Most companies are spending heavily on AI and struggling to show a result. Harvard Business Review published a piece last Thursday naming one reason: nobody pointed the money at the middle office.
The standfirst puts it directly. “Most companies overlook the opportunities for AI to improve exception-heavy tasks such as contract reviews, risk management, and compliance.”
I should say up front that the article is paywalled, and I have read the headline, the standfirst and the opening summary rather than the whole thing. The four steps in its title are behind the wall, and I am not going to pretend otherwise or guess at them. What follows is built on the claim those visible parts make, which is substantial enough on its own, plus what the phrase “exception-heavy” is doing.
Three functions worth naming
Contract review. Risk management. Compliance.
Notice what those have in common beyond being unglamorous. They are all functions that a mid-career professional either runs, reports into, or spends a significant part of their week feeding. They are not adjacent to the business. In a lot of organisations they are the part of the business that decides how fast everything else can move.
They are also the functions least likely to have been in anybody’s AI pilot. The pilot went to the technical team, or to marketing because marketing volunteered, or to customer service because the volumes made the arithmetic easy. Compliance got a memo about acceptable use.
That pattern is exactly what yesterday’s and Monday’s evidence has been circling. On Monday the figures showed legal, sales and recruiting growing far faster than engineering. This piece explains where a lot of that growth has room to go, and why the budget has not followed it yet.
What “exception-heavy” is describing
This is the phrase worth taking away, and it repays a minute of thought.
Exception-heavy work is work where every case is slightly different. Not different in kind: different in detail. A hundred contracts that are ninety per cent the same document, and the ten per cent that varies is the whole job. A risk assessment where the framework is fixed and the judgement about this particular supplier is not. A compliance check where you know precisely what you are looking for and cannot write down in advance what it will look like when you find it.
Here is why that matters historically. Exception-heavy work is precisely the work that survived the last automation wave.
Rules-based software could take anything you could specify completely. Payroll. Invoice matching. Scheduling.
What it could never take was the case that did not fit the rule, so work full of such cases stayed with people. Over twenty years that became a quiet reassurance for anyone doing it. The variability was the defence. If you could not write the rule down, nobody could automate you.
That defence is worth a good deal less than it was. The current tools are not rules engines. Their particular strength is handling material that is nearly the same as something else, which is a description of exception-heavy work almost word for word.
A worked example, and it is mine rather than theirs
Take supplier contract review, because most organisations have some version of it.
The unglamorous reality is usually a person reading a forty-page agreement against a checklist of things the organisation cares about. Payment terms. Liability caps. Termination rights. Data processing clauses. Auto-renewal.
Most of it is standard, most of the standard is fine, and the job is finding the three clauses that are not.
That work resisted automation because you cannot write a rule that catches “this indemnity is unusual for this kind of supplier”. You can, however, ask a capable model to compare this agreement against the twenty you signed last year and tell you where it differs, then have the person spend their attention on the differences instead of on page twelve of twenty identical pages.
Notice what that does and does not change. It does not remove the reviewer or the judgement. It moves the reviewer to the part of the task where judgement is actually required, and takes away the part that was only ever a search. That is a smaller and more achievable claim than most AI pitches make, and it is the one that tends to survive contact with a real process.
The spend problem underneath
The other half of the visible summary is about money. Companies are investing heavily and struggling to turn that investment into measurable business results.
That is a familiar position, and it is worth being precise about why it happens. When you cannot show a result, the usual cause is not that the tool failed. It is that the work chosen for the pilot was work nobody was measuring in the first place. Faster first drafts, better meeting notes and tidier internal documents are real improvements that show up in no number anyone reports upward.
Exception-heavy work is different in one useful respect. It is already measured. Contract review cycles have turnaround times. Compliance has backlogs and risk has queues.
Somebody already reports on all of it monthly, which means an improvement is visible without anyone inventing a new metric to prove it.
That is a strong argument for looking there first, and it has nothing to do with the technology.
What to do with this
I want to be careful about the tone here, because this could be read as a warning to the people doing the work, and that is not what it is.
The people who understand exception-heavy work are the ones who can see where AI would help and where it would be dangerous. They know which exceptions are routine variation and which are the ones that end up in front of a regulator. That knowledge is not replaceable by a tool, and it is exactly what makes the difference between a useful application and an expensive mistake.
So the practical step is small. Name one process in your area where every case is slightly different. That is where to look first, and it is very likely somewhere the AI budget has not been anywhere near.
Source: 4 Steps to Transform the “Middle Office” with AI, H. James Wilson, Chetna Sehgal, Michael Zimmerman, Ali Arsanjani, Blaise Abderholden and Jimmy Priestas, Harvard Business Review, 20 August 2026. The article is paywalled. This piece is built on the visible headline, standfirst and opening summary, and the worked example above is my own.