Est.

Bolt-On Automation and the Broken Process Problem

Faster AI on broken processes multiplies rather than fixes errors.

Editor at Large · · 10 min read
Cover illustration for “Bolt-On Automation and the Broken Process Problem”
Enterprise AI Failures · September 30, 2026 · 10 min read · 2,346 words

A Fortune 500 insurance company had documented standard operating procedures and a mature automation footprint, yet straight-through processing kept falling. The cause was structural: automation had been layered onto exception-heavy workflows, and the result was a system that was both brittle and expensive to run. Only after domain experts redesigned the workflow, stripped out the bottlenecks, and put clear ownership in the hands of business leaders did performance actually recover. That sequence, automate first, redesign later, is the pattern behind most of enterprise AI's disappointing returns, and it is worth understanding mechanically rather than as a vague complaint about "projects failing."

Older automation tools, rule-based bots and RPA scripts, were narrow enough that a person could still step in when something looked wrong. Agentic AI doesn't leave that room. It interprets goals, triggers workflows on its own, and acts across systems, so a flawed input doesn't wait for a human to catch it before spreading downstream. Whatever judgment a person was quietly supplying, catching a bad handoff, routing around an undocumented exception, gets removed at the exact moment the process speeds up.

That is the core mechanism, and it points to something counterintuitive: the more capable the AI, the more dangerous an unfixed process becomes, because agentic systems make a sequencing mistake costlier, not safer. Speed doesn't fix broken accountability or redundant steps; it just runs them faster.

Why bolt-on AI became the enterprise default

None of this happens because organizations are careless. Bolting AI onto an existing workflow needs almost nothing: a license, an announcement, maybe a training deck. Redesigning that same workflow needs leadership alignment, a real process map, new capability building, and a change program that reaches across teams that don't normally coordinate. Given that choice, most companies take the cheaper path, and the incentive to do so is entirely rational even though the outcome is not.

Deloitte's 2026 State of AI research found that 37% of companies are using AI at a surface level with no change to the process underneath it, and only around a third are genuinely reimagining how the work gets done. The rest sit in the bolt-on zone, tracking how many people opened the tool rather than what changed because of it. The World Economic Forum's 2026 AI at Work report found that dropping AI into a workflow without redesigning that workflow adds work instead of removing it, because employees end up running the old process and the new tool side by side.

That dual-process burden appears in three specific ways. AI gets inserted as an extra step before the review, formatting, or approval process that already existed, rather than replacing any of it, so cognitive load climbs with no offsetting benefit. Early use of any new tool tends to run slower than the process it's supplementing, and when nothing underneath has changed, nothing offsets that slowdown. Teams respond to this, sensibly, by keeping AI confined to low-stakes work where a mistake costs little. The tool never touches the work that actually moves the business.

The scoreboard confirms the pattern at scale. McKinsey's State of AI in 2025 found that nearly every organization surveyed uses AI in at least one business function, yet only a small fraction qualify as high performers actually capturing meaningful EBIT from it; roughly two-thirds are stuck somewhere between pilot and production. Boards are losing patience with that gap. S&P Global Market Intelligence's 2025 Voice of the Enterprise survey found that abandonment of AI initiatives jumped sharply year over year, with companies scrapping close to half of their proofs of concept before they ever reached production.

What "broken process" means in operational terms

A broken process rarely looks broken from the outside. It looks like it's running fine, right up until someone, or something, tries to act on it without the tacit knowledge that's been holding it together. The real definition is about legibility: a process is broken when its own operating logic can't be explained clearly, even by the people who run it every day, and that illegibility is exactly what trips AI up.

Sweep's 2025 post-mortem on enterprise AI deployments found that enterprise AI failed because the systems it was dropped into weren't legible enough: when no one can confidently explain why a user can or can't do something, what depends on a given field, or which rule wins when systems conflict, intelligence becomes a liability instead of a force multiplier.

AF Robotics' 2025 analysis lays out five structural bottlenecks that no amount of AI capability resolves on its own. Fragmented or poorly defined processes, hidden variations and steps nobody wrote down, produce unpredictable output the moment they're automated. Decision logic that has always lived in a person's head rather than a formal rule set leaves AI able to recommend but not act safely in compliance-sensitive situations, until someone formalizes the criteria and the escalation path. Data quality gaps let AI copy errors at scale rather than catching them, because the system amplifies whatever it's fed, good or bad. Automation running without any central orchestration produces several agents or bots acting independently and colliding with each other. Missing governance, no defined roles, no permissions structure, no audit trail, lets automation create access problems and uncontrolled exceptions nobody signed off on.

Salesforce is a useful illustration of how deep this goes. On that platform, what a user can see or do isn't determined by the data itself but by a layer of metadata sitting above it: permissions, validation rules, flows, execution context, sharing logic, dependencies between objects. For years that layer got treated as an implementation detail, something engineers handled and nobody else had to think about. AI agents collapsed that abstraction almost overnight, because an agent trying to act on a record has to understand that metadata layer the same way a human admin would, and most organizations had never documented it well enough for that.

Construction procurement shows the same illegibility problem at the field level. A 2023 Deloitte audit of mid-size contractors found a meaningful share of duplicate vendor records at the average firm, duplicates that split purchase orders across supposedly separate suppliers and mask patterns like repeated invoice uplifts or purchases made outside the negotiated contract. Automating procurement on top of that structure doesn't expose the duplication. It processes it faster and buries it deeper.

The scale of the blind spot compounds when organizations lose track of what they've even deployed. IBM's 2026 Institute for Business Value study found that most enterprises report AI sprawl is already raising both security risk and operational complexity, and a meaningful share of them have discovered AI agents or workflows running that their own security teams didn't know existed. Illegibility gets worse once nobody has a map of what's actually operating.

Why the sequencing failure is self-concealing

The bolt-on pattern survives specifically because people are still in the loop, quietly closing gaps the documented process never accounted for. Employees correct flawed inputs before they spread, catch edge cases nobody documented, and use institutional memory to route around handoffs that don't actually work as described. None of that appears in a process diagram, and it is the first thing lost the moment a step gets automated.

Retail rollouts show how this plays out at scale. Programs that post strong results in a controlled pilot often behave very differently once they're pushed across hundreds or thousands of stores operating under different local conditions, because the informal human compensation that made the pilot look clean simply doesn't travel to every location. What looked like a working process was really a process plus a person absorbing its rough edges, and the rollout removes the person while keeping the edges.

Galileo AI's December 2025 research on multi-agent systems shows what happens when that compensation disappears entirely. In simulated multi-agent environments, a single compromised agent poisoned the large majority of downstream decisions within hours, moving faster than conventional incident response could contain it. That's what cascade failure looks like once there's no human checkpoint left to catch the error before it spreads.

It also creates a new kind of exposure that didn't exist when a person was doing the work: autonomous agents talk to other agents, call tools, pass intermediate results back and forth, and request human approval at various points, and reconstructing what actually happened, when, which agent or person touched it, whether any record got altered, is now a genuine compliance question rather than a technical curiosity. The distance between what the documentation says should happen and what the agents actually did has become a liability in its own right.

Regulation has caught up to that liability faster than most organizations expected. The EU AI Act's general application, covering GPAI enforcement, transparency obligations, and most Annex III high-risk requirements, took effect on August 2, 2026, with some high-risk provisions still phasing in through 2027 and 2028. In healthcare, municipal services, and financial services, automating a process that was already broken is a compliance exposure now, one that stays invisible right up until an auditor or regulator goes looking for it.

What process-first adoption looks like in practice

Organizations that get real returns from AI don't start by asking how to fit it into what already exists. They ask what the process would look like if it were designed today, with AI capability assumed from the start, and answering that honestly requires work that has to happen before any vendor gets a call.

Celonis' 2026 Process Optimization Report, reported by VentureBeat, found that most business leaders surveyed believe AI will fail to deliver a return if it doesn't first understand how the business actually operates. Process intelligence, a shared, accurate account of how work really moves, is what separates a company with genuine AI infrastructure from one running on ambition alone.

Humaine Labs states that process-first work concretely requires pausing the existing workflow long enough to sort out which steps exist for a real operational reason and which ones survive purely as legacy constraints that AI could eliminate. And it means building new capability around the redesigned workflow, tracking cycle time, rework rate, decision speed, rather than tracking how many employees logged into the new tool.

Kuehne+Nagel's approach to customs classification shows what this looks like. Instead of bolting AI onto the existing classification process, the system routes work by confidence level: high-confidence declarations get processed automatically, mid-confidence cases go to expedited human review, and low-confidence cases go to specialist brokers. The workflow was redesigned first, and AI was given only the decisions the redesigned process could let it make safely.

Salesforce's own correction with Agentforce in late 2025 makes a similar point from a vendor's side. The company shifted away from purely probabilistic, language-model-first execution and toward a hybrid model built on guardrails, deterministic automation, and data-first design, and that wasn't a retreat from the technology. It was an acknowledgment that AI only operates safely inside a system it can actually explain, which meant the order of operations had to run: make the system legible, make its behavior explainable, make its outcomes predictable, and only then add the intelligence layer.

BCG's framing, cited by Gharpure in Forbes, holds that the common error is automating what already exists, when the real value comes from starting with the outcome you want and reinventing how to get there, treating agentic AI as a multiplier of clarity rather than a shortcut to scale. The results reflect that distinction. Firms that redesign workflows before selecting AI tools are roughly twice as likely to see a financial return from the effort, an enterprise AI implementation failure analysis found.

Understanding the work before deciding what to rebuild

The most dangerous gap in enterprise AI isn't between what a company wants to achieve and what the technology can do. It sits between what a process is documented to do and what it actually does on the ground, and closing it takes direct observation before anyone starts rebuilding anything.

Construction shows this gap in a particularly stark form. P6 schedules record intent, not achievability, and the real risk in any large program lives in procurement lead times, coordination between trades, and commissioning data, none of which appears in the declared schedule itself. The US data center construction pipeline shows this concretely: reporting citing Bloomberg found nearly half of planned builds are delayed by shortages of transformers, switchgear, and backup storage components. Build-to-commissioning now runs 18 to 30 months, and JLL found grid connection wait times in major markets already exceed four years. In Ireland, grid energization alone adds more time to the back end of a program than the entire MEP fit-out takes to complete. Transformer and chiller lead times have become a question asked at tender stage rather than something left to procurement later, because a late order forces commissioning to get compressed in ways that aren't safe. Automated reporting layered on top of a declared schedule like this doesn't catch any of that divergence. It reports the plan with total confidence while the real risk quietly builds in queues the schedule was never designed to track.

Auditing the process on the ground, rather than trusting what's written down, reveals where work actually stalls, which handoffs only function because someone is informally patching them, where the underlying data is incomplete or duplicated, and which steps survive purely because of a legacy system constraint nobody's revisited. Those are precisely the inputs a redesign needs before deciding what to automate and what to tear out.

Celonis' 2026 findings, again via VentureBeat, found that the real blockers to AI adoption are siloed teams and poor coordination across departments rather than resistance to the technology itself, structural problems that become visible once someone watches how work actually moves across teams rather than how the org chart says it should move, which is the discipline the whole argument comes down to. Before any tool gets selected, before any platform strategy gets written, before any pilot gets scoped, the work itself has to be understood as it's actually performed, not as it was described the day the documentation was last updated.

Sources

  1. Why Enterprise AI Stalled in 2025: A Post-Mortem | Sweep | Sweep
  2. Enterprise agentic AI requires a process layer most companies haven’t built | VentureBeat
  3. The Bolt-On Problem: Why Deploying AI on Top of Existing Workflows Makes Things Worse Not Better
  4. The 5 Automation Bottlenecks AI Alone Cannot Fix — and How Enterprises Should Address Them in 2026
  5. Council Post: Why Enterprises That Automate Broken Processes Will Only Break Faster
  6. The State of AI in the Enterprise - 2026 AI report | Deloitte US

More in Enterprise AI Failures