Thought LeadershipAugust 14, 2026· 7 min read

Gartner Finds 93% Use AI but Only 38% Have a Strategy. ITSM Is Making the Same Mistake

Gartner's new survey of 743 audit professionals found that 93% use AI but only 38% have an AI strategy, with usage stuck in low-stakes drafting work. IT service management is running the same play. Here is what to measure instead.

Key takeaways

  • Gartner's August 2026 poll of 743 audit professionals found 93% use AI but only 38% have an AI strategy, with usage concentrated in low-stakes drafting work
  • ITSM shows the same gap: high chatbot adoption and conversation counts while people still carry most of the actual resolution work
  • Activity metrics such as conversations and adoption flatter a program; outcome metrics such as autonomous resolution rate, MTTR, and escalations tell the truth
  • A real AI strategy defines what AI is accountable for resolving end to end, under approval-gated and audited governance, and measures exactly that

Gartner published a survey this week that every IT leader should read, even though it is not about IT.

In a webinar poll of 743 audit professionals taken in 2026, Gartner found that 93% of audit leaders report some level of AI use, yet only 38% have an AI strategy. Usage clusters in the lowest-stakes work: 60% of respondents use AI to draft audit issues, ratings, or reports, while only 30% use it for audit testing and just 12% apply it to quality assurance reviews. Gartner's analysts concluded that although adoption is high, it is not generally transforming audit processes or producing better strategic insight, and they cautioned leaders against holding up adoption or productivity numbers as evidence of success.

Replace "audit" with "IT service management" and the finding still reads true. I have sat through enough QBRs to know the pattern: the AI slide shows thousands of conversations, strong adoption, decent satisfaction scores, and the ticket queue, the MTTR chart, and the agents' workload look exactly like they did a year ago.

That gap between AI activity and AI outcomes is the most important number in service management right now. Here is how to close it.

What the Gartner Survey Actually Found

The survey's detail is more interesting than its headline. AI use in audit concentrates heavily in the reporting phase: alongside the 60% drafting issues and reports, 41% use AI to review drafts and 35% use it to prepare stakeholder communications such as presentations. Another 37% use it for general productivity, such as writing emails or translating documents. The numbers fall off as the work gets closer to the core of the function: 35% for risk assessment and audit planning, 26% for knowledge management, 30% for audit testing, and 12% for quality assurance reviews.

Read that distribution carefully. AI is welcome wherever a human still owns the outcome and the cost of an error is a bad first draft. It is largely absent from the work that defines whether the function performs. James Bourke, a director analyst in Gartner's Risk & Audit practice, made the point plainly: current use skews toward moderate productivity improvement rather than strategic application, which is why high adoption is not producing transformation. Gartner's prescription was equally direct. Link AI initiatives to quality, consistency, and insight, and stop treating adoption levels or productivity gains as the measure of success, because a narrow focus on those metrics risks missing AI's broader impact on outcomes and decisions.

None of that requires an audit background to understand. It is a description of how most enterprise functions are using AI in 2026.

ITSM Is Running the Same Play

Service management has its own version of the 93/38 gap, and most IT leaders can quote their side of it from memory.

Adoption looks great. The chatbot handles thousands of conversations a month. Employees use it. Agents use AI to summarize tickets and draft replies. Copilots are everywhere. If the question is "are we using AI?", the answer is an emphatic yes.

Then ask a different question: what is the AI allowed to finish? In most deployments, the honest answer is "very little." The assistant points employees to a knowledge article, and the employee still opens a ticket. The copilot drafts a reply, and the agent still resets the password, provisions the access, and closes the record. The AI decorates every step of the workflow without owning any of them. Employees still wait. Agents still carry the queue. The operating model is untouched.

That is drafting-and-reviewing territory, exactly where Gartner found audit teams stuck: high activity at the edges of the work, humans in the loop for the entire middle, and no strategy that says what the AI is actually accountable for.

Activity Metrics Flatter. Outcome Metrics Tell the Truth

The reason this gap persists is that the metrics most programs report are the metrics that flatter the program.

Conversation counts, monthly active users, adoption rates, drafts generated, articles served: these measure motion. They will all trend up and to the right whether or not a single employee got their problem solved faster. Gartner warned audit leaders about precisely this, and the warning transfers cleanly to IT. Usage is not value.

Outcome metrics ask harder questions. What share of requests were resolved end to end with no human touching them? How many issues were resolved before they ever became tickets? What happened to mean time to resolution? To escalation and reopen rates? To after-hours load on the team?

These numbers are harder to move, which is exactly why they are worth measuring. Across Rezolve.ai deployments, roughly 70% of requests are resolved before they become tickets. MyEyeDr resolves issues in about ten minutes, and around 30% of its issues never become tickets at all. Black Angus Steakhouse cut its after-hours IT dependency from 90% to 10%. Those are the kinds of numbers a strategy can be built around, and defended in front of a CFO, because they describe completed employee outcomes, not AI activity.

What an AI Strategy for Service Management Actually Contains

"Have an AI strategy" sounds abstract, so let me make it concrete. In service management, a real AI strategy answers four questions.

First, what outcome are we targeting? Pick the numbers that describe the function working better: autonomous resolution rate, MTTR, first-contact resolution, employee hours returned. Put a target and a date on them.

Second, what is AI allowed to resolve end to end? This is the scope question audit teams are avoiding at 12% quality-assurance usage, and ITSM teams avoid it too. Define the request types where AI owns the resolution: password resets, access requests, software provisioning, policy questions. Then pair every grant of autonomy with governance: approval gates where actions carry risk, full audit trails, and reasoning you can inspect. Autonomy without governance is a liability. Governance without autonomy is a chatbot.

Third, what does the roadmap look like, and what evidence is it built on? Your ticket history already contains the answer. Clustering historical tickets reveals which categories are high-volume, repetitive, and automatable, and in what order to pursue them, which is precisely what DeskIQ does: it ranks automation opportunities with projected impact so the roadmap is an analysis rather than a guess.

Fourth, how do humans and AI divide the remaining work? Some work should stay with people, and for that work AI should shorten it: triage, summaries, similar-ticket search, and drafted replies in the agent workspace, which is Agent Assist's job. Meanwhile, governed agents built in Agent Studio take on the categories you have decided to hand over, all on a single system of record that keeps every action auditable.

Where to Start on Monday

You do not need a transformation program to close the 93/38 gap. You need one honest report and one decision.

The report: take the last 90 days of tickets and sort them by category and volume. Most organizations discover that a small set of repetitive request types, such as resets, access, installs, and "how do I" questions, accounts for a large share of the queue.

The decision: pick the first set of those categories AI will be accountable for resolving end to end, with approval gates where needed, and instrument exactly two things: how many were resolved autonomously, and what happened to the humans' queue. Expand from there, category by category, using the evidence to earn each expansion.

That is the whole difference between the 93% and the 38%. The 93% can show you their usage dashboards. The 38% can tell you what their AI is responsible for finishing, and prove it.

Gartner's closing advice to audit leaders was to stop pointing at adoption as success. Mine to ITSM leaders is one step blunter: stop counting AI conversations, and start counting completed employee outcomes. If you want to see what a service desk looks like when it is measured that way, we will show you ours.

See the agentic service desk in action

Watch Rezolve.ai autonomously resolve real IT and HR tickets: governed, auditable, glass-box.

Book a demo

Frequently asked questions

What did Gartner's August 2026 AI survey find?

In a webinar poll of 743 audit professionals taken in 2026, Gartner found that 93% of audit leaders report some level of AI use but only 38% have an AI strategy. Usage concentrates in reporting tasks such as drafting audit issues and reports (60%), while only 30% use AI for audit testing and 12% for quality assurance reviews.

Why doesn't high AI adoption equal transformation?

Because usage tends to cluster in low-stakes assistive tasks where humans still own the outcome. When AI only drafts, summarizes, and suggests, processes, cycle times, and results stay the same, so the organization gets activity without change.

Which metrics should ITSM leaders use to judge AI success?

Outcome metrics rather than activity metrics: autonomous resolution rate, mean time to resolution, the share of requests resolved before they become tickets, escalation and reopen rates, and employee time returned. Conversation counts and adoption rates measure motion, not results.

What does an AI strategy for ITSM include?

A target outcome with a date on it, a governed scope defining which request types AI may resolve end to end with approval gates and audit trails, a data-driven automation roadmap built from ticket history, and instrumentation that measures completed resolutions.

Saurabh Kumar
LinkedIn ↗

Get service-desk AI insights in your inbox

Practical guidance on agentic AI for IT and HR support: one email, no spam.

We use these details to respond to you. See our Privacy Policy.