The AI boardroom gap in Telecom

88% of organizations use AI. Just 39% report any EBIT impact. This report explains why — and what telco leaders can do about it.

88%

of organizations use AI in at least one function.

39%

report EBIT impact— often single-digit percentages.

2X

AI showed 2x the amount of security risk violations vs. human projects.

AI is everywhere.
Maturity is rare.

There’s a widening gap between bold AI ambition and reality. Most telcos aren’t falling behind on AI because of the technology, but because their foundations can’t support it.

01

The gap is real

88% of organizations are using AI in at least one business function, and 64% say that AI is enabling their innovation. However, at the enterprise level, just 39% report EBIT impact— often single-digit percentages.

02

Boards need a shared view

Only 12% of C-suite leaders can identify the right controls for common AI risks. Boards can’t govern what they can’t see.
In telecommunications, a shared view has to extend beyond enterprise IT to the software in customer-facing systems, OSS/BSS platforms, and core network infrastructure.

03

Regulatory pressure is rising

57% of organizations cite non-compliance with AI regulations as their top AI risk. And the rules keep changing by region.
In telecommunications, AI compliance rarely stands alone: it intersects with network security obligations and sector-specific regulators such as NIS2, BEREC, Ofcom, and the FCC.

04

AI systems introduce new security risks

AI generates 2x more security violations than humans. And only 29% of organizations have formal oversight of AI-generated code. Telecom leaders should bolster existing security management processes instead of treating AI security risks in isolation.

05

AI coding needs human oversight

AI can generate large and structurally maintainable software systems. However, only a small fraction of generated systems compile or run without modification, limiting practical significance and end-to-end usability. In telecommunications, 75% of systems already fall below SIG’s recommended maintainability threshold — creating risks boards may not know about.

06

AI systems are present but not widely adopted in enterprise

From all the systems (in production) SIG has analyzed in 2025, roughly 1.5% qualify as an AI system. Of those AI systems, 70% are traditional AI /ML systems and 15% agentic AI systems.
72% of AI systems score below our recommended build-quality threshold.

Five chapters.
One boardroom-ready view.

Written for boards, CISOs, and CTOs in financial services — grounded in SIG’s analysis of 400+ billion lines of code across 30,000+ systems.

01 /
The need for
AI governance
Strategy & oversight

Only 43% of operators investing in AI are also investing in the governance capabilities needed to make it operational. Inside: the one question every board should be able to answer — what you have, where it runs, who owns it, and how it’s controlled.

Chapter 1 — governance
02 /
Compliance
snapshot
Regulation & standards

57% name non-compliance as their top AI risk (EY), and in telecom it never stands alone. A global map of the EU AI Act, NIS2, BEREC, Ofcom, FCC, US, UK, and APAC rules, plus the ISO standards (including ISO/IEC 5338, co-developed by SIG) emerging as the shared language across borders.

Chapter 2 — compliance
03 /
AI-assisted
development
Speed vs. control

Reported impact swings from a 19% slowdown to a 26% speed-up. Only 29% of organizations report having formal oversight or processes to assess AI-generated code. What separates the two outcomes is governance, not tooling.

Chapter 3 — development
04 /
AI system
engineering
Quality & readiness

72% of AI systems in production score below SIG’s build-quality threshold. Why “in production” isn’t the same as “production-ready” for the systems running network optimization, fraud detection, and customer service — and what good actually looks like.

Chapter 4 — engineering
05 /
AI systems &
security risks
Exposure & assurance

With attacks getting faster and cheaper, and AI-generated code shipping with double the security violations of human code, the exposure is widening on both sides.
In this chapter: the three risks boards can’t ignore and how to extend the security you already have instead of building a separate AI-only framework.

Chapter 5 — security

Featuring perspectives from SIG, NautaDutilh, and code4thought.

Download the report

Everyone agrees technology runs the business, yet too many organizations still don’t have a clear, end-to-end view needed to steer it. That’s certainly not a new problem, but AI is turning up the speed, the stakes, and the consequences. In telecommunications, where aging platforms are already being asked to carry the weight of AI and 5G simultaneously, losing sight of your software estate shows up where it hurts most: in network performance, security, and the experience of every customer who depends on it. 

Luc Brandts
CEO, Software Improvement Group

Software visibility
Network performance
Security
AI and 5G
Consumer impact
 

Luc Brandts, CEO, Software Improvement Group

FREE DOWNLOAD

Turn AI ambition into board-level control

Global insights to close the gap and unlock a clear path to AI success for telecom operators in 2026.

Download the AI Boardroom Gap report

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

Download AI Boardroom Gap report

This field is for validation purposes and should be left unchanged.
Name*
Privacy*

This field is for validation purposes and should be left unchanged.
Name*
What type of partnership are you interested in?*
Privacy*

Register for access to Summer Sessions

This field is for validation purposes and should be left unchanged.
Name*
Privacy*