Skip to content
SafeComs
All insights

CEO AI ownership & governance

Why 95% of corporate AI pilots fail (and what the 5% do differently)

The binding constraint is not the technology, the data, or the use case. It is who owns the decision.

Bernard Collin, CEO of SafeComs · 3 July 2026 · 8 min read

In August 2025, MIT's NANDA initiative published the most rigorous study yet on enterprise AI adoption. They looked at 300 deployments and 150 leader interviews across global companies. The headline finding was simple, and brutal.

95% of corporate generative AI pilots deliver zero measurable impact on the bottom line.

Only 5% scale into real revenue or cost reduction. The other 95% become abandoned dashboards, half-finished proofs of concept, and slide decks explaining what was supposed to happen.

You probably read that statistic and reached for the easy explanation. The technology is immature. The use cases were wrong. The data was not ready. Every one of those is a comfortable lie. The MIT team looked at all of it, and none of it is the binding constraint.

The binding constraint is who owns the project. And the function most likely to be in the way, in 2026, is your own IT department.

The CEO who owns it, wins

McKinsey ran a parallel study in early 2025. They examined 25 factors that drive AI's bottom-line impact: model selection, vendor choice, data quality, training budget, talent depth, infrastructure, twenty more. They wanted the single biggest predictor of EBIT impact from AI. It was none of those.

The single biggest predictor was whether the CEO (not the CIO, not the head of digital, not a transformation committee) personally owned governance of the AI program. Only 28% of organisations have that today. The other 72% have something that looks like it on paper: a Head of AI, a working group, a vendor partnership. None of it correlates with results the way CEO ownership does.

The CEO is the only person in the building with the authority to override an entrenched function, the political capital to absorb the early failures, and the time horizon to wait for the payoff. Everyone else has reasons to be careful, slow, or absent.

The data tells you what is happening

In 2024, 17% of companies abandoned the majority of their AI initiatives. In 2025, that number rose to 42%. S&P Global's research is unambiguous: companies are not failing slowly, they are quitting.

While they quit, their own employees are not. The 2024 Microsoft Work Trend Index reports that 78% of employees bring their own AI tools to work, and 90% of them use AI personally every day. Only 40% of their employers offer a sanctioned tool to do the same job.

The polite name for this is shadow AI. The honest name is that your team has already decided the official AI strategy is unusable, and they are running their own. Your IT department knows this is happening. Its response is to write a policy. The policy lands in an inbox. Nothing changes.

The CEOs who are winning in 2026 read that gap as a signal, not a security problem. The signal is that AI has already arrived in the company. The only choice left is whether the arrival is governed or ungoverned.

Why IT departments do this, and why it is not their fault

I have spent more than twenty years building security and IT operations for companies across Asia. I do not believe IT teams obstruct AI out of incompetence or bad faith. They are doing exactly what their incentives reward.

An IT director gets fired for a breach. They do not get fired for a stalled initiative. The asymmetry is total. Block the AI project, and the worst case is a frustrated CEO. Approve the AI project and let one wrong document escape, and the worst case is a regulator, a lawsuit, a front page.

So they block. They write a 40-page policy. They demand a vendor audit that takes nine months. They invoke PDPA, PDPO, GDPR; all real frameworks, all weaponised here to slow the decision rather than shape it. The result is the worst of both worlds. The official AI strategy moves at the speed of the audit. The unofficial one moves at the speed of a mobile app. Your data leaks anyway, with none of the productivity gains.

The match in your kitchen drawer

Think of AI as a match. A match in your kitchen drawer can heat your home, cook your food, light your candles on a difficult evening. The same match, dropped onto a curtain, burns the house down. The technology is identical. The outcome depends entirely on who is holding it and what they intend.

For the last 200 years, every household has solved this problem the same way. The adults decide where matches go, how children learn to use them, what the rules are. Nobody outsources the question to the fire department. The fire department gets called when something has already gone wrong.

Your IT department is the fire department. Its job is to make sure the building does not burn down. They are very good at this job, and they should keep doing it. What they should not do is decide which rooms get matches and which do not. That decision belongs to the person responsible for the whole house. In a company, that is you.

You already trust Microsoft with your email

Every CEO reading this has spent years storing customer contracts, board minutes, financial reports, and personal correspondence inside Microsoft 365. You have signed the data-residency agreements. You have accepted the encryption model. You have already made the trust decision.

Microsoft Copilot uses the same data, the same residency, the same encryption. It is the same trust decision applied to a new use case, if you implement it correctly. The catch is that most companies do not. They turn on Copilot without cleaning up file-sharing permissions, without setting the controls over who can see what, without giving the CEO a clear sense of what AI agents are now reading from inside the company. That is where the risk lives: in the lazy configuration around the AI, not in the AI itself.

This is the work the program addresses. We call the approach iSabai, a Thai word meaning at ease, comfortable, sorted. The idea is simple: you should not have to make a second trust decision for AI. You should not have to learn a new platform, accept a new data-residency model, or vet a new vendor's security posture. You should be able to use what you already pay for, properly configured, with the same discipline you have already applied to email.

For the CEOs who want the privacy promise stronger still (defence, finance, family office, regulated industries), we offer an on-premises version. Same iSabai approach, with a physical air-gap. Your strategic AI lives in your office. Nothing leaves the building.

Two honest counter-arguments

Anyone reading this should challenge two things. First, IT-led AI does work, sometimes. BBVA, JPMorgan, and DBS Bank are often cited as success stories where the CIO drives the program. Look closer. In each case the program runs from the CEO's office or the COO's office, with the CIO providing infrastructure and model-risk governance underneath. The CIO is the enabler. The CEO is the owner. The structure looks IT-led from the outside, and is not.

Second, without IT governance you get a breach. This is true. IBM's 2024 Cost of a Data Breach report found that shadow-AI breaches cost roughly 670,000 USD more than the average breach. The honest response is not to remove IT. It is to move IT from a gating role to an enabling role, what I call the safe yes. The CEO sets the direction. IT builds the guardrails that make that direction safely executable. Both functions matter. The order matters more.

Why APAC CEOs cannot wait

In Southeast Asia, the situation is sharper than anywhere else. ManpowerGroup's 2025 research shows 77% of employers cannot fill the skilled tech roles they need. BCG's Unlocking Southeast Asia's AI Potential found that 52 to 57% of SME and mid-market companies in the region name the skills gap as their number one AI blocker.

You cannot hire your way out of this. The talent does not exist in the quantities required, at the salaries you can pay, in the cities where your team lives. The CEOs who will win the next 24 months in this region are not going to outhire the problem. They are going to outlead it. They are going to take AI out of the IT in-tray, put it in their own, and treat it like every other transformation they have owned in their career.

The constructive path

I am writing this because I have watched too many capable APAC companies stall on AI for the wrong reasons. The technology is ready. The use cases are clear. The economics work. What is missing is one decision, made in one office, by one person. That person is the CEO.

If you take one thing from this article, let it be this: your IT department will not kill your AI initiative on purpose. It will kill it by doing exactly what you are paying it to do, in the absence of someone telling it to do something different. The someone is you. The something is to own the program, set the direction, and ask IT to build the guardrails for yes, not the case for no.

The 5% of companies winning at AI today are not luckier, richer, or more technical. They are led by people who decided this was their job. The 95% are led by people who decided it was someone else's. Pick your side.

Bernard Collin is the CEO of SafeComs, a cybersecurity and AI transformation consultancy serving CEOs across APAC since 1999. To see where your company sits on the readiness curve, take the free [AI Readiness Score](/readiness). To see CEO-owned AI running on your own Microsoft 365 tenant, [request a trial](/trial).

Own the decision. See it on your own tenant.