
.webp)
On shadow AI, governance, and why visibility comes before everything else
One of the most striking ideas in Bill Gates’ recent essay is“Human Reserved” jobs. Roles that, by deliberate choice, should stay in human hands. Care giving. Teaching. Work that is not just cognitive, but irreplaceably human. His own father had Alzheimer’s, and the care he received at the end of his life, Gates writes, was something “no robot could or should have done.”
I find this genuinely compelling. But Gates asks the rightquestion and stops just short of the most important answer.
He asks how we ensure AI does not replace humans without a plan. He proposes a “token tax” on AI to fund the transition. He calls forpublic debate. These are reasonable ideas. But they all assume that the organisations making these decisions — the governments, the companies, the regulators — actually know what their AI is already doing.
"You cannot reserve human judgment for the decisions that matter if you do not know where the machines have already taken over." Mikael Munck, CEO & Founder | 2021.AI
Most do not.
Geoffrey Hinton flagged this exact problem when he left Google in 2023. His concern was not primarily robots — it was bad actors. “It is hard to see how you can prevent the bad actors from using it for bad things,” he said. He also worried about a world where people “will not be able to know what is true anymore.” Both of those risks get dramatically worse when organisationshave no visibility into what AI is already running inside them. You cannot defend against misuse you cannot see.
I have this conversation repeatedly. I sit down with a CIO ora compliance officer at a public sector organisation, and I ask them how many AI tools their employees are currently using. The answer is almost always a number they feel confident about. Then we show them what is actually running.The real number is typically three to five times higher. Consumer-grade tools. Personal accounts. Models that were never approved, never assessed, never seen by IT or legal. Sensitive data flowing into systems nobody authorised.
This is not a future risk. It is happening right now, in organisations that believe they have AI under control.
Mustafa Suleyman calls this the “proliferation problem” in TheComing Wave — not the dramatic, visible disruption, but the quiet spread of owerful technology through institutions that have no framework to manage it. Kai-Fu Lee framed the same tension as a race between capability and governance. Right now, capability is winning by a significant margin.
So when Gates talks about Human Reserved jobs, I think about what it actually takes to protect them. Not just policy. Not just a tax on tokens. But the operational ability to see which AI systems are running inside your organisation, on what data, with what authority, and with what human oversight in place.
That is what we built GRACE AI Security to address. The AI Auto Registry auto-detects and logs every AI use case, system and model across an organisation. The Gatekeeper Agent surfaces shadow AI tools that IT has never seen. Chat Guardian catches sensitive data before it reaches a model. The AI Gateway controls which AI employees can actually access.
Not because we want to restrict AI. The opposite. The reason employees reach for unsanctioned tools is usually simple: the approved route is too slow or too complicated. Make approved AI fast and accessible, and most people will use it. That is the actual fix. Governance that works by making the right path the easy path.
Gates is right that we need a plan. But a plan starts with visibility. An d right now, most organisations are trying to govern something they cannot fully see.
Stay up to date on our latest news and industry trends