Key Takeaways
- Security and governance reviews are the main roadblocks: 82.9 % of enterprises say these processes delay AI projects from reaching production.
- Delays are costly and prolonged: Two‑thirds of affected organizations experience at‑least‑one‑month holdups, with nearly 30 % stuck four months or longer.
- AI is often deployed in a weakened state: 81.6 % of firms reduce agent autonomy or limit data access due to security concerns, diminishing the intended functionality.
- The “AI friction tax” captures hidden costs: Delayed rollouts, reduced capabilities, and extra governance overhead erode the return on AI investment.
- Autonomous AI outpaces supporting infrastructure: While ≈70 % of surveyed firms have agents capable of autonomous actions (e.g., writing to databases, calling APIs), only ≈20 % actually run highly autonomous systems in production.
- Embedding protection directly into AI workflows is favored: 91.5 % of respondents view AI‑ready data—achieved by weaving security into pipelines and agents—as very or extremely valuable for alleviating friction.
Research Initiative and Participants
Protegrity commissioned Enterprise Management Associates (EMA) to produce an independent study titled The State of AI Friction: Why Enterprise AI Deployment is Slower, Costlier, and More Limited Than Expected. The research surveyed IT and security leaders across a range of industries to quantify the obstacles that prevent AI pilots from maturing into production‑grade solutions. By capturing real‑world experiences, the report aims to illuminate the hidden costs and operational drag that organizations encounter when scaling AI beyond experimentation.
Defining AI Friction
The study introduces the concept of “AI friction” to describe the cumulative effect of security reviews, compliance procedures, sensitive‑data access restrictions, and trust concerns that impede AI deployment. Rather than stemming from insufficient AI spending or technical talent, friction arises from how enterprises safeguard data and manage risk when integrating intelligent agents into core business processes. This framing helps leaders pinpoint where governance becomes a bottleneck rather than an enabler.
Impact on Deployment Timelines
A striking 82.9 % of respondents reported that security or compliance reviews have delayed their AI initiatives from reaching production. This statistic underscores that the majority of enterprises encounter a formal gatekeeping step that adds time to the AI lifecycle. The delay is not occasional; it is a systemic pattern that affects nearly every organization attempting to move AI from proof‑of‑concept to operational use.
Extent of Delay Experienced
Among those facing delays, two‑thirds (66.7 %) experienced a stall of at least one month, while nearly 30 % endured holdups of four months or longer. Such prolonged hold‑times translate into missed market opportunities, increased labor costs, and frustration among business stakeholders who expect rapid value realization from AI investments. The length of these delays highlights the inadequacy of current review cycles for the speed at which AI models evolve.
Compromised AI Functionality
Security concerns do not only postpone deployment; they also force organizations to field AI in a diminished state. 81.6 % of surveyed companies admitted to reducing agent autonomy or restricting access to critical enterprise data to satisfy security reviews. This compromise curtails the AI’s ability to perform tasks such as autonomous data writes or API calls, thereby limiting the potential business impact and diluting the original use‑case vision.
Primary Sources of Friction
When asked to rank the biggest production bottlenecks, respondents placed security review at the top, followed by difficulty securing sensitive data, infrastructure costs, and audit/compliance requirements. These factors collectively create a layered obstacle course: each review step adds latency, while concerns about data exposure drive restrictive policies that further curb AI capabilities. The interplay of these elements explains why AI projects often stall despite strong technical readiness.
The AI Friction Tax Concept
The report coined the term “AI friction tax” to encapsulate the hidden expenses incurred because of these barriers. The tax manifests as delayed time‑to‑market, reduced AI functionality (lower autonomy or data access), and increased governance overhead—such as additional documentation, manual approvals, and continuous monitoring. Unlike a direct financial line item, this tax erodes ROI indirectly, widening the gap between AI spend and the tangible value delivered to the business.
Autonomous AI Capability Gap
A notable disparity emerged between AI ambition and supporting infrastructure: nearly 70 % of organizations possess agents capable of autonomous actions (e.g., writing to databases or triggering external APIs), yet only 19.7 % report deploying highly autonomous AI systems in production. This gap indicates that while the technology can act independently, the prevailing security and governance frameworks are not yet equipped to trust such agents at scale, forcing companies to dial back autonomy or keep agents sandboxed.
Need for Embedded Security and Governance
To overcome friction, the study advocates moving security and governance controls closer to the point of AI operation. Rather than relying on manual, periodic reviews designed for static IT environments, organizations should embed protection directly into AI workflows, pipelines, and agents. Techniques such as data‑centric encryption, tokenization, and policy‑as‑code enable real‑time safeguards that travel with the data, reducing reliance on gate‑keeping checkpoints that slow development.
Value of AI‑Ready Data Solutions
Reflecting this shift in mindset, 91.5 % of respondents indicated that having AI‑ready data—achieved by weaving security into the workflow without introducing roadblocks—would be very or extremely valuable. This overwhelming endorsement signals a market appetite for solutions that automate compliance, enforce least‑privilege access, and maintain audit trails transparently, thereby allowing AI agents to operate with full intended functionality while satisfying security mandates.
Recommendations for Reducing Friction
Based on the findings, enterprises should consider several actions: (1) adopt data‑centric security technologies that protect information irrespective of where it moves; (2) implement automated policy enforcement within CI/CD pipelines so that security checks become continuous rather than episodic; (3) establish clear governance frameworks that define acceptable AI behaviors and enable rapid, auditable approvals; and (4) invest in training for security teams to understand AI‑specific risk models, fostering collaboration rather than opposition between innovation and protection groups.
Conclusion and Outlook
The EMA‑Protegrity research makes clear that security, governance, and compliance have become the primary determinants of AI adoption speed. While AI investment continues to grow, the supporting infrastructure often lags, creating an “AI friction tax” that drains value through delays, compromised capabilities, and extra overhead. By shifting toward embedded, automated protection and aligning governance with AI’s operational tempo, organizations can mitigate this tax, unlock the full potential of autonomous agents, and realize the business outcomes they originally envisioned from their AI initiatives. As AI matures, those that successfully bridge the gap between innovation and risk management will be best positioned to lead in the next wave of intelligent enterprise transformation.

