SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Enterprise AI deployments slowed by security reviews

Enterprise AI deployments slowed by security reviews

Fri, 31st Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Protegrity has published research on barriers to enterprise AI deployment, finding that security, governance and compliance reviews are slowing projects as companies move from pilots to production.

The report, produced by Enterprise Management Associates and based on a survey of IT and security leaders, found that 82.9% of organisations had seen AI projects delayed before reaching production because of security or compliance reviews. It also found that 81.6% had deployed AI in a reduced form because of security concerns, including limits on agent autonomy or data access.

The findings point to a gap between AI investment and the practical steps needed to put systems into day-to-day use. More than two-thirds of delayed projects remained stalled for at least a month, while nearly 30% were delayed for four months or longer.

The pattern comes as many companies push beyond experimentation. The survey found that 37.5% of organisations are scaling AI across several departments and production workflows, while 20.4% have moved into autonomous agentic workflows.

Production bottlenecks

The report argues that the main obstacle is not model performance or a lack of spending, but the controls around AI use in environments that handle sensitive data and regulated processes. These checks are creating what it describes as an "AI friction tax", paid through delays, reduced functionality and heavier governance workloads.

Researchers also found that many organisations already allow AI agents to take actions in live environments. Some 69% said they operate AI agents that can write to databases or trigger application programming interfaces, yet only 19.7% reported deploying highly autonomous AI systems.

The gap suggests many businesses are willing to let AI act inside production systems but remain cautious about granting it broader independence. That tension is reflected in the reported security concerns. Data leakage through autonomous agent actions was cited by 62.5% of respondents as their leading worry, followed by regulatory compliance concerns at 48.7% and prompt injection at 44.1%.

The study also examined the business case for changing these processes. Nearly half of respondents, 47.4%, said reducing manual audit and compliance costs would be the most valuable outcome of stronger AI data security and governance.

Governance strain

The research suggests existing governance systems are struggling to keep pace with AI's spread into operational settings. Companies appear to be advancing AI projects, but often with restrictions designed to lower risk, even when those restrictions reduce the original scope of the deployment.

Another finding pointed to demand for more direct ways to secure data in AI workflows. A total of 91.5% of respondents said AI-ready data without roadblocks, enabled by embedding protection inside the workflow, would be very or extremely valuable.

For businesses adopting AI across customer operations, internal processes and software development, the results indicate that manual oversight remains a significant drag on rollout speed. Governance limitations, data protection concerns and compliance demands continue to constrain AI systems after development is complete.

That matters because many organisations have already moved beyond trials. Once AI systems begin interacting with production databases, triggering external systems or handling sensitive information, delays in approvals or restrictions on data access can change what those systems are able to do in practice.

James Rice, Vice President of Product Marketing at Protegrity, said the findings show a divide between creating AI demonstrations and putting them into business use. "AI has quickly become a business imperative, but many organizations are discovering that getting AI into production is far more difficult than building a proof of concept," Rice said. "This research helps to better understand where those barriers exist and what they're costing enterprises. The findings show that security, governance and compliance have become critical business considerations that can either accelerate AI adoption or slow it dramatically. Organisations that address this friction will be in a much stronger position to realize AI's full value."

Enterprise Management Associates said the survey showed companies are often making trade-offs rather than solving the underlying governance problem. "Security, governance and compliance are now the primary barriers preventing enterprises from moving AI into production at the pace the business demands," said Chris Steffen, Vice President of Research, Information Security at EMA. "The findings make clear that many organizations are compensating by deploying AI with reduced capabilities rather than the functionality originally intended. That compromise is widening the gap between AI investment and business value, while adding avoidable costs, delays and operational inefficiencies."