For CIOs, the enterprise ambition to deploy AI is outpacing execution and is impacting everything from talent to technology to operations. The challenge to deploy is not coming from the technology itself, but rather the complexity that we have built into our enterprise IT environments.
The more deeply AI becomes embedded across the enterprise, the more dependencies it can introduce. More systems, integrations and data dependencies create additional operational and security considerations that must be managed as AI scales.
I saw this firsthand when we started looking at how to simplify our technology landscape. We had more than 1,500 software applications after years of growth, acquisitions and technology investment. That created a broad estate to operate and secure, and when I speak with other CIOs, I hear similar stories.
That sprawl has always had a cost. Teams spend time maintaining applications, managing integrations and keeping systems current. Hybrid environments add another dimension as workloads operate across data centers and public and private clouds.
AI must work across that same environment.
This is why I believe complexity is the biggest barrier to effectively implementing AI across the enterprise. The models will continue to improve, but better models alone will not solve fragmented processes, poor data quality or unnecessary layers. Some of the workflows with the greatest potential for AI are also operationally intricate, which makes preparing people to work differently just as important as preparing the technology environment. Reducing the tech stack, integrating human control and ensuring strong data quality and governance are essential to overcoming this barrier.
AI inherits the complexity of the tech stack
There is a temptation to view AI as a way to work around technology debt. In practice, AI can expose it. That challenge is widespread, with 68% of CIOs reporting that technical debt from past integrations is blocking their ability to scale AI.
We have experienced this ourselves. Some of the hardest AI use cases are processes with many permutations and edge cases. If the underlying environment is highly customized or fragmented, an agent also must navigate that complexity. The operational burden can become greater than the problem AI was intended to solve.
That is why simplification has been a major focus for us.
As part of our broader transformation, we reduced our application landscape by more than 300 applications and consolidated over 40 data centers. The benefits extend well beyond the direct technology costs. A smaller estate gives operations teams less to maintain and security teams less to protect. It also creates a more manageable environment for AI.
This does not mean every enterprise should pursue a perfectly uniform architecture. That is neither realistic nor desirable.
Our own environment is hybrid. We operate workloads across data centers, multiple public and private clouds and sovereign environments. Different workloads have different requirements. Some complexity is necessary because of security, regulatory and business needs.
The important distinction is between complexity that serves a purpose and complexity that has simply accumulated.
That becomes more consequential with agentic AI. An agent may need to interact with multiple applications, retrieve information and initiate an action. Every additional dependency creates another place where permissions, data definitions or integrations must work correctly.
In addition to a hybrid environment, I also encourage teams not to begin their AI journey with the biggest and most complicated problem they can find. Start with use cases where the inputs and expected outputs are understood. Prove the technology can perform the task reliably. More complex orchestration can follow as confidence grows.
Nearly two-thirds of enterprises worldwide have experimented with agents, but fewer than 10 percent have scaled them to deliver tangible value. As organizations look to close that gap, data architecture becomes increasingly important. AI at scale depends on an information environment that can support it reliably.
For CIOs, this makes architecture part of the AI strategy. Before adding another agent to another workflow, we should understand what it will connect to, what information it needs and whether the environment is making the job harder than it needs to be. Not all AI use cases earn the infrastructure it demands.
Know when to trust the output
As AI becomes more capable, the challenge is not limited to the number of systems involved. CIOs also must manage the complexity of deciding how much authority to give the technology.
I think about that question differently depending on the workload.
Using AI to help someone retrieve information carries one level of risk. Allowing an agent to act inside mission-critical infrastructure carries another. The appropriate level of human oversight should reflect the consequences if the AI gets something wrong.
We are working through this in our own operations.
Our network and security operations specialists worked alongside the teams building the AI agents to define what technology should do and what people should continue to own. One of those capabilities is a resolution agent designed to help diagnose and ultimately resolve operational incidents. Today, we operate with a human in the loop. The AI agent can analyze information and recommend a resolution, but a human makes the final decision. Our team also records whether the recommendation was correct and what differed when it was not.
That feedback helps improve the system over time.
The long-term opportunity is greater autonomy and speed while ensuring business continuity. But mission-critical operations require an extremely high degree of certainty before we make that transition. Autonomy must be based on demonstrated performance rather than assuming an agent is ready because the technology makes autonomy possible.
This is where trust must become measurable. Organizations need visibility into what an agent is doing, what data it is using and whether it is producing the expected outcome. They also need clear access controls. We think about identity and access management for our agentic workforce in much the same way we think about it for people. An agent should have defined responsibilities and permissions appropriate to the work it performs.
It should also be possible to turn an agent off.
For CIOs, the goal should be controlled progression. Human involvement can change as technology proves itself, but autonomy should be earned through evidence.
Strong foundations make AI possible
Both issues ultimately come back to information.
AI needs context to be useful inside an enterprise. That means organizations must know what data they have, where it resides, how it is governed and what should be exposed to AI.
Strong information governance grows even more important as AI gets better at finding information. Anyone experimenting with enterprise AI has probably seen how quickly it can surface information buried deep inside an organization. That can create tremendous value. It can also reveal weaknesses in information governance.
Knowing your data is therefore becoming inseparable from knowing your AI.
Data controls and a clear understanding of how information is used have shaped our approach to AI. Before connecting a capability to enterprise information, we want to understand the data being used and the controls around it.
For sensitive information, we also need to understand where that data is processed and whether the deployment model provides the protection the workload requires.
This is one reason regulated organizations have an advantage. Many have already spent years establishing controls around sensitive information because regulation required it. Those investments can become a foundation for AI rather than a barrier to innovation.
Data quality matters as well. Agentic AI can operate on poor information, but that does not mean the result will be useful enough for the business to rely on. The stronger the information foundation, the more confidence you can have in the context being provided to AI.
The same applies operationally. Organizations need visibility into how AI is performing after deployment. We have been investing in continuous evaluation so we can understand what data contributed to an outcome, whether the result was accurate and where the technology needs to improve.
That evidence connects the foundation back to trust. If we know the information an agent is using, understand its permissions and can evaluate its performance, we can make a much better decision about how much responsibility to give it.
This is the work that will determine how quickly enterprise AI can mature.
AI will continue to become more capable, but adding more intelligence to a complex environment does not automatically make the environment simpler. CIOs need a strong foundation, first: reduce unnecessary complexity, strengthen control over information and establish clear boundaries for how AI operates.
Enterprise AI readiness comes down to reducing unnecessary complexity, understanding and governing the information AI depends on, and being deliberate about where human judgment remains essential. Do those things well, and AI has a much stronger chance of delivering measurable value at scale.