Eighty-eight percent of organisations are using AI in at least one business function today. Yet only a small fraction have a governance framework mature enough to actually manage it.

Sit with that gap for a second, because it is not an abstraction.

Grant Thornton asked business executives a more pointed version of the same question this year: could your organisation pass an independent AI governance audit within ninety days? Seventy-eight percent said no.

That number should unsettle anyone who has approved an AI pilot in the last two years โ€” which, at this point, is almost everyone.

Here is the pattern I keep seeing across institutions, sectors, and geographies:

Getting an AI system from pilot to production is not fundamentally a technology problem.

And getting an organisation certified or endorsed against AI standards is not fundamentally a compliance problem.

Both are accountability problems, wearing different costumes.

Who owns this system?

Who can stop it?

What evidence exists that it works the way we claim?

Can its decisions be explained?

Is the data, model, and operating footprint where we say it is?

Those questions do not change whether you are trying to scale a pilot, satisfy internal audit, brief a board, or prepare for an ISO 42001 assessment. Only the audience asking them changes.

Over the next several weeks, I am going to work through this properly, in public.

The first half of the series will look at what actually separates AI pilots that make it to production from the ones that quietly die in a steering committee deck โ€” the real capability gaps, not the ones vendors usually talk about.

The second half will look at the certification, regulatory, and assurance landscape itself: what ISO 42001 actually certifies, what NIST AI RMF structures, what the EU AI Act mandates outright, and โ€” because most of this conversation still ignores it โ€” what regulators across the GCC are already requiring today.

I am calling this discipline AI TrustOps, because that is what it is:

The operational work of making AI trustworthy enough to bet a business on โ€” not the paperwork that follows after someone has already decided to.

If you are sitting on a pilot that has been โ€œalmost ready to scaleโ€ for longer than feels comfortable, or a board that has started asking questions your AI programme cannot yet answer, this series is for you.

Next up: Why most AI pilots never make it to production, and why the reason is rarely the model.


Leave a Reply

Your email address will not be published. Required fields are marked *