
The AI risk everyone forgets is the rollout
Most AI risk conversations are about the model. The risk that quietly kills more AI initiatives is the rollout.
I have spent 20 years on the human side of technology in regulated industries: customer experience, voice of customer, transformation. The pattern I keep seeing with AI is the same one I saw with every big system before it. The technology works, and the initiative still fails. Not because the model was wrong. Because nobody planned for the people.
Three risks that live outside the model
Change management and customer experience are built to reduce them.
1. Adoption risk. You can ship a capable AI tool and watch it go unused. A pilot that returns nothing usually failed on approach, not technology. Change management is the difference between a tool that exists and a habit people trust.
2. Shadow risk. When a rollout is confusing or slow, people do not stop using AI. They go around you. Poor change management does not reduce AI use, it just pushes it into the shadows where nobody is governing it.
3. Customer-experience risk. This is the one the governance conversation misses most. An AI system can be technically sound, fully compliant, and still deliver an experience that erodes trust, especially for customers who are already stressed, vulnerable or in hardship. Compliant is not the same as kind. A wrong tone at the wrong moment does real damage, and no control catches it.
What it looks like on the ground: the handover
In a contact centre, an AI agent now handles the front of a customer conversation and hands over to a human the moment it hits something sensitive: a complaint, a hardship case, a vulnerable customer. The whole initiative lives or dies on that handover. Hand over too late and the customer has already been hurt. Hand over too early and you have automated nothing. Getting that line right is not a model problem. It is a change and CX problem.
And the factor that decides it is trust: how much the human team actually trusts the AI. This is the part almost no rollout measures. Too little trust and your agents quietly override the AI on everything, so you carry the cost and capture none of the benefit. Too much trust, blind trust, and they wave through AI decisions they should have caught, which in a hardship or complaints setting is exactly where real harm happens. Blind trust hurts as much as low trust. What you want is calibrated trust: the team knows when to lean on the AI and when to step in. Measuring that trust, and building it, is change-management and CX work, not engineering.
There is one more thing those human agents are doing that rarely gets credited. Every time they take over, correct a response, or handle what the AI could not, they are teaching the system. Their judgement at the handover is the signal that makes the next version better. Treat them as a cost to be stripped out and you lose your best source of improvement. Treat them as part of the loop and the AI gets safer over time.
Delivered is not embedded. Embedded is not sustained.
This is the gap most programmes never close. A go-live is an event. Adoption is a habit. Value that keeps working is a discipline. All three are change-management work, and they are where the return actually comes from. I have written before about why value sustained is the half of the AI value case most dashboards miss.
Three legs, not one
So reducing AI risk is not one job. It is three legs. Control it, so it is safe. Embed it, so it is used well. And keep watching the customer outcome, so it stays worth doing. Most organisations invest in the first leg and hope the other two happen on their own. They do not.
Governance done well should enable all three, not just police the first. Fast where it is safe, so adoption is not smothered. And honest about whether the thing is still being used well and still helping the customer, not just whether it shipped.
The best AI governance I have seen was never only technical. It had a change manager and a customer lens in the room from the start.
So the honest question: what is your bigger AI risk right now, the model, or the rollout?
This is the thinking behind GatedFlow: make governance proportionate, fast where it is safe, so it enables adoption instead of smothering it, and keep asking whether a use case is still delivering, not just whether it shipped. The change and customer-experience work still sits with your people; the system should make room for it, not crowd it out.