← Back to all articles
strategy

Half of GenAI Projects Now Die After the POC. Only One of the Four Causes Is About Security.

By Marc Molas·September 10, 2026·10 min read

In July 2024 Gartner predicted that at least 30% of generative AI projects would be abandoned after proof of concept by the end of 2025. When the year closed, the figure it published was at least 50%. The four reasons hadn't changed in eighteen months: poor data quality, inadequate risk controls, escalating costs, unclear business value. Half the projects, the same four reasons — and I have yet to meet anyone in a Spanish bank, insurer or regional government who found the number surprising.

I build and operate AI systems for companies that have to defend them in front of a regulator. This summer I sat in a room where a public administration asked us seven questions before we could touch a line of its code. Not one of the seven was about the model. All seven were about the perimeter: where the code goes, where inference runs, who approves a change, what gets logged. That is the seat this post is written from, and it's why I read Gartner's four causes differently from the way they travel in slide decks. Only one of the four is about security. All four get paid at the perimeter.

Gartner's 30% became 50% in eighteen months, and the four causes didn't move

The trajectory is documented in Gartner's own words. The July 2024 press release predicted 30%, citing «poor data quality, inadequate risk controls, escalating costs or unclear business value». The 2026 follow-up, «Why Half of GenAI Projects Fail», reports that by the end of 2025 at least half had been abandoned after the proof-of-concept stage — and lists the same four culprits, in the same order.

A number that doubles while its causes stay fixed is telling you something about where the projects are built, not about the technology. The models improved more in those eighteen months than in any comparable window I've worked through, and the abandonment rate went up anyway. A proof of concept that succeeds technically and still has to be abandoned was built somewhere it couldn't stay. I've written before about the American version of this story — MIT's 95% and the forward-deployed engineer — where the pilot dies in deployment because nobody was inside the workflow. The Spanish, regulated version has a more specific address.

In Spain, 96% call private and sovereign AI «key». 29% are doing something about it.

NTT DATA's Global AI Report 2026, published on 31 August 2026 from a survey of roughly 5,000 decision-makers including 75 Spanish executives, puts it in two numbers: 96% of organisations in Spain consider private and sovereign AI key to their strategy, and 97% say they are evaluating moving AI infrastructure to specific geographies for geopolitical reasons. Globally, only 29% are prioritising sovereign AI in the short term and taking concrete measures. The barriers Spanish respondents name are regulation (28%), the investment required (27%), technical complexity (24%) and a shortage of specialised talent.

Deloitte España's «El estado de la IA en las empresas 2026» (3,200+ leaders across 24 countries) reads the same way from the compliance side: 49% of Spanish companies name regulation and governance as one of their main barriers, and 70% report high or very high concern about how their proprietary data is used.

The finance sector says it in its own words. At an AI-Network executive breakfast in Madrid on 10 June 2026, with Santander, CaixaBank Tech, Bankinter, Singular Bank and MásOrange Seguros at the table, the shared conclusion was that «el gran reto ya no es probar la tecnología, sino llevarla a producción de forma segura, eficiente y alineada» — and that private cloud and on-premise environments «vuelven a ganar protagonismo» for cost control, security by design and data sovereignty. Two months later, a Mapfre executive told Cinco Días that the insurer had discarded AI cases «por seguridad de la información o sesgos del modelo», and preferred not to give examples.

The gap between 96 and 29 isn't indecision. It's a queue: use cases that have finished their proof of concept and are waiting for an entry ticket they can't get. The ticket has a name. In a regulated Spanish company, the perimeter is the set of things you must be able to show: identity and access for every component; data that never leaves the jurisdiction or the DPO's conditions; encryption keys you hold; a log a supervisor can read; an entry in the supplier register — the DORA register of information for financial entities, the ENS for public bodies; a cost ceiling; and a documented exit.

Only one of the four causes is about security. All four get paid at the perimeter.

This is my reading, from the builder's seat, of what Gartner's four labels look like when the project is Spanish and regulated. Gartner doesn't make this argument; I can't prove it from their data, and I'll say so. But I've watched each of the four happen, and they happened at the same place.

  • Data quality. The demo ran on the data you were allowed to export — a sample, an anonymised extract, last quarter's CSV. Production runs on the system of record you can't export. What gets filed as «poor data quality» is, in most rooms I've been in, «the data the proof of concept never saw».
  • Risk controls. The one everybody names: prompts leaving the country, a vendor with the contractual right to train on your inputs, no audit trail in a format the supervisor accepts.
  • Escalating costs. A proof of concept priced per token on a public API looks cheap at demo volume. At a bank's throughput the invoice scales with usage and sits outside your control. VMware's June 2026 survey of 1,800 IT decision-makers — vendor research, so discount it — has 56% running or planning production inference in a private cloud, 62% worried about costs and 51% repatriating AI workloads for security reasons (The Next Platform, 1 September 2026).
  • Unclear business value. Value is measured where the workflow runs. A proof of concept that never touched the real workflow can't produce a number someone already reports, and a number nobody reports is a value nobody believes.

I'd give the pattern a name, because a named thing is a thing a steering committee can put on the agenda: perimeter debt — the work you defer when you build the proof of concept outside the controls it will have to live inside. Like technical debt it accrues interest. Unlike technical debt it comes due in one instalment, the day someone asks for the production ticket. Gartner's 50% is, from where I sit, mostly perimeter debt being called in.

Residency is now a purchase order. The perimeter is still engineering.

If the perimeter were only about where the bytes live, 2026 would have solved it. AWS's European Sovereign Cloud went live on 15 January, operated exclusively by EU residents. Microsoft's Sovereign Private Cloud on Azure Local added fully disconnected, air-gapped operation in early 2026. Telefónica Tech and Google Cloud launched a sovereign offering for Spain on 28 May, with encryption keys held by Telefónica. The Comunidad de Madrid began deploying its own sovereign AI cloud in Alcalá de Henares on 20 August. VMware shipped Private AI Cloud on 1 September. «Our data stays in the EU» is now a line item a procurement team can buy in an afternoon.

What the purchase order doesn't buy is the rest of the list: the use case rebuilt inside those controls, inference operated with your keys, evals as the regression suite a supervisor will ask to see, the register entry, the runbook, the exit. I made the longer version of this argument when I read Sergio Cruzes' sovereignty paper: residency is the legal layer, and the legal layer is the easy one. Eight months of launches have made it easier still. They haven't touched the operational layer, and that's where the ticket gets issued.

The honest counter-number: some of those projects should have died

A proof of concept exists to be killable. Gartner's 50% includes projects correctly abandoned on data, cost or value, and abandoning a proof of concept on written criteria is the process working, not failing. Two more numbers cut against my thesis and belong in the room. MIT's 95% measures a P&L window that mature technologies routinely miss. And McKinsey's State of AI 2026 (August 2026) has 37% of respondents attributing any EBIT impact to AI and 6% qualifying as high performers — both flat year on year — which says the winners are few whether or not they solved the perimeter. The perimeter isn't the whole story. It's the part of the story a regulated company in Spain controls.

One disclosure before the recommendations: Conectia sells production inside the perimeter — private inference in your region with your keys, proofs of concept with written success criteria — so the diagnosis and the pitch point the same way. Discount accordingly, then check the sources above, which aren't mine.

The failure I'm pointing at is narrower than «half of GenAI projects fail». It's the proof of concept that can't be judged because it never ran inside — killed on a feeling, because the numbers it would have needed lived on the other side of the wall.

What I'd do this quarter with one use case in a regulated company

  1. Write the perimeter before the prompt. One page: which data, in which system, under whose conditions; where inference runs and whose keys encrypt it; who approves a change; what gets logged and in what format; what the supplier register entry will say (DORA article 28 if you're a financial entity, the ENS if you're a public body).
  2. Run the proof of concept inside from day one. Real identity and access, real data under the DPO's rules, inference in your region with your keys. If a vendor can't run there, that's a finding of the proof of concept, not an obstacle to it.
  3. Timebox it with the criteria written before the first commit. Three weeks, success criteria on paper, a kill date. A proof of concept without a kill date isn't waiting for production; it's waiting for a budget review.
  4. Measure where the workflow runs. One number someone already reports to the board. Either the «unclear value» cause dissolves or it's confirmed, and both outcomes are worth the three weeks.
  5. Write the exit into the kickoff. Code and runbooks yours, a no-training clause, a documented exit. They're the same fields the register asks for, so you'll write them anyway — better in week one than in the audit.

Five numbers to take into the room

  • At least 50% of GenAI projects were abandoned after proof of concept by the end of 2025, up from a predicted 30%, for the same four reasons (Gartner, 2024 and 2026).
  • 96% of Spanish organisations call private and sovereign AI key to their strategy; 29% globally are acting on it short-term (NTT DATA Global AI Report 2026, 31 August 2026).
  • 49% of Spanish companies name regulation and governance as a main barrier; 70% report high or very high concern about the use of their proprietary data (Deloitte España, 2026).
  • 56% of IT decision-makers run or plan production inference in a private cloud; 51% are repatriating AI workloads for security (VMware survey, June 2026 — vendor research).
  • 37% attribute any EBIT impact to AI and 6% are high performers, flat year on year (McKinsey State of AI, August 2026).

The number doubled and the causes didn't move because the causes were never about the model. They were about the wall between the room where the demo runs and the room where the company lives, and about who does the engineering to get the use case through it. If you have one use case waiting at that wall, talk to a CTO — bring the one page from step one, and we'll start there.

Work with the authors

The CTOs who write this also build

Fractional CTO engagements, AI engineering squads and an AI development platform we install on your codebase in 24 hours. If this piece matched how you think, the conversation is short.

Teams we have embedded engineers in
MintIDCNN InternationalSony Music