OpenAI says one in five Codex users is not a developer. Anyone can build software tailored to their own work without waiting for the engineering backlog!

That is fantastic if the need to move is big and the blast radius is small. Someone close to the problem can try an idea and start using it while they have context.

But when the tool starts to matter, when a reconciliation script made for one person becomes the only way refunds are processed, it becomes a liability as much as an asset. Nobody decided to make it critical. It just became critical because it worked.

Engineering has had a long time to get used to owning operational risk. On-call and restoring garbled data are part of the job. We know that different systems deserve different levels of protection. The person who built a local tool may be perfectly capable of maintaining it, but their role probably does not leave much capacity for that work once other people depend on it.

Putting governance around every experiment would remove much of the advantage. Waiting until a tool breaks is obviously too late.

Who detects this shift, and what does the organisation do when it happens?