Bring Your Own AI
People do not adopt what watches them. They adopt what works for them.
The enterprise AI mistake
Do not install a company brain inside every employee’s phone.
01 / The room
What I keep seeing
At Charleston AI, the people who walk through the door appear to need completely different things.
One owns a roofing company. One teaches piano. One is managing a household. One is a student. One has thirty employees. One has no employees and does not want any.
But the work underneath the work is almost always the same.
First, establish a direct relationship with a frontier model. Then use that relationship to build a personal operating system: your database, your files, your methods, your automations, your permissions, your history. You are not merely a user inside it. You are the super administrator.
Once a person feels that authority, ordinary software begins to feel strangely constraining.
You want to say, “I heard search engines introduced a new metadata convention. Research it. Decide whether it applies to my website. If it does, implement it and verify the result.”
That is a super-administrator sentence. It describes an outcome. It assumes your intelligence can inspect the system, change the system and prove what happened.
Inside a conventional app, the sentence collapses into menus, plan tiers, plugins, help articles and someone else’s permission model. The provider may not expose the necessary access. An add-on may approximate the result. Your AI may explain every step and still be unable to perform any of them.
Once you learn to speak in outcomes, menus feel like bureaucracy.
This difference becomes more consequential at work, because the problem is no longer merely friction. It is trust.
02 / The pitch
A beautiful demo
A small-business owner recently described a familiar AI proposal. His company has roughly thirty employees. Several are estimators who spend their days talking directly with homeowners.
Those conversations contain nearly everything the business needs to know: the condition of the property, what the homeowner noticed, what was promised, what the estimator observed, what materials may be required, the timing, the budget and the subtle facts that determine whether a proposal is accurate.
A software vendor offered an elegant answer. Put an app on every estimator’s phone. Record the conversations. Use AI to produce notes, train the team, capture details and generate proposals. Feed the useful information into the company.
On a slide, this is perfect.
In practice, the owner could not get people to use it.
I understood immediately. Imagine being one of the estimators. A system chosen by your employer is listening to your entire conversation with a homeowner. You do not know exactly where the recording goes, who can retrieve it, how long it will remain there, whether it will be used to score you, or which awkward sentence will become a training example.
You are told the system is there to help. Architecturally, it feels like it is there to watch.
So the app develops mysterious technical problems. The battery dies. The microphone fails. The estimator forgets to press the button. The important meeting happens in the one room where the device was left outside.
This is not irrational resistance to innovation. It is a rational response to an illegible boundary.
The hidden design variable
If a system requires people to lie about why they did not use it, the failure began in the architecture—not in the training program.
Companies often model the employee as one of many identical endpoints: install the app, collect the data, centralize the intelligence. But the person holding the phone does not experience himself as an endpoint. He experiences himself as a human being in a conversation with another human being.
That difference is the whole problem.
Architecture comparison / choose a control plane
Where does the raw context live?
Select an architecture. The business outcome can be identical. The human experience is not.
Result: the company may collect more, but people contribute less. The surveillance feeling contaminates the useful workflow.
Result: the company gets better structured work. The individual keeps a durable capability and understands exactly what crossed the boundary.
03 / The inversion
What would work
Now invert the architecture.
Give each estimator the capability as part of employment, but make the personal AI environment legibly theirs. The company does not silently own the raw memory. A software vendor does not silently absorb it. The employee can see what is captured, where it lives, what is retained and what is shared.
The estimator may use the same voice workflow for a homeowner visit, an HOA meeting, a class, a personal project or a list of errands. It becomes part of how that person thinks and works—not a company compliance ritual that exists only from nine to five.
After six homeowner calls, the estimator can say:
A person-first instruction
Use today’s six conversations to draft the proposals. Preserve the details that affect scope and price. Put the drafts in front of me. After I approve them, create the corresponding opportunities in the CRM.
The raw conversations do not need to become the company’s ambient memory in order for the company to receive excellent work. The personal AI can transform context into a bounded artifact: a proposal, a summary, a task, a CRM record. The human reviews the artifact. Only then does it cross the gate.
This is not an argument that work conversations are magically exempt from company policy, customer privacy, retention obligations or applicable recording-consent laws. Private does not mean lawless. A responsible design states what must be retained, what belongs in the company’s records, what cannot be captured and what requires consent.
The principle is narrower and stronger: do not collect an entire human context merely because the company needs one work product from it.
The company needs the approved proposal. It needs an accurate customer record. It may need a defined audit trail. It does not automatically need every raw word that passed through the employee’s day.
Send the work product. Do not annex the person.
04 / BYOAI
Not shadow IT
Bring Your Own AI is already happening. The unresolved question is whether companies will treat it as an enemy, ignore it, or design for it.
Microsoft and LinkedIn’s 2024 Work Trend Index surveyed 31,000 full-time employed or self-employed knowledge workers across 31 markets between February 15 and March 28, 2024. Among respondents who used AI at work, 78 percent said they were bringing their own AI tools; the figure was 80 percent at small and midsize companies.
That finding is descriptive, not a causal proof of why workers choose their own tools. But it makes the direction visible. People are establishing direct working relationships with models faster than most organizations can standardize them.
The dangerous version is uncontrolled shadow AI: employees paste confidential material into consumer tools, grant broad access, create invisible data copies and leave the company unable to govern its own information.
The useful version is not a free-for-all. It is person-first, policy-aware interoperability.
The person brings a preferred intelligence layer and accumulated methods. The company publishes explicit interfaces, scopes and rules. The personal agent can act inside those limits. The company still owns and governs its systems of record. The individual does not receive authority merely because an AI asked for it.
The difference between shadow AI and Bring Your Own AI is the quality of the boundary.
A cleaner contract
The employee keeps the instrument. The company keeps the ledger. Every transfer between them is visible, limited and attributable.
This is also why connector standards matter. The Model Context Protocol authorization specification describes how an AI client can request access to a restricted server on behalf of a human user, using established authorization patterns. Its enterprise-managed authorization extension describes centralized organizational policies for which MCP servers employees may access and under what conditions.
Those specifications do not solve culture, privacy or product design. They do reveal the emerging shape of the architecture: a personal client, an enterprise resource, an explicit authorization flow and a bounded token for a specific target.
That is far healthier than pretending the only choices are a single company bot or chaos.
05 / The product
Build the boundary
The next generation of enterprise AI will be won at the boundary between private context and institutional action.
Most vendors are concentrating on the intelligence in the middle: the model, the summarizer, the proposal generator, the dashboard. But frontier models will improve, change and become replaceable. The durable product is the trust architecture around them.
Private plane
The person’s context
History, working style, rough notes, unfinished thinking and reusable methods remain under the person’s control.
Consent plane
The review gate
Capture is disclosed. Sensitive material is handled intentionally. The person sees what will cross before it crosses.
Action plane
Scoped company access
Short-lived, least-privilege credentials allow specific actions against approved enterprise tools.
Record plane
The company ledger
Approved proposals, customer commitments, decisions and required records land in governed company systems.
NIST’s AI Risk Management Framework describes trustworthy AI in terms that include accountability, transparency and privacy enhancement. Its core calls for transparent policies, documented roles and examination of privacy risk. The NIST Privacy Framework likewise treats privacy risk as something organizations can manage while building useful products.
A person-first architecture is not a substitute for that governance. It makes the governance legible to the person expected to use the system.
That legibility changes behavior. When I know the raw transcript is mine to review, I am more willing to capture it. When I know exactly which fields will enter the CRM, I am more likely to approve them. When I can revoke a connector without losing my entire working memory, I am more willing to connect it in the first place.
Control is not the opposite of adoption.
Control is what makes adoption possible.
06 / The build
Six rules for owners
If I were advising that roofing company now, I would not begin by shopping for a better recorder. I would begin by writing the boundary.
- Give each person a private workspace.The employee should understand the account, storage, retention and export model without needing a lawyer or administrator to interpret it.
- Make capture conspicuous and consensual.Recording rules differ by jurisdiction and context. Build the required notice, consent, pause and deletion controls into the workflow instead of burying them in policy.
- Separate raw context from work product.A transcript is not a proposal. A private note is not a CRM record. Transform first; transfer only what the business purpose requires.
- Put a human review gate before action.Let the employee inspect the proposal, recipient, price, scope and destination before an external message is sent or a company record is created.
- Use scoped, revocable connectors.The personal AI should receive only the authority necessary for the action, for only as long as necessary, with an audit trail the company can understand.
- Design the exit on day one.When employment ends, company credentials disappear and company records remain. The person keeps the general capability, personal methods and lawful personal data without keeping unauthorized company information.
Notice what the company is actually giving the employee. It is not merely an app license. It is a durable way of working.
The estimator may eventually leave roofing. The voice workflow remains useful. The ability to turn conversations into structured drafts remains useful. The habit of reviewing an AI-produced artifact before it enters a system of record remains useful.
The company loses access when the relationship ends. The person does not lose the intelligence he learned how to use.
That is not a weakness in the employment relationship. It is a better bargain.
07 / The company
One of one, together
The first article in this sequence argued that young people should build their personal stack now, while they are young.
This is the enterprise consequence.
A company should not force thirty personal stacks to disappear into one corporate stack. It should become exceptionally good at working with thirty sovereign intelligence environments.
That does not mean the company gives up control. It means it becomes precise about what it controls.
It controls the customer ledger. It controls pricing rules. It controls authorized products, warranties, commitments and payments. It controls who may write to the CRM. It controls the definition of a completed job. It controls the interfaces through which outside intelligence may act.
What it does not need to control is every intermediate thought required to produce good work.
The future company is not one giant AI with employees attached.
It is a coordinated network of people who each have a direct relationship with intelligence and a trustworthy way to contribute.
The winning companies will make that contribution easy. They will publish excellent interfaces. They will explain their boundaries. They will reward employees who arrive with capable personal systems. They will connect those systems to the enterprise system of action and the enterprise system of record without pretending that connection requires annexation.
Bring your own AI.
Bring your own accumulated context, your methods, your judgment and your preferred way of working.
Then cross the company boundary deliberately.
Share the proposal.
Create the CRM record.
Commit the work.
Keep the person.
Evidence / checked 09.16.26
Sources
- Microsoft and LinkedIn, 2024 Work Trend Index, including the survey population, period and BYOAI measures.
- Model Context Protocol authorization specification, including human-delegated access to restricted MCP servers.
- Model Context Protocol enterprise-managed authorization, including centralized organizational access policy.
- NIST AI Risk Management Framework and the NIST Privacy Framework, for transparency, accountability and privacy-risk governance.