UpTrajectory Review

The race to deploy agentic AI—systems that act autonomously rather than simply respond to prompts—has hit a reckoning point that small-business operators should take personally. Steven Mills, BCG's chief AI ethics officer, issued a blunt warning that companies are accelerating adoption with 'no idea how to manage risk.' The pressure is familiar: vendors promise productivity miracles, competitors seem to be moving faster, and the temptation to experiment is overwhelming. But Mills frames this as a governance failure in the making, where the very speed that feels like competitive advantage becomes the mechanism for catastrophic missteps. For small businesses without dedicated compliance teams or legal buffers, that risk asymmetry is especially acute.

This matters to small operators because the AI sales pipeline is designed to bypass your skepticism. Mills notes that business leaders openly tell him their risk management feels 'cumbersome and slow' compared to exponential AI scaling—a complaint that sounds reasonable until you recognize it as the logic that produced every major tech governance disaster of the past decade. Small businesses lack the capital to absorb a regulatory fine, a customer data breach, or a reputational hit from an autonomous system making unsupervised decisions. One 'incident,' as Mills puts it, and your experimental wins unravel entirely. The question is not whether AI can help your operation; it is whether you can afford to discover its failure modes in production, with real customers and real liability.

What is genuinely new here is the specificity of the warning and its source. Mills is not an academic critic or a journalist; he is embedded at BCG, a firm that profits enormously from AI transformation consulting. When a beneficiary of the hype cycle cautions against the hype cycle, that deserves attention. The unreferenced backdrop—Anthropic researcher Jacob Coxon's viral resignation alleging that AI companies are 'gambling with our lives'—creates an uncomfortable resonance. Mills does not invoke existential risk; his concern is operational and regulatory. But the juxtaposition suggests a spectrum of failure modes, from business-destroying to worse, all emerging from the same root cause: governance structures that cannot constrain systems designed to act independently.

The second-order effects will ripple unevenly across the business landscape. Gartner's prediction that 40% of enterprises will deactivate autonomous AI agents by next year, but only after governance gaps are exposed, implies a coming wave of public failures that will reshape vendor credibility and regulatory appetite. Small businesses that held back may find themselves with clearer compliance frameworks and more mature tools; early adopters may face stranded investments and heightened scrutiny. The 'prod' that Gartner's truncated prediction references—likely 'production incidents'—will also create liability precedents. Insurance markets will respond, potentially making AI deployment unaffordable for smaller firms regardless of technical readiness. The window for thoughtful adoption may close not because of regulation, but because of risk pricing.

What to watch: whether any AI vendor selling to small businesses begins offering governance scaffolding as a bundled service, or whether that burden remains entirely on the buyer. Also watch for state-level regulatory moves—California, New York, and Illinois have shown appetite for AI accountability rules that exceed federal inertia—and for industry-specific guidance from professional associations. What to do now: inventory any 'agentic' or autonomous features already in use, document their decision boundaries and override mechanisms, and demand that vendors specify what their systems can do without human approval. If a vendor cannot answer clearly, that is your answer. Slowing down is not Luddism; in Mills's framing, it is the only way to preserve the value you have already built.

Takeaway: Demand clear documentation of what any AI agent can do autonomously before deployment, not after your first incident.

Excerpt from the original — Fast Company

Business leaders are accelerating the deployment of agentic artificial intelligence with “no idea how to manage risk,” an AI safety expert warned yesterday.

Boston Consulting Group (BCG) partner and managing director Steven Mills, the firm’s chief AI ethics officer, warned that companies are moving into agentic AI too quickly and without adequate controls—potentially leading to serious consequences for their businesses.

“The desire to move fast on AI without putting appropriate risk management in place can result in a system lapse or use cases being deployed in areas with strong regulatory requirements that organizations are unprepared for,” he wrote in a blog post.

Under tremendous pressure to show AI-driven productivity gains, many business leaders have told Mills that their risk management programs are “cumbersome and slow” and can’t keep up “in a world that’s trying to …