IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
Forrester urges firms to prioritise practical AI governance

Forrester urges firms to prioritise practical AI governance

Thu, 17th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Forrester has published three analyses urging enterprises to focus on practical AI governance and resilience challenges, arguing that debate over advanced AI risks is diverging from the issues businesses face in daily operations.

The reports come as companies embed AI tools in software development, customer service, analytics, knowledge management and broader business operations. Many organisations, Forrester argued, are still wrestling with governance, security, spending controls, workforce readiness and proving return on investment.

One analysis said discussion of advanced AI safety has moved out of step with business needs. "The gap between frontier concerns and enterprise AI reality is jarring," Forrester said.

That assessment reflects a wider concern among enterprise technology buyers that public debate on AI often centres on existential or long-term risks, while internal teams are dealing with procurement, compliance, service reliability and oversight. Leaders should avoid being distracted by another cycle of AI alarmism and instead concentrate on the operational disciplines needed for adoption, the firm argued.

Outage risks

A second analysis examined recent simultaneous disruptions affecting ChatGPT, Claude and Grok, arguing that the incidents exposed how dependent organisations are becoming on a small, interconnected AI ecosystem.

Businesses now use AI systems in processes tied closely to revenue, service delivery and employee productivity. As a result, service interruptions can quickly escalate from an IT inconvenience into a broader operational problem.

Forrester framed the issue as one of continuity as much as technology management. "AI is increasingly becoming operational infrastructure, not just a productivity tool," it said.

The point is significant for executives weighing how far to integrate third-party AI models into core workflows. If companies rely on a handful of external providers for coding assistance, customer interactions or internal search, a model-level disruption can affect multiple departments at once.

That concentration risk is likely to sharpen questions around contingency planning, supplier diversification and governance. It also adds pressure on boards and senior management teams to treat AI dependencies much like other critical digital services.

Cost of trust

The third analysis focused on the economics of AI governance, warning that many business cases underestimate the spending needed to make AI systems dependable and properly supervised.

In Forrester's view, that cost extends beyond model access or software licences. It includes governance structures, security controls, staff training, monitoring and the human oversight needed to ensure systems operate within acceptable risk boundaries.

Forrester's security analysts said the internal debate should move on from whether AI works in principle to what enterprises must invest in to make it trustworthy.

The argument comes as many Chief Information Security Officers and other risk leaders try to quantify AI-related spending in more concrete terms. While enthusiasm for generative AI remains strong, finance and security teams increasingly want clearer accounting for the controls needed to support safe use at scale.

Taken together, the three analyses present a view of AI adoption that is less concerned with headline-grabbing scenarios and more focused on implementation. The message is that governance is not only about policy statements or regulatory positioning, but also about resilience, budgeting and organisational discipline.

That stance may resonate with large companies that have moved beyond pilot projects and are now integrating AI into routine operations. At that stage, the main questions often shift from experimentation to service availability, accountability and the total cost of maintaining trust.

It also suggests the AI market's next phase could be shaped by greater scrutiny of vendor concentration and internal readiness. Enterprises may still follow the wider debate on advanced AI risk, but day-to-day decisions are increasingly driven by the demands of continuity, compliance and measurable business value.

Forrester's view is that those practical demands should now take priority in executive discussions of AI strategy.