
A year ago, every executive conversation about AI started with the same question: Should we adopt it?
Today, very few organizations are asking that anymore. The conversation has changed.
The question now is whether AI can be trusted to become part of everyday business operations. That’s a very different challenge. Most organizations have already proven AI can create value. It’s writing code, summarizing documents, assisting customer service teams, accelerating research and helping employees get more done in less time.
The technology works. The challenge is everything that comes next:
- Can AI access the right systems?
- Can it make the right decisions?
- Can it stay inside company policy?
- Can someone explain what it did after the fact?
- Can leadership trust it enough to let it become part of normal business operations?
Those aren’t technology questions. They’re operational ones. And I think they’ll define the next chapter of enterprise AI; I’ve personally seen this pattern before.
AI is Creating a New Enterprise Control Point
Every major technology shift creates a new enterprise control point. Cloud computing changed how organizations thought about infrastructure. It also created an entirely new security market. APIs transformed how applications communicate. That created API security. Software-as-a-Service made technology easier to buy than ever before. Then came Shadow IT, as organizations realized employees could adopt new applications faster than IT could govern them.
AI feels very familiar. Only faster.
Business teams can enable AI inside existing software with a few clicks. Developers can connect agents to enterprise systems in hours. Vendors are embedding AI into products organizations already use, often without customers treating it as an entirely new technology deployment. Innovation has never moved this quickly, and neither has the risks.
The challenge isn’t that organizations don’t have AI strategies, because most do. The challenge is that AI doesn’t fit neatly into the way enterprises have traditionally managed technology. Organizations are challenged to answer the question: Who owns it? That’s because:
- Security owns cyber risk.
- Legal owns compliance.
- Business units own outcomes.
- Developers build integrations.
- Data teams manage information.
- IT owns infrastructure.
AI touches all of them.
That creates something we haven’t had to deal with before: shared accountability without centralized control.
IBM’s recent global study of 2,000 CIOs and CTOs illustrates just how quickly this problem is emerging. Two-thirds said they’re now accountable for AI systems they don’t fully control. Seventy percent said technology is being deployed faster than IT can track it, while more than three-quarters believe AI adoption is already outpacing their governance capabilities. Only 11% believe their organizations are fully prepared for the scale of AI agents expected over the next year.
Those numbers shouldn’t surprise anyone. Organizations have spent the last two years learning how to deploy AI. They’ve spent far less time learning how to operate it. Deployment and operations are completely different disciplines.
AI Doesn’t Need Better Policies. It Needs Better Operations.
Deploying AI is relatively easy. Operating AI is where things become complicated. What happens when an AI agent wants access to customer records?
- Should it retrieve financial information?
- Should it trigger a payment?
- Should it update a contract?
- Should it approve a workflow?
- Should it be allowed to do any of those things without a person involved?
These aren’t theoretical questions anymore. They’re operational decisions happening inside enterprises every day. Many organizations are answering them the only way they know how. They put a person in the middle.
Someone reviews the output.
Someone approves the action.
Someone verifies the recommendation.
Someone investigates exceptions.
That approach works when AI is limited to a handful of pilot projects. It doesn’t work when AI becomes part of hundreds (or eventually thousands) of business processes. Microsoft’s 2026 Work Trend Index makes a similar observation. After analyzing trillions of workplace productivity signals and surveying 20,000 knowledge workers, Microsoft concluded that the biggest barrier to AI success is no longer the technology itself. It’s whether organizations redesign work to take advantage of it. In fact, organizational factors such as leadership, culture and operating models now have more than twice the impact on successful AI transformation than individual employee effort.
I think that’s exactly right. The next challenge isn’t helping people use AI. It’s helping organizations operate AI. There’s an important difference. For the last two years, we’ve treated AI as another productivity tool. Increasingly, it isn’t just generating content. It’s taking action, retrieving information, making recommendations and triggering workflows across connected systems.
Trust is the Foundation for Enterprise AI
As AI moves from answering questions to performing work, trust becomes the limiting factor. And trust doesn’t come from having an AI policy. It doesn’t come from publishing responsible AI principles on your website or from another governance committee.
Those things matter. But they aren’t enough.
Trust comes from knowing what AI is allowed to do before it does it. It comes from understanding what data it can access, automatic policy enforcement versus relying on someone to remember them. It comes from having visibility into every significant action, an audit trail explaining why it happened, and the ability to intervene when something doesn’t look right.
In other words, governance has to move from documents into operations. That’s where the conversation around AI governance needs to evolve. Too often, governance is treated like paperwork. Frameworks, policies, training and compliance checklists are all important foundations, but they don’t make decisions in real time. The organizations pulling ahead are thinking differently. They’re embedding governance directly into the way AI operates by implementing runtime policy enforcement including:
- Routine, low-risk actions can happen automatically.
- Higher-risk activities require human approval.
- Sensitive systems have clear boundaries around what AI can and cannot do.
- Unexpected behavior can be stopped before it becomes an incident.
That’s a fundamentally different operating model, and ultimately, that’s what builds trust. Because governance isn’t really the destination. Trust is.
Organizations won’t scale AI because they wrote better policies. They’ll scale AI because leadership has confidence that AI will behave predictably, operate within clearly defined guardrails and remain aligned with business objectives even as it becomes more autonomous.
Every major technology wave creates a new enterprise control point. Cloud created cloud security. APIs created API security. I believe AI is creating something new. Not simply another governance framework, but a new way of governing actions as AI becomes an active participant in the business itself.
That’s the next enterprise challenge. Not adopting AI but trusting it.



