Report: Enterprise AI Is Hitting a Security and Compliance Wall
- Jul 30
- 2 min read
Enterprise spending on artificial intelligence is accelerating, but many companies are discovering that building an AI system is easier than getting it approved for production.
A new report from Protegrity found that 82.9 percent of surveyed IT and security leaders said security or compliance reviews had delayed AI projects. Among organizations reporting delays, two-thirds experienced setbacks lasting at least one month, while nearly 30 percent waited four months or longer.
The research, based on an April survey of 152 technology and security executives and prepared for data security company Protegrity, describes the problem as an “AI friction tax.” Companies absorb that cost through delayed launches, restricted functionality and expanding governance overhead.
This is not evidence that enterprises have lost interest in generative AI or autonomous AI agents. More than half of respondents said their organizations were already scaling AI across departments or deploying agentic systems, while 88.1 percent planned to increase agentic AI budgets by at least 10 percent over the next year.
The bottleneck appears when prototypes need access to production data, external tools and business systems.
Security reviews were the most commonly cited production obstacle, followed by difficulty protecting sensitive training data, infrastructure expenses and audit requirements. These controls address legitimate risks, including data leakage, prompt injection, privilege escalation, manipulated tools and agent impersonation.
But the report suggests that traditional security processes are struggling to match the speed and architecture of AI development. Encryption at the storage layer and conventional data masking were designed primarily for predictable applications and human access patterns. Autonomous agents can instead query multiple systems, call APIs, modify databases and execute chained actions at machine speed.
As a result, companies are not simply launching AI products late. They are frequently shipping weaker versions of what developers originally designed.
About 43 percent of respondents said high-value AI agents were frequently deployed with reduced utility because of security concerns. Another 39 percent said this happened occasionally. Restrictions may include disabled tools, narrower permissions, manual approval checkpoints or reduced access to sensitive data.
That compromise threatens the economic case for enterprise AI. A project may be funded based on an agent capable of automating an entire workflow, but reach production as little more than an assistant that still requires human authorization at every important step.
Compliance is also becoming a direct operating expense. Nearly half of respondents identified reducing manual audit and compliance costs as the most important outcome they wanted from improved AI governance, ranking it above faster revenue generation.
The next phase of enterprise AI adoption may therefore depend less on larger models and more on whether security teams can embed protection into AI workflows without turning every deployment into a months-long approval process.


