Nobody Knows How AI Will Reshape the Firm Yet. Boards Still Have to Govern.

Nobody yet knows what the AI-enabled firm will look like. Five lenses to help boards govern value, operating coherence, time, risk and learning while it emerges.

Mark Lancelott

Artificial Intelligence, Corporate Governance, Board Leadership, Business Strategy, Business Design, Operating Models

Every week brings another confident account of the organisation that AI will create.

The flat structure. The end of middle management. The agent-orchestrated enterprise. The ten-person company doing the work of a thousand.

Some of this is thoughtful and some will prove right. But much of it describes a destination without a route. It often assumes that an organisation is a largely digital system, untroubled by customers, regulators, physical assets, professional judgement or the need to make tomorrow morning actually work.

So let me be clear about where I sit.

I have spent much of my career thinking about how organisations create value: how they make money, how the work works and how people are organised around it. I have a reasonably good map of that territory. I do not yet have a settled view of what AI does to it.

I am not sure anyone does.

Across several recent conversations, however, I have noticed the discussion beginning to mature. The question is moving beyond whether to use AI, towards its economics, its effects on the wider system of work and whether organisational understanding is keeping pace with deployment.

These are the kinds of signals from which the eventual operating models will emerge.

Waiting for a proven operating model is not a viable strategy. Neither is committing the business to whichever model is being promoted most confidently this quarter.

The board's question is not:

What is the answer to AI?

It is:

How do we keep this business viable while the answer is still being discovered?

I am not offering a target operating model. I am suggesting five connected lenses through which a board can govern the process of discovering one:

  1. Value and advantage — How does AI change what customers value, who can provide it and where we can win?

  2. Where AI lands — Where in the value chain can AI improve, remove or create work, and what authority should it have?

  3. Operating coherence — Can the wider operating model absorb the change without creating new constraints or eroding essential human judgement?

  4. Time and options — Are our decisions, investments and assurance moving at the right pace, and which choices should remain reversible?

  5. Risk, assurance and learning — Are we taking the right risks and learning fast enough to prevent exposure from outrunning understanding?

From performance to viability

Most business conversations about AI begin with performance.

Where can we increase productivity? What can we automate? How much cost can we remove? How quickly can we deploy?

Boards should ask these questions, but they should not stop there.

Performance is about whether the organisation is delivering against its current objectives. Viability is about whether it can continue to create value and adapt as its environment changes, without consuming the foundations on which its future depends.

A company can be performing well while its viability deteriorates. It can meet current targets while losing customer relevance, becoming dependent on a small number of technology providers, allowing essential expertise to atrophy or investing against assumptions whose useful life is shortening.

Conversely, a viable company will sometimes accept lower immediate efficiency to preserve options, build capability, retain trust or learn about an uncertain future.

For companies in the relevant UK listing categories, this is not merely conceptual. Boards already report on longer-term viability: the period over which they have assessed the company's prospects, the assumptions supporting that assessment and whether the business can continue to operate and meet its liabilities. (FRC, FCA)

AI raises an uncomfortable question:

What happens when the useful life of important assumptions is shortening faster than the formal assessment period?

AI does not create a new purpose for the board. It makes an existing purpose more difficult to discharge.

Lens 1: Value and advantage

How does AI change what customers value, who can provide it and who captures the economics?

The most common mistake is to begin with implementation.

Where can we deploy AI? Who owns it? What should the adoption target be? How many people have been trained? How many use cases are in the pipeline?

These are second-order questions.

The first-order question is whether AI changes what customers value, what they will pay for, who the company competes with and where advantage comes from.

If a capability is available to every competitor from the same small group of providers, at broadly the same price, it will not remain an advantage for long. It becomes a new cost of entry. Its benefits appear in customers' expectations of price, service and turnaround before they appear in the company's margin.

The democratising effect goes further. Customers are gaining access to capabilities they previously had to buy from us.

They can perform their own research, produce content, analyse data, write software or navigate a problem for which they previously needed an intermediary. They do not need to become experts. They need only become capable enough to unbundle part of an existing proposition or become much more demanding buyers of it.

The strategic question is:

What happens when customers can do for themselves some of what they currently pay us to do?

If producing an answer, document or recommendation becomes cheap, value moves elsewhere: to assurance, accountability, judgement, proprietary access, integration or the willingness to stand behind an outcome.

A customer might pay less for the production of an analysis while still paying someone to determine what it means in their circumstances, accept responsibility for the recommendation and help deliver the result.

In November 2024, I stopped work on a AI video avatar competency-based interview platform venture. Not because the product could not work, but because capabilities that had looked distinctive were becoming replicable on better-funded platforms. It could still create value - and customers were telling us this. But we could no longer see a sufficiently defensible way to capture value.

That is an easy distinction to make in a framework and a more expensive one to learn in practice. An impressive AI capability is not necessarily a business.

The more important question is what does not diffuse easily.

Proprietary data. Distribution and installed base. Physical assets and networks. Regulatory permissions. Trust. Deep relationships. Domain expertise. The ability to integrate technology into a complex operation. The organisational capacity to redesign and scale the work.

AI also introduces a less familiar competitive threat. It does not merely make an existing competitor better. It can allow a new entrant to combine activities that previously sat in separate parts of an industry, redrawing the boundaries of the market itself.

The economics need to be real

In recent conversations, I have heard clients beginning to worry about the future cost of tokens. They are looking more carefully at which work requires a frontier model, which can use a cheaper model tier, where open models are appropriate and where conventional software is both more effective and less expensive.

This feels like a healthy development.

"Use the most capable AI available" is not a strategy. The relevant question is what combination of model, data, tools, workflow and human input produces an acceptable outcome at an attractive and resilient unit cost.

The most advanced model is unnecessary for much of the work. In some cases, AI is unnecessary too.

Technical feasibility is not attractive unit economics. The full cost includes models, compute, integration, data preparation, evaluation, human review, exception handling, controls and vendor margin. Agentic systems can perform more work, but they can also consume more resources and generate more activity requiring supervision.

I would push management to show the cost per completed outcome, not merely the cost per token - and to explain how the business case changes if usage, model pricing or supplier terms change.

Lens 2: Where AI lands

Where does AI enter the value chain, and how consequential is the authority we give it?

The useful place to start is not the function - marketing, finance, HR or operations - but the chain of activities required to keep a customer promise.

Where does AI change the economics or quality of an activity? Which step disappears? What new step becomes possible? Where does an output enter another person's work, a control process or the physical world? Where will the constraint move as a result?

Only then should the conversation turn to the technology being deployed.

"AI" is not one technology on one curve. Forecasting from structured data, generating language, interpreting images and video, and acting in the physical world are progressing along different paths. A professional-services firm, a hospital and a logistics operator face different constraints, consequences and investment horizons.

Nor is the underlying model the whole capability.

The system around it can include company data, retrieval, memory, tools, rules, verification, workflow design and the permissions given to act. An agent harness is the surrounding machinery that enables a model to perform multi-step work and use tools. Changing that machinery can materially alter performance without changing the model.

The terminology matters less for a board than the implication:

The model is not the system.

A general-purpose model embedded in a tightly bounded workflow, connected to trusted data and checked against clear rules is a different business capability—and a different risk—from the same model given broad permissions to search, decide and act.

Early field research, describes a "jagged technological frontier": AI can improve performance significantly on some tasks while reducing it on other, apparently similar, tasks. The difficulty for organisations is that users cannot always see where the boundary lies. (Harvard Business School)

I have spoken with capable specialists using AI seriously who did not share a clear distinction between the base model and the harness around it, or a developed view of model risk. I do not take that as a criticism of the individuals. It shows how quickly use has spread beyond the communities in which model validation and AI-system design are established disciplines.

If experienced users do not yet share a language for describing the system and its limitations, a board should be cautious about assurance that rests primarily on user confidence or vendor demonstrations.

I would want management to answer three questions:

  • Where in the value chain does the system enter?

  • Is it informing, recommending, deciding or acting?

  • How close is it to customers, money, employment, physical assets or another consequential outcome?

The permissions given to the system can matter more than its apparent intelligence.

Lens 3: Operating coherence

Can the rest of the business absorb the change without creating new constraints or eroding essential human judgement?

Most AI experiments begin with an individual task.

Can AI help someone draft a proposal, review a contract, write code or answer a customer query?

This is a sensible place to learn. It is a poor place to stop.

In just one recent conversation, I heard how coding output had accelerated but work was now accumulating in testing and quality assurance. The developer was faster. The delivery system was not.

This illustrates a general principle:

Local acceleration moves the constraint.

Faster software development increases pressure on testing, architecture, security and release management. More content creates a brand and compliance queue. More analysis creates an executive-attention bottleneck. Automated customer contact moves exceptions into an already constrained service operation.

AI also makes some work cheaper to attempt.

If the cost of generating a proposal, analysis, product variation or policy option falls dramatically, people generate more of them. The organisation then has to select, review, coordinate and absorb the increased volume.

The limiting resource moves rather than disappears.

This matters particularly when the new bottleneck is an assurance function. The organisation can invest in capacity, redesign the control, automate appropriate tests or reduce incoming volume. Or it can allow pressure to build until people start bypassing it.

That is where a productivity gain becomes a source of risk.

Digital intelligence still has to meet the real world

Care, construction, manufacturing, hospitality, agriculture, transport, utilities and field service all involve work that happens in a place, to a thing or with a person.

The path for AI in these businesses differs from the path in a digital business.

Experimentation is more expensive. Investment cycles are longer. Errors are less reversible. Safety and reliability requirements are higher. Benefits depend on changing equipment, workflow and human behaviour together.

More fundamentally, the model never contains the whole context.

A technically optimal production schedule might not work on this site today. A standard clinical recommendation can be inappropriate for this patient. A maintenance signal means something different because of what happened on the previous shift.

In much of the real economy, humans are not simply "in the loop."

They are the interface between the digital model and a physical, social and institutional world the model does not fully contain.

They interpret exceptions, add tacit knowledge, reconcile conflicting objectives and accept responsibility in situations that cannot be reduced neatly to data.

This is not an argument for preserving every role. It is an argument for identifying where context and judgement are critical.

That matters when boards consider workforce plans built on AI assumptions. A model's ability to perform a task is not evidence that the organisation can safely remove the role. I would want to know what happens to demand, assurance, exception handling, management capacity and the development of future expertise before productivity assumptions become headcount commitments.

Local task productivity is not the same as system performance, and system performance is not the same as customer value. This is where the operating model matters. Process, organisation, information, infrastructure, suppliers, incentives and controls have to change together.

If they do not, successful experiments create a shadow operating model: work, decisions and accountabilities start moving through arrangements that the formal organisation has not designed or governed.

This is more than unauthorised tool use. The organisation chart, control framework and management information describe one company while the work is increasingly being performed by another.

The longer the gap persists, the harder it becomes to see where value, judgement and risk actually reside.

Lens 4: Time and options

Are our decisions, investments and assurance moving at the right pace, and which choices should remain reversible?

Capital allocation depends on an assumption about time.

Build the process, purchase the system, train the workforce and recover the investment over an expected period. If the useful life of a process design, software platform or skill is shortening, that arithmetic changes.

The Three Horizons model remains useful.

Horizon 1 improves and defends the current business. Horizon 3 explores possibilities that could redefine the business. Horizon 2 builds propositions and capabilities that could become material.

These are different investment logics, not simply different dates in a plan.

AI complicates the model because the distance between the horizons can collapse. A capability treated as speculative Horizon 3 work can become a Horizon 1 customer expectation surprisingly quickly.

That does not mean everything should now be managed on short cycles.

Data quality, integration, security, trust and domain capability require sustained investment. Physical infrastructure continues to operate over long periods. Companies that treat everything as an experiment risk never building anything with enough depth to defend.

Real-options thinking offers a useful response to uncertainty. Staged investment, modular architecture and explicit decision points can buy knowledge and preserve the right - but not the obligation - to make a larger commitment later.

But optionality should not become an intellectual justification for permanent piloting.

A real option has an exercise decision. The board should know what evidence will cause the company to scale, stop or make its next commitment.

The organisational clocks

My work on Requisite Pace starts from the observation that AI changes not only the cost and quality of work, but its tempo.

For a strategically important domain, I would ask management to understand five clocks:

  • Signal half-life: How quickly do the relevant information and assumptions become stale?

  • Decision latency: How long does it take to reach an authorised decision?

  • Change cycle: How long before that decision changes a real product, service or operation?

  • Assurance and learning cycle: How long before the company knows whether the change worked and remained within appetite?

  • Recovery cycle: If it fails, how quickly can the company contain, reverse or recover from it?

AI can accelerate one clock while leaving the others untouched.

Good governance is not slow governance. It is governance operating at a tempo appropriate to the consequences of the decision.

The board does not need operational cycle-time detail across the company. It should understand the material clock collisions: where opportunity is moving faster than capital allocation, delivery faster than assurance, technology faster than skill formation, or failure faster than recovery.

Lens 5: Risk, assurance and learning

Are we taking the right risks and learning fast enough to prevent exposure from outrunning understanding?

AI is not simply another entry on the enterprise risk register. It changes existing strategic, operational, conduct, cyber, people, legal, third-party and reputational risks.

It also changes their shape.

AI moves closer to consequential decisions. Errors can propagate at greater speed and scale. Multiple activities can depend on the same model, data or provider. Systems can change after approval, while their limitations and lines of accountability remain difficult to identify.

Risk appetite should therefore be expressed in terms of purpose, consequence, autonomy and reversibility - not "AI" in general.

A company can have a high appetite for low-consequence, reversible employee assistance; a moderate appetite for recommendations affecting operations; and a low appetite for opaque autonomous decisions affecting safety, employment, credit or customer rights.

The objective is not uniformly more control. It is to create areas in which the organisation can move quickly because the boundaries and potential consequences are understood.

Model risk is one under-recognised part of the picture

General-purpose models generate plausible outputs rather than guaranteed truths. Their capability boundaries can be difficult to observe. Outputs vary. The model and surrounding system change. Performance in a demonstration does not necessarily transfer to the operating environment.

I recently heard of two accounting managers using the same data and prompt at different times and receiving different answers. A technical specialist could identify several possible causes: sampling behaviour, model version, configuration, context or something in the surrounding system. The governance problem was that the users could not determine which.

In a consequential financial process, unexplained variability is a control issue. Before the organisation relies on the output, it needs to understand the conditions under which results can change, how those changes will be detected and what must be independently verified.

This does not mean AI has no place in financial work. It means controls designed for deterministic software cannot simply be carried across to probabilistic systems.

NIST's AI risk framework emphasises defined application boundaries, testing and continuing monitoring rather than assuming a system is trustworthy because it comes from a leading provider. (NIST)

The PRA's model-risk principles apply formally to certain financial institutions, but the discipline is more widely useful: identify material models, classify them by consequence, establish ownership, validate independently, control their use and monitor them over time—including externally supplied models. (Bank of England)

A company can outsource technology, but not the consequences of using it.

Experimentation is part of assurance

If the eventual operating models will emerge from practice, companies need to experiment. But the purpose of an experiment is to reduce a named uncertainty, not to produce another successful pilot.

I would want management to distinguish between technical, customer, economic, operating and risk hypotheses - and state what result would cause the company to stop.

The board does not need a list of use cases. It needs a view of the learning portfolio:

  • What important assumptions are being tested?

  • What has changed as a result?

  • What has been stopped?

  • What is ready for a larger commitment?

  • Is assurance adapting as quickly as use is changing?

The final question is whether the board itself is equipped to provide this challenge. That does not require every director to become an AI specialist. It requires sufficient shared literacy, access to independent expertise and clarity about where oversight sits - without isolating AI from strategy and enterprise risk.

When the assumptions expire before the assessment period

If important assumptions are expiring within the period covered by the company's viability assessment, the board needs more than an annual conclusion that the business remains viable.

It needs leading evidence about whether the conditions supporting that conclusion are strengthening or deteriorating.

Current performance can continue to look healthy while customer relevance, organisational capability, strategic optionality or control are already weakening.

I would look for four early signals.

  • Customer substitution and competitive rebundling: Customers or new entrants are internalising, combining or bypassing activities on which existing revenue depends.

  • Dependency and economic concentration: Reliance on a small number of models, platforms or suppliers is growing while unit economics or exit options remain uncertain.

  • Capability atrophy: Human expertise, meaningful review and the formative work through which future judgement develops are declining.

  • Temporal friction: QA queues, overrides, exceptions, workarounds and assurance delays are increasing as acceleration moves constraints elsewhere.

These are not yet a validated measurement system. They are prompts for looking beyond current financial performance to the conditions on which future performance depends.

Across all five lenses, I would keep returning to one question:

What has management learned that changed its previous view - and what evidence would cause it to change again?

The Business Model Canvas helps examine value and advantage. Value-chain mapping shows where AI enters the work. The Operating Model Canvas tests whether the business remains coherent. Three Horizons, real options and Requisite Pace bring time and capital into the design. Enterprise-risk and model-risk disciplines provide the basis for assurance.

The individual frameworks are not new. The contribution is holding them together around the viability of the firm.

Govern the process of discovery

I am reasonably confident about three things.

The fundamentals still hold. Businesses must create something customers value, capture enough of that value to remain viable and organise the work required to deliver it.

The eventual operating models will emerge from practice. Companies will need to experiment deliberately and learn faster than their assumptions expire.

And timing will prove more central than speed. The companies that navigate this well will not be fast everywhere. They will operate at different tempos in different domains, maintaining enough coherence to learn, govern and change without destabilising themselves.

I am less confident about the destination - and I would rather say that than pretend otherwise.

The board does not need to predict the final form of the AI-enabled firm.

It needs to govern the process through which the company discovers it.

I am turning these five lenses into a short diagnostic for boards and leadership teams. If your organisation is working through these questions, I would be interested in testing the thinking against your experience - particularly where practice contradicts the prevailing AI narrative.

© Mark Lancelott, 2026. Licensed CC BY-SA 4.0 — see licensing terms.