Many small and medium-sized businesses say they have an AI skills gap, but their assessment process often asks the wrong question.

The usual question is: Who knows how to use AI tools?

The more useful question is: Who can use AI reliably within this specific business workflow — and verify the result before it affects a customer, colleague, or decision?

That distinction matters. Techaisle and AWS report that 50% of SMBs identify the AI skills gap or lack of in-house expertise as a significant barrier to adoption. Meanwhile, research attributed to Enigmatica indicates that only 12% of professionals consider themselves proficient with AI tools, with the average worker using 1.3 tools on default settings.

These figures point to a practical problem, not simply a training problem. Many organisations are measuring general familiarity with software instead of the ability to complete valuable work safely with AI.

A better approach is to assess people against the workflows they actually perform. The most useful tool for doing that is an AI Worker Workflow Brief: a short operational document that defines the task, inputs, owner, AI contribution, quality standards, and mandatory human review points.

Why traditional AI skills assessments produce weak answers

A generic survey might ask employees to rate themselves on prompt writing, chatbot use, automation, or AI literacy. That can help identify interest, but it is a poor basis for deciding who is ready to use AI in live operations.

There are three reasons.

Self-reporting measures confidence more than capability

Employees interpret questions through their own experience. One person may call themselves proficient because they use an AI assistant to draft emails. Another may choose “beginner” despite using AI carefully to analyse customer data and check outputs against source records.

Their answers are influenced by confidence, self-perception, and what they believe the organisation wants to hear. A survey can therefore identify attitudes, but it cannot prove that someone can perform a workflow accurately.

Tool knowledge does not transfer automatically to business work

Knowing how to open a chatbot or write a basic prompt says little about whether someone can:

  • provide the right context and source material;
  • distinguish a plausible answer from a correct one;
  • protect confidential information;
  • recognise when an output requires escalation;
  • document what the system produced and how it was checked.

For example, a marketing coordinator may know how to ask an AI tool for ten campaign ideas. That does not establish that they can use AI to turn approved product information into campaign copy without introducing unsupported claims.

Static competency maps become outdated

AI tools, model behaviour, interfaces, and organisational policies change quickly. A skills framework built around a fixed list of tools can become irrelevant when the tool changes or a different system is introduced.

The underlying business task usually changes more slowly. A sales team still needs to qualify leads, prepare account research, update records, and follow up with prospects. Assessing capability around those workflows creates a more durable picture of competence.

Callout: Measure the work, not the tool
Replace “Can this person use ChatGPT?” with “Can this person complete this defined workflow with AI, verify the result, and escalate safely when the system is uncertain?”

What an AI skills gap looks like in a real workflow

Consider a sales operations process in which a team turns call notes into structured CRM updates.

A generic assessment might record that an employee has completed an AI prompting course. A workflow assessment would give them a realistic task:

  1. Read a set of anonymised call notes.
  2. Extract the prospect’s needs, objections, buying stage, and next action.
  3. Use an approved AI assistant to draft a structured CRM entry.
  4. Compare every important field with the original notes.
  5. Flag ambiguity rather than filling gaps with assumptions.
  6. Apply the organisation’s data-handling rules.
  7. Submit the final entry with a short record of what was checked.

This exercise reveals several distinct capabilities:

  • Direction: Can the employee provide the AI with a clear objective, relevant context, and output format?
  • Judgment: Can they decide which information is material to the CRM record?
  • Audit: Can they detect invented details, missing context, or an incorrect interpretation?
  • Security: Can they remove or avoid unnecessary personal and confidential information?
  • Escalation: Do they know when the record should be reviewed by a manager or account owner?

A person may perform well in one area and struggle in another. That is more useful than assigning a single label such as “intermediate AI user.” It tells the team what to practise and where controls are needed.

The same method works in other SMB functions:

  • Marketing: turn an approved product brief into a campaign draft while preserving claims, tone, and compliance requirements.
  • Finance: classify expenses or summarise management information while checking calculations against the accounting system.
  • Customer service: draft responses from a knowledge base while identifying cases that require a human decision.
  • Recruitment: structure interview notes without inferring protected characteristics or making unsupported judgments.
  • Operations: convert unstructured supplier updates into actions, owners, and deadlines while preserving uncertainty.

The skill gap is not simply whether someone can produce an output. It is whether they can manage the entire chain from input to checked result.

Build an AI Worker Workflow Brief

Start with the three workflows where better AI use could save time, improve consistency, or increase capacity. Do not begin with every process or every team member. A narrow pilot produces clearer evidence and is easier to supervise.

For each workflow, create a brief with the following sections.

1. Define the business outcome

Describe what the workflow is meant to achieve and what a good result looks like.

Weak definition: “Use AI to help with sales administration.”

Stronger definition: “Create a complete, accurate CRM follow-up record within ten minutes of a discovery call, including customer needs, risks, agreed actions, and next meeting date.”

The stronger definition gives the employee and reviewer something measurable to assess.

2. List the inputs and their permitted use

Document the materials the workflow may use: call notes, approved product information, policy documents, spreadsheets, or customer emails.

Also specify what must not be entered into an AI system. If the team has not decided whether a category of information is acceptable, the workflow is not ready for unsupervised AI use.

This section should answer:

  • Where do the inputs come from?
  • Who owns them?
  • Which information is confidential or personal?
  • What is the approved system for processing them?
  • What should happen when information is missing?

3. Assign a workflow owner

The owner is accountable for the result, not merely for operating the tool. This might be a sales manager, finance lead, or customer service team leader.

The owner should define the quality standard, approve changes to the workflow, and review recurring errors. Without clear ownership, the AI process becomes an informal experiment that no one is responsible for improving.

4. Separate AI actions from human decisions

Specify what the AI may do and what remains a human responsibility.

For example, an AI system may:

  • extract fields from text;
  • suggest a response structure;
  • summarise a document;
  • classify items against a defined taxonomy;
  • identify missing information for review.

A human may still need to:

  • approve customer-facing language;
  • verify figures and claims;
  • make a pricing or hiring decision;
  • interpret ambiguous information;
  • decide whether a sensitive case requires escalation.

The purpose is not to remove judgment from the process. It is to place judgment where it is most needed.

5. Add mandatory audit checkpoints

A workflow brief should state exactly what the user must check before accepting the output.

For the CRM example, those checkpoints could include:

  • every customer need is traceable to the call notes;
  • no commitment has been invented;
  • the next action has a named owner;
  • dates and figures match the source;
  • uncertainty is clearly marked;
  • sensitive information has not been unnecessarily copied.

Avoid vague instructions such as “check the AI output.” They are too easy to skip and too difficult to assess. A checklist tied to known failure modes is more effective.

6. Define escalation rules

People need permission to stop the workflow. State the conditions that require a second review, such as:

  • conflicting source information;
  • missing evidence for a material claim;
  • a customer complaint or legal concern;
  • an unusual financial value;
  • a request involving personal or confidential data;
  • an output that cannot be explained or verified.

This is where workflow proficiency becomes safer than general tool familiarity. The competent user knows not only how to proceed, but when not to proceed.

Assess people through observed performance

Once the brief exists, assess the workflow rather than asking employees to describe their AI knowledge.

Give each person the same representative task, or a small set of comparable tasks. Evaluate the process using a simple rubric:

Capability Needs support Reliable with review Reliable independently
Preparing inputs Omits context or includes unsuitable data Follows the approved input pattern Selects and prepares inputs consistently
Directing the AI Uses vague or incomplete instructions Produces usable outputs with occasional help Specifies context, constraints, and format clearly
Auditing outputs Accepts plausible errors Finds common errors with a checklist Verifies important claims and spots subtle issues
Security and privacy Unclear about data boundaries Follows documented rules Applies rules and identifies new risks
Escalation Continues despite uncertainty Escalates when prompted Recognises uncertainty and stops appropriately