Many enterprises are still gauging their AI maturity by the volume of their activity: the number of models deployed, the breadth of their ‘AI labs,’ or the scale of pilots launched. In reality, a far more sophisticated measure of a firm’s operational health – and its ultimate return on investment – is how many of those initiatives it actually has the discipline to stop.
The corporate landscape is becoming haunted by what industry insiders call an ‘AI graveyard.’ Recent data suggests that roughly 88% of AI proof-of-concepts never reach full production. This creates a trail of semi-deployed models, orphaned chatbots, and forgotten experimental pilots. These systems do not simply vanish; they often linger as ‘zombie’ processes, quietly accumulating costs and technical risk without delivering value.
The failure here is not that these initiatives failed fast, a celebrated mantra of the agile era, but that they fail slow. They don’t achieve the scale required for a positive business case, yet they are never definitively shut down.
The rise of ‘zombie’ AI
This accumulation of ‘zombie’ AI represents a governance crisis that many boards are only beginning to grasp. The symptoms are increasingly visible across major organizations: pilots running on obsolete data with no clear internal owner; duplicative solutions for the same business problem fragmented across different departments; or rogue integrations where experimental outputs feed into live business processes without proper oversight.
Beyond the immediate waste of cloud computing resources and human capital, every unmanaged model left in production can erode the very foundations of corporate accountability and trust. For the modern CEO and CIO, the critical strategic question has shifted. It is no longer, ‘How do we start more AI projects?’ but rather, ‘Which of our existing systems should we pull the plug on?’
From cradle to grave: The regulatory shift
The shift in landscape means that while boards have historically obsessed over the ‘go-live’ moment, global regulators and standards bodies are now starting to focus on the finish line for AI projects. A new wave of governance frameworks is demanding full lifecycle discipline, mandating that AI be managed from cradle to grave. This includes:
• ISO/IEC 22989 & 42001: These international standards define a formal lifecycle for AI that concludes with an explicit retirement phase. They require organizations to periodically re-evaluate and, if necessary, retire solutions as a core tenet of continuous improvement and good governance.
• The NIST AI Risk Management Framework: This US-led standard emphasises that risk management is a continuous process, rather than a one-time event. Organizations are expected to monitor performance throughout the operational life of the system and be prepared to disable models that pose unacceptable risks.
• The EU AI Act: Article 72 of the forthcoming legislation mandates that providers of high-risk AI conduct rigorous post-market monitoring. Firms must actively track an AI’s behaviour over its entire lifetime and intervene, or shut it down, to maintain safety and compliance.
• UK and US Security Guidance: Both the NCSC and CISA stress that security controls must remain active until a system is fully decommissioned, treating decommissioning as a high-stakes security event.
The message from these frameworks is clear: true AI governance means managing the end-of-life as rigorously as the launch.
Rigorous AI governance
The pattern of spinning up endless pilots without a conclusion plan often before a form of innovation theatre. Statistics show that only 4 out of every 33 AI pilots reach full production; the rest stay in a state of limbo that creates significant hidden liabilities.
The first liability is technical and security debt. In other words, unmanaged systems running on outdated data or code become unaddressed vulnerabilities, raising the risk of cybersecurity breaches and system instability.
The second risk is regulatory exposure. Under laws like the EU AI Act, a neglected model that drifts out of compliance can lead to substantial fines long after the initial project team has moved on.
And third, there is the erosion of trust. Each half-baked AI initiative that is unceremoniously abandoned makes executives, employees, and customers more sceptical of the next deployment.
Ultimately, if AI is to be a true business capability, it must be governed with the same rigor as any mission-critical asset. This requires the cultural and operational willingness to sunset systems that no longer serve the organization’s risk tolerance or strategic goals.
A hallmark of enterprise maturity
To avoid a growing graveyard, firms should design and follow a structured decommissioning process. This is not a sign of project failure, but a hallmark of institutional maturity. Key components include:
• Retirement triggers: Establish clear metrics for shutdown, such as performance dips, the emergence of superior solutions, or new regulations, at the start of every project.
• Evidence preservation: Before shutdown, archive essential documentation, data, and model artifacts to ensure a record remains for future audits and accountability.
• Dependency unwinding: Systematically map and disconnect the system from data feeds and downstream processes to prevent operational ‘breakage’ when the AI is turned off.
• Stakeholder transition: Notify and support those who rely on the system, providing alternative workflows to prevent gaps in productivity.
• Infrastructure shutdown: Deprovision cloud instances and databases to cut unnecessary costs and eliminate the risk of ‘zombie’ processes running unattended.
• Post-retirement learning: Examine why the system reached its end-of-life to feed those insights back into the next generation of development.
The value of stopping power
The most successful AI-driven enterprises of the next decade won’t be those that simply launched the most pilots. They will be the ones with the discipline to shut off what isn’t working and refocus their energy on what is. It is time to add ‘sunsetting’ to the enterprise AI playbook.
For the modern CEO and CIO, that means AI maturity will soon be measured not by how many experiments they start, but also by what they’re willing to stop. Done well, this isn’t about failure – it’s about focus. The organisations that build the confidence to switch things off will be the ones that free up the capital, talent and attention needed to scale what truly works – and will pull ahead because of it.