
There comes a point in August when even the most committed executive should be allowed to stop thinking about artificial intelligence, cyber risk, geopolitical volatility, agent orchestration and whether the latest enterprise software subscription really needs another £37 per user per month.
Unfortunately, we are not quite there yet.
Before switching on the out-of-office message, there is value in taking stock of where AI and business actually stand in mid-2026. Not where the conference keynote says we are going. Not where the vendor demonstration suggests we will be by next Thursday. And certainly not where somebody's suspiciously enthusiastic LinkedIn carousel says we already are.
The picture emerging from recent research is considerably more interesting. AI is becoming more capable, cheaper to deploy in some areas and increasingly autonomous. At the same time, its costs are becoming harder to predict, its cyberattack surface is expanding, boards are demanding clearer returns, and the competitive advantage is moving away from simply possessing AI towards integrating it intelligently into the organisation. The technology is advancing. The harder question is whether the business around it is advancing at the same speed. That is the subject worth considering before we all disappear somewhere sunny.
We have moved beyond “Do we need AI?”
One of the clearest signals comes from Gartner's 2026 CEO research.
Growth remains the dominant strategic priority, cited among the top three priorities by 52% of surveyed CEOs, while technology has risen to 36%. Gartner notes that the increase in technology prioritisation is being driven overwhelmingly by AI. More strikingly, 39% of CEOs surveyed in one wave already said they regard AI agents as employees. Respondents estimated that by 2030 an average of 19.9% of revenue could originate from AI agents or machine customers rather than human customers.
That is quite a leap from asking ChatGPT to improve an email.
Gartner describes the transition as the emergence of the “autonomous business”: an organisation in which AI does not merely assist employees but increasingly participates in operational processes, decisions, transactions and value creation. Importantly, Gartner argues that this transformation requires balance between machine autonomy and human autonomy rather than replacing one with the other. The important threshold then is not when AI becomes clever enough to write something useful. It is when AI gains permission to do something consequential.
Drafting a payment instruction is assistance. Sending the payment is agency.
Recommending a customer discount is assistance. Changing the price in the CRM is agency.
Finding a vulnerability is assistance. Deploying a remediation into production is agency.
Once you cross that boundary, governance is no longer an optional policy document lurking somewhere in SharePoint. It becomes architecture.
Agentic systems can continuously maintain information baselines, monitor indicators, test scenarios and challenge assumptions, while human practitioners retain responsibility for framing, interpretation and decision ownership. That is an excellent model for commercial organisations too. The objective should not be “maximum autonomy.”
It should be maximum useful autonomy within deliberate authority boundaries.
There is a difference.
And then there is cybersecurity
This is where the summer reading becomes noticeably less relaxing.
The 2026 Verizon Data Breach Investigations Report says ransomware featured in 48% of breaches in its dataset, up from 44%. Use of stolen credentials appeared in 36%, while exploitation of vulnerabilities doubled from 18% to 32%. Third-party involvement also reached 48% of breaches, representing a 60% increase over the previous dataset.
For smaller companies the picture deserves particular attention.
Verizon's analysis found that, among ransomware cases where company size was known, around 96% of victims were SMBs. Compromised credentials and exposed vulnerabilities were major contributors. Its separate 2026 Breach Impact Study suggests extreme cyber losses for SMBs can exceed 7% of annual revenue. Ransomware represented 39% of SMB claims in the dataset and business email compromise another 19%.
That is not an “IT issue”.
Seven percent of revenue has a habit of getting the CFO's attention.
CrowdStrike's ransomware survey adds another uncomfortable finding. Of 1,100 IT and cyber decision-makers surveyed, 78% said their organisation had experienced ransomware during the preceding year. Half of those attacked had considered themselves “very well prepared,” yet only 22% recovered within 24 hours.
This is a useful reminder of the difference between having controls and having resilience.
CrowdStrike also reports that 82% of respondents believe generative AI makes phishing harder to identify even for well-trained employees.
Attackers are gaining automation too.
CrowdStrike reports an 89% year-on-year increase in attacks by AI-enabled adversaries observed during 2025 and a 42% increase in zero-day vulnerabilities exploited before public disclosure. The report argues that AI is compressing the interval between vulnerability discovery and exploitation, which makes slow, periodic remediation increasingly inadequate.
The point is not that your encryption will be broken by lunchtime. It is that AI is beginning to accelerate highly specialised technical work.
That applies to defenders. It also applies to attackers.
Welcome to the productivity revolution.
AI agents also create their own attack surface
Traditional cyber controls were designed around users, applications, networks and endpoints. Now add autonomous software capable of accessing files, invoking tools, calling APIs, running commands, generating code and communicating with external systems. What could possibly go wrong?
Organisations first need visibility into which agents, LLM runtimes, development tools and AI applications are actually operating across the estate. Then you could start by controlling permissions, monitoring runtime activity, inspecting prompt interactions and extending protection across endpoint, browser, SaaS and cloud environments.
Whatever vendor technology you use, the architectural principle is sound. An AI inventory is becoming as necessary as a software or asset inventory. For each important agent, businesses should know:
If nobody can answer those questions, you do not have an AI agent.
You have an intern with the master password.
Humans are not the legacy component
AI's “two cost curves” provide an important warning against reducing AI strategy to technology economics.
One cost curve is obvious: licences, models, infrastructure, security, compute and integration. The second cost curve is human capability.
A company may automate work and reduce headcount, only to discover that it has also removed product knowledge, relationships, judgement, leadership capability and institutional memory. Gartner identifies precisely the same tension. CEOs want automation while simultaneously describing people as essential to resilience. Its research warns that enterprises cannot simply cut their way towards autonomous business and will need to preserve high-value human roles while automating transactional work. People frequently disengage because of poor management long before they formally leave a company. If businesses introduce AI badly, i.e. without context, development, psychological safety or clarity about changing roles. Then they may create the very capability loss they are hoping technology will solve.
There is an organisational-design lesson here.
Use AI to remove work that makes good people able to do the valuable things better or more of it.
Do not use AI in ways that make good people feel less valued.
Those are very different strategies.
And there is a marketing lesson too.
AI makes competent marketing content increasingly cheap, generic corporate communication becomes easier for everyone to produce. Human credibility, distinctive expertise, personality and trust therefore become more valuable. In other words, the same technology that lets you automate more of your communications may make it more important that customers occasionally encounter an actual human being.
That is wonderfully inconvenient.
So what should your AI stack look like when you return from holiday?
For most SMEs and mid-sized organisations, I would resist the urge to build a sprawling “AI ecosystem”.
Instead, build a controlled stack around seven layers:
Then add an eighth layer that is easy to forget:
People.
Someone still needs to decide what success means. AI is not a substitute for strategic thinkers but as a mechanism for keeping evidence, scenarios and indicators continuously updated so that humans can spend more time interpreting them. That is an attractive model for almost any leadership team. AI should reduce the amount of organisational energy spent gathering information and increase the amount available for making good decisions.
A final thought before the airport lounge
KPMG's recent analysis of the new UK government places AI alongside economic growth, energy security, geopolitics and cybersecurity. That framing feels right. Artificial intelligence is no longer an isolated technology trend. It intersects with productivity, energy, workforce design, supply chains, security, investment, customer experience and competitiveness. The businesses that gain most from it are unlikely to be those that accumulate the largest collection of AI licences. They will be the organisations that understand where AI belongs in the operating model; maintain trustworthy data; choose models intelligently; govern agents proportionately; protect the systems around them; measure financial value realistically; and retain the human judgement, leadership and authenticity that technology cannot conveniently manufacture.
So perhaps the useful question for the summer is not:
“What else can we do with AI?”
It is:
“Where can AI create measurable advantage in our business and what needs to be true for us to trust it there?”
Answer that well, and your AI stack becomes a growth capability.
Ignore it, and by Christmas you may simply have more licences, more agents, more dashboards, more cyber exposure and a finance team asking awkward questions.
On that cheerful note, enjoy the holiday.
Just remember to disable the agent that has permission to move money before boarding the plane.
I founded Velox Consilium to help small and medium-sized organisations turn their current confusion into clarity, and that clarity into practical, measurable results.