Sociotechnical hygiene
Editorial note. This chapter preserves the earlier concise English edition. A full translation of the expanded Spanish edition published on July 21, 2026 is in progress.
An AI adoption project does not end when the system works. In many late failures the go-live succeeded: what failed was what came after —data that lied again, policies no one reviewed, manual workarounds because the new flow did not address the operator’s real fear. That is sociotechnical debt: the cost of building without routines that maintain the balance between the human and technical parts.
Sociotechnical hygiene is the set of those routines. It is the natural extension of governance as a moat: not only rules at deployment but continuous maintenance. Without hygiene, the moat fills with sand within months.
Suppose Distribuidora Norte, after the at-risk customer alert project, reached production: salespeople use the tool, the “last purchase” field is aligned across branches. Six months later parallel delivery spreadsheets appear and complaints that “the system no longer reflects how we work on Fridays”. No one failed overnight: routines were missing —a data owner, glossary review, space for early complaint to be information and not late resistance. That wear is what hygiene tries to prevent.
What it is — and what it is not
Hygiene is not an imposed maintenance contract or a “best practices” PDF filed in a shared folder. It is designed with the system: who owns each routine internally, how often it is reviewed and what criterion triggers action. What is not named and not reviewed degrades — manual shortcuts appear, off-policy AI tools spread, categories people redefine in practice without updating the system.
Shadow AI —when employees use ChatGPT, Copilot or other tools on their own to work, often with internal data— has grown enough to deserve its own framing, and it is not the security one. It is not spontaneous innovation to applaud nor a crime to chase blindly: it is a diagnostic symptom. The global Melbourne–KPMG study (2025) found that almost half of employees admit to using AI in ways that contravene their organization’s policies; and IBM put the extra cost of a breach at hundreds of thousands of dollars when shadow AI is high. But the number is not the point: what it reveals is. The employee who uses AI in secret is not breaking the law, they are solving a need the organization failed to channel —the same old workaround, now with a language model instead of a parallel spreadsheet—, and like any workaround it is latent demand made visible: it says exactly what they lack in order to work. Banning without reading that demand does not remove it, it pushes it further into the shadows. Hygiene treats it as a signal: inventory of real use cases, risk assessment, and channeling toward governed alternatives —with a data-processing agreement when internal information is involved—. That almost half do it against the rules does not measure indiscipline: it measures the distance between what policy allows and what the work needs. Closing that distance turns shadow AI from a risk into an adoption roadmap.
Lifecycle and monitoring
Governance is not a document signed once. It is a cycle: idea, pilot, production, retirement. Between each stage there are stage-gates —explicit control points—: scaling a pilot to production without classifying case risk is the shortest path to incident.
In production, hygiene watches model drift: if an AI system that classifies complaints starts treating one customer group differently without anyone deciding so, something changed in the data or in use. For high-impact systems —health, credit, public resource allocation— a living algorithmic impact assessment is needed, updated when context shifts, not a report filed on launch day.
Technical hygiene includes things that sound boring and save companies: backups that are tested for real —not only configured—, agreements on RTO (how long the system can be down) and RPO (how much data can be lost) negotiated with the business, and blameless postmortems that feed new controls, not only closed tickets.
Infrastructure, cloud and network
Much sociotechnical debt lives in poorly governed infrastructure. In the cloud, vendor and client share responsibilities: if the organization believes “it’s in the cloud” and no longer needs to worry about security, it usually discovers the mistake at the worst moment. Migrating without patching holes, without backups or a plan to leave if the vendor raises prices or changes terms exports disorder into monthly spend that did not figure in the initial budget.
The network is not a cuttable expense: it is business continuity. A point of sale without connectivity, online appointments that do not load, a cloud ERP unreachable on a Saturday —the human cost arrives before the technical one: customers waiting, operators improvising, owners losing sales. Hygiene includes an updated logical diagram —who depends on whom—, service-level agreements with providers and a named owner who maintains it.
Components (designed from day one)
| Component | What it does | Typical frequency |
|---|---|---|
| Governance routines | Bias review, data quality, compliance with AI policies | Monthly / quarterly |
| Living documentation | System health dashboards, drift alerts, updated glossary —not a dead PDF | Continuous |
| Transfer of judgment | Training in the reasoning of the design, not only which button to press | At handoff + refreshers |
| Sociotechnical debt indicators | Manual shortcuts, system bypass, shadow AI as signal that routines have fallen | Periodic review |
Each component has an owner in the organization —someone with a name, not “the systems area”. The bridge designs and trains; it does not operate forever without creating dependence on an external consultant.
Transition rituals
Organizations change through rites, not only diagrams. I explicitly incorporate two:
- Symbolic closure: a retrospective where the team acknowledges what worked in the previous process. Not bureaucratic nostalgia: productive grief. If no one can say “this part of the old system did help”, the new one starts with resentment.
- Opening: a celebrated demo, a name for the new flow, space where complaints are welcome in the first weeks. Early complaint is data; late complaint is consolidated resistance.
This connects with change management and the anthropological reading of work: the meaning of change is negotiated in public, not only in an internal memo.
The bridge’s role when stepping back
In advisor mode, the goal is autonomy with a safety net: periodic sociotechnical health audits, not daily system operation. If everything collapses when stepping back, hygiene was missing from the design, not only a poorly executed handoff.
See also: Concepts of our own · Psychology of adoption · Multidimensional value metrics · The bridge applied to the public sector