Key Takeaways
- Nearly half of enterprise IT leaders (46.5%) rank AI‑driven automation as their top investment priority for the next 12‑24 months.
- Only 29.6% prioritize infrastructure as code (IaC), the version‑controlled model that provides the governance needed for safe AI operations.
- A large gap exists between AI ambition and operational readiness, introducing security and compliance risk.
- Just 13% of respondents report fully autonomous endpoint management; 87% still rely on manual or partially automated workflows.
- Patching critical vulnerabilities quickly enough to keep pace with attackers is the biggest operational challenge identified for the next three years.
- Most organizations lack visibility across device fleets, need more than a day to deploy security patches, and take over 24 hours to provision a new employee device.
- Tool sprawl is common: 87% use at least three endpoint‑management platforms, increasing complexity.
- Enterprises run an average of 14 AI applications, yet IT teams have visibility into only four; 78% of employees use personal AI tools at work.
- Infrastructure as code provides the reviewable, reversible, and auditable foundation that lets AI act as a force multiplier without sacrificing human oversight.
The Surge in AI Investment for IT Automation
Enterprise IT leaders are aggressively allocating budget to artificial intelligence, viewing AI‑driven automation as a primary lever for improving efficiency and reducing manual toil. According to Fleet Device Management’s “Road to AI in IT” report, 46.5 % of surveyed leaders rank AI automation as their top investment priority over the next 12‑24 months. This enthusiasm reflects a broader industry trend where AI is expected to handle endpoint management, routine remediation, and other repetitive IT tasks at scale. However, the same survey reveals a stark disconnect: while the appetite for AI is high, the underlying operational practices that would enable safe, governed deployment lag far behind. Organizations risk investing in sophisticated AI capabilities without first establishing the controls necessary to trust those systems with critical infrastructure changes.
Infrastructure as Code: The Missing Foundation
Infrastructure as code (IaC) is the practice of managing IT infrastructure through machine‑readable definition files that are version‑controlled, auditable, and reversible—paralleling the way software engineers treat code. Despite its proven benefits, only 29.6 % of respondents prioritize IaC in their upcoming AI initiatives. This low adoption rate indicates that many enterprises are preparing to unleash AI agents onto their environments without the guardrails that IaC provides. As Allen Houchins, CIO at Fleet, notes, software engineering did not adopt AI coding assistants until Git‑based workflows delivered the needed review, rollback, and visibility mechanisms. IT teams require an analogous framework: every change proposed by AI must be subject to human review, recorded in a version‑controlled repository, and easily reversible if unintended consequences arise. Without IaC, AI operates as a black box that can drift from policy, introduce configuration drift, or create security holes that are difficult to trace or remediate.
Risks of Deploying AI Without Governance
When AI is empowered to make changes to endpoints, patch systems, or modify configurations without proper oversight, the potential for operational and security incidents grows exponentially. The report warns that pursuing AI outcomes before establishing IaC‑style governance introduces unnecessary risk. Unreviewed automation can inadvertently disable security controls, apply conflicting patches, or create inconsistencies across a heterogeneous device fleet. Moreover, the lack of an auditable trail hampers incident response and forensic analysis, making it difficult to determine why a system behaved unexpectedly or to demonstrate compliance during audits. In short, AI without governance is akin to giving a powerful tool to an untrained operator—capable of great good, but also prone to costly mistakes.
Current State of Endpoint Management and Operational Gaps
The research paints a picture of an IT landscape still heavily reliant on manual intervention. Only 13 % of respondents describe their endpoint management as fully autonomous, while a substantial 87 % continue to depend on manual or partially automated workflows. This reliance on human touchpoints slows response times, increases the likelihood of error, and limits the scalability that AI promises. The gap between aspiration and reality suggests that many organizations are attempting to overlay AI on top of legacy processes that were never designed for rapid, automated change. Until those processes are modernized—particularly by adopting IaC and unified management platforms—AI will struggle to deliver its full value without amplifying existing inefficiencies.
Patch Management and Vulnerability Response Challenges
When asked to identify their biggest operational challenge over the next three years, IT leaders ranked “patching critical vulnerabilities quickly enough to keep pace with attackers” at the top. The data underscores why: nearly eight in 10 organizations require more than a day to deploy critical security patches, and six in 10 lack complete visibility across their device fleets. Without real‑time insight into which devices are unpatched or vulnerable, IT teams cannot prioritize remediation effectively. Moreover, delayed patching widens the window of exposure, giving attackers more opportunity to exploit known flaws. The inability to act swiftly is not merely a technical shortfall; it is a symptom of fragmented tooling, inconsistent processes, and insufficient automation—issues that IaC and a unified platform could help resolve.
Complex Device Environments and Tool Sprawl
Modern enterprises manage a diverse array of endpoints—laptops, desktops, mobile devices, IoT gadgets, and virtual machines—each with its own management nuances. This complexity is compounded by tool sprawl: 87 % of organizations rely on at least three separate endpoint‑management platforms rather than a single unified solution. Managing multiple consoles increases operational overhead, creates gaps in policy enforcement, and makes it difficult to achieve a holistic view of the estate. When AI agents are introduced into such a fragmented environment, they must navigate disparate APIs, conflicting policies, and siloed data, which heightens the chance of misconfiguration or unintended side effects. Consolidating tooling under a cohesive, IaC‑driven framework would simplify AI integration and improve overall governance.
Governance of AI Applications and Shadow AI Usage
Beyond the infrastructure that supports AI, the report highlights a growing challenge in governing the AI applications themselves. The average enterprise now runs 14 distinct AI applications, yet IT teams have visibility into only four of them. This limited oversight means that a majority of AI workloads operate outside formal governance structures, increasing the risk of data leakage, model drift, or non‑compliant behavior. Adding to the concern, 78 % of employees report using personal AI tools at work—often unsanctioned “shadow AI” that bypasses corporate security controls. Without a centralized inventory, approval process, and monitoring capability, organizations cannot ensure that AI usage aligns with policy, regulatory requirements, or risk tolerances. IaC can help by codifying the desired state of AI deployments, enabling automated detection of drift and enforcing policy through version‑controlled pipelines.
How IaC Enables Safe, Scalable AI in IT
Infrastructure as code transforms AI from a potentially unpredictable chatbot into a reliable force multiplier for IT teams. By representing infrastructure as declarative, version‑controlled code, IaC guarantees that every proposed change—whether initiated by a human or an AI agent—is subject to peer review, automated testing, and audit logging. If an AI‑driven change produces an undesirable outcome, the system can roll back to a known‑good state simply by reverting the corresponding commit. This capability mirrors the safety nets that software developers rely on when using AI‑assisted coding tools. Furthermore, IaC facilitates consistent environments across development, staging, and production, reducing the “works on my machine” problem and enabling AI models to be trained and validated in settings that closely resemble production. In essence, IaC provides the governance, visibility, and reversibility that are prerequisites for trusting AI with critical IT operations.
Conclusion: Balancing Innovation with Operational Maturity
The enthusiasm for AI in IT is understandable and warranted; intelligent automation promises to relieve teams of repetitive toil, accelerate incident response, and free talent for higher‑value strategic work. However, the Fleet Device Management research makes clear that success hinges not merely on deploying sophisticated AI models but on modernizing the operational foundation that underpins them. Infrastructure as code offers the essential guardrails—reviewability, version control, and reversibility—that allow AI to act safely and at scale. Organizations that prioritize IaC alongside AI investment will be better positioned to close the visibility gap, reduce patch latency, simplify complex device environments, and govern both sanctioned and shadow AI usage. By aligning AI ambition with mature, automated IT practices, enterprises can reap the benefits of intelligent automation without sacrificing security, compliance, or operational confidence.