Tathagata Das Sarma is Head of Analyst Relations and Market Intelligence. This is his reading of ten Gartner 2026 Hype Cycles, read end to end so you don’t have to. The ratings, placements and profile definitions are Gartner’s. The argument built on top of them is his, and is not a Gartner position.
An AI team needs somewhere to keep what an agent knows between one step and the next, so they build one. It works. Within a few months a dozen things depend on it. Eight months later a second team, elsewhere in the organization, needs the same thing, does not know the first exists, and builds a second. By the time anyone notices, there are three. Each has its own idea of what a customer is. None of them is wrong, exactly, and reconciling them now costs more than any of the projects that produced them.
Nobody decided this. Three competent teams each solved a real problem, locally, and got it right. They built their own because nothing already held what they needed. Nobody’s job was to notice that three of them were building it.
I am writing from the chief data officer’s chair, but the argument goes beyond that role. The claim is that the thing an agent runs on has no owner anywhere in the enterprise. You can check the evidence for that; the claim itself you will have to judge.
What ten reports look like together
Permalink to “What ten reports look like together”Ten of Gartner’s 2026 Hype Cycles, read as one body of text rather than ten documents:
- Agentic AI
- AI Governance Technologies
- Data and Analytics Governance
- Data Management
- Data Science and Machine Learning
- Data Security Technologies
- Data Analytics and AI Leaders and Programs
- Emerging Technologies
- ERP
- Finance Data and Analytics Governance
Context graphs and data contracts are still at the Innovation Trigger. Model Context Protocol, context engineering and AI governance are cresting the Peak, where Gartner says expectations are running ahead of real-world deployment. Governance platforms are already in the trough. Metadata management and knowledge graphs are climbing the slope.
Every category across the ten reports on one curve | Positions follow the phase Gartner assigns each profile. Composite chart, not a Gartner exhibit
Caption: Positions follow the phase Gartner assigns each profile across the 2026 cycles. Composite chart, not a Gartner exhibit.
Every profile in them carries an Obstacles section, the analyst’s own account of why the thing is not working yet. There are 314. Each was classified by the kind of barrier it names.
The closer a technology gets to a real deployment, the more the obstacle becomes an org chart.
The level changes with the definition. The slope does not | Original analysis: our classification of Gartner's Obstacles sections
Before the Peak of Inflated Expectations, an organizational barrier appears in 65% of profiles. After it, in 79%.
That fourteen-point gradient is the most durable number here. It survived the set growing from nine reports to ten, and it survived a second reader coding the same profiles independently with a broader definition, who found 77% before the peak and 91% after. The important result is the gap between the two groups, not the absolute level. Two different definitions moved the level by twelve points and the gap by nothing.
An earlier analysis suggested a crossover: technical barriers dominated before the peak and organizational barriers after it. That pattern did not survive a broader definition of “technical.” What did replicate was the fourteen-point increase in organizational barriers after the peak. The level changes with the definition; the slope does not.
Any of this matters because of where enterprise money sits. Almost nothing in your 2027 budget is pre-peak. The categories you are funding are in the trough and on the slope, and there the analysts name governance, ownership, skills and coordination far more often than they name the technology.
Gartner puts the underlying point in the Emerging Technologies cycle, in the meta-trends section that runs before the first profile.
In 2026, the current obsession with AI suffers from a dangerous belief that any legacy capability, when combined with a probabilistic model, instantly becomes a modern innovation. This “X + AI” formula has fueled immense hype, but it often masks a critical operational truth: introducing intelligence on top of an inefficient, siloed, or poorly governed process merely accelerates its failure.
Accelerates its failure. That’s a pretty direct statement from Gartner, especially this early in the report.
The three shifts: what the research is starting to show
Permalink to “The three shifts: what the research is starting to show”Your program was built to answer questions about a dataset. Where it came from, who owns it, whether it can be trusted, who can see it. The research is converging on a question about a decision: what the system knew, when, on whose authority, and whether it still holds. A catalog entry describes data at rest. An agent acts.
Three shifts sit in that gap. Two of them need the third, which is not the same as the third being the answer.
1. The record needs to follow the decision
Permalink to “1. The record needs to follow the decision”Context graphs entered the 2026 cycles as a new profile, carried into six of them at under 1% penetration and High benefit, holding semantics, decision traces, governance metadata, and causal links. The term is contested: the ontology community will tell you, not unreasonably, that this is a knowledge graph wearing a new hat. The shape of the artifact is not in dispute.
The brake on all of it is mundane. Most organizations have catalog coverage without lineage depth, so there is nothing to build on.
Here is the test, and it takes a week. Reconstruct one production agent decision end to end. Four things have to come back, and you pass or fail on all four:
- the context it retrieved
- the policy in force at that moment, not today’s
- the identity that authorized the action
- the version of the semantic definitions it used
If you can’t produce one of these, you’ve found a context gap. Also record how long it took to find out.
Why traditional governance fails at the decision level
Permalink to “Why traditional governance fails at the decision level”Traditional governance was designed for periodic, human-driven audits: checking table schemas, row counts, and access policies once a month. An autonomous agent operates on a millisecond timescale, making hundreds of contextual decisions a minute. Trying to govern agentic decisions using traditional governance frameworks is like trying to manage real-time network traffic with quarterly committee meetings. The control cannot be an external committee; it has to be built directly into the context layer itself.
2. Trust has to be checked continuously
Permalink to “2. Trust has to be checked continuously”Zero-trust data governance entered the D&A Governance cycle this year at 1% to 5% penetration, rated embryonic. The same report then puts it in the two-to-five-year column of its priority matrix, and names it alongside data observability and AI governance as a place to look for near-term value. Embryonic maturity and a near-term horizon do not sit together comfortably in Gartner’s own framework. Read that as the analysts pulling it forward.
The governance cycle carries the planning assumption directly: by 2028, half of organizations will implement a zero-trust posture for data governance, driven by the proliferation of unverified AI-generated data. With machine-generated data the lineage lines break and provenance becomes unknowable after the fact, so verification has to be continuous. Certification-based governance is entrenched because it produces a number for the board, and a posture does not.
Tag provenance for AI-generated content now, while retrofitting is still possible. This is the one item where waiting a year makes the work harder rather than merely later.
3. Metadata has to work beyond the catalog
Permalink to “3. Metadata has to work beyond the catalog”I think this one gates the other two. Metadata management solutions sits on the Slope of Enlightenment at early mainstream maturity, 20% to 50% penetration and two to five years to plateau, in six of the ten cycles including Data Security and ERP. The framing is a move from passive catalogs to active metadata available wherever it is needed, and the recommendations are about interoperability rather than coverage.
That describes a component inside someone else’s architecture, not a destination. It carries meaning, lineage and policy well, and procedure badly or not at all. Anyone who tells you the metadata layer is the context layer is selling you the part they have.
Two other profiles make the same error from the other end. Both are probably on your roadmap already.
Model Context Protocol sits on three of the ten cycles at High benefit and 1% to 5% penetration, and its obstacle text is the part to read: most MCP clients disproportionately emphasize tool listing and tool calling while ignoring the rest of the protocol, which narrows it to function calling at scale and undercuts its intended role as a general context interchange protocol. The standard is being installed before anyone has agreed what should move through it. Standardizing how a model reaches your systems does not settle what “active customer” means in either of them.
Automated data governance is the same shape. It sits at the Innovation Trigger at 1% to 5% penetration, High benefit, and five to ten years from mainstream adoption in every cycle carrying it, which is further out than most governance roadmaps assume. The reasoning is spelled out. Foundational governance capabilities have to be achieved first, and where critical definitions, rules and process knowledge remain implicit, they limit the scope of what can be automated. Automating a policy nobody wrote down does not shorten the five years. Convert your three most-referenced policies into machine-checkable rules and run them against live data. The failure rate tells you whether those policies were ever real.
The reports do not carry the gating claim. That one is my inference, so here is the case against it**.** Teams ship agent context into production without that layer every week. Foundation first is the oldest available argument for deferring work that ought to justify itself on its own merits, and a year spent on the foundation while nothing reaches production is a real cost, not a hypothetical one. What persuades me anyway is narrow. The other two both need a machine to retrieve something at decision time, you can supply that locally per use case, and three teams doing exactly that is the scene this article opened with.
Test whether your metadata can be read programmatically by something that is not your catalog’s own interface. It takes an afternoon and commits you to nothing.
Before you write next year’s budget
Permalink to “Before you write next year’s budget”Categories in this research leave by two exits. Some graduate, reaching mainstream adoption and dropping off because they started working. Others get absorbed, and that one costs you money.
Augmented data management is the case to look at. The profile carries a Transformational rating, the highest available, in both the Data Management and Finance governance cycles, and its own recommendations name agentic data management as its next phase. The Data Management cycle marks it obsolete before plateau, naming it alongside data mesh. So the highest rating available sits on a label the research is already retiring. The capability survives, the name does not, and any funding case written against the name goes with it.
Nobody owns the middle
Permalink to “Nobody owns the middle”Three things, and two of them need the third. That is the list as it looks from your chair.
Now read it from the one across the corridor. Context infrastructure is the CIO’s version of the decision record. Same question about what a system knew and who let it act, but it arrives on that desk as an unscheduled build-or-buy, and gets decided by default when three teams each solve it locally. The identity half of your zero-trust posture is, on that side, a profile called AI agent identity, which entered the Agentic AI cycle this year at 5% to 20% penetration, further along than anything on your list and far ahead of the context layer it will need to reason about. Its listed drivers read like an incident report written in advance: an epidemic of human credential sharing, agents deployed as proxies on human credentials, breaking auditing and nonrepudiation. And your metadata layer is, in the Data Security and ERP cycles, a security control and a migration dependency, frequently bought twice by two functions who do not know the other is buying it.
So you end up with the same problems sitting on two executives’ desks.
None of that is inference. Five of the ten reports state it outright.
Data Security, on data discovery: frequently no clear owner accountable for the outcomes; the teams operating the tools may lack the authority to act on the findings; the disconnect between visibility and downstream action creates accountability gaps across data domains.
Finance Data and Analytics Governance, on decision-centric governance: these innovations signal a shift from governing data to decisions while expanding governance to include knowledge, metadata and unstructured data, and progress is slowed by unclear ownership and cross-functional dependencies.
Data Management, on data contracts: low governance maturity and unclear ownership create ambiguous accountability for defining and maintaining specifications, including overlapping or conflicting ones.
Agentic AI, on agentic accountability: ownership and accountability for agentic decisions, actions and components require an approach spanning policy, technology and organizational awareness.
Data, Analytics and AI Leaders: increasingly blurring boundaries within governance silos and between adjacent governance programs, with existing bodies designed around functional areas, making enterprise accountability and decision rights hard to establish.
The wording varies, but the ownership problem is the same across all five reports.
The research also has a name for the middle. The Finance cycle carries a profile called Knowledge Fabric, defined as digital infrastructure enabling semantic interoperability by connecting diverse knowledge sources into a unified context layer, drawing on metadata alongside structured and unstructured data. The Data Management cycle’s framing for the year is an increased focus on context layers and semantics. Gartner is already using the language of a context layer. What is missing is ownership. That is the narrow claim, and it is the one this article is making.
Enterprises have clear ownership for three things. Datasets belong to the data organization, applications and infrastructure to IT, models to whichever team you designated for ML and AI. Each has a budget line, an on-call rotation, and a person whose title contains the word.
The thing an agent acts on is none of the three. Suppose someone did own context. Here is the inventory they would be maintaining:
- what a term means
- which data is authoritative
- what policy applies
- how the work is actually done here
- what happened before
- who is allowed to decide
The first three already have places where people expect to find them. Semantics live in a glossary. Provenance lives in lineage. Policy lives in documents or, increasingly, code.
The other three are much harder. Procedure lives in tickets, runbooks and the three people who remember how the monthly close runs. Decision history lives in logs nobody reads with meaning attached. Authority lives in an IAM system designed for humans.
Procedure is probably the clearest example. A catalog can tell an agent what “net revenue” means and where the authoritative table is. It cannot tell the agent that the close is not final until the Singapore entity confirms, that three known exceptions get handled by hand every quarter, or that the number is provisional until Thursday. A new analyst learns that in six weeks from people. An agent never learns it at all, because no system holds it and no function is accountable for holding it. That is the difference between a catalog and a context layer, and it is why the metadata layer, however good it gets, only ever describes part of the problem.
“Context is produced by all three functions and owned by none.”
The order matters, because it decides what you do about it. Procedure, decision history and authority are unowned partly because nothing holds them. There is no artifact for a domain expert to maintain, no system a steward could be accountable for, nothing an audit could be pointed at. The ownership gap exists partly because there is nothing concrete for someone to own. An owner appointed over that is a person with a spreadsheet. The vacancy is real, and it sits downstream of an absence.
When governance and policy is the most-named barrier across all ten reports, the analysts are not saying governance software is missing. They are saying that where these technologies have to work, there is no one whose job it is to make the call. The work sits between two org charts, and every proposal to resolve it reads to one side as a land grab and to the other as a dumping of work.
There is an obvious candidate: the data organization. You are the closest fit. Nobody else sits at the intersection of data, semantics and trust, or is already accountable for what a term means and whether a source can be relied on. Drawing the org chart from scratch, context reports to the data organization.
The research makes that harder than it sounds. All three items land at least as heavily on the CIO’s side as on yours, and the authority question underneath agent identity is not a data capability under any reading.
A CDAO handed context without the identity model, the delivery pipeline and the platform budget has been given a title rather than a job.
So here is the recommendation, plainly, because a diagnosis without one is not much use**.** Context should have one accountable owner, and that owner most plausibly sits in the data organization, holding a mandate that reaches into infrastructure. Not a council or a working group. One person with a budget and an on-call rotation, like every other capability someone owns.
The difficult part is the infrastructure authority that comes with the role. Enterprises keep stopping short of granting it. Everything below is a way to find out how far you are from being able to grant it.
What the owner would actually need
Permalink to “What the owner would actually need”An owner for context as a capability, not a tool. Organizations tend to spend most of their time debating the reporting line. The harder question is what the role can actually reach. If the owner cannot set requirements on the identity model, cannot gate the delivery pipeline, and cannot stop a team standing up its own context store, the title exists and the capability does not. The real question is for the CIO: what will you let this person constrain? Get it answered now, because after the first incident the role goes to whoever was closest to the failure.
One joint decision reconstruction, with both organizations in the room. Trace a live agent decision end to end against the four-item test. Your team will find the semantic and lineage gaps, theirs will find the identity and authority gaps, and neither finds both alone. That is the point.
One shared test for the metadata layer, agreed before either of you buys anything. Can a system that is not the catalog’s own interface read it. Use this as a diagnostic before you make it a purchasing requirement, because the answer tells you where you stand without telling you what to buy. Answered separately, the two organizations land in different places, and every downstream item inherits the discrepancy.
How to check this?
Permalink to “How to check this?”The gradient is the part you can check yourself. It comes from a keyword coding of the Obstacles text across all 314 profiles, split at the peak. Recode it your own way against your own copies of the reports. If the pre-peak and post-peak shares come back close to each other, the argument is dead. The connection between those five observations is my inference, not something the reports say directly. So is calling the thing that lacks an owner “context.”
8 questions to ask before anything else
Permalink to “8 questions to ask before anything else”To test whether this gap is currently costing your organization money, bring both IT and Data into the room and run through these eight self-diagnostic questions before your next procurement cycle:
- For the most consequential agent decision last month, can you produce the four items above: context, policy in force, authorizing identity, semantic version? How long did that take?
- What share of the data entering your estate this quarter was machine-generated, whether by models, agents or humans, and how do you know?
- Which three policies do you enforce, as opposed to publish?
- Can a system that is not your catalog read your metadata without a human in the loop?
- How many places in your estate store agent state or memory, and which team owns each?
- If an agent exceeded its authority tomorrow, whose incident process owns it?
- Are your data policy enforcement roadmap and your policy-as-code roadmap the same roadmap?
- Who would notice first if the answer to question one was “we cannot”?
Locally correct. Globally incompatible | Source: Context and Chaos
Nobody woke up intending to build three incompatible context platforms. They simply built what the organization never decided to own. Until context has an accountable owner, enterprises will not have one context layer. They will have three. Each is correct on its own terms. None of them fit together, and by the time anyone works that out, all three are load-bearing.
The Cats of Context & Chaos
Permalink to “The Cats of Context & Chaos”
Every team produces context. No team owns it. | Source: Context and Chaos
About Context & Chaos
Permalink to “About Context & Chaos”Context & Chaos isn’t just a newsletter. It’s shared community space where practitioners, builders, and thinkers come together to share stories, lessons, and ideas about what truly matters in the world of data and AI: context engineering, governance, architecture, discovery, and the human side of doing meaningful work.
Our goal is simple, to create a space that cuts through the noise and celebrates the people behind the amazing things that are happening in the data & AI domain.
Whether you’re solving messy problems, experimenting with AI, or figuring out how to make data more human, Context & Chaos is your place to learn, reflect, and connect.
Got something on your mind? We’d love to hear from you.
Share this article