The pilot is not the process
Consider the customer-service example. A pilot that summarizes chats and drafts replies from a knowledge base is a bounded task. Ask the same assistant to look up an order in the ERP, pull a full customer record from the CRM, decide whether a refund is allowed and write the result back to another system. Now it needs data access, permissions, business rules and working integrations.
This scenario is an illustration of the integration burden. It is not a finding from any of the surveys below. It does capture the pattern they describe: a model can be good enough, and the project can still stall because the business around it isn't ready.
Most organizations don't run on one tidy platform. Customer data sits in a CRM, finances in an ERP, inventory somewhere else, often in applications that have been running for years. An assistant that can't reach or safely act on those systems is limited to a clever sidebar.
Spending is racing ahead of scaling
Gartner's September 2026 forecast puts worldwide AI spending at $2.7 trillion for 2026, up 49.5% year over year. That is a spending forecast, not a measure of value delivered.
A separate Gartner survey ran from January to April 2026. It covered 1,303 respondents at organizations with at least $50 million in annual revenue. Only 22% said their organization had successfully scaled AI across multiple business units or adopted an AI-first approach. That figure bundles two descriptions, so it shouldn't be read as a measure of either one alone. The same survey found 85% of functional leaders planning to raise AI spending in 2026.
McKinsey's 2026 State of AI research adds a second gap. About 80% of respondents said AI improved their individual productivity. Only 37% reported a positive contribution to organizational EBIT. These are different measures, one personal and one financial, so they show a gap between employee-level gains and company-level results. They don't prove integration problems alone cause it.
The customer-service example fits that gap. If an agent saves a few minutes summarizing a call but still re-keys data between the CRM, billing and order systems, most of the process hasn't changed. That is analysis based on general industry knowledge, not a measured result.
What the GFT survey says about legacy systems
The most direct evidence comes from GFT Technologies. It commissioned Wakefield Research to survey 945 CIOs and CTOs in 19 countries, at companies with at least $500 million in annual revenue. The survey was fielded August 11-31, 2026.
Key results, as reported by GFT:
- 84% say limitations in their legacy systems have caused their organization to cancel an AI pilot or project.
- 93% believe failing to modernize before running AI on legacy infrastructure will eventually trigger an enterprise-wide security crisis.
- 95% said legacy technology had slowed their ability to use or scale AI, and 56% called that delay moderate or major.
- Only 20% say their organization's other C-suite executives and board members fully understand the security risks of running AI on legacy systems.
- 89% worry that global AI investment may be growing faster than the business value it can realistically deliver.
CIO Dive framed the headline result this way: more than 4 in 5 tech leaders had canceled at least one AI pilot because of legacy-system limitations.
How to read these numbers
- GFT sells modernization. It describes itself as an AI-centric digital transformation firm that modernizes technology architectures. A finding that legacy systems block AI is convenient for that business. That doesn't make it wrong, but the sponsorship matters.
- "84%" is about organizations, not projects. It means 84% of respondents said at least one pilot or project had been canceled. It does not mean 84% of AI projects fail.
- The 93% is a belief. It is an executive's prediction of a future security crisis, not a count of incidents.
- Legacy isn't the only cause. Budget, skills, data quality and unclear goals also derail AI work. CIO Dive noted that rising modernization costs and a lack of clear vision may also hold enterprises back.
- Sampling error applies. GFT's methodology note, in its Spanish-language release, gives a margin of error of 3.2 percentage points at 95% confidence globally.
Why agents raise the stakes
A tool that recaps a contract can stay fairly isolated. An agent that reviews the contract, flags a problem and starts the next step needs several things:
- Access to the relevant data.
- Permission to act on it.
- A reliable way to call the applications that control the process.
- Guardrails for exceptions and failures.
A pilot can run on curated data with a human watching. Production has to cope with messy records, access policies, ancient databases and the people who already own the process. An agent inherits the limits of every system it touches, so data access, integration, identity and security design become the real work. For Microsoft-centric shops, that points to the same unglamorous items admins already manage: permissions, data governance and connectors to line-of-business systems. This is general industry reasoning, not a claim from the surveys.
McKinsey's October 2026 piece, based on research with more than 700 executives and senior leaders, adds a related point. Companies furthest along in AI reinvention are more likely to organize cross-functional teams around end-to-end products, customer journeys and business processes. That supports the idea that workflow redesign matters as much as model choice. The detailed methods for that research weren't available in the material reviewed.
A practical readiness checklist
None of these steps comes from the surveys. They are common-sense questions to ask before an assistant is allowed to act:
- Map the process, not just the task. List every system a request touches from start to finish.
- Check data access. Can the assistant reach the records it needs, with least-privilege permissions, and nothing more?
- Define the action boundary. Decide what it may do alone, what needs human approval, and what is off limits.
- Test with ugly data. Include exceptions, duplicates, missing fields and conflicting records.
- Plan for rollback and logging. If an agent writes to a system of record, you need an audit trail and a way to undo it.
- Treat modernization as part of the AI budget. If the AI depends on a brittle system, the two projects are one project.
The partner-recognition angle
The source article closes with a note that Sonata Software received a 2026-2027 Microsoft AI Business Solutions Inner Circle recognition, its sixth. It also cites Microsoft Frontier Partner status and a Copilot-related partner program.
I couldn't verify the 2026-2027 award or the sixth-recognition count independently. What Sonata's own press release does confirm is a 2025-2026 Inner Circle award, announced September 23, 2025, which it called its fifth. That release says Inner Circle membership is based on outstanding sales achievements. A partner award is a sales and relationship milestone, not evidence that a given modernization approach works. Treat it as ecosystem context, not proof of technical results.
The bottom line
Gartner and McKinsey point to a gap between AI spending and enterprise-wide results. GFT's survey adds executive testimony that legacy systems are a significant brake. These are surveys and, in GFT's case, vendor-sponsored. They don't prove causation. But the pattern is consistent. The hard part of enterprise AI is increasingly everything around the model: the data, the permissions, the old applications and the processes people actually run.
If your organization is planning agents that act rather than just answer, the question isn't only which model to pick. Ask whether your systems can safely let it act.
References
- The biggest challenge in enterprise AI may have nothing to do with AI - 150sec 150sec · 2026-10-07T17:55:34+00:00
- Overdue modernization stokes security fears, wrecks AI plans ciodive.com
- New AI Research from GFT Technologies: 84% of CIOs Have Canceled an AI Project Over Legacy System Limits | Business Wire via.tt.se