Select Page

As we moved AI beyond the early adopters, I kept wrestling with a familiar tension: risk and opportunity, pulling in opposite directions.

Most organisations I’ve worked in resolve that tension the same way. Lock things down first. Write the policies, build the controls, restrict access, and loosen the grip slowly over years. The intent is responsible. The effect, mostly, is that momentum dies in committees while the technology gets used anyway, unseen.

This time, we flipped the script.

We leaned into the people who were curious and positive. We gave them real access, real education, and a clear deal: interrogate the outputs, check the sources, apply your judgement, and tell us what you find. We treated early low-risk missteps as intelligence rather than incidents. Every gap someone surfaced, a prompt that pulled data it shouldn’t have, a misunderstanding about what the tool could do, was a fence we now knew we needed.

I won’t pretend the approach felt comfortable. It asked me to trust people earlier than traditional governance encourages. In critical infrastructure, “trust” can sound naïve.

But here’s what I’d say to a fellow CIO or director who bristles at that word. Distrust is also a risk. When people feel controlled, they disengage, or they route around the controls, and routed-around controls are worse than none because they give you false comfort. The people using shadow tools on personal devices are invisible to you. The people inside your guardrails are teaching you where the guardrails should be.

This was never about ignoring risk. It’s about where risk knowledge comes from. Months of theoretical fence-building, or weeks of real use surfacing real issues you can actually fix?

Scaling AI is not primarily a technical challenge. It’s a cultural one. You can scale at the speed of perfect control, which is to say never. Or you can scale at the speed of trust, and build that trust deliberately, through education, observability, transparency and shared responsibility.