AI has reached an awkward but fascinating phase in the enterprise. The hype cycle hasnโt quite faded, but the conversation has undeniably shifted. CIOs are no longer asking whether AI belongs in the business – theyโre trying to figure out how to deploy it safely, scale it sensibly and actually generate value from it.
Thatโs one of the central themes running through the Lenovo CIO Playbook 2026, which suggests organisations are moving from experimentation to operational deployment. Budgets are rising, agentic AI is capturing attention, and leaders are increasingly looking beyond simple copilots towards systems that can actively drive business outcomes. Yet alongside the optimism sit some stubborn realities: only a fraction of AI pilots ever reach production, governance frameworks remain immature, and foundational issues such as data quality, integration, and security continue to slow progress.
To see how these findings resonate in the real world, we asked a range of senior executives – from CTOs and CIOs to innovation leaders and security specialists – to read the report and share their reactions. Their responses reveal a mixture of agreement, caution and challenge. Some see the Playbook as an accurate reflection of the industryโs shift from experimentation to execution. Others argue enterprises may be overstating their readiness, particularly when it comes to governance, security and scaling AI beyond isolated pilots.
What emerges is a clear picture of an industry at an inflection point. AI is no longer a curiosity or a side project. But turning ambition into production systems – and doing so without creating new operational and security risks – is proving to be the real test for enterprise leaders.
You might also be interested: What you need to know from the Lenovo/IDC CIO Playbook 2026
Rami Douenias, Senior Director of AGT and AI at SHI
While the CIO Playbook 2026 rightly flags a more measured approach to AI devices prioritising foundations, cost control, and measurable ROI over blanket deployment the conversation still risks conflating two fundamentally different categories under the same label.
‘AI Devices’ today span a wide spectrum. At one end are the familiar endpoints: AI PCs, workstations, smartphones, and tablets equipped with NPUs for lightweight on-device agents, local inference, and productivity gains. IDCโs forecast that half of enterprise PC purchases will shift to these models by 2027 is encouraging, but these devices are optimised for consumption and light orchestration, not heavy development or scaled inference.
At the other end is a new class of enterprise-grade AI supercomputers that have become commercially available ‘over the counter.’ Devices such as the Nvidia DGX Spark (a compact Grace Blackwell desktop system delivering up to 1 petaFLOP+ of AI performance in a mini-sized footprint) and high-end GPU-equipped portable workstations represent portable supercomputing. With 128+ GB of unified memory, full Nvidia AI software stacks, high-speed networking for clustering, and the ability to run, fine-tune, and serve models up to 200-400 billion parameters locally, they function as AI Enablers in several ways. ย As developer workstations for rapid prototyping and iteration, edge inference hosts for agents, real-time data collection, and low-latency applications, and as secure, air-gapped deployment platforms that reduce cloud spend and data-exfiltration risk. Plus they enable application and agent activation, iteration and creation.
Infrastructure, data and architecture still hold AI back
These are not ‘just another PC.โ They are purpose-built enablers of AI at scale that sit between the personal endpoint and the data centre delivering enterprise performance without the associated facility, power, or procurement friction. Itโs a distinction that matters. When reports lump all โAI devicesโ together, organisations risk either under-investing in the specialised hardware needed for meaningful development and edge workloads, or over-investing in commodity AI PCs that cannot carry the workloads that actually drive defensible business value.
Clarity on definitions is no longer semantic it is strategic. The organisations that will extract the highest ROI per kilowatt (and per dollar) are those that deliberately segment their AI device strategy: consumer-grade endpoints for widespread adoption, and purpose-built AI supercomputers for the development, inference, and edge layers that create the real competitive advantage. So the conversation has moved from โhow many AI devices?โ to โwhich AI devices and for exactly what outcome?โ This sharper taxonomy turns cost management from a defensive exercise into a genuine enabler of sustainable, high-value AI adoption, development and deployment.
Patrick Sullivan, Vice President of Strategy and Innovation at A-LIGN
What stands out in this research is how quickly AI has shifted from experimentation to becoming embedded in core business operations, in spite of the unknowns around AI regulatory enforcement. While organizations are seeing real returns and are moving aggressively to deploy AI across functions, governance and control frameworks arenโt always keeping pace with that adoption.
Companies sometimes lose visibility into how decisions are made or how automated processes operate as AI becomes part of day-to-day workflows. Traditional compliance and security controls were built for human-driven processes, not autonomous or semi-autonomous systems, so organizations now face new challenges around auditability, accountability, and oversight, especially in regulated industries.
Weโre also seeing AI investments expand beyond IT, with individual business units funding their own initiatives. While this accelerates innovation, it can fragment governance and increase risk exposure if organizations donโt maintain consistent standards for vendor oversight, data handling, and compliance monitoring. Many AI pilots stall before production not because the technology fails, but because governance, integration, and risk controls werenโt addressed early enough.
Bob Shaker, Chief Product and Technology Officer at ActiveState
Development teams are rapidly incorporating a growing number of open-source libraries and models to accelerate delivery. The research highlights how AI speeds innovation, but that also increases exposure to vulnerable or poorly maintained dependencies. AI code generators can also hallucinate packages, which then bad actors can commandeer to perpetrate attacks. Many organizations donโt yet have full visibility into the components running inside the code generated by AI, which becomes a challenge when moving pilots into production.
Weโre seeing enterprises shift focus from experimentation toward operationalizing AI, and thatโs where software supply chain considerations become critical. Companies are trying to standardize and reproduce development environments so they know exactly what software components are being deployed, how theyโre maintained, and whether they remain secure over time. Without that foundation, scaling AI safely becomes difficult.
As AI workloads grow – so do dependencies
Another challenge is that as AI workloads grow, so does dependency sprawl. Teams and AI code generators often pull packages directly from public repositories to move quickly. But without centralized oversight, organizations can accumulate thousands of dependencies with varying levels of maintenance and security risk. This becomes especially problematic when AI systems move into customer-facing or regulated environments. The reality is that AI can be a powerful partner in software development but itโs critical to ensure the right upstream inputs (e.g., secure open source package) are used to help keep teams secure.
Building the infrastructure means limiting what open source packages AI tools can use. More than just the packages, organizations need to have all the dependencies and shared libraries defined as well, and one way to reduce this risk is with curated components. These are trusted open source software components that are continuously monitored, maintained, and built from source in a secure environment to ensure they are free from critical vulnerabilities. These will be instrumental in ensuring generative AI is building from a trusted, clean, open source.
As the report suggests, “CIOs face growing pressure to balance sovereignty, compliance, and performance when choosing where AI runs.โ Itโs not a matter of whether or not to leverage AI. Itโs where to use it. Organizations need to determine the right place, and establish the right policies. The answers in the report are clear, and in line with what weโre seeing in enterprises today, that organizations progressing fastest are building AI into workflows. With this infrastructure in place, the intent to use AI should be a welcome innovation for an enterprise to build at scale.
Mat Clothier, CEO and Founder of Cloudhouse
The CIO Playbook 2026 broadly aligns with what I’m experiencing, though I’d push back on the adoption figures. The report suggests over 50% of organisations are actively deploying AI, but in practice, I suspect much of this reflects small teams experimenting rather than enterprise-wide implementation.
That said, the nearly 20% jump from piloting to production over just a year is genuinely encouraging and tracks with how dramatically tooling has improved. The barrier to entry is collapsing fast: non-technical colleagues in our organisation recently tailored a RAG-based chatbot that took me significant engineering effort two years ago. They troubleshot and refined it with relative ease. The proliferation of GUI wrappers and simplified interfaces (OpenAI’s Codex desktop app being a recent example) is accelerating this democratisation.
The report’s breakdown of AI types across interpretive, predictive, generative, and agentic categories feels accurate, and I expect the distribution to shift further as more companies build accessible layers for non-technical users, much like Apple’s approach of constraining options to deliver a better overall experience.
The rise of hybrid AI infrastructure
Data sovereignty is the trend I watch most closely, and the report rightly highlights it as a driver for hybrid and on-premises deployment. France’s active push to decouple from US-based AI infrastructure is just the start. When you feed AI models your data, you need absolute clarity on where it resides and who can access it โ the risk of leakage or misuse is real. The report’s finding that organisations overwhelmingly favour hybrid deployment models makes complete sense in this context.
On agentic AI, the reported growth figures of up to 296% (Scandinavian) year-on-year are striking but credible โ I’ve watched agent capabilities improve week by week over the past few months, and the pace is genuinely remarkable. However, the security implications deserve far more attention than the industry is giving them. To let agents truly act, you must grant them permissions, and with those permissions come serious risks: broken infrastructure, credential leakage, and expanded attack surfaces. People will push back against agents, as the piece acknowledges, but it’s ultimately a “use it or become part of history” argument. don’t provide your people with viable, secure AI tools, they’ll use consumer versions anyway, and that’s where IP and data risks become acute. I made it a priority to have a sanctioned alternative available as early as possible, because I knew people would use AI tools whether we approved them or not. Better to channel that energy into enterprise-grade, data-protected environments. Looking ahead, we’re exploring how to leverage existing customer data responsibly and investigating anonymised data pipelines that could enable more sophisticated model behaviour, all while maintaining the strict demarcation between company data and experimental work that our regulated environment demands.
Martin Jakobsen, Managing Director at Cybanetix
The CIO Playbook 2026 report reveals an overconfidence in the UK, with the majority of respondents (39%) claiming to have achieved a comprehensive approach to AI governance, risk and compliance (GRC), compared to 27% globally. Having a false sense of security is dangerous, particularly as many threats are only beginning to become apparent. These arenโt just limited to inadvertent data leakage, weโre also starting to see novel AI attacks spawning just-in-time malware and polymorphic ransomware for instance, so businesses that mistakenly believe they are completely prepared are more likely to become victims.
The report further shows that reducing business risk and cyber threats has gone from being the number one priority in 2025 to last place in 2026. Thatโs worrying because it suggests the resource needed to address those emerging threats has been scaled back. So why is this happening? While the UK leads the pack in Europe with an AI adoption rate of 63% the report shows adoption is being spearheaded by IT, with cybersecurity relegated to third place, predominately because security teams have not been given a seat at the table. AI is being viewed as a technology issue to solve with business benefits, with security sidelined.
Security risks and shadow AI remain major concerns
What is encouraging is that AI security, trust and transparency tools are rapidly climbing up the rankings (up seven spaces) to become an investment priority in the year ahead. But cyber is still very much regarded as a cost centre. When asked about the top business areas where AI has shown positive returns, IT came out on top, with cybersecurity listed last in fifth place, revealing that AI has yet to prove its worth here. In fact, when it comes to critical success factors, having robust data security, sovereignty and governance in place also came bottom of the list. If cyber isnโt being given the attention it deserves that could tip the scales in the attackersโ favour.
Where the report does indicate cybersecurity will add value is with respect to Agentic AI. Itโs named as the number one area where the technology will be used but Iโd take issue with that. Yes, Agentic AI promises to help automate the Security Operations Centre (SOC), resulting in some autonomous processes, but we will still need human analysts to oversee the validity of those decisions. Itโs for this reason that many are now saying that we can expect a move from human in the loop to human on the loop with respect to threat detection and response in the SOC.
John O’Connell, Founder and CEO of The Oasis Group
I agree that organizations must solve challenges in data quality, integration, control mechanisms, and change management to effectively scale AI Agents. Many industry thought leaders, myself included, have been discussing data quality for years, only to face skepticism that the problem was significant. Firms implementing AI Agents now understand that AI can generate results significantly faster than a human workflow. However, bad data will get you to the wrong answer much faster. I expect organizations to use AI Agents to analyze and potentially clean their data as initial use cases once they realize how poor their data is.
We see several enterprise wealth management firms in the North American market with formal AI policies and up to 5 AI agents in production. However, the vast majority of wealth management firms are similar to the studyโs findings. The study found that only 27% of firms have a comprehensive AI governance program. Too many firms are relying on their IT teams or IT vendors to define their AI governance. This is not an IT problem. Firms must develop better vendor management practices to understand where their data resides, AI Acceptable Use Policies that clearly outline acceptable and unacceptable use cases and tools, and training programs that teach staff to use AI safely and avoid hallucinations and bias in AI results. Silence on any of these policies is not security.
Good data and governance are the foundation for scaling AI agents
I believe we will see incumbent wealth management technology vendors rapidly implement AI capabilities in 2026. The explosion of new AI vendors (my AI WealthTech Map has over 100 AI-first solutions) will continue to grow over the next 2-3 years with little consolidation. The industry will see more agents deployed this year beyond enterprise firms into lower-enterprise and upper-middle-market firms. We will see digital workers emerging in 2027.
Most large wealth management firms are adopting a fast-follower approach to enterprise firms. Most have active projects to identify AI use cases in the first half of this year and are targeting production implementations in the second half. Firms that start forming an AI strategy now will be left behind.
I am surprised that 30% of firms in the study have no plans to implement Agentic AI over the next 12 months. These firms will be in trouble in 12 months, as competitors with Agentic AI in place begin to redeploy team members from AI-enabled tasks to more value-added or customer-facing tasks.
Mohammad Ismail, VP of EMEA for Cequence Security
Thereโs a real risk of organisations boiling the ocean with respect to agentic AI. Weโve had conversations with developers that have devoted months to pilot projects only to realise that, while they have a working prototype, they canโt scale it to become a business-grade proposition because it doesnโt have the necessary security or authentication processes or dovetail with their zero trust network architecture. Thatโs a colossal waste of time and resources.
The CIO Playbook 2026 report reveals most organisations are still at this stage, with 54% exploring, piloting, or with limited deployments of the technology. Whatโs more the majority (38%) say theyโll need more than 12 months to scale those agentic AI implementations and of course, by that time the market will have changed enormously. The technology is currently making conceptual leaps forward every 3-6 months, meaning those businesses will be at least four times behind the curve before theyโve even started.
The barriers
The report correctly identifies the main barriers to AI adoption i.e., technical complexity/integration (26%), security/privacy (26%) and uncertain ROI (24%). But those barriers are not unique to AI; theyโre commonly associated with any new rollout of a technology. Whatโs dooming these projects to failure is an inability to safely innovate fast enough and iterate through different versions, forcing the business to repeatedly start from scratch or re-engineer.
To resolve the time to market issue, businesses need a way to spin up, secure, manage, and monitor agentic AI use. AI gateways are now fast becoming a means to do this. Rather than simply being used as conduit for AI traffic, they can now act as a central hub via which the business can spin up MCP servers, connect to trusted third-party MCP servers, and monitor user-agent-API connections to look for anomalous activity. Rather than taking months to create and connect agentic AI to applications and data, the business can then simply connect its application APIs, select passthrough authentication or configure an OAuth provider, and deploy or connect to an MCP server all from within a trusted gateway in minutes. That will shorten prototype to production windows but importantly it will also ensure security is built-in to deployments from the get-go.
Dr Seena Rejal, CCO of NetMind.AI
Itโs no surprise that business leaders are confident – or merely hopeful – they can unlock AIโs ROI this year. After more than three years of hype since ChatGPT launched, the honeymoon period is over. Executives are desperate to realise the gains. The conversation has shifted from 2025โs experimentation to 2026โs enterprise-wide deployment.
Iโm specifically seeing an increased appetite for agentic AI, which corresponds with the reportโs findings of a 65% jump in organisations preparing for it. But many leaders I speak to feel both anxious about falling behind and uncertain about how to actually deploy these agents safely and to commercially powerful effect.
AI is moving from experimentation to execution
The reality is that most organisations are ready for agentic AI, but they need to sort out the basics first. We recently helped a fintech client move from millions of fragmented, unstructured documents to a RAG (Retrieval-Augmented Generation) system. We had to get their house in order first – turning that corporate data into a searchable, compliant engine – before the AI could actually be useful. As they say, the output is only as good as the inputs.
Ultimately, the โdevelopingโ state of governance in the report is a red flag. In regulated sectors like finance, โmoving fast and breaking thingsโ isnโt a viable strategy but a recipe for disaster. As a result, the winners in 2026 will be the first to build robust, explainable frameworks. You cannot scale what you cannot govern.
Chris Newton-Smith, CEO of IO
Itโs insightful to see the Lenovo CIO Playbook 2026 position governance as the gatekeeper to AI at scale. At IO, weโre witnessing the same shift. Organisations are no longer satisfied with AI capability alone, theyโre demanding embedded, demonstrable AI governance from their suppliers.
Our own State of Information Security Report reinforces this momentum. 28% of respondents now require suppliers to be ISO 42001 certified – up from just 2% in 2024. Thatโs not a marginal increase; itโs a market signal. AI is no longer experimental. Itโs operational, and it must be governed accordingly. Organisations that strategically embed AI into core operations, with clear ethical AI management, are separating themselves from those still reacting to risk.
There is also a clear alignment between our findings and the CIO Playbook when it comes to AI implementation and scaling. While 56% of CIO Playbook respondents say they are still developing their approach to AI and governance, 54% of leaders in our research admit they adopted AI technology too quickly and are now facing the difficult task of scaling it back or retrofitting responsible controls.
The governance gap slowing enterprise AI
The pattern is clear; AI adoption is outpacing governance. In the rush to streamline operations and reduce costs, controls and guardrails are often implemented only after incidents occur. Proactive organisations, by contrast, are realising that governance is a benefit – an enabler of secure scale, operational resilience and, critically, customer trust.
Itโs no surprise that a lack of responsible AI ranks as the top trust concern. However, shadow AI may be an even greater threat than the CIO Playbook suggests – because it is harder to see, monitor and prevent. 37% of respondents to our State of Information Security Report say employees have engaged in shadow AI use in the past 12 months – and that figure only reflects known cases. Shadow AI is now the second most common employee-driven security mistake after shadow IT (40%), and 33% of organisations cite it as a top emerging threat over the next year. The visibility gap is where the real exposure lies.
At IO, our response is clear. Governance must be unified, not siloed. We are progressing through the ISO 42001 certification process as part of a unified compliance loop that integrates information security, data privacy and AI governance. Alongside our recent re-certification to ISO 27001 and ISO 27701, this approach strengthens not just AI oversight, but our overall business resilience.
AI scale without governance creates risk. AI scale with governance creates advantage.
Joe Wilson, Chief Evangelist at bunq
Broadly agree with global wide adoption findings and see it reflected in industry. Itโs very on trend right now to profess or position any company or service as being โAIโ. However, as an AI-first organization, we at bunq understand both the benefits and pitfalls required to implement a full AI approach across a company. For us this is not a retro fit, however itโs part of our original design. I expect enterprise AI to see a strong focus on the productivity space as companies add agentic tools to their workforce and hope for upsides. Our learnings are that it is not that simple. If you want to take advantage of the power of the data that you hold (and in our case itโs held in deep trust, with clear GDPR expectations) as well as the advances that LLMS provide, you have to become culturally and mechanically AI first. This will require a rewiring of how the companies in the survey actually work. Adding AI to a stack wonโt do it; they will have to deep wire this capability into the most mission critical parts of their business to feel the benefits they seek.
AI is embedded at the core of how bunq operates rather than being treated as a separate initiative. We built our growth model to be AI-led from day one, making automation and intelligence central to how the bank scales. Today, over 85% of bunqโs operations across 25 teams run on AI, generating more than โฌ34 million in savings in 2025 alone. This operating model allows us to be one of Europeโs most productive banks, with profit per employee significantly above the banking industry average.
AI-first organisations are already proving the model
At the centre of this approach is Finn, bunqโs proprietary GenAI platform, launched in December 2023 and continuously expanded since. Finn now handles around 97% of all user support interactions, with roughly 80% fully automated, delivering average response times of 47 seconds (industry average is 60 seconds), while maintaining a 90% user satisfaction rating. Beyond support, Finn powers key product features such as receipt and image recognition, budgeting insights, multilingual assistance, and real-time speech-to-speech translation, enabling bunq to operate seamlessly in 38 languages – more than any other bank globally.
AI also plays a critical role in fraud prevention and deepfake detection, supporting user safety while ensuring complex cases are escalated to human experts when needed. Overall, bunqโs AI journey is focused on practical, scaled deployment, delivering measurable impact across operations, user experience, and security.
Trends should be divided between users and companies, as – like with any new tech – they are at different states of adoption. Users tend to be ahead of companies by a wide margin when it comes to embracing new tech; itโs a known phenomenon that allocates people into innovators, early adopters, early majority, late majority, and laggards. In this case, the advanced crowd is even teaching the creators of AI services what can be done. The hyped version of this is Clawdbot running on Claude and taking off at a crazy fast pace. These kinds of users are the ones that might be setting up their own customized agents and getting them to take over everyday tasks for them while watching Moltbook like itโs Netfilx (with recent research showing strong expectations that AI agents will meaningfully improve productivity)
Why AI must be built into the business, not bolted on
At a company or enterprise level the story is different. Companies in general are just beginning to give AI access to their employees (source). In fintech specifically, the majority of companies are coming around to the benefits of AI, with the biggest advantage being its application to battle fraud. In fact, this is one of the most interesting use cases for modern AI; exploring how it can advance the protection of users more rapidly than bad actors can dream up ways to go after them.
Beyond these, I expect we will see a surge in physical AI (where AI and physical components are joined) such as surveillance, smart materials, retail sales etc all take off faster than other industries.
Sean Blanchfield, Jentic Co-Founder and CEO
IDC’s CIO Playbook 2026 confirms what we hear every day from enterprise technology leaders – the conversation is moving from “should we adopt?” to “how do we scale safely?” The finding that only 46% of proofs of concept reach production is the single most important number in this report. It reflects what we see in the market: organizations are struggling with integration, reliability, security, governance, and maintainabilityโฆ not with model intelligence. We strongly agree with IDC’s emphasis on hybrid deployment as the default enterprise model.
With 82% of EMEA organizations planning on-premises or edge AI workloads, it’s clear that AI infrastructure must meet data where it lives. This validates the platform-first, vendor-neutral, open-standards, VPC-deployed approach that we build for in Jentic. Enterprises want a systematic way to deploy AI across complex, distributed landscapes without being locked into a single vendor or cloud; they need their AI journey to be on a path to autonomy, not increased dependency.
The report’s identification of agentic AI as the next frontier, with a 65% year-on-year increase in adoption interest, is particularly striking. But it’s the challenges alongside that enthusiasm that resonate most: technical complexity, integration with existing systems, and security concerns. These are the daily reality of every enterprise trying to move agents from prototype to deployment. What’s missing from most agentic AI strategies isn’t a better model โ it’s the platform that allows the enterprise to innovate at AI speed.
Why so many AI pilots never reach production
Where we would go further is the fleet management challenge. The most advanced technology leaders we’re speaking to have already moved past thinking about individual AI use cases. They’re asking a new question: how do I manage and maintain thousands of agents and workflows in production, in the face of ever-changing business requirements? This is where the conversation shifts from point solutions to platform thinking. Reliability, security, and compliance matter enormously โ but so does the operational reality of orchestrating AI at fleet scale, with consistent observability, control, and lifecycle management across the entire estate. That’s the maturity leap that separates organisations running a handful of successful pilots from those embedding AI systematically into how they operate.
One area where we’d also push further is the treatment of “shadow AI” as primarily a trust concern. Shadow AI is a symptom, not a cause. It emerges when official channels can’t deliver AI capabilities fast enough. The answer is to make the governed path the fastest path, so that doing things properly is also the quickest route to value.
The race for enterprise AI is real. But the winners won’t be those with the most sophisticated models โ they’ll be those with the strongest foundations, focused on AI-enablement of their existing platforms, who build the infrastructure to innovate at inference speed.
Ahmed Bashir, CTO at DevRev
Scaling challenges are foundational: the top success factors cited are AI skills and training, scalable infrastructure, strong data governance, and integration across systems.โ
The IDC study rightly calls out skills, infrastructure, and governance as scaling barriers. But the deeper issue is architectural coherence. Many organizations are attempting to scale AI on top of fragmented systems, where data, permissions, and workflows are distributed across departmental silos. In that environment, AI agents can only federate across APIs, which introduces latency, inconsistency, and governance blind spots. Scaling AI doesnโt mean deploying more models, it requires unifying enterprise memory so systems can reason across the business with context and control.
Agentic AI interest is accelerating
The number of organizations preparing for agentic AI has increased 65% year-on-year, but most say they are still 12+ months away from scaled deployment.
The surge in interest around agentic AI shows that organizations now want AI to take action, not just generate insight. But action raises the stakes. When agents operate across systems, they require structured long-term memory, real-time integration, and clear operational boundaries. The fact that most companies remain 12 months away from scaled deployment reflects how much foundational work is still required. Agents cannot simply be layered onto legacy environments, systems must be designed to support them.
Governance is a growing pressure point
Many organizations still describe their AI governance as โdevelopingโ or โad hoc,โ with top concerns including lack of responsible AI, data security risks, and shadow AI.
When agents begin operating across enterprise systems, governance cannot remain โdevelopingโ or โad hoc.โ Responsible AI, data security, and shadow AI concerns emerge when governance lives in policy documents rather than in system design. Agents need explicit permissioning, auditable workflows, and embedded controls built into the platform itself. Successful organizations will be those that treat governance as an architectural principle from day one, rather than attempting to retrofit it after deployment.
Milan Novotnรฝ, Senior Director of SEO and Content, CloudTalk
We agree with the reportโs thesis that AI has shifted from a learning phase to a core engine of business performance. At CloudTalk, we have moved beyond seeing AI as a chatbot add-on. We treat it as an end-to-end workflow (with some supervision still needed, of course).
Where we diverge is in the report’s cautious tone regarding the pace of adoption. The playbook notes that many organizations are still in structured pilots. Our stance is far more radical. The pilot phase is over. The most dangerous place for a company to be right now is not rejecting AI, but rather endless piloting. While organizations wait for perfect foundations, the market is accelerating. Companies only testing today are already putting themselves at a massive disadvantage.
We do not implement isolated AI features. Instead, we are implementing complete AI agent workflows that fundamentally transform our engineering processes. Our developers start their day with an AI-prioritized overview of system events and metrics aggregated from Jira, GitHub, and Slack. The AI agent proposes complex solutions rather than just snippets of code. This allows our engineers to focus on business alignment rather than syntax.
In Sales and CRM, we have deployed our own AI Voice Agents to revive dormant leads. Out of 8,000 neglected contacts, our agents generated 160 qualified opportunities and a pipeline worth nearly โฌ7,000 entirely without human intervention. This confirms the playbookโs insight that AI is a massive driver for revenue growth and profit.
We are observing a transformation in the role of the developer. Writing the actual code is no longer the bottleneck. Today, the real challenge is understanding the problem, designing the architecture, and accurately formulating prompts for the AI. A junior developer equipped with AI can now deliver what a medior previously could, while seniors are increasingly required to demonstrate much stronger leadership skills.
We also anticipate the end of the myth that the human touch is necessary in frontline customer support. Routine calls do not need humans. The report highlights customer service as a top area for AI ROI. We see this firsthand. Our clients using AI Voice Agents have seen up to a 150% increase in bookings while saving dozens of hours of manual work.
The AI defense line
AI is deeply integrated into our production processes. Most code changes at CloudTalk first pass through an AI defense line. This AI finds bugs, checks performance, and generates tests before a human ever reviews them.
While AI handles routine work for us, 100% of the responsibility remains on us. We align with the reportโs emphasis on trust and governance and do not settle for blindly deploying AI. We build our own RAG (Retrieval-Augmented Generation) approaches to ensure that an AI model provides answers based on verified sources rather than generating information off the top of its head.
Confirmed Suspicion: The fact that 41% of organizations realized improved CX validates exactly what we see with our AI Voice Agent users. AI is no longer theoretical. It is already raising service quality and reducing operational effort.
The Big Surprise: The report mentions that only 46% of POCs reach production. To us, that is a significant red flag for the industry. It suggests a massive integration and governance gap that CIOs must bridge immediately if they want to see the 2.78 dollar return for every dollar spent that the report predicts.
We believe this low production rate is often caused by a fear of moving beyond the lab. While we always advocate for deploying robust and reliable AI (not just a makeshift MVP), there is no substitute for real world usage. High performance AI is not built in a vacuum. It is refined through a disciplined cycle of live deployment and constant iteration based on actual performance. There is a fine line between quality control and stagnation. If you spend too long perfecting a model in a staging environment, you will miss the boat while your more agile competitors are already learning from their users and evolving.
Filip ลฝรญลพala, CTO of Patron GO
What I agree with most is that the AI conversation has shifted from hype to execution. That resonates. The real challenge is not building demos, itโs embedding AI into core processes where it actually changes economics. In fintech especially, that means risk, compliance, personalization, revenue. Where Iโm more skeptical is around how โreadyโ enterprises claim to be. Strategy decks are ahead of operational reality in many cases.
At Patron GO, we donโt treat AI as a layer on top of the product. It is the product logic. Weโre building systems that detect financial opportunities from transaction data, prioritize them, personalize the communication, and route them either to automation or to a human guide. Itโs less about chatbots and more about decision engines. The goal is simple: money optimization that runs itself.
I think weโre moving toward autonomous finance. Not just recommendations, but execution. Switching providers automatically, optimizing subscriptions, managing liquidity in real time. At the same time, governance AI will become critical. As automation increases, so does regulatory scrutiny. The winners will be those who can combine intelligence with control.
Weโre well beyond experimentation. AI is embedded in our daily operations and in the core of the app. It drives opportunity generation, personalization, and internal workflows. But weโre still in the early stages when it comes to full autonomy. The real leap will be seamless orchestration between AI systems and human experts without friction.
What didnโt surprise me is the gap between ambition and scaled impact. Many companies say AI is strategic, fewer can point to material revenue driven by it. That confirms what Iโve believed for a while: access to models is not the differentiator. Architecture, clean data, and disciplined execution are. Thatโs where the race will be won.
Vijay Kumar, EVP & Chief Innovation Officer, Rimini Street
The data from IDC paints an ambition gap – between what enterprises want to achieve with AI – and the challenges they need to overcome. Ranked as the number #1 business priority for 2026, there’s clear confidence in this technology, which means increased competition as enterprises vie to make AI adoption a success. Organisations that wait for AI to arrive through costly vendor upgrade cycles rather than building composable AI capabilities today risk falling behind.
While 94% of organisations expect a positive return on their investment, much of the AI spend remains fragmented across co-pilots, basic automation, and digital assessments. Enterprises need to consolidate their spend on initiatives that can scale, and consider AI as an operating layer fundamental to the success of their enterprise strategy – a sophisticated action layer that runs through the core of ERP.
The research also reveals the pressures of governance, with organisations rushing toward agentic AI while simultaneously admitting their governance as “developing” or “ad hoc.” Defining AI is unclear when enterprises see machine learning, chatbots, and virtual agents all housed under the same umbrella, and scaling Agentic AI becomes a question mark if it can’t contact critical business systems. To avoid this, organisations must establish governance and data discipline from the start. In practice, this means following a human-in-the-loop approach, deploying AI in validated use cases, and ensuring that the RAG architecture is included.
Agentic AI is the next frontier – but organisations arenโt ready
With organisations preparing for agentic AI increasing 65% year-on-year, it’s vital they target high-friction enterprise workflows. Enterprises need to think of scalability as more than just GPUs and compute power – it requires foundational ERP sub-process knowledge. As enterprises pursue AI, they must move away from the “experiment” mindset. Agentic AI ERP will become the differentiator there, layering AI on top of existing legacy ERP stacks, and keeping critical systems running.
AI will reward the prepared, and for enterprises serious about deploying agents at scale and safely in the next year, they must ensure their data and compliance are ready. By using your legacy proprietary data to develop this compliance framework, you can ensure AI is specific to your enterprise, and create models that uniquely honour your business needs. AI is no longer just an IT initiative, and process and business owners can drive AI applications directly on top of their ERP, with IT maintaining governance and control.
Agentic AI ERP is a modern way to overcome the status quo, in which enterprises are constantly pushed to migrate, creating budgetary pressure and overlooking the hybrid-first advantage of integrating AI across on-premises, edge, data centres, and the cloud. 82% of enterprises planning a hybrid of on-prem or edge deployments is a key example of the opportunity for Agentic AI ERP: complex, distributed AI that interacts with ERP, building modular systems that enable strategic AI initiatives on your own terms.