For the first few months, every AI conversation in our organisation orbited the same question: should we allow this?
It’s the natural question for critical infrastructure. We supply an essential service. Our risk culture is strong for good reason, and “should we allow it” is how that culture greets anything new. But I came to believe it was the wrong question, because it only has two answers, and both of them are bad.
Say no, and the technology doesn’t go away. It goes underground. People use personal accounts on personal phones, and you lose all visibility of the very risks you were trying to manage.
Say yes, and without more thought you’ve simply opened the gates and hoped.
The question we replaced it with has shaped everything since: what would make this safe to scale?
The distinction matters. “Safe to use” is about the tool, and vendors will happily answer that one for you. “Safe to scale” is about the organisation. It forces you to look at everything that has to be true before hundreds of people can use these capabilities in real operations. Do people have the judgement to challenge outputs? Do processes have owners who can say what good looks like? Is our data fit to be consumed at speed? Do our access controls hold when an agent, not a person, is doing the asking? Does our governance move at the pace of learning?
None of those are questions about AI. They are questions about us. That’s the point.
Framed this way, risk and opportunity stop being opposites. Every gap you close to make AI safe to scale, clearer process ownership, better data, sharper access control, makes the organisation stronger even before the value of AI shows up.
Nearly everything I’ve learned in this journey traces back to that reframing. Not “should we allow it”, but “what would make it safe to scale”. I’d encourage you to put that question to your own executive team and see where it takes you.