The Arrival of the AI Operating Model

When I talk with CIOs these days, a subject that was mostly absent from serious enterprise discussions even a year or two ago is suddenly top of mind: What is our new operating model for AI?

It’s a revealing shift. For the first few years of generative AI, most organizations were understandably preoccupied with basic LLM access, pilots, use cases, governance, data protection, productivity, and just determining whether the technology was useful enough to warrant widespread deployment. Those questions have not entirely disappeared. But a much larger one is beginning to subsume them. AI is becoming sufficiently capable, economical, persistent, and autonomous that enterprises now have to decide how they will actually operate when machine intelligence becomes a load-bearing component of the business.

The timing is unusually fraught. The opportunity offered by AI presents itself at truly extraordinary speed, faster than enterprises have ever had to face, excepting perhaps 1H 2020. Yet so are the consequences of getting it wrong. Organizations face the most momentous window for intelligent automation since the arrival of computing itself, accompanied by the tantalizing ability to pursue entirely new categories of products, services, markets, and business models. At the same time, IT organizations face growing risks from unreliable autonomy, organizational dependency, loss of human capability, cyber exposure, regulatory intervention, vendor concentration, geopolitical fragmentation, and increasingly explicit warnings from the frontier AI laboratories themselves about the potential adverse behavior of much more advanced systems.

This is not a normal technology cycle.

Infographic titled 'The Arrival of the AI Operating Model' illustrating the economic impact and governance challenges of AI technologies. Left section highlights statistics on AI adoption, comparing performance between AI and human agents, with data on task success rates and cost reduction over time. Right section discusses the importance of operational models, governance maturity, and various risks associated with AI integration, including reliability issues and cognitive concentration risks.

The stakes are higher because both sides of the equation are becoming consequential at the same time. This means moving too quickly can create operational and even strategic dependencies on technology whose behavior cannot always be anticipated. Moving too slowly can (and will) leave an incumbent competing against a rapidly growing population of AI-native organizations with radically different cost structures, product development speeds, and capacity for experimentation.

The enterprise therefore needs something more substantial than an AI strategy or governance framework. It needs an AI operating model: The organizational and technical system through which it continuously determines what intelligence to use, where to use it, how much autonomy to grant it, how to verify its output, what risks to accept, how to preserve resilience, and how aggressively to exploit capabilities appearing at the frontier.

For many organizations, building that operating model is becoming urgent because AI itself is crossing a maturity threshold.

AI Is Becoming Load-Bearing

There is now a preponderance of evidence that frontier AI has moved well beyond the stage where it is useful primarily as an assistant. On a growing range of knowledge-work tasks, contemporary models are approaching or exceeding competent human performance, while agentic systems are increasingly able to carry work through applications and tools to an actual, reliable, usable outcome.

Stanford’s 2026 AI Index shows us just how quickly this has happened. On WebArena, which tests agents on 812 realistic, multi-step web tasks, success rates have risen from approximately 15% in 2023 to 74.3% in early 2026. This is only four percentage points below the measured human baseline of 78.2%. On OSWorld, which requires agents to operate real computer environments across applications and operating systems, the leading result reached 66.3% against a human baseline of 72.35%. SWE-bench Verified, a demanding benchmark based on real software-engineering issues, went from roughly 60% performance to near saturation in a single year.

This does not mean AI is universally reliable. Far from it. The same Stanford report illustrates what researchers call the jagged frontier: Systems capable of winning gold-medal-level mathematics competitions can still worryingly struggle with apparently elementary tasks. The leading evaluated system could correctly read an analog clock only 50.1% of the time. On Humanity’s Last Exam, performance jumped roughly 30 percentage points in a year, yet high-confidence errors remain common.

The resulting enterprise reality is important to state precisely: AI can now be better than humans at many bounded tasks while remaining unexpectedly unreliable at adjacent ones. It can be enormously capable without yet being conventionally dependable.

Yet the maturity trajectory is unmistakable. Anthropic reports that by May 2026 more than 80% of the code merged into its own codebase was authored by Claude, compared with low single digits before Claude Code entered research preview in February 2025. Its engineers were merging roughly eight times as much code per day as in 2024. More strikingly, Claude’s measured success rate on Anthropic’s most open-ended internal engineering tasks reached 76% in May 2026, a gain of roughly 50 percentage points in six months. Anthropic gives an example in which Claude diagnosed and fixed a live infrastructure problem in about two hours that would ordinarily have taken a human engineer two or three days.

For most enterprises, the implication is no longer difficult to see. Simply put, AI is becoming good enough to carry a meaningful share of important operational knowledge work.

Not all work. Not without controls. And certainly not with equivalent reliability everywhere. But sufficiently much of it that CIOs now have to design organizations on the assumption that AI will increasingly become part of the production machinery of the enterprise rather than merely a productivity tool sitting alongside it.

This is the arrival of load-bearing AI.

The Economics Make Adoption Difficult to Resist

Capability is only half of the force pushing enterprises across this threshold. The economics of machine intelligence are improving just as quickly.

The most useful metric is increasingly not price per token, but cost per successfully completed unit of work. Raw token prices obscure the extraordinary changes occurring beneath them. Models become more efficient. Smaller models inherit capabilities that previously required cutting-edge frontier systems. Reasoning techniques improve. Inference optimization, caching, quantization, specialization, and improved hardware reduce costs. Increasingly capable routing systems can select the least expensive model able to perform each task to the required standard.

The practical result is that intelligence itself has become a serious arbitrage opportunity. A routine extraction task might go to an extremely small model. A difficult analysis might go to a stronger reasoning system. A high-consequence decision might ultimately invoke several independent models, followed by deterministic verification and human review. It’s dynamic digital labor in a way that’s never been possible before. Organization’s can continuously match the cost and capability of intelligence to the economic value and risk of the work being performed.

That is a profound step change in enterprise economics. If useful cognition continues to become cheaper while its quality rises, activities that previously required too much human analysis, customization, research, coordination, or judgment can suddenly become economically viable. Enterprises will not merely automate existing work. They will begin creating work, services, and products that were previously too cognition-intensive to contemplate.

This leads directly to what may be the most important innovation discipline of the AI era.

From Moonshots to Starshots

The digital era taught large organizations to pursue moonshots: Occasional, high-ambition initiatives intended to create major new products, capabilities, or markets. They were appropriately uncommon because large-scale digital innovation was expensive, slow, organizationally demanding, and frequently dependent on substantial custom technology development.

AI easily remakes those economics sufficiently enough that the model itself needs to change.

I call the emerging equivalent a starshot: A high-ambition attempt to create fundamentally new business value specifically by exploiting capabilities near the frontier of artificial intelligence. Starshots are not simply larger AI projects. They ask what becomes possible when very large quantities of reasoning, research, software production, simulation, personalization, analysis, design, experimentation, and increasingly autonomous execution become inexpensive enough to embed into ordinary products and operations.

A service can place what once would have been thousands of hours of expert analysis behind every customer interaction. Software can increasingly be created or extensively modified on demand. Products can become individually generated. Scientific and engineering discovery loops can accelerate dramatically. Previously uneconomic micro-markets can become viable. Persistent agents can fundamentally redesign customer relationships. Entire operational functions can be reconceived around abundant machine cognition rather than scarce human attention.

This is where the competitive stakes become especially high. Established enterprises are not merely competing with one another. They increasingly face thousands of small AI-native disruptors able to make inexpensive attempts against assumptions that incumbents have treated as fixed for decades.

These challengers do not need to succeed every time. They just need one breakthrough.

Consequently, the AI-era enterprise cannot treat a moonshot-scale innovation exercise every year or two as sufficient. It needs a standing starshot capability capable of making faster and more frequent attempts, accepting intelligent failure, discovering nonlinear opportunities, and scaling the few that work. A portfolio might contain many modest experiments, several serious frontier explorations, and a small number of genuinely radical attempts to overturn some part of the organization’s own business model before an outsider does.

This requires operating deliberately close to the frontier. That is inherently uncomfortable for large enterprises because frontier technology is exactly where capability is highest and certainty is lowest.

Yet avoiding the frontier carries its own real risks that CIOs must ensure are managed closely and sustainably.

The AI operating model must therefore support both exploitation and controlled exploration. It has to make ordinary AI safe enough to become core operational infrastructure while simultaneously giving the organization a governed mechanism for flying considerably closer to the edge when the potential return justifies it.

The Door to an AI-Fluent Enterprise

Technology alone is insufficient to accomplish this. Before an organization can sustainably become highly automated, agentic, or AI-native, it has to pass through another threshold: It must become AI-fluent.

AI fluency is considerably more demanding than providing employees with basic training. It means building sufficient practical understanding throughout the organization that people can make competent decisions every day about what machines should do, what humans should retain, how the two should collaborate, where AI is trustworthy, when it should be challenged, and when a previously sensible arrangement must be redesigned.

This affects virtually every part of the enterprise. Business leaders need to distinguish incremental productivity opportunities from genuine changes in business economics. Managers must learn to redesign work around combinations of people and increasingly autonomous systems. Technology organizations must continuously evaluate a rapidly changing model landscape. Risk, cybersecurity, finance, HR, legal, architecture, procurement, and compliance must participate in decisions that increasingly combine technology, labor, capital allocation, and corporate authority.

More challenging still, organizations may have to undergo this cultural transition several times.

I argued a number of years ago that AI would not merely change tasks but alter organizational roles themselves, producing successive stages in which responsibilities shift from execution toward managing, interpreting, and innovating with AI. I also observed that transformation at this scale would require moving beyond a traditional centralized Center of Excellence toward a Network of Excellence: A distributed structure that connects central expertise with practitioners, champions, managers, and local leaders across the enterprise.

That concept is becoming considerably more important now. A central AI organization can establish platforms, policies, architecture, governance, standards, and expertise, but it cannot possibly absorb and direct every change required when AI begins affecting most functions and potentially most workers. The organization needs a network capable of propagating new practices, identifying failures, gathering lessons from the edge, educating employees, spreading successful patterns, and repeatedly helping local teams reorganize work as the capabilities change.

The Network of Excellence becomes the human adaptation layer of the AI operating model.

This is the door organizations must pass through. On one side are companies using AI tools. On the other are organizations capable of repeatedly reorganizing themselves around changing machine intelligence.

Those unable to cross it risk becoming marginal organizations even if they make substantial investments in AI. They may own the tools without developing the adaptive capacity required to exploit them.

The Central Tension: Bounded Acceleration

This brings the opportunity and danger together. The AI operating model has two mandates that are simultaneously essential and increasingly difficult to reconcile.

It must help the enterprise consume rapidly improving intelligence as aggressively as competitive conditions demand, including creating a repeatable starshot discipline that intentionally explores capabilities near the frontier. At the same time, it must prevent the enterprise from accumulating unacceptable operational, human, security, financial, regulatory, supplier, and systemic risks as that intelligence becomes embedded more deeply into the organization.

An operating model optimized primarily for control will probably move too slowly, and worse, it’s likely to fail. One optimized primarily for acceleration may eventually create an enterprise whose operations exceed management’s ability to understand or reliably govern them.

The objective is therefore bounded acceleration: Move as quickly as capability, economics, reversibility, observability, and verification permit, while tightening controls as autonomy, consequence, connectedness, and uncertainty increase.

This becomes especially important as AI shifts from advising people to acting for them. An incorrect answer from a chatbot is generally an information-quality problem. An incorrect decision by an agent possessing credentials, financial authority, communications access, corporate data, and permission to invoke other systems is an operational event. Once agents begin interacting with other agents, the relevant object of governance becomes even larger: Models, prompts, memory, enterprise data, tools, permissions, external services, humans, and automated feedback loops form a single socio-technical system.

The enterprise cannot make probabilistic intelligence deterministic. It can, however, surround probabilistic intelligence with deterministic controls wherever possible.

That means authoritative retrieval, independent verification, deterministic validation, policy constraints, permission boundaries, action limits, anomaly detection, observability, human escalation, rollback, audit trails, and kill mechanisms. At higher levels of consequence, several of these mechanisms should operate simultaneously.

This is not mere governance added after automation. It is what allows consequential automation to occur at all.

The Downside Is Becoming Material

Reliability is the most obvious risk, but it is far from the only one. The jagged capability frontier means that even extremely sophisticated systems can fail unpredictably, and increasing capability does not necessarily eliminate this problem. More capable models will simply be entrusted with harder work, perpetually moving the enterprise back toward the edge of what machines can reliably accomplish.

Autonomy quickly magnifies the consequences of those errors because failure moves from generating incorrect information to taking incorrect action. Cybersecurity risk rises as agents receive credentials, APIs, data access, tools, and the ability to communicate externally. A compromised or misdirected machine worker potentially operates at machine speed and scale.

There is also an underappreciated human risk. Successful automation can progressively remove not merely jobs but organizational knowledge. Manual procedures disappear. People who understood why processes worked leave. Entry-level roles through which future experts acquired experience can vanish. Human situational awareness declines as machines perform more of the intermediate work.

The result can be an extraordinarily efficient organization that is surprisingly unable to function without its AI.

I believe enterprises should begin treating this explicitly as cognitive concentration risk. We already manage concentration risk in cloud infrastructure, telecommunications, financial services, semiconductor supply chains, and critical vendors. Increasingly, we will have to manage dependence on externally supplied cognition in much the same way.

Provider concentration compounds the problem. A relatively small group of companies produces much of the world’s frontier intelligence, while the physical infrastructure beneath it has its own geographic and supplier concentrations. Stanford notes that nearly all leading-edge AI chips still depend upon a single Taiwanese foundry, illustrating how seemingly abstract machine intelligence ultimately depends on very tangible industrial infrastructure.

A major model can therefore become unavailable or unsuitable for reasons having little to do with enterprise architecture: Provider distress, pricing changes, model retirement, compute shortages, cyber incidents, geopolitical intervention, regulatory decisions, litigation, safety restrictions, or infrastructure failures. Once AI becomes load-bearing, these become business-continuity scenarios.

There is also the problem of governance lag. Technical capability is changing faster than organizational controls, management practices, workforce skills, laws, and social expectations can comfortably absorb. That gap will generate recurring friction. Regulatory environments will differ across jurisdictions. Certain models, data uses, autonomous actions, or decisions may be permissible in one country but prohibited in another. Enterprise AI routing consequently becomes not merely an economic mechanism but potentially an increasingly important compliance mechanism.

Perhaps most difficult is the possibility of organizational exhaustion. Enterprises are accustomed to large transformation programs separated by periods of relative stability. AI may instead require significant changes in roles, processes, controls, incentives, skills, and operating structures repeatedly over a relatively short period. Without distributed change capacity, enterprises may simply lose the ability to assimilate what technology makes possible.

And then there is the frontier itself.

The Coming AI Event Horizon

The leading AI laboratories are now discussing risks that would have seemed extraordinary in an enterprise technology article only a few years ago. Anthropic, OpenAI, and Google DeepMind all explicitly examine scenarios involving advanced autonomy, loss of control, autonomous AI research, or systems materially accelerating the development of more capable AI.

Anthropic’s internal experience is particularly instructive. More than 80% of the code it merged by May 2026 was AI-authored, while the typical engineer was merging roughly eight times as much code per day as in 2024. Anthropic emphasizes that this is not yet recursive self-improvement and that such an outcome is not inevitable. But it also states plainly that extending the trend could eventually produce an AI capable of autonomously designing and developing its successor.

That possibility changes long-range planning because the variables begin to interact. Better AI can improve AI research. Improved research creates better AI, which can then contribute still more effectively to subsequent research. Compute, energy, semiconductor fabrication, physical experimentation, capital, and other real-world constraints may keep this feedback loop bounded. We simply do not yet know.

For CIOs, however, the practical concept matters even before anything resembling runaway recursive improvement occurs.

There is an AI event horizon when the rate at which useful machine intelligence changes becomes faster than the organization’s ability to understand, govern, and adapt to it.

An enterprise does not need to encounter superintelligence to cross this threshold. If relevant capabilities double or transform faster than architecture cycles, procurement processes, workforce adaptation, regulation, and management practices can respond, conventional three- or five-year AI roadmaps become increasingly speculative.

This is another reason the operating model itself must be dynamic.

Four Hard Choices

The job of the AI operating model is ultimately to help leadership navigate four increasingly stark tradeoffs rather than pretending that they can be eliminated.

The first is Transformation or Marginalization. Enterprises can use AI principally to make the existing organization faster and cheaper, or they can continually use frontier capability to challenge their own products, services, processes, and economics. Productivity matters enormously, but organizations that never build a serious starshot capability increasingly risk being attacked by companies that have. This is not a call for indiscriminate disruption. It is recognition that the cost and speed of attempted disruption are falling sharply, which means incumbents must increase their own rate of meaningful experimentation.

The second is Delegation or Sovereignty. Organizations can give machines progressively more responsibility for execution and decision-making, capturing enormous economic benefit, or maintain meaningful human authority over consequential activities. Too little delegation eventually leaves much of AI’s value unrealized. Too much creates a business whose executives remain accountable for systems they no longer genuinely understand or control. The objective should be maximum economically useful autonomy consistent with verified control.

The third is Dependence or Optionality. Tight integration with a small number of leading AI providers may offer excellent capability, economics, and simplicity. Preserving multiple providers, model portability, open systems, fallback procedures, and human expertise adds cost and complexity. But once intelligence becomes operational infrastructure, optionality becomes a form of resilience. The inefficiency looks unnecessary until the primary system is unavailable.

The fourth is Acceleration or Survival. There will be moments when a new capability justifies moving surprisingly quickly and occasions when an organization should deliberately stop. A security incident, reliability regression, regulatory action, geopolitical event, provider failure, or unexpected autonomous behavior could require an immediate reduction in AI authority. A mature enterprise needs the operational ability to accelerate toward opportunity and decelerate away from danger without rebuilding its entire architecture each time.

In other words, the enterprise needs both an accelerator and a brake, and increasingly sophisticated judgment about when to use each.

The Architecture of the AI Operating Model

The resulting operating model is not another governance committee. It is a persistent enterprise capability for controlling and exploiting machine intelligence.

At its core is an intelligence control plane. Significant AI workloads need an explicit business purpose, approved model set, required capability level, acceptable cost, data-access envelope, tool permissions, autonomy ceiling, verification requirements, human escalation path, fallback model, and continuity plan. These parameters should increasingly be adjustable as models, economics, regulations, and risk conditions change.

An assurance layer surrounds consequential AI with independent verification, deterministic validation, authoritative data, monitoring, constraints, action controls, and escalation. A resilience layer ensures that critical functions can degrade gracefully if a model or provider disappears and that enough human knowledge survives to maintain organizational sovereignty.

The Network of Excellence provides the human adaptation layer, distributing learning and organizational change at a speed no centralized AI group can achieve on its own. The FinOps and routing layer continuously arbitrages between models and methods to obtain the least expensive intelligence that can produce the required verified result.

And the operating model needs one more first-class function: A starshot portfolio.

Infographic titled 'The Arrival of the AI Operating Model', depicting a dynamic enterprise system for AI with a focus on governance, risk, and autonomy.

This should not sit on the periphery of the AI program. It should be an explicit mechanism through which the enterprise continuously tests whether new frontier capability has invalidated an existing constraint, opened a new market, enabled a new product, or made an apparently impossible operating model economically feasible.

Governance and starshots belong inside the same system precisely because the organization must take more risk in some places in order to remain conservative in others. A sandboxed starshot with carefully bounded data, capital, authority, customers, and blast radius can explore the frontier aggressively without granting experimental technology equivalent authority over core production operations.

This is how a large enterprise can learn to fly close to the edge without betting the company every time.

A Different Operating Cadence

Traditional enterprise technology was built around periods of stability. Select a platform, implement it, standardize it, optimize it, operate it for several years, and eventually replace it.

AI is increasingly incompatible with that cadence. The emerging loop is continuous: Sense new capabilities, evaluate them, experiment, route work to appropriate intelligence, execute, verify, observe results, adjust authority, distribute learning, retire obsolete assumptions, and repeat.

The starshot portfolio runs beside this cycle asking one especially important question:

What has become possible now that was impossible six months ago?

That deserves to become a standing executive question because annual strategy cycles will increasingly miss meaningful portions of the frontier.

The human organization must operate at a similar rhythm. People learn new capabilities, redesign work, discover local practices, share them through the network, adapt roles and controls, and then prepare to do it again. AI fluency is therefore not an educational endpoint. It is the institutional ability to keep learning as the underlying intelligence changes.

There May Be No Final AI Transformation

One of the hardest ideas for enterprises to absorb may be that there is no stable future state waiting at the end of an AI transformation program.

Transformation is traditionally imagined as a bridge between current and future operations. AI increasingly resembles a changing environment instead. Organizations may have to substantially redesign how work is allocated among people and machines several times as models become more capable, persistent, inexpensive, autonomous, and connected.

This is why all of these threads belong in one operating model. AI fluency allows the enterprise to understand what is changing. A Network of Excellence allows it to adapt at organizational scale. Dynamic routing allows it to exploit changing capability and economics. Assurance makes increasingly consequential probabilistic systems usable. Resilience prevents successful automation from becoming dangerous dependence. Starshots ensure that safety and scale do not turn into strategic timidity. Frontier governance determines how much authority the organization is prepared to grant as the technology approaches increasingly uncertain territory.

Together they create something more important than an AI platform. They create organizational adaptive capacity.

The Path Forward

I remain optimistic about our ability to build this. Human beings have repeatedly created institutions capable of operating technologies and systems vastly more complex than any individual can understand. Aviation, electrical grids, global financial systems, telecommunications, supply chains, hyperscale computing, and the Internet became dependable not because uncertainty disappeared, but because we surrounded them with professional disciplines, redundancy, monitoring, controls, standards, training, and cultures capable of managing their risks.

AI can be treated with the same seriousness. The difference is that we may have to build those mechanisms while the underlying technology continues changing at exceptional speed.

The enterprises that succeed will therefore not necessarily be those with today’s best model, the largest AI budget, or the highest percentage of automated tasks. They will be organizations that can repeatedly absorb new intelligence without surrendering judgment; automate aggressively without becoming brittle; preserve human and architectural optionality; distribute AI fluency throughout the enterprise; recognize when risk requires a brake; and continuously make enough ambitious starshot attempts to discover what the new frontier makes possible before competitors do.

That is a demanding operating model, and the stakes are higher than in most previous technology transitions. An enterprise can now plausibly move too quickly and create profound new vulnerabilities. It can also move too slowly and find that its economics, products, or even its reason for existing have been overtaken by organizations built around a fundamentally different abundance of intelligence.

The goal is therefore neither unrestrained acceleration nor defensive caution. It is to create an enterprise capable of repeatedly approaching the frontier, extracting disproportionate value from it, and returning safely enough to do it again.

Many organizations will make it through this door. Some will become radically more capable than they are today, combining human judgment with machine intelligence at a scale that was previously impossible. They will automate much of the ordinary work of the enterprise while redirecting considerably more human energy toward invention, relationships, judgment, leadership, and ambitious new outcomes.

But some organizations will not make the transition. They will adopt AI without becoming AI-fluent, automate without building resilience, govern without innovating, experiment without scaling, or protect today’s business so thoroughly that they leave tomorrow’s business to somebody else.

For CIOs, this is why the AI operating model has moved so quickly to the center of the agenda.

The downside of moving too quickly is increasingly real, yet the downside of moving too slowly may ultimately be larger. The task now is to build an organization capable of knowing the difference—and changing its answer continuously as the frontier continues to move swiftly.

Sunday Musings: Google’s Identity Struggles, Plus Social Media Bans Around the World

The Web’s missing features for built-in user identity have become a real headache for the industry, and for its users too. It certainly took its toll on market leader Google this week as its “Identity Theater” continued (Source: Kevin Marks.) The issue? It’s turning out that making every single user comply with the Common Names policy isn’t workable for a variety of reasons. Reports of Google deleting accounts en masse are driving a lot of the discussion. Robert Scoble has his own recommendations for Google and while they’re probably the least that would be acceptable to the majority of people, it doesn’t go far enough I think.

It certainly doesn’t have to be this way. Twitter allows companies, bots, and just about every other type of social account and it works quite well in the end. Twitter ran into a similar identity issue in a big way a couple of years back after facing lawsuits and widespread complaints. They managed to muddle through with Verified Accounts.

A growing consensus is that Google should allow user-defined accounts as well, with verified identity for those that want or need it. Personally, I’m not sure I see Google coming around with a response fast enough to prevent some damage to services and impacting Google Plus‘s runaway adoption. But in my analysis, it’s most likely to only hurt the commercialization of the service, not regular usage for most for now.

Social Identity Ownership - Google or Facebook?

Worse, the problem may actually be core to the way Google’s stack is conceived and architected. It may not be easy for them to change course in the short-term without ripples through the way global Google’s services fundamentally operate from a security and identity perspective. It also may not be good for their business model which is almost certainly based on the fact they know who people really are. This issue is one to watch given Google’s pervasiveness. It also has some significant implications for business users of its products, especially now that they seem to be gaining some much needed traction in the social networking wars.

For now, I’d recommend that businesses use Google Plus with an eye towards experimentation while the Web giant gets its philosophy and policies around identity sorted out. Frankly, the bigger industry issue is social Web identity itself. Users and companies increasingly depend on commercial providers like Facebook, Twitter, and Google to provide everything identity-related, from login access to storage and maintenance of their social graph. This is causing key elements of power and control to start to swing away from the open standards that made the Web so successful and essentially fair.

Will the W3C step in and resolve what’s appearing to be an increasingly glaring absence in the Web stack? So far it seems unlikely given the failure of many years of open standard Web identity efforts. The culprit? You have only to look in the mirror. Apathy by users and lack of consensus on the part of Web developers. There’s also a lot at stake financially for those that end up owning a big chunk of Web identity. Consequently, online — and especially social — identity is likely to grow into a full blown brouhaha in the next couple of years as issues, missteps, and abuses inevitably surface. However, we could also decide to put our own house in order before governments step in, the least desirable of all outcomes in most imaginable scenarios. The worst probably being governments owning, issuing, and centrally managing verified Web identity credentials for everyone.

Which brings us to the next subject…

Government Bans Chipping Away At Social Media Freedoms?

A couple of interesting things happened this week with governments aiming their considerable might at social media. While knee-jerk responses to this space were common enough a few years ago, with the U.S. Marines banning social media access for a while for example, these are now generally understood to be counterproductive and unworkable for a long list of reasons.

However, that didn’t stop the German government from banning the Facebook ‘Like’ button on Friday, sure to ignite a small firestorm in that country given that it seems to apply to any site accessible from inside its borders and the fine is a stiff €50,000. The Like button, used on millions of sites around the world to enlist users to leverage their Facebook social network to share content from 3rd party sites (see: k-factor), is significant enough on its own to put German Web businesses at some competitive disadvantage on the global stage. The concern is over privacy and that “all the information was sent to the US company even if someone was not a Facebook member.

In another similar situation, the Missouri state government’s new law preventing teachers from using social media to communicate privately with students, the former who just announced that they are fighting back, is another case in point. There are obvious free speech issues with the law despite the good intent on its face to protect students. The real issue is that the law is that violations are almost impossible to detect and enforce, until its too late, and that it ensures teachers, one of the most collaborative and interaction driven professions with far reaching impact, can’t have much of a social media presence of any kind until the implications are sorted out. It also presumably doesn’t prevent teachers from privately communicating with their students in any number of other digital channels. All of this means the law won’t accomplish a whole lot other than sowing confusion and promoting the use of increasingly obsolete methods in an increasingly fast-changing economic and societal landscape.

The real issue with both of these laws is that they are 1) essentially short-sighted, 2) exhibit such poor understanding of social media as to be essentially useless, and 3) are therefore unlikely to be meaningfully carried out. Worse, they chip away at the edges by introducing step-by-step, largely ineffective government oversight and control over social media, one of the largest economic, cultural, and societal changes of our time. This will become an even hotter topic as the Middle East’s social media coordinated model for uprising spills out of the developing world. In fact, this has already happened in Britain and there are already cries to ban social media in cases of civil unrest.

I should be careful to note here: I’m not by and large suggesting there’s any overarching government scheme to interfere with and control social media. Instead, I’m suggesting we keep a close eye on these developments as social media legislation increasingly (and inevitably) accumulates in bits and pieces on the base of knee-jerk responses to individual situations. This will have a great many unintended and unwanted consequences. The continued growth of laws and regulations in a vital new industry that thrives on inherent openness and trust has the potential to limit it so profoundly that we could lose much of the great promise that social media can provide.

While we must find ways that work to protect our citizens, we must also provide them access to one of the most open, free, and powerful means of interacting that has been invented. Let’s push back on unreasonable measures while also proactively being responsible for solving them. It’s up to us to start finding globally acceptable solutions to privacy, security, and misuse in social media and getting them into the hands of those who don’t understand this space well enough yet to govern it. The options for making this happen are something I’ll explore as soon as I can.

Connecting Agile Business with Social Business

When Jim Highsmith graciously invited me to give the opening keynote at the inaugural Agile Executive Forum in Salt Lake City this week, I had to really sit down and think about what I’ve been working on the last few years, namely social business, as compared the conference theme, agility and business. While agile methods have had many separate and distinct threads within the business and technical worlds over the last 20 years, one of the most active areas has been in software development. For its part, social business is a much newer phenomenon that’s become a top priority for many business leaders in the last couple of years. So, while I’ll cover the details of my presentation — in which I connected agility and social business as drivers of innovation, in another post — I will attempt to more formally to capture the specific similarities here.

In recent years, as agile development has been increasingly borne out as a fundamentally better, more efficient, lower risk, and more cost effective way of doing things, there has been significant and growing effort apply agile lessons to business in general. And, as it turns out, agility and social business, as two major new ways of connecting and organizing people in directed activity, have plenty in common. Perhaps even more importantly, they have key things to learn from each other.

I’ve had quite bit of experience with agile methods personally, having led extreme programming project teams and been closely involved in large, distributed SCRUM projects in years past. I’ve seen agile methods work significantly better than classical processes. This is probably why it’s now the most common development process in software that developers identify with in my experience. Consequently, I’m in a position to see some of the connections between business agility and social business, in all their many flavors. The connection isn’t trivial either. There are hard won lessons learned from agility that social business initiatives could certainly benefit from. Just as there are innovative new approaches to scale, transparency, process, and tooling that social business brings to the table, as extreme and radical as they may appear to agile folks, who are more used to being the harbingers of change.

Comparing Agile Business and Social Business

What’s the point of connecting these two approaches? Because they can learn a great deal from each other. Agile methods can be updated and modernized from what social business brings to the table, and social business can apply some maturity and rigor to what it does, as appropriate. This I believe is a fruitful exercise for both disciplines and is one I summarize below.

Agile Business and Social Business: Side-by-Side

Keeping in mind that some agile process purists are still on the fence about applying the methods more broadly, the focus here is on agile processes of any kind as applied to general people-based business activities. Some processes are more amenable to agility, just as some are more amenable to social business. In general, however, the less collaborative, more rigid, and user-isolated a business activity is, the less applicable either agile or social media methods will be to it. However, if you have a complex, open-ended, and outcome-oriented business process involving many people, especially including those that it most directly affected (typically, the customer, internal or external), then both approaches represent the very best ways that we know of today to deliver successfully on them.

As you’ll see, agility and social have much more in common than they have differences. Here’s my take on how they break down:

  • Coordination Instead of Control. Both agility and social eschew using centralized hierarchies to achieve control. Instead, as Brad Appleton has long recommended, they both work best with autonomous, adaptive, and accountable actors. The first two are something that applies very much to social business, while the latter is something inherent in any social environment that has a strong identity system (which, unfortunately, not all do.) The lesson here is that emergence (an important and prized aspect of Enterprise 2.0) and self-organization are very similar and are shared as core values in both disciplines.
  • Designing for Change/Loss of Control. This is something in which agile is inherently stronger than nascent social business methods, which are just wrapping their heads around this. Not killing emergence requires the acceptance that external change is a desired constant and should be responded to productively to get the right results with the resources at hand. Ignoring that requirements aren’t what the customers need, that the planned outcome of a business process won’t be very useful, and other denying of reality is anathema to both disciplines, but is more formal and well-defined in agile methods. Social business does recognize that the majority of productive output is on the edge of the network and largely outside of formal control, but other than measuring community sentiment, that’s often as far as it goes in terms of responding to new ground truths. The best results in both approaches are when there are tight feedback loops to all stakeholders and that a planned response to that feedback is the central factor in re-engagement with the project or online community in the next cycle. For additional insight, read Tim Leberecht’s great overview of this issue, titled Openness or How Do You Design For the Loss Of Control.
  • Frequent Work Cycles. Agilists call work cycles iterations. Social business doesn’t have as strong a notion of discrete work cycles because it’s essentially continuous and itself emergent, a more extreme version of agile when you look at collaborative work in social media environments such as crowdsourcing efforts or Social CRM. In either case, the project and/or community must assess and respond to change at the end of each iteration, or do it continuously which is more common in the case of social business processes.
  • Open Contribution. Social business works best when the broadest possible invitation is made for stakeholders to get involved and contribute. Agile processes tend to define valid contributors to a smaller audience, though it’s entirely up to the project and varies widely. Social business realizes that the “anyone can contribute” default stance is one of the most powerful concepts in recent business history (as only those that care about the outcome will get involved, yet that’s almost always many more people than you thought.) Agile methods could learn from the extreme openness and fewer contribution boundaries and barriers in social media. I made the point in my speech that open source software has proven this in the real-world better than any a priori speculation about what works best ever could.
  • Working Results. It’s long been the mantra that agile processes value working software as soon and often as possible at any given time in the project. When the requirements are right and/or the budget runs out, you have the best possible output, ready to use. Social business is not yet so disciplined in its directed outcomes, yet by its very nature is always up-to-date with the latest revisions, contributions, or updates.
  • Continuous Processes. While agile business typically recommends iterations, milestones, review steps, and other processes to happen as often as they provide useful course corrections (typically every few days, or weeks at most), social business is even higher velocity and larger scale. Consider real-time processes that run around the clock globally involving tens of thousands and sometimes a million or more simultaneous contributors. This means the scale and velocity of social business often outpaces agile by two to four orders of magnitude. Social business could learn a lot about continuous in the small (builds, releases, work product iterations, etc) while agile can perhaps learn to scale and go even faster in a way it never could before.

This comparison just scratches the surface but is a useful start. I’m happy to be called out on any details anyone feels like I may have gotten wrong. I do believe that agility and social business go hand-in-hand and that we can cross pollinate the two to create far stronger results that either can by themselves today. Put simply, agile business and social business are two sides of the same coin. That may be a controversial statement to some but I believe that as far along as these two disciplines have come in parallel, they will do better with more explicit and effective connection. Our organizations (businesses, organizations, government, etc.) will almost certainly benefit.

What do you see as the commonalities and differences between agility and social?