Skip to content

We only publish what we can defend in a vendor meeting. Every claim carries an ID, a review date, and a verdict you can check.

Issue 017 · Week 17 · 2026
Ledger
Status moved

No verdict transitions in the last 30 days. Every tracked claim is currently holding or pending its scheduled review. See the ledger →

The AI-written publication for enterprise AI leaders.

Claude writes every piece. Peter — a senior IT leader — sets the brief, checks the evidence, signs off, and owns every claim on a 30–90 day review cycle.

Newest · AI Implementation

The State of Enterprise Agentic AI 2026

An aggregate analytical report on enterprise agentic AI in 2026, drawing from approximately 60 tracked claims. The deployment record is bimodal, the vendor landscape converged to four credible plays, the governance gap is structural, and the EU AI Act enforcement window opens 2 August 2026. The defining variable for the year is deployment discipline, not model capability.

Read the piece →·Written by Claude, signed by Peter

Recent pieces

Full archive →
Risk & Governance

Non-human identity for AI agents: the 2026 IAM playbook

AI agents are not just another flavour of non-human identity. They are dynamic, ephemeral, delegating actors with reasoning capacity that legacy IAM cannot represent. The 92% of enterprises that report low IAM confidence for agentic AI are running an identity model with one structural axis where the deployment requires four. The remediation is a layered extension on top of existing IAM, not a rip-and-replace migration.

12 min
Risk & Governance

NIST AI RMF mapping for enterprise agentic AI

Mapping the NIST AI Risk Management Framework's four functions (Govern, Map, Measure, Manage) onto enterprise agentic AI deployment work. The same artefacts that satisfy EU AI Act Article 9 cover NIST AI RMF substantially. The reverse mapping requires more work.

10 min
Implementation

Multi-agent architecture playbook for enterprise AI

Three orchestration patterns for enterprise multi-agent systems (hierarchical, peer-to-peer, broker-mediated) with materially different governance properties. The choice is not a free architectural decision under EU AI Act Article 9; broker-mediated is the 2026 default for high-risk deployments.

10 min
AI Implementation

MCP and the coming standard for enterprise agent tooling

Model Context Protocol reached enterprise procurement gravity in 18 months. The 10,000+ active public servers, adoption by ChatGPT, Cursor, Gemini, Copilot, and VS Code, and the December 2025 Linux Foundation donation made MCP a tooling-layer choice that ripples through every adjacent agentic-AI decision. The procurement question is not whether to adopt; it is which servers, which scopes, and how cross-agent delegation gets governed.

12 min
Risk & Governance

HIPAA-compliant agentic AI: the 2026 healthcare playbook

Four conditions for HIPAA-compliant agentic AI deployment in U.S. healthcare in 2026: BAA covering the agent workflow, dual-purpose audit log structure, PHI flow mapping under minimum necessary, clinical-correctness drift monitoring. Anthropic's three-cloud BAA position is structurally distinct.

9 min
Risk & Governance

The Head of AI Governance role specification, 2026

The role specification for the Head of AI Governance: six accountabilities, executive-committee reporting line, $250K-$1.2M compensation range, 60% F100 adoption per Forrester. The single strongest predictor of enterprise readiness.

10 min
Risk & Governance

EU AI Act Article 12 audit-evidence template for agentic AI

A 14-field audit-evidence template that operationalises EU AI Act Article 12 record-keeping requirements for agentic AI deployments. Captures every agent decision in regulator-queryable form. Designed for under-4-business-hour evidence assembly.

9 min
Business Case & ROI

Anthropic vs OpenAI vs Google vs Microsoft for enterprise agents in 2026

The four credible enterprise agentic AI platform plays in 2026 are Anthropic, OpenAI, Google, and Microsoft. The procurement decision between them is no longer primarily about model capability. It is about pricing model, governance and BAA posture, and ecosystem distribution. Treating it as a model-quality bake-off is the most common 2026 procurement mistake.

12 min
Business Case & ROI

The 2026 Enterprise Agentic AI Procurement Playbook

A six-stage procurement track integrating build-vs-buy-vs-partner, the 60-question RFP, GAUGE governance scoring, four-vendor comparison, and EU AI Act compliance into one operational sequence. Ships in 8 to 10 weeks for standard enterprise environments. Produces an audit-defensible procurement artifact that satisfies EU AI Act Article 9 by construction.

11 min
Risk & Governance

EchoLeak and the cross-agent prompt-injection class

EchoLeak (CVE-2025-32711) is not a Microsoft 365 Copilot bug. It is the canonical example of a class of attacks affecting any architecture where an agent ingests untrusted content and has tool surfaces capable of exfiltration. Closing the class requires architectural separation, not point-fixes.

9 min
Risk & Governance

Centralized vs federated AI governance: the 2026 design choice

Three AI governance organisational models (centralised, federated, hybrid) with materially different scaling and compliance properties. Hybrid is the dominant Fortune 500 pattern in 2026. The right model depends on deployment count, regulatory exposure, and existing risk-management maturity.

8 min
Understanding AI

When AI writes about AI: the case for tracked claims

Most enterprise-AI publications hide their AI use. A few disclose it. This site argues the disclosed model produces more verifiable commentary, and the ledger is the proof.

11 min
Business Case & ROI

AI agent ROI calculator: the 2026 enterprise framework

Eight-input ROI calculation framework for enterprise AI agent deployments. Covers what standard SaaS calculators miss: per-session-hour cost, HITL labour, instrumentation, compliance, productivity uplift, avoided incidents, revenue net of regression risk, strategic-option value.

10 min
Risk & Governance

The AI agent risk register: 2026 enterprise template

A 12-column risk register template that operationalises EU AI Act Article 9 and NIST AI RMF Manage. Integrates threat surface, controls, audit substrate, and kill-criterion enforcement into a single living artefact owned by the Head of AI Governance.

8 min
Business Case & ROI

AI agent contract exit clauses: 8 provisions for 2026

Eight contract exit-clause provisions that standard SaaS templates do not cover but enterprise agentic AI procurement requires: audit-log export, trained-state extraction, prompt portability, connector reconfiguration, named handoff, regulatory-evidence preservation, data-residency continuity, liability-tail.

9 min
Risk & Governance

The agentic AI readiness diagnostic: 10 questions for the high-performing tail

10 questions auditing the operating profile of the high-performing 6-12% enterprise agentic AI cohort. Answer 8 to 10 YES for the high-performing tail. Answer 4 or fewer YES for the operating profile of the 88-94% struggling segment.

13 min
Risk & Governance

Six documented agentic AI failure cases and what they teach

Six publicly documented agentic AI deployment failures from 2024-2025: Air Canada, NYC MyCity, Replit, Cursor, Klarna, DPD. Three structural failure modes, mapped to the seven-control surface. The pattern is consistent enough to use as a procurement filter.

12 min
Implementation

A2A protocol: enterprise agent-to-agent interoperability

The A2A (Agent2Agent) protocol is the most credible 2026 candidate for cross-vendor agent interoperability. MCP handles agent-to-tool; A2A handles agent-to-agent. Adoption trajectory points to deployment-grade stability in H2 2026 with widespread enterprise rollout in 2027.

8 min
Business Case & ROI

The McKinsey 17% EBIT claim: what the survey actually measured

The McKinsey 17% EBIT-attribution figure is the most-cited single statistic in 2026 enterprise agentic AI procurement. The way it is typically read materially overstates what the underlying survey supports.

7 min
Risk & Governance

The shadow-AI discovery playbook: finding the agents your org already has

The 2024 framing of shadow AI assumed unsanctioned tool adoption. The 2026 reality is agentic capability silently activating inside already-approved tools. A 12-question discovery playbook for enterprise IT, oriented to capability state rather than vendor identity, with the EU AI Act August 2026 deadline as the forcing function.

13 min
Risk & Governance

The EU AI Act and agentic AI: what August 2026 actually requires

The 2 August 2026 enforcement deadline applies high-risk-system obligations to most enterprise agentic AI deployments operating in EU jurisdiction. The operational scope is broader than the Annex III categories suggest, and the compliance gap most enterprises face is structural. Building the evidence layer post-hoc is the failure mode.

13 min
Understanding AI

AI assistant vs AI agent: the procurement distinction

AI assistants and AI agents are not the same product class. One suggests; the other acts. The procurement, governance, audit, and TCO models differ categorically. Conflating them is the most common 2026 enterprise procurement mistake.

9 min
Business Case & ROI

Why 88% of agentic AI deployments fail

Stanford 2026 data: 12% of agentic AI deployments clear 300%+ ROI; 88% miss. The distribution is not a capability problem. It is a governance gap.

9 min
Business Case & ROI

The McKinsey 23%: the agentic AI scaling gap

McKinsey 2025: 23% scaling, 39% experimenting. The pilot-to-production chasm is not about model readiness. It is about operational preconditions.

9 min
AI Implementation

The enterprise agentic AI RFP: 60 vendor questions

Generic SaaS RFPs miss six dimensions that decide whether an agentic deployment survives 18 months. Here's the GAUGE-mapped 60-question version.

11 min
Risk & Governance

The enterprise agentic AI governance playbook for 2026

Most enterprise agentic AI governance in 2026 is compliance theater. The board sees an EU AI Act map; the deployments shipping out of IT ops have no.

11 min
Business Case & ROI

The CMU 30.3%: the enterprise agent capability gap

Carnegie Mellon 2026: 30.3% task completion for best frontier models. The deployments that work operate within the 30.3%, not around it.

9 min
Business Case & ROI

The CFO's agentic AI business case: TCO and ROI

Most agentic AI business cases fail audit. Three documents survive: TCO with named components, ROI with pre-deployment baseline, scenario-weighted NPV.

10 min
Business Case & ROI

Build vs buy vs partner for enterprise agentic AI in 2026

Most enterprises frame agentic AI as build vs buy. It's a binary on a three-body problem. Partner — the third path — is systematically under-chosen.

11 min
Risk & Governance

Agentic AI in financial services: five frameworks

Financial services sit at the intersection of DORA, NIS2, MiFID II, EU AI Act, and GDPR. Agentic AI inherits every obligation. The sector playbook.

11 min
AI Implementation

The unverified citation chain: where enterprise AI decisions actually come from

Vendor claims reach CIO procurement decisions through a four-link chain: earnings call to analyst note to trade press to board deck. No link in that.

8 min
Risk & Governance

Agentic AI got real in Q1 2026. Most enterprise charters were written for a different quarter.

Gartner said 28%. Stanford said 62%. Unit 42 said the prompt-injection attacks are now in the wild at commercial scale. Three data points, one quarter.

8 min
AI Implementation

Google AI Mode restaurant booking: the template for every partner-aggregation vertical

Google shipped agentic restaurant booking to eight countries on 10 April 2026. The restaurant vertical is not the story. The story is that eight named.

5 min
AI Implementation

From DMAIC to AI agents: how traditional optimization methods accelerate agentic AI success

Six Sigma organisations report 87% success with agentic AI against 27% for organisations without. The obvious reading is that DMAIC accelerates AI.

5 min
Latest AI Developments

GPT-5 Pro at $200 a month: what the pricing tier signals to enterprise IT

OpenAI's GPT-5 Pro tier launched in August 2025 with no benchmarks and a $200/month subscription. The pricing decision is more interpretable than the capability claim. What the tier signals for enterprise procurement and how the McKinsey 17% EBIT-attribution figure cited around the launch should actually be read.

10 min
AI Implementation

The agentic AI success formula: what 171% average ROI actually hides

Enterprise agentic-AI deployments report 171% average ROI. The average obscures a bimodal distribution — roughly 12% of deployments clear 300%+, and.

5 min
AI Implementation

The bimodal ROI distribution in enterprise agentic AI

Enterprise agentic AI ROI is bimodal, not normally distributed. Stanford DEL, Gartner, and OneReach data converge on the same shape: a high-performing tail and a much larger struggling body. What separates the two is not capability — it is operational discipline.

26 min
AI Implementation

Multi-agent systems in manufacturing: the 30% downtime claim, examined

The 30% reduction in unplanned downtime is the most-cited single figure in manufacturing AI. The 2026 case-study record supports it, but only for a narrow architectural pattern. What the underlying studies actually measured, and where the figure gets over-cited.

6 min
AI Implementation

Agentic AI Centers of Excellence: who actually staffs them, who doesn't

The Agentic AI CoE pattern across enterprise IT in 2026. Where the model works, where it stalls, and the staffing realities — function lead, evaluation owner, governance interface — that determine which side a deployment lands on.

23 min
Business Case & ROI

The hidden costs of agentic AI: a CFO's guide to true TCO and ROI modeling

Enterprise TCO models underestimate agentic-AI programmes by 40-60%. The surprise is not that the costs are hidden. It is that they are distributed.

5 min
Use Cases

The $7.2M firewall-change incident: what the number actually represents

A widely-cited $7.2M figure for a Fortune-500 firewall-change incident in 2025. The decomposition: capex, opex, opportunity cost. What the line items signal about agentic IT-ops change-management, and where the headline number overstates the case.

7 min
AI Implementation

Back-office vs front-office: where agentic AI's economics actually compound

Enterprise agentic-AI ROI is bimodal. The 12% of deployments that compound share one structural trait — they live in back-office operations where.

6 min
AI Implementation

Salesforce's 9,000-person redeployment: the template most enterprises will copy

Salesforce's Agentforce rollout automated the bulk of tier-1 support work and moved roughly 9,000 engineers into new roles rather than out of the.

6 min
Use Cases

Enterprise agentic AI in 2024-2025: what shipped, what landed, what didn't

Agentic AI's $3.50-per-dollar average return masks a 70% task-failure rate on the Carnegie Mellon benchmark. Narrowly-scoped deployments clear the bar.

10 min
Business Case & ROI

AI readiness in organizations: The 2024-2025 landscape

Global AI spend is on track for $644 billion, yet only 9% of firms have reached true AI maturity — and 30% of generative-AI pilots will be abandoned.

12 min
Framework · GAUGE

The Enterprise Agentic Governance Benchmark. Six dimensions, scored 0–100. Free 5-minute web diagnostic; 30–45 minute Excel for governance groups.

Score a deployment →

Coming next

Peter's editorial calendar — honest dates, bumped-with-notes if missed.
  1. Week 17
    26 Apr 2026
    Non-human identity — the first procurement question CIOs aren't asking yet

    Every enterprise agent deployment passes through a credential. Most teams still hand the agent a human's credential. Naming the NHI gap is the next Q2 procurement conversation.

  2. Week 18
    03 May 2026
    Shadow agent sprawl — what telemetry catches and what it misses

    The browser-as-agent-runtime pattern creates a detection gap that MDM/CASB don't see. What the first wave of shadow-AI discovery tools actually find, and the three categories they miss.

  3. Week 19
    10 May 2026
    The AI agent MSA — four clauses every enterprise contract needs by August

    EU AI Act enforcement activates 2 Aug 2026. The clauses that survive legal review in the next quarter will be the ones that don't pretend the agent is conventional SaaS.

Vigil · 35 reviewed