Every organisation I've walked into over the last two years has an AI project stuck in the same place. The demo was brilliant. The executives were delighted. A pilot got funded, a model got built, someone stood up in a town hall and showed it answering questions about the business as if it had worked there for years. And then it stopped — not with a failure anyone could point to, but with a slow, grinding stall on the way to production that nobody quite has the language for. I have the language for it. It's not a model problem. It's governance debt, and the AI project is simply the first creditor big enough to come collecting.

Governance debt is the exact cousin of technical debt, and it accrues the same way: through a decade of small, reasonable shortcuts. Nobody catalogued that dataset because the deadline was Friday. Nobody wrote down what the column actually means because the one person who knew was still in the building. Access was granted broadly because narrowing it was fiddly and the auditors weren't asking yet. Lineage was "in someone's head." Each shortcut saved a day and cost nothing measurable — until you try to point a large language model at your data and every single one of those deferred decisions demands to be settled before you can go a step further.

Why AI is when the bill arrives

Traditional reporting is forgiving of governance debt in a way that AI is not. A human analyst building a dashboard brings context the data lacks: they know that rev_final_v2 is the one you actually use, that the German subsidiary loads a day late, that a certain flag means something different after 2021. They quietly route around the debt, and the debt stays invisible. It's a subsidy the whole organisation has been living on without noticing.

An AI system has none of that context and infinite confidence. Point it at an ungoverned estate and it will happily join the wrong tables, surface the deprecated metric, expose the salary column to the intern who asked a clever question, and state all of it in fluent, authoritative prose. Suddenly every shortcut is a live risk instead of a private inconvenience. This is why the pilot works and production doesn't: the pilot ran on a small, hand-curated, quietly governed slice of data that someone cleaned up specially. Production means turning the model loose on the real estate — and the real estate is where the debt lives.

So the "AI readiness" everyone is scrambling for in 2026 turns out to be something much less exciting than the vendors implied. It's not GPUs or a frontier model or a Copilot licence. It's the boring plumbing: a catalogue that tells you what you have, lineage that tells you where it came from, quality you can measure, and access control you can defend. The EU AI Act's high-risk obligations, now moving from slideware to real deadlines, only sharpen the point — you cannot document and govern an AI decision if you never governed the data underneath it.

The symptoms, so you can name it

  • The pilot-to-production cliff. Everything works on the curated demo dataset and nothing works on the real one. This is the single clearest tell.
  • The "which number is right" argument. If your own people can't agree on the authoritative version of a metric, your model certainly can't pick it.
  • Nobody will sign off. The project stalls at a risk review because no one can answer "what data does this touch, and who's allowed to see the output?"
  • Every question becomes an archaeology dig. Teams spend weeks reconstructing what a field means because the knowledge was never written down.

If two or more of those are familiar, you don't have an AI problem. You have a governance-debt problem that AI made visible, and that's actually good news — because it means the fix is known, even if it isn't glamorous.

Paying it down without a two-year programme

Here's where I'll say the unpopular thing: the answer is not a grand enterprise governance programme. I've watched those consume budgets for years and deliver a policy document nobody reads. Governance debt, like technical debt, is paid down best incrementally and in service of a concrete goal — and you now have the most concrete goal imaginable in the stalled AI project everyone wants unstuck.

  1. Scope to the use case, not the enterprise. Don't catalogue everything. Catalogue the data this AI project actually touches. A narrow, complete, trustworthy domain beats a boil-the-ocean initiative every time, and it ships this quarter.
  2. Make lineage and definitions a deliverable, not a hope. For the data in scope: where does it come from, what does each field mean, who owns it, how fresh is it. Written down, in a catalogue like Microsoft Purview, not in someone's memory.
  3. Fix access before you fix cleverness. Decide who is allowed to see what before the model can surface it. This is the control that keeps the salary column out of the wrong answer, and it's the one risk reviewers actually ask about.
  4. Measure the quality you're betting on. You don't need perfect data. You need to know how good it is, so you can tell the model — and the executives — where to trust it and where not to.

Do that for one use case and something quietly powerful happens: you've built the pattern. The second AI project inherits a governed domain and a way of working, and it moves faster. The debt gets paid down along the grain of real delivery instead of as an overhead nobody wants to fund.

The uncomfortable reframe

I've argued for years that governance is the steering wheel, not the brake — the thing that lets you go fast safely rather than the thing that slows you down. AI has finally made that argument for me, more persuasively than I ever could. The organisations pulling ahead in 2026 are not the ones with the best models. Frontier models are a commodity you can rent by the token. They're the ones who did the unfashionable work of governing their data, and who can therefore actually deploy — turn a promising pilot into a production system a regulator won't flinch at and a board will trust.

The counter-view deserves its hearing: yes, you can absolutely stand up an impressive AI demo on ungoverned data, quickly and cheaply, and plenty of vendors will help you do exactly that. But a demo is not a deployment, and the distance between them is measured almost entirely in governance debt. The pilot is easy because the pilot doesn't have to be trustworthy. Production does.

So if your AI project is stuck, stop tuning the model. Go and look at the data underneath it. The blocker was never the intelligence. It was the ten years of shortcuts, all coming due at once — and the good news is that paying them down is the most valuable thing you'll do all year, with or without the AI on top.