Innovation is about balancing control with autonomy. But when a “perfect prototype” developed with high autonomy meets the reality of enterprise-wide deployment, many organizations find themselves unprepared for the complexities of scaling.
According to KPMG’s 2026 Global Tech Report, roughly 60% of organizations say AI investment is outpacing their governance capabilities.
Enterprise AI puts new demands on IT operations. As AI takes on a larger role, CIOs need the structures to govern and manage it over time. An IT maturity assessment can help CIOs prioritize the investments and improvements needed to support their AI goals.
The IT maturity gap behind AI
AI can move quickly with a prototype because teams tightly control where and how it operates. In full-scale production, AI has to work within the parameters of existing technology and processes, including legacy systems, architecture constraints, and security requirements.
For example, one KPMG LLP insurance client found that its underwriting AI team had to develop enterprise architecture rules as it tried to move its solutions into production. As you might expect, those rules were overwritten when they went to scale. This leads to what can be called the “perfect prototype problem.” A team becomes anchored to a solution that works perfectly in isolation but resists the necessary controls required to scale.
Further, without clear ownership and lifecycle management, organizations risk growing a population of “AI dark zombies” that cost money, drift from their original intent, go unsupported by the help desk, and never properly shut down. This army of dark AI will create significant technical debt and risk.
Once deployed, AI needs clear ownership, so it remains supported and useful as technology and business needs change. IT also needs visibility into what AI is running across the organization so teams can manage those investments and retire deployments that no longer serve a purpose.
What AI readiness requires from IT
An IT maturity assessment shows how well current IT capabilities can support AI and identify the areas that need attention.
AI readiness depends on several core IT capabilities:
- Enterprise architecture (EA): AI leaders have a 44-point maturity gap over laggards in enterprise architecture, highlighting how critical this “revenge of the EA” is for success.
- Strategy and investment management: Use value architecture to assess AI investments and determine what’s worth pursuing.
- Asset management: Manage AI as an enterprise asset, optimizing costs and managing it throughout its lifecycle.
- Governance and risk: Define how much autonomy AI should have and where human oversight is needed.
- Data management: KPMG research shows that AI leaders are 2.5 times more likely to have mastered their data, often through the use of certified data products that can be trusted across the organization.
With strength in these capabilities, teams can take new approaches with AI more quickly because the structures needed to support them are already established.
Build trust before adding autonomy
Trust in an AI system, much like trust between humans, relies on four fundamental behaviors:
- credibility
- reliability
- transparency
- cooperation
Within KPMG’s Trusted AI framework, these behaviors are operationalized across 10 ethical pillars, such as explainability, data integrity, and accountability. This ensures that systems remain values-driven and human-centric as autonomy scales.
It also requires fine-tuning the enterprise risk framework specifically for AI by identifying new threat vectors, assessing their likelihood and impact, and defining mitigations. AI is sharing more “first line of defense” responsibility with humans, so organizations must negotiate and monitor expectations when the “line” is not human.
Unlike with most human decisions, an AI system’s decisions can be systematically inspected. Under a mature Trusted AI model, transparency and explainability eliminate the black box by validating data integrity upfront. This model also provides traceable decision logic that allows CIOs to verify whether stated behavior matches actual execution.
Scale AI without losing sight of it
For AI to take on more responsibility, CIOs need to decide where it can act independently and where human oversight is warranted based on risk. IT also needs ongoing monitoring to make sure AI continues to perform as intended and stays within boundaries.
These data and controls give CIOs greater confidence to extend AI into higher-value use cases while protecting the business from operational and reputational risk.
See how the KPMG IT Maturity Assessment can help you prioritize the IT improvements needed to expand AI across your enterprise.
©2026 KPMG LLP, a Delaware limited liability partnership, and its subsidiaries are part of the KPMG global organization of independent member firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved.
Read More from This Article: Is your AI strategy creating “dark zombies”?
Source: News

