Notes from a closed-door ClairX roundtable with senior UK and European enterprise leaders on what actually stands between AI pilots and accountable production systems.
We recently brought together senior leaders for a closed-door roundtable: CIOs, heads of transformation, and risk and governance leads from financial services, the public sector and regulated industry across the UK and Europe. The brief was simple. What is really getting in the way of enterprise AI?
The conversation moved past technology within the first ten minutes. It settled instead on the things that decide whether any of this survives contact with a regulator, a board or a workforce: governance, operating models, adoption and trust.
"Nobody in the room was arguing about whether the models are good enough. Everyone was arguing about who is accountable when they are wrong."
That, in one sentence, is where enterprise AI sits in mid-2026. The industry has stopped debating whether AI works. It is now debating whether anyone can be held accountable for what it does.
What the numbers say
2026 was supposed to be the year enterprise AI grew up. In one sense it has. Adoption has run ahead of what most analysts predicted twelve months ago. The scaffolding around it has not.
McKinsey's State of AI Trust in 2026 survey, run across roughly 500 organisations with direct responsibility for AI governance, risk or investment, found that responsible-AI maturity has improved overall. Look closer and the picture is less comfortable. Only around a third of organisations have reached a level of governance maturity capable of overseeing the agentic systems they already operate, and nearly two thirds now name security and risk concerns as the single biggest barrier to scaling further.
Gartner tells a similar story from a different angle. Task-specific agents are set to appear in 40% of enterprise applications by the end of this year, up from under 5% twelve months ago. Gartner also expects a comparable share of agentic AI projects to be abandoned by 2027, mostly over governance failures and unclear returns.
Adoption data and governance maturity data, side by side. The gap between them is the story.
Capability is outrunning accountability. Every leader in the room recognised the pattern because they are living it. And, as the discussion kept coming back to, this is not a model problem. It is an operating model problem.
Why this lands harder in the UK and Europe
If you operate in the UK or the EU, the governance gap is no longer an internal matter.
The EU AI Act's compliance clock is running. Brussels adopted the Digital Omnibus in June, which pushed the high-risk obligations back: December 2027 for stand-alone Annex III systems, August 2028 for AI embedded in regulated products. The headlines called it a delay. Read the detail and it is a narrower reprieve than it sounds. The Act's transparency rules under Article 50 still apply from 2 August 2026. That covers chatbot notices, labelling of AI-generated and deepfake content, and disclosure duties that touch most customer-facing AI. New prohibitions arrive in December 2026. Supervisors have also been clear that the extra runway on high-risk systems is meant for conformity work, not a pause.
Financial services firms have been living with this logic since January 2025, when DORA turned operational resilience, including resilience of AI-dependent services and their ICT suppliers, from good practice into a regulatory obligation.
The UK has taken a different route to a similar destination. There is no single AI statute. Instead the FCA, PRA, ICO and other sector regulators apply existing rules to AI systems today, and they have said repeatedly that "the algorithm did it" is not a defence. In the public sector, buyers already expect DCB0129-style safety cases, DPIAs and algorithmic transparency records as a condition of procurement rather than an afterthought.
The UK and EU compliance clock, 2025 to 2028. The Digital Omnibus moved some deadlines. It did not move the question of accountability.
So the question our roundtable kept circling, "who is accountable when the system is wrong?", is not a philosophical one in this market. It is the question a supervisor, an auditor or a tribunal will ask first.
Four themes from the discussion
Two hours of conversation kept resolving into the same four themes. None of them is about model capability.
The four themes senior leaders kept returning to, none of which is solved by a better model.
1. Governance built in, not bolted on
The organisations further ahead treat governance as part of the design brief rather than a compliance step added after the first incident. Model risk, explainability, audit trails and escalation paths get decided before go-live. Nobody wants to reconstruct how a decision was made while a regulator waits on the phone.
2. Operating models over one-off projects
The sharpest divide in the room was structural, not technical. Who owns an agent once it is live? Who retrains it, who monitors drift, who answers for it six months after the launch deck has been forgotten? Without a standing operating model, even a successful pilot has nowhere to go. Several leaders admitted the honest answer in their organisation today is "nobody, yet".
3. Adoption that survives contact with the business
There was no shortage of candour on this one. Most organisations represented have plenty of demos. What they lack is evidence that day-to-day work has actually changed, rather than the AI sitting alongside it as a novelty. The distinction that stuck: pilots people admire versus systems people rely on.
4. Trust as the real scaling constraint
Every theme eventually came back to trust. Trust from regulators, from boards, from the employees expected to rely on these systems, and in the public sector from citizens. The consensus was blunt: trust is not a soft add-on to an AI programme. It is the mechanism that decides whether the programme scales at all.
Where this leaves enterprise leaders
If the honest answer to "could we explain how that decision was made?" is currently "not really", that is not a failing unique to your organisation. On McKinsey's numbers it is roughly where two thirds of the market sits. In the UK and the EU, though, the window for that answer being survivable is closing on a published schedule.
The leaders getting this right are not necessarily running the flashiest use cases. They have quietly reframed the question, from "what can AI do for us?" to "what does it take to run AI safely, continuously and at scale, inside an organisation that answers to a regulator, an auditor or an electorate?"
That reframing is where the work starts: governance designed in from day one, a named owner for every system in production, adoption measured in changed workflows rather than completed pilots, and trust treated as an engineering requirement with evidence behind it.
That is the conversation we will keep having, in the room and here. More on each of these four themes to follow in this series.
Sources referenced : McKinsey & Company, State of AI Trust in 2026: Shifting to the Agentic Era (survey conducted Dec 2025 to Jan 2026), Gartner, 2026 Hype Cycle for Agentic AI and related 2026 CIO and agentic AI adoption forecasts, Regulation (EU) 2024/1689 (EU AI Act), as amended by the Digital Omnibus on AI adopted June 2026, Regulation (EU) 2022/2554 (DORA), applicable from 17 January 2025