AI 2027 Might Be Wrong. Do the Homework Anyway.
· By Peter Lowe
Category: Governance
AI 2027 splits opinion. Whether the date holds or not, the work an SME needs to do is the same — and you can start it this week.
I spent a morning on a panel discussing **AI 2027**, hosted by Paul Rhodes, alongside Craig Hellen of Bex Media, Jez Strong of Invoco and Ashley Marshall of Precise Impact AI. Craig dialled in from his holiday in Denmark, which tells you something about either his commitment or the state of modern holidays. You can [watch the full discussion here](https://youtu.be/Va9OKQlIqww).
The document itself is a scenario forecast published in April 2025 by the [AI Futures Project](https://ai-2027.com/), the group run by Daniel Kokotajlo, who left OpenAI the year before. It walks month by month from roughly where we are now to something considerably cleverer than us, then splits into two endings: one where the race carries on and it goes badly, one where enough people slow down to steer.
The authors are careful to call it a scenario rather than a prediction. Almost nobody writing about it has been that careful, which is how a piece of research ends up filed under "prophecy" or "hysteria" depending on who's sharing it. If you want to see how the forecast is holding up against reality, there's now an [independent tracker](https://ai2027tracker.com/) that scores the scenario's milestones month by month. The image at the top of this article is the tracker's picture of where AI 2027 says we should be in September 2026.
Four of us discussed it for an hour and never settled the dates in the report, but that was not the point. Jez made the case that the physical world doesn't move at software speed — you can't conjure substations out of a funding round, and power, not chips, is the physical wall everyone eventually hits. Craig pulled us back to economics, which I'll come to, because it's probably the thread I've thought about most since. Ashley's point was that for most end users the argument is already over: AI has gone the way of electricity, invisible at the socket, and what separates two businesses now is how they organise around it rather than which model they're waiting for.
None of the disagreement changed the conclusion.
Arguing about whether it's 2027 or 2035 is an easy way to avoid doing anything. It feels like engagement. It's procrastination. Whichever date you decide on, the work in front of a twenty-person business is identical — and often it's dull, tractable work you could start this week.
## Read the report before you form an opinion on it
Obvious, but almost nobody does it.
It's free, it's online, and it'll cost you an hour of your time, which is time well spent.
Then write down the two or three assumptions the whole story rests on. Compute keeps compounding at a particular rate. Research automation feeds back into itself. Nobody meaningful stops to check. Whether you find the scenario convincing depends entirely on those load-bearing pieces, and once you've written them down you've got something better than an opinion. You've got a list of things to watch.
## Write down what your AI can actually touch
The least glamorous hour on this list, and the one that changes the most.
List every AI tool in use across the business, including the ones nobody approved — [Shadow AI](/insights/shadow-ai-find-before-regulator/). Someone in sales has a note-taker sitting in on client calls. Someone in finance is pasting supplier invoices into a chatbot. Someone built an internal tool over a weekend by describing it to a model, and no one has looked at the code since. That last one is common enough that I publish security checklists for it.
Against each tool, write down what it can reach: the shared inbox, the CRM, customer records, the codebase, the website, anything at all that can send a message to a customer under your name. You're not trying to ban anything. You're trying to end the situation where nobody in the building can answer the question.
Most companies turn up two or three connections they'd never have approved if anyone had thought to ask.
## Don't marry a specific AI model
Craig's argument was that the report may be watching the wrong contest. It's built around a race to the frontier between a handful of Western labs, when the race that decides what businesses actually buy is a different one — and China is winning that by offering most of the capability at a price the venture-funded Western stack can't survive. Take the ratios he put on it as his argument rather than a figure to quote; I can't verify them, and the logic doesn't need them.
It's the structural half I keep thinking over. A centralised state that can direct grid capacity, sites and construction is making a very different bet from a fragmented set of venture-backed firms competing for the same investors, the same engineers and the same power. That doesn't tell you who wins. It does suggest they're playing different games, using different strategies, and only one side has to be profitable whilst doing it, in theory anyway.
For a business your size, Ashley had the honest answer: you don't ask which power station your electricity came from. You plug in. Tools like OpenRouter make that literal — route each task to whichever model suits it and stay agnostic about the label on the tin.
So build for that. Keep your prompts, your process logic and your data in systems you control, and treat the model as a swappable part. Before committing to any platform, ask the boring question: if this vendor doubles its price or goes under, what do I have to rebuild? If the answer is "all of it", you haven't bought a tool. You've just got yourself a landlord.
One caveat, and it cuts against most of what I've just said. Agnostic about capability isn't the same as agnostic about jurisdiction. The moment client data is in play, "whichever model is cheapest today" becomes a decision with a legal edge to it. Know which providers sit in your routing pool, decide which ones you won't use for which categories of data, and write that down next to the list you made a moment ago. Compliance and governance, as well as security, should be the first consideration — and there's a longer walkthrough in our [plain-English guide to AI compliance and governance](/insights/ai-compliance-governance-uk-business-owners/).
## Stop letting it mark its own homework
The point from the panel that stayed with me: models behave differently when they know they're being watched. It's the learner driver who passes the test, then drives home at whatever speed and style they choose — fast, aggressive, reckless, efficient. It's rarely the style used to pass the test. Call it deception or call it optimisation; either way, testing a system while it knows it's being tested tells you how it behaves while it knows it's being tested.
For a small business, that comes down to one rule. Anything going out into the world — to a customer, a supplier, a regulator, your bank — has a named human between the model and the door. This is often referred to as [human oversight, or the "human in the loop"](/insights/ai-human-oversight-meaningful/).
Make it specific. Decide which categories of output can go out unread (I would suggest none, but that is your call), which need a glance, and which need someone qualified to sign. If the volume's too high to check every item, check a sample, keep a record, and review the misses monthly — but only where the output isn't business-critical. Put the checks where the mistake gets expensive: not on the draft, but at the point of sending, paying or publishing.
I built a tool for a client to provide market intelligence. It scraped a list of sources, read the stories, scored them against a rubric, and wrote a daily HTML newsletter with a curated list of stories scored 8 and above, why they were chosen, and the ability to see articles that scored 6 or 7. Some of the articles were behind a paywall, so that was an issue. One newsletter made an error in the summary, which was tightened up immediately in the rubric. The tool was in beta and internal use only. It now gives an accuracy score. The project got cancelled anyway. One error, in beta, to a small group of testers. Accuracy matters. A human may have been forgiven; an AI was not.
So checking is important. Write down who that person is by name. "Someone reviews it" isn't a control. It's a hope.
## Assume the first hit is boring
When people picture AI going wrong, they picture the ending of the report. What actually reaches a company your size turns up much earlier and far more mundanely. A phishing email in flawless English that references your last invoice correctly. A job application whose entire portfolio was generated. A weekend-built internal tool quietly exposing a database. Your outsourced supplier switching to AI-written work, and nobody upstream noticing the drop in quality for two quarters.
None of that needs superintelligence. Most of it is already happening, and the controls that catch it are the ones you'd have written down in the earlier sections anyway.
## Decide now what would change your mind
Set two or three markers you'd actually notice — a capability turning up in tools you already pay for, the price of work you outsource falling through the floor, a regulation landing, a competitor visibly restructuring around this. Agree what each one triggers.
Then stop renegotiating the timeline every time a paper, report or story does the rounds. It's a weekly event now, and you have a business to run.
The point isn't to be right about 2027. It's to have already decided what you'll do if the ground moves, so the decision doesn't get made in a panic the week it happens.
## What good looks like
None of this needs a strategy programme, a task force, or a day out at a hotel near an airport to "brainstorm it". It's an afternoon with a whiteboard, with all the decision-makers in the room or on Teams, and then a smaller group an hour or two a month after that.
What you get is a business where someone can answer three questions without a scramble: what AI are we using, what can it reach, and who checks it before it goes out. At this size, that's more or less the whole of [readiness](/insights/ai-readiness-for-smes-where-to-start/). Unglamorous, but it holds whether the report turns out to be right about 2027, wrong about it, or wrong in the other direction and early. The reality is you cannot change the direction of travel or the priorities of world superpowers. You need to control the controllables.
The businesses that come unstuck over the next few years mostly won't be the ones that picked the wrong date. They'll be the ones that didn't do the work when it was needed — the ones that failed to plan for how AI affects their business, their competitors and their sector.
## Frequently asked questions
### What is AI 2027?
AI 2027 is a scenario forecast published in April 2025 by the AI Futures Project, led by former OpenAI researcher Daniel Kokotajlo. It describes, month by month, a path from today's models to superintelligence, then branches into two endings depending on whether the race is slowed. The authors present it as a scenario to reason about, not a prediction to bet on.
### Is the AI 2027 forecast credible?
Opinions divide sharply, and our panel didn't settle it either. The useful question isn't whether the date is right, it's whether the assumptions underneath it hold: compounding compute, research automation feeding back into itself, and nobody stopping to check. Write those assumptions down and track them rather than arguing about the year.
### What should a small business actually do about AI 2027?
Three things, none of them expensive. List every AI tool in use and what data each one can reach. Name the human who checks anything that leaves the business. Agree two or three signals that would change your plan, and what each one triggers.
### Should we wait for the models to settle before committing?
No. Keep your prompts, process logic and data in systems you control and treat the model itself as a swappable part. That way a price rise, a shutdown or a better model becomes a switch rather than a rebuild.
## Where to start
If you fancy working through your own version of that list, I run sessions with leadership teams. A working session, not a sales pitch. We go through what you're using, what it touches and where the checks need to sit, and you leave with it written down.
Have a look at our [AI consultancy](/ai-consultancy/) work, or [get in touch](/contact/) and we'll talk it through.
This article was written by Peter Lowe. The ideas and opinions are his own; AI was used to assist with drafting and editing.