Announcing C1 Transform 2026
blog

Seven Ways Enterprise AI Programs Die

Seven failure modes I've watched kill AI programs. If your current setup has two of these, you're heading for the failure mode. Three, and you're already there.

Kevin PaigeKevin Paige, Field CISO

Share

Seven Ways Enterprise AI Programs Die

I want to show you a graveyard.

Not a metaphorical one. A pattern graveyard. Seven failure modes I've watched kill AI programs at C1, at customer sites, in the published histories of RPA initiatives and Cloud Centers of Excellence. If your current setup has two of these, you're heading for the failure mode. Three, and you're already there.

Tombstone 1: Every team picks its own AI tool#

"Just let people use what works for them." Fourteen overlapping subscriptions, zero audit trail, three production incidents you'll find out about at the breach.

Tombstone 2: Just put it behind SSO#

SSO solves login. Not action. The moment an agent is past the login boundary, your SSO is blind. It can't tell you what the agent did, what it touched, or what it's doing right now.

Tombstone 3: Share the service account across agents#

Zero attribution when things go sideways. "Service account 47 accessed production at 2 a.m." is not an answer at a board meeting. It's not even a starting point for an investigation.

Tombstone 4: Policy on the wiki#

Nobody reads docs. People read defaults. If your governance program lives in a Confluence page, you don't have a governance program. You have a document that will be out of date by next quarter.

Tombstone 5: The central review board for every AI project#

Becomes the bottleneck within a quarter. This is the exact pattern that killed Cloud CoEs by 2020 and RPA CoEs by 2023, and it's currently killing AI Councils in real time. Same shape every time. Projects route through it. It reviews. It approves. It owns the roadmap. The business waits. Innovation dies on the intake form.

Tombstone 6: The CoE reborn as the "AI Council"#

Tombstone 5 with cosmetic surgery. AI initiative failure rates are running 70-85%. The five recurring failure modes (unclear mandate, weak executive sponsorship, siloed operation, governance theatre, over-centralization) are the same five the RPA CoE community catalogued in 2021. We're repeating the experiment.

Tombstone 7: "We need to stand up a team to figure this out"#

This one is the most expensive mistake, because it feels responsible. The agentic migration doesn't need a new org chart. It needs your existing people to start running the methodology. Every quarter you spend designing the new team is a quarter your competitor's existing people are shipping. The methodology is the team. The people are the team. There is no separate team that goes off and "figures out agentic" so the rest of the org can adopt it later. That is the slowest possible path.

What all seven have in common#

The default state under all seven: a service-account password in a .env file and a prayer.

Each tombstone is a version of the same mistake: centralizing control, adding friction to the safe path, or deferring the methodology to a future state that never arrives. Cloud didn't fail because the technology was wrong. RPA didn't fail because automation was a bad idea. They failed because the governance model was wrong. Gating instead of enabling. Ownership instead of federation. Documentation instead of defaults.

The AI wave is giving enterprises a third shot at getting this right. Most are setting up to fail the same way.

What to do if you've already built one of these#

A lot of organizations did. The 2024-25 wave pushed every Fortune 500 to stand up an AI Center of Excellence, an AI Council, an AI Working Group. If you read the tombstones above and thought "that's us," you're not excluded from fixing it. You hired good people. You spent political capital getting the function approved. Don't burn either down.

Convert the function, not the team. The move is from gating to enabling. Same people, different mandate, different metric. The team that used to approve projects becomes the team that makes the next agent ship 25% faster than the unmanaged path. That's the entire conversion.

The signal you've done it right: a business unit ships an agent without checking with the CoE first and the CoE finds it in the audit log the next morning and says "good, here's the policy template that would have saved you two days."

That's the destination. Everything in the methodology points at it.


Part two of a series based on the Agentic Adaptation Playbook. Part one: the agentic migration is already happening. Next: most enterprises think they're on rung 3 of the agentic maturity ladder. They're on rung 1.

Ask AI to write a summary of this post

Stay in touch

The best way to keep up with identity security tips, guides, and industry best practices.

Explore more articles

Launch Week Roundup: The Agentic Control Plane

Launch Week Roundup: The Agentic Control Plane

Introducing agentic security and intelligence: close identity risk with C1

Introducing agentic security and intelligence: close identity risk with C1

Introducing agent runtime governance: intent-based access control for AI agents

Introducing agent runtime governance: intent-based access control for AI agents