Technology is currently being rolled out under time pressure. In July 2026, the International Monetary Fund identified a technology-driven investment boom as one of the main forces shaping the global economy. Within companies, this pressure is evident in budgets for AI, the cloud and automation. AI is already used by 88 per cent of the organisations surveyed, and generative systems are present in at least one function at 70 per cent of them. However, agent-based implementations remain in the single figures for most processes. Experimentation has become the norm; autonomy is only just entering production.
The line between a sensible pace and recklessness is not determined by the type of technology. It is defined by the reversibility of decisions and the scope of error. A new assistant for the marketing team can be rolled out quickly. A system that changes prices, blocks accounts or controls production requires a different approach.
This was best illustrated by the CrowdStrike outageon 19 July 2024 – the company sent out a routine configuration update for the Falcon sensor on Windows systems. A bug caused the operating system to crash. The update was withdrawn after 78 minutes, but had already reached around 8.5 million devices. This represented less than one per cent of Windows computers. However, the impact extended to organisations providing critical services.
This is a significant incident because it did not involve a cyberattack or a failed, long-running migration. The source of the global disruption was a routine change to a security tool. Its technical scope was limited, but the software operated close to the system kernel and was rapidly deployed to a large number of devices. A minor bug gained privileged access and global distribution.
CrowdStrike subsequently announced canary deployments, phased roll-outs of updates, additional monitoring and greater customer control over where and when updates are installed. These are mechanisms for limiting the scope of an outage, not ways of producing error-free code. In its report for the quarter ending 30 April 2026, the company continued to report on legal and professional costs, extended sales cycles, and discounts and subscription extensions offered to customers following the incident. The technical error has had an impact on the profit and loss account and commercial relations.
The same mechanism is beginning to apply to AI. Model accuracy is just one of the parameters. Of greater importance is the authority to act that the system is granted upon implementation. A model that drafts a response poses limited risk. A model that independently rejects a complaint, adjusts a price or blocks a transaction can propagate a single error to thousands of customers.
In such processes, a parallel processing stage, a decision log, the possibility of appeal, and a model-free alternative are required. Human oversight is only valuable if the employee has the time and authority to challenge the outcome. From 2 August 2026, further transparency requirements under the AI Act will also apply in the European Union, including those concerning the provision of information about interactions with the system and the labelling of synthetic content. Regulation cannot replace operational oversight, but it increases the cost of implementations where actions cannot be reproduced.
The second area is dependence on suppliers. ENISA notes an increase in the exploitation of critical points of dependence within the digital supply chain. DORA, which will apply to the financial sector from January 2025, covers the management of risks associated with external technology suppliers. A secure system is not enough if the failure of a single service renders a company unable to operate.
Before scaling up, it is worth asking three questions. How quickly can a change be halted? How far will a fault spread? What will remain of the process once the technology is switched off? The answers should influence the pace of implementation, the architecture and the terms of the contract with the supplier.
A more cautious approach to scaling comes at a price. Maintaining two systems, recovery testing and the option to switch suppliers all increase the cost of the project. A pilot phase that lasts too long may cost you your market advantage. Not every change requires additional months of testing. It is needed for changes that cannot be easily reversed.
Technological advantage is usually measured by time to market. In critical systems, it is equally important to consider how much an error costs and how quickly its effects can be mitigated. A mature company does not assume that the technology will not fail. It designs it in such a way that a single failure does not bring the entire business to a standstill.

