HA7CH

Lawted on McKinsey II: AI Is Not a New Board Agenda Item

Before reading: start with McKinsey’s original essay

This essay is not a summary of McKinsey, and it cannot replace the original.

In “The AI Reckoning: How Boards Can Evolve,” McKinsey lays out four possible AI postures for a company and six actions a board should take. It explains why boards must engage with AI, how a company should choose its posture, and how governance changes with that choice.

The argument below extends that framework. The reading order matters: read McKinsey first, then return here. Original: https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/the-ai-reckoning-how-boards-can-evolve

In the first installment of “Lawted on McKinsey,” I argued that AI is not an HR remake. This time I am not disagreeing for the sake of a critique. The essay is directionally right and, among traditional consulting firms’ writing on AI, relatively advanced.

It recognizes an important shift: AI is no longer merely an issue for the CIO, CTO, or digital team. It is now an enterprise issue that the board must face directly.

But it still does not carry the argument to its conclusion.

McKinsey treats AI as a core new item on the board’s agenda. What we see in Ha7ch’s fieldwork is that AI will not remain one agenda item. It will become the company’s new operating system.

Those two statements sound close. They lead to very different companies.

1. The conclusion first: this is an essay boards should read carefully

McKinsey reports that more than 88% of organizations use AI in at least one business function, while board governance lags far behind. Only 39% of Fortune 100 companies disclose some form of board-level AI oversight; 66% of surveyed directors say their boards lack AI knowledge and experience; and nearly one-third say AI is not even on the board agenda.

These figures are not directly comparable. An employee using AI does not mean the enterprise has transformed, and a company that does not publicly disclose an AI committee may still govern AI internally. Together, however, the numbers reveal the same gap: AI is spreading through companies faster than management and boards can understand it.

Employees are already experimenting with AI tools. Business units are launching local trials. Vendors are selling new Agents. Yet many boards still interpret all of this as a conventional IT program. Management sees budgets, procurement, pilots, and ROI; people on the front line feel their work boundaries, collaboration patterns, and professional value changing.

McKinsey’s contribution is to put that mismatch in front of the board.

It does not reduce AI governance to risk, compliance, and ethics. It asks boards to define the company’s AI posture and connect it to strategy, competition, business models, and capital allocation. That is the right starting point.

Without a shared view of what AI means for the company, budgets, talent, organization, vendors, and governance will pull in different directions. Business teams chase short-term efficiency, IT demands standardization and security, innovation teams produce demos, and the board approves a collection of projects that cannot be compared.

The essay is worth reading because it elevates AI from “a new tool the technology department should study” to “a strategic choice the highest governing body must make.”

2. What McKinsey gets right

McKinsey defines a company’s AI posture along two dimensions.

The first is the source of value: does AI primarily optimize the existing business, or does it create new products, markets, and revenue?

The second is breadth of adoption: is AI limited to a few proven use cases, or embedded across the organization?

That creates four postures:

• Internal transformation: AI enters operations broadly and becomes a foundation for redesigning the operating model.

• Business expansion: AI drives new products, services, and growth, redefining competitive advantage.

• Functional reinvention: AI enters selected workflows with clear returns and improves critical functions step by step.

• Measured adoption: the company waits for capabilities and market value to be validated, then follows selectively.

This framework is useful for companies still asking whether they should “do AI.” It forces the board to move beyond the tool layer. Is AI merely an efficiency tool, a portfolio of investments, a new product capability, or a reconstruction of the business and operating model?

I especially agree with McKinsey’s description of internal transformation. Once AI enters planning, supply chains, maintenance, and other cross-functional workflows, the board cannot look only at the accuracy of one tool. It has to understand system dependencies, enterprise architecture, interoperability, resilience, observability, and explainability.

That is close to what Ha7ch has consistently emphasized. An FDE must understand more than RAG, model tuning, or MCP integration. The core question is how AI enters a company and what Harness the company needs to receive it.

A company that expects to use Agents broadly needs its own Context, Skills, Gateway, permissions, audit records, and feedback mechanisms. Models supply intelligence. The company must build the architecture that receives, constrains, and accumulates that intelligence.

McKinsey has therefore recognized something important: AI transformation eventually becomes an enterprise-architecture question, not a procurement question.

3. It still treats AI as a portfolio of projects to govern

The governance playbook in the second half remains recognizably traditional: map the AI portfolio, evaluate pilots, calculate ROI, manage vendors, define risk thresholds, and scale successful projects.

None of that is wrong. Companies should stop projects that create no value and know where the budget goes. But the playbook assumes AI remains a class of software operated by humans.

That assumption changes once AI can understand work, call systems, allocate tasks, and act on a person’s behalf.

Traditional software defines functional permissions: after logging in, an employee may view a table, edit a field, or submit an approval. An Agent needs action permissions. It can read information across systems, understand a goal, plan steps, call tools, and continue executing.

A sales Agent may touch customer records, historical quotes, contract templates, and collections status. A finance Agent may read regulations, past project documents, and operating data. A manager’s Agent may synthesize team progress, identify risk, assign work, and follow up automatically.

At that point, the object of governance is no longer whether “an AI project” launches. It is how the right to know, judge, call, and act is redistributed inside the enterprise.

McKinsey focuses on what the board should review, which risks should escalate, and which investments need oversight. Ha7ch focuses on how those principles become part of daily operations. Without systematic permission checks, call logs, accountability, and exception escalation, even a complete AI policy remains a document on a shelf.

The disagreement is therefore not whether AI matters. It is the level at which we observe it.

McKinsey sees AI mainly as part of enterprise strategy and the investment portfolio. ANC goes one layer deeper and treats AI as the company’s new runtime.

4. The four AI postures are better understood as an evolution path

McKinsey presents business expansion, internal transformation, functional reinvention, and measured adoption as four strategic postures. That classification helps boards align, but real companies rarely fit into one box.

A large enterprise may pursue internal transformation in production, functional reinvention in customer service, business expansion in a new unit, and measured adoption in high-risk legal or financial work. Different business units can occupy different stages at the same time.

For most traditional companies, the four postures are less like fixed identities and more like a path of evolution.

The path usually begins with one concrete business point whose value can be verified. Once it works, the team gains more Context, discovers human judgments and exceptions, and turns a one-off delivery into a reusable capability. Only as those capabilities expand along the workflow can the company reconstruct operations and eventually create new products or revenue.

That is why we proposed Lawted’s 48 theory.

48 hours: find one point inside a broader surface

Forty-eight hours does not complete an enterprise transformation or promise an entire platform in two days. It identifies a small entry point with clear enough value to test in the real business.

In manufacturing, that point may turn resignation forms, inspection sheets, or workshop records into structured data and give a supervisor immediate statistics. In accounting, it may convert policy documents, bids, and project archives into summaries, fields, and verifiable spreadsheets. In a fleet or project organization, it may let an Agent read scattered records and complete one real task before anyone builds a platform nobody uses.

The first stage validates the original processing time, AI processing time, field usability, required human corrections, and whether the business owner wants to keep using it.

48 days: turn the result into enterprise capability

A successful demo does not mean the company owns AI capability. The decisive question is whether project Context, judgment rules, failure cases, and human corrections keep accumulating.

Over 48 days, scattered material becomes knowledge, Skills, and reusable workflows. AI moves from a one-off demonstration into stable work. The company begins tracking usage frequency, task volume, correction rates, feedback cycles, the number of Skills, and whether errors fall over time.

Many pilots fail to scale not because the model is weak, but because every project starts from zero. Data, Context, and human corrections do not accumulate. When the vendor leaves, the capability leaves too. The company runs many pilots without becoming more intelligent.

48 weeks: reconstruct the end-to-end workflow

Once multiple business points become stable capabilities, AI can expand upstream and downstream. The object of change is no longer one job’s efficiency, but cross-functional information, task, approval, and accountability flows.

In McKinsey’s language, 48 hours resembles the beginning of functional reinvention; 48 days begins internal transformation; 48 weeks creates the conditions for real business expansion.

A company does not need to rush to label itself with one posture. It needs to know its current stage, which capabilities the next stage requires, and how to prevent every pilot from ending at zero.

5. What boards really have to govern is an Agent’s right to act

McKinsey proposes six actions: define the AI posture, allocate oversight, institutionalize governance, speak more often with frontline owners, connect investment to business value, and improve the board’s AI literacy.

All six are valid. The Agent era requires another, more operational layer.

The first layer is Context governance.

Meetings, customer conversations, operating records, business documents, and employee experience cannot become universally accessible merely because the company wants to “train AI.” The company must define which Context belongs to the organization, which roles may access it, what may enter an external model, and what must remain local, domestic, or in a dedicated environment.

The second layer is Skills governance.

Once business experience is packaged as a Skill, it changes from one person’s method into a rule the organization can execute repeatedly. Someone must own the authority to create, review, publish, modify, and retire Skills, with versions and change history preserved.

The third layer is Agent permission governance.

“AI allowed” and “AI forbidden” are not enough. Permissions must specify what an Agent may read, which systems it may call, the value or risk level of actions it may execute, and where human approval is mandatory.

The fourth layer is accountability.

Every critical AI workflow needs an explicit Owner and DRI. The board sets governance boundaries, management owns business results, the business Owner owns value, and the DRI owns implementation. AI can perform work; it cannot become an excuse for responsibility to disappear.

The fifth layer is exception and escalation governance.

High-risk calls, unauthorized behavior, sensitive-data leakage, sudden quality drops, and errors at scale must trigger explicit stop, rollback, and reporting mechanisms. Governance should not occur only in an annual review. It has to execute inside every real Agent action.

This is why ANC needs a permission system. Governance is not an AI ethics statement on the wall; it is a constraint enforced whenever the system retrieves, calls, executes, and publishes.

6. Companies need an AI operating layer, not more AI tools

If AI is treated as a project category, the natural response is to keep buying tools: one for sales, another for finance, another for HR, plus separate vendors for knowledge, service, meeting notes, and analytics.

That can launch quickly and create clear vendor accountability. Over time it creates a new fragmentation: each tool holds part of the data, each vendor encloses part of the business logic, each department maintains another knowledge base, and employees switch between a growing number of AI entry points.

ANC adds an enterprise AI operating layer beneath those tools:

• Tokens or models provide base intelligence.

• The Harness understands the task, organizes the steps, and calls capabilities.

• The Gateway connects Feishu, DingTalk, desktop clients, or an employee’s own Agent.

• Context preserves enterprise knowledge, field information, and organizational memory.

• Skills encode reusable business capabilities.

• Permissions and audit define what an Agent may see, do, and represent.

• Feedback writes every human correction back into organizational capability.

This operating layer does not require replacing every existing system or building everything in-house. It lets the enterprise retain its Context, process, permissions, and business judgment while models and vendors continue to change.

Build versus buy is therefore not binary. A company can buy models, tools, and industry capabilities, but it must own the critical business Context, Skills, permission boundaries, and accountability structure.

7. ROI alone understates the organizational change

McKinsey recommends tracking AI-project ROI, the share of AI-enabled business, human intervention, resilience, retraining, and compliance. Those metrics matter, but they mainly reveal whether a project produces visible returns.

AI-native transformation needs three additional groups of metrics.

The first measures capability accumulation: how long it takes to turn a business problem into a usable AI capability; how quickly frontline feedback becomes a Skill; whether a capability is reused across departments; and whether human corrections reduce the next execution’s error rate.

The second measures governance: whether critical workflows have an Owner and DRI; whether Agent permissions are traceable; whether high-risk behavior requires confirmation; whether exceptions can roll back; and whether core Context has explicit data boundaries.

The third measures organizational structure: whether AI reduces repetitive reporting and manual coordination; whether decisions move closer to the real field; whether management spans increase; and whether information that once depended on middle-layer relays can reach decision-makers under controlled conditions.

Traditional ROI asks whether a project makes or saves money. These metrics ask whether the company is developing the ability to keep evolving.

The first determines whether the project continues. The second determines whether the company remains competitive.

8. The board cannot demand transformation only from everyone else

McKinsey’s title asks how boards can evolve, but most of the essay discusses how boards should supervise management, review projects, and track risk.

The deeper question is what happens when AI changes the company’s information and decision structure. Boards, executives, and middle layers all enter the scope of reconstruction.

Boards traditionally understand the company through management reports. Management understands the front line through layers of aggregation. One of the middle layer’s central functions is to collect information, coordinate resources, monitor progress, and report upward. Much of the structure exists because information is scarce, delayed, and costly to coordinate.

With continuously updated Context, traceable task systems, and Agents that understand business state, information no longer needs to pass through five layers of slides before reaching a decision-maker. Coordination no longer always requires a human relay.

That does not mean every company should immediately remove middle management, or that boards should bypass executives and command the front line. It means structures created by opaque information and high coordination costs must be tested again for value.

Managers who create judgment, accept responsibility, develop people, and handle complex conflict become more valuable. Roles built mainly around relaying information, chasing progress, producing reports, and maintaining process will compress.

If a board asks employees to learn AI and business units to submit AI projects while declaring today’s hierarchy, approvals, and power structure untouchable, that is not AI transformation. It is an old company with more AI tools.

AI rewriting the rules means no role sits outside the rewrite, including the board itself.

Conclusion: McKinsey explains why; Ha7ch cares about how

Overall, I agree with roughly 70% of McKinsey’s argument.

It correctly raises AI from a technology-tool question to one of strategy, governance, and capital allocation at board level. It also recognizes the importance of enterprise architecture, cross-functional workflows, and business value. Companies that still think AI means chatbots, knowledge bases, or office plug-ins should read it.

But the essay stops mainly at governance principles and project portfolios. It does not continue into enterprise AI runtime architecture, Agent permissions, organizational accountability, and management redesign.

That is precisely what Ha7ch and ANC are trying to answer.

McKinsey tells boards why they must begin governing AI.

Ha7ch asks how Context accumulates, how Skills grow, how Agents receive permissions, how Owners and DRIs remain accountable, and how a company starts from one real business point and gradually becomes an AI Native Company over 48 hours, 48 days, and 48 weeks.

We are not rejecting McKinsey. We are following its conclusion one step further.

AI is not one more slide in the board’s quarterly deck, or one more topic at the annual strategy meeting.

It will become the company’s new operating system.

The board’s real evolution is recognizing that it must not only govern this system. It is also inside the system being rebuilt.