The change control board on a program I was brought into used to see four or five requests a month. It now sees closer to thirty. The program didn't get bigger and the teams didn't get more indecisive. What happened is that writing a change request stopped being work. Somebody who wants a scope change describes it to an assistant in a sentence, and ninety seconds later they have four pages with an impact assessment, a risk narrative, a dependency list, and three options with a recommendation. It's better written than anything that board saw in 2023. And there are thirty of them.

The obvious reading is that AI caused scope creep, and that isn't true. Scope creep predates every one of these tools by decades: PMI's 2018 survey of more than 5,000 practitioners found that 52% of projects completed in the prior year had experienced scope creep, up from 43% five years before. The appetite for change was always there. What changed is the cost of expressing it — and that cost was doing more governance work than anyone had accounted for.

The filter nobody designed

Ask most PMO leads what filters scope on their program and they'll describe the board: the criteria, the thresholds, the impact assessment, the sponsor approval. That is the filter they designed. It is not the filter that was doing most of the work.

The filter doing most of the work was effort. Before anything reached the board, a requester had to spend real hours building the case — pulling numbers, chasing an estimate from a team lead, writing the thing. Somewhere in hour two, a meaningful share of requests died quietly, and they died in the best possible place: inside the head of the person who wanted them, before they consumed anyone else's attention. That was triage. It was invisible, unmanaged, and free.

Every organisation is carrying controls like this — governance that works for reasons nobody wrote down. They look like process and they're actually economics. A monthly report is read carefully partly because there are only twelve a year. An escalation carries weight partly because raising one is socially expensive. Remove the cost and the control doesn't get more efficient. It stops being a control.

What breaks when asking becomes free

1. The board becomes the bottleneck it was never sized to be

A forum built to deliberate over five items a month cannot deliberate over thirty. It can only do two things instead: rush, or queue. Rushing produces waved-through approvals; queuing produces a six-week wait for a decision the team needed in a week. Either way you've relocated the failure into the decision backlog, which is where programs actually bleed schedule. The scope didn't creep past a gate. The gate stopped closing fast enough to matter.

2. Quality stops telling you anything

The board used to read a weak request and infer something real from it — that the requester hadn't thought it through, or couldn't get their own team to back the estimate. Now every request is articulate, structured, and internally consistent. This is the same problem I've written about in vendor selection, arriving from inside the house: when the artifact stops varying in quality, it stops carrying information, and a board that is still reading for polish is reading a signal that has gone flat.

3. The requester stops doing their own triage

This is the one that worries me most. The hours a person used to spend building the case were hours spent interrogating their own idea. Cheap generation removes that. The request now arrives fully argued without ever having been thought about, which is a genuinely new object — and the confident structure of it does what fluent output always does: it borrows credibility the thinking behind it never earned.

The principle

A control that runs on effort isn't a control — it's a toll booth. When the toll drops to zero, the road is open, and you will not find that out from the process documentation, because the cost was never written down as part of the design.

Rebuilding the filter on purpose

The fix is not to ban AI-drafted change requests. That's unenforceable, it's the shadow-AI mistake in a new costume, and it would be punishing the wrong thing — the writing was never the value. The fix is to reprice the ask in a currency the machine can't spend on the requester's behalf.

Three things do that, and none of them are technical. First, require a named sponsor's signature at submission rather than at approval. A generated document costs nothing; another executive's willingness to put their name on it costs exactly what it always did, and it re-creates the private triage that used to happen in hour two. Second, require a stated tradeoff: what comes out of the plan, or what date moves, if this goes in. AI will happily write the case for something; it will not volunteer what the requester is prepared to give up, because that's a commitment, not a composition. Third, put the board on a batch cadence with forced ranking — every request for the period considered together and ordered against the others. Serial consideration is how thirty individually reasonable changes become one unrecognisable program.

Then watch two numbers. Approval rate first: a board approving ninety-plus percent of what reaches it is not filtering, it's notarising. Then baseline drift — the cumulative delta between the scope you committed to and the scope you're now building, reviewed quarterly against the original. Individual changes always look affordable. The sum is what kills you, and the sum is the view nobody is looking at.

How to actually do this
  • Find the controls on your program that run on effort rather than judgment — change requests, escalations, exception approvals — and assume each one just lost its filter.
  • Reprice the ask: require a named sponsor's signature at submission, not at approval. Generated prose is free; another executive's name is not.
  • Make every request state its tradeoff — what leaves the plan or what date moves. AI will argue for a change; it won't volunteer what you're giving up.
  • Batch and force-rank change requests instead of hearing them one at a time. Serial approval is how thirty reasonable changes become one unrecognisable program.
  • Track approval rate and cumulative baseline drift. Above ninety percent approval you have a notary, not a board.

The bottom line

Every governance process in your organisation carries a load-bearing assumption about what things cost, and almost none of those assumptions are written down. AI is falsifying them one at a time, invisibly — nothing fails, no alarm sounds, the process keeps executing exactly as designed while the thing it was protecting walks out the back. So go find them before they're tested. For every control you rely on, ask the uncomfortable version of the question: is this working because someone exercises judgment, or because it used to be too much trouble to abuse? If it's the second, the filter is already gone. You just haven't been billed for it yet.