The Governance Training Nobody Budgets For

Nobody has ever failed a project because they didn’t know how to build a Gantt chart. However some failed because nobody taught them who was allowed to say no.

I have sat in quite a number of programme inductions, and every one of them covers the same ground. Scheduling. Budgeting. Risk logs. RAID templates. Reporting cadence. Then, somewhere around the second afternoon, someone puts up a slide about governance and the room’s attention visibly leaves the building. It is treated as the compliance module, the thing you sit through before you get to the real work. Nobody walks out able to say, with any confidence, who actually owns the call when a decision does not fit neatly on a template.

That gap is not an oversight. It is a choice organisations keep making, year after year, without ever naming it as one.

 

The curriculum has a hole in it

Ask a newly promoted programme manager to explain their RAID log and they will do it fluently. Ask them who has the authority to accept a risk above a certain threshold without escalating it, and watch the pause. That pause is the sound of someone realising they were never actually taught the answer, only ever expected to absorb it by watching more senior people long enough.

A 2026 AI Governance Gap Report surveying more than 500 HR professionals found that only 45 per cent of organisations provide AI literacy training to all employees, one concrete, measurable instance of the broader governance-literacy gap this piece is about. Two-thirds of HR teams are already using AI to shape compliance and policy decisions, and the same report found fewer than half have given employees even that AI-specific literacy training to keep pace. The gap shows up well beyond HR too, in every function that has ever built a decision-rights framework, filed it in a folder, and assumed the document itself did the teaching.

Documents do not teach. People do, and usually only the ones who were already senior enough to have picked it up somewhere else.

 

Decision rights are treated like folklore

Most organisations do not lack a governance framework. They have one, usually a good one, sitting in a policy library that almost nobody outside the PMO has opened. What they lack is a mechanism for turning that document into instinct.

The result is a workforce that learns decision rights the hard way: by guessing wrong in front of a steering committee, by escalating something trivial and being quietly told off for wasting everyone’s time, or by not escalating something serious and finding out only when it has become a crisis. Every one of those is an expensive way to teach a lesson that could have been taught in an afternoon.

This is where the “knowing-doing” research cited by Harvard Business Review becomes uncomfortable reading for anyone who runs a training budget. Two out of three managers say they are still uncomfortable having accountability conversations with their own people, despite most of them having sat through the leadership training designed to prepare them for exactly that. The problem was never a shortage of content. Knowing a framework exists and being able to act on it under pressure are two entirely different skills, and organisations keep training the first while assuming it produces the second.

Governance training suffers from the same fault line. Knowing there is an escalation policy is not the same as recognising, in the middle of a stressful Tuesday, that the decision in front of you is the one the policy was written for.

 

The training everyone skips because it looks obvious

There is a reason this particular gap survives budget reviews when almost nothing else does. Governance training looks like it should be simple, so nobody prioritises building it properly. Everyone assumes the framework document is self-explanatory, right up until the moment someone makes the wrong call and the post-incident review discovers that three different people had three different understandings of who was supposed to decide.

I have run those reviews. The finding is almost never “the framework was wrong.” Almost always, nobody had ever been walked through what the framework meant in a live situation, so everyone applied their own version of common sense, and common sense is not actually common.

 

What actually needs teaching

A longer policy document will not fix this. Longer documents get read less, not more. The fix is teaching people to recognise a decision point before it arrives, not after.

That means running people through real scenarios instead of abstract categories, trading “what is your escalation threshold” for “here is a supplier problem that looks small and is not, what do you do in the next ten minutes.” It means naming, out loud and often, the handful of decisions in your organisation that carry disproportionate weight, so people learn to feel the shape of one before it is labelled for them. And it means treating governance literacy the way you would treat safety training: refreshed, tested, and taken seriously enough that senior leaders visibly participate in it themselves, rather than left as a one-off induction module.

The organisations that get this right build fewer, better decision-makers rather than thicker governance frameworks: people at every level who can spot a genuine decision point on instinct, the same way an experienced engineer can hear an engine fault before the dashboard lights up.

You cannot budget for the crisis a decision creates and then refuse to budget for teaching people to see it coming.

 

 

Small Talk Is Not Wasted Time. It Is the Only Rehearsal for Big Trust.

Most executives treat small talk as the tax you pay before the real conversation starts. Research on negotiation and workplace behaviour suggests it’s closer to the opposite: the low-stakes rehearsal that determines whether the real conversation goes anywhere at all.

 

What the Research Actually Shows

A frequently repeated claim holds that people who make small talk before negotiating are four times more likely to reach agreement. That number doesn’t survive a check against the study it’s supposedly drawn from. The actual 2002 research behind it, published in Group Dynamics, found something more modest but still real: negotiators who “schmoozed” beforehand reported significantly higher rapport than those who didn’t, and reached an impasse less often, 40.6% of the time versus 60.7%, though that gap was only marginally significant. The finding itself is that small talk measurably raises rapport and modestly improves outcomes. It is not some four-times multiplier, and repeating the inflated number would undercut exactly the kind of precision this argument needs to be taken seriously.

 

The Mechanism, Confirmed More Recently

A 2021 study in the Academy of Management Journal tracked 100 employees across 978 daily workplace observations over three weeks and found small talk works through a specific, two-sided mechanism: it “enhanced employees’ daily positive social emotions at work,” which increased helpful, cooperative behaviour toward colleagues, while simultaneously disrupting people’s ability to concentrate on their actual tasks in the moment. Both things are true at once. Small talk builds the social capital that makes cooperation possible later, and it costs a small amount of focus right now. A 2024 qualitative study of 35 B2B professionals found the same rapport-building mechanism operating specifically in negotiation contexts, identifying genuine curiosity, active listening, and respect for boundaries as the actual ingredients, not just friendly chatter for its own sake.

 

The Counterargument Worth Taking Seriously

Not everyone in this field agrees, and the disagreement is worth taking seriously rather than editing out. Kim Scott, whose Radical Candor framework has shaped how a generation of executives think about direct feedback, has argued the opposite case directly: real trust with employees comes from substantive one-on-ones and working relationships, not casual chat, and treating small talk as the relationship-building mechanism risks substituting a comfortable habit for the harder work of actually knowing someone. That critique lands hardest in ongoing management relationships. The negotiation and cross-cultural research above is mostly about a different situation: the first few minutes with someone you don’t yet have a working relationship with, where there’s no substantive history to draw on yet, and small talk is the only tool available to establish enough trust for the real conversation to start at all.

 

Why This Matters More in Some Rooms Than Others

Research on Arab business negotiators found relationship-building carries even more weight in that context, with negotiators leaning on personal networks and trust-building as central to how deals actually get made, rather than an optional warm-up. The mechanism isn’t unique to any one culture. It’s just more visibly load-bearing in markets where trust is built through recurring personal contact rather than through contracts alone.

 

What This Means in Practice

Skipping small talk to “get to the point faster” isn’t efficient. It’s removing the only low-stakes moment where two people calibrate whether they trust each other, before the stakes get high enough that a miscalibration actually costs something. The application is genuine curiosity about the person in front of you, delivered before you need anything from them, rather than performed friendliness, so that when you do need something, the trust required to ask for it is already there.

Regional Leadership Roles Reward a Different Kind of Patience Than Western Corporate Careers Teach.

Most Western executives arrive in a regional leadership role with the instincts that got them promoted at home: move fast, show visible wins early, let the quarterly numbers do the talking. Those instincts do not transfer. They actively work against you.

Western corporate careers train impatience, and reward it. Promotion cycles run on twelve to eighteen month windows. Performance reviews measure the quarter just closed. The fastest route up is a visible individual win, attached cleanly to your name, delivered before the next review cycle starts. None of that is wrong inside the system that built it. It is a system optimised for institutional and contractual trust, built on the assumption that the relationship survives even if the individual leaves tomorrow.

 

What Regional Leadership Rewards

Gulf leadership runs on a different clock, and the data on how regional leaders actually spend their time backs that up. PwC’s most recent Middle East CEO survey found Saudi Arabian chief executives dedicate 27% of their time to planning five years or more ahead, compared with 16% globally, and GCC chief executives overall spend meaningfully more of their schedule on long-term strategic planning than their global counterparts. That time allocation is a rational response to a business environment where relationships carry the weight of a deal through its inevitable rough patches.

The mechanism underneath that patience has a name: wasta, the use of personal relationships and trust networks to get things done. Research summarised by Northeastern University’s D’Amore-McKim School of Business puts it plainly: “in the Arab context, trust at the interpersonal level needs to be established before any business relationship can unfold.” That is not a bureaucratic delay. It is the actual mechanism through which decisions get made, and skipping it does not speed anything up. It just means the decision never fully lands.

 

The Failure Rate Everyone Quotes Does Not Hold Up

Ask any expat executive circle and you will hear it: 20 to 40% of international assignments fail. It is one of the most repeated statistics in expatriate management, and it is very likely wrong. Anne-Wil Harzing’s 1995 analysis traced the figure back to a small number of frequently misquoted articles, only one of which actually contained solid empirical evidence, and that evidence showed failure rates to be low. The myth persisted for three decades anyway, because it made a better opening line for a consulting pitch than the more boring truth.

The more useful question is why the ones who do fail actually fail. The qualitative research on that is far less contested: misjudging the local pace of trust-building rather than any shortage of competence or effort.

 

What Patience Looks Like in Practice

Cross-cultural consultancy Commisceo Global puts the practical advice plainly: do not expect deals to be completed in two visits to the region, because the relationship has to be nurtured before the commercial conversation can move forward at all. That advice sounds soft to an executive trained to treat a second meeting without a signed term sheet as a stalled deal. It is a description of how decisions actually get authorised in a hierarchy where personal trust in the room outweighs the org chart on paper.

Twenty years running programmes across markets that operate on this clock, the pattern I have seen most often has nothing to do with understanding the concept. Most executives can recite the advice back accurately in an interview. Where they struggle is stopping themselves from behaving as though the Western clock is still running underneath it: checking for the win they would expect by month three, reading the absence of one as a signal that the relationship has stalled, when it has not.

 

Three Things That Actually Help

Building trust deliberately, rather than waiting for it to accumulate on its own, takes specific behaviour. Spend real time in the room before asking for the decision. Learn who actually holds influence in a given relationship, because it is rarely only the most senior title at the table. And resist manufacturing a visible early win for the story it tells back home, because the fastest way to damage the trust being built is to be seen optimising for your own next review cycle instead of the relationship in front of you.

 

What This Requires

The patience regional leadership rewards has nothing passive about it. Ninety-three per cent of CEOs across the GCC expect domestic momentum to keep strengthening, against 55% of their global peers. These are not leaders coasting on a slow market. The patience is aimed at a specific target: building the trust that makes fast execution possible later, instead of chasing a fast, visible win the relationship cannot yet support.

That is a genuinely different skill to the one a Western corporate career trains for, and it rarely shows up on the resume that got someone the role in the first place. The executives who actually succeed in regional leadership rarely arrive already patient. They learn to notice, quickly, that the clock they were trained on is the wrong clock, and recalibrate before the org chart tells them they have run out of time to.

Two-Thirds See AI Working. The CFO Still Can’t Prove It.

Two-thirds of organisations say AI is delivering real productivity gains. Ask the CFO whether that translates into a return they can defend, and the answer changes completely.

 

Two Surveys, Same Landscape, Different Question

Deloitte’s 2026 State of AI in the Enterprise report, surveying 3,235 senior leaders across 24 countries, found 66% of organisations reporting real productivity and efficiency gains from AI, and 53% reporting genuinely better insights and decision-making. That is not a marginal result. Two-thirds of a very large sample are seeing the operational benefit show up in how the work actually gets done.

EY’s 2026 Global DNA of the CFO Survey, covering 1,610 CFOs, finance directors, and heads of finance at organisations with over a billion dollars in revenue, was fielded in the same window and asked a different question: not whether AI is helping, but whether finance can prove it in the language capital allocation actually requires. The answer is uncomfortable. Just 12% of CFOs say their finance transformation outcomes exceeded expectations over the past two years. Only 21% describe their function’s AI readiness as leading or advanced. And 71% say plainly that traditional metrics are not enough to evaluate initiatives that combine people and technology.

 

This Is Not Two Surveys Disagreeing

Read carelessly, that looks like a contradiction: one report says AI is working, the other says it isn’t. It isn’t a contradiction. It is two different functions answering two different questions, and the gap between the answers is the actual story.

The operational teams reporting gains in the Deloitte data are measuring what they can see directly: faster cycle times, fewer manual steps, sharper analysis. None of that is fabricated, and none of it is trivial. But productivity gain and return on invested capital are not the same measurement, and the EY data shows finance has not built the bridge between them. Sixty-one per cent of CFOs cite data quality and bias as their top challenge in securing further AI investment, which is a polite way of saying the numbers underneath the business case are not yet reliable enough to defend in a capital allocation meeting.

A separate July 2026 survey of 1,505 senior finance leaders across the US, UK, Australia, and India found the same pattern from a slightly different angle: 92% feel active pressure to prove AI investment is paying off, while only half report their AI agents have actually achieved a measurable return. The pressure to prove value is running well ahead of the organisation’s actual ability to measure it.

 

The Real Governance Gap

None of this is a technology problem. The Deloitte numbers show the technology is doing what it was bought to do, in a majority of cases, across a very large sample. It is not really a capital problem either. Boards are still funding AI investment at pace, and EY’s own data shows CFOs largely expect that to continue.

It is a measurement problem, and measurement problems are governance problems wearing a data costume. Somebody has to own translating “the team says this is working” into “here is the return, measured the way capital allocation actually requires it to be measured,” before the investment decision, not after it, using metrics that were agreed while everyone could still agree on them.

Most organisations have not assigned that ownership to anyone specific. It sits, by default, somewhere between IT, who built the thing, and finance, who has to defend the number nobody built the measurement framework to produce.

 

What Actually Closes the Gap

Fixing this does not start with better AI. It starts with defining, before the next AI investment gets approved, exactly what “return” means for that specific initiative, in terms finance and the operational team both sign off on before deployment, not after. It means putting one named owner against that measurement framework, not a committee, and not IT by default because they happened to build the system. And it means accepting that a lot of the value AI is already producing is real but currently invisible in the metric finance is required to report against, which is a reason to fix the metric, not to distrust the value.

 

The Question Worth Asking Before the Next AI Business Case

The next time someone asks whether an AI investment delivered a return, the sharper question is whether anyone defined, in advance, what return was actually supposed to look like, and in whose language it would need to be proven. Most organisations running significant AI programmes right now cannot answer that question. That is the real gap the numbers are describing, and it is entirely fixable, starting with the next business case, not the last one.

Transformation Fatigue Is Not About the Number of Changes. It Is About the Absence of a Finish Line.

Most organisations diagnose change fatigue as a volume problem: too many initiatives running at once, too many change requests hitting the same team. The volume is real, but it isn’t the actual mechanism.

 

What the Volume Framing Gets Right, and Wrong

The average employee experienced ten planned enterprise changes in 2022, up from two in 2016, according to Gartner research reported in Harvard Business Review. Prosci’s long-running change-saturation research puts 73% of organisations near, at, or past the point where employees are running out of capacity to absorb more.

Those numbers are real, and the standard academic definition of change fatigue treats volume as the cause: “a perception that too much change is taking place.” A 2021 peer-reviewed study in Public Money & Management tested this directly across repeated public-sector reorganisations and found the number of prior changes predicted fatigue, mediated by uncertainty and workload.

That is the correct diagnosis for some organisations. It is an incomplete one for most.

 

The Mechanism That Volume Alone Doesn’t Explain

Deloitte’s 2026 Global Human Capital Trends research, covering 9,000 leaders across 76 countries, names the actual shift more precisely than a raw change count can. One-third of surveyed workers experienced 15 major changes in the past year alone, but only 27% of leaders say their organisation actually manages change well, and just 8% found their change and learning efforts highly effective. Deloitte’s own recommendation is a reframe, not a volume reduction: move from episodic “change management,” which assumes a start and a finish, toward continuous “changefulness,” because the assumption of a finish line no longer holds.

It is not just that there is more change. It is that employees no longer get the stabilisation phase that used to follow each change, the period where a new way of working became the way of working, before the next initiative started.

 

Why Closure Isn’t Optional

Kurt Lewin’s original change model, still the theoretical foundation for most modern frameworks, has three stages: unfreeze, change, refreeze. Refreeze is the stage where a new behaviour actually solidifies into habit, where people stop consciously managing the transition and start simply working the new way. Skip refreeze consistently enough, running one unfreeze-change cycle straight into the next, and nothing ever solidifies. Every process, every system, every way of working stays permanently provisional.

Psychologist Pauline Boss’s concept of ambiguous loss, a loss that is real but never gets acknowledgement or closure, was developed for grief, not transformation programmes. But the mechanism translates directly: what exhausts people is not the change itself, it is never getting to grieve the old way and fully arrive in the new one before being asked to leave that behind too.

 

What This Actually Means for Leaders Running Transformation

BCG’s own research on transformation puts a number on the stakes: only about one in four transformations succeeds in capturing both short-term and long-term value, while people-centred change management, done properly, increases the odds of sustained improvement by up to 90%. Most of that people-centred work gets spent managing the volume of change. Almost none of it gets spent deliberately building in stabilisation points, the moments where a team is told, explicitly, that this phase is genuinely done.

The fix is not necessarily fewer initiatives. Some organisations doing fine with a high change volume have simply built real closure into the cadence: a defined point where the previous change is declared stable, celebrated as finished, and left alone for long enough that people stop bracing for the next disruption to hit the same process again.

 

The Question Worth Asking Before the Next Initiative Launches

Before adding another initiative to the roadmap, the honest question is not whether the organisation can absorb one more change. It is whether the last one was ever actually declared finished, or whether it’s still technically in flight, quietly compounding on top of whatever comes next.

Most transformation fatigue comes down to a single sentence leaders rarely say out loud: this is done, and it is going to stay this way for a while.

The PMO Evolves From Reporting to Enablement Engine

Most PMOs are still optimised for a question that stopped mattering years ago: is the project on time.

That question still matters. It has just stopped being the question that decides whether the PMO survives.

Clarkston Consulting’s 2026 programme management research puts the shift plainly: leading PMOs are moving beyond reporting to serve as enterprise enablement engines, connecting strategy to execution, building readiness into delivery from the start, and treating benefits realisation as a core discipline with clear ownership and early indicators of whether value is actually being created. A better dashboard will not get you there. This is a different function entirely.

 

The Reporting Function Was Never the Point

A PMO built around status reporting produces a specific kind of artefact: a red, amber, or green rating, a variance against plan, a risk log updated on schedule. Useful, in a narrow sense. None of it tells an executive whether the portfolio is creating value, whether the organisation’s capacity to change is being spent well, or whether the thing being delivered still matches the strategy that funded it eighteen months ago.

Wellingtone’s PMO research this year makes a related but sharper point: the inconsistency that plagues portfolio reporting, different teams defining “green” differently, decisions made on opinion rather than evidence, is a data problem before it is a reporting problem. Standardise the definitions and data model underneath the reporting, and AI can act as an assistant that takes a defined goal such as producing this week’s portfolio report or re-planning a delayed project, and coordinates the steps across your tools, removing low-value work rather than just colouring in a status field faster.

That distinction matters because AI is already acting as that assistant. It is already running in PMOs now.

 

Where the Real Shift Is Happening

House of PMO’s 2026 trends names the structural change underneath the tooling change: PMOs are increasingly being embedded into business areas rather than operating as a distant central function. This proximity builds trust, improves understanding, and allows PMOs to influence decisions earlier, where they can actually make a difference. The PMO becomes a connector between strategy and delivery, between different delivery models, and between governance and pace, rather than a function three steps removed from where the decisions get made.

Put those two shifts together: the data foundation improving enough for AI to generate real insight, and the PMO physically and organisationally closer to where decisions happen. The reporting function stops being the PMO’s reason to exist. It becomes infrastructure, while the enablement work, the strategic conversation, the early warning that changes a decision before it becomes a recovery programme, is where the value actually sits.

 

The Question Every Sponsor Should Be Asking

For anyone accountable for a large programme or portfolio, there is one question worth asking about the PMO function right now: has it been designed for accountability, or for assurance.

An assurance PMO produces reports that document what happened. It is useful for the audit trail and largely irrelevant to the decisions that mattered, because by the time the report lands, the decision has already been made without it. That is not a project management decision. It is a leadership decision about what the function is actually for, and most organisations have never asked it directly. They inherited a PMO structure built around reporting cadence and have never revisited whether reporting cadence was ever the point.

 

Why the Clock Is Actually Running

The reason this stops being an optional repositioning is straightforward. AI is already absorbing the administrative core of traditional PMO work: status compilation, report drafting, risk-log maintenance, the tasks that used to justify a PMO analyst’s headcount. A PMO whose value proposition is still “we produce the reports” is competing against a capability that produces the same reports faster, more consistently, and without a salary.

Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027, mostly because organisations deployed the technology without redesigning the governance and decision rights around it. That is precisely the work a repositioned PMO is suited to do, and precisely the work a reporting-only PMO has no mandate to touch.

 

What This Looks Like in Practice

The organisations getting this right are not adding an AI tool to the existing PMO operating model. They are redesigning what the PMO is accountable for first, then deciding what gets automated underneath that redesign. That means fewer metrics, chosen because they connect directly to financial outcomes, risk reduction, or strategic alignment, not because they are easy to collect. It means a PMO embedded close enough to the business to have the conversation before the decision, not after the variance report. And it means a governance model built to keep pace with AI and agentic deployments, not one still calibrated for a world where the only automation was a spreadsheet macro.

That happens by deciding, at leadership level, what the PMO is actually for, not by upgrading the reporting tool.

My own view is that this repositioning does not stop at a PMO with better metrics. Within a couple of years, the distinction between the PMO and whatever function owns strategy execution will start to disappear in the organisations doing this well, because once a function is genuinely accountable for whether strategy translates into delivered value, calling it a project management office undersells what it has become.

The PMOs still measuring themselves on whether the project shipped on time are answering a question that stopped being the one that mattered. The ones worth funding are the ones that can already tell you whether it was the right project.

Pre-Mortem: The UK’s Critical Third Party Regime

On 13 July 2026, Amazon Web Services, Google Cloud, Microsoft Azure, and Oracle became the first companies formally designated as Critical Third Parties to the UK financial system. The Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority now hold powers to gather information, assess resilience, and make enforceable rules against the four providers for the services they supply to the financial sector. A 2024 Bank of England and FCA survey found the top three cloud providers accounted for 73% of all cloud providers named by respondents across the UK financial sector. The designation names the risk. It does not resolve it.

This is the tenth piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

The UK is betting that direct regulatory oversight of four technology providers, applied specifically to their financial-sector services, will reduce the systemic risk from having most of the sector’s cloud infrastructure concentrated in three companies. The Financial Services and Markets Act 2023, which created the CTP regime, gives the Bank of England, PRA, and FCA powers to assess resilience and enforce CTP-specific rules. The designation is a supervisory relationship, not a structural remedy. If that supervisory relationship produces documented, published improvements in resilience before the first major cloud incident in UK financial services, the bet holds.

 

The Assumption

The regime’s credibility turns on one scoping decision: that overseeing four providers for the services they supply to the UK financial sector is sufficient to contain risks generated by four companies whose infrastructure decisions are made globally, across legal jurisdictions and customer bases far larger than the UK financial system. Microsoft Ireland Operations Limited is the designated entity. Its architecture decisions are made in Redmond. The supervisory perimeter covers the financial-sector slice. The concentration risk does not stop there.

 

The Sequence

The concentration risk pre-dated the regime by years. The Financial Services and Markets Act 2023 established the legislative basis for the CTP framework. A 2024 Bank of England and FCA survey confirmed the scale: three providers controlling the majority of UK financial-sector cloud infrastructure. HM Treasury announced the first four designations on 10 July 2026, effective 13 July. The sequence is legislation, then evidence, then designation. The risk was present throughout.

 

The Pager

Rachel Blake MP, Economic Secretary to the Treasury and City Minister, made the designation announcement. The Bank of England, PRA, and FCA share oversight of the four providers under the regime. Three regulators. Three separate mandates. No published document names which of the three leads incident coordination when a designated provider’s outage affects UK financial services. The CTP framework assigns supervisory responsibility. It does not assign the call.

 

The Proof

The measure that would settle this regime’s effectiveness is a published resilience outcome: a before-and-after comparison of systemic vulnerability at a named date after the CTP rules take effect. No such commitment has been published. The three regulators hold powers to gather information from the four providers. No public document names what information will be published, in what form, and by when. The first formal review cycle has no published date.

 

Verdict

If the three regulators jointly publish a named lead for CTP incident coordination and commit to a quantified resilience outcome before the first formal review cycle, the designation will stand as the most substantive step the UK has taken to address cloud concentration risk in its financial sector. Without that, four of the world’s most powerful technology companies have been formally named, and the framework that names them has not yet named who is in charge when one of them goes down.

Healthcare AI Enters Its Accountability Phase

Healthcare AI has stopped being an experiment. Holland & Knight, the US law firm, put it plainly in its mid-2026 healthcare report: the sector has entered a “recalibration phase,” where capital discipline and demonstrable return on investment have replaced the growth-first logic that funded the last five years of digital health.

That is a legal and investment framing, not a clinical one. But the clinical evidence backing it up is now specific enough to name.

Kaiser Permanente’s Permanente Medical Group rolled out ambient AI scribing to 7,260 physicians across more than 2.5 million patient encounters between October 2023 and December 2024. The result, confirmed by Kaiser’s own Division of Research: nearly 16,000 clinician-hours of documentation time saved. Not a pilot cohort. Not a vendor’s projection. A production deployment, measured after the fact, across a workforce large enough that the number means something.

Ambient documentation is also the part of healthcare AI with the least room left to argue about. A 2026 survey of 120 US health systems, run by the healthcare research firm Eliciting Insights, found clinical note-taking and ambient listening tools now sit at 68% adoption, up 62% year on year. Among the health systems able to quantify results, 61% report at least a 2x return specifically from ambient listening tools.

 

The $3.20 Figure Is Real, and Older Than It Looks

The oft-quoted “$3.20 return for every $1 invested in healthcare AI” is genuine, but it is worth knowing where it actually comes from before repeating it in a board pack. It traces to a Microsoft-sponsored IDC study published in late 2023 and reported in early 2024, not a fresh 2026 finding. It has simply become the industry’s standing benchmark figure, cited so often across 2025 and 2026 coverage that it now reads as current data. It is not wrong. It is just two years old and vendor-commissioned, which matters if you are the one deciding how much weight to put on it.

The Kaiser and adoption figures matter more, precisely because they are recent, specific, and independently reported rather than recycled.

 

What Actually Produced the Return

This ROI happened because of a specific programme design, not because someone bought a good tool, one that most other sectors experimenting with AI have not adopted.

Kaiser did not deploy ambient scribing and then discover the workflow around it. Clinical documentation workflow got redesigned first, and the AI tool was the mechanism, not the starting point. Accountability for the outcome, hours saved, adoption sustained, clinician trust maintained, was established before rollout, not retrofitted afterwards to justify the spend. And the whole exercise operated under exactly the capital discipline Holland & Knight describes: prove the return, or the funding does not continue.

That sequence, workflow redesign first, accountability from day one, capital discipline over growth optimism, is the actual explanation for why healthcare produced verifiable ROI while most other sectors are still producing pilot decks.

 

Healthcare Is Now the Benchmark, Not the Exception

Treat healthcare’s result as evidence that AI works and you will draw the wrong lesson. The technology was never really in question. What was in question, and what most other sectors are still failing to answer, is whether the organisation deploying it redesigned anything before switching it on.

Healthcare had no choice but to answer that question properly. Clinical documentation errors have consequences that show up in patient outcomes and malpractice exposure, not just quarterly numbers, so the sector could not afford the deploy-first governance-later approach that has quietly become normal everywhere else.

That is what other sectors should actually be benchmarking against: not whether their AI produces a return, but whether their programme was ever designed to make one provable.

 

The Question Worth Asking Before the Next AI Business Case

Before signing off the next AI investment, the question is not whether AI delivers value. Healthcare has already answered that question, under specific and now well-documented conditions.

The real question is whether your programme has been designed to match those conditions, workflow redesign before deployment, accountability defined from the outset, capital discipline over growth optimism, or whether it has been designed the way most digital health investment was designed before 2026: fund it, hope the outcomes show up eventually, and find out later whether anyone was ever going to check.

Healthcare already found out. That is the whole difference.

Pre-Mortem: The EU AI Act’s Accountability Gap


On 2 August 2026, the EU AI Act gives the EU AI Office the power to fine the developers of general-purpose AI models up to three per cent of global annual turnover, demand documentation, and commission independent access to source code. Three weeks before that date, the high-risk AI compliance deadline moved from August 2026 to December 2027, enacted as binding law on 29 June. The two facts share a date. They do not share a plan.

This is the ninth piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

The EU is betting that extending the deadline for high-risk AI compliance by 16 months, agreed in May 2026 and enacted on 29 June, produces better enforcement outcomes than a met deadline inside a half-prepared enforcement architecture. The logic holds. As of August 2026, only nine of 27 member states have shown advanced public implementation of enforcement infrastructure. Germany has designated the Bundesnetzagentur as its market surveillance authority and adopted draft transposition legislation. Spain built the AESIA, a dedicated supervisory agency, from scratch. Ireland deployed fifteen coordinated authorities under a central National AI Office. Those are genuine structural commitments. Eighteen member states have not reached that point. The extension gives them time. Whether they use it is the bet.

 

The Assumption

The entire framework rests on this: that national competent authorities, operating under 27 different legal frameworks, will converge on consistent enforcement before December 2027. The AI Act is a directly applicable regulation. Its enforcement infrastructure is not. The regulation sets the rules uniformly across the bloc. The authorities responsible for applying them have been built at very different speeds, under very different political conditions. That divergence is the risk the extension is buying time to close. There is no public commitment that the time is sufficient.

 

The Sequence

The AI Act entered into force in August 2024. Member states were required to designate their national competent authorities by August 2025. At least twelve missed that deadline. Seven months later, in May 2026, the Council and Parliament agreed to simplify the rules as part of the Digital Omnibus package. On 29 June, the high-risk AI deadline moved. What remains in force on 2 August is a narrower set: general-purpose AI model obligations and transparency requirements for new deployments. The high-risk AI rules, the Act’s original centre of gravity, are no longer in that set. Governance was adjusted to fit the readiness gap. That is not the order in which enforcement architecture is supposed to be built.

 

The Pager

Lucilla Sioli, Director of the EU AI Office, carries accountability for general-purpose AI enforcement from 2 August. For high-risk AI systems, including credit-scoring models, recruitment tools, and systems used in border control, healthcare, and law enforcement, accountability rests with national competent authorities. In 17 of 27 member states, no public designation exists. The Act names the category. Seventeen member states have yet to name the person.

 

The Proof

The measure that would settle this in 2028 is year-one enforcement consistency: the share of member states that have conducted at least one formal high-risk AI enforcement action, under the same evidentiary standard, in the first twelve months after the December 2027 deadline. No EU institution has publicly committed to publishing that figure. The AI Office’s annual progress reporting is the closest mechanism on the public record. It tracks activity. No published mechanism commits to measuring whether enforcement actions are consistent across member states.

 

Verdict

If the Commission designates a public accountability owner in each member state before December 2026 and commits to publishing year-one enforcement data by name, the 16-month extension holds up as a governance decision made under realistic conditions. Without that, a framework that took two years to reach enforcement hands itself an extension with nobody carrying it.

Plans Don’t Deliver Outcomes. Decisions Do.

The biggest myth in project management is not that it is only about schedules and budgets. That myth was debunked so long ago it barely warrants a mention.

The real myth is more dangerous: that a good plan delivers an outcome.

It does not.

A plan is the document everyone agrees on before the work starts. Delivery is determined by the thousand decisions that happen when that plan meets reality.

 

What a Plan Actually Is

A project plan is a structured expression of intent. It represents the best thinking of a group of people, at a specific point in time, about how they expect work to unfold.

The moment work starts, the plan begins diverging from reality. Not because the planning was poor. Because work is complex, environments shift, and the future is not fully knowable in advance.

The plan does not respond to those divergences. People do.

Someone decides what gets prioritised when two workstreams compete for the same resource. Someone decides what gets descoped when the timeline compresses. Someone decides what gets told to the sponsor and what gets managed quietly at team level. Someone decides whether to hold to the original scope or absorb a late change request that no one has formally costed.

These are not project management artefacts. They are leadership decisions. They happen every day, in every programme, at every level, and the cumulative quality of those decisions determines the outcome, not the quality of the plan that preceded them.

 

What the Data Shows About Plans and Outcomes

McKinsey’s research with Oxford’s Global Projects programme, originally published in 2012 and still McKinsey’s standing figure on its current insights page, based on more than 5,400 IT projects, found that just one in every 200 large IT projects meets all three basic measures of success: on time, on budget, and delivering intended benefits. The same research found that 17 per cent of large IT projects go so badly they threaten the very existence of the company delivering them. Bain’s January 2026 research on reorganisations, based on a survey of nearly 1,000 global executives and employees, found that 88 per cent of company leaders believe their new organisational structure will achieve its goals. Only 36 per cent of the employees actually working inside those structures agree.

These are organisations with project plans. Most of them had quite detailed ones.

The plan was not the variable that determined whether the transformation succeeded. The decisions made inside the transformation were.

McKinsey has been explicit on this, in its analysis of large technology programme management: traditional project management is not built for the complexity of managing a large number of interdependent workstreams. What that observation is really describing is a decision-making capacity problem, not a planning methodology problem.

When multiple workstreams intersect, when dependencies conflict, when assumptions that underpinned the plan prove false, the organisation needs fast, well-informed, appropriately escalated decisions. The project plan cannot make those decisions. A governance structure can enable them, but only if the people inside it are willing and able to act.

 

The Organisations That Deliver

I have worked across a wide range of organisations and programmes. The ones that consistently deliver are not the ones with the most sophisticated planning tools or the most comprehensive project documentation.

They are the ones with a leadership culture that makes fast, honest decisions when the plan diverges from reality.

That culture has specific characteristics. Issues get escalated without penalty. Status reporting reflects what is actually happening, not what the sponsor wants to hear. Scope changes get properly evaluated and decided, rather than quietly absorbed and then discovered six months later as the reason for a cost overrun.

Decisions about resources, priorities, scope, and timing get made by the right people at the right level, at the point when the decision matters, not deferred until the situation has become a crisis requiring emergency intervention.

This is not about removing the plan. A plan is genuinely useful. It creates shared understanding, allocates resources, sequences work, and provides a baseline against which reality can be measured. All of that matters.

But the plan is the starting point, not the delivery mechanism.

 

The Governance Gap Nobody Names

Most programme governance is designed to review progress against plan. Status reports, RAG ratings, milestone trackers, action logs. These are retrospective instruments. They tell you where you have been relative to where you intended to be.

They do not, by themselves, generate decisions.

A programme with robust governance can still fail because the governance structure reports on problems without resolving them. The issues log fills up. The risk register grows. The steering committee meetings run to time, and the programme slides, week by week, toward a late and over-budget delivery, or a cancellation that could have been a scope-reduced success.

The missing element is decision velocity, the willingness and authority to make the calls that change the trajectory, rather than the calls that record that the trajectory has changed.

 

What Good Actually Looks Like

The shift required is not from planning to improvisation. It is from planning-as-delivery to planning-as-baseline.

Build the plan. Use it. Measure against it. But invest as heavily in decision-making culture as in planning rigour. Who has authority to make what decision at what level? How fast can an escalation reach someone with genuine authority? What happens to the person who brings a difficult problem to the steering committee: are they received as someone providing valuable intelligence, or treated as someone who has failed to manage their workstream?

The organisations with the best project outcomes have thought hard about these questions. They are not the ones with the best plans.

They are the ones that can make the right call at 9am on a Tuesday when the plan says one thing and reality says another.

That capacity is the real delivery engine.