AI ROI Is Up 31%—But 73% Still Fail at the Basics

SAP and Oxford Economics surveyed 2,600 AI leaders: global ROI up 31% but 73% have data failures and only 3% are ready for agentic AI.

By Rajesh Beri·July 23, 2026·9 min read
Share:
THE DAILY BRIEF
Enterprise AIAI ROIAgentic AIAI StrategyAI Governance
AI ROI Is Up 31%—But 73% Still Fail at the Basics

SAP and Oxford Economics surveyed 2,600 AI leaders: global ROI up 31% but 73% have data failures and only 3% are ready for agentic AI.

By Rajesh Beri·July 23, 2026·9 min read

There's a study out this week from SAP and Oxford Economics that I think every CIO, CTO, and CFO should read before making their next AI budget decision. They surveyed 2,600 business leaders across 13 countries and the results are a perfect portrait of where enterprise AI actually stands in 2026—not where vendors say it stands.

The headline is good: global AI ROI jumped from 16% to 21% year-over-year. On a typical $28 million AI budget, that's $6.3 million in return. It's real money, and it's moving in the right direction.

But then you read the next page.

Seventy-three percent of enterprises have serious problems with data quality. Seventy-nine percent report rework, delays, or backlogs caused by poor AI outputs. Only 3% say they're fully prepared for agentic AI. And 69% admit they're deploying AI agents faster than they can govern them.

That's not a success story. That's a house with a freshly painted exterior and a foundation that's starting to crack.

The ROI Numbers Actually Make Sense—If You Know What You're Measuring

The 21% ROI figure sounds underwhelming until you understand what's being measured. Companies are spending $28 million on AI and getting $6.3 million back this year. By 2028, that same $28 million is expected to return $15.9 million—a 38% ROI.

Here's what's driving the optimism: agentic AI. In conversations with finance leaders and operations executives, I keep hearing the same thing—the big ROI jump they're betting on isn't coming from copilots or chat assistants. It's coming from autonomous agents that can execute multi-step workflows without human handoffs. The SAP/Oxford data backs that up: average ROI from agentic AI is projected to reach $17.6 million in two years, more than quadrupling from last year's $4.3 million estimate.

That's the bet enterprises are making. And it's a reasonable one—if the foundation is solid.

For CFOs evaluating AI spend, the implication is clear: the companies hitting strong ROI this year are the ones who will capture the agentic wave next year. The ones still struggling with basics will get left further behind, not caught up.

What "The Basics" Actually Means

When 73% of global enterprises say they have data quality problems, that's not a technology issue—it's a business readiness issue.

Here's what I mean. Most organizations I've spoken with in the last year approached AI by layering it on top of existing data infrastructure. The logic was: we already have the data, we just need the AI. But AI doesn't forgive messy data the way a human analyst does. A person reads a customer record, notices the address is clearly wrong, and compensates. An AI agent routes a shipment to an invalid address, generates a refund, and flags a customer complaint—all before anyone realizes the source record was corrupted.

Seventy-nine percent of businesses in this survey are experiencing rework, delays, or backlogs from exactly this problem. They deployed AI on top of data that wasn't ready for it.

For technical leaders, the fix isn't glamorous: it's data governance, master data management, and schema discipline. The kind of work that doesn't make it into board presentations but determines whether your AI investments actually pay off.

The Agentic Readiness Gap Is Bigger Than Most Executives Realize

Three percent. That's how many enterprises say they are fully prepared for agentic AI.

The rest—97%—are either partially prepared or not prepared at all. But here's the part that should genuinely concern business leaders: 69% say they're deploying agents anyway, faster than they can govern them.

That's not bold. That's exposure.

When you deploy agents into production without proper controls, you're not taking calculated risk. You're creating invisible liability. Agents make decisions, take actions, send communications, modify records, and commit transactions. Without the right governance infrastructure in place, you lose auditability, you lose control, and in regulated industries, you potentially lose compliance standing.

The SAP data surfaces three specific gaps that matter most:

Human oversight is missing. Thirty-eight percent of companies don't have a human-in-the-loop process for agentic workflows. That means agents are executing consequential actions with no checkpoint. In finance, legal, or HR contexts—that's a material risk.

Permissions aren't configured. Thirty-seven percent don't have permission and access controls for agents. When an agent can reach any system it needs to complete a task, you've effectively given it the same access as your most privileged users, without the same accountability.

Nobody knows what's running. Only 44% of companies have a registry of the agents deployed in their business. Talking to security leaders recently, I heard this described as the new shadow IT problem. Shadow agents—built by individual teams, running on company systems, accessing customer data—are accumulating faster than IT can track them.

For CIOs and CTOs: the conversation with your board shouldn't be "how many agents do we have running?" It should be "do we have a complete, auditable picture of every agent, what it can access, and who approved it?" If the answer is no, that's the thing to fix before the next deployment.

The Leadership Problem Nobody Talks About

Fewer than half of global enterprises—46%—have a dedicated AI leader responsible for AI adoption.

That number surprises people, but it explains a lot. When AI ownership is distributed across business units without central coordination, you get piecemeal adoption. The SAP data confirms it: piecemeal approaches are still the dominant model, at 41% of companies. Strategic, coordinated investment is still the minority at 17%.

The companies getting strong AI ROI are not the ones who said "yes" to every AI pilot. They're the ones who built an intentional strategy, assigned clear ownership, and measured outcomes against a baseline. Only 52% of companies have clear frameworks for AI development. Only 41% have trained employees on AI capabilities and risks.

You can't govern what you haven't defined, and you can't measure what you haven't baselined. These aren't technology problems—they're organizational design problems.

CFOs often ask me how to evaluate whether their company's AI investment is generating real returns. My answer: if you didn't establish a baseline before you deployed, you can't know. Industry research consistently shows that companies that skip the baseline step find themselves unable to attribute performance improvements to AI with any confidence.

What the $17.6 Million Agentic Prize Actually Requires

Eighty-three percent of business leaders say agentic AI has moderate-to-very-high potential to transform their organization. That's near-universal consensus. The business case for agentic AI is not in dispute.

What's in dispute is whether companies will do the work to capture it.

The path from 21% ROI today to 38% ROI in two years runs directly through three capabilities that most enterprises don't have yet:

Context-aware data. Agents need to operate on data that's clean, connected, and contextualized within business processes. A customer service agent needs to know not just the customer's account status, but the history of their last three interactions, the current product backlog status, and the escalation policy for their contract tier. Most enterprise data architectures weren't built for this kind of operational context at agent speed.

Governance infrastructure. Permissions, access controls, audit logs, human escalation paths, and a comprehensive agent registry. This isn't optional infrastructure—it's the difference between agents you can trust and agents you're just hoping don't cause problems.

Measurement discipline. The companies capturing outsized AI ROI are the ones that defined success metrics before deployment, not after. They know their baseline cost per transaction, their error rate before AI, their cycle time before automation. Without that, you're flying blind.

Talking with operations leaders at large enterprises, the pattern I see in high-performing AI programs is consistent: they start with a narrow, measurable use case, prove the return against a documented baseline, then expand. The temptation to deploy broadly and measure later is what's producing the 79% rework and delay figure in the SAP data.

The Shadow AI Problem Is Getting Worse

Sixty-nine percent of enterprises say shadow AI use happens at least occasionally. Last year that number was lower. It's moving in the wrong direction.

Shadow AI—employees using unauthorized AI tools on company data and workflows—is the agentic era's version of employees downloading unauthorized software onto company laptops. The risk profile is different, though. A piece of unauthorized software sits on one machine. An unauthorized AI agent can be querying company data, generating customer-facing communications, and executing process steps across multiple systems.

For CISOs and risk officers: shadow AI needs to be on your threat model right now, not after an incident. The governance gap between how fast AI tools are being adopted by individual employees and how fast enterprise policy is catching up is measurable in the data—and the data says the gap is widening.

The Bottom Line for Enterprise Leaders

The SAP/Oxford Economics Value of AI Report 2026 is one of the most data-rich pictures of enterprise AI reality I've seen this year. What it tells me is this:

AI ROI is improving, and the trajectory is real. Companies that get the fundamentals right now are positioning themselves for the agentic dividend—$17.6 million average ROI from agentic AI within two years. That's not a small prize.

But the 73% data quality failure rate, the 38% missing human oversight, the 37% without agent access controls, and the 69% deploying faster than they can govern—those aren't metrics that fix themselves. They require deliberate organizational investment: in data infrastructure, in governance frameworks, in leadership accountability, and in measurement discipline.

The enterprises that will capture the 38% ROI in 2028 are the ones doing that work today. Not next quarter. Today.

If you're a CIO or CTO reading this: run a quick internal audit. How many agents do you have in production? Do you have a complete registry? Do you have human-in-the-loop controls for consequential decisions? If you can't answer all three with confidence, those are your next three projects.

If you're a CFO or COO: ask your AI team to show you the baseline metrics they established before your last major AI deployment. If they can't, that's a conversation worth having before the next budget cycle.

The gap between AI winners and the rest isn't closing on its own. The data makes that clear.


The SAP and Oxford Economics Value of AI Report 2026 surveyed 2,600 business leaders across 13 countries. Full methodology and data available at the linked report.

Connect with Rajesh on LinkedIn or X for more enterprise AI analysis.

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

AI ROI Is Up 31%—But 73% Still Fail at the Basics

Photo by Pixabay on Pexels

There's a study out this week from SAP and Oxford Economics that I think every CIO, CTO, and CFO should read before making their next AI budget decision. They surveyed 2,600 business leaders across 13 countries and the results are a perfect portrait of where enterprise AI actually stands in 2026—not where vendors say it stands.

The headline is good: global AI ROI jumped from 16% to 21% year-over-year. On a typical $28 million AI budget, that's $6.3 million in return. It's real money, and it's moving in the right direction.

But then you read the next page.

Seventy-three percent of enterprises have serious problems with data quality. Seventy-nine percent report rework, delays, or backlogs caused by poor AI outputs. Only 3% say they're fully prepared for agentic AI. And 69% admit they're deploying AI agents faster than they can govern them.

That's not a success story. That's a house with a freshly painted exterior and a foundation that's starting to crack.

The ROI Numbers Actually Make Sense—If You Know What You're Measuring

The 21% ROI figure sounds underwhelming until you understand what's being measured. Companies are spending $28 million on AI and getting $6.3 million back this year. By 2028, that same $28 million is expected to return $15.9 million—a 38% ROI.

Here's what's driving the optimism: agentic AI. In conversations with finance leaders and operations executives, I keep hearing the same thing—the big ROI jump they're betting on isn't coming from copilots or chat assistants. It's coming from autonomous agents that can execute multi-step workflows without human handoffs. The SAP/Oxford data backs that up: average ROI from agentic AI is projected to reach $17.6 million in two years, more than quadrupling from last year's $4.3 million estimate.

That's the bet enterprises are making. And it's a reasonable one—if the foundation is solid.

For CFOs evaluating AI spend, the implication is clear: the companies hitting strong ROI this year are the ones who will capture the agentic wave next year. The ones still struggling with basics will get left further behind, not caught up.

What "The Basics" Actually Means

When 73% of global enterprises say they have data quality problems, that's not a technology issue—it's a business readiness issue.

Here's what I mean. Most organizations I've spoken with in the last year approached AI by layering it on top of existing data infrastructure. The logic was: we already have the data, we just need the AI. But AI doesn't forgive messy data the way a human analyst does. A person reads a customer record, notices the address is clearly wrong, and compensates. An AI agent routes a shipment to an invalid address, generates a refund, and flags a customer complaint—all before anyone realizes the source record was corrupted.

Seventy-nine percent of businesses in this survey are experiencing rework, delays, or backlogs from exactly this problem. They deployed AI on top of data that wasn't ready for it.

For technical leaders, the fix isn't glamorous: it's data governance, master data management, and schema discipline. The kind of work that doesn't make it into board presentations but determines whether your AI investments actually pay off.

The Agentic Readiness Gap Is Bigger Than Most Executives Realize

Three percent. That's how many enterprises say they are fully prepared for agentic AI.

The rest—97%—are either partially prepared or not prepared at all. But here's the part that should genuinely concern business leaders: 69% say they're deploying agents anyway, faster than they can govern them.

That's not bold. That's exposure.

When you deploy agents into production without proper controls, you're not taking calculated risk. You're creating invisible liability. Agents make decisions, take actions, send communications, modify records, and commit transactions. Without the right governance infrastructure in place, you lose auditability, you lose control, and in regulated industries, you potentially lose compliance standing.

The SAP data surfaces three specific gaps that matter most:

Human oversight is missing. Thirty-eight percent of companies don't have a human-in-the-loop process for agentic workflows. That means agents are executing consequential actions with no checkpoint. In finance, legal, or HR contexts—that's a material risk.

Permissions aren't configured. Thirty-seven percent don't have permission and access controls for agents. When an agent can reach any system it needs to complete a task, you've effectively given it the same access as your most privileged users, without the same accountability.

Nobody knows what's running. Only 44% of companies have a registry of the agents deployed in their business. Talking to security leaders recently, I heard this described as the new shadow IT problem. Shadow agents—built by individual teams, running on company systems, accessing customer data—are accumulating faster than IT can track them.

For CIOs and CTOs: the conversation with your board shouldn't be "how many agents do we have running?" It should be "do we have a complete, auditable picture of every agent, what it can access, and who approved it?" If the answer is no, that's the thing to fix before the next deployment.

The Leadership Problem Nobody Talks About

Fewer than half of global enterprises—46%—have a dedicated AI leader responsible for AI adoption.

That number surprises people, but it explains a lot. When AI ownership is distributed across business units without central coordination, you get piecemeal adoption. The SAP data confirms it: piecemeal approaches are still the dominant model, at 41% of companies. Strategic, coordinated investment is still the minority at 17%.

The companies getting strong AI ROI are not the ones who said "yes" to every AI pilot. They're the ones who built an intentional strategy, assigned clear ownership, and measured outcomes against a baseline. Only 52% of companies have clear frameworks for AI development. Only 41% have trained employees on AI capabilities and risks.

You can't govern what you haven't defined, and you can't measure what you haven't baselined. These aren't technology problems—they're organizational design problems.

CFOs often ask me how to evaluate whether their company's AI investment is generating real returns. My answer: if you didn't establish a baseline before you deployed, you can't know. Industry research consistently shows that companies that skip the baseline step find themselves unable to attribute performance improvements to AI with any confidence.

What the $17.6 Million Agentic Prize Actually Requires

Eighty-three percent of business leaders say agentic AI has moderate-to-very-high potential to transform their organization. That's near-universal consensus. The business case for agentic AI is not in dispute.

What's in dispute is whether companies will do the work to capture it.

The path from 21% ROI today to 38% ROI in two years runs directly through three capabilities that most enterprises don't have yet:

Context-aware data. Agents need to operate on data that's clean, connected, and contextualized within business processes. A customer service agent needs to know not just the customer's account status, but the history of their last three interactions, the current product backlog status, and the escalation policy for their contract tier. Most enterprise data architectures weren't built for this kind of operational context at agent speed.

Governance infrastructure. Permissions, access controls, audit logs, human escalation paths, and a comprehensive agent registry. This isn't optional infrastructure—it's the difference between agents you can trust and agents you're just hoping don't cause problems.

Measurement discipline. The companies capturing outsized AI ROI are the ones that defined success metrics before deployment, not after. They know their baseline cost per transaction, their error rate before AI, their cycle time before automation. Without that, you're flying blind.

Talking with operations leaders at large enterprises, the pattern I see in high-performing AI programs is consistent: they start with a narrow, measurable use case, prove the return against a documented baseline, then expand. The temptation to deploy broadly and measure later is what's producing the 79% rework and delay figure in the SAP data.

The Shadow AI Problem Is Getting Worse

Sixty-nine percent of enterprises say shadow AI use happens at least occasionally. Last year that number was lower. It's moving in the wrong direction.

Shadow AI—employees using unauthorized AI tools on company data and workflows—is the agentic era's version of employees downloading unauthorized software onto company laptops. The risk profile is different, though. A piece of unauthorized software sits on one machine. An unauthorized AI agent can be querying company data, generating customer-facing communications, and executing process steps across multiple systems.

For CISOs and risk officers: shadow AI needs to be on your threat model right now, not after an incident. The governance gap between how fast AI tools are being adopted by individual employees and how fast enterprise policy is catching up is measurable in the data—and the data says the gap is widening.

The Bottom Line for Enterprise Leaders

The SAP/Oxford Economics Value of AI Report 2026 is one of the most data-rich pictures of enterprise AI reality I've seen this year. What it tells me is this:

AI ROI is improving, and the trajectory is real. Companies that get the fundamentals right now are positioning themselves for the agentic dividend—$17.6 million average ROI from agentic AI within two years. That's not a small prize.

But the 73% data quality failure rate, the 38% missing human oversight, the 37% without agent access controls, and the 69% deploying faster than they can govern—those aren't metrics that fix themselves. They require deliberate organizational investment: in data infrastructure, in governance frameworks, in leadership accountability, and in measurement discipline.

The enterprises that will capture the 38% ROI in 2028 are the ones doing that work today. Not next quarter. Today.

If you're a CIO or CTO reading this: run a quick internal audit. How many agents do you have in production? Do you have a complete registry? Do you have human-in-the-loop controls for consequential decisions? If you can't answer all three with confidence, those are your next three projects.

If you're a CFO or COO: ask your AI team to show you the baseline metrics they established before your last major AI deployment. If they can't, that's a conversation worth having before the next budget cycle.

The gap between AI winners and the rest isn't closing on its own. The data makes that clear.


The SAP and Oxford Economics Value of AI Report 2026 surveyed 2,600 business leaders across 13 countries. Full methodology and data available at the linked report.

Connect with Rajesh on LinkedIn or X for more enterprise AI analysis.

Share:
THE DAILY BRIEF
Enterprise AIAI ROIAgentic AIAI StrategyAI Governance
AI ROI Is Up 31%—But 73% Still Fail at the Basics

SAP and Oxford Economics surveyed 2,600 AI leaders: global ROI up 31% but 73% have data failures and only 3% are ready for agentic AI.

By Rajesh Beri·July 23, 2026·9 min read

There's a study out this week from SAP and Oxford Economics that I think every CIO, CTO, and CFO should read before making their next AI budget decision. They surveyed 2,600 business leaders across 13 countries and the results are a perfect portrait of where enterprise AI actually stands in 2026—not where vendors say it stands.

The headline is good: global AI ROI jumped from 16% to 21% year-over-year. On a typical $28 million AI budget, that's $6.3 million in return. It's real money, and it's moving in the right direction.

But then you read the next page.

Seventy-three percent of enterprises have serious problems with data quality. Seventy-nine percent report rework, delays, or backlogs caused by poor AI outputs. Only 3% say they're fully prepared for agentic AI. And 69% admit they're deploying AI agents faster than they can govern them.

That's not a success story. That's a house with a freshly painted exterior and a foundation that's starting to crack.

The ROI Numbers Actually Make Sense—If You Know What You're Measuring

The 21% ROI figure sounds underwhelming until you understand what's being measured. Companies are spending $28 million on AI and getting $6.3 million back this year. By 2028, that same $28 million is expected to return $15.9 million—a 38% ROI.

Here's what's driving the optimism: agentic AI. In conversations with finance leaders and operations executives, I keep hearing the same thing—the big ROI jump they're betting on isn't coming from copilots or chat assistants. It's coming from autonomous agents that can execute multi-step workflows without human handoffs. The SAP/Oxford data backs that up: average ROI from agentic AI is projected to reach $17.6 million in two years, more than quadrupling from last year's $4.3 million estimate.

That's the bet enterprises are making. And it's a reasonable one—if the foundation is solid.

For CFOs evaluating AI spend, the implication is clear: the companies hitting strong ROI this year are the ones who will capture the agentic wave next year. The ones still struggling with basics will get left further behind, not caught up.

What "The Basics" Actually Means

When 73% of global enterprises say they have data quality problems, that's not a technology issue—it's a business readiness issue.

Here's what I mean. Most organizations I've spoken with in the last year approached AI by layering it on top of existing data infrastructure. The logic was: we already have the data, we just need the AI. But AI doesn't forgive messy data the way a human analyst does. A person reads a customer record, notices the address is clearly wrong, and compensates. An AI agent routes a shipment to an invalid address, generates a refund, and flags a customer complaint—all before anyone realizes the source record was corrupted.

Seventy-nine percent of businesses in this survey are experiencing rework, delays, or backlogs from exactly this problem. They deployed AI on top of data that wasn't ready for it.

For technical leaders, the fix isn't glamorous: it's data governance, master data management, and schema discipline. The kind of work that doesn't make it into board presentations but determines whether your AI investments actually pay off.

The Agentic Readiness Gap Is Bigger Than Most Executives Realize

Three percent. That's how many enterprises say they are fully prepared for agentic AI.

The rest—97%—are either partially prepared or not prepared at all. But here's the part that should genuinely concern business leaders: 69% say they're deploying agents anyway, faster than they can govern them.

That's not bold. That's exposure.

When you deploy agents into production without proper controls, you're not taking calculated risk. You're creating invisible liability. Agents make decisions, take actions, send communications, modify records, and commit transactions. Without the right governance infrastructure in place, you lose auditability, you lose control, and in regulated industries, you potentially lose compliance standing.

The SAP data surfaces three specific gaps that matter most:

Human oversight is missing. Thirty-eight percent of companies don't have a human-in-the-loop process for agentic workflows. That means agents are executing consequential actions with no checkpoint. In finance, legal, or HR contexts—that's a material risk.

Permissions aren't configured. Thirty-seven percent don't have permission and access controls for agents. When an agent can reach any system it needs to complete a task, you've effectively given it the same access as your most privileged users, without the same accountability.

Nobody knows what's running. Only 44% of companies have a registry of the agents deployed in their business. Talking to security leaders recently, I heard this described as the new shadow IT problem. Shadow agents—built by individual teams, running on company systems, accessing customer data—are accumulating faster than IT can track them.

For CIOs and CTOs: the conversation with your board shouldn't be "how many agents do we have running?" It should be "do we have a complete, auditable picture of every agent, what it can access, and who approved it?" If the answer is no, that's the thing to fix before the next deployment.

The Leadership Problem Nobody Talks About

Fewer than half of global enterprises—46%—have a dedicated AI leader responsible for AI adoption.

That number surprises people, but it explains a lot. When AI ownership is distributed across business units without central coordination, you get piecemeal adoption. The SAP data confirms it: piecemeal approaches are still the dominant model, at 41% of companies. Strategic, coordinated investment is still the minority at 17%.

The companies getting strong AI ROI are not the ones who said "yes" to every AI pilot. They're the ones who built an intentional strategy, assigned clear ownership, and measured outcomes against a baseline. Only 52% of companies have clear frameworks for AI development. Only 41% have trained employees on AI capabilities and risks.

You can't govern what you haven't defined, and you can't measure what you haven't baselined. These aren't technology problems—they're organizational design problems.

CFOs often ask me how to evaluate whether their company's AI investment is generating real returns. My answer: if you didn't establish a baseline before you deployed, you can't know. Industry research consistently shows that companies that skip the baseline step find themselves unable to attribute performance improvements to AI with any confidence.

What the $17.6 Million Agentic Prize Actually Requires

Eighty-three percent of business leaders say agentic AI has moderate-to-very-high potential to transform their organization. That's near-universal consensus. The business case for agentic AI is not in dispute.

What's in dispute is whether companies will do the work to capture it.

The path from 21% ROI today to 38% ROI in two years runs directly through three capabilities that most enterprises don't have yet:

Context-aware data. Agents need to operate on data that's clean, connected, and contextualized within business processes. A customer service agent needs to know not just the customer's account status, but the history of their last three interactions, the current product backlog status, and the escalation policy for their contract tier. Most enterprise data architectures weren't built for this kind of operational context at agent speed.

Governance infrastructure. Permissions, access controls, audit logs, human escalation paths, and a comprehensive agent registry. This isn't optional infrastructure—it's the difference between agents you can trust and agents you're just hoping don't cause problems.

Measurement discipline. The companies capturing outsized AI ROI are the ones that defined success metrics before deployment, not after. They know their baseline cost per transaction, their error rate before AI, their cycle time before automation. Without that, you're flying blind.

Talking with operations leaders at large enterprises, the pattern I see in high-performing AI programs is consistent: they start with a narrow, measurable use case, prove the return against a documented baseline, then expand. The temptation to deploy broadly and measure later is what's producing the 79% rework and delay figure in the SAP data.

The Shadow AI Problem Is Getting Worse

Sixty-nine percent of enterprises say shadow AI use happens at least occasionally. Last year that number was lower. It's moving in the wrong direction.

Shadow AI—employees using unauthorized AI tools on company data and workflows—is the agentic era's version of employees downloading unauthorized software onto company laptops. The risk profile is different, though. A piece of unauthorized software sits on one machine. An unauthorized AI agent can be querying company data, generating customer-facing communications, and executing process steps across multiple systems.

For CISOs and risk officers: shadow AI needs to be on your threat model right now, not after an incident. The governance gap between how fast AI tools are being adopted by individual employees and how fast enterprise policy is catching up is measurable in the data—and the data says the gap is widening.

The Bottom Line for Enterprise Leaders

The SAP/Oxford Economics Value of AI Report 2026 is one of the most data-rich pictures of enterprise AI reality I've seen this year. What it tells me is this:

AI ROI is improving, and the trajectory is real. Companies that get the fundamentals right now are positioning themselves for the agentic dividend—$17.6 million average ROI from agentic AI within two years. That's not a small prize.

But the 73% data quality failure rate, the 38% missing human oversight, the 37% without agent access controls, and the 69% deploying faster than they can govern—those aren't metrics that fix themselves. They require deliberate organizational investment: in data infrastructure, in governance frameworks, in leadership accountability, and in measurement discipline.

The enterprises that will capture the 38% ROI in 2028 are the ones doing that work today. Not next quarter. Today.

If you're a CIO or CTO reading this: run a quick internal audit. How many agents do you have in production? Do you have a complete registry? Do you have human-in-the-loop controls for consequential decisions? If you can't answer all three with confidence, those are your next three projects.

If you're a CFO or COO: ask your AI team to show you the baseline metrics they established before your last major AI deployment. If they can't, that's a conversation worth having before the next budget cycle.

The gap between AI winners and the rest isn't closing on its own. The data makes that clear.


The SAP and Oxford Economics Value of AI Report 2026 surveyed 2,600 business leaders across 13 countries. Full methodology and data available at the linked report.

Connect with Rajesh on LinkedIn or X for more enterprise AI analysis.

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe