Blog

Artificial Intelligence: Are We as Ambitious About Its Possibilities as We Are Vigilant About Its Risks?

Discussions surrounding artificial intelligence sometimes give the impression that we must choose between enthusiasm and caution. Some emphasize its capacity to transform the economy, science, organizations, and work, while others insist on the risks that ever more powerful systems can create. For executives, however, this opposition is far less useful than the question of how to make progress on both dimensions at once.

In an interview with Fortune, Lila Ibrahim, Chief AI Readiness Officer at Google DeepMind, brings the reflection back to two concerns that are particularly relevant for organizations: are we doing everything we can to reduce the risks associated with artificial intelligence, and are we also doing everything we can to maximize the possibilities it offers us?

These two questions should be asked together. AI is becoming powerful enough to profoundly transform the way organizations work, make decisions, use their knowledge, and develop their capabilities. That power simultaneously demands governance, a security architecture, and organizational thinking on a par with what it now makes possible.

At Quantum Beyond, we consider this dual progression one of the best indicators of maturity in artificial intelligence. A mature organization seeks to increase the value it can create with AI while developing its capacity to understand, govern, and secure this new operational power.

The possibilities offered by artificial intelligence are already considerable. It can accelerate research, analyze volumes of information far exceeding human capacity, automate certain tasks, assist specialists, improve decision-making, and give relatively small organizations access to capabilities that previously required far greater resources.

The arrival of AI agents amplifies this transformation. Systems can now receive an objective, use tools, consult several sources of information, interact with applications, and carry out a succession of actions in order to reach a result. Google DeepMind notably highlights the development of agentic capabilities in fields as varied as cyber defense, scientific discovery, and product development.

For organizations, this evolution opens up considerable room to maneuver. Part of the administrative work can be automated, specialists can be assisted in their research, scattered knowledge can become accessible far more quickly, and some processes can be executed at a speed that was hardly conceivable before. Teams can progressively learn to work with digital capabilities available at all times to research, analyze, prepare, verify, or execute certain activities.

Maximizing these possibilities nonetheless requires far more than buying licenses or adding an AI assistant to the tools already in use. The organization must determine where artificial intelligence can genuinely create value, which processes deserve to be rethought, which knowledge must be structured, which skills must evolve, and which activities can be automated, assisted, or profoundly transformed.

It must also measure what it obtains. An increase in the number of queries, agents, licenses, or automations does not automatically constitute an improvement in performance. Maturity requires linking the use of technology to results: quality, productivity, speed, decision-making capacity, client experience, reduction of work without added value, improvement of available knowledge, or the creation of new organizational capabilities.

It is from this perspective that Quantum Beyond approaches AI Adoption and AI Organizational Transformation. The Qb Knowledge Standard – AI Readiness & Knowledge Governance prepares the knowledge that systems need, while AI Onboarding structures the operational integration of agents. These disciplines pursue a single objective: enabling the organization to make greater use of artificial intelligence capabilities in a concrete and productive way.

This ambition becomes inseparable from the second question raised by Lila Ibrahim: are we developing our capacity to master the risks that accompany this power sufficiently?

These risks already exist at a scale perfectly familiar to companies. An AI can receive confidential information. An agent can access an email inbox, a CRM, a cloud environment, or financial data. A system can produce an erroneous recommendation that influences an important decision. An automation can repeat an error thousands of times before anyone detects it, while an agent with overly broad permissions can carry out an action going far beyond its user's original intent.

The more we increase a system's capabilities, the more important the distinction becomes between what it can do and what it is authorized to do. An organization might have an agent technically capable of sending emails, modifying financial data, or deleting files without necessarily wanting to automatically grant it each of those authorities.

This distinction between capability and authority should become fundamental in the governance of agentic AI. Technology determines what is possible. The organization must determine what is permitted, in what circumstances, under what conditions, and with what level of supervision.

Current work on AI safety reflects this evolution. Google DeepMind notably uses its Frontier Safety Framework to identify the emergence of capabilities likely to create severe risks and to plan various measures when certain thresholds are reached. Interactions between agents are also an important area, since individually controlled systems can, when they collaborate, produce behaviors or chains of actions that are harder to anticipate.

At the organizational level, the NIST AI Risk Management Framework offers a complementary approach by integrating questions of trustworthiness and risk management into the design, development, use, and evaluation of artificial intelligence systems. The resulting principle is particularly useful: AI security must progress alongside its adoption rather than be added once systems are already deeply integrated into operations.

This is precisely where ambition and vigilance stop being contradictory. An organization that better masters its environment can reasonably allow its systems to do more.

An agent must be able to access the information it needs for its work without automatically obtaining access to all of the company's knowledge. It can use the tools required for its mission without receiving permanent administrative privileges. Some operations can be automated, while others trigger human validation based on their potential consequences.

Agent-specific identity, least privilege, Zero Trust, Continuous Trust, segmentation, logging, behavioral monitoring, and the ability to quickly revoke access therefore do not serve only to restrict AI. These mechanisms create the conditions that make it possible to grant it more capabilities once the level of mastery is sufficient.

This relationship between control and capability deserves to be underlined. An organization that knows precisely what an agent can consult, which tools it can use, which actions it can perform, and how to interrupt its operation has more latitude to entrust it with responsibilities than an organization that does not know these things.

Hypersecurity makes it possible to extend this thinking to the ecosystem in which agents operate. With agentic AI, risk no longer resides solely in the model. It is also found in identities, knowledge, APIs, applications, vendors, data, permissions, and interactions between several systems. Each of these elements can be reasonably secured individually while their combination creates new paths of action.

The challenge is therefore to observe the architecture as a whole and how it evolves. Hypersecurity connects the disciplines of cybersecurity to governance, resilience, knowledge, technological dependencies, and sovereignty in order to maintain a continuous capacity to anticipate, withstand, detect, contain, recover, and adapt. In an agentic environment, this vision becomes particularly important since a system's capabilities can evolve without its official role having changed.

A model is updated, an application is connected, an API evolves, an agent receives a new tool, a data source becomes available, or two previously independent agents begin to collaborate. A permission that was appropriate at deployment can thus become excessive a few months later.

Governance must consequently become dynamic. This is what Quantum Beyond calls agentic cybervigilance: maintaining a sufficiently precise knowledge of what agents can actually do, observing their behavior, and reassessing their identities, permissions, interactions, and capabilities as their environment evolves.

This vigilance will become all the more important as organizations move from a few easily identifiable agents to dozens, hundreds, or eventually more agentic capabilities distributed throughout their operations. The question will then no longer be only whether each model is sufficiently secure. It will be necessary to understand whether the ecosystem in which all these systems have been placed remains under control itself.

The other essential condition for an ambitious use of AI concerns organizational knowledge. A company may hold decades of experience scattered across its documents, databases, procedures, emails, and, above all, in the memory of its employees. That knowledge may contain contradictions, may have become outdated, may remain implicit, or may be difficult to access.

Connecting an artificial intelligence to that environment does not automatically turn all of that information into reliable knowledge. An AI capable of accessing bad information more quickly can simply produce a bad answer more quickly.

The Qb Knowledge Standard – AI Readiness & Knowledge Governance aims precisely to prepare this essential layer. Before asking AI systems to understand an organization, its information assets must be made sufficiently structured, reliable, and governed to be used correctly. This approach simultaneously increases the potential of artificial intelligence and reduces the risks associated with information that is erroneous, contradictory, obsolete, or inappropriate.

We find the same relationship once again: the quality of governance makes it possible to increase capability. Better organizational knowledge improves the relevance of systems while strengthening control over what they can know and use.

This logic also applies to autonomy. At Quantum Beyond, AI Onboarding treats autonomy as a capability that must be proportional to the role, the risk, and the results observed. The agent can start by working in a controlled environment, observing a process, assisting a person, or producing recommendations. Certain actions can then be granted to it with human approval before greater autonomy is considered when its behavior and results justify it.

This progression makes it possible to avoid two equally unproductive situations: keeping powerful systems indefinitely in roles so limited that they create little value, or immediately granting them an autonomy the organization does not yet have the means to govern.

The objective is therefore not maximum autonomy. It is to determine the optimal level of autonomy for each responsibility. A repetitive, reversible, low-risk task may justify substantial automation, while a decision producing major legal, financial, or human consequences may require explicit intervention. Between the two lies an entire continuum of supervision and authority that the organization can adapt.

This approach brings us back to the very notion of AI maturity. A mature organization should not be measured solely by the sophistication of the technologies it deploys. It should also be assessed on its ability to transform its processes, prepare its knowledge, develop its teams' skills, measure the value produced, govern its agents, control their identities, and evolve their autonomy.

Maturity lies precisely in the ability to advance these dimensions together. The more capable the organization becomes of governing AI, the more reasonably ambitious it can be in using it. And the more ambitious it becomes, the more it must strengthen the mechanisms that allow it to retain that mastery.

This progression must ultimately remain oriented toward people. Lila Ibrahim underlines the importance of using these technologies to improve the world we live in and to increase human potential. This perspective connects directly with the way Quantum Beyond approaches transformation through artificial intelligence.

We do not simply want to help organizations accumulate AI tools. We want to help them become better because of them: enabling employees to accomplish more, making knowledge more accessible, reducing certain tasks without added value, giving specialists more time to exercise their expertise, accelerating problem solving, and creating new organizational capabilities.

This ambition also implies protecting people, their information, their autonomy, and their capacity for judgment. Google DeepMind's work on the risks of manipulation by artificial intelligence systems is a reminder that security does not concern only data and infrastructures. As conversational systems become more convincing and personalized, understanding their ability to influence human behavior also becomes a matter of security and governance.

Technology becomes genuinely useful when it increases human possibilities while preserving our ability to decide the objectives it should pursue and the limits within which it may act. A model's performance, the number of agents deployed, or the proportion of tasks automated remain means. The value created for people and for the organization is the end.

The two questions proposed by Lila Ibrahim ultimately offer an excellent maturity test for organizations investing in artificial intelligence today: are we doing enough to exploit its possibilities, and are we doing enough to master the risks that accompany this new capability?

These questions are best examined together because they reinforce one another. An organization that structures its knowledge can obtain better results while reducing errors. An organization that masters the identities and permissions of its agents can grant them more responsibilities. An organization that measures performance can identify the areas where autonomy genuinely produces value. An architecture capable of detecting and containing unexpected behaviors makes it possible to experiment with greater confidence.

At Quantum Beyond, this relationship between ambition and vigilance connects directly with AI Adoption, AI Organizational Transformation, AI Onboarding, the AI Governance Office, the Qb Knowledge Standard, IAM, Zero Trust and Continuous Trust, agentic cybervigilance, cyber resilience, and Hypersecurity. These disciplines do not constitute an accumulation of controls around artificial intelligence. They form the architecture that allows the organization to progressively exploit more of its capabilities while retaining the necessary understanding and control.

The decisive question will therefore probably not be how far artificial intelligence can go. Its capabilities will continue to evolve and we will regularly discover new ones. For organizations, the far more useful question is to determine how far they can go with it while simultaneously developing their own capacity to understand it, govern it, and intelligently integrate it into human work.

It is in this shared progression that true maturity probably lies: becoming more ambitious because we are better prepared, and becoming more vigilant precisely because we want to go further. Artificial intelligence can considerably increase organizations' possibilities. Our responsibility is to advance, along with it, our capacity to ensure that humans remain the beneficiaries of this transformation.