
The AI problem in most companies is not the model. Not the budget, not the appetite. It is that almost nothing has left pilot.
The published numbers make that hard to argue with.
McKinsey surveyed 1,719 organisations across 97 countries this year. Nearly nine in ten use AI in at least one part of the business. 37% see any effect on profit at group level. Six per cent are getting significant value from it, and that figure has not moved in a year.
Three years of investment. Six per cent conversion, flat.
If a campaign of mine converted at six per cent and had not improved in twelve months, I would have stopped it and asked what we were not seeing.
This is not an adoption problem
Adoption was never the hard part. The tools went in. The pilots ran. The budget was approved, usually more than once.
I also do not believe the six per cent have better technology. Everybody is buying from the same handful of providers, and the models are not where companies are separating.
The six per cent got something into production. That is the whole difference.
Everybody else has a pilot that worked. A team tried something, it was good, and then it stopped. Not because it failed. Because putting it in front of thirty thousand people is a different decision to putting it in front of twelve.
What separates the six per cent is duller than a technology decision. They could answer for the system before somebody senior asked. There was a name against it. The clean-up underneath had already been done, often years earlier and usually for another reason entirely. None of that reads like an AI advantage, and that is the point.
What actually stops a pilot shipping
It is never the model. It is three questions, and they arrive the moment somebody proposes scale.
- What can this thing reach.
- Who owns it.
- What happens if it touches something it should not.
Those questions come from security and risk, and they are the right questions. I would ask them. Anybody accountable for an estate would ask them.
All three are governance questions. Not the policy document kind. The kind that needs a real answer about a real system, on the day somebody asks for it.
The problem is that in most organisations nobody can answer them. Not won’t. Cannot.
That is not caution and it is not bureaucracy. It is a question nobody can answer, doing the job of a no.
So the pilot stays a pilot. It gets renewed, it keeps costing money, and it never reaches the scale where it would have produced a number worth reporting.
What a stalled pilot costs
This is the part that shows up in no report anywhere, because nothing went wrong.
The licence renews. The team that built it keeps maintaining it for the twelve people using it. The business case that got it approved is still in a slide deck somewhere with a number on it that nobody is tracking any more.
And the twelve people are getting real value out of it, which is the awkward part. The pilot is not a failure. It is a success that was never allowed to become material.
Every one of those pilots was approved against a business case. None of them produced the number in it, because none of them reached enough people to. So the next AI proposal arrives after three years of spend that cannot be pointed at a result.
The finance question is never whether AI works. It is why the last four things that got funded are still running at twelve users each.
That is what kills the budget. Not scepticism about the technology. A record of approved investments that never scaled, and nothing on file explaining why.
Most organisations are setting next year’s numbers right now, which is the practical reason to do the counting this quarter rather than the next one. If the AI line is going up, somebody will ask what the last one produced. If it is going down, somebody will ask what can be cut. Both questions need a list of what is actually running and who is actually using it, and without one the budget gets set against what people remember asking for. That is always a fraction of what is there.
Multiply that by the number of pilots a large organisation has run in three years. That is what sits underneath the six per cent, and it is not a technology write-off. It is value that was produced, proven, and then left at twelve users.
Why nobody can answer
Because the visibility is partial, and partial by design.
Every AI provider reports on itself. Its own console, its own usage data, its own audit log. And on Menlo Ventures’ numbers, no single provider holds more than 40% of enterprise use.
Governance built inside a provider can only ever govern that provider. That is not a flaw in any of them, it is the shape of the market.
So the best case in a large organisation is that you can answer those three questions for 40% of your AI, and you are guessing at the rest. No security team signs off on a guess, and they should not.
The guess also gets worse the further you go. The share you can see is the provider somebody chose deliberately. The rest arrived through pilots, departmental trials and features switched on inside software the company already owned. The part you cannot see is the part nobody decided on.
I see the consequence of that from the other side. A year ago the governance conversation opened with Microsoft 365. Sites, teams, permissions, sharing. Now it opens with AI, and the first question is almost never about features. It is some version of: can you tell me what is running. The second one decides it. Does this cover everything, or only the part I already knew about.
It gets harder from here
Until recently AI answered questions. Now it acts.
An agent holds its own permissions and runs without anybody watching it. So “what can this reach” stops being a governance question and becomes an operational one, because the answer decides what an unsupervised system is allowed to do on the company’s behalf.
And more organisations are going that way. McKinsey has 40% of companies above one billion dollars in revenue now scaling AI agents, up from 27% the year before. Smaller companies stayed flat at 22%. This is happening at the top end first, where the estates are biggest and the permissions are in the worst shape.
Gartner expects the average global Fortune 500 enterprise to be running over 150,000 agents by 2028. In 2025 the figure was under 15.
So the number of questions nobody can answer is rising, and the consequence of not answering them is getting bigger. That is not an argument for slowing down. It is an argument for fixing the visibility first, because the alternative is another three years of pilots that work and never ship.
Which puts governance on the other side of the argument
Governance normally gets sold internally as insurance. It protects you from something that has not happened yet, which is why it competes badly for budget against anything with a return attached.
That framing is wrong here, and it is costing companies money.
The fair pushback is that governance has its own record of going nowhere. Plenty of it has been a policy document that changed nothing in the estate. I would separate the two. A policy describes what should happen. An inventory tells you what is happening. The first competes for attention with everything else on the roadmap. The second answers a question somebody is already asking, usually with a deployment waiting on it.
On the evidence above, governance is not what slows AI down. It is the thing standing between a pilot that works and a system the whole company uses. It belongs on the value side of the business case, not the cost side.
The cost of ungoverned AI is not a breach. It is a pilot that never ships.
What governing across actually means
The answer has to sit above the providers, because none of them can see the others.
That starts as one inventory of every AI in use. Every user, every project, every session, every setting, every unit of spend, in one place rather than four exports nobody has time to reconcile.
Then the part that makes it governance rather than a list. Every AI account resolved back to the same person in the directory the organisation already runs.
Because the same employee is a separate account in every system. Somebody joins the finance team and gets a Microsoft 365 account. Over the following year they turn up as a user in a second AI tool through a departmental pilot, as the owner of two projects in a third, and as a member of a workspace somebody else set up in a fourth. Four systems now hold part of that person, each names them differently, and none of it is joined up.
Ask what that one person can reach across every AI the company runs and no system can answer, because no system holds the whole person.
Identity is the only part of this that does not change. Providers come and go. Pilots end, departments switch tools, software gets replaced. The person stays, and what they are allowed to reach is what the security team is actually asking about.
That is the work Rencore has done across the Microsoft estate for thirteen years. Ownership, permissions, sharing and sensitivity labels. Who owns a thing, who can get to it, where it has been shared outside the company, and how it is classified. Same work, more places. What it covers, and in what order, is what we are setting out on 1 October.
Two things change once it exists, and I have watched both happen in other categories.
The first is that the three questions get answers, so the decision to scale becomes a normal commercial decision rather than an unanswerable one. A pilot that would have waited a quarter on a security review goes through in a fortnight. Do that four times in a year and the six per cent stops being a number about somebody else.
The second is that you find things. Duplicate tools bought by two different departments. Pilots still running that nobody has opened in months. Access that should have been removed when somebody changed role. None of it is dramatic. All of it is money, and it usually pays for the exercise.
Three questions worth asking this week
Not of a vendor. Of your own organisation.
- How many AI tools are in production here, as opposed to in pilot.
- For each one, can somebody say what it can reach.
- For everything still in pilot, do we know what is stopping it.
If the third question has no answer, that is worth more attention than anything on the AI roadmap. Something is holding back every piece of value the investment was supposed to produce, and nobody has written down what it is.
On the first question, we built a thirty minute estate review. It is not a product demonstration. If it comes back saying Microsoft 365 Copilot is the only AI in play, then this is early for you and we will say so.
Matt and Tiina cover the detail on 1 October. Matt on why we are doing this. Tiina on what has been built and what comes next.
Sources
- McKinsey & Company, The state of AI in 2026: On the road to ROI. Published 25 August 2026. 1,719 respondents across 97 countries, fieldwork 4 May to 8 June 2026. Used here for: nearly nine in ten organisations using AI in at least one part of the business. 37% reporting any effect on profit at group level. 6% getting significant value, unchanged year on year. 40% of companies above one billion dollars in revenue scaling AI agents, up from 27%.
- Menlo Ventures, 2025: The State of Generative AI in the Enterprise. Published 9 December 2025. 495 US enterprise AI decision makers, surveyed 7 to 25 November 2025. Used here for: no single AI provider holding more than 40% of enterprise use. Anthropic 40%, OpenAI 27%, Google 21%, all others 12%, measured by large language model API usage.
- Gartner press release, 28 April 2026. Gartner Identifies Six Steps to Manage AI Agent Sprawl. Used here for: an average global Fortune 500 enterprise running over 150,000 agents by 2028, up from fewer than 15 in 2025.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organisation and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
McKinsey, Menlo Ventures and Gartner figures are reported as published and are not Rencore’s own. Rencore does not claim that its software makes any organisation compliant with any regulation.
Last updated 29 September 2026

