How Do Organizations That Adopt AI Remain Viable?

For the last few years, the question most people have asked about AI is whether it works.
Does it give accurate answers?
Does it save time?
Does it deliver a return on investment?
These are reasonable questions. They are also incomplete.
There is a deeper question that deserves our attention.
How do organizations that adopt AI remain viable?
I have been reflecting on this question while revisiting an article I wrote on Cybernetic Control. That article was written for risk and compliance. Its principles speak directly to what organizations face as they adopt AI.
What Viable Means
Most people hear the word viable and think of a system that works. A viable business makes money. A viable product meets a need. A viable plan can be carried out.
Stafford Beer gave the word a stronger meaning. For Beer, a viable system is one capable of maintaining its existence in a changing environment. It senses what is happening. It adapts. It regulates itself and stays within acceptable limits as conditions change. It continues to achieve its purpose over time.
A system can work today and fail tomorrow when conditions shift. Viability is the capacity to keep working as the world changes.
Viability is very close to governance. Governance exists to keep an organization on mission, meeting its obligations, and capable of adapting to what comes. It sets direction, assigns authority, and regulates the organization so that it stays between the lines.
Beer made this connection explicit in his Viable System Model. The functions that monitor performance, look outward to the future, and define identity and purpose are the functions of governance. To ask whether an organization is viable is to ask whether it is well governed. The question of AI viability is a question of governance.
The Organization Is the System
Governance applies to the organization as a whole, and AI is part of that whole. AI is deployed within an organization, governed by it, and accountable through it. The organization defines its purpose, supplies its data, integrates it into processes, and answers for its outcomes.
An AI model may perform well in testing. Once deployed, it becomes part of a larger system that includes people, processes, technology, and obligations to stakeholders. Its behaviour affects customers, employees, environment, and the public.
The question of viability belongs to the organization.
When AI becomes part of how an organization operates, does the organization remain capable of meeting its obligations and achieving its mission?
The Law Behind Viability
Ross Ashby gave us the law behind viability. His Law of Requisite Variety states that only variety can absorb variety. A control system must have at least as much variety as the system it seeks to regulate.
In Cybernetic Control, I described four principles that follow from this law:
When the variety of the environment exceeds the capacity of a system, the environment will dominate.
The larger the variety of actions available to a control system, the larger the variety it is able to compensate.
A control system can only regulate what its channels of communication allow it to see and act on.
The response time of the control system must meet or exceed the speed of change.
These principles explain why some controls are effective and others are not. They apply to any organization that must stay between the lines on its way to mission success.
AI Adds Variety and Uncertainty
AI adds enormous variety to the organization. It creates variety in what it outputs and in how it acts within the business. Together, these create significant uncertainty.
Traditional software are deterministic. The same input produces the same output. Its behaviour can be specified, tested, and verified.
Consider what AI outputs. Its outputs are probabilistic. Its behaviour can change with context, with data, and over time. Its reasoning is often opaque, even to those who build it.
Consider how AI acts. It acts in more ways than the systems it replaces. It writes, recommends, decides, and executes. It can choose among many paths to reach a goal, including paths no one anticipated. Agentic AI chains these actions together across tools and systems on the organization's behalf at machine speed. Every new way of acting is new variety the organization must regulate.
This uncertainty enters at every point AI touches: decisions, processes, customer interactions, and operations.
This deserves deep reflection.
Governance controls are mostly designed to regulate variety coming from the environment, such as market shifts, regulatory changes, and operational upsets. With AI, the organization imports uncertainty into its own operations. The source of variety is now inside the walls.
Four Questions
Ashby's principles raise four questions for every organization using AI.
Does the uncertainty AI creates exceed our capacity to contend with it? Ashby tells us that when variety exceeds a system's capacity, the variety will dominate. Outcomes are then determined by what AI does, and the organization loses control of its own operations.
Do our controls have the variety to absorb the uncertainty AI brings? Many controls were designed for deterministic systems with predictable failure modes. They may lack the range of responses needed for systems that behave in unexpected ways.
Do we have the channels to see what AI is doing across the organization? A control system cannot regulate what it cannot observe. Many organizations do not know where AI is being used, let alone how it is behaving.
Do our controls respond as fast as AI acts? Governance cycles often run quarterly or annually. Audits look back. Agentic AI decides and acts in seconds.
The Limits of Feedback
Most organizations rely on feedback control. We measure outputs, find deviations, and take corrective action. Management systems, standards, and regulations are built around this loop.
As I noted in Cybernetic Control, feedback has a significant weakness. It requires outputs to be measured first. For risk and compliance objectives, this is often too slow and too late, particularly with respect to safety.
With AI, this weakness grows. By the time a deviation is measured, an AI system may have made thousands of decisions. An agent may have taken actions that cannot be undone. Harm may already have reached customers or the public.
This is why feed-forward control matters. Feed-forward control anticipates deviation and acts to prevent it before it happens. It shapes conditions, constrains behaviour, and designs out failure modes in advance. It is central to engineering practice, and it is what organizations need as AI becomes part of their operations.
Restoring Balance
Beer offered two ways to achieve requisite variety.
We can attenuate the variety entering the system.
We can amplify the variety of the system that regulates it.
For organizations using AI, attenuation means reducing uncertainty at its source. This includes limiting where AI is used, bounding the authority of AI agents, and defining the operating envelope within which AI is permitted to act.
Amplification means increasing the organization's capacity to regulate. This includes building competence in people, establishing channels that make AI behaviour visible, creating controls that respond at the speed of AI, and strengthening the structures that keep the organization aligned with its obligations.
Viable organizations do both. They reduce the uncertainty they take on, and they increase their capacity to contend with the uncertainty that remains.
A Question Worth Asking
Many organizations are adopting AI as fast as they can. They measure success by whether it works. That is understandable. It is also a narrow measure.
An organization that works today may not be viable tomorrow. Viability depends on whether the organization's capacity to regulate keeps pace with the uncertainty it takes on. Ashby's law offers no shortcuts. Variety must be matched by variety.
I find myself returning to the same question. Alongside asking whether AI works, we need to ask whether our organizations can remain viable with it.
This is a question every leader can ask of their own organization.
As we adopt AI, how will we remain viable?
Lean Compliance can help you answer this question. Our Forward Assurance program helps organizations operationalize AI governance so they stay between the lines, ahead of risk, and on mission as they adopt AI. Reach out to learn how Forward Assurance can help your organization remain viable.




