By The Chiri Team
Ask a technology leader what is stopping the company from scaling AI. Almost four in five will not say the model.
A new Google Cloud report puts a number on a shift that many buyers have already made in private. Security, governance, and operations now sit at the top of the list of blockers to scaling AI inference. Model quality does not. The industry has told itself a story for two years. The story says the race is about capability, and the winner ships the smartest model first. The finding corrects that story. Buyers stopped believing it before most vendors noticed.
The numbers behind the shift
Google Cloud’s report, “State of AI Infrastructure Report: Agent Governance and Security,” published August 24, 2026, surveys technology leaders on what actually blocks AI programs from scaling. Three findings define the shift.
Seventy-nine percent of tech leaders cite security, governance, or operations as their most significant challenge to scaling inference. That is not a rounding error against model capability. It is a near-consensus that the constraint has moved somewhere else.
Thirty-five percent of senior IT decision makers cite insufficient security for multi-system access as a primary issue preventing agentic deployment. An agent that can only read one system is safe and mostly useless. An agent that can act across a customer database, a finance tool, and an internal wiki is useful. Without the right controls, it is also a liability. That gap is where deployments stall.
Sixty-nine percent of surveyed executives now rate a full-stack platform as a critical requirement. Eighty percent say data compliance is the primary factor dictating that choice. Buyers are not asking for a better model wrapped in a nicer interface. They are asking for a platform that can prove what an agent touched, and show why the agent was allowed to touch it.
What changed is the question, not the technology
Two years ago, a buyer evaluation meeting centered on a leaderboard. Which model reasons better. Which model hallucinates less. Which model costs less per token. Those questions have not disappeared. They no longer decide the deal.
The report shows a buyer base that has moved on to a harder question: who is accountable when an agent touches a sensitive system. That question has no leaderboard answer. It has an architecture answer, an access-control answer, an audit-log answer. A vendor with the best model, and no answer to that question, now loses deals. Eighteen months ago, that same vendor would have won them.
This is not a story about buyers getting more cautious for its own sake. It is a story about what has become scarce. Model output used to be the scarce thing. Governed access to real systems is now the scarce thing, and the survey numbers confirm it. Data compliance drives 80% of the full-stack requirement for a specific reason. Compliance is where the accountability question gets tested first. It shows up in an audit, a breach postmortem, or a regulator’s request for logs.
Not every AI workload carries the same requirements
Chiri’s own reading of the infrastructure market rests on a distinction the model race obscures. Different categories of AI work carry different real requirements. A developer using a coding assistant works inside a narrow, well-understood task with clear pass or fail criteria. A finance team asking an agent to reconcile vendor invoices, or an HR team asking an agent to pull data across three systems to answer a compliance question, works inside the operational core of the business.
That second category is exactly the workload the Google Cloud numbers describe. The 35% who cite insufficient multi-system access security are not talking about a coding copilot. They are talking about an agent working across systems that were never built with agent access in mind.
A governed, full-stack platform earns its place at exactly this layer, over the non-coding, day-to-day operational work most vendor roadmaps treat as an afterthought. The survey shows this is the layer buyers now evaluate first, ahead of raw model quality.
What full-stack governance actually covers
The 69% figure is easy to agree with in principle. It gets harder once a buyer has to define what “full-stack” covers in an actual deployment. Three areas keep surfacing, and each one maps to a specific fear behind the survey numbers.
The first area is infrastructure posture. Before an agent runs, the systems it can reach need a known, checked state. Encryption should be on. Storage should not be public. Credentials should rotate on a schedule instead of sitting stale for years. That coverage now has to extend to the systems an agent can reach, alongside the systems a person can reach.
The second area is code validation. Agents increasingly write and change code, including infrastructure code that provisions and configures systems. That code needs a security review before it ships, the same way a human engineer’s pull request does.
The third area is input and output validation. This layer checks what an agent receives, and what it is about to do, against a set of rules. It is the layer that answers the 35% figure directly. A team can grant an agent access to multiple systems this way, without granting it unlimited trust in any of them. If one agent gets compromised, the right architecture isolates that one agent instead of shutting down the whole environment.
These three areas, together, are what “full-stack” means to the 69% of executives who now call it a critical requirement. None of the three is a model problem. All three are governance and operations problems, which is exactly what the Google Cloud survey found sitting ahead of capability.
The accountability layer is what buyers are actually pricing
A basic AI product has gotten cheap to build, using models available to any team. Product alone is no longer, by itself, a defensible position. What stays hard to replicate is the governed layer underneath a product: the access controls, the audit trail, and the accountability that lets a business stand behind what an agent did.
Every agent deserves the same baseline treatment as a new employee. It needs defined access controls. It needs a system of action that records what it touched. If something goes wrong, the failure should stay contained to that one agent instead of spreading across the environment. That framing matches what survey respondents describe. They name security and governance, ahead of capability, as the barrier to scaling.
The person who signs off on an agent deployment is rarely the person who selected the model. That person wants to know who is accountable if the agent touches the wrong system. Under the Google Cloud findings, that question is what decides the deal now, not a benchmark score.
Where this leaves the rest of the market
Most AI vendors built their pitch around the model: a faster model, a cheaper model, a model with a longer context window. That pitch answered a question buyers were asking in 2024. It does not answer the question 79% of tech leaders now name as their biggest blocker.
A vendor needs an access-control map, an audit trail, and a compliance answer to compete for these deals. Without those three, the vendor is left competing for a smaller set of deals, where governance has not yet become the gate. That smaller set keeps shrinking, if the report’s own trend line holds.
The platforms built for this moment share three traits the survey implies, without listing them as a checklist. They govern access across systems, instead of trusting a single API key. They log what an agent did, in language a compliance officer can read. They price and sell the full stack as the product. The model becomes one component inside it, not the whole offer.
This lands differently depending on where you sit
CEOs see a buying committee that has already changed its criteria. A pitch built around model capability now answers the wrong question in the room. The pitch needs to open with accountability and governance, then let capability follow as proof.
CIOs and CISOs see validation for a position many of them have held for a year. Security and compliance are not a late-stage checkbox on an AI deployment. They are the first gate a vendor has to clear. The 80% figure on data compliance gives that position a number to cite internally.
CTOs see a technical requirement, not a marketing claim. Multi-system access control, audit logging, and blast-radius containment have to exist in the architecture. They have to exist before an agent goes near a production system. The 35% figure names insufficient security as the primary blocker for a reason.
CHROs and operations leaders see a workforce question underneath the infrastructure question. The agents stalled by weak security and governance handle operational and administrative work in most companies. That work is meant to free people for judgment-heavy tasks. A stalled deployment is stalled capacity, as much as it is a stalled project.
Procurement and finance leaders see a pricing signal. Sixty-nine percent of executives call a full-stack platform a critical requirement. A point solution priced like a model wrapper is mispriced twice over against that number. It is underpriced for what buyers actually want to purchase. It is overpriced for what it can deliver on governance alone.
The constraint on AI has moved from what a model can do to who is accountable when it acts. What does an organization’s own buying process still evaluate as though the old constraint were still in force?
