
[ 14 ]
ARTICLE
August 2026
AI Is Scaling Where It Is Easiest to Govern, Which Is Not the Same as Where It Is Safest
The governance budget already exists. It is being spent on watching, not testing.
There is a useful piece of data in the August edition of PYMNTS Intelligence's Enterprise AI Benchmark Report, and a caveat that should come with it.
The caveat first. The survey is 60 senior technology executives at US companies with at least a billion in annual revenue, fielded in June 2026. Sixty is small. Treat the numbers as directional, not precise. Anyone quoting these to two decimal places is overselling them.
With that said.
The finding
The report's argument is that enterprise AI adoption is not uniform inside a company, and the dividing line is not industry or budget or executive enthusiasm. It is function.
AI is scaling fastest where organisations already have structured data, technical ownership, and outcomes that can be measured with some precision. PYMNTS puts it plainly: companies are scaling AI where the operating environment makes it easiest to govern, evaluate and improve.
In data and technology functions, broad or embedded deployment is now the norm. Ninety five percent of financial services firms, 84 percent of healthcare firms, 81 percent of media firms.
Among the firms that have scaled in data and technology, the most common applications are security monitoring at 77 percent, infrastructure optimisation and data ingestion and cleansing at 68 percent each, and AI governance tooling at 63 percent.
Note the framing on that last set of numbers, because it gets misquoted. It is 63 percent of firms already scaled in data and technology, not 63 percent of everyone surveyed. Different denominator, meaningfully different claim.
Why this matters more than it looks
Two things fall out of this.
The first is that the security function is not a laggard in AI adoption. It is the leading edge. Security monitoring is the single most common scaled application in the whole dataset. Whatever you think about enterprise AI hesitancy, security teams are already running it.
The second is that the governance budget exists. Governance tooling is a scaled deployment at nearly two thirds of the firms furthest along. Nobody has to be convinced that AI governance is a category worth spending on. That argument is over.
For anyone selling into this, that is the difference between educating a market and competing in one. It is a much better problem.
The word doing the heavy lifting
Go back to the PYMNTS sentence: easiest to govern, evaluate and improve.
Evaluate is carrying a lot of weight there, and I think it means something narrower than it sounds.
In these functions, evaluate means you can measure the outcome. Did the anomaly detection catch the anomaly. Did the forecast match the cash position. Did the pipeline finish. Those are auditable because the ground truth arrives later and you can compare against it.
That is a good reason to start there. It is also why the same approach does not transfer to safety.
Safety behaviour has no arriving ground truth. If your model quietly stopped refusing a category of request after you compressed it, nothing shows up in your logs, because the failure looks like a normal successful response. There is no delayed signal to compare against. Nobody files a ticket.
So the functions where AI scaled first are exactly the functions where a monitoring approach works. Which is fine, and also why monitoring became the dominant tool.
Monitoring and testing are different purchases
This is the part I would push on.
Governance tooling, as deployed today, mostly watches the running system. Access control, policy enforcement, logging, drift alerts on outputs. It is genuinely valuable and it is clearly selling.
It watches the deployment. It does not test the artifact.
Testing the artifact means taking the specific weights you are about to ship, after fine tuning, after quantization, after whatever your serving stack does to them, and attacking them deliberately to see what changed. That is a pre deployment activity that produces evidence, not a dashboard.
Nothing on the PYMNTS list is that. Security monitoring is not that. Governance tooling is not that.
Which is either a gap in the market or a gap in the survey categories, and both readings are interesting.
What I would take from this
Three things.
The buyer exists, is technical, owns a budget, and has already bought adjacent tooling. That is the good news, and it is not nothing.
The mental model in place is monitoring. Anything sold as testing has to explain why watching production is not sufficient, and the honest answer is that a silent safety regression produces no signal to watch.
And the numbers are from 60 people. Use them to describe a direction, not to prove a market size.
The category is real. The specific thing we do is not on the list yet.
References
- PYMNTS Intelligence (August 2026). Enterprise AI Benchmark Report. Survey of 60 senior technology executives at US firms with $1B+ annual revenue, fielded June 2026.
- Capability Evaluations Are Not Safety Evaluations
START FREE
If any of this describes your pipeline, SichGate runs the adversarial battery and gives you the differential before you ship.
START FREE ASSESSMENT →