Why I Believe the Future of Enterprise AI Is Not About Renting Artificial Employees, but About Owning, Defending and Governing the Intelligence That Runs Your Business.
Synopsis
October 2026. The artificial intelligence industry is moving at extraordinary speed. Everywhere I look, companies are promoting AI employees, AI workforces, autonomous agents and subscription-based digital workers. The proposition sounds attractive: instead of hiring more people, businesses can subscribe to artificial intelligence that performs tasks, manages workflows, communicates with customers and operates around the clock.
Yet after more than two decades of building websites, software systems, databases and business applications, I see something that concerns me deeply. The greatest risk may not be what these AI employees can do for a company, but what the companies providing them could potentially learn about their customers.
I believe the subscription-based AI workforce industry, particularly services that require extensive access to an organisation's internal knowledge and operations, may face a serious crisis of trust. The more intelligent these systems become, the more difficult it will be for customers to understand what happens behind the interface.
My concern is not simply cybersecurity. It is something potentially more consequential: the ownership, extraction and reproduction of organisational intelligence.
Two Decades of Building Systems Have Taught Me to See What Others Overlook
I began building business software long before artificial intelligence became a fashionable commercial product. Since the early days of my career, I have worked across websites, databases, business applications, software implementation and digital infrastructure. To outsiders, these may appear to be ordinary technology services. To me, however, building a system has never been merely about delivering functionality.
A system must perform its intended purpose, but it must also be designed to withstand misuse, identify unusual activities, record operational behaviour and preserve evidence when something goes wrong. Whenever I build something, I naturally think from two directions: how it should work and how it could fail or be exploited. I want to know who accesses information, what actions they perform, where errors occur, what data moves between systems and whether anyone is attempting something outside the intended boundaries.
This habit has become part of my professional instinct. I do not see logging, monitoring and reporting as secondary technical features. They are fundamental instruments for protecting an organisation and continuously improving its technology. The information collected from legitimate operational monitoring can reveal weaknesses, expose inefficiencies and help developers improve systems over time.
An Experience From 2007 Changed How I Think About Information Protection
In 2007, I developed a business system that would eventually teach me an important lesson about the relationship between technology, employees and organisational trust. Several years after its implementation, an employee left the organisation and copied customer data from the system. That incident triggered something in my thinking that has remained with me ever since.
I realised that protecting software was not enough. The real asset was often the information contained within it, and the people authorised to use a system could sometimes represent a greater risk than outsiders attempting to break into it.
From that experience, I became increasingly sensitive to access controls, audit trails, operational logs and the ability to detect unusual behaviour. My philosophy was straightforward: if I build a system for people to use, I must also understand how it is being used. Not because every user should be treated as suspicious, but because responsible technology ownership requires visibility and accountability.
That lesson was learned in the conventional software era. Today, artificial intelligence has made the same problem considerably more complicated.
Artificial Intelligence Is Not Just Another Software Application
Traditional software generally operates according to defined logic, programmed functions and structured data flows. Although conventional systems can be extremely complicated, developers can usually investigate their architecture, inspect their code, examine database transactions and trace how particular operations occur.
Artificial intelligence introduces another dimension. Modern AI agents may combine language models, external tools, memory systems, APIs, retrieval mechanisms, autonomous workflows and third-party integrations. Some operate through open-source frameworks and increasingly complex orchestration environments. Each additional component creates new functionality, but also expands the potential attack surface.
Over recent months, I have been deeply involved in experimenting with agentic AI, automation workflows, self-hosted infrastructure and open-source agent frameworks. The deeper I explore these technologies, the more I appreciate their extraordinary potential. At the same time, I have become more concerned about how easily poorly configured systems can expose information or permit unintended actions.
An AI agent may appear to be performing a simple task, while behind the interface it could be accessing multiple databases, reading documents, calling external services or transmitting information between systems. Without appropriate observability and controls, even the organisation deploying the agent may struggle to reconstruct everything it has done.
The Invisible Back Door Is Only the Beginning
Consider a company subscribing to an external AI workforce service. The provider installs or configures an AI employee that handles customer enquiries, prepares proposals, reviews documents and assists with internal operations. The customer sees a convenient interface and measurable productivity improvements. What the customer may not see is the complete technical architecture supporting those operations.
Who controls the agent's instructions? Which external tools can it invoke? Where are its operational logs stored? Can the provider remotely change its behaviour? Are conversations retained? What happens when a third-party integration is compromised? Can the customer independently verify what information leaves the organisation?
These are not accusations against every AI workforce provider. Many vendors implement serious security controls, contractual protections and technical safeguards. Nevertheless, the risk exists because the architecture can create opportunities for unauthorised access, insecure integrations, malicious instructions or hidden data transfers.
A sophisticated back door does not necessarily announce itself through an obvious system failure. It may remain invisible during ordinary operations. More importantly, even a technically legitimate feature can become a security weakness if its permissions exceed what the business actually requires.
The question is therefore not whether every external AI workforce contains a back door. The question is whether the business owner has sufficient evidence to establish that its most sensitive operations remain under its control.
Data Leakage Is Dangerous, but Intelligence Leakage Could Be Worse
Most business owners understand the consequences of customer data being stolen. They worry about personal information, financial records, intellectual property and confidential documents. These are legitimate concerns, and existing cybersecurity practices are designed to reduce such risks.
However, artificial intelligence introduces a less obvious category of exposure. An AI workforce may interact with employees every day, observe recurring decisions, process internal discussions, interpret customer requirements and participate in operational planning. Over time, these interactions can reveal how an organisation thinks and behaves.
Imagine an AI assistant that helps a chief executive prepare proposals, evaluate opportunities and negotiate contracts. Through repeated interactions, it may encounter the executive's pricing philosophy, commercial judgement, risk appetite, preferred negotiation tactics and strategic priorities.
Whether that information is retained, analysed or used for further model development depends on the provider's architecture, contractual commitments and technical controls. It is not inevitable that every AI service learns from customer conversations. But where such processing is permitted or insufficiently restricted, the consequences could extend beyond conventional data leakage.
A company may lose not only confidential information, but valuable insight into the decision-making patterns that distinguish it from competitors.
What Happens When One AI Provider Serves One Hundred Competitors?
Let us imagine that I establish an AI workforce company specialising in the medical industry. I provide intelligent operational assistants to one hundred medical businesses. Each customer uses my service for scheduling, administration, procurement, customer communication, operational reporting and management support.
Individually, each organisation may see substantial productivity improvements. Collectively, however, the service provider could occupy a remarkably powerful position within that industry's information ecosystem.
If the architecture allows customer interactions to be retained and analysed across accounts, the provider could potentially identify common operational weaknesses, purchasing patterns, customer behaviours, commercial strategies and management practices. With sufficient access, the provider might develop a sophisticated understanding of how an entire sector operates.
Now consider the more troubling possibility. What if those insights were used to develop a competing business, inform another customer or construct specialised AI systems that reproduce the operational expertise of existing organisations?
This would not require the crude act of downloading a customer database. It could involve extracting patterns, processes, decisions and business knowledge from accumulated interactions. Reproducing a company's expertise accurately would still be technically difficult, and contractual or legal restrictions may prohibit such use. Nevertheless, the strategic possibility deserves serious examination.
The real competitive advantage of many companies is not their software. It is the knowledge embedded in how their people make decisions. If that knowledge becomes accessible to an external intelligence provider, the boundary between technology supplier and potential competitor becomes increasingly important.
The Subscription Model May Be Selling Convenience at the Expense of Control
I understand why AI workforce subscriptions are attractive. Businesses want immediate results. They do not necessarily have internal developers, AI engineers or the financial resources to establish their own infrastructure. A ready-made AI employee appears to solve these problems quickly and affordably.
But convenience should not be confused with ownership.
When a company subscribes to an external AI workforce, it must examine what it actually controls. Does it own the agent's configuration, workflows, memory, knowledge base and operational records? Can it inspect the system's permissions? Can it migrate to another provider without losing accumulated organisational knowledge? Can it terminate the relationship and verify that its confidential information has been deleted according to agreed retention policies?
I foresee that generic AI workforce subscriptions will face increasing pressure as AI development becomes more accessible and businesses become more conscious of data sovereignty. Providers selling only convenient access to standard AI capabilities may struggle to sustain differentiation.
This does not mean all AI subscriptions will disappear. Specialised providers with strong security, transparent governance and genuine domain expertise may continue to thrive. However, I believe the market will increasingly distinguish between renting artificial intelligence and surrendering control over business intelligence.
Those are two very different commercial decisions.
The Future Should Be Internally Governed AI, Not Blindly Trusted AI
My preferred direction is for businesses to develop the capability to own and govern their critical AI workflows internally. This does not necessarily mean every company must train its own language model or build every component from scratch. That would be economically unrealistic for many small and medium enterprises.
Instead, organisations should understand their AI architecture, retain ownership of their business knowledge, control access permissions and establish clear boundaries around external services. They should know what information an AI agent can access, what actions it can execute, where data is processed and how every significant operation can be audited.
External technology can still play an important role. Open-source frameworks, commercial models, cloud infrastructure and specialised vendors can all be incorporated into a properly governed architecture. The essential principle is that the organisation must remain capable of controlling, inspecting and replacing critical components.
For SMEs, this may begin with something as practical as assigning an internal employee to understand AI workflows, maintaining an inventory of connected systems, restricting sensitive data access and implementing approval requirements for high-risk actions.
AI governance cannot guarantee absolute security, and no single regulator can eliminate every technical risk. But effective governance, supported by technical verification, contractual accountability and continuous monitoring, can significantly reduce exposure.
Businesses should not become dependent on intelligence they cannot inspect, control or safely disconnect.
The Most Valuable Technology Professionals Will Know How to Build and Defend
Throughout my career, I have never been satisfied with understanding only how technology works when everything goes according to plan. I am equally interested in understanding what happens when something goes wrong, when someone attempts to misuse a system or when a seemingly harmless feature creates an unexpected vulnerability.
I believe this combination of offensive and defensive thinking will become increasingly valuable in the AI era. Organisations need builders who understand architecture, implementation and business operations. They also need people who can challenge assumptions, investigate hidden dependencies, recognise unusual patterns and question the intentions or consequences behind technical decisions.
These capabilities resemble elements of cybersecurity investigation, technical due diligence, adversarial testing, AI governance and strategic intelligence. They require more than knowing how to write software or operate an AI tool. They require curiosity, scepticism, technical experience and the willingness to investigate what others may overlook.
I have spent more than two decades developing that mindset through real systems, real customers, operational incidents and continuous experimentation. I remain a builder by nature, but I have learned that responsible building requires an equally strong instinct for defence.
In the AI era, creating something powerful is only half the responsibility. Understanding how that power could be misused is the other half.
Perhaps Every Organisation Needs Someone Who Thinks Like a Spy
Sometimes, I wonder whether the future of technology will require a different kind of professional. Not necessarily another software engineer, cybersecurity specialist or AI consultant, but someone who approaches technology with the curiosity of an investigator, the imagination of a strategist and the instincts of a builder.
Imagine a character in a corporate thriller. He walks into a room where everyone is celebrating the successful deployment of an intelligent system. The executives are impressed by its efficiency, the developers are proud of its architecture, and the employees are delighted that their workload has become lighter. Yet while everyone is admiring what the system can do, one person quietly asks a different question: What else could this system be doing that nobody has thought to examine?
Perhaps that is the kind of character I find fascinating. Someone who understands how systems are constructed because he has spent years building them. Someone who recognises weaknesses because he has experienced failures. Someone who can think like an attacker without becoming one, and defend like an engineer without assuming that every system is secure.
In the movies, such characters often work in intelligence agencies, investigating threats that remain invisible to ordinary observers. In the real world, the challenges may be less dramatic, but the underlying mindset is remarkably similar. The ability to notice unusual patterns, question convenient assumptions and imagine what might happen behind a perfectly functioning interface could become increasingly important as artificial intelligence grows more autonomous.
I sometimes think that if I had chosen a different career, I might have enjoyed being a technology detective. Fortunately, building software and businesses for more than two decades has provided enough mysteries of its own.
And perhaps, somewhere in the corporate world, there are challenges that need precisely this unusual combination of curiosity, technical experience and imagination.
After all, the most dangerous weakness in a system may not be the one that everyone can see. It may be the one nobody has thought to look for.
Dream It. Execute It. Ground It.
Build with imagination. Defend with intelligence.
Ts. Lukas J. Tan
Founder & CEO, OPERION Ecommerce & Software Sdn Bhd
Technology Builder | Digital Transformation | AI Systems & Governance