
Why 95% of AI Projects Fail: Model Risk & AI Governance | Sandip Wadje, BNP Paribas
Why do 95% of enterprise AI implementations fail? According to Sandip Wadje, Managing Director at BNP Paribas, many organizations attempt complex reasoning tasks on day one rather than building a mature foundation around data hygiene and simple summarization workflows. In this episode, Ashish sits down with Sandip to explore how global financial institutions navigate Model Risk Management (MRM), GenAI governance, and regulatory expectations across regions like the UK, EU, and US. Sandip breaks down why classical 20-year-old MRM frameworks fall short when applied to non-deterministic black-box LLMs, and why security leaders must focus on output drift and event taxonomies rather than just input prompt filtering. We also examine the concept of the "AI Kitchen" - a cross-functional governance model bringing together IT, CISOs, legal, and Data Protection Officers alongside practical strategies for calculating AI blast radius, cleaning up overprivileged non-human identity (NHI) permissions, and training CSIRT teams for ML SecOps incidents. Questions asked: (00:00) Introduction: AI Risk in Regulated Financial Institutions(01:50) Sandip Wadje’s Background at BNP Paribas(02:50) Classical Model Risk Management (MRM) vs. Generative AI(04:40) Governing the Black Box: Finding the Security Delta(08:00) The CMDB Problem: Building an Accurate AI Use Case Inventory(11:30) Why 95% of AI Projects Fail: Summarize, Write, Reason(15:00) Continuous Evaluation (Evals) and Catching Output Drift(18:50) Event Taxonomy: What Happens When AI Decisions Drift?(25:40) Training CSIRT and SOC Teams for ML SecOps Incidents(30:00) Compensating Controls: Remote Browser Isolation & Prompt Monitoring(34:30) Non-Human Identities (NHI) & Cleaning Birthright Permissions(36:30) Balancing a $1M Savings Against a 4% Revenue Fine(38:30) Open-Weight Models vs. Frontier LLMs in Financial Services(41:00) The "AI Kitchen": Cross-Functional AI Governance(44:30) The #1 Rule for AI Security: Understand Your Data First