Declining AI maturity confidence reflects a more realistic appraisal of challenges
For many organizations, lower confidence in AI looks like bad news. It is actually a sign of progress. When companies first launch AI initiatives, especially pilot projects, success is relatively easy to achieve because the environment is controlled and the scope is limited. Production is different. AI agents begin interacting with real systems, making decisions that affect real business processes, and operating continuously. That is where the difficult questions appear.
The Q3 2026 trends report shows this shift clearly. Six months ago, 40% of organizations considered themselves mature in AI deployment. Today, that figure is 23%, based on a survey of 800 IT leaders across the U.S. and U.K. At first glance, this looks like a decline. In reality, it suggests that organizations have gained a better understanding of what enterprise AI actually requires.
This is an important transition for executives. High confidence without operational experience can create a false sense of readiness. Once AI reaches production, leaders discover challenges around governance, security, visibility, accountability, and operational resilience that were invisible during pilot testing. Lower confidence at this stage often means leadership teams are measuring themselves against higher standards instead of celebrating early success.
That distinction matters. AI adoption is no longer about proving that a model can generate useful output. It is about proving that AI can operate reliably inside the business every day while meeting security, compliance, and operational expectations. Organizations that recognize these gaps early are generally in a stronger position to build AI into their long-term strategy.
For executive teams, the objective should not be maximizing confidence scores. The objective should be creating confidence that is supported by measurable operational capability. Honest assessment makes investment decisions more accurate, governance more effective, and future expansion significantly easier.
Scaling AI successfully requires a robust governance framework
Getting an AI pilot running is relatively straightforward. Scaling AI across an enterprise is where the real work begins. The requirements change completely once AI agents start accessing production systems, interacting with customers, supporting employees, or making decisions that affect business operations.
A pilot usually performs one task under controlled conditions. A production AI system operates continuously, often without direct human supervision. That changes the risk profile. Organizations now need to know which AI agents are running, what systems they can access, what actions they are allowed to perform, and how quickly unusual behavior can be detected and investigated. These capabilities are part of governance.
The research indicates that 84% of organizations plan to expand AI use in IT operations over the next 6 to 24 months. That level of planned investment makes governance a business priority rather than a technical detail. Expanding AI without expanding governance increases operational risk as AI becomes more deeply integrated into core business processes.
Executives should also recognize that governance is an enabler of growth. Organizations often view governance as something that slows innovation. In practice, the opposite is true. Strong governance allows companies to deploy AI more broadly because leaders have greater confidence in security, compliance, accountability, and operational reliability. Teams spend less time responding to unexpected issues and more time delivering business value.
This also changes how success should be measured. Counting AI deployments is not enough. Business leaders should evaluate whether AI is producing measurable outcomes while operating within clearly defined controls. That means monitoring performance, managing access rights, maintaining auditability, and ensuring every AI agent has clear ownership throughout its lifecycle.
The organizations that scale AI most effectively are not necessarily those deploying the fastest. They are the ones building the operational foundation that allows AI to expand safely, consistently, and with confidence across the enterprise.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
The accelerated deployment of AI is outpacing the implementation of necessary governance controls
Enterprise AI is moving quickly. Governance is not keeping up. That gap is becoming one of the biggest challenges facing organizations today. Many companies have focused on deploying AI agents as fast as possible to capture productivity gains, but they have invested less in the controls needed to manage those systems at scale.
This creates a predictable problem. AI agents become embedded across different business functions, often using multiple platforms with different security models, monitoring tools, and access controls. Over time, leaders lose a complete view of where AI is operating, what it can access, and how its actions can be reviewed. The technology continues to expand, but visibility does not expand at the same pace.
High-performing organizations simplify their technology environments instead of adding separate tools for every new AI capability. They treat AI agents as governed digital identities with clearly defined permissions, ownership, and accountability. They also measure business outcomes rather than simply tracking how many AI systems have been deployed.
This is a leadership issue as much as a technology issue. Every new AI deployment increases operational complexity. Without clear governance standards, complexity grows faster than organizational control. That affects cybersecurity, compliance, operational resilience, and ultimately customer trust.
The report highlights the business impact of building governance early. Organizations in the highest tier of the maturity model are five times more likely to report no barriers to expanding their AI agents compared with the average organization. That finding suggests governance is not slowing AI adoption. It is making expansion more practical because organizations have already established the operational foundation needed to scale.
Executives should view governance as part of enterprise infrastructure rather than as an additional compliance requirement. AI initiatives will continue to grow over the coming years. Organizations that build governance into their operating model now will be able to expand with fewer disruptions, lower operational risk, and greater confidence in the decisions their AI systems make.
Weak governance of non-human identities is becoming one of the most significant challenges
Every AI agent operating inside an organization has a digital identity. That identity determines what systems it can access, what actions it can perform, and what information it can retrieve. As organizations deploy more AI, the number of these non-human identities increases rapidly. In many companies, they already outnumber human users.
The challenge is that governance has not evolved at the same speed. Human employees usually have established onboarding processes, defined responsibilities, access reviews, and formal offboarding procedures. Many AI agents have none of these controls. They may continue operating long after their original purpose has ended, while retaining permissions that are no longer appropriate.
These unmanaged systems are often called “Zombie Agents.” The concern is not simply that they exist. The greater issue is that they can continue accessing business systems without clear ownership or effective oversight. As organizations deploy hundreds or thousands of AI agents, unmanaged identities become increasingly difficult to monitor, increasing security exposure and reducing accountability.
The report illustrates the scale of the issue. Only 21% of organizations have implemented non-human identity governance, despite non-human identities already outnumbering human users in 83% of organizations. This suggests that governance practices have not kept pace with the rapid expansion of AI across enterprise environments.
For executive teams, this should be treated as a strategic priority rather than a technical detail. Every AI agent should have a documented owner, clearly defined access permissions, continuous monitoring, regular access reviews, and a structured process for retirement when it is no longer needed. These controls establish accountability and reduce unnecessary security risk.
The broader issue is trust. AI can only become a core part of business operations if leaders understand who, or what, is performing critical actions inside the organization. Clear governance creates that visibility. It enables organizations to expand AI with greater confidence while maintaining security, regulatory compliance, and operational discipline.
Honest self-assessment and transparency are essential for responsible, long-term AI adoption
One of the strongest signals of AI maturity is not high confidence. It is the willingness to identify weaknesses before they become larger problems. Organizations that reassess their AI readiness after moving into production are often building stronger foundations than those that continue to report high confidence without the same operational experience.
Companies lowering their AI maturity ratings are not reducing their ambitions. They are increasing their expectations. They recognize that deploying AI is only one part of the challenge. Long-term success depends on building governance that covers AI agents alongside people and devices, creating unified oversight across the technology environment, and measuring business outcomes instead of simply counting deployments.
This shift represents a more disciplined approach to AI investment. As organizations gain practical experience, they move away from viewing deployment as the primary objective. Instead, they focus on operational reliability, security, accountability, and measurable business value. Those priorities create a stronger foundation for expanding AI across critical business functions.
The report reinforces that organizations are not slowing their AI strategies. According to the survey, 84% of organizations plan to expand AI use over the next two years. The difference is that many now recognize expansion must be supported by stronger governance, clearer ownership, and better operational controls. Growth without these capabilities introduces unnecessary risk that becomes more difficult to address later.
For executives, this is an important leadership lesson. AI should be governed with the same discipline applied to any business-critical capability. Regular assessments of AI maturity should be viewed as strategic management tools rather than performance scorecards. A lower maturity rating today may reflect a more accurate understanding of current capabilities and a clearer roadmap for improvement.
Organizations that encourage honest reporting are also better positioned to make informed investment decisions. Teams are more likely to identify gaps in identity management, security, compliance, monitoring, and operational processes before those gaps affect customers or business operations. That enables leadership to prioritize investments based on measurable risk rather than assumptions.
Ultimately, responsible AI adoption depends on maintaining high standards as systems become more capable and more deeply integrated into the enterprise. Organizations that combine ambitious AI strategies with disciplined governance, transparent evaluation, and continuous improvement will be better equipped to scale AI safely and consistently. The goal is not simply to deploy more AI. It is to build AI capabilities that executives, employees, customers, and regulators can trust over the long term.
Main highlights
- Build confidence through production experience: A drop in AI maturity confidence can indicate stronger operational awareness. Leaders should treat honest reassessments as a way to identify governance gaps before they become larger business risks.
- Make governance part of every AI deployment: Moving from pilots to production requires visibility, accountability, access controls, and continuous monitoring. As 84% of organizations plan to expand AI use, governance should scale alongside AI investments.
- Close the governance gap before expanding AI: Rapid deployment without consistent oversight increases operational, security, and compliance risks. Organizations that simplify their technology environments and govern AI agents as managed identities are better positioned to scale with fewer obstacles.
- Prioritize non-human identity governance: AI agents need the same lifecycle management, ownership, and access controls as human users. With non-human identities outnumbering human users in 83% of organizations and only 21% implementing dedicated governance, this is an immediate security and accountability priority.
- Measure AI maturity by operational discipline: Long-term AI success depends on transparent self-assessment, measurable business outcomes, and strong governance foundations. Organizations that raise their operational standards today will be better equipped to scale AI responsibly as adoption accelerates.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


