Thinking · Article

AI Is Not the Problem. Losing Control Is.

As AI shifts from answering questions to taking action inside the business, lasting value depends on keeping data, decisions and accountability firmly under your own control.

Points of view

Ai is not a problem - losing control is

Topics

For businesses, the question is no longer whether to use AI. It is how to deploy it on their own terms and who remains accountable when it moves from generating answers to taking action.

A few years ago, the most compelling question about AI was what a language model could do. Could it write convincingly, summarise a lengthy document, generate code, translate or analyse information? Today, we know it can. We also know that this is only the beginning.

The next phase will be defined by systems that do more than respond to prompts. They will carry out tasks, retrieve information, interpret documents, prepare recommendations and work across business applications. They will also coordinate with other AI agents. AI will become an integral part of how businesses operate, rather than simply a tool employees consult.

That creates enormous opportunity. But the risk is not intelligence itself. It is giving AI access, authority and room to act without the controls to match.

Beyond the Chatbot

Using a public chatbot feels straightforward. You enter a prompt, receive a response and decide whether to use it. The user appears to remain in control.

Inside an organisation, the picture is more complicated.

An AI system might read internal policies, interpret customer records, generate reports, prepare proposals, categorise complaints or compare supplier contracts. It might draft a board briefing, retrieve information from a finance system, update a calendar or trigger a workflow.

At that point, it is no longer just a conversational interface. It is a system with access to business-critical information and the ability to affect how work gets done.

The question is not whether it will make mistakes. Every system can fail, and people make mistakes too. The question is whether we can understand what happened when something goes wrong.

Which data did the system use? What permissions did it have? Which model generated the output? What action did it take? Who authorised the next step?

If we cannot answer those questions, we do not have an AI strategy. We have unmanaged risk.

Shadow AI is one manifestation of that problem

Executives worry, understandably, about employees pasting customer correspondence, internal documents, presentation drafts or commercially sensitive information into external AI tools.

But a blanket ban does not address the underlying need. It may simply drive AI use out of sight.

Most employees are not trying to bypass security. They are trying to get their work done: reduce repetitive tasks, respond faster and produce better results. Shadow AI is therefore not primarily a disciplinary issue. It is a signal that the organisation has yet to provide a safe, practical alternative.

The right response is not simply to tell people what they cannot use. It is to give them an environment in which AI genuinely helps, without exposing sensitive knowledge or assuming decision-making authority without oversight.

Enterprise Knowledge Is More Than Documents

The business value of AI does not necessarily come from the model itself. General-purpose models already offer impressive capabilities. What matters to an organisation is whether those capabilities can be applied reliably within its own operating context.

Does the system understand the definitions in a contract? Does it know which policy is current? Can it distinguish an approved procedure from an obsolete version? Does it respect the fact that one employee may access information that another may not?

Enterprise knowledge is not a single database or a collection of files. It includes documents, systems, decisions, access rights, business relationships and professional judgement built up over years.

Connecting an AI system to a document repository is not enough. Access must have a purpose, permissions must be enforced and information must be interpreted in context.

The issue is not simply whether the organisation has enough data. It is whether the system uses the right information, at the right time, under the right permissions and understands its relevance to the task.

This is also where trust becomes an architectural question.

In technology presentations, trust is often reduced to a padlock icon, an encryption specification or a compliance statement. Those elements matter, but they are not sufficient.

Trust is not a feature. Trust is an architecture.

It starts with knowing where the system runs and who can access the data. It requires authentication, role-based access control, logging, audit trails and clearly defined human approval points. It also requires the ability to intervene: to change the system’s behaviour, restrict its permissions or stop it altogether.

This is what sovereignty means in a business setting. It does not require every organisation to build its own language model or source every component from one geographical region. It requires meaningful control and genuine choice.

An organisation should be able to choose its deployment environment, select the models it uses, define its data policies and change providers. It should decide which actions can run automatically, which require approval and which must never be delegated.

Freedom here is not the absence of rules. It is the ability to set and enforce them.

Automate Tasks, Preserve Human Accountability

The debate about enterprise AI often falls into two extremes. One is to keep AI away from critical operations because it is unpredictable. The other is to assume that more automation will inevitably deliver greater competitive advantage.

Neither is an adequate operating model.

The aim should be well-designed human - AI collaboration. AI can process large volumes of information, accelerate repetitive work, generate alternatives, identify patterns and prepare decisions. But accountability, value judgements and the assessment of legal and commercial consequences cannot simply be delegated to a model.

A well-designed system strengthens human judgement where it matters most. It distinguishes routine execution from decisions that carry significant consequences.

AI can summarise evidence, flag inconsistencies and recommend a course of action. It may coordinate several steps in a workflow. But when a business approves a contract, makes a commitment to a customer, submits a regulatory filing or takes a decision affecting an employee, a named individual must remain accountable.

Human oversight should not be a vague promise attached to the system. It should be built into the workflow: who reviews what, at which point, with what information and with the authority to intervene.

The objective is not to put a person in front of every automated step. It is to preserve meaningful human control over the decisions that warrant it.

Build an Operating Model, Not a Dependency

Enterprise AI is not simply a procurement exercise in which we select the best model and adapt the business around it.

That may be convenient initially. Over time, however, it can create dependencies that are expensive and difficult to unwind.

A more durable approach establishes an operational layer between AI models and the business. This layer coordinates data sources, enterprise applications, workflows and, where appropriate, multiple models. It defines what each AI agent is allowed to do, what information it may use and how its actions are recorded and reviewed.

Under this approach, AI does not acquire an open-ended role within the organisation. It is deployed for a defined purpose, with permissions and controls proportionate to that purpose.

The question we need to answer is practical: how do we connect AI agents to an organisation’s knowledge and systems while keeping data access, decision-making and accountability under control?

The architecture should support deployment in the organisation’s chosen environment on-premises, in a private cloud or in a sovereign cloud. It should allow the organisation to select and replace models, connect to existing business applications and retain oversight of how information moves between them.

These choices are not merely technical preferences. They determine how much freedom the organisation retains as its use of AI grows.

This is not just a technology decision. It is an operating model decision.

Control Is a Competitive Advantage

The organisations that gain lasting value from AI will do more than experiment with the latest tool. They will turn experimentation into a repeatable, governed way of working.

They will know which data can be used, which processes are suitable for automation and where human approval is required. They will assign accountability for AI agents and establish clear conditions for intervention.

Those controls should not be treated as obstacles to innovation. They are what allow an organisation to move beyond isolated experiments and deploy AI with confidence.

A system that delivers an impressive demonstration but cannot be integrated, governed or audited is not yet a dependable business capability. Conversely, a controlled environment gives organisations room to expand: to introduce new use cases, test different models and automate more work without surrendering oversight.

I do not believe the defining achievement of enterprise AI will be the number of tasks we can hand over to machines. It will be our ability to organise knowledge, judgement and responsibility more effectively.

The real test is not whether we use AI. It is whether, as we use it more extensively, we remain in control of our organisation’s knowledge, data and decisions.