Here is the statistic that should frame every IT leadership conversation this year. In CIO.com’s 2026 State of the CIO, fewer than one in five leaders say their AI initiatives have met or exceeded business goals. After three years of investment, that is not the number anyone expected. And the window to fix it is closing: The boards that once funded experimentation are now asking where the return is, and the agents arriving this year act on the business rather than merely advise it.
The easy explanation is that the technology isn’t ready. In the organizations I advise, that’s rarely what I see. The models work. What’s missing is the operating system they plug into, the way the enterprise decides, the way work gets done and supervised, and the way trust is engineered. AI amplifies the operating system you already have. Point it at a strong one and value compounds. Point it at a fragmented one, and you simply industrialize the fragmentation.
That reframes the job. The 2026 IT leader isn’t measured on how much AI they deployed. They’re measured on three things they now have to architect: How the organization decides, who does the work and what makes it safe to let go.
Vipin Jain
Start with where AI programs actually stall. In the banks I advise, pilots rarely fail in the lab. They fail at the handoff — the moment a working capability meets an organization that has no place to put it. There is no owner accountable for the outcome, no decision forum that moves at the speed of the tool, and no scorecard that separates real value from visible activity. The model performs. The operating model doesn’t.
This is why CEOs have stopped being impressed by demos. As CIO.com’s reporting on CEO priorities makes plain, chief executives no longer want AI experiments; they want initiatives that move revenue, cost and risk, and they expect their CIOs to create those opportunities rather than merely collaborate on them. The money is available; nearly seven in ten organizations expect IT budgets to rise this year, according to Foundry’s State of the CIO. What’s scarce isn’t budget or technology. It’s an operating model that can convert either into outcomes. Analysts are converging on the same point: Info-Tech now urges CIOs to run IT by the numbers and tie AI to value streams rather than activity.
That shifts the center of gravity for the role. IT leadership used to be measured by how well you ran the technology. It is now measured by how well you architect the decisions the technology feeds. The State of the CIO captures the new job description bluntly: The CIO of 2026 is “half operating architect, half risk officer.” Running the platform is table stakes. Designing how the enterprise decides is the work.
The teams that struggle most here are not the ones with the weakest technology. They are the ones whose governance forums meet quarterly while their agents act by the hour. What I see most often is a review board built for a slower era, one that approves projects but never revisits them, that funds pilots but never kills them. In a fast-moving portfolio, the cadence itself is the control. If the enterprise decides in quarters, an AI that decides in seconds will simply outrun its own oversight.
What that looks like in practice is unglamorous and decisive. Assign a single accountable owner to every AI use case on the business side, not in IT. Retire the vanity metrics (copilots deployed, pilots launched, dashboards built) that let activity masquerade as progress. And rebuild the executive decision cadence so that when an agentic workflow produces a recommendation, there is a forum ready to act on it in days, not quarters. In a Fortune 500 health insurer whose portfolio I helped rationalize, the pilots that had been circling for quarters shipped only once each had a named business owner and a standing forum with the authority to act — the fix was to the operating model, not the model.
Tie every initiative to the language the board already speaks: Revenue gained, cost removed, risk retired, time-to-value shortened. Say “we cut fraud losses by half a million dollars,” not “the model hit 94 percent precision.” A dashboard full of pilots isn’t a strategy. It’s a symptom of one you haven’t written yet.
The second shift is quieter and larger. Agentic AI is turning the CIO into the architect of a blended workforce: part human, part software that acts on its own. The vendor conversation has already moved from copilots that suggest to systems that act: Google’s Agentic Data Cloud and Gemini Enterprise Agent Platform, AWS’s Bedrock AgentCore and ServiceNow’s control tower are all built to let agents execute work across systems, not just describe it. In retail, I watch teams push agents into production faster than they build the controls to govern them.
Most organizations are still onboarding those agents the way they onboard licenses: provisioned, counted, forgotten. At one property-and-casualty insurer, I watched a team stand up a dozen agents with no more oversight than a new software seat. An agent that acts is not a license. It is closer to a new hire, and it needs what any hire needs: A scoped job, boundaries, supervision, an escalation path and a named human who answers for it.
This reshapes the team as much as the tooling. The value of a junior person who only produces work falls; the value of someone who can review, correct and supervise what an agent produces rises. The classic talent pyramid: Many juniors, a few seniors starts to look more like a diamond, thick with experienced people who can tell good output from output that merely looks plausible. Leaders who treat agents purely as a headcount lever miss the point. The scarce skill now is judgment: Knowing when the agent is wrong, and owning the call when it is.
It helps to be concrete about where that value shows up first. Across very different industries, it is the same kind of work: High-volume, rules-clear, with a clear definition of “good.” In a bank, that is fraud triage and reconciliation. In a health plan, it is first-pass claims and prior-authorization routing. In retail, it is service-case deflection and returns. In a federal agency, it is eligibility screening and case intake. None of these are moonshots. They are the unglamorous, high-friction workflows where an agent under supervision takes out cost and cycle time without betting the business and where the supervision muscle gets built for the harder, higher-stakes work that follows. Start where the value is obvious and the blast radius is small.
The cost of skipping that is now quantified. Gartner projects that more than 40 percent of agentic AI projects will be canceled by the end of 2027, not because the models fail, but because of escalating costs, unclear business value and inadequate risk controls. The market muddies the picture further through what Gartner calls “agent washing”: Of the thousands of vendors claiming agentic capability. CIO.com’s own reporting finds the same pattern inside enterprises — pilots that demo beautifully stall the moment they meet production, where documents vary, exceptions multiply and someone has to be accountable when an agent acts. What I see most often is that the teams that struggle aren’t the ones with the weakest platform. They’re the ones with the vaguest intent. AI amplifies ambiguity as efficiently as it amplifies capability.
The leadership response is not a bigger bake-off among platforms. Naming vendors tells you where the market is heading; it doesn’t tell you what to do. The work is to design the roles around the agents. People move up the value chain — from doing the task, to steering it, to supervising and handling the exceptions the agent can’t. Autonomy follows a ladder, not a switch: Assistant, then participant, then genuine team member, with human supervision tightening as the stakes rise. Start with a bounded use case, build the supervision muscle and only then widen the boundary. In a federal modernization program I advised, the teams that pulled ahead began with a single high-volume, rules-clear workflow, proved the audit trail and human sign-off, and widened autonomy only once the supervision held. The goal was never more agents. It is agents that belong to a team someone actually leads.
The third shift is the one leaders most want to skip, and the one that now decides the other two. As agents begin to act, governance stops being paperwork and becomes the thing that lets you move. The current gap is telling: In the State of the CIO, 83 percent of leaders have or are planning cross-functional AI steering committees, but only 53 percent have any formal process for approving AI projects. Committees are easy. The boundary that lets you say “yes, act” is hard.
I recommend a reframe most leaders resist at first. Governance is not the office of “no.” Observability, evaluation, approval boundaries and rollback are precisely what let you grant more autonomy, sooner, with confidence. They are how you catch a failing agent before it becomes a headline — and, as one analysis of the Gartner forecast observes, agentic projects fail when companies grant systems access and authority before they define ownership and rollback controls. Used well, that discipline is what turns acceleration into advantage instead of avoidable damage.
This is not a distant concern. In a health plan I advise, an ungoverned action doesn’t just fail a demo: It can surface as a compliance finding, which is why governance gets attention there first. For the first time in over a decade, state CIOs have ranked AI as their number one priority, displacing the cybersecurity focus that held the top spot for twelve straight years, the very settings where autonomy is most consequential. The analyst community has reached the same conclusion: Gartner now lists evolving IT strategy, governance and operating models among the top priorities for CIOs this year, alongside operationalizing AI itself. Governance and operating-model design are no longer separate agenda items. They are the agenda.
And the pressure only builds. Gartner expects that by 2028, 15 percent of day-to-day work decisions will be made autonomously by agents, up from essentially none in 2024, with a third of enterprise applications shipping with agents inside them. Governance that feels optional today becomes load-bearing the moment agents are deciding at that scale. The leaders building the trust layer now — while the stakes are still small enough to learn on — are the ones who will be able to say yes when the stakes are not.
Guardrails aren’t what slow the car down. They’re what let you take the corner at speed.
The three moves are facets of a single reframe. The center of gravity for IT leadership has shifted from running the technology to architecting the system around it. Decisions, workforce and trust are not three initiatives competing for budget; they are three faces of one job: Building the operating system that turns capability into results.
Old center of gravity | New center of gravity | What the leader must architect | | | Decisions | Delivering technology reliably | Turning capability into outcomes | Accountable owners, a fast executive decision cadence, outcome-based metrics | | Workforce | Managing tools and licenses | Leading a human-plus-agent team | Scoped agent roles, supervision that scales with stakes, staged autonomy | | Trust | Controlling risk after the fact | Enabling speed through governance | Observability, evaluation, approval boundaries, rollback |
None of this requires a reorganization to begin. It requires a sequence. The leaders getting ahead aren’t doing more; they’re doing these five things in order, on the bounded use cases where they can afford to learn.
**1. Name the intent. **For every AI use case, write the business outcome and the person accountable for it before a line of code ships. Vague intent is the most expensive input in the system.
**2. Set the guardrails, then the autonomy. **Decide what an agent may touch and what still requires a human before you widen its reach. Boundaries first, freedom second, never the reverse.
**3. Instrument for observability. **If you can’t see what an agent did and why, you can’t supervise it. Build the audit trail into the work, not after the incident.
**4. Evaluate against Tuesday, not the demo. **Test agents on the messy production reality, the missing field, the duplicate record, the exception — not the clean pilot. What passes in the lab rarely survives first contact with real work.
**5. Measure what the board measures. **Retire activity metrics; report revenue, cost, risk, time-to-value and release confidence. If a number wouldn’t move a board conversation, it doesn’t belong on the scorecard.
Vipin Jain
Do these in order and autonomy compounds. Skip a step and you join the 40 percent whose agentic projects get canceled before they ever earn their keep.
The most common strategic mistake I see in 2026 is subtle, because it doesn’t look like a mistake. Leaders are scaling powerful new technology on an operating model built for a slower, all-human enterprise, and then blaming the technology when the returns don’t come. The failures won’t come from the models. They’ll come, as they always have, from business strategy, IT and organizational culture not being architected to move together, a pattern I have watched hold across every industry I work in, from trading floors to healthcare programs.
The good news is that this is architectable, and it is the CIO’s to architect. The leaders who will look prescient a year from now aren’t the ones who bought the most capable AI. They’re the ones who rebuilt the operating system it runs on: How their organization decides, who does the work and what makes it safe to let go. The tools will keep getting better on their own; the operating system will not: It is built, on purpose, by someone in the room. The technology was never the hard part. The leadership is. That’s the job now.
This article was made possible by our partnership with the IASA Chief Architect Forum. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the IASA, the leading non-profit professional association for business technology architects.