AI capabilities may create competitive advantage, but they expand the attack surface, introduce new vulnerabilities, and concentrate critical infrastructure in ways that boards are only beginning to reckon with.

Several major cyber retail incidents of 2025 changed the board conversation about cyber risk more effectively than years of CISO warnings. When the financial consequences of a breach can be expressed in weeks of lost payment processing rather than terabytes of compromised data, the argument lands differently. Sovereignty has traveled a similar distance in less time, driven by the concentration of AI infrastructure in U.S.-headquartered providers, supply chain risks made newly concrete by geopolitical events, and a data dependency problem that no existing security framework was built to catch. 

"Organizations need to modernize their cybersecurity programs now more than ever. The cost of modernization today is a fraction of the value destruction that follows a breach because your security model is fundamentally obsolete."
Megha Kalsi, Partner
Megha Kalsi

Key themes


Cybersecurity in the post-perimeter era 


The castle-and-moat model of cybersecurity, a hardened perimeter protecting trusted systems within, is dead and no longer addresses the reality of the current threat environment. Organizations can no longer defend a perimeter that does not exist, especially with cloud and edge infrastructure spread across multiple providers, data sprawl, employees on home networks, and integrated partners throughout the supply chain. There is no clear boundary between ‘inside’ and ‘outside’ anymore. AI compounds this situation. As agents embed in devices, applications, and core business processes, the traditional concept of a discrete AI tool dissolves. AI systems interacting with other AI systems, taking action without direct human instruction, expand the potential impact of any compromise.


Technology sovereignty, the new frontline 


The sovereignty calculation is reshaping vendor selection, architecture decisions, and PE asset evaluation. For European organizations the exposure is both extensive and structural: dependence on U.S. providers is extensive across most of the stack, European alternatives don't exist at scale in most categories, and the regulatory environment that protects European data also constrains how quickly European companies can move. The mitigation can only be a managed dependency, built into procurement decisions before the vendor relationship is established. 

Our State of Enterprise Technology Report is split across the following chapters. Click through to learn more:

2026 State of enterprise technology

AI is not just changing what technology does for enterprises, it has the potential to change how they are structured, how decisions get made, even what business they are fundamentally in.

Our expert insights cover the whole terrain, from the mechanics of AI-native engineering to the financial exposure building in cloud and vendor contracts to the newly pressing question of software and data sovereignty.

Download the full report