What Happens After the AI Pilot Ends

A candid panel discussion at Milestone XPerience Days explores what organizations learn after moving AI from proof of concept into real-world operation.

Key Highlights

  • Practitioners from Advanced Data Risk Management and Harvard Business School joined a Milestone XPerience Days panel to share hard-won lessons from real AI deployments, moving well beyond vendor talking points.
  • Data readiness is the first obstacle — cleaning inconsistent, siloed records often proves harder than selecting the AI platform itself.
  • The clearest takeaway: define the operational problem first, then determine whether AI can help solve it. Organizations working in reverse consistently struggle.

This article originally appeared in the July 2026 issue of Security Business magazine. Don’t forget to mention Security Business magazine on LinkedIn or our other social handles if you share it.

(Editor’s note: A third panelist participated in this discussion. At the request of that panelist’s employer, all comments and references associated with that panelist have been removed from this article.)

Between the keynotes, solution showcases and standing-room product demonstrations, AI has become the organizing principle of nearly every security industry event. The capabilities are real. The momentum is real. But somewhere between the conference center and the operations center, things get complicated in ways that don’t make it onto the agenda.

Milestone Systems wanted to explore that reality during a panel discussion at Milestone XPerience Days 2026 titled “No Hype Allowed: An Honest Conversation About AI.” The goal was simple: move beyond vendor talking points and hear from practitioners who have already put AI into operation.

Dan O’Neill, President and CEO of Advanced Data Risk Management, and John O’Connor, Managing Director of Administrative Services and Operations at Harvard Business School, fit that description.

What emerged was a discussion that had less to do with AI itself and more to do with the operational challenges organizations face once deployment begins.

The data problem comes first

When asked what real-world deployment taught them that they didn’t fully understand during the evaluation stage, O’Connor immediately pointed to data.

“Across our operational technology, these systems are generating millions of rows of records on a daily or annual basis — just sitting in a database, locked away,” he said.

The realization that this information could answer important operational questions was eye-opening. Making that data usable, however, proved more difficult than expected.

AI delivers the greatest value when applied to specific operational challenges rather than deployed for its own sake.

“Finding the data that’s going to give us answers, then working through the specifics of how to get it from where it is today to where we want it to be in the future — that has been a lot more challenging than I initially thought,” O’Connor said.

The challenge often comes down to data quality and consistency. One system may classify an asset one way while another system uses a different taxonomy altogether. Cleaning that up at scale can become a major undertaking.

Organizations often focus on the AI platform and assume their data is ready. In many cases, it isn’t.

Start with the problem, not the technology

O’Neill described a framework his company uses to identify where AI can create value. The tool is a simple two-by-two matrix that weighs impact against effort.

The objective is to identify areas where AI can move activities from high impact and high effort to high impact and low effort.

For many security organizations, those opportunities include video search, false-alarm reduction, system maintenance and camera health monitoring.

In practice, that approach has produced workflows where AI prioritizes issues requiring attention, guides technicians to the problem and, in some cases, initiates remediation automatically.

O’Neill also shared a case study involving a global client that used AI-generated assessments to secure funding for security improvements. After implementing those upgrades, the organization used AI-analyzed data to demonstrate risk reduction, which led to additional funding for future projects.

The lesson was clear: AI delivers the greatest value when it is applied to specific operational challenges rather than deployed for its own sake.

The human factor matters

While data readiness is a significant hurdle, both panelists suggested that people often present the bigger challenge.

O’Connor described the anxiety many employees feel when introduced to AI tools.

“Is this going to replace my job? How am I going to feed my family if my job isn’t there tomorrow?” he said.

Harvard Business School responded by investing in broad training and encouraging experimentation. The goal was to help employees become comfortable with the technology and identify new ways to improve operations.

“We’ve gone from folks who are deniers — ‘I will never utilize these tools’ — to actually now surfacing some pretty neat ideas and new ways of making us more efficient,” he said.

O’Connor also emphasized a “fail forward” mindset. Organizations should expect some initiatives to fall short, learn from those experiences and continue moving ahead.

Community acceptance can’t be overlooked

O’Neill highlighted another challenge that security professionals sometimes underestimate: community perception.

“One of the things we underestimated was potential pushback from the community,” he said.

Even technologies that appear to offer clear security benefits can face resistance over privacy and surveillance concerns. In one example, O’Neill described how community opposition significantly delayed implementation and required additional legal review and outreach efforts.

He also referenced an active shooter incident in a neighboring municipality. While a gunshot detection system did not play a role in the response, the city council later ended its use following years of public scrutiny and debate.

The episode reinforced a reality that many security leaders face: a strong security case does not automatically guarantee public acceptance.

Don’t lead with AI

Near the end of the discussion, O’Connor offered what may have been the session’s most important takeaway.

“We sit around the table in our operations suite and ask: what are the actual problems that we’re trying to solve?” he said.

AI may be part of the solution, but it should not be the starting point.

Organizations often become excited about a technology and then search for a use case. The organizations seeing the most success appear to be working in the opposite direction: defining the problem first and then determining whether AI can help solve it.

That final point stayed with me. Behind every AI strategy, every data initiative and every deployment plan is a person who ultimately has to use the technology to do their job.

If the technology helps them, it worked. If it doesn’t, no amount of impressive demonstrations changes that.

That’s what “no hype allowed” actually means.

About the Author

Rodney Bosch

Editor-in-Chief/SecurityInfoWatch.com

Rodney Bosch is the Editor-in-Chief of SecurityInfoWatch.com. He has covered the security industry since 2006 for multiple major security publications. Reach him at [email protected].

Sign up for our eNewsletters
Get the latest news and updates