The gap between what AI can do and what we can control.
None of 3
leading AI cost tools we tested connect spend to a revenue outcome.
78%
of finance executives cannot fully tie AI spend to outcomes.
Vendor-commissioned survey; directional.
~1 in 5
vendors in a 90-company AI-GTM universe absorbed by a larger platform in 18 months.
Go-to-market organizations have deployed AI faster than they have built the ability to control it. This is not a report about whether AI works. It is a report about the distance between two speeds: how quickly an organization can switch on a new AI capability, and how slowly it can answer three much older management questions about that capability.
In this report, commercial control means an organization's ability to govern what AI can access, verify what it produces, and connect what it costs to the outcomes it delivers. Across every organization studied for this report, capability had raced ahead of all three.
The finding rests on three independent bodies of evidence, cross-checked against one another: an anonymized corpus of senior go-to-market practitioners, a bounded refresh of the public record, and direct product testing of the leading AI governance and cost tools. None was designed to agree with the others. All three surfaced the same three gaps.
The sharpest evidence is not an opinion and not a survey. When we tested the three leading AI cost-management platforms directly, none connected AI spend to a specific account, opportunity, or revenue outcome as a shipped capability. And the most resourced AI companies in the world describe the same three gaps in their own operations, on the record. If Microsoft, Salesforce, and Google have not closed these gaps with their resources, no go-to-market organization should assume the market will close them on its own.
The three gaps compound. An organization cannot trust the cost data it has not governed, and cannot govern access it has not verified. This report names the gaps, shows the evidence, and closes with three questions any leader should be able to answer today. Those who can have commercial control over their AI. The rest are not behind on adoption. They are behind on the second, quieter half of the same work.
Opening
The Maturity Mismatch
An organization can turn on a new AI capability in an afternoon. Building the ability to control it takes much longer, and most have not done it yet.
Over the past year, go-to-market teams have adopted AI at a pace that would have been hard to imagine two years ago. Adoption is up, tooling is everywhere, and the prevailing story is one of progress. That story is true. This report does not dispute it. It adds a second story that has moved more slowly and drawn far less attention.
Commercial control is an organization's ability to govern what AI can access, verify what it produces, and connect what it costs to measurable business outcomes.
Those three abilities lag capability everywhere we looked. Organizations are confident about what their AI can do. They are far less confident about who can reach it, whether they can trust what it produces, and what it is actually costing them against what it returns. We call these the three control gaps, and the rest of this report takes them one at a time before showing why they are one problem rather than three.
A note on evidence. Where a claim is a verified public fact, it is presented as one. Where it is our reading of the evidence, we say so. That distinction is kept throughout.
Gap One
Access and Governance
Who and what can the AI reach, once it is connected to the systems that run the business?
The most consistently raised issue among senior practitioners was not what AI could do. It was what AI could reach. Operators described being blocked, restricted, or made uneasy by how little control they had over what a tool could see once it was connected to a real business system.
One example stood in for many. A consultant could not use an AI file-drive connector on a client engagement, because the connector exposed the entire drive with no way to limit it to a single folder, in direct conflict with the client's data-handling agreement. The problem was not the model. The problem was that access was all-or-nothing.
Direct product testing confirmed this as a real and current limitation, not an anecdote. A leading AI assistant's file-drive connector offered only a binary choice: grant access to everything, or grant access to nothing. There was no native way to scope the tool to one folder.
Set against that, the picture inside a single well-configured system was more encouraging. At least one major CRM platform already enforces field-level and object-level rules on AI connections, applying the same permissions that govern human users. The gap, in other words, is not primarily inside any one well-run system. It is in the seams between systems. An organization's AI footprint rarely lives in one place. It spans the CRM, a file store, a messaging platform, and a lengthening list of point tools, each governed separately, if at all.
Verified incident · August 2025
The Drift product from sales-engagement vendor Salesloft became the entry point for a supply-chain breach in which OAuth tokens tied to its CRM integration were stolen. Cloudflare, a named affected customer, confirmed roughly 104 of its own API tokens were exposed. The cause was a conventional token supply-chain attack, not anything AI-specific, but it is a precise illustration of this gap: a third-party integration with broad, loosely scoped access to a CRM becomes the single point of failure.
There is a pattern worth naming in how organizations respond. Faced with uncertainty about how to govern access precisely, many reach for the blunt instrument, banning a tool outright or mandating a single approved one, rather than configuring the finer controls that, in at least one major platform, already exist. Why reach for the ban? One explanation, which this research raises as an open question rather than a settled finding, is that no single function clearly owns the decision. Security owns the tools that enforce access. RevOps owns the CRM. Individual operators adopt point tools directly, sometimes without telling either. When ownership is unclear, the blunt instrument is the path of least resistance.
Where this leaves an executive
"We banned the risky tools" and "we have a CRM with permissions" are not the same as "our AI access is under control." Neither addresses the seam between systems where the real exposure sits, and neither answers who is accountable for closing it.
Gap Two
Reliability and Verification
Can the organization trust the output without a hidden manual tax?
The practitioners most enthusiastic about deploying AI were also, consistently, the ones describing the most manual safeguards around it. This is the pattern that defines the second gap: the people closest to the technology trust it the least at face value.
One incident captured it. An automated weekly report silently pulled the wrong reporting period's data, and when the discrepancy was noticed and the tool was asked to explain itself, it produced a fabricated explanation rather than acknowledging the error. This was not raised as a rare malfunction. It was raised as the kind of thing that keeps otherwise enthusiastic operators from treating these tools as a dependable core layer without independent checking. The same operators reported reliability degrading as agents were asked to run several workstreams at once, which drove more manual review, not less.
The public record corroborates the pattern. Coverage through 2026 frames the moment as a rebuilding period for enterprise AI agents, driven specifically by reliability problems surfacing after early pilots. A survey of roughly 1,300 AI and engineering professionals found quality and accuracy cited as the single largest blocker to moving agents into production.
The organizations furthest ahead in adopting AI are, by their own account, also investing the most in checking it. That verification work is an unglamorous operating cost, and it tends to fall informally on whoever is already using the tool rather than being planned or budgeted for. It also sits underneath every optimistic productivity claim made about the same tools.
Scroll the exhibit →
Exhibit B. The tooling meant to supply verification is itself the fastest-consolidating category, a reason not to assume a stable, permanent verification layer yet exists to lean on.
Where this leaves an executive
A tool evaluated on capability alone is priced on only part of its real cost. The unpriced part is the verification required to trust its output.
One boundary, stated carefully: the rapid consolidation above should not be read as proof of reliability failure. Most of those were premium acquisitions. It is a reason not to assume a settled category of verification tools already exists.
Gap Three · The analytical payoff
Economics and Accountability
Can AI spend be connected to accounts, pipeline, and revenue outcomes?
This is the analytical center of the report, and the gap where the evidence is strongest.
Senior practitioners described AI spend growing large enough to require the CFO's direct involvement, with cost models built alongside finance because usage was accelerating faster than per-unit prices were falling. Some described being caught off guard when a vendor shifted from seat-based to usage-based billing. In the absence of anything better, a few had built their own token-tracking tools by hand.
Then we tested the tools directly. Of the three leading AI and cloud cost-management platforms we examined, none natively attributes AI spend to a specific CRM account, sales opportunity, or revenue outcome as a shipped, ready-to-use capability. All three are built for engineering and finance-operations buyers, require technical setup, and, with one partial exception offering finance-facing reporting, are not designed for a revenue leader to use directly. This is the most rigorously established finding in the report, because it is a direct product observation rather than an inference from silence.
The public record points the same way. A 2026 survey of more than 2,100 senior leaders across twenty countries found AI's shift to usage-based billing actively confusing finance leadership. Separate pricing research shows per-seat software pricing losing meaningful share to usage-based models over roughly the past year.
One vendor put a number on it. CloudZero, which sells directly into this problem, published research finding that 78% of finance executives cannot fully tie AI spending to business outcomes. The figure should be read for what it is: vendor-commissioned research, from a company with a direct interest in the gap appearing large, based on a survey that does not disclose an independent pollster, field dates, or margin of error. With that stated plainly, it is a directional data point from the supply side echoing what the practitioner testimony and the product testing had already established independently.
What the best-resourced companies admit
The most striking corroboration comes from the companies with the most reason and the most resources to have solved this already. In their own words, on the record, the largest AI operators describe the same three gaps inside their own businesses.
Scroll the exhibit →
Exhibit C. Three companies, three gaps, three on-the-record admissions. This is the frontier describing its own operations, not GAIN's opinion and not a vendor's marketing.
On access and governance, Microsoft built an entire control layer to retrofit governance onto agent sprawl, describing agents that "will increasingly need tools for identity, governance, security and more." A control plane for non-human actors is being built now, after the agents arrived, not before. On reliability, Salesforce's President and CMO described the core problem without euphemism: "you ask it the same question, you get 2 different answers. So it's a probabilistic nondeterministic system." On economics, Google's own CFO framed the company's AI investment not as proven return but as forward conviction: "a strategic commitment to balancing near-term returns with investments in future innovation."
Where this leaves an executive
If the frontier has not closed the gap between AI cost and business outcome with the resources these companies command, waiting quietly for the market to close it for you is not a plan.
One boundary, stated deliberately. A confirmed product gap is not the same as confirmed market demand. This report can say the tool connecting AI spend to revenue outcome does not yet exist as a shipped capability in the platforms we tested. It does not claim to know how large or urgent the market for building it would be. That would require direct validation with the leaders who own the budget, which is a next step, not a finding.
Synthesis
The Gaps Compound
Three gaps, not three purchases. They stack, and each one undermines the layer above it.
An organization cannot reliably connect AI cost to revenue outcome if it lacks governance visibility into what is being used, by whom, against which accounts. It cannot trust the cost and usage data it does have if the agent behavior producing that data has not itself been verified. Solve economics without governance, and you have built an accountability system on top of ungoverned inputs. Solve governance without reliability, and you are auditing access to a system whose outputs you still cannot fully trust.
Scroll the exhibit →
Exhibit A. Commercial control is one discipline, read from the foundation up.
This is why commercial control is one discipline in this report, not three line items. And it is why the durable lesson outlasts any single tool, vendor, or model generation.
Capability is bought in a day. Control is earned over quarters.
The lesson of Issue #2
The organizations that internalize that will treat their commercial operations with the same design discipline, verification, and accountability that good teams already apply to product and to code. The gap this report describes is, in the end, the gap between those two levels of rigor.
What This Means for GTM Leaders
Three questions. Answerable today.
This report stops short of a prescriptive roadmap. How to close these gaps will vary by size, industry, and existing tooling. So instead of a roadmap, three questions. Any go-to-market leader should be able to answer all three today. In most organizations studied for this report, they could not.
1
Access
If an AI tool is connected to your CRM, your file storage, or your messaging platform right now, do you know exactly what it can see, and who decided that?
2
Reliability
When an AI agent produces an account summary, a forecast input, or an outbound message, what is your process for catching it when it is wrong?
3
Economics
If asked what your organization spent on AI last quarter, could you say which accounts, campaigns, or deals that spend was in service of?
An organization that can answer all three has commercial control over its AI deployment. An organization that cannot is not necessarily behind on adoption. The evidence suggests the opposite is often true: the most aggressive adopters are the most exposed on all three questions. They are behind on the second, less visible half of the same work. That half is the work worth doing next.
Methodology and Evidence Standard
How this report was built.
This report is built from three sources, cross-checked against one another.
An anonymized senior-practitioner corpus
Senior go-to-market operators discussing real AI deployments in a professional setting, over roughly a two-month window. All of it is anonymized. No individual, employer, or source community is named anywhere in this report, and no direct quotes from that corpus are reproduced. It is used for human texture and pattern, never as sole proof of a claim.
A bounded refresh of the public record
Independent trade press, analyst research, named public incidents, and public-company disclosures, used to test whether the practitioner patterns held up against evidence gathered a different way.
Direct product testing
Rather than infer gaps from absence, the report's central finding was tested by directly examining the named capabilities of the leading tools in the relevant category and reporting what was, and was not, present.
Verified, then frozen
Every statistic was checked against its original source before publication. Figures that could not be independently verified were corrected or removed. Some proposed findings were tested adversarially and dropped when they did not hold up, including one claim that AI vendors themselves share their customers' gaps, which was investigated and abandoned as unsupported. Public-company statements were verified word-for-word against the earnings-call and filing record before being placed in quotation marks. A full source ledger is available on request.
The report distinguishes throughout between what was directly observed, what is a reasonable inference from it, and what is GAIN's interpretation of what it means. That discipline is the standard for this series.
[GTM]lgy
The research runs on GTMology, the commercial intelligence lab behind GAIN. It collects signals, normalizes company context, and synthesizes evidence across an account universe. It accelerates the research. The judgment, and the standard above, remain the work.
About This Series
Commercial intelligence for founder-led companies.
The GAIN Research Series examines how great commercial organizations will be built and operated. AI is the first domain the series takes up, because it is where the distance between capability and control is currently widest. The method is the point: verify the evidence, freeze it, then build on it.
GAIN is an independent commercial intelligence and research platform. If this report prompted a question, or an observation worth comparing notes on, a reply is the only call to action here.
Capability is bought in a day. Control is earned over quarters.