Alt-Consulting · 2026-05-20 · 43 min
Key moments - from our scoring
Substance score
67 / 100
Five dimensions, 20 points each
John Willis brings 35+ years of IT leadership experience to bear on the AI governance problem, arguing that enterprises are confusing experimentation with production and missing fundamental lessons from DevOps, cloud, and management science. The episode tackles why companies obsess over token leaderboards and adoption percentages while missing actual business value, how shadow AI replicates the risks of shadow IT but at exponential scale, and what the PocketOS database deletion really reveals about delegated authority and system design. Willis critiques the "fluorescence" metaphor for AI (constant energy) versus boom-bust cycles, emphasizing that AI with unlimited knowledge at machine-executable speed requires fundamentally different governance than previous automation waves. He walks through specific agent incidents - hallucinated git commands, agents accessing secrets managers without human oversight, super-user tokens in PCI-regulated environments - to show that catastrophes aren't AI's fault but organizational design failures waiting to be exposed. The conversation is essential for CTOs, governance officers, and enterprise architects grappling with agentic systems sprawl, data classification for AI, and how to set delegation boundaries without stifling innovation.
Shadow AI refers to uncontrolled AI agent and tool adoption without explicit IT or governance oversight, mirroring shadow IT from the cloud era but with exponential risk because agents have instantaneous access to unlimited knowledge and delegated authority, creating potential data breaches and compliance violations in regulated industries.
PocketOS had a poorly designed architecture with backups on the same volume as production, used super-user tokens, and delegated authority to Claude Code without proper boundaries - the agent didn't cause the failure, but the system's design shortcuts and improper delegation authority did.
Organizations are confusing token leaderboards and consumption metrics with actual value creation, repeating the KLOC metric mistake from the 1980s; Jensen Huang warned of this, noting that metrics should measure learning and outcome, not raw throughput.
Delegated authority is the level of access and decision-making power given to an agent - when agents have super-user access or root credentials in regulated environments without proper constraints, they can make autonomous decisions (like uploading secrets to public models) that humans wouldn't intuitively make.
Rather than prescriptive rules for every scenario, leadership should ask first-principles questions about what the organization is trying to do, set clear boundaries around authority and data access, use system design patterns from cloud governance (IAM, data classification, FedRAMP principles), and treat failures as learning opportunities on the J-curve.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers substantive ideas about AI governance, organizational readiness, and the distinction between experimentation and production at regular intervals. However, significant portions involve setup, agreement between hosts, and conversational meandering that dilutes density. Strong concepts (fluorescence metaphor, shadow AI parallels, first-principles thinking) are present but often restated rather than deepened.
We do have to fundamentally think different about what this thing can do this AI, right? It is a machine that gives us unlimited knowledge at machine executable seed. And if we delegate authority, there is potential for catastrophic and the blast radius really high.
prototype does not equal production...prototype is a learning artifact. You know, basically production is a liability artifact.
Willis draws effectively on management science (Deming, Senge, Akoff) to frame AI adoption, which is somewhat fresh in the AI discourse, but the core thesis - that organizational dysfunction precedes and is amplified by AI - is increasingly common. The fluorescence metaphor is creative but the underlying argument (history repeating, metrics obsession, shadow IT parallels) has appeared in other AI governance conversations.
Those are the wrong metaphors, right? They're really more like a fluorescence...With Florence's is the energy is always there
And here we are again, where CEOs and CIOs are saying, oh, we increased our AI adoption from 25 % to 35%, or we're doing this many pull requests, or this token leaderboard. nonsense, right?
Willis is highly credible: 35+ years in IT leadership, DevOps Handbook co-author, worked across enterprise governance and audit at scale, now focused on AI governance. He has demonstrable practitioner experience and has conducted qualitative analysis across major financial institutions. The transcript shows he draws from real engagements, not theory alone.
John brings more than 35 years of hands-on IT leadership experience and is widely known for his foundational work in DevOps movement. He's the co-author of the DevOps Handbook
I interviewed like three, four hundred people in a bank that managed 10 trillion in asset holdings. And it was incredible when I gave that report to the CIO about what he didn't realize his organization was doing.
The episode includes some concrete examples (PocketOS database deletion, Meta's agentic tool accuracy rates, the vault/secrets manager incident, the bank with 10 trillion in assets) but many lack precision. Numbers are often approximate ("95 out of 100 calls", "don't quote me on the exact numbers"). The PocketOS case is explored substantively; other examples are sketched without timelines, monetary impacts, or resolution details.
a company's whole database has been deleted in nine seconds and it's backups too, right?
out of like 100 calls to a tool, 95 will be the right tool, like tool X, and five of them will be Y
The host, Utsav, asks decent opening questions and provides context-setting interjections, but rarely presses Willis on claims or asks for deeper specificity. Many of Willis's assertions (Meta's numbers, exact percentages, architectural advice) go unchallenged. The conversation often devolves into mutual agreement and anecdotes rather than productive friction or verification. Follow-ups tend to restate rather than probe.
Yeah, no, I think the point that you mentioned that a lot of people confuse with, you know, the shiny new promise that your technology brings, but look into more deeply what operational impact it might have
I think two points, two thoughts actually came to my mind while you sharing that...This might actually, the whole AI adoption might actually be exposing weaknesses which already exist in the organization.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Alt Consulting: AI Adoption Conversations, Utsav Bhatt speaks with John Willis, DevOps pioneer, co-author of The DevOps Handbook , and author of Rebels of Reason , about why AI adoption is not fundamentally a technology problem, but an organizational transformation challenge. The conversation explores why many companies are investing heavily in AI transformation initiatives, copilots, AI agents, task forces, councils, and token-usage dashboards, yet still failing to achieve meaningful productivity gains or operational change. John argues that AI is not creating organizational dysfunction. It is exposing the weaknesses that already existed inside the enterprise. A major theme is the difference between AI experimentation and enterprise AI adoption. John explains that prototypes are learning artifacts, while production systems are liability artifacts. Many organizations are deploying AI pilots into real workflows without addressing governance, operating model redesign, risk management, data quality, authority structures, or AI change management. The discussion also critiques the obsession with token economics and AI activity metrics.
Transcribed and scored by The B2B Podcast Index.
Utsav Bhatt: Welcome to Alt Consulting, where we do AI adoption conversations. I'm Utsav Bhatt, founder of Strattof. We help companies drive AI adoption and innovation-led growth. One of the patterns I'm seeing across organizations today is that AI adoption is being treated primarily as a technology problem.
Companies are launching co-pilots, deploying agents, running workshops, tracking, token usage, but very few are seeing meaningful transformation in how work actually gets done. John Willis: you Utsav Bhatt: And when things fail, we often blame the technology. But what if AI is simply exposing the weaknesses that already existed inside the organization? That's exactly what we are exploring today.
My guest today is John. John brings more than 35 years of hands-on IT leadership experience and is widely known for his foundational work in DevOps movement. He's the co-author of the DevOps Handbook and the author of Rebels of Reason. John Willis: you Thanks.
Utsav Bhatt: A fascinating book tracing the history of AI and the people and ideas that shaped it. Over the years, John has worked across enterprise systems, governance, audit, DevOps, cloud infrastructure, and now increasingly around AI governance and agentic systems. John, it's great to have you today. John Willis: It's great.
Great to be here. I remember when we first talked about doing the podcast, it seemed like we were on a mind meld, you know, because, you know, I did some research on your background and I'm like, and then when we talked, like everything you just said in the intro is like spot on. We can end the podcast now. Yes, I agree.
So now it's it's now good. was actually it's refreshing. You know, I mean, I do a lot of podcasts, but it's refreshing that when it seems like we're both on the same wavelength here on Utsav Bhatt: Hahaha John Willis: some fundamental things that people need to be thinking about right now. Utsav Bhatt: Perfect.
Perfect. So you have had a front row seat to multiple technology revolutions over the last, say, four to five decades from mainframe to clouds to DevOps and now AI. Now, when you look at the current AI way, what feels fundamentally different this time and what feels like history is repeating itself? John Willis: Yeah, I love this question because one of the things I cover in my book, The Rebels of Reason, which is the history of AI, is I talk about the AI winters and the AI springs, right?
And one of the things I wish I would have done this in a book, I thought about this after the book about, those are the wrong metaphors, right? They're really more like a fluorescence. And what's interesting about fluorescence, it's about energy. So springs...
winters and springs are boom and bust, right? It like sort of it goes away and then it hibernates and you know the spring comes. With Florence's is the energy is always there and so I like that idea because I think it's a better metaphor for not just AI but just you said I've done five decades of technology shifts and transformations you know from mainframes to now you know the latest AI ⁓ wave if you will. They're always in this fluorescence and I think the thing that you have to sort of decouple is What are the things that you your question about like what what is different like and what feels like history repeating?
The difference are the things that are inside the energy of the if I'm using the fluorescence right and those things are that We do have to fundamentally think different about what this thing can do this AI, right? It is a machine that gives us unlimited knowledge at machine executable seed. And if we delegate authority, there is potential for catastrophic and the blast radius really high. So the things that are different is that I think we've always had complex automation and automation creates a newer blast radius.
But I don't think we've ever had instantaneous access to a corpus of knowledge. We were always mitigated to automation by basically the defined rules that you gave it. Now, depending on what delegated authority you give this AI. And this is where I get, we can go into deeper in this later why I'm very interested in what sort of governance looks like, what internal audit looks like.
But then the things are the same. If you think about this sort of energy fluorescence, right? And I really like that this metaphor is the things that we know. The history repeats, the social technical system, system thinking, not just getting focused in completely on the tool adoption.
That's why this AI wave is different. It is a tool adoption from an external point of view. And so what that means is we need to understand and obey the history of organizational dynamics. And we've got 100 years of management science.
I am a big student. One of my books is about Dr. Deming. I'm a student of the management scientists, the Eastern and the Western, the Western, the Deming, Akoff, Sange, Drucker.
And then, you know, I've studied a lot about lean and lean comes from Toyota production systems. I can go on and on and I won't, but Oh no, single, Tagata, Taguchi. There, you know, there is just a wealth of information about organizational behavior and we cannot ignore that because we're caught up in the fluorescence or the glow of this. fluorescent site.
Does that make sense? Utsav Bhatt: Yeah, yeah. And you know, this enormous excitement which is there with AI right now, every enterprise seems to have their own pilots and co-pilots and AI task force and now chief AI officer, AI councils. But despite all that activity, most organizations are still struggling to translate AI into measurable business impact.
So why do you think this gap exists? John Willis: Yeah, you I like your sort of framing of this transformation paradox, right? And I think of it, you know, very sort of aligned with that. ⁓ I think organizations are, you know, again, we're in this sort of glow of the, and we've all, we all feel, fall prey to this, right?
I mean, you know, my, love experimenting with new technology. You know, my, every technology transformation that I've been involved with over the last five decades, it starts out on like, I become a geek. I see how far I can take it, how much I learn. And at some point, I remind myself, what do I do?
You know, we talk about DevOps. I am basically the O in DevOps. My whole career has been operations and infrastructure. And one of the things I think about as I reflect is when I get out of that sort of fascination phase, I step back and say, what is the technology going to do?
to an operational infrastructure, more importantly, how do I protect the brand of a regulated or high consequence business? And right now, what we're seeing is there's a lot of confusion between experimentation and what transformation means. And I think most people, in fact, I stand up in front of an audience now, sometimes a thousand people in a room. And I say this, I'll say, prototype does not equal production.
And then I kind of half jokingly apologize that I have to say that out loud in 2026, you know? ⁓ You know, and, you know, I think we're not learning from what a prototype is. prototype is a learning artifact. You know, basically production is a liability artifact.
And I think we're just missing a lot of signals because of this fluorescence. And then you talk about organizational change, right? This wave of AI and every technology transformation I've been involved in, it needs some type of systemic organizational change to adapt. And there's this phrase social-technical which comes from like, I think it's a 19th century ⁓ sociologist who studied coal miners, And this idea that it's not just the technical and it's not just the human, it's this system.
where humans work together. And again, I think every technology is with, we forget these things, we have to learn, and then we kind of come to the enlightenment that it isn't just a technology, stupid, you know? Utsav Bhatt: Yeah, no, I think the point that you mentioned that a lot of people confuse with, you know, the shiny new promise that your technology brings, but look into more deeply what operational impact it might have and look at the operating model. That brings me to a sort of a point that we discussed earlier, which is operationally, then people start measuring different metrics to see how effectively they're using AI and they come to, hey, my token usage is so and so.
And now with OpenAI and Cloud and others sort of doling out all these awards of a million token or a billion token, people are sort of talking about it. Now, can you unpack that a bit in terms of token economics is what people are focusing on rather than value economics. John Willis: Yeah. you ⁓ Yeah, and think there's two ways to break this down, right?
And, you know, I'll start with sort of the negative. think, you again, the idea that where is history repeating itself? You know, I'm old enough to be like in the 80s and 90s, 1880s, 1980s, now I'm not that old, 1980s and 1990s, we used to do a thousand lines of K-locks, we called it, right? Or costs per K-lock or K-lock per person.
And by the time we got into the 2000s and Agile and DevOps, we sort of realized that was sort of nonsense, right? And here we are again, where CEOs and CIOs are saying, oh, we increased our AI adoption from 25 % to 35%, or we're doing this many pull requests, or this token leaderboard. nonsense, right? You know, Jensen Hong, right, like recently said that, you know, if a $500,000 a year did not consume at least 250,000 tokens, like then there's something wrong, right?
Like he's deeply alarmed as he said, this is what's missing in both of those, KLOX and token. It's value, capital V value. I don't care how many tokens, I didn't care how many KLOX. Did we not learn that, and KLOX could be gained.
Tokens are being gamed. Token leaderboards are literally, you you're forcing humans to say, hey, I'm going to pat you on the head because you've used more tokens. What do you think they're going to focus on? As opposed to, you know, I'll go back to the Deming and, you know, the giants of management scientists, in my opinion, you know, they would tear this, they'd be, you know, Deming doesn't, he isn't alive today, but he'd be ripping this apart.
And you know and I think the one thing I will say is the idea of token economics I think we need to separate and I think again we're conflating You know token usage and token leaderboard and token consumption with you know What is the fintech aspect and that's a real valid argument and one last thing I like to say too is What I care about is are we learning right and so you know we and the other thing we kind of constantly look at is like the S curve, things like diffusion, innovation, or chasm.
I'm very focused on the idea of a J curve. Instead of sort of everything's incremental, the J curve gives you this idea that you're in it, you sort of dip, and then you recover and you improve it. So all this discussion about AI failing, and it is, there are a lot of failures. But I think the organizations that I work with either understand or I help them understand.
that if you can look at this not as failure, because what is failure? It's a learning opportunity. And if you look at it like you are in this dip or the bottom of J curve, then you can sort of calibrate how do you climb out of there? And what are you learning?
What are you doing wrong? What are you learning from what you're doing wrong? And I think we're just not asking the right questions. And I think metrics is a really good point to start with is, are we asking the right questions by what we're observing.
And the answer I say is no right now. Utsav Bhatt: Yeah, ⁓ I think there is another sort of point which I to bring in with this conversation around what kind of metrics we are measuring. There is also a behavior that we have seen for a long time in organizations with IT. There's a concept of shadow IT, which for listeners who don't understand, it's a term which is used to say basically software, hardware or cloud services which are used within an organization without explicit approval by the IT department or their oversight.
This is essentially driven John Willis: Mm-hmm. Mm-hmm. Utsav Bhatt: by people who want to drive some productivity improvement, but it causes potential security compliance concerns and data leakage issues because they lack central management. Now we are also hearing term like shadow AI and uncontrolled agents sprawl.
How serious is this becoming inside enterprises, especially say regulated industries, because everyone, any dollar license, they go and put some data and they feel like it's protected. John Willis: Yeah, no, Yeah, no, I think there's a meta conversation about this shadow. Concept the shadow IT was driven heavily by cloud right like and and then so shadow AI now is really the same thing in fact There's sort of the this sort of swing back that like now with agents. We're creating shadow IT version 2 right ⁓ You know in words.
It's it the whole you know we've now come full circle, but And there's two ways to look at it. There's the pressure points of an organization I guess it all goes back to this if leadership is not giving the right direction. And a lot of times they can't give the right direction because they don't really understand their organization. They have different goals.
so what happens in an organization is you have, you know, I like to put things in three, make my life simple, make my explanations more simple, is you have three groups of people, and I know you have more than three, but you have basically the people who are basically innovators that are going to use the latest tools. And if leadership is not setting the right boundaries or giving the right definitions, then they're going to basically do now, ask forgiveness later and solve problems.
And more often than not, they win. If they do something great, it's like, yeah, you shouldn't have done it that way, but pat on the back. Then you've got that middle group who's stuck in the middle. They know they should be using some of the advanced AI tools, but they're torn because they haven't gotten any direction.
And they're the kind of people that actually like to follow directions, but they're innovators. And then the other group who are basically, you hey, I work from eight to five, you know, like, just let me do my job, right? And that's your talent plane. Now you're trying to sort of like be concerned about like what is, you know, we want to do this or we don't want to do this.
And you're not giving clarity of what you can do and can't do or what you should be doing in this organization. And what is the danger of shadow IT? It's the same danger now exponentially with shadow AI, which is to your point, we create a level of risk. know, the biggest problem that happened in shadow IT with cloud, was organizations didn't tell their employees or technologists that they could or couldn't use cloud.
They kind of deferred the answer. So that third group went ahead and used it. And there was no sort of connection to. know, internal audit, governance, risk control, compliance, all those things.
And what we found in the first wave was like these horror stories where, you know, critical, you know, intellectual property wound up on somebody's cloud that were publicly accessible. Right. And so what we came back and we started doing data classification and like we matured about how, and then regulatory bodies got more involved in like, if you're bank, this is what you can use for cloud. at FedRAMP and all that stuff.
Well, we're in the pre-FedRAMP, we're in a pre-data classification phase right now with a tool, like I said earlier, that has a set of tools that have unlimited knowledge at machine execute speed in any sort of... inch that we give it in delegated authority. Again, this is not a deterministic, here's the rules, do this. This is sort of a gateway to catastrophe.
So all the same problems apply, but now they're exponential in terms of the risk. Utsav Bhatt: Hmm. Right. In fact, the point that you mentioned around how agents are exploding within organizations and it becomes difficult to track them with shadow eye now becoming a big problem.
It reminded me of the work which I used to do around a decade back. So I was running a practice called application portfolio rationalization, where we will go and find out applications which companies are running. And I was so surprised in certain situations we could find applications which John Willis: Mm-hmm. Mm-hmm.
Utsav Bhatt: Neither business was owning nor IT was owning. They did not know where it was running and people have left. So nobody knows where's the instance of that application. Now, I almost think that terminology of the practice was called APR, Application Portfolio Racialization.
I'm sure in five years, we'll have agentic portfolio rationalization because you'll have so many front-end marketing agents, sales agents, you have backend IT ticketing system agents and John Willis: So yeah. Utsav Bhatt: people will sort of find it very difficult to get their hands on, you know, which one is actually better than the other, how are they doing, you know, from a performance perspective. So it's interesting how this will evolve. But this also sort of raises a concern.
Those like the three groups of people that you mentioned, there's some who are quite risk averse and they are waiting and watching. And every example which comes in the in the newspapers or on any blog post around, hey, John Willis: Mm-hmm. That's right. Utsav Bhatt: because of AI, this problem happened.
They sort of take that, take into the organizations and talk about the rules of using AI and we should be more cautious in our approach. We should be followers of others. So there was an incident that we were discussing earlier around a whole production database was deleted and then they blamed AI for it. So how can organizations learn from this?
Because as we experiment and those innovators were trying to do new things, will... end up doing a few things which might harm an organization. So how do you sort of manage such a such a issue? John Willis: Yeah, now I think going back to this, what are the things that are history repeating itself?
And again, I like to bring up the organizational management, organizational dynamics of things that we've learned. if I was just to sort of say, Dr. Deming, Edward Deming, he would basically look at AI right now and he would... tell you that if a system is poorly designed, AI will help you create defects faster.
Russell Aykhoff, one of the top systems thinkers, would say AI will accelerate broken process. If you haven't transformed your organization, you have industrialized dysfunction. And Peter Senge, who's still alive, who is the fifth discipline guy, he would say that you ⁓ would basically say the organization's We're not the ones who deploy the most AI. They're the ones that use AI back to the, you know, the metrics question.
You know, so the thing we talked about is that pocket OS, right? And this is an interesting story. It's a company, you know, the headlines are, you know, a company's whole database has been deleted in nine seconds and it's backups too, right? Well, I dug a little deep on that, right?
And there is, they're in lies like Deming's saying, like if you have a poorly designed system. and you delegate the wrong level of authority, bad things will happen. I I can't, I've been for the last year and half, almost two years, I've been tracking almost as a hobby rogue agent. And I've got like all these great stories of rogue, not even the public ones, people that come up to me and tell me how they use, you know, get and get hallucinated on a command and it deleted their repo, right?
Like these, you know, would click code, right? But the thing is, is that when you, With the case of the Pocket OS, they had a terribly designed architecture. They had the backups on the same volume as the production system. were, as far as I could say, this is a counterfactual, but they were lazy and they used super tokens.
And they didn't use a cloud service provider that had extremely robust, like why you don't use Amazon Cloud today, or even Google Cloud, but Amazon's cloud. It has a robust set of, you know, identity and IAM and the features. And now you may not take advantage of that. I mean, you still might use it.
But what they did is they literally took all the shortcuts. And then they decided to use Claude code. You know, sorry, what? Like, again, that's a tale of two cities.
Can I wipe out your whole business? Absolutely. Do you have a poorly designed system? It probably will.
Do you have a reasonably designed system where you're not using super tokens and you're not putting the backups on that? I mean, if you've been in IT for more than four days, you probably know you shouldn't put backups on the same volume as your production systems. ⁓ So again, that's the interesting tale of two cities is that a lot of these catastrophes... I had another solution where somebody, this was an interesting world activity, they decided that they literally wanted to get a list of servers in there and they were ⁓ PCI regulated, was regulated business, credit card use and stuff like that.
And somebody wanted to use code code and basically they figured, you know what, let me use code code and I'm just going to use code code to go get a list of ⁓ servers that I might want to remediate some patches for. And they used a super user like what they call a fire call, which was a root access for a small period of time. And so they thought that code code was going to act the way a human would. A human would probably go to the load balancer.
It would go to some registry that might have all the servers, right? Well, the agent, because it was in root, it had root access. It saw there was a secrets manager called vault available. It really made the decision on its own to say, hmm, that's going to be a much quicker way.
And it went ahead and then loaded all the secrets into the public anthropoclod frontier model. And that poor kid had to, next for the three days, every, you know, with his boss standing over him, kind of yelling at him. But the point is that that was a terrible idea. And going back to the leadership problem, I'm not saying leaders are to basically tell every person when, what particular scenario they should be using, an agentic process would say Git or systems like solutions.
But what I'm saying is try to set some, ask some questions. I run a workshop on an agentic automated governance, right? And one of the things that... I tell people, I don't know the answers.
These are complicated questions right now, incredibly complicated questions. And all I'm telling you is what I'm doing in my first couple of revs of this workshop is forcing you to ask questions about what you're trying to do. And what are the questions you should be asking? And then you can ask deeper questions.
It's first principles. First principle thinking, ⁓ systems thinking. And again, I think... We're in efflorescence.
We're forgetting, we're thinking this is all new, so everything's new territory. And some of it is new territory, but some of it is just basics that we should know better. Utsav Bhatt: I think two points, two thoughts actually came to my mind while you sharing that. First was the way we set up this conversation.
You exactly made the same point. ⁓ This might actually, the whole AI adoption might actually be exposing weaknesses which already exist in the organization. And the other thought was, this is similar to the conversation which people were having when big data came into picture. Hey, we are doing big data, we'll do analysis on it.
But if you have garbage data, which is not organized, not structured, not captured, John Willis: Mm-hmm. Okay. Utsav Bhatt: you have accuracy issues, then whatever you do on top of it, it's not going to yield any, but in that case, at least you just had a visualization or interpretation of data. Here, this might be much more severe because you might allow agent to take a decision on your behalf and then sort of go back looking at the problems that it faces.
So when you do these workshops, and one thing which actually scares me a bit is the whole agents, like I have done some workshops with people talking about how you develop. ⁓ agents for marketing team and sales team and others. We hadn't even had those conversations in depth with companies and then this autonomous agent concept came in and companies latched on it and like, yeah, we'll do autonomous agent. You don't have right now foundation ready to do a simple agent in your organization, which is full proof, tested, ⁓ works really well, gives you the benefit and now you're moving towards fully agentic system, which are autonomous.
John Willis: Mm-hmm. Hmm. Utsav Bhatt: So although this is a very complicated question to answer, but what are some sort of two, three guiding principles that you tell organizations that they should keep in mind when they are trying to adopt AI, especially those organizations which might not have a good foundation or might not have a good understanding of what underlying infrastructure exists. John Willis: Yeah, I think the data science is a good example because that sort of came right, like sort of leaped on top of cloud or very close to each other in terms of the birth and the growth.
And one of the things I think ⁓ is interesting in the data science and the space, was bad data actually has a cost. And it's the same thing with inference now, because I want to break down. There's sort of two things we need to think about. And a lot of what we need to think about is data.
So it's very much similar. And the problem with data science is depending on what those answers are providing. I always talk about if somebody wants to build a chatbot in an organization, what's the risk? Well, if it's an internal chatbot, let's say it's a chatbot on where to go to lunch at a corporate head course.
Yeah, the risk is very low. What if it's a chatbot that sort of organizes logistics internally? Now, is that brand reputation? Probably not.
Can you get regulated severe enforcement? Probably not. Can you waste $5 million in a year because you had 80,000 employees following these rules, right? And it was the bad, you know, non-optimum advice, right?
So now you have this same problem in inference. Right? And you have two-fold problems with inference, right? When inference I talked about like Gen of AI giving you answers, right?
So you have this assistance mode, which is either code assistance or knowledge assistance, right? And the question then is, the first couple of advice questions is, can you share or can you understand the providence of the data that is creating the answers in the inference or the probabilistic answers? And there's a whole, if you look at OWASP-L on top 10, which is a great resource for prompt injections and all the ways that you can get into a lot of trouble for what's called tainted propagation of data.
And so that's, like... It's no difference in cloud. What would we find out when I said earlier when we found out we let the early adopters do what they wanted because we didn't tell them what they couldn't do. They did the do now as we get us laid.
The first thing we found was a lot of data showed up in the cloud that shouldn't have been there. ⁓ And then we pulled it back and we did data classification. So first and foremost, what data is being used to create assisted answers, questions, code, and then the... The scarier question now is what data is being used to create decisions that have consequences?
And this is the agentic stuff. So it always goes back to data. There's been some great presentations by Meta. about how they've been using agentics in anger for a while now.
They recently gave a conference presentation where they talked about what they'll find is in most curated atomic execution of agents, still find that out of, and don't quote me on the exact numbers, but out of like 100 calls to a tool, 95 will be the right tool, like tool X, and five of them will be Y. And like, that's the nature of the beast. There's a percentage of risk when you're doing probabilistic, which is what we're doing now. And so organizations have to understand the data and the risk that they're willing to accept if they're going to use these tools to answer questions, particularly if questions answers are in regulatory, like they're under regulatory bounds, right?
⁓ Finance or whatever. And then if they're going to take actions. Utsav Bhatt: Thank Yeah. John Willis: There's a risk.
And I think the reality check is people are not learning from the history of like, okay, before we get to this, let's understand the data. Let's understand the risk surface. Is this agent able to read? this, you know, and the risk there that, you know, there are actually some executable read-only hacks and sort of, ⁓ but then is, it write?
Can it mutate a production service? Utsav Bhatt: Thank John Willis: Can it execute in a multi-system environment? And what's really fascinating to me is I'm talking to some of largest organizations in planet. And the advisors that are very high up at the architectural level of these organizations are telling me these questions are not being asked.
Utsav Bhatt: Yeah. So we have spoken about a lot of technical details which people who work behind the scenes, ⁓ managing AI implementation would really resonate with. But just the last question, for leaders who are ⁓ running their businesses, either business unit heads or the CEO, CSO, who are overwhelmed by the pace of AI change right now, because every other day there's a new vendor coming in talking about how they can bring in AI and they're listening to podcasts, they're listening to conversations which are happening, keynotes which are being given.
John Willis: Mm-hmm. Utsav Bhatt: What are some first principles that they should get back to? Like as a leader when you're overwhelmed with the amount of information on AI that is coming your way, what you should practically do in next say 12 to 18 months. John Willis: Yeah, yeah.
No, I think, you know, I like your framing of reimagined, redesigned, realized, right? Because I don't use those exact terms, but I think about, and this is what I do with leaders. The first question I like to ask, because I have leaders that tell me, John, I don't think my organization can understand AI. And they're like really begging me to tell them, yeah, you should bring in a really large consulting company to help you.
That's never going to be my firm's answer. It may be one of my answers. But then the first question I ask is, you have an innovation plan. Like you think there's an organizational structure.
You've got pressures from the market pressures. You've got executive pressures. You've ⁓ obviously you've got audit and risk pressures. But what you don't have, and then your good leaders do a pretty good job of trying to create innovation strategy.
But what they don't do a good job with, almost universally, is understanding their talent. And you can't have an innovation strategy without understanding your talent. And so when I think about the transformation, any transformation, but certainly this AI wave we're in right now, is do you have a very simple question? And if you don't understand the question, let's deeper dive, I'm not saying you, but the executive that I'm working with is, do you have a talent and innovation strategy?
Because if you don't have both, like what is your talent? Is it those three categories? Well, that's probably the first thing I need to fix. I need my talent to be on the same wavelength.
And I need clarity. And if the people who are the eight to fiveers don't want to do AI, then maybe they're not in right place. And if the people in the middle are like, why is AI, but they don't know what, we need clarity. And then, know, the sort of that third group, hold on there, buddy, don't use open claw.
Like maybe we should hold off on using something that right now in a high consequence business. So you need to understand where you're talented. And I'm a big fan of like qualitative analysis. I've done many of these over the years where you go in and I did one, ⁓ a few summers back, before the AI phase, was about DevSecOps, IT risk and audit and all that.
And I interviewed like three, four hundred people in a bank that managed 10 trillion in asset holdings. And it was incredible when I gave that report to the CIO about what he didn't realize his organization was doing. In fact, at first they get mad at me. ⁓ count the desk, it can't be so.
The big five told us that we were great at this and now I can't, you know, like, no, I mean, like, I can't make this stuff up. I got it from your people. And here's the one other problem. A lot of organizations that come in when a CIO is sort of asking me to give them the green light to go bring in large consulting organization.
I don't know, the big four these days or big five, I can't keep count, but I'll say the big five and I'm probably wrong. But they want the green light and my question is like, they're going to talk to the leaders. And we have this thing where we call the green shading, right? Like everything in the bottom is like red.
As it goes up a level, it becomes a little yellow. As it goes up a little higher, it gets a shade of green. By the time it gets the executive, it's green, right? And some people call it the water mail in effect, right?
In other words, you know, it's sort of green on the outside, it's all red in the middle. And unless you're basically talking to the talent, the people that put their fingers on the keyboards. mean, how many times I've gone into an organization where I talk to people with fingers on the keyboard and they just spent 18 months with a big five and they laugh and say, you know, you're the first person that's actually come to talk to us about this. So again, think there are, and this is just sort of management science 101.
Read a book by Deming, read a book by Senge, read a book by Akoff, read a book by Duck Drucker, and the list can go on and on and on. And you'll get the same sort of, like I'm not some genius that made all this stuff up. I'm just following the playbooks that have been laid out for us. Utsav Bhatt: Yeah.
Yeah. Yeah. And you know, working in the consulting industry for 18 years now, ⁓ the reason I sort of branched out and tried to do my own thing was I feel a lot of these answers don't lie with hiring a big four, big five consulting firm. What they actually need is some time to spend within the organization to have some thoughtful conversation on where you're headed, what you want to reimagine, what's the problem, how do you overcome that?
And maybe John Willis: Yep. Utsav Bhatt: a big four could come in for doing the final board level alignment because you need to get budgets for moving things forward. But the whole analysis could be done differently. That's what I also bring in the book, Alt Consulting, ⁓ which I authored.
This talks about the same thing. Unbundled consulting, do your analysis with a different set of providers, much like they're taking advice from you rather than hiding an extension and saying, please tell me what I should do with AI. Similar business side just. John Willis: you Utsav Bhatt: try to get it done differently.
And then if you need leadership alignment, we could do that. yeah, that's exactly where we're going to John Willis: Yeah. No, no, I think you're spot on on this. ⁓ I've read a lot of stuff.
I've still got your book in my shelf. I want to read it because I do. think fundamentally we are aligned in this. Back in the 1990s and 2000s, between that year 2K thing, I did a lot of work with IBM companies that were around the IBM portfolio.
And the idea was get in, get out. Teach your client to fish. I think you talk about being an advisor. I don't know where Butts and Seats, sorry for explaining it that way, I don't know if Butts and Seats consulting lands in today's world because there's a lot of build versus buy.
Utsav Bhatt: Yeah. John Willis: things going on right now in large organizations, the ability to create your own solutions. There's a lot of dust that needs to settle. But I've always felt that the first order process should never be bring in a big five.
In fact, for a couple of reasons. One is, I would tell, when I did the qualitative analysis, one of my cells was I would tell a CIO, Utsav Bhatt: Yeah. John Willis: large corporations. mean, one was looking at 10 trillion asset holding, but I did some really banked large healthcare.
And I'd say, here's the difference between me and them. One is I'm going to tell you the absolute truth. Oh, John, we want the truth. No, no, you're not going to like the truth and you're going to get mad.
Oh, no, no, John, where I, you know, and I'm just said, here's the thing. I'm not sticking around, so I don't care. like if you get mad at me and you will by the way pound your fist on the desk I guarantee you when some of the things I'm going to tell you and I said but here's the thing you're going to pay me regardless you know and and it is an enlightened because they've been through so many because what is the big five one to do when they're doing the advisement it's sort of the green shading problem they're not going to walk into the CIO and tell them all the horrible things because they I'm telling you even though they promised me they're not going to get mad at me and I don't mind because I'm like Utsav Bhatt: Yeah.
Yeah. John Willis: You know what, if this works, you'll call me back in a year from now or five years or three years from now when there's another technology explosion and you trust me. But I'm in here for a short period of and my answer will probably be, it's usually going to be a mid-size consulting business that I have a lot of, there's a couple that I think are really good at implementation, I reckon, but I'm not immune to a big five as well. I had a CIA one time where they had 18 months.
They had one of the big five in there. And I came in for a month. And when I gave the report, she was just furious. Not furious at me, just furious.
She's like, you found out more in a month than they found in 18 months. But the joke is on me. They charge like $400,000, $500,000, maybe a million. I charge like $300,000, know, for like, it was more than a month, but you know, about $100,000 a month, right?
⁓ You know, so, but anyway, that's the way I roll. I don't come in, you know, but I think the point is people like us, ⁓ like why not invest in us first? One, we're gonna give you the brutal truth. We want to be your advisor.
I want you to trust me more than anything. know, large companies sort of delegate trust because they want long-term business. Right? Yeah.
And so I think you're spot on. I do think the world, the idea of consulting, I think it's a fascinating conversation to have about how, you know, the landscape of consulting business has been changing over the years. Now I think it's got a wedge in it because of all this sort of new AI. Utsav Bhatt: Yes.
And I think now it's becoming more ⁓ affordable for people, say mid-sized companies who could never earlier reach out to them because consulting is also getting partially automated and analysis is getting done differently. But John, this was a fascinating conversation. think one of the biggest takeaways for everyone listening to this is that AI is not just about introducing a new technology, a new shiny technology. It's exposing ⁓ old organizational assumptions, weak operating models, unclear governance.
John Willis: That's it. That's right. Utsav Bhatt: and maybe leadership gaps that may have already existed, but we never knew about them. And perhaps the companies that succeed won't necessarily be the ones with the most AI tools or most number of tokens as we discussed, but the ones which are willing to rethink how they operate.
Thank you so much for joining me. John Willis: Yeah, that was great. I loved our pre-conversation and I knew this would be a lot of fun because we are definitely aligned on the way we're thinking. I think you're spot on in the way you're thinking about this problem.
great. Now, thank you so much. Utsav Bhatt: Great. Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.