Most companies treat their AI problems as strategy problems, which they attempt to address in the traditional ways: by creating committees, evaluating platforms, and running pilots … all in the hopes of finding a clear answer to which AI models, vendors, and use cases they should actually commit to.
Meanwhile, AI has already come into every company from every direction. Workers are using it via personal accounts on unmanaged devices. SaaS applications now ship with AI assistants built in. Individual departments are starting pilots with their own token sources. IT has bought everyone Copilot licenses, (though they’re unsure what they’re being used for or whether it’s even worth it. The workers wonder the same thing.) And even for companies that put up all the “proper” security guardrails, workers just point their phones at their laptop screens and snap whatever’s there to run through their own personal AI subscriptions anyway.
All this is happening now, before most companies have fully figured out their AI strategies. So rather than asking, “Which AI platform should we standardize on?” The actual questions you should be asking are, “What AI is running in your company right now?” “What data does it reach?” “Whose identity is it using?” And, “Who can see it?”



