Insight · Advisory

96% Expect AI Returns. 42% Have Already Had an Incident.

Debt is not a moral failing. It is a timing choice — take the benefit now, pay for it later, usually with interest. Most mid-market AI estates are running on exactly that arrangement, and almost nobody is calling it what it is.

In June 2026, Netrio published a Censuswide survey of 401 U.S. IT leaders at companies with 200 to 5,000 employees. Two numbers from it belong on the same slide, and they almost never are: 82% said AI is already in production somewhere in the organization or in widespread use. Only 26% said AI is scaled and governed enterprise-wide.

That 56-point spread is the governance debt. It is not a technology gap — the technology is already deployed and working. It is the accumulated distance between what a company is running and what it can actually account for.

82% / 26%

82% of mid-market companies have AI in production or widespread use. 26% say it is scaled and governed enterprise-wide. 42% have a formal AI policy with actively enforced controls; 53% have full visibility into AI tool usage.

Netrio · Censuswide · 401 U.S. IT leaders, 200–5,000 employees · June 2026

How the debt accrues

No one decides to run ungoverned AI. It arrives the way most operational debt arrives — through a sequence of individually reasonable decisions.

Notice what is missing from that sequence: a bad decision. Every step was locally sensible. The failure is that no step in the chain triggered ownership, and by the time one does, the estate is already large enough that mapping it is a project rather than a conversation.

The four barriers are one barrier

Asked what was actually blocking them from scaling AI, the same 401 leaders ranked their obstacles: security, privacy and compliance (19%), data readiness (17%), integration complexity (16%), and lack of internal expertise (10%).

Read that list again in reverse. The three barriers that top it are not independent problems sitting alongside the fourth — they are what the fourth produces.

Security and compliance exposure is what happens when nobody senior is accountable for what tools are running and what data reaches them. Data readiness is not a spontaneous condition; data gets ready because someone with authority decides what "ready" means for a specific use case and sequences the work. Integration complexity is the accumulated cost of tools chosen one at a time by people who were not asked to consider the estate. Each of the top three is a downstream symptom of the bottom one.

Respondents ranked the cause fourth and its three symptoms first — and 52% of all named barriers are the same missing person.

52% → 10%

Security/privacy/compliance (19%), data readiness (17%) and integration complexity (16%) together account for 52% of named barriers to scaling AI. "Lack of internal expertise" — the condition that produces all three — was ranked last at 10%.

Netrio / Censuswide barrier rankings · ETHOSLINK analysis

You cannot buy your way out of a governance problem with more tooling. Tooling is what created it.

Confidence priced against experience

Here is the part that should give a CEO pause. In the same survey, 96% said they are confident their organization will realize measurable ROI from AI within 24 months. 88% expect to invest at least $100,000 over the next 12 to 24 months; 56% expect to invest at least $250,000.

So the market is 96% confident about a return it has not yet booked, while carrying a 42% realized-incident rate on the risk it has already taken. Those two numbers describe the same population. One is a forecast, the other is history — and the forecast is being made as if the history were not there.

It is worth setting that 96% next to what we know about pilot survival. As we covered in The AI ROI Gap, roughly 88% of AI agent pilots never reach production at all, and the minority that do return an average of around 171%. Near-universal confidence in a two-year return is difficult to reconcile with an industry pilot-mortality rate that high. The gap between those figures is not optimism. It is the absence of anyone whose job is to say which pilots are actually on track.

96% vs 42%

96% are confident of measurable AI ROI within 24 months. 42% have already had a confirmed AI security incident, and 31% more a near-miss. The same companies, the same year — one number a forecast, the other a fact.

Netrio · Censuswide · June 2026

What the missing person actually does

The instinct in most mid-market companies is to solve this by hiring a full-time AI leader, discovering the comp, and shelving it. That is the wrong shape of solution for a problem that is mostly decisions rather than hours. What the estate needs is someone senior enough to make binding calls — what runs, what stops, what data may touch what, which two pilots get resourced and which four get killed — for perhaps a day or two a week.

That is precisely the case for a fractional Chief AI Officer, and the reason we start engagements with a fixed-fee AI Opportunity Diagnostic rather than a build: at $9,500, the diagnostic costs under 10% of the $100,000 the survey's median respondent is about to spend, and its entire job is to establish what you are already running, what it touches, and which of it is worth scaling before that money moves. If you're weighing whether the timing is right, the six readiness signals are the shortest version of that test.


The mid-market did not lose the AI race. On the survey's own numbers it is ahead — 82% in production is not a laggard's figure. What it did was take the adoption benefit early and defer the accounting, which is a reasonable trade right up until the moment it isn't.

Debt gets repaid on a schedule you choose or a schedule chosen for you. Forty-two percent of this market has already discovered which one it was on. The remaining question for everyone else is whether the first complete inventory of what AI is running inside the company happens on a Tuesday with a diagnostic, or on a Saturday with a lawyer.

Frequently asked

Questions about mid-market AI governance

How many mid-market companies actually govern their AI?

In a June 2026 Censuswide survey of 401 U.S. IT leaders at companies with 200–5,000 employees, commissioned by Netrio, 82% said AI is already in production somewhere or in widespread use — but only 26% said it is scaled and governed enterprise-wide. 42% have a formal AI policy with actively enforced controls, and 53% have full visibility into AI tool usage.

How common are AI-related security incidents?

42% of surveyed mid-market IT leaders reported a confirmed AI-related security incident or exposure in the past twelve months, and a further 31% reported a near-miss — roughly 73% combined. Only 63% said they had formally assessed whether sensitive company or customer data is being entered into AI tools.

What is really blocking mid-market companies from scaling AI?

Respondents named security, privacy and compliance (19%), data readiness (17%), integration complexity (16%), and lack of internal expertise (10%). ETHOSLINK's reading is that the first three are downstream symptoms of the fourth: exposure, unready data and integration sprawl are all what happens when no one senior is accountable for the AI estate. 52% of named barriers trace back to the barrier ranked last.

Do we need a full-time Chief AI Officer?

Usually not at mid-market scale. The problem is a decision problem more than an hours problem — what runs, what stops, what data may touch what, which pilots get resourced. That needs someone senior enough to make binding calls a day or two a week, which is the fractional CAIO case. ETHOSLINK engagements begin with a $9,500 fixed-fee AI Opportunity Diagnostic — under 10% of the $100,000 most surveyed companies are about to spend — to establish what is already running and what is worth scaling before the money moves.


Can you list every AI tool running in your company right now?

If that list would take a week to assemble, that is the governance debt with a number on it. The $9,500 AI Opportunity Diagnostic produces the inventory, the risk map, and the two or three systems actually worth scaling.

Book a Discovery Call