The GTM Proficiency Gap Is Quietly Inflating Your CAC
Being AI-curious is not the same as being AI-ready. Bad CRM data, shadow AI, ungoverned agents, and data decay all widen the gap, and your CAC pays for it.

Every story that crossed my desk this week had the same shape once I stopped reading the headlines and started looking at the pattern underneath them. A stat about shadow AI. A stat about CRM data. A framework banks are building just to answer who's accountable for an agent's actions. A founder who told me his team was already using AI everywhere, and meant a couple of people poking around in ChatGPT with no plan behind it. Different rooms, same confusion: the gap between being curious about AI and actually being ready for it, and who ends up paying when a company mistakes one for the other.
I started calling this the GTM Proficiency Gap a few weeks ago, almost as a throwaway phrase. This week it earned the name. Curious means you bought the tool. Ready means you can tell me where the leak is, who owns the fix, and what the number looked like before anything shipped. Every story below is really the same story: what happens in the space between those two words, and who's left holding the bill when the gap finally shows itself.
What's the Actual Difference Between Being AI-Curious and AI-Ready?
Curious means you bought the tool. Ready means you can name the leak, the owner, and the baseline before anything shipped.
A founder I talked with recently was adamant his team was already using AI, and pushed back hard when I asked what that actually meant day to day. I hear a version of this constantly right now, and I understand exactly why founders believe it. From the C-suite, everything looks like it's humming: deals close, dashboards stay green, the tool is paid for. What that view can't show you is that the institutional knowledge for how the business actually runs lives in two or three people's heads, and the process underneath was stitched together over time, built to survive founder-led growth, not to scale past it. Nobody in the building has had the nerve to say it's held together by duct tape.
That's why I'll say something that sounds harsh out loud: I think roughly 90% of organizations aren't actually ready for AI yet. Readiness keeps getting judged by what's been purchased instead of whether the data, process, and ownership underneath it can actually support what was purchased. Nearly every team I look under the hood of is further behind than it believes.
Two patterns repeat almost every time. The plumbing is the problem: data architecture, CRM hygiene, attribution, and the handoffs between teams are exactly where revenue quietly leaks, and putting AI on top of that just makes the leak move faster in the wrong direction. And everyone swims in their own lane: Marketing, Sales, Product, and CS each run their own plan with no central strategy tying them together, so nobody owns the number end to end. The comfortable myth is that AI fixes that coordination gap on its own. It doesn't. It just inherits it, at scale.
There's nothing wrong with being curious. Every team I've ever worked with started there, and it's a healthy place to start. The expensive part is calling curiosity readiness, and skipping the plumbing because the tools are already paid for.
Related: stackfinder.com/answers/ai-readiness-diagnostic
68% of Marketers Have Had a Number Challenged Because of Bad CRM Data. Who Actually Pays for That?
Almost never the person who approved the AI initiative. Almost always the person underneath them who'd been asking for the budget to fix it.
A recent survey of 500 marketers put real numbers on a pattern I've watched play out inside almost every CRM I've ever worked in. 68% have had a pipeline or performance number challenged or walked back in front of leadership because the underlying data was wrong. Only about a quarter say their CRM data is even 76 to 100% complete, and completeness isn't the same thing as accuracy. Close to 40% spend two to five hours a week just fixing data issues by hand, and another quarter spend six to ten. Nearly 45% let AI send campaigns, score leads, and reallocate budget with no human review at all.
The causes people named most were unclear ownership and no real collaboration between the departments feeding the CRM in the first place, and neither of those gets fixed by someone sitting three levels below the actual decision.
Here's the part that bothers me most. The board never sees any of this. What they see is the dashboard, and the dashboard looks fine, because AI will build a perfectly confident forecast on stale fields without blinking once. Leadership's confidence comes from the color of the dashboard, not the data underneath it, and that's true of every CRM I've ever personally worked inside. My honest, slightly cynical read: some boardrooms already suspect the data is shaky and keep the dashboard looking clean anyway, because a tidy story plays better with investors than a true one.
So, when the C-suite won't invest the time to actually understand the problem, everyone downstream of that data gets stuck living with it: a forecast drifts a few points, a segment that should have converted doesn't, a renewal slips because the record behind it was stale. Eventually someone has to answer for it, and it's rarely the person who signed off on the AI initiative in the first place. The finger usually lands on whoever's been quietly cleaning the CRM six hours a week, now labeled the problem and shown the door.
If you're the one presenting to the board, start by uncovering the why behind every KPI before you trust the dashboard in front of it. Ask who owns each field, and what the AI is already acting on without a human ever approving it.
Related: stackfinder.com/answers/data-governance-framework
31% of GenAI Users Are Using Tools Their Employer Doesn't Know About. Here's Why Banning Them Won't Help.
Because the actual driver isn't rebellion, it's curiosity with nowhere sanctioned to go, and banning a tool doesn't remove the need it was quietly solving.
A UK survey on GenAI use this week found that 31% of GenAI users are using tools their employer has no idea about, and half of all users have received no formal training on the AI tools their company actually gave them. Shadow AI shows up two ways: people using tools their security team never approved, and people paying for tools out of their own pocket (something like 17% of users, adding up to roughly a billion dollars a year), quietly assuming that because nobody's watching, the company has no exposure.
That second version feels safer to the person doing it, and it's actually one of the bigger risks a company can carry. The customer list and the pricing sheet still end up inside a model the company has no record of, whether anyone signed off on it or not. Separate research found sensitive data inside roughly 11% of what employees paste into one popular consumer AI tool, and with half of all users untrained, essentially nobody is checking what any of it ingests. A recent breach report tied shadow AI to 43% of AI-related breaches, up from 20% the year before, at an average cost north of $5 million per incident.
Shadow AI looks a lot like ghost SaaS to me, just with sharper teeth. Point solutions for individual problems, data quietly sprawling everywhere, and now agents talking to models that don't talk to each other, all because there's no central, controlled place for any of it to live. It's the same systematic failure teams once hoped AI itself would fix, playing out again underneath AI, because the unsexy plumbing keeps getting skipped in favor of the flashy new object sitting on top of it. History has a sense of humor that way.
Banning curiosity was never going to fix this. Training, and a sanctioned place to actually experiment, will.
Related: stackfinder.com/answers/shadow-ai-governance
What Should a Company Actually Do Before It Hands an Agent Real Authority?
Inventory what you already own, define what the agent can never do, fix the data underneath it, automate the boring well-defined parts first, and only then hand over authority with a human who can explain and undo what it did.
A payments executive told a recent Fortune Leaders Forum that banks need a “know your agent” equivalent of know-your-customer: who the agent is, who owns it, and who actually authorized it. A few of the largest payment networks in the world have already started building an interoperability framework around exactly that question this month.
The compliance question is the easy part to talk about out loud. The harder one is what most teams actually find when they go looking for an honest answer. I've been inside enough stacks to know the pattern by now: the agent is almost never the actual problem. The process it got pointed at was already broken, and nobody had written down what “working” was supposed to look like before it went live. Now something is acting on that broken process at machine speed, and the audit trail starts at the agent instead of at the workflow underneath it, which is exactly backwards.
The order I keep coming back to, every time, looks like this: inventory what you already own before buying anything new. Reverse-engineer the process the agent is about to touch, and write down what it should never be allowed to do, ideally with an actual subject matter expert in the room. Fix the data underneath it, because an agent reading bad records just produces bad records faster than a person ever could. Automate the boring, well-defined parts first. Only then hand over real authority, paired with a human who can explain what the agent did and undo it if it needs undoing.
Start smaller than feels satisfying: one process, one baseline, one definition of done that Marketing, Sales, Product, Finance, and Customer Success all actually agreed on together. A small, provable win buys the budget and the trust for the next one, the same playbook finance has been running for years before handing a system real authority. The teams that get this right in the next few years won't be the ones with the best agent. They'll be the ones who actually knew what their process looked like before they ever pointed an agent at it.
What Does a 95% Bounce Rate Have to Do With Whether Your Business Is AI-Ready?
It's the same gap, just showing up on your website instead of your CRM: a site that looks finished can still be losing nearly all of its visitors, and nothing about building it faster with AI fixes that on its own.
Building a website used to be hard. Now almost anyone can type a prompt, pick a template, and watch a working prototype appear in minutes. That gets you maybe 60% of the way there. The other 40% comes down to taste, judgment, context, actually knowing your audience, understanding how people navigate a page, and grasping the real mechanics behind a site that converts instead of one that just exists. Building a website stopped being a skill a while ago. It's a commodity now.
What AI still can't tell you is why a specific visitor left your page without filling out the form. Something like 95% of website traffic will read a page and bounce without you ever knowing why, and as more of the early research phase shifts from humans to agents browsing on their behalf, I expect that number to climb, not fall. I spent over a decade learning to watch that exact behavior, first as a growth marketing manager and later inside a leading SEO company, long before AI could build a page for anyone. Watching what makes a visitor trust a site enough to actually buy, and what makes them quietly leave instead, was the whole job.
I ended up packaging that conversion background into a diagnostic tool, which I'll admit I haven't talked about much out loud until now. The idea behind it is the same one running through this entire issue: it's not really about driving more traffic to a site. It's about converting the traffic that's already there, since most sites lose people who were already ready to buy. It's also turned into a genuinely practical starting point for the readiness question from the first section: where the revenue leak actually is, and where an AI effort should start instead of guessing.
I don't think this problem is unique to big companies with a marketing department, either. It shows up just as often, maybe more often, on the other end of the market, which is where I want to spend the next section before we get to the numbers.
Why Is Everyone Chasing Enterprise AI While Ignoring 80% of the Market?
Because the enterprise logo is glamorous and the SMB fix is not, and that exact imbalance is why the SMB opportunity is still sitting wide open.
Small and medium businesses make up roughly 80% of the market. Sit with that number for a second, because almost nobody selling AI right now is actually building for it. Small businesses carry the same underlying problems as any enterprise: broken handoffs, unclear ownership, stale data, an under-resourced GTM motion. The difference is they're working with a fraction of the budget and usually zero dedicated technical staff, and almost nobody is building specifically for them, because everyone's fighting over the same few hundred enterprise logos instead.
The enterprise AI market is already crowded: a long line of agencies and vendors fighting over a small number of accounts, and that's before the frontier labs themselves start competing directly for the same deals. Meanwhile, millions of small businesses remain almost completely untouched. The work there is genuinely unglamorous: no six-figure contracts, no logo wall, no polished strategy deck to post about, just unsexy problems solved one business at a time, focused on outcomes instead of optics.
That's exactly why I think the opportunity is real. The market that's too boring for most people to chase is usually the one with the most room left in it. This reminds me a lot of what happened during COVID, when small businesses either digitized fast or got left behind entirely. I think the same forcing function is happening again right now, just with “AI” standing in for “digitize.” My honest bet is on the SMB and growth-stage teams nobody's paying attention to yet, not the crowded enterprise logos everyone else is fighting over.
What Is Data Decay Rate, and Why Does It Quietly Inflate Your CAC?
Data Decay Rate is the percentage of your CRM records that become inaccurate over a given period, and B2B data typically decays two to three percent a month whether anyone's watching it or not.
People change roles, companies get acquired, phone numbers and emails go stale, all continuously, whether or not anyone's actively maintaining the database. A commonly cited range for B2B contact and account data is somewhere around 2 to 3% decaying every month, which compounds into a meaningfully different, and less accurate, database by the end of a single year if nobody's actively correcting it.
This is exactly the mechanism behind the CRM statistics from earlier in this issue. Nearly 40% of marketers spending two to five hours a week fixing data issues, and another quarter spending six to ten, are fighting decay in real time, mostly by hand, mostly without anyone officially owning the job. An agent layered on top of decaying data doesn't slow the decay down. It acts on the bad record with total confidence and produces a bad outcome faster than a person would have.
Here's the direct line back to CAC. Every rep-hour spent correcting a decayed record is fully-loaded acquisition cost that produced zero net new pipeline. Every outreach sent to a contact who changed jobs eight months ago is spend that left the building and never had a chance to convert. And every AI-driven decision made on top of decayed data (a lead score, a discount approval, a renewal risk flag) inherits an error rate nobody budgeted for, which shows up later as a CAC or retention number that's harder to explain than it should be. Decay isn't a data-hygiene inconvenience. It's a slow, compounding tax on every dollar spent acquiring or keeping a customer.
Related: stackfinder.com/answers/data-decay-rate
How Does Each of These Actually Impact Your CAC?
Here's the direct mechanism behind each pattern above: not just that it costs money, but specifically where in your CAC math it shows up.
Confusing curious with ready: Readiness gets judged by what's been purchased instead of whether the process underneath can support it. CAC impact: acquisition spend gets routed through a process nobody's verified works, so the cost of every deal absorbs the same undiagnosed leak, deal after deal.
Unclear CRM ownership: When nobody owns a field, the record decays until a number gets challenged in front of the board, and the operator who was fixing it takes the fall instead of the process that let it happen. CAC impact: every hour spent manually correcting data instead of working pipeline is fully-loaded acquisition cost with nothing to show for it, and the eventual cleanup, personnel change included, gets billed to the same budget.
Shadow AI with no sanctioned alternative: Banning a tool doesn't remove the need employees were quietly solving for, it just moves the exposure somewhere leadership can't see it. CAC impact: a breach tied to an unsanctioned tool carries real incident, legal, and trust-repair costs that land in the same budget meant to fund new customer acquisition, at the exact moment trust is hardest to rebuild.
Skipping the process baseline before granting agent authority: An agent pointed at an undefined process doesn't create an audit trail, it just acts with confidence and no way to explain itself afterward. CAC impact: every decision the agent makes without a defined boundary is a decision nobody can defend to a customer or a board, and defending the indefensible is one of the most expensive conversations a revenue team can have.
Treating a website as finished once it's built: A site that looks complete can still be losing nearly all of its visitors, and nobody sees the loss because it never shows up as a complaint. CAC impact: every visitor who was ready to buy and bounced anyway is acquisition spend that already paid to get them there, wasted at the very last step, the most expensive place in the entire funnel to lose someone.
This Week’s Move, starting Monday, 9/28/2026
Before you hand an agent real authority over anything, write down the answer to one question: what did “working” look like on this process before anyone touched it? If you can't answer that in a sentence, that's this week's actual task, not the agent rollout.
Have a workflow, metric, or mistake you want broken down in a future issue? Reply to this email or send me a DM on LinkedIn.
Share this issue