AWS
How AWS supports this: The GenAI Readiness Assessment identifies candidate processes, benchmarks organisational maturity against industry peers and produces a prioritised roadmap with clear success criteria for the first production agent.
3.3 Invest in five capability pillars
88 % of AI pilots never reach production. The failure is rarely technical. It is organisational: missing governance frameworks, inadequate operational tooling, inability to measure value, or workforce resistance. Organisations must assess their readiness across all five pillars( Governance, Technical Infrastructure, Operational Excellence, Value Realisation, People & Culture) and invest in closing gaps before scaling
THE BCG 10-20-70 RULE:
10 % OF SUCCESS COMES FROM TECHNOLOGY,
20 % FROM DATA AND
70 % FROM PEOPLE AND PROCESSES agent deployments. The BCG 10-20-70 rule holds: 10 % of success comes from technology, 20 % from data and 70 % from people and processes.
How AWS supports this: The Five Pillars assessment maps an organisation’ s execution readiness and identifies which capabilities must be built, bought, or partnered for. AWS Professional Services and partners deliver capability building across all five dimensions.
3.4 Implement deterministic controls for autonomous agents
Agentic AI introduces a new risk category: autonomous systems taking actions with real-world consequences at machine speed. Traditional IT controls are insufficient. Organisations need three layers purpose-built for agent governance: Preventive Controls( policy enforcement, permission boundaries, guardrails before any action executes), Detective Controls( realtime observability, drift detection, cost tracking during operation) and Responsive Controls( automatic rollback, human-in-the-loop escalation, incident response when thresholds are breached). Without these layers, the blast radius of a single agent failure can extend across the enterprise.
How AWS supports this: Amazon Bedrock Guardrails provides content filtering and policy enforcement. AgentCore delivers identity management, gateway-level access control and deterministic policy