A new State of AI in the enterprise report from Box shows a dramatic one‑year shift in how companies are using AI. The survey polled 1,640 IT decision makers across the United States, the United Kingdom, France and Japan.
The most striking change: the combined share of organizations that describe themselves as advanced or leading‑edge rose from 8% to 64% in one year, while the share that say they are early stage or have not started fell from 53% to 9%. Eighty percent of respondents reported a notable return on their AI investment—defined in the survey as at least a 10% improvement—and more than half saw measurable business impact within six months of project approval.
Olivia Nottebohm, Chief Operating Officer of Box, attributes the rapid swing not to a single technological breakthrough but to how companies organize AI use. “We’ve moved from standalone experimentation at the individual level into systematized, integrated agentic operations—agents that are in production and can be used in a repeatable manner,” she said.
Why leaders post higher ROI
Execution separates tiers. Half of leading‑edge companies reported AI‑driven ROI above 25%, compared with just 11% of early‑stage companies. The advanced tier reported 33% and the developing tier 16% in that band. Nottebohm emphasizes the real differentiator is how rigorously organizations integrate and govern AI: the right teams to deploy agents, formal governance, and consistency in the content layer that agents work from.
Content access is the 2026 bottleneck
According to the survey, 96% of organizations say agents need access to company‑specific content, yet only 36% have connected agents to trusted content across many use cases. The issue is more about trust and governance than raw model capability: agents are only as good as the content they can reference and the protections around that content.
Getting the content layer right also enables agents to work across previously siloed departments. Roughly a quarter of organizations point to data fragmented across systems, 24% cite difficulty integrating AI into existing systems, 21% say they lack adequate permissions and access controls, and 18% describe their content as too unorganized to make accessible. Among the most mature organizations, 63% regard unstructured documents, contracts and reports as a competitive advantage rather than dead weight.
Data exposure incidents and governance gaps
Nearly half of organizations report having experienced an AI‑related data exposure incident; that rises to 60% among leading‑edge companies, which may both expose them to greater risk and make them more likely to detect incidents.
Reported adoption of established or advanced governance frameworks climbed from 24% in 2025 to 73% this year, but gaps remain in instrumentation: only 39% have comprehensive visibility across sanctioned and unsanctioned AI use, 34% have formal standards for how agents access company data, and 27% still describe their governance as ad hoc. Nottebohm notes that incidents have acted as a forcing mechanism: 93% of respondents told Box that better governance actually let them move faster. Once content is secured and highly permissioned, organizations can run multiple agents across multiple processes and achieve a multiplier effect.
One practical consequence is revisiting permission models built for human users so they work for agents. Many enterprises are going back through corpora of unstructured data to either clean up content or set new permissions.
Avoiding vendor lock‑in and embracing multi‑model, headless architectures
Companies are increasingly wary of relying on a single AI vendor: 68% say they are concerned about dependence on a single provider. The average number of officially adopted AI tools has risen to 3.3, and 79% consider it important or critical that agents operate headlessly—connecting directly to systems and APIs without a human interface.
Nottebohm frames this as analogous to the multi‑cloud shift: flexible architectures favor platform interoperability, multiple models, headless operation and swappable stack components so organizations don’t have to bet on any single tool.
Recommended next steps for the coming three years
Box recommends prioritizing organization, classification and cleanup of unstructured content; hiring and building teams around emerging roles; and adopting a hybrid token compute budget model where IT owns core infrastructure and token budget while business units own application‑level spend. Nottebohm adds that companies don’t have to climb maturity stages slowly: if they build governance, the content layer and a multi‑model system from the start, they can enter as leading companies and capture outsized impact.
Note on sourcing
The report was presented by Box; the article originally appeared as sponsored content on VentureBeat. Sponsored articles are produced in partnership with or paid for by a company and are clearly labeled as such.



