John Laverick

Idea

If technology makes delivery dramatically faster, can the functions that make delivery safe keep up without becoming the bottleneck?

As AI reduces the cost and time required to build and experiment, security, data, architecture, assurance and other enabling functions need to evolve too. Good governance should make responsible action easier, not depend on friction being slow enough to control behaviour.

Current thinking

A lot of the discussion about AI-enabled transformation focuses on the people doing the building.

Developers can move faster.

Product teams can prototype sooner.

Individuals can automate work that previously required specialist support.

That matters.

But organisations are systems, and delivery does not happen in isolation.

Around the team doing the work sit security, architecture, data, finance, commercial, assurance, risk and other functions designed to make sure that change is responsible and sustainable.

Many of those processes were created for a world in which change itself was expensive.

If building something took months, waiting several weeks for a review could feel proportionate.

If a useful prototype can now exist by tomorrow afternoon, the same process can consume more time than the experiment.

That creates an uncomfortable choice.

Either the organisation gives up much of the speed the technology created, or people discover routes around the controls.

Neither is particularly attractive.

Make the safe path the easy path.

That sounds simple, but it implies a different way of thinking about enabling functions.

The objective cannot only be to approve or reject work presented to them.

It increasingly needs to be to create conditions in which teams can move quickly inside known boundaries.

Some of that can be built into the organisational harness.

Approved models.

Known data classifications.

Reusable identity and access patterns.

Standard evaluation approaches.

Observable costs.

Logging and tracing.

Clear authority boundaries.

Pre-agreed patterns for low-risk experimentation.

The more of the routine safety work that can be made reusable, the less often every team needs to rediscover it.

This is not about removing controls.

In some areas the consequences of being wrong are too significant for speed to dominate.

The distinction is between controls that manage a real risk and friction that exists because the organisation has historically had enough time to tolerate it.

The economics of certainty change the calculation.

When an experiment is cheap, contained and reversible, the cost of deciding whether to permit it should probably be different from the cost of deciding whether to operate a critical service.

That connects directly to permission to operate.

The safe path for experimentation should be easy.

The threshold at which an experiment becomes something the organisation depends on should be clear.

And the obligations should increase as the consequences increase.

There is a wider transformation point here.

If AI makes the delivery team ten times faster while every dependency around that team stays at the old speed, the organisation does not become ten times faster.

The constraint simply moves.

Eventually the biggest gains may come not from accelerating the people who build things, but from redesigning the system that allows responsible change to happen.

Governance should still slow us down when slowing down is valuable.

It should not need slowness in order to work.

Writing on this idea