Synthesis · top quartile of 269 publisher resources

What the evidence says executives should actually do about AI

Consultancies, hyperscalers and frontier labs publish AI playbooks faster than anyone can read them. Nobody has read them all. Read across 269 of them, 76% published in 2025–26, the disagreements are smaller than the noise suggests — as is the list of things that demonstrably work.

Updated August 2026 · newest source August 2026

00 — What changed

What’s new

Everything added to the index appears here automatically as it is added — this is a record, not a selection. Listed from Aug 13.

What changed

Aug 14new topicWhere the capability sitsOperating model redesign
Aug 14new topicWho owns itOperating model redesign
Aug 14new topicBuild, buy or partnerOperating model redesign
Aug 14new topicRoles & the shape of the workforceOperating model redesign
Aug 14new issueFear of falling behind is making the sourcing decisionOperating model redesign / Build, buy or partner
Aug 14new issueOne person is asked to be both advocate and guardianOperating model redesign / Who owns it
Aug 14Added2 sources from FinOps Foundation
Aug 14Added3 sources from NIST
Aug 14Added3 sources from AWS
Aug 14Added2 sources from Cloud Security Alliance

Newest by publication date

August 2026Agentic AI change leadershipMcKinsey & Company
August 2026Avoiding AI vendor lock-in riskBoston Consulting Group
August 2026Closing the CEO–board knowledge gapBoston Consulting Group
August 2026AI token cost accountingDeloitte
01 — The read

Four numbers that reframe the plan

If a transformation plan does not have an answer to each of these, it is not yet a plan.

02 — Where they agree

The consensus is broader than the marketing

Share of the 269 sources that substantively address each theme, and how many distinct publishers raise it. Measured across every document, not hand-picked.

Theme prevalence across 269 sources

How many of the 269 sources substantively discuss each theme. This measures the index rather than the industry: a short bar can mean the theme is under-sourced here, not that publishers are quiet about it.

03 — Moving the needle

What is measurably working

Findings with a number attached and a named source. Every one of these is a structural change, not a tool purchase.

Rebuilding a workflow end to end

>50%

In the early-adopter teams on one bank’s 400-component core modernization, time and effort fell by more than half, with people moved to supervising agent squads that document, write, review and integrate code. Reported by the consultancy from its own engagement.

McKinsey & Company · March 2025

Top-of-funnel commercial work

89%

Among 100 sales leaders whose organizations already run agentic AI, 89% report a positive effect on growth, 87% on rep productivity and 61% on lead conversion. The gains cluster in the earliest commercial steps — identifying which accounts to chase and in what order — while nurture further down scores mid-range. Adopters only, and self-reported.

Oliver Wyman

Writing the strategy down, and owning it

78%

35% of companies said they had an AI strategy in place, and 78% of those reported returns from generative AI (Google Cloud, 2024). Separately, organizations with someone owning AI at C-suite level report 10% higher return on AI spend — IBM counted equivalent roles as well as the formal title, so this is not evidence for creating a new seat.

Google Cloud · IBM · October 2024
04 — Not moving it

What is absorbing budget without returning it

The pattern is consistent: effort spent adding AI to the existing shape of the work, or waiting for the economics to fix themselves.

Copilots bolted onto processes nobody redesigned first

Grafting AI onto task flows that should first have been eliminated or consolidated makes low-value work faster and leaves the cost structure where it was. BCG rates the companies furthest along on AI maturity as reporting roughly three times the cost reduction of laggards — self-reported, and measured only inside the areas where AI is applied.

Boston Consulting Group · July 2026

Waiting for token prices to solve the economics

Total spend is set by how the system is built, not by the list price. Ungoverned retrieval and a default to frontier models are the two decisions that dominate the bill, and both are configuration rather than rebuild. The unit of management has changed.

BCG · Infosys · July 2026

Rolling the copilot wider instead of rebuilding the work

General-purpose assistants deploy fast and cheaply, and the time they save is real — but it lands a few minutes at a time across thousands of people, where no P&L line records it. The changes that show up in results are built into a single function’s process, and McKinsey estimates most of those are still short of production.

McKinsey & Company · March 2025

Managing token spend the way you manage cloud spend

FinOps exposes infrastructure cost well and is the right starting point — but a token bill moves with prompt length, retrieved context, model choice and how long an agent keeps going before it settles. The same spend belongs in three places at once: capital where it builds reusable capability, operating where it runs internal work, cost of goods where it sits inside the product.

Boston Consulting Group · July 2026
05 — Where it breaks

The four debts, and the failure modes nobody budgets for

Genpact and HFS put $18 trillion of recoverable value behind four interlocking debts. 85% of leaders say those debts actively limit AI value; over half have no funded plan to address them.

Data debt

33% of data is AI-ready

The gap between the data firms hold and what AI needs. Data quality failures delay, degrade or sink 42% of analytics and AI initiatives. Cited as the single biggest blocker.

Process debt

about 40% of the work week is manual

Workflows that are largely undocumented and hard to change — fewer than half are formally documented. Point an agent at one unaltered and it carries out the same flawed sequence, only faster and at scale.

Tech debt

42% of development-team time absorbed

Core enterprise systems run to about ten years old on average, and roughly two fifths of development-team time goes to maintaining the debt they carry rather than building anything new.

Talent debt

32% of workforce is AI-ready

The readiness gap that quietly compounds all three other debts — and the one whose cost never lands in a ledger of its own.

61% say their AI has already been compromised

Among 1,000 C-level executives, 61% say something in their AI estate — a model, its data, or the assets around it — was breached in the past year. In a separate survey of 300 security and IT professionals, only about a quarter are confident their organization can run a security strategy for AI; 21% say plainly that they are not, and half sit on the fence.

IBM with Palo Alto Networks · Cloud Security Alliance with Google Cloud

A trust failure has cost a fifth to a majority of market value

The range most often quoted for market capitalization lost after a serious breach of trust. Follow it back and it is older and broader than it looks: Deloitte relays it here from its own 2021 work on institutional trust, which in turn attributes it to earlier research. It predates generative AI and is not about AI at all — carried here because it is the order of magnitude an AI governance failure is being weighed against, not because anyone has measured that.

Deloitte, relaying its 2021 trust research · October 2024

Lock-in is becoming cognitive, not just technical

As the stack consolidates, dependence shifts from the platform to the reasoning layer that shapes how the organization thinks. Where the boundary sits around the company’s own IP, essential data and business rules is a chief-executive question, and not one to settle inside IT alone.

Boston Consulting Group · August 2026
06 — The economics

A cost line that has no owner yet

Token spend behaves nothing like a software licence. It scales with usage, it has no natural budget owner, and the crossover points that decide build-versus-rent arrive faster than most planning cycles.

Three-year total cost of ownership at scale

Deloitte’s modelled comparison at equivalent configuration and token volume: once demand is sustained, an owned AI factory is roughly 2.1× more cost-effective than metered API hosting over three years.

Metered API hostingOwned AI factory
API hosting
index 100
AI factory
index 48

The curve moves fast in both directions: Deloitte models a greater than 90% fall in cost per billion tokens between year one and year three for the owned path, against roughly 150% annual TCO growth as volume climbs. The decision is therefore about sustained demand, not today’s per-token price. Two architectural choices — how model calls are routed and how retrieval is governed — account for 78% of achievable savings, and programmes that put governance in before scaling spend 40–50% less.

07 — Where to focus

Seven moves, and who owns each

Ordered by how much the research agrees on them and how early they gate everything downstream.

  1. 01
    CEO / CFO

    Re-baseline the budget on 1:3:5

    McKinsey finds the transformations that work put three dollars into reshaping how the work runs, and five into teaching people to run it, for every one spent on the technology. Read as a budget test, a plan without that shape is not funded.

    McKinsey
  2. 02
    CFO / CIO

    Instrument token spend at workflow level before scaling

    Meter tokens per workflow, not per platform, before scaling. FinOps was built for infrastructure and does not price a loop an agent runs; the unit that matters is cost per useful outcome, with an owner on every material workflow.

    BCG · Infosys
  3. 03
    CEO / COO

    Rebuild a few workflows end to end instead of assisting twenty

    Both publishers argue the value sits in eliminating and reordering steps rather than adding assistants to them, and that spreading AI thinly is what produces diffuse benefit and no earnings impact. Pick where value is concentrated and rebuild the whole path.

    BCG · McKinsey
  4. 04
    CAIO / CISO

    Bound each agent before you widen it

    Anthropic’s security team screens every agentic use case on four axes: which of its inputs an attacker could write, which actions it can take and under whose identity, how far the damage reaches if it goes wrong, and whether its actions can be told apart from a person’s in your logs. Give it the least reach that still completes the work.

    Anthropic
  5. 05
    CDO

    Pay down data debt along the chosen workflows

    McKinsey finds readiness is the link between structured and unstructured data rather than a cleanup of either alone, and that governance has to reach the embedding and retrieval layer instead of stopping at the document. Genpact ranks data debt alongside process debt and finds the two are created by the same manual work. Sequencing the paydown behind the workflows you are rebuilding is our own recommendation.

    McKinsey · Genpact
  6. 06
    CEO / Board

    Close the board gap in person

    Frame what AI means for value creation yourself, run hands-on sessions, and consider a transformation committee of the more fluent directors rather than waiting for the full board to catch up.

    BCG
  7. 07
    CTO

    Preserve model liquidity

    A modular, layered stack with a security perimeter around proprietary knowledge lets you adopt better models as they arrive. Decide sovereignty deliberately rather than inheriting it from a vendor roadmap.

    Palantir · BCG