TL;DR: Enterprise technology spending reached nearly $4 trillion in 2025, and Arxan Technologies’ analysis says the bigger story was execution strain: cloud, AI, modernization, and software investments multiplied faster than organisations could absorb them. The result is a governance problem for capacity, dependency management, and adaptive planning, not simply a budget problem.
NHIMG editorial — based on content published by Arxan Technologies: Two Tales of $4 Trillion: The Reality Behind 2025’s IT Spend
By the numbers:
- $4 trillion poured into cloud, o cloud, AI infrastructure, modernization programs, and enterprise software in 2025.
- AI infrastructure spending grew at a high rate of more than 35% year over year.
- Cloud spending grew at a moderate rate of about 19% to 21% year over year.
Questions worth separating out
Q: How should security teams govern access when transformation programmes change continuously?
A: They should treat access governance as a live control process, not a periodic review.
Q: Why do AI infrastructure programmes create new identity governance risk?
A: They create risk because machine-speed workflows can combine APIs, secrets, and delegated authority faster than conventional review cycles can observe.
Q: What are the signs that identity controls are falling behind transformation work?
A: Common signs include frequent manual access exceptions, delayed entitlement cleanup, inconsistent ownership of service accounts, and review findings that repeat across multiple projects.
Practitioner guidance
- Map identity controls to transformation milestones Tie entitlement reviews, privileged access approvals, and service-account recertification to migration waves, AI rollouts, and platform cutovers instead of quarterly calendars.
- Track machine identity growth as a programme risk Measure new service accounts, tokens, certificates, and delegated access paths created by each initiative, then assign ownership before the workflow goes live.
- Embed access cleanup into delivery pipelines Require offboarding, rotation, and entitlement pruning as part of project closure so temporary access does not survive after modernisation work ends.
What's in the full article
Arxan Technologies' full blog covers the operational detail this post intentionally leaves for the source:
- The article breaks down the five investment domains and the practical pressures behind each one, including AI infrastructure, cloud, enterprise software, modernization, and outsourcing.
- It expands the vision-versus-reality comparison with examples of where budget growth did not translate into usable capacity or stable operations.
- It outlines the adaptive planning model the vendor recommends for teams managing concurrent transformation programmes.
- It includes the source set and market-signal references the post only summarises at a higher level.
👉 Read Arxan Technologies' analysis of 2025 IT spend and execution strain →
$4 trillion in IT spend: what capacity gaps should teams fix?
Explore further
Execution capacity is becoming an identity control issue. When organisations scale AI, cloud, and modernization simultaneously, the practical failure is not just operational overload. It is that identity governance, especially for service accounts and privileged access, cannot absorb the pace of change. Programmes that treat access review as a periodic ceremony will miss the fact that entitlements are now moving inside live transformation streams. Practitioners should therefore treat change velocity as a control variable, not a business metric.
A question worth separating out:
Q: What should organisations prioritise first when security and delivery capacity are stretched?
A: They should prioritise control freshness for the highest-change areas, especially cloud, AI, and privileged access. The first goal is not perfect coverage, but reducing the time between environment change and access correction. That sequence limits drift while broader governance improvements catch up.
👉 Read our full editorial: Enterprise IT spend hit $4 trillion, but execution capacity lagged