two numbers from the same desk, and they explain each other. gartner puts real agentic capability at roughly 130 vendors out of the thousands claiming it, and expects more than 40 percent of agentic ai projects to be scrapped by the end of 2027, on cost, unclear value, or risk controls nobody built.
a canceled project does not just burn the budget. it burns a year of calendar and the company's appetite for the next attempt, which is the expensive part.
the fake move is picking a bigger platform and granting the agent more autonomy, which schedules the production incident sooner. do the version that holds: ask the vendor to name one decision the system makes without a human and what happens when that decision is wrong. then scope the smallest agent that touches nothing irreversible, and earn the next one.
ai infrastructure spend is running near $400 billion a year against roughly $100 billion in enterprise ai revenue. chip stocks slid into a bear market this summer, and fund managers just logged a record reading on overspend worry.
the gap belongs to the hyperscalers. the buying habit it normalized landed on you: seats, tiers and capacity bought ahead of any workload that asked for them, on the theory that the capability would find a use later. it shows up in your p&l as licenses nobody activated and a committed tier you keep renewing because unwinding it now looks worse than paying for it.
the move going around is to wait out the shakeout and buy cheaper in a year, which is the same unattached purchase with a later date on it. do the version that holds: name the one workflow costing you the most hours this quarter, buy only what that workflow needs, and write the number it has to move before the renewal lands.
77 percent of employees now paste content into ai chatbots, and roughly 82 percent of the risky pastes go through personal, unmanaged accounts. that is client data, pricing, contract language and code sitting in a consumer account tied to someone's personal email: outside your retention policy, outside legal hold, and out the door with them when they leave.
68 percent of security leaders report an ai-linked data leak while only 23 percent have any policy written down, which tells you the leaks are running well ahead of the paperwork.
the move everyone reaches for is the blocklist and the annual training module, and it produces exactly one measurable outcome: the same work, done on a phone, in a tab you have no visibility into. do the version that holds: stand up one sanctioned account with retention and admin controls on, tell people plainly it is there and why, then write the policy in three lines. use the company account, never paste client or employee data, one named person owns exceptions.
publicis sapient surveyed 1,550 ai decision-makers at companies with at least 500 people and $100m in revenue, and the two numbers that matter sit right next to each other. 73 percent say ai is used regularly or across most business processes. 10 percent say it is core to how the business operates.
47 percent think the technology is already good enough for what they need today, while 42 percent say their own company is not built to capture the value. that is a room full of buyers quietly telling you the bottleneck is not on the vendor's side of the table. the cost is a year of licenses, training hours and pilot calendar spent buying a faster version of the same process, with the same handoff, the same approver, and the same undocumented definition of good sitting underneath it.
the fake move is the next platform, or the agent layer on top of the platform, which adds capability to work nobody has written down. do the version that holds: take the one process that touches revenue most often, write its real steps as they happen now and not as the org chart claims, name who owns each handoff, define a good output in one paragraph, then let the tool into that.
ai-washing is now an enforcement category, with thirteen federal actions since 2024 over claims about what a product could actually do. the one worth reading is air ai, banned this march from marketing business opportunities after selling small businesses an ai phone agent at $25,000 to $100,000 upfront, with the complaint describing software that was glitchy or not consistently available and buyer losses reaching $250,000.
notice the structure, because it repeats far below the level that gets a press release. the capability lives in the demo and the deck, the money is due before anything runs, and the contract you sign describes a license to software rather than a job the software does. the cost is not only the check. it is the quarter you spent staffing around a capability that never arrived, and the credibility you spent internally telling everyone it would.
the fake protection is due diligence theater: asking the vendor whether the ai is real, sitting through a longer demo, reading a security whitepaper written by the same marketing team. do the version that holds: make them write into the contract the specific task the system performs without a human, pay monthly against it rather than upfront, and put in a thirty day exit if the task is not being performed.