Key Takeaways
- MIT's 2025 study of enterprise AI found that only around 5% of pilots were producing measurable financial return, and linked the gap to organisational approach rather than model quality or regulation.
- McKinsey's November 2025 survey found only around 6% of organisations were capturing material EBIT impact from AI, and that high performers were substantially more likely to have fundamentally redesigned their workflows.
- NIST places documented roles, responsibilities and lines of communication for AI risk under Govern 2.1, within a governance function it designs to be cross-cutting and infused throughout mapping, measuring and managing.
- ISO/IEC 42001 was deliberately built on the same clause structure as ISO 9001, 14001 and 45001, so AI governance can extend an existing management system rather than duplicate one.
- More than a decade after its publication, IOGP Report 510 continues to provide a recognised framework for operational governance and risk management within the oil and gas industry. As organisations adopt AI-enabled technologies, the framework offers a mature and proven foundation for integrating AI governance into existing management systems, avoiding the complexity and duplication of establishing standalone governance structures.
- The EU AI Act's high-risk deadline was reported as adopted on 29 June 2026, moving from 2 August 2026 to 2 December 2027 for stand-alone systems. Transparency obligations remain on the original schedule, bar a narrow watermarking exception for systems already deployed.
Energy, Minerals and Resources (EMR) sits at the back of the enterprise AI adoption curve, not the front. The evidence below scores the sector at or near zero for structural disruption, and that is precisely why the governance question is worth answering now. Every sector ahead of EMR had the operating model conversation after deployment, when the gaps were already load-bearing. EMR can have it before. Vendors are already in the room, pilot teams are already active, and Boards are already asking where AI touches operational decisions. What is less visible is why deployments elsewhere stall once they leave the pilot stage, and what that pattern predicts for operators who are about to follow.
Across EMR capital programmes and operations, AI pilots are multiplying faster than production deployments. As we have previously discussed, the vendors are already embedded and the pilot teams are already active. Boards are asking pointed questions about where AI touches operational decisions right now. What is less visible is why so many of these deployments stall once they leave the pilot stage.
The instinctive explanation is technical: the model was not accurate enough, the data was not clean enough, the integration was too complex. Those factors matter, but the strongest recent evidence points somewhere else first. When AI deployments stall in industrial operations, the diagnosis is rarely the algorithm. It is the operating model: unclear decision rights, escalation routes that were never built to cover an automated decision, competence requirements written for roles that have since changed, and documentation the new systems cannot read.
This matters because a weak operating model is a problem with or without AI. AI simply exposes it faster, and at greater cost, than the slower failure modes EMR operators are used to managing.
Why Do AI Deployments Stall Before the Algorithm Becomes the Problem?

The most widely cited evidence comes from MIT's Project NANDA, which reviewed over 300 enterprise AI initiatives, 52 structured interviews and 153 senior leader survey responses in its July 2025 report on the state of AI in business. It found that only around 5% of integrated AI pilots were extracting measurable value, while the large majority showed no measurable impact on profit and loss. The researchers were specific about the cause: the divide did not appear to be driven by model quality or regulation, but by how organisations approached deployment.
That study deserves a caveat this article will not skip. It was published as preliminary findings rather than peer-reviewed research, and the widely repeated "95% failure" framing has been challenged on the grounds that the 5% success figure referred to a narrower category, custom enterprise tools reaching production, than the "all AI pilots" denominator the headline implies. The authors' own affiliation with an agentic AI infrastructure project has also drawn comment. Anyone quoting the 95% figure as a settled statistic is quoting something that has not been settled.
What has held up is the diagnosis rather than the rate. That distinction matters, because the diagnosis is what this article rests on, and it is corroborated independently by a much larger and more transparent sample.
McKinsey's global survey of AI use, published in November 2025 and drawing on 1,993 respondents across 105 countries, points the same way. Regular AI use in at least one business function had reached 88% of organisations, yet only about 6% qualified as AI high performers, attributing EBIT impact of 5% or more to AI and reporting significant value from it. Those organisations were distinguished not by their models but by their behaviour: they were substantially more likely than their peers to have fundamentally redesigned workflows around AI. McKinsey's earlier March 2025 survey tested roughly 25 organisational attributes against business impact and found fundamental workflow redesign the strongest single correlate, while only 21% of adopters had actually done it.
Two studies of very different scale and rigour, arriving at the same mechanism. The organisations succeeding treat AI deployment as a workflow redesign exercise, not a technology rollout, which means changes to decision rights, escalation paths and role definitions rather than changes to the model. Neither study is specific to Energy, Minerals and Resources, but both describe the pattern PDAS sees in capital programmes and operations: adoption is not the constraint. Absorption is.
What Actually Breaks: Decision Rights, Escalation and Competence
Four failure modes recur, and each looks different once it has a face rather than a label.
- Decision rights. An AI system recommends a change to a drilling parameter. Who signs off, the drilling superintendent, the geologist or the maintenance manager? If the operating model never named an owner for that class of recommendation, all three assume it is someone else's call, and it sits unactioned.
- Escalation. A model flags an anomaly in pipeline pressure data. The escalation procedure was written for a human operator who knows who to call. The alert queues instead, because no one owns triage for a flag that came from a system rather than a person.
- Competence. A control room operator is asked to verify an AI recommendation but was never trained on the model's confidence intervals or known failure modes. They either accept the output without question or override it without being able to say why.
- Documentation. A management of change process requires a named change initiator to complete a form. A system that updates its own parameters weekly has no name to put on that line, so the change happens outside the process built to catch it.
This is not unique to AI. It is what happens when an operating model that was adequate for its original scope is asked to absorb a new kind of decision-maker without being deliberately extended. The NIST AI Risk Management Framework treats this as foundational rather than incidental. Its Govern function is described as cross-cutting, informing and infusing the other three functions, and it requires that roles, responsibilities and lines of communication for managing AI risk be documented and clear as a precondition for the governance structure that mapping, measuring and managing all assume..
It is also worth naming what does not fully explain the gap. Skills shortages and data quality are real constraints, and organisations often respond to them with training rather than structural change, which leaves the underlying decision rights and escalation gaps untouched. The operating model is not the only variable. It is consistently the one that gets skipped.
One Management System, Extended: Fitting AI Governance Into What You Already Run

The good news for EMR operators is that the fix does not require a parallel governance system. ISO/IEC 42001, the international standard for AI management systems published in December 2023, was deliberately built on the Harmonised Structure that ISO uses across its management system standards, giving it the same clause architecture, Clauses 4 to 10, as ISO 9001, ISO 14001 and ISO 45001. Clause 6.2 requires organisations to set AI objectives that are consistent with a stated AI policy, measurable where practicable, and backed by a plan that specifies what will be done, what resources are needed, who is responsible, and how results will be evaluated. None of that is unfamiliar to an operator already running a quality or safety management system. It is the same discipline, extended to cover a new class of decision-maker.
For oil and gas operators, IOGP Report 510 already provides the anchor, with direct read-across for minerals and resources operators running equivalent operating management systems. Its four fundamentals and ten elements, covering everything from leadership to management of change, apply across every type of upstream or downstream activity, from construction to decommissioning.
None of this is automatic. Extending Report 510 to cover AI means mapping AI-specific controls onto existing elements, not assuming they fit by default. It means reconciling a risk appetite calibrated for safety and process risk with the different, probabilistic character of algorithmic risk. Auditors and process owners need enough fluency in AI-specific controls to test them credibly, not simply add them to a checklist. And document control needs to handle a change initiated by a system rather than a person, which most management of change procedures were never written to do. A second, parallel system does not remove this work. It just duplicates the effort and adds interface risk in exactly the place AI needs clarity: who decides, who signs, who stops.
Extending Governance Before AI Forces the Question
AI deployments across Energy, Minerals and Resources operations are not stalling because the technology is immature. They are stalling because the operating models meant to govern them were never built for an automated decision-maker. The evidence above is consistent: success correlates with workflow redesign, not model accuracy, which is why the fix does not start with a better algorithm. It starts with extending the management system already in place, anchored in IOGP Report 510 and ISO/IEC 42001, to cover AI-specific decision rights, escalation and competence.
That is the same test independent project reviews already apply to everything else in a capital programme: whether reported process matches observed practice. AI is simply the newest place that question needs asking, and the newest place a gap can sit undetected until it fails.
The EU AI Act's high-risk deadlines were reported as deferred on 29 June 2026, to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in regulated products, so Brussels is not the reason to act now. Client questionnaires, insurer programmes and Board scrutiny are arriving on a faster timeline than that, and none of them are waiting for a regulator. The question is not whether to extend governance to cover AI. It is whether to do so on your own terms, before an incident forces the issue.
PDAS's Operating-Model and Management-System AI-Readiness Diagnostic gives Boards and COOs an independent, evidence-based read on whether their operating model and management system are ready to govern AI, benchmarked against ISO/IEC 42001 and the NIST AI Risk Management Framework. Independent by structure, PDAS builds no AI models, sells no technology and takes no vendor commissions.









