The Connor blog
Thoughts on distributing AI skills and governing the tools your agents use.
Shadow AI: what it is, and why you should care
Shadow AI is the AI your team already uses that you cannot see — models, agents and tool connections wired into live systems, outside any oversight.
James Zhao and Kashif RafiqGetting everyone using AI isn't the same as getting value from it
Most companies measure how many people use AI. The number that predicts return is how deeply it is used, and whether the quality of the output is going up.
James ZhaoMost companies can't tell if their AI is actually paying off
Most companies are not failing to get value from AI. They are failing to find out whether they did. Here is why returns go missing, and what closes the gap.
James ZhaoHow to write an AI Skill your team will actually use
Most Skills fail at discovery, not quality. They are never triggered because the description is vague. Here is how to write one that gets picked up and used.
James ZhaoWhy banks have paid $3.5bn in fines over WhatsApp
Every firm fined already banned WhatsApp for business. They were not punished for the app. They were punished for being unable to say what was said on it.
Kashif Rafiq and James ZhaoYou probably don't need to build an AI agent for that
The reflex is to commission an agent per workflow. Most of the time the right unit is a Skill plus the tool connections it needs, which nobody has to build.
James ZhaoEvery real AI incident comes down to what you connected it to
Samsung, Apple, Asana, Air Canada, Microsoft 365 Copilot. A tour of what actually happened when AI met company systems without governance — and the pattern underneath.
James Zhao and Kashif RafiqWhat a shadow AI report actually shows you
A real Connor scan of an 86-person company found 402 MCP servers and 273 skills. Here is how to read the report — the egress surface, the risk, the sprawl.
James Zhao and Kashif RafiqYour team keeps rebuilding the same AI skills
Most teams lose time, not gain it: the same AI skills get rebuilt on desk after desk and the best ones never spread. Here is why it happens, and the fix.
James ZhaoThe risk isn't the AI. It's the access you bolt on around it.
Giving your team AI access is the easy part. The risk is not the model: every connected tool is an unscoped key, with no record of what it did.
James Zhao and Kashif RafiqThe hidden token tax in every MCP call
Every MCP tool call returns far more than the model needs, and you pay for all of it. Here is where the token tax comes from and how to cut it.
James ZhaoWhat is an AI control plane?
An AI control plane is the governed layer between your team and the AI tools they use. Here is what it does, why teams need one, and when to adopt it.
James Zhao and Kashif Rafiq

