AI is no longer waiting at the edge of the enterprise.
It is being implemented in workflows, incorporated into operating strategies and used daily by employees. In our 2026 research into how AI is changing work across Australia and New Zealand, 53% of organisations had progressed to implementing AI in workflows or embedding it in strategy, compared with only 13% a year earlier. Meanwhile, informal experimentation fell from 48% to 15%.
That is a significant shift in 12 months. It is not, however, proof of successful transformation.
As adoption accelerates, the harder questions become more important:
- Is AI improving the outcomes that matter?
- Are use cases supported by appropriate data, controls and accountability?
- Can the organisation identify where AI is creating value?
- Where is AI introducing cost, risk or complexity?
These concerns are increasingly visible across the technology industry. Gartner predicts that more than 40% of agentic AI projects will be cancelled by the end of 2027 due to escalating costs, unclear business value or inadequate risk controls.
The technology is advancing. The constraint is now execution.
Adoption is no longer the milestone
The rapid movement from experimentation into implementation suggests that organisations are no longer waiting for AI to mature before acting.
Twenty-nine percent of respondents now report that AI has been implemented in workflows, compared with 9% last year. A further 24% say it is embedded in organisational strategy, up from 4%.
As Jack Jorgensen, General Manager – Data, AI & Innovation at Avec, explains:
“There has been a significant shift in AI maturity over the past year, with ‘not started’ and informal experimentation dropping sharply while implementation in workflows and embedded strategy have grown. This suggests organisations are no longer just preparing for AI—they are actively rolling it out and working through what it takes to make it part of how the business operates.”
The distinction between deployment and operational maturity matters.
Providing access to an AI tool is deployment. Operational maturity requires approved use cases, reliable data, integration with existing processes, clear ownership, appropriate controls and a defined view of how the technology contributes to business performance.
Without those foundations, adoption can scale activity without scaling value.
Measure the outcome, not the AI
At an individual level, the productivity signal is strong. Eighty-five percent of respondents report some form of efficiency gain from AI, including 53% who say it has saved meaningful time.
At an organisational level, the evidence is less conclusive.
Only 8% say their organisation measures AI impact using clear metrics or KPIs. Another 13% measure it informally or inconsistently, leaving 79% without a robust approach to measurement. Among organisations assessing return on investment, only 18% say the value is clearly measurable, while around a third describe it as difficult to quantify.
Part of the difficulty comes from measuring the technology rather than the outcome.
Usage volumes, licence activation, prompt counts and time-saved estimates can provide operational signals. They do not necessarily establish whether AI has improved service quality, reduced risk, increased throughput or delivered a better commercial result.
As Jack puts it:
“Stop asking how much AI employees are using. Start asking whether the things the business already cared about are moving. The moment ROI becomes an adoption target, teams optimise for the metric, not the return. Leadership will then get a great chart and no measurable impact.”
Effective measurement starts before deployment. Organisations need a baseline for the outcome they intend to change and a clear way to determine whether AI has materially influenced it.
Depending on the use case, that could mean measuring cycle time, cost to serve, error rates, resolution times, customer outcomes or delivery capacity at an agreed quality threshold. Adoption metrics can help diagnose implementation. They should not become the definition of success.
AI governance must operate inside the workflow
The research also exposes a gap between documented governance and practical control.
Seventy-nine percent of respondents say their organisation’s AI rules are at least somewhat clear. Yet only 16% are very confident that employees understand what data is safe to enter into AI tools.
That uncertainty is already reflected in the risks organisations are observing. Fifty-seven percent identify entering confidential or client data as a leading risk behaviour. The same proportion are concerned about employees relying on AI outputs without checking them, while 47% flag decisions being made without human oversight.
A policy is necessary, but it is not an operating model.
Effective AI governance needs to define ownership at both enterprise and use-case level. It should establish approved data sources, acceptable use boundaries, escalation pathways, review requirements and controls proportionate to the consequences of failure.
This approach is consistent with recognised frameworks. The NIST AI Risk Management Framework organises AI risk activity around four connected functions: govern, map, measure and manage. ISO/IEC 42001 similarly treats responsible AI as a management system that must be established, implemented, maintained and continually improved, not as a one-off compliance exercise.
Australia’s updated policy for responsible AI use in government follows the same operational direction, requiring agencies to establish a strategic approach, designate accountability and apply risk-based actions to individual AI use cases.
The implication for enterprise leaders is clear: governance must be embedded into how AI is selected, configured, deployed and monitored.
Human oversight remains a production requirement
Improving model performance does not remove the need for human judgement.
Loss of human judgement was the most frequently identified concern in our research, selected by 21% of respondents. Almost half also believe organisations remain influenced by AI hype, while only 21% think expectations have become grounded in the technology’s actual capabilities and limitations.
This combination creates a material delivery risk. Organisations can become more confident in AI output at the same time as use cases become more consequential.
Human oversight should therefore be designed as a control, not added as a vague instruction to “check the output”. The required level of review should reflect the use case, the quality of the underlying data and the potential consequences of error.
A low-risk internal summary does not require the same assurance process as advice affecting a customer, employee, financial decision or regulated service. Both, however, need a clear owner accountable for the final outcome.
As Jack explains:
“Before AI, major technology investments were expected to be supported by a clear business case, evidence of value, an understanding of the risks and appropriate governance. Those standards should not disappear simply because AI is moving quickly or attracting significant attention.”
Speed does not reduce the need for rigour but increases it.
Value depends on the wider operating model
AI implementation is often framed as a technology program, but its value is determined by the wider system in which it operates.
Forty-four percent of organisations are responding to AI by upskilling existing employees. By comparison, only 22% are redesigning roles or workflows.
Capability building is essential, but training people to use AI within an unchanged process places a ceiling on the value it can create.
Organisations also need to examine how work moves between people and systems, where decisions sit, how exceptions are managed, and which controls should be automated or retained. Data architecture, security, workflow design, governance and workforce capability must evolve together.
Jack shares:
“Upskilling employees is essential, but training alone isn’t enough. Organisations need to build people’s capability while also adapting the processes, workflows and governance around them. New technology only delivers meaningful value when people, process and governance evolve alongside it.”
AI adoption has accelerated faster than many organisations’ ability to operationalise it. The next phase will not be defined by who deploys the most tools, but by who can connect the right use cases to measurable outcomes, reliable controls and accountable delivery.
Our full report examines how more than 1,500 business leaders and technology professionals across Australia and New Zealand are navigating that shift, from rapidly increasing adoption to the continuing gaps in measurement, governance and operational maturity.
.png)
