Orphaned Access: The Silent Cybersecurity Gap
Benedikt Langer
5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...
HBR’s analysis of more than 12,000 real-world deployments reveals a clear pattern: the companies that scale AI don’t treat it as a technology project; they treat it as a budget and ownership decision. The other 70 percent churn out pilots that never make it into the P&L.
Key Takeaways
Harvard Business Review evaluated one of the largest collections of real-world AI deployments in 2026-no surveys, no hypotheticals, just documented projects from companies with more than 1,000 employees. The result is both sobering and precise.
The number that sets the direction
68 percent. of the analyzed projects remained stuck at prototypes or limited pilots. Only 29 percent reached a stage where value contribution was regularly measured and operations handed off to the line organization. The remaining 3 percent were later shut down. Source: HBR, analysis of 12,000+ AI cases, 2026.
What matters is not the technology. The successful cases used largely the same models and platforms as the failed ones. The difference lies in the anchoring before the first prompt. The data also show that the gap between “pilot live” and “value contribution on the balance sheet” averages 14 months-and in many cases is never closed.
The analysis identifies three patterns that recur in scaling projects-and are missing in most others.
1. The P&L anchor. In the cases that scale, a business owner with profit-and-loss responsibility is at the table from the start. Not as a “stakeholder,” but as a co-decision-maker on scope, budget, and termination criteria. In DACH companies this is often the CFO or a division head who will ultimately bear the costs. Without this anchor, AI becomes a cost center nobody defends when the next budget cycle arrives.
2. The hard 90-day rule. Successful teams define three measurable criteria before the first sprint; missing any triggers automatic project termination. Typical examples: break-even on a defined user cohort within 90 days or a reduction in a specific process time by at least 18 percent while maintaining quality. Without this rule, pilots morph into permanent experiments that tie up resources and erode credibility.
3. Platform over use-case collection. Scaling companies build an early, lean but mandatory platform layer (data, access rights, logging, FinOps). The others launch dozens of use cases in parallel on different tools and later wonder why governance costs and inconsistencies skyrocket. The platform isn’t decoration-it’s the prerequisite for the second and third use case to cost less than the first.
The HBR data is global. For German and Austrian companies, an additional layer comes into play: organizational and regulatory friction is systematically higher. Works councils and co-determination extend the time from pilot to rollout by an average of four to seven months-this isn’t a bug, it’s reality. Ignoring it means planning with American or Asian assumptions and failing at the first escalation. Procurement processes and legacy contracts add to the challenge.
The decisive difference isn’t the algorithm. It’s who ultimately owns the outcome. In scaling cases, there’s a clearly designated sponsor whose bonus or budget in the next cycle hinges on the result. That creates a completely different discipline around scope, data quality, and change management than in run-of-the-mill “digital-office” projects. The HBR data also reveals: companies that launch AI as a cost center scale less often than those that treat it as an investment with a clear ROI model. The distinction isn’t semantic-it determines whether the CFO still defends the project after nine months or quietly buries it. In the successful cases, success metrics weren’t defined by the project team but by the future operations lead.
“We stopped collecting use cases. Instead, we set a single KPI that the department head personally owns. Suddenly, everything else fell into place.”
– CIO of a mechanical-engineering group, DACH, 2026
Not every pilot must scale. The analysis also shows cases where experimentation was deliberately used to build competence or assess a strategic risk. The difference from failed projects lies in the conscious decision and a clear time limit. Yet anyone still running a third pilot without a platform or ownership rule isn’t generating a learning curve-only costs. The 12,000 cases clearly distinguish between “controlled learning” and “diffuse experimentation without exit criteria.”
Whoever launches a new AI initiative now should lock in three things before the first workshop:
Without these three elements, the odds rise that this project will join the 12,000-case graveyard of unscalable pilots. Technology is now the smallest part of the equation.
In the analysis, scaling companies typically started with one to a maximum of three, expanding only after successful platform validation. More than five parallel pilots without a shared infrastructure correlates strongly with failure. Governance and context-switching costs grow faster than the learning payoff.
These tools scale quickly for individual productivity. HBR case studies, however, show that the major value contribution almost always comes from process-integrated systems, not general-purpose assistants. Both are legitimate – just not interchangeable. Gains in individual productivity are easier to capture than sustainable process-cost reductions.
Successful DACH examples brought the works council in early as a co-designer, not a roadblock. That means sharing concrete data on job impacts and agreeing on transparency and co-determination before the first pilot. It takes time up front, but prevents escalations and renegotiations under deadline pressure later.
Only if that person also owns the budget and the results. Pure staff roles without P&L ties produced significantly more unscalable pilots in the analysis than line managers with direct cost accountability.
Read more on Digital Chiefs
Digital ChiefsGermany as a Business Location Needs ProductivityDigital ChiefsMade for Germany: What 735 Billion Are Really WorthDigital ChiefsThe Chief AI Officer is here. The problem remains.More from the MBF Media Network
cloudmagazinWhen the AI bill blows up the cloud budget mybusinessfuture95 percent of AI pilots deliver nothing; 5 percent already deliverImage source: AI-generated (July 2026).