Adoption is everywhere, control is nowhere

Every organization is using AI. Almost none of them are governing it.

That was the uncomfortable truth at the heart of Jan Smedts' keynote at the recent Dropsolid x Beltug event in Ghent, "AI on Your Terms." As Head of Digitaal Vlaanderen, Smedts brought a number that should give every CIO and CTO pause: roughly 67% of people are already using AI in their day-to-day work, but according to McKinsey research, only around 18% of organizations have a governance framework in place to actually manage that use.

In other words: adoption is everywhere. Control is nowhere.

From innovation topic to survival question

For years, the AI conversation inside most organizations has been about experimentation, pilots, proofs of concept, productivity tools like Copilot or ChatGPT. Smedts argued that this framing has quietly run out of road. The real question today isn't whether to use AI, or even how fast to adopt it. It's whether you can keep moving fast without losing control of what your systems are doing, what they depend on, and who ultimately holds the reins.

He described AI as a "dependency multiplier." It doesn't create new weaknesses so much as it aggressively exposes and deepens the ones you already have. Fragile infrastructure gets more fragile. Weak data governance gets exploited harder. Fragmented architecture fragments faster. AI doesn't automatically make an organization smarter, left unmanaged, it makes it more brittle.

This isn't a hypothetical risk. Smedts pointed out that more than half of organizations have already reported a negative AI-related incident in the past year, with data leakage among the most common causes.

Plan A, Plan B, and the migration path between them

The antidote Smedts proposed wasn't caution for its own sake, it was optionality. He framed real strategic autonomy around three things every organization needs:

Plan A: The technology you're actively using to deliver your mission today. Innovate, experiment, move.

Plan B: A credible alternative you could switch to without a catastrophic cost or a loss of control over outcomes.

Migration Path: A path between the two, so switching is a conscious choice rather than a crisis response.

He was careful to note that strategic autonomy isn't about isolation or building digital walls. It's about not being locked in, but about being able to negotiate, adapt, and choose. Recent events (including brief regulatory turbulence around access to certain AI models) reinforced his point in real time: it's far better to discover you don't have a Plan B while the stakes are still low than to find out during a crisis.

The real enemy is your own complexity

Perhaps the most striking part of the keynote was Smedts' take on cybersecurity. Despite a documented three-fold increase in external attacks over the past two years, he argued that the bigger risk isn't external actors, it's internal complexity. Every custom exception, every one-off integration, every bespoke security workaround adds a new point of failure. Zoom out far enough and most organizational architectures start to resemble a plate of spaghetti that nobody fully understands anymore.

His answer: platformization. At the Flemish Government, this takes the shape of what Smedts calls the "Government OS," which is a shared foundation covering network, hosting, data, workflow, and interaction layers, so that individual teams and applications don't have to reinvent security, authentication, or data handling every single time. Standardization, in this model, isn't bureaucracy for its own sake, it's what frees teams to move fast on the 20% of the stack where they actually create unique value, instead of re-solving the same foundational problems over and over.

The takeaway for every organization, not just government

Smedts was clear that the Flemish government's challenges aren't unique to the public sector. Any organization scaling AI faces the same tension: move faster, stay safer, keep control of dependencies, and keep delivering, all at the same time, not sequentially.

The organizations that will handle this well aren't the ones with the flashiest AI pilots. They're the ones that have quietly done the less glamorous work: mapping their dependencies, building a credible Plan B, and investing in the platform foundations that make governance possible at scale, rather than governance as a slide deck that nobody actually operationalizes.

Adoption without control isn't progress. It's just risk moving faster.

See it live