The Second Price of AI Is Your Firm's Process
Every prompt, correction, and override teaches a third-party system how your firm actually works. That is the asset no professional services firm has on its balance sheet.
A professional services firm’s only durable asset is how it does the work. On July 14, the chief executive of the world’s largest enterprise software company said out loud what most buyers have not priced: companies adopting AI are paying twice, once in cash and once in the proprietary operational knowledge their people hand over through prompts, corrections, and agent activity.
The argument is uncomfortable coming from a company that profits from the adoption it is warning about, which is precisely why it is worth reading carefully. His point was not about client data. It was about the layer underneath: which tools your people reach for, which approvals a matter requires, which exceptions get escalated and to whom, and how a file moves from intake to close. Every time a professional prompts a tool, rejects an output, and rewrites it, that correction encodes a rule. Enough corrections, and the system holds a working model of your method.
Adoption is compounding faster than anyone is classifying what it exports
Firm-level AI adoption across OECD member economies moved from 8.7% of firms in 2023 to 14.2% in 2024 to 20.2% in 2025. Professional, scientific, and technical services sat at 36.8% in 2025, well ahead of the all-industry average and second only to ICT. Within the professions specifically, a 2026 survey of more than 1,500 legal, tax, accounting, risk, and government professionals across 27 countries found organizational generative AI use at 40%, up from 22% a year earlier. Agentic AI, systems that execute multi-step work rather than assist with a task, sits at 15% today, with 77% expecting it to be central to their workflow by 2030.
Now the operational detail that matters. In that same research, more than half of individual professionals reported using publicly available consumer tools rather than firm-provisioned systems. That is the mechanism. The method does not leave through a procurement decision anyone reviewed. It leaves one prompt at a time, from a senior associate pasting a redline at 9 p.m., from a manager describing the escalation path in order to get a usable answer, from a partner correcting an output until it matches how the firm would have done it.
The asset nobody classified
Ask a managing partner what the firm protects and the answer is client data. Privilege, confidentiality, audit independence, engagement NDAs. The governance architecture in professional services was built entirely around information belonging to someone else, and it is genuinely sophisticated at that job.
Now ask what protects the firm’s own method. There is usually no answer, because there is no category for it. Data classification policies distinguish client records, trade secrets, documents, and source code. Almost none of them classify prompts, agent logs, workflow corrections, or exception handling logic, which is where a firm’s actual competitive difference lives. A litigation boutique’s edge is not its access to case law, which is public. It is the sequence of judgment calls that turns intake into strategy. An accounting firm’s edge is not the tax code. It is the review protocol that catches what the code does not flag.
That method took years to build and it exists mostly in the heads of people who cannot fully articulate it. AI systems are exceptionally good at extracting exactly that kind of tacit process knowledge, because articulating it is what a prompt does.
What ownership looks like operationally
The response is not abstinence. Firms that refuse AI lose on cycle time, and 36.8% sector adoption says that race is already running. The response is architectural, and it comes down to where the work is executed and who holds the record of how it ran.
This is where CXO’s Custom Agentic Workflow work sits. The distinction is concrete: workflows configured to the firm’s own rules, systems, and exception paths rather than a generic tool the firm bends itself around; the orchestration layer under the firm’s control, so models can be swapped without rebuilding the process; and the logs, corrections, and routing logic held inside the firm’s environment, where they accumulate as an asset rather than as training signal somewhere else. The method gets encoded either way. The only decision is whose system it gets encoded into.
Three questions size the exposure this week. First, how many of your people are using consumer AI tools for firm work right now, and would you know? Second, if you deployed an agentic system tomorrow, which of your workflows could you write down precisely enough to configure it, and which exist only as habit? Third, if your process logic were readable by a competitor, what about your practice would still be defensible?
The third question is the one that determines whether the first two are urgent. Most firms will answer it in 2030, after the encoding is complete and irreversible, when the 15% running agentic systems today has become the 77% expecting to. The window for choosing where your method gets written down is open now, and it is the kind of window that closes quietly, without a decision anyone remembers making.
In most operations, far more work can be automated than leadership realizes. One discovery call is enough to size what automating it would return to your bottom line. Book it at https://cxocorporation.com/contact.