▰ TL;DR

MIT NANDA reports 95% of enterprise generative-AI pilots fail to deliver measurable profit-and-loss impact[1] — the finding is industry-wide, across federal agencies and commercial enterprises alike. On the federal side, OMB M-24-10 (March 2024)[2] mandates every agency designate a Chief AI Officer, and GAO has counted 1,757 active or planned federal AI use cases[3]. On the commercial side, US sector-specific regimes — Federal Reserve SR 11-7 (bank model risk management), NYDFS Part 500 (financial services cybersecurity), and FDA AI/ML SaMD (medical devices) — set the baseline, and the Colorado Artificial Intelligence Act (signed May 2024, effective February 2026)[8] is the first comprehensive US state-level high-risk-AI law. Stanford HAI counted 59 new US AI regulations in 2024 alone[7]. NIST AI RMF[4] and the AI 600-1 Generative AI Profile[5] are converging as the cross-sector reference. The technology is ready; the governance scaffolding is not. This piece walks the role-by-role workflows AI could enable in a cyber program — federal or commercial — the regulatory floor those workflows have to clear, and what bridging the gap could look like in practice.

Where AI is failing cyber programs today

The headline number is the same one MIT NANDA's State of AI in Business 2025[1] reports for enterprise GenAI broadly: 95% of pilots fail to deliver measurable P&L impact. MIT names the failure modes: missing learning loops, integration gaps, governance scaffolding, and workflow adaptation. Inside cyber programs — federal and commercial — the same failure modes show up in domain-specific shapes:

MIT also finds that vendor-led implementations succeed roughly twice as often as internal builds — 67% vs. 33%[1]. For any cyber program running internal AI builds without a governance partner, that ratio compounds the 95% failure rate. The cost isn't just wasted budget. It's audit deficiency, regulator exposure, and — for federal agencies — erosion of authorization to operate AI at all; for commercial enterprises, board-level risk and potential fines under cross-border regimes.

95%
Of enterprise generative-AI pilots fail to deliver measurable P&L impact — across federal and commercial enterprises. The failure modes — delegation boundary ambiguity, missing audit evidence, no regulatory citation chain — are why. MIT NANDA · State of AI in Business 2025

What good AI could look like for cyber programs — by role and task

Imagine the same cyber program — federal or commercial — with the governance scaffolding in place. The AI doesn't change. It's the same large language models, the same agent frameworks, the same automation primitives. What changes is that every workflow has a documented delegation ceiling, a regulatory citation chain, and machine-readable audit evidence on the back end. Three roles, the workflows each could run:

Role · Chief AI Officer (CAIO) / Head of Responsible AI

Single source of truth for every AI use case

Role · Cyber program lead / CISO

AI-augmented operations with defensible bounds

Role · Auditor / IG liaison / Compliance officer

Machine-readable governance evidence on every AI use case

The non-negotiable — governance is the bottleneck

None of the role-by-role workflows above are possible without disciplined governance underneath. And neither federal nor commercial cyber programs have the option to defer the governance work. The regulatory floor solidified between January 2023 and August 2024, with parallel mandates on both sides:

The slope is steepening, not flattening. Stanford HAI's 2025 AI Index[7] counted 59 new US federal AI-related regulations introduced in 2024 — more than double the 25 counted in 2023. US state-level AI regulation is following the curve: Colorado leads with SB 24-205; California, New York, Texas, Connecticut, and Illinois have all introduced or passed comparable bills. Any cyber program — federal or commercial — that builds governance scaffolding once and abandons it will fall out of compliance within a quarter. What's needed is a framework engine that absorbs new standards as they emerge and produces audit-defensible deliverables in weeks, not quarters.

Introducing ARKONA + COMET

ARKONA + COMET — the platform and the framework

ARKONA is Intrepid's multi-tenant agent + governance platform. COMET is the AI-governance framework that runs on it.

COMET is designed as a deterministic citation-to-delegation engine. Feed it a free-text description of an AI task — "auto-summarize incoming threat-intel reports for the watch floor" — and it returns a structured artifact: the applicable regulatory citations (NIST AI RMF, AI 600-1, DoD RAI, Colorado AI Act, agency- and sector-specific US guidance), the recommended delegation ceiling on a five-level taxonomy (advisory only → fully autonomous within audited bounds), the responsible-accountable-consulted-informed matrix, and the machine-readable compliance evidence (OSCAL, CSV, PDF) needed to satisfy an Inspector General review.

Built by federal cyber operators. Designed for the auditor — IG, Big-4, regulator — on the other side of the desk.

What an engagement could look like

Intrepid's COMET engagements are designed to ride a three-tier ladder. Each tier maps to the agency's stage in the governance buildout:

About Intrepid

INT
Intrepid Cybersecurity Engineering & Consulting, LLC is a Maryland-based veteran-owned firm offering strategic AI-governance consulting (COMET) and platform subscriptions (ARKONA) to federal cyber operators, GovCon primes, and regulated commercial enterprises — financial services, healthcare, energy, and beyond. Founded by Jhon B. Arango (NSA Computer Network Operations Development Program graduate, 20+ years DoD systems engineering, including director-level operations roles at NSA-aligned cyber units at Fort Meade) and Jonathan A. Arango, MBA (11 years enterprise sales leadership in networking & security at NASDAQ-listed ScanSource).

Briefings on AI-governance engagements: jhon.arango@intrepidcyber.ai

References

  1. MIT NANDAState of AI in Business 2025. nanda.media.mit.edu
  2. OMB Memorandum M-24-10Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence, March 28, 2024. whitehouse.gov
  3. GAO-24-105980Artificial Intelligence: Agencies Have Begun Implementation but Need to Complete Key Requirements, December 2023. gao.gov
  4. NIST AI Risk Management Framework 1.0 (NIST AI 100-1), January 2023. nist.gov
  5. NIST AI 600-1Generative AI Profile, July 2024. nist.gov
  6. DoD Responsible AI Strategy & Implementation Pathway, June 22, 2022. ai.mil
  7. Stanford HAIAI Index 2025. hai.stanford.edu
  8. Colorado Artificial Intelligence Act (SB 24-205), signed May 17, 2024 by Gov. Jared Polis; effective February 1, 2026. leg.colorado.gov