AI in Organizations: The Model Isn't the Real Hurdle
A Dev.to report from June to September 2026 reveals why banks, law firms, and agencies struggle with AI security, permissions, and costs.

Stock photo for illustration only, not from the actual event
- The main barrier to using AI in enterprises is not the AI model itself.
- Organizations struggle with data access scopes and audit logging controls.
- Most AI connectors assume cloud setups, complicating self-managed deployments.
- Uncapped AI consumption costs make per-agent budgeting difficult.
Over the period between June and September 2026, discussions across engineering forums and professional communities highlighted a major shift in enterprise AI adoption. Banks, accounting firms, law clinics, and IT providers are finding that the core challenge is no longer the capability of the AI model, but the operational layers surrounding it.
Regulatory bodies have established strict boundaries. In June, the IRS Office of Professional Responsibility emphasized that practitioners must handle client data exclusively through secure, enterprise-approved AI tools. Meanwhile, legal professionals note that strict confidentiality ethics prevent them from uploading sensitive files to public cloud tools like ChatGPT.

Stock photo for illustration only, not from the actual event
Another critical bottleneck is identity and access management. When an AI connects to company systems, it typically operates under a single service account rather than the individual user. This breaks information barriers in banks or ethical walls in law firms. Cost predictability also remains an issue, with M365 administrators reporting users consuming up to 71,000 credits in a single month without effective per-agent spending caps.
"Until we can build and deploy our own agents in a fully gapped environment, 9/10 projects in my org can't use them."
Government security practitioner
In highly regulated sectors, the push toward on-premise or self-managed deployments often clashes with vendor software designed primarily for the cloud. Furthermore, giving third-party developers network access for integration is a non-starter for security teams, meaning AI tools must ultimately run entirely within a firm's own local infrastructure under strict internal control.
Smaller firms also face software licensing hurdles, such as tax software agreements restricting automated interactions, making custom development an impractical trade-off compared to waiting for upcoming commercial compliance tools.
Source: Dev.to
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment