“The AI-native company does not exist yet” is a provocation, not the result of checking every company on earth. It uses a demanding definition. A business does not become AI-native because it ships a generative feature or buys copilots for every employee. Under the standard used here, AI must be able to work inside the company’s real decision rights, budgets, operating records, controls, and accountability model.
Without that boundary, one AI statistic can support four incompatible stories. Product sees feature adoption. Finance sees no movement in payroll or margin. Security sees unmanaged data. Employees see an approved tool that takes weeks to access while a personal account works this afternoon. I have sat in service-planning meetings where the same deck earned applause in one room and silence in the next. The disagreement was not about the model. Each function was measuring a different company.
The current evidence shows wide adoption and shallow operating change. In McKinsey’s 2025 global survey, 88% of respondents said their organization regularly used AI in at least one function. Only about one-third had begun scaling AI across the enterprise. Twenty-three percent reported scaling an agentic system somewhere, yet no individual business function had more than 10% reporting agent scale. AI is common. A redesigned enterprise is not.
Using AI is not the same as operating through AI
There is an obvious challenge to the headline. A June 2026 working paper from INSEAD and Harvard Business School explicitly studies “AI-native firms.” The researchers classify venture-backed US startups and Y Combinator companies first financed from 2020 through 2024. Relative to non-AI startups in the same industry and cohort, the AI-native firms were 25% smaller, had a 13% greater engineering share, and had roughly 15% lower shares of both entry-level workers and managers.

Source: INSEAD, AI-Native Firms, checked 2026-08-18. This is a 2026 working paper. It classifies startups using product descriptions, job postings, and workforce data.
That is meaningful counterevidence. Companies built around AI products already exist, and their staffing may be leaner and flatter. It is not evidence that purchase approvals, customer-data access, legal review, payment exceptions, and incident ownership have been rebuilt as one auditable operating system. The authors themselves separate a product channel, where AI is embedded in what the firm sells, from a process channel, where AI changes how people work inside the firm.
Microsoft offers another useful but different label. Its 2025 Work Trend Index calls an organization built around on-demand intelligence and human-agent teams a “Frontier Firm.” It predicts fluid, outcome-oriented “Work Charts” in place of rigid organization charts. Microsoft also describes these firms as emerging; the report combines a worker survey, Microsoft 365 signals, and LinkedIn data. It is a market view backed by a technology vendor, not an audited register of businesses that have rebuilt every operating control.
The practical split is between AI in the business and AI on the business. The first uses AI to make a product, answer, campaign, or service better. The second changes how the company allocates authority, money, information, and responsibility. Plenty of firms have the first. The difficult claim in the headline concerns the second.
Agents collide with the operating rules that never reached the manual
An org chart can tell an agent who reports to whom. It cannot explain how work actually gets finished. A supplier payment may appear to require one finance approval. In practice, a particular contract goes to legal first, a threshold requires a director’s message, and month-end processing uses a different spreadsheet. One experienced coordinator knows all three exceptions. When that person is away, the process stalls.
A person can ask the coordinator. An agent must behave consistently when the requester changes, the team reorganizes, or the exception happens at 2 a.m. That requires the source of data, approval conditions, stopping rules, and escalation owner to be readable. Once those rules leave someone’s head and enter a system, awkward questions become unavoidable. Why does only this person approve the exception? Why does one department have a private route? Why is the same contract keyed twice?
This is where a technology rollout becomes organizational change. Most workarounds were not created by villains defending a fiefdom. People built them to bridge old systems, meet deadlines, and avoid incidents. Over time, the workaround also becomes a balance of influence and territory. Making it legible can change who controls the decision. Resistance is rational when the deployment quietly removes discretion or exposes a fragile agreement.
The fashionable answer is to create a separate AI-native subsidiary. It can hire quickly and avoid some legacy approval paths. It also tends to lack the customer data, ERP access, purchasing authority, revenue responsibility, and process owners required to change the core business. The unit produces a polished demonstration and an impressive board memo; the operating workflow stays where it was.
A smaller internal team with real authority is usually the better first move. It needs a budget, engineering capacity, and permission to work with the owners of one end-to-end process. A committee can recommend. An operating team must be able to change the route and remain accountable for the result.
Shadow AI is misconduct and a speed signal
Suppose an approved AI purchase takes three months but an employee must classify 80 customer documents this week. The employee will not wait for the strategy deck. They will open a personal ChatGPT or Claude account, upload the files, or run an agent on a laptop. The company system shows no project. The real work finishes outside it. That is shadow AI.
Microsoft Security describes shadow AI as unsanctioned and unprotected use of AI applications, with a clear risk of sensitive-data leakage. Its response includes access controls and browser data-loss prevention. Those controls matter. A longer blocklist does not remove the deadline or the workload. It can simply push the workaround farther out of sight.
The approved route has to win on usefulness as well as safety. Employees need an authorized workspace, a short route to the right model, and a documented way to connect internal systems. Access should take days, not quarters. Standardization does not have to mean one model for every task. It should mean consistent data classes, external-transfer rules, human approval points, and support ownership across the models the company permits.
Agents also need their own identities and least-privilege access. Borrowing an employee’s account hides who or what acted. A usable record links the requester, source data, reasoning result, tool action, and changed object. High-risk actions—external sending, payment, deletion, and permission changes—should stop for human approval. When something goes wrong, an owner must know how to stop, recover, notify, and review.
This is not governance theatre. The NIST Generative AI Profile recommends an inventory of organizational generative-AI systems, defined human oversight roles, record-retention policy, incident-response procedures, and after-action reviews. For third-party AI, it also calls for named incident ownership, rehearsed plans, and fallback arrangements. Treating an agent like a participant in the organization means adapting the identity, access, record, and incident practices that already apply to employees and software services.
Old value units cannot price agent work
Even a well-controlled environment runs into an accounting problem. Companies have spent decades budgeting with headcount, hours, seats, and output counts. Consulting and legal services bill time. Software prices a named user. Annual plans turn work into FTE. When an agent completes an 80-hour analysis in 40 minutes, value has been created, but the old ledger has nowhere honest to put it.
Keeping the hourly model punishes the supplier that finishes in 40 minutes. Billing the old 80 hours makes the buyer distrust the price. A design team faces the same problem when people and agents generate dozens of variants: one “deliverable” no longer describes the work or its value. Seat licensing also bends out of shape when one agent works across several processes around the clock.
Microsoft’s proposed human-agent ratio is a useful prompt, but it is not a result measure. Ten agents can create drafts that one employee must rewrite from scratch. Digital capacity increased; the workflow did not improve. The better view follows a customer or business request to its actual end: total elapsed time, human correction time, rework, unauthorized actions, failed handoffs, and recovery cost.
I would start the operating scorecard with four lines. Completion rate checks whether the result met a human-defined finish condition. Cycle time runs from the request to the real close, not to the agent’s first answer. Human review time measures how much reading and repair remained. Risk-adjusted value subtracts the cost of data exposure, permission errors, failure, and recovery. The formulas will differ by company. The governing question should not: did total time and effort to finish the customer problem fall?
The first 90 days should change one workflow end to end
There is no need to declare the company AI-native on day one. A better 90-day objective is to prove that one cross-functional workflow can finish safely. Refunds, supplier onboarding, or sales-proposal approval work well because they have a recognizable start and end while crossing several teams. A simple FAQ is easier, but it does not test the operating model.
During weeks one and two, watch the real screens and conversations rather than trusting the procedure manual. Record the private spreadsheet, message approval, repeated data entry, and exception that only one employee remembers. In weeks three and four, map the decision owner, data source, exception, human gate, and stopping condition. If the group cannot agree, do not connect the agent. The problem is unresolved process ownership, not failed automation.
Weeks five through eight begin in an approved workspace with read-only data. Let the agent classify and draft. Keep external messages, payments, deletion, and access changes behind a person. Record the requester, inputs, decision result, and action. In weeks nine through twelve, compare completion, cycle time, review time, exceptions, and incidents. Add write access only where the improvement is real and recovery is tested.
Stop conditions should be decided before the pilot. Do not expand if correction time remains flat, the same exception keeps recurring, nobody can name the final owner, or the log cannot support restoration. If one workflow does finish safely, the organization has gained something reusable: a data contract, permission model, escalation path, and measurement baseline for the next workflow.
The internal AI team needs authority more than branding. It should be an engineering and operations team that can spend a budget, set tool standards, and change a process with its owner. A single executive or advisory council cannot do that work. Moving the team outside the company recreates the distance from data and decisions that blocked the first attempt.
AI in the business is the easier half. AI on the business asks the company to reveal how work truly moves, make the official route faster than shadow AI, assign identity and responsibility to agents, and replace inherited value units. The missing ingredient is not another frontier model. It is the willingness to rewrite operating rules that the organization spent decades optimizing around people.
References and reporting
Public pages used for reported facts, official documentation, policy background, product details, and claims that may change.
- AI-Native FirmsINSEADUsed for: research definition of AI-native startups; differences in firm size and workforce structure; product and process channelsChecked: 2026-08-18
- The state of AI in 2025: Agents, innovation, and transformationMcKinsey & CompanyUsed for: AI adoption; enterprise scaling; agent scaling by function; enterprise EBIT impactChecked: 2026-08-18
- The 2025 Annual Work Trend Index: The Frontier Firm is bornMicrosoftUsed for: Frontier Firm; Work Chart; human-agent ratioChecked: 2026-08-18
- Microsoft unveils Security Copilot agents and new protections for AIMicrosoft SecurityUsed for: shadow AI; unsanctioned AI applications; access controls and data loss preventionChecked: 2026-08-18
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence ProfileNISTUsed for: AI system inventory; record retention; responsible roles; incident response and reviewChecked: 2026-08-18



