in early 2024 a finance employee at arup, the engineering firm behind the sydney opera house, joined a video call with the cfo and several familiar colleagues, took the instructions, and made fifteen transfers totalling about $25 million into five hong kong accounts. every other person on that call was generated, built from video and audio the company had already published.
months later a ferrari executive got a call in the ceo's voice, southern italian accent included, pushing an urgent confidential deal. the whole thing collapsed the moment he asked the title of the book the ceo had recommended him days earlier. that is the entire defense, and it cost nothing.
the advice going around is to train your team to spot deepfakes, which asks a person to win a perception contest against software that improves every quarter, on a bad monday, under pressure from someone who sounds like their boss. the smaller the company the worse the exposure, because there is nobody standing between a convincing request and the bank login. write one rule and put it where the money is: any payment, any change to bank details, any transfer outside the normal pattern gets confirmed by calling back a number already in your own records, never the number that called you and never a reply in the same thread. then tell whoever holds that login, in writing, that they are allowed to make you wait ten minutes.
roughly three quarters of employees now paste company material into ai tools, and about the same share of workplace chatgpt accounts are personal logins with no admin, no retention setting, and no record you can produce.
what goes in is not exotic: pricing, a client list, an unsigned contract, a spreadsheet with names in it, pasted by the people who move fastest because nobody gave them a sanctioned way to move that fast. the bill arrives later and in someone else's words. a client asking where their data sits. a renewal stalled on a vendor questionnaire. an insurer comparing what your policy claims against logs you cannot pull.
the advice going around is to write an ai policy and block the tools, which does not stop the paste. it moves it to a personal phone where you have no visibility at all. do the version that holds: put every employee on a managed company account for one or two approved tools with training and retention switched off, and write a single page naming what may be pasted and what may not, in examples rather than categories. that is an afternoon of admin, and it closes the largest hole you currently have.
the count is the tell. most companies now carry somewhere between eight and twenty ai or software lines and cannot say which one owns which job. 78 percent of it leaders were hit with an unexpected ai or consumption charge last year, because usage pricing means one power user or one looping workflow spends real money quietly and reports it a month later.
forrester has platform spend growing around 40 percent through 2026 against 5 percent for point solutions, and the companies that consolidated their stacks report cost reductions of 20 to 35 percent. that is not a negotiation win. it is the price of the duplication they were already carrying.
the advice going around is to run a software audit and push harder at renewal, which trims the invoice and leaves the sprawl exactly where it sits, ready to grow back by q4. do the version that holds: list every ai and software line, write beside each one the single job it owns and the person accountable for that job, and cancel anything whose job is already owned by something else. then put a spend alert on every usage-priced account so the meter tells you before the invoice does.
pwc read over a billion job ads across six continents and found the bottom of the ladder moved: ai-exposed entry-level roles are now seven times more likely to ask for judgement, leadership, and decision-making, skills that used to arrive in year five.
the cost lands on you twice, because the cheap junior who used to absorb the rote work is now expected to show up with taste, and the rote work they were supposed to learn on has already been automated out from under them.
the advice going around is to pay up for ai skills, and the market is not wrong about the price: the ai wage premium hit 62 percent this year, up from 57. paying more does not close the gap, because what you are actually buying is a person to exercise judgement your company has never made explicit, and no salary band compensates for that. do the version that holds: take the three decisions your newest people get wrong most often, write the rule, the exception, and one worked example for each, and put them somewhere a person on day four can find without asking.
in march the ftc barred air ai and its owners from marketing business opportunities, after charging that the company sold small businesses on ai sales agents using income claims it could not support.
the comedy is structural, not personal: a company selling software to replace your sales team was itself running a sales pitch no software could have made good on. the cost does not land on the people who wired them money, it lands on the whole category, because buyers now expect the sequence to be demo, number, subscription, with the working system optional.
gartner expects more than 40 percent of agentic ai projects to be scrapped by 2027, and almost none of that is the model failing. it is that nobody could run it in production once the vendor stopped presenting. the advice going around is to vet vendors harder and ask for more case studies, which is asking a sales process to police itself. do the version that holds: before you sign anything, write down the workflow it touches, the single number it should move, and the person inside your company who owns it on the monday after go-live.