73 views
1 hour ago

5 technology leaders explain why most AI projects stall before they pay, and what the ones that paid did first

In July, Sharjah Maritime Academy in Khor Fakkan switched on Majid, an admissions agent that answers prospective students and their parents by voice and chat at any hour. The academy decided against public AI services and built a private platform around a large language model hosted on its own infrastructure, a decision Muhammad Affan Habib, its Director of IT, explained in terms of control. “This enables us to leverage generative AI while maintaining full control over institutional data, ensuring privacy, regulatory compliance, and intellectual property protection,” Habib said.

The choice behind Majid sits at the centre of what happened to enterprise AI over the past 12 months. The 15 leaders who responded to AI Times described a year in which companies stopped testing what generative AI could say and began handing it work, a change that Alfred Manasseh, COO and co-founder of Shaffra, which builds AI agents designed to act as digital employees, said has fundamentally altered the questions business leaders ask.

“We have entered a new phase where AI is becoming part of the workforce itself, building an intelligent operating layer that enables humans and AI to work together at enterprise scale,” Manasseh said.

Once software is permitted to act on an organisation’s behalf, the questions a leadership team has to settle change with it. The responses gathered here kept returning to whether the data beneath the system can be trusted, how much of the business it is allowed to touch, and which person is responsible when it gets something wrong, and the deployments producing measurable returns tend to belong to organisations that dealt with those questions before the first agent went live.

The first hard returns came from software wired into the transaction

The most specific financial case came from Suliman Gaouda, Regional Vice President, AI, APJMEA at the industrial software company IFS, who pointed to Kodiak Gas Services, a US gas compression operator, where a single digital worker handling material replenishment reclaimed more than 90,000 hours a year and removed over US$3m in cost. IFS gave the figures without a baseline, so the improvement on previous practice cannot be judged. “When the AI lives where the transaction happens, the value is captured automatically and shows up in the same operational metrics the business already tracks,” Gaouda said.

Gaouda traced most stalled projects to one design decision, in which a single general-purpose model is asked to plan a workflow, choose the tools, write the language and judge the outcome at once, and his remedy is to separate the planning work from the language work so that each can be checked.

“That separation is what makes an agent behave the same way on a Monday morning as it does at 3 a.m. on a Sunday, and it is what makes every decision auditable,” he said.

Salman Kazmi, Area Vice President for the Middle East, Turkey and Africa at BMC Helix, described the same shift inside IT departments, where customers have moved on from proofs of concept and now judge AI on how quickly faults are fixed. “Within IT operations, key indicators include faster incident resolution, increased automation, improved service availability and reduced operational costs,” Kazmi said.

He expects the service desk to change further as agents take on more routine work. “IT operations will become increasingly autonomous as AI will be able to predict incidents, resolve many issues by itself and continuously optimise enterprise services,” Kazmi said.

Failed projects began with a purchase order and went looking for a problem

Sami Alfaraj, MEA Head of Technology at Submer, which builds liquid and immersion cooling systems for data centres, has watched buyers acquire computing capacity first and search for a use afterwards. “Failed initiatives begin with a procurement event: GPUs are acquired, then the organisation searches for problems worthy of them,” Alfaraj said.

The programmes that succeed, he said, first establish which processes move the profit and loss account and which data feeds them, and Meriam ElOuazzani, Vice President for the Middle East, Turkey and Africa at Censys, identified the step that tends to set them apart. “I’ve found that successful initiatives share one quality: someone senior made the risk tolerance explicit before procurement happened,” ElOuazzani said.

Augusta Spinelli, Regional President at SAP EMEA, said the organisations making progress start from a defined business problem, now that chief executives and finance chiefs sit in on AI decisions. “The more successful organisations ask, ‘What business challenge are we trying to solve?'” Spinelli said.

Haider Amjed, Head of Technology for the UAE at NTT DATA, set out what stalled programmes tend to lack, and argued that AI has to be run as a transformation programme with executive sponsorship attached. “Failed initiatives often start with technology enthusiasm but lack a measurable business outcome, a clear owner, or the integration required to move beyond a proof of concept,” he said.

Sujay Patil, Senior Regional Sales Director at Kissflow, whose low-code platform runs approvals and procurement for manufacturers, property companies and retailers, sees the consequences in pilots that never connect to the rest of the business. “They deploy AI pilots that remain isolated from core business processes, enterprise systems, and governance,” Patil said.

A model is only as reliable as the records it reads

Alexandre Depret-Bixio, SVP International at the threat intelligence company Anomali, placed the dividing line beneath the model, in the condition of the data it is fed, and cited a survey of 75 US bank cybersecurity leaders in which a move towards decisions driven by business outcomes ranked among the most common priorities for the coming year. “Those that fail bolt AI onto fragmented systems and hope for the best, and most of those inherit noise, blind spots, and risk,” Depret-Bixio said.

Mansoor Baig, Head Scientific Computing/Senior Technical Specialist at King Faisal Specialist Hospital & Research Centre in Riyadh, where scientific computing systems manage and analyse tens of petabytes of clinical data, sees the same dependency in medicine. “Ultimately, a well-orchestrated, multi-modal data repository is the non-negotiable foundation needed to successfully scale AI across the enterprise,” Baig said.

Dr Rania Khalaf, Chief AI Officer at WSO2, which makes integration and API management software, cited Jonathan Ruane of MIT, who compares the moment to factories that swapped gas lamps for bulbs and gained little until they replaced a central steam engine with a motor at every machine, the redesign that produced the assembly line.

“AI experiments can be quick and exciting, but people often underestimate the effort of going from that to a production-grade, deployed solution that fits in the enterprise architecture and is providing actual value,” Khalaf said.

Amjed made the same point about the systems underneath, arguing that cloud platforms, data architecture, integration and security all have to be ready before AI can leave the pilot stage. “My view is that AI will only scale when the enterprise architecture is ready for it,” Amjed said.

Companies want AI managed like staff, and they rarely take access away from staff

Manasseh argued that the organisations moving past experimentation give each agent the equivalent of a job description, borrowing their discipline from human resources. “AI should be treated like any other member of the workforce with defined responsibilities, permissions, performance metrics, and accountability,” Manasseh said.

Depret-Bixio sees a warning in the comparison, because new employees join with access matched to their role and tend to keep it long after their responsibilities have moved on. “We’re good at granting entitlements and bad at revoking them, so blast radius, which is the gap between what someone’s job requires and what they’re able to touch, can grow for years,” he said.

The same drift happens faster with AI agents, he said, since agents gather permissions to do their jobs and rarely face anyone checking whether those permissions still make sense. Haider Pasha, Chief Security Officer for EMEA at Palo Alto Networks, put a figure on the population involved. “Research from Idira, part of Palo Alto Networks, found that machine identities now outnumber human identities by 116 to 1 in the UAE, driven largely by AI identities,” Pasha said.

Patil said AI should inherit the permissions a business already enforces, and warned against letting it grow into another form of shadow IT. “Organisations need AI that operates within defined business rules, respects user permissions, protects sensitive data, and provides transparency around decisions,” Patil said.

Khalaf described the controls from the software side, arguing that they matter more as agents gain autonomy. “Enterprises must be able to define guardrails, give every agent a verifiable identity, monitor its behaviour, enforce security policies, and maintain complete audit trails,” Khalaf said.

Attackers mapped the new AI estate faster than its builders did

ElOuazzani, whose company maps what organisations expose to the internet, argued that every AI platform and agent put into production becomes infrastructure with exposures of its own, citing the exploitation of the open-source Langflow tool and malicious prompts injected into generative AI platforms at more than 90 organisations. “What I’ve found is that most organisations haven’t applied the same outside-in scrutiny to their AI stack that they would apply to any other external-facing asset,” ElOuazzani said.

She cited an average breakout time of 29 minutes last year for intruders moving from a first foothold into the rest of a network, a CrowdStrike record of 27 seconds, and a gap between the roughly 87% of organisations claiming clear AI governance frameworks and the 8% that independent research says have comprehensive ones. Much of the exposure begins with visibility, she said, because few teams know what AI is already running inside their environment.

“Shadow AI has become one of the most consistent friction points I hear about from security leaders,” ElOuazzani said.

Pasha said agents make attractive targets because of the access they carry. “AI agents require identities, permissions, credentials, and access to applications, making them attractive targets if governance is weak,” Pasha said.

He expects attackers’ use of AI to force a matching response from defenders, who will need security that correlates activity across networks, cloud, endpoints and identities. “Attackers are already using AI to automate and accelerate attacks, meaning defenders must rely on AI-powered security capable of detecting novel threats,” Pasha said.

Working governance can name, within minutes, who answers for an AI decision

Dr Betania Allo, a technology lawyer and AI governance adviser who developed a framework she calls the Intelligent Control Stack, proposed a check that any executive team could run at its next meeting. “A useful test for any blueprint: can it tell you, within minutes, who is accountable for a given AI decision, and what happens next if that decision needs correcting?” Allo said.

Her framework sorts AI uses by risk from the first day, so a customer service assistant can launch under standard controls while a system recommending credit or hiring decisions receives bias testing and human oversight first, an approach she said carries particular weight in Saudi Arabia, where frameworks from SDAIA and the National Cybersecurity Authority continue to mature. She also identified a blind spot that data protection rules on their own miss.

“Many enterprises maintain excellent compliance on data residency while relying on AI models hosted or trained outside their jurisdiction, creating a governance gap at the model layer that pure data-protection frameworks do not address,” Allo said.

Amjed said the region’s priorities give that discipline real commercial value for enterprises. “In the Middle East, where trust, privacy, and data sovereignty are critical, governance becomes a business enabler,” Amjed said.

Patil argued that most organisations already own the control machinery an agent needs, in the approval chains of their existing business processes. “The right approach is to build AI on top of governed business processes, where organisations already have role-based access, approvals, audit trails, compliance controls, and workflow governance,” Patil said.

Tolga Özdil, Regional Commercial Director for META at ASUS, reported strong UAE demand from financial services, government and professional services, where compliance weighs as heavily as performance. “Successful businesses will have a well-defined policy in place for the use of data and will make sure that there is human intervention in case of high-stakes decision making,” Özdil said.

Kazmi expects oversight tools to rise up the agenda as AI takes on critical work. “Another trend which has received increased attention is that of AI governance, observability and explainability as organisations adopt more intelligent applications for mission-critical tasks,” Kazmi said.

The holders of the most sensitive records are keeping their models at home

Baig’s hospital runs smaller, domain-specific language models inside its own secure infrastructure, and he described a governance gate built into the software that weighs each recommendation before anyone acts on it. “This governance gate continuously analyses the certainty and clinical impact of every AI recommendation, automatically tripping an operational circuit breaker to route low-certainty or high-risk tasks directly to a licensed clinician,” Baig said.

Habib has applied the same logic of containment in Khor Fakkan, where hosting internally keeps sensitive records with the academy.

“Hosting our AI platform within our own secure infrastructure allows us to maintain greater control over institutional information while reducing reliance on external public AI platforms for sensitive academic and operational data,” Habib said.

Özdil sees the same instinct reaching individual laptops, as neural processing units allow transcription, summarisation and translation to run on the device itself. “Running AI workloads locally on devices equipped with a powerful Neural Processing Unit (NPU) will also become important, as it helps organisations improve performance, reduce reliance on cloud infrastructure and keep sensitive data on the device,” Özdil said.

At national scale, Alfaraj said, GCC enterprises and governments increasingly want AI capacity on their own soil and under their own jurisdiction, which makes power and cooling a strategic matter now that rack densities have climbed from 10kW towards 100kW, beyond what air cooling can serve. “You can iterate on models weekly and software daily, but power, cooling and physical capacity are decisions that lock in for a decade,” Alfaraj said.

Counting prompts told boards little, so better-run firms count hours, incidents and watts

Khalaf warned against treating usage as proof of progress, a habit that has acquired its own nickname. “‘Tokenmaxxing’ has been the practice of measuring and maximising AI usage in organisations as an indicator of AI maturity,” Khalaf said.

She said the measure had been easily gamed, and urged companies to track the time and cost removed from specific tasks, new customer segments reached and revenue from AI products. Özdil pointed to how few executives trust their own numbers, citing a figure he did not source. “Although AI spend is increasing rapidly, only 29% of executives believe that they can accurately measure the ROI from their AI projects,” Özdil said.

Alfaraj said the most sophisticated customers model AI returns the way a manufacturer models a plant, and claimed that 2 identical GPU clusters can differ by 30% to 40% in output on thermal and power efficiency alone, a figure from a company that sells that efficiency. “Mature organisations measure economics: cost per inference, tokens per dollar, and increasingly, intelligence per watt,” Alfaraj said.

In healthcare, Baig said, the measures of success have to be agreed with clinicians before any development starts, and expressed in time saved, risk reduced and patient experience. “This clinical-first methodology mandates that success metrics are defined clearly before any development begins, preventing the common trap of prioritising technical complexity over actual patient outcomes,” Baig said.

ElOuazzani put the share of AI investments delivering measurable financial returns at around 12%, without naming a source, and Spinelli said reliable answers come to organisations that settle the measure first. “They establish a baseline, identify the desired outcome and measure progress against specific business objectives,” Spinelli said.

By 2028 AI is expected to disappear into operations, taking the accountability question with it

Most leaders expect AI to stop being discussed as a separate programme within 2 years, and Depret-Bixio expects the vocabulary to age with it. “Within the next 2 to 3 years, I expect the term ‘AI strategy’ to sound as dated as ‘digital strategy’ does today,” Depret-Bixio said.

Manasseh cited PwC estimates that AI could contribute US$135.2bn to Saudi Arabia’s economy and around US$96bn to the UAE’s by 2030, and expects AI to reshape career progression. “With this level of investment and focus, AI is likely to become embedded across most core business functions by 2028,” Manasseh said.

Gaouda expects autonomous machines to add to the load, with connected assets heading towards 22bn while only about half of industrial equipment is connected. “Every robot, drone, and self-driving machine is an asset with a lifecycle that must be planned, deployed, maintained, serviced, and orchestrated,” Gaouda said.

Spinelli expects the demand for human sign-off to grow as more of that work is handed to software. “As organisations automate more decisions and processes, governance, transparency and accountability will be essential. Human judgement will remain critical, particularly where decisions have significant business or societal impact,” Spinelli said.

Allo argued that the single most useful preparation for regulators is a name attached to every system that makes decisions. “Assign clear, named accountability for every AI system with decision-making authority, since this single practice does more to build regulatory confidence than any policy document,” Allo said.

In Khor Fakkan, Habib has described Majid as the first phase of the academy’s programme, with AI-powered professors, learning assistants and personalised study tools being developed within the same AI ecosystem, alongside the people and rules to govern them. “AI literacy, staff training, governance committees, cybersecurity programmes, and clearly defined AI usage policies help establish a culture where innovation and responsibility coexist,” Habib said.

Leave a Reply

Don't Miss

SandboxAQ just gave away the code to put any AI agent in your Slack

SandboxAQ has released Switch, software that brings AI agents from competing vendors

TII joins AMD, Intel and Microsoft on a standard built to prove what an AI agent actually did

The Technology Innovation Institute has signed on as a founding collaborator in

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy