
Enterprise AI has entered a different phase.
The challenge is no longer convincing organizations to experiment with artificial intelligence. AI is already spreading across business functions, development environments, cloud platforms, enterprise applications and increasingly autonomous agents.
The new challenge is control.
IBM’s 2026 Tech Leader Study, based on research by the IBM Institute for Business Value and Oxford Economics, surveyed 2,000 senior technology executives across 33 geographies and 19 industries. Its findings point to a growing gap between the speed at which enterprises are deploying AI and their ability to see, govern and financially manage it.
Two-thirds of surveyed CIOs and CTOs said they are being held accountable for AI systems they do not fully control.
And 70% said teams across the business are deploying technology faster than IT can track.
That is not simply an AI adoption problem.
It is an enterprise AI control gap.

AI Is Scaling Faster Than Governance
IBM found that 77% of surveyed organizations say AI adoption is already outpacing their current governance capabilities.
At the same time, the pressure to scale is increasing.
Technology leaders surveyed by IBM expect the number of deployed AI agents to increase by 38% by 2027. While 80% reported CEO-driven AI transformation mandates, only 11% believe they are fully prepared for the scale of AI agent deployment expected over the next year.
These figures expose a structural problem.
Organizations are being asked to deploy more AI, increase automation and introduce greater autonomy while many of the systems used to manage technology were designed for a very different environment.
Traditional enterprise IT management assumes that technology assets can be identified, assigned an owner, reviewed periodically and governed through relatively predictable change processes.
AI changes that model.
Providers can change.
Models can change.
Costs can vary with consumption.
Employees can adopt new AI services independently.
Developers can connect models through APIs.
Applications can introduce embedded AI capabilities.
Agents can access tools, data and other systems.
MCP and similar integration mechanisms can expand what an AI system can reach and what actions it can perform.
The AI landscape is becoming dynamic.
Governance built around static inventories and periodic reviews risks becoming outdated before the review is complete.

Accountability Without Visibility Is a Dangerous Combination
The IBM finding that technology leaders are responsible for systems they do not fully control deserves particular attention.
Accountability normally assumes visibility.
A CIO cannot meaningfully govern an AI environment without knowing what exists within it.
A CISO cannot evaluate AI-related exposure without evidence of which services, applications, identities and agents are active.
Finance cannot manage AI investment without understanding consumption and spend.
Governance teams cannot assess compliance without connecting AI activity to ownership, policies, data and organizational context.
Yet enterprise AI can now emerge through many different channels.
An officially purchased AI platform is visible.
An employee creating a personal account on an AI service may not be.
An API used by a development team may appear only in cloud billing or technical telemetry.
An AI feature embedded inside an existing SaaS application may never appear as a separately purchased AI product.
An agent created by a business team may exist outside the traditional application inventory.
A model connected through an orchestration framework may change without the underlying business process changing.
Visibility therefore cannot stop at the provider level.
Enterprises need to understand the relationships between providers, models, applications, identities, agents, tools, usage, cost and organizational ownership.
Agentic AI Makes the Control Gap More Serious
AI agents make this problem fundamentally different from traditional software governance.
A conventional application generally waits for a person to use it.
An AI agent may be permitted to evaluate information, select tools, interact with other systems and execute multiple steps toward an objective.
That means governance is no longer concerned only with whether an application has been approved.
Organizations need to ask:
Which agents exist?
Who owns them?
Which model do they use?
Which identity do they operate under?
What tools can they access?
Which systems can they modify?
What actions are they permitted to take?
What actions have they actually taken?
Can a human intervene?
Is the execution traceable?
The scale of the operational challenge is already visible in IBM’s research.
Surveyed organizations reported an average of 54 AI agent incidents during the previous year, defined as unintended or harmful events that required human correction. Of those incidents, 17% were reported as high severity and required more than four hours to contain. Among those high-severity incidents, 37% involved data exposure or security breaches, 33% caused cascading system failures and 17% triggered compliance issues.
IBM also found that organizations embedding controls directly into their AI systems experienced 25% fewer incidents than organizations relying on manual governance.
The implication is important.
Manual governance may work when an organization has a small number of AI experiments.
It becomes much harder when AI systems operate continuously and agents begin acting across multiple enterprise systems.

Governance Is Not the Same as Blocking AI
The obvious response to loss of control is to restrict access.
Sometimes that is necessary.
An organization should be able to prevent clearly inappropriate AI usage, protect sensitive information and enforce security controls.
But blocking AI is not the same as governing AI.
A mature governance model needs to distinguish between legitimate adoption, unmanaged adoption, unacceptable risk and innovation that needs an appropriate controlled path.
This becomes especially important when business teams are adopting technology faster than central IT can track.
The objective cannot simply be to stop decentralized innovation.
The objective is to make decentralized adoption visible, attributable and governable.
That means organizations need enough evidence to understand not only that an AI service or agent exists, but also the context in which it is being used.
The same AI technology could represent:
an approved enterprise capability,
an unmanaged business experiment,
a security concern,
an unnecessary duplicate subscription,
an underutilized license,
a high-value productivity tool,
or a critical agent performing an important business process.
Without context, these can look identical in a technical inventory.
With context, they require completely different management decisions.
The AI Control Gap Is Also a Financial Control Gap
IBM’s study shows that the governance issue does not stop with operational risk.
AI spending is becoming a material part of enterprise technology budgets.
Surveyed technology leaders expect AI spending to grow from just under 15% of IT budgets in 2025 to nearly 25% by 2027, representing a 71% increase in two years.
But financial management capabilities are not keeping pace.
IBM found that:
84% of surveyed technology leaders had not fully operationalized AI financial management.
85% still lacked full visibility into real-time AI spending.
This introduces another form of control gap.
Organizations may know how much they spend on traditional software because licenses, contracts and subscriptions are relatively predictable.
AI economics can be different.
Costs may come from:
subscription licenses,
API consumption,
tokens and requests,
cloud infrastructure,
model hosting,
embedded AI services,
agent execution,
developer tooling,
and external AI services purchased by different business units.
The same organization may therefore have several different economic models operating simultaneously.
A provider invoice answers only part of the question.
Enterprise management needs to know who generated the spend, which team or project it belongs to, which model or service was used, whether licenses are actually being adopted, and whether the cost supports a meaningful outcome.

More Control Does Not Necessarily Mean Less Innovation
One of the most interesting findings in the IBM research is that stronger control was not associated with slower AI deployment.
IBM’s analysis found that organizations embedding control into their AI systems deployed 16 times more AI agents than organizations relying on manual governance. The same group was associated with 18% higher operating margins and substantially lower AI budget consumption in IBM’s analysis.
Organizations with strong financial discipline also deployed 2.4 times more AI agents without a higher AI-to-IT budget ratio and were three times more likely to say they were fully prepared for AI scale.
These are associations identified in IBM’s research, not proof that governance by itself causes higher margins or agent deployment.
But they challenge an important assumption.
Governance does not have to be the brake on AI adoption.
Poor governance can become the brake.
When organizations lack visibility, ownership, cost attribution and clear decision processes, every new AI initiative creates uncertainty.
When those foundations exist, organizations can make decisions faster because they understand the boundaries within which AI can operate.
Provider Flexibility Is Becoming Part of AI Governance
IBM also found that surveyed organizations that designed for adaptability early, keeping workloads portable and models replaceable rather than creating hard dependencies, reported a 10% higher return on AI investment in 2025.
This introduces another dimension of AI governance.
Governance should not mean locking an enterprise into a single provider or model.
The AI market is changing too quickly for that assumption to be safe.
Organizations may need different providers for different workloads.
Models will improve.
Pricing will change.
Regulatory expectations will evolve.
Business requirements will shift.
Some providers will become stronger while others may become less relevant.
Enterprise AI management therefore needs to preserve provider-specific detail while still creating a normalized management view across the organization.
This enables leadership to compare adoption, cost, risk and value without requiring every AI service to behave identically.
The objective is not provider uniformity.
It is management consistency across provider diversity.
From AI Control Gap to AI Management Layer
The IBM research raises a fundamental management question:
If AI adoption, AI agents and AI spending are all scaling faster than traditional governance processes, what does an enterprise need to regain control?
The answer is not another static inventory.
It requires a connected management layer.
This is the problem AssetUno AI is designed to address.
AssetUno AI brings together evidence from AI providers, enterprise workspaces, developer AI tools, security sources, identity context and outcome systems to create a structured view of the enterprise AI landscape.
The management process can be understood across several connected capabilities.
AI Discovery and Shadow AI identify known, unmanaged or insufficiently governed AI services and connect available evidence with organizational context.
AI Landscape and Registry establish what providers, services, models and AI assets exist, together with ownership and approval information.
Agentic AI Governance extends visibility toward agents, executions, tools, actions and connections such as MCP as organizations move toward autonomous systems.
Organizational Context and Attribution connect AI activity and spend to users, teams, departments, cost centers, projects and repositories.
Usage & Cost Optimization brings together available consumption, token, request, subscription and cost information to support financial visibility and optimization.
Governance and Risk connect evidence with policies, ownership, exceptions, risk and management actions.
AI Value & Outcomes moves the discussion beyond consumption by connecting AI usage with work output, accepted output and measurable business outcomes.
The objective is not to replace security tools, identity systems, AI providers or financial systems.
It is to connect their evidence into a management context where enterprises can make better AI decisions.

Control Starts With Knowing What Exists
The IBM study describes a situation that will become increasingly difficult to ignore.
AI deployment is accelerating.
Agents are multiplying.
Technology decisions are becoming more decentralized.
Spending is increasing.
Operational incidents are appearing.
Governance processes are struggling to keep pace.
At the same time, CIOs and CTOs remain accountable.
This changes what enterprise AI maturity should mean.
Maturity cannot simply be measured by the number of AI initiatives, users or deployed agents.
An enterprise should also be able to answer:
What AI exists across the organization?
Which providers, models and agents are involved?
Who owns them?
Who is using them?
What systems and data can they access?
What actions can agents perform?
How much are we spending?
Where should that cost be attributed?
Which risks require action?
What measurable business value is being created?
The first generation of enterprise AI strategy focused on adoption.
The next generation must focus on visibility, control, governance and value at scale.
Because when AI moves faster than the enterprise can understand it, adoption itself becomes a source of risk.
And when governance can move at the same speed as AI, control becomes an enabler of scale rather than an obstacle to it.
Primary Reference: IBM Institute for Business Value, 2026 Tech Leader Study: Building the IT Foundation for Agentic AI at Scale
The study was conducted with Oxford Economics and surveyed 2,000 senior technology executives across 33 geographies and 19 industries between January and April 2026.



