NEWS
Twenty-Two Months Later, Three 2025 Tech Challenges Still Bind
Technology executives listed 20 challenges for 2025. The AI-first revenue bet missed the P&L, while identity, talent, and regulation now bind operators.
MIT’s Project NANDA found that 95% of generative AI pilots produced no measurable profit impact in 2025, the year technology executives had just named as their AI-first test. The finding sat on between $30 billion and $40 billion of enterprise GenAI spend. McKinsey’s 2026 survey, published August 25, 2026, then put the share of companies getting real financial impact at about 6%, unchanged from 2025.
On December 3, 2024, twenty executives had laid out 20 challenges for the year ahead. Most of the list was about making AI pay, ship, and scale. Twenty-two months later, the items that bind operators are the ones they treated as side work: machine identities, scarce skills, and rules that apply in pieces.
Four Constraints From That List Now Run the Shop
Daniel Khachab, then at food-ordering firm Choco, said every company had to become AI-first and turn the technology into a revenue engine, not a chatbot on support. Olga Megorskaya of Toloka AI warned that safety and reliability would get harder as systems grew more autonomous. Tim Eades of Anetac said AI-enhanced attacks would target machine identities and service accounts. Akshay Prabhu of Capital One said the shortage would be engineers who could handle AI foundations and messy data, and that the fix was upskilling people already on the payroll.
Those four lines now describe the job. Individual output rose. Company earnings mostly did not. Agents showed up with real credentials and no clean owner. Hiring screens asked for agent experience that junior roles never taught. Brussels turned the lights on for some duties and slid the hardest ones.
THE FOUR THAT LANDED
- The P&L gap: Widespread pilots, almost no earnings movement at firm level.
- The identity gap: Agents, APIs, and service accounts outran human-shaped access tools.
- The skills gap: Demand jumped for AI-fluent senior security and data people; the junior rung shrank.
- The calendar gap: Some AI rules applied on time; high-risk duties moved after a 2026 rewrite.
The rest of the 2024 list was not wrong so much as early, or aimed at the wrong scoreboard. Engineering productivity, container platforms, and “speak to software” still occupy roadmaps. They did not decide who got funded, who got breached, or who had to label synthetic output.
The Revenue Engine Mostly Idled
Project NANDA’s July 2025 paper, The GenAI Divide: State of AI in Business 2025, reviewed more than 300 public AI initiatives, interviewed people at 52 organizations, and surveyed 153 senior leaders between January and June 2025. Lead author Aditya Challapally and colleagues Ramesh Raskar, Chris Pease, and Pradyumna Chari wrote that the split was so sharp they named it a divide: just 5% of integrated pilots were pulling millions in value, while the rest showed no measurable P&L hit. They traced zero return from enterprise GenAI to approach, not to model quality.
General tools spread fast. More than 80% of organizations had explored or piloted products such as ChatGPT and Copilot, and nearly 40% reported some deployment. Task-specific systems were harsher: 60% of firms evaluated them, 20% reached a pilot, and 5% made it to production. Partnered or purchased tools succeeded about twice as often as internal builds, roughly 67% against 33%.
That pattern is why investor questions about AI returns moved from slideware into earnings calls. S&P Global Market Intelligence, in a 2025 survey, found 42% of companies abandoned most of their AI initiatives that year, up from 17% in 2024. McKinsey’s 2026 State of AI work, fielded in May and June 2026, still found about 6% of firms as high performers that could tie at least 5% of EBIT to AI. In the same research, 80% of workers said the tools made them more productive. The gain showed up in people. It did not show up in the accounts.
THE SCOREBOARD AFTER THE PILOTS
- 95%: Share of generative AI pilots with no measurable P&L impact, MIT Project NANDA, July 2025.
- 6%: Share of companies McKinsey counted as AI high performers in 2026, flat versus 2025.
- Over 40%: Share of agentic AI projects Gartner expects to cancel by the end of 2027.
- 42%: Share of companies that S&P Global said abandoned most AI initiatives in 2025.
On June 25, 2025, Gartner said over 40% of agentic AI projects will be canceled by the end of 2027 because of rising costs, unclear business value, or weak risk controls. Anushree Verma, a senior director analyst there, did not blame the models.
Most agentic AI projects right now are early stage experiments or proof of concepts that are mostly driven by hype and are often misapplied.
Anushree Verma, Senior Director Analyst, Gartner newsroom, June 25, 2025
A January 2025 Gartner poll of 3,412 webinar attendees found 19% had made large agentic bets, 42% conservative ones, 8% none, and 31% waiting or unsure. The firm also estimated that only about 130 of the thousands of vendors using the agent label were building the real thing. Separately, it still forecasts that by 2028 at least 15% of day-to-day work decisions will be made by agentic AI, up from 0% in 2024, and that 33% of enterprise software will include it, up from less than 1%. Those two forecasts can both be true if a lot of projects die and a smaller set ships.
GARTNER’S JANUARY 2025 POLL
- Large bets: 19% said their organization had made significant agentic investments.
- Cautious spend: 42% had made conservative investments.
- No spend: 8% had put in nothing.
- Waiting: 31% were on hold or not sure.
Thushera Kawdawatta of Axiata Digital Labs had wanted generative AI for automation plus a people-first culture. Darko Pavic of Fiscal Solutions wanted new development roles around AI coding tools. Those programs can raise commits and cut keystrokes. NANDA’s split, and McKinsey’s flat 6%, say that is not the same as a revenue engine.
Machine Identities Outran the Security Model
Eades’s 2024 warning was specific. Attacks would go after machine identities and service accounts, and companies would need identity security that found holes, scored new risk, and changed access on the fly. Kalyan Gottipati of Citizens Financial Group put the same pressure in broader terms: more AI in operations, a wider attack surface, and messier cross-border privacy rules.
By 2026 the industry had a name for the gap. CrowdStrike’s product copy now treats service accounts, AI agents, API keys, and workloads as non-human identities expanding the attack surface, because they run in the background with standing privilege and weak owners. On September 2, 2026, at Fal.Con, the company launched an Agentic Identity Provider so agents can be registered, given short-lived tokens, and tied back to a human or system. Scott Kriz, general manager of Continuous Identity, said traditional identity tools break the moment an agent acts on its own.
Securing AI agents demands solutions built for how they operate. Continuous Identity modernized identity security for the agentic era, but you cannot continuously authorize an identity you were never able to establish, and traditional identity providers break the moment an agent acts on its own.
Scott Kriz, GM of Continuous Identity, CrowdStrike, September 2, 2026
Hrishikesh Joshi of Okta had already called for governance, scale patterns, and monitoring around enterprise GenAI. Brittany Greenfield of Wabbi wanted DevSecOps treated as a full risk program, not a pipeline add-on. The 2026 product wave is those sentences in software form. Practitioners arguing about agents keep returning to the same three questions: which agent is this, who owns it, and what is it allowed to do. Copying an agent should not copy its budget. Restarting it should not revive a used permit. That is identity work, not model work.
Upskilling Never Closed the Hiring Gap
Prabhu’s plan, partnering with schools and leaning on coding assistants, was the consensus fix in late 2024. The 2026 labor data says the bottleneck moved, it did not ease. The Cisco-founded AI Workforce Consortium, reading G7 job ads, found that the share of cybersecurity postings that asked for AI skills doubled from 14.2% in the six months through March 2025 to 28.5% in the six months through March 2026. Senior-titled cyber ads grew 65% in that later window. Junior-titled ads grew 5.9%. Overall cyber demand rose 9.5%. Forty-nine percent of security leaders said hands-on agent experience was among the hardest things to find in entry-level candidates.
Accenture’s June 2, 2026 workforce study found 59% of open cyber roles want mixed technical and strategic skills, while only 40% of the current workforce fits that mix. It put AI-related cybersecurity skills demand at 2.5 times the 2020 level, with fewer than 30% of organizations funding structured upskilling. Forty-nine percent of leaders said shortages hurt the cyber function. Eighty-seven percent called AI-related vulnerabilities the fastest-growing cyber risk.
Kerry Brown of Celonis had argued that transformation had to pull every department, not just IT, with SAP’s 2027 migration as the forcing date. Mark Cameron of Alyve Consulting told leaders they would have to manage a carbon-base workforce of humans and a silicon-base workforce of agents. The hiring data is what you get when the silicon layer is staffed by borrowing senior people and skipping the jobs that used to train them.
Brussels Set Dates, Then Moved the Hard Ones
Sheraz Ahmed of STORM Partners wanted compliance as a live checkpoint so product teams would not outrun the law. Naveed Anwar of Citi said AI could help treasury catch breaches, with the caveat that human judgment stays in the chair. Michael Malyuk of HumanSignal said human-in-the-loop work would be how companies scale AI without dropping quality or ethics. The European calendar is the test of all three.
The Commission’s AI Act Service Desk now publishes an EU AI Act implementation timeline that already includes the Digital Omnibus on AI. Prohibitions and AI literacy applied on February 2, 2025. Rules for general-purpose AI models and the governance setup applied on August 2, 2025. On August 2, 2026, Article 50 transparency duties applied and enforcement began on the rules already live. High-risk duties did not.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026. It moved Annex III high-risk rules to December 2, 2027, and high-risk AI inside regulated products under Annex I to August 2, 2028. Full rollout of the main milestones is now set for August 2, 2028. Innovation did outrun the hard obligations. The reply was a later clock, not a tighter one.
THE ACT’S LIVE AND MOVED DATES
- August 1, 2024: The AI Act enters into force.
- February 2, 2025: Prohibitions and AI literacy apply.
- August 2, 2025: General-purpose AI model rules and governance apply.
- July 27, 2026: The Digital Omnibus on AI enters into force.
- August 2, 2026: Article 50 transparency applies; enforcement starts on live rules.
- December 2, 2026: New deepfake and CSAM bans apply; leftover synthetic-content marking is due.
- December 2, 2027: Annex III high-risk rules apply.
- August 2, 2028: High-risk AI in Annex I products applies.
December 2, 2026 is the next hard day on that list. New bans cover AI systems that generate non-consensual sexual deepfakes and child sexual abuse material. Providers of generative systems already on the market before August 2, 2026 also have until that December date to meet the machine-readable marking duty in Article 50(2). Safety, in other words, is being written into labels and bans before it is written into the high-risk product regime Megorskaya’s reliability problem would actually sit in. Documented cases of frontier models used in intelligence work have made that lag harder to treat as a paperwork delay.
How the Original 20 Challenges Aged
Meghana Puvvadi of NVIDIA wanted architectures that could swap models, prompts, and guardrails. Mohit Gupta of Damco Solutions wanted hybrid upgrades that did not blow up legacy cores. Ben Ghazi of Codiac wanted containers ready for AI workloads. Cristina Gupca of Key IVR wanted modular systems that shipped fast without breaking. Those are the plumbing under every failed pilot NANDA logged, and they remain unfinished work rather than disproved ideas.
Lindsey Witmer Collins of WLCM App Studio said users would speak to software and get what they needed. That interface arrived in consumer tools. It did not, on NANDA’s numbers, become the enterprise revenue engine Khachab described. Matthew Sole of Zeal had worried that investors would demand longer proof of monthly recurring revenue. The 95% P&L miss is that worry with a research stamp on it.
2024 WARNINGS, 2026 VERDICTS
| 2024 challenge | Who raised it | 2026 read |
|---|---|---|
| Turn AI into a revenue engine | Daniel Khachab, Choco | Missed at firm level; about 6% high performers |
| Engineering productivity via GenAI | Thushera Kawdawatta, Axiata Digital Labs | Individual output up; P&L mostly flat |
| Safety and reliability of autonomous AI | Olga Megorskaya, Toloka AI | Still open; high-risk EU duties now 2027 and 2028 |
| Machine-identity attacks | Tim Eades, Anetac | Landed; agent identity is now a product line |
| AI and data talent shortage | Akshay Prabhu, Capital One | Landed; senior AI-cyber demand far outran junior hiring |
| Human-in-the-loop quality | Michael Malyuk, HumanSignal | Landed as the working method, not a phase |
| Innovation ahead of regulation | Sheraz Ahmed, STORM Partners | Mixed; some rules live, hard ones delayed |
| Carbon and silicon workforces | Mark Cameron, Alyve Consulting | Landed as an operating problem, not a slogan |
The graded list is lopsided on purpose. The 2024 roundup gave each item equal type. 2025 and 2026 did not. Flexible platforms, hybrid cores, and better UX still matter to the teams building them. They did not sort winners from everyone else.
Humans Still Sit in the Loop
Malyuk’s sentence from December 2024 is the one that aged with the least spin. Human-in-the-loop workflows, he said, would bridge AI speed and the judgment people still have to apply. Anwar said the same thing from a bank: machines help, they do not replace the person who owns the file. Cameron’s carbon-and-silicon pairing is the org-chart version.
That is also why so many agent projects will not survive Gartner’s 2027 window. Verma’s three kill-reasons, cost, fuzzy value, and weak controls, are what you get when a silicon worker is dropped into a carbon process with no owner, no rollback, and no identity. The companies that already treat agents as staff with badges, budgets, and a manager are the ones the 5% in NANDA looks like. The rest still have a demo.
December 2, 2026 will not fix earnings. It will force more labels onto synthetic output and add two ugly bans to the list that started on February 2, 2025. The high-risk regime that would actually test Megorskaya’s reliability claim is still a year and more beyond that. Until then, the 2024 list’s quieter items remain the ones with due dates, headcount, and incident tickets attached.
Khachab’s AI-first year happened as a spending cycle. NANDA’s 95% and McKinsey’s 6% are what that cycle bought. Eades, Prabhu, and Malyuk named the bill.
-
BUSINESS4 months agoMusk’s $914 Billion Lead Is a Public SpaceX Bet
-
NEWS2 months agoMicrosoft’s 96% Cyber Score Sits at 86.3% on the Board
-
SPORTS3 months agoFree Live Sports Streaming in 2026: What to Watch Without Cable
-
ENTERTAINMENT4 weeks agoSterling Point Holds No. 2 on Prime Video After 32 Days
-
ENTERTAINMENT3 months agoThe Odyssey’s IMAX Film Run Hit a 41-Theater Limit
-
ENTERTAINMENT3 months agoEndgame Encore’s $86 Million Trial for Infinity Vision
-
ENTERTAINMENT2 years agoAndrew Garfield’s Spider-Man Films Are No Longer Free
-
NEWS4 weeks agoG20 Cheers AI Investment After Bailey’s Frontier Cyber Warning
