Summary: A recent enterprise survey found that the vast majority of organizations have delayed or cancelled AI projects this year, and the reason isn’t the technology. Governance, compliance, and regulatory challenges are forcing organizations to confront data architectures that weren’t built for AI. This piece unpacks why that’s happening, why some companies are pulling AI workloads back from public cloud, and what it actually takes to build a data foundation that can support AI at scale.
Everyone loves to talk about how fast AI is moving. New models, new copilots, new agents that promise to do the boring parts of your job for you. But if you sit down with the people actually responsible for running enterprise data infrastructure, the story sounds a lot less triumphant. A recent survey of enterprise architects and data leaders, conducted by Cloudera, found that the overwhelming majority of organizations have delayed or scrapped AI projects this year. Not because the technology didn’t work. Because governance, compliance, and regulatory challenges got in the way.
That distinction matters more than it might seem at first glance.
The Architecture Problem Hiding Behind AI
For the past few years, the AI conversation has mostly lived at the application layer. Which model to use, which vendor to pick, how to write a better prompt. Those are real questions, but they’re also the easy ones. The harder question, the one most companies are quietly running into right now, is whether their data can actually support what they’re trying to build. And for a lot of organizations, the honest answer is no.
Think about how most enterprise data environments actually got built. Piece by piece, system by system, usually over a decade or more. A data warehouse here, a handful of SaaS tools there, some legacy databases nobody wants to touch, maybe a recent migration to a cloud platform that’s still half finished. Each of those systems probably has its own way of handling access control. Its own definition of who counts as an admin. Its own patchwork of exceptions that made sense at the time and now nobody remembers why they exist.
That kind of environment can limp along just fine for traditional analytics. Reports run, dashboards update, everyone’s more or less happy. But AI doesn’t behave like a traditional workload. It touches more data, more often, across more systems, and it does it fast. An AI agent doesn’t wait for a quarterly access review. It queries whatever it’s been pointed at, right now, and if your governance model can’t keep pace with that speed, you end up with one of two outcomes. Either you slow the AI down until it’s not actually useful anymore, or you let it run and hope nothing sensitive slips through. Neither is a great place to be.
You Might Also Like: Your AI Agent Can’t Answer to an Auditor. You Still Have To.
What the Survey Actually Found
This is really what’s behind the numbers. Seventy-two percent of organizations said their existing data architecture needs a significant overhaul to support AI workloads. Nearly three quarters said governance has gotten more complex since AI entered the picture. And 55% said they’ve delayed or canceled more than six AI initiatives in the past year because of governance, compliance, or regulatory concerns. That’s not a technology problem. That’s an architecture problem wearing an AI costume.
You Might Also Like: Can You Answer These 5 Questions About Your AI Agents?
The Quiet Retreat From Public Cloud
There’s also a quieter shift happening underneath all of this, and it’s worth paying attention to. A lot of companies spent the last several years moving everything they could into public cloud, treating it as the obvious default for any new workload, AI included. That instinct is starting to reverse. A meaningful share of organizations say they’ve actually pulled AI workloads back out of public cloud and into private cloud or on-premises environments over the past year. Not because public cloud stopped working. Because the calculus changed. When you’re moving sensitive data across a dozen different environments every month, and each of those environments has a slightly different governance posture, the risk math starts to look different than it did when AI was still mostly a pilot project running in a sandbox.
None of this means hybrid is inherently safer or public cloud is inherently risky. What it means is that organizations are finally being honest about the tradeoff they’ve been ignoring. Speed of deployment and consistency of control are two different things, and you can’t optimize for both by accident. You have to actually design for it.
Building Governance That Actually Holds Up
So what does designing for it look like in practice? It starts with a shift in mindset that a lot of security and data teams haven’t fully made yet. Governance can’t live at the application layer anymore, bolted on after the fact as a checklist item before launch. It has to live at the data layer itself, built into how information is classified, accessed, and monitored no matter which system it happens to be sitting in that day. If a policy only applies inside one platform, it’s not really a policy. It’s a local exception that happens to work most of the time.
That also means rethinking what “governed” actually means for a company. A lot of organizations can answer the question “where is our sensitive data” for their most mature, most tightly controlled systems. Fewer can answer it for everything else. The development environments, the notebooks, the exports nobody tracks, the SaaS tools that quietly accumulated real customer data over time. AI doesn’t respect the boundary between your governed core and everything else. It goes wherever it’s pointed, and if that boundary is where your controls stop, that’s exactly where your risk starts.
Where This Actually Leads
The good news, if there is one, is that this isn’t actually a new problem dressed up in new language. Data teams have been dealing with fragmented environments and inconsistent controls for years. What’s changed is the cost of ignoring it. When the consequence of weak governance was a slow audit or an awkward compliance conversation, plenty of companies could afford to defer the fix. When the consequence is that your AI strategy simply can’t move forward, that’s a different kind of pressure, and it tends to get budget approved a lot faster.
The organizations that get past this moment won’t be the ones with the flashiest AI use cases. They’ll be the ones who did the less glamorous work first. Consistent data classification across every environment, not just the important ones. Access policies that travel with the data instead of stopping at a platform’s edge. Real visibility into who and what is touching sensitive information, in something close to real time, rather than reconstructed after the fact during an audit. That’s not a sexy roadmap. It’s also the only one that actually holds up once AI stops being a pilot and starts being how the business runs.
The pause enterprises are hitting right now isn’t really a pause on AI. It’s a forced reckoning with data foundations that should have been fixed years ago. The companies that treat it that way, instead of waiting for a better model to solve a governance problem, are the ones who’ll actually get to the other side of this.