The long window

An AI-native operating model — a person directing a fleet of agents that design, ship and run the system — is a once-in-a-lifetime, compounding advantage, and adoption lags what the technology deserves, which is exactly why the early-mover window is real. The instinct that stops legacy organisations from taking it is ambiguity aversion: under a short knowability horizon we draw inward and avoid rather than evaluate. This memo reframes the migration as a tractable risk-management problem — identify the events, rate the inherent risk, install the control, read the residual — and is surgical about scope: only four risks actually change when agents do the work. The operating model is guardrails, not gates, applied at four chokepoints; and a closing chapter draws the clean line for regulated industries, where the rule is that regulation attaches to a data type and an activity, not to a brand.

Published · Updated · By Dan Walter

Executive summary

An AI-native way of working — one person directing a fleet of agents that design, write, ship and run the system — is a once-in-a-lifetime, compounding advantage: cycle time in weeks not years, cost decoupled from headcount, a profit-per-person the old cost base can't match. It comes from redesigning the work around AI, not bolting a chatbot on, and because adoption always lags what the technology deserves, the early-mover window is real and long — but it belongs to whoever moves first. The instinct that stops a legacy organisation from taking it isn't reason, it's a named bias: ambiguity aversion, which makes us avoid the unknown rather than evaluate it, and quietly wave through the far larger risk of falling behind.

This memo treats the migration as what it is — a tractable risk-management problem. Identify the risk events, set an appetite, install the controls, read the residual; where appetite is a function of reversibility, so control design is the work of converting one-way doors into two-way ones. It is deliberately surgical: of all of engineering risk, only four things actually change when agents do the work, and those are the only ones the register carries. The target operating model is guardrails, not gates — reversible infrastructure at the base, automated guardrails in the middle, human escalation only at the tip — applied at four chokepoints that every agent action funnels through. A closing chapter draws the clean line for regulated industries (pharmacy and insurance), where the governing rule is that regulation attaches to a data type × an activity, not to a brand — so most of the work runs in the general environment and only a small, walled core needs the compliance-grade treatment. The one-line version: the migration is not a leap of faith; the only unmanaged risk on the page is refusing to start.

The opportunity — and the block

We are living through a once-in-a-lifetime change in how work gets done, and the operators who understand it early will pull away from everyone else. Just as digital natives disrupted bricks-and-mortar, AI-native operators now disrupt the digital natives — and the advantage is structural, not cosmetic: cycle time measured in weeks instead of years, cost decoupled from headcount instead of scaling with it, a profit-per-person that makes the old cost base uncompetitive. It does not come from bolting a chatbot onto the existing operating model. It comes from redesigning the work around AI — a person directing a fleet of agents that design, write, ship, and run the system.

And the frontier is moving on a monthly clock. What was true a week ago is not true in two months; each capability becomes the building block for the next, and the whole thing compounds — the technology is even improving its own inputs. That is what makes this a window rather than a milestone: the operator set up to absorb each month's improvement compounds ahead; the one still routing every change through manual hands falls further behind. The upside is running the core loops of the business at a fraction of the time and cost; the downside is quiet and terminal — adoption always lags what the technology deserves, which is exactly why the early-mover window is real and long, and exactly why someone in every market will take it. Why now is the whole point: the window is open, and it does not stay open for the second-fastest mover. The ambition is to move onto that path fast, at full AI leverage — and everything that follows is about how to do it without betting the business.

Why it feels dangerous — and the block to name. Moving fast into this feels dangerous, and the feeling points at something real: genuine unknown-unknowns and a short knowability horizon. But there is a well-documented bias for exactly this situation, and naming it is half the cure. It is ambiguity aversion: faced with a known risk and an unknown one, people reliably choose the known — even when the unknown is the better bet — because it can be measured. Two cousins sharpen it: omission bias (harm from acting feels worse than greater harm from not acting, so inaction gets a free pass) and zero-risk bias (we over-invest in eliminating one vivid risk while ignoring a larger, diffuse one). Together they produce one failure: we fixate on the vivid risk of an agent doing something bad and wave through the diffuse, unpriced, far larger risk of falling behind. The discipline that beats it is the rest of this memo — turn "scary unknown" into "evaluated risk."

Risk management, in four moves

Stripped of mystique, risk management is a loop: identify the risk events; set an appetite for each (how much you'll tolerate); install the controls that appetite implies; and read the residual risk that remains. If residual sits above appetite, add controls and go again. Two definitions carry the whole memo. Inherent risk is the severity of an event before any control — the raw one-way door. Residual risk is the severity after the control has done its work. And the move that turns this checklist into a design principle: appetite is a function of reversibility. An irreversible action has no recovery control, so its appetite is zero — you prevent it. A reversible action carries a recovery control by definition, so its appetite is high — you let it run and undo it if it goes wrong. Control design therefore has a single shape: converting one-way doors into two-way doors.

The appetite line this memo works to is explicit: residual ≤ 2 runs autonomously; a residual 3 needs a named owner and active monitoring; nothing above 3 runs unsupervised.

The incremental register — only what changes when agents do the work

Most of engineering risk — destructive database writes, bad deploys, IAM slips, supply-chain — existed with human coders too, and a register that re-litigates all of it is noise. The only useful question is incremental: what changes, or is genuinely new, when you go from humans writing the code to agents doing most of it? Two kinds of thing qualify — risks whose character changes because autonomy removes the human backstop or speed amplifies the blast radius, and risks that simply did not exist before LLMs. Everything else stays governed by your existing controls, unchanged. That collapses the register to four, stack-ranked by severity.

Exhibit — Four risks change when agents do the work — each with a control and a named residual. The residual is named, not just numbered — that is what makes a '2' or a '3' mean something. Source: Compiled by Dan — incremental to human-authored development, 2026-07.

Where they come from: #1 is a new channel — code, secrets, or customer/regulated data reaching the model or provider, the risk we manage with the account and data-boundary decisions. #2 is a changed risk — the destructive write always existed, but autonomy removed the human who used to be in the way. #3 is genuinely new — an LLM can be steered by untrusted input in a way a compiler never could. #4 is amplified — a wrong pattern applied at machine speed across the whole surface before anyone eyeballs it. Notice the residuals are honest: #1 and #2 drop to a reversible 2, but #3 and #4 stay at 3 — you reduce them but can't eliminate them, which is exactly why those two keep a human in the loop. Everything not on this list — money-movement bugs (reversible), IAM misconfig (general security), infra deletes (deletion-protection handles it) — is unchanged by AI and stays with your existing controls. Supply-chain is the one to watch: agents pull more dependencies, so it drifts up, but it isn't new.

The operating model: guardrails, not gates

The instinct in a legacy organisation is to make the human the control — every change reviewed, every migration approved by hand. That is the opposite of what we're building: it re-introduces the bottleneck the whole migration exists to remove. The correct model puts automated controls at a few chokepoints and lets agents run freely everywhere else, with a human appearing only as a rare escalation. It stacks in three layers.

Exhibit — Guardrails, not gates: the agent runs free at the base, humans appear only at the tip. Almost every action lives in the base and runs unsupervised; human-in-the-loop is the rare exception at the top. Source: Reversibility / two-way doors (Bezos, 1997); SRE guardrails. Compiled by Dan.

Reversible infrastructure (the base — where almost everything lives) is the highest-leverage layer, because it removes controls entirely: make an action recoverable and its appetite goes up and the agent runs it unsupervised. Automated guardrails (the middle) are policy-as-code at the dangerous operation — the guard bites, the agent runs. Human-in-the-loop escalation (the tip) is reserved for the residual 3s and the genuinely novel. Two properties keep it safe: enforcement lives on the platform (branch protection, database grants, CI), never in the agent's own config; and the agent runs under its own least-privilege identity, scoped, revocable, holding no ambient production credentials.

The chokepoints — where the controls live

You don't police a thousand agent steps. An agentic pipeline has only a handful of gateways every action funnels through, and one automated control at each governs a whole class of risk. Put the guardrails here:

Exhibit — Four chokepoints every agent action passes through — control the gate, not the thousand steps. One automated control per gateway is cheaper and stronger than reviewing every step. Source: Compiled by Dan, 2026-07.

Regulated industries — where the clean line falls

The mistake is to think regulation attaches to a brand — "insurance is regulated," "pharmacy is regulated." It doesn't. Regulation attaches to a specific data type × a specific activity. So you decompose each business into its data flows and ask two questions: is there sensitive data (health or financial)? and are we performing a regulated act (dispensing, or giving advice)? The line falls exactly where the answer flips to yes — and the conclusion, up front, is reassuring: for both lines, most of the work is ordinary customer data in the general environment; only a small, well-defined core needs the walled, compliance-grade treatment.

A note on status: everything specific to Pet Circle in this chapter — the white-label structure, which data we do and don't hold, how the pharmacy is run — is an assumption formed from the outside, before starting, not a confirmed fact. It is set down precisely so it can be checked on day one with the team and the lawyer. The framework (data-type × activity) holds regardless; the specifics below are all to be verified.

Insurance — a white-label distribution position. Pet Circle is an Authorised Representative (AR 001300998); Pacific International underwrites and Knose administers. That means the regulated financial record — the policy, the pricing, the claims — never lands on our systems. What we hold is marketing and acquisition data: the same CRM we run for any product. The exhibit separates it cleanly (these are assumptions to verify, not confirmed facts):

Exhibit — White-label means we touch the marketing, not the regulated financial record. ~90% of insurance work is general-environment data; the regulated edge is narrow, and it's an activity, not a datastore. Source: Pet Circle insurance teardown; ASIC AR register. Assumptions, to verify.

So what does it mean in practice? Everything in the green column, we work as normal — general enterprise AI, ordinary repos and databases, standard privacy hygiene. Only two things need care, and neither is a big data-segregation job: (1) don't let an AI surface recommend a specific policy to a specific person — it can inform and route, but recommending crosses into personal financial advice the AR permission doesn't cover; (2) if we ever ingest real policy or claims PII, that specific dataset goes in the walled environment. The one thing to watch is flow-back: if regulated data ever joins the general CRM, it drags the general environment into scope — so the rule is that it never does.

Pharmacy — a real regulated core, and what "walled environment" actually means. Pharmacy is different because we perform the regulated act: dispensing prescription (S4) medicines through a registered pharmacy. That gives us data insurance never does — the prescription, the dispensing record, and by implication the pet's health tied to an identifiable owner, which is sensitive information under privacy law. That core must never enter a general AI context. Concretely, a walled environment is not a policy you promise to follow; it is: a separate enterprise/AI agreement (a BAA-equivalent for health data); a physically or logically separate environment — its own project, its own database, a zero-retention or self-hosted/VPC model so regulated data never sits in a shared context; access-controlled to authorised roles only, with the pharmacist in the loop on the actual dispense; fully audited (every access logged) with its own retention rules; and no flow-back into the general CRM. Everything upstream of that core — browsing, the catalogue, non-prescription products, general service — stays in the general environment. That segregation is the control that takes regulated-data risk from a 5 to a 2.

The principles

Exhibit — Five principles that let us move fast and sleep at night. Source: Connective Shift operating principles. Compiled by Dan.

The one-line version, for the room: the migration is not a leap of faith — it's a register of four named risks, each with a control that turns a one-way door into a two-way one, applied at four chokepoints. The only unmanaged risk on the page is refusing to start.