A magenta demo stage that does not connect to a production track, why AI pilots stall before production, Amelia S. Gagne
Ai Getting Started • Updated • 8 min read

Why AI Pilots Stall Before Production

AI pilots stall before production for boring reasons: no owner, no definition of done, no data path, no kill switch. CISA 1 May 2026: start low-risk. NIST AI RMF: Govern, Map, Measure, Manage.

AI pilots stall before production because nobody named an owner, nobody wrote what done looks like, nobody mapped which records the agent may touch, and nobody practiced a way to turn it off. A fluent walkthrough is not a live workflow. On 1 May 2026, CISA and its Five Eyes partners told organizations to start with low-risk, non-sensitive tasks and to put agentic AI inside the security model they already use for people and vendors.

I run Kief Studio with Brian, from Shrewsbury, Massachusetts. When a founder walks me through a demo on a call, I am listening for those four missing pieces, not for how pretty the last paragraph sounded. NIST AI RMF 1.0, published 26 January 2023, is the voluntary US process: Govern, Map, Measure, and Manage. Overnight agents still have to survive a real ticket, which is 3am versus the demo. Watching the whole run, not each click, is sequence governance.

A magenta demo stage that does not connect to a production track, why AI pilots stall before production, Amelia S. Gagne
Start with a low-risk task, map what the agent can touch, measure whether it works, and know how you stop it. A slide deck does none of that.

The stall starts with a missing owner

You already know the meeting. Someone shares a screen. The answers come back fast. The sentences are clean. Ten minutes later the room is talking as if the thing is on the night shift. Then Tuesday arrives, a real ticket hits the queue, and nobody can say whose calendar includes this agent. That is the stall. It is not a model failure. It is an empty chair.

I will not recycle unsourced lines about ninety-five percent of pilots failing. MIT numbers and vendor surveys get quoted without the method, and a number you cannot open is not a plan. Use a process you can audit. NIST names four functions, and they are ordinary office work if you say them that way. Govern is who is accountable. Map is what exists and what the agent may touch. Measure is how you will know it worked. Manage is what you do when it does not.

Across this table, Govern is a person whose calendar includes this agent. If the Slack channel is everyone, there is no owner. Map is a list of tools and records the agent may read and write. If that list is whatever the demo used, you have not mapped. Measure is a number you wrote down before the wow moment. Manage is how you stop the thing on a Tuesday when the person who liked the screenshot is in another meeting.

A pilot that cannot name a person for Govern already stalled. A pilot that cannot list the tools in Map is a demo of a model, not of a system. CISA, NSA, and the allied centers on 1 May 2026 listed privilege creep, behavioral misalignment, and obscure event records as agentic risks. Those are stall conditions. If you cannot see what the agent did, you will not put it on the night shift, and you should not.

Five Eyes guidance for a small business is the five-move translation of that paper. Privilege creep, in the office, is the agent that started on FAQ drafts and now has the CRM password because someone pasted it to try one lookup. The lookup worked. The password stayed. That is how a low-risk job becomes a production risk without anyone deciding it.

Decision tree from pilot demo through owner, definition of done, data path and kill switch to production or stall, Amelia Gagne
Four gates. Fail any one and you keep the demo. Pass all four and you have a job, not a model brand.

Write done, the data path, and the kill switch before you scale

Done means the agent completes a named task on a named system, with an error rate under a number you wrote down, for a number of days, with a person who gets paged. The CEO liked the screenshot is applause. Applause is not Measure. If you cannot state the task, the system, and the number of days, you are still inventorying. Here is an example you can take back to the team. The task is draft a reply to the common shipping FAQ. The system is the help-center folder. The window is ten business days with fewer than two corrections per day from the owner. Write that on a sticky note. If you need a paragraph, the job is still too big.

The data path is which records the agent may read and which it may write. Data governance where to start is the prerequisite, not a later phase. Disconnected data makes a fluent wrong answer. Disconnected data is two spreadsheets that both claim to be last month's invoices. The agent will pick the easier one, and it will sound sure. CISA said do not grant unrestricted access to sensitive data. A pilot on the production CRM with a shared login has already skipped that line. You did not start small. You started where the customer records live.

The kill switch is how you disable the non-human identity without firing a human. A non-human identity is the agent's own login, the way a contractor has a badge. Bill Fisher and Ryan Galluzzo at NIST, on 27 August 2026, wrote the login version: unique credentials, no long-lived keys in a markdown file, and no impersonation of a person. If the only way to stop the agent is to rotate the founder's password, the pilot is not ready. You would not share your bank login with a contractor and call it onboarding. Do not share it with software either.

Practice the kill switch once while everyone is calm. Disable the agent identity. Confirm the night job did not run. Re-enable it on purpose. A switch nobody has flipped is a rumor you will not find at 3am. Write two sentences about who is on call if it misbehaves over the weekend. If both of you are the company, one of you is still the owner, and the other is the backup who can flip the switch.

The pretty demo, and why people believe it

The walkthrough is built to look finished. The last fluent paragraph lands, the invoice matches, and the room stands up feeling like the product is already in production. Looking good in a meeting is not the same as being ready to refund a customer's card. So start with work where a mistake is easy to fix. The vendor closes on a perfect match. The three errors that needed a human leave the room with the leftover coffee. Write the error count down before everyone stands up. If nobody wrote it, you measured applause.

That is why Govern has to be a person with a calendar, not a Slack emoji. Evaluating AI tools without getting sold is the vendor-facing sibling of this conversation. You can like a demo and still refuse to point it at payroll. Liking it is allowed. Skipping the four gates is how the pilot lives in a slide forever.

Microsoft's June 2026 MCP research showed agents that act, not only read. A pilot that adds MCP tools without pinning descriptions is expanding the stall. You cannot Measure a tool list that changes under you. MCP as a supply chain is the practical rule. Pin versions the way you pin a lockfile. Public lockfile checks live on kief.dev. If a tool description can change without anyone reading it, the agent can attach extra invoice data and every click will still look allowed.

A production checklist that is still small

You do not need a binder. You need eight lines a person can read on a call.

  1. A named owner on payroll holds the agent.
  2. The task is one written sentence.
  3. The success number is written before the wow moment.
  4. The agent has its own identity, not a borrowed human login.
  5. The tool list is an allowlist, and the versions are pinned.
  6. A human sits on pay, send, delete, and deploy.
  7. The logs name the agent, not a shared mailbox.
  8. Someone has practiced the off switch while calm.

That is Manage in the NIST sense, plus CISA's instruction to start low-risk. Low-risk, in the office, is drafting internal FAQs from pages you already published. High-risk is refunds, payroll, or anything that sends money or deletes records. CISA's paper is explicit: begin with non-sensitive tasks. Do not call it a pilot on the production CRM because the demo looked clean. If you need and also to describe the first job, cut the job until the sentence fits on one line.

It is also how LTFI treats a department. We run what we recommend, which means an owner exists. You do not install a binary. You own name, content, and data. Security architecture for the control plane is on briansgagne.com. The layer you keep when the model brand changes is own versus rent AI. A hired department still needs the eight lines above. Paying someone else does not skip Govern.

Measure something smaller than ROI theater

Teams stall on ROI because the demo never defined a unit. Pick one: tickets closed, invoices coded, FAQs drafted, or minutes to first response. Write the baseline for last month. Run the agent for two weeks on the low-risk task CISA described. Compare. If you cannot measure, you are still in Map. AI will save us time is not a unit. Time on which task, compared with which month, counted by whom, is a unit.

Moving the goalposts keeps the demo alive because nobody has to declare it finished or dead. A kill switch is also a permission to stop. That is governance. If two weeks of FAQ drafts need more corrections than last month's intern, you stop. You still learned. You did not fail AI. You measured. The intern had a named owner and a last day. The agent should too.

Two-person studios can put an agent in production on that low-risk task with a named owner and an off switch. That is the Five Eyes start. Payroll stays out of bounds. If you are two people, the owner is one of you, named, with a backup who can flip the switch. The company is not a name. We will watch it is not a calendar. Put the name on the login, put the job in one sentence, and leave the pretty demo in the conference room until those two exist on paper.

Related reading

Frequently Asked Questions

Why do AI pilots stall before production?

They stall when there is no owner, no definition of done, no data path, or no kill switch. CISA asked you to start on low-risk work. NIST RMF still wants Govern, Map, Measure, and Manage. A demo is none of those.

Is there an official failure-rate statistic?

Many percentages circulate without methods. Use CISA and NIST process gates instead of an unsourced ninety percent or ninety-five percent line unless you open the primary study.

Who should own a pilot on a two-person team?

One named person on payroll, plus a backup who can flip the off switch. The company is not an owner. Five Eyes still applies at that size.

What is a kill switch in practice?

Disable the agent's own identity so jobs stop without rotating a human password. Practice it once while calm. If the only stop is fire the intern, you do not have a switch.

What is a low-risk first task?

CISA asked for non-sensitive work inside your existing security model. Drafting internal FAQs from published pages is a start. Refunds, payroll, and production CRM writes are not.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe