Critical application performance dashboard displayed on a laptop screen, showing real-time analytics, charts and operational metrics in a modern office environment.
Blog
Posted by
By Julius Damato, Director, Microsoft Modern Work & AI Solutions

Everyday AI made building easy. Nobody planned for what happens after.

Here's a story I wish I'd made up.

Someone at one of our clients built a small app with an AI tool. It pulled some data, did some math, and produced the numbers a team needed every morning. It worked great. So great that other people started relying on it. Then the person who built it got on an 18-hour international flight. The app was running on their laptop. The laptop was in the overhead bin. The business had a very bad morning.

Nobody did anything wrong, exactly. They solved a problem. That's what makes this tricky.

Building got easy. Owning didn't.

Copilot, Claude, and ChatGPT have changed who gets to build things at work. Not long ago, if you wanted an app, an automation, or a dashboard, you filed a request with IT and waited. Now you describe what you want in plain English and have something working before your coffee gets cold.

That's a real win, and I'm not here to tell anyone to stop. I use these tools every day. You'd have to pry them out of my hands.

But each of these tools now comes with its own ecosystem of things you can build. Copilot has agents and Copilot Studio. ChatGPT has custom GPTs and projects. Claude has projects and artifacts. All of them will happily write you an app or a slick HTML dashboard if you ask nicely.

What almost none of our clients have is a plan for what happens after the thing gets built. Who owns it? Who updates it? What happens when the person who built it leaves, changes roles, or just takes a vacation? Most organizations can't answer those questions. Most haven't asked them yet.

Three patterns I keep seeing

1. Dashboards that carry more than you think

This one surprises people the most. Ask an AI tool for a dashboard and you'll often get an HTML file. It looks like a picture of a report. It isn't. The numbers behind every chart are usually sitting right there inside the file, and anyone who opens it can get to them.

So someone builds a nice summary for the leadership team and shares it. Someone else forwards it to a partner, a vendor, or their personal email to look at later. Nobody thinks twice, because it looks like a harmless chart. Meanwhile, the full data set just left the building. If that data happens to be material non-public information, you now have a very different kind of problem, and it has Legal's name on it.

This isn't a Copilot problem or a ChatGPT problem. It's just how these files work. The tool did exactly what you asked: it built a self-contained page, and self-contained means the data comes along for the ride.

The person who forwarded it had no idea. That's the point. You can't expect people to protect something they don't know is there.

2. Agents and apps nobody owns

Agents, custom GPTs, projects, and vibe-coded apps (the ones you build by describing what you want and letting AI write the code) all follow the same pattern. Someone builds one to scratch their own itch. It works. A teammate asks for access. Then the whole team. Six months later it's part of how the department runs, and nobody ever made a decision about that. It just happened.

Now ask a few simple questions. Who owns it? Where does it actually run? Whose login is it using to get to the data? What happens when that person leaves the company? In a lot of cases, the honest answer is "I don't know," followed by a nervous laugh.

3. Things that were never meant to scale

Most of what people build with AI is built for one person and one moment. That's fine for one person and one moment. It's not fine for fifty people and three years.

Data sources change. Systems get upgraded. The prompt that worked perfectly in March starts giving strange answers in September. Meanwhile, the business has quietly come to depend on something that was never designed to be maintained, tested, or supported. It's like building your house on a folding table. Holds up great until someone leans on it.

And when it does break, there's no help desk ticket, no documentation, and no vendor to call. There's one person who knows how it works. Hopefully they're not on a plane.

Why most clients aren't thinking about this

Honestly? Because it doesn't look like a risk. It looks like productivity. Nobody files a ticket for it, so IT never sees it. Security tools mostly watch the data, not the little tools people build on top of it. And the builders are usually some of your best people, so nobody wants to be the one asking awkward questions.

We've seen this movie before. Remember the spreadsheet with seventeen tabs and macros that only one person in accounting understood? The Access database that somehow ran a core process? This is that, except it's faster to build, easier to share, and there are a lot more of them.

The answer isn't to lock everything down. Ban these tools and people will just use them on their phones, and you'll end up with less visibility, not more. The answer is to know what's out there and have a simple way to decide when something needs to grow up.

The Graduation Test

Here's the gut check I give clients. Four questions. Anyone can ask them about anything they've built, whether it's an agent, an app, a custom GPT, a project, or an HTML dashboard.

The test

Ask yourself

The Vacation Test

If you were unreachable for two weeks, or stuck on an 18-hour flight, would it stop working? Would someone come looking for you?

The Forward Test

If this file or link landed in the wrong inbox, would Legal or Compliance get a phone call?

The Decision Test

Do people outside your immediate team use it to make decisions about money, clients, or anything a regulator cares about?

The Stranger Test

If it broke tomorrow, would you be the only person who could fix it?

Notice that none of these questions care how the thing was built or which tool built it. I don't care if it's the prettiest agent in the company. I care about what happens when it breaks, or when it ends up somewhere it shouldn't.

If you answered yes to any of these, it's time to graduate it. That doesn't have to mean a big project. It means getting it on IT's radar, naming an owner and a backup, and deciding together whether it moves to a managed platform, gets rebuilt properly, or gets retired.

If you answered no to all four, great. Keep building. That's exactly what these tools are for.

What graduation actually looks like

For most clients, this comes down to a handful of practical steps. None of them are glamorous. All of them are cheaper than an outage.

  • Find out what exists. You can't govern what you can't see, so start with an inventory of the agents, apps, and shared AI outputs across Copilot, Claude, and ChatGPT.

  • Give everything important an owner and a backup. A person, not a team name.

  • Move business-critical work off personal laptops and personal logins, and onto platforms your organization manages and supports.

  • Treat AI-built HTML files like the data inside them, not like a picture. Label them, limit sharing, and teach people what's actually in there.

  • Put a review date on anything that matters. AI-built tools drift, and someone should check that they still work and still make sense.

  • Make the right path the easy path. If graduating a tool takes six weeks of forms, nobody's going to do it.

The builders aren't the problem

I want to be clear about this. The people building these things are not the problem. They're usually the most curious, most motivated people in the building, and they're doing exactly what everyone told them to do with AI. The gap is that most organizations encouraged the building and skipped the part where someone owns what gets built.

The good news is that it's fixable. And it's a lot easier to fix now than after the next 18-hour flight.

Not sure what's already out there in your environment? Want help setting up a simple way to decide what should graduate? That's the kind of thing ECI helps clients with every day. Reach out to your ECI team and let's talk.

Contact ECI

Microsoft 365 Copilot

Speak With One Of Our Experts Today

Learn How ECI Can Unlock Real Value For Your Firm.