Key Takeaway
Generative AI has put utility-grade technology in employees' hands before organisations have evolved to wield it effectively. Now they have to catch up.
The Bottom Line Upfront (BLUF)
Your staff had access to frontier models at home before your organisation had anything to offer them. That gap is where the next two years of risk sits.
Anthropic, OpenAI, Google, Microsoft, and others have done something incredible. They have provided general, multipurpose intelligence as a raw ‘on tap’ utility, free to use, or at low cost – for now. Unlike previous waves of innovation, generative AI has leapfrogged the usual process by which new technology is adopted by organisations. This is a problem.
If your staff have access to the latest technologies often earlier at home and on their mobile phones than they do at work, then the question is: how will the transition and redesign of your organisation occur in a positive way? The organisational challenge now is how to transform AI as a raw commodity into strategic outcomes. To make exciting technology boring through secure, repeatable processes guided by sound governance, standards, and accountability.
How disruptive technologies get adopted and become boring
Writing about the Industrial Revolution and the impact of electricity upon the world's economy, two MIT economists, Erik Brynjolfsson and Andrew McAfee, wrote about the transformative impact of electrification on the industrial base at the turn of the 20th century. In their book "The Second Machine Age," Brynjolfsson and McAfee detailed how long it took four decades for electricity to go from a magical concept to an invisible utility. Citing earlier work by Stanford economist Paul David, they described how, at first, industry attempted to retrofit electricity into its existing business models, merely replacing power at mills and factories. From water-driven turbines and steam to big electrical motors powering vast networks of belts, leather belts to drive machinery.
It would take four decades from the 1880s to the 1920s for electricity to be fully exploited and to begin to provide measurable gains. Simply having access to electricity didn't create a competitive advantage. Organisations, factories, and industries had to redesign their processes, structures, and products around that technology, embarking on a new age of innovation and adapting and pivoting to new opportunities as markets were created, shaped, or remade.
Industry finally abandoned the centralised power models they inherited from the steam age and earlier water and wind sources of power. Instead, factories were redesigned to a ‘unit drive’, incorporating motors into industrial machinery. This vastly lowered the barrier for entry for new industries, new business models, new companies, creating progress, wealth, and prosperity for millions of people over coming generations.
The revolution went further. Machines formerly the sole preserve of industrial facilities were reinvented for the consumer. This included new machines operating on a smaller scale to perform household manual labour. The sewing machine, the electric iron, the refrigerator, the vacuum cleaner and the washing machine all made their entrance subtly and not-so-subtly changing lives for millions of people, and for women in particular.
I personally remember the joy I felt in the 1980s when my family finally got a dishwasher, ending the ages-old intra-sibling conflict over who washed and who dried the dishes after dinner. Peace in our time.
But whereas industry at the turn of the century controlled the spread of new technology by investing in new machinery and retraining its workforce, Generative AI is already universally available. Employee access to LLMs, whether sanctioned or unsanctioned, has occurred before organisations have had time to institute considered investments, reforms and changes to capitalise on this new technology.
Making technology boring: moving through the four stages of capability maturity
For most of the past decade my former colleagues and I have worked to move organisations towards artificial intelligence and data science using a four-stage framework.

We would start with a proof of concept, run in partnership with business and domain experts, to explore what was viable. Quick and time-bound — a few weeks at most, enough to find out whether the idea held, not long enough to disappear down a rabbit hole.
If it held, we built a crude prototype and put it in front of the business. The point was never the prototype. It was to let people experiment with something real, challenge their existing processes, and redesign the work around what the capability could actually do.
We sought to mature prototypes that survived that contact into products. Products can be handed over to another team, another section, another organisation or partner to run themselves. That meant resilience, stability, security, and meeting organisational standards for sustainability inside a secured funding envelope. A notable danger zone for most organisations. This is the point where innovation demands change to the status quo.
The aspiration beyond that was utility-grade analytics: models and capabilities offered as a microservice, written into any new system as a functional feature, now or years later. A valid risk score available for every article of mail or person arriving in Australia. Optical character recognition capability trained on mail packaging, pre-built and ready to be integrated as a standard feature into the next examination system.
This is how corporate insights and intellectual property get banked securely while still translating into real-world impact. At each stage the specialists and originators become less and less critical to the capability's performance.
Readers familiar with Simon Wardley's mapping work will notice a similar trajectory from genesis to commodity; he arrived there independently and applies it to whole value chains, where this is about a single capability maturing inside one organisation.
Why this approach won’t work this time
That process of experimentation to prototype, prototype to product, product to utility, has been circumvented by the arrival of consumer-accessible frontier models. Your employee has a utility at their disposal. Your organisation has nothing in response, because it has yet to apply that broad general-purpose capability to the very specific problems it is mandated to solve, in a way that protects its strategic positioning, its intellectual property and its security.
In 1905 no sailmaker brought a domestic pedal driven Singer sewing machine to work to sew hard canvas sails. The consumer machine and the industrial machine were not the same machine, and the work could not leave the building. Today consumer technology is arguably good enough for an industrial workload, and in the post COVID era the line dividing work from home has been blurred. In some jurisdictions, enshrined in industrial relations law and workplace agreements.
Unsanctioned use is therefore not an employee discipline problem. It is a structural challenge.
What organisations can do about it
Given the easy access and availability of frontier models to the consumer, attempts to outlaw their use wholesale serve only a leadership team’s sense of control. A workforce committed to the mission will strive to perform and will use what looks like a free and easy resource to do it. While well-meaning, these actions may be dangerous and create unacceptable risk.
The biggest danger of shadow AI within organisations is not the malicious actor. It is the most dedicated, innovative, and valuable members of staff. Here organisations have a huge opportunity to engage with these early adopters within the ranks. They have intimate knowledge of your organisation and its challenges, they’ve done the reconnaissance and can champion positive change within your organisation rather than route around it.
Don't try to boil the ocean. Identify where the risk sits and where the opportunity sits, and concentrate your scarce specialist capacity there. Draw a dividing line: general-purpose work — drafting, summarising, tidying — gets policy guardrails, education, a licence to use the right tool, and then let people get on with their jobs.
Be wary when drafting policy. The first version will be too conservative because it's written by people managing exposure rather than doing the work. If left unchanged and without engagement or review, it becomes a compliance artefact and pushes usage underground. Review policy quarterly with the people doing the work in the room. The people most likely to breach the policy are the ones who should be writing it.
Where possible, use architecture and technical controls to reduce the risk rather than relying on policy alone. Make sure the sanctioned service is genuinely good enough to do real work, even if it isn't the newest release. Consider in-house capability or smaller local models such as SLMs for high-trust, high-accountability needs. Do you really need the latest Claude model to talk to a customer about a solar panel installation?
Then turn to the organisation itself: how this utility-grade capability actually serves your strategic objectives. Identify the high-value, high-risk work that depends on your data, your rules and your intellectual property. Move it deliberately through proof of concept, prototype and product — and integrate that intellectual muscle into the organisation properly.
Organisations still have to climb the ladder
Historically every previous general-purpose technology made organisations climb the ladder and it took time. There was no other way to get value from that capability. Generative AI, on the other hand, has arrived at the top and left the organisation standing at the bottom. Unlike those industrialists at the turn of the 20th century, we don't have four decades to work it out, particularly since the workforce has already started evolving.
The hard part hasn’t started.
