I have been thinking a lot about artificial intelligence lately, which probably isn’t much of a revelation considering how much time I have spent experimenting with it over the past couple of years. I have used AI to make music, write code, develop small applications, analyze data, research subjects I knew very little about, troubleshoot computers and electronics, and help with any number of other things that I probably wouldn’t have even attempted a few years ago.
And yet, the more I learn about AI and the more capable I become at using it, the more I have this nagging suspicion that I am still something of a neophyte.
At my age, I think I am probably ahead of the curve compared with many of my peers when it comes to actually using AI rather than simply reading about it. But sometimes I wonder if I am really the equivalent
of one of those first-generation PC owners who discovered Broderbund Print Shop and proceeded to kill several trees worth of tractor-feed paper while proudly telling everyone, “Look what my computer can make!”
For those too young to remember it, that really was amazing at the time.
But nobody sitting in front of an Apple II or IBM PC making a twelve-foot HAPPY BIRTHDAY banner was contemplating smartphones, cloud computing, streaming music, digital photography, online banking, Amazon, ransomware, social media, or a world in which billions of people would carry more computing power in their pockets than most businesses possessed at the time.
And maybe that’s approximately where we are with AI.
I can make a song. I can build an application. I can ask AI to analyze something that might have taken me hours to work through manually. Those things are genuinely impressive and useful. But I increasingly wonder if the much bigger transition isn’t going to be from “look what AI helped me make” to “AI handled that for me.”
And that is where my thoughts about all of this start wandering in a lot of different directions.
There seems to be a strange dichotomy developing around AI. On one hand, there are AI researchers, technology leaders, and governments increasingly talking about safety, guardrails, and whether development should slow down long enough for us to understand and control what we are creating. On the other hand, corporate America doesn’t seem particularly interested in slowing down. If anything, the message seems to be to double down.
Use AI. Learn AI. Find ways to incorporate it into your job. Increase productivity. Automate processes. Become an AI-enabled company. There are even variations of the warning that if you aren’t using AI today, you may find yourself irrelevant in a few years.
I understand the argument. If AI really is as transformational as many of us believe it could be, a company that spends the next five years cautiously studying it while competitors figure out how to fundamentally change their businesses could have a very different problem on its hands.
But there is another message being delivered at the same time.
Don’t trust AI without verifying what it tells you. Don’t put sensitive information into the wrong model. Watch for hallucinations. Protect your data. Don’t allow agents excessive permissions. Put guardrails around everything.
So apparently we need to use AI aggressively while simultaneously not trusting it.
Those two ideas aren’t necessarily incompatible, but I am not convinced we have figured out how to communicate both of them particularly well.
Some of my own experiences have made that problem much less theoretical for me.
It is entirely possible for someone to ask AI how to solve a technical problem, receive instructions that actually work, and still end up doing something they shouldn’t be doing. The AI may have answered exactly the question it was asked.
The problem may have been the question.
“How do I make this work?” isn’t necessarily the same thing as “How do I make this work safely, within the intended architecture, without circumventing a security control and without violating policy or accepted best practices?”
Someone with enough experience may immediately recognize the difference. Someone who assumes the AI knows more than they do may not.
That worries me more than some of the obviously ridiculous hallucinations we like to share because it isn’t necessarily obvious that anything went wrong. The solution provided may work perfectly.
AI literacy can’t simply mean learning how to write better prompts. It also has to mean knowing enough about the subject to recognize when the answer should be questioned.
That gets particularly interesting when businesses begin rebuilding processes around AI rather than simply using it as another tool.
There is a growing temptation to burn the bridges. Don’t just experiment with AI. Commit to it. Redesign the workflow. Automate the process. Reduce the manual work. There is no going back.
Maybe that is exactly what successful companies will eventually have to do.
But I keep coming back to a fairly simple question.
What happens when the AI isn’t available?
Traditional disaster recovery assumes that a computer system may fail, so there needs to be another system, a backup, another site, or some manual process that allows the business to continue operating.
AI introduces another possibility. What if the backup disappears because nobody remembers how to do the work anymore? Sort of like COBOL programmers coming out of retirement for Y2K.
If an organization automates a significant portion of some business function and eventually reduces the number of people capable of performing that work manually, the disaster recovery question isn’t simply, “How quickly can we restore the AI?”
It becomes, “Can we still run the business without it?”
A day? Three days? A week?
I don’t know how many organizations aggressively adopting AI are seriously considering that yet, but I think they eventually will have to.
Then there is the money.
This is another area where I don’t think we completely understand what we are signing up for.
For decades, businesses have become accustomed to fairly predictable software economics. Buy a license. Buy a subscription. Pay a certain amount per user per month. Microsoft has certainly trained corporate America to understand that model.
AI can be different because every interaction potentially consumes something.
It might be tokens. It might be API calls. It might be compute units, agent executions, GPU time, or some combination of all of them.
While that may not seem particularly important while a company is experimenting with AI, it could become very important after management tells 50,000 employees to use it every day and they actually do.
And what happens when AI is no longer just helping someone write an email but becomes part of a critical business or security process?
Suppose AI is analyzing security events, investigating suspicious activity, evaluating transactions, or looking for fraud. What happens when the organization reaches a token limit, compute limit, API quota, or whatever capacity constraint exists in that particular implementation?
I have started wondering whether attackers will eventually recognize this as something they can exploit.
Could an attacker generate enough seemingly legitimate activity to force an AI-based security system to consume a significant amount of its available resources and then launch the activity they actually care about later?
I don’t know if anyone is doing that today at meaningful scale. I am certainly not suggesting that this is already some widespread attack technique. It just strikes me as the sort of thing someone will eventually try.
We learned a long time ago that you don’t necessarily have to defeat a security system if you can exhaust it. I think anyone in IT operations or cybersecurity has faced this decision at least once in their career: “Do we have it fail open or closed?” One keeps the business operating while the other keeps us safe, and sadly, the people outside of operations and security tend to have the final say.
There is also a difference between making AI inexpensive while an organization is learning to use it and what it costs after business processes have been built around it. A capability offered inexpensively—or even free—during adoption can become considerably harder to walk away from once workflows, automation and employee habits depend upon it. If the eventual pricing model is based on tokens, compute units or conversion ratios that can change over time, organizations may discover that they didn’t simply adopt another software product. They adopted a variable-cost dependency that can sometimes seem as volatile as the stock market.
AI doesn’t make that lesson go away.
One answer to the cost and capacity problem will undoubtedly be, “We’ll run our own AI.”
That makes sense for a lot of reasons, particularly when proprietary or sensitive information is involved. But I don’t think running AI internally makes the economics disappear.
It just moves them somewhere else.
Instead of paying directly for tokens, now you are paying for GPUs, electricity, cooling, storage, networking, people, and all of the infrastructure required to keep the thing running.
And the compute is still finite.
If an employee wants AI to rewrite an email at the same time an AI security system is analyzing a potentially serious incident, should those requests have equal priority?
Probably not.
Someone will eventually have to make those decisions, which means organizations may find themselves allocating AI capacity much like they allocate other finite computing and network resources today. Could AI QoS become a thing?
The part of internal AI that concerns me more, however, isn’t the hardware.
Someone has to decide what data these systems use, how they are trained or augmented, how their answers are evaluated, what guardrails exist, who can access them, how updates are tested, and what happens when they behave in unexpected ways.
That requires expertise.
Do most corporations actually possess enough of that expertise to build and operate their own AI environments responsibly?
I don’t know.
And perhaps the more important question is whether they know when they don’t.
So far, all of this assumes that a company is worrying about its own AI.
I think things get much stranger when my AI starts talking to your company.
Suppose someday I tell my personal AI agent to take care of something for me. Maybe it is something mundane like negotiating a better price on a service. Maybe it is making a purchase. Maybe it eventually involves moving money.
My agent shows up at your company and essentially says, “I’m working for Tim, and he authorized me to do this.”
How do you know that’s true?
How do you know the agent really belongs to me? What exactly did I authorize it to do? How long does that authorization last? Can I revoke it? Has somebody compromised the agent? Did I authorize this particular transaction or just give it some broader instruction that it interpreted incorrectly?
And if something goes wrong, can I simply say, “I didn’t tell it to do that?”
We have spent decades figuring out identity and access management for people, computers, and applications. Now we may have to figure it out for software entities that act as representatives of people.
Even more interesting is that a company may decide it doesn’t want anything to do with autonomous AI agents and still have to spend money dealing with them because its customers are using them.
That is a cost of AI adoption that may show up on someone else’s balance sheet.
Fraud presents another version of the same problem.
AI is already making it easier to create convincing resumes, correspondence, images, voices, and video. It can provide real-time assistance during interviews. Extend that to synthetic identities, social engineering, account takeover, and financial fraud, and there is an economic imbalance that bothers me.
AI may make it incredibly cheap to appear legitimate.
At the same time, it may make it increasingly expensive for businesses to prove that someone actually is legitimate.
The attacker doesn’t need AI to make every attempt successful. AI just needs to make each attempt cheap enough that the attacker can attempt thousands or millions of them.
Then the defender gets to pay for figuring out which ones are real.
Agentic AI makes this considerably more concerning because an agent can do something.
If a chatbot gives me a bad answer, I may act on it and do something stupid.
If an autonomous agent gives itself a bad answer and has sufficient authority, it may simply do the stupid thing itself.
At that point, the problem isn’t simply whether the model is accurate.
What can it access? What can it modify? Can it execute code? Can it send messages? Can it spend money? Can it interact with another agent? Can something it reads convince it to perform an action nobody intended?
Interestingly, the solutions start sounding like security lessons we learned decades ago.
Least privilege. Separation of duties. Approval thresholds. Logging. Access controls. Revocation.
Apparently artificial intelligence doesn’t repeal the basics.
There is another aspect of this that I hadn’t given much thought to until fairly recently.
For years, we have worried about software monocultures. If millions of computers run the same vulnerable software, a single vulnerability can create an enormous problem.
What happens when thousands of businesses depend upon the same handful of AI models not simply to run software but to help make decisions?
Could we eventually have something resembling a reasoning monoculture?
And the chain behind those decisions could get remarkably complicated. An AI may use a model from one company, connect to another system through some tool or protocol, retrieve information from somewhere else, call another API, and possibly interact with another agent.
Where exactly is the trust boundary in all of that?
We have spent years talking about software supply chains and trying to understand what components are buried inside applications. I have to think that eventually we will need to understand the supply chain behind AI decisions as well.
That also raises a question much closer to something I understand: what happens when we have to investigate one of these decisions after the fact?
Today, an investigation may establish that a particular user logged into a system and performed some action.
In an agentic environment, that may not be enough.
Which AI model was being used? Which version? What instructions did it receive? What information did it retrieve? Which tools did it have available? What permissions did it possess? What decisions did it make along the way? What did the human actually approve?
Hopefully somebody thought to log all of that.
I can easily imagine future investigations where reconstructing what an AI agent did becomes every bit as important as reconstructing what a human user did.
And while all of this software is supposedly happening somewhere in “the cloud,” there is another part of the AI story that is decidedly physical.
The cloud still has a power cord.
AI requires data centers, electricity, cooling, water, networking, land, backup generation, and enormous amounts of specialized hardware.
The discussion often becomes a debate over how much electricity AI will consume globally, but I wonder if the more immediate problems will sometimes be local.
A country can have enough electricity overall while a particular utility can’t suddenly provide another several hundred megawatts to a cluster of new data centers without building generation and transmission capacity that may take years.
That means AI could increasingly find itself competing with manufacturing, housing, transportation, and ordinary consumers for infrastructure.
There is something slightly ironic about one of the most advanced technologies humans have ever created potentially being constrained by things like transformers, transmission lines, and cooling water. When it becomes cost-effective for large AI companies to buy old nuclear power generation stations, we know the answer. Maybe AI can come up with a workable fusion power generation design to solve its own predicament.
And then I start thinking about what happens if AI really does deliver on some of the grander promises being made for it.
What if AI becomes extremely good at scientific discovery?
What if it identifies twenty promising drug candidates where researchers previously found two? What if it discovers hundreds of interesting new materials or produces thousands of potentially useful engineering designs?
That’s fantastic.
But discovering something isn’t the same thing as proving that it works.
If AI dramatically accelerates discovery but laboratories, testing facilities, researchers, and regulatory agencies don’t accelerate at the same rate, we haven’t eliminated the bottleneck.
We’ve moved it.
We could eventually have discoveries waiting for scientists to validate them and validated discoveries waiting for regulatory bodies to review them.
Then add public awareness to the equation.
Imagine headlines announcing that AI has discovered a promising treatment for a serious disease. Six months later, people are asking why it isn’t available yet.
The answer may simply be that discovering something potentially useful isn’t remotely the same thing as proving that it is safe.
But I can imagine enormous pressure building around that distinction.
And somewhere in all of this is another question we haven’t completely answered.
Who is responsible when an AI agent does something wrong?
If my agent makes a purchase I didn’t really intend, is that my fault? If a company’s AI agent makes a bad decision, is the company responsible? The developer? The model provider? The company providing one of the tools the agent used? What if bad information from somewhere else influenced the decision?
I suspect lawyers will eventually have a field day with that one.
There is even a larger economic question that I haven’t completely wrapped my head around.
Today’s Internet was largely built around people visiting websites.
We search. We browse. We see advertisements. We compare products. We read reviews. We click links. Somewhere along the way, somebody makes money from our activity.
What happens when my AI does the browsing for me?
Why would I visit fifteen websites comparing products if I can tell an agent what I want and have it look at three hundred of them?
That sounds pretty good to me as a consumer.
I’m not sure it sounds nearly as good to businesses built around getting me to visit their website.
Maybe search engine optimization eventually becomes something more like convincing AI agents that your product is the one they should recommend.
I don’t know what that Internet looks like yet, but I doubt it looks exactly like this one.
Which brings me back to something that may bother me more than any individual technical problem.
Who verifies the verifier?
An employee uses AI to perform some work. Someone else uses AI to review the work. Another person uses AI to analyze the review. Management uses AI to summarize the analysis, and perhaps another AI helps someone decide what to do about it.
Every one of those uses may be perfectly reasonable.
But somewhere in that chain, I still want a human being who understands the underlying subject well enough to look at the answer and say:
“That sounds perfectly reasonable, and it’s wrong.”
Maybe that becomes one of the most important skills in an AI-enabled world.
Not prompting.
Not knowing which model scored highest on the latest benchmark.
Knowing enough about something real to recognize when the machine doesn’t.
And that expertise takes years to develop, which makes it particularly ironic if we eliminate it because AI appears capable of doing the same work faster.
Which brings me back to Print Shop.
I remain enthusiastic about AI. If anything, using it has made me more optimistic about what an individual person may eventually be capable of accomplishing.
Things that once required a team of people, specialized skills, and months of work may increasingly become projects that one motivated person can at least attempt.
At this stage of my life, I find that incredibly exciting.
But I also wonder whether the things I am so impressed with today will eventually look rather quaint.
Maybe the songs, applications, analyses, graphics, and other things I have made with AI are my tractor-feed birthday banners.
“Look what I made!”
And maybe twenty years from now, someone will look back at this period and wonder why we were so fascinated by an AI that could make a song or write some code when the truly transformative development was the moment we started allowing AI to act on our behalf.
If that’s where we’re going, then making artificial intelligence more capable is only part of the job.
We also have to figure out how to authenticate it, authorize it, audit it, pay for it, secure it, regulate it, investigate it, and occasionally operate without it.
And perhaps most importantly, we need to preserve enough human knowledge to recognize when it is wrong.
There is an enormous push right now to make AI indispensable.
I just hope we spend as much effort making it dependable before we discover that we can no longer do without it.
And, yes, I realize I never mentioned SkyNet.
Sources and Further Reading
1. AI agents, identity and authorization.
NIST’s National Cybersecurity Center of Excellence is developing guidance around applying identity standards to AI agents, including identification, authentication, authorization, auditing, non-repudiation and protections against prompt injection. In September 2026, NIST announced that its first implementation use case will focus on identifying, authenticating and authorizing AI agents within the software-development lifecycle.
NIST — Software and AI Agent Identity and Authorization
2. Agent permissions and the risk of autonomous action.
OWASP identifies “Excessive Agency” as a specific LLM/agent security risk. It highlights excessive functionality, excessive permissions and excessive autonomy, and recommends familiar controls including least privilege, limiting available tools and requiring human approval for consequential actions.
OWASP — LLM06:2025 Excessive Agency
3. AI-assisted employment and identity fraud.
The FBI has warned that North Korean IT workers have used artificial intelligence and face-swapping technology during video job interviews to conceal their identities. Its recommendations include identity verification during interviewing, onboarding and throughout remote employment.
FBI — North Korean IT Workers Conducting Data Extortion
4. Data centers and electricity demand.
The International Energy Agency’s updated outlook projects global data-center electricity consumption increasing from approximately 485 TWh in 2025 to about 950 TWh in 2030. AI-focused data-center electricity consumption is projected to grow considerably faster than overall data-center consumption.
IEA — Key Questions on Energy and AI
5. The local infrastructure problem.
The IEA notes that data centers can be brought online considerably faster than the broader energy infrastructure needed to support them. Data centers may become operational in two to three years, while generation, transmission and other energy infrastructure can require substantially longer planning and construction periods.
IEA — Energy Demand from AI
6. Yes, the nuclear-power observation is real.
Microsoft has entered a power purchase agreement with Constellation supporting the restart of the former Three Mile Island Unit 1—now called the Crane Clean Energy Center—to provide carbon-free electricity supporting Microsoft’s data-center power requirements.
Microsoft — 2026 Environmental Sustainability Report