By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: Trust3Published September 23, 2025

TL;DR: AI adoption is still far less operational than the hype suggests, with MIT and Gartner data in the source article showing low production use, high pilot failure, and a clear trust gap between mature and immature organisations, according to Trust3. The real constraint is not model availability but the governance, data integrity, and control framework needed to make AI reliable at scale.


At a glance

What this is: This is an analysis of why AI adoption continues to stall, with the article arguing that trust, governance, and connected data matter more than model novelty.

Why it matters: It matters because AI programmes now intersect with identity, access, and governance decisions, especially when human workflows, machine identities, and agentic systems all depend on the same control plane.

By the numbers:

👉 Read Trust3's analysis of why AI adoption depends on trust, governance, and context


Context

AI adoption often fails for reasons that sit outside model quality. The recurring problem is fragmented data, weak governance, and an inability to turn pilots into controlled production services, which is why the article's primary finding is really about operational trust rather than AI capability itself.

For identity and security teams, the more interesting question is how AI systems are governed once they touch production data, business workflows, and delegated access. As agentic AI spreads, the boundary between model governance and IAM becomes harder to ignore, because AI systems increasingly act through credentials, APIs, and policy decisions.

The article's starting position is typical of current enterprise AI programmes: enthusiasm is high, but the control model is still immature.


Key questions

Q: How should organisations govern AI systems that can make consequential decisions?

A: Organisations should govern consequential AI systems with the same discipline used for high-risk identities: defined ownership, least privilege, logging, approval boundaries, and human override. The critical requirement is to connect model behaviour to real access paths so legal review, security review, and audit evidence all describe the same system.

Q: Why do AI pilots fail to reach production so often?

A: AI pilots fail when organisations design for experimentation but not for operational control. Production requires trustworthy data, access boundaries, monitoring, change control, and clear accountability. Without those controls, the pilot may work in isolation but collapse under real-world dependency, security, and compliance requirements.

Q: What do organisations get wrong about human oversight in agentic AI?

A: They confuse a named reviewer with effective oversight. Real oversight requires training, escalation practice, and decision authority under pressure. If approvers have never rehearsed the scenario, they are likely to trust the system too quickly or miss the moment when denial is the safer outcome.

Q: How do teams know whether AI governance is actually working?

A: Look for evidence that every AI interaction can be traced end to end, from identity and intent to output and enforcement. If auditors can ask for a transaction and receive a complete record in hours, not weeks, the programme is producing usable control evidence rather than just documentation.


Technical breakdown

Why disconnected data systems break AI reliability

AI systems depend on consistent context. When data is split across silos, workflows, and inconsistent ownership boundaries, models can only infer from partial information, which increases error rates and undermines repeatability. In practice, this is not just a data problem but a governance problem, because the same fragmentation that weakens analytics also weakens policy enforcement, auditability, and decision traceability. For agentic AI, poor context means agents can take actions that are internally coherent but operationally wrong. The control challenge is to make data lineage and policy visibility part of the AI operating model, not an afterthought.

Practical implication: establish governed data sources and traceable context paths before allowing AI systems to act on production decisions.

Why pilot-to-production failure is a control issue

The 95% pilot failure rate reflects a common pattern in enterprise AI: experimentation is easy, but production requires security, lifecycle management, and operational ownership. Many pilots are built like proofs of concept, then collapse when they encounter authentication, access scoping, monitoring, and change control requirements. This is where AI governance and identity governance intersect. If an AI system needs access to systems, data, or downstream automation, it must be treated as a controlled workload, not a temporary script. Reliability is therefore inseparable from privileged access management, logging, and revocation discipline.

Practical implication: assign clear ownership and access boundaries to every AI pilot before moving it into production.

System of context and agentic AI identity

A system of context is a shared control layer that lets multiple AI agents operate with the same rules, data references, and business meaning. Without that layer, agentic AI becomes a coordination problem, because each agent may optimise for a narrow task while missing the broader policy or risk environment. This is where identity becomes critical. Agents that can call tools, query data, or trigger actions need governed identities, scoped permissions, and event-level accountability. In effect, the organisation must know not only what the model said, but what identity acted, under what policy, and with which delegated authority.

Practical implication: design agentic AI with explicit workload identity, scoped permissions, and auditability from the start.


NHI Mgmt Group analysis

AI adoption is now a governance problem, not a model problem. The article's core evidence points to a familiar enterprise pattern: most AI value is blocked by operational controls, not by model performance. Data fragmentation, weak ownership, and poor lifecycle management stop pilots from becoming services. For security and identity teams, the lesson is that AI programme success depends on control design as much as on technical capability.

Agentic AI introduces a new identity surface that traditional IAM was not designed to manage. Once AI systems can select actions, invoke tools, and operate with delegated access, they behave like governed workloads with their own identities, privileges, and accountability requirements. That makes AI governance inseparable from workload identity, secrets management, and policy enforcement. Practitioners should treat agentic AI as an access boundary, not just an application layer.

Trust is the named concept that most clearly explains why AI programmes stall. In this context, trust is not a soft cultural issue. It is the accumulated confidence that data is reliable, permissions are scoped, outputs are auditable, and actions are reversible. When any one of those controls is missing, AI can still function, but it cannot be safely scaled. The practitioner conclusion is simple: trust must be engineered into the operating model.

The most important shift is from project success to operational accountability. Many organisations can build AI demos, but far fewer can run AI continuously with defensible controls, clear ownership, and measurable outcomes. That is why AI maturity should be judged by governance depth, not by the number of pilots launched. The field is moving toward accountable AI operations, and security teams need to be part of that design early.

Identity governance is becoming the control plane for agentic AI. As AI systems gain access to business processes, the question is no longer whether they are intelligent enough, but whether they are authorised enough. That intersection with IAM, PAM, and NHI governance is where enterprise AI programmes will either scale safely or generate unmanaged risk. Practitioners should build AI identity controls into governance from day one.

What this signals

AI governance is converging with identity governance faster than most programmes are structured to absorb. The practical implication is that AI systems will increasingly need the same discipline applied to service accounts, workload identities, and privileged automation. If the organisation cannot answer who or what is acting, the AI programme is already exposing a governance gap.

Confident deployment is a weak maturity signal if access and context remain uncontrolled. The more useful marker is whether the programme can prove least privilege, traceable data lineage, and reversible actions across production workflows. Those are the controls that determine whether AI becomes operational infrastructure or a recurring exception process.

Agentic AI creates a new version of identity sprawl, where each agent, tool call, and delegated credential expands the attack surface. That is why teams should align AI governance with the NIST SP 800-63 Digital Identity Guidelines where human authentication is involved, and with workload identity controls when machine actors are acting on production systems.


For practitioners

  • Map every AI system to a named owner and access boundary Document which data sources, APIs, and production actions each AI system can touch, then require explicit approval for any delegated access path. Include revocation criteria and a review cadence so pilots do not become unmanaged production services.
  • Treat agentic AI as a workload identity problem Assign governed identities to agents, secrets, and automation layers instead of embedding shared credentials. Use scoped permissions, short-lived access where possible, and audit trails that show which identity initiated each action.
  • Build data lineage into AI governance Require traceable source systems, context ownership, and policy checks for the data feeding AI decisions. If the organisation cannot show where the data came from and who approved its use, the system is not ready for high-impact workflows.
  • Measure AI reliability by operational control, not pilot volume Track production stability, access-review completion, incident rates, and reversible change paths for each AI service. These indicators reveal whether AI is being governed as a business capability or merely tested as a prototype.

Key takeaways

  • AI programmes fail most often at the point where governance has to become operational, not experimental.
  • The strongest signal of maturity is not how many pilots exist, but whether access, data lineage, and accountability are controlled.
  • Agentic AI pushes identity governance into the centre of AI security because every delegated action needs an authorised actor.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10Agentic AI and delegated tool use create the core governance risk in the article.
NIST AI RMFGOVERNThe article is fundamentally about governance, accountability, and operational trust.
NIST CSF 2.0PR.AC-4AI access scoping and least privilege are central to the article's control gap.
NIST SP 800-53 Rev 5AC-6Least privilege directly addresses over-broad AI access and delegated authority.
NIST Zero Trust (SP 800-207)Section 3.1Zero Trust principles align with continuous verification for AI actions and access paths.

Require continuous verification for AI-to-tool interactions and verify each delegated action in context.


Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • SYSTEM Context: SYSTEM context is the highest-privilege local security context on Windows endpoints, used by core operating system services. When attackers obtain execution in this context, they can install persistence, manipulate services, and broaden their control far beyond a normal user session.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Workload Identity: The identity assigned to a software workload — such as a containerised application, serverless function, or microservice — enabling it to authenticate to other services without storing static credentials.

What's in the full article

Trust3's full analysis covers the operational detail this post intentionally leaves for the source:

  • How Trust3 frames the difference between AI experimentation and production readiness for enterprise teams
  • The article's deeper discussion of the 'system of context' concept for coordinating agentic AI
  • The source's full treatment of trust, governance, and security as prerequisites for scaling AI
  • Additional examples of how AI adoption intersects with workforce change and operational accountability

👉 Trust3's full article adds the supporting evidence and the broader discussion of agentic AI adoption challenges.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and workload identity. It helps security and identity practitioners build the control model needed for AI systems, service accounts, and delegated automation.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org