You don’t get to decide whether your team uses AI
Last Friday in Melbourne, Satya Tammareddy from OpenAI put a chart on the screen that quietly argued with two days of my own thinking.
The conference was IRAI, the IEEE’s conference on responsible AI, at La Trobe’s city campus. I’d spoken on the same stage the day before, so I was already well into the question of who is responsible for what.
Her chart had generative AI at 40% adoption. It had it getting there roughly five times faster than the internet did, and ten times faster than the PC. I’m quoting a slide rather than a paper, so take the multiples as the shape of the thing rather than as a measurement.
It stayed with me, because I don’t think it was a chart about adoption at all.

On this page:
The half of this that was well covered
Most of the responsibility here sits with the companies building and training the models. I mean that plainly. Safety, alignment, what a model refuses to do, what it discloses about itself, how it behaves when someone deliberately pushes on it - that is the harder engineering problem, and it belongs to them. IRAI covered it properly, with people who work on it for a living. I can’t add anything to that half.
The half I keep thinking about is the one sitting at the end of the conference’s own description, where it’s easy to skim past: responsible design, development, deployment, and responsible adoption. Adoption is the word that belongs to the rest of us.
What the chart is actually telling you
A technology does not reach 40% of people that fast through procurement.
It gets there because someone opened a tab. So by the time a number like that exists, hardly any organisation in it has run a process to decide whether its people will use AI. The people decided, and most of them didn’t mention it.
Which means that if your AI governance strategy is built around whether, it is governing a decision that was made without you, some time ago.
I understand the instinct to reach for restriction. It is usually the first thing on the table, and it has the shape of a decision: block the domains, publish the policy, name three approved tools, and put everyone through the training module. What it produces is fairly predictable. Your team uses AI on their phones instead, on the work they care most about, and you end up with no record of any of it. The exposure is still there, happening in places you can’t see.
The building I was standing in had gone the other way. Theo Farrell, La Trobe’s Vice-Chancellor, described an AI-first university from that same stage: 750 Copilot licences, secure enterprise ChatGPT access being widened from staff out to the broader community, profession-specific AI skills built into the curriculum rather than bolted onto it. Whatever you make of a university moving at that speed, notice what isn’t in the plan. Nobody is being asked for permission to use AI. The effort went into the environment they use it in.
The part no model builder can do for you
So here is what I think the two halves really are.
A model can be trained to refuse to help with something harmful. It cannot be trained to know your approval chain.
It doesn’t know that your Queensland pricing isn’t your Brisbane pricing. It doesn’t know that the same product page is legally reviewed in one market and not in another, or which of your people should be able to change a price, or that the agency contractor with a login this month should be nowhere near a live homepage. A model that has never seen your org chart, deciding what a contractor is allowed to publish.
None of that is knowable from the model side, and no amount of alignment work will make it knowable, because it is a fact about your business rather than a fact about AI.
Which is oddly good news, because it makes your half of this small and specific. Your half is an access and action problem, and those can be enumerated.
Four questions instead of a policy
Whatever your team is using this week, and whatever they move to next week, these are the four I’d want answered about anything AI touches. Ask them of any vendor, ours included.
- What can it read? Not “our data”. Which systems, which fields, which properties, and whether that changes depending on who is asking.
- What can it change? Reading is browsing. Changing is the part with consequences, and it should be a much shorter list than the reading one.
- Who signs before it lands, and does that differ by what is changing and where? The person who should approve a price change and the person who should approve a hero image are usually not the same person, and neither of them is the person who typed the prompt.
- What is in the log afterwards? The prompt, the plan, the person, the property, the time. “Who asked for this” is the first question anyone asks when something goes wrong, and that is a bad moment to find out it wasn’t recorded.
That is the order an action actually lives in: something is read, something is changed, someone signs, and a record survives. Notice that none of the four mention which model. Answer them properly and the choice of model stops being a governance decision at all, because the governance is sitting underneath the work, where a change of model can’t reach around it.
How we’re approaching it at Core dna
This is very much the shape we’re building to. We want teams to work with different models and LLMs and get the productivity that comes with them, rather than learning another AI interface we invented. ChatGPT, Claude, whichever one becomes part of someone’s day.
The platform underneath carries on governing what the AI can reach and what it is allowed to do. Before anything executes there is a plan for every property it will touch. Approvals are configured by role and by property group. If a run fails partway through it rolls back, rather than leaving half your properties changed and the other half waiting for someone to notice. And the prompt, the plan, the user, the property and the time all land in the log.
You could reasonably say that is just permissions, and that we’ve had permissions since the 90s. You’d be right, and it’s exactly why this is the interesting part. The permission layer most teams are running was built for one person clicking one thing at a time. Nobody ever asked it what to do when one sentence has to land in 60 places at once.
Where that leaves the chart
I don’t read that curve as a story about how good the models have got, and I don’t read it as a reason to be frightened. I read it as a deadline.
Adoption arrived at every organisation before governance did, ours included, and the gap between the two is where the exposure actually lives. The panel’s own answer to that was to start from the business problem rather than adopting the technology for its own sake, which I’d extend by one step: start from the business problem, and put the controls where the work happens rather than where the model does.
I don’t think we have the whole shape of this yet. But the enterprise question is not how we restrict AI. It’s whether the layer underneath the work is ready for people to use it properly.
Summarize with