17.03.2026
4 min read

IT budgets are growing 9.8 percent nominally in 2026 – but shrinking in real terms after inflation. At the same time, CIOs are expected to scale AI, implement NIS2, reduce cloud costs, and strengthen security. The AI budget paradox reveals a stark truth: CIOs cannot fund everything simultaneously. Those who fail to prioritize radically will founder on the mathematical impossibility of their mandate.

TL;DR

  • 📊 9.8% nominal growth, but real decline: According to Gartner, global IT budgets are rising 9.8 percent nominally. After accounting for inflation and rising software license costs (Microsoft alone increased enterprise licenses by 10-15 percent), there is no real growth.
  • 💰 AI consumes the budget: Gartner estimates AI spending will become the single largest line item in the IT budget in 2026. GPU costs alone can consume 15-25 percent of the cloud budget.
  • 🔒 Compliance adds unplanned cost: Implementing NIS2 is estimated to cost €100,000-€500,000. Add DORA and the EU AI Act – and most budget plans didn’t anticipate these expenses.
  • 📉 Legacy systems absorb 70%: In many organizations, 70-80 percent of the IT budget funds ongoing operations – legacy applications, on-premises infrastructure, maintenance contracts, and support. Only 20-30 percent remains for innovation, AI, and compliance.
  • 🎯 Radical prioritization is essential: CIOs must have the courage to retire legacy projects, shut down AI “pilot graveyards,” and reframe compliance spend as strategic investment – not overhead.

The Widening Gap Between Expectations and Budget

CIOs have always faced pressure to do more with less. In 2026, that tension escalates to a new level. Executive expectations are unambiguous: Scale AI – because competitors are doing it. Implement NIS2 – because personal liability looms. Reduce cloud costs – because the CFO is scrutinizing the ballooning bill. Strengthen security – because a ransomware attack could be existential.

The budget grows by 9.8 percent. But in real terms – after inflation and surging software license costs (Microsoft raised enterprise licenses by 10-15 percent alone) – available headroom shrinks. CIOs attempting to meet all four demands simultaneously overload their teams and deliver meaningful results in none. The alternative? Radical prioritization.

In many companies, 70-80 percent of the IT budget flows into operating existing systems: legacy applications, on-premises infrastructure, maintenance contracts, and support. Just 20-30 percent remains for innovation, AI, and compliance initiatives. According to the Gartner CIO Agenda 2026, the global average allocated to innovation is 26 percent. The rest is “keeping the lights on.”

“77 percent of CFOs plan technology budget increases for 2026 – but most digital initiatives miss their targets. The gap between investment and impact is widening, not narrowing.”
Gartner IT Spending Forecast (February 2026), IBM Cost of a Data Breach Report 2025

Where the Money Goes: The Four Cost Drivers

Cost Driver 1: AI Infrastructure. GPU-based cloud workloads cost multiples of standard compute. A company running an internal LLM for customer service may incur €15,000-€50,000 per month in cloud costs for GPU inference. Add data preparation, model monitoring, and MLOps staffing – and AI stops being free the moment you move beyond ChatGPT subscriptions.

Cost Driver 2: Compliance. NIS2 implementation is estimated at €100,000-€500,000. DORA requires additional investments in ICT risk management and resilience testing. The EU AI Act mandates documentation, risk assessments, and audits for high-risk AI systems. These costs were omitted from most 2026 budgets because regulatory timelines remained unclear for too long.

Cost Driver 3: License Price Hikes. Microsoft, Oracle, SAP, and other enterprise vendors raised license prices in 2025 and 2026. Microsoft Enterprise Agreement renewals are up 10-15 percent year-on-year. Copilot licenses add $30 per user per month – $1.8 million annually for 5,000 employees, with no guaranteed ROI.

Cost Driver 4: Security. The threat landscape is intensifying. Ransomware attacks against DACH-region companies rose sharply, according to the BSI (Federal Office for Information Security) threat report. Average costs of a successful breach stand at $4.44 million, per IBM. Investments in EDR, SIEM, identity management, and incident response are no longer optional.

9,8 %
IT-Spending Growth (nominal)
70-80 %
Budget for ongoing operations
4,44 Mio. $
Avg. cost of cyberattack

Sources: Gartner 2026, industry estimates, IBM Cost of a Data Breach 2025

Five Levers for Budget Prioritization

1. Radically streamline the legacy portfolio. Every organization runs applications that haven’t been meaningfully used in years – or that modern alternatives could easily replace. CIOs should conduct an Application Rationalization Assessment: Which applications have fewer than 50 active users? Which cost more to maintain than they deliver in business value? Experience shows 15-25 percent of legacy portfolios can be retired without significant business impact.

2. Shut down AI pilot graveyards. As previously noted: only 26 percent of companies advance beyond pilot projects. Ongoing AI pilots without clear scaling paths drain budget, talent, and leadership attention. CIOs should map all AI initiatives onto a 2×2 matrix (impact vs. feasibility) and halt the bottom 50 percent. Freed-up resources flow to the top 20 percent.

3. Professionalize FinOps. Flexera estimates average cloud waste at 32 percent. On a €2 million cloud budget, that’s €640,000 wasted annually. Professional FinOps – with dedicated tools and ownership – pays for itself within three months.

4. Reframe compliance as investment. NIS2 and DORA aren’t cost centers – they’re risk mitigation. The average cost of a successful cyberattack ($4.44 million, per IBM) dwarfs compliance spend by orders of magnitude. CIOs who position compliance as insurance – not overhead – secure board approval far more easily.

5. Negotiate license agreements aggressively. Enterprise license agreements typically renew every three years. CIOs who don’t negotiate at renewal accept vendor-imposed price hikes outright. Leverage points include: soliciting competitive bids, transparently sharing usage data (how many licenses are actually consumed?), and dropping unnecessary premium features. With disciplined negotiation, 10-20 percent license cost savings are realistic.

What CIOs Must Tell the Board

The honest message to the board: With just 9.8 percent budget growth, not everything can be funded simultaneously. Scaling AI, achieving NIS2 compliance, and upgrading security demand trade-offs. CIOs who communicate transparently – about what’s feasible and what isn’t – build trust. Those who promise everything and deliver nothing lose it.

The proposal to the board should include a prioritized roadmap with explicit trade-offs: “If we prioritize AI in Q1 and Q2, we defer compliance to Q3. If we pursue both in parallel, we need €X in additional budget – or we must decommission Y legacy applications.” Transparency about trade-offs isn’t weakness – it’s strategic maturity. And that’s precisely what boards expect from their CIOs in 2026.

Frequently Asked Questions

What’s the average IT budget in Germany?

In Germany, IT spend averages 3-5 percent of revenue – varying by sector. Financial services firms allocate 7-10 percent; manufacturers, 2-3 percent. Nominal growth for 2026 averages 9.8 percent.

How much should a company budget for AI?

There’s no universal answer. Analysts recommend allocating 10-15 percent of the IT budget to AI initiatives – focused on no more than three to five high-impact use cases. GPU costs, personnel, and compliance effort must all be factored in.

How much does NIS2 implementation cost?

Estimates range from €100,000 to €500,000, depending on company size and current maturity. Firms already certified to ISO 27001 hold a distinct advantage. Ongoing costs for audits, monitoring, and staff also apply.

How can cloud waste be reduced?

Establish FinOps as a formal discipline: assign dedicated ownership, deploy real-time cloud cost dashboards, automate alerts for overspending, and conduct regular rightsizing reviews. With average cloud waste at 32 percent, a €2 million cloud budget holds €640,000 in savings potential.

Should CIOs position compliance costs as investment?

Yes. The average cost of a cyberattack is $4.44 million. NIS2 compliance investments of €100,000-€500,000 are, by comparison, a relatively inexpensive insurance premium. Plus, executives face personal liability for noncompliance.

More from the MBF Media Network

Header Image Source: olia danilevich / Pexels

Share this article:

Also available in

More Articles

09.06.2026

Apple Builds AI as Its Moat: The Golden Gate Strategy

Bernhard Liebl

8 Min. read time The real message of WWDC 2026 lies in the subtext of the Siri presentation. Apple is ...

Read Article
07.06.2026

AI on the Board: Why Only 12 Percent Benefit

Eva Mickler

5 min read 6 min read Boards are investing, but the returns aren't materializing. In the latest PwC ...

Read Article
06.06.2026

The AI pilot is running, regular operations are not

Eva Mickler

6 min read 41 percent of German companies now use AI, more than twice as many as a year ago. Yet, in ...

Read Article
05.06.2026

Managed Security Services: CISO Does Not Bear Sole Liability

Benedikt Langer

7 min read 8 Min. Read In many companies, the CISO is seen as the person who takes responsibility for ...

Read Article
04.06.2026

Technical Debt: Why the Board Must Act Now

Eva Mickler

7 min read Technical debt doesn't appear on any balance sheet, yet it exacts a very real toll on every ...

Read Article
03.06.2026

Data Spaces: Where Smart Industry and Smart City Converge

Eva Mickler

5 min read 8 min read For a long time, industrial and municipal data were considered two separate worlds: ...

Read Article
A magazine by Evernine Media GmbH