▰ TL;DR
MIT NANDA reports 95% of enterprise generative-AI pilots fail to deliver measurable profit-and-loss impact[1] — the finding is industry-wide, across federal agencies and commercial enterprises alike. On the federal side, OMB M-24-10 (March 2024)[2] mandates every agency designate a Chief AI Officer, and GAO has counted 1,757 active or planned federal AI use cases[3]. On the commercial side, US sector-specific regimes — Federal Reserve SR 11-7 (bank model risk management), NYDFS Part 500 (financial services cybersecurity), and FDA AI/ML SaMD (medical devices) — set the baseline, and the Colorado Artificial Intelligence Act (signed May 2024, effective February 2026)[8] is the first comprehensive US state-level high-risk-AI law. Stanford HAI counted 59 new US AI regulations in 2024 alone[7]. NIST AI RMF[4] and the AI 600-1 Generative AI Profile[5] are converging as the cross-sector reference. The technology is ready; the governance scaffolding is not. This piece walks the role-by-role workflows AI could enable in a cyber program — federal or commercial — the regulatory floor those workflows have to clear, and what bridging the gap could look like in practice.
Where AI is failing cyber programs today
The headline number is the same one MIT NANDA's State of AI in Business 2025[1] reports for enterprise GenAI broadly: 95% of pilots fail to deliver measurable P&L impact. MIT names the failure modes: missing learning loops, integration gaps, governance scaffolding, and workflow adaptation. Inside cyber programs — federal and commercial — the same failure modes show up in domain-specific shapes:
- Threat-intel triage pilots stall because there's no agreed delegation boundary — when does the AI summary go to the watch floor (federal) or SOC (commercial) unreviewed, and when does it require human sign-off?
- Log-analysis copilots get shadow-banned because operators can't explain to an inspector general (federal) or a Big-4 auditor (commercial) which control objectives the model satisfies and which it doesn't.
- Identity-governance AI gets shelved when the audit team can't produce machine-readable evidence aligned to NIST 800-53, NIST AI 600-1, ISO 27001, or SR 11-7 (banking) within an audit window.
- Incident-response orchestration plateaus at PoC because the runbook can't cite the regulation that authorizes a given autonomous action — whether the controlling framework is DoD RAI, Colorado AI Act, or NYDFS Part 500.
MIT also finds that vendor-led implementations succeed roughly twice as often as internal builds — 67% vs. 33%[1]. For any cyber program running internal AI builds without a governance partner, that ratio compounds the 95% failure rate. The cost isn't just wasted budget. It's audit deficiency, regulator exposure, and — for federal agencies — erosion of authorization to operate AI at all; for commercial enterprises, board-level risk and potential fines under cross-border regimes.
What good AI could look like for cyber programs — by role and task
Imagine the same cyber program — federal or commercial — with the governance scaffolding in place. The AI doesn't change. It's the same large language models, the same agent frameworks, the same automation primitives. What changes is that every workflow has a documented delegation ceiling, a regulatory citation chain, and machine-readable audit evidence on the back end. Three roles, the workflows each could run:
Role · Chief AI Officer (CAIO) / Head of Responsible AI
Single source of truth for every AI use case
- Single-pane inventory of every AI use case in production or planned, with governance posture, delegation ceiling, and compliance status at the use-case level — whether the buyer is a federal agency satisfying OMB M-24-10 or a commercial enterprise preparing for a NIST AI RMF audit or Colorado AI Act readiness review.
- Automated regulatory mapping — every use case cross-referenced against NIST AI RMF 1.0, NIST AI 600-1, IEEE 7000-series, Colorado AI Act, and DoD Responsible AI Strategy & Implementation Pathway where applicable.
- Audit-ready OSCAL evidence packages on demand — Inspector General review (federal) or Big-4 audit (commercial).
Role · Cyber program lead / CISO
AI-augmented operations with defensible bounds
- Watch-floor or SOC copilot that summarizes incoming threat intelligence with a delegation ceiling set to "advisory only" — operator reviews every output, AI never commits to action.
- Log-analysis agent that flags anomalies with delegation set to "autonomous within audited bounds" — AI escalates anomalies above a threshold; all decisions logged with regulatory citation chain.
- Incident-response orchestration that pulls from a playbook library, with each playbook step pre-mapped to the regulation that authorizes it — federal RAI tenets or commercial regulatory regimes (NYDFS, GLBA, HIPAA, sector-specific).
Role · Auditor / IG liaison / Compliance officer
Machine-readable governance evidence on every AI use case
- OSCAL output for every use case — federal IG auditors or commercial Big-4 auditors consume structured evidence rather than reading prose reports.
- Cross-framework rollup at the click of a button: a single use case mapped to NIST + DoD RAI + Colorado AI Act + agency- or sector-specific US guidance, with no duplicate work.
- Reproducible audit trail showing the regulatory citation chain behind every autonomous AI action the organization took during the audit period.
The non-negotiable — governance is the bottleneck
None of the role-by-role workflows above are possible without disciplined governance underneath. And neither federal nor commercial cyber programs have the option to defer the governance work. The regulatory floor solidified between January 2023 and August 2024, with parallel mandates on both sides:
- OMB Memorandum M-24-10 (March 2024)[2] — requires every federal agency to designate a Chief AI Officer, stand up an AI Governance Board, and maintain a public AI use-case inventory. Binding policy.
- NIST AI Risk Management Framework 1.0 (January 2023)[4] + AI 600-1 Generative AI Profile (July 2024)[5] — the de facto US federal standards every agency must reference.
- DoD Responsible AI Strategy & Implementation Pathway (June 2022)[6] — DoD-wide responsible-AI tenets with working-council enforcement.
- Colorado Artificial Intelligence Act (SB 24-205, signed May 2024, effective February 2026)[8] — first comprehensive US state-level AI regulation; mandates impact assessments for high-risk AI systems used in consequential decisions, with state attorney-general enforcement.
- Sector-specific commercial regimes — including SR 11-7 (US bank model risk management), NYDFS Part 500 (NY financial services cybersecurity), FDA AI/ML SaMD framework (medical devices), HIPAA (health information), and Gramm-Leach-Bliley Act safeguards.
The slope is steepening, not flattening. Stanford HAI's 2025 AI Index[7] counted 59 new US federal AI-related regulations introduced in 2024 — more than double the 25 counted in 2023. US state-level AI regulation is following the curve: Colorado leads with SB 24-205; California, New York, Texas, Connecticut, and Illinois have all introduced or passed comparable bills. Any cyber program — federal or commercial — that builds governance scaffolding once and abandons it will fall out of compliance within a quarter. What's needed is a framework engine that absorbs new standards as they emerge and produces audit-defensible deliverables in weeks, not quarters.
Introducing ARKONA + COMET
ARKONA + COMET — the platform and the framework
ARKONA is Intrepid's multi-tenant agent + governance platform. COMET is the AI-governance framework that runs on it.
COMET is designed as a deterministic citation-to-delegation engine. Feed it a free-text description of an AI task — "auto-summarize incoming threat-intel reports for the watch floor" — and it returns a structured artifact: the applicable regulatory citations (NIST AI RMF, AI 600-1, DoD RAI, Colorado AI Act, agency- and sector-specific US guidance), the recommended delegation ceiling on a five-level taxonomy (advisory only → fully autonomous within audited bounds), the responsible-accountable-consulted-informed matrix, and the machine-readable compliance evidence (OSCAL, CSV, PDF) needed to satisfy an Inspector General review.
Built by federal cyber operators. Designed for the auditor — IG, Big-4, regulator — on the other side of the desk.
What an engagement could look like
Intrepid's COMET engagements are designed to ride a three-tier ladder. Each tier maps to the agency's stage in the governance buildout:
- Assessment (4–6 weeks). Map the organization's current AI use-case inventory against the controlling obligations — M-24-10 (federal), Colorado AI Act / NIST AI RMF (commercial), or sector-specific US regimes. Identify gaps. Deliver a baseline governance posture report with framework cross-reference.
- Delegation roadmap (12 weeks). Build the framework architecture for the organization. Produce evidence templates, delegation-ceiling decision trees, and a trained-operator handoff. Customer leaves the engagement self-sufficient.
- Strategic retainer (ongoing). For organizations in steady-state production. New use cases come in; COMET classifies them; new regulations are absorbed; audit cycles run cleanly.
About Intrepid
References
- MIT NANDA — State of AI in Business 2025. nanda.media.mit.edu
- OMB Memorandum M-24-10 — Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence, March 28, 2024. whitehouse.gov
- GAO-24-105980 — Artificial Intelligence: Agencies Have Begun Implementation but Need to Complete Key Requirements, December 2023. gao.gov
- NIST AI Risk Management Framework 1.0 (NIST AI 100-1), January 2023. nist.gov
- NIST AI 600-1 — Generative AI Profile, July 2024. nist.gov
- DoD Responsible AI Strategy & Implementation Pathway, June 22, 2022. ai.mil
- Stanford HAI — AI Index 2025. hai.stanford.edu
- Colorado Artificial Intelligence Act (SB 24-205), signed May 17, 2024 by Gov. Jared Polis; effective February 1, 2026. leg.colorado.gov