Pre-Mortem: NHS Federated Data Platform

 

On 3 August 2026, NHS England apologised. The apology confirmed what National Data Guardian Nicola Byrne had identified five days earlier: the Data Protection Impact Assessment (DPIA) for the Federated Data Platform had stated that only NHS staff could access identifiable patient data. That statement was wrong. Palantir staff held access to identifiable patient information within the national data integration environment, an arrangement the DPIA had not disclosed.

This is the fifteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

The Bet

NHS England is betting that a £330 million platform built on Palantir’s proprietary Foundry software can serve as the trusted data infrastructure for NHS analytics, and that the governance commitments made publicly about data access are auditable in practice. The bet has been partially called already. The DPIA that underpinned the programme’s public accountability framework described access controls that did not match operational reality. NHS England acknowledged the error and corrected it. The bet that now matters: that the February 2027 break clause decision, whether to extend or exit, can be made on the basis of accurate information.

The Assumption

The single belief the whole framework rests on: that NHS England can demonstrate meaningful oversight and control of a platform whose codebase NHS analysts cannot read or edit. Palantir owns the Foundry software. NHS analysts work within the platform but cannot examine or modify the code that shapes its outputs. The National Data Guardian (NDG) criticism was triggered by the gap between what was publicly asserted about data access and what was operationally true. If the accountability assertion in the DPIA did not survive scrutiny, the assumption that NHS England can verify what Palantir staff do with patient data inside a proprietary system deserves the same examination.

The Sequence

November 2023. Palantir wins the £330 million FDP contract.

April 2026. Parliamentary debate on the FDP. NHS England officials warned staff internally not to criticise the platform’s performance.

12 May 2026. NHS England confirms Palantir staff have administrative access to identifiable patient data in the national data integration environment, contradicting earlier assurances.

June 2026. The government announces a formal review of the Palantir contract, following a Science, Innovation and Technology Committee report that branded the company “an unacceptable point of weakness” in UK public sector infrastructure.

9 July 2026. The Health and Social Care Committee writes to the Health Innovation Minister recommending the exercise of the February 2027 break clause, citing “serious mistrust” among the public towards Palantir.

29 July 2026. National Data Guardian Nicola Byrne formally criticises NHS England for inaccurate DPIA disclosure.

3 August 2026. NHS England apologises and confirms the DPIA error.

The Pager

The National Data Guardian used her statutory function and the result was a public apology from NHS England. The named individual who authorised the submission of a DPIA that did not accurately describe Palantir staff access has not been identified publicly. Jules Hunt, interim Director General for Technology, Digital and Data, holds the relevant executive function. The chief digital and information officer role has not had a permanent holder since at least early 2025; the most recent interim departed in April 2026, before the DPIA error became public. The programme sits with interim leadership in the window immediately before the most consequential procurement decision of its lifespan.

The Proof

February 2027 is the break clause decision point. The Department of Health and Social Care must actively trigger the first extension; if it does not, the contract lapses in spring 2027. The Health and Social Care Committee’s recommendation is on the public record. The government has not yet responded. The outcome measure is binary and specific: the break clause is exercised or it is not. Whether the platform’s actual adoption record across NHS trusts factors into that decision is the proof measure.

Verdict

If the government exercises the February 2027 break clause, it becomes the first time a cross-party parliamentary committee recommendation, a National Data Guardian rebuke, and a public apology from the contracting body have together produced a procurement exit in NHS technology history. That would be a significant accountability signal for every future public sector AI contract. If the contract is extended, the question shifts to what changed in the governance architecture to justify continuation, and whether the interim executives carrying the programme can demonstrate what that change looks like in operational terms. The break clause is not a threat. It is a proof point with a date.

Pre-Mortem: A Billion Workers Scored in Secret. Is It Legal?

On 20 January 2026, two job applicants filed a class action against Eightfold AI Inc. in a California state court. The complaint alleged that the company had scraped personal data on over one billion workers, scored every candidate on a zero-to-five scale, and discarded low-ranked applicants before any human saw their application. The legal basis is the Fair Credit Reporting Act (FCRA). The plaintiffs’ central claim is not that the algorithm was biased. It is that the algorithm existed in secret.

This is the fourteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

 

The Bet

Eightfold AI and the companies deploying its platform are betting that an AI system which aggregates third-party data, including social media profiles, location data, and online tracking cookies, to score individuals for employment purposes does not meet the legal definition of a Consumer Reporting Agency under the Fair Credit Reporting Act. The complaint names Microsoft, Morgan Stanley, Starbucks, BNY, PayPal, Chevron, and Bayer as companies using Eightfold in their hiring process. Co-Founder and CEO Ashutosh Garg responded with a public statement on responsible AI, noting that the platform undergoes third-party bias audits and that data comes from candidates or employers, not third-party scraping. The bet is not about whether the algorithm is accurate. It is about jurisdiction: whether the FCRA, written before algorithmic hiring existed at this scale, reaches far enough to cover what Eightfold built.

 

The Assumption

The single belief the whole framework rests on: that an AI platform scoring candidates for employers is categorically different from a consumer reporting agency, because the platform does not produce a consumer report in the form the FCRA contemplates. Eightfold filed a 35-page motion to dismiss arguing precisely that. The hearing was held on 4 August 2026 before U.S. District Judge Yvonne Gonzalez Rogers in Oakland. No ruling has been published. If the assumption is wrong, the compliance obligations the FCRA places on consumer reporting agencies, including disclosure, consent, and accuracy mechanisms, apply to every AI hiring platform operating on third-party data at comparable scale.

 

The Sequence

20 January 2026. Class action filed by former EEOC Chair Jenny R. Yang and the nonprofit Towards Justice. The complaint: Eightfold AI functioned as an unregistered consumer reporting agency across a dataset of over one billion workers.

18 June 2026. Plaintiffs’ opposition to Eightfold’s motion to dismiss filed.

22 June 2026. In the parallel Mobley v. Workday case, a federal judge denied Workday’s motion to dismiss claims of race, age, and disability discrimination through AI hiring tools.

9 July 2026. Eightfold reply brief filed.

4 August 2026. Motion to dismiss argued in Oakland before Judge Yvonne Gonzalez Rogers. No ruling published as of 16 August 2026.

13 August 2026. Eightfold AI named “Agentic AI HR Solution of the Year” at the HR Tech Breakthrough Awards.

 

The Pager

Kistler et al. v. Eightfold AI Inc., No. 3:26-cv-01768 names Eightfold AI as defendant. No talent acquisition leader or CHRO at Microsoft, Morgan Stanley, Starbucks, or any other company deploying the platform has been named as a defendant, and no deploying company has publicly committed to disclosing the tool’s existence to applicants. The pager sits with the vendor. The question of who carries it at the companies deploying the platform remains unanswered.

Garg’s public statement on responsible AI is a creditable position. It does not address what obligations the companies using Eightfold carry, or what those companies owe to the candidates who may have been scored and discarded before a human saw their application.

 

The Proof

The motion to dismiss ruling is the first proof point. A denial advances the FCRA question to discovery and the merits. It would be the first federal answer on whether AI candidate scoring constitutes consumer reporting. A grant sends the question back to the FTC and Congress, where progress has not matched the scale of deployment. The outcome measure worth watching is not which side wins the motion. It is whether any major Eightfold client commits to applicant disclosure before the court decides whether disclosure is legally required.

 

Verdict

If Judge Gonzalez Rogers denies the motion to dismiss, the case advances and the FCRA question gets its first federal answer in the context of AI hiring tools. That ruling will matter to every organisation using algorithmic screening, not only Eightfold’s clients. A denial does not mean Eightfold loses; it means the question gets answered in a setting with evidence, argument, and binding precedent. If the motion is granted, the accountability gap returns to regulatory and legislative channels, where the pace has not matched the scale of the deployment. What would change this assessment is action of a different kind: a major employer publicly committing to applicant disclosure before the court makes the decision for them.

Your Gates Aren’t Protecting the Business. They’re Protecting Themselves.

Nobody sets out to build a bureaucracy. Every heavy stage-gate process started as three good intentions: get bad projects killed early, get good projects through fast, and keep a clean record of why each call was made. Then it grew a review board nobody remembers approving, and the good projects started waiting as long as the bad ones.

That is the actual failure. Not that gates exist. That almost nobody still measures them against the job they were built to do.

 

The Test a Stage Gate Was Actually Built to Pass

Governance run properly delivers three things, and nothing else matters as much as these: faster decisions, so a good project stops waiting weeks for a yes. Earlier kills, so a weak one frees up capital instead of quietly draining it for another two quarters. And a clean audit trail, so nobody has to reconstruct the reasoning after the fact. Get those three right and a stage gate speeds decisions. Miss them and it slows every decision down, good and bad alike, because the mechanism has stopped doing the job it was built for.

Someone genuinely has to decide which projects live, which pivot, and which ones are quietly draining the business. That much was never in question.

 

Why the Mechanism Rots

Four patterns do most of the damage, and each one accumulates quietly rather than arriving as a single bad decision. Entry gates get heavy while exit and kill discipline stay weak or disappear entirely, so zombie projects clog the funnel and starve the strong ones of attention. Panels grow larger and meetings grow longer until authority is spread across so many people that nothing actually gets decided. Reviews turn into theatre, rubber-stamping or deferring rather than choosing, and momentum dies in the gap between gates. And decision rights stay ambiguous enough that nobody is the clear owner of the yes or the no, so everything escalates and stalls at once.

Each of those four is a governance design that stopped serving the teams running through it and started serving itself, not a process flaw you fix by adding another step. The entry gate feels productive, so it keeps growing. The exit gate feels harsh, so nobody wants to own it, and that imbalance is where most of the trouble actually starts.

 

The Numbers Behind the Frustration

The frustration shows up in real operating numbers, not just complaints. At Vivix Vidros Planos, a Brazilian flat-glass manufacturer, resolving a customer complaint used to take weeks, long enough for a buyer to lose patience and take the next contract elsewhere. After building an AI-powered chatbot into its existing production and quality data, that shrank to minutes, an 80% reduction in complaint resolution time. Responses to production-line issues sped up by a further 85%. Both figures come from Vivix’s own case study, published jointly by Siemens and AWS. The underlying pattern holds regardless of the exact numbers: the real cost of a slow gate shows up as lost trust and lost contracts, not just lost hours.

 

What Minimum Viable Governance Actually Looks Like

The fix is sizing each gate to the actual risk in front of it, rather than running every decision through the same heavy process regardless of what it actually requires. A low-risk process tweak does not need the same panel as a bet-the-quarter platform launch, and treating both the same is exactly how standing committees fill up with work they should never see in the first place. High-risk decisions keep full board review, because that rigor is proportionate there. Mid-tier decisions get a lightweight gate with a single accountable owner. Low-risk work proceeds by default through a simple intake form, with oversight applied only if something in it actually warrants it.

The useful design target sits between two failure modes: above a ceiling, controls become bottlenecks and teams quietly route around them; below a floor, real risk creeps in unmanaged. Getting that band right is not abstract. One organisation that tightened its policy down to the minimum viable version halved the time complex decisions took and surfaced three times more opportunities than peers still running the heavier version.

 

The Test Most Gates Would Fail

Pick the last three projects your organisation killed at a gate, and the last three it approved. If the kills took longer to reach than the approvals, the gate is not protecting the business from bad decisions. It is protecting itself from having to make any decision at all.

Prompt Injection Is a Governance Failure Wearing a Technical Costume.

Every prompt injection headline reads like a technical failure. A model got tricked. A filter didn’t catch it. The vendor needs to patch something.

That framing is comfortable, and it is wrong. The technical trick is real. The governance failure sitting underneath it is the actual story, and it is the one almost nobody in the room wants to own.

 

Why the Trick Works in the First Place

The mechanism is architectural, not a bug in the usual sense. Large language models treat the system prompt, the user’s request, and any text retrieved from an external source as a single stream of tokens. There is no reliable internal boundary between an instruction and a piece of data. A hostile sentence buried in a document, a web page or a support ticket can carry the same authority as a command typed directly by a trusted user, because the model was never built to tell the difference.

OWASP’s 2026 State of Agentic AI Security and Governance report found prompt injection now maps to six of its ten top categories for agentic applications, up from a mostly theoretical concern in the 2025 edition to one backed by documented breaches and tracked vulnerabilities. Coding agents dominate the attack data, and only 37% of organisations report having a policy in place to even detect unauthorised AI deployments running inside their own environment.

 

The Failure Is a Control Boundary, Not a Model Flaw

This is where the governance framing actually matters. Prompt injection succeeds because enterprise workflows assume the model can reliably tell trusted instruction apart from hostile text, an assumption that fails the moment one interface carries user intent, retrieved content and tool-facing control signals in the same session. Most organisations respond by treating guardrails as a static filter list rather than a real system of content separation, monitoring and authorisation. A filter can catch a known bad phrase. It cannot answer the actual governance question, which is who controls what the system is allowed to do once it has been steered.

Security researcher Simon Willison’s “lethal trifecta” names the actual risk condition plainly: an AI agent with access to private data, exposure to untrusted content, and the ability to communicate externally, all three at once, is where exfiltration happens. Meta’s own internal guidance treats those three properties as a budget rather than a checklist. Combine all three and the agent needs a human in the loop before it acts, not after.

 

Why This Keeps Getting Treated as IT’s Problem Alone

Handing this to the security team as a patching exercise misses what the data is actually showing. A model update might close one exploit path. It will not answer who approved an agent’s access to a customer database, why that same agent can also send emails externally, or what happens the day it does both at once because nobody ever wrote down that it should not be allowed to. Those are ownership questions, not model questions, and ownership questions do not get solved by a vendor release note.

 

What Governance-First Actually Requires

Start by classifying every channel an agent reads from according to trust level, and keep untrusted content out of instruction scope entirely rather than hoping the model sorts it out at runtime. Quarantine tool access behind explicit policy gates, so an agent combining private data access, untrusted content and external communication needs sign-off before it can act, not a retrospective audit after it already has. Treat a pattern of near-miss prompts as an abuse signal worth escalating, not a string of isolated one-off incidents each closed out individually.

All of it is the same governance discipline organisations already apply to identity and access management, pointed at a new kind of actor that happens to run on language instead of credentials, not a new technology purchase.

 

Who Approved This, and Did They Know What They Were Approving

Before the next prompt injection incident gets logged as a technical exploit, ask who actually approved the access the exploit relied on.

If nobody can answer that cleanly, the model was never the vulnerability. The governance around it was.

Your Twenties Reward Hustle. Your Forties Reward Judgement. Few People Notice the Shift in Time.

Nobody tells you when the game changes. You keep playing the twenties game in your forties and quietly wonder why the same effort stopped yielding the same results.

The shift is real, not a mood. It has a name in the research and a shape most people never get to see clearly enough to plan around.

 

What Actually Peaks in Your Twenties

Stanford’s Center on Longevity has the cleanest explanation of why hustle works so well early. Fluid intelligence, the raw ability to solve new problems quickly without relying on prior knowledge, peaks as people enter their third decade. That is a genuine cognitive advantage, not a myth about youthful energy. Speed, pattern-spotting on unfamiliar problems, and the appetite to grind through volume are all things a twenty-something brain does better than it ever will again.

That is exactly why hustle gets rewarded so visibly early on. It is the highest-value thing on offer at that stage, and organisations are right to reward it.

 

What Actually Peaks Later, and Why Nobody Notices

The mistake is assuming that advantage holds. It does not, and something else takes its place instead of just fading. Crystallized intelligence, the accumulated knowledge and judgement built from lived experience, keeps rising well into the seventh decade. Emotional intelligence peaks in the forties. Moral reasoning keeps improving through adulthood. Stanford’s own framing of it is the clearest version I have read: the twenty-five-year-old brings speed and fresh perspective, the fifty-year-old brings integration and judgement, the seventy-five-year-old brings wisdom and pattern recognition across decades none of the others have lived through.

Almost nobody plans their career around that curve, because almost nobody is shown it. The result is a lot of very capable forty-somethings still competing on twenties metrics, wondering why the hours are not converting into the same visible wins they used to.

 

Early Excellence Does Not Predict What You Think It Does

A December 2025 review published in Science, covering nearly 35,000 world-class performers across sport, music, chess and the sciences, found that early standouts and eventual world-class performers are largely different people. Peaking early does not reliably predict who ends up at the top later. The performers who lasted tended to explore broadly before specialising, building a wider base of judgement to draw on rather than narrowing down early and grinding one lane harder than everyone else.

The same pattern shows up at executive level. Generalist chief executives, the ones with genuine cross-functional experience rather than a single specialist lane, file more than double the patents annually compared with specialist peers, with 55% higher originality ratings. Jeff Bezos building AWS and Satya Nadella’s Microsoft turnaround both drew on lateral experience outside their original speciality, not deeper hustle inside it.

 

What Judgement Actually Looks Like at Work

Judgement rarely looks impressive in the moment, which is part of why it goes unrewarded for so long. It looks like not escalating something that will resolve itself on its own, and letting a good-enough answer stand instead of spending three more hours perfecting a version nobody asked for. It looks like knowing which fight is worth having this quarter and which one can wait, a decision hustle never had to make because hustle just took every fight.

The forty-something who is still measuring their own value in hours and visible output is applying a twenties scorecard to a role that has already moved past it. The actual multiplier at that stage is rarely personal execution. It is knowing which three things matter this month and being willing to let the other twelve go undone.

 

The Shift Worth Naming Out Loud

Nobody sends a memo when hustle stops being the highest-value thing you offer and judgement takes over. It happens quietly, somewhere in the decade nobody warns you about, and the people who notice early enough to adjust are the ones whose forties look like a promotion instead of a plateau.

The question worth asking yourself this year is not whether you are working hard enough. It is whether you are still being rewarded for the twenties game, or you have quietly moved into a different one without updating your scorecard.

Pre-Mortem: The Accountability Question the Mills Review Left Open

On 6 July 2026, the Financial Conduct Authority published the Mills Review, its examination of how AI will reshape retail financial services in the UK. The review covers seven recommendations across the regulatory perimeter, oversight architecture, and the transition to autonomous decision-making. It names the accountability gap at the centre of autonomous AI trading. It does not close it.

This is the thirteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

 

The Bet

UK firms deploying autonomous trading AI are betting that the Senior Managers and Certification Regime (SMCR), the framework that holds named executives personally accountable for conduct failures in their area of responsibility, covers their position through general senior manager oversight. The FCA has been clear that delegating a decision to an algorithm does not transfer senior manager liability to the algorithm. The bet is that this principle, correctly stated and on the public record, can be demonstrated in practice before an enforcement case defines what demonstrating it actually requires.

 

The Assumption

Seven recommendations. One question still without an answer:

When an autonomous trading system executes a decision at machine speed, without pausing for human approval of the individual trade, which specific senior manager function is accountable if that decision causes a customer loss, and what does demonstrating adequate oversight of a system like that actually require?

The Mills Review acknowledged the problem directly. Without guidance, the review found, the combination of greater opacity in AI-mediated decisions and factors such as model drift makes it harder for the regulator to identify a de facto responsible individual, or for senior managers to evidence meaningful human control. Stakeholder feedback throughout the review called for clearer guidance on what constitutes the “reasonable steps” expected of senior managers. The review recommends the FCA develop it. The FCA has not yet published it. Every firm currently deploying autonomous trading AI is operating on the assumption that its existing accountability structure covers the gap. That assumption has not been tested in an enforcement case.

 

The Sequence

December 2019. SMCR extended to all FCA solo-regulated firms, completing its rollout across financial services.

27 January 2026. The FCA launched the Mills Review, acknowledging that AI in retail financial services had developed faster than the regulatory frameworks designed to govern it.

24 February 2026. Call for input closed.

6 July 2026. The review published seven recommendations. The FCA committed to adapting its regulatory frameworks as the transition to autonomous models continues. No guidance named a specific senior manager function as accountable for autonomous trading decisions. No guidance defined what “reasonable steps” requires for a system executing at machine speed without human review of individual decisions.

The capability reached the market before SMCR was tested against it. The review arrived after the capability. The guidance has not arrived yet.

 

The Pager

The FCA has confirmed there will be no dedicated Senior Manager Function for AI, and that accountability falls on existing functions. That is a clear policy position and it deserves credit for being stated plainly. The Treasury Select Committee has urged the FCA to publish guidance specifying the level of assurance expected of senior managers for AI-related harm. The Mills Review carried that request forward into its recommendations. The harder question is the one seven recommendations did not answer: when an autonomous trading system causes a customer loss, which specific function holder carries the call?

 

The Proof

There are no enforcement cases. The first case will establish what “reasonable steps” means in an AI trading context. The Mills Review is a process measure: it produced recommendations. The outcome measure worth watching is whether the FCA’s follow-on guidance names a specific function and defines the oversight standard in operational terms rather than principles alone. A principle restated is not a gap closed.

 

Verdict

If the FCA’s follow-on guidance names the senior manager function accountable for autonomous trading AI and defines what “reasonable steps” requires at the operational level, UK financial services will have resolved an accountability gap that every other major jurisdiction is still navigating. The review’s existence, the named individual who led it, and the seven published recommendations are genuine evidence that the FCA identified the problem and moved on it. Without operational guidance, the gap stays open. The first enforcement case will write the rule in the least comfortable setting available. That is a considerably worse way to write it.

Why Traditional Project Management Is Failing Modern Teams

Why Traditional Project Management Is Failing Modern Teams

Most project failures get blamed on execution. A missed deadline. A stakeholder who went quiet at the wrong moment. A scope that crept until nobody could point to when it happened.

Look earlier and the failure was already built in before a single sprint started.

A Forbes Technology Council analysis makes the point directly: misalignment gets embedded into the foundation long before execution begins, not manufactured somewhere in the middle. The team that won the deal rarely stays involved in delivery. The customer’s actual operating mindset only reveals itself once work is already moving. The incentives written into the contract often point delivery and client in different directions before day one. Teams execute a plan that was already structurally unsound before the first sprint started.

Traditional project management was never built to catch that kind of problem. Waterfall assumes you can define requirements fully upfront, lock them, and deliver against a fixed spec months later. That assumption survives about as long as the first change request. Priorities that shift inside a six-week planning cycle, which describes most programmes now, make a locked spec obsolete before it has even shipped.

 

Rigidity Is the Symptom. Something Else Is the Disease.

Here’s the twist most framework debates miss. Methodology by itself isn’t what separates the teams that deliver from the ones that don’t. PMI’s most recent Pulse of the Profession research found project performance sits at roughly 73.8% whether a team runs predictive, hybrid, or agile delivery, and whether people work remote, hybrid, or in-person. What actually moved the needle was business acumen: professionals strong in it posted 27% lower failure rates, regardless of which framework sat on the wall.

Framework still matters. It was just never the whole story, and treating “which methodology” as the central question misses where most programmes actually break.

A PM Solutions case study makes the same point at a larger scale. A U.S. staffing company with more than 8,000 internal and 90,000 contract employees had already tried and failed to stand up a PMO once. On the second attempt, the team built a hybrid methodology suited to the client’s actual environment, blending traditional project management, agile, and the touchpoints where each meets software delivery, then added a governance structure, portfolio visibility and resource planning on top of it. Within six months, every project flagged red under the new reporting system, more than $13 million worth of work, was recovered. One severely troubled multi-year project, over budget and behind schedule, was turned around in four weeks once it had a dedicated programme manager working inside that structure. Not a framework doctrine. Governance and visibility.

 

The Real Adoption Curve

That pattern shows up in the adoption numbers too. Hybrid delivery has grown 57% since 2020, while purely predictive approaches have fallen 24% over the past three years. The pattern behind that shift is simple: pure Waterfall and pure Agile were both answering questions the actual work wasn’t asking, and organisations are admitting it with their adoption numbers rather than in a strategy memo.

Rigid, one-size-fits-all implementation is what actually ages badly, more than the framework choice underneath it. Portfolios that mix delivery models by what the work actually demands, a predictable cadence for mature products, flow-based delivery for continuous work, fast validation cycles for early bets, consistently outperform portfolios that force every initiative through the same certified process regardless of fit.

 

What This Means for the Programme You’re Running Now

The practical shift isn’t abandoning structure for chaos. It’s building governance that travels with whichever delivery model fits the work, instead of assuming the delivery model is the governance.

Start by naming decision rights before the kickoff, not after the first dispute breaks something. Someone owns scope changes. Someone owns the call when a dependency slips. Everyone on the programme should be able to name both without asking. Build the escalation path into the plan itself rather than inventing one under pressure in week eight, and match the delivery model to the type of work in front of you rather than to what worked on the last programme. A regulated, multi-vendor transformation and a ten-person product team shipping a new feature are not the same problem, and forcing them through the same framework produces the same failure pattern twice.

Track what the framework was supposed to deliver, not whether the ceremonies happened. A team that ran every stand-up and still shipped nothing useful followed the process and failed anyway.

 

The Question Every Kickoff Should Answer First

Before the next programme gets a charter and a framework stamped on the cover page, ask a harder question first: who owns the decision when priorities collide, and does that answer exist in writing before the first sprint starts?

If it doesn’t, the framework on the cover page was never going to save the programme underneath it.

The $5.5 Trillion Bill for Doing Nothing About AI Skills

IDC put a number on the cost of enterprises not knowing what to do about AI skills: $5.5 trillion. Not by 2030. By the end of 2026.

That is not a distant workforce-planning problem. It is the price tag on decisions organisations are making, or more often deferring, this quarter.

The number comes from IDC’s survey of enterprise IT leaders across the US and Canada. It measures a specific kind of pain: product delays, lost competitiveness, and business walking out the door because the people needed to build and run AI capability were not there when the work needed them.

An IDC Spotlight Paper distributed via workforce-skills platform Workera applies the same figure directly to the AI skills conversation, and the application largely holds up. Most of what IDC’s original survey describes as a broader tech talent shortage is, in practice, an AI capability shortage wearing a wider label.

Three other figures make the same point from different angles. The World Economic Forum’s Future of Jobs Report 2025, surveying over a thousand employers and 14 million workers across 55 economies, found that 59% of the global workforce will need reskilling or upskilling by 2030, and that 11% of that group are unlikely to receive it. Indeed’s hiring data shows the share of job postings with “AI” in the title has more than tripled since 2022, from 2.6% to 8.3%. And PwC’s 2026 Global AI Jobs Barometer, built on more than a billion job advertisements, found that AI-skilled workers now command a 62% wage premium over comparable peers, up from 57% the year before and roughly 25% two report cycles before that.

These numbers describe a market that has already repriced itself, not a future state, while most enterprise workforce plans are still budgeted as though it hasn’t.

 

The Premium Is the Market Telling You Something

Wages move slowly almost everywhere except where genuine scarcity exists. A skill premium that has climbed from roughly 25% to 62% across three consecutive PwC survey cycles is not a normal labour-market signal. When a specific skill commands 62% more pay than the equivalent role without it, and that gap is still widening year over year, that is the market pricing in a shortage faster than most HR functions can respond to it, not a talent management curiosity.

Second Talent’s 2026 research puts a shape on that shortage: roughly 1.6 million open AI-related roles globally against around 518,000 candidates qualified to fill them, a demand-to-supply ratio a little over three to one. Every organisation competing for AI capability right now is competing inside that gap, and every quarter spent treating reskilling as a training-budget line item rather than a capital allocation decision is a quarter spent losing that competition to whoever moved first.

 

Why This Belongs in the Risk Register, Not the Learning and Development Plan

Most organisations still route AI reskilling through the same governance as any other training initiative: an L&D budget line, a completion metric, a once-a-year review. That treatment made sense when the skills in question were incremental. It does not hold up against a $5.5 trillion cost estimate and a wage market moving by double digits year over year.

A capital risk gets tracked differently to a training initiative. It gets a named owner, a quantified exposure, and a review cadence tied to the business calendar rather than the HR calendar. Few organisations apply that discipline to AI skills, because the function historically responsible for skills, HR, was never built to run risk registers, and the function that runs risk registers, finance and the PMO, was never asked to own workforce capability.

That gap in ownership is the reason the $5.5 trillion figure keeps compounding instead of shrinking, not a technicality.

 

What Actually Changes the Trajectory

Closing this gap requires three specific shifts most organisations have not made, not a bigger training budget.

Put a named executive owner on AI capability risk, distinct from whoever owns general L&D, with the same reporting rigour as any other material risk on the register. Measure the capability gap in the terms the wage market already uses: roles you cannot fill, roles you are overpaying to fill, and work you are declining because you lack the people to do it, not completion percentages on a training platform. And treat the reskilling decision as time-sensitive capital allocation, where every quarter of delay is a quarter in which the 62% premium, and the competitors already paying it, get further ahead.

 

The Window Is a Cost Curve, Not a Deadline

There is no single date after which the AI skills gap becomes unrecoverable. What exists instead is a cost curve that gets steeper the longer it is ignored, priced daily by a labour market that has already decided what AI capability is worth.

The organisations that treat this as a 2027 problem will be paying 2026 prices for it well into the decade. The ones already moving are the ones setting the price.

The Governance Training Nobody Budgets For

Nobody has ever failed a project because they didn’t know how to build a Gantt chart. However some failed because nobody taught them who was allowed to say no.

I have sat in quite a number of programme inductions, and every one of them covers the same ground. Scheduling. Budgeting. Risk logs. RAID templates. Reporting cadence. Then, somewhere around the second afternoon, someone puts up a slide about governance and the room’s attention visibly leaves the building. It is treated as the compliance module, the thing you sit through before you get to the real work. Nobody walks out able to say, with any confidence, who actually owns the call when a decision does not fit neatly on a template.

That gap is not an oversight. It is a choice organisations keep making, year after year, without ever naming it as one.

 

The curriculum has a hole in it

Ask a newly promoted programme manager to explain their RAID log and they will do it fluently. Ask them who has the authority to accept a risk above a certain threshold without escalating it, and watch the pause. That pause is the sound of someone realising they were never actually taught the answer, only ever expected to absorb it by watching more senior people long enough.

A 2026 AI Governance Gap Report surveying more than 500 HR professionals found that only 45 per cent of organisations provide AI literacy training to all employees, one concrete, measurable instance of the broader governance-literacy gap this piece is about. Two-thirds of HR teams are already using AI to shape compliance and policy decisions, and the same report found fewer than half have given employees even that AI-specific literacy training to keep pace. The gap shows up well beyond HR too, in every function that has ever built a decision-rights framework, filed it in a folder, and assumed the document itself did the teaching.

Documents do not teach. People do, and usually only the ones who were already senior enough to have picked it up somewhere else.

 

Decision rights are treated like folklore

Most organisations do not lack a governance framework. They have one, usually a good one, sitting in a policy library that almost nobody outside the PMO has opened. What they lack is a mechanism for turning that document into instinct.

The result is a workforce that learns decision rights the hard way: by guessing wrong in front of a steering committee, by escalating something trivial and being quietly told off for wasting everyone’s time, or by not escalating something serious and finding out only when it has become a crisis. Every one of those is an expensive way to teach a lesson that could have been taught in an afternoon.

This is where the “knowing-doing” research cited by Harvard Business Review becomes uncomfortable reading for anyone who runs a training budget. Two out of three managers say they are still uncomfortable having accountability conversations with their own people, despite most of them having sat through the leadership training designed to prepare them for exactly that. The problem was never a shortage of content. Knowing a framework exists and being able to act on it under pressure are two entirely different skills, and organisations keep training the first while assuming it produces the second.

Governance training suffers from the same fault line. Knowing there is an escalation policy is not the same as recognising, in the middle of a stressful Tuesday, that the decision in front of you is the one the policy was written for.

 

The training everyone skips because it looks obvious

There is a reason this particular gap survives budget reviews when almost nothing else does. Governance training looks like it should be simple, so nobody prioritises building it properly. Everyone assumes the framework document is self-explanatory, right up until the moment someone makes the wrong call and the post-incident review discovers that three different people had three different understandings of who was supposed to decide.

I have run those reviews. The finding is almost never “the framework was wrong.” Almost always, nobody had ever been walked through what the framework meant in a live situation, so everyone applied their own version of common sense, and common sense is not actually common.

 

What actually needs teaching

A longer policy document will not fix this. Longer documents get read less, not more. The fix is teaching people to recognise a decision point before it arrives, not after.

That means running people through real scenarios instead of abstract categories, trading “what is your escalation threshold” for “here is a supplier problem that looks small and is not, what do you do in the next ten minutes.” It means naming, out loud and often, the handful of decisions in your organisation that carry disproportionate weight, so people learn to feel the shape of one before it is labelled for them. And it means treating governance literacy the way you would treat safety training: refreshed, tested, and taken seriously enough that senior leaders visibly participate in it themselves, rather than left as a one-off induction module.

The organisations that get this right build fewer, better decision-makers rather than thicker governance frameworks: people at every level who can spot a genuine decision point on instinct, the same way an experienced engineer can hear an engine fault before the dashboard lights up.

You cannot budget for the crisis a decision creates and then refuse to budget for teaching people to see it coming.

 

 

Small Talk Is Not Wasted Time. It Is the Only Rehearsal for Big Trust.

Most executives treat small talk as the tax you pay before the real conversation starts. Research on negotiation and workplace behaviour suggests it’s closer to the opposite: the low-stakes rehearsal that determines whether the real conversation goes anywhere at all.

 

What the Research Actually Shows

A frequently repeated claim holds that people who make small talk before negotiating are four times more likely to reach agreement. That number doesn’t survive a check against the study it’s supposedly drawn from. The actual 2002 research behind it, published in Group Dynamics, found something more modest but still real: negotiators who “schmoozed” beforehand reported significantly higher rapport than those who didn’t, and reached an impasse less often, 40.6% of the time versus 60.7%, though that gap was only marginally significant. The finding itself is that small talk measurably raises rapport and modestly improves outcomes. It is not some four-times multiplier, and repeating the inflated number would undercut exactly the kind of precision this argument needs to be taken seriously.

 

The Mechanism, Confirmed More Recently

A 2021 study in the Academy of Management Journal tracked 100 employees across 978 daily workplace observations over three weeks and found small talk works through a specific, two-sided mechanism: it “enhanced employees’ daily positive social emotions at work,” which increased helpful, cooperative behaviour toward colleagues, while simultaneously disrupting people’s ability to concentrate on their actual tasks in the moment. Both things are true at once. Small talk builds the social capital that makes cooperation possible later, and it costs a small amount of focus right now. A 2024 qualitative study of 35 B2B professionals found the same rapport-building mechanism operating specifically in negotiation contexts, identifying genuine curiosity, active listening, and respect for boundaries as the actual ingredients, not just friendly chatter for its own sake.

 

The Counterargument Worth Taking Seriously

Not everyone in this field agrees, and the disagreement is worth taking seriously rather than editing out. Kim Scott, whose Radical Candor framework has shaped how a generation of executives think about direct feedback, has argued the opposite case directly: real trust with employees comes from substantive one-on-ones and working relationships, not casual chat, and treating small talk as the relationship-building mechanism risks substituting a comfortable habit for the harder work of actually knowing someone. That critique lands hardest in ongoing management relationships. The negotiation and cross-cultural research above is mostly about a different situation: the first few minutes with someone you don’t yet have a working relationship with, where there’s no substantive history to draw on yet, and small talk is the only tool available to establish enough trust for the real conversation to start at all.

 

Why This Matters More in Some Rooms Than Others

Research on Arab business negotiators found relationship-building carries even more weight in that context, with negotiators leaning on personal networks and trust-building as central to how deals actually get made, rather than an optional warm-up. The mechanism isn’t unique to any one culture. It’s just more visibly load-bearing in markets where trust is built through recurring personal contact rather than through contracts alone.

 

What This Means in Practice

Skipping small talk to “get to the point faster” isn’t efficient. It’s removing the only low-stakes moment where two people calibrate whether they trust each other, before the stakes get high enough that a miscalibration actually costs something. The application is genuine curiosity about the person in front of you, delivered before you need anything from them, rather than performed friendliness, so that when you do need something, the trust required to ask for it is already there.