Most organizations still pick a security framework the way they did in 2022: find the biggest name, check the box, move on. That approach hasn’t survived contact with the last three years, three new regulations, a finalized quantum-cryptography standard, and an entirely new AI threat surface later.

The current situation: A framework landscape transformed since 2022

Choosing the right security framework has never been more consequential or more complex. When IDC last published comprehensive guidance on this topic in 2022, the landscape was manageable: a stable set of well-known frameworks and a relatively predictable regulatory backdrop. The intervening years have fundamentally changed both dimensions.

Four structural shifts now define what buyers must navigate:

  • NIST CSF 2.0 (February 2024) introduced a formal Govern function, its first major revision in a decade, elevating cybersecurity from an operational discipline to a board governance obligation and broadening scope to all organizations regardless of size or sector.
  • DORA (EU 2022/2554) became fully applicable in January 2025, imposing mandatory ICT risk management and third-party oversight obligations on approximately 22,000 EU financial entities.
  • PQC standards were finalized: NIST released three post-quantum cryptography standards in August 2024 (FIPS 203, 204, 205), transforming quantum readiness from a theoretical concern to an operational imperative.
  • AI has created a new risk surface: NIST published a draft Cyber AI Profile (IR 8596) in December 2025, extending CSF 2.0 specifically to AI-related cybersecurity risks. Organizations that have deployed AI, particularly agentic AI or LLM-integrated workflows, must now factor AI governance into framework selection.

The wrong framework choice, one that exceeds organizational maturity, understates regulatory obligation, or ignores supply chain exposure, produces worse security outcomes than a well-adopted, properly scoped, simpler framework. The good news: there are strong options. The challenge: the decision is more complex than it was three years ago.

Decision-making criteria and methodology

Security framework selection is a risk management decision, not a technical checklist, requiring input from legal, compliance, finance, operations, and the board. IDC’s 2026 methodology starts with crown-jewel data classification, then splits into regulated and non-regulated tracks, now including universal AI governance and quantum-readiness branches. Key criteria include data classification, regulatory obligations, threat landscape, and AI adoption footprint. Organizations deploying agentic AI face risks that general-purpose frameworks don’t address, while harvest-now-decrypt-later (HNDL) exposure demands cryptographic roadmap planning alongside traditional control mapping.

Additional criteria round out the methodology: third-party risk (CSF 2.0’s Govern function and DORA Article 28 set the compliance floor), PQC readiness (FIPS 203-205 are finalized, with 2030 as a planning horizon), and organizational maturity (smaller organizations should start with CIS Controls IG1 rather than overreaching). Budget discipline favors phased, risk-prioritized roadmaps supported by cyber risk quantification. Finally, multi-framework interoperability and GRC technology support are now prerequisites: manual evidence collection across concurrent regimes such as CSF 2.0, ISO 27001, HIPAA, and DORA is no longer sustainable at scale.

Regulated versus non-regulated organizations: Two different journeys

Regulated organizations

For regulated organizations, the regulator largely determines the framework; strategic focus shifts to execution. Key questions: How can multiple simultaneous requirements (DORA + ISO 27001; HIPAA + NIST 800-53) be satisfied without duplicating evidence work? Which GRC platform best automates cross-framework mapping? How should gap closure be sequenced within the budget? Have ICT third-party providers been assessed against CSF 2.0 Govern, DORA Article 28, and NIST 800-161? Mature organizations typically adopt a “framework stack”: CSF 2.0 or ISO 27001 as backbone, NIST 800-161 for high-risk vendors, plus industry-specific overlays.

Non-regulated organizations

Non-regulated organizations must perform more active analysis, with the right starting point depending on maturity. Early-stage or SMB organizations should adopt CIS Controls v8 Implementation Group 1, 56 safeguards achievable with limited staff, mapped to NIST CSF 2.0 for growth. Mature programs or those facing elevated threat exposure should adopt NIST CSF 2.0 or ISO 27001:2022, both of which include a Govern function that supports board-level accountability and SEC disclosure readiness. All non-regulated organizations, regardless of status, should evaluate the AI Governance and Quantum Readiness branches given their present-day risk implications.

AI and quantum: Two criteria that didn’t exist in 2022

Artificial intelligence: risk surface and governance obligation

AI has added two urgent dimensions to the framework selection process. Offensively, adversaries use LLMs for convincing phishing, automated vulnerability discovery, and direct attacks via model poisoning and prompt injection. Assess whether your framework addresses AI-enabled detection and response. Defensively, organizations deploying AI in production, especially autonomous agentic AI, face authorization, auditability, model integrity, and supply chain risks that general-purpose frameworks don’t address. The NIST Cyber AI Profile (IR 8596, December 2025 draft) extends CSF 2.0 across three risk areas and should serve as a supplementary governance layer. Shadow AI and SaaS-embedded AI remain largely unmeasured exposures requiring dedicated governance tooling.

Post-quantum cryptography: from theory to operational imperative

PQC standards are finalized: NIST published FIPS 203, 204, and 205 in August 2024, with a fourth HQC-based standard selected in March 2025. The harvest-now-decrypt-later threat is present today: adversaries are collecting encrypted data now to decrypt once quantum computing matures, creating real exposure for organizations holding financial, healthcare, or critical infrastructure data. NSA’s CNSA 2.0 mandates 2030 migration for National Security Systems; commercial organizations should treat this as a planning horizon, not a start date. Immediate actions include completing a cryptographic inventory, prioritizing long-lived data systems, evaluating vendor PQC roadmaps, and considering hybrid cryptographic approaches.

Essential guidance for the technology buyer

A well-adopted, properly scoped framework always outperforms a theoretically superior one that exceeds organizational capacity. Buyers should structure stakeholder conversations, including legal, compliance, finance, and the board, around the 10 decision criteria, treating AI governance and PQC readiness as first-order, not future-state, considerations. Conduct a cryptographic inventory now and evaluate AI footprint against the NIST Cyber AI Profile. Address third-party risk per CSF 2.0, NIST 800-161, and DORA Article 28. Favor frameworks with strong cross-mapping, invest in automated GRC technology, and adopt cyber risk quantification for CFO-ready budget conversations. Build a phased, five-year roadmap, closing highest-risk gaps first, and recalibrate annually.

“The right security framework is a critical factor in adequately managing security risks, not only those present today, but also those that could emerge in the future. The 2026 landscape demands that organizations evaluate AI governance and post-quantum cryptography readiness as first-order criteria, not future-state considerations.”Philip D. Harris, Research Director, Cybersecurity GRC Solutions, IDC

Guidance for the technology supplier and services provider

The security framework market is in structural transition, and suppliers calibrated to 2022 are selling into a market that no longer exists. Multi-framework compliance automation is now the dominant selection criterion, making unified control libraries across CSF 2.0, ISO 27001, HIPAA, and DORA essential. Suppliers should build DORA as a named capability, establish AI governance credibility now while the Cyber AI Profile remains in draft, and develop a PQC advisory practice anchored to cryptographic inventory services. Value propositions should be reframed financially for CFO-influenced procurement, while midmarket buyers increasingly favor managed compliance wrappers. Roadmap priorities span CSF 2.0/DORA now, Cyber AI Profile alignment in 2027, and full PQC/EU CRA support by 2030.

Philip D. Harris, CISSP, CCSK

Philip D. Harris, CISSP, CCSK - Research Director, Governance, Risk, and Compliance (GRC) Solutions

Phil Harris is Research Director for GRC Solutions at IDC, where he develops and promotes IDC's point of view on risk, advisory, privacy, and compliance services and software. He conducts research on business strategies and the impact of relevant offerings…

Global spending on digital transformation (DX) software is on pace to hit $640 billion by 2029, and where that money goes is shifting fast. IDC’s latest Worldwide Digital Transformation Spending Guide shows AI pulling value out of infrastructure and into applications, with the pace of that shift varying sharply by sector.

Software is becoming the primary engine of digital transformation

Digital transformation (DX) is the broad shift by organizations to embed technology into every layer of their operations, customer experiences, and business models. It spans hardware, services, and software. Data shows software is increasingly where DX investment is concentrating.

Among the three technology groups that make up DX spending, software is the fastest growing. Its share of total DX spend rises from 32% in 2026 to 36% by 2029, with a 21.7% CAGR, leading both services (10.6% CAGR) and hardware (19.8% CAGR). This momentum is increasingly driven by the scaling of AI, which is rapidly shifting value from infrastructure into applications and accelerating demand for AI powered software capabilities.

By 2029, AI will account for roughly 40% of worldwide DX software investment, which is a significant shift from today. The other 60% still flows into business applications, system infrastructure, and development and deployment platforms. The AI investments showing up across every sector in this analysis do not stand alone. They run on top of foundational layers already in place, and in many cases they depend on those layers to deliver value at all. Across the six sectors, the pace of AI adoption varies considerably, and that variation tracks closely with how mature the underlying software stack already is. AI is coming everywhere, but it is arriving on top of what organizations have already built.

Six sectors. Significant scale. Different priorities.

IDC’s Worldwide Digital Transformation Spending Guide (V1 2026) tracks DX software spend across six major industry sectors. Overall software investment is growing strongly in all six, and AI’s share within it is rising – but the pace, scale, and use case priorities differ considerably by sector. What drives DX spending in retail and services is not what drives manufacturing or financial services. Sector context matters.

“The growth in DX software is broad-based. This is not simply an AI spending wave. Organizations are investing across the full software stack to transform how they operate, and AI is an accelerating part of that — not the whole of it.”Mariya Yahnyuk, Research Analyst, Data and Analytics

#1 Retail and services

The Retail and Services sector leads all sectors in total DX software spend. This sector covers both retailers and a range of activities such as hospitality, travel, services, and more. Customer management tops the list of investment priorities: engaging customers across every channel, in real time, with personalized and consistent experiences. Omnichannel commerce and service delivery platforms come second, as both retailers and service providers now operate across physical, digital, and mobile simultaneously.

The third priority is operational intelligence: energy management, workforce scheduling, and efficiency tools that apply equally to store environments and service operations. Many of these investments sit in the applications and infrastructure layers of DX software – the customer data platforms, workforce systems, and integration layers that make AI useful when it arrives. AI is projected to grow to 42% of this sector’s DX software spend by 2029, building directly on that operational foundation.

#2 Financial services

Financial services have the highest existing AI share of any sector, and the broader DX investment picture explains why it got there. Security leads the use case list: detecting cyber threats and preventing fraud are areas where software investment delivers clear, measurable returns, making them natural anchors for DX spending early. Automating core business operations comes next, as financial institutions replace manual, rules-based processes with systems that can adapt and scale.

The pattern here is integration. AI is being built into existing DX programs, the same core applications and infrastructure platforms institutions have been modernizing for years. That is why the spending is sustaining: it is tied to operational outcomes that financial institutions already care about.

#3 Manufacturing and resources

Manufacturing currently has the lowest AI share of any sector in DX terms, which also makes it one of the most interesting to watch. DX investment here is driven by very practical pressures: aging equipment, fewer experienced engineers, and increasingly complex supply chains. The largest spending area is autonomic operations, production environments moving toward systems that can monitor and adjust on their own, recovering from most faults without needing a person in the loop.

Self-healing assets and augmented maintenance follow closely. A third priority, less obvious but growing, is customer and client management: manufacturers are increasingly investing to understand and serve end customers directly, not just to optimize internal operations. Together, these priorities describe a sector using DX investment to reduce operational risk, extend asset life, and build closer market relationships.

“Manufacturing’s lower AI share today should not be read as lower ambition. The use cases driving DX investment are autonomic operations, asset health, customer proximity, that’s exactly where AI delivers durable, measurable value. The growth trajectory reflects that.” —Mariya Yahnyuk, Research Analyst, Data and Analytics

Three actions for technology providers

The DX software data carries clear implications for technology vendors and platform providers. These are not passive trends to monitor – they are signals that should shape how you position, sell, and support your customers.

Help your customers understand where they stand. Most organizations do not have a clear view of how their software investment compares to peers in their sector. Use sector-level DX spending data to show them where investment is concentrating, where they may be behind, and what use cases are driving results for similar organizations. Then recommend tools that fit where they are in their journey.

Make the case for platform integration using evidence. Organizations that rely on fragmented point solutions face growing complexity as DX programs scale, and slower AI outcomes as a result. Many of your customers have not made that connection yet. Use the spending data trends to show them concretely that platform integration is delivering better results and why consolidation is the more practical path forward.

Treat data readiness as a customer success issue, not a prerequisite. DX outcomes and AI outcomes depend on the quality and accessibility of underlying data. Offer data quality and governance support as part of the engagement, so customers build data readiness while the work is underway.

Want the full picture?

This analysis draws on IDC’s Worldwide Digital Transformation Spending Guide (V1 2026), which covers DX investment across all six industry sectors, further detailed by 27 industries, 12 technology markets, and geographies through 2029. The full research covers Healthcare, Infrastructure and Energy, and Public Sector in depth alongside the three sectors featured here.

Mariya Yahnyuk

Mariya Yahnyuk - Research Analyst, Data and Analytics

Mariya Yahnyuk has been a research analyst in IDC’s Worldwide Data and Analytics team since 2022. Yaknyuk supports the development of IDC's Spending Guide portfolio, assuring alignment with technology and market changes, relevancy, and business value for customers Mariya directly…

Key questions answered in this article: What is the AI supercycle and what does it mean for Japan? What are the biggest gaps between AI vendors and enterprise buyers in Japan? How is AI changing B2B technology buying decisions?

The energy in the room at IDC Directions Tokyo 2026 on June 23 said it all: Japan’s AI moment is no longer approaching — it has arrived. And the central message from IDC’s Senior Vice President Sandra Ng was both a wake-up call and a roadmap. The question, as she put it bluntly, is not whether AI will reshape the Japan market. It is: who will create the most value in the shortest time?

IDC Directions Tokyo 2026 brought together close to 400 attendees, with 65% at Director level or above, a room full of decision-makers, not just observers. Analyst 1-on-1 sessions were fully booked, and the volume of questions from the floor made one thing clear: the conversation was hitting a nerve.

The Supercycle Is Real and Japan Is Playing Catch-Up

To understand the scale of what is happening, consider this: global IT spending in 2025 is growing at 14% on a $4.2 trillion market base, the strongest IT spending growth since 1996. Back then, that same 14% growth rate applied to a $700 billion market. The numbers are in a different league entirely. (Source: IDC Worldwide Black Book, 31 March 2026)

This is the AI supercycle. While regions like China, Taiwan, and India are racing ahead as “AI Superpower Built-Outs” or “Digital Native Scalers,” IDC positions Japan alongside Korea as a Legacy Modernizer, a market where the path to AI value runs directly through modernization. That is not a disadvantage. It is a specific strategic imperative.

Japan’s AI market reflects this momentum. Domestic AI infrastructure spend is expected to reach $9 billion by end of 2026, growing at a 24% CAGR through 2029. AI services are projected to hit $8 billion by 2030 or 3.2x the 2025 figure. Moreover, 61% of CEOs in Asia Pacific named agentic and generative AI at scale as their number-one new investment priority. (Source: IDC Worldwide AI and Generative AI Spending Guide, Forecast V1 2026; IDC CEO Survey, March 2026)

The Vendor-Buyer Disconnect Is Costing Everyone

Here is where the conversation got uncomfortable and important.

Sandra Ng identified four persistent gaps between what enterprise buyers in Japan need and what technology vendors are actually delivering:

Gap #1 — Business case clarity. Buyers want outcomes grounded in their industry, not generic global benchmarks. “Show me what this looks like for a Japanese manufacturer” is a very different ask from a global case study slide.

Gap #2 — Total cost of AI ownership. This one deserves more attention than it typically gets. Hidden AI implementation costs in Japan — covering data preparation, system integration, ongoing model maintenance, compliance monitoring with METI guidelines, and change management, routinely add 50–70% beyond the headline technology price. Vendors who do not address this upfront are losing trust at the CFO conversation.

Gap #3 — AI governance readiness. Japan’s regulatory environment is real and specific. The FSA AI guidance, METI’s AI governance framework, and the Act on Protection of Personal Information (APPI) set high standards. Buyers are moving faster than many vendors’ governance answers can keep up.

Gap #4 — The “show me” moment. Japanese enterprise buyers want a local reference customer, a deployment timeline, and measurable outcomes, not a global success story. Vendors who cannot produce this are losing shortlist positions.

What Japan’s Leading Enterprises Are Actually Doing

These gaps are not theoretical. IDC’s CxO conversations in 2025–2026 point to concrete examples of how Japan’s most forward-thinking companies are navigating them:

  • Toyota built a proprietary in-house AI platform with a hyperscaler partner, saving 10,000 hours of manual work annually and documenting a 25% reduction in paint defects through AI-assisted quality systems.
  • Tokio Marine responded to METI and FSA guidance by publishing a 5-pillar AI governance policy first, covering transparency, human oversight, bias elimination, data protection, and operational reliability, before deploying AI for document and image analysis. Governance policy first, deployment second—this is the sequence Japan’s regulators now expect.
  • Yamato Transport used AI-driven supply chain optimization across 1.6 million corporate customers and 4,000+ logistics partners, targeting a 65% reduction in labor costs and a 42% cut in GHG emissions by optimizing relay points across 80 routes.

These are not pilots. These are production deployments with documented outcomes—exactly the reference stories buyers are demanding.

Your Buyers Are Already Using AI to Research You

One of the most striking data points from Sandra Ng’s presentation is that 84% of global technology buyers agree that AI will change how their companies buy technology in the next 12 months. (Source: IDC B2B Technology Buyer Survey 2025, WW n=406)

The buying journey has already shifted and it looks like this: AI discovery → vendor website check → peer and colleague validation → channel partner consultation → shortlist. If your brand and solutions do not surface clearly when a CIO or CFO uses ChatGPT or Google Gemini to research a purchase decision, you are being eliminated before you even know you are in the running.

This makes Answer Engine Optimization (AEO) and Generative Engine Optimization (GEO) business-critical capabilities, not just marketing experiments. By 2027, 35% of Japanese organizations are projected to have unified, coordinated AI governance in place. The vendors who are visible, credible, and well-structured in AI-generated answers will have a compounding advantage. (Source: IDC FutureScape 2026 – AI-Fueled Business Strategies, Japan)

Agentic AI: The Next Competitive Frontier

The broader industry shift reinforces why speed matters. As highlighted in the presentation by IDC Japan’s Takuya Uemura, the AI supercycle is now entering its second investment wave — moving from infrastructure build-out to enterprise application and services adoption. Enterprise AI platform, app, and services spend globally is projected to grow from $400 billion in 2026 to $1 trillion by 2029. (Source: IDC Worldwide AI and Generative AI Spending Guide V1 2026)

Critically, 83% of buyers surveyed agreed that AI agents are lowering switching barriers between suppliers. The vendors who lock in outcome-based relationships now, before the market commoditizes, will be the ones defining the next competitive moat.

Three Moves That Matter Right Now

Sandra Ng’s closing framework was direct and actionable:

Do now: Replace generic benchmarks with a single Japan reference customer, one metric, one timeline. Map your go-to-market pitch to the full buying committee, not just the CIO. Fix your AI discoverability gap immediately.

Do this year: Make ROI transparency your competitive weapon. Build deployable agentic workflow stories. Invest in AI-optimized third-party content that earns citations in AI-generated answers.

Bet on this: Position into AI governance, trust, and compliance as a revenue line, or become the vendor that makes compliance an outcome rather than a conversation. Start measuring your share of answer by category, persona, and geography. Execute a layered discovery strategy: SEO + AEO + GEO. (Source: IDC C-suite Survey, September 2025, APJ, n= 300)

Japan’s AI Supercycle Will Not Wait

The window to establish leadership positioning in Japan’s AI market is open—but it will not stay open indefinitely. The enterprises that move from experimentation to outcome-based deployment, the vendors who close the four gaps, and the organizations that make themselves discoverable in AI-powered buying journeys are the ones who will define the next era of Japan’s technology market.

The conversation that started in Tokyo continues in Osaka.

Join us at IDC Directions Osaka on July 28, 2026 to go deeper on how Japan’s AI supercycle is reshaping your industry, what the data says about where the next wave of value will be created, and how your organization can get ahead of it. Register for IDC Directions Osaka today. Seats are limited.

Mike de la Cruz - Corporate Communications Director - IDC Asia/Pacific

Mike de la Cruz is Corporate Communications Director for Asia Pacific at IDC, bringing over 25 years of career experience in marketing and communications for the information technology industry. He shapes and amplifies IDC's research-driven narratives, positions executives and analysts as authoritative industry voices, builds relationships with top-tier technology and business media across the region, ensures consistent brand voice and positioning, develops content that drives audience engagement, and leverages social media and digital communications to extend IDC's reach.

国际数据公司(IDC)最新研究显示,AI超级周期带来的不仅是技术代际的更迭,更是一场深层次的组织范式变革。以智能体为核心驱动力的新型生产力形态——OPX(One-Person X),正在悄悄影响传统的企业组织逻辑,并对PC等终端硬件市场产生结构性的拉动效应。

AI超级周期下的组织重构

以智能体为代表的AI超级周期带来的不仅是技术迭代,更是一场生产力供给的结构性变革。当智能体从“辅助工具”进化为能够独立执行与产出的“生产力单元”,组织形态的底层逻辑必然随之重构。国际数据公司(IDC)最新研究将这一变化命名为OPX(One-Person X)——AI时代以单人为核心决策单元的新型组织范式,其核心共识可概括为:少数人负责决策与价值判断,AI智能体集群承担执行与产出

基于这一框架,OPX下辖两种落地形态:OPC(One-Person Company),即以个人为核心决策者、AI智能体为生产力引擎的企业级组织形态;OPE(One-Person Expert),面向个人专业服务领域。其中,OPC是AI重构商业组织最具颠覆性的形态。IDC对其的定义是:以个人为核心决策者,AI智能体/工具为核心生产力,至少可在单一任务环节独立完成业务,人工负责审核、判断与异常处理,最终实现传统需多人团队才能完成的商业闭环。从组织规模看,OPC可以是1个人,也可以是10人以内的轻量化团队

OPX的运作模式催生了一套独特的硬件需求:7×24小时不间断运行(无专职运维,中断即停业)、全生命周期高性价比(设备与算力成本均需可控)、端到端自动化闭环(任务接收、拆解、执行无需人工干预)、多设备无缝协同(跨终端业务连续性刚需)、无人值守下的远程管理与自进化,以及数据隐私与端侧主权保护。在这一需求图谱中,手机承担移动交互,云端提供弹性算力,而本地AI推理、多任务编排与端侧数据保护均依赖本地算力这使得PC设备,尤其是AI PC、AI主机设备,正成为OPX工作流的本地中枢。

OPX驱动的PC出货量近160万台

根据 IDC 最新预测,2026 年中国 PC 市场总出货量约为 4,038万台,同比微降 6.1%,整体大盘小幅收缩。但在结构层面,以 OPX(一人公司/超级个体)范式驱动的 PC 需求正在形成一个独立的增长极。IDC预测,2026年由OPX驱动的PC市场出货量近160万台。

IDC 认为,OPX 对 PC 市场的拉动效应正在经历从 “边缘增量”到”结构性力量” 的转变。尽管 160万的出货量仍属早期,但考虑到 OPX 的增速逻辑,即存量企业业务扩张、设备换机周期叠加、AI Native 工具链持续成熟。这一力量的上升值得重点关注。我们判断,OPX 有望在未来 3-5 年内成为 PC 市场增长叙事中不可绕过的结构性变量。

OPX对PC市场的影响集中体现在两个核心维度:采购逻辑的多元化和换机节奏的两极分化。首先,采购逻辑正在走向多元化。传统企业PC采购长期由人员规模驱动,OPX则打破了这种一一对应关系,设备需求开始更多地由任务负载而非人头数定义,一个创业者同时运行多台设备处理不同任务流的情况在特定场景下已成为现实。其次,OPX的换机节奏呈现两极分化态势。驱动快速换机一侧的力量来自OPX业务机会的不可预见性,当核心设备直接承载产出,AI技术的代际迭代持续抬高硬件准入门槛,不具备新能力的旧设备将在特定场景中丧失竞争力,都可能迫使OPX为抓住机会而在短期内高频地更新设备。另一方面,OPX极致追求效率与性价比敏感又构成了强大的延缓效应。

IDC建议

采购触达方面,OPX群体的决策路径迥异于传统企业客户——信息获取以与AI结合的评测内容、技术社区和同行口碑为核心,购买决策由个人独立完成,无需IT部门审批,购买渠道偏向个人消费路径。这意味着,针对OPX组织形态,厂商需要结合AI相关的内容做精准触达,可能包括评测合作、社区运营、KOL口碑建设,将成为撬动OPX客群的杠杆。

产品策略方面,OPX在消费级价格、企业级可靠性与AI原生能力之间提出了三元要求。面向OPX群体的产品设计,不宜简单地在现有企业或消费产品线上做加减法,而应从OPX的实际业务场景和工作流出发,重新定义产品配置与服务组合。

服务创新方面,OPX用户缺乏IT部门的缓冲,设备故障直接等同于业务中断。这种脆弱性定义了一个高付费意愿的服务市场,快速响应维修、备用机备援、数据恢复保障等“个人级紧急兜底”服务,有望成为PC后服务市场增长最快的板块之一。

AI超级周期带来的不仅是技术迭代,更是生产力供给的结构性变革。OPX之所以值得PC产业持续关注,根本在于生产力的最小单元正从“企业”转变为“个人+AI智能体”。产业的价值链条正从以硬件为中心的线性供给,转向围绕“个人生产力闭环”的软硬服一体化。

进一步交流

IDC中国终端系统研究团队将持续追踪OPX范式下的硬件需求演变与市场机会。如需获取更详尽的PC市场季度追踪数据、OPX用户画像深度分析,或定制化的市场策略咨询,欢迎随时与IDC中国团队取得联系。让我们共同探讨,如何在“一人即公司”的时代,重新定义计算终端的价值边界。如对其他研究内容感兴趣,也可与我们保持沟通。

引言:算力变局下的真实回响,拨开智算云迷雾

在日新月异的AI时代,中国智算云市场正经历着前所未有的狂飙突进。从大模型百模大战的喧嚣,到智能体应用的全面爆发,算力需求的重心正在发生深刻转移。然而,在千亿级市场规模的宏大叙事下,企业真实的使用现状却往往被层层迷雾所掩盖。当行业逐渐褪去‘唯算力规模论’的狂热,转向对效能与价值的理性审视时,真实的AI业务落地究竟面临着怎样的需求和挑战?

为了探寻这一命题,国际数据公司(IDC)与中国信通院分别从企业使用智算云服务与专属智算云建设两大视角,面向涵盖互联网、政府、金融、制造、通信、交通、能源等多个行业的250家企业用户,开展了一场深入调研,旨在还原当前中国企业智算云使用的十大真相。

核心数据总览:中国企业智算云整体产业格局

中国智算云市场正迎来从百亿级迈向千亿级的历史性跨越,整体格局呈现出规模扩张与结构优化并进的态势。

IDC数据显示:2025年中国智算云基础设施市场(AI IaaS)规模达到486.7亿元,同比迅猛增长128%,预计未来2年超千亿。互联网、大模型服务、汽车等行业是当前该市场的采购主力,部分制造、医疗、政务数智化项目从试点采购转向常态化租赁,成为拉动该市场的新增力量。

与此同时,企业的大模型推理服务需求呈指数级爆发,推动专属智算云建设市场进入高速增长通道。联合调研测算数据显示:截至2026年2月,中国企业自建智算云推理算力规模已超过350EFlops,能够支撑日均Token产能超70万亿,成为中国大模型推理服务的核心承载形态。

真相一:混合部署成产业标配,单一形态已不再是企业算力战略的最优解

在数据安全、成本效益、业务弹性的多重考量下,企业智算云部署已告别单一模式,“智算云服务+专属智算云建设”组合成为当前多数企业的默认形态和最优解。

IDC所调研的智算云服务用户中,85.8%的企业选择了 “外部AI算力服务+自建数据中心” 的混合架构,表明企业既希望解决突发峰值算力、短期项目研发、临时模型微调等弹性需求,又希望保持对核心数据、高频稳定业务的控制权。

中国信通院调研数据也显示:超过80%的省市级政务单位通过政务专有云平台部署大模型服务;头部银行机构中96%的算力规模采用自建模式,而中小金融机构则更多采用“专属云+公有云服务”的混合架构。此外,能源、制造等行业普遍遵循分级部署,按需采购原则。

真相二:通算与智算各司其职,共同构成企业算力供给底座

此前在智算中心大热的背景下,“通用算力中心是否会被取代”成为行业热议话题,本次调研数据给出了明确的答案。

从实际应用来看,通算凭借低成本、高兼容优势持续占据企业算力底盘,支撑 日常办公、ERP 、数据库、大数据离线统计等 IT 业务;智算作为增量支撑模型训练、多模态推理、Agent 智能应用等AI 业务,二者形成互补分工格局。

在问到企业当前智算和通算的使用比例时,最高比例(40.0%)的企业选择了“智算超过40%,通算少于60%”,但69.2% 的企业认为未来2年智算占比仍在50%以内。

2026年,随着AI迈入智能体时代,CPU迎来了新的发展机遇。过去大模型训练高度依赖GPU强大的并行计算能力,但随着智能体应用的规模化落地,智能体工作负载不仅需要GPU提供的大规模并行推理能力,也需要CPU所擅长的复杂任务编排、多步逻辑控制、系统级调度与状态管理能力。这一变化正推动 “CPU-GPU协同均衡”发展。

真相三:智算云规模增势迅猛,整体利用率均衡,但行业资源利用率分化明显

从供给侧看,智能算力利用率呈现节点与区域分化特征。枢纽节点的智能算力利用率高于非枢纽节点;东部地区整体利用率与西部地区相近,西部地区承接大量东部外溢的低时延、高计算密度、弱交互性的智算需求,显示出跨区域调度对提升整体算力效率的积极作用。从需求侧看,不同行业的智算资源利用率呈现分化格局。IDC调研数据显示:近半数企业的智算资源利用率维持在 51%-70% 的中等区间,且仍有 6.7% 的企业利用率仅为 31%-50%,处于较低水平。

头部云厂商、互联网企业、AI 自研大厂、新能源汽车等凭借多年技术积累,通过算力调度平台、精细化资源管控系统与全栈协同优化体系,实现了算力资源的高效复用,部分头部企业核心集群利用率突破80%。

制造、政务等行业的利用率低于平均水平,实现 70% 及以上高利用率的企业占比不足 35%。不少自建智算项目存在 “重硬轻软” ,仅完成了服务器、GPU 等硬件设备的上架部署,但缺乏配套的统一算力调度平台、资源池化管理系统与动态资源分配机制,造成了算力资源的浪费。

真相四:推理场景消耗AI算力过半,线下推理算力贡献1/3以上

百模大战时期,资本市场聚焦千亿参数大模型自研训练,训练算力需求一度占主导,但随着 Agent 应用规模化落地,轻量化小模型 + 端云协同推理进一步拉动推理算力需求,推理场景成为智算云市场的基本盘。

IDC调研数据显示,当前八成以上的企业用于训练工作负载的AI算力占比低于50%,如果按样本数加权平均计算来看,企业用于训练和推理工作负载的AI算力四六开。泛互(60%)、金融(46.7%)用于训练的AI算力占比高于平均值,而政府和制造行业2/3的AI算力都用于推理。

中国大模型 Token 调用量的爆发式增长,进一步推动了线下推理的崛起态势。根据发改委数据:截至2026年3月,中国智能算力规模超过1882EFLOPS。调研显示:推理算力占据六成,而其中企业自建智算云贡献的线下推理算力占比超过34%。政务、金融、能源等强监管行业的核心业务推理需求正不断通过物理隔离或逻辑强隔离实现线下部署,既能保障数据安全合规,又能实现毫秒级低时延响应,适配核心业务的严苛要求。

真相五:硬件与公有云IaaS仍是中国企业IT最大支出项

2025年企业总体IT支出中, IT软件与第三方服务花费占比不足三成,七成用于采购IT硬件和公有云IaaS。具体到AI相关支出,中国企业也高度集中在AI硬件与AI IaaS上,在 AI 应用和服务层的投入仍处于早期阶段。

IDC调研数据显示:当前智算云企业用户IT硬件支出中用于GPU服务器的占比为58.4%,公有云IaaS支出中用于AI IaaS的占比为54.3%。泛互行业作为AI投入力度最大的行业,AI支出占比超过上述平均水平。

真相六:100P算力是企业智算云部署模式偏好的关键分水岭

IDC调研数据显示:当前超过85%的企业使用了26-100 PFLOPS规模的AI算力。这一区间足以支撑中小参数大模型后训练、企业级场景推理及数据密集型AI应用,是兼顾成本与实用性的主流选择。对于该算力区间的企业而言,AI业务往往存在阶段性、波动性特征,全年算力使用起伏较大,自建投入的回报率偏低,因此更倾向于采购公有智算云服务。

中国信通院调研显示,100P FP16等效算力是企业选择规模化自建和上云的核心分界指标。当算力需求超过100P时,企业倾向于自建以掌握核心资产并实现长期成本摊薄。这类主体主要为大型央企、头部银行机构、头部互联网企业。调研发现,当前国有六大行自建智算云规模均超过100P,实现了完全物理隔离的私有云环境。而当需求在几十P级别时,企业更倾向使用服务商提供的共享或独享的云服务,这一分化布局现象在能源行业尤为突出。

真相七:制约智算云产业规模化落地的并非算力短缺,而是全链路配套能力不足

AI 基础设施落地是系统性工程,单一环节短板会形成 “木桶效应” ,拉低整体算力效率。IDC调研数据显示:企业 AI 基础设施落地的瓶颈已从 “算力短缺” 转向 “全链路配套能力不足” ,机房环境、网络互联、软件适配、存储吞吐等共同构成了制约 AI 业务规模化落地的系统性障碍。

真相八:使用 MaaS 和 Agent 的挑战是“将 AI 真正用进业务里”

模型即服务(MaaS)与Agent的持续落地,让AI的获取变得像水电一样简单,但“用好”依然是巨大挑战。调研显示:企业核心瓶颈并非算力供给不足,真正的挑战在于:如何与现有业务集成打通业务孤岛?如何让Agent理解复杂的业务逻辑?如何管理数量庞大功能各异的智能体?只有跨越了从 “技术工具” 到“业务引擎” 的鸿沟,AI才能真正创造商业价值。

真相九:全栈智算云在线下推理场景凸显效能优势

对于采用智算云服务的企业而言,推理效能取决于云服务商;而对于自建智算云的企业而言,AI落地涉及从底层芯片、算力调度、云平台,到大模型部署、场景微调、应用开发的每个环节,任一环节的短板都会拉低整体效能。

本次联合调研及实测数据显示,相较于零散拼凑多厂商软硬件的项目,采用全栈AI云服务厂商产品组合的项目词元产出效能提升超过20%(词元产出效能:相同场景下单位算力日均Token调用量),全栈厂商在芯片、云平台与模型层面可实现端到端协同优化,降低跨产品兼容损耗。

真相十:国芯国模适配逐步完善,全栈国产化进入规模化部署窗口

IDC调研数据显示:总体而言,当前国产AI芯片的使用率已高于国外品牌,但不同行业差异较大,互联网、模型和IT服务行业国外品牌的使用率明显高于国产品牌;汽车和金融服务行业两者的使用率相当;政府、能源和传统制造行业中国产品牌的使用比例更高,政务行业新建智算项目已100%采用全栈国产化方案,大型银行机构的核心业务系统逐步完成了国产化适配,能源、制造等行业的国产化替代进程也在不断加速。

随着国产芯片市场占有率逐步提升,国产AI芯片与国产大模型的协同适配正从“单点突破”走向“联合体推进”,基于“国芯+国模”的全栈国产化解决方案已迈入实质性规模化部署周期,这点在政府、银行、能源等关键行业表现得尤为明显。

结语:中国智算云告别粗放,迈入精细化运营时代

2026年的企业智算云市场,正在经历一场深刻的 “成人礼” 。随着市场认知回归理性,粗放式堆算力的发展逻辑彻底落幕,逐渐进入精细化运营时代。在这个时代,赢家不再属于单纯囤积算力的人,而是属于那些能够精准调度异构资源、深刻理解行业场景、并将AI无缝融入业务血脉的长期主义者。

IDC相关研究

围绕智算云相关研究内容、技术能力与市场格局,IDC 将持续开展系统性研究,包括但不限于:

  • 《中国智算云基础设施服务(AI IaaS)市场跟踪,2025下半年》(2026年4月发布)
  • 《IDC Market Forecast:中国整体云计算市场预测,2025-2029》(2026年5月发布)  
  • 《IDC Survey:中国智算云服务市场企业用户调研,2026》(即将发布)
  • 《IDC Tech Assessment:面向智能体的混合云智算基础设施技术能力评估,2026》(即将发布)
  • 《IDC Market Share:中国AI云存储市场份额,2025》(即将发布)
  • 《IDC PeerScape:中国市场异构算力调度和管理实践洞察,2026》

如需进一步了解智算云相关研究内容,或咨询 IDC 在云计算、AI 基础设施及数字化转型领域的其他研究成果,欢迎与我们保持联系

Rachel Liu

Rachel Liu - Research Director

Rachel Liu is a research director for China’s Cloud and Services group. Her research covers public cloud, private cloud, edge cloud, industrial cloud, intelligent computing, and IT services. She is responsible for research plans, research execution and management, data tracking…

2025年,中国金融行业站上了从”数字化”迈向”智能化”的关键转折点。银行、保险、证券这类一向以稳健著称的机构,在合规与风控的硬约束之下,对新技术的引入历来审慎;但生成式AI带来的效率跃升与体验重塑,又是任何一家金融机构都不愿错过的红利。行业演进的核心驱动力,已经从最初”要不要用大模型”的试探和观望,转向场景的快速扩张、应用的规模化落地,以及对底层算力、解决方案与合规能力的系统性需求。金融AI云的竞争逻辑由此发生了一次根本性跃迁——从比拼算力”资源供给”维度,转向以”算力底座、平台调度、行业模型与合规可控”为核心的全栈能力竞争。

国际数据公司(IDC)最新发布的《中国金融云市场跟踪研究Add-on_AI全栈云》报告首次对中国金融云市场中公有云AI算力服务、私有云软硬件AI基础设施和GenAI解决方案子市场做出全栈式市场营收评估,中国金融AI全栈云市场2025全年市场规模207.6亿人民币,较2024年同比增长50.0%,远超金融云总盘23.9%的同比增速。这个数据对比显示出金融机构对AI相关领域的重视程度不断升级,预算投入持续加码,市场潜力快速兑现。

金融全栈布局下,头部云厂商的五种路径

经过几轮市场调整,金融AI全栈云的第一梯队逐渐清晰。五家代表性厂商在算力、平台、模型与应用上的侧重各有不同,拼出一张完整的能力地图。

公有云算力+私有化交付双轨并进:代表厂商 阿里云

阿里金融云,在公有云一侧依托灵骏智能计算集群,在大规模算力调度与推理优化上持续投入;金融自主私有云一侧,平头哥自研的真武AI芯片已进入规模化部署阶段,并从2025年下半年开始逐步起量。叠加面向金融场景打磨的通义点金行业大模型,以及可落入客户机房的一体机交付形态,阿里云事实上把”芯片—模型—应用”的链路在金融场景里走通了一遍,并将在2026年持续深耕,加速复制。

软硬协同稳扎稳打:代表厂商 华为云

华为昇腾系列智算服务器,多年来在国产算力替代的进程中扮演压舱石角色。对金融机构而言,华为的吸引力恰恰在于”软硬一体、自主可控”带来的确定性——在数据不出域、供应链安全成为硬约束的当下,一套经过大规模验证的昇腾底座,往往比单纯的性能参数更有说服力。

AI应用和智能体先行:代表厂商 火山引擎

背靠字节跳动内部高并发推理场景的长期锤炼,火山引擎在推理成本控制与资源利用率方面建立了差异化优势,豆包C端的成功也给火山解决方案带来足够的曝光度和品牌效应,豆包大模型与火山方舟平台构成其对外的主要解决方案抓手。在智能营销、智能客服等高频交互场景中,这种”应用先行、智能体多点开花”的策略,更容易让金融客户在数据非敏感领域优先尝到AI红利甜头。

让金融AI“融汇贯通”起来:代表厂商 腾讯云

依托在平台层数据库和大数据产品的行业优势,腾讯云从AI通用大模型到上层AI应用,从平台产品到底层异构算力管理,试图把这条链路做成一个连续整体,而非彼此割裂的模块。对于拥有庞大存量系统、又要稳步引入AI能力的金融客户来说,这种平滑过渡、整体交付的能力,本身就是一种稀缺竞争力。

“芯片+平台”组合拳:代表厂商 百度智能云

昆仑芯P800已完成规模化验证,2025年以来已交付多个万卡集群,并支撑了文心大模型新版本的训练。配合百舸AI计算平台在异构调度上的能力和千帆平台对金融应用场景的支撑,百度为金融客户从模型基础训练到推理开发上线,铺设了一条相对完整的国产化通道。

五家厂商路径不同,指向的判断却高度一致:在金融这样对”稳健”近乎苛求的行业里,单点能力很难构成壁垒,唯有把算力、平台、模型、应用与合规能力打通,才能真正站稳脚跟。

金融ISV服务商:增量市场背后的挑战

在AI云厂商与金融机构之间,往往活跃着各个子赛道金融ISV服务商的身影。他们既是AI方案的集成者,也是AI应用落地的”最后一公里”。2025年,金融ISV服务商感受到了明显的市场变化,AI市场带来新增营收机会的同时,也带来了全新的机遇和挑战。

一方面,金融AI场景在2025年正式跨过了项目落地的门槛,并呈现出明显的量价齐升势头。在传统金融预算大环境整体承压的当下,这样一块实打实的市场增量殊为不易,它意味着新的项目机会、新的合作入口,以及与客户重建深度连接的契机。不过,这份增量需要冷静看待,AI相关收入对整体金融云解决方案营收的直接贡献占比仍然偏小,更多扮演的是”敲门砖”与”引流器”的角色——通过AI项目切入客户、增强黏性,再向定制化开发、平台软件乃至底层基础设施资源的销售导流,而这些方向的受益者往往是云厂商占优。真正的商业价值,可能兑现在AI之外。

另一方面,金融机构对AI方案的选型普遍呈现迷茫状态。用哪家大模型,走开源还是闭源,部署在公有云还是落到本地机房,是否涉及业务系统解耦和微服务改造,数据安全合规如何满足监管要求,未来方案兼容性与可持续性又如何保证——这些问题几乎没有现成经验可以照搬。金融ISV服务商需要陪伴客户共同摸索试错,在反复的POC与调优中消耗大量人力成本。这种”陪跑”固然能加深信任,却也推高了交付成本,挤压了本就不宽裕的利润空间。

IDC市场调研发现,金融ISV AI服务商正从”项目制交付”向”持续运营”转型,从单纯的技术提供者,转变为深度参与客户流程重构的”业务转型伙伴”。金融AI可能对未来ISV服务商竞争格局带来颠覆性变化,金融服务商不仅要懂业务,还要懂AI、养AI、用AI,扛的住长期AI运营的玩家才能在未来竞争中立于不败之地。

IDC洞察:金融AI要以全栈能力和生态协同赢得长期战斗的胜利

对于金融云服务商和云厂商而言,是否全栈式布局已不再是选答题,而是必答题。金融客户要的不是某一颗更快的芯片或某一个更准的模型,而是一套数据模型平台应用服务端到端打通、并能自我迭代和强化的能力体系。在这一点上,自主算力与行业大模型的协同尤为关键,它既回应了自主可控的政策诉求,也构筑起别人难以复制的护城河。与此同时,”合规”应当被前置为产品能力而非事后补丁——数据不出域、决策可追溯、幻觉可约束,在通用市场或许是加分项,在金融市场却是入场券。

随着智能体应用从单点走向全流程,推理调用量将呈指数级放大,按需租赁、弹性扩容与混合部署在未来三到五年内,有望逐步替代传统的重资产采购模式,成为金融AI基础设施建设的新常态。能在保障性能的同时把综合成本压下来的厂商,将在长期竞争中占得先机。

此外,建议金融云厂商加大对金融ISV服务商的支持力度。ISV是云厂商触达金融客户的重要渠道,也是行业Know-How的历史沉淀者,并在AI拓展方面成本承压。云厂商在算力补贴、平台开放、收益合作与人才培养上给予生态伙伴更深层的支持,可加快金融AI整体升级节奏。

金融行业要的,从来不是非此即彼的”创新”或”稳健”,而是两者之间的平衡。能否帮客户既迈得开步子、又站得稳脚跟,正是这场金融AI全栈云竞速中,最终拉开差距的地方。

如需进一步了解IDC相关研究,或就中国金融云AI市场发展趋势进行深入交流,欢迎与IDC联系,获取更多洞察与数据支持。

北京,202665——国际数据公司(IDC)最新发布的《2026年第一季度全球手持智能相机市场跟踪报告》显示,2026Q1全球手持智能相机市场出货量达到414万台,同比增长33%。销售额超过105亿元人民币,同比增长20%。IDC预计,至2030年,全球手持智能相机市场规模将会超过4000万台,五年复合增长率接近18%。

2026Q1全球手持智能相机发展状况

  • 运动相机市场:26Q1全球运动相机出货量接近201万台,同比增长39%。平均单价2149人民币,同比下降11%。推动市场高速增长的主升浪来自于大疆和影石爆款明星产品热销,同时上一代产品的强势调价促销也为厂家贡献了良好业绩。大疆和影石出货量市场份额同比攀升13个百分点,老牌厂商GoPro生存空间继续被挤压。从运动相机市场细分品类来看,可拆卸运动相机即“拇指相机”出货量同比增长惊人超过350%,不可拆卸运动相机同比增长16%。
  • 云台相机市场:26Q1全球云台相机出货量同比增长超过18%,平均单价2840人民币,同比下调12.5%。此市场大疆继续保持独占领先优势。手持云台相机市场在产业上下游供给侧和最终用户需求端都保持了高热度,26年将迎来产品突破升级和新竞争厂商出现。
  • 全景相机市场:26Q1全球出货量超过50万台,同比增长高于50%。影石在全景相机领域排名第一且大幅领先,出货量份额接近七成,大疆Osmo360火爆单品保持热度拿下超过两成市场。

2026Q1全球手持智能相机市场主要厂商概况:

26Q1全球手持智能相机市场,大疆以65%出货量市场份额保持第一,同比增长38%。影石出货量市场份额达到22%,同比增长66%排名第二。GoPro受到大疆和影石的全球激烈竞争出货量同比持续萎缩。

大疆

大疆凭借无人机领域全产业链成功多年积累的硬件核心技术(多轴云台稳定系统,影像及多传感器融合技术,飞行及运动控制系统)向手持智能影像设备迁移,打造高可靠性和易用性的影像产品全系列矩阵。品牌拥有完善供应链体系,成本抗压弹性,议价能力,上游核心部件定制化能力均较强。26Q1云台相机自身出货量占比超过一半,Pocket4新品预售火爆断货,3代产品调价后继续受到市场追捧。不可拆卸运动相机出货量市场份额同比上升3和百分点增长至54%,可拆卸运动相机即“拇指相机”单品Osmo Nano在25年发售后保持热销,26Q1出货量拿下过半市场份额。在全景相机领域,26Q1大疆凭借Osmo360单品赢得22%出货量市场份额占稳这一市场。

影石

26Q1全球出货量接近90万台(结果基于IDC研究方法论统计得出,涉及上市公司数据最终请以厂商财报披露为准)。影石持续加大投入研发资源,凭借在全景相机领域作为全球领军厂商的多年技术积累,已经在差异化应用场景和应用软件方面形成独特优势和壁垒。其系统应用软件在拼接算法,多场景防抖,深度主体追踪以及在AI助手一键剪辑方面获得庞大用户群的广泛认可。影石在全景相机领域虽然遭遇挑战,但26Q1仍旧保持了接近七成出货量市场份额。在不可拆卸运动相机领域,AcePro2街拍套装促销取得成功,出货量市场份额创新高超过17%,同比吃掉7个百分点。在可拆卸运动相机市场,尽管面临强势竞争,产品出货量同比增长翻倍且Go Ultra表现亮眼。此外云台相机高热度新品将在第二季度全球出货也为厂商锚定新的增长点。

GoPro

遭遇中国厂商全球激烈竞争,面临供应链成本上涨,削减库存等多方面压力同比大幅收缩。26Q1全景相机出货量同比跌幅大于运动相机,运动相机内部Lit Hero以及Hero低价老品自身比重增加,整体均价同比下调17%。虽然发布M1系列新一代运动相机以及继续推广全景Max2新品但市场表现有待观察。

IDC分析师洞察与市场未来发展预测:

  1. 手持智能相机从硬件堆叠到全产品矩阵,进一步深度挖掘场景覆盖。回顾手持智能相机发展历程,关键硬件研发诸如大底传感器,可变光圈系统,8K超高分辨率等技术仍旧是推动市场发展的核心因素。从产品端侧看已经由全景相机,不可拆卸运动相机,手持云台相机到可拆卸运动相机形成手持智能影像全产品矩阵。与此同时覆盖用户人群由小众极限运动极大拓展到广大运动爱好者到Vlog创作者和大众记录日常。厂商仍旧致力于深挖用户场景需求乐此不疲。
  2. AI融入手持智能影像终端最终能为用户带来什么价值。目前AI功能主要集中于AI场景深度感知,AI智能降噪,多帧合成算法,暗光画质增强,AI后期智能剪辑成片等功能型应用。AI融入手持智能影像终端的未来愿景是成为智能影像机器人终端的底座和大脑,由被动的影像记录终端成长为基于海量数据采集可以按照用户各种需求主动生成创作内容的超级智能体。
  3. 中国是手持智能相机的第一大市场。从2025年度出货量来看,中国贡献了超过一半的市场份额,26Q1延续了这种趋势且贡献进一步有所加大。除中国外,美国,西欧,亚太区和日本是全球前四大市场。海外市场产品渠道营销是国内厂商投入资源的核心议题之一。
  4. 手持智能相机市场的渗透率仍旧较低,未来增长空间可期。手持智能相机市场无论从产业资本和上下游供给侧还是最终用户消费者层面仍旧保持高热度。无论哪一条细分产品线市场的未来五年复合增长率均高于15%。IDC预计,至2030年,全球手持智能相机市场规模将会超过4000万台,总体复合增长率接近18%。

IDC手持智能相机定义

IDC对手持智能相机的定义是指具备计算处理能力,搭载电子或光学等防抖能力,分辨率2K及以上且可手持使用的消费级便携影像设备,包括运动相机(包含可拆卸和不可拆卸运动相机两种形态),全景相机和云台相机。

IDC更多相关详细内容,敬请关注:IDC WW Quarterly Handheld Smart Camera Tracker

请点击此处与我们联系

Jacky Xue

Jacky Xue - Research Manager

Jacky Xue is a research manager with the Client Systems Research team at IDC China, responsible for projector, IWB and enterprise client devices research and analysis. His responsibilities include tracking the industry data, monitoring the market development, analyzing the future…

Organizations worldwide are failing to deliver cybersecurity metrics that serve their boards, executives, and operational teams, and the emergence of AI has widened that gap significantly. Cyber risk has risen from an operational concern to an existential business risk. Ransomware attacks have shut down companies outright. Regulatory frameworks, including DORA, NIS2, and SEC disclosure rules, now hold boards directly accountable for risk and compliance posture. The stakes have never been higher, yet the tools used to communicate cybersecurity health remain fundamentally misaligned with the audiences that need to act on them.

Just as revenue and expense data flows across every level of an organization, cybersecurity risk intelligence must reach operations, management, and governance audiences, calibrated to each. The message appropriate for a security operations team is not the message appropriate for a board of directors.

More importantly, many CISOs do not know how to communicate with executives and board members, and executives and board members do not know what they want from CISOs. CISOs want to discuss in cybersecurity terms, but executives and board members really only understand business, revenue (dollars), and resilience, and they don’t understand cybersecurity. This data-driven cybersecurity metrics framework was written specifically to deal with that problem in a way that lets the CISO, executives, and board members communicate in a language both understand.

Why cybersecurity metrics are misunderstood

Cybersecurity matured in reverse. Unlike most disciplines that flow from strategy to goals to policies to tactics, cybersecurity built itself from the bottom up: tactics first, strategy last, if ever. The consequences of that legacy persist today:

  • Formal strategy is largely an accumulation of small tactical decisions made over decades, never designed for governance audiences.
  • Boards are routinely presented with operational metrics — firewall blocks, vulnerability counts, patch rates — that were never built for governance consumption.
  • Regulatory pressure is accelerating the problem: governments worldwide now hold executives and boards directly accountable for risk and compliance posture.
  • The result is a persistent, structurally embedded mismatch between what cybersecurity teams can easily produce and what governance audiences actually need.

Why executive and board meetings fail to communicate cyber risk

Boards govern. Executives strategize. Neither runs day-to-day operations. Yet most cybersecurity presentations treat them as if they do:

  • Executives lack deep cybersecurity domain expertise by design; their role is strategic governance, not running a security operations center.
  • When metrics are misaligned, board meetings devolve into data dumps, forcing executives to decode technical minutiae rather than engage in meaningful risk dialogue. A single DLP block statistic can consume an hour of board time with no actionable outcome.
  • CISOs typically rise through technical security leadership, not business management, limiting their experience translating risk into the language of business strategy.
  • Board-level cybersecurity accountability is a relatively recent demand, driven by the ransomware pandemic rather than strategic planning. There is no established playbook; most CISOs learned by trial and error.
  • The result: CISOs default to presenting what they have — operational metrics — and boards are left searching for the risk signal buried in the technical noise.

Why traditional metrics failed everyone

The failure wasn’t malicious. It was structural. Both sides operated in good faith with the wrong tools:

  • Metrics were built from available data, not from audience needs. Current metrics are often fragmented across multiple repositories and formats, making collection laborious and time-consuming.
  • What existed was appropriate for operations management — rarely in a form useful for executive decision-making.
  • Noncompliance rates, firewall blocks, and vulnerability scan results are tactical measures with no clear call to action at the executive level.
  • Management asked, “Are we OK?” and received patching statistics in response: a fundamental mismatch between the question asked and the answer provided.
  • Tactical metrics aid day-to-day program management but lack the context and comprehensiveness required for strategic leadership. Without a centralized intelligence platform, this gap cannot be closed.

How AI has changed the metrics imperative

AI has added two urgent, distinct dimensions to an already unsolved problem.

Offensive: AI as an adversarial weapon

  • Threat actors are weaponizing AI to generate convincing phishing campaigns at unprecedented scale.
  • Deepfake audio and video are being used to impersonate executives and manipulate internal decision-making.
  • AI accelerates vulnerability discovery, exploit development, and evasion of traditional detection controls.
  • The net effect: faster, higher-volume, more sophisticated attacks, with compressed detection and response windows.

Defensive: Ungoverned internal AI deployments

  • Organizations are embedding AI into products, services, and operational decisions at a pace that far outstrips governance and oversight controls.
  • Shadow AI, agentic AI, and SaaS-embedded AI are widely deployed and largely untracked.
  • This creates a new class of enterprise risk: model failures, hallucinated outputs influencing strategy, customer harm, and regulatory exposure.
  • Without AI-focused metrics at every organizational level, the gap between the questions executives are asking and the answers cybersecurity leaders can provide will only widen.

The qualities of data-driven metrics

Data-driven metrics must serve specific audiences, telling a coherent story calibrated to each stakeholder’s role, accountability, and risk exposure. Three tiers are required:

Governance (Board/C-Suite)Strategic risk oversight, compliance posture, AI governance status. 6–10 high-signal metrics organized across 4 IDC-defined categories.
Managerial (C-Suite/LOB/Ops Management) Program health, AI incident trends, shadow AI exposure, regulatory compliance progress. Both strategic and tactical in nature.
Operational (CISO/Functional Teams)Day-to-day control effectiveness, AI attack surface, shadow AI detection, hallucination monitoring, data protection. Essential for execution teams; too granular for boards.

Effective data-driven metrics share these qualities:

  • Audience-specific: Each tier receives only what is relevant to its function, accountability, and decision-making authority.
  • Outcome-driven: They measure progress toward defined business objectives, not activity volume.
  • Actionable: Every metric carries an implicit or explicit call to action, enabling informed, confident decisions.
  • Contextual: Risk is framed in financial, operational, or reputational terms, not technical jargon.
  • AI-inclusive: Every tier must now incorporate AI-specific risk intelligence alongside traditional cybersecurity metrics.

Elements to consider in crafting metrics

Building metrics that work requires a structured, iterative process anchored in business context, not available data.

1. Understand the risks

  • Begin with the business: define key functions, processes, and associated risks before mapping them to cybersecurity priorities.
  • Engage stakeholders from IT, audit, legal, risk, compliance, BISOs, and senior executives to build consensus around what matters most.
  • Incorporate AI as both an internal operational risk (from the organization’s own deployments) and an external threat vector.
  • Expand the stakeholder group to include AI governance officers, AI product owners, and legal or privacy counsel with AI expertise.

2. Align data collection

  • Shape metrics collection around agreed risks, automating data sources through GRC platforms capable of generating audience-specific intelligence.
  • Treat AI systems as first-class data sources: model inventories, output logs, decision audit trails, and third-party AI component registries are required inputs alongside traditional telemetry.

3. Analyze the Data

  • Use automation and AI to analyze large volumes of contextual intelligence against the risk register, surfacing asset ownership gaps, CMDB inaccuracies, and emerging risks.
  • AI-generated analyses must be subject to human validation before informing decisions.
  • AI output accuracy should itself become a tracked and reported metric.

4. Interpret Results in Business Terms

  • Outcomes must be specific, measurable, and meaningful — for example, a DLP implementation should show users changing behavior, exfiltration declining, and residual risk being quantified.
  • When AI systems produce outcomes, interpretive frameworks must distinguish human-driven from AI-driven results and assess accuracy and fairness, not just control effectiveness.
  • AI-generated recommendations must never be treated as equivalent to validated analyst conclusions.

5. Consider the stakeholders

  • Manufacturing LOBs: focused on process uptime and network segmentation risks.
  • eCommerce LOBs: focused on application security and architecture risks.
  • AI-deploying LOBs: carry distinct AI-related cybersecurity risks requiring specific communication.
  • Expand the model to include AI product owners, data scientists, and AI governance officers wherever AI intersects cybersecurity risk.

6. Empower decision-making and monitor continuously

  • Cybersecurity leaders own the recommendation; the risk decision belongs to the business owner accountable for it. Their role is to build a story that lets decision owners act with confidence.
  • Monitor for model drift; schedule regular AI system reevaluation and retraining.
  • Continuously retire irrelevant risks and elevate newly emerging ones, including those introduced by evolving AI deployments.
  • Embed AI governance explicitly: model approval policies, mandatory preproduction risk assessments, human review standards for high-risk AI decisions, and AI incident management procedures are all required.

What is needed for data-driven metrics

Effective data-driven metrics communicate risk likelihood versus business impact. They go beyond statistics to deliver actionable insights supporting both strategic and tactical decision-making. Achieving this requires:

  • A centralized intelligence repository consolidating contextual business, IT, and cybersecurity data, including AI-specific signals, into a single, consistent source of truth.
  • Three metric tiers (governance, managerial, and operational) generated consistently over time from that single source.
  • AI-specific metrics at every tier: shadow AI detection, AI regulatory compliance posture, agentic AI governance, model IP protection, SaaS-embedded AI risk, and AI output integrity.
  • Automation, machine learning, orchestration, and AI to generate an ever-evolving set of metrics and adjacent risk insights.
  • Audience-specific dashboarding and stakeholder messaging that translates technical cybersecurity data into business risk language, calibrated to the level of accountability and required response.

The role of GRC platforms and intelligence fabric

Modern GRC platforms are uniquely positioned to close the metrics gap. By consolidating internal and external business, IT, and cybersecurity intelligence into a single repository, enhanced through automation, machine learning, and AI, they power consistent, audience-specific metrics at scale.

The intelligence fabric is the contextual data layer at the core of a modern GRC platform. It must enrich the risk register with:

  • Newly discovered assets and their sensitivity classifications
  • Potential data and asset ownership
  • Estimated monetary impact of risks and compliance issues
  • Contextual interpretation of risks against organizational policies

The fabric must now extend to AI-specific intelligence, organized by metric type so each audience sees the right signal at the right altitude:

1. Cybersecurity risk posture2. Compliance posture3. Program outcomes4. AI governance status

This includes:

  • AI model inventories and ownership records
  • Shadow AI detection signals
  • AI output logs and decision audit trails
  • AI regulatory compliance mapping (EU AI Act, NIST AI RMF, and sector-specific requirements)

What this enables:

  • Single source of truth: Centralized GRC intelligence across cybersecurity, IT, and business functions.
  • Audience-specific dashboards: SOC views for operational teams; risk posture views for executives and boards.
  • Outcome-driven metrics: Actionable statistics, trends, and risk-driven insights tied to business objectives.
  • Targeted stakeholder messaging: Calibrated by audience and required response — for-your-information only, executive risk-based decision required, or action needed (e.g., budget approval).
  • Reduced human bias: AI-assisted analysis increases consistency and accuracy across the metrics program.

Advice for technology buyers and suppliers

For the technology buyer

A passing awareness of cybersecurity posture is no longer acceptable at any level of leadership. Buyers should:

  • Partner with a qualified cybersecurity GRC software provider experienced in collecting, analyzing, and generating audience-appropriate metrics aligned to this three-tier framework.
  • Ensure the platform consolidates contextual business, IT, and cybersecurity intelligence, internal and external, into a robust, integrated repository.
  • Demand at least three levels of metrics: governance (strategic), managerial (strategic and tactical), and operational (tactical), generated consistently over time from a single source.
  • Require AI-specific risk metrics across all three tiers: shadow AI detection, AI regulatory compliance posture, agentic AI governance, model IP protection, and SaaS-embedded AI risk.
  • Insist on automation, machine learning, and orchestration to generate an evolving metrics program that stays ahead of the threat and regulatory landscape.
  • Boards must be able to confirm: Are AI systems governed? Is AI risk being measured? Are AI incidents — regulatory actions, customer harm, reputational damage — being proactively managed and reported?

For the technology supplier and services provider

The market opportunity is clear, immediate, and structurally durable. Organizations at every level need current, audience-appropriate visibility into cybersecurity risk and compliance posture, and most lack the platforms, skills, and frameworks to deliver it. Suppliers should:

  • Build or extend GRC platforms with a consolidated intelligence repository that centralizes business, IT, and cybersecurity data to power consistent, audience-specific metrics at scale.
  • Deliver all three metric tiers (governance, managerial, and operational) from a single consolidated intelligence source. Providers who can do this address a gap most organizations cannot close without external platform support.
  • Invest in audience-specific dashboarding that translates technical cybersecurity data into business risk language, designed for boards, executives, and operational teams alike.
  • Incorporate AI governance metrics: shadow AI detection, AI regulatory compliance posture, agentic AI risk, and model IP protection across all three audience tiers.
  • Develop consulting and managed service offerings that help customers build data-driven, AI-inclusive metrics programs and bridge the business acumen gap most cybersecurity teams face.
  • Providers who help CISOs speak the board’s language, translating cyber-risk into business risk, will earn lasting customer loyalty and reduce competitive displacement risk.

“The cybersecurity metrics market is at an inflection point. Customers are being held accountable for AI risks they cannot yet measure, and boards are demanding business risk context that most security tools still cannot deliver. Technology and service providers that step into this gap, with consolidated intelligence platforms, audience-specific metrics, and AI governance capabilities, will define the next generation of cybersecurity and GRC market leadership.”Philip D. Harris, Research Director, Governance, Risk, and Compliance Solutions, IDC

Philip D. Harris, CISSP, CCSK

Philip D. Harris, CISSP, CCSK - Research Director, Governance, Risk, and Compliance (GRC) Solutions

Phil Harris is Research Director for GRC Solutions at IDC, where he develops and promotes IDC's point of view on risk, advisory, privacy, and compliance services and software. He conducts research on business strategies and the impact of relevant offerings…

For years, small and medium-sized businesses took the same approach to AI: watch, wait, and let someone else absorb the cost of a failed experiment. In 2026, that calculus has changed. IDC’s Katie Evans, Senior Director of Worldwide Small and Medium Business Research, sat down to share what the latest data, drawn from more than 2,700 IT decision-makers across 23 countries, reveals about where SMBs are now, what’s driving the shift, and what any SMB owner should do before making their first AI investment.

The “fast follower” strategy paid off

Three years ago, IDC research consistently surfaced a pattern in how SMBs talked about AI. They weren’t early adopters. They were deliberate holdouts, not because they didn’t see the opportunity, but because the risk calculus didn’t work in their favor.

“They would say, ‘I want to be a fast follower,'” Evans explains. “We don’t have the budget for a failed AI experiment.”

That instinct turned out to be sound strategy. While large enterprises absorbed the costs of early-stage AI experiments (the failed pilots, the shaky implementations, the expensive custom builds), SMBs watched and learned. By the time vendors began packaging AI into the tools SMBs were already using, those businesses knew exactly what they were looking for.

IDC’s 2025 survey captured the inflection: in 2024, AI ranked third among forward-looking technology priorities for SMBs. By 2025, it had jumped to number one. The share of SMBs not using AI at all dropped from 11.2% to 6.3% in a single year.

The proof arrived. The fast followers moved. And the first thing most of them did was look inward.

What SMBs are actually using AI for

The businesses that have moved fastest share a common starting point: they looked at their own operations before they looked at any vendor. The number one current AI use case for SMBs worldwide reflects that instinct: generative AI for content creation. That includes marketing copy, internal documentation, customer communications, and code. It’s the entry point, and it’s well-established.

But the picture is expanding. IDC’s research shows SMBs are moving beyond isolated productivity tools into more operational territory. Digital assistants to manage tasks are rising fast, particularly among smaller businesses with lean staff. Robotic process automation (RPA) is growing. And the next wave, agentic AI, which can take autonomous action on behalf of a business, is already on the planning horizon.

Evans points to a practical lens for SMBs trying to decide where AI fits in their business: look at where work is piling up.

“Look for high-volume, repetitive tasks: invoice processing, data entry, inventory tagging, moving figures from PDFs to spreadsheets,” she says. “If those tasks are increasing as your business grows, you’re building a bottleneck. That’s where AI can take over.”

There’s a retention argument here too. SMBs, which often can’t match the compensation packages of larger competitors, can use AI to remove the dull, error-prone work that drives good employees out the door. “If you can make their workplace more fulfilling by leaning into technology,” Evans notes, “it really helps with retention.”

The goal, she is clear, isn’t to save a few minutes per task. It’s to increase revenue per employee.

But knowing where AI can help is only half the equation. The other half is finding a solution that a lean, non-technical team can actually use.

Why embedded AI is winning

Here is the constraint that shapes everything else for SMBs: 40% of the nearly 3,000 SMBs IDC surveyed do not have a single full-time IT employee in-house. That number has held steady for several years, even as SMB technology budgets have grown. A third of SMBs cite lack of IT staff as a top challenge. Another third flag user adoption as a major obstacle.

These numbers explain why standalone AI point solutions are losing to embedded ones.

“SMBs that are seeing real results from AI are not adding it as a separate point solution,” Evans says. “They’re turning on AI capabilities that are already inside the platforms they use every day: their CRM, their ERP, their accounting system.”

The logic is straightforward: no new interface to learn, no separate implementation cycle, no change management burden. The vendor is already known and trusted. The AI feature is just a feature that gets switched on.

Vendors have started meeting SMBs where they are. IDC’s 2026 market data shows a clear shift toward GenAI as the top forward-looking technology priority, overtaking traditional AI and process automation. And increasingly, vendors are embedding those capabilities directly into their products: consumer-grade interfaces, guided chat prompts, no-code and low-code options, designed for non-technical staff with no IT backup.

“As easy as you can make AI for your employees to use is the key,” Evans says. “Think of it like an app on your phone. Something that just works.”

Vendors are getting there. But two obstacles are slowing the journey for SMBs that are ready to move.

The barriers that still need solving

Unpredictable pricing is the first. When an SMB implements an AI capability, sees it working, and then watches its bill triple because it crossed an invisible usage tier, trust breaks down fast. Evans puts it plainly: “SMBs have tighter budgets. Unpredictable costs are a big red flag.”

What SMBs want is transparency: credit-based models that let them control usage, freemium options that allow experimentation before commitment, and clear communication about what each pricing tier actually means. The lowest price isn’t always the winner. Predictable pricing, where the total cost of ownership is legible, is.

Security is the other major barrier, and it’s gotten bigger, not smaller. IDC’s 2026 data found that implementing new technology securely is the number one challenge SMBs name when asked what’s standing between them and their business priorities. It ranked above lack of budget, above user adoption, above lack of IT staff.

“AI is a data guzzler,” Evans says. “It constantly needs new, fresh data to train its models. So SMBs are asking: where is the data coming from? Are you using my customers’ data? How long is it being stored?”

The ask from SMBs is clear: security and compliance built in, not bolted on. A business with no cybersecurity expert on staff needs its vendor to handle that layer. And for an SMB still building consumer trust and brand reputation, a breach isn’t just an operational disruption. It’s potentially an existential one.

IDC forecasts that 50% of SMBs will increase security spending over the next 12 months. For tech suppliers, that is signal: security credibility is a sales requirement, not a feature differentiator.

For SMB owners, it is a checklist item. Before signing with any AI vendor, ask how they handle your data, where it is stored, and what compliance frameworks they operate under. Pricing and ease of use matter. So does knowing your customers’ information is protected. With those boxes checked, the path forward is clearer than it has ever been.

What smart SMBs should do next

The data is there. The vendor options are growing. The path to AI adoption for SMBs isn’t as steep as it was three years ago. But it still requires some deliberate homework.

Evans’s advice, distilled from conversations with hundreds of SMBs and thousands of data points: start with an operational audit. Before evaluating any specific AI tool, walk your own business and look for the work that consistently slows you down. High-volume, repetitive tasks. Processes that pile up as you grow. Places where a lean staff is spending hours on work that produces no strategic value.

Then look for AI that is embedded in platforms you already trust, built for non-technical users, and priced transparently. Any vendor worth considering should be able to show you measurable outcomes, not just capabilities.

“Many solutions that are a good fit for your business are out there,” Evans says. “But you need to find something that meets your unique needs. Do your homework.”

IDC predicts that by 2027, driven by the widespread adoption of AI and agentic AI, 70% of medium-sized businesses will achieve digital payback at twice the rate of previous technology cycles. That’s not a forecast about large enterprises with armies of engineers. That’s a forecast about companies like yours.

The window the fast followers waited for is open. The question now is how confidently you walk through it.

Christina Cardoza - Content Marketing Manager - IDC

Christina Cardoza is a Content Marketing Manager at IDC, where she specializes in brand content and social media strategy. With a background in journalism and editorial leadership, she has a proven ability to transform complex technology topics into clear, actionable insights.

Most AI intelligence platforms are built for the general case. Ask them about cloud infrastructure spending trends, managed services growth, or competitive positioning in a vendor landscape, and they’ll produce something fast, sourced, and useful. 

Now ask them something specific to you. What does this market data mean for a company operating across three distinct verticals with no direct peer set? How does this vendor analysis map against the internal roadmap we’ve already committed to? What’s the right staffing model for an organization at our scale, in our geography, with our constraints? 

That’s where most platforms go quiet. Or give you a generic answer dressed up as a tailored one. 

Two questions are buried in that problem, and they’re worth separating. The first is whether an AI intelligence platform can meet you where you are, understanding your context, your data, your priorities, rather than handing you a market-wide answer and leaving the translation work to you. The second is what happens to your strategy once you’ve shared it. When you bring your internal documents, your roadmaps, your competitive thinking into an AI session, where does that information go? 

These aren’t hypothetical concerns. According to IDC’s Future Enterprise Resiliency & Spending Survey, more than three-quarters of AI projects fail to move from proof of concept to production. The most cited barriers aren’t technical. They’re trust-related: 27% of organizations cite challenges protecting against sensitive data exposure, and 23% report inadequate data governance as a blocker. In IDC’s Enterprise Intelligence Services Survey, security, privacy, and governance concerns ranked as the single most common challenge for buyers adopting AI-driven intelligence solutions, ahead of budget, skills, and technical integration. 

The platforms aren’t failing because AI doesn’t work. They’re failing because organizations can’t answer two basic questions before they fully commit: 

Does this platform understand my situation?

Is my strategy safe here?

IDC Quanta, IDC’s AI platform built on 60 years of proprietary research, is built around both questions. The Contextual and Secure pillars aren’t marketing language. They’re specific product commitments backed by real mechanics. A few organizations that have already been living with them offer a clearer picture of what those commitments mean in practice. 

How contextual AI intelligence adapts to your business, not the market average 

Phillip Langeberg leads technology for The Resorts Companies, a 100% employee-owned Virginia-based group operating across hospitality, real estate, and recreation. Massanutten Resort alone spans 6,000 acres and 2,500 accommodations, with a waterpark, a ski mountain, golf courses, and a 55+ residential community under development. 

There is no standard industry benchmark for that. 

When Langeberg went looking for intelligence to inform vendor decisions, staffing models, and technology roadmaps, he wasn’t operating in a category where peer data arrived pre-packaged. Hospitality benchmarks didn’t capture the complexity of real estate. Real estate data missed the recreation dimension. Manufacturing comparisons were close in some ways and irrelevant in others. 

What he needed wasn’t a faster way to retrieve a generic market answer. He needed a platform that could take his context, his organizational structure, his operational specifics, his ongoing priorities, and benchmark it against IDC research in a way that produced something actually applicable. 

That’s the Contextual pillar. It is a specific product capability, not a marketing shorthand for personalization. You bring your own documents, data, and history into the intelligence session and query them alongside IDC’s proprietary research. The context persists across sessions. You’re not re-briefing the platform every time you return. It accumulates what it knows about your situation and applies it to every answer. 

For Langeberg, that meant analyst conversations and IDC Roundtables that compared his operation with peers across water treatment, manufacturing, and other adjacent industries, not because those were his competitors, but because they operated at a comparable level of complexity. Quanta extended that same principle into a platform: the ability to bring his situation to the intelligence, rather than extracting generic intelligence and hoping it applied. 

“When I walk into that moment where I’m not sure where I need to be on something, I know that IDC is there as a partner — through their research, the AI platform, the analysts — to help us plot the right course.” — Phillip Langeberg, CTO, The Resorts Companies

Market intelligence that knows your business isn’t a luxury for complex operators. It’s the difference between a useful answer and a generic one. 

Why AI research platforms must protect your strategic data 

Eric Walk leads AI data platforms at Perficient, a global technology consultancy with more than 7,000 advisors, engineers, and designers serving over 300 Fortune 500 clients. Perficient’s value proposition is straightforward: help organizations apply emerging technology effectively, and stand behind the advice with enough confidence to stake their reputation on it. 

That proposition depends entirely on the quality of the intelligence that feeds it. 

“You can open up the world and have AI crawl the internet and look at any source of information, but you’re going to get results that reflect the internet. It’s critical for us to ensure we have trusted inputs to produce trusted outputs.” — Eric Walk, VP AI Data Platforms, Perficient

There’s a second-order version of the same problem that gets less attention. When a consultancy brings internal client context, competitive analysis, strategic positioning documents, and roadmap data into an AI research session, the question isn’t just whether the output is accurate. It’s whether the inputs stay contained. 

Most enterprise AI tools don’t give a clean answer to that question. They say things like “we take privacy seriously” and point to terms of service. That’s not the same as a specific architectural commitment. 

The Secure pillar is the specific commitment. Your queries, documents, and outputs live in a private, isolated workspace: not shared with other users, not visible across sessions, not accessible to anyone outside your organization. IDC never uses what you bring into the platform to train its models. Every user is token-isolated. Documents are automatically deleted after 90 days. The platform uses AES-256 encryption, holds SOC 2 Type II certification, and supports enterprise SSO and SAML authentication in general availability. 

That is not reassurance language. It’s architecture. And for a firm like Perficient, where the advice is the product and the advice depends on thinking that can’t afford to leak, the architecture is the point. 

As Jennifer Glenn, IDC Research Director for Information and Data Security, has noted: “AI is only as trustworthy as the data it consumes.” The Secure pillar ensures that the data you bring to that exchange stays yours, every session. 

How contextual and secure work together for enterprise AI adoption 

The sales conversation around IDC Quanta deliberately distinguishes between audiences. For smaller, growth-stage organizations, the most immediate value tends to be Embedded (intelligence delivered without a new tool to learn) and Rigorous (sourced, defensible answers that hold up in front of leadership). Those are the two concerns that surface fastest when teams are lean and can’t absorb errors. 

For larger, more complex organizations, the ones operating at scale with complex internal data, real data governance stakes, and strategy that competes in sophisticated markets, the conversation starts with Contextual and Secure. 

The reason is sequential. You don’t bring your internal roadmap, your competitive intelligence, your client data into an AI platform until you know two things: that the platform will calibrate its answers to your situation rather than the generic market, and that what you share won’t find its way somewhere it shouldn’t. Contextual answers the first. Secure answers the second. 

For an organization like Kyndryl, which spun out of IBM in 2021 as one of the world’s largest managed service providers with 80,000 employees and an analyst relations function serving hundreds of internal stakeholders, the ability to surface IDC research interactively transformed a function that had been bottlenecked by synthesis time. Weeks of research became minutes of conversation. 

But the precondition for that kind of organizational adoption is exactly the trust that Contextual and Secure establish: strategy, product, finance, and sales teams all querying the same platform, knowing their context is understood and their inputs don’t leave the room. 

What to ask before adopting an enterprise AI intelligence platform 

Most organizations ask one due diligence question before adopting an AI intelligence platform: Does it have the data I need? That’s table stakes. IDC Quanta’s foundation is 60 years of proprietary research, 1,300+ analysts across 110+ countries, and 6,000 documents published annually. The data is there. 

The questions most organizations skip are the ones that determine whether an AI platform actually becomes part of how decisions are made, rather than something that gets evaluated, approved, partially adopted, and quietly abandoned when the answers don’t quite fit. 

Does it understand my business well enough to give me an answer I can use?

Can I trust it with the internal context I’d need to share to make that happen?

Contextual and Secure exist because those questions have a right answer. Getting that answer right is what separates an AI intelligence platform that changes how your organization operates from one that sits alongside it. 

Ryan Smith - Content Marketing Director - IDC

Ryan Smith is the Director of Content Marketing at IDC, where he leads brand-level content and social media strategy, aligning research insights with compelling storytelling to engage technology decision-makers. With a background in both IT and marketing, Ryan brings a unique blend of technical understanding and creative strategy to his work. He’s also a seasoned storyteller, speaker, and podcast host who believes the right message, told the right way, can drive both trust and transformation.