TL;DR: Enterprise AI often lifts individual productivity without changing enterprise outcomes, and Arxan Technologies cites McKinsey data showing only 39 percent of organisations see meaningful financial impact at the enterprise level. The missing ingredient is workflow-level context, because intelligence scattered across tools becomes intelligence debt instead of coordinated decision-making.
NHIMG editorial — based on content published by Arxan Technologies: The Real ROI of AI Starts Inside the Workflow Core
By the numbers:
- According to McKinsey’s State of AI 2025, only 39 percent of organisations are seeing meaningful financial impact at the enterprise level.
- According to ISG State of Enterprise AI Adoption 2025, 31 percent of enterprises have moved pilots into production, but only 25 percent are getting the return they expected.
- According to Gartner, 40 percent of enterprise applications will include task-specific AI agents by 2026, up from less than five percent today.
Questions worth separating out
Q: How should security teams govern AI-enabled workflows that can act on their own?
A: Treat them as identity-governed execution paths, not just software features.
Q: Why do local AI productivity gains often fail to produce enterprise ROI?
A: Local gains stop at the task level, while enterprise ROI depends on coordination across planning, sequencing, and delivery.
Q: What are the signs that AI is operating outside the workflow core?
A: Common signs include repeated manual handoffs, duplicated context gathering, inconsistent priorities across teams, and AI outputs that help individuals but do not change delivery outcomes.
Practitioner guidance
- Define the workflow core first Identify the planning, prioritisation, and delivery systems where enterprise decisions are actually made, then determine which AI functions belong inside those systems rather than around them.
- Map shared state and context boundaries Document which data elements an AI system must see to make a correct recommendation, and where context is intentionally withheld for privacy, segregation, or policy reasons.
- Treat AI permissions as process design Align access rights, approval paths, and human override points to the workflow step the agent supports, not to a generic user role model.
What's in the full article
Arxan Technologies' full article covers the operational detail this post intentionally leaves for the source:
- How Digital.ai Agility Sage is positioned inside planning and portfolio workflows rather than as a standalone assistant
- Examples of the specific planning, capacity, and dependency structures the vendor says Sage can interpret
- The article's explanation of how workflow placement is intended to improve alignment, not just individual productivity
- The vendor's own framing of where agentic AI fits within enterprise agility and delivery
👉 Read Arxan Technologies' analysis of agentic AI ROI inside the workflow core →
Agentic AI in the workflow core: what it means for ROI?
Explore further
Workflow context is the real control plane for enterprise AI. Local productivity gains do not create enterprise value if the system cannot see dependencies, priorities, and constraints together. That is why feature-level deployments stall at assistance and why embedded AI becomes the meaningful design choice. For identity and governance teams, the lesson is that decision context is part of the control surface, not a convenience layer.
A few things that frame the scale:
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
- 33% of organisations report their AI agents have accessed inappropriate or sensitive data beyond their intended scope.
A question worth separating out:
Q: How should security teams govern agentic AI that can execute IAM tasks?
A: Start by treating the agent as an NHI with bounded authority, explicit ownership, and revocation procedures. Require human approval for high-risk actions, log every decision path, and enforce least privilege at the workflow level. If the agent cannot be audited or rolled back, it is not yet ready for autonomous IAM execution.
👉 Read our full editorial: Agentic AI ROI depends on workflow-level decision context