Skip to content

AI Outlooks

News and viewpoints on the latest in AI security

Primary Menu
  • Home
  • What’s new in AI
    • AI Security News
    • Agentic AI News
    • AI Regulation News
    • AI Research News
    • AI Model News
  • Solutions
  • Cybersecurity
    • AI security
    • OWASP
    • Ransomware
    • Shadow AI
  • Learn
    • AI security
    • LLM security
    • AI governance
    • AI compliance
    • Agentic AI
    • AI infrastructure
    • AI data security
  • Home
  • News
  • Why AI governance fails: What MIT’s 2025 report actually found
  • News

Why AI governance fails: What MIT’s 2025 report actually found

Staff May 11, 2026
governance failure

The numbers are brutal. Companies poured an estimated $30 to $40 billion into generative AI. Less than 5% of those projects made it to production with measurable returns. MIT’s 2025 State of AI in Business report, led by researcher Aditya Challapally, interviewed 150 leaders, surveyed 350 employees, and analyzed 300 public AI deployments to find out why.

AI governance fails for the same reason most corporate transformations do. Not because the technology is broken. Because the organization never changes around it.

The GenAI Divide: High adoption, zero transformation

MIT calls it the GenAI Divide. On one side, roughly 80 to 90% of companies have adopted some form of AI. ChatGPT, Copilot, Claude. The adoption numbers look great in board decks. On the other side, only 5% have scaled custom AI tools to production. Everything in the middle is pilot purgatory.

Challapally puts it bluntly in the report: “The 95% failure rate for enterprise AI solutions represents the clearest manifestation of the GenAI Divide.”

The core issue is not model quality. It’s what the report calls the “learning gap.” Generic tools like ChatGPT work for individuals because they’re flexible. But they stall in enterprise settings. They don’t retain context. They don’t learn from your workflows. They don’t get smarter the more you use them. A salesperson gets better at selling over time. The AI sitting in their CRM doesn’t.

Root cause 1: AI projects that don’t connect to business goals

More than half of all AI budgets go to sales and marketing. The flashy stuff. Chatbots on the homepage. Email generators. Ad copy assistants. These are fine for marginal productivity gains. But the real ROI lives in the back office.

Document processing. Procurement. Contract review. Claims handling. These are unglamorous functions. They’re also where MIT’s case data shows companies saving $2 million to $10 million a year by replacing outsourced labor.

The problem is structural. Pilots get funded because a VP read about AI on LinkedIn and wants a demo for the next board meeting. The pilot works in a controlled test environment. The team celebrates. Then it hits real workflows. Real data quality issues. Real compliance requirements. It breaks. And nobody has the authority or budget to redesign the process around the tool. So it dies quietly.

Almost no GenAI pilot shows measurable ROI in its first iteration. Not because it can’t. Because it’s aimed at the wrong target.

Root cause 2: Nobody owns the problem

MIT’s research points to a clear accountability gap. Centralized AI governance sounds safe. One team reviews every AI purchase. Every model. Every use case. It becomes a bottleneck.

When MIT’s team interviewed leaders across sectors, one manufacturing COO captured the frustration: “The hype on LinkedIn says everything has changed, but in our operations, nothing fundamental has shifted.”

The procurement data confirms the ownership problem. AI projects sourced from external vendors succeed 67% of the time. Internal builds? 33%. External vendors bring accountability baked into contracts. They have to deliver results or lose the deal. Internal teams operate in a softer frame. No hard deadlines. No competitive pressure. Just another internal tool that might work someday.

The companies that break through this name specific owners. Not a steering committee. A person. Someone who can say “stop” or “scale” based on actual business outcomes, not internal politics.

Root cause 3: The same old workflow with a new tool on top

Adding AI to a broken process just makes the broken process faster.

The MIT report is unambiguous about this. AI fails when it’s layered onto workflows that were designed for humans doing manual work. Not redesigned. Not rethought. Just augmented with a chatbot.

Challapally told Fortune that successful AI deployment requires a complete reimagining of daily operations. The organizations that get results redesign their processes around AI capabilities. They don’t just install a plugin and hope for the best.

The report identified four structural factors behind the divide. Limited disruption: only two of nine major sectors (Tech and Media) show material business transformation. The enterprise paradox: large firms lead in pilot volume but lag in successful deployment. Investment bias: budgets overwhelmingly favor sales and marketing despite better returns in operations. And the implementation advantage: tools built by external vendors succeed twice as often as internal builds.

The shadow AI economy: When employees build governance around you

While companies debate whether to approve the enterprise Copilot license, 90% of employees are already using personal AI tools at work. ChatGPT. Claude. Perplexity. Only 40% of companies have any enterprise AI subscription at all.

This is shadow AI. Unsanctioned. Untracked. And it’s producing real ROI faster than the official pilots. MIT found Fortune 500 insurers where sanctioned GenAI pilots looked polished in boardrooms but collapsed in the field. Meanwhile, employees were quietly using personal AI to speed up claims processing, part of a pattern that MIT says is already saving companies $2 million to $10 million a year in external costs and cutting agency spend by 30%.

The instinct is to clamp down. Block the domains. Write stricter policies. That’s the wrong response. The data shows that the companies handling this well formalize what employees are already doing. They provide secure, governed versions of the tools people want to use. They make the official path easier than the shadow path.

Shadow AI isn’t a technology problem. It’s a governance signal. When employees build their own productivity stack outside IT, IT needs to ask whether the official stack is actually serving people.

What the 5% who succeed do differently

The 5% of companies that cross the GenAI Divide follow a consistent pattern. Not coincidentally, their approach maps directly to fixing the three root causes.

First, they tie governance to business outcomes, not compliance checklists. They measure whether AI reduces document processing time by 40%, not whether the model meets technical benchmarks. They hold vendors accountable for operational results, not feature checklists.

Second, they assign ownership to individuals, not committees. MIT’s findings show that external vendor partnerships consistently outperform internal builds because they create hard accountability lines. Someone’s contract depends on the results.

Third, they embed governance into daily workflows. Not quarterly reviews. The most advanced organizations track model performance in real time. They document version histories and decision prompts. Teams have the authority to halt a project the moment risks exceed thresholds. The EU AI Act and GDPR are not distant regulatory concerns. They’re design constraints built into the process from day one.

Looking ahead, MIT researchers stress that the next phase will be defined by agentic AI, systems that remember, learn, and act autonomously. Protocols like NANDA and the Model Context Protocol are laying the groundwork for what the report calls an “Agentic Web,” where AI agents coordinate across organizations and platforms, replacing static SaaS tools.

Fixing AI governance: Four changes that actually work

If you read one section of this article, read this one.

One. Tie every AI initiative to a single business metric. Not “explore AI opportunities.” Something like “reduce document processing time by 40%” or “cut agency spend by 30%.” If you cannot name the metric it moves, do not fund the pilot.

Two. Redesign the workflow before you buy the tool. Standardize the process. Document the handoffs. Eliminate the tribal knowledge that lives in one person’s head. Then automate. Automating chaos produces faster chaos.

Three. Give one person Stop/Start/Scale authority per initiative. A governance committee can advise. But committee-run governance is the mechanism that lets pilots live in limbo for years, draining budget without producing returns.

Four. Audit continuously, not annually. AI changes too fast for static policies. Schedule regular reviews. Assess whether outputs remain fair, accurate, and aligned with business goals. The MIT report documents organizations saving millions annually in back-office costs alone. But only the ones that treat governance as an ongoing practice, not a one-time framework document, keep those savings.

FAQ

Why do AI governance efforts fail in most companies?

MIT’s research points to three primary reasons. First, companies bolt AI onto existing workflows without redesigning them. Second, nobody has clear ownership. Centralized governance creates bottlenecks while shadow AI flourishes in the gaps. Third, tools don’t learn or adapt. They’re static systems dropped into dynamic environments. The “learning gap” Challapally identifies is the fundamental mismatch between tools that can’t remember context and organizations that need them to.

How can companies ensure AI projects deliver real value?

Start with a measurable business outcome, not a technology demo. Set a target like “cut procurement processing time by 40%.” Redesign the workflow to make AI central to the process, not bolted on top. Assign a single owner with Stop/Start/Scale authority. MIT found external vendor partnerships succeed at nearly double the rate of internal builds because they bring accountability and domain fluency.

Why is workflow redesign so important for AI ROI?

Because AI amplifies whatever process you give it. A broken process becomes a faster broken process. The organizations that get results redesign their operations first and add AI second. MIT’s report identifies this as one of four structural factors behind the GenAI Divide: tools that don’t integrate into workflows cannot deliver sustained value, regardless of how good the underlying model is.

How do you measure if AI governance is working?

Track three things. Adoption rate: are employees using the sanctioned tools or building shadow AI? Business outcomes: did the AI reduce time or cost by the specific percentage you targeted? Risk signals: are compliance incidents trending up or down? If adoption is low despite investment, governance is too restrictive. If risk signals are rising, governance is too loose. Strong governance sits in the middle.

What is the GenAI Divide?

MIT’s term for the gap between AI adoption (high) and AI transformation (low). 80 to 90% of companies use AI in some form. But only 5% have scaled custom AI to production with measurable business returns. The divide is not about access to technology. It’s about the organizational learning gap between piloting tools and actually changing how work happens.

Related topics

  • AI governance frameworks — A deeper look at the NIST AI RMF, ISO 42001, and which framework fits your organization
  • AI privacy risks — Why shadow AI is a privacy problem before it’s even a governance problem
  • What is AI sprawl — The unchecked proliferation of AI tools and how it undermines governance

Continue Reading

Previous: AI governance frameworks
Next: What is shadow AI?

More in AI security

  • Guide

The agentic AI security checklist: 12 controls to verify before you deploy

Staff September 4, 2026
Twelve controls to verify before you deploy an AI agent, each mapped to an OWASP ASI risk...
Read more Read more about The agentic AI security checklist: 12 controls to verify before you deploy
LLM jailbreak defense: techniques that actually stop attacks Jailbreak defense
  • Cybersecurity

LLM jailbreak defense: techniques that actually stop attacks

Staff July 28, 2026
How do enterprises secure AI data pipelines at production scale? safety
  • Cybersecurity

How do enterprises secure AI data pipelines at production scale?

Staff July 28, 2026
How companies can defend against AI model extraction attacks
  • Guide

How companies can defend against AI model extraction attacks

Staff July 23, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026

Glossary

model router
  • LLMs

What is a model router for AI? A plain-English guide

Staff July 30, 2026
A model router for AI is a decision layer that picks which large language model answers each...
Read more Read more about What is a model router for AI? A plain-English guide
What is agentic SDLC?
  • Glossary

What is agentic SDLC?

Staff July 22, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026
LLM system prompt leakage: what it is, how it works, and how to stop it agentic ai
  • Glossary

LLM system prompt leakage: what it is, how it works, and how to stop it

Staff July 15, 2026
What is LLM supply chain security? (OWASP LLM03:2025 explained) llm supply chain
  • Glossary

What is LLM supply chain security? (OWASP LLM03:2025 explained)

Staff July 14, 2026

Guides

The agentic AI security checklist: 12 controls to verify before you deploy
  • Guide

The agentic AI security checklist: 12 controls to verify before you deploy

Staff September 4, 2026
LLM jailbreak defense: techniques that actually stop attacks Jailbreak defense
  • Cybersecurity

LLM jailbreak defense: techniques that actually stop attacks

Staff July 28, 2026
How do enterprises secure AI data pipelines at production scale? safety
  • Cybersecurity

How do enterprises secure AI data pipelines at production scale?

Staff July 28, 2026
How companies can defend against AI model extraction attacks
  • Guide

How companies can defend against AI model extraction attacks

Staff July 23, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026
How to prevent adversarial attacks on AI models
  • Guide

How to prevent adversarial attacks on AI models

Staff July 22, 2026
  • Home
  • What’s new in AI
  • Solutions
  • Cybersecurity
  • Learn
Copyright © All rights reserved. | by AF themes.