Index Report · v1.1 · September 2026
assessments contributed to date

Segment benchmarks from AIMI's own respondent data are published only at N≥30 per cell. Until then the Index reports published external evidence — never a fabricated peer number.

State of AI Maturity in DACH Enterprises — 2026

v1.1 · 20 September 2026 (v1.0: 20 September 2026) · Andrzej Chądzyński, AIMI Research

Version note. v1.1 (20 September 2026) adds the McKinsey 2026 Global Survey, Gartner's September 2026 scaling survey and Bitkom's September 2026 DACH survey; no other figures changed.

What this is (honesty note). This report synthesises published, third-party evidence through the AIMI lens — the gap between AI adoption and AI maturity, read at the level of the business function. It is not yet "the AIMI Index": the proprietary index built from AIMI assessment responses follows only once the sample is large and representative enough to defend (see the methodology). Every figure below carries a named source. Authored for a board-level / executive audience, DACH-first.


Executive summary (one page for the board)

  1. AI adoption is now universal; AI maturity is rare. Nearly nine in ten organisations use AI regularly in at least one function and 44% report scaling it across the enterprise — yet only 37% see any EBIT contribution and just 6% are AI high performers, both flat year on year (McKinsey Global Survey, August 2026; n=1,719). Only ~1% consider themselves fully mature (McKinsey, June 2026). The question has moved from "are we using AI?" to "can we govern and scale it — and make it pay?"
  2. The constraint is no longer technology — it is the operating model. ~95% of GenAI pilots deliver no measurable P&L impact; the root cause is lack of integration, learning and process adaptation — not talent, infrastructure or regulation (MIT NANDA, 2025). BCG's case work puts ~70% of AI value in people and process change, only ~10% in algorithms (the "10-20-70" rule).
  3. Boards are accountable for a risk they largely don't understand. Disclosure of AI as a risk across the S&P 500 jumped 12% → 83% (2023→2025), while directors with AI expertise rose only 1.5% → 2.7% (The Conference Board). 66% of boards self-report "limited to no knowledge" of AI (Deloitte). Yet board engagement tracks value: 63% of high-AI-ROI organisations put AI on every board agenda, versus 13% of low-ROI ones (Protiviti/BoardProspects).
  4. In the DACH core, governance is regressing even as AI becomes universal. All DAX40 companies now treat AI as a strategic key technology, but only 12 of 40 meet full "Digital Leadership" criteria (down from 15), and digitalisation is a success metric in just 16 of 40 (down from 28) — the DAX Digital Monitor's first decline (2025).
  5. The regulatory clock has started — and the supervisor has not. Under the EU AI Act, transparency obligations (Art. 50) have been in force since 2 August 2026, enforceable with fines up to €15M or 3% of global turnover; high-risk conformity follows in December 2027. Yet only 9 of 27 Member States had designated both required authorities — in Germany the Bundesnetzagentur is named in draft law still awaiting parliament. Obligations are live and fineable while supervision is still being built: the responsibility sits with the board, not with a regulator's calendar.

The AIMI thesis: maturity is not capability you have, it is capability you can govern and scale. That is why AIMI scores at the level of the function and lets governance cap the level — you cannot be more "transformed" than you can oversee.


1. The adoption–maturity gap

Adoption is no longer the story. Stanford HAI's AI Index reports organisational AI use rose to 78% in 2024 (from 55% the year before). McKinsey's June-2026 "Seven Operating Truths" put use of AI in ≥1 function at ~88%, with only ~1% describing themselves as fully mature, and called the shift "the largest organizational paradigm shift since the industrial and digital revolutions."

The cost barrier that justified caution has collapsed: inference cost for GPT-3.5-level performance fell ~280× in two years ($20.00 → $0.07 per million tokens, Nov 2022 → Oct 2024; Stanford HAI). When access and cost are no longer the constraint, the differentiator is organisational maturity.

McKinsey's 2026 Global Survey (published 25 August 2026; 1,719 participants in 97 nations, fielded 4 May – 8 June 2026) makes the gap explicit. Nearly nine in ten organisations use AI regularly in at least one function and 44% now report AI scaling across the enterprise (up from 38%). 80% of respondents say AI has improved their own productivity. Yet only 37% report any positive EBIT contribution — flat year on year — and the share of AI high performers (≥5% of EBIT from AI) is stuck at 6%. What separates the 6%: nearly three-quarters have fundamentally redesigned workflows (versus one quarter of the rest), and they are twice as likely to have defined processes to measure impact. McKinsey's own conclusion: "The limiting factor is increasingly the organization's ability to absorb change." Gartner's independent read (1 September 2026; 1,303 organisations ≥ $50M revenue) lands in the same place: only 22% have scaled AI across multiple business units, and 11% do not even know what their function spent on AI.

And maturity is not arriving on its own. IDC's 2026 MaturityScape Benchmark (1,900 organisations across 20 markets) finds only 3.1% at the optimised stage and just 12.8% in the top two stages, while 61.3% remain in the two least mature stages. The mean maturity score moved from 2.39 to 2.43 in a year — statistically, the field is standing still. Ambition is everywhere; maturity is rare.

Notably, IDC elevated governance to a distinct dimension in this year's model, on the reasoning that "trust and risk management became prerequisites for scaling AI." An independent analyst house, working from its own dataset, arrived at the principle AIMI is built on: governance is not one ingredient among several — it is the precondition.

2. Why maturity — not technology — is the constraint

  • MIT NANDA (2025): ~5% of AI pilots achieve rapid revenue acceleration; the large majority deliver little to no measurable P&L impact. Crucially, the cause is not talent, infrastructure or regulation — it is the absence of learning, integration and contextual adaptation. (Precise framing: ~95% see no measurable P&L return — not "95% of the technology fails.")
  • BCG 10-20-70: ~10% of AI value comes from algorithms, ~20% from technology and data, ~70% from people and process change. "The technology is the small part."
  • Deloitte (Q4, 2,773 director-to-C-suite respondents): more than two-thirds expect ≤30% of their GenAI experiments to scale within 3–6 months — yet ~three-quarters say their most advanced initiative is meeting or exceeding ROI. Value is real where initiatives are mature; the gap is scaling, not viability.

Read through AIMI: these findings map directly onto AIMI's six dimensions — Data & Knowledge, Tooling & Agents, People & Skills, Process Integration, Governance & Risk, Value & Measurement — with the weight where the evidence puts it: people, process, governance.

3. Where value concentrates (the function view)

McKinsey estimates $2.6–$4.4 trillion/year of potential gen-AI value, concentrated in customer operations, marketing & sales, software engineering and R&D. This is why AIMI assesses functions, not organisations — and why its phase-1 functions are Customer Operations, Business Controlling (FP&A) and Field Service Management. Named, verified deployments anchor each:

  • Customer Operations — Klarna (2.3M chats in month one, the work of ~700 agents, ~67% of volume); IKEA/Ingka (Billie ~47% of inquiries, €1.3B remote-design revenue, 8,500 staff reskilled); Anthropic→Intercom Fin (50.8% resolution rate, ~1,700 hours saved in month one).
  • Business Controlling — finance-AI adoption 59% (2025) vs 58% (2024) vs 37% (2023); ~25% stuck moving from planning to piloting (Gartner, n=183).
  • Field Service88% report AI improving uptime/cost/CX and 75% better first-time-fix (Geotab 2025); Vodafone "Field Technician Assist" reported ~28% fewer repeat visits.

4. The DACH picture

The DAX Digital Monitor 2025 (FOM / Uni Duisburg-Essen) finds all DAX40 companies now position AI as a strategic key technology — but embedded governance is declining: only 12 of 40 meet full Digital Leadership criteria (down from 15), and digitalisation is an explicit success/compensation metric in only 16 of 40 (down from 28). Bitkom's representative survey of 603 companies (14 September 2026) shows what that looks like below the DAX: for the first time a majority — 57% — of German companies use AI (36% a year earlier, 20% two years earlier). But among those users, not one says it exploits AI's potential fully, and 59% say "not at all". German enterprises are universalising AI in strategy while regressing on the governance that makes it carry weight — precisely the gap a function-level, governance-capped measure is designed to expose.

5. The board & governance dimension

Boards now own AI risk faster than they have built AI competence:

  • The Conference Board (S&P 500): AI-risk disclosure 12% → 83%; director AI expertise 1.5% → 2.7% (for contrast: tech expertise 20%→51%).
  • Deloitte Global Boardroom: 66% of boards report "limited to no knowledge" of AI; 31% say AI is not on the board agenda.
  • MSCI Institute (14,500+ directors): only ~2% of individual directors are AI experts; 25% of boards have ≥1, but just 14% have integrated it effectively.
  • Protiviti / BoardProspects (772 board members & C-suite): 63% of high-AI-ROI organisations put AI on every board agenda vs 13% of low-ROI ones — engagement tracks value, not just oversight.
  • SmarterX / Marketing AI Institute (2026, n=2,109): only 13% of organisations have all four AI-governance foundations (roadmap, council, GenAI policy, AI-ethics policy); 32% have none.

This is the empirical case for AIMI's governance cap: an organisation that has deployed AI it cannot oversee is not more mature — it is more exposed.

6. The regulatory clock — now running

EU AI Act (Reg. (EU) 2024/1689): prohibited practices and AI-literacy duties applied from 2 Feb 2025; GPAI and penalty provisions from 2 Aug 2025.

Since 2 August 2026, Art. 50 transparency obligations are in force. Four things must now be disclosed or marked: that a user is not interacting with a real person; deepfakes (image, audio or video resembling real people, objects, places or events); emotion-recognition and biometric-categorisation systems; and text published to inform the public on matters of public interest without human review. Fines reach €15M or 3% of global annual turnover (EU institutions: €750k), enforced by national market surveillance authorities together with the European AI Office and the EDPS. The Commission has published Art. 50 Guidelines (20 July 2026) and a Code of Practice on Transparency of AI-Generated Content.

The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — deferred the high-risk tranche: standalone Annex III systems to 2 December 2027, AI embedded in regulated products to 2 August 2028. It did not touch Art. 50. (For prohibited practices under Art. 5, penalties remain the higher tier: €35M or 7%.)

The part boards should notice. Enforcement capacity lags the obligations. As of mid-2026 only 9 of 27 Member States had designated both a market surveillance authority and a notifying authority — against a deadline that passed in August 2025. Germany has named the Bundesnetzagentur for both roles in draft legislation still awaiting parliament; Austria has stood up an AI Service Desk but not yet appointed authorities. No Art. 50 enforcement actions were reported in the first weeks.

This is a sharper argument than "the regulator is coming". The duties are live and fineable now, while the supervisory machinery in DACH is still being assembled — so the discipline has to come from inside the company. A deferral is not permission to wait; it is the window in which prepared organisations pull ahead. For a DACH enterprise, AI maturity and AI-Act readiness have become the same conversation.

7. How to read an AIMI maturity level

AIMI scores a function on a five-level ladder — L1 Manual/Ad-hoc → L2 Assisted → L3 Integrated → L4 Orchestrated → L5 Transformed — across six dimensions, with governance capping the achievable level. The output is a level, a peer benchmark (shown as a model-based reference until a segment reaches a defensible sample — N≥30 per cell), a function-specific use-case roadmap with ROI, and EU-AI-Act exposure flags. Full scoring logic and its defence: methodology.

Why the level is capped rather than averaged. Deloitte's August 2026 readiness survey (n=501 US senior leaders) measured the same organisations on three fronts: 52% felt prepared on vision and strategy, 39% on risk, security and governance, and only 5% on the business processes themselves. Seventy per cent said they could not trust and govern AI agents; 74% expect roughly half their processes to be rebuilt around agents within four years, yet only about one in five believe they could actually carry out that redesign.

Average those three numbers and an organisation looks moderately mature. Cap at the weakest and the truth appears: strategy has run ahead, governance is trailing it, and execution has barely begun. AIMI reports the second number — because that is the one that determines what the organisation can actually carry.

8. Methodology & limitations (stated, not hidden)

This report synthesises published external evidence; it does not yet report AIMI's own respondent data. Peer benchmarks and any "Index" figures are released only once samples are representative (≥30 per cell; ≥150–200 per function) — until then AIMI is a self-assessment + roadmap, framed as such, with no fabricated numbers. Known limitations of the eventual respondent index: single-respondent self-report bias, convenience-sample skew, and the need for external methodological validation (see methodology).


Appendix A — Maturity markers: what each level looks like

A board member can self-locate a function on this ladder. Markers are generic across functions; the governance cap (right column logic) applies throughout. The behavioural patterns echo McKinsey's seven operating truths of AI-native companies (June 2026).

LevelWhat you see in practiceGovernance reality
L1 — Manual / Ad-hocIsolated, individual experiments ("shadow AI"); no ownership, no policy, no measurement. AI is a curiosity, not a capability.Nobody is accountable. Capped here regardless of tooling.
L2 — AssistedIndividuals use AI copilots for personal productivity; outputs are not integrated, shared or measured; the knowledge an agent would need is still trapped in people's heads.Informal at best; data-protection and AI-Act exposure unmanaged.
L3 — IntegratedAI is embedded in some core workflows with a named owner, a basic policy, and first KPIs; the knowledge layer starts to be captured and queryable (truth 3: "your model isn't the bottleneck — accessing your tribal knowledge is").An owner with mandate exists; classification and oversight are emerging.
L4 — OrchestratedMulti-step / agentic workflows with human-approval gates (truth 5: "trust precedes autonomy"); a model-agnostic, swappable stack (truth 4); success measured by full cycle-time (generation + review), not generation speed; adoption spreads through sharebacks (truth 7).A real governance backbone — identity, permissions, security tiers, data classification — is in place. Required to sit at L4.
L5 — TransformedAI reshapes the operating model of the function — new capability, not just efficiency; agents act as teammates with names and escalation paths (truth 1); humans are deployed surgically where judgement is irreplaceable; adoption is a self-reinforcing flywheel.Governance keeps full pace with capability — which is exactly why L5 requires top governance (the cap). A function with L5 capability but weaker oversight is scored down: that is exposure, not maturity.

How to use this for a board conversation: locate each material function on the ladder, then ask the truth-5 question — where is human approval mandatory, and is it encoded into the workflow today? Maturity is the capability you can govern and scale, not the capability you happen to have switched on.


Sources (named, verified)

McKinsey "The State of AI in 2026: On the road to ROI" (Global Survey, 25 Aug 2026, n=1,719/97 nations) · Gartner "Only 22% of Organizations Have Successfully Scaled AI Across Multiple Business Units" (1 Sep 2026, n=1,303) · Bitkom "Erstmals nutzt die Mehrheit der Unternehmen KI" (14 Sep 2026, n=603) · IDC "MaturityScape Benchmark: AI-Fueled Organization Worldwide, 2026" (n=1,900/20 markets) · Deloitte "AI Agents are Only the Beginning" (Aug 2026, n=501) · European Commission "Safer and more transparent AI" (2 Aug 2026) + Art. 50 Guidelines (20 Jul 2026) · Regulation (EU) 2026/1744 (Digital Omnibus on AI) · McKinsey "The Seven Operating Truths of AI-Native Companies" (June 2026) · McKinsey "Economic potential of generative AI" · MIT NANDA "The GenAI Divide: State of AI in Business 2025" (via Fortune) · BCG "10-20-70" / CEO's Guide to Maximizing Value from AI · Deloitte "State of Generative AI in the Enterprise" Q4 · Stanford HAI AI Index 2025 · Gartner 2025 Finance AI survey (via CFO Dive) · Geotab 2025 State of Field Service · Klarna/OpenAI, Ingka, Fin.ai (Anthropic→Intercom) · The Conference Board "Governing AI" (S&P 500) · Deloitte Global Boardroom · MSCI Institute · Protiviti & BoardProspects Global Board Governance Survey · SmarterX "2026 State of AI for Business" · DAX Digital Monitor 2025 (FOM) · EU AI Act Reg. (EU) 2024/1689.
Full source links, dates and samples: /research. Only figures verified at the primary source are used; publisher-attributed or unverified figures are excluded by policy.

How to cite: Chądzyński, A. (2026). State of AI Maturity in DACH Enterprises — 2026 (v1.1). AIMI Research, aimiresearch.com/the-index.

Author: Andrzej Chądzyński · v1.1 · 2026-09-20