When Anyone Can Build Anything

By Nathan Waterhouse ยท 2026-08-13

In the early 2000s I used to help organisations set up innovation departments. You know the gig. A Head of Innovation role. A skunkworks, or an innovation centre, possibly with beanbags. Maybe a fund. Almost certainly an annual fair, and later, hackathons. Most of them dried up. The ones that worked were the ones that resisted the urge to pipeline everything, because pipelines have bottlenecks, and at the end of every pipeline sits someone on the hook for actually building the thing. That person gets busy, the queue grows, and slowly the enthusiasm the whole apparatus was built to capture drains away.

I have been thinking about those departments a lot lately, because the problem organisations now face with AI is that one turned inside out. Back then, the challenge was getting people to build at all, so we constructed elaborate machinery to coax ideas out of them. Now anyone can build anything. Most of them are, and they are not telling their bosses.

The numbers on this are startling. Microsoft's Work Trend Index found that 78% of AI users bring their own tools to work, rising to 80% at smaller companies. Before anyone blames the juniors, the worst offenders are at the top: 88% of security leaders use unapproved AI tools themselves. One executive I work with, mid-way through designing his company's AI governance, cheerfully confessed to running an unapproved AI agent inside his CRM because it was too useful to give back. His words: I'm as bad as anyone.

I saw the consequences up close recently. A tool I had helped one client build was being offered to other parts of the organisation, and a team responded with a shrug: "oh, we already built one of those". Now, duplication is not a bad thing in creativity: NASA created parallel rocket designs in the Apollo programme on purpose, and Google has engineering teams running blind parallel projects on purpose. It is, after all, the creative confidence IDEO co-founder David Kelley spent decades trying to inspire in people. The difference is that NASA could see its parallel bets; nobody in this organisation even knew the bets were being placed. The trouble is that the tools do not talk to each other. They duplicate effort, embed different assumptions, and none of them will scale. The dream from my old innovation gigs has come true, and it has arrived as an uncoordinated mess.

The two reflexes, and why both fail

Faced with the mess, organisations reach for one of two familiar levers.

The first lever is to restrict access: ban personal use of AI or lock everyone into one lesser model. However, when companies block AI tools, people don't just stop using AI, they find other ways: 71% of knowledge workers use AI without IT approval, switching to whatever tools sit outside the firewall, and 57% actively hide their use from management.

Just like any parent of teenagers knows, telling someone not to do something just makes it invisible and harder to manage. Samsung learned this the expensive way: after engineers pasted proprietary chip data into ChatGPT, the company banned the tool, then reversed course and built an internal alternative, having discovered that prohibition mostly removed their ability to see what was happening. The contrast is Moderna, which also cut off public ChatGPT, but simultaneously gave every employee mChat, a secure internal version their engineers had built. The ban held, I suspect, because people were handed something better at the same moment the old thing was taken away.

There is a talent play here too: a client recently told me his new head of marketing left her last company when it banned the technology rather than fall behind her own market.

The second reflex is the one I (and countless other consultants in the early 2000s) helped invent: the pipeline. An AI council. A Chief of AI. An intake form, a review board, an approval workflow. I understand the appeal, and a cross-disciplinary group absolutely has a role to play, but as the primary mechanism it fails for the same reason the innovation funnels failed. Everything queues behind a small group of busy people. One leader building exactly this structure described his own fear to me perfectly: it starts to feel like asking people to turn up to court with an idea. There is a deeper mismatch too. Committees meet monthly and the tools answer in seconds, so by the time a request reaches its slot on the agenda, the person asking has usually found another way or stopped asking.

The stakes run in both directions. MIT researchers found 95% of organisations see no measurable return from their official AI pilots, while the unsanctioned tools employees bring themselves often outperform the corporate ones. Sprawl carries real liability too: a tribunal ordered Air Canada to honour a discount its chatbot invented, establishing that you own what your AI says. Govern too tight and you waste the technology; govern too loose and you invite the lawsuit. What troubles me about the pipeline is that it protects you from neither: it is simply too slow to keep up with what people are already doing.

A slightly crazy idea

Here is a thought that started as a joke on a client call and I keep coming back to: what if the answer to governing AI is AI? I know it sounds a bit like asking the Terminator to play a role in George Orwell's 1984, but suspend judgement for a minute.

To clarify: the AI does not govern. Humans govern; the AI makes their decisions available at the speed people actually work. It would need three layers.

The first layer is a rulebook, owned entirely by humans. A cross-disciplinary group, the IT, legal, brand, people and comms voices my clients keep listing, but with one crucial inversion: the committee governs the rules, not the requests. It never hears individual cases. It meets to ask whether the rulebook is still right, informed by what people are actually trying to do. Nobody turns up to court. The rulebook needs risk tiers to work, or the queue simply rebuilds itself one level up: whole categories of routine use are pre-approved by the committee, known dangers are pre-refused, and only the truly novel reaches a human. This is roughly where the market is already heading. Microsoft now requires a named human sponsor for every AI agent identity, and agent registries with a documented owner are fast becoming standard, not least because 82% of organisations have discovered an AI agent their security team did not know existed. Moderna, one of the most closely studied AI adopters, runs exactly this kind of tiering: a criticality matrix that classifies every employee-built GPT by impact of failure and audience, so a tool that makes branded video-call backgrounds faces minimal controls while the company-wide benefits assistant faces the most stringent oversight in the building.

The second layer is a concierge. A chatbot, hardened with those rules, that anyone can ask: can I do this? It answers in seconds, not weeks. Can I put this customer data in this tool? No, and here is why, and here is the approved route that gets you most of what you want. Done well, it does more than gate. It teaches. I have written before about the Oracle Effect, the way AI that simply hands down answers bypasses the thinking that makes learning stick. A governance bot built as an oracle would be a compliance machine that everyone learns to route around. Built as a coach, it becomes the fastest AI literacy programme the organisation has, because it meets people at the exact moment they are motivated to learn: when they want to build something. This is less speculative than it sounds. Moderna's legal team built a GPT to answer employees' policy and compliance questions, and the company's Chief Legal Officer reports that compliance actually improved, because people use a tool that answers in seconds where they used to guess rather than bother a human and wait.

One design rule matters more than any feature: the concierge is a tool, never a colleague. New research from BCG published in Harvard Business Review found that when organisations frame AI as an employee rather than a tool, personal accountability drops, escalation jumps by 44%, and reviewers catch 18% fewer errors, because failures get narrated as the bot's mistakes rather than the humans' who deployed it. A governance concierge with a friendly name and a seat on the org chart would institutionalise exactly that transfer, handing everyone in the building someone else to blame. This is why the concierge never decides anything. Every yes and every no it hands out was made in advance by the committee; the bot only retrieves, explains, and names the human who owns the rule, because accountability has to stay somewhere it can actually live. Naming that human is necessary but not sufficient. Ryan McDonough, in his new book Human Accountable for the Loop, calls the belief that a person's presence controls a system the accountability illusion: an owner who cannot pause the tool or change its rules is not an owner, just someone to blame when the controls fail. The humans named in your rulebook need the power to suspend what they own.

The third layer is a commons. A shared internal marketplace of the apps, prompts, data connections and lessons that people have already built, so the concierge can answer the other question that matters: has someone already done this? This is the layer that fixes what worries me most about distributed building, the duplication and inconsistency and unscalable one-offs. Even Moderna, whose employees built more than 1,400 custom GPTs in a year, felt the bite: their head of AI discovered four separate travel-and-expense GPTs, none of them built by the travel and expense team, and no way for anyone to know which one to trust. The commons exists so that the team saying oh, we already built one of those stops being a symptom and becomes a supplier.

One warning from my own opening applies here, though. Innovation departments died partly because their repositories did: nobody was rewarded for sharing, so nobody shared. The commons that survive are social before they are technical. Moderna's hundred-strong champions team selected itself through a company-wide, peer-voted prompt contest, and Brice Challamel, who led AI products there, describes it self-organising like a World of Warcraft guild: it elects its own leaders, and he deliberately did not interfere. Citi tells the same story at scale: adoption of its approved tools passed 70%, with a network of 4,000 peer champions at the centre of the rollout. Left to itself, a marketplace is just another portal slowly filling with things nobody looks at. What made these ones work was the people tending them, and the sharing followed from that.

Before anyone points it out: yes, I have proposed governing AI with the very technology that got Air Canada sued. That ruling established that you own what your chatbot says, which means a governance bot that hallucinates an approval could create precisely the legal exposure it was built to prevent. This is exactly why the first layer matters. Humans own every rule. The AI only delivers them, logs what it was asked, and hands anything ambiguous to a person. The committee's job shifts from processing requests to auditing the one system that answers them, which is a far better use of five busy people than a monthly docket of permission slips.

There is a harder problem I will not pretend to have solved. If every question to the concierge is logged, then asking becomes confessing, and the people doing the riskiest things will be the last to ask. The numbers say this plainly: 54% of employees would carry on using AI tools even if the company banned them, which is why governance practitioners now argue for AI amnesties, time-limited windows to disclose what you are using without punishment, modelled on 'tax amnesties' and 'bug bounties'. A concierge people fear is a concierge nobody asks, and then you have rebuilt the shadows inside your own solution. The closest thing I have seen to an answer comes, once again, from Moderna: an agent called Stardust that privately reviewed how each employee was using AI and sent them personalised coaching every week, with no human ever seeing the individual detail. That does not fully resolve the tension between a safe place to ask and an audit trail, but it suggests where an answer might live: humans oversee the patterns of use across the organisation, while an individual's personal dialogue stays between them and the machine.

The question the bot cannot answer

A few years ago I argued that AI would push authority to the edges of organisations, and I cheered. I still cheer, mostly. Lately, though, I have come to think I had the geometry wrong. Distribution is not the destination. It is the starting condition. The power to build has already moved to everyone; the numbers above are simply what that looks like before anyone has designed for it, and capability without direction is just noise with a sense of accomplishment. A leader I know was recently, and proudly, shown an AI-generated cartoon training video by a colleague who had built it with real initiative and was rightly pleased with the effort. It was also wrong for the brand, wrong for the audience, and destined for nowhere.

When anyone can build anything, the question that matters is no longer can you. It is should you. I have written before about how teams default to the how because the why is cognitively expensive, and building is the most seductive how there has ever been. A concierge can answer may I in seconds. A marketplace can answer has someone already. Only strategy can answer should we, and no chatbot, however well governed, will supply it.

For twenty years, IT was the bottleneck on distributed innovation, and we resented it. That bottleneck is gone. What remains is the one that was always underneath it: alignment. A person with an idea at the edge of the business should be able to find out in seconds whether they may build it. Whether they should is not a governance problem. It never was.

The Moderna detail in this piece draws on Harvard Business School's case study, "Moderna: Democratizing Artificial Intelligence", and on material generously shared by Brice Challamel.