Every leader I talk to says they’re “working on their AI strategy.” Almost none of them can tell me which of three stages they’re actually in. That gap is exactly why so many AI initiatives stall before they produce anything durable.
Gartner now predicts that more than 40% of agentic AI projects will be canceled by the end of 2027. The reasons aren’t mysterious: escalating costs, unclear business value, and inadequate risk controls. “Most agentic AI projects right now are early-stage experiments or proof of concepts that are mostly driven by hype,” said Gartner Senior Director Analyst Anushree Verma when the prediction was published in June 2025. That’s not really a technology problem. It’s a maturity problem, and it’s one most companies never diagnose because they aren’t looking at the right map.
The map most companies don’t have
In governance and architecture work, I’ve never met a company that jumped straight from “no AI” to “AI-native.” Every organization moves through the same three stages. What varies is whether they move through them on purpose or get stuck in the middle one without realizing it. I call this the Governed Growth Model: Shadow AI, Managed AI, and Governed AI-Native.
Stage 1: Shadow AI
This is where almost every organization starts, whether leadership admits it or not. Microsoft’s Work Lab research puts the number at roughly 8 in 10 office workers now using some form of public AI, often without their IT department’s knowledge or approval. Cisco’s research found that about 60% of organizations have already had at least one data exposure incident connected to employees using public generative AI tools. Shadow AI isn’t a scandal. Every ungoverned technology adoption cycle looks like this at first. The mistake is staying here while telling the board you’ve “adopted AI.”
If you haven’t done it yet, the first honest step is an actual inventory rather than a policy document. I wrote about why that distinction matters in Your AI Policy Is Not Your AI Inventory.
Stage 2: Managed AI, the stage everyone skips
This is the stage that produces Gartner’s cancellation numbers. A policy exists. A steering committee exists. But there’s no real inventory connecting that policy to where AI actually touches the business, and no architecture decision-making translating governance intent into system behavior. Companies either believe they’re further along than they are, or they skip this stage entirely, moving straight from scattered pilots to enterprise rollout claims without ever building the connective layer between the two. Gartner also estimates that only around 130 of the thousands of vendors marketing agentic AI products are doing anything close to what they claim. The rest are “agent washing,” rebranding existing products without meaningfully agentic capability. Managed AI, done honestly, is where a company starts being able to tell the difference.
Stage 3: Governed AI-Native
This is the stage where governance is architecture, not a document. Two things have to be true at once. Process owners can say exactly which decisions are AI-assisted and why, which is what the Six-Lens Opportunity Map in From Process Maps to AI Opportunity Maps is built to surface. And the enterprise architecture itself can enforce that boundary without depending on someone remembering to check it, which is the point of the Decision Spine in Enterprise Architecture as a Living Decision System. Neither piece works without the other. A workflow map without an architecture that can enforce it is a wish. An architecture without a workflow map behind it is guessing at what to enforce.
Which stage are you actually in?
Four questions tend to separate the stages honestly, more honestly than most internal AI scorecards:
- Can you list every AI tool touching customer or employee data today, or only the ones you formally approved?
- If an auditor asked for your AI decision trail tomorrow, could you produce it in a day, or would it take a quarter?
- Does your architecture stop a risky AI use case before launch, or only flag it after something goes wrong?
- Is your AI governance a document people signed once, or a system that updates itself as new tools and workflows appear?
If the harder version of the answer applied to more than one of those, you’re probably not stuck in Stage 1. You’re stuck in Stage 2, which is a more expensive place to be stuck than most leadership teams realize. It’s the stage that quietly produces the pilots Gartner is counting toward that 40%.
Where this goes next
I’m building a short, self-scored AI Governance Maturity Assessment for the Playground section of this site, so you’ll be able to place your own organization on this model in a few minutes rather than guessing. Until it’s live, the honest self-check above will get you most of the way there. If you’re trying to figure out which stage your organization is actually in, that’s a conversation worth having before you write the next AI policy, not after.
