AI you can trust, and the keys to prove it

· 6 min read
AI-generated image: AI you can trust, and the keys to prove it
AI-generated image

Every announcement worth reading today circles the same question: how much of your work should an AI system touch, and on whose terms. The answers coming from the largest vendors are less about raw capability and more about control — where your data sits, which model you come to depend on, and who can prove they are who they claim to be.

That is a useful lens for anyone choosing tools this quarter. A feature demo tells you what a product can do on a good day. The questions below tell you what you are committing to on every other day: the switching cost, the blast radius of a mistake, and the parts of the job software still cannot do for you.

The risk of building on a single model

When a business wires a process around one proprietary AI model, it is making a quiet bet that the model, its price, and its terms will stay roughly where they are. That bet is cheap to place and expensive to unwind. The more of your workflow that assumes a particular model's behaviour — its tone, its speed, the shape of its output — the harder it becomes to move when the terms change underneath you.

Satya Nadella used strong language on this point [1]. You do not need to agree with every word of the warning to take the underlying caution seriously. The practical response is not to avoid AI; it is to treat the model as a component you can replace rather than a foundation you have poured concrete into. Keep your prompts, your data, and your business logic in places you own, so that the model at the other end is a plug you can pull. When you evaluate a tool, ask what happens to your work if the vendor changes the model behind it — and whether you would even be told.

This is the same discipline we have written about in what AI should and should not do in your business: keep the judgement, the record, and the exit in your hands, and let the model do the narrow task in front of it.

Grounding an assistant in what your company actually knows

A general-purpose AI model knows a great deal about the world and nothing about your business. It has never seen your contracts, your onboarding notes, or the reason a particular customer churned in March. That gap is why so much AI output reads as fluent and generic at the same time. The fix has a name — grounding — and it means pointing the model at your own material so its answers are anchored in your reality rather than the average of the internet.

Dropbox announced integrations that bring company content into ChatGPT workflows for exactly this reason [2]. The idea is sound: an assistant is only as useful as the material it can draw on, and drawing on your own documents beats drawing on none. The trade-off to think through is scope. Pointing a model at a curated set of current, correct material gives you sharper answers. Pointing it at every file a company has ever saved — including the drafts, the superseded contracts, and the note that was wrong even when it was written — gives you fluent answers built on stale ground. The value is in the curation, not the connection, and the connection is the part that is easy to buy.

So before you plug an assistant into your document store, do the unglamorous work first. Decide which material is current, who owns it, and how it gets retired when it stops being true. We have made that case in keeping customer data current: a model reading your records will repeat your mistakes faster than any person would, so the records have to be worth reading.

A second factor you can hold in your hand

Security announcements rarely make headlines, but this one matters for any business that runs Windows machines. Google's Credential Provider for Windows now supports FIDO2-compliant physical security keys as a second factor at sign-in [3]. In plain terms, that means a member of staff can be asked to tap a small hardware key — something they physically possess — before their machine will let them in.

The reason this is worth the effort is that not all second factors are equal. A code sent by text or read from an app can be phished: an attacker who has fooled someone into handing over their password can often fool them into handing over the code moments later. A hardware key resists that class of attack because it will only respond to the real sign-in page, not a convincing copy of it. For a small team, the cost is a handful of keys and an afternoon of setup; the benefit is that the most common route into a company — a stolen or guessed password — stops being enough on its own.

The broader principle is one we keep returning to in one login and why it matters: the point where a person proves who they are is the point an attacker attacks, so it is the point worth spending on. A phishing-resistant factor is one of the few security upgrades where the payoff is easy to reason about.

Point automation where your people cannot reach

There is a natural instinct to aim your newest, cleverest tool at your best opportunities. SaaStr made the opposite argument today, and it is the more interesting one: put AI on the leads your representatives will never get to, not the hot ones they are already working [4]. The reasoning is a matter of where the marginal value sits. A human is already calling the hot lead, and calling it well. The cold lead, the one that went quiet six months ago, the one nobody has the hours to chase — that is work not being done at all, which means automation there adds something rather than duplicating it.

This is a good default test for any task you are thinking of automating. Automation is most valuable where the alternative is nothing, and least valuable where it competes with a person doing the job properly. Aimed at the long tail, an AI system recovers revenue that would otherwise have been left on the floor. Aimed at the deals already in good hands, it mostly adds noise to a process that was working.

It also fits what we have written about in how to tell whether a task should be automated: the question is not whether a machine can do the task, but whether a person is doing it today and doing it well. The leads that go quiet are the clearest case, and we described how they get there in the anatomy of a lead that goes cold.

What software still cannot do for you

Amid a day of AI announcements, one of the sharpest pieces was about turning up in person. SaaStr recounted losing a Fortune 50 customer at renewal despite a flawless implementation and users who liked the product [5]. The satisfaction scores were high. The renewal was lost anyway, and the lesson drawn was that showing up in person would have changed the outcome.

The point is not that travel beats technology. It is that some parts of a business relationship do not compress into a dashboard, a summary, or an automated touch. A model can tell you a customer is healthy on every measurable axis and still miss the thing a face-to-face conversation would have surfaced in ten minutes. As you decide which tasks to hand to software this year, it is worth keeping an honest map of which ones you should not — the conversations, the judgement calls, and the moments where a person in the room is the whole product. The tools announced today are useful precisely because they free up the hours for that.

The thread running through all of it is ownership. Depend on a model you can replace, feed it material you have curated, guard the door with a factor that cannot be phished, and point automation at the work nobody is doing rather than the work being done well. None of that is about buying the cleverest tool. It is about staying in control of the ones you have already bought.

Sources

  1. [1] Satya Nadella has issued a shocking warning to companies using AI — TechCrunch
  2. [2] The context layer for AI: Bringing trusted Dropbox content into OpenAI workflows — Dropbox
  3. [3] Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant physical security keys as a second factor for authentication — Google Workspace Updates
  4. [4] Don't Put AI on Your Hot Leads. Put It on the Ones Your Reps Will Never Call. There's Millions in Revenue There. — SaaStr
  5. [5] Should You Visit More Of Your Prospects In Person? Almost Certainly — SaaStr

The 360REV newsletter

What is actually changing across productivity software, written for operators and cited to sources. No more than one email a day.

Double opt-in — we send one confirmation link and nothing else until you click it. Unsubscribe from any edition. We never sell or share your address.