KATA.

KATA / INSIGHT-002

AI導入が止まる本当の理由──ガバナンス整備とアップデートの追いかけっこ

Why AI adoption stalls — governance is losing a race against the update cycle

SERIES : INSIGHT — 経営と業界の考察 DATE : 2026.08.25 TOPICS : AI活用, コンサル

生成AIの導入について企業の方と話すと、「どのツールを選ぶか」で止まっている会社は実は少ない。詰まるのは選定の後だ。利用規約をどう整えるか、社内ルールをどう作るか、事故が起きたときに誰が責任を持つか。それを決めている間にAI側の機能が更新され、前提が変わり、検討をやり直す。この繰り返しで「検討中」のまま季節が変わっていく。

調査データも、この実感とおおむね整合する。

進む導入、出ない価値

導入率そのものは急速に伸びている。McKinseyの2025年調査(105カ国・1,993人)では、88%の組織が少なくとも1つの業務でAIを定常利用し、生成AIの利用率は72%と、2024年の33%から倍以上になった。日本でも帝国データバンクの2026年3月調査(有効回答10,312社)で活用企業は34.5%と、2024年調査の17.3%からほぼ倍増している。しかも活用企業の86.7%が業務効果を実感していると答えている。

一方で、価値の側の数字は厳しい。BCGの2025年調査では、AI導入企業の60%が投資に見合う実質的価値を生めておらず、大規模な価値創出に成功しているのは5%にとどまる。McKinseyでも、EBITの5%超をAIに帰属できる企業は6%しかない。MITのProject NANDAに至っては、企業の生成AIパイロットの95%が損益への測定可能な効果を生んでいないと報告した。S&P Globalの調査では、AI施策の大半を断念した企業が2024年の17%から2025年には42%へ跳ね上がっている。

使ってはいる。効果の手応えもある。しかし事業の数字になっていない。この乖離が現在地だと考えられる。

障壁の正体──ルールと運用の未整備

では何が価値創出を堰き止めているのか。人材不足がどの調査でも上位に来るのは事実だが、それと並んで一貫して浮かび上がるのがガバナンスだ。

ISACAが2026年5月に発表した調査(デジタルトラスト専門家3,400人超)では、正式で包括的なAIポリシーを持つ組織は38%で、25%はポリシー自体が存在しない。AIのROIが期待通りだったと答えたのは22%にとどまる。Deloitteの継続調査では、規制・リスクへの懸念が四半期を追うごとに拡大して最大の障壁に浮上し、自律型エージェントのガバナンス体制が成熟していると言える組織は5社に1社しかない。

日本はさらに一段遅れている。PwC Japanの2025年の5カ国比較調査では、生成AIガバナンスの中央組織を整備している企業が米中英独では80%以上あるのに対し、日本は64%だった。帝国データバンクの調査でも「トラブル時の責任所在などのルール整備」が課題として25.5%の企業から挙がっている。

追いかけっこの構造

ここで冒頭の話に戻る。ガバナンス整備が遅れている最大の理由を、私は担当者の怠慢だとは思っていない。構造的に、整備のスピードがAIの更新スピードに追いつかないのだ。

社内規程は通常、起案、法務レビュー、決裁という手順を踏む。数か月かかるこのサイクルの間に、AIサービス側では新モデルの投入、エージェント機能の追加、料金体系の変更が起きる。規程が完成した時点で、規程が想定していた利用形態が既に古い。

これは企業だけの問題ではなく、ルールを作る側全体で起きている。日本のAI事業者ガイドライン(総務省・経済産業省)は2024年4月の第1.0版から、2025年3月に第1.1版、2026年3月に第1.2版と、ほぼ年1回のペースで改定され続けている。EU AI Actも2025年2月から2027年8月まで段階的に施行が続く。国家レベルのルールでさえ「完成」せず走りながら直しているのが実態で、企業の社内規程だけが一発で完成するはずがない。

つまり「ルールが固まってから使う」という発想を採る限り、検討が終わる日は来ない。

それでも投資すべき理由

ではガバナンス整備を諦めて様子見に回るべきかというと、データは逆を示していると読んでいる。

生成AIのROI調査は、実は結果が割れている。IDCがMicrosoftの委託で実施した調査(2024年・世界4,000人超)は投資1ドルあたり平均3.7倍、先進企業では最大10.3倍のリターンを報告した。Google Cloudの2025年調査(24カ国・3,466人)でも74%の企業がROIを実感したとする。一方で前述のとおり、独立系の調査では価値を出せている企業は5〜6%にすぎない。ベンダー系調査に楽観バイアスがかかりうる点は割り引くべきだが、この乖離自体が重要な情報だと考えている。つまり生成AIの投資対効果は「平均」で語れる技術ではなく、やり方次第で数倍の差が開く分布の技術だということだ。実際、BCGの調査でも先進企業は他社の2.1倍のROIを見込んでいる。

調査の数字だけの話ではない。私自身が支援した生成AI導入でも、削減工数×時間単価を分子、導入・運用コストを分母に置いた単純な算定で、ROIは1000%を超えている。計測できた案件ではいずれもそうだった。もちろんこれは、導入の設計段階から外部の支援を入れた案件という偏りを含む数字だ。ただ、その偏りこそが本稿の論点でもある。設計と運用を整えた導入なら分布の上側は現実に届く、ということを実測として確認してきた。

そして上位グループと残りを分けている変数は、これまで見てきたとおり、モデルの性能でもツールの選定でもなく、運用とガバナンスの成熟度である可能性が高い。ポリシーを持つ組織が38%しかない世界では、ポリシーと運用を整えること自体が競争優位になる。ガバナンス整備は「守りのコスト」ではなく、価値を出せる5%側に入るための投資と位置付けるべきだと考える。

完成を待たないガバナンス

最後に、追いかけっこを前提にした整備の進め方を提案しておきたい。

第1に、最初から完成形を目指さない。禁止事項、データの区分(入力してよい情報・いけない情報)、困ったときの窓口。この最小限だけ決めて運用を始める。第2に、規程に版数を付け、四半期ごとの見直しを最初から予定に組み込む。国のガイドラインが年1回改定される時代に、社内規程だけ「制定したら終わり」という設計は現実に合わない。第3に、この暫定運用を回す人員と工数を正式に割り当てる。片手間の兼務で追いかけっこに勝てないことは、ここまでの数字が示しているとおりだ。

AIの更新は今後も止まらない。だからこそ、追いかけ続けられる体制を作った企業から順に、導入率と価値の乖離を埋めていくはずだと考えている。

出典

EN : English edition Business & Industry Insight

When I talk to companies about generative AI, few are actually stuck on which tool to choose. They get stuck after the selection: how to handle terms of use, what internal rules to write, who owns the risk when something goes wrong. While those questions are being settled, the AI itself gets updated, the assumptions change, and the review starts over. Repeat this a few times and a company stays "under consideration" for quarters on end.

The survey data is broadly consistent with this picture.

Adoption is up. Value is not.

Adoption itself is growing fast. In McKinsey's 2025 survey (1,993 respondents across 105 countries), 88% of organizations now use AI regularly in at least one function, and generative AI use has jumped to 72% from 33% in 2024. In Japan, Teikoku Databank's March 2026 survey of 10,312 companies found 34.5% actively using generative AI — nearly double the 17.3% of 2024 — and 86.7% of adopters report tangible benefit.

The value side looks much worse. BCG's 2025 research found 60% of AI adopters are not generating value commensurate with their investment, and only 5% are creating value at scale. McKinsey finds just 6% of companies can attribute more than 5% of EBIT to AI. MIT's Project NANDA reported that 95% of enterprise generative AI pilots produce no measurable P&L impact. And S&P Global found the share of companies abandoning most of their AI initiatives jumped from 17% to 42% in a single year.

Companies are using AI and feel it helps — but it is not showing up in the business numbers. That gap is where we are.

The real barrier: rules and operations

What is damming up the value? Talent shortages rank high in every survey, but governance shows up alongside them with striking consistency.

ISACA's poll of 3,400+ digital trust professionals (published May 2026) found only 38% of organizations have a formal, comprehensive AI policy; 25% have none at all. Only 22% said AI ROI met expectations. In Deloitte's tracking survey, regulatory and risk concerns have grown quarter over quarter into the top barrier, and only one in five organizations has mature governance for autonomous agents.

Japan lags further. PwC Japan's five-country comparison (2025) found 64% of large Japanese companies have a central body for generative AI governance, versus 80%+ in the US, China, UK and Germany. In the Teikoku Databank survey, 25.5% of companies name "rules for accountability when things go wrong" as a top concern.

The structure of the race

I do not read the governance lag as negligence. Structurally, the speed of rule-making cannot keep up with the speed of AI updates.

An internal policy typically goes through drafting, legal review and formal approval — a cycle measured in months. Within that cycle, AI vendors ship new models, add agent capabilities and change pricing. By the time the policy is finalized, the usage it envisioned is already out of date.

Nor is this unique to companies. Japan's AI Business Operator Guidelines (METI/MIC) have been revised roughly once a year — v1.0 in April 2024, v1.1 in March 2025, v1.2 in March 2026. The EU AI Act is phasing in from February 2025 through August 2027. Even nation-level rules never reach "finished" — they are patched while running. Expecting a corporate policy to be written once and be done is against the nature of the object it regulates. Which means that if your posture is "we will use AI once the rules are settled," the review never ends.

Why invest anyway

Should companies then wait it out? I read the data as pointing the other way.

ROI studies of generative AI famously disagree. An IDC study commissioned by Microsoft (2024, 4,000+ respondents) reported an average return of $3.7 per dollar invested, up to $10.3 for leaders. Google Cloud's 2025 survey (3,466 executives, 24 countries) found 74% of companies realizing ROI. Independent studies, as above, find only 5–6% of companies capturing real value. Vendor-sponsored optimism deserves a discount — but the disagreement itself is informative. Generative AI is not a technology with an "average" return; it is a distribution where execution opens up multi-x differences. BCG's own data shows leaders expecting 2.1x the ROI of everyone else.

Nor is this only what the surveys say. In the generative AI rollouts I have supported myself, computing ROI the simple way — hours saved times hourly cost in the numerator, implementation and running costs in the denominator — the figure has exceeded 1,000%, in every engagement where we measured it. The number carries an obvious bias: these were rollouts designed with outside help from the start. But that bias is precisely the point of this article — with design and operations in place, the upper end of the distribution is reachable, and I have measured it.

And the variable separating the leaders from the rest, on the evidence above, is not model choice but maturity of operations and governance. In a world where only 38% of organizations have a real AI policy, building the policy and the operating muscle is itself a competitive advantage. Governance spend is not defensive overhead; it is the ticket into the 5% that captures value.

Governance that doesn't wait for "final"

Three suggestions for building governance on the assumption that the race never ends.

First, do not aim for completeness. Decide the minimum: prohibited uses, data classification (what may and may not be entered), and a contact point for questions — then start operating. Second, give the policy a version number and schedule quarterly revisions from day one; when national guidelines are revised annually, a write-once corporate policy is a design error. Third, staff the loop properly. As the numbers above suggest, you do not win a race run as a side duty.

AI updates will not stop. The companies that build a capacity to keep chasing — rather than waiting for the finish line — are the ones I expect to close the gap between adoption and value.

Sources

Same as the Japanese edition above (McKinsey 2025; Teikoku Databank 2026; BCG 2025; MIT Project NANDA 2025; S&P Global via CIO Dive 2025; ISACA 2026 AI Pulse Poll; Deloitte State of Generative AI; PwC Japan 2025; IDC/Microsoft 2024; Google Cloud ROI of AI 2025; METI/MIC AI Guidelines v1.0–1.2; EU AI Act implementation timeline).


KATAは、戦略コンサルタントがAIを実務に入れる過程を記録している個人サイトです。

← 記事一覧 / All posts お問い合わせ / Contact RSS

KATAは、戦略コンサルタントがAIを実務に入れる過程を記録している個人サイトです。

X / @Katacons111note