The AI Crisis That’s Already Here
Working Through It
Ideas, questions and observations from the problems I'm trying to solve for myself and clients.
While we debate whether AI poses an existential threat, businesses face a much more immediate risk.
I've been following the recent developments in AI, and they're getting a little wild.
AI agents escaping supposedly secure testing environments. Models taking actions their creators didn't anticipate. Swarms of agents working together on complex problems.
All of this has accelerated the much bigger debate about where AI is headed. Are we approaching artificial general intelligence? The singularity? Are we creating systems we eventually won't be able to control?
I don't know.
There are people far closer to these models – and far smarter than I am about their capabilities – who are wrestling with those questions. They're important questions. Maybe the most important questions we'll ever confront.
But in my current work. In the here and now. I'm thinking about a somewhat smaller but important AI crisis.
It's happening inside companies every day as organizations race to adopt AI.
And I see three big risks that are currently causing companies headaches.
The risk from inside
Your employees are using AI.
Some are using company-approved systems. Others are probably using tools you don't know about.
They may be uploading documents. Summarizing information. Analyzing data. Writing code. Researching competitors. Creating presentations. Building their own AI workflows.
Mostly with good intentions.
But good intentions don't prevent someone from inadvertently uploading confidential customer information into the wrong system. Or acting on an AI-generated answer that's confidently wrong. Or giving an AI agent access to information or systems it shouldn't have.
Companies spent decades building controls around information security, privacy, intellectual property and compliance.
Then along came a technology so useful and easy to access that virtually anyone in the organization can create a new hole in those controls with a keystroke.
The risk from outside
The same tools making your employees more capable are making bad actors more capable, too.
AI can make phishing more convincing. Impersonation easier. Deepfakes better. Attacks faster and cheaper. I got duped myself because I was moving too fast trying to resolve an issue with a platform I was working on (a story for another day).
Bottom line: the AI systems businesses are integrating are themselves becoming targets.
And then there's the human risk
This one may get less attention than it deserves.
A lot of people are scared of AI.
Some distrust it. Resent it. Even hate it. And plenty are wondering whether the technology their company is encouraging them to use is eventually going to replace them.
Imagine you're an employee and your company announces an ambitious AI transformation.
Management talks about productivity, innovation, competitiveness.
You probably interpret that as We're figuring out how to do more with fewer people.
That's a problem for the company. Organizations can't simply install AI and expect transformation to happen. People have to participate.
If employees don't understand why the company is adopting AI, how it will affect their work, what the rules are, what they can trust, and – perhaps most importantly – what it means for them, resistance shouldn't be surprising.
People might avoid using the tools. Use them secretly. Or badly. Or check out entirely.
This isn't just an IT problem
That's the mistake I think organizations need to avoid. I see the non-IT risks in my work every day. And they’re considerable.
AI governance absolutely requires technology, cybersecurity, legal, compliance and risk expertise.
But it also requires something much more basic.
People need to understand what's happening.
Companies should be talking openly with employees about how AI will – and won’t – be used. They should establish simple, understandable rules for what information can be put into which systems. They should train people not merely on how to use AI, but when to question it, when to verify it and when not to use it at all.
They should create mechanisms for employees to raise concerns and report mistakes without feeling like they've just confessed to a felony.
And leaders should be candid about the elephant in the room: what AI could mean for jobs.
That doesn't mean making promises you can't keep. It means acknowledging the uncertainty instead of pretending employees aren't thinking about it.
Most importantly, companies need to treat AI adoption as an ongoing organizational change instead of a technology rollout.
Because the organizations that get AI right won't simply be the ones with the best models.
They'll be the ones whose people understand how to use those models intelligently, safely and responsibly. And they won’t be able to do that if they don’t trust their organizations.
Maybe someday we'll have to figure out how to keep superintelligent machines from taking over the world.
For now, most companies have a more immediate problem.
They need to figure out how to keep AI from creating a crisis inside their own four walls.
If you’re trying to figure out how to manage the risks AI pose within your organization and have ideas that have worked (or haven’t), or questions you’re asking, I’d love to hear from you. It’s a big and ever-changing issue, and I welcome other perspectives that may help shape my thinking.