AI Updated 29 Sep 2026

The chatbot we approved in January is not the tool sitting on the desk now

For thirty years IT decided what software could do and who could do it. Codex in the hands of an end user quietly ended that arrangement, and almost nobody was told.

By Steve Ogilvie · Okavyx, Adelaide

A small business starts using ChatGPT in January. Maybe the owner buys Pro. Maybe twelve staff get Business seats. Either way, the decision gets made once.

At first it writes emails, tidies quotes, explains things. Everyone gets a bit quicker.

Nine months on, the invoice hasn't changed. Neither has the login. The product behind them has changed a great deal, and nobody was asked to approve any of it.

None of that is a scandal. It's just how software works now. It's also genuinely new, and nobody has a settled answer for it yet.

What those nine months did

The chatbot learned to write and run code. Depending on the plan, ChatGPT Work and Codex now sit alongside it. Same account, genuinely different class of tool.

It also learned to reach into other systems through apps and connectors: Google Drive, SharePoint, Slack, Teams and Gmail. In ChatGPT Business those apps are enabled by default, so restricting them is something an administrator has to actively decide to do. Users still have to connect or authenticate services where required, but the capability is already sitting there waiting to be used.

And plenty of small businesses won't have a Business workspace at all. They'll have individual Plus or Pro accounts, sometimes paid for on a company card, with no central administrator deciding what is enabled, what is connected, or what staff are doing with it.

None of this arrived as a project. No rollout, no training, no approval form. It arrived the way software updates arrive.

And this isn't unique to OpenAI. Claude, Copilot and Gemini are all moving in the same direction.

The defaults are the tell

On ChatGPT Enterprise, Workspace Agents launched switched off by default. An administrator has to deliberately turn them on.

Set that against the apps and connectors described earlier, which arrive enabled on Business. One product posture assumes somebody is watching. The other assumes nobody needs to be.

Commercially that makes sense. Enterprise customers have governance teams and expect controls. Small businesses want software that works immediately.

The effect is worth noting all the same. The organisations with change boards and IT departments got the cautious defaults. The twelve-person business with no IT manager got the ready-to-go ones.

The safety valve went to the organisations that already had one.

This is a break with how IT has worked for a generation

For thirty years the arrangement was consistent. IT decided what software existed on the estate, what it was allowed to do, and who was allowed to do it. Capability arrived through procurement, testing and deployment. An end user got a fixed set of things they could do, and somebody else had decided what that set was.

Codex in the hands of an end user ends that arrangement.

The capability is general now, not fixed. It isn't a tool that does one job. It's a tool that will attempt more or less whatever it is asked to do, bounded only by the permissions of the person asking. And the range of what it will attempt grows every few weeks, with no deployment and no version number anyone is tracking.

I spent 30 years in corporate IT. If I'd proposed adding code execution and access to company storage to software already deployed on every desk, without testing, training or announcement, I'd have been laughed out of the change meeting. Quite rightly.

That process existed because the gap between what software can do and what anyone has considered it doing is where problems happen.

Software used to change when someone approved a change. Now it changes underneath us, often announced in release notes nobody reads.

Change control wasn't repealed. It just quietly stopped applying.

Two things follow from that

First, staff don't necessarily know the product changed either. Someone who started using AI to rewrite customer emails may now have access to something far more capable. Nobody necessarily explained what it can do, what it shouldn't touch, or what "access your files" actually means.

Second, when connected to other systems, it generally works within the permissions of the person using it.

That matters because small-business permissions are often terrible. Everyone can see everything on the shared drive: payroll, contracts, client files. It accumulated that way because it was easier and nothing bad happened.

Nothing bad happened because humans don't systematically explore every folder they can access. Dave in accounts may have been able to open the HR folder for nine years. He never did, because Dave had work to do.

The permissions were always too broad. A human being was the reason it rarely mattered.

Two scenarios

Someone asks: pull together what we're spending on staff by department so I can sanity-check the budget. Perfectly reasonable.

The tool has their existing access, including HR. So it retrieves salaries, bonuses and other relevant information, then neatly produces a spreadsheet.

Nobody hacked anything. Nobody bypassed permissions. But now somebody has information they probably shouldn't have seen.

You can restore a deleted file. You can't un-know what your colleague earns.

The second scenario matters more, because it involves action rather than reading.

Someone asks the system to chase overdue invoices. It has access to the accounting data and the mailbox through connected systems. Thirty-one reminders go out in seconds.

Four customers already paid but weren't reconciled. One account is in dispute and the solicitor wanted to review any contact. Another belongs to the company's biggest referral partner.

Nobody exceeded their authority. The employee has chased invoices for years. What disappeared was the afternoon it used to take, and during that afternoon they would probably have noticed.

That's the genuinely new part. The friction was the control.

Where this actually sits today

Most staff are not running autonomous agents across company file servers this week. That still requires deliberate setup, authentication and permissions, and some people selling AI security are overstating how common it is.

Today's risk is simpler. A document uploaded for summarising. A client list pasted in for formatting. A contract dropped in with "what does this clause mean?"

That's already happening. And in many businesses nobody has ever said a word about it in either direction.

The agentic version isn't hypothetical though. It's early, and apps and connectors are the on-ramp. Nine months took us from chatbot to code execution and multi-step agents. Nine months isn't much of a planning horizon.

What's worth looking at

Not a project. Probably not even an afternoon.

The useful first step is an inventory. On a Business workspace that means opening one staff account and inspecting the actual product rather than the marketing page: Work, Codex, Agents, Apps, Connectors, and what is already enabled. Then whether SharePoint, Drive, Slack or email has actually been connected to anything.

Where people are using individual Pro or Plus accounts, it means finding out who has them, what they are being used for, and whether company information is going through personal workspaces.

And asking one employee what they uploaded last week.

That costs nothing, and it is the only honest place to start.

What this isn't

It isn't an argument for banning it. Bans tend to move the same behaviour onto personal accounts and personal phones, where nobody can see it at all.

It isn't an argument for a governance programme either. Most of this is about decisions. What is AI for? What information shouldn't leave the business? Who can access what, now that software may exercise those permissions too? Would anyone know afterwards what it did?

Those decisions were overdue anyway. AI didn't create the problem. It found it, like a new tenant discovering every fault in a house the previous one lived with happily for years.

Where that leaves us

Most businesses are going to adopt this. Much of it is genuinely useful, and competitors aren't waiting.

The problem is the order most organisations are doing it in: buy the subscriptions first, find out what they became later.

What has changed seems clear enough. What anyone should do about it is much less settled, and this early, anyone sounding certain is selling something.

The one thing that does look certain is that nobody is going to send a memo when it changes again.

← All insights Log a job →