Contents
- The short answer
- Why the annual AI plan keeps breaking
- First, fix the number you are benchmarking against
- The two-clock model
- The no-regret test: decide now or buy information
- What this looks like over four quarters
- Common mistakes
- Limitations of this guidance
- Frequently asked questions
- Related MASSIVUE resources
- Sources
Capability is doubling on a three to seven month cycle and the compliance dates keep moving. Here is how to build an AI plan that does not need rewriting every quarter.
By Sandeep Joshi, Founder and Managing Director of MASSIVUE, an enterprise AI adoption firm building structured learning infrastructure for APAC enterprises. Published by MASSIVUE. Last reviewed: August 2026.
The short answer
You plan for AI by putting your decisions on two different clocks. A small set of decisions genuinely depends on what the models can do this quarter, and those should be re-decided every quarter. A larger set does not change when the model changes: who holds decision rights over AI, what data you may lawfully use, who answers when an output is wrong, and how people are retrained and redeployed. Those are operating model decisions, they hold for years, and they are the ones worth committing to now.
The test for sorting a decision is a single question. If the answer changes when the model changes, it belongs on the fast clock. Everything else belongs on the slow clock, and re-opening it every quarter is one of the more reliable ways to stall an AI programme.
Why the annual AI plan keeps breaking
Two things moved underneath enterprise AI plans in the last eighteen months, and they moved in opposite directions.
The capability clock is faster than a planning cycle
METR measures how long a task an AI agent can complete autonomously, calibrated against how long the same task takes a human professional. In its January 2026 update, the time horizon at which a frontier model succeeds half the time was doubling every 196.5 days measured from 2019, every 130.8 days measured from 2023, and every 88.6 days measured from 2024. The leading model at that point had an estimated fifty percent time horizon of 320 minutes.
Whatever the exact rate, all three figures are shorter than an annual planning cycle. A plan that fixes an assumption about what AI can do, and then holds that assumption for twelve months, is making a bet the measured trend does not support.
The caveats matter as much as the headline, and most summaries drop them. METR's confidence interval on that 320 minute figure runs from 170 to 729 minutes. The task set is 228 tasks drawn from software engineering, machine learning and cybersecurity, and of the 31 long tasks only five have measured human baseline times. METR is explicit that a time horizon of a given length does not mean an AI can do that much of the work of a professional who already has context on the project. So the trend is real and fast, and it is not a forecast of which jobs get automated. It tells you how often to revisit a capability assumption, not what the answer will be.
The regulatory clock moved, but not in the direction most people assume
On 24 July 2026 the European Union published Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026, six days before the AI Act's high-risk obligations were due to apply. It deferred the obligations for standalone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for AI embedded in products already covered by EU product safety law under Annex I from 2 August 2027 to 2 August 2028.
Read carelessly, that looks like a reprieve. It is not. The Article 50 transparency obligations still applied from 2 August 2026, with a grace period to 2 December 2026 for marking content produced by systems already on the market. More importantly, nothing about the substance changed. The obligations that were coming are still coming. What moved was the date, and it moved because the harmonised technical standards needed to demonstrate compliance were not ready.
This is the pattern worth internalising. Compliance dates are negotiable and they have now visibly moved. The underlying requirement to know what your AI systems do, who is accountable for them, and what data went into them has never moved. An enterprise that built the second thing is unaffected by changes to the first.
First, fix the number you are benchmarking against
Before deciding anything, correct the adoption figure in your board pack. Two credible sources published very different numbers for the same period, and boards are routinely shown the higher one without the qualifier.
| Source | Reported AI use | What it sampled |
|---|---|---|
| Stanford HAI, 2026 AI Index | 88% of organisations | Organisations responding to a global AI survey, weighted toward larger enterprises |
| US Census Bureau, Business Trends and Outlook Survey | 17% to 20% of firms nationally | A probability-based survey of US employer businesses of all sizes |
| Same survey, firms with 250 or more employees | 37% | The subset closest to an enterprise peer group |
| Same survey, Information sector | 39.7% | The highest-adoption sector measured |
The gap is not a contradiction and neither source is wrong. It is a sampling difference. The Census Bureau surveys the whole population of US employer businesses, most of which are small. The AI Index figure describes organisations that responded to a survey about AI. Since November 2025 the Census question has asked about AI use in any business function, which is close to the phrasing behind the higher figure, so wording no longer explains the difference. The sample does.
The practical consequence: if you are a large enterprise, 88% is not your peer benchmark and neither is 20%. The closest published comparator is the 37% of US firms with 250 or more employees, and even that counts any use in any function rather than deployment at scale. Treating 88% as the bar produces a manufactured sense of lateness, which is a poor basis for capital allocation and an excellent basis for buying tools you have not scoped.
Two further figures from the 2026 AI Index are worth holding alongside it. Agent performance on the OSWorld computer-use benchmark rose from 12% to roughly 66% task success, and agents still fail about one attempt in three on structured benchmarks. Documented AI incidents rose to 362 in 2025 from 233 in 2024. Capability and failure are compounding together.
The two-clock model
The planning problem is not that things change. It is that enterprises apply one cadence to decisions that change at very different rates. Vendor selection and decision rights end up in the same annual document, so either the document is rewritten constantly or the slow decisions never get made at all.
Separating them is the fix. Sort every decision in the AI plan by how quickly its right answer changes, then give each set its own cycle.
Fast clock decisions are the ones a capability jump invalidates: which model and vendor, which tasks are worth automating, how many tool seats to buy, what a pilot should try to prove. Given a doubling time measured in months rather than years, review these quarterly and expect to change your mind. Design them to be cheap to reverse. Avoid multi-year commitments to a specific model, and prefer architectures where swapping the underlying model is a configuration change rather than a rebuild.
Slow clock decisions are the ones a capability jump does not touch. Who is allowed to authorise an AI system for a given class of decision. What data the organisation may lawfully use, and how that is evidenced. Who is accountable when an output is wrong, and how that failure is detected. How people whose work changes are retrained and where they go next. None of these have a different answer because a better model shipped. They take quarters to build, and they are what a compliance date, whenever it lands, will actually test.
This is the layer MASSIVUE builds through Protum, its AI operating model framework, and it is why the deferral of the EU high-risk date changes very little for organisations that were already building it. The fuller argument for why the operating model is the durable asset is set out in What Is an AI Operating Model?.
The failure mode when the two clocks are merged is well documented. Gartner predicts that more than 40% of agentic AI projects will be cancelled by the end of 2027, and attributes the cancellations to escalating costs, unclear business value and inadequate risk controls rather than to model limitations. Those are all slow clock failures surfacing inside fast clock projects.
The no-regret test: decide now or buy information
Sorting decisions by clock speed tells you how often to revisit them. It does not tell you whether to commit today. For that, four questions are enough.
- Does the answer change if capability doubles? If yes, it is a fast clock decision and it can wait for the next quarterly review unless there is a real cost to waiting. If no, waiting buys you nothing at all.
- Would we still need this if we changed vendor tomorrow? If yes, it is infrastructure rather than a bet. Data lineage, access control, an inventory of where AI touches customer decisions, and a retraining route for affected roles all survive any vendor change.
- Who carries the cost of being wrong? If the cost falls on a customer, an employee or a regulator rather than on your own budget, the controls come first and the deployment waits. This is the question that separates a defensible pilot from an incident.
- Can we reverse this within one quarter for less than the cost of the delay? If yes, decide now and learn from it. If no, spend the quarter buying information instead: a scoped trial, a shadow run, a measured baseline.
Most enterprise AI decisions that feel paralysing turn out to be question two in disguise. They are not bets on a technology trajectory at all. They are infrastructure that has been deferred because it was filed alongside genuine bets.
What this looks like over four quarters
| Clock | Decision | Cadence | What good looks like |
|---|---|---|---|
| Slow | Decision rights: who may authorise AI for which class of decision | Set once, review annually | A named accountable owner for every AI system touching a customer or employee outcome |
| Slow | Lawful data basis and lineage | Set once, maintained continuously | You can answer what data trained or grounded a given output without launching a project to find out |
| Slow | Workforce redesign and retraining routes | Rolling, reviewed half-yearly | Affected roles have a named destination before the tool arrives, not after |
| Fast | Model and vendor selection | Quarterly | Swapping the model is a configuration change, and the contract term matches the review cycle |
| Fast | Which tasks to automate next | Quarterly | Re-scored against current capability rather than against last year's assessment |
| Fast | Pilot scope and success criteria | Quarterly | Every pilot has a kill criterion agreed before it starts |
The asymmetry is the point. Three of these take quarters to build and then hold for years. Three should be cheap enough to change that reversing one is unremarkable. If your situation is inverted, with vendor commitments that are hard to unwind and decision rights that are still unassigned, the plan is on the wrong clocks.
Common mistakes
- Benchmarking against 88%. It is a real figure from a real source, and it is not a statement about the typical enterprise. Using it as a peer comparison manufactures urgency and funds tooling ahead of scoping.
- Treating the EU deferral as breathing room. The date moved because the standards were not ready. The obligations did not change, and the work they require takes longer than the extension granted.
- Signing model commitments longer than the review cycle. A three-year commitment to a specific model is a bet against a doubling time measured in months. Match contract terms to the clock the decision sits on.
- Reading benchmark progress as job displacement. METR measures low-context software, machine learning and cybersecurity tasks. It is a rate-of-change instrument, not a workforce forecast, and its authors say so.
- Re-opening decision rights every planning round. Authority over AI decisions is a slow clock item. Reconsidering it each quarter guarantees it is never actually assigned, which is the condition most stalled programmes share.
- Running pilots without a kill criterion. Gartner attributes agentic project cancellations to unclear business value and cost, not to model capability. A pilot with no agreed failure condition cannot produce a decision.
Limitations of this guidance
The capability trend rests on one measurement programme with wide confidence intervals, a task set concentrated in software, machine learning and cybersecurity, and only five measured human baselines among its long tasks. If your work is not software-shaped, treat the doubling times as an indication that capability assumptions decay quickly, not as a rate that applies to your functions.
The adoption comparison is drawn from a US survey and a global one. The Census figures describe US employer businesses and do not transfer directly to other markets. The AI Index organisational figure is not a probability sample, so it should not be read as a population estimate anywhere.
The regulatory position described here is the EU one as at August 2026. Other jurisdictions are moving on their own timetables, and the EU dates have already moved once. The two-clock argument does not depend on any particular date holding, which is rather the point, but any specific date in this article should be re-checked against the source before it is relied on.
Frequently asked questions
How long should an enterprise AI plan be?
Use two horizons rather than one. Capability-dependent choices such as model selection, automation targets and pilot scope should be reviewed quarterly, because measured agent capability has been doubling on a cycle of roughly three to seven months. Operating model choices such as decision rights, data lineage, accountability and workforce redeployment should be set on a multi-year horizon, because they do not change when the model changes and they take quarters to build.
Why do AI adoption statistics disagree so much?
Mostly because of who was sampled. Stanford HAI's 2026 AI Index reports 88% organisational adoption from a global survey of organisations that responded to a questionnaire about AI. The US Census Bureau's Business Trends and Outlook Survey reports 17% to 20% of US firms, because it samples the whole population of employer businesses, most of which are small. Among US firms with 250 or more employees the figure is 37%. Since November 2025 both are asking about AI use in any business function, so the wording no longer accounts for the gap.
Did the EU AI Act high-risk deadline actually move?
Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published on 24 July 2026 and entered into force on 27 July 2026. It moved the obligations for standalone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products under Annex I from 2 August 2027 to 2 August 2028. The Article 50 transparency obligations still applied from 2 August 2026, with a grace period to 2 December 2026 for marking content from systems already on the market.
Should we wait for the technology to settle before committing?
Waiting only helps for decisions whose right answer changes when capability changes. It does not help for data lineage, access control, accountability, or knowing where AI already touches customer decisions, because those are needed under any technology trajectory and take longer to build than any plausible pause. If a decision would survive changing vendor tomorrow, waiting costs you time and buys you nothing.
What is the first thing to fix if our AI plan keeps getting rewritten?
Separate the plan into the decisions that a capability jump invalidates and the decisions it does not, and stop reviewing them on the same cycle. In most organisations the rewriting is caused by a small number of genuinely volatile items dragging a much larger set of stable operating model decisions back open each round.
Related MASSIVUE resources
- What Is an AI Operating Model? sets out how decision rights over AI are allocated, which is the core of the slow clock described here.
- Why Your AI Strategy Needs an Operating Model makes the case for why strategy without an operating model does not survive contact with delivery.
- Why Enterprise AI Pilots Stall Before Production covers the delivery-side failure modes behind the cancellation statistics cited above.
- Agentic AI Governance covers the control layer that the deferred high-risk obligations will eventually test.
- How to Manage Change During Enterprise AI Transformation covers the workforce redesign and retraining routes named on the slow clock.
- Protum, MASSIVUE's AI operating model framework, builds the six business capabilities that make AI and human work coordinate.
- AI Transformation and Enterprise Transformation are the service lines behind this article.
- In MASSIVUE Academy, Digital Strategy for AI Business Success covers the part competitors cannot copy, including business model, proprietary data, workflow depth and operating model. AI for Business Executives (AIBE) is the shorter strategic briefing for leaders who need the decision frame rather than the delivery detail.
Sources
Each figure above was checked against the publisher's own material at the last review of this article. Where a source is preliminary, narrowly scoped or based on a non-probability sample, that is stated at the point of use.
- METR, Time Horizon 1.1, 29 January 2026. Doubling times of 196.5 days since 2019, 130.8 days since 2023 and 88.6 days since 2024; 228 tasks; frontier 50% time horizon of 320 minutes with a 170 to 729 minute confidence interval. https://metr.org/blog/2026-1-29-time-horizon-1-1/
- METR, Task-Completion Time Horizons of Frontier AI Models. Methodology and stated limits on interpreting time horizons as real-world work. https://metr.org/time-horizons/
- European Union, Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal, 24 July 2026, in force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes, 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- Hunton Andrews Kurth, EU Digital Omnibus on AI Enters Into Force, 2026. https://www.hunton.com/privacy-and-cybersecurity-law-blog/eu-digital-omnibus-on-ai-enters-into-force
- Stanford HAI, 2026 AI Index Report. Organisational adoption of 88%; OSWorld agent task success from 12% to roughly 66%; 362 documented AI incidents in 2025 against 233 in 2024. https://hai.stanford.edu/ai-index/2026-ai-index-report
- US Census Bureau, Large Firms With at Least 20 Employees Biggest AI Users, May 2026. Business Trends and Outlook Survey, data collection 14 December 2025 to 3 May 2026; question revised in November 2025 to ask about AI use in any business function. https://www.census.gov/library/stories/2026/05/ai-use-businesses.html
- US Census Bureau, Business Trends and Outlook Survey, programme page and methodology. https://www.census.gov/programs-surveys/btos.html
- Gartner, Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027, 25 June 2025. https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027