Mahati Logo

The IT Department Taught Everyone Else to Work Without It. Now What?

Business Insurance

Problem Statement

THE IT DEPARTMENT DIDN'T LOSE ITS RELEVANCE. IT TRAINED THE ORGANISATION TO NOT NEED IT.

There is a version of this story that gets told as a crisis. IT is dying. AI is taking over. The department that used to hold the keys is being bypassed, defunded, and quietly made irrelevant by the same business teams it spent two decades serving. I have heard that version in boardrooms, at conferences, in the LinkedIn posts of people who enjoy a good disruption narrative. It is not wrong exactly. It is just not the interesting part. The interesting part — the part most organisations are not yet structurally honest about — is that IT did this to itself. Not through failure. Through fifteen years of doing its job well. Every platform it rolled out, every tool it democratised, every system it handed to the business to run independently moved the organisation one step closer to the day the business stopped needing a gatekeeper. That day is not coming. For most organisations, it already arrived. The question is not what happens to IT. The question is whether IT figures out what it actually is now — before the next incident makes the answer for it. Gartner projects that 40% of enterprise applications will have AI agents embedded in them by end of 2026. Most of those agents are being deployed by business teams, not IT.

The business teams have caught up. A finance analyst who spent three years learning Salesforce, then Power BI, then Workday, is not waiting for a ticket queue to tell her what's possible. She is configuring AI agents now — pulling pipeline data, flagging anomalies, drafting board summaries — with the same self-sufficiency she brought to every tool before it. The operations manager who ran his own Power Automate flows in 2022 is running multi-step agents in 2025. They didn't need permission then. They don't need it now.

The IT department is not disappearing. But the version of it that derived organisational weight from being the sole interpreter between business need and technical execution — that version is already gone in the organisations paying attention, and going fast in the ones that aren't.

What You’ll Learn

This piece is a clear-eyed read of what is actually happening inside organisations where AI agents are being adopted — not in the press releases, but in the operating model. It explains why the traditional IT department structure is losing its logic faster than most CIOs are comfortable admitting, what business teams are genuinely taking on and where they are struggling, and what the three structural shifts are that separate organisations navigating this well from those accumulating invisible risk. The reader will leave with a way of thinking about IT's future role that is neither the inflated "AI transformation hub" narrative nor the uncomfortable "IT is dead" provocation — but the more precise and actionable truth that sits between them.

SOLUTION

THREE SHIFTS THAT SEPARATE THE ORGANISATIONS GETTING THIS RIGHT FROM THE ONES THAT AREN'T

The organisations managing this transition well did not get there with an AI strategy document or a centre of excellence. They got there by making three structural decisions that most organisations are still avoiding — because each one requires someone senior to admit that a long-standing operating assumption no longer holds.

Shift One — Accept That Execution Has Moved, and Stop Trying to Reclaim It

I've watched IT departments respond to the rise of business-led AI adoption the same way they responded to shadow IT in 2015 and shadow cloud in 2018: with governance frameworks designed to slow the business down until IT can catch up.

It didn't work then. It will not work now.

IBM's internal AI agent, AskHR, replaced hundreds of routine HR roles in 2024. The savings went straight into programmers and salespeople. Total headcount went up. What that tells you is not that AI replaced people — it's that an entire support function compressed down to its minimum viable form, and the organisation redirected the freed capacity to where it actually needed human judgment. The department didn't fight the compression. It accepted it and was better for it.

IT departments that are still trying to own AI agent deployment — building everything centrally, approving every business-unit use case, positioning themselves as the gateway — are doing the equivalent of a travel agency insisting that nobody should book their own flights. The tools have made it possible. The business has the motivation. The argument is over.

The diagnostic question: is your IT department's current AI agenda about enabling business teams to build and run their own agents, or about maintaining IT's position as the builder? Those two agendas are not compatible. Organisations where IT is still primarily the builder will find their business units going around them within twelve months if they haven't already.

Shift Two — Build the Governance Architecture Before the Incidents Force You To

Here is the part of this story that nobody is talking about loudly enough.

68% of employees are currently using AI tools without IT approval. 80% of organisations have already experienced incidents involving AI agents doing something they were not supposed to — data exposed, decisions made on bad inputs, outputs trusted that had no basis for trust. Deloitte's 2026 State of AI in the Enterprise found that only one in five companies has a mature governance model covering how their AI is actually being used. The business teams moved. The governance did not follow.

This is not a technology problem. It is a structural accountability problem. When a business user deploys an agent connected to live customer data, who is responsible if it exposes something it shouldn't? When an AI-generated output is wrong and a decision is made on it, where does the accountability sit? In most organisations right now, the honest answer is: nowhere in particular.

Scania saw this coming. When AI tools started spreading organically across their business units without oversight, they didn't try to shut it down or pull it back under central control. They introduced what they called the Team Mandate — AI access granted to teams collectively, and only to teams that had defined how they would use it before they used it. Shadow AI became structured AI. Business teams kept ownership. IT built the guardrails around them rather than before them. It is the same model we have helped clients build across insurance and financial services operations — governance that follows the business rather than preceding it.

That is the model. Not IT controlling what the business can do. IT building the conditions under which the business can do it without breaking something the organisation can't afford to break.

Shift Three — Become the Function the Organisation Can Blame When Trust Breaks Down

This is the hardest shift because it requires IT to accept an identity that has no glamour in it. Not the builder. Not the innovator. Not the transformation lead. The guardian.

When a business team's agent exposes customer data it shouldn't have touched, someone needs to be accountable. When an AI-generated decision gets challenged in an audit and nobody can explain how it was made, someone needs to own that gap. When three different agents across three different business units are pulling from three different versions of the same data and producing contradictory outputs, someone needs to have seen that coming.

That someone is IT. Not because IT deployed those agents — it probably didn't. But because IT is the function responsible for the conditions under which any of that should have been possible in the first place.

The language most IT departments use to describe their evolving role is so broad it means nothing. "Enabling digital transformation." "Partnering with the business on AI." "Moving from build to enablement." These phrases sound like strategy. They are the absence of strategy.

The IT function that survives this transition will be defined by three things specifically:

Security and access architecture — who is accountable for ensuring that agents deployed across the organisation cannot touch data they have no business touching, cannot be exploited from the outside, and can be shut down cleanly if something goes wrong. As AI agent deployment scales, every agent is a potential exposure point. This is not optional and it is not a project. It is a standing responsibility.

Integration and data integrity — the reason most AI agent deployments fail at scale is not the agent. It is the data underneath it. Incomplete records. Conflicting sources. Systems that were never designed to be read by an autonomous process making consequential decisions. Someone has to own the plumbing — the standards, the pipelines, the data contracts — that determine whether the agents the business builds can actually be trusted. That is IT's job.

Security and access architecture — when the business deploys an agent that makes a decision affecting a customer, a claim, a financial transaction, or a compliance obligation, the organisation needs to be able to explain what happened and why. Audit trails. Explainability frameworks. Escalation protocols for when an agent hits a situation it was not designed for. The business team built the agent. IT builds the infrastructure that makes it defensible.

Business teams measure their own outcomes. That is as it should be — they own the agents, the workflows, and the results those workflows produce. IT's accountability is narrower and more specific: whether the infrastructure those outcomes depend on is trustworthy, auditable, and safe enough to stand behind when something goes wrong.

The diagnostic question: can your IT team point to a named owner for each of those three accountabilities today — not a committee, not a shared responsibility, but a specific person with a defined mandate? If not, the function has not yet made the shift.

IMPLEMENTATION TABLE

Accept execution has moved

What It Looks Like in Practice

IT formally exits the AI agent builder role for business units. Shifts to enablement model. Business units own deployment with IT support.

Effort

Medium — requires leadership decision and internal communication. Biggest cost is cultural, not operational.

Time to Impact

Immediate unblocking of business adoption. Trust rebuilding with business: 3–6 months.

Who Owns It

CIO must make and communicate the call. Cannot be delegated downward.

Build governance architecture

What It Looks Like in Practice

Documented policy on AI agent deployment — data access rules, accountability by role, incident response. Built with business, not imposed on it.

Effort

Medium — two to three workshops to draft, one governance cycle to ratify.

Time to Impact

Incident risk reduction within 30 days of policy adoption.

Who Owns It

CIO and COO jointly. Neither alone will make it stick.

Become the guardian of trust

What It Looks Like in Practice

Named owners assigned for security architecture, data integrity, and explainability infrastructure. Each accountability has a mandate, not just a job title. Reviewed as a standing board-level risk item, not an IT project.

Effort

Low to structure. High to sustain — requires the organisation to hold IT accountable for trust, not activity.

Time to Impact

Reduction in ungoverned AI risk within one quarter. Organisational credibility for IT within six months.

Who Owns It

CEO sets the expectation. CIO owns the delivery. Board holds both accountable.

Where This Lands

I've spent enough time in rooms where IT and the business are talking past each other to know that the problem rarely gets solved in the room. It gets solved when someone with enough authority decides that the current arrangement is costing more than the change would.

The current arrangement — IT departments defending relevance by staying involved in execution while business teams quietly build the capabilities they need anyway — is costing organisations in duplicated effort, ungoverned risk, and the slow erosion of trust between two functions that genuinely need each other.

The IT department is not going away. But it is being asked to be something different. Something smaller in headcount, larger in accountability, and far more precise about what it actually does.

Business teams own the outcomes. IT owns the conditions those outcomes depend on.

The appliance is still there. The electricity still runs. But the facilities team has stopped pretending it built the building.

Conclusion

There is a version of this story that gets told as a crisis. IT is dying. AI is taking over. The department that used to hold the keys is being bypassed, defunded, and quietly made irrelevant by the same business teams it spent two decades serving. I have heard that version in boardrooms, at conferences, in the LinkedIn posts of people who enjoy a good disruption narrative. It is not wrong exactly. It is just not the interesting part. The interesting part — the part most organisations are not yet structurally honest about — is that IT did this to itself. Not through failure. Through fifteen years of doing its job well. Every platform it rolled out, every tool it democratised, every system it handed to the business to run independently moved the organisation one step closer to the day the business stopped needing a gatekeeper. That day is not coming. For most organisations, it already arrived. The question is not what happens to IT. The question is whether IT figures out what it actually is now — before the next incident makes the answer for it.

BETA