CRAIG WILLETTS ISO & BUSINESS CONSULTANT
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards

How to Tell If Your Team Is Using AI 

Picture
Most managers aren't actually worried about AI use itself — they're worried about not knowing it's happening. Unattributed AI use in reports, client emails, or code creates a visibility gap, and visibility gaps are where governance problems start. Before getting into policy, it helps to know what to actually look for.

In this article:
- General tells that text (or code) was AI-generated
- Tells specific to each major AI model
- Why detection alone isn't the answer
- AI safety fundamentals every business needs
- Practical steps for managers

General Tells Across All AI Models

A few patterns show up regardless of which tool was used:

- Uniform sentence length. Human writing naturally varies — short punchy sentences mixed with longer ones. Human writing naturally varies—we mix short sentences with long ones, a punchy three-word sentence followed by a 30-word complex one, while AI text tends to keep sentences at a similar length throughout, creating a monotonous rhythm.
- Excessive hedging. AI models are trained to avoid definitive claims, so they hedge constantly, and when almost every claim is softened with qualifiers, that's a pattern AI tends to produce — human writers are more willing to take a stance.
- Em dash overuse. This has become one of the most discussed AI writing signatures in 2025-2026 — AI models, particularly ChatGPT, use em dashes at a much higher rate than typical human writers, and if you see them in more than 30% of sentences, it's worth flagging.
- Stock phrases and filler. Watch for lines like "in today's fast-paced world" or "it is important to note that" — the stiff clause "notable works include" shows up more than 120 times as often in AI prose as in prose written by people, and the stock phrase "today's fast-paced world" appears 107 times more often.
- Rigid structure. A tendency to follow a rigid 'Intro-Point-Point-Point-Conclusion' format is common, along with fluff sentences that sound polished but carry no real data or insight.
- Overused vocabulary. AI tends to use 'hallmark' vocabulary including words like tapestry, delve, leverage, and testament, which often signal a lack of human nuance.

Tells Specific to Each Major AI

Different models have distinguishable habits, which is useful if you're trying to work out *which* tool was used, not just *whether* one was:

- ChatGPT — overuses em dashes and triplets, and historically leaned on lengthy introductions, ethical consideration paragraphs, and words like "delve" and "landscape", though many of these have since been trained out or become less common as users grew wise to them.
- Claude — tends to be more verbose with caveats ("it might be", "it seems that"), and Claude responses tend to be more concise than responses from ChatGPT overall, with a tendency to avoid curly quotation marks in raw output.
- Gemini — produces more structured, list-heavy content, and like Claude, tends to be more concise than ChatGPT or Grok.
- Grok — overuses superficially "scientific" words like causal, empirical, correlate, and continues to overuse underscore.
- Cross-model quirk — the word "quiet" appears everywhere in AI output — quiet confidence, quiet rebellion, quietly growing — a pattern flagged as consistent across Claude, ChatGPT, and Gemini. Unsolicited, therapy-style reassurance ("You're not imagining it," "You're not alone") turning up in business documents is another shared tell.

Worth flagging: none of this is foolproof. AI detectors look for 'perplexity' and 'burstiness,' and if your writing style is very formal or uses predictable patterns, a detector might mistakenly flag it as AI — so treat these as indicators worth a conversation, not proof of anything.

Why Detection Alone Isn't the Real Answer

Here's the uncomfortable truth: spotting AI-written text tells you almost nothing about the risk that actually matters. The bigger issue isn't whether an email was drafted with ChatGPT — it's what your organisation doesn't know is happening with AI at all.

When CIOs are asked how many AI tools their employees are using, the answer is usually somewhere between 60 and 70 — organisations assume that covers the landscape, but once monitoring is turned on, the real number is often 200 or even 300 AI tools in use. That gap between the approved AI stack and the actual one is where genuine exposure sits.

AI Safety Fundamentals for Business

- Build a real system inventory. An honest AI system inventory covers all AI deployments in organizational use — including tools used by individual departments without centralised visibility, vendor-embedded AI not separately evaluated, and shadow AI tools — classified by risk level, regulatory exposure, and business criticality, with clear ownership identified.
- Protect data at the point of use, not just at the policy level. Even with an approved AI tool, employees can inadvertently share data that shouldn't leave the organisation, and a policy that says "don't paste customer data into AI tools" is only as effective as every employee's ability to remember and follow it in the moment — policy-based data protection at the browser level solves this by enforcing rules in real time. This matters given that 35% of employees have entered proprietary company information into public AI tools.
- Make governance cross-functional. AI governance that lives exclusively in IT and security produces policies that address only the risk surface IT can see — effective governance is cross-functional, with legal owning contractual and liability exposure, compliance owning regulatory mapping, business units owning the use case inventory, HR owning training and communication, and security owning detection and response.
- Keep humans in the loop on critical decisions. Critical business decisions should not rely entirely on AI-generated outputs — human review helps reduce risks related to AI hallucinations and misinformation.
- Enable rather than block. Governance that enables rather than blocks matters because the alternative isn't no AI, it's ungoverned AI — and blocking without an alternative creates substitution, not elimination, simply moving the risk to other tools.

Practical Steps for Managers

- Don't treat AI-written drafts as inherently a problem — ask about attribution and review process instead of policing style alone.
- Run (or commission) a shadow AI discovery exercise to see what's actually in use versus what's approved.
- Put a simple, memorable data rule in front of every employee: if you wouldn't post it publicly, don't paste it into an AI tool.
- Assign clear ownership for AI risk — for every AI system, one person should own the risk.
- Revisit policy regularly — a significant share of organisations report their AI policies are either too restrictive for current tools or too broad to be meaningful, so treat this as a living framework, not a one-off document.

The Bottom Line

Learning to spot ChatGPT's em dashes or Gemini's list-heavy structure is a useful party trick, but it isn't governance. The organisations getting this right are focusing less on catching AI use after the fact and more on building visibility, ownership, and sensible controls before problems surface.

If you'd like support building a practical AI governance framework for your business, CAW Consultancy can help.

Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.




​

If you need any advice or have any questions, then please get in touch - [email protected]

Don't forget to share this blog to help others with get great free advice

Picture
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards