Back to resources

The AI Friction Tax, and What Removes It

Abstract

Enterprise AI investment is accelerating, but moving AI from pilot to production is still creating friction. Security reviews, compliance requirements, sensitive data access, and concerns about autonomous agents can slow approvals or reduce what ultimately ships.

Research commissioned by Protegrity and conducted independently by Enterprise Management Associates found that nearly 83% of surveyed IT and security leaders experienced AI production delays tied to security or compliance review. Among organizations reporting delays, two-thirds waited at least a month, while 82% said AI shipped in some diminished form.

The AI Friction Tax, and What Removes It examines why traditional access and review models struggle with AI systems that retrieve, combine, infer, and act across enterprise data. It also outlines an alternative approach built around protecting sensitive data itself, defining policy centrally, and enforcing that policy across AI workflows.

Key Themes

AI Friction Starts Between Pilot and Production

Many AI projects work technically before they reach security, compliance, and governance review. The paper examines how approval delays, restricted deployments, and governance overhead create an AI friction tax that can slow production.

Agentic AI Changes the Security Model

AI agents can inherit legitimate access while combining information, calling tools, and acting at machine speed. That changes the security question from simply who has access to what an agent may retrieve, combine, resolve, and do in context.

Protect Data and Enforce Policy Where AI Uses It

The paper outlines a model where sensitive data is protected at the data layer and policy is enforced across the datastore, agent tool call, and model prompt. Each decision creates evidence that security, compliance, data, and AI teams can use during review.

What You’ll Learn

  • Why enterprise AI projects can stall between pilot and production.
  • How agentic AI changes traditional access and governance requirements.
  • Why AI data protection needs to extend across data, agents, prompts, and model responses.
  • How central policy management and distributed enforcement can work together across AI workflows.
  • A practical path for applying these controls to one AI workflow at a time.