ai · security · skills

Perspective · for leadership

$4–7B spent on pilots. Most produced no capability.

Between 2023 and 2025 the enterprise market spent four to seven billion dollars on AI security pilots. Somewhere between one in five and one in ten survived to scaled deployment. The cost isn’t just the money — it’s the credibility: the next AI proposal is met with more scepticism.

Pilots funded — $4–7Bsurvivedthe rest: absorbed into innovation decks · shelved at governance walls · failed production-readiness review

Real appetite, unprecedented spend — and a one-in-five-to-ten survival rate the market keeps repeating.

The structural reason

AI security sits between two functions moving at different speeds — security, slow and audit-bound by necessity; AI, fast and experimental by culture. Pilots that don’t reconcile that tension don’t survive contact with production.

“Why do our pilots demo beautifully and then die at production — and how do we sponsor one that lasts?”

The answer

Five failure modes, each with a countermeasure rarely applied.

Every one is observable in pilots running today; every one has a structural fix. Recognise them in any pilot under your sponsorship.

1

Optimised for demo, not deployment

Build against production constraints from day one — messy data, real latency, one live touchpoint by day 60.

2

The governance vacuum

Inside the governance perimeter from the start — not a “just a pilot” exception that can’t graduate.

3

Brittle institutional knowledge

Capability as executable skills you keep — not tribal knowledge that leaves with the person.

4

Measurement that collapses at scale

A task-level before/after on real data — not demo numbers taken under conditions that no longer apply.

5

The integration tax

Fit to the stack you already run — not a new tool whose integration cost sinks the rollout.

What protects the survivors

The methodology is the countermeasures, made structural.

Every failure mode above maps to something the practice enforces by design — production-realistic measurement, governance in the perimeter, skills you keep, and fit-to-stack over new tools — applied across the 18 AI Controls Matrix (AICM) control domains.

See the worked example →
← Back to Insights

Subscribe for the next essay.