Where scarcity goes when it leaves


A few weeks ago I wrote that boards are treating AI intelligence as a permanently scarce, permanently expensive input, and that this assumption is already cracking. A few people asked me a fair follow up question. If intelligence stops being the scarce thing, where does the scarcity actually go. It doesn’t just vanish. Someone always ends up holding it.

I have watched this happen up close twice in my own career, and I know a third example only from history, but it is the cleanest one to start with because you can actually see the migration happen.

The first time was containers. Malcolm McLean did not invent a faster ship. He invented a standard box, and that box made loading and unloading cargo dramatically cheaper. Everyone assumed the story was over once ships stopped idling in port for a week at a time. It wasn’t. Ports suddenly needed acres of land to stack containers. Rail lines had to sync up with ship schedules. Crane operators and terminal planners became more valuable than the stevedores whose jobs the container had just eliminated. The scarcity did not disappear when loading got cheap. It walked a few hundred yards down the dock and set up shop in land, rail and coordination.

The second time was the shift from FTE pricing to outcome pricing in IT and BPO, which is a conversation I have had more times than I can count over the last two years. For a long time, the constraint looked like headcount. You needed bodies to run processes, so you priced by the body. As automation and now agentic AI made raw execution cheaper, everyone assumed the constraint would just dissolve along with the headcount. It didn’t, because the bottleneck was never just labor. It was the entire system built around buying, measuring and governing labor. Procurement teams that are set up to negotiate FTE contracts are, frankly, not set up to negotiate outcome contracts, and it isn’t only because procurement is slow. When a workflow runs through a mix of human teams, vendor agents and enterprise software, agreeing on who actually caused a given outcome is a genuinely messy problem, not just a paperwork one. Finance teams that know how to forecast a headcount ramp don’t automatically know how to forecast a variable outcome fee they can’t cleanly attribute in the first place. That system, not the labor it was built to manage, is the thing that is actually scarce right now. I said back in February that this is exactly why Khosla’s five year timeline for IT and BPO extinction won’t hold. Enterprises are slow to redesign the muscle that buys and governs work, and rebuilding that muscle takes a lot longer than swapping the underlying technology.

The third time is AI, and we are living through the early innings of it.

The public conversation is entirely about model capability. Whose benchmark is better this month, whose inference is cheaper, whose context window is longer. That is the visible layer, and it is genuinely moving fast. But if you sit in enough steering committee meetings, as I do, you notice the real conversation has already shifted somewhere else. Nobody is asking whether the model is good enough anymore. They are asking who is accountable when an agent acts on its own, how you audit a decision a model made six tool calls deep, and whether legal and risk can sign off before the business quarter ends. Legal, risk and compliance are quietly becoming the functions that decide how fast AI actually ships, not engineering. And this isn’t only a soft, organizational story either. I wrote back in February that Jevons paradox is still very much alive in AI, cheap intelligence doesn’t shrink total demand, it multiplies the number of things people try to do with it. That multiplication is what’s straining power grids and chip supply right now, and it will keep straining them. The bottleneck isn’t only moving into legal’s inbox. It’s splitting, part of it lands on governance, part of it lands on the physical world’s ability to keep up.

That is the pattern, and it holds across all three examples. When something that used to be the bottleneck becomes cheap, the constraint does not evaporate. It relocates to whatever has to absorb the new abundance. Land and rail after containers. Contracts and procurement after outcome based pricing. Governance and organizational readiness after intelligence.

I want to be honest about where this framework is weaker than it sounds. It is easy to find three examples that fit a pattern after the fact. The real test is whether it predicts anything, and whether there are cases where it breaks. It does break sometimes. The cloud is actually the interesting counterexample here, not the confirming one. When compute got cheap, the constraint should have moved to independent architecture and security specialists. Instead, the hyperscalers largely built and sold that layer themselves. AWS didn’t watch a market of third party cloud governance firms spring up and capture the value, it built Control Tower and Security Hub and kept the margin in house. The incumbents who already controlled the abundant layer often reach up and grab the scarce layer too, they just do it slower than a scrappy new entrant would. Call it the adjacent ownership problem if you want a name for it.

But I don’t think AI plays out quite the same way, and it’s worth being precise about why. AWS could absorb cloud security because cloud security is still fundamentally tooling, dashboards, policies, audit logs, things a vendor can build and sell. Frontier labs can absorb model guardrails the same way, and several of them are trying to. What they cannot absorb is the thing sitting underneath the tooling: whose name is on the regulatory filing, who eats the liability when an agent makes a bad call, who signs the indemnity clause. That layer doesn’t move to the vendor no matter how good their safety tooling gets. It stays inside the enterprise. So the AI version of this migration may actually be more durable than the cloud version, the technical guardrails can be commoditized by whoever owns the model, but the accountability cannot be outsourced the same way. Though I’d bet even that has a shelf life. The moment someone figures out how to price and package agentic risk the way insurers price everything else, that liability becomes securitizable too, and the scarce resource quietly becomes actuarial expertise instead. Scarcity doesn’t stop migrating just because it hit an enterprise’s balance sheet. And I should be honest that this bottleneck doesn’t always slow things down the tidy way a land shortage slows down a port. Sometimes a business unit just routes around legal entirely, the way shadow IT always found a way around IT, and what looks like delay from the boardroom is actually unowned risk quietly accumulating somewhere nobody is tracking it yet.

So if you are trying to figure out where value is actually migrating in your own AI strategy, the technology roadmap is the least useful thing to stare at. Watch where the friction is showing up instead. Watch which meetings in your company have gotten longer, not shorter, since AI arrived. Watch which job titles didn’t exist eighteen months ago and are now impossible to hire for fast enough. Watch whether your procurement team can even write a contract for an outcome nobody has priced before.

The technology tells you what just became possible. The friction tells you where value is about to accumulate. And the companies that win the next few years will not be the ones who called the breakthrough early. They will be the ones who noticed where the scarcity went after it left.

The First Permission Architecture


How Automated Underwriting Revealed the Real Bottleneck in Autonomous Systems

The hardest problem with autonomous systems has never been only intelligence. It’s permission. A system can produce a decision in milliseconds. The harder question, the one that actually determines whether an organization can act on that decision, is whether anyone has redesigned liability, workflow, and trust around it.

The mortgage industry answered that question in 1995. Then it stopped asking it carefully enough, and broke the answer thirteen years later in a way worth studying as closely as the original solution.

The system

In October 1994, Fannie Mae piloted a program called Desktop Underwriter. By June 1995 it was live in production. DU was what the AI field of that era called an expert system: not a model that learned patterns from data the way modern machine learning does, but a rules engine that encoded the judgment of experienced human underwriters into a structured decision process, built to evaluate incomplete, unverified, and sometimes conflicting borrower data against a structured set of underwriting rules.

Feed it a loan file, and DU would return a credit recommendation and an eligibility recommendation, an automated judgment on whether a mortgage met Fannie Mae’s standards, in minutes instead of the days a manual file review took. Freddie Mac shipped a competing system, Loan Prospector, around the same time.

The consequential design choice wasn’t the automation. It was what came attached to the recommendation. When a loan file received DU’s top designation, Approve/Eligible, Fannie Mae extended lenders a waiver: relief from having to represent and warrant that the loan met Fannie Mae’s underwriting and eligibility standards, provided the lender’s data was accurate and properly documented. If DU said yes, and the paperwork behind that yes checked out, Fannie Mae absorbed a defined slice of the underwriting risk, the part tied to credit and eligibility judgment. The lender still carried the rest: data accuracy, fraud, documentation, the obligations no waiver ever touched.

That’s not automation. That’s a liability transfer, conditioned on a machine’s output, bounded by data-integrity rules the lender had to satisfy to earn it. Nobody at Fannie Mae in 1995 would have called it this, but it’s what I mean by an offensive permission architecture: not just letting a system make recommendations, but redesigning liability, workflows, and incentives around what it recommends, so the organization can act on the machine’s judgment without waiting for a human to re-verify every step of it. I use “offensive” deliberately and narrowly here: not aggressive deployment without safeguards, but an organization building the permission to act before the market or a regulator forces it to ask for that permission later, on someone else’s terms.

The advantage was never going to belong to whoever owned the automated underwriting system. Fannie Mae made DU available to every lender on identical terms. It was going to belong to whoever rebuilt their institution around the new source of authority DU created.

The permission stack

Pull the case apart and it separates cleanly into five questions, and the mortgage industry had to answer all five before automated underwriting became a source of advantage rather than a novelty.

Decision permission: can the system’s output count as a real decision, not just an input to one? DU cleared this by producing a recommendation lenders could act on directly.

Liability permission: when the decision is wrong, who absorbs it? Fannie Mae did, on Approve/Eligible loans that met the data-integrity conditions. Without this layer, DU is just a faster opinion. With it, DU is authority.

Operational permission: can the organization actually execute at the standard the authority requires? A lender had to have clean data pipelines and documentation discipline strong enough to survive scrutiny, or the waiver didn’t apply. This is the layer most companies underbuild, because it’s unglamorous compared to the technology itself.

Verification permission: does the organization’s own check on the system actually catch a systemic failure, or does it just confirm the system complied with its own rules? Fannie Mae required lenders to run post-closing quality control review on a sample of closed loans, checking that DU’s findings were properly resolved and documented. That’s a real verification layer, and for years it looked sufficient.

Verification is the layer most likely to create false confidence. A review process can be rigorous, sampled files, documented findings, signed-off reviews, and still be structurally blind, if the reviewer and the system share the same underlying assumptions. Fannie Mae’s QC reviewers were checking loans against the same underwriting guidelines DU had encoded, not independently assessing whether those guidelines still matched reality. It wasn’t that nobody was checking. Lenders sampled files constantly, documented every finding, signed off on schedule. The checking simply couldn’t see past a blind spot it shared with the thing it was checking. When Fannie Mae and Freddie Mac themselves loosened those guidelines through the 2000s, to accept lower credit scores, less documentation, less money down, the QC process could still confirm compliance. It just meant less, because the rulebook it was checking against had moved.

Market permission: will the parties outside the transaction, investors buying the resulting mortgage-backed securities, regulators overseeing the system, trust an outcome a machine helped produce? This was the layer verification was supposed to protect. It took the industry years to earn, and it was the layer that failed most visibly when trust collapsed in 2008.

These five layers don’t sit on top of each other so much as feed into each other. Faster decision permission creates operational pressure. Operational pressure, left unchecked, is what quietly erodes verification. Eroded verification is what eventually costs an institution its market permission. Pull on any one layer and the others move.

Most conversations about AI autonomy right now are stuck entirely on the first layer, whether the system can reason well enough to be trusted with a decision. The mortgage industry’s experience says that’s the easy one. The remaining four layers are where the actual advantage, and the actual risk, live.

The capture

Lenders who built the operational permission to qualify for the waiver, clean data pipelines, documentation that would hold up, systems that could feed DU reliably, got faster closings and lower risk retention than lenders who didn’t. That’s not a marginal efficiency gain. Between the first and second halves of the 1990s, the volume of mortgage-backed securities issued and guaranteed by Fannie Mae and Freddie Mac combined jumped from roughly $127 billion to $314 billion. Automated underwriting wasn’t the only driver of that, but it was a structural one: it changed what speed and scale were possible for lenders who’d built around it.

Notice what scarcity actually did here, because it’s the whole argument in one case. Before DU, one of the scarce resources was underwriting judgment itself, and it lived inside individual underwriters who couldn’t be copied or scaled. DU made that judgment portable and cheap. The scarce resource didn’t vanish, it moved, to whichever lender had built the institutional machinery to trust an automated decision enough to act on it at scale. That’s Default Capture: the winner isn’t whoever owns the technology, it’s whoever owns the constraint the technology creates downstream of itself, and builds the permission stack to act on that constraint before anyone else does.

The break

Here’s the part a triumphant case study would leave out.

The waiver was built for a specific kind of loan file: standard documentation, standard verification, standard borrower profiles, priced against risk assumptions Fannie Mae’s underwriters had spent decades calibrating. What changed through the 2000s wasn’t that riskier files quietly slipped through unnoticed. Fannie Mae and Freddie Mac actively loosened the rules DU was checking against, under real competitive pressure. Private-label securitizers were taking market share fast, the GSEs’ combined share of new mortgages fell from 52 percent in 2002 to 44 percent by 2006, and both agencies responded by expanding what counted as an acceptable loan: lower credit thresholds, zero-down products, wider acceptance of low and no-documentation files. Fannie Mae authorized more than eleven thousand underwriting variances in 2005 alone. The authorization architecture didn’t fail by drifting out of sync with a changing world. It failed because the people who owned the rulebook kept rewriting it to chase volume.

The lesson isn’t that automated underwriting caused the 2008 crisis. It didn’t, on its own, and plenty of other forces did more damage: private-label securitization, layered risk, ratings failures among them. The lesson is less comfortable than a single cause would be. The same architecture that safely accelerated standardized underwriting for a decade could be pointed at a much riskier target once the people who controlled it chose to loosen what the permission covered. The system didn’t fail by breaking. It failed by continuing to work exactly as designed, on a rulebook its own owners had rewritten to permit exactly the inputs it was never supposed to see.

When the crisis forced a reckoning, permission got rebuilt from the outside. In September 2012, the Federal Housing Finance Agency, then overseeing Fannie Mae and Freddie Mac in conservatorship, directed both GSEs to adopt a new representation and warranty framework, one with harder, more codified rules about when relief applied, tied to specific payment-history performance rather than a point-in-time automated recommendation alone. That framework wasn’t something any single lender could engineer its way into faster than competitors. It was imposed, uniformly, by a regulator, as a condition of an industry that had lost the market’s trust. Market permission, the layer nobody had been watching closely, was the one that failed most visibly, and once it did, the other four layers couldn’t keep operating at the same scale, even where they still functioned fine on their own terms.

Why the distinction matters

This is close to the cleanest real-world illustration of a distinction I keep coming back to: internal permission and external permission are different problems with different playbooks.

Fannie Mae’s original DU waiver was internal permission. It was a counterparty relationship, Fannie Mae and an individual lender, that a lender could earn through its own engineering: better data, better documentation, better systems. That’s a problem a company can solve on its own timeline, and the lenders who solved it early captured real advantage before competitors caught up.

The 2012 rep and warranty framework was external permission. It came from a federal regulator, after a crisis, uniformly, on a timeline no single company controlled. No amount of internal engineering discipline would have gotten a lender there faster. The authority to shape that outcome sat with FHFA, not with the industry.

Conflating those two, treating a regulator-controlled reset as something you can outbuild the way you outbuild a competitor’s data pipeline, is the exact category error I’d warn anyone in a regulated industry against making.

The lesson for what comes next

Strip away the paper and the decade, and the mechanism is identical to what enterprises are building around AI agents right now: bounded automated authority, a defined answer to who’s liable when the system is wrong, and a real, capturable advantage for whoever engineers the full permission stack before their competitors do.

Lay the two eras side by side and the mapping is almost exact. DU’s Approve/Eligible recommendation then is an agent approving a transaction or shipping code now. Fannie Mae’s rep-and-warranty waiver then is whoever indemnifies when the agent is wrong now. Clean data pipelines and documentation discipline then are sandboxing, API boundaries, and execution limits now. Post-closing QC review then is test suites and human-in-the-loop spot checks now. Trust from MBS investors and regulators then is regulatory clearance and user trust in the output now. Same five questions, thirty years apart.

Which companies actually get to run their agents at scale won’t be settled by model quality alone, the same way it wasn’t settled by whose rules engine evaluated files best in 1995. It’ll be settled by who builds the liability, operational, verification, and market permission underneath the decision, on their own timeline, before a regulator builds it for them on someone else’s. Intelligence is getting cheap fast. Permission still has to be built by hand, one institution at a time.

How Much of the Future Does Your Strategy Need?


Every post-mortem on a brilliant flop blames bad timing, a comforting explanation because it treats timing like weather. The vision was right, the universe just didn’t show up on schedule.

Google Glass wasn’t wrong about head-mounted computing. It needed battery density, social norms, and form factor to mature at once, and Google owned none of them.

That’s a different disease than the one that killed Webvan, which didn’t fail waiting on someone else’s clock. It failed spending its own capital as if it already owned logistics infrastructure it hadn’t built yet. One company bet on clocks it didn’t control, the other burned cash pretending a clock didn’t exist. Both look like bad timing in hindsight. Only one of them was.

Timing is a lazy diagnosis. The real question is narrower, and answerable before the fact.

The Question Boards Never Ask

Almost every strategy framework tells executives how to choose a future. Almost none tell them how to survive while waiting for it. The question that actually matters:

How much of the future has to arrive, on someone else’s schedule, before this strategy pays for itself?

Every strategy pays a synchronization tax, determined by its Synchronization Load: the count of external conditions that must become true, none of which you control, before the strategy becomes viable. By viable, I mean the point where the business can fund its own next step instead of relying on fresh capital to survive. Every additional independent clock extends the period capital sits committed before it can compound. That delay is the tax, and every strategy with unowned dependencies pays it. Load is estimable before you write the check. Getting it wrong turns a payable tax into a fatal one.

Synchronization Load counts independent clocks, not mentions. Four dependencies that all unlock when a single enabling condition arrives are one clock wearing four disguises. The real count is how many separate parties, none reporting to each other, must move on their own schedule.

Same Prediction, Different Bill

In 2002, Bill Gates announced the Tablet PC and predicted pen computing would dominate within five years. He was right about the destination. Microsoft’s strategy required simultaneous leaps in stylus software, digitizer hardware, desktop OS changes, and mobile battery tech: four unowned clocks, expected to strike midnight together. Microsoft burned hundreds of millions waiting for an ecosystem that hadn’t formed.

Apple made the identical prediction and paid a different bill. Through the 2000s, it built high-margin MP3 players and phones while Samsung, Toshiba, and LG matured touchscreens, flash memory, and ARM chips on their own balance sheets. By the time the iPad shipped in 2010, someone else had already paid for most of the runway.

Apple didn’t forecast more accurately than Gates. It needed less of the future to arrive, and what little it did need, like the AT&T deal that got the first iPhone onto a network, it negotiated and owned outright rather than hoping for. That’s not an exception to the framework, it is the framework: the dependency didn’t disappear, it got internalized into a contract Apple controlled.

Engineering Viability on a Slice of the Vision

Netflix didn’t wait for broadband to become universal. It first built a DVD business that generated the cash to survive until broadband caught up. The DVD business wasn’t the vision. It financed the wait. They built something that got paid before the future arrived.

Amazon did the same with AWS: viable on plain storage and compute while developers built simple applications on top, long before enterprise cloud transformation was real. Same pattern, different infrastructure.

Skeptics will call this survivorship bias with better vocabulary, every winner reading as low load in hindsight and every loser as high load. Fair challenge, and it would sink the idea if the count only existed after the outcome. It doesn’t: Gates announced his four dependencies in the same press cycle as the prediction, and Apple’s AT&T dependency was visible the day the deal was signed. The count is available at the moment of the bet.

Three Moves, Ranked by Risk, Not Interchangeable

When a strategy depends on external clocks, leadership has exactly three moves, and they are not peers. Treating them as equally safe is how internalization turns into a second Webvan.

1. Exploit existing economics. Build on infrastructure that already exists while the rest matures on someone else’s balance sheet. Lowest risk, because you’re not funding anyone else’s clock.

2. Sequence the exposure. Take on one unowned clock at a time instead of four at once. SpaceX didn’t need Mars colonization or a satellite constellation to reach viability. A single NASA contract made Falcon 1 viable, and every dependency after was funded by the last one’s revenue.

3. Internalize the risk. Build the dependency yourself when no one else will move fast enough. Tesla built Superchargers and Gigafactories because utilities and automakers wouldn’t. This is the highest-variance move, not a shortcut around risk. You haven’t removed the clock, you’ve bet the company you can out-execute it. It only makes sense once the first two are ruled out.

All three assume the clock belongs to engineering or capital, something a balance sheet or contract can eventually own. Some clocks don’t work that way: a regulatory approval, a licensing regime, a standards body with members who don’t answer to each other. None bend to a bigger check or a faster team. You can’t exploit your way around an FDA review or internalize a spectrum auction.

The Test, Before You Write the Check

Skip the debate about how exciting the end-state is. Run the strategy through three questions instead:

  • What external conditions have to go right before this becomes viable, and how many separate clocks does that reduce to?
  • Which do we control today, through ownership, contract, or capital, and which can no amount of either move?
  • For the rest: are we exploiting existing economics, sequencing one clock at a time, or internalizing deliberately, and can we afford that last option?

If the answer to the first question is four industries aligning on day one, and the answer to the third is “we’re hoping,” you’re not running a strategy. You’re holding a coordination bet dressed up as one.

The best strategists don’t predict the future more accurately than everyone else in the room.

They simply need less of it to arrive on time.

The companies that win aren’t the ones that see farther. They’re the ones whose businesses start working sooner.

The first job of strategy isn’t choosing the right future. It’s designing a business that can survive until that future arrives.