ICYMI
The Org Chart You Didn’t Design – Conway’s Law has gone into reverse, as AI agents reshape organisations.
Executive Summary
Employees are adopting AI quickly, with or without permission, and building their own tools, workflows and software.
Each tool works for the person who built it. But they draw on different data and use different business rules, so they aren’t consistent or compatible.
The result is a new kind of legacy system that is hard to monitor, hard to connect with and hard to switch off.
The tools people build for themselves often fit the work better than those imposed from the centre. The preferred approach is to enable experimentation inside common guardrails and promote high-value tools into company-wide assets.
From the line’s opening in 1844 until 1854, passengers travelling between Bristol and Birmingham had to change trains at Gloucester. The Bristol and Gloucester Railway used Brunel’s 7 ft ¼ in broad gauge but the Birmingham and Gloucester used the 4 ft 8½ in gauge that became the national standard. Where the two met, passengers, luggage and freight had to be transferred between trains. Both railways worked, but they didn’t work together.
Companies are now creating similar compatibility problems for themselves. Employees are enthusiastically embracing AI to help them improve their personal productivity. The latest low-code agent builders and AI coding tools let non-technical employees create entire workflows and lightweight software. They can, for example, stand up agents or AI co-workers to triage emails, draft progress reports or reconcile spreadsheets. This ‘toolmaker’ activity can bring significant benefits. Who wouldn’t want their employees taking greater ownership and innovating solutions to front-line problems? The trouble comes when thousands of employees take up toolmaking, and every tool is different. Anyone can now lay a new railway, with its own gauge.
Workers are acutely aware of AI’s ability to improve how they work, with many paying for their own tools to circumvent corporate restrictions. Microsoft found that three in four knowledge workers use AI at work, and more than three quarters of them bring their own tools rather than wait to be given one. A University of Melbourne survey of more than 48,000 people found that almost half had used AI in ways that broke their employer’s rules. I’ve covered this in depth in AI in the Shadows
The tools are powerful. Across three large field trials, software developers using an AI assistant completed about 26 per cent more tasks, with larger gains among less-experienced developers. In a field experiment at Procter & Gamble, individuals using AI matched the average performance of two-person teams working without it. The tools work, so workers will keep building and using them.
The concern here is not occasional prompting, but reusable workflows that connect company data, encode business rules, or take actions. Evidence of this shift is beginning to appear. In an OpenAI case study, BBVA said its employees had created more than 20,000 custom GPTs, around 4,000 of which were used frequently.
Different Gauges
The catch is that each tool is built to meet the needs of one person. One analyst pulls data from a spreadsheet, another from a live system, a third from last month’s report. One person outsources output checking to an AI, while another checks every line by hand. One person builds in a control step, and one omits it. On its own, each choice is reasonable. Together, they mean that two people asked the same question can give two different answers, drawn from two different sources, checked in two different ways. The result is fragmented and diverging workflows that aren’t consistent and aren’t composable. A company is a set of synchronised workflows, not a pile of individuals doing separate tasks. When the joins between tasks are unreliable, so is the company’s output. Put another way, the company is rapidly accumulating a new kind of legacy system.
Fragmentation Creates Four Risks
When new processes and their supporting code and data are built ‘bottom up’, the resulting workflows carry four risks:
Opaque. It becomes hard to see how work is actually getting done. Pre-AI, standard operating procedures (SOPs), together with processes and controls embedded in IT systems, provided some assurance that work was done in line with strategic and operational goals and with appropriate controls. Now, the outputs may look fine, but it becomes impossible to understand the process that led to the output. That brings several risks. In June 2026, KPMG withdrew a published report after GPTZero found that only five of its 45 citations accurately matched real, uncorrupted sources. UBS, the NHS, Swiss Federal Railways and Transport for London said claims about them were untrue or misleading. If errors of this kind can pass a Big Four publication’s review, a manager glancing at a slide is unlikely to detect them. Reviewing the output is not the same as checking the work that produced it.
Inconsistent. As Toyota demonstrated, quality is a function of process. A 2026 preprint involving 128 knowledge workers at one multinational industrial company found that GenAI increased efficiency across three tested task types. Quality improved for knowledge packaging and knowledge creation, but declined for knowledge acquisition. The implication is not that AI invariably reduces quality, but that its effect depends on the task and on the process surrounding it. As employees customise those processes, operational variation may increase even if average model performance improves.
Unintegrated. Like the early railways, solutions built in isolation don’t join neatly with one another. Everyone may be using the same AI model while the data, definitions and controls underneath are inconsistent. This becomes problematic when attempting to build end-to-end workflows that cross multiple functions. For example, when a customer is onboarded, data needs to flow cleanly between sales, compliance and finance.
Brittle. User-built tools can depend on models and connectors outside the company’s control. Even where vendors publish deprecation schedules, unexpected shifts still occur. During OpenAI’s August 2025 GPT-5 rollout, older models were removed from ChatGPT without warning, disrupting model-specific workflows before some access was restored. In June 2026, Anthropic suspended Fable 5 globally for three weeks following a US government directive. A workflow can fail unexpectedly even when its own code has not changed.
Together, these are warning signs of an emerging legacy estate. A system becomes legacy when business dependence outlives the organisation’s ability to change, support or replace it. Ward Cunningham introduced the ‘technical debt’ metaphor in 1992 to describe how a quick technical shortcut creates a future liability. The United States federal government now spends more than $100 billion a year on IT and cyber investments, and agencies report that roughly 80 per cent goes to operating and maintaining existing systems.
None of this is an argument for stopping workers using AI to make their own tools. We are in the foothills of AI’s evolution, and clamping down now would kill experimentation and valuable learning. The toolmaking itself is not the problem. The problem is leaving it private and unconnected until one day it becomes critical infrastructure without anyone realising. So, the task is to capture the best tools and turn them into capabilities the whole company can rely on. Six moves can deliver that.
The Playbook
The controls should be proportional to risk. Personal experiments inside a protected sandbox can remain light touch. Any workflow that accesses sensitive data, takes an external action, feeds a material decision or serves multiple users should be given a higher risk classification and proper controls.
Lay the rails. Decide which standards are not up for negotiation and enforce them. Britain began standardising rail gauges by law in 1846. This prevented the problem from growing, but the installed base still took decades to convert. Common data definitions, approved sources and connectors, mandatory controls, and security protocols provide the rails for workflows.
Arm the workforce. The best way to stop people using risky, unapproved AI is to give them the tools they want. Samsung learned this the hard way in 2023, when engineers pasted sensitive source code into a public chatbot. BBVA went the other way and gave its people an enterprise tool; more than 100,000 employees were using it by June 2026.
Instrument and observe. Maintain a lightweight registry of reusable workflows. Record the business outcomes (e.g., efficiency uplift) but also drivers of risk such as permissions, dependencies and number of users. This reveals where both value and risk are accumulating.
Harvest and harden. When a tool demonstrates repeatable value and manageable risk, adopt it properly. Assign a product owner, validate its outputs, document its data and controls, test failure modes, provide a fallback and then release it more broadly. That captures the know-how and reduces dependence on the original builder.
Make it a team sport. Left alone, useful work often remains local and tacit. The alternative is to encourage shared innovation. One way to do that is to establish a guild where builders compare notes and raise the standard together. It also helps to recognise and reward the people whose tools get adopted broadly.
Retire and consolidate. Harvesting the best tools is only half the job. Tools that do not meet the bar for wider deployment need to be culled. Give tools a review or renewal date and retire those that are unused, unsupported, or unsuitable.
It took until 1892 to eliminate the Great Western Railway’s remaining broad-gauge network. Over one weekend that May, about 4,200 workers converted 171 miles of track to standard gauge. Brunel’s broad gauge offered smoother, faster journeys, but had not been widely adopted. In the agentic age, companies must harness what their people are building and turn it into something the whole company can use. The alternative is to allow a risky new type of legacy system to take hold.
Monday Morning Actions for Executives
Initiate an inventory. Launch a quick review of user-built tools.
Meet the demand. Provide workers with sanctioned AI tools to avoid Shadow AI.
Put someone in charge of the rails. Name an owner for standards and controls.
Pick a tool to harden. Select one high-value workflow and move it into production.
Set the tone. Communicate principles on worker-made tools. Reward the best makers.
Questions for the Board
If a regulator or an auditor asked how a key number or decision was produced, could we show them?
Which critical workflows depend on a particular model, vendor, connector or version, and what is the tested fallback?
Are we getting the right balance between rewarding individual innovation and building capability for the whole organisation?
Sources & Notes
Railway gauges and conversion: Network Rail, “Why the end of the gauge war didn’t standardise Britain’s railway” (20 May 2021); UK Parliament, “Railways—The Broad and Narrow Gauge” (Hansard, 16 June 1846); Friends of the National Railway Museum, “The end of the Great Western Railway’s broad gauge”.
Microsoft, “AI at Work Is Here. Now Comes the Hard Part” (2024 Work Trend Index Annual Report, 8 May 2024).
Nicole Gillespie et al., “Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025” (University of Melbourne and KPMG, 2025).
Kevin Z. Cui et al., “The Effects of Generative AI on High-Skilled Work: Evidence from Three Field Experiments with Software Developers” (working paper, 2025).
Fabrizio Dell’Acqua et al., “The Cybernetic Teammate: A Field Experiment on Generative AI Reshaping Teamwork and Expertise” (NBER Working Paper 33641, 2025).
GPTZero, “Chasing the Hallucinations: KPMG’s AI-Powered Attempt at ‘Redefining Excellence’” (June 2026); Financial Times, “KPMG report contained AI hallucinations on benefits of AI” (12 June 2026).
Toyota Motor Corporation, “Toyota Production System”; Sven Bottesch et al., “Faster, Higher, Stronger? The Impact of GenAI on Knowledge Work Productivity—Evidence from the Field” (arXiv preprint, 28 July 2026).
OpenAI, “Introducing GPT-5” (7 August 2025); Ars Technica, “OpenAI brings back GPT-4o after user revolt” (13 August 2025); OpenAI, “API deprecations”.
Anthropic, “Model deprecations”; “Statement on the US government directive to suspend access to Fable 5 and Mythos 5” (12 June 2026); “Redeploying Fable 5” (30 June 2026).
Ward Cunningham, “The WyCash Portfolio Management System” (OOPSLA ’92 Experience Report, 1992).
U.S. Government Accountability Office, “Information Technology: Agencies Need to Plan for Modernizing Critical Decades-Old Legacy Systems” (GAO-25-107795, 17 July 2025).
TechCrunch, “Samsung bans use of generative AI tools like ChatGPT after April internal data leak” (2 May 2023).
OpenAI, “How BBVA is scaling AI from pilot to practice across the org” (6 November 2025); “BBVA puts AI at the core of banking with OpenAI” (11 June 2026). Company- and vendor-reported evidence.

