal. The point of this exercise is simply to see it plainly.

Why we're telling you this before asking you to change anything

This module doesn't ask you to adopt AI, ban it, or write a policy today. It asks you to look honestly at where you already stand, because two things are quietly true for almost every cautious firm reading this:

  • You cannot opt out of Level 0. Even a firm that bans every AI tool internally is still exposed to AI-written scam emails, AI-cloned voices on the phone, and AI features baked into software you didn't choose. "We haven't adopted AI" protects you from exactly nothing on that front.
  • Most real incidents happen one level above where people think they are. A firm that believes it's at Level 0 ("we don't use AI") often has someone quietly at Level 1 or 2 already — and that gap between the honest answer and the assumed answer is where mistakes happen unnoticed.

Naming your level isn't a verdict and it isn't a demand to move up or down the ladder. It's a map. Everything else in this course — the real cases, the plain-language rules, the "AI advises, human decides" habit — will be shown to you at the level that matches your firm, and one level above it, so you can see what's coming next before you get there.

What your score sets up for the rest of the course

Keep your six answers somewhere. The lessons that follow use them directly:

  • If you're mostly Level 0, the next case studies focus on scams and impersonation aimed at you — the fake supplier email, the cloned voice on a phone call — because that's where your real exposure sits today.
  • If you have any Level 1 or 2 answers, you'll also see cases about small, individual mistakes: sharing the wrong information with a chat tool, trusting a confident-sounding but wrong AI answer, or acting on AI output without checking it.
  • If any Level 3 features are already switched on in your software, later lessons will show you what to check in tools you already own, in plain language, without needing to understand how they work underneath.

Nobody is graded on this. There's no "failing" level. The only mistake is assuming your level is lower than it actually is — because that's the one assumption this whole course is built to correct.

This lesson is written and reviewed by named humans. Content current as of 21 July 2026. See the Trust Center for our review process and AI-assistance disclosure.