A while back I met an old colleague for cocktails. We do this every so often - two people who have seen enough server rooms and steering committees to know that the best incident reviews happen over a Negroni.
He was in a great mood. His company's vibe coding (quickly developing software using AI like Claude without writing (or sometimes even understanding) the code itself) adoption was through the roof. And not just among developers - consultants, architects, support engineers, basically anyone with a pulse and a Claude license was building tools. Management was celebrating. They threw around numbers like trophies: one engineer burned through 100 dollars a day in tokens. Applause. High fives. Slide decks.
And honestly? Fair enough. If a 100-dollar-a-day token bill produces a tool that saves ten hours of engineering time per week, that's the cheapest employee you ever hired. I am not here to rain on token budgets. Fun fact on the side: "vibe coding" went from a casual Karpathy tweet to Collins Dictionary Word of the Year within roughly twelve months. That's faster adoption than most companies manage for a new expense tool.
But while my colleague was celebrating, I was doing what 20+ years in support trenches trains you to do: listening for the alarm underneath the applause.
Ten Things Your Company Should Never Delegate to a Machine, Ranked by Blast Radius
Classic scenario: an executive pasted an entire acquisition contract into a free public chatbot. He wanted a summary because reading twelve pages was, quote, "not a good use of his time." He got a lovely summary. He also got a confidential M&A document uploaded to a third-party server, which - depending on how you read the NDA he had personally signed - was somewhere between "career-limiting" and "please forward all future correspondence to my lawyer."
The best part: the deal was so straightforward that his own legal counsel could have summarized it in the elevator. He didn't save time. He converted a five-minute conversation into a compliance incident.
Everyone asks what AI can do for their company. Almost nobody asks the more profitable question: what should it never do? So let's invert the problem. If I wanted to guarantee an AI disaster, what would I deploy? Here's the list. Count how many your org is already doing. Two or fewer is excellent. Five or more - well, it was nice knowing you.
The hard no's: where lawyers get involved
1. Feeding confidential or regulated data into unvetted tools. GDPR data, health records, trade secrets, customer contracts. Pasting them into a public chatbot is publishing with extra steps. There's no attorney-client privilege for your chat history - it can be subpoenaed, and courts have already gone fishing in exactly those waters. The chatbot will never sit in the deposition. You will. That's the whole test right there: never delegate a decision to something (or someone) that can't be fired, fined, or sued for it. The AI has no skin in the game. Yours is the only skin available.
People occasionally corner me after a talk or in a comment thread and ask, half accusing: "So you're against AI?"
No. Clear no. I think AI is the future. I also think nuclear energy is one of the greatest inventions of the last century. You can build power plants that bring cheap electricity to millions of people. Or you can build the other thing. The technology doesn't care. The people wielding it decide the outcome - and right now, a lot of them are holding the hammer by the wrong end and wondering why the nail keeps laughing at them.
Being honest about a technology's capabilities, shortcomings, and risks is not opposition. It's the minimum requirement for using it well. Nobody calls a nuclear safety engineer "anti-nuclear."
The number that should end every AI keynote
A study published by the National Bureau of Economic Research surveyed almost 6,000 executives across multiple countries. Roughly 90% of companies implementing AI reported no discernible impact on productivity or employment. Not "underwhelming impact." No measurable effect at all. PwC's global CEO survey landed in the same crater: 56% of CEOs saw neither increased revenue nor decreased costs from AI after a year of deployment.
Every two weeks, like clockwork, I walked to the kiosk and bought the same magazine. This was back when "the cloud" still meant rain. The pages were glorious. Linux distribution shootouts - Debian vs. SUSE vs. Fedora vs. Ubuntu, complete with benchmark tables nobody asked for and everybody loved. Firewall configs. Server hardware reviews. How to set up remote access so you could SSH into your home box from the office and play terminal Tetris when the boss wasn't looking. How to share your "totally legally acquired" movie collection across the family network. Best open-source database. Troubleshooting tips that actually worked.
It was nerd church. I read every word, including the ads.
Then something shifted. First subtle, then about as subtle as a forklift through a glass door.
The Linux comparison shrank to half a page. Then a quarter. Then a sidebar. In its place: best LCD monitor for Photoshop. Best smartphone for the outdoorsy type. Best printer for home photo printing. Music apps you "cannot live without." Best home cinema projector. Dolby surround systems that cost more than my first car.
The magazine hadn't been cancelled. It had been quietly lobotomized. Same logo, same price, same kiosk. Different soul. It went from "build it yourself" to "buy this and consume." And teenage me was annoyed because none of it helped my career. I didn't want to know which speaker thumped hardest, primarily because I didn't have any money to buy one. I wanted to know how to make the server stop falling over.
If your European tech company is not making these demands of every vendor, you are subsidizing the offshoring of your own economy and gambling with your sovereignty. I once sat through a postmortem with a German SaaS company that had a Severity 1 outage lasting 38 hours. Their vendor had a platinum support contract with "30-minute first response" but the first response was from Bangalore, asking, "Have you tried restarting the service?" After escalating for 6 hours, they got someone who knew the product - but that someone was in the US and needed to wake up. The contract had no teeth, the data was on AWS us-east-1, and the vendor's escalations went through three continents before reaching someone with decision power.
This is not a support experience. It is a hostage situation.
If you are a larger European tech company, you are actually in a position to make demands. You have the leverage. Use it. Here is the minimum you should enforce with every vendor and service provider. Do not apologize. Do not negotiate on the top items.
Top Priority - Non-Negotiable Core
Data hosted exclusively in Europe
Your PII, your customer data, your telemetry, your configuration, your logs - everything must be stored and processed within the EU. That means no data replication to US regions, no backup in Israel, no disaster recovery in Singapore unless it meets the same standard. The US has the Cloud Act and the Patriot Act. Europe has GDPR, and it is the strongest data protection framework on earth, but it only works if your data never leaves. Include contractual language that forbids data transfer to any territory without adequate protection, with explicit penalties for violating data residency.
Why Smart Companies Are Mad to Trust Any Foreign Software With Their Crown Jewels
You know the date. A single file pushed by a high-profile cybersecurity vendor turned millions of computers into expensive paperweights. Airlines grounded flights. Hospitals stopped surgeries. Banks locked their vaults. It was the largest digital outage in history.
That file ran at the deepest level of the operating system. It could read every byte of memory, every keystroke, every piece of intellectual property on those machines. And it was delivered silently, automatically, without any human approval.
Now ask yourself: how many other files like that are already on your systems?
This isn't about one company or one country. It's about a structural vulnerability that every organization faces when it outsources its security and operational software to vendors with close ties to any foreign intelligence apparatus. Some of these vendors are based in democracies, which is no guarantee that they don't spy on you or aren't concerned about your sovereignty behind closed doors. Some are based in countries with documented programs to use commercial software as offensive tools. Some have even been caught using shell companies to corrupt the supply chain itself.
You don't need to know which ones. You only need to know that the risk exists, and the only safe move is to reduce your dependency.
I was eighteen, doing my civil service in Germany. My assignment was a temporary substitute gig - a few weeks covering for someone's vacation. My patient was a man in his early sixties, sitting in a wheelchair, partially paralyzed on one side. He needed help with breakfast. He needed help with the morning toilet routine. Not glamorous work, but someone had to do it.
Every morning started the same way. His wife would prepare a modest portion of bread, cheese, and cold cuts. And every morning he would insist he was still hungry. She would hold the line - firmly, not cruelly - explaining that wheelchair-bound patients gain weight easily, that it would hurt his rehabilitation, that the doctors were clear about his diet. He would argue, push back, and sometimes sulk like a child caught sneaking cookies. She would stay calm and patient, but she never gave in.
I watched this dance and felt uncomfortable. Here was a grown man, a man who had done important things, being treated like a little boy about toast and butter. It felt degrading. But she was right. And he knew it. That only made it worse.
The daily rehabilitation sessions were brutal. He had to relearn how to walk. A man in his early sixties, trying to convince his paralyzed side to cooperate, lifting one leg with his hands, sweating through the simplest exercises. You could see the frustration in his eyes. He had climbed mountains once. Now he struggled to shuffle ten feet with a walker.
My wife loves our lawn mowing robot. She sees a robot quietly mowing the lawn and thinks "Finally, less work and a pretty lawn." I see a very expensive, very opinionated Roomba with blades that decides on its own which parts of the garden are worth mowing.
The marketing is excellent. It promises a smart, autonomous, AI-powered lawn butler that will handle everything while you sip coffee. The reality is a machine that regularly gets stuck on paths it has driven over a hundred times, parks itself under the car (because apparently cars are not obstacles), and occasionally loses its blades so you can never walk barefoot in your garden ever again.
It also has a special talent: finding the exact same spot to get stuck in, over and over. You rescue it, send it back to the charger, and it immediately heads straight back to the same stupid corner like it's on a personal mission. The RTK antenna is so sensitive that losing the signal makes it panic - but instead of waiting patiently like any sensible machine, it tries to start mowing anyway. And don't even think about tall grass or paths narrower than one meter. The robot itself is only 60 cm wide, yet it still needs a full meter of clearance. So I still end up manually mowing between the raised beds like some kind of 19th-century peasant.
(Why the Real Fight Is USA vs China - And What That Means for Everyone Else)
I've spent my entire career in Western enterprise tech support. For a long time the narrative felt solid: Europe (especially Germany) still stood for precision engineering, rock-solid quality, and thoughtful innovation. "Made in Germany" wasn't marketing - it was a promise.
Lately that promise has started to feel like a vintage sticker on a product that's quietly assembled somewhere else.
In the past ten years, Europe has produced almost no globally dominant tech companies. No new Googles, no new Amazons, no new Huaweis. The biggest "wins" are standards like USB-C (which is genuinely useful) and a handful of strong deep-tech or B2B players. But when it comes to consumer platforms, cloud scale, AI infrastructure, or the kind of companies that define the modern economy - the scoreboard is clear: it's USA vs China, with Europe mostly watching from the stands.
This isn't about talent. Europe still produces excellent engineers, researchers, and operators. It's about systems.
Early in my 1st-level support days I got the classic "we lost the admin password" ticket.
Business-critical application. Low-level software. No backdoor, no recovery flag, no magic command. The only way forward was the one we always gave: reinstall and restore the data from backup. I sent the standard template, closed the ticket in my head, and moved on.
This customer didn't close it.
He pushed back hard, so I scheduled a call. On the line he sounded desperate in a way most tickets never reach. I walked him through the security reasons again, step by step, expecting the usual frustrated "fine, we'll do the reinstall." Instead, he went quiet for a long second and then told me the real story.
One of his colleagues - the only guy who managed the entire infrastructure - had died in a car accident a few weeks earlier. The laptop with every password, every recovery key, and every piece of documentation went up in flames with the car. No off-site copy. No shared vault. No second person who knew the master credentials. The whole company's core systems were now running in a zombie state: accessible to nobody, restorable by nobody.