← The Record
The Record · The argument

Why AI implementations
die.

Agents are cheap. Nothing that killed the last three years of enterprise pilots was a model problem. They died because the work coming out of them was unsignable: no control over what got touched, no cap on what got spent, no record anyone would put their name against.

01 · The receipts

Start with other people’s numbers.

None of the figures below are ours. Three independent readings of the same enterprise, taken by people with nothing to sell you on this page. Read together they describe one condition, and it is not a capability gap.

  1. 01>40%Gartner · 2025

    of agentic AI projects will be canceled by the end of 2027

    Cancellation is not the same as failure. Most cancelled projects worked. Somebody looked at what it would take to run one against real systems, real money and a real audit, and could not write the memo that authorised it.

  2. 02~21%Deloitte · State of AI 2026

    of enterprises have a mature agentic-AI governance model; four in five do not

    Four in five have the mandate and not the structure. That gap is where the cancelled projects in the figure above go, and closing it is a build problem before it is a policy problem.

  3. 0382:1CyberArk · 2025

    machine identities for every human identity: the surface nothing governs by default

    Every access model an enterprise owns was designed around people: joiners, movers, leavers, a quarterly review. Machine actors already outnumber people eighty-two to one, and almost none of them sit inside that model.

02 · The shape of it

Count the ones who can sign.

A survey result is an abstraction until you put it on a grid. One hundred enterprises, every one of them with agents already bought, a board asking about them and a budget behind the answer. Light the ones whose governance is mature enough to answer for the work.

Enterprises that bought agents

21 of every 100 enterprises
hold a mature agentic-AI governance model · Deloitte

The twenty-one are not the ones with the better models. Everybody had the same models, from the same handful of providers, inside the same eighteen months. What separates them is that somebody could answer five questions in writing before the work went live: what it can touch, what it can spend, who approves, what ships, and what got logged.

The rest have the mandate and not the structure, and they find that out in a meeting rather than in a benchmark. That meeting is the next section.

03 · The three refusals

One yes, three refusals.

None of this is mysterious once you sit in the room where the decision actually gets made. The mandate is genuine and well funded. So are the objections, and every one of them is correct.

The CEOApproved

Wants the agents working, this year.

The budget exists. The board has asked about it twice. This is the easiest yes in the building, and it is the only one the project ever gets.

The CISORefused

Nothing controls what an agent touches.

A prompt is not a permission. If the only thing between a model and a production repository is an instruction not to go there, the control being signed off is a paragraph of text that other text can argue with. No security officer signs that, and none should.

The CFORefused

Agent spend is unbounded by default.

Spend is metered per token and reported the next morning. A run that goes wrong keeps costing money until a person notices it, and the bill is the first place anyone finds out. There is no ceiling to write into a budget line, only a number to read afterwards.

AuditRefused

There is no forensic record of any of it.

Application logs are not an audit trail. They record that something happened, not who authorised it, under which limit, against which version of the rules. Asked to reconstruct a single decision from six months ago, nobody can. That answer is a no before it is a finding.

Three refusals, no appeal.
The slide says “ROI unclear.”
04 · The turn

Policy does not hold. Structure does.

The standard answer to all three refusals is a document. An AI usage policy, a set of written guardrails, a review board, a training module with a completion certificate. Each one sits beside the work instead of inside it, and each one is, in the end, a request.

Written rules govern people because a person can be held responsible for breaking one. That mechanism is missing here. A rule that exists only on paper has to be obeyed voluntarily by something that cannot be sanctioned, cannot be fired, and will not remember the training.

Governance as policyGovernance as architecture
Where it livesIn a document beside the workIn the path the work runs through
When it appliesWhen somebody remembersEvery time, by construction
Who can overrule itAnyone in a hurryNobody, including the people who built it
What an auditor getsAn assertionThe record, and every refusal in it
The controls are the structure the work runs inside.

Read the three refusals again against that sentence. The security control becomes a path list checked against the diff, so out-of-bounds work never becomes a pull request at all. The spend ceiling becomes a cap checked before the model is called, and a ledger written in micro-dollars while the run happens. The audit record becomes a by-product of a chain of command in which nothing approves its own work and a named person signs every merge it holds in probation.

None of that is a claim about how well the agents behave. It is a statement about what the architecture will and will not let through, which is the only kind of statement the three refusers can sign. It installs in your own infrastructure, which is how the same argument answers the question sitting underneath all five: the code and the data never leave.

05 · What to read next

The rest of the argument.

This essay is the diagnosis. The library is where the structural answer is worked out in detail, one decision at a time.

The layer that makes it signable

Five agents or five thousand… one chain of command.

Defined seats, hard gates on what any AI can touch and spend, and a human signature on every merge until you graduate it. It runs in your own infrastructure.