AI adoption is accelerating at a pace that few organizations can keep up with in a structured way.
A recent finding from the Perforce 2026 State of DevOps Report makes this crystal clear: 70% of IT leaders worldwide confirm that solid DevOps practices directly contribute to successful AI adoption across the entire software development lifecycle.
Sounds encouraging, right?
But there is another side to this coin that deserves attention.
When a company’s DevOps foundations are still fragile or immature, AI does not fix the problem. It amplifies those problems, and it does so at machine speed. This is exactly where data governance enters the picture, a topic that spent far too long in the background of technology discussions but now sits at the center of the debate.
It is no exaggeration to say that, without well-structured governance, letting AI agents operate autonomously within an organization is like handing the car keys to someone who has not learned to drive yet, except on a high-speed highway.
The good news is that you can change this scenario with concrete steps and without shutting everything down. 🚀
What the Perforce report reveals about DevOps and AI
The Perforce 2026 State of DevOps Report is not just another market survey. It interviewed IT leaders across different industries and regions, and what emerged is a pretty honest picture of where companies stand today. The most striking conclusion is that mature DevOps practices act as a kind of rail that guides AI in the right direction. Without that rail, language models and autonomous agents simply operate in chaos, making decisions based on data that no one knows for sure where it came from, who validated it, or when it was last updated.
Another point the report highlights is that organizations with well-defined delivery pipelines, automated testing, and short feedback cycles can integrate AI tools much faster and with far fewer critical incidents. This is no coincidence. It is the direct result of a culture that already values transparency, traceability, and accountability at every stage of development. When you have those elements working well, adding AI to the process is a natural evolution. When you do not, it is a risky bet.
And the most concerning data point of all? A significant portion of the companies that reported adopting AI in the survey also admitted that their DevOps foundations are still in the consolidation phase. In other words, a lot of people are trying to run before they have learned to walk, and that has a real cost, whether in production failures, security gaps, or automated decisions that nobody can explain after the fact.
When AI agents go from assistants to decision-makers
There is an enormous difference between using AI to suggest code snippets and letting autonomous agents execute entire tasks without direct supervision. The first scenario is what most companies experience today: technology helps humans work faster. The second scenario is what is rapidly taking shape, and it is where risk shifts to a significantly higher level.
Imagine a developer arrives at work in the morning and discovers that overnight, an AI agent modified 12,000 lines of code, ran 10,000 tests, wrote 200 pages of documentation, and deployed 32 new features, with a million users already accessing those changes. That developer could barely do random spot-checks of what the AI did, let alone have a complete picture of everything that happened. This scenario is not science fiction. It is already knocking on the door of many engineering teams around the world.
When AI agents stop merely assisting and start acting on behalf of developers, the risk is no longer limited to poorly written code. It extends to bad data flowing through autonomous systems, feeding decisions without anyone having the chance to review what is happening. For organizations that already struggle with weak governance and DevOps processes, AI agents will magnify existing problems at a staggering speed.
Trust in AI outputs does not match audit capabilities
Here is one of the most revealing paradoxes the report brought to light. While 77% of organizations report confidence in AI-generated outputs, only 39% have fully automated audit trails. That means the vast majority of companies trust what AI delivers but lack the proper mechanisms to verify, track, and audit what was actually done.
This gap between trust and auditability is dangerous. It is like trusting an airplane’s autopilot without having access to the black box. While everything runs smoothly, nobody notices the problem. But when something goes wrong, the absence of complete and immutable records makes it nearly impossible to understand what happened, fix the error, and prevent it from happening again.
That is why putting processes and tools in place that make it safer to trust AI outputs is so important. This covers compliance, security, transparency, auditability, and traceability. And this structure needs to be built now, not after autonomous agents are already operating at full scale.
Data governance: the foundation no one can afford to ignore
Data governance is, in practice, the set of policies, processes, and responsibilities that define how an organization’s data is collected, stored, accessed, shared, and disposed of. It sounds bureaucratic when described that way, but in the context of AI, it becomes something much more tangible and urgent. An AI model is only as good as the data it was trained and fed with. If that data is inconsistent, outdated, biased, or simply poorly cataloged, the model will reproduce those problems at scale, at speed, and without asking permission.
Within modern DevOps practices, data governance is starting to be treated as a discipline integrated into the software lifecycle, not as a separate step that only happens when legal or compliance teams come knocking. This means engineering teams need to think about cataloging, data lineage, and access control from the moment a feature starts being designed. It also means data teams and product teams need to speak the same language, something that has historically been one of the biggest bottlenecks in organizations.
Transparency is another fundamental pillar here. Good data governance does not just protect the company from legal or regulatory risks. It creates an environment where all stakeholders, from the engineering team to the executive board, can understand where the decisions made by AI came from, which data it operated on, and what criteria were used. This is what specialists call explainability, and without it, trust in the system simply does not hold up over time. 🔍
Going back to basics is not going backward
It might seem contradictory to talk about going back to basics at a time when everyone wants to move as fast as possible with AI. But this is precisely the most sensible recommendation for anyone leading technology teams today. Reviewing the maturity of existing DevOps foundations or agile methodologies and prioritizing the reinforcement or adoption of best practices should not be seen as a setback. It is, in fact, the fundamental work needed to prevent weak security, inconsistent data governance, or other broken processes from becoming ticking time bombs when AI agents go into action at scale.
This foundational effort needs to happen now, not as an afterthought following the widespread implementation of AI agents. When that tipping point of scale arrives, mitigating the problems can become difficult or even impossible. Governance needs to be at the heart of this DevOps maturity review, especially for companies operating in highly regulated industries. The ability to build trust in AI through full transparency, auditability, traceability, and guardrails will become a real competitive differentiator for organizations that want to keep innovating without compromising operational security.
Security and transparency go hand in hand
One of the biggest mistakes organizations make when talking about security in the context of AI is treating the topic as if it were exclusively a cybersecurity issue, firewalls, encryption, and access control. These elements are essential, of course, but security in the AI era has an additional dimension that goes beyond technical protection. It includes ensuring that models are not operating on sensitive data without proper consent, that AI-generated outputs can be audited and challenged, and that a clear process exists for correcting errors when they occur, because they will occur.
Responsible AI adoption requires security teams to be involved from the very start of the system design process, not called in only when something goes wrong. This is a principle that came directly from DevOps culture, where the concept of shift left is already well established: catching problems early so they are resolved before they reach production. In the context of AI, this same principle applies to both technical security and ethical and regulatory security, especially as frameworks like the European AI Act begin to gain traction and global influence.
Transparency also plays a direct role in security. When processes are visible, when logs are properly maintained, and when automated decisions can be traced, it becomes much easier to identify anomalous behavior, whether it is an external attack attempt or a bias in the model that nobody noticed during training. Organizations that invest in operational transparency end up creating, almost as a positive side effect, an additional layer of protection against a range of risks that do not always show up on the radar of traditional security teams. 🛡️
Seven practical steps to improve governance
Talking about governance in general terms is easy. The hard part is translating it into concrete actions. Fortunately, there are starting points that organizations of different sizes and maturity levels can apply. Here they are:
Maintain good data hygiene
Cleaning data is a practice accepted virtually everywhere, but many organizations fall into the trap of treating it as a one-and-done task. The truth is that data will not stay clean. It changes, grows, and transforms continuously. That is why the most important thing is not cleaning the data itself, but fixing the processes that generate that data. Identify the specific data flows that support business decisions and apply the appropriate governance controls. And one critical point: make sure AI never accesses real customer data or other sensitive information. Techniques like data masking allow you to work with realistic information without ever exposing actual data.
Ensure solid testing frameworks
Establish robust unit, functional, and performance tests. Make sure the right policies are defined and enforced, including compliance requirements, whether internal or mandated by the industry the company operates in. Without reliable tests, any AI-generated output is vulnerable to errors that can propagate silently through the chain.
Eliminate bottlenecks
Work to get CI/CD pipelines running end-to-end smoothly, minimizing the need for human intervention to trigger processes. Automate as much as possible, but always ensuring that the appropriate security measures are active for each AI system involved.
Make security and compliance checks easy
For now, many processes still require a human in the loop, but those steps need to be as simple as possible. Give users everything they need to make a clear yes-or-no decision, instead of requiring them to dig through reports, log into multiple systems, and interpret findings on their own. Use AI itself to summarize the picture: I ran these checks, everything passed, and here is my verdict.
Track absolutely everything
We are rapidly heading toward a world where conversations with AI become part of the intent behind software development. These interactions need to be captured. Soon, it will be essential to maintain a single source of immutable truth, with write-once, read-only records that neither humans nor AI agents can alter after they have been logged.
Contain AI agents
Place AI agents in sandboxes or containers, ensuring they only have access to the data and tools they actually need. Prevent them from modifying information that must remain immutable, such as audit records. This containment is one of the most effective layers of protection against unexpected behavior from autonomous systems.
Start in stages and build from there
Put the basic framework in place first, then add accelerators on top as the organization advances through AI maturity levels. Levels one and two are human-driven, following human intent with reviews conducted by people. Levels three and four are where AI becomes multi-agent autonomous at scale, with proactive and self-improving systems that require minimal human involvement, only to guide high-level intent. None of this happens overnight, especially in mission-critical or high-security environments where humans still need to be heavily involved. 📊
How to move forward in practice without stalling operations
The question that comes up most when this topic reaches leadership meetings is: where do we start, without stopping what is already working? The honest answer is that there is no single path, but there are a few moves that tend to deliver faster results with less friction. The first is conducting a real inventory of the data the organization already has, not just listing it, but understanding its origin, quality, update frequency, and who is responsible for each dataset. This exercise alone usually reveals gaps that nobody knew existed.
The second move is connecting data teams with development teams in a structured way, with rituals, shared documentation, and clear quality criteria. Within more mature DevOps practices, this already happens naturally, but in companies that are still building this culture, it may be necessary to create formal bridges before creating automations. A poorly documented data pipeline is just as dangerous as a code pipeline without tests, and the two together, in AI systems, can be disastrous.
Even in highly regulated or mission-critical environments, the adoption of AI agents will accelerate rapidly and push companies toward higher maturity levels. That is why starting to build or reinforce these foundations now is so important, using DevOps practices, which are ultimately the established common sense of the software development lifecycle, as a guide to achieving competitive innovation at speed while always prioritizing strong governance.
Finally, it is worth remembering that data governance does not need to be a two-year project before it starts generating value. Small initiatives, like creating a shared data dictionary, defining who approves changes to critical datasets, or setting up automated alerts for anomalies in ingestion pipelines, already represent real progress. AI adoption with security and responsibility is an incremental journey, and the organizations that go the farthest are exactly the ones that did not wait for everything to be perfect before taking the first step. 💡
