Certified Private AI™ The Five Rungs of AI Adoption From the book Certified Private AI by Truc Nguyen

The owner's case for putting AI to work, rung by rung

How much of this decision have you handed to AI, and did you mean to?

That is the only question the Five Rungs ask. This app works the way the book does: a working model you can run yourself, the book's evidence laid out with its limits attached, the independent research record set beside it so the case does not rest on one author's say-so, the objections owners raise most taken one at a time, and four challenges, each tracked on its own clock: a seven-day onboarding challenge, a two-week rung challenge, a red-flags challenge against your current vendor, and a seven-move challenge to automate an onboarding process, a new client's or a new employee's, rung by rung, testing the case in your own business instead of in a brochure. The argument, stated plainly: AI is already inside your business. The only live question is whether you govern it, rung by rung, or it governs itself.

An ornate brass clock mechanism with concentric engraved rings and gears, and a five-rung ladder standing in its glowing center
The Adoption Clock. Five rungs at the center, the work of running them around the rim.
The working model

The Adoption Clock

This clock no longer runs on its own. It runs on your work. Pick the rung you are implementing, then check off the book's seven-step loop as you actually do it in your business: find the opportunity, choose the rung, approve the arrangement, test, measure, revisit, and expand only when the evidence says so. The hand moves when you move, and the rung arcs on the face fill in as each rung goes live.

ADOPTION LOOP
Your next step
Identify the opportunity

Start with a task that carries a number: revenue, cost, service, capacity, or consistency. If you cannot measure it before AI touches it, you cannot prove AI helped.

    Tap a step to check it off as you finish it in your business. Tap again to undo. Finish all seven and the loop counts as complete.

    Loop for
    Challenge 01 · Seven days, one decision a day

    The Onboarding Challenge: Your First Week on the Clock

    New here? Start with this one. Seven short moves, one per day, each checked off on the clock as you finish it in your business: find out which AI your staff already opened this week, pick one measurable task, place it on the ladder, and leave the week with a written starting point. Finish this clock and you are ready for the 14-Day Rung Challenge below.

    0/7days done

    Start at Day 1. One honest answer a day.

    Your reading so far

    Nothing checked off yet. Day 1 takes five minutes and usually changes the conversation.

    0 of 7 complete

    Done means done in your business, not read about. Tap a day again to undo it. Like everything in this preview, the clock keeps score for this visit only. Members will receive access to the member version, where challenge progress saves to your account.

    Every challenge on its own clock, all driven by your work

    Track Your Climb

    Nothing on these clocks advances on its own. Mark a rung implemented as it goes live, check off chapters as you read them, log your onboarding and 14-day challenge days, run the owner tools, work the red flags challenge against your current vendor, and automate an onboarding process rung by rung. Every dial on this page reads from the same work, so progress you make in one section shows up everywhere.

    0/7days done

    Onboarding Challenge

    Challenge 01, the seven-day start. Tap a segment here, or work the checklist in the Onboarding Challenge section above.

    0/7moves done

    Automate Onboarding

    The Automate Your Onboarding Challenge, seven moves from baseline to a decision made with numbers, for a new client or a new employee. Tap a segment here, or work the checklist in that section below.

    0/5rungs live

    The Five Rungs

    Tap a segment as each rung goes live in your business, or mark it from the rung explorer below.

    0/26chapters read

    Book Chapters

    Tap a segment here, or tap chapter titles in the lesson library, as you finish each chapter.

    0/14days done

    14-Day Challenge

    Synced with the challenge checklist further down. Checking a day in either place updates both.

    0/5tools used

    Owner Tools

    Find Your Rung, the exposure audit, Trace One Prompt, the onboarding automation challenge, and today's lesson. Tap a segment to jump to that tool.

    0/10flags reviewed

    Red Flags

    Chapter 17, worked one by one against your current vendor. Tap a segment to jump to the checklist.

    For Certified Private AI members

    Members will receive access with saved progress

    This preview does not offer sign in or saving. Members will receive access to the member version of this app, where rungs implemented, chapters read, 14 day challenge days, and owner tool results save to your account and are there when you return. Use this preview to explore the rungs and tools, and bring your readings to your AI Opportunity Call.

    Chapter 13, the heart of the book

    The Five Rungs of AI Adoption

    The rungs describe how much responsibility you hand to technology for one business process. They are not five products, a higher rung is not a better business, and Rung 2 is deliberately different: it automates work with fixed rules and no AI judgment at all. Start at the lowest rung that meets the need. Climb only when measured value justifies the added responsibility and you can control it reliably.

    Why every business owner, argued with evidence

    The Case for Putting AI to Work

    Not hype, and not fear. Five arguments, each with its evidence and its limits attached, the way the book presents them. Where a number is a recollection or an estimate, it says so.

    From the book, Introduction

    AI is already inside your business

    A salesperson is drafting proposals. An office manager is writing customer emails. A technician is troubleshooting with AI. If an employee pastes sensitive business information into an unapproved AI tool to finish a task, the business has created a data flow nobody assessed. Doing nothing does not keep AI out. It only keeps AI unmanaged.

    The choice is not whether AI gets used. The choice is whether its use is chosen, approved, and measured by the owner, or discovered later by a customer or a regulator.

    Published incident, source [8] Mar 2023 OpenAI outage report

    Uncontrolled data flows fail in public

    In March 2023, OpenAI reported a bug that let some users see other users' chat titles and potentially the first message of a conversation, and exposed payment-related information for some subscribers. That was a software isolation failure at the largest AI provider on earth. Your employees' prompts travel to systems you do not operate, under terms you have not reviewed.

    An approved or private arrangement does not eliminate failure. It decides in advance whose failure it can be, and what the information was allowed to touch.

    Law, sources [12] [13] [14] Jan 1, 2027 Colorado AI obligations begin

    The rules are arriving on a schedule

    New York City's Local Law 144 already governs AI used in employment screening. The EEOC has published its position on AI and employment law. Colorado's SB26-189, signed May 14, 2026, puts key automated decision-making obligations into force on January 1, 2027. Businesses that adopt AI with records, approvals, and named owners will meet these as paperwork. Businesses that adopted it casually will meet them as archaeology.

    From the book, Chapter 6

    A leak is priced in more than money

    An incident can require investigation, recovery work, business interruption, notifications, affected-person support, legal and contractual response, technical remediation, and customer retention work. The time to solve a data exposure problem is before it happens, not after a patient asks how their information was handled. Adopting AI with the controls chosen first is how the exposure stays a managed risk instead of a surprise.

    From the book, Chapters 13 and 26

    Starting small is the whole design

    You do not need to own or train a frontier model, buy all five rungs, or bet the company. Rung 1 is a person using an approved assistant and reviewing every output. That alone, governed properly, captures real value this month, and each further rung has to earn its place with measured results. The cost of starting is small. The cost of starting late, with shadow AI already everywhere and no records, compounds.

    The same case, proven outside the book

    The Outside Evidence

    A book arguing for its own method is a claim. The public record is a check. Six findings from independent researchers, industry benchmark reports, and reported incidents, none of them published by Certified Private AI, each with its source linked and its limit stated. Read them at the source. That is what they are there for.

    Independent research, peer-reviewed +14% issues resolved per hour

    Assisted agents outperform, and your newest staff gain most

    Brynjolfsson, Li, and Raymond studied 5,179 customer support agents at a Fortune 500 software company as an AI assistant rolled out in stages. Access to the tool raised productivity 14% on average, and 34% for novice and lower-skilled workers, while customer sentiment and employee retention improved and top performers barely moved. Published in the Quarterly Journal of Economics, 2025.

    What it means for your business

    This is the Rung 1 pattern measured in the wild: a person, an approved assistant, a review habit. The biggest gains went to the least experienced staff, the people a small firm can least afford to train slowly.

    Limit: one company, one job type, and it measures assistance, not autonomy. Source: "Generative AI at Work," NBER Working Paper 31161.

    Independent field experiment, Harvard and BCG +40% higher rated quality, inside the frontier

    The frontier is jagged, and that is the argument for rungs

    In a field experiment with 758 Boston Consulting Group consultants across 18 realistic tasks, consultants using GPT-4 on tasks inside its capability finished 12.2% more tasks, 25.1% faster, at over 40% higher rated quality. On one task deliberately outside that capability, consultants using AI were 19 percentage points less likely to reach the correct answer than consultants without it.

    What it means for your business

    The same tool lifts one task and quietly misleads on a similar looking one. Choosing the rung per task, and keeping a human reviewer where the answer matters, is how a business keeps the gains and refuses the losses.

    Limit: consulting tasks and one generation of models; the frontier moves as models change. Source: "Navigating the Jagged Technological Frontier," Harvard Business School.

    Survey, 31,000 people in 31 countries 78% of AI users bring their own tools to work

    Most knowledge workers already use AI. The open question is governance.

    Microsoft and LinkedIn's 2024 Work Trend Index found that 75% of knowledge workers use AI at work, that 78% of those users bring their own AI tools rather than waiting for a company provided one, and that 60% of leaders say their company lacks a plan to implement AI.

    What it means for your business

    If your business runs on knowledge work, the odds are strong that AI use is already happening inside it, one personal account at a time. The decision still on your desk is whether that use runs on approved tools with written rules, or on personal accounts with none.

    Limit: self-reported survey data from a vendor with AI products to sell; treat the direction as reliable and the decimals as approximate. Source: 2024 Work Trend Index, Microsoft and LinkedIn.

    Industry benchmark, 600 breached organizations $4.44M global average cost of a breach, 2025

    Ungoverned AI now has a measured price

    IBM's Cost of a Data Breach Report 2025 put the global average cost of a breach at $4.44 million, and $10.22 million in the United States. One in five breached organizations reported a security incident involving shadow AI, and those breaches cost about $200,000 more on average. Sixty-three percent of organizations had no AI governance policy in place.

    What it means for your business

    Shadow AI has moved out of the hypothetical column and into the benchmark data, priced. A written approved list, named owners, and records are the controls that keep your business out of that statistic.

    Limit: averages across breached organizations, weighted toward large companies; your exposure is your own numbers, not the average. Source: Cost of a Data Breach Report 2025, IBM.

    Reported incident, Bloomberg, April 2023 20 days from permission to leak, then a company-wide ban

    Samsung: the leak was an employee trying to work faster

    Weeks after Samsung Electronics allowed staff to use ChatGPT, engineers pasted proprietary semiconductor source code and confidential meeting notes into it. Samsung responded by banning generative AI tools on company devices and networks while it worked on controlled alternatives, after an internal survey in which 65% of respondents already believed such services posed a security risk.

    What it means for your business

    Nobody hacked Samsung. Helpful employees used a free tool with no approved path and no written rule. That is the exact failure an approved list and a controlled route exist to prevent, and it took under three weeks.

    Limit: a single incident, with some details Samsung never disclosed; it proves the failure mode, not its frequency. Source: Bloomberg News, "Samsung Bans Staff's AI Use After Spotting ChatGPT Data Leak".

    Global survey, 1,993 respondents in 105 countries 88% use AI somewhere; about one in three is scaling it

    Nearly everyone has the tools. A third have begun scaling them.

    McKinsey's State of AI 2025 reports that 88% of organizations now use AI regularly in at least one business function, up from 78% a year earlier, while roughly two-thirds have not begun scaling beyond pilots and only about 6% qualify as high performers reporting meaningful profit impact. Reporting on the survey points to the same separator: the high performers redesign workflows instead of layering AI on top of old ones.

    What it means for your business

    Access to AI is now something anyone can buy off the shelf. The scarcer asset is a documented, governed process wrapped around it, pointed at a measured outcome. That is precisely the thing Certified Private AI implements.

    Limit: self-reported survey; "high performer" is McKinsey's definition, and correlation is not proof of cause. Source: "The State of AI in 2025," McKinsey, as reported by Information & Data Manager.

    Watch the Researchers Say It Themselves

    The app this page is modeled on leaned on a featured video every day. The habit worth copying is not its conclusion; it is sending people to watch the evidence themselves. Four talks on YouTube by or about the researchers behind the studies above, each labeled with what it can and cannot prove. They open on YouTube, in a new tab.

    Video, Microsoft WorkLab podcast, 2023

    Erik Brynjolfsson on How AI Will Transform Productivity

    The lead author of the 14 percent study, in conversation: AI pays off when organizations restructure work around it, and augmenting people beats automating them away. The economist behind the first card above, explaining his own numbers and what they do not show.

    Pairs with

    The first evidence card, and Move 1 of the onboarding automation challenge below: measure the task before you delegate any of it.

    Limit: a podcast conversation, not the paper itself. For the numbers, read the study. Watch on YouTube.

    Video, study presentation

    Ethan Mollick: Navigating the Jagged Technological Frontier

    Wharton professor Ethan Mollick, a co-author of the Harvard and BCG experiment, walks through its design and result: large gains on tasks inside the frontier, a 19 percentage point penalty on the task outside it, and why that boundary is hard to see from inside the work.

    Pairs with

    The second evidence card, and Move 6 of the onboarding automation challenge: the test day that decides whether an agent earns wider scope.

    Limit: one study, presented by its own author; models have moved since it ran. Watch on YouTube.

    Video, Strange Loop podcast

    How to Build an AI-First Organization

    Mollick on the management side: most companies use AI to shave costs and think too small, while the organizations that gain redesign roles around it, keep humans in the loop where judgment lives, and treat adoption as a leadership job rather than an IT purchase.

    Pairs with

    Move 4 of the onboarding automation challenge: the written arrangement, owned by a named person, that turns scattered use into a governed system.

    Limit: expert argument, not measurement. Weigh it as informed advice. Watch on YouTube.

    Video, Insight Partners ScaleUp:AI, October 2025

    The Jagged Frontier of Generative AI

    Mollick with Insight Partners managing director Lonne Jaffe on what actually blocks adoption inside companies: not model capability, but leadership, organizational design, and incentives. Small accuracy gains can quietly multiply what an agent can safely carry, which is why rung decisions get revisited on a schedule instead of made once.

    Pairs with

    Move 7 of the onboarding automation challenge: the decision, made with numbers, to climb a rung or stay where the evidence says to stay.

    Limit: a venture firm's event stage, and the host invests in AI companies. Discount accordingly. Watch on YouTube.

    One chapter a day, like a featured lesson

    Today's Lesson From the Book

    The model is only the map. The territory is 26 chapters of decisions: data, process, testing, buying, oversight, cost, and people. One rotates to the front each day. The full library sits below it, because a claim this size should show its whole evidence shelf.

    13
    Chapter
    Part 5, Getting It Live

    The Implementation Roadmap and The Five Rungs of AI Adoption

    The Five Rungs describe increasing forms of delegated work and responsibility, not a technical ranking of model intelligence. Treat them as five possible levels of work to assign, not five purchases every company must make. Start with the least authority that solves the task.

    Key move: ask of every task, how much of this decision have you actually handed over, and did you mean to?

    Tap any chapter title to mark it read as you work through the book. Your reading dial above keeps the count.

    Challenge 02 · The 14-day test, run on your own business

    The 14-Day Rung Challenge

    Arguments end. Evidence accumulates. Spend ten minutes a day for two weeks doing, not reading, and by day 14 you will have your own reading: where your business stands on the ladder, a candidate first win with a baseline number attached, and a written flag count for your current AI vendors. Whether the case holds is for your evidence to say. Check each day off as you finish it and watch the challenge clock fill, one segment per day.

    0/14days done
    0 of 14 days complete

    In this preview, check off each day as you finish it to see your progress while you work. Members will receive access to the member version, where challenge progress saves to your account between visits.

    Challenge 04 · Automate one process, rung by rung

    The Automate Your Onboarding Challenge: Client or New Employee

    This is the challenge the rest of the app has been building toward: take one onboarding process, a new client coming in the door or a new employee joining the team, and move it up the Five Rungs one automation at a time, measured against the baseline you set yourself. A client's onboarding runs from signed engagement to a working file; a new hire's runs from accepted offer to a first productive week. The paperwork, the chasing, and the hand-offs in between are the same shape either way, which is why one ladder carries both. The moves below walk a small accounting firm bringing clients on, so you can see the shape before you start; read "new hire" wherever you read "client" and the same moves fit the day a person joins. Your numbers will differ from the firm's; producing them is the point. Every number in this walk is an Illustrative target to measure against, not a reported client result. Check each move off on the clock as the automation goes live on real clients or real new hires. Before Move 1, answer one question honestly: which AI tools did your staff open this week, and on whose accounts? If you cannot answer it, that gap is your first baseline finding.

    0/7moves done

    Start at Move 1. Measure before you automate.

    Your reading so far

    Nothing checked off yet. Move 1 is a stopwatch and one honest page: time today's onboarding end to end before you change a thing.

    0 of 7 complete

    Done means the automation is live on a real onboarding, a new client or a new employee, with its checkpoint in place, not planned, demoed, or promised by a vendor. Tap a move again to undo it. Like everything in this preview, the clock keeps score for this visit only. Members will receive access to the member version, where challenge progress saves to your account.

    A Foundation Assessment is this challenge scoped to your business: your onboarding process, client-side, hiring-side, or both, with your baseline, your rung, your data rules, and your test plan, in writing, before anything is purchased.

    Instruments, not opinions

    Three Tools to Locate Yourself

    Every good model ships with tools to take a reading. These three mirror the book's own diagnostics: find your rung, count your unmanaged exposure, and trace exactly where your data goes when someone asks an outside AI for help.

    Find Your Rung

    Six questions about one real task in your business. Answer for the task, not for the company brochure, and the tool will place it on the ladder with the next move the book prescribes.

    Your reading

    Rung 1, AI as a Tool

    Shadow-AI Exposure Audit

    Check every statement that is true in your business today. Each one is an unmanaged data flow or a missing control, drawn from the book's own checklists. The count is your real starting point.

    Your reading

    0 exposures checked

    Trace One Prompt

    Follow a single employee question from keyboard to consequence. This is Chapter 4 walked step by step, first on the path most businesses are actually on, then on the approved path the book builds.

    Got an objection? It has an answer

    Questions Owners Actually Ask

    The objections owners raise most, taken one at a time and answered the way the book answers them: directly, with the limit of each answer stated too. If yours is not here, the honest next step is a Foundation Assessment, not a bigger brochure.

    Is this just ChatGPT with extra steps?

    No, and the extra steps are the point. ChatGPT, Claude, and tools like them are the capability. The book is about everything around the capability: which tasks it may touch, which information it may see, where the work runs, who approves the result, and how you prove it helped. A governed external service is a legitimate answer for plenty of workloads. An unexamined one is how customer records end up in places nobody chose.

    Do I have to climb all five rungs?

    No. The rungs are levels of delegated work for a particular process, not a maturity score and not a purchase list. Some businesses will get the most from an approved assistant and fixed reminders, and should stop there. Each rung must earn its place with measured value and reliable control. The framework's job is to tell you which level a task actually needs, including when the answer is the lowest one.

    Is a higher rung better?

    Not automatically. A higher rung means the business has accepted more responsibility for supervising delegated work. An AI employee that mishandles exceptions is worse than an AI tool that drafts well. Move upward only when the process, controls, and risk justify it, and when the measured benefit beats the rung below.

    What does "private" actually mean here?

    It is a control decision, not a slogan. Where does the work run, who controls the information, permissions, workflows, and approvals, and who is accountable when something is wrong? Depending on the workload, the right answer may be an approved external AI service, a correctly sized client-controlled private environment, or both. A dedicated deployment is one option, not the automatic next step, and the book says so plainly.

    Will a private system guarantee my data never leaks?

    No, and walk away from anyone who says otherwise. The book names that exact claim, perfect accuracy, zero exposure, automatic compliance, as a red flag when it lacks a defined scope and evidence. Dedicated infrastructure changes some shared-application risks. It can still suffer defects, compromised credentials, and misconfiguration. What you are buying is chosen controls, tested failure behavior, and records, not immunity.

    Is the AI employee going to replace my people?

    Rung 5 is a name for a system assigned recurring approved work. It is not a person and it does not assume human accountability. It handles routine tasks inside defined limits and brings exceptions and important decisions to a named human owner. Employment judgment, regulated decisions, and the conversations only a person should have stay with people. That boundary is a chapter of the book, not a footnote.

    What if the AI is confidently wrong?

    It will be, sometimes. A plausible answer can omit a prerequisite that matters in the real system. That is why the lower rungs keep a person reviewing output before anything consequential happens, why testing uses representative data and stated pass criteria before sign-off, and why higher rungs are gated on permissions, approval requirements, and tested failure behavior. The method assumes error and designs for catching it.

    We already use AI informally. Are we in trouble?

    You are in the normal position, which is exactly why the book starts with an inventory. Check where AI features are enabled in your CRM and business systems, who has access, and what information is flowing where. Then decide, on purpose, which tools are approved for which information. The exposure is rarely the tool. It is the absence of the decision.

    My industry is regulated. Does any of this apply?

    It applies most there, with a caveat the book is careful about: HIPAA permits appropriately governed cloud services, PCI DSS has its own validation path, and a compliance work package does not make a business legally compliant or guarantee an insurer accepts it. Controls get matched to your actual obligations, and qualified professionals still provide legal advice and independent audits. Anyone who sells you automatic compliance is selling you a future finding.

    What will this cost me?

    Less than the brochure version of AI, more than the free version. Every engagement starts with a scoped Foundation Assessment, and the written proposal, not a book, an app, or a sales call, states what will actually be delivered and what it costs: the work itself, plus equipment, cloud, and model use priced separately. The honest comparison includes the cost of the work staying manual and the plausible cost of an incident, without pretending a purchase eliminates risk.

    How long before I see anything real?

    Rung 1 and Rung 2 wins are measured in days: an approved assistant drafting under review, one fixed rule moving one piece of work. The discipline is in the loop around them: pick a measurable task, test the smallest useful version with a few staff, compare actual time and errors against the starting figures, then decide whether to extend. If a vendor's timeline skips the measuring, the timeline is the product.

    What is the certificate, honestly?

    A dated record that four baseline conditions were assessed for one client environment: a single client environment, client control of administrative access, records and recovery checks, and client-approved AI settings. The implementing business may conduct the assessment itself, and that is disclosed. It is not an independent audit, not government accreditation, not a legal compliance determination, and not a guarantee against data exposure. It records what passed, on a date, at a stated scope. Section below lists the four checks and the full set of things the certificate does not claim.

    Why should I act now instead of next year?

    Three clocks are already running. Your staff is already using AI, with or without your approval. Regulation has effective dates, including January 1, 2027 in Colorado. And every undocumented process in your business is knowledge that walks out the door a little more each year. Starting means a measured first task under your control, not a transformation program. Next year's starting line is behind this year's.

    The proof standard, applied to ourselves first

    What "Certified" Checks, and What It Does Not

    Chapter 24's assessment is deliberately unglamorous: four baseline conditions, a date, a stated scope. Next to it, Chapter 17's ten warning signs for any AI vendor, including the ones selling private systems. Hold every provider to both lists. Start with this one.

    The Four Assessment Checks

    The Certified Private AI Assessment evaluates these baseline criteria for a defined client environment, and records the result with its date, scope, and limits.

    1

    One client environment

    The assessed system is a defined environment for one client, not an undifferentiated shared pool where tenancy boundaries are assumed rather than shown.

    2

    Client control of admin access

    The client holds and controls administrative access to their own environment. The implementer works under the client's authority, not the other way around.

    3

    Records and recovery checks

    Processing events are recorded, and backup and recovery are checked as operating practices, not assumed from a product brochure.

    4

    Client-approved AI settings

    The AI configuration in use, destinations, models, retention-relevant settings, is the one the client approved, and changes to it are visible.

    What the certificate is not
    • Not an independent third-party audit
    • Not a government accreditation
    • Not a legal or regulatory compliance determination
    • Not a guarantee against data exposure
    • Not proof that optional features, such as information masking, are installed

    Ten Red Flags to Walk Away From

    Chapter 17, verbatim in substance. These apply to dedicated deployments and hosted services alike. One flag is a question to resolve. Three is a vendor to replace.

    1. The provider cannot describe where data is processed, stored, backed up, or transmitted.
    2. Access and retention claims are not reflected in contracts or demonstrated settings.
    3. The provider refuses representative testing under reasonable confidentiality and security arrangements.
    4. Claims of perfect accuracy, zero exposure, or automatic compliance lack a defined scope and evidence.
    5. Broad permissions are requested without a task-specific justification or a revocation procedure.
    6. No one can identify who owns incidents, patches, alerts, and recovery after deployment.
    7. There is no tested failure behavior when a model, filter, connector, or approval service is unavailable.
    8. Pricing or effort estimates omit dependencies, usage charges, exclusions, or change-control terms.
    9. A deadline-driven sales tactic prevents technical and contractual review.
    10. Cancellation, data export, credential transfer, and deletion are left undefined.
    Challenge 03 · Chapter 17, worked as a checklist

    The Red Flags Challenge: Work Them Against Your Vendor

    The ten warning signs from the proof standard above, turned into work you can finish. Take your current AI vendor, or the one pitching you this week, and check each flag in order. Tap a flag when you have actually verified it against a contract, a settings screen, or a written answer. The clock on the left and the Red Flags dial in Track Your Climb both move as you work. One flag is a question to resolve in writing. Three flags is a vendor to replace. This section does not save between visits in this preview. Members will receive access to the member version, where this review saves to your account.

    0/10flags reviewed

    Start at Flag 01. Work top to bottom.

    Your reading so far

    No flags reviewed yet. Pick your main AI vendor and start with where its data is processed, stored, backed up, and transmitted.

    0 of 10 reviewed

    How to use this honestly: reviewed means you saw the evidence, not that a salesperson said the right words. If you cannot get the evidence, leave the flag unchecked and write down who owes you the answer. Bring the count to your AI Opportunity Call and we will work the open flags first.

    How to read the evidence

    Sources and Notes

    Bracketed numbers in the book point here. A story labeled illustrative shows how to think through a decision; it is not a measured customer result. Firsthand experience is marked as firsthand. The 17 sources below are the book's own, reviewed September 23 and 24, 2026, followed by the independent research cited in The Outside Evidence section.

    1. The author's firsthand account of early network operations work at a Houston telecommunications company.
    2. Amazon Web Services, Amazon EC2 Dedicated Instances documentation, on shared tenancy versus dedicated configurations. docs.aws.amazon.com
    3. Carlini et al., "Extracting Training Data from Large Language Models," USENIX Security Symposium, 2021. usenix.org
    4. US Department of Health and Human Services, Guidance on HIPAA and Cloud Computing. hhs.gov
    5. US Department of Health and Human Services, Guidance Regarding Methods for De-identification of Protected Health Information. hhs.gov
    6. PCI Security Standards Council, Merchant Resources and PCI DSS materials. pcisecuritystandards.org
    7. European Union, Regulation (EU) 2016/679, General Data Protection Regulation. eur-lex.europa.eu
    8. OpenAI, "March 20 ChatGPT outage: Here's what happened," March 2023. openai.com
    9. National Institute of Standards and Technology, AI Risk Management Framework: Generative AI Profile, NIST AI 600-1, July 2024. nvlpubs.nist.gov
    10. National Institute of Standards and Technology, CSF 2.0 Profiles. nist.gov
    11. National Institute of Standards and Technology, AI Risk Management Framework 1.0. airc.nist.gov
    12. New York City, Local Law 144 of 2021, Automated Employment Decision Tools. nyc.gov
    13. US Equal Employment Opportunity Commission, "What is the EEOC's role in AI?" April 2024. eeoc.gov
    14. Colorado General Assembly, SB26-189, Automated Decision-Making Technology, signed May 14, 2026; key obligations begin January 1, 2027. leg.colorado.gov
    15. PCI Security Standards Council, "What is a PCI DSS Self-Assessment Questionnaire?" FAQ 1215. pcisecuritystandards.org
    16. Microsoft Learn, Role Based Access Control for Applications in Exchange Online. learn.microsoft.com
    17. Microsoft Learn, Overview of Selected Permissions in OneDrive and SharePoint. learn.microsoft.com

    Independent research and reporting cited on this page

    Not part of the book's source list. Cited in The Outside Evidence section above, with statistics as published by each source.

    • Brynjolfsson, Li, and Raymond, "Generative AI at Work," NBER Working Paper 31161, published in the Quarterly Journal of Economics, 2025. nber.org
    • Dell'Acqua et al., "Navigating the Jagged Technological Frontier," field experiment with Boston Consulting Group, Harvard Business School. d3.harvard.edu
    • Microsoft and LinkedIn, 2024 Work Trend Index, survey of 31,000 people in 31 countries. blogs.microsoft.com
    • IBM, Cost of a Data Breach Report 2025, analysis of 600 organizations breached between March 2024 and February 2025. ibm.com
    • Bloomberg News, "Samsung Bans Staff's AI Use After Spotting ChatGPT Data Leak," May 2023, reporting Samsung's internal memo and staff survey. moneyweb.co.za
    • McKinsey and Company, "The State of AI in 2025: Agents, Innovation, and Transformation," global survey of 1,993 respondents. idm.net.au

    Business examples labeled illustrative composites explain decisions and failure modes; they are not client case studies. Laws, provider documentation, and service terms change. Confirm the current requirements for a specific implementation before relying on a technical or legal description. This page mirrors the book's model app, the Flat Earth Sun, Moon and Zodiac Clock by David Weiss (Blue Water Bay), whose feature set is documented at AppRecs and Consumer Rights Wiki.

    Chapter 26, your next step

    Start With a Conversation, Not a Purchase

    What the business actually does, where the time is really going, what data has to stay private, and whether a Private AI Foundation Assessment makes sense before anything else moves forward. That conversation becomes a scoped assessment: the selected workflow, the appropriate rung, the data and approval rules, the test plan, and how success will be measured.

    • 01The task you want to improve, in one sentence.
    • 02How you measure it today, even roughly: hours, errors, or turnaround time.
    • 03The information that must stay private while the work gets done.

    If you ran the tools above, bring your rung reading and your shadow-AI count. If you did not, the call starts there instead. Either way, you leave with a written next step or a clear reason to wait. No purchase decision is asked for on the call.