I've been watching videos on YouTube of employees proudly showing off AI tools they've built inside their companies. Internal applications, automations, agents, reporting tools, even entire workflows.
And some of this has gone beyond experimentation. Teams are effectively competing with each other over who can build the better tool, automate the next process or move faster.
In reality, I actually think this is great. I've been very guilty of this myself in some of my own companies.
But watching these videos, I keep coming back to one question:
Does the owner know any of this exists?
Because something an employee built on a Tuesday afternoon can quietly become part of how the company operates. Three people use it. Then ten. Then an entire department depends on it.
And you don't even have to build an AI tool to create exposure.
An employee uploads a financial model for analysis. A customer list to clean it up. A contract to summarize it. Pricing information to build a proposal. An HR document to help write a review.
All completely innocent. Probably making them more productive.
But does the company know where that information just went?
What platform processed it, is it retained, who can access it and was the employee authorized to put it there? If the answer to any of these questions is 'we don't know,' then the company doesn't really have control of its data.
That's when this stops being an IT issue and starts becoming a valuation issue.
You spent twenty years building something worth selling. The buyer has to figure out how much of that value they can actually take ownership of and continue operating.
If part of the business depends on undocumented AI tools, individual employees, unknown data flows or systems nobody can properly explain, the buyer has to price that uncertainty.
And buyers price uncertainty in one direction. Down.
The answer isn't shutting down AI experimentation.
That would be a mistake. The companies that get this right will probably have employees building and using more AI, not less.
But let that go long enough without any governance and what started as innovation shows up in due diligence as a problem the buyer wants someone else to pay for.
Companies are already springing up to solve pieces of this problem. Vanta is one example. Compliance platforms, system audits and AI governance tools will become increasingly important.
But technology alone isn't the answer.
The bigger question for an owner is what these exposures mean to the value and transferability of the business.
This is one of the areas we're starting to pay much closer attention to at BuiltWorth.
Not because we want to tell companies which AI tools to use. We don't. Our concern is what happens when technology, systems, people or processes create a risk to the value of the company - particularly a risk the owner doesn't know exists until a buyer finds it.
Our role is to help owners identify those risks early, understand what they could mean to enterprise value, and guide the company on what needs to be addressed before it becomes a buyer's negotiating point.
Undoubtedly this is going to show up in mere months from now, not years.
The earlier you find it, the more control you have over how it gets resolved and take control to bring in a vetted and data secure/industry compliant solution.
Find it in due diligence and the buyer owns that conversation.
Your employees using AI isn't the problem.
Not knowing what they're building - or what they're putting into it - is.
If you're thinking about a sale in the next two to five years and you're not sure what your team has built or what it's connected to, that's exactly the kind of conversation we have at BuiltWorth. A valuation and technology risk assessment can tell you what a buyer will find before they find it.
Reach out at hello@builtworthadvisory.com. We'll take a look.

