TL;DR: AI adoption is still far less operational than the hype suggests, with MIT and Gartner data in the source article showing low production use, high pilot failure, and a clear trust gap between mature and immature organisations, according to Trust3. The real constraint is not model availability but the governance, data integrity, and control framework needed to make AI reliable at scale.
NHIMG editorial — based on content published by Trust3: Artificial Intelligence (AI) is no longer just a buzzword; it’s the engine that has been driving the next wave of innovation
By the numbers:
- Only 6% of U.S. companies were using AI in 2017, according to MIT research.
- 95% of AI pilot projects never make it to production, according to Trust3.
- 45% of organisations with high AI maturity have kept their AI projects operational for three years or more, according to Gartner's 2025 survey.
Questions worth separating out
Q: How should organisations govern AI systems that can make consequential decisions?
A: Organisations should govern consequential AI systems with the same discipline used for high-risk identities: defined ownership, least privilege, logging, approval boundaries, and human override.
Q: Why do AI pilots fail to reach production so often?
A: AI pilots fail when organisations design for experimentation but not for operational control.
Q: What do organisations get wrong about human oversight in agentic AI?
A: They confuse a named reviewer with effective oversight.
Practitioner guidance
- Map every AI system to a named owner and access boundary Document which data sources, APIs, and production actions each AI system can touch, then require explicit approval for any delegated access path.
- Treat agentic AI as a workload identity problem Assign governed identities to agents, secrets, and automation layers instead of embedding shared credentials.
- Build data lineage into AI governance Require traceable source systems, context ownership, and policy checks for the data feeding AI decisions.
What's in the full article
Trust3's full analysis covers the operational detail this post intentionally leaves for the source:
- How Trust3 frames the difference between AI experimentation and production readiness for enterprise teams
- The article's deeper discussion of the 'system of context' concept for coordinating agentic AI
- The source's full treatment of trust, governance, and security as prerequisites for scaling AI
- Additional examples of how AI adoption intersects with workforce change and operational accountability
👉 Read Trust3's analysis of why AI adoption depends on trust, governance, and context →
AI pilots and agentic systems: where do governance controls break down?
Explore further
AI adoption is now a governance problem, not a model problem. The article's core evidence points to a familiar enterprise pattern: most AI value is blocked by operational controls, not by model performance. Data fragmentation, weak ownership, and poor lifecycle management stop pilots from becoming services. For security and identity teams, the lesson is that AI programme success depends on control design as much as on technical capability.
A question worth separating out:
Q: How do teams know whether AI governance is actually working?
A: Look for evidence that every AI interaction can be traced end to end, from identity and intent to output and enforcement. If auditors can ask for a transaction and receive a complete record in hours, not weeks, the programme is producing usable control evidence rather than just documentation.
👉 Read our full editorial: AI adoption stalls when trust, governance, and data stay fragmented