This series set out to describe the gap between an AI prototype everybody liked and a service citizens could actually use. Eight articles later, the pattern is clearer than it was at the start, and it is worth stating in one place.
Almost none of the work that decided the outcome was AI work.
What each stage actually cost
The prototype settled the idea and told us nothing about delivery. Its lasting value was content and design language, not code.
The spec was the asset. Making it the source of truth — and writing the guardrails down as versioned artefacts rather than intentions — is what made an AI coding agent safe to run fast.
Access was the first sprint, in practice if not on the plan. Five predictable approval gates, each a round-trip, none of them engineering problems.
Least-privilege was a design constraint encoded once and reused, not a blocker. Federated identity, resource-group scope, constrained role assignment, all in the infrastructure code.
Residency was the hardest question in the programme and had nothing technical about it. One data-protection question determined the architecture, the cost model and the launch risk.
Evidence had to be captured while green. A milestone without a named artefact is not defined, and reconstruction months later produces something weaker.
Content was the real critical path, owned by people outside the delivery team, and it set the quality ceiling for the AI as well as the portal.
Translation unstuck more schedule than any engineering decision. Decisions were not hard; they were badly framed.
Read that list back and notice how much of it a demo tells you nothing about — and how much of it is where a delivery actually succeeds or fails.
The six questions
If the series compresses into one artefact, it is a checklist. Eugene Perumal of Valutivity, writing in ITWeb in August 2026 (Deploying AI agents safely), poses six questions that technology and risk leaders should be able to answer before an agent reaches production. They map almost exactly onto what this delivery learned the slow way.
None are difficult. All are dramatically cheaper to answer before the thing is built. And an agent that cannot survive all six is not ready for a regulated environment, regardless of how well it performs in a demo — which is the same conclusion this series reached from the delivery side rather than the governance side.
The sixth is the one that most often exposes the others. If you cannot describe the audit trail, it is usually because the access model was never scoped, which means the first three questions were never really answered either.
Governance is not the brake
The instinct in most delivery teams — and I have had it myself, mid-sprint, blocked on an approval — is that governance is the thing slowing the work down.
The evidence does not support it. Perumal reports that around 40% of agentic AI projects fail, attributed to missing foundations rather than model quality, and that 95% of executives say their organisations have already experienced negative consequences from enterprise AI use, with direct financial loss the most common outcome. Against a projected $1.3 trillion in agentic AI spending by 2029, that is a very large amount of money moving quickly in the wrong direction.
His line is the right one to end on: "Ungoverned agentic AI does not move faster. It moves confidently toward value-destroying events, regulatory penalties, data breaches, failed audits and erosion of customer trust."
And: "governance maturity is the single strongest predictor of AI readiness."
That matches what we saw. The delivery did not go well because the model was good. It went well because the spec was written down, the access was mapped, the permissions were scoped, the residency question was answered by the right person, and the evidence existed. The AI part was, honestly, the straightforward bit.
For South African organisations specifically
Three things worth carrying, whatever sector you are in:
Least-privilege is a POPIA requirement, not a security preference. Automated processing of personal information must be purposeful, proportionate and accountable. Access beyond the task fails proportionality whether or not it is ever used — the exposure is the grant.
On anything citizen- or customer-facing, the exposure is the input. What people type into a free-text box is personal information, regardless of how public your knowledge base is. Design the intake as a personal-information channel.
Have an in-country fallback designed from the start. Retrieval-only in-country is available regardless of how the personal-information question resolves, which means the launch date never depends on an approval you do not control.
The unglamorous middle
The reason this series exists is that the middle of this work is where consultancies earn their fee and where almost nobody writes anything down. The demos are public. The responsible-AI principles are public. The bit in between — the access map, the scoping decision, the residency memo, the content template, the one-page options paper — is where the delivery actually happens, and it is nearly all undocumented.
If you have a prototype everyone liked and cannot work out why it is not live yet, the answer is almost certainly somewhere in the eight stages above. It is rarely the model.
How CloudNala can help
We work with organisations at exactly the point this series describes: the prototype exists, the appetite is real, and the path into a governed environment is unclear. The useful early work is usually small — an access map, an honest read on residency, a risk-capability classification of what is being built, and evidence points attached to the milestones. Done at the start, that work is inexpensive. Done after a stalled delivery, it costs considerably more.
Work with CloudNala
CloudNala helps organisations move from technology ambition to practical execution across cloud, AI, data, platform engineering and digital services.
Whether you are exploring AI, modernising your cloud environment, building a public-sector digital service, or turning an idea into a working MVP, we can help you shape the roadmap and deliver the next step.
Book an AI Readiness Workshop or write to us at consult@cloudnala.co.za