SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
IT leaders prioritise AI over infrastructure as code

IT leaders prioritise AI over infrastructure as code

Mon, 27th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Fleet Device Management has published research suggesting many enterprise IT leaders are prioritising AI automation over infrastructure as code. The survey covered more than 500 enterprise IT leaders.

The findings show that 46.5% of respondents rank AI-driven automation as their top IT investment priority over the next 12 to 24 months, while 29.6% prioritise infrastructure as code, or IaC. Fleet argues that IaC provides the version-controlled foundation for governance, auditability and rollback when AI systems make operational changes.

The research also points to a gap between AI spending plans and current automation levels in endpoint management. Only 13% of respondents described their organisations' endpoint management as fully autonomous, while 87% said they still rely on manual or partly automated workflows.

That mismatch also appears in the operational challenges IT teams expect to face over the next three years. The leading concern was patching critical vulnerabilities quickly enough to keep pace with attackers, followed by managing rising device complexity, handling disruptive changes that cannot easily be reversed, and keeping up with AI adoption.

Patch deployment times remain slow for many organisations. The survey found that 79% take more than a day to deploy critical security patches, even as threat actors move quickly to exploit newly disclosed vulnerabilities.

Visibility across device fleets is also limited. Six in 10 organisations said they still lack complete visibility across their devices, while 59% take more than 24 hours to fully provision a new employee device. More than a quarter said the process takes four days or longer.

Tool sprawl is adding to the burden on IT teams. The survey found that 87% of respondents rely on at least three endpoint management tools rather than a single platform, creating extra complexity in day-to-day operations.

AI oversight

The research also highlights governance issues around workplace AI use. The average enterprise in the survey runs 14 AI applications, yet IT teams have visibility into only four, while 78% of employees use personal AI tools at work.

That points to a broader shadow AI problem, with staff adopting tools outside formal oversight. Fleet cited IBM data showing that breaches involving shadow AI cost organisations an average of USD $670,000 more than breaches without it, raising the average breach cost from USD $3.96 million to USD $4.63 million.

Allen Houchins, Chief Information Officer at Fleet, said the gap mirrors earlier AI adoption in software development, where coding assistants became more practical once Git-based controls were in place.

"While you can turn an AI agent loose, you probably shouldn't. Software engineering didn't embrace AI coding assistants until Git-based workflows provided the necessary guardrails. IT organizations need the same kind of machine-readable, version-controlled infrastructure before AI can safely manage endpoints, automate remediation and perform operational tasks," said Allen Houchins, Chief Information Officer, Fleet.

"Without that foundation, organizations risk chasing AI outcomes without the governance, visibility and controls required to deploy them confidently," Houchins said.

Operational base

Infrastructure as code is commonly used to define and manage systems through version-controlled files rather than manual configuration. In practice, that allows changes to be reviewed, tracked and reversed, making it a central discipline in software and cloud operations.

Fleet argues that the same model is becoming more important in endpoint management as companies seek to give AI systems a larger role in routine IT tasks. Those tasks can include remediation, provisioning and system changes that would otherwise require manual intervention.

The company linked the issue to wider business risk. If AI tools are being used across an organisation without clear visibility, IT departments may be expected to govern technologies they cannot fully see or control while also struggling with slow patching, fragmented tools and limited automation.

Mike McNeil, Chief Executive Officer and Co-Founder of Fleet, said version control and human review are necessary before AI can be trusted with greater operational responsibility.

"Infrastructure as code turns AI from a chatbot into a force multiplier for IT teams," said Mike McNeil, Chief Executive Officer and Co-Founder, Fleet.

"Because every change is reviewed, version-controlled and reversible, AI can automate routine operations without giving up human control and oversight. In other words, the people who deployed Claude, Codex and other AI tools can now actually use them," McNeil said.