How CIOs Build, Buy and Partner to Scale AI Capabilities

28 April 2026 - ID G00853271 - 10 min read
By Stewart Buchanan
CIOs who have never scaled a new AI capability before lack business-domain experience, leading to the costly failure of pilots. This note explains how CIOs evolve from a standard “build-versus-buy” technology decision to capability-driven partnerships that orchestrate work for rapid success, reliability, and long-term governance.

Insights at a Glance


AI often disappoints, not because CIOs built or bought the wrong technologies, but because they bought them without the capability to blend them into their enterprise. Sourcing technology that CIOs cannot orchestrate fails to scale without loss of control, creating AI debt faster than business value.
Key Advice
Treat AI sourcing as an operating model decision rather than a technology purchase. Acquire AI capabilities and partners that you can govern, orchestrate and evolve at scale, otherwise you will accumulate AI debt faster than business value.
Core Insights
  • AI failures start with technology-led sourcing: They embed cost volatility, risk exposure, and dependency in partner choices, contracts and commercial models.
  • A build-versus‑buy decision does not orchestrate work: Buying AI as a technology ignores readiness and mismatches technology with what the enterprise can govern.
  • AI sourcing must focus on business outcomes: Partners contribute significant value in workflow design, trust controls, and long‑term agility by filling gaps in internal capabilities — not just technology delivery.
Recommended Actions
  • Source AI capabilities, not just technology: Choose AI the enterprise can govern, integrate and evolve.
  • Gate sourcing decisions on governance readiness: Require evidence of commercial scalability, flexibility and TRiSM before committing to vendors.
  • Source work orchestration, not dependency: Structure partnerships, contracts, and commercial terms to scale. Agentic AI requires partners offering migration and long-term model operations (ModelOps).

Strategic Planning Assumption


Most agents built before 2028 will need replatforming or rebuilding by 2030, creating demand for partners that provide migration, rightsizing, and long‑term ModelOps and governance services (see The Death of Enterprise Applications Is Greatly Exaggerated).

Impact


Few CIOs can afford the time and expert resources to build their own AI from the ground up. So, partners are a determining factor, not a delivery choice. AI services operate at the intersection between business, technology architectures and operations, as shown in Figure 1. This creates emerging competencies that CIOs must source to blend a well‑governed mix of built and bought capabilities to achieve business outcomes.
Figure 1: Service Partner Capabilities
Core capabilities include data and analytics, software engineering, and business process design, with emerging strengths in insight engineering, AI integration, and work orchestration. AI services unify and enhance these areas for greater impact.
The urgency to partner is driven by disappointing returns on investment when costly pilots fail to scale.1 Buying without an adaptive governance framework creates “agent anarchy” and unmanageable AI debt. General-purpose AI is easy to adopt but falls short at domain-specific tasks. When sourcing technology, organizations risk acquiring powerful tools they cannot govern as they blend both built and bought AI.2 Lack of AI experience often results in overconfidence in IT’s ability to augment and automate work, the key capabilities CIOs need to source.

Actions


Only capability‑led work orchestration scales without loss of control. To effectively scale AI capabilities, CIOs need to orchestrate work and govern partner delivery of business outcomes.
  • Gate sourcing through the AI center of excellence (COE): Protect your credibility and avoid premature commitments by engaging business partners in COE governance to ensure that your organization, its data and partners meet AI goals.
  • Implement capability-driven proofs of value: Proceed only when business stakeholders have defined workflow complexity and decision logic using the agentic use‑case compass. Test governance, trust, risk and security management (TRiSM) and integration capabilities in addition to cost scalability.
  • Evaluate partners on commercial and operational flexibility: Prioritize hybrid commercial models that reflect what the enterprise can realistically govern and operate. Structure contracts through competitive dialogue to align pricing, risk, and delivery commitments with what is technically achievable and governable.

Cautions


  • Partnerships quickly become dependencies without ecosystem-building collaboration clauses: Include commitments for professional services/COE support, co‑development and developer enablement training with SDKs and sandboxes to scale in‑house skills.
  • Watch out for regulatory exposures from IP and data leakage. True partners protect each other’s IP and data, practically and contractually, with indemnities for exposure, opt‑out/data‑use restrictions, ring‑fencing, encryption/confidential computing, audit rights, compliance reporting.
  • There cannot be real partnership without TRiSM integration: Require native governance controls, audit logs, agent registries/intake, red‑teaming support and TRiSM ecosystem integrations (OneTrust, Securiti, Wayfound, etc.).

How to Execute


Engage Business Partners First by Expanding Governance Through the AI Center of Excellence

The CIO’s most complex AI sourcing and vendor management challenge is navigating hype to agree the business objectives and outcomes AI can meet. Both business and technology teams lack experience in applying AI technology within a specific business domain. That is why they need effective partners.
Verify prerequisites, organizational AI readiness and data before engaging vendors to avoid premature commitments, and earn their respect by developing a center of excellence (COE). Before assessing technical solutions, CIOs must enable business units to define their AI ambition by codifying their workflow decision logic and environmental context with a framework such as the agentic use‑case compass (see Innovation Insight: Use the Gartner Agentic Compass for Better Business Outcomes). Two key areas of intersection are identified in Figure 2. The COE needs to build consensus before engaging a partner, for example, between business enterprise and IT. The orchestration of work with AI requires trusted master data, securely shared and maintained among people, processes and technologies.
Figure 2: AI Service Dependencies
Shared services emerge from the intersection of enterprise, IT, and business, while master data is created by aligning people, technology, and process. Effective AI services depend on integrated support and unified data foundations.
To scale AI without creating “agent anarchy,” CIOs must evolve from tool buyers into value orchestrators who govern a complex mix of built and bought capabilities. Success depends on establishing governance through the COE. AI is becoming an embedded enterprise capability with complex pricing and supplier risks; traditional siloed IT procurement is insufficient. When CIOs complain about poor business engagement in AI governance, Gartner often discovers that governance was established without involving business stakeholders. To be effective in vendor partnerships, the COE must play a dedicated, cross‑functional enterprise AI value orchestrator role that serves as the single point of accountability for AI demand, sourcing, economics, innovation and risk, to align decisions to business outcomes.
CIOs need valuable AI partners who contribute their own expertise and excellence to COE orchestration. A competitive dialogue with prospective service providers is often the most effective way to determine what is possible and contractually deliverable. This speeds up traditional request-for-information (RFI) processes. Conducting separate negotiations as the go-between the business and potential service partners creates unnecessary delays and potential misunderstandings. CIOs must move contract negotiations beyond price to mandate native governance controls and safeguards against model drift, security exposure, fragmented adoption, duplicated spend and vendor lock‑in.
  • Establish internal governance and AI readiness as the basis for service provider partnership.
  • Engage business stakeholders to establish shared governance through an AI center of excellence
  • Ground strategic partnerships on the COE’s ability to translate business objectives and architectural intent into enforceable, outcome- and value‑driven contracts.

Implement Rigorous Proofs of Value to Assess AI Orchestration Capabilities for Effective Governance

To orchestrate AI value, a COE needs service partners who empower governance without introducing inflexibility and lock-in. Their ability to integrate additional functionality is essential to preserving business agility. Retain the ability to choose from a continuous flow of new and updated AI offerings while maintaining continuity of service. Your organization cannot afford to flit between service providers as you operationalize AI. To forge lasting partnerships, replace hype‑driven pilots with hard governance gates that prevent proof‑of‑concept stagnation.
  • Turn exploratory pilots into proofs of value (PoVs) as capability‑driven assessments that validate AI orchestration, governance and trust, risk and security management (TRiSM).
  • Ground PoVs in clearly defined business decision logic and workflow assumptions established upfront; where these cannot be validated, PoVs should not proceed.
  • Focus on the top priorities that define a successful partnership, with governance spanning all three emerging capabilities of AI integration, workflow orchestration and insight engineering.
  • Demand vendor TRiSM capability and integration, including native governance controls, audit logs, agent registries/intake, red‑teaming support and integrations with TRiSM ecosystem tools (such as OneTrust, Securiti or Wayfound).

Evaluate Partners on Commercial and Operational Flexibility

In a strategic partnership, it is essential to develop a flexible working relationship that will stand the test of time. Align sourcing and commercial choices to the organization’s actual ability to govern, integrate, and operate AI capabilities, not to default build‑versus‑buy positions. Evaluate service partners on their ability to follow contractual ground rules without building in inflexibility, which often proves more valuable than individual technology features. This includes improving the enterprise’s operational readiness, an important vendor capability that is often overlooked. Prioritize the most manageable commercial models that combine consumption-based pricing with outcome-based milestones and fixed components. But even the most attractive partner can become the hardest to live with when constantly competing for their attention. Partnership can turn into dependency and concentration risk without the deliberate design of an ecosystem of multiple partners.
  • Embed ecosystem and capability‑building clauses, including commitments for co‑development, knowledge transfer, professional services/COE support, and developer enablement (SDKs, sandboxes, and training) to scale in‑house skills.
  • Build mutual trust to protect each other’s IP, data and regulatory exposure both practically and contractually as a prerequisite for partnership and ecosystem building.
  • Require opt‑out/data‑use restrictions, ring‑fencing, encryption/confidential computing, audit rights, indemnities for IP infringement and obligations for compliance reporting.

Success Measures


In addition to measuring business outcomes and operational efficiencies, CIOs should check for sourcing effectiveness at creating and sustaining meaningful AI partnerships:
  • Time to value for pilots: Reduction in the time between initial sourcing and production at scale, indicating fewer stalled pilots and cleaner source to scale transitions.
  • Governance coverage: Percentage of AI agents registered with active drift and security monitoring, proving that governance is embedded from the outset, not retrofitted as an afterthought.
  • Cost predictability: Variance between projected and actual unit consumption costs in hybrid commercial model, to demonstrate alignment between sourcing assumptions and operational reality.
  • Sourcing effectiveness: Use these metrics to measure how successfully new capabilities can be onboarded into the existing ecosystem and scaled.

Evidence


1 Only 22% of IT leaders report that generative AI tools are currently providing “significant value” to their organization, with most stating the tools are only somewhat valuable or yet to realize consistent value.
2 Survey responses show “hybrid blending” as the norm, with 37% of enterprises reporting an “even mix of building in-house and buying off-the-shelf from a provider.” Nineteen percent “build more in-house, buy some off-the-shelf,” and only 5% “build completely in-house.”
2025 Gartner Business Outcomes of Technology Survey. This survey was conducted to understand how industries leverage technologies for various use cases. It assessed investment, deployment and implementation strategies for industry technologies. It also examined key areas intended to be impacted by technology investments, including challenges to realizing business outcomes and industry key performance indicators. The survey was conducted online from June through August 2025. The 648 respondents were from midsize, large and global enterprises from North America, EMEA and Asia/Pacific. The respondents were screened for senior IT and some business leadership roles with technology decision-making responsibilities. Disclaimer: The results of this survey do not represent global findings or the market as a whole, but reflect the sentiments of the respondents and companies surveyed.
2025 Gartner Generative and Agentic AI in Enterprise Applications Survey. This study was conducted to understand the key challenges and opportunities when deploying generative AI (GenAI) tools, and where organizations should focus their AI investments. This research also aims to understand what stage organizations are at on their AI agent journey and their thoughts on AI agents. The research was conducted online from May through June 2025 among 360 respondents from organizations with at least 250 full-time employees across all industries (except IT software) in North America (n = 149), Europe (n = 140) and Asia/Pacific (n = 71). Soft quotas were established for country, company size, and respondent’s function type and job level to ensure a good representation across the sample. Organizations were required to have deployed or plan to deploy in less than one year at least one generative AI tool in at least one core enterprise application domain: digital workplace applications, customer relationship management applications, or enterprise resource planning applications. Respondents were team leaders or above, excluding C level, and involved in the rollout of generative AI tools; they were required to have certain responsibilities regarding these generative AI tools. Disclaimer: The results of this survey do not represent global findings or the market as a whole, but reflect the sentiments of the respondents and companies surveyed.