The Great AI Paradox: When Enthusiasm Outruns Governance
Why the latest enterprise data reveals a behavioural science problem, not a technology one.
Why the latest enterprise data reveals a behavioural science problem, not a technology one.
Here is a number that should stop you in your tracks: 78% of global companies now use AI in their business. Generative AI adoption has surged from 33% to 71% in two years. Worldwide AI spending is projected at $1.5 trillion in 2025. The enterprise AI market alone is heading toward $97.2 billion this year, with compound annual growth rates exceeding 30%.
And yet.
Only 29% of organisations report seeing significant ROI from their generative AI investments. 79% faced challenges adopting AI in 2026, a double-digit increase from the year before. 77% of businesses cite AI hallucinations as a significant concern. 52% say data quality and availability remain the primary barrier to adoption.
Read those two paragraphs again. The first is a sprint. The second is a stumble. And they are describing the same organisations, in the same fiscal year, with the same budgets and the same leadership teams.
This is not a technology problem. The technology works. It works spectacularly well in the right conditions. What the data actually reveals is a behavioural science problem, one that the STAR Framework was designed to explain, and one that two of its seven theoretical pillars illuminate with uncomfortable precision.
The Compass and the Processor
If you have read anything about the STAR Framework, you will know that it operates as a Human Operating System. Four mindsets. Twelve archetypes. Seven psychological theories doing the heavy lifting behind the scenes. Two of those theories are doing particularly heavy lifting right now, in the middle of the most significant technology adoption event since the internet.
The first is Regulatory Focus Theory, developed by E. Tory Higgins. It is the Compass layer of the STAR Operating System, and it explains the direction in which human motivation points. Higgins distinguished between two broad orientations: Promotion Focus, which is oriented toward growth, advancement, and the pursuit of gains; and Prevention Focus, which is oriented toward safety, responsibility, and the avoidance of losses.
The second is Dual Process Theory, most famously articulated by Daniel Kahneman. It is the Processor layer, and it explains the tempo at which decisions are made. System 1 is fast, associative, and intuitive. System 2 is slow, deliberate, and analytical.
Between them, these two theories explain virtually everything that is happening inside enterprise AI adoption right now. And the gap between the two is where the real story lives.
The Promotion-Prevention Split
Look at the enterprise data through the lens of Regulatory Focus Theory and a striking pattern emerges. Organisations are splitting into two distinct motivational camps, and the split is not along the lines you might expect. It is not large versus small, or tech versus traditional, or even cautious versus bold. It is a split in how organisations frame the very nature of AI adoption.
The promotion-focused camp sees AI as a growth engine. These are the organisations sprinting toward deployment, embedding AI agents into enterprise applications (79% adoption by mid-2025), and planning to increase their generative AI spending (92% over the next three years). They are sensitive to the presence of gains: new revenue streams, competitive advantage, operational efficiency. Their strategy is eager. Move fast. Seise opportunities. Tolerate higher levels of risk. When they succeed, they experience the cheerfulness and enthusiasm that Higgins described. When they fail, they experience dejection, but they recover quickly because the next opportunity is already in their peripheral vision.
The prevention-focused camp sees AI as a risk to be managed. These are the organisations where data sovereignty has become the dominant conversation, where 51% now rate sovereignty as “very important” (up from 42% just a year ago), and where 76% expect its importance to keep rising. They are sensitive to the presence of losses: data breaches, regulatory penalties, reputational damage, vendor lock-in. Their strategy is vigilant. Double-check details. Ensure stability. Move cautiously. When they succeed, they experience the quiescence and calm that Higgins described, the quiet satisfaction of having avoided a negative outcome. When they fail to act, they do not experience it as failure at all. They experience it as prudence.
Here is what makes this split so consequential: both camps are behaving rationally within their own regulatory orientation. The promotion-focused organisation is not reckless. The prevention-focused organisation is not timid. They are each pursuing success as they define it. The problem is that their definitions of success are fundamentally different, and the gap between them is widening.
The Data Sovereignty Paradox
The numbers on sovereign AI are particularly revealing. Over 95% of organisations recognise the importance of private and sovereign AI. That is near-universal agreement. And yet only 29% are prioritising it in a concrete, near-term way.
That 66-point gap between recognition and action is not an execution failure. It is a Regulatory Focus problem. The organisations that recognise sovereignty as important are operating in a prevention frame. They understand the risk. They can articulate the threat. But their prevention orientation means they are waiting for the “right” conditions before committing resources: a clearer regulatory landscape, a proven vendor solution, a competitor who moves first and survives.
Meanwhile, the promotion-focused organisations are not waiting. They are deploying, experimenting, and iterating. They are the ones driving the 78% adoption figure. They are also, crucially, the ones generating the 79% “challenges in adopting AI” figure, because their eager strategy means they are hitting problems that the prevention-focused camp has anticipated but not yet encountered.
The irony is sharp. The organisations that are moving fastest are discovering risks that the cautious organisations already feared. And the cautious organisations, having anticipated those risks, are now using them as evidence that their inaction was justified. Both camps feel vindicated. Neither is fully right.
The Enthusiasm-Rigour Gap
This is where Dual Process Theory enters the picture, and where the data becomes truly interesting.
System 1, the fast and associative engine, is driving the enthusiasm for AI. The intuitive appeal is enormous. AI promises speed, efficiency, novelty, and competitive advantage. For the Socialiser and Adventurer mindsets, whose cognitive architecture is optimised for rapid pattern recognition and opportunity mapping, AI is practically irresistible. Their System 1 is firing on all cylinders: this is new, this is powerful, this works. The “feeling of rightness” that Higgins describes is overwhelming.
System 2, the slow and deliberate engine, is where the rigour lives. And here is the problem: System 2 is metabolically expensive. It consumes significant cognitive resources. It requires sustained focus. In the context of enterprise AI adoption, System 2 is the voice asking: “Have we tested this properly? Do we understand the data pipeline? What happens when the model hallucinates? Who is accountable when this goes wrong?”
The enterprise data tells a clear story about which system is winning. 71% of organisations are regularly using generative AI. Only 29% are seeing significant ROI. That 42-point gap is the enthusiasm-rigour gap made manifest. Organisations are deploying AI at System 1 speed and then discovering, at System 2 speed, that deployment without governance is not adoption. It is experimentation masquerading as strategy.
Kahneman called this the Rationalisation Trap: System 1 reaches a rapid conclusion based on a motivational trigger, and instead of scrutinising the impulse, System 2 constructs a plausible narrative to justify it. In the enterprise AI context, the narrative sounds like this: “We need to move fast on AI or we will be left behind.” That is a System 1 conclusion, and it feels correct. System 2 then builds the business case, the implementation roadmap, the ROI projections, all in service of a decision that was already made intuitively.
The Thinker and Realist mindsets, whose cognitive architecture is designed for exactly this kind of scrutiny, are the ones sounding the alarm. They possess a higher “effort threshold” before experiencing cognitive fatigue. They are psychologically rewarded for the effort of analysis: the Thinker derives self-esteem from rigour, and the Realist derives safety from the avoidance of impulsive error. They are the ones asking the uncomfortable questions about data quality, about hallucination rates, about the gap between individual productivity gains and organisational ROI.
And they are being ignored. Not because they are wrong, but because the System 1 momentum of AI enthusiasm is so powerful that System 2 scrutiny feels like obstruction.
The Realist’s Moment
This brings us to the Realist, and to a claim that might seem counterintuitive in a culture that celebrates innovation and disruption: the Realist archetype has never looked more prescient.
The Realist is the most consistently prevention-focused mindset in the STAR Framework. Their entire psychological architecture is built to safeguard stability. For a Realist, success is the absence of disruption. They are the guardians of the bedrock, the ones who ensure that when the vision is launched, the foundations hold.
In the context of enterprise AI adoption, the Realist is the one asking the questions that the data now suggests everyone should have been asking all along. How much will this cost? Who is responsible? How do we maintain it? What are the failure modes? What happens to our data when it enters the model? These are not the questions of a Luddite. They are the questions of someone whose cognitive architecture is optimised for structural reliability.
The NTT DATA research from May 2026 is striking in this regard. It reveals that enterprise AI is “hitting the wall,” with growing privacy and sovereignty barriers creating friction that promotion-focused organisations did not anticipate. The BARC study shows that 76% of organisations expect data sovereignty to become more important, not less. The EU AI Act is entering full enforcement in 2026. At least 34 countries have strengthened data localisation requirements. Gartner predicts that by 2027, over 40% of AI-related data breaches will stem from improper cross-border use of generative AI.
Every single one of these data points validates the Realist’s prevention orientation. The losses they anticipated are materialising. The risks they flagged are becoming regulatory requirements. The “inaction” that their promotion-focused peers dismissed as timid is being retroactively reframed as foresight.
But here is the nuance that matters: the Realist is not always right, either. Their operational blind spot, the belief that “doing nothing” is a safe option, is itself a form of risk. In a rapidly evolving landscape, the cost of inaction is not zero. It is the compounding opportunity cost of falling behind while the competition builds capability. The organisations that achieve the best outcomes are not the ones that default to either promotion or prevention. They are the ones that achieve what the STAR Framework calls Cognitive Agility: the meta-cognitive ability to toggle between System 1 and System 2, between promotion and prevention, as the operational context requires.
The Stewardship Narrative
So what does Cognitive Agility look like in practice? The STAR Framework offers a specific tool: the Stewardship Narrative.
The Stewardship Narrative is the bridge between promotion and prevention. It pairs an aspirational goal with a protective rationale. The logic is straightforward: “We must innovate to ensure our long-term stability and protect our core values.”
In the context of enterprise AI adoption, a Stewardship Narrative sounds something like this: “We are deploying AI because it will fundamentally improve how we serve our customers and compete in our market. And we are building the governance, data sovereignty, and quality frameworks first, because deploying AI without them is not innovation. It is exposure.”
That is not a compromise between the sprinters and the cautious. It is a synthesis. It gives the promotion-focused organisation the growth narrative it needs to maintain momentum. It gives the prevention-focused organisation the safety framework it needs to commit resources. It uses the “eager” strategy of promotion while embedding the “vigilant” strategy of prevention into the execution model.
The organisations that will win the AI era are not the ones that move fastest. They are the ones that move with both speed and rigour. The ones where the Adventurer’s enthusiasm is tempered by the Realist’s feasibility scanning. Where the Thinker’s analytical filter is deployed before deployment, not after the first hallucination hits a customer. Where the Socialiser’s relational intelligence ensures that the people affected by AI adoption are included in the conversation, not surprised by the outcome.
The Behavioural Science Underneath the Numbers
When you strip away the technology and look at the behavioural science underneath, the enterprise AI story is not really about AI at all. It is about how human organisations respond to rapid, high-stakes change. It is about the tension between the mindsets that see opportunity and the mindsets that see risk. It is about the cognitive systems that process information at different speeds, and the regulatory orientations that point motivation in different directions.
The latest enterprise data is staggering, yes. But what is truly staggering is how precisely it maps to the psychological architecture that behavioural science has been describing for decades. Higgins was writing about promotion and prevention focus in 1997. Kahneman was writing about System 1 and System 2 in 2011. The STAR Framework synthesised these theories into a practical model years before the current AI wave made them urgent.
The Realist archetype has never looked more prescient, not because caution is always the answer, but because the questions they ask are the ones that determine whether AI adoption becomes genuine transformation or expensive experimentation. The 29% seeing significant ROI are almost certainly the ones where Realists had enough organisational influence to ensure that governance kept pace with enthusiasm.
The rest are learning the lesson the hard way. Which, to be fair, is how most organisations learn.
The question is not whether your organisation will adopt AI. It already has, or it will within the next eighteen months. The question is whether your organisation has the behavioural architecture to adopt it well. Whether your Compass points in the right direction and your Processor runs at the right speed. Whether you have people who can hold both the promotion and prevention frames simultaneously, who can toggle between the eager strategy and the vigilant strategy, who can build the Stewardship Narrative that turns enthusiasm into durable advantage.
That is not a technology question. It is a human one. And it always has been.
The STAR Framework synthesises seven established psychological theories into a practical model for understanding human behaviour. If you want to understand why your organisation responds to change the way it does, start with the mindsets. The technology is just the catalyst. The behaviour is the story.
Data Sources:
- Harvard AI Index Report, 2025
- BARC “Data Sovereignty 2026” Study
- NTT DATA Enterprise AI Research, May 2026
- Gartner Generative AI Deployment Projections
- PEX Report 2025/26
- Accenture Europe AI Sovereignty Report, 2025
The STAR Framework
If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.