24.04.2026

8 min read · Updated: 23.04.2026

Ray Wang and Constellation Research have published the Enterprise Intelligence Monthly on April 22, 2026. The central message directly impacts boardroom discussions: AI is transitioning from promise to execution. Agentic scaling reveals architectural weaknesses. Cybersecurity is becoming the control layer for AI operations. Three observations are essential for board members to read, as they can shift the strategic tone for the next board meeting. Ignoring this update as a US-centric background noise overlooks the critical shift.

Key Takeaways

  • Observation 1: Agentic AI is moving out of the demo phase, and scaling challenges are becoming concrete board-level questions.
  • Observation 2: Cybersecurity is becoming the control layer for AI operations, which is structurally enhancing the role of CISOs.
  • Observation 3: Competitive advantage is shifting from models to infrastructure, requiring a reevaluation of vendor assessments.
  • Conclusion: Boards should no longer view AI in 2026 as an IT topic but as an integrated strategy, security, and investment theme.
  • Time Frame: By the end of Q3 2026, companies that have not consolidated a board-level perspective on these three axes will lose momentum compared to competitors that have grasped the shift.

What Constellation Really Says in the April Update

What is Agentic AI Scaling? Agentic AI scaling describes the transition from individual agentic applications in the pilot phase to multiple agents operating productively in business processes. It requires a comprehensive platform with shared identity, data, and compliance layers. Companies operating a single agent do not need a platform, but those running ten do. By 2026, many companies that have invested in individual use cases over the past 18 months will reach this threshold. Constellation identifies these scaling challenges as a central board-level issue.

In the April update, the observation focuses on agentic applications transitioning from pilot to scaling in 2026. This creates a different class of scaling challenges compared to individual pilots. Suddenly, interactions between agents emerge, and permission boundaries need to be redefined. Cost allocation per agent becomes a serious control challenge. Ray Wang argues that many companies underestimate this scaling challenge because the pilot phase gives a false impression of complexity.

A second observation changes the role of the CISO. Constellation argues that by 2026, cybersecurity will no longer be a risk layer alongside business layers but the control layer for AI operations. Companies running productive agentic applications need security mechanisms that provide audit trails, identity boundaries, and response pipelines. This elevation of the CISO role has direct implications for board structures. Boards that delegate cybersecurity to the audit committee must actively manage the integration with the tech mandate.

The third observation impacts vendor evaluation. Constellation notes that competitive advantage is shifting from models to infrastructure. By 2026, having the best model will be less critical than having the best data and compute infrastructure. This has strategic implications for vendor selection, platform investments, and contract architecture. The Meta Muse Spark Closed-Source Shift is a signal in this direction: vendors are now competing for platform dominance rather than model headlines.

3 Observations
from the Constellation Enterprise Intelligence Monthly April 2026, which boards should incorporate into every tech discussion in 2026
Source: Constellation Research Enterprise Intelligence Monthly Update April 2026

How the Three Observations Translate to DACH Supervisory Boards

The first observation focuses on strategic architecture discussions. Supervisory boards should explicitly ask in the next meeting how many agentic applications are currently running productively in the house, which platform layer they connect to, and how the scaling logic is planned. Those without a consolidated answer have a governance issue. The Merck-Google-Cloud Alliance is an example of how this architectural question is addressed in a regulated conglomerate.

The second observation changes the CISO mandate. Boards should clarify whether their CISO has the mandate and resources to oversee AI operations as a control layer. In many DACH houses, the CISO mandate is still traditionally limited to IT security without explicit AI responsibility. Those who do not update this risk shifting the responsibility to a position without a formal mandate. This can lead to avoidable friction during the first serious crisis.

The third observation requires a provider inventory. Which of our current AI and platform providers have genuine infrastructure depth, and which primarily sell models? Which contracts should be adjusted by 2026 or 2027 because the competitive logic has shifted? This inventory is worth a half-day strategy workshop with IT leadership, procurement, and compliance. The managed services discussion provides the operational template.

What Supervisory Boards Should Actively Address

  • Number of productive agentic applications with scaling plan
  • CISO mandate for AI operations control layer
  • Provider evaluation based on infrastructure depth rather than model promises
  • Quarterly maturity KPIs in board briefings

What Boards Should Not Do by 2026

  • Delegate KI topics to IT leadership entirely
  • Treat CISO as a pure risk reporting function
  • Extend provider contracts without infrastructure architecture evaluation
  • Accept pilot stories as proof of maturity

How the Observations Connect with Other April Signals

The Constellation note is not alone. Three additional April signals reinforce the strategic message. First, the Merck-Google-Cloud Alliance on April 22 with its commitment to Gemini Enterprise as a platform rather than individual KI tools. Second, the Cognizant-Fortune argumentation on outcome-based IT service models that cannot function without an agentic AI platform. Third, the ASP.NET Core patch wave from Microsoft, which shows how closely engineering and compliance must be intertwined by 2026.

For supervisory boards, this results in a consistent message. The KI discussion in 2026 is not a side-season tech initiative but an integrated strategy, security, and investment question. Those who treat it in isolation in any of these three areas build in friction losses. Those who integrate it gain strategic depth. This integration requires conscious board architecture where tech, risk, and strategy topics do not fall into separate committees.

A second connection deserves attention. The Constellation observation on cost governance directly links to the FinOps maturity discussion. Those who want to perceive KI as a quarterly burden need a consolidated cost allocation view that spans across departments and tools. Supervisory boards should request a consolidated cost report quarterly that details KI spending by business unit, provider, and use case class. Those who cannot provide such a report have a governance gap that will become visible in the next crisis.

A 90-Day Path to a Consolidated Board Perspective

Three months are sufficient for substantial preparation of the next board meeting with a clear stance on the three constellation observations.

Month 1
Inventory. Count productive agentic applications, platform architecture, CISO mandate, provider landscape. Result: tabular overview with maturity indicators.
Month 2
Strategy Workshop. Evaluate three axes per business area, prioritize gaps, explore investment options. Involve external sparring partners from the advisory board or independent consulting.
Month 3
Board Presentation. One page per observation with concrete recommendations, investment framework, and success KPIs. Clear language, without tech jargon, with explicit decision options.

What the Constellation Note Means Structurally for Boards

Three strategic consequences deserve the attention of boards. First: Tech topics lose their niche position in the board calendar. AI will be a cross-cutting theme in every strategy, risk, and investment discussion by 2026. Anyone who relegates the AI discussion to an annual agenda item has a governance problem. A quarterly tech session with a clear topic architecture is the answer.

Second: The hybridity of mandates increases. CIO, CISO, and CFO work more closely together in the AI discussion than two years ago. Boards should actively shape the interfaces, otherwise friction losses will occur. A clear mandate clarification with documented responsibilities per AI axis is not bureaucracy but governance hygiene by 2026.

Third: The evaluation of external sources becomes more important. Constellation, Forrester, Gartner, and Bitkom provide different slices of the same reality. Boards should not favor one source but consciously shape the mix. Anyone who builds a quarterly synthesis from two US sources and two DACH sources has a better discussion foundation than a house that relies on a single provider report.

One final observation belongs in the strategic discussion. Constellation argues that the competitive landscape will shift faster in 2026 than board routines can keep up. Anyone as a board member who has a quarterly reporting that does not reflect the shift is flying blind. The adjustment of reporting logic belongs in the next meeting. Anyone who delays this will be in a discussion in 2027 that they could have prepared for in 2026.

Frequently Asked Questions

Who is Ray Wang and why is his observation valuable for DACH Supervisory Boards?

Ray Wang is the founder and principal analyst at Constellation Research in Silicon Valley. His Constellation Enterprise Intelligence Monthly is recognized as one of the most important independent sources for enterprise technology topics. Supervisory boards appreciate the combination of quantitative observation and sharp analysis, which structures board discussions.

How does Constellation compare to Gartner and Forrester?

Constellation works leaner and more opinionated, while Gartner and Forrester bring greater research depth and quadrant evaluations. Constellation is ideal for strategic briefings, and Gartner and Forrester are better for vendor selection. A combined use covers the spectrum.

Which DACH sources complement the US perspective?

Bitkom studies for Germany, Lünendonk for vendor evaluations in the DACH market, and IfM Bonn for mid-sized company perspectives. Constellation and these sources complement each other well because DACH structures are not fully captured by US reports.

How often should Supervisory Boards include such sources?

Quarterly as a mandatory program, monthly for tech-focused Supervisory Boards, or when making important architecture decisions. A quarterly internal synthesis on one page is the right cadence.

What does “Cybersecurity as a Control Layer” mean in practice?

The CISO function will mandate AI operations by 2026, with identity boundaries for agents, audit trails for agent decisions, and a detection layer for unexpected AI behavior. Cybersecurity will become a cross-cutting theme, not a downstream risk block.

What is the scaling threshold for agentic applications?

Once you reach five to ten productive agents, a true platform architecture becomes worthwhile. Below that, ad-hoc setups may suffice, but beyond that, complexity without a platform becomes uneconomical. Supervisory Boards should actively monitor this threshold.

Source Title Image: Pexels / Werner Pfennig (px:6949476)

Share this article:

Also available in

More Articles

04.08.2026

Local AI: Governance Before Hardware Purchase

Benedikt Langer

10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...

Read Article
03.08.2026

AI Regulation: Up to 3 Percent of Corporate Revenue

Tobias Massow

5 min read Article 50 of the AI Act has bound providers and deployers to concrete transparency obligations ...

Read Article
31.07.2026

You are paying for the R&D of the next competitor

Benedikt Langer

4 min read You are funding the R&D of your next competitor and calling it AI transformation. Frontier ...

Read Article
29.07.2026

Model Harness Instead of Model Marriage: Who Controls the AI Chain?

Eva Mickler

6 min read The lock-in is shifting from the individual model to the orchestration layer. Those who don’t ...

Read Article
28.07.2026

Washington decides which AI is allowed to run here

Eva Mickler

6 Min. read time In just eight days, Washington has shifted the dispute over Chinese AI models from ...

Read Article
23.07.2026

Orphaned Access: The Silent Cybersecurity Gap

Benedikt Langer

5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...

Read Article
A magazine by Evernine Media GmbH