Cortex Logo
Core

The better your brakes, the faster you can go… Right?

Tom Corkett5 min read

Organisations built better brakes so they could move faster with confidence. Now, the driving force of AI across the business has turbo-charged acceleration in new ways. Risk teams, and their traditional "brakes", have become overloaded and the business is not interested in slowing down. We need to update how we think about our control systems to recognise our vehicle is no longer the same.

Trundle Corp built reliable brakes for its heavy, regulated, load.

Every braking mechanism and control is layered on for sensible reasons. An incident that exposed a gap, an audit that found a deficiency and a well-intentioned governance committee that ensured comprehensive review. Trundle Corp confidently ensures good ideas always receive the necessary support – assuming they surface past the burden of red tape. The "Ministry of No" operates with impunity versus lost opportunity, whilst leadership think they are moving faster as their roadmaps successfully deliver yesterday's outcomes.

Brakes and bureaucracy are the friction to innovation.

“Better brakes let you go faster” does not hold true under disruption, where the drivers, the road and the vehicles of change are drastically different. Business cases before experiments, waterfall governance around uncertain work, death by committee and gated access to environments all restrain the value to be realised from AI. Corporate structures and governance built up over years now deserve the same scrutiny as the technology they oversee.

Innovation needs more than just a directive from leadership.

Organisations often respond to the pressure to innovate with training (sometimes literally called “innovation training”), give-your-use-case-catalogues and another call-to-arms message from leadership. Teams are told to experiment, but only after securing funding, architecture approval, security review, environment access and a sufficiently polished explanation of an idea they have not yet had the chance to test.

All of this also assumes people have the space to experiment at all. More often, this is relegated to “side of desk” work squeezed around the corporate demands and operational burden needed to keep the existing machine moving. Innovation needs leadership support, but it also needs the removal of the contradictions beneath it.

AI has massively lowered the barrier for building.

The distance between an idea and something tangible has become highly compressed. Solutions that previously needed specialist skillsets, a project plan and several weeks of effort can now be investigated by one person in an afternoon. When the cost of building an idea collapses, organisations should focus on enablement and curation of the people that deliver it.

The constraints need lifting, whilst retaining confidence.

The answer is not to dismantle governance and hope for the best. Give low-consequence ideas room to move, then increase scrutiny as access, investment, reach and consequence increase. Create bounded environments where experimentation is expected, make mistakes inexpensive, and codify the heavier governance machinery directly into the environments where these ideas can deliver genuine consequence.

Make the safe path the easy path.

Bounded experimentation only works if people actually do it. Give teams accessible environments, representative data and an obvious route from an idea to something the organisation can usefully consume. If the approved path is slower or harder than the workaround, people will find the workaround. Preserve the intellectual stimulus that produces good ideas whilst making it cheap to fail, easy to learn and natural for skills to compound along the way – far more powerfully than any training programme.

Safety and security deliver confidence.

Removing procedural friction only works if confidence comes from somewhere else. Organisations need to know where AI is operating, which identities it is using, what data and tools it can reach and what actions can leave the environment. Strong technical control is the pathway to eliminate bureaucratic control.

Embed permission into the environment.

Traditional governance expresses intent through policies, standards, reviews and people expected to interpret them correctly. AI brings the opportunity to push that intent directly into the environment itself. Give agents distinct identities, constrain the tools and data available to them, make dangerous combinations difficult and observe what actually happens rather than relying on what was approved to happen.

Autonomous systems need continuous control.

Most enterprise assurance happens point-in-time. An architecture review, a risk assessment, an annual recertification, a production release...

A self-driving vehicle does not receive approval for the journey and then stop observing the road. It continuously senses its environment, adjusts its behaviour and knows when conditions fall outside what it can safely handle. AI systems that act with increasing autonomy need the same shift from periodic assurance towards continuous observation, constraint and intervention.

Human-in-the-loop creates approval fatigue at machine speed.

The promise of a "human-in-the-loop" to deliver observation and intervention can easily become security theatre. Routine requests quickly become routine approvals. Our attention is increasingly challenged. If people lack the time, context or expertise to meaningfully evaluate each action, an approval button records participation rather than judgement. At agent speed, repeatedly asking for input becomes neither efficient automation nor particularly reliable control.

Human-on-the-loop instead elevates supervision to the boundaries.

Guardrails can apply agreed standards to routine actions without demanding human approval each time. People instead define the boundaries, test whether they remain appropriate and watch for changes in behaviour or consequence that suggest they are being approached. Human attention shifts from approving the flow to supervising the system around it, making the common actions cheap and consequential actions conspicuous.

Increase autonomy as confidence compounds.

Organisations do not need to choose between tightly supervised AI and full autonomy. Authority can expand progressively with more data, more tools, more freedom to act and fewer points of human intervention as evidence grows that each boundary works.

A research assistant, deployment agent and payment agent should not receive the same freedom simply because they use similar technology. Start with safe environments, clear boundaries and tight authority, then widen as visibility, controls and interventions are demonstrated to work.

Accelerate out of Trundle Corp's lane and reimagine your vehicle.

The frontier belongs to organisations prepared to redesign the vehicle rather than bolt AI into existing machinery. Confidence should increasingly come from the way the system operates, not from whether the risk questionnaire has ticked the right boxes.

Start by asking: Where are we still using approval and process because we have not built enough confidence into the system? Find one of those bottlenecks. Decide what visibility, boundaries and intervention would make the approval unnecessary, then prove it works.