I spent much of my career helping organizations operationalize customer and employee intelligence. During that time, I watched an entire industry emerge around dashboards.

Companies invested billions collecting customer feedback, employee sentiment, operational metrics, and business intelligence. Entire software categories were built around helping organizations visualize that information and drive action.

The model worked extraordinarily well.

Companies like Qualtrics, Medallia, Tableau, Salesforce, and many others helped define a generation of enterprise software. But over time, a pattern emerged.

The problem was never collecting the data; the problem was getting people to use it.

Organizations spent years trying to encourage executives, managers, and frontline employees to regularly log into dashboards, review reports, identify issues, and take action.

Adoption became a business problem unto itself. The intelligence existed, but the behavior did not.

The hidden cost of dashboards

The challenge with dashboards is simple: they require users to interrupt their workflow.

Every dashboard assumes a user will:

  1. Stop what they are doing.
  2. Open a separate application.
  3. Find the relevant information.
  4. Interpret it.
  5. Decide what to do next.

That process creates friction, and friction is the enemy of adoption.

Today, most professionals spend the majority of their time in a handful of environments:

  • Email
  • Teams
  • Slack
  • CRM platforms
  • ChatGPT
  • Claude
  • Productivity applications

These have become the operating systems for modern work. Every additional application competes for attention against those environments, and most lose.

AI changes the equation

Large language models have created a new interface for work, allowing users to interact with intelligence through natural language rather than reports, dashboards, and portals. For the first time, intelligence no longer needs to live in a separate destination. Instead, it can travel directly to the user.

An executive can ask a question inside ChatGPT.

A seller preparing for a customer meeting can instantly surface market trends, competitive threats, and analyst insights directly within Salesforce.

A product leader can receive market insights through Teams.

A strategist can query complex research through an AI assistant.

The user never leaves their workflow, because the intelligence comes to them. This represents more than a user experience improvement: It’s about introducing a fundamentally different operating model.

The goal isn’t simply better intelligence. It’s reducing the friction between intelligence and action.

Why proprietary data matters more than ever

Many organizations believe AI itself is the competitive advantage. I believe the opposite.

As models become increasingly accessible, the differentiator will be intelligence.

Organizations that possess unique, proprietary, trusted data will have a significant advantage because they can combine AI with insights that cannot be found on the open internet. That’s exactly what makes this moment so rich with potential.

At IDC, we have decades of proprietary market intelligence: market sizing data, competitive positioning, technology adoption trends, vendor performance data, industry forecasts, and strategic research.

These are the datasets organizations use to make billion-dollar decisions. Historically, customers accessed that intelligence through reports, portals, and analyst interactions.

Today, AI allows us to reimagine how that intelligence is consumed.

From intelligence systems to decision systems

The next evolution is bigger than dashboards, and it’s bigger than reports. It’s even bigger than AI assistants.

The real opportunity is creating a technology intelligence layer that connects:

  • Market intelligence
  • Customer intelligence
  • Operational intelligence
  • Financial intelligence
  • First-party enterprise data

When those signals come together, organizations gain a more complete view of their markets, customers, competitors, and business performance. At that point, we are no longer talking about a research platform, but a new decision system.

IDC Quanta was built around this idea: bringing trusted technology intelligence directly into the workflows where decisions are made.

The organizations that win in the next decade will not necessarily have the most data, but they will have the least friction between intelligence and action.

Dashboards are dead because intelligence no longer needs a destination. It can travel directly to the moment of decision.

Nick Mercurio - Chief Revenue Officer - IDC

Chief Revenue Officer As Chief Revenue Officer of IDC, Nick Mercurio leads the company’s global commercial organization, including Sales, Customer Success, and Revenue Operations. He is responsible for accelerating growth, expanding customer value, and advancing IDC’s position as the technology intelligence layer of the AI economy.

Right now, the world is generating more than seven petabytes of data every second. That’s roughly the equivalent of producing 17 billion books every second. By 2029, that number will more than double. And that’s before more than a billion AI agents come online, each one generating, consuming, and amplifying information at machine speed. [IDC Global DataSphere Forecast, 2025–2029]

We’re drowning in information.

But more data doesn’t mean more clarity. In fact, it’s quite the opposite. Most of what’s flooding in isn’t even original; it’s copies, reprints, and regurgitations. And AI can make even bad data look very convincing.

In a world where noise is growing and clarity is fading; the biggest challenge enterprises face is discerning what’s real from what’s just an echo.  The winners won’t be the organizations with the most data. They’ll be the ones with frictionless access to the truth — and the confidence to act on it.

Today, IDC is delivering that with IDC Quanta, the technology intelligence fabric of the AI-enabled enterprise. For more than 60 years, organizations around the world have trusted IDC to help them navigate technology decisions and deliver data-backed intelligence to sharpen business strategies.

IDC Quanta takes the same structured, sourced, defensible insights, pairs them with your data and context, and puts them inside the tools your teams already use. A process that previously required disjointed systems, manual synthesis, and endless hours is now relevant, citable, and frictionless.

Intelligence embedded where you work

IDC Quanta lives inside email, inside Anthropic’s Claude AI, and inside the custom AI tools and workflows enterprises are building right now. No portal or separate login required. No need to leave the tools or workflows you’re already in. Instead, IDC Quanta gives you the ability to call on its intelligence the moment you need it — whether that’s a competitive client deal on the line, a board presentation, a roadmap under review, or vetting a new software platform.

Intelligence built on your context

Upload your own data and documents, and IDC Quanta synthesizes and visualizes them alongside IDC’s research in a single session. Adding to that is an extensive memory layer that ensures every conversation deepens what IDC Quanta knows about your role and your priorities, making each answer it returns sharper than the last. Your business context, combined with IDC’s, gives you a fuller picture than either could produce on its own.

But there’s something else important to note when it comes to context, and that’s security. With more than 175 beta customers helping us shape IDC Quanta’s development, the questions we heard most were simple: is loading data and documents secure, and are those documents used to train the model? The answers are “yes” and “no, respectively. Every upload lives in a private workspace with AES-256 encryption, enterprise-grade compliance and privacy controls, is automatically deleted after 90 days, and is never used to train IDC’s models. That means the confidence IDC Quanta gives you never comes at the cost of what you shared to get it.

Intelligence you can defend

Every response IDC Quanta gives runs through a multi-agent system that validates it against IDC’s 15B proprietary data points and expert-led research before it ever reaches you. An expandable reasoning panel shows exactly how the answer was built and includes detailed citations for answers you can stand in the boardroom and defend.

Intelligence on your schedule

IDC Quanta doesn’t wait to be asked. Automated scheduling capabilities enable IDC Quanta to proactively deliver the intelligence you need to monitor with regularity and then goes a step further, surfacing anonymized peer signals and related follow-up questions you didn’t know to ask.

An exciting future

IDC Quanta is live today and available to all current and new IDC customers. It was Amarok CIO Ashley Spicer who said it best:

“We are getting ridiculous, previously unimaginable value from IDC Quanta.  If you had told me 20 years ago that I would have access to something like this in my lifetime, I would have said no way. Our team is creating massive value by fielding questions and guiding understanding for critical decisions and strategic programs.”

With more integrations, more use cases, and packages tailored specifically for CIOs and IT leaders arriving this August, we’re just getting started. Intelligence will never be the same.

Visit www.idc.com/quanta to see it for yourself.

 

Lorenzo Larini - Chief Executive Officer - IDC

Chief Executive Officer of IDC, responsible for leading the company’s global strategy, operations, and growth. Lorenzo brings more than two decades of experience across the Research, Advisory Services, Enterprise Software, and AI sectors, most recently serving as CEO of Mint.ai, where he led the development of AI-driven workflow solutions. Previously, he served as CEO of Ipsos North America, where he led transformative growth for one of the world’s top market research and data analytics firms. He has also held global senior executive roles in Gartner’s technology division, including SVP of Executive Programs, advising global CIOs and enterprise leaders on digital transformation and operational excellence.

The fitness tracker on your wrist has quietly been turning from an electronic watch with a few cool features into something closer to a medical device, and AI is accelerating this change. Sensors such as those tracking heart rate, sleep, and body temperature have been increasing in accuracy for years, but for the most part the data they produce has been interesting yet largely non-actionable. What does the average user really get out of knowing their heart rate is 65 bpm and their readiness score is 80 out of 100? AI is changing that. For the first time, this vast and increasingly accurate data stream can be analyzed at scale, and the insights that are emerging are quietly revolutionary.

Detecting illness Before symptoms appear

Research has documented that even a common illness can produce early warning signs a full day before a person feels ill. Some of the most common signals are elevated core temperature and disrupted sleep patterns, both of which today’s smartwatches can already detect. So why does a single day’s warning matter? Because you may already be contagious. For nurses, doctors, and others who care for vulnerable people, the implications are striking. Imagine a doctor working in a small practice, seeing 25 patients a day. They’re uniquely exposed to infection, and when infected, uniquely positioned to pass it on to the most vulnerable people they treat. Now imagine that doctor had been wearing a device that flagged the infection, so they didn’t spend the day passing their illness to every patient who came in. Multiply this across a national healthcare system, and the number of preventable infections and deaths each year would be significant. AI improves this by making detection more accurate. Sleep patterns and core body temperature fluctuate for many reasons, including alcohol, caffeine, a heavy meal before bed, and jet lag, all of which create noise. But as AI evaluates ever larger volumes of data with increasing accuracy, that noise becomes easier to see through, and false positives and false negatives continue to decrease.

The longer horizon: Alzheimer’s and chronic disease

But why settle for a single day’s warning when wearable devices might soon detect the onset of illness years, even decades, before the first noticeable symptom? A 2025 review of sleep research links Alzheimer’s and other forms of dementia to detectable changes in sleep patterns more than a decade before recognizable symptoms begin. The link appears to run through deep slow-wave sleep, the part of the sleep cycle where the brain clears out metabolic waste, including the proteins that clump into Alzheimer’s plaque. Newer treatments can now help remove this plaque buildup and slow the disease’s progression, extending a person’s healthy lifespan. While major wearable manufacturers don’t yet claim to detect Alzheimer’s, Apple Watches have tracked sleep-cycle stages since 2022, and that measurement has grown more accurate over time. If that trend continues, it seems likely that Alzheimer’s will be detectable through a smartwatch within the next several years.

The data problem AI solves

These use cases are just the beginning. Sensors on smartwatches grow more precise with each generation, and hundreds of millions of people wear them every day. IDC’s Worldwide Quarterly Wearable Device Tracker counted 164 million smartwatches sold worldwide in 2025 alone. That volume of health data would have been unmanageable in 2020; analyzing it at any meaningful scale or accuracy would have verged on impossible. But with the buildout of data centers and advances in AI, today’s models can process this data efficiently, surfacing patterns no human could have spotted. If a person’s near-continuous stream of health data spanning years could be matched with their health records, and that approach scaled to tens of millions of people, the resulting insights would be substantial. Faint warning signs never considered before could be matched to the diseases they precede, long before the first noticeable symptom emerges. Integrating constant health monitoring and early detection into the medical system would shift it from reacting to emergencies to preventing them. Catching issues early is almost always the cheaper option, both financially and in terms of suffering. It’s the difference between finding cancer early, when a minor procedure can treat it, and finding it once it has spread, requiring grueling chemotherapy and years of costly treatment.

The barriers worth naming

Clearly there are legal, ethical, and logistical barriers to tracking a person’s health data for years, especially when matching it to their medical records. Many people will justifiably have concerns about companies accessing their health data, viewing the risk of data leaks and Big-Brother-style surveillance as not worth the upside. But many people already buy these devices for the health benefits they believe they offer, and deeper integration would only make that benefit more powerful. Data accuracy and AI hallucinations remain real concerns, but both sensor quality and AI reliability have improved rapidly and should continue to do so.

Where this is heading

In the long run, it seems inevitable that wearable devices and AI-generated insights will be deeply integrated into healthcare. Today’s system relies on overworked doctors who know little about the patient in front of them, glancing at a medical history before deciding how to proceed. Instead, healthcare should run on a system that holds a deep well of medical data on each patient, understands their individual baseline, and uses that data to inform diagnosis and next steps. That shift would turn healthcare from a point-in-time reaction to a crisis into a continuous, preventative system, one that saves both money and lives.

Frederick Stanbrell

Frederick Stanbrell - Research Analyst, IDC Europe Wearables

Frederick Stanbrell joined IDC in 2022, as an associate research analyst based in London, leading the European Wearables tracker. As head of the European Wearables tracker he collates guidance, tracks market trends and provides insight and forecasts into the region,…

The headlines from InfoComm 2026 said the industry moved “from rooms to experiences.” We’ve been observing this transition for a while. But what’s more relevant to anyone who buys, runs, or just sits in meeting rooms is that the room has become another device on the corporate network, and that changes who is in charge of it. 

For years, the meeting room was the thing on the wall you hoped would just work. InfoComm 2026 in Las Vegas, the pro AV industry’s big annual show, made the case that those days are over. The room is no longer a fixed installation. Yes, it is becoming an experience, but it also bears a striking resemblance to something IT knows all too well, a textbook case of AV/IT convergence: a managed device, bought like an endpoint, run like part of a fleet, and increasingly able to collect data about the people inside it. 

The industry has agreed on the theme: outcomes, not spec sheets, now drive what companies spend on collaboration technology. Buyers want rooms that simply work and that prove their value. But what’s worth exploring is how they get there. What is different in how a meeting room is bought, run, and governed? And who ends up operating it? 

Let’s look at some numbers. Attendance at InfoComm 2026 fell about 9% year on year. What rose was the share of buyers in the room. AVIXA (the Audiovisual and Integrated Experience Association, which owns and produces InfoComm) reported that end users made up 37% of attendees, a record, up from 35% last year and 29% in 2024. So fewer people came, but more of them were the ones who sign the purchase order. What they found was a transitioning market: value is continuously moving away from hardware and installation labor toward software, cloud, and AI. 

Three groups of announcements at the show summarize this: one each for how a room is bought, how it is run, and how it is governed. 

Your next room upgrade starts with the chip that runs on-device AI 

For years, a room upgrade meant better cameras, microphones, and displays. InfoComm 2026 reframed it as a decision about processing power. HP introduced its Poly Studio Room Compute, and Cisco showed new endpoints, built on an operating system called RoomOS 26 that it developed with NVIDIA, that run AI agents directly on the device rather than in the cloud, an approach some now call edge AI. 

Cisco leaned hardest on this point, and the argument threaded through the entire show: the features that do real work in a meeting, not just record it, need on-device AI processing, so a room built on incompatible or aging hardware simply cannot run them. In other words, AI in the meeting room is no longer only a software question. It’s about hardware. Perhaps the more uncomfortable part for most buyers is that a lot of the equipment bought in the last few years may not run the features now being sold, which turns a routine refresh into a spending decision that requires a business case. 

Enter the agentic AI 

Think about what happens today when a meeting room misbehaves. Someone files a ticket and waits for a technician. Well, according to InfoComm 2026, you will soon be asking an AI assistant to sort it out. 

Several vendors connected their room systems to AI assistants using the Model Context Protocol, the open standard that companies are adopting to let AI act on their other software. Neat’s version runs on your own network and works with assistants like Claude or Cursor, so the assistant can see what is wrong in a room, change the settings, and resolve common problems without specialist knowledge or a site visit. Others are taking their own routes to the same idea: Shure, the show’s headline partner, is moving beyond hardware with ShureCloud, which manages devices centrally and adds an AI assistant for troubleshooting and support, while Cisco has connected Microsoft’s Copilot to Webex. Related tools now watch over rooms from many brands, and across Teams, Zoom, Google Meet, and Webex, from one place. 

Why should anyone outside AV care? Because this is the same move toward AI agents that is happening across the workplace, only now reaching the meeting room, and the payoff is both money and time saved: fewer call-outs, fewer help-desk tickets. It also pushes the firms that install AV toward ongoing service instead of one-off projects. However, it is still early. Most of this was shown as a capability, not a full rollout, and whether “agentic” lives up to the label is still unproven. 

So the room is now collecting data. But who governs it? 

The moment a room becomes “intelligent”, it starts producing data: who was in it, who spoke, and how the space was used. That makes it interesting to a lot more people. HR, legal, and security now have a stake in it, alongside IT, and each comes at it from a different angle. 

HR sees a room that can log who attended, who spoke, and how much, and wants to reassure employees that this isn’t being used against them and retain their trust. Legal sees the recordings and transcripts as personal data: information that carries consent, retention, and residency obligations, and that can be pulled into discovery if a dispute arises. Security sees a networked device sitting in on confidential conversations and asks the obvious questions, namely who can access that data, where it is stored, and how much bigger a target the room has become. IT, which used to own the room outright, now runs it on behalf of all three. And there is still no security standard written specifically for AI in these systems, and general ones like NIST cover only part of it. 

The industry’s early answer is to keep the processing and the data inside the room rather than sending it to the cloud, which helps with privacy and with rules about where data is allowed to live. Those questions are climbing the data governance priority list for IT and security teams this year, and writing the policy before you roll rooms out widely saves you the harder job of untangling it later. 

The room reads you now. Time to read the room. 

The meeting room is now bought like any other endpoint, run as part of your device fleet, and governed as a data source. That is a long way from the box on the conference-room wall. 

What to do before your next upgrade:  

  1. Ask which AI features run on the hardware you already own, and what you would need to buy for the rest.  
  1. Before you believe any “agentic” pitch, run a small pilot and hold it to a measurable result, such as fewer support tickets.  
  1. And before you scale, decide who owns the data the rooms collect.  

Do that, and the answer to who operates your meeting rooms, AV, IT, or an AI agent, becomes all three, working alongside. The companies that treat the room that way will get the most out of what vendors are now building. 

Navigate your next workplace technology decision with the evidence to back it. Explore IDC’s Intelligent Workplace research, forecasts, and analyst guidance, or speak with our analysts

Gala Spasova

Gala Spasova - Senior Research Manager, Europe Smart Office and EMEA Content & Knowledge Management Strategies

Gala Spasova is a senior research manager in IDC's Future of Workplace & Imaging team. Her research focus is on Hybrid working, Smart Office technology and Content & Knowledge Management Strategies in EMEA.  Spasova is also part of the European…

随着AI和智能体在企业业务、生产和办公场景中的广泛应用,零信任网络访问(ZTNA)解决方案不仅要防护传统用户和设备,还需针对AI模型、自动化智能体、API调用等新型主体进行身份认证、访问控制和行为审计。AI和智能体已成为新的访问与攻击面,ZTNA架构必须扩展至“人+设备+AI Agent”统一治理,防范AI身份伪造、越权访问、提示注入等新型风险。

与此同时,AI技术正深度赋能ZTNA解决方案。通过行为分析、风险建模、自动化策略生成和智能响应,AI显著提升了ZTNA的动态风险感知、异常检测、自动化运营和复杂场景下的安全决策能力。AI不仅是防护对象,更是能力跃迁的驱动力,使ZTNA成为智能体时代企业安全治理的核心平台。

零信任理念已成市场普遍认知

在全球数字化转型、云化和远程办公常态化的推动下,企业IT架构正快速从传统集中式数据中心模式,演进为覆盖云、多云、SaaS、边缘计算与第三方生态的分布式体系。业务边界、访问边界和数据边界不断模糊,传统“内外网边界”安全模型逐渐失效。攻击面扩展至终端、API、云工作负载、供应链及AI应用生态,网络安全风险高度动态化和复杂化。身份滥用、会话劫持、权限滥用成为主流攻击路径,“身份即边界”成为行业共识。

零信任理念(ZTNA)以“永不信任、持续验证”为核心,通过身份、设备状态、行为上下文和风险态势的动态访问控制,替代静态信任模型,成为企业安全架构升级的主流方案。中国企业对零信任的认知度和接受度已广泛提升,ZTNA逐步成为企业现代安全访问控制的主流方案。

中国ZTNA市场规模与竞争格局

近日,国际数据公司(IDC)发布了针对中国零信任网络访问(ZTNA)解决方案市场的一系列报告:

  • IDC MarketScape:中国GenAI赋能的零信任网络访问解决方案2026年厂商评估
  • 中国零信任网络访问解决方案市场份额,2025
  • 中国零信任网络访问场景之软件定义边界市场份额,2025
  • 中国零信任网络访问场景之终端安全市场份额,2025

通过这些研究对中国ZTNA整体市场和主要细分市场的规模、产品发展现状和技术发展趋势,以及市场主要代表厂商的能力和特点进行了全面介绍。有如下洞察:

1. 中国ZTNA技术能力发展现状

  • 厂商ZTNA解决方案相关的各项基础能力建设已经趋于成熟。国内主流安全厂商已基本具备身份认证、终端可信接入、应用级访问控制、动态权限管理、细粒度审计以及持续风险评估等核心能力,并逐渐形成覆盖身份、终端、网络与应用的一体化零信任架构。
  • 中国ZTNA市场正加速向安全访问服务边缘(SASE)方向演进。随着企业业务环境向多云、SaaS与分布式办公架构发展,单一ZTNA能力已难以满足企业对统一安全接入与持续安全运营的需求。越来越多厂商开始将ZTNA与SWG、CASB、SD-WAN、数据安全、终端安全以及安全运营能力进行深度融合,构建统一SASE平台,实现跨网络、跨云、跨终端环境的一体化安全访问控制。
  • 中国ZTNA市场正在进入“AI赋能ZTNA”的新阶段。当前,基于机器学习、行为分析与GenAI能力的智能检测、动态风险评估、自动化策略生成以及安全事件分析,已经在众多安全场景中取得显著效果,推动安全体系从“人工驱动”向“智能驱动”加速演进。与此同时,AI正在显著提升安全产品的实时分析能力、自动化运营能力和复杂环境下的风险感知能力,逐渐成为安全产品竞争力的重要核心。
  • AI自身安全问题成为国内技术提供商重点关注的新方向。当前,行业已经开始围绕AI身份管理、提示注入防护、模型调用安全、敏感数据保护等领域持续加大研发投入,希望构建面向“人+设备+智能体”的新一代安全体系。从目前中国市场发展阶段来看,AI自身安全能力与ZTNA体系之间仍未实现充分融合,大部分厂商对于AI智能体身份治理、AI行为持续监测、模型调用链审计以及AI最小权限控制等能力支持仍相对有限。

2. 中国ZTNA市场规模发展现状

虽然近几年受到宏观环境的影响,中国整体网络安全市场承压明显,但ZTNA市场仍然凭借厂商不断完备的技术演进以及企业级客户的真实需求增长保持稳定增长态势。从市场规模来看,2025年中国零信任网络解决方案市场的整体规模达到27.6亿元,其中软件定义边界(SDP)依旧是最主要的ZTNA实现方式,市场规模为15.4亿元,零信任终端安全继续保持快速增长,市场规模为7.9亿元。深信服科技、奇安信、腾讯、启明星辰集团、亿格云、易安联、指掌易、华为等厂商在ZTNA市场占据重要的市场影响力。

IDC的调研发现,中国企业对零信任理念和ZTNA的认知度与接受度已广泛提升,ZTNA逐步成为新一代统一访问控制与身份安全体系的重要基础能力。主要技术提供商的ZTNA基础能力建设已经已覆盖远程办公、互联网暴露面治理、第三方接入、云原生、工业互联网及AI应用访问等复杂场景。同时,中国ZTNA市场正加速向SASE平台化演进,满足多云、分布式办公和AI应用生态下的统一安全接入与持续运营需求。IDC《中国智能安全访问服务边缘市场预测,2026—2030》报告数据显示,中国SASE市场在未来5年将保持快速增长,年均复合增长率为25.9%,市场规模在2030年将达到48.7亿元。

在另外一本《IDC MarketScape:中国GenAI赋能的零信任网络访问解决方案2026年厂商评估》报告中,IDC从能力、战略和营收等多个维度对国内市场主要的ZTNA解决方案技术提供商进行了全面评估,充分展现厂商各自的能力、优势和挑战,并最终选择阿里巴巴、持安科技、从云科技、缔盟云、华为、吉大正元、南凌科技、奇安信、启明星辰集团、山石网科、深信服科技、腾讯、网宿科技、易安联、亿格云、中国电信、竹云、指掌易入选本次报告(按拼音首字母顺序排列)。

ZTNA技术发展趋势:AI场景的双驱动

结合今年的市场研究,IDC对ZTNA解决方案的技术发展趋势有如下判断:

  • AI赋能ZTNA能力升级:国际与中国技术提供商普遍将AI/GenAI技术深度嵌入ZTNA体系。AI驱动行为基线建模、动态风险评估、自动化策略生成、智能事件分析与响应,显著提升安全事件分析、预测和处置的智能化水平,降低人工运维负担。
  • 智能体安全防护:随着大模型、智能体、MCP、API等新型主体广泛应用,ZTNA需扩展至“人+设备+智能体”统一治理。技术提供商需要加大AI身份管理、访问控制、提示注入防护、模型调用安全、敏感数据保护和行为审计等研发投入,防范AI身份伪造、越权访问、提示注入、敏感数据泄露等新型风险。
  • 平台化与生态化融合:ZTNA正加速与SASE、IAM、安全运营、数据安全等体系深度融合,向一体化安全访问与运营平台演进。技术提供商将强调开放集成能力,支持多云、SaaS、分布式办公、AI应用等复杂场景下的统一安全管控。
  • 行业场景化与持续运营:针对政府、金融、能源、制造等重点行业,技术提供商需要提供定制化ZTNA/SASE方案,强化与云服务、终端安全、身份安全、SaaS等生态伙伴协同。ZTNA/SASE产品从单点部署转向长期治理与持续运营,提供全生命周期服务。
  • 数据安全与合规:技术提供商普遍将数据安全能力原生嵌入ZTNA架构,支持敏感数据识别、分级管理、全流程追踪、动态脱敏、泄密溯源水印及多渠道外发管控。AI助力数据行为监测、异常识别和自动化响应,推动数据安全防护从被动防御向主动治理转型。

因此,AI既是防护对象,也是能力跃迁的驱动力。未来,ZTNA将逐步演进为AI时代统一安全控制平面的关键组成部分。技术提供商需积极拥抱AI赋能,强化平台能力和生态协同,持续提升产品智能化和运营服务能力,以应对高度动态化的业务与攻击环境。

IDC建议

IDC中国网络安全市场高级研究经理赵卫京认为,在企业数字化、云化与AI化持续深入的背景下,ZTNA正在与SASE、IAM、安全运营及数据安全等体系深度融合,向平台化、智能化方向发展。GenAI与智能体的快速普及,也在从‘AI赋能安全’和‘保护AI自身安全’两方面重塑ZTNA解决方案。当前,中国ZTNA市场整体已进入规模化落地阶段,厂商基础能力逐渐成熟,但在AI与安全的融合、统一运营以及复杂场景适配等方面仍面临挑战。未来,ZTNA将逐步演进为AI时代统一安全控制平面的关键组成部分。”

进一步交流

AI攻防规则已变。IDC深耕大模型安全与智能体治理研究,助您量化风险、重构防线。欢迎联系IDC,获取最新洞察与定制化咨询,共探破局之道。

Austin Zhao

Austin Zhao - Senior Research Manager

Austin Zhao, senior research manager of IDC China, focuses on research and analysis of the China network security market. He provides intelligence and consulting services to both local and multinational cybersecurity vendors. Austin has deep insights into the China network…

办公和协同软件市场正在经历从“AI助手”向“AI Agent”和“AI原生工作流”的剧烈转型。各组织正快速从孤立的AI试点项目,转向企业级规模化部署,从根本上重塑人力与智能系统之间的工作分配模式。这一转型凸显了人类独有的核心能力——判断力、创造力与关系管理能力,而AI智能体则负责处理常规性、重复性及知识密集型任务。进入2026年,这个市场的硝烟已经从简单的对话框延伸到了企业的核心业务链条中。OpenClaw这样的AI Agent开源项目的流行标志着AI原生的智能化工作平台在企业数字化转型中的加速落地:其以多Agent驱动、自动化流程和深度生态集成为核心,极大提升了团队协作效率和创新能力。AI Agent不仅重塑了智能化工作平台的用户体验,还推动了市场对AI驱动工作流、安全合规和开放集成生态的高度关注。

国际数据公司(IDC)于20266月发布的《中国智能化工作平台In-App AI Agent评估, 2026对于智能化工作平台领域中的AI助手/Agent能力进行评估,希望通过对中国市场中主要产品技术提供商的产品评测以及对最终用户的客观访谈来帮助市场更加全面地了解中国智能化工作平台AI能力的发展现状,能力特点和应用情况以及未来的技术发展趋势。IDC定义的智能化工作平台是指通过整合企业通讯、协同办公应用、生产力工作套件以及AI助手/AI Agent等数字化工具,帮助个人和组织高效、有效地完成任务或工作,实现目标的综合性平台。评估的内容包括智能办公能力、AI Agent流程自动化能力、集成和跨平台能力、基安全合规/Agent执行安全能力、行业解决方案和客户、AI生态建设等维度。

IDC通过这次评估观察到,智能化工作平台头部厂商的AI能力已经迈向逐渐成熟的发展阶段。领先厂商已经能够支持智能写作、会议纪要生成、文档总结、知识库问答、数据收集和分析、日程与任务建议、跨应用信息检索,以及基于用户指令调用部分办公工具完成稍有难度的任务。这说明AI能力正在从辅助内容生产,逐步走向办公流程中的任务协同。但是从一些评估维度来看,AI Agent流程自动化能力、Agent执行安全和AI生态建设整体得分偏低,说明该领域仍在快速探索阶段。模型稳定性、任务理解能力、流程编排能力、权限控制机制、执行边界管理以及生态伙伴协同机制尚未完全成熟,不同厂商之间的能力差异也比较明显。总体来看,当前市场的竞争核心正在从传统协同工具转向AI驱动的平台能力。未来市场竞争的关键,将不再只是AI功能的数量,而是厂商能否让AI Agent真正进入企业业务流程,并在可控、安全、可审计的前提下实现规模化应用。

基于本次评估情况和对未来趋势的判断,IDC认为,未来中国智能化工作平台市场将有以下发展趋势:

1. AI原生与多Agent驱动的智能化工作平台将成为主流

未来的智能化工作平台将以AI为核心驱动力,原生集成多模态协作、智能代理(Agent)、自动化、知识管理等能力。AI不仅承担任务自动化、智能推荐、内容生成,还将通过多Agent协作实现流程编排、知识流转和业务决策支持。IDC预测,企业将逐步从“AI插件”过渡到“AI原生”平台,AI与人、AI与AI之间的协作将成为提升创新力和敏捷性的关键。Agentic协作将推动企业从单一任务自动化迈向端到端的智能业务流程重塑。

2. 多模态与可视化协作体验持续深化

随着智能化办公场景的复杂化,智能化工作平台正快速融合文本、语音、视频、视觉画布、手势等多种交互方式。可视化协作(如数字白板、流程画布、可视化工作流)和“多人游戏化”体验成为主流。根据IDC全球调研数据,82%的企业认为视觉协作显著提升了创新与决策效率。未来,平台将进一步支持XR、智能硬件(如AI眼镜)、多语言和无障碍访问,实现全员、全场景的沉浸式协作体验。

3. 数据治理、信任与合规成为平台落地前提

随着AI和多方协作的深入,数据安全、隐私保护、合规和AI治理成为平台采购和部署的核心考量。平台需支持细粒度权限,权限继承自动化,数据驻留,合规认证(如GDPR、ISO等),合规审计可追溯,并通过透明的数据政策和治理机制建立员工与组织间的信任。IDC强调,信任是数字协作的基石,缺乏信任的协作空间难以实现持续创新和高效运营。

4. AI治理与FinOps兴起

随着数字员工增多,企业开始担心“AI乱花钱”或“AI越权”。因此,海外出现了专门审计AI Token消耗和AI安全合规的工具。Token成为财务成本,企业开始像审计水电费一样审计AI的Token消耗量。厂商需要推出更精准的ROI分析工具,用来证明AI助理到底帮员工省了多少时间。

5. 平台化与低代码深度融合

智能化工作平台正在从沟通和流程工具,升级为企业统一的工作入口。它可以通过连接ERP、CRM、HRM、财务和供应链等系统,把组织协作、业务流程和数据处理整合到同一界面中。与此同时,低代码能力将与AI和AI Agent深度结合。业务人员可以用自然语言描述需求,由AI辅助生成表单、流程、报表和轻量级应用;AI Agent则可以根据业务规则自动触发流程、分派任务、同步数据和提醒异常。

分析师观点

IDC
中国助理研究总监李昭表示,AI在办公场景中的演进,正在从“提升个体效率”加速走向“重构办公执行体系”。以OpenClaw为代表的新一代Agent框架,已不再局限于知识问答、内容生成、沟通协作、会议助手、数据和表格处理、日程规划等传统助手能力,而是进一步具备跨应用调用、连续任务执行和自主编排流程的特征,这标志着企业办公AI正从“会说”走向“会做”。软件不再只是工具,而是数字员工。AI Agent不再是被动响应,而是具备了规划能力,能自主跨应用完成复杂任务。与此同时,近期市场变化也表明,Agent的价值正在快速释放,但其规模化落地已不再只是技术问题,而是进入“技术能力、治理能力与成本模型”三重约束并行的新阶段。

进一步交流

如果您希望进一步了解Agent在企业软件中的落地路径、市场演进趋势或对自身业务的具体影响,欢迎与IDC分析师团队联系(点击此处)。IDC将基于持续的市场跟踪与研究,提供更具针对性的洞察与建议,支持企业与厂商在这一轮变革中做出更有前瞻性的决策。

Lizzie Li

Lizzie Li - Associate Research Director

Lizzie Li is Associate Research Director of IDC China's Enterprise System and Software Research that focuses on research and analysis of the China Datacenter, Cloud Computing, and IT infrastructure markets. She also provides intelligence and consulting services in customized projects for…

この記事でわかること:AIスーパーサイクルとは何か、そして日本にとって何を意味するのか。AIベンダーと日本企業のバイヤーの間にある最大のギャップとは何か。AIはB2Bテクノロジーの購買意思決定をどう変えているのか。

2026年6月23日、IDC Directions Tokyo 2026の会場には特別な熱気が漂っていた。日本のAIの転換点は、もはや「近づいている」段階ではなく、「すでに到来した」——それを物語る空気だった。IDCシニアバイスプレジデントのSandra Ngが伝えた中心的なメッセージは、警鐘であり、同時に進むべき道筋でもあった。彼女は率直にこう語った。問うべきは、AIが日本市場を変えるかどうかではない。誰が最短時間で最大の価値を生み出せるか、なのだ。

IDC Directions Tokyo 2026には約400名が参加し、そのうち65%が部長職以上。単なる情報収集の場ではなく、意思決定者が集う場となった。アナリストとの1対1セッションは軒並み満席となり、フロアから相次いだ質問の多さが、議論の核心を突いていたことを物語っている。

スーパーサイクルは現実だ。そして日本は、いま追う立場にある

何が起きているのか、そのスケール感を伝える数字がある。2025年、世界のIT支出は4兆2,000億ドルという市場規模の中で14%成長した。これは1996年以来、最も高い成長率だ。ただし当時、同じ14%成長が適用されていた市場規模はわずか7,000億ドル。桁がまるで違う。(出典:IDC Worldwide Black Book、2026年3月31日)

これこそがAIスーパーサイクルだ。中国・台湾・インドが「AIスーパーパワー・ビルドアウト」や「デジタルネイティブ・スケーラー」として競争を加速させる一方、IDCは日本を韓国とともに「レガシー・モダナイザー」と位置づけている。つまり、AIの価値にたどり着くまでの道筋が、モダナイゼーション(近代化)を必ず経由する市場ということだ。これは不利な条件ではなく、日本ならではの戦略的な立ち位置である。

日本のAI市場も、この勢いをそのまま映し出している。国内のAIインフラ支出は2026年末までに90億ドルに達し、2029年にかけて年平均24%(CAGR)で成長する見通しだ。AIサービスは2030年までに80億ドル、2025年比で3.2倍に伸びると予測されている。さらにアジア太平洋地域のCEOの61%が、エージェント型AIと生成AIの大規模活用を、新規投資の最優先分野に挙げている。(出典:IDC Worldwide AI and Generative AI Spending Guide、Forecast V1 2026;IDC CEO Survey、2026年3月)

ベンダーとバイヤーの間にある断絶が、双方にとって損失になっている

ここから議論は、耳が痛いが避けて通れないテーマへと移った。

Sandra Ngは、日本企業のバイヤーが本当に求めているものと、テクノロジーベンダーが実際に提供しているものとの間にある、4つの根本的なギャップを指摘した。

ギャップ①——ビジネスケースの明確さ
バイヤーが求めているのは、自社の業界に根ざした成果であり、グローバル共通の一般的なベンチマークではない。「日本のメーカーにとって、これは具体的に何を意味するのか見せてほしい」——このニーズは、海外の事例紹介スライドを並べるだけでは満たせない。

ギャップ②——AIの総所有コスト
このテーマは、通常の議論よりもう一段深く掘り下げる必要がある。日本でAIを導入する際の隠れたコスト——データ準備、システム統合、継続的なモデルメンテナンス、METIガイドラインへの準拠状況の監視、チェンジマネジメント——は、表示されている技術価格に対して50〜70%以上も積み上がるのが当たり前になっている。これを事前にはっきり示さないベンダーは、CFOとの商談で信頼を失っている。

ギャップ③——AIガバナンスへの準備
日本の規制環境は、決して名目だけのものではなく、独自の色合いを持つ。金融庁のAIガイダンス、METIのAIガバナンスフレームワーク、個人情報保護法(APPI)——いずれも高い基準を求めている。バイヤー側の動きの速さは、多くのベンダーのガバナンス対応が追いつけていないほどだ。

ギャップ④——「実例を見せてほしい」という瞬間
日本企業のバイヤーが求めているのは、国内のリファレンス顧客、導入までの具体的な期間、そして数字で示せる成果だ。海外の成功事例ではない。それを提示できないベンダーは、検討リストから静かに外されていく。

日本のトップ企業は、実際にどう動いているのか

これらのギャップは、机上の話ではない。2025〜2026年にIDCが実施したCxOへのヒアリングからは、日本を代表する先進企業がこの課題にどう向き合っているか、具体的な姿が見えてくる。

  • トヨタは、ハイパースケーラーのパートナーとともに自社開発のAIプラットフォームを構築し、年間1万時間分の手作業を削減した。AIを活用した品質システムによって塗装の不良率を25%減らしたことも、実績として記録されている。
  • 東京海上は、METIと金融庁のガイダンスを踏まえ、文書・画像分析へのAI導入に先立って、透明性・人による監視・バイアス排除・データ保護・運用面での信頼性という5つの柱からなるAIガバナンスポリシーを先に公表した。ガバナンスを先に固め、導入はその後——これが、日本の規制当局がいま求めている順序だ。
  • ヤマト運輸は、160万社の法人顧客と4,000社を超える物流パートナーからなるサプライチェーン全体に、AIによる最適化を導入した。80ルートに及ぶ中継拠点の最適化を通じて、人件費65%削減、温室効果ガス排出量42%削減を目標に据えている。

いずれも実験段階のパイロットではない。数字として記録された成果を伴う、本番環境での導入だ——まさに、バイヤーが求めているリファレンスストーリーそのものである。

バイヤーは、すでにAIを使ってあなたの会社を調べている

Sandra Ngのプレゼンテーションの中でも、とりわけ印象的だったデータがある。世界のテクノロジーバイヤーの84%が、「今後12ヶ月でAIが自社の技術購買のやり方を変える」と答えているのだ。(出典:IDC B2B Technology Buyer Survey 2025、WW n=406)

購買までの流れそのものが変わりつつある。今の順番はこうだ:AI検索 → ベンダーのウェブサイトで確認 → 同僚やピアによる検証 → チャネルパートナーへの相談 → 候補リストの確定。CIOやCFOがChatGPTやGoogle Geminiを使って調査したとき、あなたのブランドとソリューションが明確に浮かび上がらなければ、競争に参加していたことすら知られないまま、選考から外れているということになる。

だからこそ、AEOAnswer Engine Optimization:回答エンジン最適化)とGEOGenerative Engine Optimization:生成エンジン最適化)は、もはやマーケティングの実験ではなく、事業の存続を左右する能力になっている。2027年までに、日本企業の35%が体系的なAIガバナンスを整備すると予測されている。AIが生成する回答の中で、露出度が高く、信頼され、戦略的に進めているベンダーには、時間とともに積み重なる優位性が生まれる。(出典:IDC FutureScape 2026 – AI-Fueled Business Strategies、Japan)

エージェンティックAI:次の競争フロンティア

業界全体で起きている転換が、なぜスピードが重要なのかを裏付けている。IDC Japanの植村 卓弥が強調したように、AIスーパーサイクルは今、投資の第2波——インフラ構築からエンタープライズアプリケーション・サービスの採用へ——に入りつつある。エンタープライズ向けAIプラットフォーム・アプリ・サービスへの世界の支出は、2026年の4,000億ドルから、2029年には1兆ドルに達する見込みだ。(出典:IDC Worldwide AI and Generative AI Spending Guide V1 2026)

注目すべきは、調査対象バイヤーの83%が「AIエージェントによってサプライヤーの乗り換えが以前より容易になった」と回答していることだ。市場がコモディティ化する前に、成果ベースの関係をいま築いておけるベンダーこそが、次の競争優位を決めることになる。

今すぐ取るべき3つのアクション

Sandra Ngが最後に示したフレームワークは、シンプルで、すぐに動き出せる内容だった。

今すぐ行うこと:
一般的なベンチマークは捨て、日本国内のリファレンス顧客1社、指標1つ、導入タイムライン1つに置き換える。GTMのピッチを、CIOだけでなく購買委員会全体を意識した内容に組み直す。AIの中での自社の見え方(検索可視性)のギャップを、今すぐ修正する。

今年中に行うこと:
ROIの透明性を競争力の武器にする。実際に導入できるエージェント型ワークフローのストーリーをつくる。AIが生成する回答の中で引用されるよう、AIに最適化されたサードパーティコンテンツに投資する。

長期的に投資、実施すること:
AIガバナンス、トラスト、コンプライアンスを、新たな収益の柱として位置づける。あるいは、コンプライアンスを単なる話題ではなく、実際の成果として提供できるベンダーになる。カテゴリー、ペルソナ、地域ごとに「アンサーシェア」の計測を始める。SEO+AEO+GEOを組み合わせた、重層的なディスカバリー戦略を実行する。(出典:IDC C-suite Survey、2025年9月、APJ、n=300)

日本のAIスーパーサイクルは待ってくれない

日本のAI市場でリーダーの座を確立するための窓は、今現在は開いている——ただし、それが開いたままでいる保証はない。実験段階からいち早く成果ベースの導入へ進む企業、4つのギャップを埋めるベンダー、そしてAI主導の購買ジャーニーの中で自社を見つけてもらえる組織。これらこそが、日本のテクノロジー市場の次の時代をつくっていく。

東京で始まったこの対話は、大阪へと続く。

2026728日開催のIDC Directions Osakaでは、日本のAIスーパーサイクルが各業界をどう再編しているのか、次の価値創出の波がどこで生まれるのか、そしてあなたの組織がその一歩先を行くにはどうすればよいのかを、データとともにさらに深く掘り下げます。今すぐIDC Directions Osakaにご登録ください。席数には限りがあります。

Note:本記事は202671日に英語で公開されたブログの抄訳です。原文は以下からご覧いただけます:https://www.idc.com/resource-center/blog/japans-ai-supercycle-is-here-are-you-ready-to-lead-it/

Mike de la Cruz - Corporate Communications Director - IDC Asia/Pacific

Mike de la Cruz is Corporate Communications Director for Asia Pacific at IDC, bringing over 25 years of career experience in marketing and communications for the information technology industry. He shapes and amplifies IDC's research-driven narratives, positions executives and analysts as authoritative industry voices, builds relationships with top-tier technology and business media across the region, ensures consistent brand voice and positioning, develops content that drives audience engagement, and leverages social media and digital communications to extend IDC's reach.

On June 22, 2026, the White House made quantum computing a formal US national priority, releasing two executive orders that position quantum computing and post-quantum cryptography at the center of US industrial policy and national security strategy.

The urgency is evident in the data. IDC surveyed 535 US government organizations and found that 32% are currently running quantum computing pilots; among federal agencies specifically, that figure rises to 49%, with another 40% planning to launch pilots within the next 12–24 months. This is no longer theoretical exploration; it reflects active government commitment to quantum technology development.

Two executive orders target quantum computing

The first executive order, “Ushering in the Next Frontier of Quantum Innovation,” establishes the Quantum Computer for Application Development and Discovery Science (QC-ADDS) program. This initiative directs the Department of Energy, in coordination with Defense, Commerce, and intelligence agencies, to develop quantum computing systems capable of solving problems beyond classical computing capabilities. Potential applications include climate modeling, advanced signal processing, and defense logistics optimization.

The timeline is demanding: the Department of Energy must publish technical specifications within 90 days and explore private-sector partnership models within 180 days. The Pentagon is directed to field at least three quantum sensor projects by September 2028. The order also addresses critical infrastructure gaps, including stronger protections for domestic quantum supply chains, expanded counterintelligence measures for quantum technology, and a mandate for a government-wide quantum workforce strategy.

The second executive order addresses the defensive imperative: “Securing the Nation Against Advanced Cryptographic Attacks.” It confronts a specific and present threat: adversaries may be collecting encrypted US data today, banking on the ability to decrypt it once large-scale quantum computers become operational.

This tactic is known as “harvest now, decrypt later”: the practice of stockpiling encrypted data today in order to decrypt it later, once the technology catches up. It demands immediate action.

The order establishes a comprehensive post-quantum cryptography (PQC) migration strategy with clear deadlines. All high-value federal assets and high-impact systems must adopt PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. Federal contractors face identical compliance timelines, enforced through updates to the Federal Acquisition Regulation. NIST will begin pilot migration on its own systems by the end of 2027.

Quantum computing investment and market growth

These orders arrive at an inflection point for quantum technology.

IDC’s Worldwide Quantum Computing Forecast, 2025–2029 projects total spending will reach $17.3 billion by 2029, representing a 43% compound annual growth rate. Government investment has been a primary driver, with quantum spending increasing 37% between 2024 and 2025—gains attributed to advances in error correction and modular quantum architectures.

These executive orders follow the Department of Commerce’s May 2026 announcement of $2 billion in CHIPS Act funding for quantum manufacturing, signaling a pivot toward industrial-scale ecosystem development beyond early-stage research funding. Priority investment areas include manufacturing, packaging, cryogenics, and control systems: the engineering challenges that will determine whether quantum computing can achieve scalable commercial deployment.

Three factors that will determine quantum policy success

The effectiveness of these executive orders depends on three elements:

  • Funding continuity: Executive orders require sustained appropriations and bipartisan Congressional support to insulate quantum policy from electoral cycles. Organizations must prioritize use cases that deliver measurable return on investment within 12–24 months. Academia and private industry must also establish collaborative partnerships to share investment risks and accelerate development.
  • Organizational readiness and talent: The 90-day deadline for technical specifications will clarify the government’s near-term expectations. More fundamentally, both government and industry face significant quantum talent shortages. The current dependence on a limited number of advanced research centers and specialized technology companies represents a strategic vulnerability that must be addressed through coordinated workforce development.
  • Federal contractor preparation: The PQC compliance mandate for federal contractors, with its December 2030 deadline, has the potential to reshape procurement standards across the broader IT industry. Technology vendors and systems integrators that have already established quantum centers of excellence or actively participated in federal quantum pilots are positioned to realize competitive advantages.

What’s next for quantum computing policy

These executive orders represent a sustained commitment to transition quantum computing from the experimental phase toward operational deployment. The combined focus on innovation (QC-ADDS), defensive security (PQC migration), and supply chain development signals a comprehensive approach to quantum technology as critical infrastructure.

For agencies and contractors, the near-term deadlines are now fixed: publish technical specifications, hit PQC migration milestones, and build the workforce needed to run quantum and classical systems side by side.

Massimiliano Claps

Massimiliano Claps - Research Director

Massimiliano (Max) Claps is the research director for the Worldwide National Government Platforms and Technologies research in IDC's Government Insights practice. In this role, Max provides research and advisory services to technology suppliers and national civilian government senior leaders in…
Ruthbea Yesner

Ruthbea Yesner - Group Vice President, Worldwide Public Sector

Ruthbea Yesner is Group Vice President, Worldwide Public Sector, leading IDC's research teams for the Health and Life Sciences and Government and Education. Her teams deliver research and advisory services on the technologies, strategies, and business models shaping healthcare, life…

Most organizations still pick a security framework the way they did in 2022: find the biggest name, check the box, move on. That approach hasn’t survived contact with the last three years, three new regulations, a finalized quantum-cryptography standard, and an entirely new AI threat surface later.

The current situation: A framework landscape transformed since 2022

Choosing the right security framework has never been more consequential or more complex. When IDC last published comprehensive guidance on this topic in 2022, the landscape was manageable: a stable set of well-known frameworks and a relatively predictable regulatory backdrop. The intervening years have fundamentally changed both dimensions.

Four structural shifts now define what buyers must navigate:

  • NIST CSF 2.0 (February 2024) introduced a formal Govern function, its first major revision in a decade, elevating cybersecurity from an operational discipline to a board governance obligation and broadening scope to all organizations regardless of size or sector.
  • DORA (EU 2022/2554) became fully applicable in January 2025, imposing mandatory ICT risk management and third-party oversight obligations on approximately 22,000 EU financial entities.
  • PQC standards were finalized: NIST released three post-quantum cryptography standards in August 2024 (FIPS 203, 204, 205), transforming quantum readiness from a theoretical concern to an operational imperative.
  • AI has created a new risk surface: NIST published a draft Cyber AI Profile (IR 8596) in December 2025, extending CSF 2.0 specifically to AI-related cybersecurity risks. Organizations that have deployed AI, particularly agentic AI or LLM-integrated workflows, must now factor AI governance into framework selection.

The wrong framework choice, one that exceeds organizational maturity, understates regulatory obligation, or ignores supply chain exposure, produces worse security outcomes than a well-adopted, properly scoped, simpler framework. The good news: there are strong options. The challenge: the decision is more complex than it was three years ago.

Decision-making criteria and methodology

Security framework selection is a risk management decision, not a technical checklist, requiring input from legal, compliance, finance, operations, and the board. IDC’s 2026 methodology starts with crown-jewel data classification, then splits into regulated and non-regulated tracks, now including universal AI governance and quantum-readiness branches. Key criteria include data classification, regulatory obligations, threat landscape, and AI adoption footprint. Organizations deploying agentic AI face risks that general-purpose frameworks don’t address, while harvest-now-decrypt-later (HNDL) exposure demands cryptographic roadmap planning alongside traditional control mapping.

Additional criteria round out the methodology: third-party risk (CSF 2.0’s Govern function and DORA Article 28 set the compliance floor), PQC readiness (FIPS 203-205 are finalized, with 2030 as a planning horizon), and organizational maturity (smaller organizations should start with CIS Controls IG1 rather than overreaching). Budget discipline favors phased, risk-prioritized roadmaps supported by cyber risk quantification. Finally, multi-framework interoperability and GRC technology support are now prerequisites: manual evidence collection across concurrent regimes such as CSF 2.0, ISO 27001, HIPAA, and DORA is no longer sustainable at scale.

Regulated versus non-regulated organizations: Two different journeys

Regulated organizations

For regulated organizations, the regulator largely determines the framework; strategic focus shifts to execution. Key questions: How can multiple simultaneous requirements (DORA + ISO 27001; HIPAA + NIST 800-53) be satisfied without duplicating evidence work? Which GRC platform best automates cross-framework mapping? How should gap closure be sequenced within the budget? Have ICT third-party providers been assessed against CSF 2.0 Govern, DORA Article 28, and NIST 800-161? Mature organizations typically adopt a “framework stack”: CSF 2.0 or ISO 27001 as backbone, NIST 800-161 for high-risk vendors, plus industry-specific overlays.

Non-regulated organizations

Non-regulated organizations must perform more active analysis, with the right starting point depending on maturity. Early-stage or SMB organizations should adopt CIS Controls v8 Implementation Group 1, 56 safeguards achievable with limited staff, mapped to NIST CSF 2.0 for growth. Mature programs or those facing elevated threat exposure should adopt NIST CSF 2.0 or ISO 27001:2022, both of which include a Govern function that supports board-level accountability and SEC disclosure readiness. All non-regulated organizations, regardless of status, should evaluate the AI Governance and Quantum Readiness branches given their present-day risk implications.

AI and quantum: Two criteria that didn’t exist in 2022

Artificial intelligence: risk surface and governance obligation

AI has added two urgent dimensions to the framework selection process. Offensively, adversaries use LLMs for convincing phishing, automated vulnerability discovery, and direct attacks via model poisoning and prompt injection. Assess whether your framework addresses AI-enabled detection and response. Defensively, organizations deploying AI in production, especially autonomous agentic AI, face authorization, auditability, model integrity, and supply chain risks that general-purpose frameworks don’t address. The NIST Cyber AI Profile (IR 8596, December 2025 draft) extends CSF 2.0 across three risk areas and should serve as a supplementary governance layer. Shadow AI and SaaS-embedded AI remain largely unmeasured exposures requiring dedicated governance tooling.

Post-quantum cryptography: from theory to operational imperative

PQC standards are finalized: NIST published FIPS 203, 204, and 205 in August 2024, with a fourth HQC-based standard selected in March 2025. The harvest-now-decrypt-later threat is present today: adversaries are collecting encrypted data now to decrypt once quantum computing matures, creating real exposure for organizations holding financial, healthcare, or critical infrastructure data. NSA’s CNSA 2.0 mandates 2030 migration for National Security Systems; commercial organizations should treat this as a planning horizon, not a start date. Immediate actions include completing a cryptographic inventory, prioritizing long-lived data systems, evaluating vendor PQC roadmaps, and considering hybrid cryptographic approaches.

Essential guidance for the technology buyer

A well-adopted, properly scoped framework always outperforms a theoretically superior one that exceeds organizational capacity. Buyers should structure stakeholder conversations, including legal, compliance, finance, and the board, around the 10 decision criteria, treating AI governance and PQC readiness as first-order, not future-state, considerations. Conduct a cryptographic inventory now and evaluate AI footprint against the NIST Cyber AI Profile. Address third-party risk per CSF 2.0, NIST 800-161, and DORA Article 28. Favor frameworks with strong cross-mapping, invest in automated GRC technology, and adopt cyber risk quantification for CFO-ready budget conversations. Build a phased, five-year roadmap, closing highest-risk gaps first, and recalibrate annually.

“The right security framework is a critical factor in adequately managing security risks, not only those present today, but also those that could emerge in the future. The 2026 landscape demands that organizations evaluate AI governance and post-quantum cryptography readiness as first-order criteria, not future-state considerations.”Philip D. Harris, Research Director, Cybersecurity GRC Solutions, IDC

Guidance for the technology supplier and services provider

The security framework market is in structural transition, and suppliers calibrated to 2022 are selling into a market that no longer exists. Multi-framework compliance automation is now the dominant selection criterion, making unified control libraries across CSF 2.0, ISO 27001, HIPAA, and DORA essential. Suppliers should build DORA as a named capability, establish AI governance credibility now while the Cyber AI Profile remains in draft, and develop a PQC advisory practice anchored to cryptographic inventory services. Value propositions should be reframed financially for CFO-influenced procurement, while midmarket buyers increasingly favor managed compliance wrappers. Roadmap priorities span CSF 2.0/DORA now, Cyber AI Profile alignment in 2027, and full PQC/EU CRA support by 2030.

Philip D. Harris, CISSP, CCSK

Philip D. Harris, CISSP, CCSK - Research Director, Governance, Risk, and Compliance (GRC) Solutions

Phil Harris is Research Director for GRC Solutions at IDC, where he develops and promotes IDC's point of view on risk, advisory, privacy, and compliance services and software. He conducts research on business strategies and the impact of relevant offerings…

Global spending on digital transformation (DX) software is on pace to hit $640 billion by 2029, and where that money goes is shifting fast. IDC’s latest Worldwide Digital Transformation Spending Guide shows AI pulling value out of infrastructure and into applications, with the pace of that shift varying sharply by sector.

Software is becoming the primary engine of digital transformation

Digital transformation (DX) is the broad shift by organizations to embed technology into every layer of their operations, customer experiences, and business models. It spans hardware, services, and software. Data shows software is increasingly where DX investment is concentrating.

Among the three technology groups that make up DX spending, software is the fastest growing. Its share of total DX spend rises from 32% in 2026 to 36% by 2029, with a 21.7% CAGR, leading both services (10.6% CAGR) and hardware (19.8% CAGR). This momentum is increasingly driven by the scaling of AI, which is rapidly shifting value from infrastructure into applications and accelerating demand for AI powered software capabilities.

By 2029, AI will account for roughly 40% of worldwide DX software investment, which is a significant shift from today. The other 60% still flows into business applications, system infrastructure, and development and deployment platforms. The AI investments showing up across every sector in this analysis do not stand alone. They run on top of foundational layers already in place, and in many cases they depend on those layers to deliver value at all. Across the six sectors, the pace of AI adoption varies considerably, and that variation tracks closely with how mature the underlying software stack already is. AI is coming everywhere, but it is arriving on top of what organizations have already built.

Six sectors. Significant scale. Different priorities.

IDC’s Worldwide Digital Transformation Spending Guide (V1 2026) tracks DX software spend across six major industry sectors. Overall software investment is growing strongly in all six, and AI’s share within it is rising – but the pace, scale, and use case priorities differ considerably by sector. What drives DX spending in retail and services is not what drives manufacturing or financial services. Sector context matters.

“The growth in DX software is broad-based. This is not simply an AI spending wave. Organizations are investing across the full software stack to transform how they operate, and AI is an accelerating part of that — not the whole of it.”Mariya Yahnyuk, Research Analyst, Data and Analytics

#1 Retail and services

The Retail and Services sector leads all sectors in total DX software spend. This sector covers both retailers and a range of activities such as hospitality, travel, services, and more. Customer management tops the list of investment priorities: engaging customers across every channel, in real time, with personalized and consistent experiences. Omnichannel commerce and service delivery platforms come second, as both retailers and service providers now operate across physical, digital, and mobile simultaneously.

The third priority is operational intelligence: energy management, workforce scheduling, and efficiency tools that apply equally to store environments and service operations. Many of these investments sit in the applications and infrastructure layers of DX software – the customer data platforms, workforce systems, and integration layers that make AI useful when it arrives. AI is projected to grow to 42% of this sector’s DX software spend by 2029, building directly on that operational foundation.

#2 Financial services

Financial services have the highest existing AI share of any sector, and the broader DX investment picture explains why it got there. Security leads the use case list: detecting cyber threats and preventing fraud are areas where software investment delivers clear, measurable returns, making them natural anchors for DX spending early. Automating core business operations comes next, as financial institutions replace manual, rules-based processes with systems that can adapt and scale.

The pattern here is integration. AI is being built into existing DX programs, the same core applications and infrastructure platforms institutions have been modernizing for years. That is why the spending is sustaining: it is tied to operational outcomes that financial institutions already care about.

#3 Manufacturing and resources

Manufacturing currently has the lowest AI share of any sector in DX terms, which also makes it one of the most interesting to watch. DX investment here is driven by very practical pressures: aging equipment, fewer experienced engineers, and increasingly complex supply chains. The largest spending area is autonomic operations, production environments moving toward systems that can monitor and adjust on their own, recovering from most faults without needing a person in the loop.

Self-healing assets and augmented maintenance follow closely. A third priority, less obvious but growing, is customer and client management: manufacturers are increasingly investing to understand and serve end customers directly, not just to optimize internal operations. Together, these priorities describe a sector using DX investment to reduce operational risk, extend asset life, and build closer market relationships.

“Manufacturing’s lower AI share today should not be read as lower ambition. The use cases driving DX investment are autonomic operations, asset health, customer proximity, that’s exactly where AI delivers durable, measurable value. The growth trajectory reflects that.” —Mariya Yahnyuk, Research Analyst, Data and Analytics

Three actions for technology providers

The DX software data carries clear implications for technology vendors and platform providers. These are not passive trends to monitor – they are signals that should shape how you position, sell, and support your customers.

Help your customers understand where they stand. Most organizations do not have a clear view of how their software investment compares to peers in their sector. Use sector-level DX spending data to show them where investment is concentrating, where they may be behind, and what use cases are driving results for similar organizations. Then recommend tools that fit where they are in their journey.

Make the case for platform integration using evidence. Organizations that rely on fragmented point solutions face growing complexity as DX programs scale, and slower AI outcomes as a result. Many of your customers have not made that connection yet. Use the spending data trends to show them concretely that platform integration is delivering better results and why consolidation is the more practical path forward.

Treat data readiness as a customer success issue, not a prerequisite. DX outcomes and AI outcomes depend on the quality and accessibility of underlying data. Offer data quality and governance support as part of the engagement, so customers build data readiness while the work is underway.

Want the full picture?

This analysis draws on IDC’s Worldwide Digital Transformation Spending Guide (V1 2026), which covers DX investment across all six industry sectors, further detailed by 27 industries, 12 technology markets, and geographies through 2029. The full research covers Healthcare, Infrastructure and Energy, and Public Sector in depth alongside the three sectors featured here.

Mariya Yahnyuk

Mariya Yahnyuk - Research Analyst, Data and Analytics

Mariya Yahnyuk has been a research analyst in IDC’s Worldwide Data and Analytics team since 2022. Yaknyuk supports the development of IDC's Spending Guide portfolio, assuring alignment with technology and market changes, relevancy, and business value for customers Mariya directly…