Where Do the Holes in Your AI Initiative Line Up?

Posted on October 5, 2026

0


Jon W. Hansen, FCIPS · Procurement Insights | Hansen Models™

In a single morning, five very different conversations about AI crossed my desk.

Gartner published its first Magic Quadrant for Enterprise AI Assistants, describing these assistants as the new “front door” for work. Cisco gave 90,000 employees their own AI agent. McKinsey’s Technology Trends Outlook 2026 warned that the limit is no longer how fast AI can generate work, but how fast organizations can absorb it. A widely shared post laid out the six technology layers, from machine learning to agents, that make modern AI possible. And across most of these conversations, governance meant guardrails: permissions, security and approval gates.

Each one looks at something different: a market ranking, a deployment figure, a bottleneck, a technology stack and a set of controls. But they all have one thing in common. They describe the boxes.

The boxes and the operation

On the left is the way most organizations, and most of the market, picture the work: a sequence of boxes, each handing off to the next. On the right is how the same functions actually operate. Each one moves at its own rhythm, and outcomes are decided at the moments when those rhythms line up.

Seen against this graphic, the five conversations fall into place:

  • A quadrant ranks the boxes. It tells you which assistant has the strongest capabilities. It cannot tell you what happens when that assistant enters an operation where people, suppliers and systems all move at different speeds.
  • A deployment figure counts the trains. Ninety thousand agents is a measure of scale. It is not a measure of whether the work got better.
  • A bottleneck shows where the problem surfaces, not where it starts. When review and decision cannot keep up with AI, the choke point is usually where the mismatch between the diagram and the real operation finally becomes visible.
  • A technology stack builds more capable boxes. Integrating the layers makes the technology stronger. It leaves the operating problem exactly where it was.
  • Guardrails control each box on its own. They do not see what happens between the boxes.

The holes in the cheese

The one conversation that came closest to the right side of the graphic came from Bertrand Maltaverne.

Bertrand compared this moment in AI to the early days of aviation, using the well-known Swiss cheese model of safety. Every layer of protection has holes. A crash happens when the holes in several layers line up at the same moment. He then mapped that idea onto the three planes of agentic AI: Julie Simou‘s control plane for what an agent may do and data plane for what it may trust, and the operating plane I added underneath both.

Bertrand’s post is here.

A note for clarity: Bertrand, Julie and I are not formally collaborating. We have each arrived at the same view from different directions, and it is a view I have described through the Strand Commonality™ lens since 1998.

That is the right-hand side of the graphic in another field. A crash is rarely the failure of a single layer. Every layer can pass its own inspection, and the holes still line up at the wrong moment. The bright blocks in the animation are exactly that: the moments when several parts of the operation align, and an outcome follows that none of them caused alone.

How aviation actually got safe

Aviation did not become one of the safest ways to travel by adding more guardrails to each layer. It got there because every accident is investigated, the findings are fed back into the system, and the same holes become less likely to line up again.

That is the lesson for AI governance. Humans govern. They decide what the limits are and what matters. A learning loop that carries what actually happened back into the system builds the firm fences that make those limits work in the live operation. Guardrails on their own are a list of controls. Governance is the loop.

In 1998, the system we built for the Department of National Defence worked this way. Every order, delivery and post-delivery result was automatically fed back into the system, which utilized advanced self-learning algorithms. The holes kept moving, and the system kept learning where they were.

A simple test

All of this comes down to one practical question for anyone buying AI, or any technology, for their operation.

If your solution provider can only explain the left-hand side of this graphic, they can configure the technology. If they cannot explain the right-hand side, including how your people, systems and suppliers actually interact, how their timing shifts and how what happens feeds back into what happens next, then success on the left-hand side is unlikely.

Configuring the workflow is not the same as making it work.

Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™

-30-

Posted in: Commentary