cd /news/ai-policy/why-ai-projects-are-stalling-on-gove… · home topics ai-policy article
[ARTICLE · art-100519] src=techstrong.ai ↗ pub= topic=ai-policy verified=true sentiment=· neutral

Why AI Projects Are Stalling on Governance, Not Models

Gartner projects that by the end of 2026, up to 40% of enterprise applications will include task-specific AI agents, up from less than 5% in 2025, and that by 2030, half of all AI agent deployment failures will trace back to AI governance platforms unable to enforce policy at runtime. IBM's 2025 Cost of a Data Breach Report found that 97% of organizations experiencing an AI-related security incident lacked proper access controls on their AI systems. The article argues that legacy governance and access models built for human users are the primary bottleneck for enterprise AI initiatives, not the models themselves.

read5 min views1 publishedAug 17, 2026
Why AI Projects Are Stalling on Governance, Not Models
Image: Techstrong (auto-discovered)

Most of the AI conversation in enterprises right now centers on the frontier models: which one reasons better, which one hallucinates less, which one ships fastest, which one costs the most. That conversation matters, but it’s not the one that determines whether AI initiatives are actually successful inside a large organization.

I talk to a lot of CISOs, data leaders, and platform teams who are past the pilot stage. They’ve deployed copilots. They’ve stood up agents that read and act on real data. And what they keep running into isn’t a model problem. It’s that legacy governance, fragmented permissions, and access models built for people don’t hold up once machines become the ones asking for data.

Gartner expects up to 40% of enterprise applications to include task-specific AI agents by the end of 2026, up from less than 5% in 2025.[1] That’s not a gradual shift. That’s a significant share of the enterprise application layer picking up an agent in about twelve months, on top of infrastructure that was never built to govern non-human requesters at that scale.

Legacy Access Models Weren’t Built for This

Most access frameworks assume a human on the other end of the request: someone logs in, asks for something, waits while a role gets checked. That assumption made sense for a long time. It doesn’t hold once an AI agent is the one requesting.

Agents don’t file tickets or wait on approvals. They call an API at intervals measured in seconds, sometimes thousands of times a day, and if the permission exists, the data moves. A permission that’s slightly too broad used to be a finding on an audit report. Now it’s a door that gets walked through constantly, by something that doesn’t to ask if it should.

IBM’s 2025 Cost of a Data Breach Report found that 97% of organizations that experienced an AI-related security incident lacked proper access controls on their AI systems.[2] They didn’t just have weak controls. Most lacked them entirely. You can’t call that an AI problem when it’s clearly a governance failure.

Why Governance Becomes Infrastructure, Not a Checkbox

A lot of security leaders still picture old-school governance: a policy binder, an annual audit, a committee that meets once a quarter. That worked when data moved at the pace of people filling out request forms. It doesn’t work at agent speed, though, and Gartner’s own forecasting reflects that gap: by 2030, the firm projects that half of all AI agent deployment failures will trace back to AI governance platforms that simply can’t enforce policy at runtime, across the different systems agents touch.[3]

Gartner has also predicted that through 2027, manual AI compliance processes will expose 75% of regulated organizations to fines exceeding 5% of global revenue,[4] and that through 2030, a third of all IT work will go toward remediating AI data debt just to make existing data usable and secure enough for AI.[5] Again, none of that is a model problem; it’s the operational burden of trying to govern machine-speed systems with human-speed processes.

What enterprises need looks less like a policy document and more like infrastructure: enforcement that lives at the data layer, evaluates each request as it happens, and applies consistent policy whether the identity behind the request is human or not. Gartner has made a similar case on the identity side, predicting that by 2028, 70% of CISOs will rely on identity visibility and intelligence capabilities specifically to shrink the combined human-and-machine identity attack surface.[6]

That’s a different category of investment than most security roadmaps currently include. I’d expect it to become a standard line item over the next few years, sitting alongside the model and platform spend getting most of the attention today.

The Bottleneck Enterprises Are Underestimating

Ask teams further along in AI deployment where the actual delays are, and the model rarely comes up. It’s security staff manually mapping which agents can reach which datasets. Data teams writing one-off scripts to enforce least privilege across Snowflake, Databricks, and whatever else is in the stack, none of it using a shared policy language. Compliance asking a fair question: can you show what this agent touched and why, and nobody having a clean answer.

None of that shows up on a roadmap slide. All of it decides whether the roadmap holds up once the project reaches production.

Trusted Access Is What Makes AI Success Possible

AI success depends on scalable, trusted data access more than it depends on which model an enterprise picks. Organizations building policy enforcement that works across every platform their agents touch, at the speed agents actually operate, are the ones getting to production. Organizations still leaning on quarterly access reviews and static roles are going to keep hitting the same wall on the next project, and Gartner’s failure-rate projections suggest a lot of enterprises are heading straight for it.

Model quality improvement appears set to continue its upward trajectory. But what’s less certain is how model access will be managed: do you know what your AI agents can access today, and can you show it?

Closing that governance gap, not picking the next model, is the real AI work ahead.

Sources

  • Gartner, “Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026, Up from Less Than 5% in 2025,” press release, August 26, 2025.
  • IBM, Cost of a Data Breach Report 2025.
  • Gartner, “Gartner Announces Top Predictions for Data and Analytics in 2026,” press release, March 11, 2026.
  • Gartner, “Gartner Predicts AI Applications Will Drive 50% of Cybersecurity Incident Response Efforts by 2028,” press release, March 17, 2026.
  • Gartner, “Gartner Predicts AI Applications Will Drive 50% of Cybersecurity Incident Response Efforts by 2028,” press release, March 17, 2026.
  • Gartner, “Gartner Predicts AI Applications Will Drive 50% of Cybersecurity Incident Response Efforts by 2028,” press release, March 17, 2026.
── more in #ai-policy 4 stories · sorted by recency
── more on @gartner 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/why-ai-projects-are-…] indexed:0 read:5min 2026-08-17 ·