<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AI Track &#8211; Vici Consulting</title>
	<atom:link href="https://www.consultvici.com/category/ai-track/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.consultvici.com</link>
	<description>Principal-led operating leadership in data, analytics, and AI</description>
	<lastBuildDate>Thu, 06 Aug 2026 21:34:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>
	<item>
		<title>AI Governance Should Not Be a Department of No</title>
		<link>https://www.consultvici.com/2026/07/26/ai-governance-should-not-be-a-department-of-no/</link>
					<comments>https://www.consultvici.com/2026/07/26/ai-governance-should-not-be-a-department-of-no/#respond</comments>
		
		<dc:creator><![CDATA[Judesther Marc]]></dc:creator>
		<pubDate>Sun, 26 Jul 2026 09:00:00 +0000</pubDate>
				<category><![CDATA[AI Track]]></category>
		<guid isPermaLink="false">https://www.consultvici.com/?p=118</guid>

					<description><![CDATA[The flagship bank AI rulebook of 2026 says generative and agentic AI are "not within the scope." That is not a loophole. It is the assignment. For regulated industries, this is the uncomfortable reality of AI governance right now: the safe lane for GenAI does ]]></description>
										<content:encoded><![CDATA[<div class="wp-block-group" style="padding-top:24px;padding-bottom:24px">
<div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p class="wp-block-paragraph" style="font-size:13px;letter-spacing:0.08em;text-transform:uppercase">VICI Insights • AI Track • Week 08</p>
<h1 class="wp-block-heading">AI Governance Should Not Be a Department of No</h1>
<p class="wp-block-paragraph">The flagship bank AI rulebook of 2026 says generative and agentic AI are &quot;not within the scope.&quot;</p>
<p class="wp-block-paragraph">That is not a loophole. It is the assignment.</p>
<p class="wp-block-paragraph">For regulated industries, this is the uncomfortable reality of AI governance right now: the safe lane for GenAI does not fully exist on paper yet. SR 26-2 revised the model risk guidance, but explicitly carved out generative and agentic AI while still saying firms need appropriate governance and controls.</p>
<p class="wp-block-paragraph">In plain English: the regulator told leaders, &quot;You still own the risk,&quot; but did not hand them a complete answer key.</p>
<p class="wp-block-paragraph">That is why AI governance cannot become the Department of No.</p>
<p class="wp-block-paragraph">The companies that win here will not be the ones that say yes to everything. They also will not be the ones that send every use case into a committee maze until business teams give up and build shadow AI on the side.</p>
<p class="wp-block-paragraph">They will be the ones that make the safe lane visible.</p>
<p class="wp-block-paragraph">Three moves matter:</p>
<ul class="wp-block-list">
<li>Publish the pre-approved lane.</li>
</ul>
<p class="wp-block-paragraph">Name the sanctioned tools, data types, workflows, and use patterns employees can use today without asking for a one-off ruling. A default &quot;yes, within these rails&quot; beats a vague &quot;come to governance first.&quot;</p>
<ul class="wp-block-list">
<li>Tier by risk and route accordingly.</li>
</ul>
<p class="wp-block-paragraph">A low-risk internal summarization workflow should not face the same approval burden as a model influencing credit, pricing, fraud, or customer treatment. Light use cases need a light logged lane. High-materiality decisions need ownership, effective challenge, controls, and an approval path.</p>
<p class="wp-block-paragraph">Governance is a router, not one gate at one height.</p>
<ul class="wp-block-list">
<li>Measure both adoption and control.</li>
</ul>
<p class="wp-block-paragraph">Track sanctioned-lane usage, shadow usage, incident rate, cost, quality, and business impact. If adoption is low, the lane is probably too narrow or too slow. If incidents are high, the tier is too loose. Tune the system. Do not freeze it.</p>
<p class="wp-block-paragraph">This is not just compliance theater. Grant Thornton&#x27;s 2026 AI Impact Survey found that 78% of executives were not strongly confident they could pass an independent AI governance audit in 90 days, while only 7% of pilot-stage firms were very confident compared with 74% of fully integrated firms.</p>
<p class="wp-block-paragraph">The governed firms are not necessarily the slow ones. They are often the ones with enough confidence to scale.</p>
<p class="wp-block-paragraph">MIT Sloan has called out the real failure mode: governance can become a bottleneck. The answer is not no governance. It is minimum viable governance: proportional, embedded in the workflow, and designed to enable the right work faster.</p>
<p class="wp-block-paragraph">Where is this showing up for you?</p>
<p class="wp-block-paragraph">Is your AI governance opening safe lanes, or has it become the Department of No?</p>
<p class="wp-block-paragraph">And where are you feeling it most: experimentation, governance, data readiness, or scaling?</p>
<div class="wp-block-group" style="border-top:1px solid #d9d4c8;margin-top:28px;padding-top:18px">
<p class="wp-block-paragraph"><strong>Prefer LinkedIn?</strong> <a href="https://www.linkedin.com/feed/update/urn:li:share:7488941837316087809" rel="noopener" target="_blank">Join the discussion on the original post</a>.</p>
</div>
</div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://www.consultvici.com/2026/07/26/ai-governance-should-not-be-a-department-of-no/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Banking Taught Me About AI Risk</title>
		<link>https://www.consultvici.com/2026/07/19/what-banking-taught-me-about-ai-risk/</link>
		
		<dc:creator><![CDATA[Judesther Marc]]></dc:creator>
		<pubDate>Sun, 19 Jul 2026 09:00:00 +0000</pubDate>
				<category><![CDATA[AI Track]]></category>
		<guid isPermaLink="false">https://www.consultvici.com/?p=117</guid>

					<description><![CDATA[The model-risk rulebook I trained on in banking was just rewritten in 2026. And it deliberately leaves out the AI everyone is actually deploying. That is the part most leaders are missing. Banking has spent years building discipline around model risk: validati]]></description>
										<content:encoded><![CDATA[<div class="wp-block-group" style="padding-top:24px;padding-bottom:24px">
<div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p class="wp-block-paragraph" style="font-size:13px;letter-spacing:0.08em;text-transform:uppercase">VICI Insights • AI Track • Week 07</p>
<h1 class="wp-block-heading">What Banking Taught Me About AI Risk</h1>
<p class="wp-block-paragraph">The model-risk rulebook I trained on in banking was just rewritten in 2026.</p>
<p class="wp-block-paragraph">And it deliberately leaves out the AI everyone is actually deploying.</p>
<p class="wp-block-paragraph">That is the part most leaders are missing.</p>
<p class="wp-block-paragraph">Banking has spent years building discipline around model risk: validation, effective challenge, governance, documentation, monitoring. Those instincts matter. But the 2026 US model-risk guidance from the Federal Reserve and OCC treats generative and agentic AI as novel enough to sit outside the revised framework, while the promised interagency AI RFI still has not landed.</p>
<p class="wp-block-paragraph">So the useful banking lesson is not, &quot;we already have the rules.&quot;</p>
<p class="wp-block-paragraph">It is: build defensible controls in the gap before the rules arrive.</p>
<p class="wp-block-paragraph">That is especially relevant right now. India&#x27;s banking regulator has a 2026 draft model-risk framework in live consultation through July 24 that explicitly pulls AI and machine-learning models into governance and calls for human oversight, override, suspension, and deactivation mechanisms. In plain language: an off-switch.</p>
<p class="wp-block-paragraph">That is not fear of AI.</p>
<p class="wp-block-paragraph">That is risk discipline.</p>
<p class="wp-block-paragraph">Here is the operating model I would use with any regulated AI program:</p>
<ul class="wp-block-list">
<li>Tier the decision, not the tool.</li>
</ul>
<p class="wp-block-paragraph">Start with the business decision and its blast radius. A customer-facing credit decision is not in the same risk tier as an internal meeting-notes copilot. Governance should scale with impact, not with how impressive the demo looks. The CFPB has already made clear that &quot;the algorithm is too complex&quot; is not a defense when a consumer is owed an adverse-action explanation.</p>
<ul class="wp-block-list">
<li>Name an owner and an off-switch.</li>
</ul>
<p class="wp-block-paragraph">Every model or agent needs a human owner, an approval path, and a way to override, suspend, or deactivate it before launch. Accountability cannot be delegated to software. If an AI agent can take an action, someone has to own the authority behind that action.</p>
<ul class="wp-block-list">
<li>Validate with effective challenge, then monitor.</li>
</ul>
<p class="wp-block-paragraph">The banking concept that transfers cleanly is effective challenge: independent review with enough authority to question the output, not simply admire the system. For GenAI and agentic workflows, that also means post-launch monitoring for drift, over-reliance, automation bias, and exception handling.</p>
<p class="wp-block-paragraph">This is where banking&#x27;s old discipline becomes useful again. Not because it solves AI risk by default, but because it teaches leaders to ask the right questions before scale:</p>
<p class="wp-block-paragraph">What decision is this AI influencing? Who is accountable when it is wrong? How do we stop it? Who can challenge it? What do we monitor after launch?</p>
<p class="wp-block-paragraph">The winners in regulated AI will not be the companies that choose speed over control. They will be the ones that learn how to make control part of speed.</p>
<p class="wp-block-paragraph">Where are you seeing this show up in your organization: experimentation, governance, data readiness, or scaling?</p>
<div class="wp-block-group" style="border-top:1px solid #d9d4c8;margin-top:28px;padding-top:18px">
<p class="wp-block-paragraph"><strong>Prefer LinkedIn?</strong> <a href="https://www.linkedin.com/feed/update/urn:li:share:7488579172152283137" rel="noopener" target="_blank">Join the discussion on the original post</a>.</p>
</div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Difference Between Consumer AI and Enterprise AI</title>
		<link>https://www.consultvici.com/2026/07/05/the-difference-between-consumer-ai-and-enterprise-ai/</link>
		
		<dc:creator><![CDATA[Judesther Marc]]></dc:creator>
		<pubDate>Sun, 05 Jul 2026 09:00:00 +0000</pubDate>
				<category><![CDATA[AI Track]]></category>
		<guid isPermaLink="false">https://www.consultvici.com/?p=116</guid>

					<description><![CDATA[Your enterprise AI strategy is competing with the ChatGPT app already on your employees' phones — and losing. 66% of professionals use AI at work that policy doesn't allow. The consumer/enterprise divide didn't disappear. It moved. For regulated-industry leade]]></description>
										<content:encoded><![CDATA[<div class="wp-block-group" style="padding-top:24px;padding-bottom:24px">
<div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p class="wp-block-paragraph" style="font-size:13px;letter-spacing:0.08em;text-transform:uppercase">VICI Insights • AI Track • Week 05</p>
<h1 class="wp-block-heading">The Difference Between Consumer AI and Enterprise AI</h1>
<p class="wp-block-paragraph">Your enterprise AI strategy is competing with the ChatGPT app already on your employees&#x27; phones — and losing. 66% of professionals use AI at work that policy doesn&#x27;t allow. The consumer/enterprise divide didn&#x27;t disappear. It moved.</p>
<p class="wp-block-paragraph">For regulated-industry leaders, CIOs, and CDOs, this isn&#x27;t a compliance footnote. It&#x27;s the operating reality of 2026.</p>
<p class="wp-block-paragraph">Here&#x27;s the defensible line that actually matters: it&#x27;s not the model. Most enterprise AI tools run the same weights as the consumer apps. The difference is the blast radius. A hallucinated restaurant recommendation and a hallucinated credit decision can come from the same LLM. Only one ends up in a regulatory finding.</p>
<p class="wp-block-paragraph">That means enterprise AI in 2026 is not a product category — it&#x27;s a use category. Three rules to govern it:</p>
<p class="wp-block-paragraph"><strong>1. Same model, different blast radius.</strong> Draw the enterprise line where a wrong answer creates regulatory, financial, or customer harm, not where the vendor logo changes. If your test is &quot;which logo is on the login screen,&quot; you&#x27;re already behind the employees who pasted customer data into the free version last Tuesday.</p>
<p class="wp-block-paragraph"><strong>2. Govern the use, not the tool.</strong> Data boundaries, query-time permissions, logging, named ownership, and measurement wrapped around whatever tool people actually use. The Federal Reserve&#x27;s SR 26-2 explicitly excluded GenAI and agentic AI from model-risk scope — it&#x27;s non-enforceable guidance, and the promised interagency RFI still hasn&#x27;t dropped as of early July. NIST&#x27;s AI RMF 1.0 is itself being revised right now. So there is no examiner-issued rulebook for the highest-velocity technology in your building. The wrapper is self-built by design, not bought as a SKU.</p>
<p class="wp-block-paragraph"><strong>3. Make the sanctioned path beat the shadow path.</strong> 89% of workers met their AI tool at home first. 77% say company AI restrictions limit their professional growth; 75% would look for a new job offering better AI skills development. If the approved tool is worse than the one in their pocket, your governance is a suggestion. Adoption quality is a design requirement of enterprise AI, not a change-management afterthought.</p>
<p class="wp-block-paragraph">The Economist in the room will say this governance posture is a retention problem. I agree — and that&#x27;s why the third rule is non-negotiable. Prohibition isn&#x27;t governance; it&#x27;s cost-shifting from the risk ledger to the talent ledger. The 66% policy-violation figure proves bans don&#x27;t stop usage; they just remove visibility. Build the approved path so your people don&#x27;t need the shadow one.</p>
<p class="wp-block-paragraph">The Skeptic will say enterprise AI is just consumer AI plus markup. I concede the model is often identical. You&#x27;re not paying for the weights; you&#x27;re paying for the operating model: who can see what data, what gets logged, who&#x27;s accountable when the answer is wrong, and whether the output survives an audit. If a vendor can&#x27;t articulate what&#x27;s in that wrapper, walk away.</p>
<p class="wp-block-paragraph">The transformation for regulated industries: stop classifying AI by product and start classifying it by consequence. The wall isn&#x27;t between two products. It&#x27;s between governed and ungoverned use of the same product — and right now, that wall is built by you, not shipped by a vendor.</p>
<p class="wp-block-paragraph">Where are you seeing this show up in your organization — experimentation, governance, data readiness, or scaling? If you&#x27;re thinking through AI governance, workflow design, adoption, or production-readiness in your organisation, feel free to reach out to me on LinkedIn with questions. You can also find me at www.consultvici.com.</p>
<p class="wp-block-paragraph"><strong>Verification flags:</strong></p>
<ul class="wp-block-list">
<li>66% policy-violating AI use, 88% shared work info, 34% customer data, 72% out-skill IT, 89% personal-first, 77% + 75% retention figures — PagerDuty Shadow AI Survey, Jun 11, 2026, Wakefield Research, n=1,250, companies ≥$500M revenue, US/UK/AU/JP. (⚠ ~3.5 weeks old at draft time, verified live Jul 5.)</li>
<li>SR 26-2 GenAI/agentic exclusion, non-enforceable guidance, RFI &quot;near future&quot; — verbatim-checked live from Federal Reserve SR2602a1.pdf and OCC Bulletin 2026-13, Apr 17, 2026.</li>
<li>RFI not yet issued as of Jul 5, 2026 — verified by absence in Federal Register + agency newsrooms via search.</li>
<li>NIST AI RMF 1.0 under revision + Apr 2026 Critical Infrastructure profile concept note — live-fetched from nist.gov/itl/ai-risk-management-framework, modified Jun 10, 2026.</li>
<li>Verizon DBIR 4× shadow AI detections / 45% regular users — search-index/secondary coverage (TechTimes, Jun 15, 2026), attributed as directional, not hard-quoted.</li>
<li>OpenAI 900M weekly / 92% Fortune 500 / ~9M business seats — search-index tier, directional, attributed to OpenAI/2026 trackers, not hard-quoted.</li>
</ul>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RAG Is Not a Feature. It Is an Operating Model.</title>
		<link>https://www.consultvici.com/2026/06/28/rag-is-not-a-feature-it-is-an-operating-model/</link>
		
		<dc:creator><![CDATA[Judesther Marc]]></dc:creator>
		<pubDate>Sun, 28 Jun 2026 09:00:00 +0000</pubDate>
				<category><![CDATA[AI Track]]></category>
		<guid isPermaLink="false">https://www.consultvici.com/?p=115</guid>

					<description><![CDATA[Chosen hook: Option 2 — "The teams whose RAG broke in 2026…" The teams whose RAG broke in 2026 didn't have a worse retriever. They had no owner for permissions, freshness, evaluation, or audit. RAG isn't a feature you ship. It's an operating model you run. I'v]]></description>
										<content:encoded><![CDATA[<div class="wp-block-group" style="padding-top:24px;padding-bottom:24px">
<div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p class="wp-block-paragraph" style="font-size:13px;letter-spacing:0.08em;text-transform:uppercase">VICI Insights • AI Track • Week 04</p>
<h1 class="wp-block-heading">RAG Is Not a Feature. It Is an Operating Model.</h1>
<p class="wp-block-paragraph"><strong>Chosen hook:</strong> Option 2 — &quot;The teams whose RAG broke in 2026…&quot;</p>
<p class="wp-block-paragraph">The teams whose RAG broke in 2026 didn&#x27;t have a worse retriever. They had no owner for permissions, freshness, evaluation, or audit.</p>
<p class="wp-block-paragraph">RAG isn&#x27;t a feature you ship. It&#x27;s an operating model you run.</p>
<p class="wp-block-paragraph">I&#x27;ve heard the counterargument all year: &quot;RAG is dead. Long-context windows and agentic file-search killed it.&quot; And here&#x27;s what I think: they&#x27;re right about the feature. Naive retrieval — vector similarity as a bolt-on — is being abstracted away. Good.</p>
<p class="wp-block-paragraph">But that argument quietly proves my point. Every team that replaced their RAG pipeline with agentic retrieval or a long-context approach still had to rebuild permissions, freshness enforcement, evaluation, and audit. They didn&#x27;t delete the operating model. They relocated it.</p>
<p class="wp-block-paragraph">The architecture is churning. The accountabilities aren&#x27;t.</p>
<p class="wp-block-paragraph">Here&#x27;s how I frame it across six concerns — in the order production actually breaks them:</p>
<p class="wp-block-paragraph"><strong>1. Retrieval is a governed pipeline, not plumbing.</strong> The document-level permission that exists in your source system does not automatically travel with the chunk at query time. Research on enterprise-retrieval pipelines finds that ungated retrieval leaks cross-tenant data in roughly 98–100% of probes when authorization checks are absent. That&#x27;s not an edge case — that&#x27;s the default state if you stand up a retrieval layer without explicit permission enforcement. The first design question is not &quot;which vector DB?&quot; It&#x27;s &quot;does each retrieved document carry its source-system ACL all the way to the query?&quot;</p>
<p class="wp-block-paragraph"><strong>2. Evaluation and observability are your QA function — and your compliance surface.</strong> If you can&#x27;t measure answer quality, retrieval precision, and drift, you can&#x27;t manage them. OWASP&#x27;s 2025 Top 10 for LLM Applications moved Sensitive Information Disclosure to #2 and added Vector &amp; Embedding Weaknesses as a new category — both are retrieval-layer failures, not model failures. More pressing for regulated industries: EU AI Act Article 12 logging for high-risk AI systems becomes binding on August 2, 2026 — automatic logging of inputs, retrieved context, and outputs, with penalties up to €15M or 3% of global turnover. That logging requirement is not a model concern. It&#x27;s a retrieval-layer operating model concern.</p>
<p class="wp-block-paragraph"><strong>3. Assign ownership and a risk tier before you scale.</strong> Name who owns the corpus. Name who owns the permission model. Name who owns the freshness job. Tier the use case. Put it on an approval path. Architecture beneath this layer — vector, graph, agentic, long-context — is swappable. Ownership is not.</p>
<p class="wp-block-paragraph">For the leaders running financial services, insurance, or any high-accountability environment: approximately 40–60% of enterprise RAG implementations never reach production. The cited failure isn&#x27;t the retriever. It&#x27;s the absence of document ownership, access controls at query time, PII handling, and freshness enforcement. That&#x27;s an operating-model gap, not a technology gap.</p>
<p class="wp-block-paragraph">The Monday-morning test: take your live RAG use case and answer three questions. Does each retrieved document still carry its permission at query time? Who owns freshness? Where are answers logged for audit? If you can&#x27;t answer all three, you have a demo — not an operating model.</p>
<p class="wp-block-paragraph">The &quot;RAG is dead&quot; crowd is killing the feature and rebuilding the operating model at the same time. The teams that already built the operating model are the ones watching calmly.</p>
<p class="wp-block-paragraph">Where are you seeing this show up in your organization — experimentation, governance, data readiness, or scaling?</p>
<p class="wp-block-paragraph">If you&#x27;re working through AI governance, retrieval architecture, or production-readiness in financial services, fintech, insurance, or another high-accountability environment, feel free to reach out to me on LinkedIn. You can also visit www.consultvici.com.</p>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The AI Pilot Trap</title>
		<link>https://www.consultvici.com/2026/06/22/the-ai-pilot-trap/</link>
		
		<dc:creator><![CDATA[Judesther Marc]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 09:00:00 +0000</pubDate>
				<category><![CDATA[AI Track]]></category>
		<guid isPermaLink="false">https://www.consultvici.com/?p=114</guid>

					<description><![CDATA[88% of enterprise AI pilots never reach production. The other 12% didn't have better models — they refused to treat production like a bigger demo. The median AI pilot is quietly shut down 14 months after it was approved. I've watched this happen inside large o]]></description>
										<content:encoded><![CDATA[<div class="wp-block-group" style="padding-top:24px;padding-bottom:24px">
<div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p class="wp-block-paragraph" style="font-size:13px;letter-spacing:0.08em;text-transform:uppercase">VICI Insights • AI Track • Week 03</p>
<h1 class="wp-block-heading">The AI Pilot Trap</h1>
<p class="wp-block-paragraph"><strong>88% of enterprise AI pilots never reach production. The other 12% didn&#x27;t have better models — they refused to treat production like a bigger demo.</strong></p>
<p class="wp-block-paragraph">The median AI pilot is quietly shut down 14 months after it was approved. I&#x27;ve watched this happen inside large organizations and I&#x27;ve watched it happen from the outside as a consultant. Almost every time, the autopsy says the same thing: no measurable business objective from day one, data that wasn&#x27;t ready, no one who actually owned the outcome.</p>
<p class="wp-block-paragraph">That&#x27;s not a technology failure. It&#x27;s an operating-model failure.</p>
<p class="wp-block-paragraph">42% of companies abandoned at least one AI initiative in 2025. Average sunk cost per abandoned initiative: ~$7.2M. Gartner projects 60% of AI projects lacking production-ready infrastructure will be abandoned through 2026. None of that is happening because the model underperformed a benchmark. It&#x27;s happening because the pilot was treated like a science fair, not a production system.</p>
<p class="wp-block-paragraph">Here&#x27;s the trap in plain language:</p>
<p class="wp-block-paragraph"><strong>1. Start from a workflow with an owner and a number — not a demo looking for applause.</strong> If no one owns the metric the AI is supposed to move, you don&#x27;t have a pilot. You have a conversation piece. Before anything goes to an executive sponsor, there should be one person whose name is next to one KPI.</p>
<p class="wp-block-paragraph"><strong>2. &quot;Production&quot; must mean governed — not just more users.</strong> Only 21% of organizations have a mature governance model for agentic AI. SR 26-2 doesn&#x27;t automatically bring GenAI under model-risk scope — that gap is yours to close. Graduating a pilot to production means it graduates onto a risk tier, a control framework, and an approval path. More users without that isn&#x27;t a launch; it&#x27;s an ungoverned expansion.</p>
<p class="wp-block-paragraph"><strong>3. Model the cost-to-scale before you scale.</strong> Cost overruns average ~380% vs. pilot projections at production scale. That&#x27;s not a surprise that happens at the end — it&#x27;s a measurement failure that starts in the middle. The four measures that survive finance review: quality, adoption, cost, and business impact. If the unit economics don&#x27;t hold at scale, kill it fast and redeploy the budget.</p>
<p class="wp-block-paragraph">The organizations that are winning right now didn&#x27;t find a better AI vendor. They redesigned the workflow around what the system can actually do, then measured it. Deloitte&#x27;s 2026 research shows agentic AI averaging ~171% ROI where enterprises do that work. The same research shows most organizations haven&#x27;t.</p>
<p class="wp-block-paragraph">The 88% failure rate is real. So is the 171% ROI. They&#x27;re not contradicting each other — they&#x27;re describing two different operating approaches to the same technology.</p>
<p class="wp-block-paragraph">The pilot mindset is the trap. The question is whether your organization is building infrastructure for production or infrastructure for more demos.</p>
<p class="wp-block-paragraph"><strong>Where are you seeing this show up in your organization — experimentation, governance, data readiness, or scaling?</strong></p>
<p class="wp-block-paragraph">If you&#x27;re thinking through AI governance, workflow design, adoption, or production-readiness in your organization, feel free to reach out to me on LinkedIn with questions. You can also find me at <a href="http://www.consultvici.com">www.consultvici.com</a>.</p>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why Regulated Industries Can&#8217;t Move Fast and Break Things With AI</title>
		<link>https://www.consultvici.com/2026/06/15/why-regulated-industries-cant-move-fast-and-break-things-with-ai/</link>
		
		<dc:creator><![CDATA[Judesther Marc]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 09:00:00 +0000</pubDate>
				<category><![CDATA[AI Track]]></category>
		<guid isPermaLink="false">https://www.consultvici.com/?p=112</guid>

					<description><![CDATA[In April, the Fed issued its flagship 2026 model-risk guidance — SR 26-2 — and deliberately left generative AI and agentic AI out of scope. "Novel and rapidly evolving," the agencies said. A Request for Information is coming. That means the most consequential ]]></description>
										<content:encoded><![CDATA[<div class="wp-block-group" style="padding-top:24px;padding-bottom:24px">
<div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p class="wp-block-paragraph" style="font-size:13px;letter-spacing:0.08em;text-transform:uppercase">VICI Insights • AI Track • Week 02</p>
<h1 class="wp-block-heading">Why Regulated Industries Can&#x27;t Move Fast and Break Things With AI</h1>
<p class="wp-block-paragraph">In April, the Fed issued its flagship 2026 model-risk guidance — SR 26-2 — and deliberately left generative AI and agentic AI out of scope.</p>
<p class="wp-block-paragraph">&quot;Novel and rapidly evolving,&quot; the agencies said. A Request for Information is coming.</p>
<p class="wp-block-paragraph">That means the most consequential AI systems banks deployed in the last two years — the ones generating content, summarizing documents, powering chatbots, and starting to execute decisions — are operating in a gap. No formal regulatory template. No SR 11-7 equivalent. Leadership owns the bridge until the rules arrive.</p>
<p class="wp-block-paragraph">That&#x27;s what &quot;regulated industries can&#x27;t move fast and break things with AI&quot; actually means in 2026. It&#x27;s not that regulators have hemmed you in. It&#x27;s that they haven&#x27;t yet — and you&#x27;re accountable anyway.</p>
<p class="wp-block-paragraph"><strong>The cliché is wrong. The constraint isn&#x27;t slowness — it&#x27;s survivable speed.</strong></p>
<p class="wp-block-paragraph">In banking, insurance, fintech, and payments, a bad AI answer isn&#x27;t an embarrassing hallucination on a demo. It&#x27;s a credit decision with a disparate-impact exposure. It&#x27;s a claims denial a regulator will reconstruct. It&#x27;s a customer interaction a class-action attorney will subpoena.</p>
<p class="wp-block-paragraph">The question isn&#x27;t whether you can move fast. It&#x27;s whether the speed survives an exam, an audit, or a failure.</p>
<p class="wp-block-paragraph">Right now, it largely doesn&#x27;t. A Wolters Kluwer survey of 230 U.S. banking professionals found nearly three in four couldn&#x27;t confidently operate a kill switch on a malfunctioning AI model or report a failure to supervisors. Examiners from the Fed, OCC, and FDIC are pressing on exactly these capabilities in every exam cycle — even as their April guidance declines to define them.</p>
<p class="wp-block-paragraph"><strong>The three things a regulated AI program needs that most don&#x27;t have:</strong></p>
<p class="wp-block-paragraph"><strong>1. Make it auditable before you make it fast.</strong> Every regulated AI decision needs a traceable owner, input, and rationale. Not because a regulator will definitely look — because when they do, and they will, the decision needs to be reconstructable. Speed is fine. Speed without a paper trail is a liability.</p>
<p class="wp-block-paragraph"><strong>2. Build the bridge framework where regulators left a gap.</strong> SR 26-2 excludes GenAI and agentic AI. That&#x27;s not a green light — it&#x27;s a governance gap you now own. The working framework is NIST AI RMF + EU AI Act (high-risk FSI use cases, including credit scoring, carry penalties up to €15M or 3% of global turnover; the August 2, 2026 deadline is active) + applicable state law. Build the lane now. Retrofitting it after an incident costs orders of magnitude more.</p>
<p class="wp-block-paragraph"><strong>3. Prove you can stop it.</strong> Kill switch. Failure reporting path. Vendor-chain and data-boundary documentation. These aren&#x27;t theoretical — examiners are asking in active cycles. Nearly 3 in 4 banks can&#x27;t answer confidently. That&#x27;s the gap.</p>
<p class="wp-block-paragraph">The institutions that build these controls first don&#x27;t move slower. They move faster afterward, because they&#x27;re not re-litigating every model with risk and compliance each time. The audit trail is the speed advantage.</p>
<p class="wp-block-paragraph">&quot;Move fast and break things&quot; was built for a world where the things you break are yours to fix. In regulated AI, the things you break belong to your customers, your regulators, and your charter.</p>
<p class="wp-block-paragraph">If you&#x27;re working through AI governance, workflow design, or production-readiness in financial services, fintech, or insurance, feel free to reach out on LinkedIn or visit www.consultvici.com.</p>
<p class="wp-block-paragraph">Where are you seeing this show up in your organization — experimentation, governance, data readiness, or scaling?</p>
<h2 class="wp-block-heading">#EnterpriseAI #AIGovernance #FinancialServices #RegulatedAI #AIStrategy #RiskManagement #AILeadership</h2>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI That Survives the Enterprise</title>
		<link>https://www.consultvici.com/2026/06/09/ai-that-survives-the-enterprise/</link>
		
		<dc:creator><![CDATA[Judesther Marc]]></dc:creator>
		<pubDate>Tue, 09 Jun 2026 03:41:28 +0000</pubDate>
				<category><![CDATA[AI Track]]></category>
		<guid isPermaLink="false">https://www.consultvici.com/?p=25</guid>

					<description><![CDATA[AI Strategy • Governance • Enterprise Execution AI That Survives the Enterprise Enterprise AI is not in a clean value-realization phase. It is in a value-separation phase. A small minority of organizations are turning AI into real operating capability. A much larger group is still stuck in demos, scattered pilots, and unsanctioned experimentation that never&#8230; <a class="more-link" href="https://www.consultvici.com/2026/06/09/ai-that-survives-the-enterprise/">Continue reading <span class="screen-reader-text">AI That Survives the Enterprise</span></a>]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-group" style="padding-top:24px;padding-bottom:24px"><div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p class="wp-block-paragraph" style="font-size:13px;letter-spacing:0.08em;text-transform:uppercase">AI Strategy • Governance • Enterprise Execution</p>



<h1 class="wp-block-heading">AI That Survives the Enterprise</h1>



<p class="has-large-font-size wp-block-paragraph">Enterprise AI is not in a clean value-realization phase. It is in a value-separation phase.</p>



<p class="wp-block-paragraph">A small minority of organizations are turning AI into real operating capability. A much larger group is still stuck in demos, scattered pilots, and unsanctioned experimentation that never survives contact with production.</p>



<p class="wp-block-paragraph">The market data is increasingly hard to ignore. MIT research found that roughly <strong>95% of enterprise generative AI pilots showed no measurable P&amp;L impact</strong>, and the core problem was not model quality. It was the integration and organizational learning gap. Writer’s 2026 enterprise AI research points in the same direction: only about <strong>29% of enterprises report significant ROI from generative AI</strong>, despite substantial ongoing investment.</p>



<h2 class="wp-block-heading">The wrong lesson from failed pilots</h2>



<p class="wp-block-paragraph">The skeptical response is predictable: if 95% of pilots fail and fewer than a third of enterprises report meaningful ROI, maybe enterprise AI is still mostly hype.</p>



<p class="wp-block-paragraph">That is the wrong conclusion.</p>



<p class="wp-block-paragraph">If the failure pattern were mainly about weak models, the conversation would be different. But the stronger conclusion is that most enterprises still have an operating-model problem. They know how to run pilots. They do not yet consistently know how to connect AI to workflow ownership, governed data, adoption, measurement, escalation, and accountability.</p>



<p class="wp-block-paragraph">That is what I mean by AI that survives the enterprise. Not the model that looks strongest in a demo. The capability that survives production reality.</p>



<h2 class="wp-block-heading">Three conditions for enterprise survival</h2>



<h3 class="wp-block-heading">1. Tie AI to a workflow with a named owner</h3>



<p class="wp-block-paragraph">Not a sandbox. Not a generic use-case list. Not a slide about transformation. A real workflow, a real owner, and a real decision or outcome that matters to the business.</p>



<p class="wp-block-paragraph">If nobody owns the workflow, nobody really owns the result. At that point, the organization does not have a capability. It has a demo that stayed alive longer than expected.</p>



<h3 class="wp-block-heading">2. Put it on a risk tier with a control and approval path</h3>



<p class="wp-block-paragraph">This matters in every industry, but the point becomes sharper in financial services, insurance, and other high-accountability environments.</p>



<p class="wp-block-paragraph">One of the most important signals in 2026 is that SR 26-2, the Federal Reserve’s updated model-risk guidance, explicitly excludes generative and agentic AI from scope. That exclusion is not a technical footnote. It is a governance gap.</p>



<p class="wp-block-paragraph">In practical terms, leaders cannot pretend legacy model-risk frameworks fully solve the GenAI problem. They need a bridge approach now: clear internal ownership, risk-tiering, human review, approval paths, and a control structure that reflects the actual use case rather than the comfort of old categories.</p>



<h3 class="wp-block-heading">3. Measure value, adoption, and cost</h3>



<p class="wp-block-paragraph">This is where many pilots die quietly. If a team cannot show whether the workflow improved, whether users actually adopted the capability, and whether the economics hold up, the business case is not established.</p>



<p class="wp-block-paragraph">Cost is not a side issue. It is part of the test. Many failed pilots did not collapse because the output was technically impossible. They collapsed because the business case never became durable enough to survive scrutiny.</p>



<h2 class="wp-block-heading">The shadow AI problem is already here</h2>



<p class="wp-block-paragraph">Another data point should force urgency into the conversation: Writer reports that about <strong>67% of executives believe their company has already had a data breach tied to unapproved shadow AI tools</strong>.</p>



<p class="wp-block-paragraph">That should end the illusion that inaction is the safe choice.</p>



<p class="wp-block-paragraph">People are already using AI. The leadership question is whether they are using it inside a sanctioned lane tied to the business, or outside one. Survival depends not only on model capability, but on whether the organization creates a governed path before employees create their own unofficial one.</p>



<h2 class="wp-block-heading">Architecture will keep changing. Accountability will not.</h2>



<p class="wp-block-paragraph">Some will argue that the framework above is too generic for 2026. The real conversation, they will say, is agentic workflows, context engineering, long context, retrieval design, and evaluation systems.</p>



<p class="wp-block-paragraph">Those things matter. But they sit below the durable layer, not above it.</p>



<p class="wp-block-paragraph">Architectures will keep changing. Enterprises will move from naive retrieval to agentic retrieval, from static prompt patterns to more sophisticated evaluation and oversight methods. But the core questions remain stubbornly consistent: Who owns the workflow? What is the risk tier? What is the control path? What metric is supposed to move? What does it cost? What happens when the system is wrong?</p>



<p class="wp-block-paragraph">Those are the questions that survive every architecture cycle.</p>



<h2 class="wp-block-heading">What leaders should do now</h2>



<p class="wp-block-paragraph">If I were pressure-testing AI readiness inside an organization this week, I would start with one use case that is already active somewhere in the business and ask four questions:</p>



<ol class="wp-block-list"><li>Who owns the workflow?</li><li>What risk tier does it sit in?</li><li>What metric is it supposed to move?</li><li>What does it cost to run, maintain, and govern?</li></ol>



<p class="wp-block-paragraph">If the answers are vague, the organization does not yet have a production-ready capability.</p>



<h2 class="wp-block-heading">Bottom line</h2>



<p class="wp-block-paragraph">The organizations that win with AI will not necessarily be the ones with the flashiest demos or the noisiest architecture conversations. They will be the ones that connect AI to workflow ownership, risk controls, adoption, measurable value, and cost discipline.</p>



<p class="wp-block-paragraph">That is what it means for AI to survive the enterprise.</p>



<p class="wp-block-paragraph"><strong>Question:</strong> Where is AI actually surviving in your organization — tied to a workflow and a metric, or still a demo looking for an owner?</p>
</div></div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
