Council Post: ​AI Is Dominating IT Budgets: Are You Making The Right Cuts?

David Bennett, CEO, Object First.

getty

AI is continuing to dominate enterprise technology conversations and IT budgets. Organizations are integrating new AI use cases while grappling with how to measure and govern AI safely and effectively, train their workforce on these new tools and prove ROI to stakeholders who increasingly expect AI to be part of every business strategy. IT teams sit at the center of all these decisions, from rolling out new AI tools to setting up guardrails around what models can access and what actions they can take.

That work is necessary. The argument for most companies is not whether they should invest in AI, but rather how they can do so without weakening the systems that keep the business running. Gartner predicts global IT spending will rise 13.5% in 2026, but this spend disproportionately favors AI and data centers over other areas. AI investment is not simply adding another line item to the IT budget. In many organizations, it is reshaping priorities and forcing leaders to decide which projects can be delayed, reduced or cut. In fact, over half (53%) of leaders say AI pulls budget away from other IT initiatives.

The stakes are high. If leaders pull too much funding away from foundational cyber resilience, their organizations can become vulnerable to debilitating cyberattacks at a time when AI is empowering cybercriminals with new, faster and more sophisticated forms of attacks. Lost data and operational downtime from such attacks can make or break a business. Business interruption remains the single largest driver of cyber insurance claim severity. These interruptions are, on average, 650% more costly than nonbusiness interruption claims.

The most important consideration for CIOs and security leaders is not whether AI deserves investment. It does. The question is whether AI spending is being balanced against the infrastructure that ensures your business remains standing when a cyberattack tries to bring everything crumbling down. In that equation, a consistent and resilient backup strategy should not be treated as optional.

AI Raises The Stakes For Business Resilience​

Our 2026 World Backup Day survey polled 500 IT and security workers. We found that 89% are scared that AI-powered cyber threats will put their organization’s data in jeopardy, and only 53% are very confident in their ability to quickly recover their data from a ransomware incident.​

That confidence gap should concern business leaders. Cybersecurity strategy is often framed around detection and prevention, but resilience depends on what happens after an attacker gets through. Immutable backup storage—digital vaults that secure data by ensuring it cannot be modified or deleted once it has been backed up, even by the most privileged admin—can determine whether an organization can restore operations, protect critical data and reduce the leverage attackers have during a ransomware event.​

As AI-generated threats proliferate, security teams may feel pressure to adopt a host of new cybersecurity technologies. Some of those tools will be valuable. However, in the process, they may deprioritize zero-trust security practices at the exact moment these principles are more critical than ever to make recovery possible. AI may change the speed and sophistication of attacks, but it does not eliminate the need for zero-trust principles, immutable backup, recovery testing and clear data restoration processes.​

Between the constant barrage of cyberattacks and the massive increase in data available—AI is expected to create more data in just three years than ever before, according to the Hinrich Foundation's recent report, as cited by Anadolu Agency—front-line technology workers are facing mounting pressure. CIOs will need to support AI adoption. IT teams will need to build or integrate new tools. Security teams will need to understand how AI changes data access, identity risk, threat detection and governance.​

Even the flashiest and most advanced cybersecurity detection and protection solutions are fallible. They’re not the magic bullets they’re often touted as, and the rise of AI-generated threats has only exacerbated that fact. A winning resilience strategy is built on the zero-trust assumption that some attacks will succeed and that the organization must be prepared to recover quickly when they do. That mindset does not diminish the value of prevention. It puts prevention in the right context: It's one layer in a broader continuity strategy.​

The Bottom Line​

Data administration and recovery should not sit on the back burner. However, it shouldn’t consume so much operational effort that IT teams have no capacity for strategic work. Organizations should seek out security and backup approaches that are deeply integrated, easy to operate and do not require much oversight or cost to run. The goal is to strengthen resilience without requiring excessive manual oversight or diverting scarce specialists away from AI and other business-critical initiatives.​

For CIOs and security leaders, budget decisions should be framed around business continuity. AI can create new value, but only if the organization remains stable enough to capture it. Immutable backups are not a legacy concern. They are the operational foundation that determines how well a company can withstand ransomware, insider threats, human error and data loss.​

Data protection and cyber resilience are far too often a checkbox for C-suite leaders, deprioritized in favor of flashy protection tools or AI use cases. But when a ransomware attack, insider threat or human error destroys the lifeblood of the business—its data—the only thing that truly matters is recovery.​

AI deserves a place in the IT budget. So does the infrastructure that keeps the business standing when something goes wrong.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?