The AI Revolution Nobody Can Switch Off

Posted on September 24, 2026

0


The AI Revolution_ A Post-App World

Somewhat sooner than I thought here is the piece I referenced in ‘It’s Not the Model, Stupid … Standards Must Govern Authority, Not Intelligence‘. We may be approaching an infrastructure revolution in AI that makes today’s arguments about controlling frontier models look strangely temporary. Something that may also challenge the perception of frontier labs and their inflated valuations.

Hardware such as NVIDIA’s DGX Spark-class (dedicated AI inference) and RTX Spark N1X (dual purpous, PC/AI inference) systems, with 128GB of unified memory, point towards a world where increasingly capable AI models run locally. To put that in context, this means the ability to run near frontier level models, or for the more techie, support for up to 200 billion parameter models (quantised inference, not running a 200 billion model at its original training precision, time to first token @5 sec + 10 – 20 tok/s). Oh yes, and Nvidia do something rather funky, you can stack these units, up to x4 with the DGX class to give you frontier model capability. Combine that with open-weight models and AI is no longer necessarily a service rented from a hyperscaler. It becomes something individuals and businesses can own, modify and operate. No token meter, no mandatory connection to the mothership and no big brother is watching kill switch, and for the privacy minded, your own data store under your control to augment your locally running model(s). This could democratise AI much as the PC democratised computing.

At the same time another transformation is happening as I wrote about earlier in ‘AI Won’t Kill the OS, It Will Make You Forget It Exists’, the operating system is disappearing from view. Not technically of course. Windows, Linux, OSX and iOS remain critical infrastructure but increasingly we will not consciously operate them. We will tell an agent what outcome we want and it will select models, APIs, data and services to accomplish it.

I believe AI is moving from being purely a service you access to becoming infrastructure you can own, while the operating system is simultaneously becoming infrastructure you no longer consciously see. The PC I hypothesis could become the personal AI datacentre. Democratising AI down to a consumer level.

The significance is not simply that local models become cheaper. It is that the economics and control point of AI change. Today we largely think Device > OS > Browser/App > Cloud AI > Model. However with powerful local compute the future will possibly look more like  User > Agent > Local models > Tools/data/other agents, with the cloud invoked only when necessary.

That creates the AI equivalent of the PC revolution. Mainframe computing became personal computing; hyperscale AI begins becoming personal AI and then the OS starts disappearing as noted above.

For corporate cyber teams, this democratisation could be equally transformative. Today, sophisticated AI enabled defence risks becoming another expensive capability rented from a handful of vendors. Local models change that equation. A security team could run its own specialist models against sensitive telemetry, threat intelligence, code, configurations and incident evidence without surrendering that data to an external AI provider. More importantly, teams could build autonomous defenders tailored to their own environment, continuously hunting, testing controls, analysing attack paths and investigating alerts at machine speed. I included a proof of concept outline in my piece ‘AI Won’t Kill the OS, It Will Make You Forget It Exists’.

Important for cyber teams to align with is that autonomy should not mean unlimited authority and autonomous does not mean infallible. An agent/model may be extraordinarily capable at detecting an attack, yet still lack the organisational context to understand that isolating a compromised server could interrupt a safety critical process, breach a contractual obligation or trigger a cascading operational failure. Models do misinterpret evidence, operate from incomplete data, be manipulated by adversaries and optimise an immediate objective at the expense of a wider business outcome. Worse, machine speed can turn a small error into an enterprise wide event before a human has even recognised what is happening.

Autonomy therefore needs graduated authority. An agent or model might freely observe, correlate and investigate; require stronger authority to contain or reconfigure; and require explicit human or multi-party approval for actions carrying significant operational, financial, legal or safety consequences. Authority should also be contextual, temporary and revocable not a standing entitlement granted simply because an agent has previously been trusted.

That requires a governance architecture around the AI rather than dependence upon governance inside the model. Acknowledging that identity establishes who or what is acting; cryptographic proof validates it; trust determines whether it should be admitted; delegated authority defines what it may do; policy constrains where, when and against what resources it may act; data rights determine what it may learn; and immutable evidence records what actually happened. Higher-impact actions can then trigger additional authorisation, human intervention or an immediate withdrawal of authority.

This changes the cyber operating model. Humans increasingly move from processing every event towards designing, supervising and governing the boundaries within which machines operate. The objective is not maximum autonomy but governed, bounded autonomy, with machines free to reason, recommend and act at machine speed where consequence is tolerable, while humans retain authority where judgement, accountability and systemic consequence matter.

The SOC of the future may give every analyst the equivalent capability of hundreds but its success will depend less on how autonomous those machines become than on how precisely we decide what they are never autonomous enough to do.

That changes security fundamentally. If models become local, interchangeable and potentially uncensored, making the model itself the security boundary becomes increasingly unrealistic. The durable control point moves elsewhere as noted above to identity, cryptographic proof, trust, authority, policy and evidence, and therein is another casualty hiding in that transition … the app economy.

The Apple iPhone’s dominance was built not simply on hardware, but on making the app the gateway to the digital world, Agentic AI potentially dismantles that assumption. Why open an airline app, banking app or shopping app etc when your agent(s) can negotiate directly with their APIs?

Imagine the impact on marketplace ecosystems and economics when the OS disappears, then the apps disappear and AI agents become the predominant interface. Apple’s greatest threat may not be that nobody cares which smartphone they are holding. It is that somebody else becomes the agent they trust while they are holding an iPhone, because The OS doesn’t really disappear, it becomes the plumbing, it is the agent that becomes the customer and whoever controls the agent inherits the economics of the interface.