Back to Blog

    The Five Ways Companies Are Actually Deploying AI

    Research 3 min readBy Drew Rutter · September 21, 2026
    Share

    Ask a leadership team how their company is deploying AI and you will usually hear one answer: "We rolled out Copilot," or "We bought Claude seats." Ask their IT, security and engineering leads the same question separately and you will hear four or five different answers. All of them are true.

    That is the real state of enterprise AI in 2026. Companies are not choosing a deployment approach. They are accumulating them. After reviewing how organizations are rolling AI out this year, we see five distinct patterns running side by side.

    1. Managed desktop assistants

    Claude, ChatGPT Enterprise, Microsoft 365 Copilot or Gemini, licensed per seat with single sign-on. This is the default on-ramp, and it got easier this year when Anthropic made its Enterprise plan self-serve.

    It is fast and broad. Its weakness is that value depends on each individual. Deloitte found sanctioned AI access grew from under 40% of workers to about 60% in a year, yet fewer than 60% of people with access use it daily, and that number has not moved. Licenses do not create value. Packaged, shared workflows do.

    2. Self-hosted open agent runtimes

    Tools like OpenClaw that run on a laptop or a server with access to the shell, the file system and the browser. They are capable and they let teams pick any model.

    They are also where risk concentrates. In February 2026, SecurityScorecard counted more than 40,000 OpenClaw instances exposed to the internet, with about a third flagged as vulnerable. Microsoft's security team says plainly that the runtime ships with limited built-in security controls. Very few enterprises are formally deploying these. Far more are finding them already installed.

    3. Agents embedded in your SaaS

    Salesforce, ServiceNow, Workday, Microsoft 365 and most vertical tools now ship agents. Gartner forecast that 40% of enterprise applications would include task-specific agents by the end of 2026, up from under 5% a year earlier.

    This pattern arrives whether you choose it or not. The upside is that the agent inherits the application's permissions and data model. The downside is that each one is a silo, priced per action, and none of them can see across systems.

    4. Custom agents on model APIs

    Engineering teams building on Anthropic, OpenAI or Google APIs, or on cloud platforms and frameworks. This is where the most differentiated value lives, and also where most failed pilots sit. Gartner expects more than 40% of agentic projects to be canceled by the end of 2027, citing cost, unclear value and inadequate risk controls. Every team that builds its own agent also rebuilds its own guardrails.

    5. Governed agent platforms

    A policy, identity and audit layer that agents run on or through. Microsoft is converging its agent registries under Agent 365. MCP gateways are doing the same for connectors. Purpose-built platforms, including our own Axionic Agents, enforce policy outside the model.

    This pattern exists because of the other four. Once you have assistants, embedded agents and custom agents running together, you need one place to answer three questions: what agents exist, what may they do, and what did they do.

    The question that matters

    The mistake is treating this as a tool choice. The useful question is which class of work belongs on which pattern.

    Individual knowledge work belongs in a desktop assistant. Repeating team workflows belong in an assistant with a centrally published plugin. Work inside one system of record belongs to that system's embedded agent. Unattended, cross-system or regulated work belongs on a governed platform. Custom builds are worth it when the AI is the product.

    Most organizations have work sitting on the wrong pattern: a finance reconciliation running as somebody's personal scheduled task, or a custom agent doing what the CRM's built-in agent already does. Getting placement right is usually cheaper than buying anything new.

    The full analysis, including the nine controls that apply to every pattern and a worked budget for a 500-person firm, is in our white paper, Deploying AI at Scale.