Whose job is AI?

"There is no plan to ease the entry into the AI era."

Painterly illustration of a vast engine hall at dusk: one huge machine of gears and pipes, five business-dressed figures around it each holding a torch that lights only their own patch.

“There is no plan to ease the entry into the AI era.”

That’s Bill Gates, in his recent essay on Gates Notes. He’s talking about governments and international bodies, and none of us can do much about those from where we sit.

But one passage in the essay is really about organisations. Any organisation. Have a read of this with your own leadership team in mind:

“A labor department may understand workforce disruption but not security risk. A business regulator may understand market concentration but not AI’s effects on children and teenagers. Left to themselves, institutions will see only one part of the system, while the consequences of AI will ripple across the entire system.”

And the impact: “an AI-enabled attack might succeed because no one thought it was their job to stop it.”

Now swap in your own functions. IT understands the security risk but not what AI does to the workforce. P&C understands the workforce but not the data. Legal understands the contracts but not what’s actually running in the business.

Risk sees a register. Each of them sees one part of the system.

So there is no plan. And in most organisations I walk into, there isn’t even a plan to have a plan. There’s a policy that says which tool is approved, and that’s about it.

The symptoms

I’ve had this exact conversation in the last fortnight. Staff at one organisation were telling their colleagues to use an AI tool that wasn’t approved and “ask forgiveness later”. The leadership team found out about it when someone escalated it. It came to them as an incident rather than information.

And you can’t really blame the staff. The approved tool was approved on paper, but there was no usable guidance and nothing much to use. If you ban something without providing an alternative, that’s a pretty indefensible position.

They’re going to turn around and say, you haven’t given us anything, I had to use something.

Shadow AI is usually a clarity failure. There’s a lack of clarity about what the AI direction is, so people are making their own decisions.

The antidote

I’ve addressed this using a three-layered approach with a few very different organisations this year.

1. AI fluency.

A common language at the leadership level. When you say AI, what are you actually talking about? Copilot chat, an agent, a model, a robot? If leaders have that fluency and they can all be talking the same language, that’s like 90% of the work.

2. AI direction.

I don’t call it strategy anymore, because people get overwhelmed when you use the word strategy. It’s not strategy. It’s just a direction. What role is AI going to play here, and what does the next step up look like? Most of the decisions have already been made in your digital, cyber and information security strategies. The direction just makes them visible for AI.

3. Governance and foundations.

A working group with terms of reference and a standing agenda, and a technical platform underneath it where the approved tools are actually usable. The working group doesn’t make new decisions. It surfaces the ones already made and asks how we’re adhering to them. And it gives people a channel to say “we’re about to do this, is it a problem?” so that the next thing arrives as information rather than an incident.

Repetition is the mechanism. Those three layers get talked about every time the working group meets. If every meeting approaches AI with new thinking from zero, it’s exhausting, and it just goes in circles. That’s exactly what happens when there’s no agenda… everyone reacts to whatever case study they read that week.

If you haven’t read Bill Gates’ essay yet

Stop reading this right now and go read it now!

I read every word (no AI summarisation). It’s one of the more pragmatic and balanced views I’ve come across in a while. He acknowledges both the potential for immense good and the potential for catastrophe for humanity, and he does so with some really enlightening arguments that I hadn’t fully considered.

Whilst his message is very simple, some of his ideas are very controversial. In short:

  • Three big risks. Many jobs will disappear forever, and faster than people can reskill, because AI runs on the hardware we already have and learns the way people learn. AI will empower people (and perhaps AIs) to do more harm, at a new scale. And AI could stunt our kids’ development and replace human relationships… an AI companion designed to never upset you is, in his words, “a big, protected greenhouse”.
  • The positives. Scientific advancement and what that could do for healthcare, agriculture for farmers in low-income countries, government services people can actually get to, and education where teachers get freed up to work with struggling students.
  • Two bold ideas. “Human Reserved”, work we agree should always be done by humans even if a robot could do it. And taxing AI tokens and robots, because right now the tax system nudges you towards replacing people with machines.

And Human Reserved has a version inside your organisation too. It’s deciding which decisions stay with a person, even when AI could make them. Govern the decisions, not the tools.

None of this fixes the international framework. Gates is right that it will take years, and it’s not ours to build. But he’s also right that we don’t have the luxury of moving slowly, and the plan for your own organisation is something you can write this quarter. There’s a lot to think about, but if we break it down, it’s nothing we can’t handle if we’re diligent.

If your working group keeps starting from zero...

Building the fluency, the direction and the governance your organisation can actually run is what the AI Governance work at evince is built around. Govern the decisions, not the tools.

Learn about our AI Governance work