AI And The New Visibility Problem For IT Leaders
As AI moves into production, midmarket IT leaders face a new challenge: understanding what it can access, what it costs and where it creates risk.
(From left: Jay Pasteris, Nick Phelps, Jeff Cratty and Jay Martin speak during a keynote panel at Blue Mantis Futures 2026 in Newport, R.I., Oct. 5.)
As AI moves from pilot projects into production systems, Blue Mantis executives say IT organizations will need better answers about what AI can access, what it costs and whether existing security controls can keep up.
For years, IT leaders have been told they need greater visibility across increasingly complex environments.
Now, AI is making that problem even harder to ignore.
During a panel session at Blue Mantis’ recent Futures event, executives from Blue Mantis and Congruity360 repeatedly returned to a common challenge: Organizations lack a clear view into the data, costs, infrastructure and security risks surrounding AI.
For midmarket IT leaders, the problem goes beyond selecting the right AI tool. They need deeper visibility into how these tools operate.
As AI becomes embedded into business workflows, CIOs and other IT leaders may increasingly be asked to explain exactly what data AI has access to, what employees are doing with it, how much that activity costs and whether security teams can quickly detect when something goes awry.
“Just because you have dashboards doesn’t mean you have observability,” said Nick Phelps, field CTO at Congruity360.
That core theme surfaced throughout a panel discussion that encompassed AI infrastructure, data governance and security, FinOps, red teaming and the evolving security operations center.
AI Is Showing Up In Bills
For Jeff Cratty, vice president of cloud and innovation at Blue Mantis, one sign that AI has moved from pilot stage is clear: organizations are getting billed.
“AI is here because it’s showing up in invoices,” Cratty said. “It’s showing up in invoices, which means it demands an explanation.”
Cratty then went on to speak about a client that encountered a recurring five-figure charge for token usage in one of its tenants. What started as a question about the charge quickly raised deeper, more pointed inquiries: Which users were consuming it? What tasks were they performing? What business value did their activity provide for the client?
Jay Pasteris, chief operating officer at Blue Mantis, and panel moderator, described the emerging challenge as the “FinOps era of AI,” and drew a connection between unpredictable cloud consumption and the growing use of tokens and AI services across organizations.
These questions should be familiar to any CIO, director or other IT leader who has spent years trying to get cloud costs under control. Cloud computing is hardly new, yet cost management remains a concern. Recent MES and Computing spending-intent research found that IT leaders are still wrangling with cloud economics, particularly those associated with rising costs and licensing changes.
AI adds a new and complex consumption model and suggests that IT leaders shouldn’t expect visibility into AI-related costs overnight.
[RELATED: Reining In Cloud Computing Costs]
Before AI Can Use Your Data, IT Has To Understand It
Cost is only one part of the visibility issue.
AI’s usefulness depends a lot on the data available to it, but giving AI access to enterprise information also raises concerns surrounding security risks.
Phelps said organizations need to understand not only where their data resides and who has access, but also where data moves and what happens to it.
He also cautioned that ROT, or redundant, obsolete and trivial data, does not disappear after an organization implements AI.
“AI sees that stuff too,” Phelps said.
That points to the AI dilemma for most organizations: giving AI access to useful information, while preventing it from reaching data it should not use.
**[WATCH: Why AI Can’t Move Faster Than Your Data Security -**For more on the data visibility and security challenges that come with scaling AI, watch this related episode of Ready.Set.Midmarket!]
That is where detailed visibility comes in. Phelps argued that organizations need to understand the challenge before effectively addressing it.
AI Creates A New Attack Surface
That same visibility issue rears up with cybersecurity.
Jay Martin, chief information security officer at Blue Mantis, said the company is looking at AI red teaming that tests models, agentic environments, APIs and AI-developed applications. That work also includes testing for prompt injection to uncover what an organization may be exposing as it implements AI.
Bringing in a white-hat team can provide a “second pair of eyes” into potential exposure, Martin said.
Organizations are now facing adversaries who are using AI to ramp up cyber attacks while the security industry and IT teams are beginning to use the same technology to prioritize alerts and analyze information from different systems.
Martin expects AI to shoulder the burden of more of that analysis, but he pushed back against the idea that humans completely disappear from security operations.
“You still need that human today,” he stressed. “You absolutely need that human.”
He said AI could collect alerts, group them and perform analysis that currently often requires security teams to monitor multiple consoles.
The Bigger AI Question: Can You Explain What It Does?
The panel discussion touched on a shift in the questions IT leaders may need to ask about AI.
During the initial, experimental phase of AI the questions largely were: What can AI do for us? Which use cases are best applied? Where can it improve productivity?
Now that more organizations are in the operational phase, the questions become: What data can AI reach? Who is using it? What does that usage cost? How do we secure it? What happens when AI activity becomes part of day-to-day operations?
Cratty compared the direction of AI consumption to electricity, where the technology is simply available throughout an organization, but someone is still tasked with accounting for consumption.
The takeaway from the session is that organizations, having moved beyond AI pilots, may be at the hardest stage of AI adoption: developing the necessary and deep visibility needed to govern AI effectively.
The challenge is no longer figuring out what AI can do. It is being able to accurately explain what AI is doing inside the organization.
[RELATED: The AI Your Company Approved May Not Be The AI Running Today]
[RELATED: The Data Problems Undermining Midmarket AI Projects In 2026]