IT has surrendered: why 56 % of IT leaders can’t explain GenAI, and what that means for governance
Three paradigm shifts hit the IT organisation in under a decade. Nobody updated the governance model for any of them.
According to a 2026 Gartner study, 56 % of IT leaders admit they cannot explain the output of their GenAI systems.
The number is alarming. It is not surprising.
Because, honestly: many IT departments could not explain the cloud either. At least not in the language boards, auditors and works councils need.
What we are watching is not a failure of IT. It is the result of three tectonic shifts that arrived without a pause, and for which nobody updated the governance model.
Wave one: the cloud, or loss of control as a service
For decades the IT department owned its infrastructure. Servers in the basement, data on its own disks, updates on its own schedule. The world was deterministic, auditable, governable.
Then came the cloud.
On paper an efficiency gain. In reality a break in paradigm. Control over hardware, handed over. Control over patch cycles, handed over. Control over the physical location of data, handed over.
Plenty of large enterprises managed that transition professionally. Mid-sized industry, honestly, did not always finish it. Hybrid landscapes, unclear ownership, shadow IT growing in cloud tenants nobody ever consolidated.
And before that construction site was closed, the next wave arrived.
Wave two: data sovereignty, the question nobody asks out loud
The cloud runs. On whose infrastructure?
AWS, Azure, Google Cloud. Three American hyperscalers dominate the European market. That is no secret, and the strategic implications are discussed remarkably rarely.
The questions are on the table.
- Where does the data physically sit? And is a European region genuinely as sovereign as it sounds when the operator falls under the US CLOUD Act?
- Who has access? Not theoretically, per contract, but in practice, when an American authority knocks?
- What happens after a change of government? Recent years taught European IT that transatlantic data agreements are more fragile than anyone would like.
The uncomfortable answer: there is currently no European cloud alternative at the production quality and scale needed to run an S/4HANA landscape or an industrial IoT backend reliably. GAIA-X is a political signal, not an operational product.
Which leaves the IT department with an unsolvable brief: guarantee data sovereignty, on infrastructure it does not own, does not control, and whose legal frame can change at any time.
Then came the third wave.
Wave three: GenAI and the EU AI Act, compliance for the unexplainable
Generative AI breaks the last foundation classical IT governance stands on: the assumption of determinism.
An ERP system is deterministic. Same input, same output. Always. That assumption is the basis of every audit, every SOX control, every IATF 16949 certification.
GenAI is probabilistic. Same input, different output. That is not a bug, it is the operating principle. And it breaks every governance model built on traceability and reproducibility.
At the same time the EU AI Act takes effect. It requires:
- risk classification of the AI systems in use
- transparency obligations towards users and supervisory authorities
- documentation of the decision logic
Sensible in principle. In practice the question becomes: how do you document the decision logic of a system that has no deterministic logic? How do you explain to an auditor why the model recommended this supplier and not another one, when the honest answer is that on this run the probability distribution came out that way?
The AI Act sets guardrails. The tooling to implement those guardrails in industrial daily operations barely exists. Not as a prototype, but as a production-ready solution with ERP integration, an audit trail and an approval workflow.
The diagnosis: three waves, no governance
Step back for a moment.
In less than a decade, the IT department faced three fundamental shifts:
- Cloud: loss of control over infrastructure.
- Hyperscaler dominance: loss of sovereignty over data.
- GenAI: loss of explanation over results.
Each one alone would have required a new governance model. IT received none of them. Every wave was stacked onto the existing model, a model designed for on-premise systems in a data centre down the road.
No wonder 56 % have surrendered.
In regulated industries, automotive, pharmaceuticals, aerospace, that governance vacuum is not a blemish. It kills audits. If nobody can explain why the model gave a particular recommendation, who is liable? The CTO? The business unit? The vendor?
What is needed: adult supervision
The answer is not to send IT departments through AI bootcamps. The answer is a different understanding of who owns generative AI.
GenAI governance is not an IT task. It is a leadership task.
A CTO does not need a whitepaper on transformer architectures. A CTO needs a decision framework:
- Where may the model act autonomously? Summarising meeting notes, for instance.
- Where does it need human release? Supplier recommendations in sourcing.
- Where is it forbidden outright? Safety-critical process decisions in production.
That is what adult supervision means. Not hostility towards technology. Not braking for its own sake. A strategic decision about where the machine may run, and where an experienced person with process knowledge keeps a hand on the wheel.
To stay with the image: you do not have to build engines to know when to brake. You do have to know that the engine under the bonnet no longer runs deterministically, and that this has consequences.
The real question
It is not why IT cannot explain GenAI.
It is: who in your company is accountable for decisions no human can fully retrace?
If the answer is silence, the problem is not in IT.
#AI #GenAI #Governance #Sovereignty
Sven Vollmer
The Industrial Translator. Building bridges between the operational reality of industry, SAP and supply chain, and what generative AI actually delivers today. The focus is on applications that create value, not on the hype.