How to Tell If Your Team Is Using AI (And Why That’s Not the Real Problem)

Most managers are not actually worried about AI use itself — they are worried about not knowing it is happening. Unattributed AI use in reports, client emails, or code creates a visibility gap, and visibility gaps are where governance problems start. Before getting into policy, it helps to know how to tell if your team is using AI — but more importantly, why detection alone is not the answer.

In this article:
General tells that text (or code) was AI-generated
Tells specific to each major AI model
Why detection alone is not the answer
AI safety fundamentals every business needs
Practical steps for managers

General Tells Across All AI Models

A few patterns show up regardless of which tool was used:

Uniform sentence length. Human writing naturally varies — short punchy sentences mixed with longer ones. Human writing naturally varies; we mix short sentences with long ones, a punchy three-word sentence followed by a 30-word complex one, while AI text tends to keep sentences at a similar length throughout, creating a monotonous rhythm.
Excessive hedging. AI models are trained to avoid definitive claims, so they hedge constantly, and when almost every claim is softened with qualifiers, that is a pattern AI tends to produce — human writers are more willing to take a stance.
Em dash overuse. This has become one of the most discussed AI writing signatures in 2025-2026 — AI models, particularly ChatGPT, use em dashes at a much higher rate than typical human writers, and if you see them in more than 30 percent of sentences, it is worth flagging.
Stock phrases and filler. Watch for lines like “in today’s fast-paced world” or “it is important to note that” — the stiff clause “notable works include” shows up more than 120 times as often in AI prose as in prose written by people, and the stock phrase “today’s fast-paced world” appears 107 times more often.
Rigid structure. A tendency to follow a rigid Intro-Point-Point-Point-Conclusion format is common, along with fluff sentences that sound polished but carry no real data or insight.
Overused vocabulary. AI tends to use hallmark vocabulary including words like tapestry, delve, leverage, and testament, which often signal a lack of human nuance.

Tells Specific to Each Major AI

Different models have distinguishable habits, which is useful if you are trying to work out which tool was used, not just whether one was:

ChatGPT — overuses em dashes and triplets, and historically leaned on lengthy introductions, ethical consideration paragraphs, and words like “delve” and “landscape”, though many of these have since been trained out or become less common as users grew wise to them.
Claude — tends to be more verbose with caveats (“it might be”, “it seems that”), and Claude responses tend to be more concise than responses from ChatGPT overall, with a tendency to avoid curly quotation marks in raw output.
Gemini — produces more structured, list-heavy content, and like Claude, tends to be more concise than ChatGPT or Grok.
Grok — overuses superficially “scientific” words like causal, empirical, correlate, and continues to overuse underscore.
Cross-model quirk — the word “quiet” appears everywhere in AI output — quiet confidence, quiet rebellion, quietly growing — a pattern flagged as consistent across Claude, ChatGPT, and Gemini. Unsolicited, therapy-style reassurance (“You are not imagining it,” “You are not alone”) turning up in business documents is another shared tell.

Worth flagging: none of this is foolproof. AI detectors look for perplexity and burstiness, and if your writing style is very formal or uses predictable patterns, a detector might mistakenly flag it as AI — so treat these as indicators worth a conversation, not proof of anything.

Why Detection Alone Is Not the Real Answer

Here is the uncomfortable truth: spotting AI-written text tells you almost nothing about the risk that actually matters. The bigger issue is not whether an email was drafted with ChatGPT — it is what your organisation does not know is happening with AI at all.

When CIOs are asked how many AI tools their employees are using, the answer is usually somewhere between 60 and 70 — organisations assume that covers the landscape, but once monitoring is turned on, the real number is often 200 or even 300 AI tools in use. That gap between the approved AI stack and the actual one is where genuine exposure sits.

AI Safety Fundamentals for Business

Build a real system inventory. An honest AI system inventory covers all AI deployments in organisational use — including tools used by individual departments without centralised visibility, vendor-embedded AI not separately evaluated, and shadow AI tools — classified by risk level, regulatory exposure, and business criticality, with clear ownership identified.
Protect data at the point of use, not just at the policy level. Even with an approved AI tool, employees can inadvertently share data that should not leave the organisation, and a policy that says “do not paste customer data into AI tools” is only as effective as every employee’s ability to remember and follow it in the moment — policy-based data protection at the browser level solves this by enforcing rules in real time. This matters given that 35 percent of employees have entered proprietary company information into public AI tools.
Make governance cross-functional. AI governance that lives exclusively in IT and security produces policies that address only the risk surface IT can see — effective governance is cross-functional, with legal owning contractual and liability exposure, compliance owning regulatory mapping, business units owning the use case inventory, HR owning training and communication, and security owning detection and response.
Keep humans in the loop on critical decisions. Critical business decisions should not rely entirely on AI-generated outputs — human review helps reduce risks related to AI hallucinations and misinformation.
Enable rather than block. Governance that enables rather than blocks matters because the alternative is not no AI, it is ungoverned AI — and blocking without an alternative creates substitution, not elimination, simply moving the risk to other tools.

Practical Steps for Managers

Do not treat AI-written drafts as inherently a problem — ask about attribution and review process instead of policing style alone.
Run (or commission) a shadow AI discovery exercise to see what is actually in use versus what is approved.
Put a simple, memorable data rule in front of every employee: if you would not post it publicly, do not paste it into an AI tool.
Assign clear ownership for AI risk — for every AI system, one person should own the risk.
Revisit policy regularly — a significant share of organisations report their AI policies are either too restrictive for current tools or too broad to be meaningful, so treat this as a living framework, not a one-off document.

Frequently Asked Questions

Can AI detection tools reliably identify AI-written content
Not reliably. AI detectors look for patterns like perplexity and burstiness, but they produce false positives — formal human writing or predictable writing styles can trigger them. They are indicators worth investigating, not proof of AI use.

Is using AI tools at work against company policy
Not necessarily. The issue is not AI use itself — it is uncontrolled AI use without visibility or governance. Many organisations are moving toward “approved AI tools with clear guidelines” rather than blanket bans.

What is the biggest AI safety risk for UK businesses
Shadow AI — tools employees use without IT or compliance visibility. When 60 to 70 approved tools exist but 200 to 300 are actually in use, that gap is where data breaches, compliance failures, and IP leaks happen.

Should we ban AI tools to protect data
Bans rarely work — they create substitution, not elimination. Better approach: enable approved tools with data protection rules enforced at the browser level, combined with clear guidance on what data can and cannot be shared.

The Bottom Line

Learning to spot ChatGPT’s em dashes or Gemini’s list-heavy structure is a useful party trick, but it is not governance. The organisations getting this right are focusing less on catching AI use after the fact and more on building visibility, ownership, and sensible controls before problems surface.

If you would like support building a practical AI governance framework for your business, CAW Consultancy can help.

Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit https://www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.

Leave a comment

I’m Craig

Meet Craig Willetts

Welcome to the ISO and Compliance Blog, I have spent over 20 years in compliance specialising in accreditation and business growth, I own a number of compliance related businesses including CAW Consultancy, Global ISO Services, CAW Digital, Screen my staff and fusion consultancy worldwide and this blog is designed to help SME’s on their journey to top notch compliance, any questions feel free to drop me an email at Craig@CAWConsultancy.co.uk

Let’s connect