The State of AI Friction: Why Enterprise AI Deployment is Slower, Costlier, and More Limited Than Expected

Enterprise AI is not stalling for lack of ambition. Fewer than 2% of organizations have paused their AI projects over risk concerns, and 88% are raising agentic AI budgets by 10% or more. What is missing is a clean path from prototype to scaling in production. 

EMA's July 2026 research surveyed more than 150 IT and security leaders. 83% have had AI projects delayed by a security or compliance review, and among those delayed, two-thirds waited a month or longer. 82% have deployed AI agents to production in a diminished state, with restricted permissions or reduced autonomy, because of security concerns. 

The research ranks five structural sources of friction: security review, compliance and audit, sensitive data access, autonomy limits, and trust and risk. Together they add up to an "AI friction tax" paid in time lost, capability lost, and compliance overhead.

The paper explores why traditional approaches force a trade-off between data utility and data risk — restrict access and the model reasons on a diminished subset, open it up and the exposure is real — and outlines a path toward protection embedded in the AI workflow itself, so AI reaches production faster, more securely and at full capability.

The State of AI Friction, by Chris Steffen, VP of Research at EMA. Independent research, sponsored by Protegrity.