Read the full written lesson (~8 min)
The comfortable lie: 'We don't use AI here'
If you asked ten small, careful firms whether they use AI, most would say no — and mean it honestly. Nobody has a ChatGPT subscription on the company card. Nobody was told to use AI. So the firm assumes it sits outside this whole conversation.
That assumption is the single biggest blind spot this course exists to close. Not using AI yourselves does not mean AI isn't already touching your business. Three things are true at the same time, even at a firm that has never typed a prompt:
- Your email provider, invoicing software, and phone system almost certainly already have AI features quietly switched on — spam filtering, auto-suggested replies, voicemail transcription.
- Your suppliers, bank, and insurer are using AI on their end, and their AI-generated communications now land in your inbox indistinguishable from a human's.
- People who want to scam you — fake invoices, fake supplier emails, fake 'urgent' calls from 'head office' — are using AI to make their attempts far more convincing than anything you've seen before.
We call this Level 0 on the ladder: a firm with no AI adoption of its own, sitting inside a world where AI is already being used around it and, sometimes, against it. Level 0 is not the safe end of the scale. It's the starting line — and the reason this course opens here, before any lesson on 'using AI well.'
The six questions that actually place you
Forget the word "adoption" for a moment — it makes people think of a big decision, a rollout, a policy meeting. Real AI exposure creeps in through small, everyday choices nobody remembers deciding. Answer these six questions honestly, as a group, thinking about the whole firm rather than any one person:
- Has anyone at the firm ever used a chat tool like ChatGPT, Copilot, or Gemini for work — even once, even for something small like tidying up an email or looking up a phrase?
- Do any of your everyday tools already have an "AI" or "smart" feature switched on — auto-reply suggestions in email, meeting summaries, spam/phishing filtering, a chatbot on your website?
- Has anyone used an AI voice, photo, or video tool for firm business — even something as ordinary as a phone app that cleans up a photo or generates a voice message?
- Does any system take an action on its own, without a person clicking "approve" first — auto-scheduling, auto-replying, automatically approving a routine invoice?
- Has anyone here recently received a message that felt oddly polished, personal, or urgent — an email, call, or voicemail that used a name, a voice, or details that made it feel legitimate, but something felt slightly off?
- Is there anything written down — even one paragraph — about what staff can and can't do with AI tools at work?
Notice what these questions are not asking: they don't ask whether you have an "AI strategy," a budget, or a training program. They ask what is already true today. Most firms answer "yes" to at least two or three of these without ever having made a deliberate choice to use AI at all.
The ladder, in plain language
Here is what each answer pattern usually means, level by level. You are not trying to get a "good" score — you're trying to see clearly where you stand, because the rest of this course will show you real cases at your level and the level just above it.
- Level 0 — No adoption, but not immune. You answered "no" to questions 1–4, but recognised something in question 5. Nobody here has chosen to use AI, but AI-generated scams, vendor tools, and spam filters already reach your firm daily. Your risk is entirely about being targeted, not about your own mistakes.
- Level 1 — Occasional, individual use. One or two people quietly use a chat tool now and then, on their own initiative, with no guidance from the firm. This is the most common starting point once a firm moves off Level 0, and it usually happens without anyone deciding it should.
- Level 2 — Routine, everyday use. Several people use AI tools regularly for real tasks — drafting quotes, summarising notes, writing emails — as a normal part of how they work, even though it's still informal and undocumented.
- Level 3 — Built into your systems. AI features are switched on inside the software you already pay for and rely on — your CRM, scheduling tool, or accounting package — whether or not anyone consciously turned them on.
- Level 4 — Acting without a human click. Some process now runs on its own: an assistant that sends replies, books appointments, or approves routine items without a person reviewing each one first. Very few small firms are fully here, but pieces of Level 4 show up earlier than people expect — inside a single automated workflow, not the whole business.
Most firms are not one clean level — they're mostly Level 0 or 1, with a stray Level 3 feature already switched on inside a piece of software nobody thinks of as "AI." That mix is normal. The point of this exercise is simply to see it plainly.
Why we're telling you this before asking you to change anything
This module doesn't ask you to adopt AI, ban it, or write a policy today. It asks you to look honestly at where you already stand, because two things are quietly true for almost every cautious firm reading this:
- You cannot opt out of Level 0. Even a firm that bans every AI tool internally is still exposed to AI-written scam emails, AI-cloned voices on the phone, and AI features baked into software you didn't choose. "We haven't adopted AI" protects you from exactly nothing on that front.
- Most real incidents happen one level above where people think they are. A firm that believes it's at Level 0 ("we don't use AI") often has someone quietly at Level 1 or 2 already — and that gap between the honest answer and the assumed answer is where mistakes happen unnoticed.
Naming your level isn't a verdict and it isn't a demand to move up or down the ladder. It's a map. Everything else in this course — the real cases, the plain-language rules, the "AI advises, human decides" habit — will be shown to you at the level that matches your firm, and one level above it, so you can see what's coming next before you get there.
What your score sets up for the rest of the course
Keep your six answers somewhere. The lessons that follow use them directly:
- If you're mostly Level 0, the next case studies focus on scams and impersonation aimed at you — the fake supplier email, the cloned voice on a phone call — because that's where your real exposure sits today.
- If you have any Level 1 or 2 answers, you'll also see cases about small, individual mistakes: sharing the wrong information with a chat tool, trusting a confident-sounding but wrong AI answer, or acting on AI output without checking it.
- If any Level 3 features are already switched on in your software, later lessons will show you what to check in tools you already own, in plain language, without needing to understand how they work underneath.
Nobody is graded on this. There's no "failing" level. The only mistake is assuming your level is lower than it actually is — because that's the one assumption this whole course is built to correct.