The three most common gaps in AI Adoption

Over the last few months, we’ve been helping clients understand what it really takes to adopt AI well. Across those conversations, three challenges keep coming up.

From what we’re seeing, successful AI adoption is not just about buying the right tool. It’s about aligning leadership ambition with operational reality, preparing the organisation’s information environment, and making sure security is strong enough for AI to work safely.

1. Mismatch between the buyer and executor of AI

Executives are often sold on the promise of productivity gains, but the people expected to implement AI may not have been part of the buying conversation. That creates a gap between expectation and execution.

    The numbers back this up. IBM’s 2026 Global CEO Study found that 85% of employees now have access to AI tools at work, but only 25% use them regularly: a 61-point gap between what’s been rolled out and what gets used day to day.

    CEOs in that same study ranked employee adoption as their single biggest AI concern, ahead of cost, security, and even accuracy. And a separate 2026 survey of 2,400 global leaders found that 75% admit their own AI strategy is “more for show” than actual internal guidance.

    That’s the pattern we keep seeing on the ground: a strategy deck gets approved at the top, licenses get bought, and the people meant to use the tool day-to-day were never in the room when the promise was made. AI can be incredibly powerful, but it needs proper assessment, clear use cases, and a strong understanding of the organisation’s workflows. It is almost never a plug-and-play solution.

    2. Readiness for adoption

    At its heart, AI is intelligent automation. We’ve had tools that reduce human effort in knowledge work for a long time. What has changed is that AI can now interpret, manage, and make decisions when we allow it to. For that to work well, it needs the right information, in the right structure, with the right context.

      Practically, that means organised files, structured databases, and data storage that AI can interpret reliably. Without that foundation, AI becomes either too expensive to scale or too error-prone to trust. MIT’s widely cited research found that roughly 95% of enterprise generative AI pilots deliver no measurable business impact. The root cause almost always being organisational and data-related, not technological. Gartner has found that 63% of organisations either don’t have, or aren’t sure they have, the data management practices AI needs to work with. And a Cloudera/Harvard Business Review survey of over 1,500 enterprise IT leaders found only 7% of organisations describe their data as completely AI-ready.

      Put simply: most companies are further along in buying AI than they are in preparing for it. The model is rarely the bottleneck. The mess underneath it is.

      3. Security

      There’s a lot of noise right now about the long-term risks of AI, but for organisations considering adoption, the immediate concern is much more practical: security. Are your permission structures set up correctly? Have you made your files secure? Are sensitive details stored somewhere they shouldn’t be? Any existing risk in your organisation can be magnified by AI, because AI makes information easier to find, combine, and act on.

      Microsoft Copilot is a good, concrete example of this; Copilot doesn’t override your permissions, but it works entirely within them. This sounds reassuring until you realise most enterprises have spent over a decade accumulating SharePoint sites, Teams channels, and shared folders with access rights nobody has audited in years. In one documented Microsoft incident, Teams Copilot surfaced content from HR investigation channels, legal hold discussions, and executive compensation threads, simply because the users asking had been given overly broad group access.

      Concentric AI’s research puts a number on the scale of the problem: on average, 16% of business-critical data sits overshared across an organisation. This amounts to roughly 800,000 at-risk files per company. And per IBM’s 2025 breach report, 97% of organisations that suffered an AI-related security incident didn’t have proper AI access controls in place with “shadow AI” usage alone adding an average of $670,000 to the cost of a breach.

      AI doesn’t create these gaps. It finds them faster than any employee ever could.

      What this means

      If organisations want AI to deliver real value, they need to do more than switch on a new tool. They need to set realistic expectations, build the right foundations, and close the security gaps that AI will otherwise expose.

      In practice, that starts with three questions before any rollout:

      Who actually has to use this day-to-day, and were they consulted? Is the data this tool will touch organised well enough to trust? And who currently has access to what, and has anyone checked recently? These are questions about people, processes, behaviour and organisational readiness.

      That is the work I focus on at Engage Group: helping organisations understand where they are ready for AI, where the gaps are, and what needs to change for adoption to work in practice.

      Because successful AI adoption is ultimately a human challenge as much as a technology one.

      At Engage Group, we help organisations navigate the human side of business. And when it comes to AI, that human side matters more than ever.

      By Shreerag Plakazhi, AI & Technology Adoption Lead