AI confidence among IT leaders just fell sharply. Here is why that is good news.

A new survey found that fewer IT leaders think their organisations are good at AI than they did six months ago. The reason tells you everything about where AI is actually headed.

AI2Day Newsdesk· 3 min read
AI agents in a digital network with security icons
Share

Key points

  • The share of IT leaders who called their organisations "mature" at deploying AI fell from 40% to 23% between early 2025 and Q3 2026, according to a JumpCloud survey of 800 IT leaders in the US and UK.
  • 84% of those same leaders plan to expand AI use in IT operations over the next six to 24 months, so the drop is not a retreat.
  • Only 21% of organisations have formal governance, meaning rules, oversight and accountability, for non-human AI agents, the lowest adoption rate of any AI security practice measured.
  • In 83% of organisations, AI agents and automated software identities now outnumber human employees on their systems.

Six months ago, four in ten IT leaders said their organisations were genuinely good at deploying AI. Today, fewer than one in four say the same thing. On the surface that sounds bad. It is not.

JumpCloud, a company that sells software for managing IT access and security, surveyed 800 IT leaders across the US and UK for its Q3 2026 trends report, first covered by VentureBeat. The leaders who revised their confidence downward are, overwhelmingly, the ones who moved AI agents, software programs that carry out tasks on their own without a human approving each step, from small test projects into live production environments. Real work, real systems, real problems.

Pilots are tidy. Production is not.

In a controlled test, an AI agent does one thing in a safe setting. In a live environment, it connects to real company data, makes decisions that change how work gets done, and runs around the clock, often with nobody watching. The governance infrastructure needed for that, meaning the rules, logs, and oversight systems that keep the agent accountable, is far more demanding than what it takes to run a pilot.

What happens to ordinary workers when AI agents go unsupervised?

The risk lands on everyone in the building, not just the IT team. JumpCloud's data identifies a specific failure point it calls "zombie agents": AI programs that were set up for a task, then never properly switched off or reviewed. They keep running. They keep accessing files and systems. Nobody owns them. Nobody audits them.

Non-human identities, a term for any software program or agent that logs into company systems the way a person would, now outnumber human users in 83% of organisations. Yet only 21% of organisations have formal governance for them. No named owner. No defined limits on what they can access. No process to shut them down when the job is done.

When a human employee does something unexpected at work, there is an accountability trail. When an autonomous agent does, that trail does not exist unless someone built it deliberately. Most organisations have not built it yet.

The organisations that have closed that gap share a common approach. They treat AI agents the same way they treat human employees: registered, limited to the access they actually need, and removed from systems when their purpose expires. The payoff is concrete. Organisations in the top tier of JumpCloud's maturity model are five times more likely to report no barriers to expanding their AI programs than the average organisation.

Confidence built on a real foundation is worth having. Confidence built on a pilot that has not met the real world yet is a liability dressed up as progress. The leaders dropping their scores are the ones doing the honest accounting.

© 2026 AI2Day