
Organizations are investing aggressively in AI to automate IT operations, but most are overlooking the operational foundation required to deploy it safely and effectively. New research from Fleet Device Management found that while nearly half (46.5%) of enterprise IT leaders rank AI-driven automation as their top investment priority over the next 12–24 months, just 29.6% are prioritizing infrastructure as code (IaC), the version-controlled, auditable operating model that enables AI to make changes with governance, human review and rollback capabilities.
The findings, published in Fleet’s Road to AI in IT report, suggest that many organizations are pursuing AI outcomes before putting the underlying operational practices in place. As AI becomes increasingly responsible for endpoint management, remediation and routine IT tasks, that gap introduces unnecessary operational and security risk.
“While you can turn an AI agent loose, you probably shouldn’t,” said Allen Houchins, CIO at Fleet. “Software engineering didn’t embrace AI coding assistants until Git-based workflows provided the necessary guardrails. IT organizations need the same kind of machine-readable, version-controlled infrastructure before AI can safely manage endpoints, automate remediation and perform operational tasks. Without that foundation, organizations risk chasing AI outcomes without the governance, visibility and controls required to deploy them confidently.”
The research highlights how far many organizations still have to go. Only 13% of respondents describe their endpoint management as fully autonomous, while 87% continue to rely on manual or partially automated workflows. At the same time, IT leaders identified patching critical vulnerabilities quickly enough to keep pace with attackers as their biggest operational challenge over the next three years, followed by managing increasingly complex device environments, handling changes that cannot easily be rolled back and keeping pace with AI adoption.
Current operational realities reinforce those concerns. Nearly eight in 10 organizations require more than a day to deploy critical security patches, six in 10 lack complete visibility across their device fleets, and 59% take longer than 24 hours to fully provision a new employee device. Meanwhile, 87% rely on at least three endpoint management tools rather than a single unified platform, adding complexity to everyday IT operations.
The report also highlights the growing challenge of governing AI itself. The average enterprise now runs 14 AI applications, yet IT teams have visibility into only four of them, while 78% of employees use personal AI tools at work.
Fleet argues that infrastructure as code provides the operational framework needed to safely scale AI across enterprise IT by ensuring every change is reviewed, version-controlled and reversible.
“Infrastructure as code turns AI from a chatbot into a force multiplier for IT teams,” said Mike McNeil, CEO and co-founder of Fleet. “Because every change is reviewed, version-controlled and reversible, AI can automate routine operations without giving up human control and oversight.”
As organizations continue accelerating AI adoption, the report concludes that success will depend not just on deploying intelligent tools, but on modernizing the operational foundations that allow those tools to be governed safely, securely and at enterprise scale.
Join our LinkedIn group Information Security Community!











