Lynn Greiner at CIO, September 23: worldwide AI spending will rise 49.5 percent in 2026 to $2.7 trillion, then 36.2 percent in 2027. John-David Lovelock, Gartner Distinguished VP Analyst, is the named voice. CIOs got net-new AI money in 2024 and a little in 2025. Now, he says, more of the spend is rebranding than diversion.
That is the sentence to keep. A laptop with an NPU is an AI laptop. A strategy offsite about AI is still an offsite. The invoice grew. The work graph may not have.
Agents and assistants, broken out from other software, are forecast up 77.3 percent. AI security spend almost doubles. Infrastructure 51.2 percent. Software 60.2 percent. Development platforms were raised from 28 percent growth in the May note to 39 percent now, because enterprises and vendors are building custom apps. Those are different shops. Do not average them in a steering committee.
We already wrote that agents are acting while the guardrail meeting is late and that the CIO job is where agents may write. This week is the budget appendix.
$2.7 trillion is not your cost center
Gartner updates IT spend quarterly. This cut is a worldwide roll-up. Your company is not in the $2.7 trillion as a line you can manage. You are in the rebrand Lovelock described. Existing projects pick up an AI sticker. New money still prefers the sticker.
By 2030, Lovelock says every dollar will be an AI dollar one way or another. Treat that as analyst theater with a useful warning: if your 2027 plan still has a non-AI column for “core systems,” finance will eventually relabel the column. Relabeling is not a platform.
He says hyperscalers have not diverted a dime from cloud. AWS, Google, Microsoft, Meta build at 2022-ish rates and run an AI buildout he calls the largest infrastructure project humanity has ever undertaken. You are not a hyperscaler. You are the customer who will be asked to fund both the cloud bill and the agent bill. Those can be the same invoice with a new SKU name.
Enterprise AI ROI already had a credibility problem. Futurum’s newer survey, in the SAP note below, puts expected and actual returns around 14 percent. If your board deck still says 5x because AT&T said 5x last month, you are quoting someone else’s platform.
Do not divert the ERP upgrade to fund a chatbot. Lovelock’s point is that diversion mostly did not happen at the macro layer. Inside a mid-size IT shop, diversion happens in the sprint board: three engineers off the data catalog and onto a Copilot plugin. That is the version you can stop.
If your CFO asks where the 49.5 percent is, the honest answer is “not here as a single check.” Show agents, security, and platforms as three rows. Security almost doubling is the row that should make the CISO a signer, not a slide.
77.3 percent is the write path
Agents and assistants growing faster than the rest of software is the tell. Chat that drafts is software. Chat that refunds a customer is an agent. The forecast does not split those. Your control policy has to.
If you only budget “AI software +60.2 percent,” you will buy seats. Seats are how you get 30 million Copilot logos and still have no write allow-list. Microsoft’s own retune, per CIO Dive on September 25, is a Copilot app with three tabs: Home for Word/Excel/PowerPoint tasking, Code on GitHub tech, Autopilot as a productivity assistant. Charging moves toward usage, not seats. They already reported more than 30 million Microsoft 365 Copilot paid seats in the Q4 2026 call in July, including customers above 50,000 seats.
Usage billing is a governance gift if you read the meter. It is a surprise if you do not. A department that lets Autopilot run overnight will not look like a seat count. It will look like a spike. Put a budget cap on the meter before the three tabs go default.
Gartner raised the development-platform forecast because custom apps are back. Custom apps are how you bypass the SaaS vendor’s agent and roll your own. They are also how you skip procurement’s vendor review. If platform growth is the 39 percent, the review queue needs an identity standard for internal agents, not just Salesforce’s.
Security spend almost doubling is not a product recommendation. It is an admission that the 77.3 percent line creates a new insider, which is the sentence Zscaler’s CISO already gave Fortune last week. Buy the control that can deny a write. Do not buy a dashboard that explains the write after it posts.
Capital One spent 14 years, not a quarter
CIO Dive on September 28 restates Richard Fairbank’s July earnings line: 14 years transforming the bank’s technology from the bottom of the stack up. Agentic systems sit on that. Chat Concierge, a multiagent car-buying flow, has been in production more than two years: dealer, test drive, digital purchase.
That timeline is the product. You cannot copy Concierge in a hack week. You can copy the boring sentence from their governance person: agentic and genAI apps should be managed, governed, secure, and standardized for regulatory needs and for a sane path to deploy. Banks talk like that because examiners exist. Your industry may not have examiners. Your customers still notice a wrong refund.
Internal plus external cases means they did not only ship a customer demo. Internal agents without a data platform are the 96 percent “poor data foundations” group from the Fortune survey we already cited. If you do not have 14 years, you still need a catalog and an identity before the second agent.
Do not announce an agentic strategy in the same quarter you start a lakehouse. Fairbank’s “way down that path” is the whole story. The path is the asset. The agent is a UI.
If a consultant shows up with Capital One in the slide, ask them which year of the 14 they are selling you. Year one is plumbing. Year 12 is Concierge. Most decks are year 12 screenshots on a year one invoice.
None of this is a stock view on COF. It is a sequencing rule. Platform, then agent, then customer write. Reverse that and you get a car-buying bot that hallucinates a rate.
SAP’s Atlanta patch is process, not a model
Keith Kirkpatrick at Futurum, dated September 24, covering SAP’s Transformation Excellence Summit in Atlanta on September 22: updates to Signavio, LeanIX, WalkMe, and Cloud ALM in the Business Transformation Management portfolio. The pitch is deploy, govern, monitor agents with process knowledge, ownership, risk, and adoption.
That is the unfashionable stack. Signavio is how a process actually runs. LeanIX is what systems you own. WalkMe is whether a human will click the thing. Cloud ALM is whether operations can see it. If your agent cannot name the process, it is a chatbot with API keys.
Futurum’s 2H 2026 Enterprise Software Decision Maker Survey, n=833 in August, found expected and actual returns on recent software purchases both around 14 percent. 41.5 percent said validated ROI studies would increase budget confidence. SAP is selling into that skepticism. You should too. Ask for the process ID the agent is allowed to touch. If the answer is “customer experience,” that is not an ID.
WalkMe in an agent conversation is a tell. Adoption tools exist because employees ignore the last automation. If you need WalkMe to make people use the agent, the agent is not saving the 14 percent. It is adding a coaching layer on a tool nobody asked for.
Cloud ALM monitoring is the part that belongs in the same sentence as Gartner’s security doubling. You cannot govern what you cannot see. If ALM is only for SAP-shaped workloads and your agents live in a copilot tab, you have two observability holes. Pick one system of record for agent actions. Then make SAP, Microsoft, and the bank-style internal bot all write to it.
Atlanta on September 22 was a product announcement. It is not your transformation. Your transformation is the list of processes you will not let an agent start.
Sovereignty is the other invoice
Martin De Saulles in CIO, September 28, puts open models 3.3 percent behind frontier on the 2026 Stanford HAI Index. Close enough that fine-tunes become a lock-in path if weights and training configs are not exportable.
Sovereignty is not a flag. It is whether you can leave. If 39 percent platform growth is custom apps on a hosted model, write the exit as a requirement: weights, prompts, eval sets, and traces leave with you. If the vendor says no, you are renting a personality.
Open models still need people who can fine-tune. De Saulles flags third-party help as a lock-in vector. Same rule. The contractor’s notebook is your IP or it is theirs. Put that in the SOW this week, not after the 49.5 percent lands in a renewal.
Regulated data in a frontier API is a different row from a copilot that summarizes your own mail. Split them. The $2.7 trillion will not.
If your board wants “AI sovereignty” as a 2027 theme, give them three tests: where inference runs, who owns the fine-tune, which law can subpoena the logs. Anything else is a white paper.
What to put on the Monday agenda
Three rows: agents (77.3 percent class), security (almost double), platforms (39 percent). Assign a human owner to each. The owner for agents is the person who can deny a write, not the person who booked the vendor.
Read the Copilot meter if you have 365 seats in the 30 million. Usage-based is coming even if your contract is still seats. Set a cap.
If someone cites Capital One, ask for the year on the path. If someone cites SAP Atlanta, ask for the process ID. If someone cites Gartner $2.7 trillion, ask which of the three rows they are requesting money for.
Rebrand the projects that already existed. Do not rebrand the data catalog as an agent and skip the catalog. Lovelock already told you the trick. The trick only works on an analyst chart. It does not work on a customer refund.
By 2030 every dollar may wear an AI sticker. Your job this quarter is to keep the sticker from writing to payroll, to the general ledger, and to anyone in a regulated file. The spend will show up anyway. The allow-list will not, unless you type it.