I gave this talk last week — a straight rundown of where AI is actually landing inside companies right now, not where the vendor slides say it’s landing. The slides are attached here, followed by some notes, and then the full transcript.
Short version: everyone’s trying to figure out their AI strategy before they’ve even looked at what AI is already doing inside their own walls. That’s backwards. You can’t transform what you can’t see, and AI is already in the building from every direction — official pilots, people’s personal ChatGPT accounts, a copilot bolted onto every SaaS tool, a pile of POCs nobody’s tracking. Step one isn’t strategy. It’s visibility.
I walk through it as three waves: the AI that’s already there (a configuration problem, not a migration — you already own the tools, just point them at AI instead of only at humans), the AI knowledge layer that visibility actually unlocks (why dumping your raw files at a model just gets you hallucination-filled garbage, and what an actual knowledge factory looks like instead), and AI going everywhere — onto the device, into your own region, out of anyone’s central datacenter. Then I close on where Citrix fits into all of it, which hasn’t really changed in 37 years.
The core arguments
The real question right now isn’t “what’s our AI strategy,” it’s “how do we get useful AI without losing control” of the systems, data, and workflows the business already runs on.
AI did not wait for your strategy — it’s already in the building from every direction (official pilots, personal AI accounts, embedded SaaS copilots, ad hoc experiments). The only real choice left is whether you can see it.
Wave 1 (the AI that’s already there) is a configuration exercise, not a migration — the same access/identity/governance/control playbook already run for decades, just pointed at AI. Nothing about existing systems has to change.
Agent identity is the one genuinely new problem: AI inheriting a human worker’s own permissions is unsafe by default.
“Visibility is the new security” — every governance control point doubles as a visibility point into how work actually happens.
Wave 2 (the AI knowledge layer) fails without Wave 1 first: pointing AI straight at raw inputs and asking for finished outputs produces hallucination-filled garbage no matter how good the model is, because the real judgment — the invisible 80% — was never in those inputs. The fix is a managed canonical layer built backward from specific outputs.
Forward-deployed engineers (FDEs) are a rebrand of 1990s business-transformation consultants, and every major AI lab and hyperscaler spent this summer racing to build FDE armies — but the work doesn’t require an outside hire.
Wave 3 (AI everywhere) makes capability portable two ways at once: down to the device, and into a customer’s own region via open-weight models.
Citrix’s role hasn’t changed in 37 years — deliver, govern, and secure whatever “existing work” runs on, decade to decade.
Quotes
“AI did not wait for your strategy.”
“You cannot transform what you can’t see.”
“This is a configuration, not a migration.”
“Visibility is the new security.”
“The ‘S’ in MCP is for Security.”
“Urgency ≠ Fear.”
“It’s the 15th of September, 2026. AI is good enough now.”
Transcript
Thank you all. My name is Brian Madden, and I’m the futurist for Citrix. I actually live in France — I’m joining you today from New York City, where I’m at a Wall Street Journal executive conference of CIOs talking about how AI is entering the workplace.
As Citrix’s futurist, I work across our product management groups, our go-to-market teams, and our executives, focused on how Citrix evolves as work itself evolves. Fundamentally, I’m a researcher. I know a lot of you go back a long way with Citrix — I first started working with Citrix technology and end-user computing back in the 1990s, and I wrote my first book about Citrix more than 25 years ago. So I’ve been doing this a long time, and I want to share some perspective today — the latest snapshot of my research: what I’m seeing, how I see digital workspace evolving as AI enters that world, and how we think about that at Citrix.
Here’s where I’m coming at this from. A lot of people right now, when it comes to AI, are just trying to figure out what they need to do with it — which AI should we be betting on, what’s our strategy, what are we going to do. I know a lot of you have scientists and engineers who roll their eyes at the current AI conversation, because classic machine learning and pattern recognition have already been part of your operations for decades. But once ChatGPT entered the world, it changed the conversation — suddenly AI coming into the workplace became a mainstream thing. It’s been a few years now, people are using it, and everyone is trying to figure out their strategy: what should we be doing, what should we let AI see?
I actually think that’s the wrong question to ask first. It’s an important question, but figuring out your strategy is like figuring out the solution — and I think that’s premature, because we’re not ready to be designing AI solutions for the enterprise when AI is just starting to enter the enterprise. AI is evolving faster than we can even adopt it. So instead of the solution, the question I think matters most right now is: how do you make AI useful without losing control?
Because you all know the pattern — you try AI as a little copilot on the side of Microsoft Office, and it’s cute, it answers questions, but it’s not the AI that changes your work. Then you start hearing about computer-using agents coming into your applications, your processes, actually changing how your company functions. That’s the AI that seems to really transform things — but how do you do that if it means handing over all your work, your existing systems, your existing data, your existing workflows to AI? Now you’ve lost control completely.
So the issue right now isn’t the strategy — it’s the approach. And if you’re going to pick one thing right now, it’s this: look at what’s already going on with AI in your workplace. Spending more time on a hypothetical strategy is an intellectual exercise, when in reality you already have AI in your company. I like to say: AI did not wait for your strategy. While you’re figuring out your strategy, AI has already come into the building, from every direction. You’ve got your official AI efforts — transformation projects, department pilots, specific applications — but AI is also in every personal account your workers use for work, official or not (how many times in a meeting have you seen someone’s camera pop up like they’re checking something, then go back down — yeah, that’s someone’s screen talking to AI). Every SaaS application has some kind of AI chatbot or copilot built in now. And on top of all that, there are experiments and proofs of concept running everywhere, from every team, every individual, every department.
Understanding this is what’s really important. And it’s funny, because we’ve been saying this for years — ChatGPT was released to the public in November of 2022, almost four years ago. We’ve been talking about this mainstream AI moment for four years, and I’m telling you today the most important thing is to understand what AI is already doing in your company.
So why say this today, and not two years ago? I think the honest answer is that most companies have been waiting for AI to be “good enough,” in air quotes. You used ChatGPT when it first came out — it was cute, a party trick, it hallucinated — and then it got better, and better, more capable, GPT-3.5, GPT-4, GPT-5 and on. Most enterprises have been in a holding pattern: sure, there’s a future here, but let’s wait until we really understand it, until it’s good enough to roll out broadly across our users.
I’m telling you: it’s the 15th of September, 2026. It’s good enough now. Literally from the past week — OpenAI released GPT-6, which they’re calling Astra. Astra can do your work. Look at the release videos if you haven’t seen them — it can use a computer, run long-horizon business tasks, do cognitively advanced work without getting confused. Almost anything a knowledge worker can do, AI is now technically capable of doing. That doesn’t mean it has all the knowledge it needs to do everything — but the technical capability is there. We’re also seeing open-weight models close the gap with frontier models — Chinese open-weight models get a lot of press, but Western companies are releasing serious open-weight models too. And we’re seeing models that run locally, on-device, that are actually useful now.
My point isn’t that you need to run out and transform everything today. It’s that you can’t use “we’re waiting for the technology to get better” as your excuse anymore. It’s good enough now, and that is not the reason to stop you.
I think the real problem is people confuse urgency with fear. I believe we all need a real sense of urgency right now about bringing AI into our workplaces and our digital workspaces, because the capability is there to make a real difference. There’s also a lot of fear — GPT-6 came out two weeks ago, and the first few days of conversation were all about its capabilities, and then it flipped into “is AI going to kill us all” territory. Those are different conversations, but I think the fear conversation has taken over, and we’re missing the fact that the AI capabilities that exist right now are extremely robust, and it is genuinely possible to fundamentally transform the way you do your work.
To understand why, and the real challenge underneath it, you have to actually understand what knowledge work is. Everyone talks about AI transforming knowledge work, but you have to step back and ask: what is knowledge work? A lot of us think of Microsoft Office, email, documents, Teams, OneDrive, SharePoint, meeting transcripts, chat transcripts — that’s knowledge work. I’d argue that’s only about 20% of it, and it’s the visible 20%. Most knowledge work is, well, in the name — it’s knowledge, it’s in people’s heads. It’s how they think, how they reason, their judgment, the processes that were never written down, the way things actually work versus how they’re documented on paper. It’s the time people spend staring out the window, watching birds. That’s where the real knowledge work happens, and none of it is captured anywhere. The visible 20% isn’t the knowledge work — it’s the artifacts of the knowledge work, the output of it.
If you point your AI only at the outputs of knowledge work, it’s never going to truly integrate into your processes or understand how the work really happens. That’s why AI today can write emails, summarize a PowerPoint, summarize a PDF, summarize a transcript — but it can’t do your job, because your job is more than summarizing transcripts and emails. AI needs to get into the invisible part of knowledge work. I don’t think that means AI takes all knowledge work away from humans — but I’d point out that the technology’s real growth area right now is new territory. It doesn’t change any of your existing systems, your document processing, your policies — all of that stays the same. What AI brings is digging into what was previously invisible, and creating a new layer of digitization out of it. That’s the big shift, and it’s important to understand: for AI to really impact your digital workspace and how you run your company day to day, it has to go into this previously invisible part of knowledge work.
The way I think about this is as three “waves” of AI — and I put “waves” in quotes because these aren’t really sequential phases so much as three separate trends piling on top of each other. Let me walk through them quickly.
Wave one is the AI that’s already here — already in your business today. This is what you have right now, what we have at Citrix and Cloud Software Group, what everyone has. The first thing to understand: you cannot block or remove the AI that’s already in your company. I mentioned all the different places it lives — SaaS applications, official strategy, whatever workers are using on their own. The idea that you’re going to somehow close it off, block it, or roll it back is absurd — it’s not a real choice. Your only real choice is whether you can see the AI that’s already in your company, or whether you just don’t look for it. And I’d argue you need to look, because fundamentally, you cannot transform what you can’t see. So the true first step — understanding this first wave of AI that’s already here — is visibility.
Now, visibility doesn’t replace transformation. You will transform how your business runs with AI — maybe not today, maybe in a year, maybe in five years, maybe in five weeks. That transformation is coming regardless of timing. But the first step, whenever that transformation begins, is getting visibility into the AI that’s already in your organization.
And the good news: this is the same playbook you already run. Everything you’ve been doing for decades to manage your estate applies here. Look at access — all the corporate AI you’re already paying for can be routed through the gateway products you already own; you don’t need to buy anything new, just deploy a new configuration, so all corporate AI goes through a single gateway. Look at identity — this one’s genuinely new. AI agents, whether fully autonomous or an individual worker using something like Copilot or Claude that can operate their computer, are moving mice and clicking screens with access to your systems and data. The problem is that most people’s AI runs with the same rights as the human worker using it — and I, for one, have a lot of access within Citrix that I do not want my AI having by default. Letting workers run AI agents on their own user accounts is genuinely unsafe. There are hard problems here — multi-factor authentication and authorization for agents is a real, ongoing conversation — but the point is: getting visibility here is an identity conversation, using products you already have, configured differently for AI. Look at governance — how is AI interacting with your current applications and data? AI isn’t human, which is actually good news, because it means you don’t have to monitor it like a human. None of us want our employer recording everything we do on our laptops all day — and as Europeans, we have real protections against that as workers. AI has no such protections. If an AI agent is operating a desktop, I want to record everything it does — turn on every security and session-recording option you have, for the AI. And look at control — governing the protocols and access points AI uses. A lot of AI is talking to other AI over MCP, and the old joke is that the “S” in MCP stands for “Security.” That doesn’t mean you can’t use MCP — HTTP needed a security layer wrapped around it in its early days too — it means you have to govern it with real enterprise protocols, and that’s entirely possible to do today.
None of this requires new products or new licenses. It’s configuration changes to the products you already run, pointed at your environment, to understand what your AI is actually doing — the same way you’ve always worked to secure your environment. Every point where you have governance is also a point of visibility. If you instrument your existing estate for governance, you get, for free, the side benefit of having instrumented it to see how work actually happens.
So this is a configuration, not a migration. I’m not telling you to migrate to a new AI strategy, implement some new transformation, or change anything about how you operate. You already have AI in your environment. You can make simple configuration changes to your existing products and start understanding what AI is actually doing — without changing your existing systems or processes. Your policy administration system keeps running exactly the way it does today. Your entire existing system, as it runs today, doesn’t have to change. I think a lot of people look at AI’s impact and assume they have to rip out every system and rethink everything from scratch — especially in a regulated environment where you can’t just do that. You don’t have to. Get visibility into how AI is operating in your environment, without changing the environment. Look at your existing systems, your users, your policies, your desktops, your apps — everything they use and how they use it — and give yourself visibility into where AI is entering that picture.
Once you’ve got that visibility across your whole system, it connects into what I’m calling wave two. Wave one is understanding all the AI activity in your existing estate and instrumenting it. Wave two is taking what you learned and building the AI knowledge layer — because the real question that visibility raises is: now what do you do with it? Now you can see how the work actually happens — which apps people move between, which apps the AI moves between, where the same information gets entered three times, where the real process differs from what’s written down. This is where you can finally start to understand the 80% that lives in people’s heads. Watching the work happen is how you understand how and why it happens — and if you’re going to transform that, which AI is very good at, you have to watch it first so you have the visibility to make that transformation possible.
Because here’s the dream most people have, and why it doesn’t work: you look at everything you have today — all your raw inputs, documents, PDFs, policies, customer records, file shares, source code, wikis, Slack — and you look at everything you want AI to produce — new policies, competitive documentation, marketing material, websites, applications — and you just point AI at the raw pile and say, “go build me the stuff I want, here’s everything I own.” It doesn’t work. You get hallucination-filled garbage. And it’s not because the model isn’t good enough — better models don’t fix this. It’s because there’s too much conflicting information, the same fact stated four different ways in four different places, and a huge amount of what these outputs actually need lives only in people’s heads, invisible to anything the AI can see.
What’s missing is a middle layer — a managed, canonical layer between your raw inputs and your generated outputs. I call it the canonical knowledge base: knowledge blocks that capture how things actually work. The way you build it is you start from the outputs you need, work backward to the inputs, and sit down with the people who actually know how it’s done — I’ve walked through this in more detail on other podcasts. It’s genuinely possible to build systems like this that transform how knowledge work operates — but it’s not your existing systems, it’s a brand-new AI knowledge layer. I can speak from experience: we’ve built several of these inside Citrix. We call it our knowledge factory.
This is the transformative use of AI — actually rebuilding business processes to create real value. But it takes real engineering. You’ve probably seen the news this summer about AI labs and hyperscalers hiring forward-deployed engineers, FDEs — which is really just a modern name for what business-transformation consultants did back in the 1990s. These are engineers who genuinely understand your business, because AI’s raw capability keeps improving, but that capability doesn’t automatically diffuse down into how your company actually operates. There’s a real gap between what AI can do and what you’re doing with it, and someone has to wire it into your systems, your processes, your people, and get it properly secured. That’s the FDE’s job. And you don’t have to go out and hire them — we have five or six people inside Citrix acting as forward-deployed engineers who are just Citrix employees who understand AI and understand our business; this is now their job. So this isn’t something that requires an outside hire — a lot of you already have people internally who know AI well. What it requires is building this knowledge layer, using what wave one’s visibility taught you about how AI is actually being used, to rebuild your processes around that.
The third and final wave — I’ll call it AI everywhere. This is AI moving onto the endpoint. Local models are real now — I’m running Qwen 3, around the 27-billion-parameter version, on my own laptop; it’s roughly Sonnet/Opus-class, it’s slow, but it runs. AI is moving out of the datacenter — Apple’s made announcements, Google’s made announcements about on-device AI. So AI is going to run everywhere, on workers’ own devices — and also in your own region. As open-weight models get better, you no longer need the US or China to host your models for you — you can run open-weight models in your own datacenter, your own country, under your own data-sovereignty rules, with providers you choose. So this wave is going to be about AI showing up everywhere, and when it does, you get the same questions everywhere: what level of sensitivity is the data and knowledge the AI can see, what’s the trust level of the model, whose agent is this, what can the local model see, and how do you patch all of it?
Let me close with where Citrix fits into this. I’m not here to do a product pitch, but Gartner expects 20% of enterprise virtual machines to be running agents by 2030 — as was noted earlier on this call. Every one of those environments your agents run in needs an identity, an access boundary, and the ability to be audited. Citrix’s role hasn’t changed in 37 years: we deliver, govern, and secure your existing work. In the ‘80s that was DOS apps out to terminals; then Windows client-server apps out to home users; then web apps; then Windows apps out to web users; then cloud; now AI. Citrix has always been the layer that takes the processes you already have and connects them into the new way of working. We don’t build the models, we don’t build the AI — what we do is manage the rails that your new AI and new models use to connect into your existing enterprise estate and applications. I’m not asking you to replace the applications that already work and are compliant in your EUC environment. I’m asking you to understand how those connect into your AI environment, and how your AI environment can access them securely, in a way that’s governed, audited, and managed. That’s how we see ourselves fitting in — and honestly, it’s not that different from what we’ve been doing for the past 37 years.
Last thing, in my final minute, instead of Q&A: I’ve been a big proponent of the AI second brain, and the knowledge factory I just described is really the same idea, applied to an entire company. I built my own second brain, and I’ve made it open source — with Citrix’s full support. Go to BrianMadden.ai — that’s the web version of my second brain. My AI writes daily briefings there based on the news and my own perspective, published every day; you can subscribe and read the same thing I do. Every article, every podcast, everything I do lives there. The whole thing is open source, on GitHub — you can download it, fork it, do whatever you want with it. It has an MCP server, so you can connect your own AI directly to my second brain and ask it questions — open your chatbot, connect it to mcp.brianmadden.ai, and ask away. That’s my perspective as Citrix’s futurist on all of this, and you can go dig through the details yourself. I’m also blogging on the Citrix blog, and we have a podcast, Citrix AI Hotsheet, about all of this.
So with that — thank you so much for your time, I really appreciate it. Happy to do follow-ups — go find me at Brian Madden AI. This is how we at Citrix see the industry going, and how we see ourselves fitting into AI as it evolves in your workplace. Thank you all, and good luck out there — it’s a lot of fun these days.



