Fleet Tells Lets Data Science Why 7 in 10 Companies Aren't Ready for AI
Enterprises are pouring money into AI automation while skipping the one thing that makes it safe to run. Fleet Device Management's new Road to AI in IT survey of 500+ enterprise IT leaders finds 46.5% rank AI automation as their top investment while only 29.6% prioritize infrastructure as code, the version-controlled foundation that gives AI governance, review, and rollback. In written answers to Lets Data Science, Fleet CIO Allen Houchins explained what breaks first for those organizations (control), why shadow AI is now a $670,000-per-breach problem, and the exact order teams should follow before letting agents touch production, ending with a line worth framing: autonomy should be the outcome of operational maturity, not the starting point.
Every enterprise wants the finished AI outcome. Almost none of them, it turns out, have built the thing the outcome stands on.
That is the blunt takeaway from Fleet Device Management's Road to AI in IT report, released today after surveying more than 500 enterprise IT leaders. Nearly half rank AI-driven automation as their top investment priority for the next 12 to 24 months. Fewer than a third are prioritizing infrastructure as code, the version-controlled, auditable operating model that lets AI make changes with human review and a way back when something goes wrong.
After reviewing the report under embargo, Lets Data Science put five questions to Allen Houchins, Fleet's Chief Information Officer. His written answers, quoted throughout this story, read like a field guide to the gap between AI ambition and operational reality.
"The organizations funding AI without modernizing their underlying operating model are effectively adding speed to a system that still lacks steering and brakes," Houchins told Lets Data Science.
The numbers behind the gap
| Finding | Figure |
|---|---|
| Rank AI automation as their top IT investment | 46.5% |
| Prioritize infrastructure as code, the foundation for it | 29.6% |
| Still rely on manual or partially automated endpoint management | 87% |
| Take more than a day to deploy critical security patches | 79% |
| Lack complete visibility across their device fleet | 60% |
| AI apps per enterprise, versus the number IT can actually see | 14 vs 4 |
The shadow AI numbers carry a price tag. With 78% of employees using personal AI tools at work, the report cites IBM's Cost of a Data Breach research: breaches involving shadow AI cost an average of $670,000 more, lifting the typical loss from $3.96 million to $4.63 million.
What breaks first
We asked Houchins what actually fails over the next 12 months for organizations investing in AI without the foundation.
"Control breaks first," he said. "Organizations will introduce more AI-powered tools and automation, but their IT teams will struggle to understand what changed, who approved it and how to reverse it when something goes wrong. That leads to unsafe automation or AI pilots that never make it into production, as teams just can't trust them."
The existing problems compound from there: patching stays slow, configuration drift grows, and teams burn time managing exceptions across fragmented tooling. Per the report, 55% of organizations already juggle three or more endpoint management tools before any AI is added.
Why infrastructure as code is the prerequisite
Houchins' case for infrastructure as code is practical rather than ideological. "AI needs a structured, machine-readable environment in which to operate," he told Lets Data Science. "Traditional endpoint management often lives across dashboards, manual workflows and ticket queues that an AI agent cannot reliably interpret or modify."
Turning configurations and policies into version-controlled files gives every AI-proposed change a visible diff, a human approval step, a permanent audit record, and an immediate path back to the last known-good state. "Infrastructure as code lets AI move quickly but doesn't remove human accountability," he said.
A 30-day playbook for the shadow AI problem
For IT leaders staring at the 14-apps-visible-into-4 statistic, Houchins laid out a first month that starts with looking, not blocking:
- •Establish which AI tools are in use, on which devices, by whom, and with access to what company data
- •Identify duplication, unmanaged spend, and anything connected to sensitive systems
- •Classify tools by risk and stand up an approved set of AI services
- •Target the highest-risk activity first: personal accounts touching corporate data, and agents that can act inside production
"Simply blocking everything will usually drive usage further underground," he said. "The objective should be to replace invisible adoption with governed adoption."
Machine-speed attackers, ticket-queue defenses
The 79% patch-lag figure gets sharper once AI agents enter the picture. "Attackers and AI agents can discover, test and exploit weaknesses in hours, while most organizations are still responding on a timeline measured in days or weeks," Houchins said. A single poorly patched device stops being one exposed endpoint and becomes "a launch point into systems operating at machine speed," since a compromised agent may hold credentials across multiple applications.
His prescription: remediation should move "at the speed of a reviewed code change rather than a ticket queue."
The right order, according to Fleet
Asked what must come first and what can wait, Houchins gave a sequence: visibility first, a full inventory of devices, configurations, and vulnerabilities. Then consolidation, cutting tool sprawl and moving policies into version control. Then automation of the repeatable, lower-risk work. Only then agents, starting with recommendations and pull requests.
"Full autonomy can wait," he told Lets Data Science. "Autonomy should be the outcome of operational maturity, not the starting point."
Fleet CEO Mike McNeil, in the launch announcement, framed the payoff in plainer terms: infrastructure as code "turns AI from a chatbot into a force multiplier for IT teams," adding that "the people who deployed Claude, Codex and other AI tools can now actually use them."
The full survey data is in Fleet's Road to AI in IT report, and the launch release is on PR Newswire.
Key Points
- 1Fleet's survey of 500+ IT leaders finds 46.5% rank AI automation their top investment while only 29.6% prioritize infrastructure as code, the foundation that makes it governable.
- 2Fleet CIO Allen Houchins told Lets Data Science that control breaks first: teams lose track of what changed, who approved it, and how to reverse it.
- 3His 30-day shadow-AI playbook starts with visibility before enforcement, and his sequence ends bluntly: autonomy is the outcome of maturity, not the starting point.
Scoring Rationale
Survey of 500+ enterprise IT leaders on the AI-readiness gap, elevated by an exclusive written Q&A with Fleet's CIO provided directly to Lets Data Science; directly actionable for teams deploying AI in production environments.
Sources
Primary source and supporting public references used for this report.
Practice with real Ad Tech data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Ad Tech problems

