IaC Adoption Critical for Secure Enterprise AI Automation, Fleet Research Reveals
A recent report from Fleet Device Management, highlighted by Cybersecurity Insiders, reveals a critical disconnect in enterprise IT strategies: while nearly half (46.5%) of IT leaders are prioritizing AI-driven automation, only 29.6% are concurrently investing in Infrastructure as Code (IaC). This disparity points to a fundamental oversight, as IaC is presented as the essential operational foundation for safely and effectively deploying AI in enterprise IT environments. The research, published in Fleet's 'Road to AI in IT' report, suggests that many organizations are pursuing AI outcomes without first establishing the underlying operational practices, introducing unnecessary operational and security risks.
This matters profoundly to cloud and DevOps practitioners because the promise of AI in automating IT operations—from endpoint management to remediation—cannot be realized securely or efficiently without the governance and control that IaC provides. Mike McNeil, CEO and co-founder of Fleet, emphasizes that IaC transforms AI from a mere chatbot into a force multiplier for IT teams by ensuring every change is reviewed, version-controlled, and reversible. Without this framework, organizations risk deploying AI agents that can make changes without adequate human oversight or rollback capabilities, leading to potential inconsistencies, vulnerabilities, and compliance issues.
The broader context for this finding lies in the accelerating adoption of AI across all facets of technology, coupled with the long-standing principles of DevOps and GitOps. Just as software engineering embraced Git-based workflows to provide guardrails for AI coding assistants, IT organizations need similar machine-readable, version-controlled infrastructure before AI can safely manage operational tasks. The report notes that current operational realities, such as over a day to deploy critical security patches and a lack of complete visibility across device fleets for many organizations, exacerbate these risks. The increasing complexity of device environments and the challenge of managing disruptive changes that cannot easily be rolled back further underscore the need for a robust IaC foundation.
In practice, this means that practitioners should view IaC not as a separate initiative, but as an integral component of any AI automation strategy. Concrete implications include prioritizing the codification of all infrastructure, from cloud resources to endpoint configurations, to ensure that AI agents operate within defined, auditable parameters. Teams should focus on implementing robust Git-based workflows for IaC, enabling human-in-the-loop approvals and clear rollback mechanisms for AI-initiated changes. Furthermore, the report highlights the growing challenge of governing AI itself, with many IT teams having limited visibility into the numerous AI applications running in their environments. By integrating AI operations into an IaC framework, organizations can gain better control, reduce shadow IT risks, and build the trust layer necessary for truly autonomous and secure AI-driven IT operations. Ignoring this foundational step risks chasing AI outcomes without the necessary governance, visibility, and controls, ultimately undermining the very benefits AI promises.
Read original source