The AI Risk Gap Is a Release Gap
Originally published on the Dromeas blog. Gartner's latest quarterly has a line I keep coming back to: to protect the value you get from AI, plan to spend at least twice as much on derisking it as you spend on the tools
Originally published on the Dromeas blog.
Gartner's latest quarterly has a line I keep coming back to: to protect the value you get from AI, plan to spend at least twice as much on derisking it as you spend on the tools themselves.
That's aimed at CEOs and CFOs. But if you run engineering or security, I think it lands on you faster than on anyone, because that's where AI output turns into something real. Agent-written code reaches production at the release. So that's where I'd look first.
A quick caveat. Gartner's numbers are about AI in general, not code. Everything below about releases is my reading, not theirs.
The gap, in Gartner's numbers
Their opening message calls the AI value gap "really an AI risk gap," and splits it into three pillars: cost, cybersecurity and trustworthiness. Miss one and you lose the value you were chasing.
Two data points from their CEO survey (203 executives, April to May 2026) stand out:
- 75% of CEOs are increasing spend on technology, data and IT. Only 28% are increasing spend on security and risk.
- Only 37% say they're highly prepared for cyber escalation. For what Gartner calls AI industrialization, it's 20%.
And only 23% of CxOs say they're confident in their organization's generative AI outputs.
(Gartner is clear this is a survey of the people it asked, not the whole market. Take it as a signal, not a census.)
Why the release is the cheapest place to start
Derisking "AI" sounds huge. Governance frameworks, sandboxes, vendor contracts. Some of that is a company-wide job.
But for software, there's one point every change has to pass through: the release. It's the last moment you can still say no, and it's where you can attach evidence to the yes. Let me take Gartner's three pillars one at a time.
Trustworthiness: can you say why this release is safe?
If only 23% of leaders trust their AI outputs, "the agent said it was fine" isn't going to cut it. A trusted release has a verdict and the evidence behind it: what was checked, what was found, how confident we are, and who or what disagreed.
Cybersecurity: guardrails that don't depend on someone remembering
Gartner's advice to CISOs is automated guardrails and containment, rather than hoping reviewers catch everything. For agent-written code that means checks that run on every change and every release, scoped to what actually changed, so they're fast enough that nobody routes around them.
The 28% figure matters here. Most security budgets weren't sized for the volume of code agents produce. A gate that scales with the diff is one way to keep up without hiring a reviewer per agent.
Cost: the iceberg under the license fee
Gartner talks about a "hidden iceberg" of AI costs: energy, data engineering, observability, workflow redesign, compliance audits. They note only 45% of senior functional leaders stayed on their planned 2025 AI budget.
The engineering version is rework. Bugs and security findings caught after release cost far more than ones caught before. I'm not going to put a number on it, because I don't have a clean 2026 source for one. But the direction is not in doubt.
"Certify before you scale," as an engineering checklist
One recommendation I liked: no AI pilot should get scale funding until the CFO, CIO and general counsel jointly certify its cost structure, value potential, data provenance and risk controls.
Here's how I'd translate that for a team shipping with agents:
- Know where agents touch your code. Including the ones people installed themselves.
- Gate every release on a verdict, not a vibe. What was checked, what was found, who signed off.
- Keep the evidence. An auditor, a customer or your own CFO should be able to ask "why did this ship?" and get an answer in minutes.
- Know what's inside. DataGrail's 2026 privacy report found 63.6% of software vendors that advertise AI capabilities don't disclose an AI subprocessor. Your own software should have a bill of materials for its AI, which matters more if you're covered by the EU AI Act.
- Budget for it. If the AI tooling line grows and the checking line doesn't, that's the gap Gartner is describing.
Where we fit
This is what we build at Dromeas: code review and release checks with a verdict, the evidence behind it, and the audit docs generated as a by-product. More on the compliance side.
โ Manos
Sources: Gartner Business Quarterly 4Q26: "The AI Value Gap Is Really an AI Risk Gap" (Sallam, Mesaglio) and "CEO Watch 4Q26" (Furlonger), based on the 2027 Gartner CEO Survey (203 respondents, AprโMay 2026) and the 2026 Gartner C-Suite AI Survey ยท DataGrail, Privacy and AI Trends Report 2026
Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes โ full credit and traffic to the original publisher.