Insights — Ts. Lukas J. Tan on AI Leadership & Digital Transformation

Insights · 1/40 08 Oct 2026

The AI Workforce You Subscribe to Today May Become the Intelligence That Competes Against You Tomorrow

Why I Believe the Future of Enterprise AI Is Not About Renting Artificial Employees, but About Owning, Defending and Governing the Intelligence That Runs Your Business.

Synopsis

October 2026. The artificial intelligence industry is moving at extraordinary speed. Everywhere I look, companies are promoting AI employees, AI workforces, autonomous agents and subscription-based digital workers. The proposition sounds attractive: instead of hiring more people, businesses can subscribe to artificial intelligence that performs tasks, manages workflows, communicates with customers and operates around the clock.

Yet after more than two decades of building websites, software systems, databases and business applications, I see something that concerns me deeply. The greatest risk may not be what these AI employees can do for a company, but what the companies providing them could potentially learn about their customers.

I believe the subscription-based AI workforce industry, particularly services that require extensive access to an organisation's internal knowledge and operations, may face a serious crisis of trust. The more intelligent these systems become, the more difficult it will be for customers to understand what happens behind the interface.

My concern is not simply cybersecurity. It is something potentially more consequential: the ownership, extraction and reproduction of organisational intelligence.

Two Decades of Building Systems Have Taught Me to See What Others Overlook

I began building business software long before artificial intelligence became a fashionable commercial product. Since the early days of my career, I have worked across websites, databases, business applications, software implementation and digital infrastructure. To outsiders, these may appear to be ordinary technology services. To me, however, building a system has never been merely about delivering functionality.

A system must perform its intended purpose, but it must also be designed to withstand misuse, identify unusual activities, record operational behaviour and preserve evidence when something goes wrong. Whenever I build something, I naturally think from two directions: how it should work and how it could fail or be exploited. I want to know who accesses information, what actions they perform, where errors occur, what data moves between systems and whether anyone is attempting something outside the intended boundaries.

This habit has become part of my professional instinct. I do not see logging, monitoring and reporting as secondary technical features. They are fundamental instruments for protecting an organisation and continuously improving its technology. The information collected from legitimate operational monitoring can reveal weaknesses, expose inefficiencies and help developers improve systems over time.

An Experience From 2007 Changed How I Think About Information Protection

In 2007, I developed a business system that would eventually teach me an important lesson about the relationship between technology, employees and organisational trust. Several years after its implementation, an employee left the organisation and copied customer data from the system. That incident triggered something in my thinking that has remained with me ever since.

I realised that protecting software was not enough. The real asset was often the information contained within it, and the people authorised to use a system could sometimes represent a greater risk than outsiders attempting to break into it.

From that experience, I became increasingly sensitive to access controls, audit trails, operational logs and the ability to detect unusual behaviour. My philosophy was straightforward: if I build a system for people to use, I must also understand how it is being used. Not because every user should be treated as suspicious, but because responsible technology ownership requires visibility and accountability.

That lesson was learned in the conventional software era. Today, artificial intelligence has made the same problem considerably more complicated.

Artificial Intelligence Is Not Just Another Software Application

Traditional software generally operates according to defined logic, programmed functions and structured data flows. Although conventional systems can be extremely complicated, developers can usually investigate their architecture, inspect their code, examine database transactions and trace how particular operations occur.

Artificial intelligence introduces another dimension. Modern AI agents may combine language models, external tools, memory systems, APIs, retrieval mechanisms, autonomous workflows and third-party integrations. Some operate through open-source frameworks and increasingly complex orchestration environments. Each additional component creates new functionality, but also expands the potential attack surface.

Over recent months, I have been deeply involved in experimenting with agentic AI, automation workflows, self-hosted infrastructure and open-source agent frameworks. The deeper I explore these technologies, the more I appreciate their extraordinary potential. At the same time, I have become more concerned about how easily poorly configured systems can expose information or permit unintended actions.

An AI agent may appear to be performing a simple task, while behind the interface it could be accessing multiple databases, reading documents, calling external services or transmitting information between systems. Without appropriate observability and controls, even the organisation deploying the agent may struggle to reconstruct everything it has done.

The Invisible Back Door Is Only the Beginning

Consider a company subscribing to an external AI workforce service. The provider installs or configures an AI employee that handles customer enquiries, prepares proposals, reviews documents and assists with internal operations. The customer sees a convenient interface and measurable productivity improvements. What the customer may not see is the complete technical architecture supporting those operations.

Who controls the agent's instructions? Which external tools can it invoke? Where are its operational logs stored? Can the provider remotely change its behaviour? Are conversations retained? What happens when a third-party integration is compromised? Can the customer independently verify what information leaves the organisation?

These are not accusations against every AI workforce provider. Many vendors implement serious security controls, contractual protections and technical safeguards. Nevertheless, the risk exists because the architecture can create opportunities for unauthorised access, insecure integrations, malicious instructions or hidden data transfers.

A sophisticated back door does not necessarily announce itself through an obvious system failure. It may remain invisible during ordinary operations. More importantly, even a technically legitimate feature can become a security weakness if its permissions exceed what the business actually requires.

The question is therefore not whether every external AI workforce contains a back door. The question is whether the business owner has sufficient evidence to establish that its most sensitive operations remain under its control.

Data Leakage Is Dangerous, but Intelligence Leakage Could Be Worse

Most business owners understand the consequences of customer data being stolen. They worry about personal information, financial records, intellectual property and confidential documents. These are legitimate concerns, and existing cybersecurity practices are designed to reduce such risks.

However, artificial intelligence introduces a less obvious category of exposure. An AI workforce may interact with employees every day, observe recurring decisions, process internal discussions, interpret customer requirements and participate in operational planning. Over time, these interactions can reveal how an organisation thinks and behaves.

Imagine an AI assistant that helps a chief executive prepare proposals, evaluate opportunities and negotiate contracts. Through repeated interactions, it may encounter the executive's pricing philosophy, commercial judgement, risk appetite, preferred negotiation tactics and strategic priorities.

Whether that information is retained, analysed or used for further model development depends on the provider's architecture, contractual commitments and technical controls. It is not inevitable that every AI service learns from customer conversations. But where such processing is permitted or insufficiently restricted, the consequences could extend beyond conventional data leakage.

A company may lose not only confidential information, but valuable insight into the decision-making patterns that distinguish it from competitors.

What Happens When One AI Provider Serves One Hundred Competitors?

Let us imagine that I establish an AI workforce company specialising in the medical industry. I provide intelligent operational assistants to one hundred medical businesses. Each customer uses my service for scheduling, administration, procurement, customer communication, operational reporting and management support.

Individually, each organisation may see substantial productivity improvements. Collectively, however, the service provider could occupy a remarkably powerful position within that industry's information ecosystem.

If the architecture allows customer interactions to be retained and analysed across accounts, the provider could potentially identify common operational weaknesses, purchasing patterns, customer behaviours, commercial strategies and management practices. With sufficient access, the provider might develop a sophisticated understanding of how an entire sector operates.

Now consider the more troubling possibility. What if those insights were used to develop a competing business, inform another customer or construct specialised AI systems that reproduce the operational expertise of existing organisations?

This would not require the crude act of downloading a customer database. It could involve extracting patterns, processes, decisions and business knowledge from accumulated interactions. Reproducing a company's expertise accurately would still be technically difficult, and contractual or legal restrictions may prohibit such use. Nevertheless, the strategic possibility deserves serious examination.

The real competitive advantage of many companies is not their software. It is the knowledge embedded in how their people make decisions. If that knowledge becomes accessible to an external intelligence provider, the boundary between technology supplier and potential competitor becomes increasingly important.

The Subscription Model May Be Selling Convenience at the Expense of Control

I understand why AI workforce subscriptions are attractive. Businesses want immediate results. They do not necessarily have internal developers, AI engineers or the financial resources to establish their own infrastructure. A ready-made AI employee appears to solve these problems quickly and affordably.

But convenience should not be confused with ownership.

When a company subscribes to an external AI workforce, it must examine what it actually controls. Does it own the agent's configuration, workflows, memory, knowledge base and operational records? Can it inspect the system's permissions? Can it migrate to another provider without losing accumulated organisational knowledge? Can it terminate the relationship and verify that its confidential information has been deleted according to agreed retention policies?

I foresee that generic AI workforce subscriptions will face increasing pressure as AI development becomes more accessible and businesses become more conscious of data sovereignty. Providers selling only convenient access to standard AI capabilities may struggle to sustain differentiation.

This does not mean all AI subscriptions will disappear. Specialised providers with strong security, transparent governance and genuine domain expertise may continue to thrive. However, I believe the market will increasingly distinguish between renting artificial intelligence and surrendering control over business intelligence.

Those are two very different commercial decisions.

The Future Should Be Internally Governed AI, Not Blindly Trusted AI

My preferred direction is for businesses to develop the capability to own and govern their critical AI workflows internally. This does not necessarily mean every company must train its own language model or build every component from scratch. That would be economically unrealistic for many small and medium enterprises.

Instead, organisations should understand their AI architecture, retain ownership of their business knowledge, control access permissions and establish clear boundaries around external services. They should know what information an AI agent can access, what actions it can execute, where data is processed and how every significant operation can be audited.

External technology can still play an important role. Open-source frameworks, commercial models, cloud infrastructure and specialised vendors can all be incorporated into a properly governed architecture. The essential principle is that the organisation must remain capable of controlling, inspecting and replacing critical components.

For SMEs, this may begin with something as practical as assigning an internal employee to understand AI workflows, maintaining an inventory of connected systems, restricting sensitive data access and implementing approval requirements for high-risk actions.

AI governance cannot guarantee absolute security, and no single regulator can eliminate every technical risk. But effective governance, supported by technical verification, contractual accountability and continuous monitoring, can significantly reduce exposure.

Businesses should not become dependent on intelligence they cannot inspect, control or safely disconnect.

The Most Valuable Technology Professionals Will Know How to Build and Defend

Throughout my career, I have never been satisfied with understanding only how technology works when everything goes according to plan. I am equally interested in understanding what happens when something goes wrong, when someone attempts to misuse a system or when a seemingly harmless feature creates an unexpected vulnerability.

I believe this combination of offensive and defensive thinking will become increasingly valuable in the AI era. Organisations need builders who understand architecture, implementation and business operations. They also need people who can challenge assumptions, investigate hidden dependencies, recognise unusual patterns and question the intentions or consequences behind technical decisions.

These capabilities resemble elements of cybersecurity investigation, technical due diligence, adversarial testing, AI governance and strategic intelligence. They require more than knowing how to write software or operate an AI tool. They require curiosity, scepticism, technical experience and the willingness to investigate what others may overlook.

I have spent more than two decades developing that mindset through real systems, real customers, operational incidents and continuous experimentation. I remain a builder by nature, but I have learned that responsible building requires an equally strong instinct for defence.

In the AI era, creating something powerful is only half the responsibility. Understanding how that power could be misused is the other half.

Perhaps Every Organisation Needs Someone Who Thinks Like a Spy

Sometimes, I wonder whether the future of technology will require a different kind of professional. Not necessarily another software engineer, cybersecurity specialist or AI consultant, but someone who approaches technology with the curiosity of an investigator, the imagination of a strategist and the instincts of a builder.

Imagine a character in a corporate thriller. He walks into a room where everyone is celebrating the successful deployment of an intelligent system. The executives are impressed by its efficiency, the developers are proud of its architecture, and the employees are delighted that their workload has become lighter. Yet while everyone is admiring what the system can do, one person quietly asks a different question: What else could this system be doing that nobody has thought to examine?

Perhaps that is the kind of character I find fascinating. Someone who understands how systems are constructed because he has spent years building them. Someone who recognises weaknesses because he has experienced failures. Someone who can think like an attacker without becoming one, and defend like an engineer without assuming that every system is secure.

In the movies, such characters often work in intelligence agencies, investigating threats that remain invisible to ordinary observers. In the real world, the challenges may be less dramatic, but the underlying mindset is remarkably similar. The ability to notice unusual patterns, question convenient assumptions and imagine what might happen behind a perfectly functioning interface could become increasingly important as artificial intelligence grows more autonomous.

I sometimes think that if I had chosen a different career, I might have enjoyed being a technology detective. Fortunately, building software and businesses for more than two decades has provided enough mysteries of its own.

And perhaps, somewhere in the corporate world, there are challenges that need precisely this unusual combination of curiosity, technical experience and imagination.

After all, the most dangerous weakness in a system may not be the one that everyone can see. It may be the one nobody has thought to look for.

Dream It. Execute It. Ground It.

Build with imagination. Defend with intelligence.

Ts. Lukas J. Tan
Founder & CEO, OPERION Ecommerce & Software Sdn Bhd
Technology Builder | Digital Transformation | AI Systems & Governance

Insights · 2/40 07 Oct 2026

Why Storytelling May Be One of the Most Powerful Ways to Teach Children About Online Scams

Introduction

Throughout history, stories have always been one of humanity’s most powerful tools for education. Long before formal classrooms, textbooks, or digital learning platforms existed, knowledge was passed from one generation to another through stories. Parents shared life lessons with their children, elders passed down wisdom through storytelling, and communities preserved important values by remembering memorable characters and meaningful experiences. Although technology has transformed the way we communicate today, one thing has remained remarkably consistent — people still remember stories far better than instructions.

This simple observation became one of the guiding philosophies behind ScamAlert Junior™. As digital scams become increasingly sophisticated and children spend more time interacting with technology, I began asking a different question. Instead of focusing only on how to explain scams, perhaps we should first consider how children actually learn. Children rarely remember long lists of rules or complicated technical explanations. They remember characters they admire, conversations that make them think, and stories that make them feel something. If we truly want to prepare the next generation for a safer digital future, then perhaps the most effective lesson does not begin with a warning. It begins with a story.

Children Remember Characters More Than Rules

Every parent and teacher has experienced the same situation. A child may struggle to remember a classroom lesson taught just a few weeks ago, yet they can accurately recall the name of a favourite cartoon character, a memorable scene from a movie, or a comic book dialogue they read months earlier. This is not because children dislike learning. It is because the human brain naturally remembers information that is connected to emotions, experiences, and relationships.

When education is delivered only as instructions, children often understand what they should do, but they may not fully understand why those actions matter. However, when the same lesson is experienced through a character facing a challenge, children become emotionally involved. They imagine themselves in similar situations, consider different choices, and naturally begin developing judgement alongside the character. Instead of memorising information, they are learning through experience.

This is why educational storytelling has remained effective across generations. A relatable character becomes a trusted companion rather than an authority figure. Children do not feel they are being lectured. Instead, they feel they are joining a journey where every decision carries a lesson. That emotional connection makes the learning process more enjoyable, more memorable, and ultimately more meaningful.

For digital safety education, this approach is particularly valuable because online situations are rarely black and white. Children need to develop judgement rather than simply memorise rules, and stories provide the perfect environment for building that kind of thinking.

Turning Complex Cybersecurity into Everyday Conversations

Cybersecurity is often perceived as a complicated subject filled with technical language, computer systems, and specialised knowledge. Adults frequently associate it with hackers, data breaches, passwords, and corporate security policies. For children, however, these concepts can feel distant and difficult to understand. Yet the risks themselves are already part of their everyday lives.

A child receiving a message from an unknown player during an online game, clicking an attractive advertisement while watching videos, downloading a free application, or sharing personal information on social media are all situations connected to digital safety. The challenge is not introducing technical cybersecurity terminology. The challenge is helping children recognise situations where good judgement is required.

Storytelling makes this possible by translating abstract concepts into familiar experiences. Instead of explaining phishing through technical diagrams, a story can show a character receiving an exciting message that promises an unbelievable prize. Instead of discussing identity theft, children can follow a storyline where someone pretends to be someone they are not. Rather than overwhelming young readers with technical definitions, stories encourage them to pause, observe, ask questions, and think before making decisions.

This approach transforms cybersecurity from an intimidating subject into an accessible conversation that children can understand. It demonstrates that digital safety is not simply about computers. It is about making responsible choices in everyday life.

Learning Together as Families and Communities

One of the greatest advantages of storytelling is that it naturally encourages conversation beyond the pages of a book. Unlike traditional lessons that often end once the classroom session finishes, a meaningful story creates opportunities for children to ask questions, share opinions, and discuss situations with the adults around them. These conversations often become the most valuable part of the learning experience.

When a child reads about a character facing an online scam, parents can ask simple questions such as, “What would you do if this happened to you?” Teachers can encourage classroom discussions about different choices the characters could have made. Grandparents can relate similar lessons using their own life experiences, showing that while technology changes, the importance of honesty, patience, and careful decision-making has always existed.

This collaborative learning environment is particularly important because digital safety cannot be taught by schools alone. Children move constantly between home, school, community activities, and online environments. The messages they receive become stronger when parents, teachers, and caregivers reinforce the same values consistently.

Storytelling provides a common language that everyone can participate in. Instead of discussing complicated cybersecurity concepts, families discuss familiar characters and relatable situations. The conversation becomes less about technology and more about trust, responsibility, communication, and good judgement. These are lessons that extend well beyond digital safety and contribute to lifelong character development.

Building Critical Thinkers Instead of Teaching Fear

Many awareness campaigns rely heavily on fear to capture attention. Images of cybercrime, alarming statistics, and warnings about online dangers certainly remind people that risks exist. While these approaches may be effective in raising awareness, they do not always build confidence. In some cases, excessive fear may even discourage children from asking questions because they worry about making mistakes or being criticised.

My belief has always been that education should empower rather than frighten. The objective is not to convince children that the internet is dangerous or that technology should be avoided. The goal is to help them become confident users who know how to think carefully before acting. Confidence grows when children understand how to recognise warning signs, verify information, seek advice, and make responsible decisions independently.

This philosophy influenced every aspect of ScamAlert Junior™. The stories are intentionally designed to encourage curiosity instead of anxiety. Characters are allowed to make mistakes because mistakes become valuable learning opportunities. Rather than portraying digital threats as unbeatable dangers, the stories demonstrate that observation, teamwork, communication, and critical thinking often lead to better outcomes.

Children who develop these habits early are not simply learning how to avoid scams. They are developing a mindset that helps them evaluate information, question assumptions, and make thoughtful decisions throughout their lives. In many ways, these skills become even more valuable than the specific cybersecurity lessons themselves.

Conclusion

Technology will continue changing at an extraordinary pace. Artificial intelligence, immersive digital experiences, smart devices, and new communication platforms will introduce opportunities that today’s children will naturally embrace throughout their lives. Alongside these opportunities, however, new forms of scams, misinformation, and digital manipulation will continue emerging in ways that we cannot yet fully predict.

Preparing children for this future requires more than teaching them today’s online threats. It requires helping them develop timeless skills that remain valuable regardless of how technology evolves. Critical thinking, empathy, observation, responsible communication, and the confidence to ask questions will always be among the strongest forms of digital protection.

That is ultimately why storytelling remains such a powerful educational tool. Stories create emotional connections that information alone cannot achieve. They transform lessons into experiences, characters into mentors, and reading into meaningful conversations that continue long after the final page has been turned.

ScamAlert Junior™ was built upon this belief. Not simply to entertain children, and not merely to warn them about online scams, but to help them become thoughtful, responsible, and confident digital citizens who understand that the best protection often begins with one simple habit: think before you click.

Insights · 3/40 05 Oct 2026

Meet the Seven Characters Behind ScamAlert Junior™ — Every Character Has a Purpose

By Ts. Lukas J. Tan — Founder of ScamAlert Junior™ | CEO of OPERiON | AI & Digitalisation Strategist

Introduction

When people first hear about ScamAlert Junior™, many naturally assume it is simply a children’s comic with a few interesting characters. In reality, every character within the ScamAlert Junior™ universe was created with a very specific educational purpose. None of them exists merely to make the story more entertaining or colourful. Each personality, behaviour, strength, weakness, and interaction was intentionally designed to reflect the different ways children learn, communicate, make decisions, and solve problems in everyday life.

As someone who has spent many years working in digital transformation, technology, and cybersecurity awareness, I have learned that education is rarely effective when people feel they are being lectured. Children, in particular, connect with people rather than information. They remember personalities before they remember rules. They remember conversations before they remember instructions. Most importantly, they remember characters they admire. That understanding became one of the guiding principles behind the creation of ScamAlert Junior™. Instead of building superheroes with extraordinary powers, we created ordinary characters with extraordinary values. Together, they form a learning ecosystem that encourages observation, curiosity, empathy, responsibility, and critical thinking while helping children navigate an increasingly digital world.

Every Character Represents a Different Way of Learning

Children are wonderfully different from one another. Some are naturally curious and adventurous, while others are careful observers who prefer to think before acting. Some enjoy asking many questions, while others quietly analyse situations before speaking. As educators and parents, we often discover that there is no single teaching approach that works for every child. This realisation became the foundation for designing the ScamAlert Junior™ characters.

Rather than creating multiple characters who behave in similar ways, we intentionally developed personalities that reflect different learning styles and decision-making approaches. Lukas represents calm thinking and careful observation. Leo demonstrates curiosity, enthusiasm, and learning through experience. Lynn reminds children that paying attention to small details can often prevent bigger problems later. Each child character contributes a different perspective whenever challenges arise, showing readers that there is rarely only one correct way to approach a problem.

This diversity is important because children often identify with different personalities. One child may see themselves in Lukas, while another feels more connected to Leo’s adventurous spirit or Lynn’s thoughtful nature. By creating relatable personalities instead of perfect heroes, the stories become more authentic. Children begin learning not because they are told to imitate someone, but because they naturally recognise parts of themselves within the characters.

Behind Every Child Is a Family That Shapes Good Decisions

While children are the centre of the ScamAlert Junior™ stories, they do not grow or learn in isolation. Families play an equally important role in shaping values, judgement, communication, and responsible behaviour. That is why the ScamAlert Junior™ universe extends beyond children to include positive adult role models who reflect the importance of family guidance in the digital age.

Johan represents responsible fatherhood through integrity, leadership, and accountability. Rather than solving every problem for his children, he encourages them to think carefully and make responsible decisions. Lina represents compassionate parenting through patience, trust, and open communication. She demonstrates that meaningful conversations often build stronger relationships than strict rules alone. Completing the family guidance is Atuk Hassan, whose wisdom bridges traditional life values with modern technology. Through his experiences, children learn that while digital tools continue changing, honesty, kindness, respect, and good judgement remain timeless principles.

These adult characters are intentionally portrayed as mentors rather than authority figures. They listen before judging, guide before correcting, and encourage discussion rather than fear. In doing so, they model the kind of supportive relationships that help children develop confidence to ask questions, admit mistakes, and seek help whenever they encounter uncertainty online.

Turbo — Turning Digital Safety Into Fun

Every memorable educational brand has a character that immediately captures attention and creates emotional connection. For ScamAlert Junior™, that role belongs to Turbo, the official mascot of the intellectual property. Turbo was never intended to replace the educational role of the human characters. Instead, he complements them by bringing energy, humour, curiosity, and excitement into every learning experience.

Children naturally respond to mascots because they communicate through expressions, actions, and emotions that transcend age and language. Turbo celebrates achievements, encourages teamwork, and reminds children that learning can be enjoyable. Whether he is cheering on his friends, holding a ScamAlert Junior™ book, guiding children through activities, or simply making readers smile, Turbo reinforces positive behaviour without making education feel like a classroom lesson.

Beyond the stories themselves, Turbo also plays an important commercial role. As the official mascot, he has been designed to appear consistently across books, activity materials, school programmes, exhibitions, merchandise, digital applications, and future animation projects. His bright appearance, expressive personality, and friendly behaviour make him instantly recognisable while helping children associate digital safety with confidence rather than fear. Sometimes, a simple smile can become one of the strongest educational tools.

Building an Educational Character Universe for the Future

Many successful children’s stories begin with memorable characters, but relatively few are designed from the beginning as long-term educational intellectual property. From the earliest planning stages of ScamAlert Junior™, I wanted to build something that could continue growing beyond a single publication. That required thinking not only about storytelling, but also about consistency, educational philosophy, commercial sustainability, and future development.

Every official character now has a comprehensive Character Asset Library that documents appearance, personality, behaviour, communication style, educational role, expressions, poses, costumes, colour standards, props, and approved commercial usage. This level of documentation ensures that regardless of whether the characters appear in comics, animation, classroom resources, mobile applications, games, or licensed merchandise, they remain faithful to their original identity and educational mission.

Building a character universe is not simply about creating recognisable illustrations. It is about creating trust. When children repeatedly encounter the same positive personalities across different learning environments, those characters become familiar companions who reinforce the same values over time. This consistency strengthens both educational outcomes and long-term brand recognition while allowing the intellectual property to expand responsibly into new platforms and future opportunities.

Conclusion

At its heart, ScamAlert Junior™ is not a story about superheroes defeating villains. It is a story about ordinary people making extraordinary decisions through observation, curiosity, kindness, responsibility, and teamwork. Every character was created to represent qualities that children can realistically develop within themselves, reminding readers that courage often begins with asking questions, thinking carefully, and supporting one another.

As technology continues evolving, children will face new digital challenges that previous generations never imagined. While the tools around them will change, the importance of good judgement, empathy, communication, and critical thinking will remain constant. Through Lukas, Leo, Lynn, Johan, Lina, Atuk Hassan, and Turbo, ScamAlert Junior™ hopes to provide children with positive role models they can grow alongside for many years to come.

These seven characters are more than fictional personalities. Together, they represent a shared vision of helping the next generation become thoughtful, confident, and responsible digital citizens—one story, one conversation, and one meaningful lesson at a time.

Meet the Characters in the Book

Lukas, Leo, Lynn, Johan, Lina, Atuk Hassan and Turbo are waiting for your child inside the ScamAlert Junior™ book. Give them stories that teach them to pause, ask questions and talk to the people they trust.

Buy the ScamAlert Junior™ book here →

Insights · 4/40 05 Oct 2026

AI Is Not Replacing Humanity. We Are Slowly Giving Up the Habit of Thinking.

Synopsis

For years, the debate around artificial intelligence has been framed as a question of replacement. Will AI take our jobs? Will AI become more intelligent than us? Will machines eventually make human beings unnecessary?

I increasingly believe that this framing misses the more immediate problem. The greatest danger may not be that artificial intelligence becomes too powerful. It may be that human beings become too comfortable relying on it.

What concerns me today is not a distant science-fiction future in which machines suddenly seize control. What concerns me is what I can already see in ordinary business life: websites that look almost identical, presentations that use the same language, founders who describe entirely different products with the same vocabulary, and companies that appear to be outsourcing not only production, but judgement.

Artificial intelligence was supposed to increase our ability to create, analyse and execute. Yet if we are not careful, it may also encourage a generation of professionals to stop questioning, stop editing and eventually stop forming their own point of view.

The problem is therefore not simply whether AI will replace humans. The more uncomfortable question is whether humans are slowly learning to replace their own thinking.

I Began Noticing It in Websites

I have spent a large part of my professional life building websites, software systems, digital platforms and businesses. Because of that background, when I look at a website, I rarely judge it only by whether it looks modern, clean or attractive. I instinctively look at the thinking behind it. I notice how information has been prioritised, how the company explains itself, whether the customer journey makes sense, whether the wording reflects a genuine understanding of the market, and whether the design decisions actually support the business objective.

Over the last few years, however, I began to notice a pattern that became increasingly difficult to ignore. More and more websites started to feel strangely familiar. The logos were different. The industries were different. The colours had changed. Yet the structure was often almost interchangeable.

There would be a large hero section with an ambitious statement, followed by three or four rounded boxes. After that came a benefits section, then a feature section, then another row of cards, followed by perhaps a coloured gradient, some statistics, a frequently asked questions section and finally another call to action that repeated almost exactly what had already appeared at the beginning.

At first, I assumed that this was simply the result of contemporary design trends. Every era has its own visual language, and websites have always copied successful conventions from one another. But when I started reading the content carefully, another pattern emerged. The same point was often being made repeatedly in different forms. A promise introduced at the top appeared again in the benefits section, then once more in the feature section, then again near the bottom of the page.

The website looked polished, but it did not feel edited. It felt assembled.

That distinction matters.

A good website should not merely contain information. It should reflect decisions. Someone should have decided what matters most, what can be removed, what should be said only once, what deserves emphasis and what does not need to exist at all. Increasingly, I am seeing websites where those decisions appear not to have been made.

AI Is Very Good at Producing Completeness

One of artificial intelligence's greatest strengths is also one of its weaknesses. It is exceptionally good at producing something that feels complete.

Ask an AI system to create a website structure and it will rarely leave you with too little. It will give you a hero section, benefits, features, testimonials, process, use cases, FAQs and a closing call to action. Ask it to produce a proposal and it will supply context, objectives, methodology, milestones, deliverables and expected outcomes. Ask it to create a presentation and it will usually generate a neat sequence of problem, solution, framework, value proposition and next steps.

This completeness is useful. It saves time and reduces the friction of starting from nothing. But completeness can also create the illusion that the work is finished.

It is not.

The important work often begins after the generation.

An experienced human editor will remove repetition. A founder who understands the business deeply will recognise when a sentence sounds impressive but says very little. A designer with judgement will decide that six boxes should become three. A strategist will notice that a fashionable phrase is technically correct but inappropriate for the audience.

AI can provide material, but it does not automatically provide restraint.

The problem begins when people confuse generated completeness with finished quality.

What Worries Me Is the Surrender of Judgement

I am not opposed to artificial intelligence. Quite the opposite. I use it extensively, and I believe it is one of the most powerful productivity technologies available to us.

It can accelerate research, shorten development cycles, assist with coding, improve analysis, generate alternatives, organise information and help small teams perform work that previously required far greater resources. For entrepreneurs and SMEs in particular, this is transformative. A small business can now access capabilities that were once available mainly to large organisations with dedicated teams.

Yet there is an important difference between using AI as leverage and allowing AI to become a substitute for judgement.

That difference is becoming increasingly important because the modern workflow is dangerously easy. A business owner can ask AI to write a website, copy the result and publish it. A team can ask AI to prepare a proposal, change the company name and send it. A founder can ask AI to create a presentation, adjust the colours and present it to a customer.

Technically, the work is done. But intellectually, very little may have happened.

When this becomes normal, the human role gradually changes. Instead of thinking, shaping, challenging and deciding, the person becomes an operator who accepts or lightly edits what the machine has already proposed.

That is not efficiency. That is surrender.

Then I Started Hearing the Same Language Everywhere

The visual similarity of websites was only the first sign. The more interesting change appeared in business language.

Over the last few years, certain words have begun appearing with remarkable frequency. Operating System. Revenue OS. Business OS. Core. Centralized Control. Ecosystem. Framework. Engine. Unified Platform. Command Center.

None of these terms is inherently meaningless. Some are useful, and in the right context they describe real systems accurately. I have used some of them myself.

What becomes strange is the scale of repetition.

I have sat through presentations from different technology companies offering completely different products. One may be selling an AI platform, another a productivity tool, another an automation system, another a data solution. Yet the presentation structure often feels almost identical.

A central diagram appears. Something in the middle is labelled "Core". Several functions surround it. Another slide introduces the company's "Operating System". A later slide presents the "Ecosystem". Somewhere there is a "Framework", perhaps followed by an "Engine", a "Layer" or a "Centralized Control" concept.

After seeing this often enough, I began to experience something unexpected: instead of being impressed by the sophistication of the presentation, I became less interested.

The product might still be good. The company might be capable. But the language no longer tells me much about them.

I can see the vocabulary, but I cannot see the founder.

The More Intelligent Everyone Sounds, the Less Meaning Intelligence Carries

Artificial intelligence has made professional language dramatically more accessible. Someone who is not a natural writer can now produce elegant copy. Someone unfamiliar with presentation design can create polished slides. A small software company can describe itself using language that once belonged mainly to large consulting firms.

This democratisation is useful, but it also creates an unexpected consequence.

When everyone can sound strategic, strategic language becomes less distinctive.

When every proposal is polished, polish stops proving competence.

When every founder can produce sophisticated terminology, sophisticated terminology stops proving depth.

The result is that the market gradually begins to value something else: evidence of original thought.

A founder who has spent years solving a difficult problem tends to speak differently from someone who has only researched it. A builder who has implemented real systems usually talks differently about trade-offs, failure and limitations. Someone who has actually struggled through a business problem will often describe it with imperfect but highly specific language.

Experience leaves fingerprints.

Those fingerprints matter because they make a person credible.

Artificial intelligence, if used carelessly, can polish those fingerprints away.

AI Should Amplify Identity, Not Flatten It

I have long believed that AI amplifies what is already there.

When someone has strong experience, AI can help organise and extend that experience. When someone has good judgement, AI can help test alternatives. When someone has discipline, AI can make that person dramatically more productive. When someone is already a builder, AI can increase the speed at which ideas become systems, products and results.

But the reverse is also true.

If someone has no point of view, AI can amplify generic thinking. If someone does not understand the customer, AI can produce language that sounds persuasive but lacks insight. If someone has not developed judgement, AI can provide twenty alternatives without helping that person understand which one deserves to survive.

This is where the deeper risk of standardisation appears.

Artificial intelligence is trained on patterns, and therefore it is naturally good at producing plausible patterns. If millions of professionals rely heavily on those patterns without introducing enough of their own thinking, the output of the market will gradually converge.

More companies will become competent.

More websites will look professional.

More proposals will sound intelligent.

More presentations will appear strategic.

But more of them may also become interchangeable.

That is not progress if we lose identity along the way.

The Real Risk Is Not That Machines Become Human

Much of the public discussion about AI still revolves around machine consciousness. We imagine a future in which artificial intelligence becomes independent, develops intentions and eventually challenges human control.

That possibility receives attention because it is dramatic.

But a quieter and perhaps more immediate transformation is already happening.

AI does not need to become conscious if human beings become dependent.

There is a natural progression in how we use these tools. At first, we ask for assistance. We ask AI to help us write, summarise or improve something. Then we begin asking it what we should say. Later, we may ask what we should do. Eventually, without noticing the shift, we may begin asking what we should think.

That final transition matters enormously.

The distinctive human capacity is not merely the ability to produce text or create designs. Machines are already becoming very capable at those tasks. The more valuable capability is the ability to question assumptions, disagree with consensus, reject attractive nonsense and make decisions under uncertainty.

If we surrender that capacity, then AI does not need to defeat us.

We have voluntarily given away the most important part.

I Now Look for Evidence of Human Thinking

This has changed the way I evaluate work.

When I look at a presentation today, I am no longer impressed simply because it is polished. In fact, when the deck looks too familiar, I become more cautious.

I start asking different questions.

Does the language reflect something this company genuinely believes? Does the diagram actually describe how the product works? Can the founder explain why they chose this approach? Is there anything in the presentation that could only have come from their own experience? Is there a point of view here, or merely a collection of professionally arranged statements?

These questions matter because a presentation is not only communication. It is evidence of thinking.

When someone presents a company, I want to understand how they see the world. I want to know what they have noticed that others missed, what assumption they disagree with, what problem they understand unusually well and what difficult decision they have made.

I do not need every sentence to sound perfect.

In fact, sometimes imperfect language reveals more truth than polished language.

Human Judgement May Become the Scarce Resource

The cost of production will continue to fall. Websites will become cheaper to build. Videos will become easier to produce. Code will become faster to generate. Presentations, reports, marketing materials and research will become increasingly accessible.

As production becomes abundant, production itself becomes less valuable.

Judgement becomes scarce.

The person who can look at ten generated ideas and confidently reject nine will become valuable. The person who can distinguish between a clever sentence and a useful insight will become valuable. The person who can look at an attractive website and recognise that it does not solve the customer's problem will become valuable. The person who can remove half the content because the remaining half is stronger will become valuable.

Most importantly, the person who can tell AI, "This is not how I think," will become valuable.

That is why I do not believe the future belongs simply to people who know how to use AI. Eventually, almost everyone will know how to use it.

The advantage will belong to people who retain enough judgement to use it without becoming shaped by it.

We Should Build More With AI, Not Think Less Because of It

I want AI to help people build more ambitious businesses. I want it to help SMEs compete with much larger organisations. I want entrepreneurs to move faster, experiment more cheaply and create products that would previously have been beyond their resources.

That is the extraordinary promise of this technology.

But that promise depends on maintaining a distinction between assistance and authority.

AI should help us execute faster, but it should not become the owner of our convictions. It should help us explore ideas, but it should not become the source of our identity. It should help us see possibilities, but it should not remove our responsibility to choose among them.

This is why I continue to return to a simple principle in my own work: Dream It. Execute It. Ground It.

The dream must still come from a human understanding of what could exist. Execution can increasingly be accelerated by machines. But grounding — deciding what is useful, what is real, what is appropriate, what deserves trust and what should be rejected — remains a profoundly human responsibility.

The real threat of AI may therefore be much less dramatic than the stories we have imagined.

It may not arrive as a machine announcing that humanity is obsolete.

It may arrive quietly, through thousands of small decisions in which we stop questioning, stop editing, stop disagreeing and stop forming our own conclusions.

AI does not need to destroy humanity.

It only needs humanity to become comfortable enough to stop thinking for itself.

Insights · 5/40 03 Oct 2026

Use AI to Replace Me: Why Real Breakthrough Begins When We Dare to Make Ourselves Obsolete

Synopsis

For years, the conversation around artificial intelligence has been remarkably predictable. We are told to use AI to save time, automate repetitive work, improve productivity, reduce operating costs, and free ourselves to focus on “higher-value activities.” None of this is wrong. In fact, businesses have been pursuing the same objectives through software, digitalisation and automation for decades. What has changed is the scale of what AI can now do. If our thinking remains limited to saving a few hours of work, we are underestimating the technology. I believe the more important question is no longer, “How can AI help me?” It is, “How much of me can AI replace?” If you are satisfied with protecting your current role, maintaining your present way of working, and avoiding disruption, this article may not be for you. This argument is meant for people who want to break through, even when that breakthrough requires them to dismantle parts of themselves that once made them successful.

1. The AI Conversation Has Become Too Comfortable

Much of today’s AI discussion is still based on an efficiency mindset. A company introduces AI so that employees can prepare reports faster, respond to customers more quickly, automate administrative work, or generate content in less time. The organisation celebrates because a task that previously required three hours can now be completed in thirty minutes. That is useful, but it is not yet transformation. The more disruptive question is what happens after we discover that a three-hour task only requires thirty minutes. Should the task continue to be structured in the same way? Should the same job description remain unchanged? Should the same number of people still be assigned to the same process? Should the same service continue to command the same price simply because that was how the industry operated in the past? AI forces us to confront uncomfortable questions because it does not merely make an existing process faster; it can make parts of that process unnecessary. This is why I believe we need to move beyond the language of productivity and begin discussing replacement, redesign and reinvention.

2. I Want AI to Replace What I Do Today

My personal approach is deliberately aggressive: I want to identify everything I currently do and determine how much of it can be replaced by AI, automation, software agents, knowledge systems or better processes. If I make ten decisions every day, I want to know whether five of them can be systemised. If I repeatedly answer the same questions, I want that knowledge captured so that people no longer need to wait for me. If I perform routine analysis, prepare documents, follow up with people, monitor progress or coordinate information manually, I want to know whether those activities can be handled without my direct involvement. The objective is not to make myself slightly more productive. The objective is to remove myself from work that no longer requires me. Many people are uncomfortable with this idea because their sense of professional value is closely connected to being needed. I see it differently. If a machine can take over something I currently do, then that activity should no longer be the foundation of my value. I would rather discover this myself than wait for a competitor, a younger generation, or a future technology to discover it for me.

3. There Is Value in Reaching the Point Where You Have Nothing Left to Do

One of the greatest fears surrounding AI is the possibility that people may eventually have less work to do. I understand that concern, particularly at a societal level, but at the level of personal growth I see another possibility. What happens when everything familiar has been taken away? What happens when the skills, routines and responsibilities that once occupied your entire day are no longer necessary? That moment can feel like a low point, but low points have an unusual ability to force human beings to change. When life is comfortable, there is little pressure to reinvent ourselves. When the old path disappears, however, we are forced to search for another one. I have always believed that some of the strongest growth comes after difficult falls. The deeper the fall, the more powerful the potential rebound can become, provided the person is willing to learn and rebuild. In that sense, I do not necessarily want AI to protect me from disruption. I want it to expose where I have become comfortable, where I have become dependent on yesterday’s strengths, and where I need to grow again.

4. Success Can Become a Trap When We Try to Preserve It Forever

People naturally want to protect what made them successful. A professional develops expertise and wants to preserve it. A company discovers a profitable business model and tries to extend it for as long as possible. An entrepreneur builds a process that works and becomes emotionally attached to it. The difficulty is that history does not guarantee relevance. A valuable skill can become a commodity. A premium service can become automated. A complex process can become a feature inside a software platform. A business model that once required a large team can eventually be delivered by a much smaller organisation supported by AI. This is why I do not believe in protecting a “magic sword” forever. No advantage remains permanent simply because it was once powerful. Growth requires the willingness to retire methods that still work before the market forces us to do so. In other words, the real discipline is not only learning new things. It is developing the courage to deliberately make old strengths obsolete.

5. The Higher-Level Role of Humans Is to Build Systems, Not Remain Trapped Inside Them

This principle is particularly important for entrepreneurs and leaders. In the early stages of a business, founders usually do everything themselves. They sell, manage customers, prepare proposals, solve operational problems, supervise employees, make decisions and respond to emergencies. This creates a dangerous psychological association: the more things I personally handle, the more valuable I must be. In reality, as an organisation grows, the opposite can become true. If every important process still depends on the founder, then the founder has become the organisation’s bottleneck. The next stage of leadership is therefore to convert individual capability into systems. Knowledge should become organisational knowledge. Decisions should become frameworks. Repetitive actions should become workflows. Monitoring should become automated. AI agents should be able to perform clearly defined functions within proper boundaries. The leader then moves upward, from doing the work to designing how work is done, and eventually from designing individual systems to designing an architecture of systems. That is where I see one of the most important possibilities of AI: it allows an individual to create and coordinate far more capability than one human being could personally execute.

6. If Machines Continue to Improve, Human Thinking Must Continue to Rise

The same principle becomes even more significant when we look beyond software. AI is increasingly moving into robotics, autonomous systems and physical infrastructure. Over time, the ambition will not simply be to create machines that perform isolated tasks. More advanced systems will increasingly monitor, maintain and coordinate other systems. Robots may assist in producing components used by other robots. Autonomous infrastructure may operate in environments where constant human presence is difficult or impractical. One can imagine future industrial or extraterrestrial environments in which machines draw power from available energy sources, inspect themselves, perform maintenance, manufacture tools and expand operational capacity with limited human intervention. Some people will look at such a future and see something frightening; others will see extraordinary human achievement. Either way, it raises the same philosophical question: if machines can perform an increasing share of execution, where should human value move? My answer is upward. Human beings must become better at defining purpose, creating direction, designing systems, making judgments, establishing governance and imagining possibilities that do not yet exist.

Conclusion: Breakthrough Requires the Courage to Become Obsolete

This is why I no longer find the phrase “use AI to save time so that you can focus on more valuable work” particularly inspiring. It is too safe. It assumes that our existing role should remain intact and that AI should merely make us more efficient within it. I believe we should be far more ambitious. We should use AI to challenge our current relevance. We should identify what can be automated and automate it. We should identify what can be systemised and systemise it. We should remove ourselves from activities that no longer require us and allow that temporary emptiness to force us to think again. The goal is not self-destruction for its own sake. The goal is continuous reconstruction.

My own question is simple: how much of Lukas Tan can I replace with AI today? When that version of me becomes unnecessary, I will have no choice but to create the next version. Then, one day, I should be willing to replace that version too. To me, this is what genuine growth looks like. We do not protect one version of ourselves forever. We repeatedly build, challenge, dismantle and rebuild.

That is also the kind of conversation I want to bring to organisations, businesses, universities and communities. I am not interested only in demonstrating the latest AI tools or teaching people how to complete yesterday’s work faster. Through my entrepreneurial journey, technology experience, failures, reinventions and the systems I continue to build, I want to challenge people to reconsider what makes them valuable in the first place.

If your organisation is looking for a conventional AI presentation, there are many people who can deliver one. But if you want a sharing session that challenges people to rethink their comfort zones, their careers, their organisations and the value of their own existence in an AI-driven world, that is a conversation I would be interested in having.

Because perhaps the most important question of the AI era is not how we can avoid being replaced.

It is whether, after everything replaceable has been taken away, we are capable of creating a stronger version of ourselves.

Insights · 6/40 03 Oct 2026

In the AI Era, Waiting Can Be More Expensive Than Failing

Synopsis

Many business owners today are not rejecting AI, digitalisation, or technology investment. What they are really struggling with is uncertainty. They are asking whether the system they build today will still be useful two years from now, whether AI will replace the functions they are investing in, and whether a RM20,000 or RM100,000 technology project will still make sense after the next wave of innovation arrives. I understand this concern because I have faced it myself. I have invested in systems, tested ideas, and spent months developing technology that I later decided not to continue. Yet those experiences taught me something important: in the AI era, waiting for perfect certainty can become more expensive than making a controlled mistake. The answer is not to take reckless risks. The answer is to take smaller, calculated risks, learn from them, and keep moving.

Why Business Owners Are Hesitating

The hesitation I see today is not because business owners do not want to improve. In many cases, they are very aware that AI is changing the business environment. Their real concern is whether they are investing at the right time. A business owner may look at a proposal and immediately ask whether the technology will still be relevant in three years, whether something better will appear next year, or whether the entire system may need to be rebuilt after a new AI capability becomes available. These are reasonable questions because technology is evolving much faster than before. The difficulty is that there may never be a perfect moment when all the answers become clear. If a company keeps waiting for the technology to stabilise, it may eventually discover that the market has moved on while the company is still evaluating.

I Have Paid for the Wrong Technology Decisions Too

I am not writing this from the perspective of someone who always makes the right decisions. I have made expensive mistakes and invested in systems that did not continue the way I originally expected. One of the clearest examples came from an exhibition project where we needed to process a large amount of data. We needed to scrape information, organise records, analyse leads, perform outreach, and manage follow-up. Instead of depending entirely on manual work, we decided to build an application to manage the process. Programmers worked on the system for approximately twelve months, and the project gradually became more complex. If I estimate the manpower and development investment at close to RM15,000 per month, the total exposure was approaching RM180,000. After the event, however, I had to decide whether continuing to develop the same system was still the right direction.

The Hardest Part Is Knowing When to Stop

When a company has already invested a large amount of money, the natural reaction is to continue. Management starts thinking about the time spent, the development cost, the people involved, and the fact that so much work has already been completed. Walking away can feel like admitting failure. However, previous investment does not automatically justify future investment. By the time we reviewed the system, AI had advanced significantly and new approaches were becoming possible. We could see that parts of the system we had built in a traditional way might be redesigned more efficiently with AI-driven workflows. The existing system could still function, but that was no longer the most important question. The more important question was whether continuing to invest in it would still move us toward the best future position. In the end, I decided that it would not.

Not Every Failed Investment Is Completely Wasted

From a purely financial perspective, someone could say that the RM180,000 was wasted. The original system did not continue in the way we first planned, and the long-term return was not what we expected. However, from an entrepreneurial perspective, I do not see the experience as completely wasted. Because we built the system, we learned how the entire process worked in reality. We understood where scraping became difficult, where data quality broke down, where automation became unreliable, where human intervention was still necessary, and where the architecture became too rigid. We also learned what we should not build again. Without that experience, I might still be sitting here today believing that the original approach was correct. Sometimes the value of an experiment comes from proving that a direction should not continue.

Some Answers Only Appear After You Try

I have experienced the same thing with smaller experiments. At one point, I considered using AI-generated digital humans for short-form video content. I thought about it for months before finally trying it. Once I tested it, I realised that the result did not fit the way I wanted to communicate, the style of my personal brand, or the authenticity I wanted the content to have. That experiment gave me an answer that observation alone could not provide. I did not need to keep wondering whether I should use the technology. I had tested it, understood its limitations, and moved on. This is why direct experimentation matters. You can attend conferences, watch competitors, speak to consultants, and study trends, but some business answers only become clear after you use the technology in your own environment.

The Hidden Cost of Doing Nothing

Waiting feels safe because the cost appears to be zero. If a company does not spend RM20,000, the money remains in the bank. If it does not build a system, there is no development failure. If it does not test a new AI platform, there is no risk of choosing the wrong one. However, the cost of inaction is usually hidden. A company that waits for one year may also lose one year of learning, one year of process improvement, one year of staff development, and one year of understanding how AI can or cannot help the business. It may also lose the opportunity to make small mistakes while the cost of those mistakes is still manageable. The money that was not spent is easy to see, but the capability that was never developed is much harder to measure.

A Practical AI Action Plan for SMEs

For SMEs, I do not believe the starting point should be a massive AI transformation programme. The first step should be to identify one business problem that is already costing the company time, money, manpower, or missed opportunities. It may be slow quotation preparation, repetitive customer enquiries, manual reporting, lead follow-up, document processing, internal knowledge search, or data entry. Start from the business pain, not from the AI tool. Once the problem is clear, choose one small experiment that can be completed within a defined budget and time frame. An SME should be able to answer three questions before starting: what problem are we solving, how much are we willing to risk, and what evidence will tell us whether the experiment is working?

The second step is to place a ceiling on the experiment. A company that is uncertain about a RM100,000 project should not begin by signing a RM100,000 commitment. It can begin with a RM2,000, RM5,000, or RM10,000 pilot, depending on the size of the business. The experiment should be narrow enough that failure will not damage the company, but meaningful enough that management can learn something from the result. Give the test thirty, sixty, or ninety days. Measure whether it saves time, reduces manpower, generates leads, improves customer response, or produces better information. At the end of the test, management should make a deliberate decision to stop, improve, or scale.

The third step is to keep what works and remove what does not. SMEs do not have the luxury of maintaining technology simply because management is emotionally attached to it. If the experiment works, expand it gradually. If it only works partially, redesign the weak areas. If it does not work, stop and record what was learned. The objective is not to prove that every AI project succeeds. The objective is to make each experiment improve the next decision. Over time, a company builds not only technology, but internal judgment about what AI can genuinely do for the business.

Risk-Taking Should Be Controlled, Not Reckless

For me, risk-taking has never meant gambling. It means entering uncertainty with a clear limit on what I am willing to lose and a clear idea of what I want to learn. Before making an investment, I still look at the downside, question whether there is a cheaper option, and ask whether the technology is mature enough. But there comes a point when analysis must become action. If the risk is small enough and the potential learning is meaningful enough, I would rather test the idea than spend years wondering whether it might have worked. Good risk-taking also requires the discipline to stop when the evidence says the direction is wrong.

Moving Forward Without Perfect Certainty

The AI era is unlikely to give business owners the certainty they are looking for. New models will continue to appear, platforms will continue to change, and business processes will continue to evolve. The companies that perform well may not be the ones that predict every technology correctly. They may simply be the companies that are willing to test earlier, learn faster, stop bad ideas sooner, and scale good ideas with greater confidence.

My own approach has always been to move, learn, adjust, and move again. I do not believe every business needs to take a large risk, but I do believe every business should take some risk that it can afford to learn from. For SMEs, that may mean starting with one problem, one team, one process, and one manageable budget. The objective is not to become an AI company overnight. The objective is to develop the ability to experiment, make better decisions, and adapt before change becomes unavoidable.

In the AI era, the danger is not only making the wrong move. The greater danger may be spending so long waiting for the perfect move that the organisation never develops the experience required to make the next one.

Insights · 7/40 30 Sep 2026

The Biggest AI Mistake Businesses Are Making: Automating Before Redesigning

Synopsis

Artificial intelligence is making it easier than ever for businesses to automate reports, summarize emails, analyze data, generate documents, monitor operations and deliver information instantly. Yet there is a growing danger hidden inside this convenience: companies may become faster without becoming better.

The biggest mistake businesses can make in the AI era is to take an outdated business process and simply add AI on top of it.

If a company still operates through the same meetings, approvals, emails, spreadsheets, reports and information flows it used ten years ago, adding AI will not necessarily transform the business. In many cases, it will simply accelerate the existing process. The company may receive information faster, produce more reports and automate more tasks, yet management may still spend the same amount of time reading, checking, responding and making decisions.

Real AI transformation begins before automation. It begins by redesigning how work should flow in the first place.

AI Can Make a Bad Process Faster

There is a dangerous assumption emerging in many organisations: if a process is automated, it must have improved.

That is not necessarily true.

Imagine a company where management receives twenty reports every week. Before AI, employees spend hours preparing those reports manually. After introducing AI, the same twenty reports can be generated automatically within minutes.

From a technology perspective, this looks like progress. The company has saved manpower and reduced preparation time. But there is another question that is far more important: does management still need to read all twenty reports?

If the answer is yes, then the company has automated report production without redesigning decision-making.

The bottleneck has simply moved.

Before AI, employees were overloaded with preparing information. After AI, executives may become overloaded with consuming information.

That is not transformation. It is faster information production.

Information Is Not the Same as Intelligence

AI makes information extremely cheap to produce.

A company can now generate daily summaries, weekly dashboards, customer reports, operational updates, market intelligence, sales analyses, meeting notes and recommendations almost automatically.

This sounds powerful, but more information does not automatically produce better decisions.

In fact, when organisations are not disciplined about how information reaches people, AI can make the situation worse. Managers may wake up every morning to ten automated reports, dozens of notifications, several dashboards and multiple AI-generated summaries.

Each report may be useful individually. Together, they can create a new form of corporate noise.

The purpose of AI should not be to make humans read faster. The purpose should be to reduce the amount of unnecessary information humans need to process in the first place.

True intelligence is not about showing decision-makers everything. It is about ensuring that the right person sees the right thing only when a human decision is genuinely required.

The Email Example Reveals the Problem

Email is one of the easiest examples.

Many people proudly say that they use AI to organize their inbox. The AI categorizes messages, summarizes long email threads, highlights important emails and prepares suggested replies.

This is certainly useful.

But it is still solving the problem at the surface level.

Imagine receiving 300 emails a day. AI may successfully classify those emails into categories and tell you that only 20% are important. That sounds impressive until you realize that you still have 60 important emails to review.

The better question is not, "How can AI help me read my email?"

The better question is, "Why does so much of my business depend on email in the first place?"

Perhaps internal approvals should happen inside a workflow system. Customer service issues may belong inside a ticketing platform. Sales activities should be recorded in a CRM. Project updates may belong inside a project management system. Routine operational information may not need to reach management at all unless something falls outside an agreed threshold.

Once the process is redesigned, email becomes the exception rather than the operating system of the company.

That is a much more meaningful transformation.

A Good AI Redesign Should Reduce Human Attention

I believe one of the simplest ways to measure successful AI transformation is not by asking how many tasks have been automated.

Ask how much human attention has been returned.

Suppose a business owner currently checks email from morning until night. After redesigning the workflow and introducing AI, the owner only needs to review email once a day.

That is progress.

If the system is redesigned further and the owner only needs to review email every two or three days, that is even better.

If routine communication, approvals, operational updates and internal workflows are handled through properly designed systems, and the owner only needs to review email once a week for exceptional cases, the organisation has achieved something much more important than email automation.

It has redesigned the way information reaches the leader.

The same principle applies to meetings, reports, customer follow-ups, internal approvals and operational monitoring.

The objective is not to make humans interact with AI more often. It is to reduce the number of unnecessary interactions humans need to have with the business.

Do Not Automate A-to-B-to-C If Humans Are Not Needed

Many traditional business processes look something like this: Department A prepares information and sends it to Department B. Department B reviews it and forwards it to Department C. Department C then consolidates everything into a report before management receives it.

When AI arrives, many companies automate each individual stage.

Department A uses AI. Department B uses AI. Department C uses AI.

The organisation celebrates because everyone is now "using AI."

But the more important question is whether B and C are still necessary steps.

Perhaps the information can move directly from the source system into an automated workflow. Perhaps validation can happen automatically. Perhaps approval is only required if the transaction exceeds a certain amount. Perhaps management only needs to be notified when a defined exception occurs.

In that case, the correct transformation is not to make A, B and C faster.

The correct transformation may be to redesign A-to-B-to-C entirely.

That is the difference between digital automation and business transformation.

AI Should Manage Exceptions, Not Manufacture Reports

Traditional management relies heavily on reporting because systems were historically unable to understand context.

Managers therefore asked teams to prepare reports so that they could identify what required attention.

AI changes this possibility.

Instead of producing a 30-page report every Monday and expecting management to find the problem, an intelligent system should continuously monitor the underlying data and notify management only when an agreed condition is triggered.

For example, a sales leader may not need a daily report listing every salesperson and every opportunity. The system should instead identify customers who have not been followed up within the agreed period, deals whose probability has changed significantly, unusual declines in conversion, or opportunities above a strategic value threshold.

Management should not be receiving more information.

Management should be receiving more exceptions.

That is a fundamentally different way of designing an organisation.

Start With Process Redesign, Not AI Tools

When businesses discuss AI transformation, conversations often begin with tools.

Should we use ChatGPT? Claude? Gemini? An AI agent? Automation software? An AI CRM?

These questions matter, but they are not the first questions.

The first questions should be operational.

Why does this process exist?

Why does this person need to approve it?

Why does this report need to be produced?

Why does this information need to reach management?

Why are we using email for this?

Why does information travel through three departments before reaching the customer?

Which decisions actually require human judgment?

Which decisions can be governed through clearly defined rules?

Once these questions are answered, the role of AI becomes much clearer.

AI should enter a redesigned organisation with a defined responsibility, not be attached randomly to every existing process.

AI Should Remove Work, Not Decorate Work

There is a difference between using AI and becoming an AI-enabled organisation.

A company may use dozens of AI tools and still operate fundamentally the same way it did before.

Employees generate documents faster. Managers receive better summaries. Reports look more professional. Meetings are automatically transcribed. Emails are drafted instantly.

These are useful improvements, but they can easily become cosmetic productivity.

AI becomes a digital accessory attached to the old organisation.

The deeper opportunity is to remove work.

Remove unnecessary reports. Remove unnecessary meetings. Remove unnecessary approvals. Remove repeated data entry. Remove unnecessary information transfers. Remove human involvement where clear rules already exist.

If AI merely helps employees perform the same twenty steps more quickly, we should question whether twenty steps were necessary in the first place.

The Goal Is Not More AI. The Goal Is Less Friction

The most successful companies in the AI era may not be the companies with the largest number of AI agents.

They may be the companies that require the least unnecessary human effort to operate.

Their leaders are not flooded with dashboards. Employees are not constantly producing reports. Departments are not forwarding information back and forth simply because "that is how we have always done it."

Instead, the company becomes increasingly event-driven.

Normal operations happen automatically.

Systems communicate with systems.

AI monitors patterns.

Workflows execute predefined actions.

Humans enter when judgment, creativity, relationship, negotiation, accountability or strategic decision-making is genuinely required.

That is a far more mature vision of AI.

If AI Is Giving You More to Read, Something May Be Wrong

This leads to a simple test.

After implementing AI, ask yourself:

Do you have fewer things to read?

Fewer meetings to attend?

Fewer reports to review?

Fewer approvals to make?

Fewer routine decisions?

Fewer repetitive conversations?

If the answer is no, your organisation may have introduced AI without redesigning work.

You may be producing information faster while remaining trapped inside the same operating model.

AI should not become another employee who sends the CEO more reports.

It should help redesign the company so the CEO needs fewer reports.

Redesign the Company Before You Automate It

Every organisation considering AI should resist the temptation to automate immediately.

First, map the process.

Then challenge it.

Remove what is unnecessary.

Combine what can be combined.

Move structured work into structured systems.

Define decision thresholds.

Define exceptions.

Define where human judgment is truly necessary.

Only after that should AI be introduced.

Otherwise, businesses risk spending money to automate inefficiency.

AI is extraordinarily powerful, but it cannot compensate for a poorly designed organisation. In fact, because AI can operate at extraordinary speed and scale, it can amplify poor design just as easily as it can amplify good design.

The question is therefore no longer simply, "How can we use AI?"

The more important question is:

"If we were designing this company today, knowing that AI exists, would we still design the process this way?"

For many organisations, the answer will be no.

Call To Action: Stop Automating the Old Company

If your organisation is currently rushing to introduce AI agents, automate email, generate more reports, connect more dashboards or push more information to management, stop for a moment and look carefully at the company underneath the technology.

Do not automate a business process simply because AI can automate it.

Redesign it first.

Challenge every approval, every report, every email, every handover, every meeting and every piece of information that travels through your organisation. Ask what can disappear completely before asking what can be automated.

The companies that win in the AI era will not simply be companies that use AI everywhere.

They will be companies that have redesigned themselves around a new reality: machines can execute, systems can communicate, AI can monitor, and humans should only be pulled into the moments where human judgment genuinely creates value.

If you are serious about AI transformation, do not begin by buying another AI tool.

Begin by looking directly at your company.

Redesign the process. Redesign the information flow. Redesign the decision flow. Redesign the business before AI redesigns it for you.

That is where the real work begins.

Insights · 8/40 27 Sep 2026

A Leaner Model for CSR: Less Resource, Greater Impact

For many years, I thought about Corporate Social Responsibility in much the same way many SME owners probably do. CSR was important, but it also looked expensive. It seemed to require a dedicated budget, people to organise activities, partnerships to coordinate, events to manage, reports to prepare and enough management attention to keep everything moving. Large corporations may have dedicated sustainability or CSR teams to handle this work. An SME usually does not.

This creates an uncomfortable situation. Many SME owners genuinely want to contribute to society, but the business itself is already consuming most of their resources. There are customers to serve, employees to manage, products to improve, sales targets to meet and cash flow to protect. When CSR is designed as another large project sitting on top of all those responsibilities, it becomes difficult to sustain.

I began wondering whether the problem was not CSR itself, but the way we were designing it.

What if a CSR initiative could consume relatively few additional resources while still creating meaningful impact? What if it could use capabilities that already exist inside the company instead of requiring an entirely new operation? What if we could design it once, improve it through experience and repeat it many times? And what if the impact could continue travelling even after our direct involvement ended?

Over time, through our work in scam-prevention education, I began to see a pattern.

I would describe it today as a lean, repeatable CSR model: start with something close to what you already know, reduce the resources required to deliver it, create a repeatable method, allow the beneficiaries themselves to carry the message further, and eventually build content, intellectual property and partnerships around the model so that impact can grow without resources growing at the same rate.

That sounds like business thinking because, in many ways, it is.

And I believe SMEs should apply more of it to CSR.

CSR Should Not Exhaust the Business Creating the Impact

A social initiative is not sustainable simply because its purpose is good. If every activity requires extraordinary effort, large budgets and constant founder involvement, eventually the organisation will struggle to continue it.

This is something entrepreneurs understand instinctively in business. If every customer requires a completely different process, the business becomes difficult to scale. If every sale depends entirely on the founder, there is a bottleneck. If costs increase at exactly the same rate as growth, there are limits to how far the business can expand.

We respond by building systems. We simplify processes. We create templates. We automate where appropriate. We document what works. We turn individual efforts into repeatable operations.

I began asking myself why CSR should be completely different.

The objective should not be to minimise resources simply for the sake of spending less. The objective should be to improve the ratio between resources consumed and impact created.

If ten hours of preparation are required every time we conduct a one-hour activity, can we redesign it so that the preparation is done once and the same framework can be used repeatedly? If every programme requires new materials, can we create reusable materials? If impact stops the moment we leave the room, can we create something that participants take home and share with others?

These questions gradually shaped the way I approached our scam-prevention initiative.

The Starting Point Was Not CSR

Interestingly, I did not begin by deciding that we needed a CSR programme.

I began with a problem that bothered me.

Scams were becoming increasingly visible in Malaysia. Every few days there seemed to be another story about someone losing money through impersonation, fraudulent investments, phishing, fake jobs, fake purchases or social engineering.

Coming from a technology background, I was naturally interested in the digital side of the problem. But the more I studied scams, the more I realised that technology was only one part of the equation.

The tools change, but the human vulnerabilities remain remarkably consistent.

Scammers exploit urgency. They exploit fear, trust, greed, loneliness, curiosity and love. They convince people to act before thinking. Technology makes the message faster, cheaper and increasingly convincing, but the final target is still a human decision.

That led me to a different question: if judgment is one of our defences against scams, why do we wait until adulthood to teach it?

That question eventually brought us into schools.

Initially, the idea was straightforward. We would share scam awareness with students and help them recognise risky situations. But once we began doing the work, I started applying the same questions I would ask when developing a product or business process.

What is the minimum that a child really needs to remember?

What part of the message creates the greatest effect?

What can be removed?

What can be repeated?

What can be standardised?

What can continue after we leave?

Without intentionally setting out to build a CSR framework, we were beginning to create one.

The First Principle: Start Close to What You Already Know

I believe one reason CSR becomes resource-heavy is that businesses sometimes choose initiatives far removed from their existing capabilities.

The company then has to build almost everything from zero: knowledge, content, processes, networks and sometimes even credibility.

For SMEs, I believe there is another approach.

Start close to your existing strengths.

Our company works in technology, software, digitalisation and education. I spend time speaking, training and explaining technology to different audiences. Scam prevention sits naturally beside those capabilities.

That meant we did not need to create an entirely separate organisation before contributing. We could use knowledge, communication skills, technology experience and resources that already existed.

This is the first part of the model:

Use existing capability before adding new resources.

An accounting company could contribute financial literacy. A technology company could contribute digital awareness. A restaurant could contribute food education. A creative agency could help communities communicate. An engineering business might contribute technical or safety knowledge.

Every company accumulates expertise while doing business.

That expertise has social value too.

If CSR begins with something adjacent to what the organisation already knows, the additional resources required can be dramatically lower.

The Second Principle: Reduce the Message to What Actually Matters

When we started thinking about scam education for children, it would have been easy to create a comprehensive programme covering every known category of scam.

But comprehensive does not always mean effective.

Children do not need to memorise 30 types of scams. Even adults cannot keep up with every new technique. The moment we finish teaching today's list, new variations will emerge.

Instead, I began reducing the message to three behaviours:

Slow down. Ask questions. Tell an adult.

If somebody creates urgency, slow down.

If something feels strange or unusually attractive, ask questions.

If someone asks for secrecy, especially around money or an online interaction, tell a parent, teacher or trusted adult.

These three behaviours require very little technical knowledge. More importantly, they remain useful even when the scam changes.

One technique I share is extremely simple: pause for three seconds when someone is pushing you to act immediately.

That tiny pause introduces friction between emotion and action.

Once there is a pause, there is space for a question: Why is this urgent? Why must I do it now? Why can I not tell my parents? Why am I being offered this?

In a world where technology is designed to remove friction from everything—clicking, purchasing, sharing, transferring and responding—sometimes adding a little friction back into a decision is protective.

This became the second principle of the model:

Simplify the intervention until the important part becomes easy to remember and easy to deliver.

Complexity consumes resources. Simplicity travels.

The Third Principle: Build a Repeatable Unit

The next question was operational.

If we wanted to visit schools, we could not reinvent the programme for every school. That would make the initiative dependent on too much preparation and too many people.

So we began thinking in terms of a repeatable unit.

A school. A session. A defined duration. A consistent core message. Reusable materials. A simple operating process.

Then repeat.

Each school still has its own environment and students, of course, but the underlying model does not need to be rebuilt each time.

This sounds obvious, yet I think it represents an important shift in how SMEs can approach CSR.

Instead of thinking only in terms of campaigns, we can think in terms of systems.

A campaign is designed to happen.

A system is designed to happen again.

The distinction is important because social impact often comes from accumulation rather than one spectacular event.

One school may feel small. Twenty schools are no longer so small. Thousands of students reached through a repeatable process begin to represent something meaningful.

The resources required do not need to increase at the same rate as the impact because much of the thinking, content and preparation has already been done.

That is the third principle:

Design one unit of impact that can be repeated without rebuilding the programme every time.

The Fourth Principle: Let Impact Travel Beyond the Direct Beneficiary

This was probably the most interesting part of the model for me.

When we educate one student, have we reached one person?

Initially, the obvious answer is yes.

But children go home.

They talk.

They repeat interesting things they learned in school. They tell their parents about unusual stories. Sometimes they correct adults.

A child who learns that scammers create artificial urgency may later see a parent responding to a suspicious message and say, "Wait. Let's check first."

Suddenly, the impact of educating one child has travelled beyond the person sitting in front of us.

This changed the way I thought about the initiative.

We normally imagine adults as the guardians. Parents protect children. Teachers protect students. Society protects young people.

But information can move in both directions.

A child can also become a small guardian inside the family.

I am not suggesting that children should carry adult responsibilities. They should not. What we can give them is permission to notice, question and speak up.

If a child sees something suspicious and feels comfortable telling a parent, that itself is protection. If a child brings home a simple scam-prevention principle and the family discusses it over dinner, the classroom has extended into the home.

This became the fourth principle:

Do not only measure the people you directly reach. Design the intervention so that the message can travel through them.

That is leverage.

And leverage is one of the reasons a relatively small CSR activity can produce a larger social footprint.

The Fifth Principle: Turn Repeated Knowledge Into Intellectual Property

There was still a weakness in the model.

A talk ends.

No matter how good the speaker is, everyone eventually leaves the room. Memories fade.

After visiting schools and repeating the programme, however, something valuable begins to accumulate: knowledge.

We learn which examples children understand. We learn what makes them laugh. We learn which questions they ask. We learn which explanations are too complicated. We learn what teachers notice. We learn which messages children remember.

In business, accumulated knowledge like this should not remain only inside one person's head.

It should become intellectual property.

That thinking eventually contributed to ScamAlert Jr.

The idea was not simply to publish another book about scams. The book became a way of capturing what we were learning from the initiative and turning it into something that could travel without us.

Instead of depending entirely on a speaker standing in front of students, stories and characters can carry the message.

A child can take a book home. A sibling can read it. A parent may pick it up. A teacher can return to it later.

The model begins to evolve:

School → Student → Home → Family.

And the role of the organisation changes as well.

At the beginning, impact depends heavily on our time.

Later, content begins doing some of the work.

This is the fifth principle:

Convert repeated experience into reusable content and intellectual property so that impact becomes less dependent on your physical presence.

For an SME, I think this is particularly powerful.

We may not have thousands of employees to deploy into communities. But we can create knowledge, frameworks, books, videos, tools, software or educational materials that continue working after we have left.

The Sixth Principle: Build an Ecosystem, Not a Larger Internal Team

There is another trap when an initiative begins growing.

The instinct is to build a larger internal team.

Sometimes that is necessary. But every additional layer also creates cost and management complexity.

An alternative is to build an ecosystem.

Schools already have students, teachers and communication channels. Corporate partners may have CSR budgets and community networks. Educators understand children. Industry organisations have expertise. Bookstores have distribution. Publishers and content creators understand how ideas travel.

The SME does not necessarily need to own every part of the system.

Our role can be to build the core model and then work with partners who already possess the infrastructure required for the next stage.

This is again very similar to entrepreneurship.

Strong businesses do not necessarily own every component of their value chain. They identify where they create the most value and collaborate elsewhere.

CSR can work the same way.

The sixth principle therefore is:

Scale through partnerships before scaling internal overhead.

This keeps the organisation lighter while allowing the initiative to travel further.

The Model: Less Resource, Greater Impact

Looking back, I can now see the pattern more clearly.

Our approach can be summarised as a simple progression:

Existing Capability → Simple Intervention → Repeatable Process → Beneficiary Multiplier → Intellectual Property → Partner Distribution

Each stage attempts to increase impact without requiring resources to increase at the same rate.

We start with what we already have.

We simplify what we deliver.

We make the delivery repeatable.

We encourage the people we reach to carry the message further.

We convert experience into reusable intellectual property.

Then we work with partners to expand distribution.

This is the model I am increasingly interested in developing.

I do not claim that it is appropriate for every CSR initiative. Some social problems genuinely require significant capital, specialised expertise and large institutions. Nor should "low resource" ever become an excuse for low quality.

The point is different.

Resource efficiency should be part of CSR design.

If two approaches can create comparable social value, but one requires substantially fewer recurring resources, the more efficient model has a better chance of surviving.

And longevity matters.

Impact Per Unit of Resource

Businesses constantly measure efficiency.

Revenue per employee. Cost per acquisition. Output per hour. Return on investment.

Perhaps CSR deserves a similar—but not purely financial—way of thinking.

I have started thinking about something I would call Impact Per Unit of Resource.

The concept is simple.

For every hour, ringgit and person committed to an initiative, how much useful and sustainable impact are we creating?

This should not become an excuse to reduce social contribution to a spreadsheet. Human impact cannot always be quantified accurately. But the question itself is useful because it forces us to examine the design of the programme.

Can one trainer reach several hundred students using a well-designed session?

Can those students carry the message into hundreds of homes?

Can one piece of educational content be reused across many schools?

Can a book continue delivering the message after the original programme ends?

Can corporate partners sponsor distribution rather than requiring us to finance everything ourselves?

Can teachers eventually use parts of the material without our presence?

Each time the answer becomes yes, the impact-to-resource ratio improves.

For an SME, that ratio may determine whether CSR remains an occasional activity or becomes something the company can sustain for years.

The Business Must Be Sustainable Too

There can sometimes be discomfort around discussing efficiency, intellectual property, partnerships or commercial mechanisms in the context of CSR.

I understand why.

We do not want social initiatives to become disguised marketing exercises.

But I also believe we need to be realistic.

Social impact requires resources.

Books need to be written, illustrated, printed and distributed. Programmes require people. Technology requires development. Travel costs money. Content requires time.

If the organisation providing all of this is continually depleted by the initiative, eventually the initiative stops.

Sustainability must therefore work in both directions.

The social mission must be sustainable, but so must the organisation supporting it.

That does not mean every CSR activity must generate revenue. It means we should be willing to design ecosystems in which free education, corporate sponsorship, commercial products, partnerships and intellectual property can coexist where appropriate, provided the economic mechanisms support rather than compromise the mission.

A commercially available book, for example, can extend the reach of an educational initiative. Corporate sponsorship can fund distribution to communities. Paid products can help support free activities elsewhere.

The relevant question is not simply whether money exists somewhere in the system.

The more important question is whether the system allows the impact to continue.

Why Scam Prevention Is Really About Judgment

As the model developed, my understanding of the mission also changed.

I started with scam awareness.

Today, I increasingly think we are teaching judgment.

Scam techniques will continue evolving, especially with artificial intelligence. Synthetic voices will become more convincing. Images and videos will become easier to manipulate. Messages will become increasingly personalised. It will become harder to judge authenticity simply by looking for obvious mistakes.

We cannot prepare children for that world by giving them a static list of today's scams.

We can prepare them by developing habits.

Pause.

Question.

Verify.

Discuss.

Ask who benefits.

Ask why something is urgent.

Ask whether the information can be confirmed through another channel.

These are not only anti-scam skills.

They are skills for navigating an information environment in which increasingly convincing content can be generated cheaply and at scale.

That makes the mission larger than I originally imagined.

The objective is not to create a generation that is frightened of scams.

It is to contribute, in our own small way, to a generation that thinks before reacting.

What Other SMEs Can Take From This

I am sharing this model because I believe many SMEs underestimate what they can contribute.

You do not necessarily need a CSR department.

You do not necessarily need a large annual CSR budget.

And you do not need to copy what multinational corporations are doing.

Start by looking inside your own organisation.

What knowledge have you accumulated?

What problem do you genuinely care about?

Where does that problem overlap with your existing expertise?

What is the smallest useful intervention you could create?

Can you turn it into a repeatable unit?

Can the people you help carry part of the impact forward?

Can repeated experience become reusable content or intellectual property?

Can partners eventually help distribute it?

Those questions can produce a very different type of CSR programme.

Instead of starting with resources and asking how much impact they can buy, start with a model and ask how efficiently impact can travel.

For me, that is the difference between simply conducting CSR activities and designing a CSR engine.

From One School to a Model

Our own model is still developing.

We continue going into schools. We continue learning from students and educators. We continue simplifying the message and improving the process. We are learning how to turn what began as individual awareness sessions into something more structured and more capable of travelling beyond us.

The next step is ScamAlert Jr.

ScamAlert Jr is planned for launch in Q4 2026, with availability targeted at major bookstores in Malaysia. The book is part of our attempt to convert what we have learned through school engagement into stories that children can carry home and families can discuss together.

But I do not see the book as the destination.

It is another component in the model.

A talk reaches the room.

A repeatable programme reaches more rooms.

A child carries the message into a home.

A book allows the message to stay there.

A partner helps it reach another community.

Each layer increases reach without requiring our internal resources to expand at exactly the same rate.

That is the pattern I want to continue exploring.

Perhaps the future of SME CSR is not about doing bigger projects.

Perhaps it is about designing better multipliers.

Use what you already know. Reduce unnecessary complexity. Build something repeatable. Turn experience into intellectual property. Work with people who already have the infrastructure you lack. And continually ask whether the impact is growing faster than the resources required to create it.

That is how I now think about CSR.

Not simply as giving back.

Not as an annual activity.

Not as a large cheque or a photograph in an annual report.

But as a system that can be designed, tested, improved and repeated.

For our scam-prevention initiative, the unit may begin with something as small as one child learning to pause before clicking.

If that child takes the lesson home, reminds a parent, starts a conversation and one day prevents a rushed decision, the impact has already travelled further than the original classroom.

That is the kind of CSR model I want to build:

less resource-intensive, more repeatable, and capable of creating impact far beyond the organisation that started it.

And we are only at the beginning.

Insights · 9/40 22 Sep 2026

PDF-X: From a Small File Problem to a Long-Term R&D Journey in Secure Document Processing

By Ts. Lukas J. Tan | 22 September 2026

From a Small File Problem to a Long-Term R&D Journey in Secure Document Processing

When we first started thinking about PDF-X, the idea looked almost too simple.

People have PDF problems.

A file is too large to upload. Someone needs only a few pages from a document. Several PDFs need to become one. A document needs a password before it can be sent.

There are already many PDF tools on the Internet, so at first glance there seems to be very little left to invent.

But that was exactly what made this project interesting.

The more we studied the market, the more we realised that the problem was not simply whether a PDF tool already existed.

The more important questions were:

  • Why are people still struggling with these problems if so many tools already exist?
  • Why do simple document tasks still require users to understand technical settings?
  • What happens behind the scenes when a public website processes a document uploaded by a stranger?
  • How much of the existing experience is designed around what the software can do, rather than what the user actually needs?

Those questions changed PDF-X from a small utility project into something much more interesting to us from a research and development perspective.

Today, I see PDF-X not as the end product of an idea, but as the beginning of a much longer exploration into document processing, secure execution, user experience, infrastructure efficiency and eventually the future relationship between people, documents and intelligent software.

It Started With the Market, Not the Technology

Our first step was not to decide which programming language or PDF library to use.

We started by looking at how people currently solve document problems.

There are large international PDF platforms with dozens of tools. There are desktop applications. There are free websites supported by advertising. There are paid subscription products. There are developer APIs.

Technically, the market is already mature.

But mature does not necessarily mean finished.

What we saw was a gap between technical capability and human intention.

For example, a user may be asked whether they want low, medium or high compression.

But that may not be the user's real question.

Their real question may be:

"The government portal says my PDF must be below 2 MB. Can you make it fit?"

That difference looks small, but from a product-design perspective it is significant.

The user should not need to understand DPI, JPEG quality, image recompression, object streams or PDF optimisation algorithms.

The software should understand those things.

The user should simply be able to communicate the outcome.

That became one of the earliest principles behind PDF-X:

Tell us what you need. Let the system handle the technical complexity.

This principle later influenced almost every decision we made.

We Deliberately Reduced the Product Before Expanding It

Early in the research process, it was very easy to imagine a large document platform.

PDF to Word. Word to PDF. Images to PDF. OCR. Signing. Watermarks. Rotation. Extraction. Conversion. Compression. And dozens more.

But we eventually moved in the opposite direction.

Instead of asking, "How many tools can we launch?", we asked:

What are the few problems worth solving first?

The initial public focus became four functions: Reduce PDF Size. Split PDF. Merge PDF. Protect PDF.

That reduction was intentional.

R&D is not only about adding capability. Sometimes R&D is also the process of discovering what not to build yet.

Word-to-PDF is a good example.

Technically, it is possible. But document conversion introduces another class of complexity: fonts, layout fidelity, images, headers, tables, office formats, rendering engines and additional execution risk.

Rather than releasing it simply because we could, we decided that it should wait until we were satisfied with the processing and isolation model.

That decision represents an important philosophy we developed through the project:

A feature is not finished merely because it works. It is finished when we understand how it behaves, fails, scales and affects the rest of the system.

That is a very different way of looking at product development.

"Reduce PDF" Became a Research Problem

Compression initially sounds straightforward. Take a large PDF. Compress it. Return a smaller PDF.

But once we looked more deeply, we realised the user's expectation is different from a generic compression function.

If someone asks for a PDF below 1 MB, reducing a 10 MB file to 3.5 MB is technically successful compression, but it has failed the user's task.

So the engineering problem becomes:

Given a PDF and a target maximum size, can we produce the highest practical quality result that fits within that limit?

That changes the problem. Now we are dealing with optimisation rather than a simple command.

Different PDFs behave differently.

  • A text-heavy document is different from a scanned document.
  • A document containing photographs is different from one containing vector graphics.
  • An already optimised PDF behaves differently from one containing oversized embedded images.
  • A document may not be reducible to the requested target without unacceptable quality loss.

Suddenly, a very ordinary button, Reduce PDF Size, becomes a technical research problem involving content analysis, iterative optimisation, quality trade-offs and honest communication with the user.

This is where PDF-X became particularly interesting to me.

The simpler we wanted the user experience to become, the more sophisticated the engineering underneath sometimes needed to be.

That is a pattern I believe will become increasingly important in software.

Complexity should move away from the user and into the system.

Then We Reached the Security Question

The biggest change in our thinking came when we started looking at the processing architecture itself.

A public PDF platform has a fundamental characteristic: it accepts files from people it does not know.

From a security perspective, that changes everything.

An uploaded PDF cannot simply be treated as a document. It must be treated as untrusted input.

PDF parsers and document-processing engines are complex pieces of software. They process compressed data, fonts, images, metadata, object structures and many different variations of the format.

Software can contain vulnerabilities.

So we asked a new question:

If a document-processing engine is ever compromised by a malicious file, what would that process be able to access?

This question became one of the most important R&D directions in the entire PDF-X project.

Normally, a PHP application may start an external document-processing program under the same Unix account as the application.

Without additional isolation, that child process may inherit much more access than it actually needs:

  • Application files
  • Environment variables
  • Other temporary directories
  • Network connectivity
  • Other resources visible to that account

But a document processor may only need:

/work/input.pdf
/work/output.pdf

Why should it see anything else?

That simple question eventually led us to investigate process isolation on Linux.

From PDF Processing to Sandbox Engineering

We studied how we could create a smaller execution boundary around external document-processing programs.

That led us to Bubblewrap, a Linux sandboxing technology based on namespaces and filesystem isolation.

The design gradually became very clear.

  • Each processing job should have its own workspace.
  • The external processor should see only the files required for that job.
  • It should not inherit the application's full environment.
  • Network access should be unavailable unless explicitly required.
  • Commands should be invoked as structured argument arrays rather than assembled into shell strings.
  • Processing should have time limits and resource controls.

And perhaps most importantly:

If the sandbox cannot be created, the system should fail rather than silently run without it.

That last principle became especially important.

A security feature that disappears without telling you can be more dangerous than having no security feature at all, because it creates false confidence.

So the approach became fail closed. If the containment environment is unavailable, processing stops.

Security Research Also Taught Us to Be More Precise

One of the most valuable lessons from this project was learning what not to claim.

It would be easy to say: "Our PDF processing is secure."

But security does not work as a simple yes-or-no state.

  • The sandbox isolates the spawned processing process.
  • It does not automatically sandbox the entire PHP application.
  • It does not sandbox the queue worker that started it.
  • It does not replace operating-system security.
  • It does not remove vulnerabilities from Bubblewrap or the Linux kernel.
  • It does not make output files trustworthy simply because they were produced inside a sandbox.

Some resource controls also require capabilities outside the library itself.

The deeper we went into security engineering, the more careful our language became.

Instead of saying "This makes document processing safe", the more accurate statement is:

This reduces the attack surface and limits what a compromised child process can reach.

That distinction matters.

And I believe responsible technology companies need to become much more comfortable communicating limitations.

Trust should not come from claiming perfection. Trust should come from explaining the boundaries honestly.

The Internal R&D Became an Open-Source Project

At this stage, something unexpected happened.

The sandboxing work was originally just one part of PDF-X. But we realised that the problem was not actually specific to PDF-X.

Many PHP systems execute external programs against untrusted input: OCR engines, image converters, Office-document processors, media tools, archive utilities, analysis binaries.

They all face a similar architectural question:

What is the minimum this external process needs to access?

So we extracted that work into a separate open-source project: PDF-X Secure Runner.

The package became independent from the private PDF-X application. It is framework-independent PHP. It can be used with Laravel, but Laravel is not required. It does not bundle the PDF-processing engine itself.

Its purpose is narrower: provide a controlled execution boundary around an external process.

That work was released publicly through Composer, Packagist, GitHub documentation and automated Linux containment testing.

And that created another dimension to the project. PDF-X was no longer only producing a user-facing tool. It was producing reusable infrastructure.

Open Source Changed the Nature of the Research

Once something becomes open source, the engineering mindset changes.

Internal code only has to satisfy the team maintaining it. Public infrastructure has to explain itself.

  • What does it protect?
  • What does it not protect?
  • What assumptions does it make?
  • What operating systems does it require?
  • What happens when dependencies are unavailable?
  • How can another developer verify that the containment model is actually functioning?

This led us to build documentation around architecture, security boundaries and integration. It also led to containment tests and a self-check mechanism rather than relying entirely on assumptions.

This is an important part of R&D that is sometimes overlooked.

Research is not complete when something works on the developer's machine. It becomes much more valuable when the assumptions behind the result can be tested and understood by other people.

That is one reason I am increasingly interested in open-source work.

Public review creates pressure for clarity. And clarity improves engineering.

We Also Had to Study the Reality of Infrastructure

Another lesson came from deployment.

Engineering cannot happen in isolation from business reality. It is easy to design the perfect architecture if budget, infrastructure and operating constraints do not exist. In the real world, they always exist.

We studied how much isolation could realistically be achieved on our existing Linux hosting environment.

We looked at process ownership, file permissions, shared server behaviour, queue workers, temporary storage, cleanup, memory, disk availability, request admission, rate limits and operational monitoring.

Some things could be improved through application design. Some things could be isolated through Bubblewrap. Some things ultimately depend on the host architecture itself.

And there is an important lesson here:

Application security has boundaries that application code alone cannot cross.

If strict host-level isolation is required, infrastructure may eventually need to change. Recognising that limitation is part of engineering maturity.

The answer is not always another function or another package. Sometimes the answer is architectural.

Reliability Became Part of Security

Our research also reinforced something I believe strongly: security and reliability are connected.

If a processing system runs out of memory, fills disk space or accumulates thousands of abandoned jobs, that is not only a performance problem. It can become a security and availability problem.

So we introduced controls around processing jobs:

  • Temporary job directories and automatic cleanup
  • Queue-based processing
  • Signed status and download access
  • Rate limiting
  • Disk and memory admission checks
  • Process timeouts
  • Maximum file sizes and workspace controls

The goal was to prevent a simple document-processing feature from becoming an uncontrolled resource consumer.

Once again, something that looks like a small utility on the frontend becomes a systems-engineering problem behind the scenes.

The Market Research Changed Our Definition of Innovation

When people hear the word "innovation", they often expect something dramatic. AI. Robotics. Blockchain. A completely new technology.

But working on PDF-X has reminded me that innovation can also come from reframing an existing problem.

PDF compression is not new. Splitting a PDF is not new. Sandboxing is not new. Linux namespaces are not new. PHP is certainly not new.

But innovation can happen in the way those pieces are combined.

  • Can an ordinary office worker use a technically sophisticated document-processing pipeline without having to understand any of it?
  • Can a free online utility be designed around user outcomes instead of technical settings?
  • Can the security work developed for one product become reusable infrastructure for other developers?
  • Can a document-processing platform become a laboratory for exploring secure execution, optimisation and intelligent automation?

Those questions are far more interesting to me than simply asking: "Can we build another PDF website?"

PDF-X Is Beginning to Show Us a Larger Opportunity

This is where I think the long-term R&D journey becomes interesting.

A document is one of the most common interfaces between people and organisations. Invoices. Reports. Applications. Contracts. Statements. Certificates. Forms. Purchase orders. School documents. Government submissions. Corporate paperwork.

For decades, we have focused mainly on creating, storing and displaying these documents.

The next stage may be different. Software will increasingly need to understand the user's intention around a document.

Not "Choose compression level 1, 2 or 3." But: "Make this acceptable for my application portal."

Not "Select pages 17-22." But eventually: "Give me only the pages containing the invoice and payment details."

Not "Merge file A, B and C." But: "Prepare these documents in the correct order for submission."

This is where document utilities may eventually meet intelligent systems.

But there is an important condition. AI should not be added merely because AI is fashionable. It should appear only when it reduces the amount of thinking required from the user.

The intelligence should remain underneath. The simplicity should remain on top.

Privacy Will Become More Important, Not Less

There is another future direction we are watching carefully.

As software becomes more intelligent, more user data is likely to be processed. Documents may contain some of the most sensitive information people handle: financial information, personal identification, contracts, business records, internal correspondence.

So future document intelligence cannot be developed independently from privacy engineering.

This may lead to different architectural models. Some processing may remain server-based. Some may eventually move closer to the browser or user device. Some organisations may require private deployments. Some workflows may need isolated workers. The right architecture will depend on the sensitivity of the task.

For us, this means privacy is not simply a legal page at the bottom of the website. It is an R&D topic.

We Are Also Beginning to See PDF-X as an Engineering Platform

The public sees four tools. From an engineering perspective, we now see several deeper research layers underneath them: document optimisation, untrusted-file handling, secure execution, temporary storage, resource governance, asynchronous processing, user intention, privacy, developer infrastructure, and potentially later, intelligent document understanding.

This is why I say PDF-X is only beginning.

The product may remain visually simple. But the technology behind it can continue evolving for years.

Some of that technology will remain part of PDF-X. Some may become standalone open-source components. Some may become services. Some experiments may fail completely.

That is normal R&D. The objective is not to pretend that we already know the final destination. The objective is to continue asking useful questions.

Build, Observe, Learn, Then Build Again

One of the mistakes technology companies can make is to treat launch day as the finish line. For us, launch is closer to the beginning of the experiment.

Now we can observe real behaviour.

  • Which file sizes are common?
  • Which operations are used most?
  • Where do users abandon the process?
  • Which PDF types create problems?
  • What do people ask for that we did not anticipate?
  • What security assumptions change when usage increases?
  • What becomes expensive at scale?
  • What should remain free?
  • Which infrastructure needs to be separated?
  • What should never be automated?

Those answers cannot come entirely from planning documents. They require real systems and real usage.

This is why I like building. You discover things by moving.

What I Hope PDF-X Becomes

I do not want to define PDF-X too narrowly today. At the moment, it is a simple online PDF utility. That is what users should see.

Behind it, however, we are building knowledge: how people interact with documents, secure document processing, file optimisation, resource management, infrastructure boundaries, and how much complexity can be hidden from the user without hiding important truth.

Over time, that knowledge may become more valuable than any individual button on the website.

That is often how meaningful technology develops. The first product solves a problem. The process of solving that problem reveals a deeper problem. Solving the deeper problem produces reusable technology. That technology creates the next opportunity. And the cycle continues.

This Is Why I Call It R&D

Research and development is not only something that happens inside a laboratory. For a software company, it can happen while solving very ordinary problems.

You research the market. You observe the user. You study existing technology. You test assumptions. You discover limitations. You redesign. You fail. You isolate the failure. You improve the architecture. You document what you have learned.

Then sometimes you discover that a small component of one product can become something useful on its own.

That is exactly what happened with PDF-X Secure Runner. And I suspect it will not be the last thing to come out of PDF-X.

The Beginning, Not the Conclusion

When we started, we were trying to build a useful PDF website. Today, I see something larger. Not necessarily a larger website. A larger field of exploration.

  • How can document processing become simpler for humans while becoming more disciplined underneath?
  • How can intelligent automation understand outcomes rather than force users to understand settings?
  • How can untrusted document processing be isolated more effectively?
  • How can privacy and security remain part of product architecture rather than being added after the product is built?
  • And what other reusable technologies will we discover while trying to solve these ordinary problems properly?

I do not know all the answers yet. That is exactly why this is interesting.

PDF-X is live as a product. PDF-X Secure Runner is now open source. But from an R&D perspective, both are still at the beginning.

We built something. Then we looked underneath it. And underneath that simple PDF tool, we found a much larger area worth exploring.

That is where I believe the next chapter starts.

  • PDF-X: pdf-x.co
  • PDF-X Secure Runner: open-source infrastructure developed from the engineering work behind PDF-X.

And from here, we continue to build, study, test and discover.

Because sometimes innovation does not begin with trying to invent the future. Sometimes it begins by taking one ordinary problem seriously enough to ask:

"Can this be done better?"

Ts. Lukas J. Tan
Founder & CEO, OPERION Ecommerce & Software Sdn Bhd
R&D | Secure Document Processing | AI & Business Systems

Insights · 10/40 16 Sep 2026

When AI Becomes Faster Than Our Ability to Control It

By Ts. Lukas J. Tan | 16 September 2026

Why I Am Paying More Attention to Practical AI Governance

Whenever I learn a new technology, I rarely stop at understanding what it is or watching other people demonstrate what it can do. I have always preferred to use technology myself, push it into real work, test its limits, connect it with other tools, and see how far it can actually go. Sometimes this approach creates efficiency. Sometimes it exposes weaknesses. But more importantly, when you use something deeply enough, you begin to notice things that are difficult to see from the outside.

Artificial intelligence has been no different for me. Over the past few years, AI has gradually become part of how I think, write, research, analyse information, develop software, communicate and operate a business. I have watched tasks that once required hours become tasks that can be completed in minutes. Research can be accelerated. Documents can be analysed almost immediately. Software can be developed faster. Ideas can be explored from multiple directions without assembling a large team. An individual equipped with the right AI tools can now perform work that would once have required several different skills or people.

I am excited by that development. I want AI to become more capable, not less. I want businesses to discover how much more productive they can become when AI is used properly.

Yet the deeper I use AI, the more I find myself thinking about something other than productivity.

Everyone talks about how fast AI is becoming. What concerns me is not simply that AI is fast. What concerns me is the possibility that AI is becoming faster than our ability to control what we are doing with it.

This difference matters.

For decades, computing technology has continued to accelerate. Moore’s Law became one of the best-known descriptions of how rapidly computing capability developed over time. Every generation of technology has given us greater processing power, greater connectivity and faster access to information. AI is adding something different to that acceleration because computers are no longer only storing and processing information. Increasingly capable AI systems are now participating directly in knowledge work: interpreting information, generating content, writing software, analysing documents and supporting decisions.

Consider something as ordinary as preparing a business proposal. In the traditional workflow, someone gathers information, thinks about the problem, prepares a draft, reviews it, makes corrections, discusses it with colleagues and eventually sends it to the customer. That process may take several hours or even several days. Today, an employee can provide AI with some information and receive a professionally written proposal within minutes.

That sounds entirely positive until we look at what happened to the control process.

The speed of generation increased dramatically, but did the speed and quality of human review increase at the same rate? The employee can generate faster, copy faster, analyse faster, upload faster and send faster. But management still has to review, approve, protect, verify and take responsibility.

This is what I increasingly see as the governance gap.

The issue is not that AI is doing something wrong simply because it is fast. The issue is that our organisational controls may still have been designed for a much slower world.

There are much larger debates about what happens if increasingly autonomous AI systems eventually exceed meaningful human control. Some people talk about AI controlling humanity or even posing an existential threat. I do not think anyone can state with certainty today how those scenarios will develop. They deserve serious research and discussion, but we do not have to travel that far into the future to understand why governance matters.

There is a much simpler question that every business can ask today:

Can your company control the AI that is already being used inside your company?

That question is no longer theoretical.

The Employee Leaves. What Happens to the AI?

One of the simplest examples is something that almost every business owner understands: employee turnover.

Imagine an employee who uses AI every day for company work. Perhaps the employee works in marketing, sales, administration, software development or management. The company pays the employee’s salary. The employee works with company customers and company information. Over time, AI becomes deeply integrated into that person’s workflow.

The employee may use AI to analyse customers, develop proposals, write reports, create marketing campaigns, solve technical problems, develop software, summarise meetings, research competitors and structure ideas. After one or two years, the AI environment may contain hundreds or thousands of conversations. Inside those conversations may be prompts, templates, customer context, project knowledge, instructions, research, workflows and many small pieces of organisational knowledge accumulated through daily work.

Then the employee resigns.

Most established companies already know what to do next. The laptop is returned. The company email account is disabled. CRM access is removed. Cloud storage permissions are revoked. Internal systems are locked. The employee exit checklist is completed.

But what happens if all that AI work was performed using the employee’s personal AI account?

Who owns the account? Who controls the conversation history? Where are the prompts? Where are the custom instructions and workflows? Can the company retain the knowledge that was created during employment? Can another employee continue the work?

Suddenly, what initially looked like an AI productivity issue becomes an ownership and business continuity issue.

The employee leaves, and potentially part of the company’s working knowledge leaves as well.

This is why I have increasingly returned to one very simple principle:

Keep Personal Personal. Keep Company Company.

This is not an entirely new management idea. Businesses went through similar transitions with email. We learned why company communication should not depend entirely on an employee’s personal Gmail account. We developed company servers, company databases, company cloud storage, company accounting systems and company-managed access because organisations eventually understood that business information needed ownership and continuity.

AI requires us to revisit the same principle in a new environment.

If an AI account is being used substantially for company work, management should at least know whose account it is, who controls it, what happens to access when the employee leaves, and how important organisational knowledge will be retained.

The Question Is Not Only Whose Account. It Is What Goes Inside.

Account ownership is only the beginning.

The more useful AI becomes, the more context we tend to give it. If we want AI to prepare a better proposal, we provide information about the customer. If we want AI to analyse a contract, we upload the contract. If we want it to understand a technical problem, we may provide source code. If we want it to analyse a business situation, we may give it meeting notes, financial information or internal strategy.

This creates an uncomfortable relationship between usefulness and governance.

The more context we give AI, the more useful it can become. But the more information we give AI, the clearer our information boundaries need to become.

What are employees currently putting into AI systems?

Customer information? Contracts? Internal meeting minutes? Financial information? Employee information? Source code? Business plans? Confidential documents? Strategic discussions?

The correct answer is not simply to declare that every AI platform is unsafe, nor is it reasonable to assume that every AI service handles information in exactly the same way. Different tools, subscriptions, enterprise environments and configurations can provide different levels of data control.

For management, however, there is an even more basic question.

Has the company itself decided what employees are allowed to put into AI?

If one employee thinks a customer contract is acceptable, another thinks it is prohibited, and a third has never considered the question, then the problem is not necessarily the AI platform. The organisation itself has not established the boundary.

If employees have to guess the boundary, management has not defined one.

That is a governance issue.

AI Wrote It. But Who Approved It?

There is another side to AI Governance that has less to do with what goes into AI and more to do with what comes out.

Imagine an AI system preparing a sales proposal. The proposal is beautifully written. It sounds professional, confident and complete. Somewhere in the document, however, the AI states that the project can be delivered within 30 days. The company’s actual operational capability requires 60 days.

The salesperson reads the document quickly, trusts the quality of the writing and sends it to the customer.

The customer accepts the proposal.

Now there is a problem.

Who is responsible?

The company cannot realistically resolve the customer dispute simply by saying, “The AI wrote it.”

AI can draft. AI can suggest. AI can analyse. AI can recommend. But the organisation still needs to establish who reviews important outputs, who approves them and who remains accountable for the decisions and commitments that follow.

This does not mean every AI-generated sentence needs to pass through three levels of management. That would defeat much of the productivity AI creates. Governance should be proportional to impact.

A brainstorming idea for an internal discussion may require only a light review. A customer proposal, financial analysis, contractual statement, engineering recommendation or other high-impact output deserves much stronger human verification.

The principle is straightforward:

The greater the potential consequence, the stronger the human review should be.

That is how governance supports speed rather than destroys it.

AI Amplifies What You Already Have

The more I think about these issues, the more they return me to another principle that has shaped my view of AI:

AI amplifies what you already have.

If an organisation already has clear processes, disciplined information management, responsible employees and clear ownership, AI can amplify those strengths. Good people become more productive. Good processes become faster. Knowledge becomes easier to use. Small teams can accomplish significantly more.

But amplification works in both directions.

If access is messy, AI can make messy access operate faster. If information management is poor, employees can move information outside the organisation faster. If accountability is unclear, decisions can be produced and acted upon faster without anyone knowing exactly who owns the consequence. If the underlying process is broken, automating it does not necessarily repair it. Sometimes it simply allows the broken process to operate at greater speed.

This is why I do not see AI Governance as an attempt to stop AI adoption.

Quite the opposite.

I want businesses to use AI aggressively where it creates value. But if we want to accelerate, we also need to improve the steering, the brakes and the rules of the road.

Practical AI Governance, particularly for SMEs, does not have to begin with a hundred-page document. It can begin with a few very practical areas: Account and Access, Data and Privacy, People and AI Usage, Output and Accountability, and Governance and Continuity.

From there, management can begin asking straightforward questions.

Which AI tools are actually being used inside our company? Are employees using company-managed accounts or personal accounts? What information are they putting into those systems? Do employees understand what should not be uploaded? Which AI-generated outputs require human review? Who remains accountable for the final result? Who oversees AI usage? And when an employee leaves, what happens to the company’s AI-related knowledge?

These are not futuristic questions.

They are operational questions that companies can ask today.

Before Governing the Future, Understand the Present

My growing interest in AI Governance does not come from wanting to become pessimistic about AI. It comes from the opposite direction. I have used AI deeply enough to appreciate just how powerful it is becoming.

I still want AI to become faster. I still want businesses to use more of it. I still believe that AI can dramatically amplify what individuals, SMEs and larger organisations are capable of accomplishing.

But the faster technology becomes, the more important it is that our ability to govern its use develops alongside it.

We cannot continuously upgrade the engine while ignoring the steering wheel and the brakes.

For that reason, I think the question business owners should ask is changing.

A few years ago, the question might have been:

“Should our company use AI?”

Then it became:

“How can our company use AI?”

Today, I think there is another question that deserves equal attention:

“Do we actually know how AI is being used inside our company, and are we still in control of it?”

Before we worry about governing some distant future in which AI becomes extraordinarily powerful, perhaps we should first understand what is happening inside our organisations right now.

That is where practical AI Governance begins.

Not with fear.

Not with banning technology.

Not necessarily with complicated regulation.

It begins with visibility.

Know which tools are being used. Know whose accounts they are. Know what information is going inside. Know what important outputs require review. Know who is responsible. Know what happens when people leave.

Once management can answer those questions, governance becomes something practical rather than abstract.

And if management cannot answer them yet, that does not mean the company has failed.

It simply means it is time to start looking.

A Practical Starting Point

At OPERION, we have developed a Practical AI Governance Readiness Assessment to help businesses begin that process. The assessment looks at five practical areas: Account & Access, Data & Privacy, People & AI Usage, Output & Accountability, and Governance & Continuity.

It is not a certification. It is not an audit, and it is not a legal opinion or declaration of regulatory compliance. Its purpose is much simpler: to help management see what is happening today, identify areas that may deserve attention and decide what should be examined next.

Businesses that want to understand their situation more deeply can also invite OPERION to conduct a complimentary preliminary AI Governance assessment with their management team. The objective is not to arrive with a predetermined solution. It is to understand the existing environment first.

I believe strongly in one sequence:

Assessment first. Prescription second.

AI will continue to develop. It will become more capable, more integrated into everyday work and, very likely, much faster.

We should embrace the opportunity.

But as we accelerate, we should make sure our governance can accelerate with it.

Because AI amplifies what you already have.

The question is whether we understand what we are allowing it to amplify.

Ts. Lukas J. Tan
Founder & CEO, OPERION Ecommerce & Software Sdn Bhd
Practical AI Governance | Digitalisation | AI & Business Systems

Insights · 11/40 08 Sep 2026

When Knowledge Is No Longer Scarce, What Happens to the University?

By Ts. Lukas J. Tan
Written on 6 September 2026 | Penang, Malaysia

Technology has always changed the value of human labour. Machines reduced the need for physical labour, software reduced the need for certain administrative work, and artificial intelligence is now beginning to reduce the amount of human effort required for many forms of knowledge work. I do not believe this means that human beings will become unnecessary. But I do believe that many things we once considered difficult, specialised or expensive will become easier to accomplish with fewer people. When that happens, we should not only ask what AI will do to jobs. We should also ask what it will do to the institutions that were built to prepare people for those jobs.

This brings me to universities.

The Degree Became the Product

For a long time, the role of a university was relatively clear. Universities educated people, developed specialised knowledge and issued recognised qualifications. Students went to university because knowledge was concentrated there, employers valued degrees, and a certificate provided evidence that a person had completed a certain level of education. For many families, particularly in countries such as Malaysia, the degree also represented something larger. It was associated with social mobility, professional status and the hope of a more secure future.

Over time, however, something gradually changed. Education remained important, but the certificate itself became increasingly important. Students did not necessarily enter university only because they wanted knowledge. They needed the qualification because the labour market asked for it. Employers used degrees as filters, parents regarded them as a form of security, and young people naturally followed the pathway society had created for them. A degree became both an educational experience and a ticket into parts of the employment market.

There is nothing inherently wrong with this system. Universities have contributed enormously to human development, and I would never argue that education is unnecessary. But the assumptions supporting this model deserve to be reconsidered because the environment around universities is changing very quickly.

When Industry Becomes the University

One change I have been observing in Malaysia is the growing involvement of industry in education. More companies and industrial groups are establishing their own academies, training centres and education programmes. Some have gone further into colleges and university-level education. I cannot speak for the motivation of every organisation, and there are certainly different reasons behind each institution. But from an industry perspective, one reason is easy to understand. Companies need talent that can actually function in their environment. When graduates do not arrive with the exact capabilities an industry requires, companies naturally begin to train people themselves.

In some ways, this is a sensible development. A manufacturer understands its machinery, processes and workforce requirements better than an outsider. A technology company understands the systems and tools its people need. An industry can therefore design training around actual problems instead of waiting for a general curriculum to catch up.

But when more industries begin becoming education providers themselves, another question appears. How many universities, colleges and academies does a country ultimately need?

Malaysia's Numbers Tell Two Stories at Once

Malaysia already has a substantial higher-education ecosystem. According to the Malaysia Higher Education Blueprint 2026–2035, using 2024 higher-education statistics, Malaysia had 544 higher-education institutions and approximately 1.35 million enrolled students. The private higher-education landscape alone included 64 universities, 36 university colleges, 271 colleges and 11 foreign university branch campuses.

At the same time, Malaysia is moving through an important demographic transition. According to the Department of Statistics Malaysia (DOSM), Malaysia’s total fertility rate stood at 1.6 children per woman in 2024, below the replacement level.

I believe those two developments deserve to be considered together.

If the supply of education continues expanding while future generations become smaller, competition for students will inevitably intensify. AI could add another layer of pressure by changing how young people think about learning itself.

The Competition for Students Is Already Visible

We can already see signs that higher education has become a much more competitive market. Twenty years ago, I do not remember universities competing for attention in quite the same way they do today. Now university advertisements are everywhere. We see them along roads, on social media, through digital advertising, at education fairs and through increasingly sophisticated student recruitment campaigns.

There is nothing wrong with a university advertising. Every institution needs to communicate with its market. But the intensity of recruitment tells us something important. Universities are increasingly competing for student numbers.

That competition may become much more difficult in the coming years, because AI is changing one of the fundamental reasons people historically needed educational institutions: access to knowledge.

What AI Changed for Me

This is where my view is influenced strongly by my own recent experience.

I have managed a technology company for more than a decade. Yet I have never considered myself the strongest technical person in my company. I understand business logic, system architecture, processes, how different components connect and what a system ultimately needs to achieve. But there have always been technical areas where my programmers knew considerably more than I did. That was normal. They spent years developing those skills, while my role required me to focus on a different level of the business.

Then AI changed something for me.

After spending an intensive period working deeply with AI, I found myself understanding areas that had remained outside my practical capability for years. In roughly a month, I was able to explore programming concepts, infrastructure, deployment, automation and technical workflows at a speed I had never experienced before. By September 2026, I found myself able to oversee multiple client projects while using several computers and AI systems to assist different parts of the work.

The Distance Between Not Knowing and Knowing Enough

I want to be careful about what this experience means. One month with AI did not magically give me the depth of an engineer who has spent ten or twenty years mastering a discipline. Experience still matters. Deep technical judgement still matters. Security, architecture, reliability and understanding what happens when things go wrong still require expertise.

But something significant did change.

The distance between “I don’t know how to do this” and “I can understand this well enough to make it work” became dramatically shorter.

That is the part that should interest universities.

For centuries, knowledge was scarce. If you wanted to understand an advanced subject, you needed to find the right books, the right teacher, the right institution or the right expert. Today, a person can begin with almost no knowledge of a subject and have an AI system explain it, simplify it, challenge them, answer questions, generate examples and help them apply what they have learned immediately.

The AI can be wrong, of course. That is precisely why judgement and critical thinking become even more important. But the cost and speed of acquiring practical knowledge have nevertheless changed.

Four Years, Measured in Time, Not Just Money

This leads to a question that I believe students and parents will increasingly ask: if I spend three or four years obtaining a degree, what exactly am I receiving in exchange for those years?

We normally calculate the cost of university in money. Perhaps we should also calculate it in time.

Four years is a significant portion of a young person’s life. Imagine an 18-year-old who enters university and graduates at 22. Now imagine another 18-year-old who spends the same four years intensely studying one field using AI, working with industry, building products, doing research, creating a company, failing, learning from those failures and producing real evidence of what he or she can do.

At 22, who is ahead?

The answer is not automatically the second person. A strong university student may have developed deeper theoretical understanding, powerful friendships, professional networks, exposure to research and intellectual discipline. Certain professions also cannot responsibly be reduced to self-learning. I would certainly not want doctors, civil engineers or other safety-critical professionals qualifying themselves simply because an AI told them they understood the subject.

But for many other areas, the comparison is becoming legitimate.

If one person can show a certificate while another can show four years of actual work, products, research, clients, experiments and results, employers will increasingly have more than one way to judge capability.

The degree is no longer the only signal.

What University Still Gives You

This is why I do not believe the correct conclusion is that university will become useless. My own experience tells me otherwise. University provides things that are difficult to measure on a transcript. It gives people an environment in which to grow. It creates friendships and networks. It exposes young adults to people from different backgrounds. It provides structure, discipline, mentors and intellectual challenges.

Most importantly, good education develops the ability to think.

I can often see the difference between someone who has learned how to analyse a problem and someone who simply knows how to repeat information. The ability to structure an argument, question assumptions, evaluate evidence and make a judgement remains extremely valuable.

People Who Know How to Learn vs. People Waiting to Be Taught

But here again AI creates an interesting challenge.

A person who knows how to use AI properly can also develop these capabilities outside a traditional classroom. AI can challenge an argument. It can present opposing positions. It can become a tutor. It can explain a subject at different levels. It can help someone experiment and immediately turn an idea into something tangible.

The important distinction in the future may therefore not be between people who went to university and people who did not. It may be between people who know how to learn and people who are waiting to be taught.

The Risk of a Higher-Education Bubble

This is why I believe there is a risk of a higher-education bubble.

By “bubble,” I do not mean that universities will suddenly collapse or that degrees will have no value. I mean that we may be creating more educational capacity based on assumptions about student demand and the value of traditional qualifications that could change faster than institutions expect.

Several forces are moving at the same time. Birth rates are declining. Industries are developing their own talent pipelines. Online education continues improving. Alternative credentials are becoming more accepted. People can work and earn money across borders without physically moving. AI is dramatically reducing the friction involved in self-learning and creation. Meanwhile, more institutions are competing for the same young people.

If these trends continue, something eventually has to adjust.

Why Government Still Has a Role

This is also why government has a role to play. Higher education cannot be treated purely as an ordinary commercial market where unlimited supply is always assumed to create healthy competition. When an educational institution fails, the consequences affect more than shareholders. Students may lose years. Parents may lose savings. Staff lose careers. Qualifications can become uncertain. Communities can be affected.

The question for government should therefore not simply be how many universities a country has. The more important questions are what outcomes those universities produce, whether graduates genuinely develop useful capabilities, whether programmes respond to changing economic realities, and whether institutions are financially and academically sustainable.

Access to Knowledge Is Not Access to Opportunity

At the same time, we need to be socially conscious about the alternatives we promote.

It is easy for someone with a laptop, reliable internet access, business experience and confidence to say that everyone can simply learn with AI. Reality is more complicated. Not every young person has the same environment. Some need the structure of university. Some need access to laboratories and equipment. Some need teachers because they have never learned how to teach themselves. Some need university networks because their families have no professional networks of their own.

For these students, university can still be an extraordinary engine of social mobility.

AI may make knowledge more accessible, but access to knowledge is not the same as access to opportunity.

How Universities Could Evolve

That is why the solution cannot simply be to close universities or tell young people not to study. The more constructive question is how universities should evolve.

Perhaps universities should stop seeing themselves primarily as places that deliver information and qualifications. Information is becoming abundant. Instead, universities could become environments that transform information into judgement, experience, relationships and capability.

Students could spend less time reproducing answers in examinations and more time solving real problems. Industry projects could become part of education rather than something students encounter only after graduation. AI could provide personalised tutoring while professors spend more time challenging assumptions, mentoring students and developing deeper thinking. Students could graduate not only with transcripts, but with portfolios demonstrating what they have actually built, researched, solved and contributed.

The university might also become less of a one-time four-year destination and more of a lifelong platform. People could move between employment and education repeatedly, learning what they need when they need it instead of attempting to predict at 18 everything they will need for the next 40 years.

Industry academies could also have an important role, but they should complement rather than simply duplicate universities. Industry understands immediate workforce needs; universities should retain the ability to think beyond the immediate needs of a particular employer. Society needs both.

This balance is important because education has a responsibility beyond employability. Universities also develop researchers, preserve knowledge, challenge society, study problems that have no immediate commercial return and provide spaces where ideas can be explored independently. If education becomes only training for today’s jobs, we may prepare people perfectly for industries that disappear tomorrow.

The Real Question for 2026

The deeper issue, therefore, is not whether AI will kill universities.

I do not think it will.

What AI may destroy is the assumption that universities have a monopoly over advanced learning.

That monopoly is already weakening.

Knowledge can come from almost anywhere. Skills can increasingly be demonstrated directly. Companies can train their own people. A teenager with the right tools can create something that once required an entire technical team. An experienced businessperson can use AI to enter technical areas that previously seemed inaccessible. A person with curiosity, discipline and judgement has access to learning capabilities that previous generations could hardly imagine.

Universities still have enormous value, but increasingly that value must be demonstrated rather than assumed.

Perhaps the most important question for a university in 2026 is therefore no longer, “What courses should we offer?”

The more difficult question is:

“What can a young person become after spending four years with us that he or she could not become after spending four years learning, building and creating with AI?”

If universities can answer that question convincingly, they have a powerful future.

If they cannot, the greatest threat may not be another university opening across the road.

It may be an 18-year-old sitting at home with a laptop, an AI system, four years of time and a very clear idea of what he or she wants to build.

And that is why, writing this in September 2026, I believe the discussion about the future of universities should begin now. Not because education is becoming less important, but because learning is becoming more accessible than at any other point in human history.

The institution that once controlled access to knowledge now has to compete in a world where knowledge is everywhere.

Its future will depend on what it can offer beyond knowledge.

Insights · 12/40 07 Sep 2026

The AI Era of Programming: A Short History of How Claude and Codex Learned to Code

I just shipped my first open-source project — a small thing, an animated row-deletion pattern for web apps. Nothing world-changing. But building it with an AI coding agent sitting next to me the whole time made me want to understand something I’d been taking for granted: where did these tools actually come from? What are they trained on? Who built them, and why? This is my attempt to trace that history — partly for my own understanding, partly because I think more builders should know the story of the tools they now depend on every day.

Before the agents: a foundation laid in 2017

Almost every AI coding tool in use today — Copilot, Codex, Claude, Gemini — traces back to one research paper: “Attention Is All You Need,” published by a team at Google Brain in August 2017. It introduced the Transformer architecture, which replaced the older, slower recurrent neural networks with a mechanism called “attention” — letting a model weigh the relationships between every word (or token) in a sequence simultaneously, rather than processing text one piece at a time.

This sounds abstract, but the practical effect was enormous: Transformers could be trained in parallel, at far larger scale, on far more data, than anything before them. Nearly every large language model since — GPT, BERT, Claude, Codex — is built on this same architectural foundation. The paper wasn’t about code at all; it was about machine translation. But the architecture turned out to generalize to almost any sequence of symbols, including programming languages.

The raw material: where does the “code knowledge” come from?

Before any model can write code, it has to learn from code that already exists. And overwhelmingly, that code comes from one place: public repositories on GitHub, supplemented by GitLab and a handful of other sources.

The most direct example is a dataset called The Stack, built by the BigCode Project (a collaboration between Hugging Face and ServiceNow). The Stack v1 contains over 6TB of permissively-licensed source code across 358 programming languages; The Stack v2 scaled that to over 3 billion files across 600+ languages. It exists specifically to train open, transparent code-generation models — and, notably, it lets developers request their code be removed from it, an acknowledgment of the ongoing debate around consent and public code being used this way.

OpenAI’s own Codex paper (2021) was explicit about its sourcing: the model was trained on 159 gigabytes of Python code pulled from 54 million public GitHub repositories, plus substantial amounts of JavaScript, TypeScript, Go, Ruby, C++, C#, Java, PHP, Swift, and more.

This is the uncomfortable-but-important fact at the center of this whole story: the reason today’s AI can write code fluently is that millions of developers, over nearly two decades, wrote code in public and explained it in READMEs, comments, and commit messages — not knowing, in most cases, that it would eventually become training material for machine intelligence. GitHub, with over 630 million repositories today (395 million of them public), is functionally the largest library of “how humans write and explain software” that has ever existed. GitLab contributes to this too, at meaningfully smaller scale, since GitHub remains the dominant home for public open-source work.

From autocomplete to Codex (2021)

The first real bridge between “a language model” and “a tool a developer actually uses” was OpenAI Codex, published as a research paper in July 2021 and released as an API that August. Codex was essentially GPT-3, fine-tuned specifically on code. It became the engine behind GitHub Copilot, which launched in technical preview in June 2021 and to the public in October 2021 — the first mainstream “AI pair programmer,” living directly inside your editor, suggesting completions as you typed.

This was a genuinely new category of tool. Before Codex/Copilot, code intelligence meant autocomplete based on syntax rules and static analysis — useful, but fundamentally mechanical. Copilot could suggest an entire function based on a comment describing what it should do. It felt, to a lot of developers in 2021 and 2022, like a genuine step-change.

By March 2023, the original Codex model itself was quietly retired — superseded by GPT-3.5 and GPT-4, which had absorbed vastly more code training data at greater scale and no longer needed a separately fine-tuned “code model” to be good at code.

A different lineage: why Anthropic exists at all

Claude comes from a different origin story entirely — one rooted less in “let’s build the best product” and more in a disagreement about how fast and how carefully AI should be developed.

Anthropic was founded on January 26, 2021, by siblings Dario Amodei and Daniela Amodei, along with five other researchers — all of whom had left OpenAI a few months earlier. Dario had been OpenAI’s VP of Research; Daniela had been VP of Safety and Policy. The group’s departure and the founding of Anthropic were driven by a belief that AI capability was scaling faster than the industry’s understanding of how to keep it safe and steerable. Anthropic was built, from day one, as an “AI safety company” — its research agenda (interpretability, alignment, constitutional AI) has always been positioned as core to the product, not an afterthought bolted onto a capabilities race.

Claude, Anthropic’s model family, launched publicly not long after, and the company has since scaled Claude into a full family of models (the naming conventions have shifted over time — Claude 3, Claude 4, and now the Claude 5 family, including the very model that helped write and structure this article).

The agentic turn: from suggesting code to doing the work

For a few years, both lineages — Copilot/Codex and Claude — mostly did the same basic thing: suggest code, complete a line, answer a question in a chat window. The human stayed in the driver’s seat for everything else: running commands, navigating files, testing, committing, deploying.

That changed with what’s now called agentic coding. Claude Code, Anthropic’s terminal-based coding agent, is a useful case study in how fast this shift happened. It reportedly started as one engineer’s side project during his first month at Anthropic, in September 2024. It launched as a limited research preview on February 24, 2025. Less than a year later, it had reportedly passed a $1 billion annualized revenue run rate — one of the fastest revenue ramps in software history.

What changed technically wasn’t just a bigger model — it was giving the model tools: the ability to read a whole codebase, run shell commands, execute tests, edit multiple files, and iterate on failures, all in a loop, with much less moment-to-moment human steering. The AI stopped being an autocomplete engine and started being something closer to a junior engineer you could hand a task to.

OpenAI moved the same direction with Codex — not the 2021 model anymore, but a 2025-era agentic coding product carrying the same name, repositioned entirely around autonomous task completion rather than line-by-line suggestion.

The lines blur: competitors become co-dependents

One detail that surprised me researching this: GitHub — Microsoft’s platform, and historically OpenAI’s closest coding-AI partner — now also ships Claude. Starting in October 2024, GitHub Copilot added Claude 3.5 Sonnet as a selectable model alongside OpenAI’s own, explicitly framed as “developer choice.” By February 2026, GitHub had Claude and Codex both available as coding agents inside Copilot, and in November 2025, Microsoft committed to continued Claude access across its entire Copilot family.

In other words: the platform most associated with OpenAI’s Codex now also distributes its safety-focused rival’s models, because customers wanted the choice. The AI coding landscape in 2026 isn’t really “Team OpenAI vs. Team Anthropic” — it’s a layered stack where the same underlying platforms (GitHub, GitLab) host the training data, the code, and increasingly the AI tools themselves, often from multiple competing labs at once.

Why this history matters to me right now

I didn’t write this because I think anyone’s waiting for another “history of AI” article. I wrote it because I just spent a session shipping a small open-source library with an AI agent doing a large share of the actual work — writing the backend, catching a privacy mistake I made, walking me through GitLab and GitHub settings I’d never touched, even helping me submit a pull request to a 35,000-star community project.

That whole experience only exists because of the chain this article traces: a 2017 research paper about language translation, that turned into an architecture general enough to learn code, trained on the accumulated public work of millions of developers who never expected their GitHub commits to become raw material for a machine’s understanding — built by two different companies with two different philosophies about how fast to move, now converging on the same category of tool: an agent that doesn’t just suggest code, but does the work.

I’m not a machine learning researcher. I’m someone who builds things — in software, and now, apparently, in the open-source world too. But understanding the tools I use, not just using them, feels like the right instinct for whatever comes next in this industry. This is a start.

Sources referenced in this piece

Insights · 13/40 06 Sep 2026

What a Brain Chip Made Me Think About the Future of the Funeral Industry

By Ts. Lukas J. Tan | 6 September 2026

This morning, 6 September 2026, I came across a social-media post about China’s progress in the global brain-computer interface (BCI) race. It immediately reminded me of a conversation that Elon Musk helped bring into the mainstream through Neuralink: the possibility that the boundary between the human brain and computers may one day become increasingly thin. Not very long ago, putting a chip into the human brain belonged largely to science fiction. Today, brain-computer interfaces are being tested on humans, governments are treating the field strategically, and the conversation is gradually shifting from whether such technology is possible to how far it should go.

Social-media headlines should always be treated carefully, particularly when they declare that one country or company has become the “world’s first”. What matters to me is not whether China, the United States, Neuralink or another organisation can claim technological leadership today. The more important signal is that brain-computer interfaces are moving from imagination towards reality, while some of the world’s most powerful governments, researchers and entrepreneurs now regard human-machine integration as a serious technological frontier.

There is also a governance question hidden inside that technological race. When technology begins interacting directly with the human brain, the discussion can no longer be limited to innovation, investment and national competitiveness. Questions of consent, privacy, neural-data ownership, medical safety, cybersecurity, accessibility and human autonomy become equally important. If a computer can one day interpret signals from our brains, who owns that information? Who may store it? Can it be transferred to another company? What protection should exist against discrimination based on neurological data? And if such technologies eventually enhance human capabilities rather than merely restore lost functions, will access be determined by medical need or by the ability to pay?

These questions may sound premature, but governance is most useful when it develops alongside innovation rather than after society has already become dependent upon it. We have seen this pattern before with social media, personal data and artificial intelligence. Technology often develops faster than the rules, institutions and social norms required to manage its consequences.

Yet strangely, after reading about the brain-chip race, my thoughts travelled somewhere completely different.

I started thinking about the funeral industry.

At first, the connection sounds almost absurd. What does a brain chip have to do with funeral homes, crematoriums, burial grounds or memorial services? But this is precisely what interests me when thinking about the future. When a technology emerges, we naturally concentrate on its immediate market. We ask which companies will win, what products will emerge and which jobs might disappear. The consequences that interest me more are often further away: the second-, third- and fourth-order effects that appear only after technology begins changing human behaviour and social structures.

If technology changes how we work, it changes how we use our time. If it changes how we use our time, it can influence relationships, caregiving and family formation. When families change, demographics change. And when demographics change for several generations, almost every institution and industry eventually feels the effect—including industries that appear to have nothing whatsoever to do with technology.

That was the chain of thought that began with a brain chip.

A Demographic Change Is Also a Social Change

Long before brain chips become commonplace, another enormous transformation is already happening around us: the world is producing fewer children.

The United Nations’ World Population Prospects 2024 estimated that global fertility has fallen substantially over recent generations, from approximately 3.3 births per woman in 1990 to around 2.25 today. More than half of the world’s countries and territories are already below the replacement fertility level of approximately 2.1 births per woman. Low fertility is therefore no longer an isolated demographic problem belonging only to Japan, South Korea or a handful of European economies. It is becoming a structural issue across a growing part of the world.

It would be easy to look at these numbers purely as statistics. I think that would miss the human story behind them.

People do not decide whether to have children according to a demographic chart. They make those decisions within the realities of their lives: whether housing is affordable, whether employment feels secure, whether childcare is available, whether they have time to care for ageing parents, whether a career can coexist with parenthood, and whether raising a family feels economically and emotionally sustainable.

For women especially, the question can involve difficult trade-offs between professional opportunities, caregiving expectations and motherhood. For younger generations generally, delaying marriage or parenthood may not simply represent changing values; it may also reflect the economic environment they have inherited.

Therefore, falling fertility should not automatically be framed as young people “refusing” to have children. It should also prompt governments, employers and communities to ask whether the societies we are building make family life realistically sustainable.

China is particularly important because of its scale, but the issue extends much further. Demographic change moves slowly through society, almost like a wave travelling from one institution to another. Fewer births eventually mean fewer pupils entering schools. Later, universities compete for a smaller student population. Eventually, fewer young people enter the labour market. Housing demand changes, consumption patterns change, healthcare requirements change and a smaller working population may have to support a larger retired population.

A child who is not born today does not change the labour market tomorrow morning. But that missing person will never enter the workforce twenty years from now.

The same delayed effect eventually reaches the funeral industry.

We tend to regard funeral services as one of the few businesses with permanent demand because death itself cannot disappear. Every person alive today will eventually die. From a demographic perspective, however, there is an important distinction between the certainty of death for an individual and the number of deaths occurring within an entire society.

In the near and medium term, ageing populations could actually create greater demand for funeral and memorial services. Therefore, I would not argue that declining fertility means funeral businesses are about to decline tomorrow. The demographic lag could take decades.

My question concerns what happens afterwards.

Imagine a country remaining significantly below replacement fertility for thirty, forty or fifty years. Each generation becomes smaller than the one before it. Eventually, the large older generations pass away. Behind them are smaller middle-aged generations, followed by even smaller younger generations. Unless migration or a meaningful recovery in fertility compensates for that decline, the total population eventually contracts.

At that point, even the business of death encounters demographic mathematics.

Fewer births today can eventually mean fewer deaths decades later.

But this should not be viewed merely as a prediction about market size. A shrinking and ageing society creates much broader responsibilities. There may be fewer working-age adults caring for more elderly people. More people may grow old without children. More people may live alone. Governments may face greater pressure on healthcare, pensions and long-term care, while communities confront questions about loneliness, social isolation and who takes responsibility when family support is no longer available.

The future of the funeral industry is therefore only one small part of a much larger social transformation.

AI May Save Time Without Giving Us More Life

This is where artificial intelligence enters my thinking.

One of AI’s strongest promises is productivity. Work that previously required hours can increasingly be completed in minutes. Research can be accelerated, documents drafted, information analysed, software developed faster and repetitive administrative work automated. As AI agents become more capable, one person may eventually perform an amount of work that previously required several people.

Logically, greater productivity should mean that human beings become less busy.

I am not convinced that this will necessarily happen.

History suggests that when technology increases human capacity, society frequently responds by increasing its expectations. Email made communication faster, yet it did not necessarily reduce the amount of communication expected from us. Smartphones enabled us to work from almost anywhere, but they also made us reachable almost everywhere. Cloud technology made information accessible twenty-four hours a day, while simultaneously allowing work to follow us beyond the office.

AI could take this pattern much further. If someone becomes twice as productive with AI, the economic outcome may not be that the person works half the day and spends the remaining hours with family. The organisation may simply redefine what one employee is expected to accomplish. What once required five people might be assigned to two. What once took a week may be expected tomorrow.

This is not merely a productivity question. It is a governance and leadership question.

If AI creates enormous productivity gains, we will eventually need to ask who receives the benefit. Does it appear only as higher output and lower labour costs, or can some of that productivity be returned to human beings in the form of better work, greater flexibility, more family time, lifelong learning and improved quality of life?

Technology itself cannot answer that question. Leaders, organisations and public policy will.

This matters because decisions about having children are influenced by far more than biology. Housing, financial security, working hours, childcare, education, relationships, career expectations and the distribution of caregiving responsibilities all contribute to the environment in which people decide whether parenthood is possible.

It would therefore be too simplistic to say that AI will reduce fertility. But it is reasonable to ask whether an AI-enabled economy could unintentionally intensify conditions already making family formation difficult.

This creates what I see as one of the great paradoxes of the coming AI era: we may invent machines specifically to save human time, yet create an economic system that immediately consumes every minute those machines save.

The real measure of AI progress should therefore not be productivity alone. A society that produces more but leaves people with less time for family, community, health and human relationships may be technologically efficient without necessarily becoming more human.

When Technology Moves From Our Hands Into Our Bodies

The brain-chip conversation, made globally visible in large part by Elon Musk and Neuralink, introduces an even more fundamental governance challenge. Until recently, most digital technology existed outside us. Computers sat on desks, smartphones moved into our pockets and smartwatches onto our wrists. Brain-computer interfaces represent a much more intimate frontier: technology interacting directly with the human nervous system.

This naturally raises questions about long-term health and biological exposure, but here we should be careful about separating evidence from speculation. Current scientific evidence does not justify stating as fact that AI devices, ordinary wireless technologies or brain-computer interfaces cause declining human fertility. Researchers have investigated radiofrequency electromagnetic fields and reproductive indicators, including sperm motility and oxidative stress, but findings remain mixed and do not establish a simple causal relationship.

For me, however, the absence of a proven answer does not make the question irrelevant. It tells us where further research and governance will be needed.

The technological environment surrounding a human being in 2050 or 2070 could be fundamentally different from today. We may live continuously alongside intelligent environments, autonomous systems, wearable AI, augmented-reality devices and perhaps implanted interfaces. What are the biological, psychological and social consequences of living within such an environment for fifty or seventy years? We cannot yet answer that confidently.

The responsible approach is neither to create fear without evidence nor to assume that every innovation is harmless until proven otherwise. It is to continue research, establish appropriate safeguards and ensure that commercial competition does not move faster than our ability to protect human wellbeing.

Brain-computer interfaces make this particularly important because brain data is unlike ordinary personal data. A password can be changed. A credit card can be cancelled. Neural information may reveal something far more intimate about an individual. As these technologies develop, societies may eventually need concepts such as neural privacy, cognitive liberty and explicit rights over brain-generated data.

The technological race therefore should not simply be about who becomes first.

There is another race that matters just as much: who can build the governance capable of making the technology trustworthy?

From the Funeral Industry to the Question of Human Dignity

Following these trends further changed my original question. Perhaps the future challenge for funeral businesses is not simply whether there will eventually be fewer funerals. A deeper transformation could come from the changing structure of the family itself.

Funeral traditions were developed around families and communities. This is especially visible across Asian cultures. When a person dies, children, grandchildren, siblings, relatives and friends participate in the process. Someone organises the funeral, someone handles burial or cremation, someone maintains the grave or memorial, and someone carries family memories into the next generation.

But what happens after several decades of very low fertility?

A family with five children and fifteen grandchildren has a very different support structure from a family with one child. A couple without children has another structure entirely. As more people grow old alone or without descendants, society will face questions extending far beyond the funeral ceremony itself.

Who supports someone through the final years of life? Who makes decisions when that person loses capacity? Who arranges the funeral? Who maintains the memorial? Who protects their possessions and records? And who makes sure that a person without descendants receives the same dignity at the end of life as someone surrounded by a large family?

These are not simply commercial opportunities. They are social responsibilities.

Governments, healthcare providers, communities and businesses may eventually need new systems for people ageing without traditional family support. Funeral providers could become part of that ecosystem, but their future role may extend beyond handling death towards protecting dignity, memory and legacy.

The digital dimension makes this even more significant. People already leave enormous digital footprints: photographs, videos, emails, social-media accounts, cloud files, messages, voice recordings and years of written communication. AI could eventually organise these materials into detailed personal histories and interactive memorials. People may begin planning their digital legacy before death in much the same way they prepare wills or insurance today.

This could transform part of the funeral industry into something broader: a legacy industry.

Yet this transformation will also require governance. Who owns a deceased person’s data? Should a company be allowed to create an AI representation of someone who never consented to it? Who has the right to deactivate such a representation? Can someone’s voice or likeness continue to be commercially exploited after death? Should an AI simulation of a deceased parent be available indefinitely to a child?

The technology to do some of these things may arrive before society has decided whether they should be done.

That is why innovation and governance cannot be separated.

The future funeral provider may eventually preserve not only physical remains but digital identity and human memory. If that happens, the industry will inherit an enormous responsibility: to protect dignity after death in the same way that other institutions are expected to protect dignity during life.

The Future Is Not Only About What We Can Build

I am deliberately recording these thoughts on 6 September 2026 because observations about the future are easy to make after the future has arrived.

I do not know whether the funeral industry will ultimately shrink. I do not know whether global fertility will remain low for the rest of this century. Governments may develop more effective family policies. Migration may reshape national populations. Medical science could extend healthy lifespan substantially. AI could ultimately give people greater freedom rather than increasing work pressure. Technologies we cannot yet imagine could change every assumption in this article.

Nor am I suggesting a simple relationship of brain chips causing lower fertility and lower fertility causing the funeral industry to collapse. Human society is far too complex for such a straight line.

What interests me is the chain of signals.

Brain-computer interfaces tell us that technology is moving closer to the human body. Artificial intelligence tells us that the relationship between labour and productivity is changing. Falling fertility tells us that family formation and population structures are changing. Ageing societies tell us that responsibility between generations will become increasingly difficult. Digital identity tells us that what a person leaves behind after death is becoming much larger than physical possessions.

Individually, none of these signals tells us exactly what society will look like in 2050 or 2070. Together, however, they encourage us to ask questions earlier.

When Elon Musk helped bring brain chips into mainstream conversation, the obvious question was what a brain-computer interface could enable. As China accelerates its own ambitions, another obvious question is who will lead the technological race.

I increasingly believe there is a more important question: what kind of society are we creating if all of this succeeds?

Technology changes human capability. Capability changes expectations. Expectations influence behaviour. Behaviour affects families. Families shape demographics. Demographics reshape economies and industries. At every stage of that chain, however, there is also a governance decision. We can decide how technology is regulated, how productivity gains are shared, how families are supported, how ageing populations are cared for, how personal data is protected and how dignity is preserved after death.

That is why technological progress should not be measured only by what becomes technically possible.

A country can win a technology race and still face profound social challenges. A company can achieve extraordinary productivity while its people struggle with time and family. An industry can successfully digitise itself while failing to protect the dignity and privacy of the people it serves.

The future I am interested in is therefore not simply a more advanced future.

It is a future in which innovation, society and governance advance together.

Perhaps decades from now, the funeral industry will remain largely as we know it today. Perhaps population decline will eventually reduce its traditional volume. Perhaps it will evolve into an industry centred as much on memory, identity and legacy as on death itself. I cannot know which outcome will prevail.

What I can do is record what I saw from where I was standing.

On 6 September 2026, a story about China and the brain-chip race reminded me of a conversation Elon Musk helped bring into public consciousness years earlier. But instead of making me think only about the future of computers, it made me think about the future of people: how we work, how we build families, how we age, how we care for one another, and eventually how we preserve dignity when a human life comes to an end.

Whenever I encounter a new technology today, I try not to stop at the most immediate question: what can this technology do?

I try to follow it further and ask: if this becomes normal, what else will change—and are our society and governance ready for what follows?

Because perhaps the most important measure of technological progress will not be how closely we can connect humans to machines.

It will be whether, after doing so, we still know how to put human beings first.

Insights · 14/40 17 Aug 2026

The Courage to Delete: What the AI Era Is Teaching Me About Business, Technology and Survival

We Used to Build. Then AI Changed the Equation

Over the past year, my team and I have built many internal systems to make our business operations smoother, faster and more efficient. Some of these systems were created for email management, message polishing, data scraping, email blasting, proposal writing and other repetitive business tasks that, at the time, genuinely required dedicated tools. We built them because they solved real problems. They reduced manual work, gave us greater control over our processes and allowed us to operate more efficiently. Like many technology companies, we believed that building our own systems was a sign of progress. If there was a business problem, we would design a workflow, write the code and create a solution around it.

Then AI arrived, and the equation changed far more quickly than most of us expected.

Many tasks that previously justified building an entire internal system can now be completed through AI with dramatically less effort. Writing and polishing business messages no longer requires the same kind of dedicated workflow. Proposal writing can be accelerated with AI. Research, content drafting, data processing and even parts of software development can now be handled in ways that would have sounded unrealistic only a few years ago. When the technology around us changes this quickly, the question is no longer simply, “What else should we build?” The harder and more important question becomes, “What should we stop maintaining?”

The Weight of What We Never Deleted

That was the question I found myself confronting this year.

We had several systems and projects sitting on our servers that had not been actively used for a long time. Some were internal tools that had been replaced by better solutions. Others were old client projects, dummy environments or discontinued applications that remained there simply because nobody wanted to delete them. They were not necessarily causing an immediate problem, but they occupied space, consumed attention and represented another layer of complexity inside our technical environment. More importantly, they carried a strange emotional weight. Anyone who has spent time building software will understand this feeling. You remember the effort that went into a project. You remember the nights spent debugging it, the ideas behind it and the moment it finally worked. Even when the system has become irrelevant, deleting it can feel like throwing away part of your own history.

For years, some of these projects remained untouched because of the same familiar thoughts: perhaps we might need them one day; perhaps there was something useful hidden inside; perhaps we should keep a backup just in case; perhaps it was safer not to touch anything. This is how digital clutter accumulates. One inactive project becomes five. Five become twenty. Old databases sit beside new ones. Forgotten backups remain in folders. Temporary files become permanent. Nobody remembers which version is important anymore. Eventually, a server begins to resemble a storeroom that has not been cleaned for ten years.

This Year, I Decided Enough Was Enough

This year, I decided that enough was enough.

Some of those projects had been sitting not only on our servers, but also in my mind, for several years. I knew they were no longer useful, yet I still felt reluctant to remove them. This year, and especially over the past few days, we finally deleted them completely. Not moved into another folder. Not renamed as “OLD”. Not archived somewhere simply to avoid making a decision. Deleted.

The feeling was unexpectedly liberating.

Transformation Is Not Always About Adding

It reminded me that digital transformation is not always about adding something new. Sometimes transformation begins with the courage to remove what no longer belongs. In business, we often celebrate expansion. We talk about adding new platforms, new automation, new software, new AI tools and new systems. Very rarely do we celebrate subtraction. Yet every new digital layer creates another responsibility: another login, another database, another integration, another renewal date, another potential security exposure and another system that somebody eventually has to understand.

AI is making this issue even more important. Because software can now be created faster and more cheaply, companies may end up creating even more digital clutter than before. An employee can use AI to develop a small application. A department can automate a workflow independently. A team can build an AI agent to connect different services. All of this is powerful, but the lower cost of creation does not eliminate the future cost of ownership. Someone still has to know what the system does, where the data is stored, who owns it, whether it is secure, whether it should still be running and what happens when it fails.

In other words, AI makes creation easier, but it makes digital discipline even more important.

Playing “Digital Doctor”

That thought became especially clear to me over the past two days, when I unexpectedly found myself playing a role that I now jokingly describe as a “digital doctor”.

The first situation involved a system that we had developed for a client some time ago. The application had been stable for a long period and therefore had not required much maintenance. Like many business systems, it continued operating quietly in the background until one day something went wrong. When the client contacted us, we had to return to code that we had not looked at seriously for years.

That experience was almost like digital archaeology.

Digital Archaeology

When you are actively developing a system, the logic feels obvious. You remember why each module exists, how different functions are connected and why certain technical decisions were made. Years later, that context disappears. The source code is still there, but the human memory surrounding it is gone. You look at an old function and ask yourself why it was written that way. You trace one module into another. You examine the database structure, follow the application flow and try to reconstruct the thinking of the developer who built it — even when that developer may have been your own team.

We spent almost the entire day doing exactly that. We reviewed the old logic, traced the issue, tested different possibilities, repaired the affected components and made sure that the fix did not create another problem somewhere else in the system. By night, the application was functioning correctly again and had been deployed.

There is a particular kind of satisfaction that comes from solving this type of problem. Building something new is creative. Repairing a legacy system is investigative. You are not starting with a blank page. You are entering an environment filled with previous decisions, forgotten assumptions and technical history. You have to diagnose before you can treat.

The Second Case: A Server That Kept Failing

The second case was significantly larger.

This client had been operating a critical business application on a server environment that had been causing problems for years. The server would become unavailable two or three times a year. Each time it happened, the impact on the business was serious because the company relied heavily on the system for its daily operations. When the server went down, the company’s ability to function was affected. Staff could not access what they needed, work slowed down and everyone waited anxiously for the system to recover.

For almost two years, I had been encouraging the client to move to a more reliable environment.

The answer was always complicated. A new server costs money. Migration takes time. Moving a large system carries risk. There may be downtime. Something may break during the transition. The existing setup, although unreliable, was familiar. This is one of the most common challenges in digital transformation: companies often know that something is risky, but as long as it is still working today, the urgency to change disappears.

Every outage created pain. Once the system came back online, the pain was forgotten.

Eventually, I told the client very directly that if they continued refusing to migrate, there was little more I could do. I had been following the issue for almost two years. At some point, a business has to decide whether the cost of change is greater than the cost of continued risk.

This time, the client finally decided to move.

What We Found Inside

Once we began the migration, it became clear that this was not simply a matter of copying files from one server to another. The environment included multiple applications and around six subdomains, together with a large database. The overall data volume was approximately 40 to 50 gigabytes. Even downloading, transferring and organising that amount of material was already a significant exercise.

But the real problem was not the size. It was what we discovered inside.

There were old application files, unused folders, historical backups, temporary files, unnecessary logs and remnants from previous development work. Over the years, different people had worked on the system. Different things had been added. Very little had been removed. The application had continued running, but the technical environment around it had gradually become more difficult to understand and manage.

This is more common than many business owners realise.

A business system may survive for ten or fifteen years. During that time, developers change, vendors change, employees resign, operating systems are upgraded, hosting providers change and business requirements evolve. Every generation adds something. Very few generations take responsibility for cleaning up what came before. Eventually, the system still works, but nobody has a complete picture of how everything fits together.

Cleaning the Digital House

At that point, a server migration becomes more than a technical exercise. It becomes an opportunity to clean the digital house.

That is exactly what we are doing now. Instead of simply moving all the old files into a new server and carrying years of unnecessary baggage with us, we are reviewing the application, removing what is no longer needed, organising the source code, cleaning the environment and preparing the project to be properly managed through GitLab. Once that process is completed, the cleaned and organised application can be deployed into the new server environment with a much clearer technical structure.

As I write this article, the work is roughly halfway completed.

The Real Cost of Neglect

It has been tiring, messy and at times painfully slow. Moving tens of gigabytes of data is not glamorous work. Searching through old folders is not the kind of technology story that normally appears in marketing material. There are no dramatic AI demonstrations, no shiny dashboards and no impressive product launches.

Yet this kind of work may be far more important to a business than another new AI tool.

When a legacy application fails, the consequences can be immediate. A business may lose access to customer information, inventory records, financial processes, internal workflows or operational data. Employees may be unable to continue their work. Management may suddenly realise that nobody knows where the latest source code is stored. The developer who originally built the system may no longer be available. Passwords may be scattered across different people. Backups may exist, but nobody knows whether they can actually be restored.

Technology problems rarely arrive at a convenient time.

A Digital Housekeeping Problem

This is why I increasingly believe that many companies do not necessarily have a technology problem. They have a digital housekeeping problem.

The first question should not always be, “What new system should we buy?” Sometimes the better questions are much simpler. What systems do we already have? Which of them are critical? Who owns the domains? Where are the databases? Where is the latest source code? Who has access to the server? When was the last backup tested? Which applications are still being used? Which systems are no longer necessary? What would happen if a key server stopped working tomorrow?

These questions may not sound innovative, but they determine how resilient a company really is.

The arrival of AI does not make these fundamentals less important. It makes them more important.

Innovation Needs Discipline, Not Just AI

As AI becomes embedded in more business processes, companies will connect more systems, generate more data and automate more decisions. Without discipline, the technology environment will become increasingly complicated. If companies simply add AI on top of years of technical debt, they may create faster systems without creating healthier systems.

A healthy digital organisation requires both innovation and maintenance. It needs the courage to experiment, but also the discipline to clean. It needs the ability to build new systems, but also the wisdom to retire old ones. It needs AI, but it also needs governance. Most importantly, it needs people who are willing to examine the messy parts of the business that nobody else wants to touch.

Why I Enjoy These Messy Problems

This is where I realised something important about myself.

I enjoy these messy problems.

Give me a straightforward software project and I can work through it. But give me a system that nobody understands anymore, a server that keeps failing, an old database that has grown out of control, an application left behind by a previous vendor or a problem that everyone has been avoiding for years, and I become genuinely interested.

I want to know what happened.

I want to understand how everything is connected.

I want to identify what is unnecessary.

I want to repair what still matters.

I want to organise the environment properly.

And I want to see the business regain control over something that had become a source of frustration or risk.

Becoming an “Enterprise Digital Doctor”

That is when the idea of being an “Enterprise Digital Doctor” suddenly began to make sense to me.

A doctor does not begin treatment by prescribing random medicine. The first responsibility is diagnosis. A patient may describe one symptom, but the real cause may be something completely different. Digital problems are similar.

A company may say its website is slow, but the real issue may be poor server architecture. A business may say it needs a new system, when the real problem is that three existing systems are doing overlapping jobs. Management may say it needs AI, when the company actually needs cleaner data and better processes first. A team may believe it needs a bigger server, when the real problem is years of unmanaged files and inefficient application design.

The visible problem is not always the real problem.

Diagnosis must come before development.

The Right Technology, in the Right Place, for the Right Reason

For many years, companies like ours were mainly expected to build things: websites, ecommerce platforms, internal systems, applications and digital tools. We still do that, and building will remain an important part of our work. But I increasingly believe that the greater value lies in understanding what the business truly needs before another system is created.

Sometimes the correct prescription is a new application. Sometimes it is AI. Sometimes it is migration. Sometimes it is restructuring. Sometimes it is better governance. Sometimes it is simply cleaning up years of technical debt.

And sometimes, the best solution is to delete something.

That may be one of the most important lessons the AI era is teaching me.

Transformation is not always about having more technology. It is about having the right technology, in the right place, for the right reason.

Companies that learn how to let go of unnecessary systems, protect the systems that still matter and introduce new technology with discipline will be in a much stronger position to survive the next wave of change.

As for me, I think I have found one part of my work that I genuinely want to do more of.

When a business has a digital problem that has become too complicated, too old, too messy or too difficult for anyone to understand, I want to be the person who comes in, examines the symptoms, identifies the real cause and helps bring the system back to health.

Perhaps “Enterprise Digital Doctor” sounds unconventional.

But after the past few days, it feels surprisingly accurate.

Insights · 15/40 16 Aug 2026

What I Learned from Using AI to Build Real Software

Beyond AI-Generated Code

Over the past few months, I have worked extensively with Claude, ChatGPT and Codex on real software development projects. The result has been more than a collection of AI-generated code. I have gradually developed a practical method for helping AI understand a software project, follow its rules, execute tasks and improve the system—without allowing the process to drift out of control.

The Question Behind the Work

A large part of my time has been spent trying to answer one deceptively simple question: How do I communicate with AI so that it truly understands what I want?

Easy Answers, Difficult Systems

Chatting with AI is easy. Getting an answer is easy. Generating code is becoming easier every day. Building a dependable system that people can safely use, however, is a completely different challenge.

A Software Engineer's Perspective

Coming from the software industry, I naturally brought my usual concerns into the process. Is the architecture stable? Is the database designed correctly? Who can access each function? What happens when something fails? How is the data protected? These questions remain essential, regardless of whether the code is written by a person or generated by AI.

Control, Quality and Accountability

I also had to consider how the system would preserve a complete history, who would be responsible for checking quality and which decisions could safely be made by AI. Just as importantly, I needed to identify the decisions that still required human judgement and determine whether the entire process could be repeated consistently.

Teaching AI How to Think With Me

The deeper I went, the more I realised that this was no longer simply about using AI to write software. It was about teaching AI how I approach problems, structure systems, evaluate risks and define an acceptable result.

Working Is Not the Same as Reliable

AI can produce a feature remarkably quickly. The screen may look correct, the button may work and the system may even pass a basic test. But none of these things guarantees that the underlying system has been designed properly.

The Problems Beneath the Surface

A working interface does not prove that the database is well structured. A successful test does not guarantee that access controls are secure. A feature that works today may still introduce weaknesses that cause another part of the system to fail later.

The Three-Month Test

The real measure of software is not simply whether it works at launch. It is whether the system remains understandable, maintainable and safe to change months or years later. Something that functions perfectly today can still become a system that nobody dares to touch three months from now.

Confidence Without Understanding

This is one of the greatest dangers of AI-assisted development: AI may not fully understand the requirements, yet it can still complete the task with remarkable confidence. The result can look convincing enough that important design flaws remain unnoticed.

A Challenge Across Every AI Platform

This is not a problem unique to Claude. The same issue appears when working with ChatGPT, Codex and other AI agents. Different tools may have different strengths, but all of them depend on the quality of the context, rules and boundaries they receive.

Code Is No Longer the Main Question

The real challenge is no longer whether AI can write code. It clearly can. The more important question is whether we can provide enough context and guidance for AI to produce work that genuinely meets our technical, operational and business standards.

Building Structure Around AI

To address this, I began placing more structure around the development process. This included requirement records, database rules, access controls, issue tracking, version control, testing checklists, audit logs and clearly defined human approval points.

Creating Organisational Memory

I also needed the project’s knowledge to survive beyond a single conversation, computer or AI session. Important decisions cannot remain trapped inside temporary chat histories or in the memory of one person.

Preparing for the Next AI

If another AI takes over the project later, it should be able to understand what was built, why certain decisions were made and which parts of the system must not be changed without proper review. Continuity becomes essential when multiple people and AI agents contribute to the same system.

Software Engineering Matters More Than Ever

This experience has made me appreciate software engineering even more. AI can accelerate development, but speed does not remove the need for architecture, security, governance, documentation and disciplined decision-making.

The Most Valuable Skill in the AI Era

In the AI era, the most valuable person may not be the one who writes code the fastest or produces the longest prompt. It will be the person who understands the industry, translates real business needs into clear system rules and knows how to judge whether AI has delivered the right outcome.

Industry Knowledge Cannot Be Replaced

AI cannot replace industry understanding. It amplifies it.

AI Amplifies What Already Exists

When you understand your industry well, AI can amplify your experience, judgement and ability to solve problems. But when processes are unclear, data is disorganised and responsibilities are undefined, AI will amplify those weaknesses too.

Turning Knowledge Into Systems

At OPERiON, we help businesses transform their industry knowledge into structured systems and practical AI solutions—supported by the right processes, controls and human judgement.

Moving Beyond Experimentation

If you are ready to move beyond experimenting with AI and begin applying it meaningfully to your business, let’s have a conversation.

Your Business, Amplified

Your knowledge. Your systems. Your business—amplified.

Insights · 16/40 15 Aug 2026

When AI Can Write Most of the Code, Where Does a Programmer's Value Lie?

Technology Professionals Know That Some Things Can Be Said—and Some Cannot

Those of us in the technology industry understand how quickly the market is changing. If a software company openly tells every client, “Most of your project was developed using AI,” the client’s first reaction may not be excitement. Instead, the client may ask: “If AI can do it, why should I pay a software company?”

However, even if we choose not to talk about it, the market will eventually discover the truth. AI web coding, vibe coding and automated development tools are already transforming the software industry. They can generate websites, dashboards, system modules and applications faster than ever before.

The real question is no longer whether we should use AI. The more important question is this: when almost anyone can use AI to generate code, what is the real value of a professional programmer or software company?

AI Can Write Code, but It May Not Understand the Business

AI can quickly produce a website, an API, a backend module or even an application that appears complete. However, a system that can run is not necessarily a system that is suitable for the business. It may also be unable to support the organisation over the long term.

A company does not simply need attractive screens and working buttons. It needs a solution capable of handling real business processes, operational exceptions, data accuracy, security risks and future growth.

What are the company’s actual business rules? Which processes should be automated? Which decisions must remain under human control? What happens when the number of customers, transactions or system users increases tenfold? Who should be allowed to view, edit, approve or export sensitive information?

These questions cannot be answered reliably through a single prompt. They require business understanding, technical experience and human judgement.

Foundational Knowledge Determines How Far a System Can Go

As we use AI to perform more programming work, foundational technical knowledge becomes more important—not less.

How should the data be collected? What information should be mandatory? How should the fields be defined? How should the database be structured? What should be used as the primary key? How should foreign keys connect different tables? Which data should be stored separately, and which information should be linked?

AI may suggest an answer, but a human professional must determine whether that answer is appropriate.

If the foundation is wrong, AI will simply help us produce the wrong system faster. A system may appear to work when it contains only a small amount of test data. Problems may emerge later when the data volume grows, multiple users operate the system simultaneously or the application must integrate with other platforms.

AI can accelerate development, but a knowledgeable technical professional must still decide whether the system is moving in the right direction.

The Real Expertise Lies Between Raw Data and the Final Result

Many people assume that once a large amount of data is given to AI, it can automatically generate valuable answers. In reality, there is a long and complicated journey between raw data and a trustworthy result.

The data may need to be cleaned, categorised, verified, linked and interpreted. Duplicate records must be identified. Missing information must be handled properly. Different access levels must be established. Exceptions and unusual cases must be investigated.

Which data can be trusted? Which records are incomplete? Should missing information be removed, corrected or retained? Does the same measurement carry the same meaning across different departments? Is the final result technically accurate but commercially misleading?

Without industry knowledge and domain expertise, a large dataset may produce an answer that looks convincing but is fundamentally incorrect.

The value of a technology professional is not limited to processing data. It also comes from understanding why the data appears in a particular way, recognising what may be missing and determining whether the result can be used responsibly by the business.

Programmer, Where Does Your Value Truly Lie?

Every programmer should now ask a difficult but necessary question: if AI can already generate most basic code, what additional value do I provide?

Knowing how to write code remains useful, but “I can programme” may no longer be enough to create a sustainable competitive advantage.

Your value may come from system architecture, database design, cybersecurity, software integration, performance optimisation or business analysis. It may come from your ability to transform an unclear business request into a structured and practical solution.

Your value may also come from recognising risks before they become expensive problems. It can be found in your ability to communicate with clients, coordinate with a technical team, make responsible architectural decisions and respond calmly when a live system fails.

The most valuable technology professional of the future may not be the person who writes the largest amount of code. It may be the person who understands what should be built, why it should be built that way, what could go wrong and how to recover when something fails.

Ten Programmers Do Not Automatically Create Ten Different Levels of Value

Imagine a company with ten programmers who possess similar knowledge, perform similar tasks and produce similar results. Once the organisation establishes a mature AI development framework, proper governance, reusable components and standard operating procedures, work that previously required ten people may be completed by a much smaller team.

This may be uncomfortable to hear, but avoiding the discussion will not stop the change from happening.

Some positions will be reduced. Some responsibilities will be combined. Some programmers may leave employment and start their own businesses. Others may move into entirely new technical roles.

The future may create greater demand for solution architects, AI workflow specialists, data specialists, system auditors, product owners and technical leaders who can review and govern AI-generated work.

The goal should not be to preserve an old job title forever. The goal is to develop capabilities that remain valuable even as the tools, workflows and size of development teams continue to change.

People Who Have Completed—and Rescued—Real Projects Remain Rare

At OPERiON, we are not only interested in how many websites or systems someone has built. We value people who understand the complete project lifecycle.

This means being involved in gathering requirements, planning the architecture, designing the database, developing the solution, testing it, launching it and maintaining it after deployment. It also means taking responsibility when real users begin using the system and unexpected problems appear.

Even more valuable are professionals who have taken over troubled or failed systems. They know how to investigate an unfamiliar codebase, identify structural weaknesses, repair damaged data, correct business logic and stabilise the system without causing further disruption.

Building a new system requires technical ability. Maintaining a live system requires discipline and responsibility. Rescuing a failing system requires experience, patience, sound judgement and the courage to make difficult decisions.

These capabilities will not disappear because of AI. In an environment where software can be produced faster than ever, the ability to evaluate, govern, maintain and rescue systems may become even more valuable.

Job Loss Is Not the End—It Can Be the Beginning of a New Direction

Whether the future brings a career transition, a smaller development team or an unexpected job loss, technology professionals must continue moving forward with a positive and practical mindset.

OPERiON will be opening new opportunities through an IT Specialist talent initiative. We are looking for experienced professionals who have spent at least seven years in the technology field, managed projects from beginning to completion, and remained involved during the maintenance stage.

We are particularly interested in people who have repaired, recovered or rescued systems that were failing. We want professionals who can do more than generate code—people who can understand business requirements, make sound technical decisions, take ownership and solve difficult problems.

If your career is currently going through a major change, do not immediately conclude that your experience has become irrelevant. The knowledge you accumulated through real projects, system failures, difficult clients and operational challenges may now be your greatest professional asset.

You are not necessarily being replaced by technology. You may simply have arrived at a point where you must redefine your value.

For capable, responsible and experienced technology professionals who are willing to keep learning, OPERiON hopes to offer more than another job opportunity. We want to become a new source of hope—and the beginning of the next chapter in your professional journey.

Insights · 17/40 13 Aug 2026

In the AI Era, Complexity Is the Real Security Risk

Synopsis

A company may own several domains, use different hosting providers, purchase SSL certificates separately and manage multiple renewal dates—yet still have no clear picture of how everything connects. This is not merely a technical inconvenience. It is a business continuity, security and governance risk. As AI introduces even more platforms and solutions into the workplace, leaders must resist the temptation to keep adding. The priority should be to simplify, consolidate and regain control.

The Conversation Started With a Website

During a recent client discussion, we began with what appeared to be a straightforward topic: the company’s website.

As the conversation progressed, however, the client explained that one domain had been registered with one provider, while another domain was managed through a different platform. The website was hosted elsewhere, and its SSL certificate came from yet another provider.

The client knew these services existed, but could not clearly explain which domain was connected to which server, where the SSL certificate was managed or which account controlled each component.

Every service also had a different renewal date.

From the client’s perspective, everything was technically operating. From a governance perspective, however, the entire arrangement had become dangerously unclear.

When Digital Assets Become Invisible

Many companies face the same problem. Their websites, domains, email systems, hosting accounts and security services were not necessarily planned as one complete architecture.

Instead, they were accumulated over time.

One provider registered the first domain. Another vendor developed the website. Someone else purchased the hosting package. A former team member created an account for the SSL certificate. Years later, nobody has a complete record of what the company owns, where it is located or who has access to it.

This creates a form of invisible operational risk. The website may be functioning today, but a missed renewal, expired credit card, inaccessible email account or departed team member could suddenly interrupt the business.

The company owns the digital assets, but it may not truly control them.

The First Recommendation Was Consolidation

Our advice to the client was simple: consolidate wherever practical.

If the company does not need two hosting servers, reduce them to one. If there is no strategic reason to manage domains across several registrars, consider transferring them to one trusted provider. If multiple services perform the same function, eliminate the duplication.

Most domain names can be transferred from one registrar to another, subject to the domain extension’s policies, transfer eligibility and security requirements. A domain is not normally locked permanently to the company where it was first registered.

The objective is not to force everything into one platform at any cost. The objective is to reduce unnecessary fragmentation.

Every additional provider creates another account, password, renewal date, invoice, support channel and potential point of failure. Consolidation gives management a clearer view of its digital assets and reduces the effort required to protect them.

We Drew the Architecture on the Spot

During the meeting, I drew a simple diagram for the client.

It showed where the domains were registered, which domain was connected to which server, where the website was hosted, how the SSL certificate was applied and which accounts provided administrative access.

That simple diagram immediately changed the conversation.

What had previously been stored as fragmented information in different people’s memories became visible on one page. The client could finally see the relationship between the domain, DNS, SSL, server, website and account access.

Every company should maintain this type of digital asset record. It should include the provider, account owner, administrator access, renewal date, payment method, responsible team member and recovery information for every critical service.

Documentation is not paperwork for its own sake. It is part of security, continuity and governance.

Not Every Website Needs an Expensive SSL Package

The client then asked whether a separate paid SSL certificate was necessary.

The answer depends on the website, its technical environment and the organisation’s compliance requirements. For a relatively straightforward information-based corporate website, a separately purchased premium SSL certificate may not always be required.

A properly configured Cloudflare setup, for example, can provide SSL/TLS capabilities together with DNS management, content delivery, traffic filtering and protection against certain forms of malicious activity.

This does not mean that Cloudflare automatically solves every security issue. The configuration must still be correct, and the connection between Cloudflare and the origin server must also be protected. However, it can reduce the number of separate products that a company needs to purchase and manage.

Again, the principle is not simply to choose the cheapest service. It is to select an appropriate level of protection without introducing unnecessary complexity.

Cloudflare Can Add a Protective Layer

Without an intermediary layer, a domain may point directly to the web server. Depending on the configuration, this can expose the server’s origin IP address and allow traffic to reach it directly.

With Cloudflare acting as a proxy, visitors first connect through Cloudflare before their requests are forwarded to the origin server. This can help mask the server’s IP address, filter unwanted traffic and provide an initial protective layer.

However, masking the IP address is only effective when the origin server is also configured to prevent unauthorised direct access. Cloudflare should be treated as one layer within the security architecture, not as a replacement for server hardening, access control, patching, backups and monitoring.

Security becomes stronger when each layer is understood and intentionally managed.

Security Must Match the Business Risk

The client then asked how far website security should go.

For an information-based website with no customer accounts, online payments or sensitive personal data, the security architecture does not necessarily need to be excessively complicated. It still requires proper protection, but the solution should be proportionate to the actual risk.

The situation changes when a company handles sensitive information, processes transactions or supplies services to multinational corporations and regulated industries.

I once worked with a client serving an American corporation that required monthly security audits—not only of the website, but also of the company’s email environment, domains, servers and overall external security posture.

It was the first time I had encountered such a demanding monthly requirement.

For that situation, we recommended UpGuard, a security-rating and third-party risk-management platform. It is not a low-cost solution, but some large organisations require their vendors to demonstrate formal, continuous and independently measurable security controls.

The right level of security is therefore determined not only by the website itself, but also by the expectations of the customers, industries and markets that the company serves.

A Working Website Is Not the Same as a Governed Website

Many business owners assume that if a website is online, everything must be under control.

That is not necessarily true.

A website can remain online while its domain is registered under a former vendor’s account. Its hosting subscription may be charged to an unknown credit card. Its DNS could be managed through an account that nobody can recover. Its SSL certificate may expire without anyone receiving the notification.

Technical functionality tells us whether something is working today. Governance tells us whether the company can understand, control, secure and recover it tomorrow.

This is why the real conversation is not only about websites. It is about digital ownership.

AI Must Not Amplify Our Existing Complexity

We are now entering an era in which companies can access more AI platforms, cybersecurity tools, cloud services and digital solutions than ever before.

The temptation will be to keep adding.

One team subscribes to an AI writing platform. Another adopts an automation service. A third connects a new customer system. Every solution appears useful individually, but together they can create an increasingly fragmented and ungovernable environment.

AI will amplify whatever already exists. If our processes are clear, AI can amplify efficiency. If our systems are fragmented, AI can amplify confusion. If our access controls are weak, AI can amplify risk.

We should not allow AI to amplify our complexity.

Before adopting the next solution, companies should ask: Can we consolidate what we already have? Can we eliminate duplication? Can we reduce the number of providers, accounts and renewal dates? Can everyone clearly see who owns and manages each digital asset?

Simplification Is Now a Management Discipline

The most important improvement may not be adding another platform. It may be removing one.

If we are currently managing ten separate components, can we reduce them to five? If we are managing five overlapping services, can we consolidate them into one well-governed environment?

Simplification does not mean sacrificing capability or security. Done correctly, it improves visibility, accountability, continuity and control.

This perspective comes from our years of practical experience helping businesses manage websites, domains, hosting environments, email systems, cybersecurity requirements and digital transformation.

In the AI era, companies will certainly need better technology. But they will also need the discipline to reduce, cut and simplify.

Do not begin by asking what else you can add.

Begin by asking what you no longer need to manage.

Insights · 18/40 12 Aug 2026

The Devil Inside Your AI: Why AI Governance Is Now a Business Priority

Lukas Insight | By Ts. Lukas J. Tan

After completing PDX2026, I decided to go all-in on artificial intelligence.

Nearly three weeks into this journey, I have moved beyond simply using AI tools. I am exploring how AI can learn, build, analyse, automate and operate alongside me.

My biggest discovery is simple: AI enables us to learn independently and create exactly what we need at extraordinary speed.

One person can now research a market, analyse data, prepare a strategy, develop software and automate workflows. This represents a major productivity breakthrough, particularly for small and medium-sized businesses.

But the deeper I go into AI, the more I find myself asking one uncomfortable question:

Do you know whether there is a devil inside your AI?

What Is the “Devil” Inside AI?

The devil is not AI itself. It is the hidden risk created by poor data, excessive access, unclear instructions and uncontrolled automation.

An AI system may generate a convincing answer based on inaccurate information. It may reveal confidential data because it was given the wrong permissions. An AI agent may perform an unintended action because nobody clearly defined its boundaries.

The risk becomes greater when AI moves from answering questions to operating business systems.

A human mistake usually develops at human speed. An automated AI mistake can affect thousands of records, messages or transactions before anyone detects it.

Business leaders must therefore understand three things clearly:

  • What AI can access
  • What AI can decide
  • What AI can execute

Lessons From the Age of Hacking

I come from a generation shaped by computer viruses, hacking, data scraping, software cloning and system vulnerabilities.

That experience trained me to examine technology from two perspectives: what the system is designed to do and how someone could manipulate it.

Convenience can create an entry point. Connectivity can create exposure. Automation can multiply efficiency, but it can also multiply errors.

Traditional cybersecurity focuses on protecting devices, networks, passwords and databases. AI introduces another layer that organisations must protect: the information and context influencing its behaviour.

AI does not merely store information. It interprets information, identifies patterns, generates recommendations and increasingly completes tasks.

Securing the system is no longer enough. We must also secure the decision-making process.

Can Someone Manipulate AI Data?

Yes. AI can be influenced by inaccurate, outdated or deliberately manipulated information.

The internet can be flooded with fabricated articles, fake reviews, synthetic identities, altered images and misleading statistics. Internal databases can also contain duplicate records, incorrect labels and biased historical decisions.

If AI relies on compromised information, it may produce an answer that appears professional and logical but is fundamentally wrong.

This creates a new category of cyber risk.

In the past, attackers mainly attempted to steal information or disrupt systems. In the AI era, they may attempt to influence what an AI system believes, how it reasons and what it recommends.

An attacker may not need to change the final decision directly. Manipulating the information used to reach that decision could be enough.

A company may successfully prevent outsiders from accessing its database and still make poor decisions because the data inside cannot be trusted.

Cybersecurity protects access to data. AI governance protects how that data becomes a decision.

What Is AI Governance?

AI governance is the framework that determines how an organisation selects, uses, monitors and controls artificial intelligence.

It establishes responsibilities for data protection, system access, human approval, output verification and accountability.

Without governance, every team member may create their own rules. Confidential information could be uploaded to unapproved platforms. AI-generated recommendations might be accepted without verification. Automated actions could happen without proper authorisation.

That is not a sustainable AI strategy. It is unmanaged business risk.

AI governance turns individual experimentation into a controlled organisational capability.

What Should an AI Governance Framework Include?

A practical framework should address five core areas.

  1. Data. Define what information AI may access, process and retain. Personal, confidential and commercially sensitive information requires stronger protection.
  2. Permission. Set boundaries around the systems AI can access and the actions it can perform. Access should be based on necessity—not convenience.
  3. Verification. Establish how AI-generated work will be reviewed for accuracy, relevance, bias and potential harm.
  4. Human Approval. Identify which decisions must remain under human control. Financial transactions, legal commitments, customer data changes and other high-impact actions require appropriate safeguards.
  5. Accountability. Assign clear ownership. Every AI system should have someone responsible for its purpose, performance, monitoring and risks.

The strength of these controls should correspond to the potential impact. Using AI to correct grammar does not require the same governance as allowing an AI agent to modify customer records, approve payments or deploy software.

Does AI Governance Restrict Innovation?

AI governance should not stop innovation. It should enable organisations to innovate with greater confidence.

When the boundaries are clear, the team can experiment without creating unnecessary exposure. Leaders can approve automation while maintaining visibility. Customers and partners can trust that their information is being handled responsibly.

Governance is not about controlling every prompt or slowing every project. It is about creating clear authority, traceability and accountability around AI activities that can materially affect the organisation.

The winners of the AI era will not simply be the companies using the most AI tools. They will be the companies capable of using AI reliably, explaining important decisions, protecting their data and taking responsibility for the outcomes.

The Question Every Leader Must Answer

Your organisation may already be using ChatGPT, Claude, AI agents or automated workflows—even without an official AI strategy.

Members of the team may be uploading documents, analysing customer information, generating business recommendations or using AI-created code inside company systems.

The first leadership question should therefore be:

Do we know where and how AI is being used across our organisation?

An AI Governance Assessment can identify existing tools, data exposure, access permissions, approval gaps and accountability risks. The organisation can then establish a practical governance framework aligned with its operations and level of risk.

I remain strongly positive about AI. Its potential to improve productivity, strengthen decisions and help smaller organisations compete is enormous.

But opportunity without control can quickly become liability.

AI should not be feared. It should be governed with clarity, discipline and confidence.

Do not wait for the devil to appear before creating the rules.

Insights · 19/40 11 Aug 2026

From the ILOVEYOU Virus to AI Cyberwarfare: The Most Expensive Problem Was Never the Virus—It Was the Foundation

The Era When Computer Viruses Were Everywhere

When I first started using computers, we were still living through the eras of DOS, Windows 95, Windows 98, Windows Millennium, Windows 2000, and eventually Windows XP.

At that time, almost every computer user experienced a virus infection. Computers would suddenly slow down, files would disappear, browsers would be hijacked, and sometimes the entire operating system had to be reinstalled.

The one I remember most clearly was the ILOVEYOU virus, which appeared in 2000. Disguised as an email carrying the subject line “ILOVEYOU,” it persuaded recipients to open an attachment before spreading rapidly through their contact lists.

Technically, it was a computer worm rather than a conventional virus. Within a very short time, it affected millions of computers worldwide and made the world realise something important: the more widely a technology is adopted, the greater the potential damage caused by even a small weakness in its foundation. Source: EBSCO, “ILOVEYOU Virus Attacks Computers.”

How Much Has Microsoft Spent Protecting Windows?

As Windows became one of the world’s most widely used operating systems for individuals and businesses, it naturally became one of the most valuable targets for attackers.

Microsoft does not only have to protect its operating system. It must also consider different computer brands, enterprise systems, legacy software, hardware drivers, third-party applications, and decades of compatibility requirements.

We have all encountered Windows security updates and software patches. Sometimes, just as we are preparing to shut down the computer, Windows begins installing an update and asks us to wait. From a user’s perspective, this can be frustrating. From a security perspective, however, it represents a battle that never truly ends.

Microsoft previously announced a US$20 billion investment over five years to advance cybersecurity. Its published materials also indicated that the company was investing more than US$1 billion annually in security, data protection, and risk management. These figures demonstrate how expensive it is to protect a large, open ecosystem that must continue supporting countless legacy systems. Source: Microsoft’s Cybersecurity Investment; Microsoft Cyber Defense Operations Center.

This does not necessarily mean that Windows was built on a weaker foundation. Windows faces more attacks partly because of its enormous user base, complex operating environments, and obligation to support a vast range of enterprise systems and third-party hardware and software. For cybercriminals, attacking a platform with a larger market share can offer a much greater return.

Why Do Many Mac Users Not Install Antivirus Software?

Many years later, I started using a MacBook. I noticed that many Mac users did not install separate antivirus software, yet their computers continued operating normally. Like many people, I wondered whether Macs simply could not get viruses.

Strictly speaking, that is incorrect.

macOS can still be affected by malware, ransomware, phishing, and system vulnerabilities. The difference is that Apple has integrated many protective mechanisms directly into the operating system, so users may not even notice that these protections are running.

macOS includes technologies such as XProtect, Gatekeeper, and App Notarization. Gatekeeper checks whether software comes from an identified developer, has been notarised by Apple, and has not been altered. XProtect is Apple’s built-in anti-malware technology, designed to detect, block, and remove known threats.

Apple organises its malware defence into three layers: preventing malicious software from launching, blocking it from running, and remediating it if it has already been executed. Source: Apple, “Protecting Against Malware in macOS”; Apple, “Gatekeeper and Runtime Protection.”

Apple has therefore not avoided spending money on security. A more accurate explanation is that Apple has placed much of that investment into its underlying architecture, hardware-software integration, application review process, permission controls, and automatic updates.

The fact that users do not install antivirus software themselves does not mean that there is no major security investment behind the system.

Apple also maintains greater control over its hardware and software ecosystem. It can determine which devices run macOS, how applications access system resources, and which security policies are enabled by default. This controlled environment reduces some complexity.

However, Apple’s approach cannot simply be copied and applied to Windows because the two platforms serve different markets and carry different compatibility responsibilities.

Will AI Cause Computer Viruses to Decline?

As we enter the AI era, I initially had a thought: if AI can automatically detect unusual activity, analyse malicious code, predict attack patterns, and allow firewalls to respond automatically, will traditional computer viruses gradually decline?

Part of this observation is correct.

AI can help security teams identify threats more quickly, detect phishing messages, close detection gaps, and respond at machine speed. Microsoft is already developing AI security systems designed to turn threat signals into real-time protection. Source: Microsoft, “Rethinking Security for the Age of AI.”

However, we cannot conclude that viruses will disappear simply because AI has arrived. Defenders can use AI, but attackers can use it too.

Cybercriminals can use AI to search for vulnerabilities, generate malicious code, create more convincing scam messages, and attack many more targets simultaneously. Microsoft’s security research also warns that AI adoption benefits both defenders and threat actors. Source: Microsoft Digital Defense Report 2025.

What may decline is the visible experience we once described as “my computer has caught a virus.” What may increase instead are less visible threats: identity theft, data theft, ransomware, supply-chain attacks, manipulated AI agents, and scams designed to exploit human behaviour.

Viruses may not disappear. They may simply evolve into different forms.

Was Microsoft’s Past Security Investment Wasted?

If AI can eventually automate a large part of cybersecurity work, does that mean the money, manpower, and time Microsoft invested in the past have all gone to waste?

My answer is no.

Those investments created the vulnerability databases, threat intelligence, authentication systems, security standards, update infrastructure, and defensive experience that we rely on today.

Without that foundation, AI would not have enough reliable information or established rules to distinguish normal behaviour from a genuine threat. AI is not a security expert that suddenly appeared from nowhere. Its capabilities are built upon decades of knowledge accumulated by people and organisations.

What may become obsolete is not the previous investment in security, but some of the repetitive ways security work was performed.

Security professionals may no longer need to inspect every alert manually. However, they will still be needed to design policies, supervise AI, make high-risk decisions, and ensure that the automated security systems themselves are not compromised.

Microsoft’s recent direction is also not limited to using AI to patch vulnerabilities. It has renewed its emphasis on Secure by Design, Secure by Default, and Secure Operations—placing security at the centre of design, default configurations, and everyday operations.

This tells us that even with powerful AI, everything eventually comes back to the quality of the foundation. Source: Microsoft Secure Future Initiative.

What the AI Era Has Truly Taught Me

This article is not written to criticise Microsoft or to prove that Apple is necessarily better.

It is simply a reflection from someone who lived through the eras of DOS, Windows 95, Windows 98, Windows Millennium, Windows 2000, and Windows XP—and who is now observing how computer viruses, security updates, and cyber defence are evolving in the AI era.

Different operating systems carry different historical responsibilities, user bases, levels of ecosystem openness, and security risks. We cannot judge the quality of a technology simply by asking which platform appears to suffer fewer virus infections.

However, this history has given me one important insight:

The foundation is the most important part of any good system.

If the architecture is unclear, permissions are poorly designed, data is disorganised, and responsibilities are not properly assigned, even the most advanced technology will spend its life repairing gaps.

Every time the world changes, the organisation will need more technical people, more knowledge, and more money just to keep compensating for a foundation that was never properly established.

Today, this principle does not apply only to operating systems. It applies to every organisation preparing to implement AI.

AI can help us move faster. But if our foundation and direction are wrong, it will also help us create problems at a much greater speed.

In the AI era, true competitiveness will not be determined by how many tools we own, how many technical people we employ, or how much security software we install. It will depend on whether we have designed the right architecture, governance, permissions, and accountability from the very beginning.

Technology will continue to change. Threats will continue to evolve.

But a strong foundation will never become obsolete.

Insights · 20/40 10 Aug 2026

AI Governance: From Vision to Implementation

Why Every Organisation Needs a Governance Strategy Before Scaling AI

Artificial Intelligence has moved beyond experimentation. What began as individual employees using AI to draft emails, summarise documents, or generate ideas has rapidly evolved into organisations embedding AI across customer service, finance, human resources, operations, software development, marketing, and executive decision-making. For many businesses, AI is no longer a future initiative—it is already part of daily operations. Yet while investment in AI continues to accelerate, governance has not kept pace. Most organisations have established policies for finance, cybersecurity, procurement, and data privacy, but relatively few have developed a comprehensive framework that governs how AI should be deployed, managed, monitored, and continuously improved.

This imbalance creates a significant leadership challenge. AI is fundamentally different from traditional enterprise software. Conventional systems execute predefined business rules, whereas AI learns from context, interacts with organisational knowledge, and increasingly influences decisions. As organisations connect AI to customer databases, accounting systems, cloud storage, communication platforms, and operational workflows, they are no longer managing software alone. They are managing a digital workforce capable of accessing, interpreting, and acting upon business information. This requires a new discipline. AI Governance should not be viewed as another compliance exercise. It is a leadership framework that ensures AI remains aligned with organisational objectives, business values, operational controls, and risk management. In many ways, AI Governance will become as essential to modern organisations as financial governance and cybersecurity governance are today.

AI Governance Begins With Visibility, Not Policies

One of the most common questions I receive from business leaders is, “Can you help us write an AI policy?” My answer is usually the same: not yet. Policies are important, but they should not be the starting point. An effective policy can only be written after an organisation understands how AI is currently being used. Surprisingly, many companies cannot answer basic questions. Which AI tools are employees already using? Which departments have connected AI to business systems? What information is being uploaded into external platforms? Which workflows have already been automated? Without visibility, any governance document quickly becomes theoretical rather than practical.

The first objective of AI Governance is therefore awareness. Organisations should begin by creating a comprehensive inventory of AI across the business. This inventory should identify every AI platform, every AI agent, every workflow automation, every system integration, and every business owner responsible for its operation. Once visibility exists, leadership can begin classifying AI according to business impact. Some AI applications may simply generate marketing copy or summarise meeting notes. Others may analyse financial reports, access confidential customer information, recommend purchasing decisions, or interact directly with clients. Different levels of responsibility require different levels of governance. Just as organisations classify financial approvals according to authority limits, AI capabilities should be classified according to operational impact and organisational risk.

Ownership Requires More Than Technology—It Requires Operational Discipline

Many discussions surrounding AI focus on selecting the right platform. While technology selection is important, ownership is ultimately determined by operational discipline rather than software features. Organisations often assume that implementing an AI solution automatically creates capability. In reality, capability emerges from the combination of people, processes, governance, and technology working together. AI should therefore be treated as part of the operating model rather than simply another digital tool.

One practical way to achieve this is by documenting how AI interacts with organisational systems. Every AI capability should have a clearly defined purpose, an identified business owner, and documented permissions. For example, an AI assistant responsible for preparing management reports may require read-only access to operational dashboards but should not be able to modify financial records. A customer service AI may retrieve product information but should not automatically approve refunds above a defined threshold. A marketing AI may generate content but should not publish communications without human review. These governance decisions are not technical limitations; they are management decisions that define accountability.

As organisations deploy multiple AI solutions, documenting these permissions becomes increasingly important. A simple governance register can include which systems each AI can access, whether it has permission to read, create, update, or delete information, which departments approve those permissions, and how often those permissions are reviewed. Such documentation may appear administrative, yet it forms the foundation of responsible AI operations. Governance is built through disciplined documentation, not assumptions.

AI Workforce Requires Governance Just as Human Workforce Does

One concept I believe organisations should begin embracing is the idea of an AI Workforce. Many businesses still think of AI as a collection of software applications. I believe this perspective is becoming outdated. As AI agents become increasingly autonomous, collaborate with one another, and support multiple departments simultaneously, they begin resembling a workforce rather than a toolset. Just as organisations define roles, responsibilities, reporting structures, performance expectations, and codes of conduct for human employees, they will eventually need equivalent governance structures for digital workers.

Imagine an organisation operating twenty specialised AI agents. One supports finance, another assists human resources, another manages customer enquiries, another analyses operational performance, while others contribute to procurement, legal review, project management, and executive reporting. Individually, each agent may perform a specific function. Collectively, however, they form an operational ecosystem. Leadership therefore needs visibility not only into each AI agent individually but also into how information flows between them. Can one agent trigger another? Can sensitive information unintentionally move between workflows? Which human manager ultimately approves decisions generated by AI? Governance should answer these questions before operational complexity makes them difficult to control.

For this reason, I encourage organisations to establish what I describe as an AI Workforce Register. Similar to an employee directory, this register should document every AI agent’s role, purpose, owner, connected systems, permissions, review schedule, and business value. This transforms AI from an invisible collection of technologies into an accountable organisational resource.

From Strategy to Implementation: Building Governance Step by Step

One misconception surrounding AI Governance is that it requires a large transformation programme before meaningful progress can begin. My experience suggests the opposite. The most effective governance frameworks evolve incrementally. Organisations should resist the temptation to produce lengthy policy documents before understanding operational reality. Instead, governance should mature alongside AI adoption.

A practical roadmap begins with six progressive stages. The first stage is establishing an AI Inventory to understand what already exists. The second stage involves classifying business information according to sensitivity and determining which categories of information may be accessed by different AI capabilities. The third stage documents permissions using a simple access matrix that specifies whether AI systems may read, create, update, or delete information within each connected platform. The fourth stage introduces governance policies covering approval processes, acceptable use, human oversight, and accountability. The fifth stage implements periodic governance reviews to verify that AI continues operating within approved boundaries. Finally, the sixth stage integrates AI Governance into broader corporate governance alongside cybersecurity, enterprise architecture, risk management, and strategic planning.

Importantly, governance should remain a living management system rather than a static document. As AI capabilities evolve, governance must evolve with them. New integrations, new regulations, changing business priorities, and emerging risks all require continuous review. Organisations should therefore view AI Governance as an ongoing leadership discipline rather than a one-time compliance exercise.

The Future Belongs to Organisations That Understand Their AI

Every major technological transformation eventually shifts from innovation to discipline. During the early Internet era, organisations focused on getting online. Later they learned the importance of cybersecurity. During the data revolution, businesses concentrated on collecting information before recognising the need for governance and privacy. Artificial Intelligence is following the same pattern. Today’s excitement around AI capabilities will gradually be matched by a greater appreciation for governance, accountability, transparency, and operational maturity.

The organisations that succeed in this next phase will not simply possess the most advanced AI models. They will possess the clearest understanding of how AI operates within their business. They will know which digital workers exist, what they can access, how they support decision-making, and who remains accountable for their performance. They will recognise that governance is not a barrier to innovation but an enabler of sustainable innovation. Responsible governance builds trust, improves operational resilience, strengthens executive confidence, and allows AI to scale safely across the enterprise.

Executive Diagnostic

Before expanding AI across your organisation, ask your leadership team these questions:

  • Do we have a complete inventory of every AI tool and AI agent currently operating within the business?
  • Have we documented what each AI system is allowed to read, create, update, or delete?
  • Is every AI capability assigned to a business owner rather than only an IT administrator?
  • Do we understand how information flows between different AI systems?
  • Have we established review processes for AI permissions and governance?
  • Does our leadership team discuss AI Governance with the same seriousness as financial governance or cybersecurity?

If the answer to several of these questions is “no,” your organisation’s next investment should not necessarily be another AI platform. It should be stronger governance.

Executive Action Plan

Within the next 90 days, every organisation can begin building practical AI Governance.

Create an inventory of all AI tools currently in use. Develop an AI Workforce Register identifying each AI agent’s purpose, owner, permissions, and connected systems. Build a simple access matrix defining which AI capabilities may read, create, update, or delete business information. Establish executive ownership for AI Governance rather than delegating responsibility entirely to technical teams. Finally, review governance quarterly as AI capabilities continue evolving.

Artificial Intelligence will undoubtedly reshape every industry, but governance will determine whether that transformation creates long-term competitive advantage or unmanaged operational complexity. The future belongs not simply to organisations that use AI, but to those that understand it, govern it, and integrate it responsibly into the fabric of their business.

Insights · 21/40 09 Aug 2026

Beyond Productivity: Why AI Ownership Will Define the Next Generation of Business Leadership

Every Technological Revolution Creates a New Leadership Challenge

Over the past three decades, businesses have experienced several waves of technological transformation. Each wave has fundamentally changed how organisations operate, compete, and create value. During the early Internet era, success depended on connectivity. Companies invested heavily in network infrastructure because simply being connected to the digital world represented progress. As the Internet matured, the focus shifted from connectivity to digitalisation. Businesses began redesigning workflows, introducing enterprise systems, and integrating information across departments. Eventually, the conversation evolved once again. Data became one of the world’s most valuable business assets, forcing organisations to invest in cybersecurity, privacy, governance, and regulatory compliance. Every technological revolution introduced extraordinary opportunities, but it also demanded a new level of leadership responsibility.

Artificial Intelligence represents the next stage of this evolution. Yet many organisations continue to evaluate AI using the same performance metrics that shaped previous technology investments. Boardroom discussions are dominated by productivity, efficiency, automation, and cost reduction. These are undoubtedly important outcomes, but they are no longer the defining question of enterprise AI adoption. The organisations that will lead over the next decade will not necessarily be those that deploy AI first or purchase the largest number of AI tools. Instead, they will be the organisations that understand how AI changes the ownership of organisational knowledge and that build the governance required to manage that knowledge responsibly.

This shift requires executives to rethink AI from a leadership perspective rather than simply a technology perspective. AI is not another software application that automates repetitive tasks. Unlike traditional enterprise systems, AI interacts directly with organisational knowledge. Every prompt, document, meeting transcript, customer conversation, operating procedure, and business decision that enters an AI environment carries context about how an organisation thinks and operates. That context is becoming one of the most valuable corporate assets of the AI era. Productivity remains important, but ownership is rapidly becoming the more strategic question.

Organisations Are Measuring the Wrong Success Indicator

Most AI success stories begin with impressive productivity statistics. Marketing teams generate campaigns in minutes rather than days. Software developers accelerate coding. Customer service departments respond more quickly. Managers summarise lengthy reports within seconds. These improvements are real, measurable, and valuable. However, they represent only one side of the equation.

Every AI interaction consists of two equally important components: output and input. Organisations naturally celebrate the quality of AI-generated outputs because they are immediately visible. Far less attention is given to the organisational knowledge that makes those outputs possible. Every uploaded proposal reveals commercial thinking. Every financial spreadsheet explains business performance. Every internal procedure documents operational experience accumulated over many years. Every prompt teaches AI something about how the organisation approaches decisions, solves problems, and serves customers.

This distinction is critical because knowledge differs fundamentally from data. Data records what has happened. Knowledge explains why it happened, how decisions were made, and what should happen next. Competitive advantage has never existed solely within databases or enterprise systems. It exists inside the experience of leadership teams, the judgement of managers, the expertise of employees, and the operational methods that competitors cannot easily replicate. AI has created the first environment in which organisations voluntarily convert this knowledge into machine-readable context every single day. Consequently, the conversation should extend beyond productivity and begin examining ownership. Business leaders should ask not only whether AI is improving performance, but also how organisational knowledge is being governed, protected, and managed as AI becomes embedded within daily operations.

The New Competitive Advantage Is Organisational Intelligence

For many years, organisations described data as the “new oil.” While data remains important, I believe the next competitive advantage lies elsewhere. The true strategic asset of the AI era is organisational intelligence. Organisational intelligence is the collective understanding of how a business creates value. It includes leadership judgement, operational workflows, customer relationships, pricing philosophy, risk management, quality standards, decision-making processes, and institutional experience accumulated over time. Unlike software or hardware, organisational intelligence cannot simply be purchased. It is developed through years of learning, experimentation, and continuous improvement.

Artificial Intelligence is uniquely capable of interacting with this organisational intelligence. Modern AI systems no longer process only structured information. They interpret meeting discussions, analyse policy documents, summarise technical manuals, assist with strategic planning, and recommend business decisions. This capability creates tremendous opportunities for productivity, but it also raises an important leadership responsibility. Organisations should understand what knowledge is being shared with AI systems, which systems have access to sensitive information, how permissions are managed, and how institutional knowledge is protected throughout its lifecycle. These questions are not expressions of distrust towards technology providers. Rather, they reflect good executive governance. Responsible leadership has always required visibility into the assets that create long-term competitive advantage. AI simply expands the definition of those assets.

Ownership Requires Visibility Before It Requires Technology

Many AI discussions quickly move towards selecting platforms, comparing models, or evaluating new capabilities. While technology selection is important, ownership begins much earlier. It begins with visibility. Before organisations can govern AI effectively, they must first understand how AI is already being used across the business. In many companies, employees independently adopt different AI tools, upload documents, connect cloud services, automate workflows, or integrate external applications without any central visibility. This phenomenon is understandable because AI tools are increasingly accessible and easy to use. However, accessibility should not replace management.

Business leaders do not need to become AI engineers, but they should understand the questions that define responsible adoption. Which AI applications are officially approved? What categories of information may be uploaded? Which systems can AI access? Who authorises those permissions? What governance exists when multiple AI services interact with one another? These questions represent leadership responsibilities rather than technical responsibilities. Organisations have long established governance for finance, cybersecurity, procurement, and legal compliance. AI deserves the same level of executive attention because it increasingly influences knowledge, decisions, and operations rather than simply automating repetitive work.

Building Capability Instead of Depending Entirely on Convenience

One observation has become increasingly clear throughout my own work with organisations exploring AI transformation. Many businesses focus their attention on acquiring AI solutions, yet comparatively few invest in developing internal AI capability. Purchasing AI technology is often the fastest way to improve productivity. Building internal capability, however, provides something equally important: understanding.

This does not imply that organisations should avoid third-party AI platforms. Enterprise AI providers offer significant innovation, robust security investments, and valuable capabilities. The more important consideration is whether the organisation itself understands how AI fits within its operating model. Leadership teams should know how information flows between systems, what permissions exist, who remains accountable for AI-driven processes, and where organisational knowledge resides. Over time, I believe every medium and large organisation will develop some form of internal AI capability—not necessarily to replace external platforms, but to ensure that strategic knowledge, operational processes, and governance remain aligned with business objectives.

This is also why I believe the concept of an AI Workforce will become increasingly important. Rather than viewing AI as a collection of disconnected tools, organisations should begin viewing AI as a managed workforce operating alongside human employees. Just as every employee has defined responsibilities, reporting structures, access rights, and performance expectations, every AI capability should eventually operate within clearly defined governance boundaries.

Leadership Must Move Beyond AI Adoption Towards AI Ownership

Artificial Intelligence will undoubtedly become one of the defining technologies of our generation. Every industry will adopt it. Every profession will be influenced by it. Every organisation will discover new opportunities to automate work, improve decisions, and enhance customer experiences. Yet technology alone has never determined long-term competitive advantage. Leadership has always been the deciding factor.

The next generation of business leaders will therefore need to ask a different set of questions. Instead of asking only how AI can improve productivity, they must also ask how AI affects ownership of organisational intelligence. Instead of measuring only efficiency gains, they should evaluate governance maturity. Instead of celebrating automation alone, they should ensure visibility, accountability, and responsible management accompany every implementation. Organisations that combine innovation with disciplined governance will build greater resilience than those pursuing speed without structure.

Executive Diagnostic

Before introducing AI into more business functions, every executive team should honestly consider the following questions:

  • Do we know every AI platform currently being used across our organisation?
  • Have we defined what information employees may and may not upload?
  • Do we understand which AI systems can access our core business applications?
  • Is there a documented approval process for granting AI access to sensitive information?
  • Have we identified who is accountable for AI governance at the leadership level?
  • Are we treating organisational knowledge as a strategic asset rather than simply another collection of files?

If several of these questions cannot yet be answered confidently, the priority may not be adopting more AI. The priority may be establishing greater visibility into the AI that already exists.

Executive Action Plan

Over the next thirty days, leadership teams can begin strengthening AI ownership without waiting for a major transformation programme.

First, create an inventory of every AI platform currently used within the organisation. Second, classify the types of information each platform is permitted to access. Third, define approval rules for future AI integrations. Fourth, begin documenting AI-related policies and decision-making responsibilities. Finally, appoint a business leader—not only a technical leader—to oversee the organisation’s AI governance journey.

Productivity may be the most visible benefit of Artificial Intelligence, but visibility, governance, and ownership will ultimately determine whether AI becomes a sustainable competitive advantage. The organisations that thrive in the coming decade will not simply use AI more effectively than their competitors. They will understand it more deeply, govern it more responsibly, and retain ownership of the organisational intelligence that truly differentiates them.

Insights · 22/40 08 Aug 2026

Why an Octopus? The Story Behind the PDX Mascot

Sometimes, we spend years searching for the right answer, only to discover that the answer was never meant to be created. It was meant to reveal itself when the mission became clear.

When people see the PDX mascot in the future, they may simply see an octopus. Some may think it looks friendly. Others may think it represents technology or artificial intelligence. Few will know that behind this little character lies years of conversations, hundreds of meetings, thousands of kilometres travelled, and one simple question that has shaped everything we do: How do we help businesses transform successfully in the digital era?

The story of our mascot did not begin with a design brief. It began with a problem. And like many meaningful discoveries, it appeared only after we stopped searching for it. Looking back today, I realise the octopus was never just a mascot. It became a reflection of what PDX had quietly evolved into—a platform built not around technology, but around people, collaboration, and a connected ecosystem. This is the story behind why an octopus became the face of PDX.

1. Seeing the Problem Beyond Technology

Long before PDX was established, I spent years meeting business owners across different industries. Every meeting sounded familiar. Companies wanted to digitalise. They wanted to embrace AI, automate operations, improve productivity, and remain competitive. Yet despite the growing number of software solutions, government initiatives, grants, and technology providers available in Malaysia, many businesses were still unsure where to begin. The challenge was never a lack of technology. Instead, it was a lack of clarity and coordination. Business owners struggled to translate operational challenges into digital requirements. Technology companies spoke in technical language that many business leaders found difficult to understand. Universities were producing graduates, but employers still complained about talent shortages. Funding opportunities existed, yet many businesses were unaware of them or lacked the confidence to apply. Every stakeholder was working hard within their own area of expertise, but they were rarely connected. The more conversations I had, the more convinced I became that Malaysia did not need another technology exhibition. What we truly needed was an ecosystem where every stakeholder could understand one another, collaborate, and move in the same direction.

2. PDX Was Never Meant to Be Just Another Event

That belief became the foundation of Penang Digitalisation and AI Conference & Exhibition (PDX). From the very beginning, my vision was never to organise the biggest conference or exhibition. Events last for a few days, but ecosystems continue growing long after the exhibition halls become empty. Every decision we made was driven by one question: “How do we create meaningful connections?” We wanted business owners to meet solution providers who genuinely understood their challenges. We wanted universities to hear directly from industries about future workforce requirements. We wanted government agencies to engage businesses beyond policy announcements. We wanted investors to discover innovation before it became mainstream. We wanted students to experience the opportunities waiting for them in the digital economy. Slowly, year after year, more organisations joined the journey. Government agencies, multinational corporations, startups, educational institutions, technology providers, investors, and industry associations all became part of something much larger than a conference. Without realising it, PDX was no longer just an annual event. It was becoming a living ecosystem where different communities could finally come together with a shared purpose.

3. Searching for a Mascot That Didn't Exist

As PDX matured, our team began discussing something many established organisations eventually consider—a mascot. It sounded simple at first. We organised brainstorming sessions, explored different concepts, and experimented with various designs. We sketched futuristic robots, AI-inspired characters, digital avatars, and technology icons. We even tried incorporating Penang's iconic blue, white, and yellow colours into the design. Every concept looked professional. Every illustration was creative. Yet every time we reviewed the proposals, something felt incomplete. None of them represented who we really were. Looking back today, I understand why. We were trying to create an identity before we had fully understood our own story. A mascot is not simply a marketing tool. It should represent a mission, a culture, and a belief that people can immediately recognise. At that stage, we were searching for a character. What we truly needed was a symbol that reflected the ecosystem we had spent years building. The answer could not be found in a design studio because it had not yet revealed itself in our journey.

4. The Conversation That Changed Everything

The breakthrough came in the most unexpected place—not during a branding workshop, but during a yacht networking session organised before PDX2026. There were no keynote speeches, presentation slides, or sales pitches. Instead, everyone simply shared their stories. Around the table were business strategists, AI educators, cybersecurity experts, software developers, infrastructure providers, investors, government representatives, university leaders, and entrepreneurs. Each person spoke passionately about the role they played in helping businesses succeed. As I listened carefully, I stopped seeing individual organisations. I began seeing an interconnected ecosystem. Every participant represented a different capability, yet none could create meaningful digital transformation alone. Strategy required execution. Technology required talent. Talent required education. Innovation required investment. Infrastructure enabled everything else. Government created the environment for progress. One conversation naturally connected to another, and another after that. It was one of those rare moments where the entire vision of PDX became visible—not on a presentation screen, but through the people sitting around the table.

5. The Moment I Looked at the Octopus Differently

As the evening continued, my eyes rested on a small orange octopus sitting quietly on the yacht. Until that moment, it had simply been a decorative toy. Then something unexpected happened. I no longer saw a toy—I saw the ecosystem sitting right in front of me. The brain represented strategy and leadership, providing direction for transformation. Every tentacle represented a specialised capability, from AI and cybersecurity to software development, cloud infrastructure, automation, and digital consulting. The nervous system reminded me of education and talent development, ensuring knowledge reached every part of the ecosystem. The flow of nutrients throughout the octopus symbolised funding and investment, sustaining innovation and growth. Each arm could perform independently, yet every movement remained coordinated because they were connected to the same central purpose. Suddenly everything made sense. We had spent two years searching for a mascot when, in reality, our ecosystem had quietly created one for us. The octopus was not chosen because it looked memorable. It was chosen because it perfectly represented what PDX had become.

6. The Real Meaning Behind the PDX Octopus

Today, the octopus represents far more than branding. It symbolises intelligence, adaptability, collaboration, and resilience—qualities that every organisation needs in an AI-driven economy. More importantly, it reminds us that successful digital transformation is never achieved by one company alone. No software provider can transform an organisation without leadership commitment. No consultant can succeed without technology partners. No AI solution creates value without skilled people. No innovation scales without investment, infrastructure, and policy support. Every stakeholder matters. Every contribution matters. The role of PDX has never been to become the centre of attention. Instead, our mission is to become the platform that connects every stakeholder so they can create greater value together. When businesses stop viewing digital transformation as a technology purchase and start seeing it as an ecosystem, their chances of success increase dramatically. That philosophy is what the octopus now represents.

7. A Mascot That Will Continue to Grow With the Ecosystem

People have asked me what the PDX octopus will look like in the years ahead. My honest answer is that I don't know—and that uncertainty excites me. Perhaps it will evolve into different characters. Perhaps it will inspire educational programmes for students. Perhaps it will become recognised across Malaysia as a symbol of collaboration in the digital economy. Whatever form it takes, one thing will never change. It will always represent the belief that transformation happens when people work together rather than apart. Every exhibitor, every speaker, every student, every policymaker, every investor, and every entrepreneur who joins PDX becomes another connection within this ecosystem. The mascot will continue growing because the community behind it continues growing. Its story is still being written, and every new partnership adds another chapter to that story.

8. Building the Next Chapter Together

When I reflect on the journey of PDX, I realise that the greatest achievement was never organising a successful event or introducing a mascot. The greatest achievement has been bringing together people who genuinely believe Malaysia can build a stronger, smarter, and more connected digital future. The octopus simply reminds us of that responsibility. As AI reshapes industries and digital transformation accelerates, businesses can no longer afford to navigate the journey alone. They need a clear roadmap, trusted partners, practical strategies, and an ecosystem that supports long-term growth. That has always been the mission of PDX, and it continues to be my personal mission as well.

Your Digital Transformation Journey Starts With the Right Roadmap

If your organisation is exploring digital transformation, AI adoption, automation, or long-term technology strategy, don't start by asking “What software should we buy?” Start by asking “What roadmap do we need?”

Technology is only one part of the equation. Success comes from aligning leadership, people, processes, funding, talent, and the right implementation partners into a single, practical strategy.

If you are ready to build a digital roadmap tailored to your organisation, I would be delighted to have that conversation.

Let's build your digital future—together.


Lukas J. Tan
Digital Transformation Strategist | AI Advisor | Founder, PDX
Digital Roadmap Consulting • AI Strategy • Ecosystem Development

Insights · 23/40 07 Aug 2026

When Fixing the Software Isn't Enough: A Digital Transformation Case Study That Began with an Organisation Chart

This case study is based on an actual digital transformation project undertaken during the COVID-19 Movement Control Order (MCO). To protect the confidentiality of the client, the company's identity and certain operational details have been anonymised. However, the business challenges, transformation approach and outcomes presented in this article accurately reflect the project.

Case Background

Industry: Retail Business
Business Size: 20 retail branches across Malaysia
Workforce: Approximately 200 employees
Project Type: Enterprise Digital Transformation & Business Process Redesign

The client is an established retail business operating approximately 20 branches with a workforce of around 200 employees. As the organisation expanded, managing information across multiple branches became increasingly difficult. Critical business operations still relied heavily on Microsoft Excel and manual processes, resulting in inconsistent data, duplicated work, limited visibility and weak permission control. Although the company had already invested nearly a year developing a custom business system, the project had reached a point where continuous modifications were creating more operational issues than solutions.

This article shares how we approached the project—not by fixing the software first, but by redesigning the organisation behind it. It also explains why I believe Digital Transformation must always come before Artificial Intelligence, because AI is only as good as the business processes and data that support it.

The Wake-Up Call During MCO

The COVID-19 pandemic changed the way businesses operated almost overnight. During the Movement Control Order (MCO), many companies suddenly realised that the systems and processes they had relied on for years were no longer sufficient. One particular client approached us during this challenging period with a problem that, on the surface, sounded very familiar. They were still managing critical business operations using Microsoft Excel. As the company expanded, multiple employees were editing the same files, data was constantly being overwritten, and management had no confidence that the reports they were looking at were accurate. More importantly, there was no proper permission control. Anyone with access could modify information, whether intentionally or accidentally. The management team knew they needed to digitalise, but what they believed they needed was simply a software system. What they actually needed was something much bigger.

A Year Spent Building, But Not Progressing

For various reasons, the company eventually engaged another software developer instead of working with us. Over the next twelve months, the system went through countless revisions. Every few weeks there was another meeting, another change request, another bug to fix, and another feature to modify. Unfortunately, the project slowly entered a cycle that many business owners know all too well. Every time one problem was solved, another appeared somewhere else. New features could not be introduced because the development team was constantly repairing existing functions. Users became frustrated because familiar processes kept changing, while management began losing confidence in the project altogether. After nearly a year of investment, both financially and emotionally, they were still nowhere close to having the stable business system they had originally envisioned. That was when they returned and asked if we could help.

I Didn't Start by Looking at Their System

When I first met the management team again, they expected me to review the software, analyse the database, or identify the technical problems that had accumulated over the previous year. Instead, I did something that surprised everyone in the room. I barely looked at the system at all. After nearly twenty years of building enterprise software, I have learned that software is rarely the real problem. A poorly performing system is often nothing more than a reflection of a poorly structured organisation. If the business itself lacks clarity, no amount of programming can compensate for that confusion. Rather than spending days trying to understand thousands of lines of source code or documenting every existing screen, I decided to start from the very top. Before discussing technology, I wanted to understand the business.

The First Question Was About People, Not Technology

The very first document I asked the CEO to show me was not a system manual or a workflow diagram. It was the organisation chart. I wanted to understand how the company was structured before understanding how the software had been designed. Looking at the organisation chart, I asked three simple questions for every department. How many people work here? Does this department generate revenue, or is it a support function? What is its primary responsibility? These questions may sound basic, but they immediately exposed issues that had never been discussed during software development. Several departments had overlapping responsibilities. Some approval processes existed simply because they had always existed. Certain teams were overloaded while others had unclear ownership. Before redesigning technology, we first needed to redesign organisational clarity.

Understanding the Business Before Designing the System

Once the organisational structure became clear, I asked the management team to explain something even more important. I didn't ask how every individual screen should work, nor did I request every operational detail. Instead, I asked them to walk me through the complete customer journey. How does a customer first hear about your business? What happens after they make an enquiry? How are quotations prepared? How are orders confirmed? What happens during production, delivery, invoicing and after-sales support? By understanding the entire business lifecycle, we could identify how information should naturally flow throughout the organisation. Only after understanding the business model did we begin discussing software. Technology should always support business operations, never dictate them.

Digital Transformation Is Not About Digitising Existing Problems

One of the biggest misconceptions surrounding digital transformation is that businesses believe success comes from converting manual paperwork into digital forms. In reality, that approach simply transforms inefficient manual processes into inefficient digital processes. If an organisation has unnecessary approvals, duplicated work, poor communication between departments and inconsistent ownership, software will only make those weaknesses more visible. Digital transformation is not about replicating yesterday's workflow on a computer. It is about questioning every process, eliminating unnecessary steps, simplifying communication and redesigning how the organisation operates. Only then should technology be introduced to automate and support those newly designed processes. Software should never preserve inefficiency; it should eliminate it.

Building a Business System Instead of Just Another Software Application

One aspect of this project that I truly appreciated was the trust given to our team. After we completed our analysis and proposed a new operational framework, the client allowed us to redesign the system based on business objectives instead of individual preferences. They did not interfere with every button, every screen or every workflow. Instead, they judged us based on one simple expectation: when the system is delivered, it must work. It must be intuitive for employees to use, easy for new staff to learn, and capable of providing management with accurate, real-time information. Every department would have its own permission controls, ensuring that employees only accessed information relevant to their responsibilities. Data would move seamlessly from one department to another without repeated manual entry, while every enquiry, customer case and business transaction could be monitored through dedicated operational dashboards. The goal was never to create beautiful software. The goal was to create a business that operated more effectively.

The Real Transformation Happened Inside the Organisation

When the project was completed, the biggest success was not the software itself. The greatest transformation occurred within the organisation. Departments began communicating more effectively because everyone was following the same workflow. Information no longer disappeared inside spreadsheets stored on individual computers. Management gained complete visibility into every stage of the business instead of relying on fragmented reports prepared manually by different teams. Employees spent less time searching for information and more time serving customers. Permission control reduced unnecessary risks, while structured processes improved accountability across the organisation. The company did not simply receive a new system. They gained an entirely new way of operating, where decisions were based on reliable information rather than assumptions.

Before Artificial Intelligence Comes Digital Transformation

Today, almost every boardroom conversation revolves around Artificial Intelligence. Organisations are eager to adopt AI assistants, intelligent automation and predictive analytics. Yet one important question is often overlooked: is the organisation actually ready for AI? Artificial Intelligence does not magically fix poor business processes, inconsistent data or fragmented operations. AI simply consumes whatever data an organisation provides. If the underlying data is incomplete, duplicated or inaccurate, AI will only produce faster and more convincing mistakes.

This is why I often remind business leaders that Digital Transformation is not an optional step before AI—it is the foundation upon which every successful AI initiative is built.

Digital Transformation creates structured business processes. Structured business processes generate reliable and consistent data. Reliable data empowers trustworthy Artificial Intelligence. Skip the first two steps, and AI simply becomes another expensive technology layered on top of organisational chaos.

Many organisations today are rushing to purchase AI tools before asking whether their own operations are ready. They hope AI will solve problems that actually originated from years of inconsistent processes, disconnected systems and poor operational governance. Unfortunately, AI cannot create operational discipline. It can only amplify whatever already exists. If your business operates with clarity, AI accelerates performance. If your business operates in confusion, AI accelerates confusion.

That is why I always tell business leaders during my keynote presentations that AI is not the starting point of transformation. Digital Transformation is.

A Leadership Lesson Beyond Technology

Looking back, this project reinforced something I have believed throughout my career. Technology has never been the hardest part of Digital Transformation. People often assume software development is about coding, databases and programming languages. In reality, the most difficult challenge is helping organisations rethink the way they operate.

Every company already has a workflow. Every company already has departments. Every company already has reporting structures. The question is whether those structures are still suitable for today's business environment.

Digital Transformation is not an IT initiative. It is a leadership initiative. It requires management to rethink responsibilities, decision-making, accountability and information flow before technology can truly deliver value. When leaders embrace this mindset, software becomes an enabler instead of a burden.

A Message to Business Leaders

If your organisation is constantly modifying its system but never seems to make real progress, perhaps the problem isn't your software vendor. If your employees continue relying on spreadsheets despite having an expensive system, perhaps the issue isn't user adoption. If every department keeps asking for new features while management still cannot obtain accurate information, perhaps the real challenge lies much deeper than technology.

Before introducing AI into your organisation, ask yourself a simple question: is your digital foundation strong enough to support it?

AI is only as intelligent as the data it receives. Data is only as reliable as the processes that generate it. And those processes are only as effective as the leadership that designs them. If the foundation is weak, AI will only make poor decisions faster. If the foundation is strong, AI becomes one of the most powerful business accelerators your organisation will ever adopt.

Over the past two decades, I have worked with organisations not just to build software, but to redesign how businesses operate. Sometimes that means stepping into projects that others could not complete. Sometimes it means rebuilding the architecture from the ground up. Much like an intensive care unit (ICU), our role is to stabilise critical digital transformation projects before they fail completely, allowing organisations to recover, modernise and prepare for the future.

If your organisation is facing endless software revisions, disconnected systems, poor data quality, weak permission controls or operational processes that no longer scale with your business, let's have a conversation. Whether through executive advisory, Digital Transformation consulting or one of my keynote sessions, my mission remains the same: to help organisations build the right digital foundation today, so they are truly ready for the AI-powered future tomorrow.

Insights · 24/40 06 Aug 2026

AI Gave Me Something I Never Expected. It Gave Me Back My Reading Time.

After using AI intensively over the past few weeks, I realised something interesting. My way of working has completely changed.

In the past, I spent almost the entire day operating my computer—writing, editing, checking, and executing every task myself. Today, my computer is running multiple AI agents at the same time. One is writing, another is researching, another is designing, while another is analysing data. My role is no longer to do everything manually.

Instead, I wait for the first draft. I review it, make adjustments, approve it, and let AI continue improving. My value has shifted from execution to judgment. The keyboard is no longer where I spend most of my time—my thinking is.

What the Waiting Moments Became

What surprised me most was what happened during those waiting moments. Instead of rushing to the next task, I found myself picking up a book, enjoying a coffee, or simply thinking about bigger ideas. It feels like a break, but in reality, it’s becoming some of my most productive time.

The Better Question

People often ask me whether AI will take away our jobs. I think a better question is this: When AI gives us back time, what will we do with it? Will we spend it scrolling through social media, or will we invest it in learning, reading, thinking, and becoming better leaders?

For me, that’s the real promise of AI. It isn’t replacing people—it is giving us the opportunity to focus on the things that only people can do: think deeply, make better decisions, and create a greater impact.

How has AI changed the way you spend your time? Has it made you busier, or has it given you back time to learn and think? I’d love to hear your experience in the comments.

Insights · 25/40 05 Aug 2026

AI Didn't Change My Job. It Changed How I Think.

Over the past two weeks, one of the biggest lessons I learned wasn’t about AI itself. It was about myself. For most of my career, I’ve been someone who is very detail-oriented. I like to understand every process, every implementation, and every small step before moving forward. That mindset has helped me build businesses over the years.

But recently, I found myself working differently. Instead of spending hours thinking about every detail, I began focusing on the outcome I wanted to achieve. I realised that AI is often capable of handling the detailed execution faster, more consistently, and sometimes even better than I could. It challenged a habit that I had built over many years.

Details Still Matter — But Who Handles Them Changes

This doesn’t mean details are no longer important. Details still matter. The difference is who should spend more time on them. As leaders, perhaps our greatest value is no longer doing every detail ourselves, but ensuring the direction is correct, the objectives are clear, and the instructions are precise. AI can help execute, but it still depends on us to define the destination.

Leadership Is About the Right Work, Not the Most Work

It reminded me that leadership has never been about doing the most work. Leadership is about helping people—or now, even AI—do the right work. The clearer our thinking, the better the execution becomes. I’ve started spending more time asking “What problem are we trying to solve?” rather than “How do I complete every individual task?”

I’m still learning every day, and I’m sure my thinking will continue to evolve. But this has probably been my biggest personal takeaway so far. AI isn’t replacing our thinking. It is pushing us to think at a higher level, focusing more on strategy, judgment, and leadership than ever before.

I’d love to hear your experience too. Has AI changed the way you work, lead, or make decisions? What’s the biggest mindset shift you’ve experienced? Let’s learn from one another, because I believe we’re all still discovering what leadership looks like in the AI era.

Insights · 26/40 03 Aug 2026

Why I Started PDX: Building an Ecosystem, Not Just an Event

People often ask me why I started the Penang Digitalisation & AI Conference & Exhibition (PDX). Some assume it was because I wanted to organise a conference or create another technology event. The truth is much deeper than that. PDX was never about organising an event—it was about solving a problem that I had observed for many years.

Throughout my journey with OPERiON, I had the opportunity to work with organisations across different industries. I realised that government agencies, businesses, technology providers, universities and talented individuals were all working towards the same goal of driving innovation and economic growth. However, they were often working independently, with limited opportunities to connect, collaborate and create meaningful impact together.

I came to believe that digital transformation is not simply about adopting new technologies. It is about bringing people together, redesigning the way organisations operate, and building stronger partnerships across the entire ecosystem. Technology is only an enabler. Real transformation happens when people share knowledge, trust one another and work towards a common vision.

The Future Belongs to Ecosystems, Not Individuals

As artificial intelligence continues to reshape every industry, the importance of collaboration has become even greater. No single organisation can prepare for the future alone. Governments need industry. Businesses need technology partners. Universities need closer connections with employers. Students need opportunities to learn from real-world experiences. The future belongs to ecosystems, not individuals.

That belief became the foundation of PDX. My vision was to create a platform where government, industry leaders, technology providers, universities, startups and future talent could come together under one roof. A place where ideas become collaborations, collaborations become opportunities, and opportunities become lasting impact for our communities and economy.

Every Obstacle Became Part of the Journey

The journey has not been easy. Building an ecosystem is far more challenging than building a company. There have been countless challenges, financial pressures, setbacks and moments of uncertainty. Yet every obstacle has reinforced one important lesson: if the mission is meaningful and benefits others, every challenge becomes part of the journey rather than the reason to stop.

Today, PDX represents much more than an annual conference and exhibition. It is a growing movement to accelerate digital transformation, encourage responsible AI adoption, develop future-ready talent and strengthen collaboration between the public and private sectors. It is a platform designed to help organisations learn, connect and move forward together.

Looking Ahead

Looking ahead, my vision extends far beyond the next event. I hope to see PDX become a leading AI and digital ecosystem that starts in Penang and creates impact across Malaysia and the region. Through initiatives such as AI Hackathons, leadership forums, talent development programmes and industry collaborations, we can build a stronger future together. If you share this vision, I warmly invite you to join us on this journey by following PDX2027, participating as an exhibitor, partner or delegate, and becoming part of an ecosystem that believes innovation grows stronger when we build it together.

Think Bold. Build Together. Transform the Future.


Follow PDX

🌐 Website: penangdigitalisation.com

📢 Follow the PDX social media channels for the latest updates on exhibitions, conferences, partnerships, AI programmes and exhibitor opportunities.

We look forward to welcoming you to the PDX ecosystem.

Insights · 27/40 02 Aug 2026

SEO Is No Longer Enough. Is Your Website Ready for AI?

By Ts. Lukas J. Tan

For the past two decades, businesses have invested heavily in Search Engine Optimisation (SEO). We optimised keywords, built backlinks, improved page speed, and published articles to rank higher on Google. Those strategies are still important, but while building my own AI workforce recently, I realised something that completely changed my perspective. The next generation of websites won’t compete only for search rankings—they’ll compete to be understood by AI.

One unexpected lesson came from something developers have quietly used for years: Markdown (.md). I wasn’t trying to learn Markdown. I discovered it while building AI-powered systems with Claude. At first, I wondered why almost every document was stored as a Markdown file instead of Microsoft Word or plain text. Then it clicked. Markdown isn’t just a writing format; it’s a structured way of organising knowledge. AI doesn’t care about beautiful layouts or animations. It understands hierarchy, relationships, context, and clearly organised information. The better your knowledge is structured, the easier it is for AI to understand your business.

This made me rethink how we build websites. Traditionally, we start by designing pages—Home, About Us, Services, Contact. Today, I believe we should start by designing knowledge. Most websites, especially traditional CMS platforms, were built primarily for humans to read and search engines to crawl. They can absolutely be made AI-friendly, but many organisations still organise content page by page rather than as a connected body of knowledge. With AI-assisted development, I now find myself creating structured knowledge first, then letting AI generate the website, proposals, profiles, and other business assets from that single source. The website becomes one output—not the starting point.

From SEO to GEO and AEO

I believe we are entering the next phase of digital transformation. In the past, we optimised for SEO. Today, conversations are shifting toward Generative Engine Optimisation (GEO), Answer Engine Optimisation (AEO), and other AI-focused approaches. Whatever terminology eventually becomes the standard, the direction is clear: organisations need websites that communicate expertise in a way AI systems can understand, not just pages that look attractive to people.

One Knowledge Base, Every Output

The organisations that adapt early will gain a significant competitive advantage. Imagine maintaining one trusted knowledge base that powers your website, LinkedIn articles, keynote profiles, proposals, sales materials, training content, and even your internal AI workforce. Instead of rewriting the same information across different platforms, AI understands your knowledge once and helps you publish it consistently everywhere. That changes not only how we build websites, but how we manage knowledge across an entire organisation.

I am still researching and learning in this space, but one thing is becoming increasingly clear. The last 20 years were about building beautiful websites. The next 20 years may be about building websites that AI can understand. The question is no longer, “Does your website rank on Google?” The better question is, “Can AI understand your business well enough to recommend it?” Those who begin restructuring their websites into AI-ready knowledge platforms today may be the ones who remain visible, trusted, and discoverable in tomorrow’s AI-first world.

Insights · 28/40 01 Aug 2026

I Never Chased Frameworks. I Chased Solutions.

People often ask me what framework I use or which technology I recommend. The truth is, I have never been someone who learns technology by memorising names or following trends. I learn by solving real business problems. Many years ago, I built a UI component system that made my projects more consistent and easier to maintain. Years later, someone looked at my code and said, “This is basically Bootstrap.” I smiled because, at the time, I had never even thought about Bootstrap. I wasn't trying to use a framework — I was simply trying to solve a problem.

The same thing happened again around 2009. As my projects became larger, I realised I needed a better way to control code quality. I designed my own PHP project structure so developers could only access the folders they were supposed to access. Business logic, presentation, and data were separated to make maintenance easier and reduce mistakes. Years later, I discovered that what I had built followed the same philosophy as the Model-View-Presenter (MVP) pattern. I didn't set out to implement MVP. I was simply designing a better way to build software.

The Problem Comes First, the Name Comes Later

Looking back, I realised this has always been my approach. I rarely start with a technology or a framework. I start with the problem. Once I understand the problem deeply, I build the architecture that solves it. Sometimes the industry already has a name for it. Sometimes it becomes a recognised design pattern. Either way, the name has never been the goal. The solution has always been the goal.

Why the Database Comes First

If there is one area I have always believed deserves the most attention, it is the database. Frameworks change. Programming languages evolve. AI models improve every few months. Cloud platforms come and go. But your data remains. A poorly designed database will create problems for years, no matter how modern the technology stack is. A well-designed database, on the other hand, allows applications, frameworks, and even entire platforms to evolve without disrupting the business. To me, the database is not just another component — it is the foundation of the organisation's digital assets.

That is why, throughout my career, I have invested more time in database architecture than in chasing the latest technology trends. Naming standards, relationships, primary keys, audit trails, migrations, scalability, and future-proof design are not glamorous topics, but they are the reason software survives. If people remember me for one thing, I hope it is this: build the database right, and everything else becomes easier.

If your organisation is facing challenges in database architecture, system design, digital transformation, or AI-ready application architecture, I would be glad to have a conversation. The right database design doesn't just solve today's problems — it creates the foundation for the next decade of growth.

Insights · 29/40 29 Jul 2026

Why I Started ScamAlert Junior™ — Building the Next Generation of Scam-Aware Children

By Ts. Lukas J. Tan — Founder of ScamAlert Junior™ | CEO of OPERiON | AI & Digitalisation Strategist

Over the past few years, I have had the opportunity to work closely with businesses, schools, government agencies, technology professionals, educators, and parents through various digitalisation, artificial intelligence, and cybersecurity initiatives. While every organisation has different priorities, one concern has become increasingly common — the digital world is evolving much faster than our ability to prepare people for it. Cybersecurity is no longer a topic reserved for IT departments or large corporations. It has become a life skill that affects every individual, regardless of age.

As technology becomes more accessible, children are also entering the digital world earlier than any previous generation. They learn through smartphones, communicate through messaging platforms, play games online, and increasingly interact with artificial intelligence without fully understanding the risks that may exist behind every screen. This observation led me to a simple but important question: are we preparing our children early enough to navigate the digital world safely? That question eventually became the starting point of ScamAlert Junior™, an educational intellectual property created to help children develop critical thinking, responsible digital habits, and the confidence to make better decisions before they encounter online threats.

The Digital Childhood Has Changed

Childhood today looks very different from what many parents experienced growing up. Previous generations spent most of their free time outdoors, interacting face-to-face with friends, reading physical books, or learning through direct conversations with teachers and family members. Today's children, however, are growing up in an environment where digital technology is seamlessly integrated into almost every aspect of daily life. Smartphones, tablets, online classrooms, social media platforms, streaming services, artificial intelligence, and multiplayer games have become part of their normal routine from a very young age.

While these technologies provide incredible opportunities for education, creativity, and communication, they also introduce new challenges that many children are not yet equipped to recognise. Fake online identities, phishing attempts, scam advertisements, misleading information, cyberbullying, and AI-generated content are becoming increasingly sophisticated. Children are naturally curious, trusting, and eager to explore new experiences — qualities that make them wonderful learners but can also make them more vulnerable in digital environments.

The digital world itself is not the problem. Technology is one of the greatest tools humanity has ever created, opening doors to knowledge and opportunities that previous generations could only imagine. The real challenge lies in ensuring that children develop the judgement, awareness, and critical thinking needed to use these technologies responsibly. Just as we teach children how to cross a busy road safely, we must also prepare them to navigate the digital world with confidence rather than fear.

Why Traditional Scam Awareness Is No Longer Enough

For many years, scam awareness campaigns were designed primarily for adults. The focus was often on financial fraud, investment scams, phishing emails, or identity theft targeting working professionals and senior citizens. Children were rarely considered part of the conversation because they were perceived as having limited financial resources and relatively little online independence. That assumption is changing rapidly.

Today, children are exposed to online interactions much earlier than before. They receive messages from strangers while gaming, watch influencer content across multiple platforms, click advertisements without understanding their intent, and sometimes unknowingly share personal information through quizzes, apps, or social media. Modern scams are no longer limited to stealing money. They can involve manipulation, deception, emotional exploitation, identity misuse, or attempts to build trust before targeting other members of a family.

This means digital safety education cannot begin only after an incident has occurred. Waiting until a child becomes a victim is similar to teaching road safety only after a traffic accident. Prevention has always been more effective than recovery. Instead of relying solely on warnings such as “don't click suspicious links” or “don't talk to strangers online,” we need to help children understand why certain situations are dangerous and how to think critically before making decisions.

The future of scam awareness should not be built upon fear alone. It should be built upon knowledge, observation, curiosity, communication, and responsible decision-making. These are skills that children can continue applying throughout their lives as technology continues to evolve.

Why Stories Can Teach Better Than Lectures

Throughout history, stories have always been one of the most effective ways to teach values, wisdom, and life lessons. Long before classrooms, textbooks, or digital learning platforms existed, knowledge was passed from one generation to another through stories that people could remember, relate to, and share. While technology has changed dramatically, the way children learn has remained surprisingly consistent. They still remember characters long after they forget instructions. They remember emotions more easily than statistics. They remember meaningful experiences more than lengthy explanations.

This understanding became one of the foundations behind ScamAlert Junior™. Rather than producing another educational handbook filled with warnings and technical terminology, I wanted to create characters that children could genuinely connect with. Characters like Lukas, Leo, Lynn, Turbo, Johan, Lina, and Atuk Hassan each represent different personalities, perspectives, and life experiences. Through their adventures, mistakes, discussions, and teamwork, children are encouraged to observe carefully, ask questions, verify information, and think before acting.

Storytelling transforms learning into an enjoyable experience rather than a compulsory lesson. Instead of telling children what they should or should not do, stories allow them to explore situations alongside familiar characters, developing their own understanding through observation and discussion. When learning becomes emotionally engaging, the lessons often remain with children far beyond the final page of a book.

Building More Than Just a Comic

Many people who first hear about ScamAlert Junior™ naturally assume it is simply another children's comic book. While storytelling remains an important part of the project, the comic itself represents only one component of a much larger educational vision. From the beginning, my objective was never limited to publishing a series of books. I wanted to create an educational intellectual property that could continue supporting children across different learning environments for many years to come.

Behind every official character sits a comprehensive Character Asset Library that defines visual identity, personality, behaviour, educational purpose, communication style, expressions, poses, costumes, colours, and commercial guidelines. This ensures consistency regardless of whether the characters appear in books, classroom activities, animations, mobile applications, educational games, public awareness campaigns, or licensed merchandise. Every future adaptation remains aligned with the same educational philosophy and values.

Beyond the characters themselves, the ecosystem is designed to expand into activity books, teacher resources, parent guides, workshops, digital learning materials, exhibitions, community programmes, and future educational technologies. Each component shares the same mission: helping children become thoughtful, responsible, and confident digital citizens through engaging and practical learning experiences.

Building an educational intellectual property requires thinking beyond today's publication. It requires creating a foundation that remains relevant as new technologies, new challenges, and new generations emerge.

Looking Towards the Future

Artificial intelligence will continue advancing. Digital platforms will become even more sophisticated. Online scams will undoubtedly evolve in ways we cannot yet fully predict. While technology changes rapidly, the qualities that protect people often remain timeless. Critical thinking, empathy, responsibility, curiosity, integrity, and good judgement have always been valuable, regardless of the tools people use.

This is ultimately what ScamAlert Junior™ hopes to contribute. The project is not about creating fear of technology or encouraging children to avoid digital innovation. On the contrary, it is about helping young learners embrace technology with confidence while understanding the importance of thinking before acting, verifying information before believing it, and seeking guidance whenever uncertainty arises.

I also believe protecting children online should never be the responsibility of schools alone. Parents, teachers, communities, government agencies, technology companies, and industry leaders all have an important role to play in shaping the next generation of responsible digital citizens. Education becomes most effective when these groups work together towards a common purpose.

ScamAlert Junior™ was created with that long-term vision in mind. It is more than a comic, more than a collection of characters, and more than an educational campaign. It is a commitment to helping children build the confidence, judgement, and values they will need not only to recognise scams, but to navigate an increasingly digital world with wisdom, responsibility, and hope.

Insights · 30/40 17 Jul 2026

AI Is Not Replacing Jobs — It’s Exposing Leaders Who Can’t Adapt Fast Enough

At a PDX2026 speaker briefing last year, a manufacturing CEO told me his company had just rolled out an AI forecasting tool that nobody on the floor was using. The tool wasn’t broken. Nobody had told the planning team which decision it was supposed to change. Six months and a licence fee later, the spreadsheets were still running the floor, and the AI dashboard sat open in a browser tab nobody clicked.

I hear a version of this story at almost every PDX prep call. The technology works. The leadership around it doesn’t move fast enough to point it at anything.

Three Things I Keep Seeing

The tool arrives before the decision does

Someone in IT or ops champions a good tool. It gets bought, piloted, even praised in a town hall. But nobody has decided what will change because of it — which report stops being manually built, which meeting gets shorter, which approval gets skipped. Without that, the tool becomes a second system running next to the old one, not a replacement for it.

Nobody owns the follow-through

A pilot has a project owner. Adoption rarely does. Once the vendor demo is over and the case study photo is taken, the person accountable for whether staff actually change their daily habits is often nobody in particular — which means, in practice, nobody.

Middle management absorbs a leadership problem

When adoption stalls, the story that gets told is usually “our people resisted change.” In my experience it’s rarely resistance. It’s that middle managers were handed a new tool and the same old targets, with no time carved out to actually redesign how the work gets done. They didn’t reject the technology. Nobody gave them room to use it.

A Test Before Your Next AI Pilot

Before signing off on another tool, I ask leadership teams three questions. If they can’t answer all three in one sentence each, the pilot is not ready to launch:

  • What specific decision or task does this replace, not just support?
  • Who is personally accountable for adoption twelve weeks after go-live?
  • What will we stop doing to make room for this?

If the answer to the third question is “nothing”, you’ve just bought a second job for your team, not a productivity gain.

FAQ

Will AI actually take my team’s jobs?

Rarely in one clean step. What I see far more often is a role quietly becoming unnecessary over 12–18 months because leadership never redesigned the workflow around the new tool — the job doesn’t disappear so much as the company falls behind competitors who did the redesign.

What should a leader do differently this quarter?

Pick one AI tool already sitting half-used in your organisation and answer the three-question test above for it. Fix the adoption gap before buying anything new.

Is this really a leadership problem, not an IT problem?

If your IT team can point to a tool that’s live but nobody outside IT can point to a decision it changed, it’s a leadership problem wearing an IT costume.

The Short Version

The real risk was never that AI replaces people. It’s that leaders who can’t make a fast, specific decision about how work should change get quietly outpaced by leaders who can — using the exact same tools.

Insights · 31/40 04 Jul 2026

The Next Phase of Digital Transformation in Malaysia: Where Smart Companies Are Positioning Themselves Now

Running PDX means I get a year-on-year read on what Malaysian business leaders are actually worried about, not what a survey says they should be worried about. Between PDX2025 and PDX2026, the conversations in the delegate lounge changed in a way I didn’t expect.

Three Signals From the Delegate Floor

Signal 1: Fewer people ask “what is AI”

At PDX2025, a good third of conversations were still explaining basic concepts. At PDX2026, almost nobody asked that. The question had shifted to “who else in my industry has already deployed this, and what did it cost them to get it wrong?”

Signal 2: Vendors are being asked harder questions

Exhibition-floor conversations got sharper. Procurement teams showed up with checklists instead of curiosity — asking about integration with legacy ERP systems, not just feature lists. That’s a sign the buying committee has matured past the pilot-project stage.

Signal 3: The window to catch up is visibly shrinking

A supply-chain director told me flatly that two of his competitors had already renegotiated supplier contracts around real-time data sharing. His company hadn’t started. He wasn’t worried about being behind — he was worried about being unable to catch up before contracts renewed.

Where the Smart Companies Are Actually Positioning

The organisations that stood out to me this year weren’t the ones with the biggest AI budget. They were the ones who could describe, specifically, which of their existing workflows would be redesigned in the next two quarters — and who owned that redesign. Everyone else was still in “exploring options” mode, which is a polite way of saying nothing has actually changed yet.

A Question Worth Sitting With

If a competitor called your best customer tomorrow and said “we can already do that, in real time, at lower cost” — would your team know within the hour, or find out at contract renewal?

Where This Goes Next

This is exactly the gap we built PDX2026 around: not another round of AI explainers, but a room where the people already three steps ahead sit next to the people who need to move. If you want to see where Malaysia’s next phase of digital transformation is actually heading, that’s the conversation happening on the PDX floor, not in a webinar.

Insights · 32/40 28 Jun 2026

Why Digital Transformation Can No Longer Be Solved Internally (And What Smart Companies Are Doing Instead)

A few years ago, an OPERiON client — a mid-sized distributor — asked us to help fix a warehouse system their internal team had spent eight months building. It didn’t talk to their accounting software, couldn’t handle their busiest month of the year, and had already cost more than three off-the-shelf platforms combined. The build itself wasn’t incompetent. Nobody on the team had simply been given time to look outside the building before starting.

The Situation

Their internal IT lead was smart and had built useful tools before. But he was solving the problem with the only reference points he had: what the company had done in the past, and what he personally already knew how to build. Three competitors, we later found out, were already running a widely-used regional platform for the exact same workflow — at a fraction of the cost and time.

The Insight

Internal teams aren’t under-skilled. They’re under-exposed. A good engineer who has only ever seen one company’s way of solving a problem will build a solution shaped by that one company’s history, not by what the wider industry has already learned the hard way. That’s not a competence gap. It’s a visibility gap, and no amount of internal effort closes it, because the information simply isn’t inside the building.

What Changed

We didn’t replace their team. We changed the first step: before building anything, spend two weeks mapping what already exists in the market and who in their own supplier or partner network had solved something adjacent. That single habit — look outward before building inward — turned their next three projects from eight-month builds into six-week integrations.

Why This Keeps Happening

Vendor dependency gets a bad reputation, so companies overcorrect into “we’ll build it ourselves to stay independent.” But independence built on outdated information isn’t independence — it’s isolation with extra steps. The companies actually winning right now aren’t the most self-reliant. They’re the ones with the widest, fastest-moving network of outside insight feeding into decisions made inside.

A Question for Your Next Project

Before your team writes a single line of code or signs off on a build, can anyone in the room name two ways competitors or peers have already solved an adjacent problem? If not, you’re not being independent. You’re building blind.

Insights · 33/40 26 Jun 2026

Why Traditional Technical Skills Alone Will No Longer Be Enough in the AI Era

Artificial intelligence is not reducing the importance of humans—it is redefining the value humans are expected to create.

Technology Has Entered a New Era

For almost two decades, I have worked in software development, digital transformation, and technology consulting. During most of that time, technical expertise was one of the strongest competitive advantages a professional could possess. The more programming languages you mastered, the more systems you built, and the more technical problems you solved, the more valuable you became to an organisation. Today, that equation is changing rapidly. Artificial intelligence is transforming the way software is written, analysed, tested, and maintained. Tasks that once demanded years of experience can now be accelerated within minutes using AI-assisted development tools. This is not a temporary trend or another technology cycle. It represents a structural shift in how knowledge work is performed. While many discussions continue to focus on whether AI will replace jobs, I believe the more important question is whether professionals are prepared to redefine the value they bring. Technology is evolving faster than many careers, and those who continue relying only on traditional technical skills may soon discover that technical execution alone is no longer enough.

AI Is Replacing Tasks Before It Replaces Professions

There is a common misconception that artificial intelligence will suddenly replace entire professions. In reality, AI is replacing individual tasks long before it replaces complete roles. Software developers can now generate code, automate documentation, identify programming errors, create user interfaces, and even suggest software architecture within minutes. Accountants can automate reconciliations. Designers can generate visual concepts almost instantly. Lawyers can summarise contracts with remarkable speed. These capabilities do not eliminate professionals overnight, but they significantly reduce the time required to complete routine work. As a result, organisations begin asking a different question. Instead of evaluating employees based on how efficiently they complete repetitive tasks, they increasingly evaluate them based on how well they solve business problems, make decisions, communicate across teams, and improve organisational performance. The value of execution is gradually shifting towards the value of thinking. Those who recognise this transition early will position themselves for future growth, while those who continue competing only on technical execution may find themselves competing directly against AI.

Technical Skills Will Remain Important—but They Are No Longer Enough

Some people interpret discussions about AI as suggesting that technical knowledge is becoming irrelevant. I disagree completely. Programming, engineering, cybersecurity, software architecture, and systems integration remain essential disciplines. However, technical capability is becoming the starting point rather than the destination. Future technology professionals must also understand business operations, organisational behaviour, customer expectations, process optimisation, and strategic objectives. Throughout my career, I have discovered that many software projects fail not because programmers cannot write code, but because business requirements are misunderstood, communication breaks down, or the organisation has never clearly defined the problem it wants to solve. AI may now generate thousands of lines of functional code, but it still depends on humans to ask the right questions, define meaningful outcomes, and evaluate whether the proposed solution actually creates business value. Technical knowledge remains valuable, but business understanding increasingly determines professional relevance.

The Professionals Who Thrive Will Become Translators

One observation has remained remarkably consistent throughout my experience working with clients from different industries. The individuals who create the greatest impact are rarely those with the deepest technical expertise alone. Instead, they are the people capable of translating between business and technology. They understand the language of executives while also appreciating the realities faced by programmers, engineers, and operational teams. They know how to convert a strategic objective into system requirements, and they know how to explain technical limitations in business language that decision-makers understand. Artificial intelligence will only increase the importance of this role. As AI becomes capable of generating technical output, organisations will need more professionals who can provide context, exercise judgement, resolve ambiguity, and align multiple stakeholders towards a common objective. The future belongs not only to builders, but to translators who connect ideas, people, systems, and execution.

Organisations Must Redesign Work, Not Just Buy AI

Many organisations are currently investing heavily in artificial intelligence platforms, hoping that productivity will improve automatically. Unfortunately, technology alone rarely transforms an organisation. I have seen projects where sophisticated systems were successfully deployed, yet employees continued using spreadsheets because workflows were never redesigned. Managers still approved work manually because responsibilities remained unclear. Communication problems persisted because the organisation focused on purchasing technology instead of changing behaviour. Artificial intelligence should never be viewed as an additional tool layered on top of existing inefficiencies. Instead, leaders must rethink how decisions are made, how information flows, and how responsibilities should evolve. AI changes the way work is organised, not merely the software employees use. Without leadership, ownership, communication, and redesigned processes, even the most advanced AI solution will struggle to create sustainable value.

Leadership Will Become More Valuable Than Technical Perfection

One of the biggest changes brought by artificial intelligence is the growing importance of leadership. Technical professionals who aspire to remain valuable must develop capabilities that AI cannot easily replicate. These include critical thinking, ethical judgement, creativity, emotional intelligence, negotiation, stakeholder management, adaptability, and strategic decision-making. Likewise, business leaders must develop sufficient technological understanding to make informed strategic decisions without needing to become programmers themselves. The strongest organisations of the future will not necessarily employ the most technically gifted individuals. They will build teams capable of combining business insight, technical capability, leadership, and continuous learning. In the AI era, leadership is no longer reserved for people with formal management titles. Every professional is increasingly expected to contribute ideas, challenge assumptions, coordinate across departments, and help organisations adapt to continuous change.

Dream It. Execute It. Ground It.

This philosophy has guided my work for many years, long before generative AI became part of everyday business conversations. Dreaming is about recognising opportunities that others have not yet seen. Execution is the discipline required to transform those ideas into practical workflows, systems, and measurable outcomes. Grounding is ensuring that innovation genuinely improves the lives of employees, customers, and organisations instead of becoming another technology experiment with little lasting impact. Artificial intelligence is giving organisations unprecedented capabilities, but capability without execution creates little value. Likewise, execution without grounding often produces systems that look impressive yet fail to solve meaningful problems. Sustainable innovation requires all three elements working together. Technology should serve people, support organisations, and strengthen long-term competitiveness rather than simply demonstrating technical sophistication.

The Real Question Every Professional Should Ask

Perhaps the most important question facing professionals today is not whether AI will replace them. A more meaningful question is whether they are developing capabilities that remain valuable even when AI becomes significantly more capable. If artificial intelligence can perform half of today’s technical tasks tomorrow, what unique contribution will you continue making? Will you become someone who simply executes instructions, or someone who frames problems, guides decisions, builds alignment, and creates lasting organisational value? Throughout history, every major technological revolution has rewarded those willing to evolve alongside it. The AI era will be no different. Traditional technical expertise will remain important, but the professionals who combine technology with strategic thinking, business understanding, communication, leadership, and disciplined execution will become the people organisations rely on most. In the years ahead, human value will be measured less by what we can do manually, and more by how effectively we help others navigate change.

Insights · 34/40 25 Jun 2026

Why Companies With Strong Workflow Systems Are Dominating the AI Economy

I built my first automation system in 2008 — a customer-relationship tool I called Autobot CRM, inspired by watching Iron Man and wondering if a small business could have its own version of Jarvis. There was no “AI workflow” category back then. There was just a simple realisation: the software mattered less than the sequence of steps it was automating.

The Lesson That Still Holds

Autobot CRM wasn’t powerful because of clever code. It was useful because I’d mapped, in painful manual detail, exactly which follow-up happened after which customer action, and in what order. The automation just executed a workflow that was already clear. Companies rushing to bolt AI onto a messy, undocumented process today are making the same mistake I’d have made if I’d automated a workflow I hadn’t actually understood first.

Two Kinds of Companies in the AI Economy

Companies with a workflow to plug AI into

These organisations can describe, step by step, how a task currently moves from trigger to completion, including who touches it and why. When they adopt an AI tool, it slots into a known gap and the result is immediately measurable, because the “before” state was already documented.

Companies hoping AI will create the workflow for them

These organisations buy the tool first and hope structure emerges afterward. It rarely does. The AI ends up automating confusion faster, surfacing more inconsistent outputs at higher speed, which is a worse position than the manual mess they started with.

How OPERiON Builds Around This

Every system we design leans on independent, microservice architecture on purpose — not as a technical preference, but so that a client’s workflow can keep evolving without the whole system needing to be rebuilt each time a piece changes. Fragile, tightly-coupled systems are exactly where AI adoption stalls, because nobody can safely change one part without breaking three others.

A Practical Starting Point

Before evaluating any AI vendor, write down — on one page — the current manual steps of the process you want to improve. If you can’t fit it on one page, that’s the actual project. The AI tool is the easy part that comes after.

Insights · 35/40 29 May 2026

AI Can Write Code. It Cannot Replace Software Architecture.

As AI makes software development faster, software architecture becomes more important—not less.

Everyone Is Talking About AI Writing Code. Few Are Talking About What Happens Five Years Later.

Artificial intelligence has transformed software development at an extraordinary pace. Today, developers can generate code, build websites, create mobile applications, design user interfaces, and even produce technical documentation within minutes. Tasks that once required days of programming effort can now be completed through carefully written prompts and AI-assisted development tools. This technological progress is remarkable, and I believe every technology professional should embrace it. However, while AI has dramatically reduced the time required to build software, it has also created a new misconception. Many people now assume that if software can be built faster, then software development itself has become easier. My experience over more than nineteen years tells me otherwise. Building software has indeed become faster. Building software that remains maintainable, scalable, secure, and valuable over many years is an entirely different challenge. That challenge has always been called software architecture, and in the AI era, it has become more important than ever before.

Building Software Is No Longer the Difficult Part

For many years, software projects were constrained by development speed. Businesses waited months for programmers to complete interfaces, databases, reports, and workflow modules. Today, AI has changed that equation completely. Prototypes can be created within hours. Landing pages can be generated within minutes. Developers can solve programming errors with unprecedented speed. Even non-technical users are beginning to create applications using AI-assisted platforms. This democratisation of software development is exciting because it lowers the barrier to innovation. More entrepreneurs can validate ideas, more organisations can experiment, and more people can participate in digital transformation. However, creating a working application should never be confused with creating a sustainable software platform. Speed solves the problem of building version one. It does not automatically solve the challenges of maintaining version fifty. The true complexity of software begins after deployment, not before it.

Architecture Determines Whether Software Can Grow

Every organisation changes. Customers evolve. Regulations are updated. Business models expand. New technologies emerge. As these changes occur, software must also evolve. This is where architecture becomes the foundation of long-term success. A well-designed architecture allows systems to scale without constant rebuilding. It enables modules to be upgraded independently, integrations to be added safely, and new business requirements to be implemented without affecting the entire platform. Poor architecture produces the opposite effect. Small changes create unexpected problems. New features become increasingly expensive. Technical debt accumulates. Eventually, organisations reach a point where replacing the system appears easier than maintaining it. The problem is rarely the programming language or the framework. More often, it is the architectural decisions made at the beginning of the project, when speed was prioritised over sustainability.

AI Understands Code. Architecture Requires Judgement.

Artificial intelligence has become remarkably capable of generating technical solutions. It can recommend database structures, optimise algorithms, suggest APIs, and write clean code based on detailed prompts. These capabilities significantly improve developer productivity. Yet software architecture extends beyond writing code. Architecture requires understanding business strategy, organisational workflows, operational risks, user behaviour, scalability requirements, security considerations, governance, and long-term maintenance. These decisions often involve balancing multiple priorities that cannot be resolved by technical optimisation alone. An architect must ask questions such as: How will this system evolve over the next five years? Which modules should remain independent? How should future integrations be managed? What happens if business priorities change unexpectedly? These questions require judgement, experience, and business understanding. AI can provide recommendations, but humans remain responsible for making architectural decisions that determine the future of an organisation’s technology.

The Most Expensive Software Mistakes Are Usually Invisible at the Beginning

One of the most dangerous characteristics of poor software architecture is that it often appears successful during the early stages of a project. The application launches. Users log in successfully. Reports are generated correctly. Management feels confident because the project has been delivered on time. The real problems emerge months or even years later. New business requirements become difficult to implement. Performance begins to decline as transaction volumes increase. Integrating external platforms requires significant redevelopment. Every enhancement introduces unexpected bugs because components are tightly connected. Technical teams spend more time maintaining old code than creating new value. These issues are rarely caused by poor programmers. They are usually the consequence of architectural decisions that failed to anticipate future organisational growth. By the time these problems become visible, correcting them is often significantly more expensive than building the system correctly from the beginning.

Software Architecture Must Begin with Business Architecture

Throughout my career, I have learned that successful software projects rarely begin with discussions about technology. They begin with conversations about the business itself. How does the organisation create value? Which workflows generate competitive advantage? Which information is most critical for decision-making? Where are operational bottlenecks occurring? Technology should support these answers rather than dictate them. Before writing a single line of code, organisations should first understand how work flows across departments, how responsibilities are assigned, and how customers experience the business. Software architecture should therefore reflect business architecture. When technology follows business strategy, systems remain aligned with organisational objectives even as technology continues evolving. When technology is designed independently from business reality, organisations often find themselves adapting their operations to accommodate software instead of allowing software to support the business.

AI Is Changing the Role of Software Professionals

The AI era is transforming what it means to be a software professional. Future developers will spend less time writing repetitive code and more time solving business problems. Software architects will increasingly evaluate AI-generated solutions rather than producing every technical component manually. Project managers will coordinate intelligent automation instead of supervising routine development tasks. Business analysts will become even more important because defining the right problem is now more valuable than generating another solution. Professionals who combine technical expertise with communication, critical thinking, business understanding, and architectural judgement will become indispensable. Those who focus only on code generation may discover that AI performs many of those activities faster and at lower cost. The future belongs to professionals who can bridge business strategy and technology implementation while ensuring systems remain maintainable long after the excitement of deployment has faded.

Dream It. Execute It. Ground It.

Artificial intelligence has given us extraordinary new capabilities, but technology alone has never guaranteed lasting success. Dreaming allows organisations to imagine new possibilities and innovate beyond traditional limitations. Execution transforms those ideas into working systems that improve productivity and create measurable value. Grounding ensures those systems remain practical, maintainable, scalable, and aligned with the realities of business growth. Software architecture represents this final step. It is the discipline that turns short-term innovation into long-term organisational capability. As AI continues changing how software is built, organisations should remember that technology may accelerate development, but architecture determines sustainability. The companies that succeed over the coming decade will not simply build software faster. They will build systems that continue serving their organisations long after today’s technologies have evolved into tomorrow’s history.

Executive Reflection

Before beginning your next software or AI project, ask yourself:

  • Are we designing software, or are we designing a long-term business capability?
  • Will this architecture still support our organisation five years from now?
  • Does our technology reflect the way our business actually operates?
  • Are we prioritising speed at the expense of sustainability?
  • If AI can generate code in minutes, where will our long-term competitive advantage come from?

Artificial intelligence has changed how software is built.

It has not changed the importance of designing systems that organisations can trust, maintain, and grow with.

That is why software architecture remains one of the most valuable disciplines in the AI era.

Insights · 36/40 24 May 2026

Why Leaders Must Evolve From Decision-Makers to System Architects in the AI Era

Organising the first PDX conference, I made hundreds of decisions personally — which vendor, which stage layout, which speaker slot. By PDX2026, my job had changed almost entirely. I was no longer making most of those decisions. I was designing the system that let other people make them well, without calling me first.

Decision-Maker vs System Architect

A decision-maker is the person everyone waits on. A system architect is the person whose absence doesn’t stop anything, because the structure already tells people how to decide. Most leaders I meet are still operating as the first, even as their organisation has grown far past the size where that scales.

What a decision-maker optimises for

Being right, quickly, on the specific thing in front of them. It feels responsive. It also means every important choice funnels through one person’s calendar.

What a system architect optimises for

Designing the conditions — the information flow, the escalation rules, the shared context — so that a good decision is the default outcome even when the architect isn’t in the room. It feels slower to set up. It scales without you.

The PDX Test

The clearest sign PDX had become a system rather than a one-man decision engine: during the 2026 event itself, I was mostly moving between stages, not fielding operational questions. The team had the structure to handle what came up. That wasn’t luck. It was eighteen months of deliberately building the structure instead of just making faster decisions.

FAQ

Does this mean leaders shouldn’t make decisions anymore?

No — it means reserving your personal decision-making for the handful of choices that genuinely need it, and designing everything else so your team doesn’t need to ask.

Where should a leader start?

Pick the single decision your team asks you for most often. Instead of answering it again, write down the rule you used to answer it, and hand the rule to the team. That's the first brick of the system.

Insights · 37/40 20 May 2026

Digital Transformation Is Not About Technology — It’s About How Your Organisation Thinks

The best digital tool I’ve ever built won’t stop a single scam on its own. What stops a scam is a grandparent pausing for three seconds before clicking a link, or a teenager remembering to ask “why is this stranger asking me for a one-time password?” That’s not a technology outcome. It’s a thinking habit — and it’s the exact same gap I see inside companies that have spent heavily on digital transformation and still can’t explain what changed.

Two Kinds of “Digital”

Writing Scam-Proof and building the ScamAlert Junior comics taught me something I now see everywhere in corporate transformation projects too: giving someone a tool doesn’t give them the instinct to use it well. You can install the best anti-fraud software in Malaysia on every device in a household, and it won’t matter if nobody in that household has learned to pause before trusting an urgent message. The software was never the missing piece. The habit of questioning was.

Companies make the identical mistake with digital transformation budgets. They buy the platform. They skip building the habit of questioning how work should actually flow through it. Six months later, the platform is “live” and nothing about how people actually work has changed, because the organisation never learned to think differently — it just learned to click a new button in roughly the old way.

What “Thinking Differently” Actually Looks Like

In the scam-awareness talks I give to schools and community groups, the turning point is never the moment I show a slide about phishing techniques. It’s the moment someone in the room says, out loud, “wait, I did exactly that last week.” That’s a mindset shift, and it happens through story and reflection, not through installing anything.

Inside an organisation, the equivalent moment is a manager saying “wait, we’ve been approving this the same way for six years and nobody has asked why.” If your digital transformation programme has never produced that sentence out loud in a meeting, technology has been installed, but thinking hasn’t changed — and the transformation, whatever the dashboard says, hasn’t actually happened yet.

Where to Look First

Before your next platform purchase, sit in on the process you’re trying to fix and count how many times someone says “that’s just how we’ve always done it.” That sentence, not the software gap, is what you’re actually transforming.

Insights · 38/40 14 May 2026

Why Digital Transformation Is No Longer About Technology — It Is About Redesigning the Organisation

Artificial intelligence is not simply changing the tools we use. It is forcing organisations to rethink how work is organised, decisions are made, and value is created.

Technology Is Moving Faster Than Most Organisations Can Adapt

Over the past two decades, organisations have invested billions of dollars in enterprise software, cloud platforms, automation, and, more recently, artificial intelligence. Yet despite this rapid advancement, many businesses continue to struggle with the same operational challenges they faced years ago. Meetings remain unnecessarily long, approval processes are slow, information is scattered across departments, and employees still spend valuable time performing manual tasks that technology should have eliminated long ago. This disconnect highlights an important reality. Digital transformation is no longer constrained by technology. Today’s tools are more capable than ever before. Instead, the limiting factor has become the organisation itself. The greatest challenge is no longer finding better software but redesigning how people collaborate, make decisions, share information, and execute work. Organisations that continue treating digital transformation as an IT project will increasingly find themselves falling behind competitors who understand that transformation begins with organisational redesign rather than technology acquisition.

Technology Alone Does Not Change the Way an Organisation Works

One of the biggest misconceptions surrounding digital transformation is the belief that implementing a new system automatically changes organisational behaviour. In reality, software only provides capability. People determine whether that capability creates value. I have seen organisations invest heavily in ERP platforms, CRM systems, workflow automation, AI assistants, and sophisticated dashboards, only to discover months later that employees still rely on spreadsheets, manual approvals, email chains, and disconnected processes. The technology functions exactly as intended, but daily operations remain largely unchanged. This happens because digital transformation is often approached as a technology deployment instead of an organisational redesign exercise. Installing new software without redefining responsibilities, communication channels, performance measurements, and decision-making processes simply digitises existing inefficiencies. Technology becomes an additional layer rather than a catalyst for meaningful improvement.

Artificial Intelligence Is Redefining Organisational Structures

Artificial intelligence is accelerating a transformation that extends far beyond automation. It is changing how organisations should be structured. Traditional organisations were designed around clearly defined departments, hierarchical approvals, and specialised job functions. AI is making these boundaries increasingly fluid. Employees now have access to tools that allow them to analyse information, create content, automate routine tasks, and solve problems that previously required multiple departments. As a result, organisations must rethink reporting structures, role definitions, decision authority, and collaboration models. The future organisation will rely less on rigid departmental silos and more on cross-functional teams capable of responding quickly to changing business needs. This shift is not about removing people. It is about enabling people to contribute at a higher level while allowing technology to handle repetitive execution. Organisational design must evolve alongside technological capability.

Leaders Must Shift from Managing Work to Designing Systems

Leadership itself is undergoing a significant transformation. For many years, effective managers were expected to supervise work, monitor performance, approve decisions, and solve operational problems. In the AI era, these responsibilities increasingly shift towards designing systems that allow good decisions to happen consistently without constant managerial intervention. Leaders must become architects of organisational capability rather than supervisors of daily activity. They must establish clear workflows, define accountability, simplify communication, and ensure information reaches the right people at the right time. Artificial intelligence can assist with analysis and automation, but it cannot replace thoughtful organisational design. Sustainable transformation depends on leaders who understand both business strategy and operational execution, creating an environment where technology supports people instead of forcing people to adapt to poorly designed systems.

Communication Is Becoming the Most Valuable Organisational Capability

Throughout my career in software development and digital transformation, I have observed that many projects do not fail because of poor technology. They fail because communication breaks down between business leaders, technical teams, operational users, and external stakeholders. Executives often describe business objectives while developers interpret technical requirements, yet somewhere between those conversations the original problem becomes distorted. Artificial intelligence does not eliminate this challenge. In many cases, it amplifies it. AI systems depend heavily on accurate context, clear objectives, and disciplined implementation. The organisations that succeed will therefore invest as much in improving communication as they do in purchasing technology. Employees who can translate business challenges into practical implementation strategies will become increasingly valuable because they bridge the gap between strategic vision and operational reality.

Organisational Agility Will Become the New Competitive Advantage

In the past, organisations often competed through economies of scale, production efficiency, or geographical reach. Today, competitive advantage is increasingly determined by organisational agility. How quickly can leadership recognise change? How rapidly can teams redesign workflows? How efficiently can information move across departments? How confidently can employees adopt new technologies? Artificial intelligence provides faster access to information, but organisations still require people capable of interpreting that information, making informed decisions, and executing consistently. Companies that redesign themselves around adaptability rather than bureaucracy will respond more effectively to market changes, customer expectations, and technological disruption. Agility is no longer simply an operational characteristic. It is becoming a strategic capability that determines long-term competitiveness.

Digital Transformation Requires Courage Before Technology

Every successful transformation I have witnessed began with leadership making difficult decisions rather than purchasing new software. Leaders chose to challenge long-standing assumptions, redesign familiar workflows, redefine responsibilities, and encourage employees to embrace new ways of working. These decisions often created discomfort because organisational redesign requires people to leave familiar routines behind. Technology implementation is usually the easiest phase of transformation. Changing behaviours, aligning stakeholders, and maintaining momentum require significantly greater discipline. Organisations must therefore recognise that transformation is fundamentally a leadership responsibility. Technology provides new possibilities, but courage, communication, and execution determine whether those possibilities become sustainable business outcomes. The future belongs to organisations willing to redesign themselves before competitors force them to do so.

Dream It. Execute It. Ground It.

Every meaningful transformation begins with a vision of what an organisation could become. Dreaming allows leaders to imagine a future beyond today’s limitations. Execution transforms that vision into redesigned workflows, improved communication, stronger leadership, and measurable operational improvements. Grounding ensures that transformation remains practical, sustainable, and aligned with the realities of employees, customers, and long-term organisational success. Artificial intelligence will continue evolving at remarkable speed, but technology alone will never determine which organisations succeed. Those that thrive will be the ones willing to redesign how they work, rethink how they lead, and continuously adapt how they create value. Digital transformation has therefore become much more than a technology initiative. It has become an organisational discipline that connects people, leadership, systems, and innovation into a sustainable competitive advantage.

Executive Reflection

Before launching your next digital transformation initiative, consider these questions:

  • If every employee had access to AI tomorrow, would your organisation still operate the same way?
  • Which workflows exist today simply because “that is how we have always done it”?
  • Are your organisational structures designed for hierarchy, or for speed and collaboration?
  • Does technology support your people, or have your people adapted to inefficient technology?
  • If you could redesign your organisation from scratch today, what would you do differently?

The organisations that lead the next decade will not necessarily own the most advanced technology. They will be the organisations with the courage to redesign themselves before change forces them to.

Insights · 39/40 08 May 2026

Why Most Organisations Know What to Do — But Still Fail to Execute

Everyone who has organised a large event will tell you the idea is the easy part. Turning “Penang should have its own digitalisation conference” into two days at Setia SPICE Convention Centre with government, MNCs and industry leaders in the same room meant running straight into the same execution failures I now see inside almost every organisation I work with.

Three Failures That Almost Sank PDX

1. Everyone agreed on the goal, nobody agreed on the trigger

Early on, three teams all believed “get sponsors confirmed” was someone else’s next move. Nobody was wrong about the goal. Nobody had been told exactly what event should trigger their part of the work. The fix wasn’t a pep talk about ownership — it was a one-page document naming, for every workstream, the single event that started it.

2. Knowledge lived in one person’s head

For the first PDX, sponsor relationships existed mostly in my own memory and inbox. The moment I was unreachable for two days, decisions stalled, not because the team lacked judgement, but because they lacked the context I hadn’t written down anywhere. We now document context, not just tasks — the “why” behind a relationship or a commitment, not just the “what.”

3. Feedback arrived too late to matter

In year one, we found out what delegates actually wanted from post-event surveys — useful for next year, useless for the event already over. Now we build in short feedback checkpoints during planning, not just after the event, so a bad assumption gets caught in week three instead of month eleven.

The Pattern Behind All Three

None of these were knowledge problems. Every team involved knew, in the abstract, what needed to happen. What was missing was the specific trigger, the written-down context, and the fast feedback loop that turns knowing into doing. That gap — not a lack of smart people or good intentions — is what I’d call the real execution gap.

FAQ

Isn’t this just a project management problem?

Partly — but project management tools don’t fix it if the underlying triggers and context were never defined. The tool organises the gap; it doesn’t close it.

What's the fastest way to check if my team has this problem?

Ask three people on the same project to describe, unprompted, what specifically triggers their next task. If you get three different answers, you've found the gap.

Insights · 40/40 03 May 2026

The Real Risk of AI Is Not Technology — It’s Organisations Moving Too Slowly

Scammers adopted AI voice cloning and deepfake video call scams faster than most Malaysian banks updated their customer fraud warnings. I’ve tracked this gap closely while researching Scam-Proof, and it isn’t a story about criminals having better technology. It’s a story about who moves fast and who moves slow — and that exact gap shows up inside ordinary companies too, just with less dramatic headlines.

Fast Side, Slow Side

A scam network can test a new script, drop the ones that don’t convert, and scale the ones that do, all within days. A bank updating a customer warning message often needs sign-off from legal, compliance, and brand — a process measured in months. Neither side lacks intelligence. One side has removed the friction between noticing something and acting on it. The other hasn’t.

I see the identical pattern inside companies evaluating AI tools. A competitor tests, fails fast, adjusts, and ships. The slower organisation is still circulating the seventh draft of a risk-assessment memo for a pilot with no customer data in it yet. The technology gap between them is usually small. The decision-speed gap is enormous, and it compounds every quarter.

What Speed Actually Costs You If You Skip It

To be clear, this isn’t an argument for recklessness — a bank should absolutely check its fraud messaging carefully. It’s an argument for shrinking the distance between “we noticed a problem” and “we did something proportionate about it” from months to weeks. Every extra month of deliberation is a month a faster-moving competitor, or a faster-moving scammer, gets to operate unopposed in the same window.

Three Questions That Reveal Your Real Speed

  • How long ago did your organisation last change a customer-facing process because of something you noticed last month, not last year?
  • Can anyone below senior leadership approve a small, reversible experiment without three layers of sign-off?
  • When something goes visibly wrong, does the fix ship in days, or does it wait for the next quarterly planning cycle?

If those answers are uncomfortable, the risk you’re carrying was never really about AI. It was about how long your organisation takes to notice and move — and in both fraud prevention and digital transformation, that number is the only one that actually predicts who gets hurt.

Permalink to this article You have reached the end · scroll up to revisit