Business leader considering the risks and decisions involved in AI adoption

The AI Decisions Businesses Are Making By Accident

July 22, 20267 min read

The AI Decisions Businesses Are Making By Accident

I don’t normally write about individual AI models. Their rankings and capabilities change too quickly and there are plenty of people covering every new release.

But several developments over the past five weeks are not simply product news. Taken together, they make decisions facing business owners, CEOs and boards significantly more complex.

Not even 12 months ago, the question we were asking was “Which AI model should we use?”

Fast forward to July 2026 and it is, “What parts of our business are we prepared to make dependent on someone else’s model, infrastructure, commercial model and jurisdiction?”

In June, the US government directed Anthropic to prevent foreign nationals from accessing its newest Fable and Mythos models. Because Anthropic couldn’t verify nationality in real time, it disabled them for everyone. The restrictions have now been lifted, but for that period a capability customers expected to be available disappeared because of a government decision they had no control over.

Then Chinese company Moonshot released open-weight model Kimi K3, which is competing with the leading closed models in some areas and is substantially cheaper. US company Thinking Machine Labs released Inkling, a US based open-weight model that organisations can download, customise and fine tune for their own requirements.

And at the same time, Anthropic launched Claude Tag, allowing Claude to sit inside Slack channels, connect to company tools and codebases, remember relevant context and complete work delegated by the team.

At first glance, these all look like separate pieces of AI industry news. But I think they point to a much bigger question for business leaders.

How much of your business are you prepared to build around one AI company?


The model is only one part of the decision

Right now, many businesses are trying to decide which AI model they should standardise on - Claude, ChatGPT, Gemini, Copilot or one of the growing number of open models. Too many tools create cost, confusion and fragmented ways of working so businesses need to choose where to focus.

But choosing a model for your employees to use for simple prompting tasks is very different from building your operations around that model.

AI is moving out of the separate chat window and into the systems where the business actually operates.

It’s being connected to Teams, Slack, email, customer records, financial information, company documents and codebases. It’s now remembering previous conversations, learning how the business works and taking action across multiple systems.

At that point, changing providers is no longer as simple as changing subscriptions. You may need to rebuild the integrations, transfer the knowledge, recreate the permissions, rewrite the instructions, reconstruct the audit history and retrain your team.

The model itself may be replaceable but everything you’ve built around it may not be.


This is concentration risk in another form

A few weeks ago, I wrote about how concentration risk develops inside businesses.

Nobody deliberately decides to become completely dependent on one client, one supplier, one employee or one system. It happens one sensible decision at a time.

AI dependence will develop in exactly the same way.

One model is better at coding, so your development team begins using it. Another is deeply integrated into Microsoft 365, so the rest of the business starts using that. An AI agent works well inside Teams or Slack, so you connect it to more channels and give it access to more tools.

Every individual decision is reasonable. But taken together, those decisions are creating an enterprise architecture and it needs to be consciously designed.

The part leaders need to understand is the risk isn’t just whether an AI provider could fail or disappear.

It could change its pricing. It could change how its product works. A government could restrict access. A competitor could produce a much better model. Or you may later discover that the provider you chose is no longer appropriate for the sensitivity of the work it is doing.

There is also a quieter risk. The knowledge your business feeds into these systems, as they learn how you price, sell and operate, may be accumulating somewhere you don’t control.

So there are really only two things worth protecting here and almost everything else in this decision is detail.

  • The first is your ability to move: to change providers without dismantling how you work.

  • The second is ownership of what the system accumulates: your data, and the knowledge it builds as it learns how you operate.


Owning what matters isn’t the same as hosting everything

There is an obvious response to all of this: bring the model in-house.

Open-weight models make that increasingly possible. For example, Palantir and NVIDIA recently announced a way for organisations to run customised models inside their own infrastructure, so the data and the model stay with the business rather than passing through an external provider.

For organisations with genuinely sensitive data or valuable intellectual property, that can be the right call.

But hosting your own model moves the dependency. The business now owns the infrastructure, the security, the technical skill and the ongoing maintenance required to run it reliably. For most small and mid-sized businesses, that may not be necessary or affordable.

The goal is not to own every part of the system. It is to decide, deliberately, which parts you keep control of, and which you are comfortable renting.

Different parts of the business need different answers

The mistake is treating AI as one organisation-wide decision. It is more useful to sort the work into three levels.

The first is commodity productivity: brainstorming, first drafts, summarising non-sensitive material, general research, meeting preparation. For this work, using an external AI platform may be completely appropriate. The risk is low, the benefit is immediate, and moving to another tool later would not be difficult.

The second is operational AI: the point where the system connects to your business and does repeatable work. Communicating with customers, updating company records, producing management reports, analysing operational data, making recommendations that influence real decisions. Here the business needs to know what the system can access, what it is doing and who remains accountable when it is unavailable or wrong. It should be designed so the workflow and business rules sit in systems the company controls, allowing the underlying model to be changed without rebuilding the whole process.

The third is strategic intelligence: the information and judgement that make the business valuable. Proprietary processes, pricing logic, customer intelligence, product development, the methods that have taken years to build. For this work, convenience matters less than control, and that may justify stronger contractual protection, a private environment or a carefully chosen open-weight model, with explicit limits on what information can leave the organisation.

The right answer will be different for every business. But it needs to be an intentional answer.

The questions leaders should be asking now

Owners, CEOs and boards do not need to spend their meetings debating whether Claude is better than ChatGPT or whether Kimi has overtaken both of them. That isn’t the level of decision they need to make.

They need to understand where AI is becoming part of the operating architecture of the business.

If access to your primary AI provider disappeared tomorrow, what would stop working?

If a substantially better or cheaper model became available, could you move your important processes to it?

Where does the organisational knowledge being created through AI actually live?

And are your data, business rules, prompts, permissions and decision history controlled by your organisation, or are they gradually becoming trapped inside someone else’s ecosystem?

The best-performing model will keep changing. Before choosing which AI company you want to go deeper with, the more important decision may be working out how deep you are prepared to let them go.

Because whatever you build, the business has to keep owning the things that matter: its data, its operating knowledge, its workflows, its decision rights and its ability to choose what comes next.

Until next week,

Kylie.

Back to Blog