Your teams did not wait for an AI policy. Across pharma companies in the Gulf and Egypt, employees are already using ChatGPT and Claude on personal accounts, with no training and no oversight.
Your teams did not wait for an AI policy. Across pharma companies in the Gulf and Egypt, employees are already using ChatGPT and Claude on personal accounts for daily work, with no training, no data rules, and no oversight. The question is no longer whether to adopt AI. It is whether you will govern what is already happening.
Ask any pharma leadership team about their AI strategy and you will hear about committees, evaluations, and pilots planned for next year. Ask their employees what they did this morning and you will hear something different.
The medical advisor summarised three papers with a chatbot before her first meeting. The brand manager drafted a campaign concept on his personal ChatGPT account during the commute. The market access analyst asked Claude to restructure a pricing argument. None of them told anyone, because nobody asked and no rule said they should.

This is the reality in offices from Riyadh to Cairo. The largest AI deployment in your company's history was not procured, approved, or announced. It arrived through personal phones and free accounts, one employee at a time.
Your AI rollout already happened. It just happened without governance, without training, and without you.
The problem is not that employees use AI. Used well, these tools genuinely raise output quality and speed. The problem is what "well" requires, and nobody has taught it.
Personal accounts sit outside your company's agreements and controls. When an employee pastes an unpublished study summary, a pricing file, an HCP list, or internal strategy into a personal chatbot, that data has left the building. No one masked patient identifiers, no one stripped the product names, no one checked what the tool's terms allow, because no one was ever shown how.
AI tools produce fluent, confident text that is sometimes wrong. In most industries that is embarrassing. In pharma it is a compliance event: a fabricated reference in a medical piece, an off-label implication in promotional copy, an Arabic translation that shifted a claim. Untrained users do not know what to check, so they check nothing, and the output moves into the review chain looking finished.
Regulated work must be traceable. Work done on personal accounts is invisible: no log of what was entered, no record of what the tool contributed, nothing to show an auditor or a legal team if a question comes later.

Every day without AI training, your most confidential work flows through tools you do not control, checked by habits nobody taught.
The instinctive response is prohibition. It is also the response most likely to make things worse.
Employees use these tools because they work. A ban does not remove the incentive; it removes the visibility. Usage shifts entirely to personal devices, off the company network, where you have no insight at all. The company that bans AI does not end up with less exposure than the company that governs it. It ends up with the same exposure and no map of it.
There is a second cost. Your competitors' teams are learning these tools now, in daily practice. A blanket ban freezes your people's skills while the market moves, and your best performers, the ones most likely to experiment, feel it first.
The honest position for leadership is uncomfortable but simple: the choice between "AI" and "no AI" expired quietly sometime last year. The remaining choice is between skilled, governed use and improvised, invisible use.
Proper AI training for pharma teams is not a prompt-writing class. Prompting is the smallest part. The substance is everything around it.
It covers data discipline: what can never be entered into any tool, how to mask and de-identify what remains, and how the rules differ between a personal account and a company-provided one. It covers verification: how to challenge a reference, catch a hallucinated claim, and validate Arabic output with the same rigour as English. It covers governance: how AI-assisted work is disclosed, documented, and kept audit-ready, in line with how regulators in the region are beginning to look at these questions.
And it covers performance, because safety and speed are not opposites. The same team that learns what not to paste also learns how to brief a model properly, and the difference in output quality between an untrained user and a trained one is not incremental. It is the difference between an expensive search engine and a genuine force multiplier.
The goal is not employees who use AI less. It is employees who use it better than anyone else in your market, safely.
First, see the real picture. Run a no-blame internal survey of who is using what, for which tasks, on which accounts. Amnesty matters: punish nothing you discover, or you will never see the truth. Leadership is consistently surprised by how deep usage already runs.
Second, close the urgent gaps. Before any full programme, give every employee the short version: the five things that must never enter any AI tool, and the masking habits for everything else. This takes a workshop, not a transformation project, and it removes the sharpest risks immediately.
Third, build the full capability. Company-wide baseline training on safe use, verification, and documentation, followed by role-specific depth for medical, commercial, regulatory, and access teams. Then measure it: drafting time, review cycles, errors caught before release. Training that does not move those numbers is theatre.
Do the survey this month and the first workshop this quarter. The usage is already inside your company; the only open question is whether the skill and the guardrails arrive before the first incident does.