The Human Factor Determines AI ROI

When a company decides to bring order to its use of AI, it almost always starts with the same things: tools, permissions, policies, and governance. A platform is selected, access is configured, and an acceptable-use policy is drafted. All of that is necessary. But the person who pastes a contract into a chatbot is not a tool, it is a person. And the person who decides whether to use (or ignore) the corporate AI assistant the company invested so heavily in is also a person.
That is the paradox that very few organizations truly govern. People are both the biggest AI risk within the enterprise and the factor that ultimately determines ROI. A company can have the best security architecture and the most advanced model on the market. But if employees do not understand what they can do, what they cannot do, and why, the initiative fails on both fronts at the same time.
The Risk Comes from Good Intentions, Not Where You Think
When we think about data leaks, we tend to imagine sophisticated cyberattacks or malicious employees. The reality is far more mundane. According to Verizon's 2026 Data Breach Investigations Report, 62% of security breaches involve the human factor: mistakes, social engineering, or misuse without malicious intent.
In the context of AI, this takes a very specific form. Nobody pastes a customer database into a public chatbot to harm the company. They do it to finish a report faster. As we discussed in our article on shadow AI, nearly half of workplace generative AI usage occurs through personal accounts, outside any organizational control. The pattern is clear. Data leaks are rarely caused by malicious people. They are caused by well-intentioned people who lack clear guidance about what information can leave the corporate perimeter.
This changes the nature of the solution. Technical controls are effective against external attackers. But against well-intentioned yet uninformed behavior, the only scalable defense is ensuring that every employee can confidently distinguish what information can be entered into which tools.
ROI Depends on People Too
The other side of the same coin is return on investment.
MIT's The GenAI Divide study reached an uncomfortable conclusion: 95% of generative AI pilots in organizations fail to generate measurable business impact. The primary cause is not technological. Researchers call it the learning gap—the inability to integrate AI into workflows, organizational structures, and company culture. In other words, into the way people work.
Boston Consulting Group summarizes this reality through a ratio that should appear in every AI budget: the 10-20-70 rule. Ten percent of the effort in an AI transformation is related to algorithms. Twenty percent relates to technology and data. The remaining seventy percent depends on people and processes.
Most organizations invest in exactly the opposite way. They spend heavily on licenses and platforms while investing very little in changing how people work.
The result is visible every day: AI assistant licenses purchased for an entire workforce that are actively used by only a small group of employees. The technology exists, but the return does not. Because ROI is not generated by the license itself. It is generated by the individual who changes the way they work because of that license.
Training Is More Than Sending a Policy PDF
If 70% of success depends on people, what does investing in that 70% actually mean? It does not mean distributing a twenty-page policy document and considering the job done. Effective programs share three key ingredients:
- Principles over rules. A useful policy isn’t a list of prohibitions; it’s a framework that anyone can apply in three seconds. What types of data exist within the company, which ones can be entered into which tools, and who to ask if in doubt.
- Role-based training, not generic training. The sales, finance and development teams do not use AI for the same purposes, nor do they have the same stakes. Training that changes behaviour is training that works with each team’s real-world use cases, using their own data and addressing their specific risks.
- Internal role models. People learn to use AI primarily by watching colleagues who use it well. Identifying and supporting these individuals accelerates adoption far more than any internal campaign.
And a fourth ingredient that underpins it all: a corporate solution that the team genuinely wants to use. Training provides the impetus, but if the approved tool is worse than the one everyone has on their mobile, the battle is lost before it even begins.
Questions Every Organization Should Be Able to Answer
Just as organizations assess their tools and data, they should also assess their people. Any organization serious about governing the human side of AI should be able to answer the following questions without hesitation:
- Does every employee know what data can and cannot be entered into AI tools?
- Who has received practical, role-based AI training, and who has merely signed a policy document?
- Is there a formal channel for employees to propose new AI use cases instead of adopting them independently?
- Do we measure actual adoption of the AI tools we pay for, or only the number of activated licenses?
If the answer to any of these questions is, "I'm not sure," that is where the real work begins.
At Itequia, we help organizations address the 70% that determines the outcome. From Microsoft Copilot adoption and change management programs to tailored Microsoft training for specific roles and teams, our goal is to help companies turn AI investments into measurable business results. If you would like to understand where your organization stands, contact us.
Frequently Asked Questions
How Long Does It Take to See ROI from an AI Investment?
The first individual benefits of generative AI—such as time saved on writing, summarization, or analysis—can appear within weeks when training is practical and role-specific.
Process-level benefits, such as shorter sales cycles or reduced outsourcing costs, typically take several quarters to materialize because they require redesigning workflows rather than simply layering AI on top of existing processes.
Establishing review milestones at three and six months helps prevent both premature abandonment and the continued investment in initiatives that are not producing results.
Is AI Training Mandatory Under the European AI Act?
Yes.
Since February 2, 2025, Article 4 of the European Union AI Act has required organizations using AI systems to ensure an adequate level of AI literacy among their staff, taking into account their specific context and the AI systems they use.
The regulation does not mandate a specific course or minimum number of training hours. However, it makes AI education a compliance requirement rather than an optional best practice.
Documenting the training received by each employee is the simplest way to demonstrate compliance.
How Can the ROI of AI Be Measured?
AI ROI should be measured by comparing a pre-deployment baseline against impact metrics for specific tasks, such as: Hours saved per process (e.g., preparing proposals or completing monthly reports), reduced outsourcing costs, faster delivery times, improved operational efficiency...). Without a baseline, any ROI figure is merely an estimate. In Microsoft 365 environments, Microsoft 365 Copilot usage reports and adoption dashboards can help organizations compare a