Most organisations are past the question of whether to use AI and stuck on the question of what it has changed. Licences are bought. Pilots ran. Somewhere in the business a team is already putting client data into a model nobody has classified. And the board still cannot answer, in one number, what any of it returned.
That is not a technology failure. Three gaps produce it, and all three are organisational.
The first is alignment. Ask five executives what AI is for in your company and you get five answers — cost, speed, headcount, differentiation, defence. Capital cannot be committed with confidence against five definitions, so it is committed in fragments. Fragments do not compound.
The second is capability. The people expected to deliver the change are the same people already running the business at capacity, and most have had no structured exposure to what these systems can and cannot do. Enthusiasm substitutes for literacy, and enthusiasm does not survive the first confident wrong answer in front of a client.
The third is sequencing. There is no route from awareness to production, so effort disperses towards whichever use case had the loudest sponsor. The ones that would have paid back sit unbuilt, because nobody scored them.
The EU AI Act phases in, and the timetable moved in July 2026. The prohibitions have applied since February 2025 and the general-purpose model obligations since August 2025, while the Digital Omnibus deferred the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products. The deferral changes the deadline, not the work: the inventory and the classification that everything else depends on take the same number of weeks whenever you start them.
We work the three gaps in that order, and we design the governance in from the first sprint rather than reconstructing it the week the auditor arrives.