high level ai enterprise
AI adoption hit enterprise walls fast, but governance is finally catching up.

I've watched three enterprise software cycles move through this industry, and none of them spread like this one. Adoption used to take a decade, but this one took about eighteen months. The real question now is whether anyone can actually see what the technology is doing once it's inside the walls, touching payroll, contracts, and customer records at scale.
McKinsey's 2025 State of AI survey polled more than 1,000 participants and found 78% of organizations now use AI in at least one business function, up from 55% in 2023. Cloud didn't move that fast, and mobile didn't either. Generative AI alone has landed in at least one function at 71% of those same organizations, and separate industry data puts the number even higher for large enterprises: 87% reporting AI already in production, with average annual investment around $6.5 million per organization.
So what does that mean once you're standing inside one of these companies? AI is running payroll checks, reading customer records, flagging compliance issues, moving freight through supply chains (systems where a mistake actually costs money). Adoption stopped being the interesting question a while back. What matters now is what happens after the thing is already running inside your infrastructure, quietly, at volume, mostly unwatched.
The market backdrop: a sector growing faster than almost any software category in history
Market size estimates for 2025 depend on who's counting. IMARC Group puts the enterprise AI market at $40.4 billion, while Emergen Research says $62.50 billion. That's a wide gap, and I'm not going to pretend one source is right and the other is sloppy; the direction is what matters, and every major forecaster has this sector climbing steeply, with compound annual growth rates cited between 30.2% and 37.6%.
Generative AI is the sharpest example. Menlo Ventures tracked it going from $1.7 billion to $37 billion in spend since 2023, now sitting at 6% of the global SaaS market. Menlo calls it the fastest-growing software category it has ever tracked, and the curve backs that up. Gartner projects total global AI spending will rise 47% year over year in 2026, landing at $2.59 trillion.
Numbers like that stop being abstract the moment you're sitting inside a company trying to keep pace with them. New tools, new vendors, new models, new integrations, all arriving faster than anyone can build a framework to manage them. Growth this fast doesn't wait for governance to catch up. If I were running risk at any of these companies right now, that gap (between how fast deployment moves and how slow governance moves) is exactly where I'd point my attention.
Where enterprise AI spending is actually going in 2026
Break down a typical AI budget in 2026 and it lands roughly here: about 35% to software and SaaS AI tools, 22% to cloud infrastructure, 17% to internal AI talent. The rest splits across implementation, data platforms, and governance.
Governance is the line item growing fastest, and it's not close. It now eats up somewhere between 8% and 12% of AI budgets in 2026, up from just 3% to 5% in 2024. That's doubling, sometimes tripling, in two years flat, and three forces are pushing it: EU AI Act enforcement, adoption of the NIST AI Risk Management Framework, and new audit requirements tied to AI agents running in production.
CIOs tell the same story from a different angle. Evanta surveyed 1,100 of them and found cybersecurity and risk management has held the top priority spot three years running, with operationalizing AI and data strategy close behind. One detail worth sitting with: vendor-led and co-build partnerships succeed roughly 67% of the time, while pure internal builds succeed only about 33% of the time. Going it alone is the harder bet, and the data isn't subtle about that.
Budgets shifting toward governance is a good sign, but a line item on a spreadsheet only sometimes reflects a control system actually running in real time, and plenty of organizations have the former with nothing resembling the latter.
What functions and industries are deploying AI — and where the real ROI is hiding
Customer-facing work grabbed the biggest share of 2025 deployments: chatbots, recommendation engines, sentiment tools. That makes sense, since it's visible, easy to defend in a board meeting, and it photographs well in an annual report.
Industry observers have noted that visible, customer-facing use cases tend to attract the largest share of investment, even though back-office automation is widely seen as delivering comparable or stronger returns. Document processing, data reconciliation, compliance checks, invoice handling — none of it glamorous, but all of it high-volume and rules-heavy. Process automation leads real enterprise adoption outright at 76% of organizations. Financial services has been among the leading sectors, pouring money into credit modeling, compliance automation, and personalized customer experience.
Line those two facts up and something uncomfortable falls out. The functions getting the most investment aren't the functions generating the most return, and the functions with the best return happen to sit on the most sensitive data in the company. An ungoverned agent that touches the wrong file in a compliance workflow isn't an efficiency problem anymore; that's the kind of exposure that ends up in a regulatory filing.
The ROI picture is real but deeply uneven — and most organizations haven't done the work to close the gap
Start with the skeptics, because there are plenty. A meaningful share of executives have reported that AI has yet to deliver measurable cost or revenue benefit for their companies. That sentiment is real, and it's tempting to read it as proof the whole thing is overhyped.
Except McKinsey's 2025 data tells a different story: organizations widely report measurable ROI from at least one AI initiative, most often in automation, forecasting, or customer operations. Deloitte's 2026 State of AI report surveyed 3,235 leaders across 24 countries and found productivity gains among the most commonly reported outcomes, with worker access to AI tools rising 50% over 2025. ISG's 2025 State of Enterprise AI Adoption Report found 31% of AI use cases reached full production, double the 2024 figure, though cost and productivity gains are still underdelivering against what leaders originally hoped for.
Both things are true at once, and this reflects two different populations of companies getting counted in the same survey. Research consistently finds that relatively few organizations have actually redesigned their workflows around how AI works, rather than bolting AI onto processes built for humans. Workflow redesign is the single factor most tied to financial results, full stop. The companies pulling ahead share a pattern: a serious share of the digital budget goes to AI, most of the AI resources go to people and process rather than technology alone, and ROI is expected over years, not quarters. The gap between winners and losers traces straight back to how much structural work got done before anyone flipped the switch.
Landmark deployments show what scale actually looks like when it works
Numbers make this concrete fast. Klarna's AI agent took on substantial workloads previously handled by large teams, generating significant reported savings within its first year of scaled deployment. JPMorgan runs a large and growing number of AI use cases in production every single day, which is a strange thing to type and an even stranger thing to audit.
Morgan Stanley deployed a code review agent that processed large volumes of legacy code, freeing engineers from manual code translation into actual product work. Salesforce reported meaningful legal cost reductions through contract automation.
Each of these is an agent reaching into code repositories, legal contracts, financial systems, or customer records at real production volume, far past the chatbot-demo stage. At that scale, an ungoverned agent carries systemic exposure that scales right along with the deployment. Part of why these particular rollouts worked is that the companies built operational infrastructure around the agent instead of just pointing a clever model at their data and hoping. What none of these case studies show you, and what actually matters more than the headline savings number, is the control architecture sitting underneath. That's worth digging into.
Agentic AI is the defining shift of 2026 — and it changes the governance problem entirely
Agentic AI has ranked among Gartner's top strategic technology trends, and sustained prominence on that list signals a structural shift in how enterprise software gets built.
Analysts expect task-specific agents to appear across a rapidly growing share of enterprise applications in the near term. I haven't seen a steeper projected adoption curve anywhere else in the research. Agentic AI is genuinely different from what came before it, and the difference matters specifically for governance. Agents take actions, not recommendations. They write code, execute transactions, move data, and trigger downstream workflows on their own, often without a human signing off on each step. They also operate across systems simultaneously, so a single agent might touch a CRM, a data warehouse, a document store, and an outside API within one task.
The Model Context Protocol, MCP for short, has become the connective tissue that makes this possible. It's the standard letting AI agents talk to enterprise tools and data sources directly, and every MCP server a company adds expands what its agents can reach into. That's exactly where the governance gap opens up. Companies deploying agents without a registry of what those agents can access, without role-based controls, without real-time visibility into agent behavior, don't have a reliable picture of what their own AI is doing inside their own systems. The risk isn't some dramatic act of malice; it's quieter than that. The company simply never finds out what the agent touched, because nobody kept a record of agent activity in the first place.
The governance infrastructure that separates managed scale from ungoverned sprawl
Real governance at this scale rests on a few concrete pieces, more substantial than a policy document sitting in a shared drive. A centralized registry of every AI agent and every MCP server in use comes first, because an identity nobody's tracking is an identity somebody eventually exploits. Role-based access controls need to apply to agents the same way they apply to human employees; what an agent is allowed to touch should be a decision someone made on purpose, not a default nobody thought through. Real-time observability into what agents are accessing matters just as much, since an audit log you read after something's already gone wrong is a postmortem, not a safeguard. A gateway layer enforcing policy while the agent is actually running, not after the fact, ties the rest of it together.
Here's a trap I've watched companies fall into more than once: they respond to this risk by blocking MCP servers and AI tools outright, trying to play it safe, and what actually happens is adoption goes underground. Employees find workarounds, and shadow AI use grows precisely because there's no approved path forward. Governed access reduces shadow AI far more reliably than prohibition ever does, and that might be the single most counterintuitive finding in this whole space.
There's a speed argument buried in here too, easy to miss if you're only looking at risk. Teams working with centralized, enforced access policies ship agentic AI into production faster than teams without them, because the guardrails are exactly what let leadership say yes with confidence instead of stalling everything out of caution. That's part of why governance spending grew from roughly 3-5% of AI budgets in 2024 to 8-12% in 2026. Companies are starting to treat this as infrastructure they build once, not overhead they grudgingly tolerate.
Usercentrics built MCP Manager for exactly this layer of the problem: a control plane for enterprise MCP deployments that handles the registry, the access controls, and the real-time observability needed to turn scattered agent experiments into governed production systems. Regulation is only going to make this more urgent from here. EU AI Act enforcement and NIST AI RMF adoption are turning governance documentation into a compliance requirement rather than a nice-to-have, and organizations without this infrastructure are increasingly exposed, operationally and legally both.
Why the organizations treating governance as infrastructure will outcompete those treating it as compliance
Ungoverned AI is what keeps projects stuck in pilot purgatory. Nobody trusts them enough to let them touch anything that actually matters, so they sit there, technically live, practically frozen.
Deloitte's 2026 data backs this up concretely. The number of companies with a substantial share of their AI projects in production is set to double within six months. The companies making that leap aren't moving recklessly fast; they're the ones with infrastructure solid enough to say yes safely, again and again, without treating every new deployment like a risk review starting from zero.
Look at what speed and control actually look like on the ground. A governed path to approved tools removes the pressure that drives shadow adoption in the first place. Real-time access logs turn incident response into something fast and precise instead of a forensic scramble three weeks after the fact. Role-based access for agents means expansion happens because someone decided it should, not because nobody was watching closely enough.
There's a trust question sitting underneath all of this, and it's the one that actually matters most going forward. Regulators and enterprise customers are starting to ask something sharper than they used to: whether you can show what your AI did, not just whether you use it. Companies that answer that clearly earn trust that speeds adoption up, while the ones that can't are inviting exactly the scrutiny they're trying to avoid.
The organizations that define enterprise AI over the next few years will be measured less by adoption speed and more by what they built underneath the deployment to sustain it once the novelty wore off. Enterprise AI stopped being a technology question a while back, and it's an organizational design question now. The answer sitting at the center of it (governance, access control, visibility built in from day one rather than bolted on after something's already gone wrong) is about as close to settled as anything gets in this field.


