From Pilots to Operations: A Field Study of AI Maturity, Governance, and the Evolving CIO Role
Insights From a Descriptive Field Survey at the MIT Sloan CIO Symposium 2026 and a CIO Insight Session at the Harvard Club Boston – Supplemented by Survey Results From Europe
By Dr. Tamara Leuthe (Senior Researcher), Sonny (Sönke) Claussen (CEO, Bee360)
Executive Summary
Organizations across industries have committed to AI — yet the transition from discrete pilots to embedded operational capability has proven elusive for the vast majority. This report presents the findings of a descriptive field survey conducted at the MIT Sloan CIO Symposium 2026 (May 18–19, Cambridge MA) and a CIO Insight Session held at the Harvard Club Boston on May 20, 2026.
Together, these two events produced both structured practitioner data and rich qualitative evidence on the central question: What does it actually take to make AI a core operational capability — not just a portfolio of pilots?
The field survey was conducted with 20 CIO-level technology leaders using four closed questions grounded in published frameworks (Westerman & Webster, 2025; Schrage & Kiron, 2024, 2025a, 2025b; McAfee, 2025). The following day, five CIOs convened in a two-hour facilitated roundtable to translate these findings into organizational reality under Chatham House Rules. The instrument captures AI maturity, the primary barrier to operationalization, current AI governance posture, and how the CIO role is evolving.
To extend the geographic scope of the study, the survey instrument was subsequently distributed through the Bee360 Community Network to CIO-level technology leaders in Europe. A total of 25 European respondents completed the online survey between May 26 and June 4, 2026. This European dataset spans a broader industry mix than the MIT Symposium sample and is predominantly composed of medium-sized IT organizations. The findings from the European group are reported alongside the field study results in Chapter 3, and a concluding cross-dataset comparison is provided in Chapter 5.
Key Findings
Twenty CIO-level respondents at a leading global CIO forum validated four core findings:
- AI is already changing how people work but it is not yet embedded at scale. 45% of respondents report that AI is changing how specific roles and teams work, with human oversight in place. 30% have reached operational embedding with governance. Notably, not a single respondent reported no AI adoption at all.
- The biggest barrier is organisational, not technological. 40% of respondents identify adding AI to existing processes without redesigning the work itself as the primary barrier. Data infrastructure (15%) and financial demonstrability (10%) lag far behind. The challenge is a workflow redesign and change management problem.
- Governance is reactive or absent. 50% of respondents operate with reactive guardrails (compliance-driven policies designed to prevent misuse). 35% have no AI governance structure at all. Only 15% have reached governance as architecture — the deliberate design of decision rights and accountability that Schrage and Kiron (2025) identify as the condition for AI to genuinely transform organisational decision-making. Zero respondents experienced governance as a bottleneck.
- The CIO role has fundamentally changed toward directive emergence. 55% of respondents describe their role as directive emergence — setting a direction for AI and continuously adapting as circumstances evolve, rather than executing fixed plans (Westerman, 2025). The result is highly concentrated: this is the dominant orientation across all maturity levels above individual use.
The comparison between the European and the MIT Sloan CIO Symposium data set shows:
- European CIOs lag behind on AI maturity but converge on the same primary barrier. 44% of respondents report AI use at the individual level with no coordinated organizational approach and only 4% of European respondents have reached operational embedding AI with governance. Both respondent groups identified the same primary barrier: adding AI to existing processes without redesigning the work itself (32%), confirming that the biggest challenge is organizational, not technological, across both geographies.
- Reactive governance dominates more strongly in Europe, and the CIO role is more evenly distributed. 60% of respondents describe their governance posture as reactive guardrails and 12% report that governance actively slows down AI initiatives, a dynamic entirely absent in the sample of the MIT Sloan CIO Symposium participants. On the changing CIO role, the results show a more dispersed distribution, indicating that no single leadership orientation has consolidated in European organizations at this stage of AI adoption.
Recommended Actions for CIOs
The CIO Insight Session at the Harvard Club Boston distilled five near-term actions:
- Help your team use AI responsibly and enhance them as humans by making responsibilities explicit.
- Match the tool to the purpose and train your staff for AI reliability. Not only against hallucination, but against the broader class of reasoning errors that emerge when AI acts autonomously.
- Make the knowledge base readable and usable for humans by auditing what exists and what AI can and cannot make accessible.
- Use governance as an enabler, not an enforcer by definition ownership of the AI guardrails and process rethinking.
- Identify and engage your cultural change champions by identifying the early adopters, credit them and give them a structured role.
Making AI a core operational capability is not achieved by running more pilots. It is achieved by redesigning work, deciding on governance, and leading people through the transition.
1 · The Guiding Question
Organizations across industries have invested heavily in artificial intelligence initiatives, yet the transition from discrete, bounded projects to embedded, organization-wide capability has proven elusive for the vast majority. Understanding why this transition is difficult, and what it actually requires, is a question of both scientific and practical urgency:
The question reflects a tension that has become one of the defining challenges of enterprise management in the mid-2020s: the gap between AI experimentation and AI operationalization.
1.1 Why This Question Must Be Asked Now
The McKinsey State of AI 2025 report, based on 1,993 respondents across 105 countries, documents that while AI adoption is nearly universal in principle, value realization at scale remains the exception rather than the rule. The report identifies workflow redesign, data readiness, and accountability structures as the dominant barriers. This finding challenges the prevailing framing that AI deployment is primarily a technology problem and repositions it as an organizational transformation problem (Singla et al., 2025).
Westerman and Webster (2025) argue that organizations tend to pursue what they call “Small t” transformations. With this they refer to incremental, additive deployments of AI that leave existing structures intact when the situation demands a more fundamental re-architecture of how work is organized and value is created. They propose a progression in the scaling of generative AI, from individual productivity to embedded operational capability. Most organizations are stalling at early stages of adoption, not for lack of technology, but because the organizational conditions for the next step have not been established.
Schrage and Kiron (2024, 2025) diagnose the governance dimension of this same problem. In their framework of “Intelligent Choice Architectures” (ICA), they observe that most organizations have built AI guardrails existing of compliance-driven policies that are designed to prevent misuse, but have not yet re-engineered who has the right to make decisions about AI outputs, who bears accountability when AI produces errors, and how governance should be designed not merely to constrain AI but to enable strategic decision-making through it.
McAfee (2025) adds a cultural dimension. Drawing on his framework of the four norms of “geek companies” — science, ownership, speed, and openness — he argues that organizations that excel are not those with superior technical infrastructure, but those that have cultivated a culture of evidence-based decision-making and openness to being wrong. Applied to AI adoption, this suggests the CIO’s role is not primarily technical stewardship but cultural leadership: communicating the norm that AI adoption is the expected default, making it an organizational objective, and maintaining that norm through community expectation rather than mandate.
Westerman (2025) synthesizes these threads under the concept of “Directive Emergence”: the idea that in a fast-moving environment where neither the destination nor the optimal path is fully known, the CIO’s task is to set a clear directional intent and continuously adjust course as conditions evolve. This stands in contrast to both the traditional waterfall planning model and the emergent, pilot-based approach that characterizes many current AI initiatives.
1.2 Synthesis
Against this backdrop, the guiding question synthesizes four distinct but interrelated constructs. The maturity of AI adoption, organizational barriers to operationalization, governance posture, and the evolving role of the CIO. Each of these constructs is the subject of active academic and practitioner debate. The question makes the implicit explicit, and demands a response not in theory but in lived organizational reality.
2 · Development of the Field Survey Instrument
The survey instrument was developed with the explicit goal of capturing practitioner perspectives on AI operationalization in a structured, time-efficient format suitable for field collection at a large professional conference. The design intent was not hypothesis testing but rather the generation of a descriptive, research-anchored snapshot of current practice among CIO-level technology leaders.
Methodologically, the instrument is best classified as a descriptive field survey with a purposive expert sample, situated within the tradition of engaged scholarship (Van de Ven, 2007). Van de Ven defines engaged scholarship as “a participative form of research for obtaining the advice and perspectives of key stakeholders to understand a complex social problem.” This orientation explicitly bridges academic rigor and practitioner relevance. The frameworks that shaped the response categories were developed by academic researchers, while the respondents are the practitioners whose organizational reality those frameworks seek to describe. The development process itself constitutes an instance of the engaged scholarship it embodies: the instrument did not emerge from a decontextualized review of the literature, but from a sustained dialogue between theoretical frameworks and the practical constraints of a three-minute field interview at a major professional event.
This design is distinguished from exploratory research in the Eisenhardt (1989) and Yin (2018) tradition, which typically employs open-ended instruments designed to discover emergent constructs. In the present instrument, the constructs and response categories are pre-specified from published scientific work. The instrument is also distinct from confirmatory research, as no statistical hypothesis tests are applied. The appropriate analytical mode is descriptive statistics for categorical data, including frequency distributions, modal responses, and cross-tabulation (Saunders, Lewis, and Thornhill, 2019, Ch. 12; Field, 2018, Ch. 18). The deployment of the instrument at the MIT Sloan CIO Symposium 2026 about “Human-AI Synergy: Redefining Leadership for a Transformative Future” from 18th to 19th May, 2026 at Cambridge can be understood as a form of concurrent piloting: The field conditions provided immediate and direct feedback on the instrument’s adequacy, comprehensibility, and discriminatory power.
2.1 Literature Base and Construct Selection
The four substantive questions each correspond to a distinct construct derived from the published literature on AI operationalization. The selection criterion was dual: the construct had to be both scientifically grounded, and directly actionable as a discussion stimulus for the CIO Insight Session on 20th of May, 2026 that followed the data collection. Sources published in 2024 or later were prioritized to ensure currency.
AI Maturity
The construct of AI maturity was operationalized based on Westerman and Webster (2025). They describe a level-based progression in generative AI adoption from individual productivity use cases to task-embedded applications and ultimately to process-level transformation. For the purposes of this study, this progression was interpreted as an ordinal maturity scale. A pre-Level 1 category was added to capture organizations with no meaningful AI deployment, extending the original framework for empirical applicability.
The choice for this framework was made as Westerman and Webster’s work is directly grounded in case-based research with enterprise organizations, making its categories recognizable and discriminating for a practitioner audience.
Biggest Barrier
The barrier construct was grounded in two complementary sources. McKinsey’s State of AI 2025 report (Singla et al., 2025) provides the most current and comprehensive empirical data on AI adoption barriers across industries and geographies, identifying workflow redesign, data quality, talent, and governance as the dominant obstacle categories. Schrage and Kiron’s (2024) article “Intelligent Choices Reshape Decision-Making and Productivity” adds the governance and measurement dimensions: the absence of a clear accountability framework for AI outcomes, and the inability to connect AI investments to demonstrable financial value. The five response options were designed to be mutually exclusive at the level of primary barrier type, while collectively exhausting the barrier space as defined by the combined literature. The superlative framing (“biggest barrier”) enforces a forced-choice prioritization, which is methodologically appropriate for this construct.
AI Governance
The governance construct draws on Schrage and Kiron’s sustained research program on Intelligent Choice Architectures, specifically their January 2025 MIT Sloan Management Review article “The Great Power Shift: How Intelligent Choice Architectures Rewrite Decision Rights” and their July 2025 research report “Winning with Intelligent Choice Architectures” (MIT SMR / TCS). These sources develop a conceptual argument about how organizations must redesign decision rights and governance frameworks as AI reshapes organizational decision-making. Building on this argument, the response categories of the question about AI governance operationalize four behaviorally distinct governance postures. Each response category describes a specific organizational state that a CIO can recognize with confidence in a short amount of time to make the construct applicable in the field survey context.
Changing CIO Role
This construct was developed from three sources. Westerman and Webster’s (2025) work on AI progression which describes organizations systematically progressing through levels of AI transformation, suggests a “capability builder” orientation for CIOs focused on incremental, staged development of organizational AI capability. McAfee’s (July 30, 2025) eight-step framework for AI operationalization, grounds the “guardian of openness” orientation in the specific behaviors of communicating the AI adoption norm, making AI an organizational OKR, and building infrastructure for systematic learning. Westerman’s concept on “Directive Emergence,” reported in Fortune (December 12, 2025), provides the conceptual vocabulary for the third orientation: setting directional intent and continuously adapting rather than executing fixed plans. A null category (“not fundamentally changed”) was included as the logical baseline, ensuring exhaustiveness of the response set.
2.2 Questionnaire Design
The formulation of response options followed a systematic audit against eight established rules (mutual exclusivity, exhaustiveness, single dimension per option, parallel grammatical form, no leading or loaded language, cognitive appropriateness for context, response format matches question intent, balanced scale endpoints) for the design of closed questions in survey research. These rules are grounded in four canonical methodological sources: Sudman and Bradburn (1982), Dillman, Smyth, and Christian (2014), Fowler (2014), and Krosnick and Presser (2010). All seventeen response options in the final instrument were audited against each rule.
Three demographic classification variables were included at the end of the survey. These variables are methodologically essential for two purposes: the description of the sample, and the cross-tabulation of substantive findings by subgroup. Without demographic classification, the findings of the survey can only be reported as aggregate distributions across an undifferentiated sample. The three classification variables were operationalized as follows:
- Industry: Nine categories based on collapsed ISIC Rev. 4 top-level sections (UNSD, 2008), covering the primary sectors represented in a CIO professional audience.
- IT Organization Size: Three-level Bee360 operational definition (Small: <50; Medium: 50–250; Large: >250 IT headcount). The Bee360 definition reflects the IT-specific organizational scope that is directly relevant to CIO advisory work.
- Region: Seven macro-regions based on collapsed UN M49 codes (UNSD, 2024), enabling geographic subgroup analysis for a globally heterogeneous conference audience.
2.3 Sample Size & Sampling Strategy
The sampling methodology literature provides empirical guidance on the sample sizes at which patterns in practitioner data stabilize. Guest, Bunce, and Johnson (2006) found that thematic patterns typically stabilize within 12 interviews in a relatively homogeneous sample. Hagaman and Wutich (2017), revisiting that study in multisited and cross-cultural contexts, found that 20–40 interviews were needed to reach saturation for patterns that cut across more heterogeneous groups. While both frameworks apply specifically to open-ended qualitative interview data, the underlying principle is broadly consistent with the logic of closed-question survey data collected from a purposive expert sample. In a purposive expert sample, each respondent is selected precisely because they possess the specific knowledge and experience that is the subject of inquiry (Patton 2002, pp. 230–244). The achieved sample of 20 responses across two days reaches the threshold at which the observed distributions can be considered stable.
2.4 MIT Sloan CIO Symposium 2026 as Research Site
The MIT Sloan CIO Symposium represents an unusually well-suited research site for a field study of this nature. Four specific characteristics justify this assessment.
- Concentration of qualified respondents: ~400 CIO-level technology executives from a wide range of industries and geographies attend the Symposium. The very act of attending a specialized professional conference is itself a signal of active engagement with the topic of study, making the population self-selected in a way that aligns with the research objectives.
- Direct alignment between conference content and survey constructs: The survey constructs correspond precisely to the research programs of key speakers (Westerman, Schrage, McAfee). This alignment means that respondents had been exposed to the same theoretical frameworks that grounded the survey instrument, reducing the risk of construct unfamiliarity and increasing discriminatory power of the response categories. The survey thereby functions not only as a data collection tool but as a reflective instrument: respondents are invited to locate themselves within frameworks they have just encountered in a high-quality academic context.
- Neutral research context: Conference settings reduce the social desirability pressures. A CIO responding at a professional conference is in a more neutral epistemic position and can answer more candidly.
- Concurrent validity check: The findings could be immediately cross-referenced against the claims of keynote speakers and panelists and incorporated into the CIO Insight Session the following day.
2.5 Community Network
The Bee360 Community Network is an exclusive, invitation-based peer community for senior IT executives (CIOs, CTOs, and CDOs) operating across Europe and internationally. The network brings together forward-thinking executives who share a commitment to driving organizational change through digital transformation. The network is explicitly non-commercial in its interaction design making it an unusually candid environment for practitioner discourse on strategic challenges (Bee360, 2026). Several characteristics of the Bee360 Community Network make it methodologically suitable as a sampling frame for a pre-selected expert survey, though with important differences relative to the MIT Sloan CIO Symposium setting described in Section 2.4.
- Concentration of qualified respondents: Membership in the Bee360 Community is restricted to senior IT executives who have been actively vetted or personally invited. This produces a high-quality, homogeneous population of CIO-level practitioners. Unlike open-access surveys, the pre-selection mechanism ensures that each respondent possesses direct, relevant organizational experience with the constructs under investigation (Patton, 2002, pp. 230–244).
- Absence of direct conference framing: Unlike the MIT Symposium setting, community members did not attend a shared conference prior to completing the survey. This means the construct-alignment advantage present in the in-person sample (see Section 2.4) does not apply here. Respondents approached the instrument without prior exposure to the frameworks underpinning the response categories, which may reduce the self-locating precision of responses but also reduces the risk of social desirability effects tied to keynote content.
- Online asynchronous setting: The European survey was administered as an online link distributed through the community channel, rather than collected in a supervised in-person setting. Research on online survey methodology indicates that the virtual environment reduces social influence during response formation, as participants tend to answer based on individual rather than socially motivated reasoning (Wagner-Schelewsky & Hering, 2022, pp. 1052ff.). Personal relationships between the researcher and community members, and the possibility that respondents completed the instrument at their workplace, introduce a modest social-context effect that cannot be fully controlled. These characteristics distinguish the European online sample from the collection at the MIT Symposium and are further discussed as a limitation in Section 3.2.
3 · Survey Findings
A total of 20 survey responses were conducted across May 18 and 19, 2026, at the Royal Sonesta Hotel, Cambridge, MA. The sample was predominantly North American (90%), with 5% European and 5% Latin American representation, reflecting the geographic composition of the Symposium itself. Industry representation was heterogeneous: Manufacturing & Industrial and Other each account for 30%, followed by Professional & Business Services (15%), Technology/Media/Telecom (10%), Healthcare & Life Sciences (10%), and Financial Services (5%). IT organization size is bimodal: Small (<50) 40%, Large (>250) 35%, Medium (50–250) 25%.

Figure 1: Sample Characteristics, N = 20
The European online survey was completed by 25 CIO-level technology executives between May 26 and June 4, 2026. The sample is exclusively European, which eliminates the need for regional sub-analysis. The industry composition is even more heterogeneous than the North American sample: Manufacturing & Industrial accounts for 40%, followed by Retail & Consumer Goods (16%), Financial Services & Insurance (12%), Professional & Business Services (8%), Public Sector & Government (8%), Healthcare & Life Sciences (4%), Energy & Utilities (4%), and Other (8%). IT size distribution differs from the North American sample, as medium-sized IT organizations (48%) was the predominant size the European CIOs leading.

Figure 2: Sample Characteristics Europe, N = 25
3.1 Descriptive Analysis
This section reports the frequency distribution and modal response for each of the four substantive questions. For each question, the most frequently selected option is identified, followed by a theory-informed interpretation of the observed pattern. Selected cross-tabulations are presented where they reveal structurally meaningful co-occurrences between variables. All analysis is descriptive; no inferential statistics are applied (Saunders et al., 2019, Ch. 12).
The results of the European online survey are directly compared to the field results from the MIT symposium.
AI Maturity
The modal response was AI Maturity Level 2 — “AI is changing how specific roles or teams work, and outputs are reviewed by humans before use” — selected by 45% of respondents. Level 3 (AI embedded in operations with governance, 30%) was the second most frequent response, and Level 1 (individual AI use, no coordinated organizational approach, 25%) was third. No respondent selected the pre-adoption category (not yet embedded AI), so all organizations represented have some form of AI adoption underway.

Figure 3: AI Maturity distribution
This distribution is consistent with Westerman and Webster’s (2025) pattern finding that most organizations still derive most of their generative AI value from individual-level productivity applications, while fewer succeed in embedding AI into workflows and enterprise-wide processes. It also aligns with McKinsey’s State of AI 2025 finding that while AI adoption is near-universal in practice, scaled enterprise embedding remains the minority position.
The European online survey results present a markedly different AI maturity distribution. The modal response was Level 1 — “Individual employees use AI for their own tasks, but there is no coordinated organizational approach.” — selected by 44% of respondents. A further 28% report Level 2, indicating that AI is changing specific roles or teams with human oversight. Notably, 24% of European respondents indicate that their organization has not yet embedded AI at all (Level 0), a category that received no responses in the North American sample. Only 4% report fully embedded AI with governance in place (Level 3), compared to 30% in the North American cohort. These results indicate a substantial maturity gap between the two samples, with European organizations predominantly concentrated at the early individual-use phase.

Figure 4: AI Maturity distribution Europe
Biggest Barrier
The modal response was “We add AI to existing processes without redesigning the work itself”, selected by 40% of respondents. So, the primary barrier identified by this sample is not talent (people lack skills/ willingness, 20%), not data condition (data not useable for AI at scale, 15%), not accountability (no shared accountability framework, 15%) and not missing financial value demonstration (10%). The dominance of the response regarding process redesign confirms that the challenge is organizational, not technical.
This distribution is consistent with McKinsey’s (2025) finding that workflow redesign is the strongest organizational factor correlated with AI value realization.

Figure 5: Biggest Barrier distribution
The findings on the biggest barrier to AI operationalization of the European online survey closely mirror the pattern derived from the MIT symposium. The modal response is again “We add AI to existing processes without redesigning the work itself”, selected by 32% of European respondents. The consistency of the primary barrier across both geographies, implicates this organizational factor is independent of regional context. Data quality as barrier ranks second in Europe (24%), which may reflect the lower overall AI maturity of European organizations and the greater proportion of respondents still in the data readiness phase.

Figure 6: Biggest Barrier distribution Europe
AI Governance
The modal response was “We have policies in place, designed to prevent problems rather than to enable decisions”, selected by 50% of respondents. 35% of the respondents commit they not yet have a governance structure. Only 15% stated that they are actively working on decision rights and accountability of AI outcome. Notably, nobody chose the option, that governance processes slows down AI initiatives.

Figure 7: AI Governance distribution
This distribution shows that the large majority of respondents describe governance postures consistent with what Schrage and Kiron (2025) characterize as organizations that have not yet redesigned their decision environments around AI.
The cross-tabulation of question 1 (AI Maturity) with question 3 (AI Governance) reveals the most striking pattern in the dataset. All five respondents at AI maturity Level 1 (individual AI use, no coordinated organizational approach) reported a complete governance gap for AI decisions. At AI Maturity Level 2, governance as guardrails dominates (7 of 9, 78%). At AI Maturity Level 3, two participants stated, that they engineer decision rights, indicating that the most mature organizations are beginning to invest in governance design, but reactive compliance still dominates even among them.
The response distribution of the European online survey replicates the pattern of the MIT field study, while revealing two notable divergences. The modal response is again “We have policies in place, designed to prevent problems rather than to enable decisions”, selected by 60% European respondents (in comparison to 50% of the MIT sample), indicating that a reactive AI governance is an even more dominant posture in European IT Organizations. In the European sample fewer respondents (24%), than the MIT respondents, commit they not yet have a governance structure. Interestingly, in contrast to nobody in the MIT sample, 12% of European respondents indicate that governance processes are actively slowing down AI initiatives without producing strategic benefit.
The cross-tabulation of question 1 (AI Maturity) with question 3 (AI Governance) in the European dataset reveals that governance as guardrails is the dominant posture across all AI maturity levels. Even the sole AI Maturity Level 3 chose that answer, indicating that even the most mature European organization of the dataset relies on reactive compliance rather than designed governance architecture. This contrasts with the North American dataset, where the most mature organizations had begun to engineer decision rights.

Figure 8: AI Governance distribution Europe
Changing CIO Role
The modal response was “I set a direction for AI and keep adjusting our approach as circumstances and results evolve”, selected by 55% of respondents. 20% each declare that they focus on building their AI capacity as well as spend their efforts in changing the mindset around AI. Only one respondent provided the answer, that his role has not fundamentally changed.
The cross-tabulation of question 1 (AI maturity) with question 4 (Changing CIO Role) shows that the CIO role change to a direction setter for AI with adjusting in regard to changing circumstances dominates at AI Maturity Levels 2 (67%) and 3 (67%). At Maturity Level 1 results are more distributed and the CIO role change as capability builder is most frequent (40%). This pattern is consistent with Westerman’s (2025) theoretical argument that directive emergence is the appropriate leadership mode for organizations that have achieved meaningful AI embedding, while the capability builder orientation characterizes leaders who are still constructing the organizational preconditions.

Figure 9: Changing CIO Role distribution
The response distribution of the European online survey reveals that the European CIOs – as the CIOs from the MIT Sloan CIO Symposium 2026 – predominantly recognize the change of their roles in forms of direction setting and continuous adaption (32%). Most notably, 24% of the European online survey respondents describe their role as fundamentally unchanged by AI. This response was chosen by only one respondent in the field study.

Figure 10: Changing CIO role distribution Europe
The cross-tabulation of question 1 (AI Maturity) with question (Changing CIO Role) in the European dataset shows, that even organizations with no AI adoption have CIOs who describe their role as a direction setter for AI with adjusting in regard to changing circumstances, suggesting that directional leadership posturing precedes operational AI embedding. The European pattern overall suggests that in a sample where AI maturity is predominantly early-stage, the CIO role is still being defined rather than settled, producing the uniform cross-level dispersion observed across all four orientations.
3.2 Limitations of the Field Study & the Online Survey
Four limitations must be acknowledged in any use or citation of these findings.
- Statistical non-representativeness: The sample consists of 20 respondents self-selected from a professional conference audience. The sample is not random, not stratified, and not representative of the global population of CIO-level technology leaders. Findings describe patterns within this specific, purposive sample. They cannot be generalized to broader populations, and no claim of population-level representativeness is made or implied.
- Construct validity: Response typologies are researcher-constructed categories grounded in published frameworks, not independently validated scales. Psychometric properties (reliability, construct validity) are unknown, reflecting the emergent state of the research field.
- No causal inference: Cross-tabulations are descriptive associations only. They do not establish causal relationships or control for confounding variables.
- Benchmarking limitations: Findings cannot be directly compared to McKinsey’s State of AI 2025 data, which uses a different proprietary instrument. Apparent similarities in findings (e.g., both studies identify workflow redesign as a leading barrier) reflect shared theoretical grounding, not methodological comparability.
Within these limitations, the findings are valid as what they are: a practitioner-grounded, theory-anchored snapshot of current positions among a purposive sample of CIO-level technology leaders, designed to stimulate structured expert discussion.
The extension of the study to a European online survey introduces two additional methodological limitations that must be acknowledged:
- Limited controllability of research context: Research on online survey methodology has documented that the virtual setting changes the social dynamics of response formation: respondents tend to answer in individually rather than socially motivated ways, as the absence of a co-present audience reduces the influence of social norms and impression management on response selection (Wagner-Schelewsky & Hering, 2022, pp. 1052ff.).
- No priming of used theoretical and framework underpinnings: The European respondents were not primed by prior exposure to the theoretical frameworks underpinning the response categories, which may reduce construct clarity compared to the MIT Symposium sample.
Within these constraints, the findings from the European cohort are valid as purposive, theory-anchored practitioner responses from a pre-selected expert population, and are interpreted accordingly.
4 · CIO Insight Session: From Data to Discussion
On May 20, 2026, the day following the conclusion of the MIT Sloan CIO Symposium, five CIOs convened at the Harvard Club Boston for a two-hour CIO Insight Session. The session operated under Chatham House Rules. The discussion was guided by the same overarching question that had structured the field survey: “What does it actually take to make AI a core operational capability — not just a portfolio of pilots?”
The session was structured in three phases. In the opening phase, the participants shared their current challenges of making AI a core operational capability, which were discussed thematically clustered in the core phase. In this phase the results and patterns of the survey findings were revisited as well as the participants’ key takeaways from the MIT Sloan CIO Symposium were taken into account. In the closing phase, the participants concluded with next steps to finally answer what it takes over the next month to actually tackle their shared challenges.
4.1 Common Challenges for AI Adoption
The responses, collected under Chatham House Rules and organized by the industry context each participant represented, reveal both the universality of certain challenges and the meaningful industry-specific variation in how those challenges manifest. Across six industry contexts represented in the room — energy & utilities, economic consulting, mining & resources, geotechnical engineering, professional services, software - four overarching challenge clusters emerged.
- First, the business case problem was universal. Every industry context requires a translation of AI potential into financial language that CFOs and boards can act on, and this translation remains underdeveloped across the board.
- Second, the mindset and culture challenge appears also in every industry context, though its specific form differs from professional identity anxiety in consulting to safety culture in mining.
- Third, the skill and capability gap is pervasive, though the required skills differ substantially between industries.
- Finally, many questions remain unresolved regarding governance and accountability, including “Who owns the risk? Who approves AI investment? Who defines success of AI operationalization?”
Besides convergence of the challenges across the six industry contexts, one divergence pattern was detected: The nature of the risk that constrains AI adoption. In asset-light, knowledge-intensive industries (economic consulting, software, professional services), the primary risk is reputational and cultural. The risk lies in adopting AI in ways that undermine client trust or erode the professional culture that differentiates the firm. In asset-heavy, operationally critical industries (geotechnical engineering, mining & resources), the primary risk is physical, legal, and operational. AI errors in these contexts can cause physical harm, create legal liability, and disrupt production systems that cannot be quickly restored. This divergence is worth highlighting as it has direct implications for governance design. The appropriate level of human oversight, the appropriate risk tolerance for AI-driven decision-making, and the appropriate organizational structures for AI accountability are fundamentally different across these industry contexts — a finding that the one-size-fits-all framing of most AI governance literature does not adequately capture.
4.2 Themes from the Discussion
The following themes emerged from the facilitated discussion and are reported here in the spirit of Chatham House anonymity. They are derived from the facilitator’s notes and the physical documentation captured on flipcharts during the session.
The barrier is organizational, not technological
Consistent with the survey finding that 40% of respondents identified process redesign as the primary barrier, the roundtable discussion quickly converged on the organizational and cultural dimensions of AI operationalization. Participants consistently distinguished between the challenge of making AI tools available and the challenge of embedding AI into how work is actually organized and performed. The metaphor that emerged from one participant — “make it as natural as pen and paper” — captured the ambition: not AI as a specialized capability, but AI as workplace infrastructure. This resonates with Westerman and Webster’s (2025) concept of the transition from individual productivity to operational embedding.
Participants noted the persistence of what one called “shadow AI groups”, meaning informal communities of practitioners using AI tools outside sanctioned channels, as evidence that the demand for AI capability exists but that organizational structures have not yet been designed to channel and legitimate it. The existence of such groups was interpreted both as a problem (data risk, inconsistent practice) and as an asset (organic innovation, early adopter communities that can be formalized and scaled).
Governance as a design decision, not a compliance function
The survey finding that 50% of respondents described their governance approach as reactive guardrail prompted a rich discussion of what governance as architecture would actually require. Participants converged on a formulation that extends Schrage and Kiron’s notion of governance as architecture: whereas Schrage and Kiron emphasize governance in terms of decision rights and accountability structures, participants reframed it as a continuously enacted design practice embedded within organizational processes. The question “How much human in the loop?” was identified as a question that must be answered differently for each process and each risk level, rather than through a single organizational policy.
One participant articulated a particularly clear formulation: “Governance is becoming a design decision. You have to think about the appropriate level of human oversight with every process. There is no one-size-fits-all.” This reframes Schrage and Kiron’s notion of governance as architecture by moving from organizational-level decision-rights design to process-level calibration of human oversight. The question of accountability — who owns the guardrails, who owns the risk, how a SteeringCo adjudicates between competing priorities — emerged as a live organizational challenge rather than a solved design problem.
Participants also identified a specific governance challenge that had not been anticipated in the survey instrument: the management of token costs in large language model deployments. The observation that AI resource consumption (“I want ten million dollars of tokens”) creates new categories of demand that existing IT financial governance structures are not designed to handle points to a gap in the existing theoretical literature on AI governance, which has focused primarily on decision rights and output quality rather than on resource governance.
The ROI problem and the measurement gap
The survey finding that 10% of respondents identified the inability to demonstrate financial value as the primary barrier did not fully capture the centrality of the ROI challenge in the roundtable discussion. While only a minority identified it as the single biggest barrier, virtually all participants engaged with the measurement challenge as a significant secondary concern.
The roundtable surfaced a useful distinction between two types of AI value. Efficiency gains, reducing the time or cost of existing activities, are relatively straightforward to measure but may paradoxically undermine the business case if they eliminate roles or activities that clients or internal stakeholders value. New output creation through generating products, insights, or services that could not have been produced without AI is harder to quantify in advance but represents the more durable form of value creation.

Figure 11: Redesign and restructuring of the work can enable ROI measurement and break down organizational barriers
Participants identified the CFO relationship as a critical and often under-managed dimension of AI operationalization. The challenge of translating AI’s impact into balance-sheet-relevant language that a CFO can understand and act on was described as a distinct competency that many CIOs are still developing. This connects to McAfee’s (2025) argument that making AI an organizational OKR requires not just cultural advocacy but operational instrumentation: measuring AI adoption, tracking causal impact, and communicating results in the financial language of the C-suite.
The knowledge and skill dimension
The discussion of talent and culture surfaced a set of concerns that extended beyond the survey’s framing of “people lack the skills or willingness to work differently.” Participants distinguished between three distinct challenges: functional AI literacy (understanding what AI can and cannot do, how to use it responsibly, and how to recognize compounding reasoning errors that propagate across multi-step workflows rather than isolated factual mistakes); domain application skills (knowing how to apply AI to specific professional tasks, including the mitigation of both hallucination and of autonomous prioritization errors, where AI agents allocate resources on the basis of initiative visibility rather than expected impact); and cultural readiness (the organizational willingness to change how work is organized and valued as AI becomes more capable).

Figure 12: Talent & Skill Challenges
The risk of decreasing human knowledge as AI takes on cognitive tasks was raised as a longer-term concern: if AI handles the reasoning and synthesis that junior staff previously performed, the pipeline for developing senior-level human judgment may be disrupted. This concern resonates with recent academic work on the automation of cognitive tasks and the potential for AI to compress rather than extend human learning curves in professional environments.
Several participants described leadership pressure toward over-adoption — pursuing AI initiatives without clear understanding of value, driven by top-down enthusiasm rather than bottom-up readiness — as a governance and risk management challenge in its own right. The observation that “taking on initiatives without a clear understanding of value leads to autonomous prioritization” — where token consumption and computational resources are allocated on the basis of initiative visibility rather than expected impact — illustrates the same core tension identified in the survey: the organizational structures for managing AI have not kept pace with the speed of AI adoption.
4.3 Action Steps for CIOs
Closing the CIO Insight Session, participants were invited to respond to a concrete next-step question: “What does it take over the next month to actually tackle these challenges?” The following action steps were identified collectively and documented on the facilitation flipchart. They are reported under Chatham House Rules, attributed to the group, not to individual participants.
Help your team use AI responsibly and enhance them as humans.
The framing the participants chose for immediate team action was not adoption or efficiency, but responsible use of AI paired with human enhancement. For this it must first be defined what responsible use means in every CIO's specific context. After that it must be explicitly communicated which tools are sanctioned, and what will be the consequences of non-AI-use alongside the consequences of misuse.
Match the tool to the purpose and train employees for reliability.
To get a systemic overview of the available AI tools and be able to communicate them adequately to the organization, a mapping of the AI tools to specific use cases and purposes must be done. Sensibility labels should also be considered where needed relevant to the use case. Moreover, practical trainings that teach employees not only how to use the AI tools, but how to identify and handle errors. Errors refers not only to classical hallucinations, but to the broader class of AI reasoning errors that become consequential when tools act autonomously across multi-step workflows. The goal is not a generic AI literacy but a domain-specific, responsible application of AI.
Make the knowledge base readable und usable for humans.
AI's ability to extract value from an organizational knowledge base depends on the quality of that knowledge base. A near-term action for CIOs is to audit what knowledge exists and in which form, and to determine what knowledge AI should be able to access. The AI then makes decisions about what to include in a synthesis. In this way value and meaningful information can be extracted out of that knowledge base.
Use governance as an enabler, not an enforcer.
The most concrete governance action identified for the next month is a deliberate decision about posture: Governance must become an enabler, not an enforcer. This requires deciding who owns the guardrails, who informs them, and what hard controls and training are in place to mitigate risk without those controls becoming a bottleneck. The question "Has governance become a design decision?" was posed as a leadership prompt for the coming month: Rethink every process, not just the AI policy.
Identify and engage your cultural change champions.
Cultural change was identified as requiring active facilitation, not passive communication. The near-term action should be to identify who the change agents are and to give them a structured role. Take the people along on the journey. As framed at the MIT Sloan CIO Symposium: AI is the co-pilot, humans are the pilot.

Figure 13: Overview of the five action steps
5 · Synthesis & Summary
A 20-respondent field survey at the MIT Sloan CIO Symposium 2026 found that 45% of CIOs report AI is already changing specific roles; 40% identify workflow redesign as the primary barrier; 50% operate with reactive governance guardrails; and 55% describe their role as directive emergence. All respondents at the lowest AI maturity level reported a complete governance gap. The CIO Insight Session the following day deepened these patterns: the barrier is organizational, governance must become a design decision, ROI language remains underdeveloped, and differentiated AI literacy is foundational.
Across the two-hour discussion, a coherent picture emerged that both confirmed and extended the survey findings from the MIT Symposium participants. The challenge of making AI a core operational capability is fundamentally an organizational design challenge, consistent with Westerman’s notion of directive emergence, in which leaders combine clear strategic intent with adaptive, experiment-driven implementation. This requires the redesign of work processes, the construction of process-specific governance mechanisms, the development of a measurement infrastructure that connects AI activity to organizational outcomes, and the cultivation of a learning culture that can adapt as AI capabilities and organizational conditions evolve. The CIO’s role in this challenge is not primarily technical, it is directional, cultural, and translational. CIOs must set a clear intent, communicate it consistently, build the organizational conditions for systematic learning, and translate AI’s impact into the languages of finance, operations and strategy to enable the full organization to engage.
The 25-respondent online survey distributed through the Bee360 Community Network to European CIOs produced a complementary dataset that both reinforces and refines the field study findings. The results reveal a maturity lag: 44% of European respondents report an AI use at the individual level only, and just 4% have reached embedded AI with governance (compared to 25% and 30% respectively in the MIT Sloan CIO Symposium 2026 field study). 60% operate with reactive guardrails, while 12% report that they experience governance as an active bottleneck. They describe their role – in accordance to the field study respondents – as directive emergence (32%). Also 24% describe their role as fundamentally unchanged, which could be interpreted consistent with the lower AI maturity.
Taken together, the two datasets suggest that the organizational design challenge of AI operationalization is geographically convergent in its nature but divergent in its stage: European CIOs are navigating the same structural barriers somewhat in a lower maturity journey, confirming that the transition from pilots to operations remains a challenge across both contexts.
References
Bee360. (2026). Bee360 Community — Honest peer exchange for digital leaders. Retrieved June 2026, from https://us.bee360.com/community
Field, A. (2018). Discovering statistics using IBM SPSS statistics (5th ed.). SAGE Publications.
Fowler, F. J. (2014). Survey research methods (5th ed.). SAGE Publications.
Guest, G., Bunce, A., & Johnson, L. (2006). How many interviews are enough? An experiment with data saturation and variability. Field Methods, 18(1), 59–82.
Hagaman, A. K., & Wutich, A. (2017). How many interviews are enough to identify metathemes in multisited and cross-cultural research? Another perspective on Guest, Bunce, and Johnson's (2006) landmark study. Field Methods, 29(1), 23–41.
Krosnick, J. A., & Presser, S. (2010). Question and questionnaire design. In P. V. Marsden & J. D. Wright (Eds.), Handbook of survey research (2nd ed., pp. 263–313). Emerald.
McAfee, A. (2025, July 30). Who's going to succeed with AI? The Geek Way [Substack newsletter]. https://geekway.substack.com/p/whos-going-to-succeed-with-ai
Patton, M. Q. (2002). Qualitative research and evaluation methods (3rd ed.). SAGE Publications.
Saunders, M., Lewis, P., & Thornhill, A. (2019). Research methods for business students (8th ed.). Pearson Education. Harlow, UK.
Schrage, M., & Kiron, D. (2024, October 29). Intelligent choices reshape decision-making and productivity. MIT Sloan Management Review. https://sloanreview.mit.edu/article/intelligent-choices-reshape-decision-making-and-productivity/
Schrage, M., & Kiron, D. (2025a, January 28). The great power shift: How intelligent choice architectures rewrite decision rights. MIT Sloan Management Review. https://sloanreview.mit.edu/article/the-great-power-shift-how-intelligent-choice-architectures-rewrite-decision-rights/
Schrage, M., & Kiron, D. (2025b, July). Winning with intelligent choice architectures. MIT Sloan Management Review / TCS Research Report. https://sloanreview.mit.edu/projects/scholars/winning-with-intelligent-choice-architectures/
Singla, A., Sukharevsky, A., Hall, B., Yee, L., & Chui, M. (2025, November). The state of AI in 2025. McKinsey & Company. https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai
Sudman, S., & Bradburn, N. M. (1982). Asking questions: A practical guide to questionnaire design. Jossey-Bass.
United Nations Statistics Division. (2008). International standard industrial classification of all economic activities, Revision 4 (Series M, No. 4/Rev.4). United Nations.
United Nations Statistics Division. (2024). Standard country or area codes for statistical use (M49) (Series M, No. 49). United Nations. https://unstats.un.org/unsd/methodology/m49/
Van de Ven, A. H. (2007). Engaged scholarship: A guide for organizational and social research. Oxford University Press.
Wagner-Schelewsky, P., & Hering, L. (2022). Online survey. In N. Baur & J. Blasius (Eds.), Handbuch Methoden der empirischen Sozialforschung (3rd ed., pp. 1051–1066). Springer VS.
Westerman, G. (2025, December). Scaling GenAI: Get Big Value From Smaller Effects. Reported in Fortune, December 12. https://sloanreview.mit.edu/video/scaling-genai-get-big-value-from-smaller-efforts/
Westerman, G., & Webster, M. (2025, January 22). Generate value from GenAI with 'small t' transformations. MIT Sloan Management Review. https://sloanreview.mit.edu/article/generate-value-from-gen-ai-with-small-t-transformations/


