Your AI Steering Committee Meets Monthly. Your AI Ships Weekly.

Most AI governance committees meet on a monthly or quarterly cadence. Most AI systems do not wait for them.

Anthropic’s own release notes tell the story in a single scroll. Opus 5 launched in late July 2026, a step-change release over Opus 4.8, which was barely two months old at the time. Sonnet 5 landed a month before that, at the end of June. Opus 4.8 before that, in late May. Opus 4.7 before that, in April, with breaking API changes attached. Opus 4.5 in November 2025. Sonnet 4.5 in September. Six major model versions inside ten months, with incremental API and feature changes logged in between on a near-weekly basis. That is one vendor’s changelog. Most enterprises are running several.

 

The Governance Side Has Not Kept Pace

Deloitte’s 2026 State of AI in the Enterprise survey, covering 3,235 business and IT leaders across 24 countries, found that only 21% of organisations have a mature governance model in place for agentic AI. Meanwhile, 74% of the same leaders expect their organisation to be using AI agents at least moderately by 2027, with 23% expecting extensive use and 5% expecting full integration.

That is not a small gap closing gradually. It is deployment intent running well ahead of the governance capable of managing it, at the exact moment agentic systems are gaining the authority to act rather than just draft.

 

People Have Already Stopped Waiting

The gap does not sit quietly while committees catch up. A Cybernews survey of more than 1,000 US employees found that 59% use AI tools their employer never approved. Among executives and senior managers specifically, the same survey found 93% do the same. The people who would sit on the steering committee approving AI use are, by a wide margin, the people going around it.

That is the quiet part of this problem. The people with the authority to slow things down are the ones setting the pace of the tools rather than the pace of the committee.

 

What Happens When the Gap Surfaces

Gartner’s prediction for next year is specific: 40% of enterprises will have their autonomous AI efforts partly derailed by governance gaps discovered only after a production incident, not before one. Sanchit Vir Gogia of Greyhound Research, commenting on the same data, put the mechanism plainly: “the real governance problem is not model intelligence. It is delegated operational authority moving across trust boundaries faster than enterprises can instrument, constrain, or audit it.” His own warning, in his words: “Do not scale agents faster than you can govern their authority. A small number of well-governed agents will create more enterprise value than a sprawling estate of clever, fragile, over-permissioned digital apprentices.”

 

What Governance Cadence Actually Needs to Look Like

The fix is not more meetings. A committee that reviews AI deployment quarterly cannot govern a system that changes weekly, no matter how thorough each quarterly review is. What changes the equation is moving from periodic review to continuous, tiered oversight: automatic flags for any new agent or capability change above an agreed risk threshold, standing authority delegated to a smaller operational group empowered to act between full committee meetings, and a real audit trail that lets the full committee review what was approved at pace, after the fact, rather than approving everything before the fact and creating the exact bottleneck this problem describes.

Keeping oversight in place does not mean keeping the quarterly cadence that was designed for a technology that no longer exists.

 

The Question Worth Asking Before the Next Steering Committee Meeting

Ask what actually changed in your AI environment since the last meeting, specifically, not generally. If nobody in the room can answer that with real detail, the governance structure is reviewing a snapshot that was already out of date the moment the meeting started.

The organisations that get this right are not the ones meeting more often. They are the ones who redesigned what needs a meeting at all, and gave someone standing authority to handle everything else in between.

The Difference Between an AI Pilot and an AI Programme Is Who Gets Blamed When It Fails.

A pilot has no name attached to its failure. A programme does. That is the entire distinction, and almost nobody treats it as the one that matters.

Ask most organisations why their AI initiative is still called a pilot eighteen months after launch and the answer usually involves budget, integration complexity or waiting for the model to mature. The real answer is simpler and less comfortable. Nobody has agreed who owns the outcome if it goes wrong, and a pilot is the one structure where that question never has to be answered.

 

The Pilot Was Never Built to Answer This Question

MIT’s Project NANDA found that 95% of generative AI pilots fail to deliver a measurable return, based on 150 leadership interviews, a survey of 350 employees and analysis of 300 public deployments. The report itself points to a different explanation: tools that never adapt to how the organisation actually works, budgets aimed at sales and marketing while the real return sits in back-office automation, and internal builds that consistently underperform specialist vendor partnerships.

Underneath all three is the same gap. A pilot is built to prove a capability exists. Whether anyone is answerable for what happens once that capability touches real customers, real decisions and real money is a different question, one a pilot was never built to answer. Most organisations discover this the hard way, months into a pilot that technically works and still cannot get budget to go further, because nobody signed up to own what happens next.

 

Ownership Is the Line, Not Scale or Budget

Grant Thornton’s 2026 AI Impact Survey of 950 senior leaders found 78% lack strong confidence they could pass an independent AI governance audit within 90 days. Among organisations still piloting, that confidence drops further, to just 7%. The gap shows up directly in results: organisations with fully integrated AI are close to four times more likely to report AI-driven revenue growth than those still piloting, 58% against 15%.

Grant Thornton’s Tom Puthiyamadam put the underlying issue plainly: organisations that have invested in governance move faster precisely because they have the confidence to scale, while the ones without it are one incident away from a far harder conversation.

MIT’s own findings point the same way: among the factors separating pilots that scale from the ones that stall, the report names empowering line managers, not just centralised AI labs, to drive adoption. A central lab can build a working model, but naming who answers for what that model does inside someone else’s process is a separate task entirely, one a programme takes on and a pilot leaves undone.

 

What a Programme Actually Commits To

Turning a pilot into a programme is not a budget decision. It is naming, before the next phase starts, who is accountable if the thing fails in production, what failing actually means in that specific context, and what happens in the following week if it does. None of that requires new technology. It requires a decision most organisations postpone precisely because a pilot lets them.

Just 38% of organisations have a formal, comprehensive AI policy in place, up from 28% the year before, according to ISACA’s 2026 research covering more than 3,400 digital trust professionals globally, which means most of what currently passes for AI governance gets improvised the first time something breaks, rather than designed before it ships. An owner named after an incident is not accountability. It is damage control wearing accountability’s name.

The organisations closing the gap treat this as day-one work, not late-stage paperwork. A named business owner, not a technical one, accountable for the outcome. And a clear definition of what failure looks like for that specific use case, agreed before launch rather than improvised during the post-mortem.

 

Whose Name Is on This When It Breaks

Before the next AI initiative gets called a programme instead of a pilot, ask one thing in the room where budget gets approved: if this fails next month, whose name is on the outcome, and did they agree to that before it happened or only after.

Most organisations cannot answer that today. That gap explains why so many pilots never leave the lab.

Patience Is Not Passive. It Is the Hardest Active Choice Most People Never Make

Patience gets treated as the absence of action: the thing you’re doing while you wait for something else to happen. The clearest evidence says that’s backwards, not from child-development research, but from what happens when trained professionals are given a straight choice between waiting and acting. Patience is usually the harder, more active choice, and impulsive action is often the easier one dressed up as decisiveness.

 

Retiring the Marshmallow Test

Any conversation about patience eventually reaches for the marshmallow test, the classic finding that children who delayed eating one marshmallow to get two later did better in life. A 2024 replication study in Child Development, using far larger and more representative data than the original, found the test doesn’t reliably predict adult outcomes at all: nearly every regression-adjusted relationship between childhood marshmallow performance and adult achievement, health, or behaviour came back statistically insignificant. The honest version of patience research doesn’t lean on a famous but shaky finding about children. It looks at what patience actually costs adults making real decisions.

 

The Bias That Makes Patience Feel Wrong

Behavioural economists have a name for the instinct patience has to fight: action bias, the tendency to act even when the evidence says waiting is the better choice, because acting feels like doing the job and waiting feels like doing nothing. A widely cited study of professional goalkeepers facing 286 penalty kicks found this bias in its purest form: goalkeepers dive left or right the overwhelming majority of the time, even though staying in the centre of the goal is statistically the better strategy, since kicks go there roughly 29% of the time. Goalkeepers dive anyway, because conceding a goal while standing still feels worse, and looks worse, than conceding one while visibly trying.

Medical research on “intervention bias” finds the identical mechanism in physicians: doctors reliably feel more satisfied recommending a treatment than recommending watchful waiting, “giving a sense of greater activism in their patients’ care,” even when the evidence supports doing nothing. Neither of these is really about competence. Both are about how much easier it feels to have visibly acted, regardless of whether acting was actually correct.

 

What Patient Leadership Actually Looks Like

A qualitative study of leaders who are known for patience found something specific underneath the trait: patience functions as a decision-making framework in its own right, not an absence of one, guiding a distinct process for weighing a situation before committing to act on it. A separate survey of 578 working professionals found leaders rated as more patient saw their teams’ self-reported creativity and collaboration rise by an average of 16%, and productivity by 13%.

A six-year study of more than 20 pairs of executives working in genuinely volatile markets coined the useful term for what this looks like in practice: active waiting. Not paralysis, and not indecision. Deliberate preparation during a lull, so that when a real opportunity actually opens, the leader can act decisively rather than reactively.

 

Why the Harder Choice Rarely Gets Made

None of the research above suggests patience is passivity’s better name. It suggests the opposite: patience requires resisting a bias that’s actively working against it in the moment, on a soccer pitch, in an exam room, or in a boardroom under pressure to be seen doing something. The impulsive decision is usually the one that requires less discipline, not more, because it removes the discomfort of visibly not acting while everyone is watching.

 

The Actual Choice Worth Making

The next time waiting is the objectively better move and doing something still feels necessary, the honest question isn’t whether patience is the right call. The research says it usually is. The question is whether you can tolerate looking like you’re doing nothing for exactly as long as doing nothing is correct.

Governance Fatigue Is Real, and It’s Killing the Governance That Matters

Every governance failure gets the same response: add a committee. Nobody ever asks which of the five committees already in the room should be deleted.

I have watched this play out on the same programme, twice, thirteen months apart. An incident happens. A review is commissioned. The review recommends a new gate, a new sign-off, a new board with a name that sounds important. Nobody asks whether the five existing boards had already covered this ground and simply were not being used properly. The new layer gets built. The old layers stay exactly where they were, because retiring a control is a much harder conversation than adding one, and nobody wants to be the person who removed the safeguard right before something went wrong.

Multiply that pattern across a few years of incidents, mergers, audits and regulatory nudges, and you get an organisation with more governance than anyone can actually operate.

 

The sprawl nobody planned and everybody built

Governance frameworks get bloated one reasonable-sounding addition at a time, not in a single decision. A near-miss produces a new checkpoint. An audit finding produces a new form. A departing executive leaves behind a committee that made sense under their sponsorship and none under anyone else’s. Each addition was defensible in isolation. Nobody ever sat down and asked what the whole structure looked like once you added them all together.

The organisations most proud of their governance maturity are often the ones carrying the heaviest version of this problem. More boards. More gates. More documented sign-offs. It reads as rigour on an org chart and feels like wading through treacle to anyone actually trying to get something delivered.

 

Fatigue looks like silence, not rebellion

The expensive part is what people do once the meetings stop making sense to them, not the extra meetings. They do not object. They do not escalate the absurdity of an ninth sign-off. They quietly learn which boxes can be ticked without real scrutiny, which approvals are theatre, and which route gets something through fastest regardless of whether it is the correct one.

That is governance fatigue, and it is far more dangerous than having too little governance in the first place. An organisation with no controls at least knows it is exposed. An organisation with too many controls believes it is protected, right up until the one decision that actually mattered slipped through a gate everyone had stopped taking seriously.

 

Clarity beats volume, every time

The research on decision rights backs this up more directly than most governance debates acknowledge. Itonics’s analysis of partner and programme governance found that organisations using a properly maintained RACI framework report 70 per cent fewer “who decides” disputes and 25 per cent faster decision cycle times. RACI works by replacing ambiguity with a single, shared answer to a question that used to require a meeting to resolve, not by adding another layer. The gain comes from governance that is unambiguous enough that people stop needing to ask, rather than from adding more of it.

That is the distinction most organisations miss when they respond to a failure by adding structure. The problem was usually oversight so diffuse that nobody could say, without checking three separate documents, who actually held the decision.

 

The discipline of taking something away

Fixing this requires a habit most organisations have never built: retiring governance on purpose. Every new control should come with an audit of what it is replacing, not just what it is adding. Every steering board should have to justify its existence against a simple test: if this group disappeared tomorrow, what decision would genuinely not get made anywhere else? If the answer is “nothing, it would just move up a level,” that board is inertia with a calendar invite, not governance.

The organisations that manage this well treat their governance structure the way a good engineer treats a system under load, asking what is carrying weight it no longer needs to carry and taking it out, rather than just adding capacity when something breaks.

Governance was never supposed to be heavy. It was supposed to be clear. Somewhere along the way, most organisations mistook the two for the same thing.

 

What We Found When We Measured Adoption, Not Just Deployment.

A go live report is easy to write. Every site is on the new system, every licence is issued, every training session delivered on schedule. Three months later, the usage dashboard tells a different story, and it is the dashboard nobody puts in front of the steering committee.

 

The Metric Everyone Reports

Deployment is countable in a way adoption never is. Percentage of sites migrated, number of licences activated, hours of training delivered, these are the figures that go into a programme status report because they can be measured on the day the rollout finishes. None of them says whether anyone is still using the system a quarter later, or whether they have quietly gone back to the spreadsheet it was meant to replace.

 

The Number Nobody Puts in the Steering Deck

IBM’s 2026 Global CEO Study, based on more than 2,000 chief executives surveyed worldwide by the IBM Institute for Business Value, found that only 25 per cent of workers use AI regularly in their jobs, even though 86 per cent of CEOs believe their workforce already has the skills to do so. Eighty three per cent of the same CEOs said AI’s success depends more on people’s adoption than on the technology itself. The rollout finished on schedule. The adoption did not follow.

 

What Poor Adoption Actually Costs

A Forrester Consulting study commissioned by Whatfix, surveying 335 senior decision makers at large organisations across North America, Europe, APAC and India, put a figure on what that gap costs a mid-sized enterprise, $10.9 million a year, plus 728 hours lost per employee navigating systems that were rolled out but never properly embedded. That is not a training budget line. It is the ongoing cost of a deployment nobody followed up on. The same research found a wide gap between organisations with adoption maturity and those without, 53 per cent of mature adopters reported improved user experience against 28 per cent of the rest, and 56 per cent reported stronger return on investment against 28 per cent.

 

Why Deployment Metrics Miss This

Programme reporting is built around milestones a PMO can close off: go live achieved, training complete, licences distributed. Adoption behaves more like a curve than a milestone, one that keeps moving long after the project has been marked complete and the team has moved on to the next initiative. By the time low usage shows up in a satisfaction survey or a renewal conversation, the people who owned the rollout are three programmes further down the roadmap.

Part of the reason adoption rarely gets measured is that almost nothing in a typical programme is set up to reward it. Vendor contracts are frequently structured around go live milestones rather than usage thresholds, so the commercial incentive to keep measuring stops the day the system switches on. Programme teams are resourced to deliver a rollout, not to own what happens to it afterwards, and by the time adoption data would be available, the team has usually been reallocated to the next initiative. None of this is deliberate. It simply reflects a reporting structure and an ownership structure that both end at the same milestone.

 

What We Started Measuring Instead

On some programmes I have run, the fix had less to do with better software and more to do with what the steering committee agreed to look at. We started tracking active usage at 30, 60 and 90 days after go live, alongside a simple drop off rate, how many people who logged in during week one had stopped logging in by week twelve. We also moved benefits realisation sign off away from the go live date and tied it to a usage threshold instead, so a project could not be closed as successful until people were actually using what had been built. It is a small governance change, and it surfaces problems a deployment report never will.

Rollout dates and licence counts still matter, deployment discipline was never the issue. What most programmes are missing is a second dashboard sitting next to the first one, what deployment made possible, and what adoption is showing three months after anyone stopped watching. The programmes that quietly fail are rarely the ones that missed a go live date. They are the ones that hit it, reported it as a win, and never checked what happened next.

Your Reputation Travels Faster Than You Do. Act Accordingly.

Most executives manage their reputation like a local matter: how you’re seen in this room, on this team, in this market. That’s the wrong frame. Reputation moves through networks faster and further than any individual career move, and it arrives in the next room before you do.

 

The Research Behind Why Word Travels

A 2022 study in Science, based on five years of randomised experiments across 20 million LinkedIn users, 2 billion new connections, and 70 million job applications, found that professional information travels most efficiently through weak ties, not close friends. The loose, wide network of people who know you a little, rather than the small circle who know you well, is what actually carries information about you into rooms you haven’t entered yet.

That mechanism cuts both ways. It is exactly how good work gets you noticed somewhere new. It is also exactly how a reputation for cutting corners, mistreating people, or leaving a mess behind you gets there first.

 

What Happens to Reputation That Travels Badly

The clearest, most rigorously measured evidence of this comes not from executive search literature, which is surprisingly thin on hard numbers, but from corporate governance research on company directors. A 2005 study in the Journal of Accounting Research tracked 409 US firms that restated their earnings between 1997 and 2001. Directors of those firms lost roughly a quarter of their positions on other, unrelated companies’ boards afterward, not just the one where the restatement happened. A related 2007 study in the Journal of Financial Economics found that outside directors named in shareholder fraud lawsuits saw a measurable decline in how many other directorships they held, even at companies with no connection to the original case, at an estimated cost of roughly $1 million per lost seat.

That is reputation travelling, quantified: conduct in one boardroom measurably closing doors in boardrooms that had nothing to do with it.

 

Real Cases, Not Hypotheticals

Steve Wynn resigned from Wynn Resorts in 2018 following sexual misconduct allegations. The consequences did not stay in Nevada. Massachusetts gaming regulators, investigating a market he had never previously operated in, fined the company $35 million and forced it to strip his name from its brand-new $2.6 billion property before it opened, renaming Wynn Boston Harbor to Encore Boston Harbor specifically to distance the business from him. He personally paid $10 million in 2023 to permanently exit the Nevada gaming industry. A reputation formed in one state travelled into a state where he had never done business, and shaped how a market he’d never worked in treated him before he arrived.

Travis Kalanick’s departure from Uber followed him into an entirely new, unrelated venture years later. Coverage of his food-delivery startup CloudKitchens traces his Uber exit “amid a firestorm of privacy concerns, allegations of widespread sexual harassment and gender discrimination,” then quotes a former CloudKitchens executive calling it “the most toxic place I’ve ever seen or experienced,” and an operator who said the company “tried to destroy” the brand he had built there. The new business was never assessed purely on its own merits. It was read through the lens of the one he had just left.

Not every case ends the same way. Andreessen Horowitz invested $350 million in Adam Neumann’s new venture Flow in 2022, valuing it above $1 billion before it had launched, despite WeWork’s collapse from a $47 billion to an $8 billion valuation under his leadership. Marc Andreessen’s public justification leaned on second chances: “we love seeing repeat-founders build on past successes by growing from lessons learned.” Reputation still shaped every headline, every term, and every question asked about the deal, even though it never blocked the capital.

 

Acting Accordingly

One caveat is worth stating directly: nobody has produced a clean statistic for how much weight boards or recruiters place on informal, back-channel reputation versus formal references. That data mostly doesn’t exist, and anyone who claims otherwise is making it up. The mechanism, though, is well documented: wide, weak professional networks carry information fast, and reputational damage in one role measurably reduces opportunity in entirely unrelated ones.

The practical implication isn’t paranoia. It’s that the version of you that shows up in a room you’ve never been in was written by people you may not remember meeting, months or years before you walked in. Act like the story is already there, because it usually is.

EasyJet Fixed an Age Bias in Recruitment. Most Digital Transformation Teams Haven’t

 

The number of easyJet cabin crew aged over 50 has more than doubled since 2022, up 127 per cent, according to the airline’s own figures. EasyJet says crew aged over 60 have “almost quadrupled” over the same period, and the airline has opened a fresh recruitment drive for the 2027 flying season, with applications opening in September. Getting there took a deliberate campaign. A large share of potential applicants assumed cabin crew work was reserved for younger people, and easyJet’s Director of Cabin Services, Michael Brown, put the fix plainly: over-50s bring both the skills to do the job and “a wealth of life experience that is appreciated by our customers and colleagues alike.”

 

This Is a Bigger Problem Than One Airline

The Centre for Ageing Better’s State of Ageing 2025 report shows why that perception carries a cost well beyond one airline. The UK’s employment rate for 55 to 64 year olds sits at 65 per cent, against 75 per cent in the Netherlands and Switzerland and 81 per cent in Iceland. The wider 50 to 64 employment rate sits 14 percentage points below the 25 to 49 rate. Closing that gap by 2030 would add an estimated £9 billion a year to the UK economy and £1.6 billion in annual tax and National Insurance revenue, according to the same research. That is the scale of value sitting behind a single, correctable assumption about who is fit to do a job.

 

The Same Bias, Earlier and More Expensive

The same assumption shows up earlier, and more expensively, in technology. CWJobs, working with the Centre for Ageing Better, surveyed 2,000 UK workers plus 250 people in tech who had experienced age discrimination, and found that tech employees start experiencing age bias at 29 and are considered “too old” by 38, roughly a decade before most people reach senior delivery roles. Forty-one per cent of tech workers report observing ageism at work, against 27 per cent across other sectors. Forty-seven per cent say they weren’t offered a role because of their age, and 31 per cent say they were passed over for promotion for the same reason. “Digital skills shortages mean discriminatory attitudes against age makes no business sense,” CWJobs director Dominic Harvey said when the findings were published, a point that has only got truer as the skills shortage he was describing has continued.

 

The Bias Has Already Reached a Tribunal

In Selazar Limited v McCabe, a tech company’s 29-year-old founder was found to have instructed a recruitment consultant to find “a younger team member who was more in tune with a young tech start company” in place of the firm’s 55-year-old finance director. The tribunal awarded her £125,604.98, including £20,000 for injury to feelings, and heard evidence that the founder had also signalled to potential investors that she was “too old to understand” the business. The case puts a figure on the same instinct easyJet had to overcome in reverse: treating experience as a cultural mismatch with a “young”, “digital” or “agile” identity, rather than as a straightforward capability question.

 

What Transformation Programmes Are Actually Short Of

That instinct is expensive in a way that goes beyond tribunal awards. Transformation programmes run into trouble for reasons that have nothing to do with technical skill: unclear governance, resistance treated as a communications problem rather than early diagnostic information, decisions made by people who have never been accountable for the outcome. Institutional knowledge, stakeholder trust built over years, and the judgement to recognise when a plan won’t survive contact with how the organisation actually operates are not junior capabilities. Screening for “young and agile” screens that experience out at precisely the point a programme needs it most, and does so before anyone has assessed whether the person applying could actually do the job.

 

The Fix Was Never Complicated

EasyJet’s fix did not require lowering a bar. It named the specific bias, redesigned recruitment and onboarding around it, then published the retention data alongside the recruitment numbers rather than stopping at the headline. Technology employers already have research going back years, and a tribunal ruling now sitting on the public record, telling them the same bias exists inside their own hiring and promotion decisions.

 

The Question Worth Asking Before the Next Senior Hire

What’s missing isn’t evidence. It’s a leadership team willing to treat this as a workforce design problem rather than a hiring afterthought. Before the next transformation lead, architect, or programme director role goes out with language built around “energy” or “digital native” instincts, it is worth asking what specific capability that language is actually screening for, and whether the organisation can afford to keep losing the experience it screens out along with it.

Nobody Owns AI in Your Organisation. That Used to Be Survivable.

 

In most organisations, nobody owns AI, not really. Not officially, not on an org chart, not in a way anyone could point to under pressure. For the last few years, that has been fine. Everyone touched AI a little, so no one needed to own it entirely.

That fuzziness is now expensive.

Two things changed the maths. The first is regulation. From 2 August 2026, the EU AI Act’s transparency obligations became enforceable: AI systems that interact directly with people, generate synthetic content, or use emotion recognition or biometric categorisation now require disclosure (European Commission), with providers facing fines of up to €15 million or 3 per cent of global annual turnover, whichever is higher (Cooley). A regulator does not care whether your organisation has formally assigned AI ownership. It cares who signs the compliance filing.

The second is spend. Global AI spending, including infrastructure capital expenditure, is on track to reach $2.5 trillion this year, a 44 per cent increase on last year, according to Gartner research reported by Fortune. Next year, Gartner expects that figure to climb to $3.3 trillion. That is capital being committed at a scale that normally comes with a name attached to the decision, not pocket-change experimentation.

Except it doesn’t. A Pearl Meyer survey of board members, CEOs, C-suite executives and senior managers found that just 34 per cent of C-suite executives say it is consistently clear which executive or team makes the calls on AI, the lowest confidence score of any group polled. Board members are considerably more settled, at 53 per cent. Senior managers below the C-suite, who carry out the actual AI work day to day, are more confident still, at 57 per cent. The C-suite sits in the middle of that gap, managing expectations from above and execution from below, and is the only group unsure who is actually in charge.

Meanwhile, PwC’s 29th Global CEO Survey, drawn from 4,454 CEOs across 95 countries, found that 56 per cent report no significant financial benefit from their AI investment so far, and only 12 per cent report gains on both cost and revenue (PwC). Spend accelerating, returns lagging, ownership unclear: three symptoms, one disease.

 

Governance Failure Wearing an Investment Story

I have watched this exact pattern play out on transformation programmes long before AI made it fashionable. A programme gets funded because the business case looks compelling on a single slide. Nobody sits down and decides who has the authority to stop it, slow it, or redirect it once it is underway. The absence of that decision does not read as a problem at the time, because everything is moving and everyone is busy. It reads as a problem eighteen months later, when the programme has drifted from its original purpose and there is no single person whose job it was to notice.

AI is running the same play at a faster clock speed. A RACI chart is not corporate theatre. It is the difference between a decision someone made on purpose and a decision that happened to everyone by default. Right now, most organisations have the second kind.

 

What an Actual Owner Looks Like

Contrast that with the UAE’s approach to its own AI commitment. In April 2026, Sheikh Mohammed bin Rashid Al Maktoum announced that 50 per cent of UAE government services and operations would run on agentic AI within two years, making it the first government in the world to commit to autonomous AI at that scale (Khaleej Times). Whatever view you take of the ambition, the governance structure was not an afterthought. Sheikh Mansour bin Zayed Al Nahyan was named to oversee implementation. Mohammad Al Gergawi was named to chair the taskforce running it. Before the programme scaled, someone’s name was attached to it.

It is not that most organisations lack ambition for AI. It is that they have skipped the one governance step that made every other major technology rollout survivable: deciding, on purpose, who is accountable before the spending accelerates past the point where anyone can meaningfully intervene.

 

Three Things That Actually Fix This

Name a single accountable owner for AI decisions at the level where spending actually happens. Not a committee. A person.

Separate who evaluates AI performance from who decides whether to scale it. Those are different jobs, and conflating them is how bad bets survive their first review.

Treat AI spending with no named owner attached to it as a governance red flag before it becomes an investment number on a board slide, not after.

 

None of this requires new technology. It requires the same discipline that used to be applied to every large capital commitment, before AI convinced everyone the normal rules no longer applied. They always did. The bill has simply arrived: from a regulator, from a survey, and from a CEO’s own board asking where the money went.

Your Gates Aren’t Protecting the Business. They’re Protecting Themselves.

Nobody sets out to build a bureaucracy. Every heavy stage-gate process started as three good intentions: get bad projects killed early, get good projects through fast, and keep a clean record of why each call was made. Then it grew a review board nobody remembers approving, and the good projects started waiting as long as the bad ones.

That is the actual failure. Not that gates exist. That almost nobody still measures them against the job they were built to do.

 

The Test a Stage Gate Was Actually Built to Pass

Governance run properly delivers three things, and nothing else matters as much as these: faster decisions, so a good project stops waiting weeks for a yes. Earlier kills, so a weak one frees up capital instead of quietly draining it for another two quarters. And a clean audit trail, so nobody has to reconstruct the reasoning after the fact. Get those three right and a stage gate speeds decisions. Miss them and it slows every decision down, good and bad alike, because the mechanism has stopped doing the job it was built for.

Someone genuinely has to decide which projects live, which pivot, and which ones are quietly draining the business. That much was never in question.

 

Why the Mechanism Rots

Four patterns do most of the damage, and each one accumulates quietly rather than arriving as a single bad decision. Entry gates get heavy while exit and kill discipline stay weak or disappear entirely, so zombie projects clog the funnel and starve the strong ones of attention. Panels grow larger and meetings grow longer until authority is spread across so many people that nothing actually gets decided. Reviews turn into theatre, rubber-stamping or deferring rather than choosing, and momentum dies in the gap between gates. And decision rights stay ambiguous enough that nobody is the clear owner of the yes or the no, so everything escalates and stalls at once.

Each of those four is a governance design that stopped serving the teams running through it and started serving itself, not a process flaw you fix by adding another step. The entry gate feels productive, so it keeps growing. The exit gate feels harsh, so nobody wants to own it, and that imbalance is where most of the trouble actually starts.

 

The Numbers Behind the Frustration

The frustration shows up in real operating numbers, not just complaints. At Vivix Vidros Planos, a Brazilian flat-glass manufacturer, resolving a customer complaint used to take weeks, long enough for a buyer to lose patience and take the next contract elsewhere. After building an AI-powered chatbot into its existing production and quality data, that shrank to minutes, an 80% reduction in complaint resolution time. Responses to production-line issues sped up by a further 85%. Both figures come from Vivix’s own case study, published jointly by Siemens and AWS. The underlying pattern holds regardless of the exact numbers: the real cost of a slow gate shows up as lost trust and lost contracts, not just lost hours.

 

What Minimum Viable Governance Actually Looks Like

The fix is sizing each gate to the actual risk in front of it, rather than running every decision through the same heavy process regardless of what it actually requires. A low-risk process tweak does not need the same panel as a bet-the-quarter platform launch, and treating both the same is exactly how standing committees fill up with work they should never see in the first place. High-risk decisions keep full board review, because that rigor is proportionate there. Mid-tier decisions get a lightweight gate with a single accountable owner. Low-risk work proceeds by default through a simple intake form, with oversight applied only if something in it actually warrants it.

The useful design target sits between two failure modes: above a ceiling, controls become bottlenecks and teams quietly route around them; below a floor, real risk creeps in unmanaged. Getting that band right is not abstract. One organisation that tightened its policy down to the minimum viable version halved the time complex decisions took and surfaced three times more opportunities than peers still running the heavier version.

 

The Test Most Gates Would Fail

Pick the last three projects your organisation killed at a gate, and the last three it approved. If the kills took longer to reach than the approvals, the gate is not protecting the business from bad decisions. It is protecting itself from having to make any decision at all.

Prompt Injection Is a Governance Failure Wearing a Technical Costume.

Every prompt injection headline reads like a technical failure. A model got tricked. A filter didn’t catch it. The vendor needs to patch something.

That framing is comfortable, and it is wrong. The technical trick is real. The governance failure sitting underneath it is the actual story, and it is the one almost nobody in the room wants to own.

 

Why the Trick Works in the First Place

The mechanism is architectural, not a bug in the usual sense. Large language models treat the system prompt, the user’s request, and any text retrieved from an external source as a single stream of tokens. There is no reliable internal boundary between an instruction and a piece of data. A hostile sentence buried in a document, a web page or a support ticket can carry the same authority as a command typed directly by a trusted user, because the model was never built to tell the difference.

OWASP’s 2026 State of Agentic AI Security and Governance report found prompt injection now maps to six of its ten top categories for agentic applications, up from a mostly theoretical concern in the 2025 edition to one backed by documented breaches and tracked vulnerabilities. Coding agents dominate the attack data, and only 37% of organisations report having a policy in place to even detect unauthorised AI deployments running inside their own environment.

 

The Failure Is a Control Boundary, Not a Model Flaw

This is where the governance framing actually matters. Prompt injection succeeds because enterprise workflows assume the model can reliably tell trusted instruction apart from hostile text, an assumption that fails the moment one interface carries user intent, retrieved content and tool-facing control signals in the same session. Most organisations respond by treating guardrails as a static filter list rather than a real system of content separation, monitoring and authorisation. A filter can catch a known bad phrase. It cannot answer the actual governance question, which is who controls what the system is allowed to do once it has been steered.

Security researcher Simon Willison’s “lethal trifecta” names the actual risk condition plainly: an AI agent with access to private data, exposure to untrusted content, and the ability to communicate externally, all three at once, is where exfiltration happens. Meta’s own internal guidance treats those three properties as a budget rather than a checklist. Combine all three and the agent needs a human in the loop before it acts, not after.

 

Why This Keeps Getting Treated as IT’s Problem Alone

Handing this to the security team as a patching exercise misses what the data is actually showing. A model update might close one exploit path. It will not answer who approved an agent’s access to a customer database, why that same agent can also send emails externally, or what happens the day it does both at once because nobody ever wrote down that it should not be allowed to. Those are ownership questions, not model questions, and ownership questions do not get solved by a vendor release note.

 

What Governance-First Actually Requires

Start by classifying every channel an agent reads from according to trust level, and keep untrusted content out of instruction scope entirely rather than hoping the model sorts it out at runtime. Quarantine tool access behind explicit policy gates, so an agent combining private data access, untrusted content and external communication needs sign-off before it can act, not a retrospective audit after it already has. Treat a pattern of near-miss prompts as an abuse signal worth escalating, not a string of isolated one-off incidents each closed out individually.

All of it is the same governance discipline organisations already apply to identity and access management, pointed at a new kind of actor that happens to run on language instead of credentials, not a new technology purchase.

 

Who Approved This, and Did They Know What They Were Approving

Before the next prompt injection incident gets logged as a technical exploit, ask who actually approved the access the exploit relied on.

If nobody can answer that cleanly, the model was never the vulnerability. The governance around it was.