Before You Put the Laptop in the Suitcase: What AI and Business Leaders Should Be Thinking About in Summer 2026

There comes a point in August when even the most committed executive should be allowed to stop thinking about artificial intelligence, cyber risk, geopolitical volatility, agent orchestration and whether the latest enterprise software subscription really needs another £37 per user per month.

Unfortunately, we are not quite there yet.

Before switching on the out-of-office message, there is value in taking stock of where AI and business actually stand in mid-2026. Not where the conference keynote says we are going. Not where the vendor demonstration suggests we will be by next Thursday. And certainly not where somebody's suspiciously enthusiastic LinkedIn carousel says we already are.

The picture emerging from recent research is considerably more interesting. AI is becoming more capable, cheaper to deploy in some areas and increasingly autonomous. At the same time, its costs are becoming harder to predict, its cyberattack surface is expanding, boards are demanding clearer returns, and the competitive advantage is moving away from simply possessing AI towards integrating it intelligently into the organisation. The technology is advancing. The harder question is whether the business around it is advancing at the same speed. That is the subject worth considering before we all disappear somewhere sunny.

We have moved beyond “Do we need AI?”

One of the clearest signals comes from Gartner's 2026 CEO research.

Growth remains the dominant strategic priority, cited among the top three priorities by 52% of surveyed CEOs, while technology has risen to 36%. Gartner notes that the increase in technology prioritisation is being driven overwhelmingly by AI. More strikingly, 39% of CEOs surveyed in one wave already said they regard AI agents as employees. Respondents estimated that by 2030 an average of 19.9% of revenue could originate from AI agents or machine customers rather than human customers.

That is quite a leap from asking ChatGPT to improve an email.

Gartner describes the transition as the emergence of the “autonomous business”: an organisation in which AI does not merely assist employees but increasingly participates in operational processes, decisions, transactions and value creation. Importantly, Gartner argues that this transformation requires balance between machine autonomy and human autonomy rather than replacing one with the other. The important threshold then is not when AI becomes clever enough to write something useful. It is when AI gains permission to do something consequential.

Drafting a payment instruction is assistance. Sending the payment is agency.

Recommending a customer discount is assistance. Changing the price in the CRM is agency.

Finding a vulnerability is assistance. Deploying a remediation into production is agency.

Once you cross that boundary, governance is no longer an optional policy document lurking somewhere in SharePoint. It becomes architecture.

Agentic systems can continuously maintain information baselines, monitor indicators, test scenarios and challenge assumptions, while human practitioners retain responsibility for framing, interpretation and decision ownership. That is an excellent model for commercial organisations too. The objective should not be “maximum autonomy.”

It should be maximum useful autonomy within deliberate authority boundaries.

There is a difference.

And then there is cybersecurity

This is where the summer reading becomes noticeably less relaxing.

The 2026 Verizon Data Breach Investigations Report says ransomware featured in 48% of breaches in its dataset, up from 44%. Use of stolen credentials appeared in 36%, while exploitation of vulnerabilities doubled from 18% to 32%. Third-party involvement also reached 48% of breaches, representing a 60% increase over the previous dataset.

For smaller companies the picture deserves particular attention.

Verizon's analysis found that, among ransomware cases where company size was known, around 96% of victims were SMBs. Compromised credentials and exposed vulnerabilities were major contributors. Its separate 2026 Breach Impact Study suggests extreme cyber losses for SMBs can exceed 7% of annual revenue. Ransomware represented 39% of SMB claims in the dataset and business email compromise another 19%.

That is not an “IT issue”.

Seven percent of revenue has a habit of getting the CFO's attention.

CrowdStrike's ransomware survey adds another uncomfortable finding. Of 1,100 IT and cyber decision-makers surveyed, 78% said their organisation had experienced ransomware during the preceding year. Half of those attacked had considered themselves “very well prepared,” yet only 22% recovered within 24 hours.

This is a useful reminder of the difference between having controls and having resilience.

CrowdStrike also reports that 82% of respondents believe generative AI makes phishing harder to identify even for well-trained employees.

Attackers are gaining automation too.

CrowdStrike reports an 89% year-on-year increase in attacks by AI-enabled adversaries observed during 2025 and a 42% increase in zero-day vulnerabilities exploited before public disclosure. The report argues that AI is compressing the interval between vulnerability discovery and exploitation, which makes slow, periodic remediation increasingly inadequate.

The point is not that your encryption will be broken by lunchtime. It is that AI is beginning to accelerate highly specialised technical work.

That applies to defenders. It also applies to attackers.

Welcome to the productivity revolution.

AI agents also create their own attack surface

Traditional cyber controls were designed around users, applications, networks and endpoints. Now add autonomous software capable of accessing files, invoking tools, calling APIs, running commands, generating code and communicating with external systems. What could possibly go wrong?

Organisations first need visibility into which agents, LLM runtimes, development tools and AI applications are actually operating across the estate. Then you could start by controlling permissions, monitoring runtime activity, inspecting prompt interactions and extending protection across endpoint, browser, SaaS and cloud environments.

Whatever vendor technology you use, the architectural principle is sound. An AI inventory is becoming as necessary as a software or asset inventory. For each important agent, businesses should know:

  • who owns it;
  • which models it calls;
  • which data it can read;
  • what it can write or change;
  • which systems and APIs it can invoke;
  • what credentials it holds;
  • which decisions require approval;
  • where its activity is logged;
  • what happens when it behaves unexpectedly;
  • and how quickly it can be disabled.

If nobody can answer those questions, you do not have an AI agent.

You have an intern with the master password.

Humans are not the legacy component

AI's “two cost curves” provide an important warning against reducing AI strategy to technology economics.

One cost curve is obvious: licences, models, infrastructure, security, compute and integration. The second cost curve is human capability.

A company may automate work and reduce headcount, only to discover that it has also removed product knowledge, relationships, judgement, leadership capability and institutional memory. Gartner identifies precisely the same tension. CEOs want automation while simultaneously describing people as essential to resilience. Its research warns that enterprises cannot simply cut their way towards autonomous business and will need to preserve high-value human roles while automating transactional work. People frequently disengage because of poor management long before they formally leave a company. If businesses introduce AI badly, i.e. without context, development, psychological safety or clarity about changing roles. Then they may create the very capability loss they are hoping technology will solve.

There is an organisational-design lesson here.

Use AI to remove work that makes good people able to do the valuable things better or more of it.

Do not use AI in ways that make good people feel less valued.

Those are very different strategies.

And there is a marketing lesson too.

AI makes competent marketing content increasingly cheap, generic corporate communication becomes easier for everyone to produce. Human credibility, distinctive expertise, personality and trust therefore become more valuable. In other words, the same technology that lets you automate more of your communications may make it more important that customers occasionally encounter an actual human being.

That is wonderfully inconvenient.

So what should your AI stack look like when you return from holiday?

For most SMEs and mid-sized organisations, I would resist the urge to build a sprawling “AI ecosystem”.

Instead, build a controlled stack around seven layers:

  1. Business outcomes. Choose a small number of growth, margin, customer or resilience problems worth solving.
  2. Trusted data. Improve the quality, ownership and accessibility of the information AI needs.
  3. Model choice and routing. Avoid unnecessary dependence on one model. Match capability and cost to the task.
  4. Workflow and agents. Integrate AI into processes rather than leaving it as an isolated chat window.
  5. Authority and governance. Separate recommendation from execution. Define where humans remain accountable.
  6. Security and observability. Inventory AI, restrict permissions, monitor activity and assume agents can become attack paths.
  7. Value measurement. Measure revenue, cost, cycle time, quality, conversion, customer experience or risk reduction—not merely prompts generated or hours “saved”.

Then add an eighth layer that is easy to forget:

People.

Someone still needs to decide what success means. AI is not a substitute for strategic thinkers but as a mechanism for keeping evidence, scenarios and indicators continuously updated so that humans can spend more time interpreting them. That is an attractive model for almost any leadership team. AI should reduce the amount of organisational energy spent gathering information and increase the amount available for making good decisions.

A final thought before the airport lounge

KPMG's recent analysis of the new UK government places AI alongside economic growth, energy security, geopolitics and cybersecurity. That framing feels right. Artificial intelligence is no longer an isolated technology trend. It intersects with productivity, energy, workforce design, supply chains, security, investment, customer experience and competitiveness. The businesses that gain most from it are unlikely to be those that accumulate the largest collection of AI licences. They will be the organisations that understand where AI belongs in the operating model; maintain trustworthy data; choose models intelligently; govern agents proportionately; protect the systems around them; measure financial value realistically; and retain the human judgement, leadership and authenticity that technology cannot conveniently manufacture.

So perhaps the useful question for the summer is not:

“What else can we do with AI?”

It is:

“Where can AI create measurable advantage in our business and what needs to be true for us to trust it there?”

Answer that well, and your AI stack becomes a growth capability.

Ignore it, and by Christmas you may simply have more licences, more agents, more dashboards, more cyber exposure and a finance team asking awkward questions.

On that cheerful note, enjoy the holiday.

Just remember to disable the agent that has permission to move money before boarding the plane.

Your AI stack needs to start with the business, not the model

The temptation remains to build AI strategies around products.

“Should we use Claude?”

“What about Gemini?”

“Are we standardising on Copilot?”

“Should we build agents?”

“Apparently everyone is using MCP now.”

These may be useful technology questions. They are terrible starting points for business strategy.

IT strategic-planning guidance starts somewhere much less glamorous: understand the organisation's objectives, assess the capability required to deliver them, allocate budgets against impact, determine how success will be measured and document the strategy clearly.

That sounds almost disappointingly sensible.

The same principle appears in Gartner's work on AI value. Its first-quarter 2026 research explicitly warns that time saved is not necessarily money saved. Seventy-four percent of CFOs surveyed reported productivity improvements from AI through time savings, but those minutes do not magically stroll into the P&L carrying suitcases of cash. To realise financial value, processes and operating models often need to be redesigned around the productivity gain.

Oracle NetSuite's paper Modeling AI ROI Like a CFO, Not a Vendor reinforces this. It argues that AI investment cases differ from conventional IT investment because adoption, output quality and benefits are uncertain. Its framework recommends probability-weighted cash flows, realistic adoption curves, allowance for benefit decay, explicit costing of failure, recognition of foundational investments and portfolio-level evaluation.

That should change how businesses build their AI stack.

Start with something like:

Business objective → workflow → data → AI capability → controls → measurement.

Not:

Interesting AI product → licences → enthusiastic pilot → six months later somebody asks Finance what it achieved.

The latter is not an AI strategy. It is an expensive hobby.

The model may become the least interesting part of the stack

Ramp's free LLM router offers a useful glimpse into where AI infrastructure may be heading.

Ramp has exposed technology capable of routing requests between different language models according to quality, cost and other criteria. The strategic significance is larger than the router itself. The real commercial opportunity here is having a control layer for AI expenditure. That matters because organisations are moving from “one user, one prompt” towards agentic workflows where a single business task can trigger dozens of model calls.

Model choice therefore becomes dynamic.

You may want the strongest available model for strategic reasoning, a smaller model for classification, another for code, an on-device model for sensitive tasks and perhaps no LLM at all for deterministic processes that can be handled more reliably with traditional software. New research into lookup-based architectures suggests that some AI workloads may eventually even be performed using radically less compute than conventional neural networks. They are not about to replace frontier LLMs, but they demonstrate an important principle:

AI efficiency may become as important as AI capability.

The best enterprise architecture is unlikely to be “send everything to the biggest model available.”

It will increasingly be:

use the smallest, cheapest and safest capability that reliably performs the task.

That is good engineering and it is also good finance. Conveniently it is also good sustainability.

Data quality remains the unglamorous superpower

We can give an AI agent a charming name, a carefully designed avatar and enough autonomy to book meetings, generate proposals and interrogate the ERP. If the underlying data is rubbish, we have merely created a very fast employee who is confidently wrong.

Oracle NetSuite's AI Insights You Can Act On makes this point particularly well. AI analyses the information available to it; it does not independently determine whether the chart of accounts is sensible, whether transactions are consistently categorised, whether historical data is complete or whether organisational changes have made previous classifications obsolete.

Inconsistent inputs can produce misleading analysis with considerable confidence. That observation applies far beyond finance.

If your CRM contains duplicate customers, incomplete opportunities and fictional close dates inserted because the Sales Director wanted the pipeline report to look cheerful, AI will not fix reality. It will automate your delusion.

So an effective growth-oriented AI stack requires a trusted data layer: clear ownership, consistent taxonomies, useful metadata, permissions, provenance, retention rules and mechanisms for validating critical information.

This does not make for exciting conference photography.

However, it does make AI useful.