AI ROI Brief · September 18 – 24, 2026

AI ROI Brief

The five percent thesis got its sharpest number yet this week. A survey of 830 enterprise IT leaders found that financial impact has overtaken productivity as the metric executives say matters most — nearly double the share who said so a year ago. But the same research puts the share of enterprises that can actually show measurable, at-scale AI ROI at just 5 to 8 percent. The explanation sits in the same dataset: more than half of enterprise AI budget still flows to sales and marketing, where impact is hardest to isolate, while operations and back-office functions — where returns are shown to be highest — get less than a tenth of the spend. The compliance picture shifted too, and in a direction most governance frameworks are not built for. A European regulator confirmed the first reported case of an AI agent — not a person — autonomously executing a multi-stage data breach. Paired with a separate, larger intrusion disclosed earlier this year, it is now two data points for the same emerging category: AI as attacker, not just as a place data can leak out from.

The 30-second version

Sellers using AI heavily closed 20% more often and grew revenue per account manager 9.4%

Talking point

This is the shape every AI revenue case should take and almost never does — a defined cohort, a defined comparison group, a percentage tied to a role, not a testimonial. The catch is who is grading the test. Ask any vendor case study the same three questions this one answers before you use it: who was compared to whom, over what window, and using whose tool.

Content angle

Post: "Read a vendor's own AI case study like a term sheet." Walk through the three questions above using the 9.4%/20%/75% numbers as the worked example, then flip it — ask the reader whether their own AI pilot could survive the same three questions.

Lens: Most of the Budget Went Where It's Hardest to Prove. This brief is prepared for executive orientation and general information. It is not investment, legal, or accounting advice. Figures are drawn from publicly reported research, company disclosures, and Fractional C-Sweet advisory work; where a source has a commercial interest in its own findings, that interest is noted alongside the item. Client and partner identities are withheld unless the work is already public. Independent verification is recommended before any figure is used in a business case. Fractional C-Sweet · AI ROI Brief · Week of September 18–24, 2026

Revenue

Where AI shows up on the top line — and how to tell a real case from a vendor's.

EnterpriseReadiness Signal

Sellers using AI heavily closed 20% more often and grew revenue per account manager 9.4%

A large software vendor's internal sales-pilot data compares account managers using its AI copilot at least half the time against a low-usage comparison group over the same period: 9.4% higher revenue per account manager, 20% higher close rates, and up to 75% cycle-time reduction in selected workflows.

Talking point

This is the shape every AI revenue case should take and almost never does — a defined cohort, a defined comparison group, a percentage tied to a role, not a testimonial. The catch is who is grading the test. Ask any vendor case study the same three questions this one answers before you use it: who was compared to whom, over what window, and using whose tool.

Content angle

Post: "Read a vendor's own AI case study like a term sheet." Walk through the three questions above using the 9.4%/20%/75% numbers as the worked example, then flip it — ask the reader whether their own AI pilot could survive the same three questions.

Source: Microsoft, AI Sales Playbook, published September 17, 2026 (covered by CFO Dive, September 22, 2026). Microsoft is both the vendor and the subject of its own case study; no independent verification is cited.

Professional ServicesReadiness Signal

AI-attributed leads are starting to repeat, and that's what makes them a channel

For a second week running, new prospect conversations traced back to specific AI-built artifacts: a tagged outreach channel, a generated reconnection brief, and a self-serve AI-roadmap tool. The point isn't the size of the pipeline. It's that each lead can be traced to the artifact that produced it.

Talking point

One AI-sourced lead is an anecdote. A second and third showing up the same way, two weeks running, is a channel. The distinction that makes this usable in a business case: every entry traces back to a specific artifact — a tagged channel, a generated brief, a tool submission — not "I think AI helped somehow." That is attribution designed in from day one, not measured after the fact.

Content angle

Build-in-public post: a channel isn't proven by one lead, it's proven by the second one showing up the same way.

Source: Fractional C-Sweet practice observation, September 2026. Early-stage; no conversions yet.

Cost

The gap between what firms expect their AI spend to return and what they can actually show for it.

EnterpriseReadiness Signal

Only 5–8% of enterprises can show measurable, at-scale AI ROI — and the budget is pointed away from where returns are highest

830 IT leaders surveyed. Financial impact is now the top-cited AI success metric at 21.7%, nearly double the prior year, overtaking productivity. Yet research cited in the same study puts the share of enterprises achieving measurable, at-scale ROI at just 5 to 8%. Over half of enterprise AI budget still flows to sales and marketing, where impact is hardest to isolate; operations and back-office functions, where the same data shows returns are highest, receive under 10% of spend.

Talking point

Executives are finally asking the right question and funding the wrong function to answer it. If returns are concentrated in operations and back-office work, and the money is concentrated in sales and marketing, the ROI gap isn't a technology problem or even a measurement problem — it's a budget-allocation problem, and it's fixable without buying anything new.

Content angle

A single-chart post: two bars, "share of AI budget" against "where the ROI actually shows up," sales/marketing on one side, ops/back-office on the other. Caption: "The money and the returns are pointed at each other." Close with one question: where does your next AI dollar go, and did anyone check first?

Source: Futurum Group, 1H 2026 Enterprise Software Survey (830 IT leaders), cross-referencing MIT NANDA, BCG, KPMG, McKinsey and Gartner research.

WealthReadiness Signal

A third of wealth and asset management firms don't know their own AI ROI — or what they're spending to get it

Senior leaders at UK wealth and asset management firms ranging from £30 billion to £6+ trillion AUM: 44% expect ROI of 10–30%, 72% expect payback within 24 months — optimistic figures sitting on top of real uncertainty, since one in three firms say they don't actually know their ROI and 33% aren't sure of their total AI spend. 94% cite operational efficiency as the primary investment goal, but specific productivity or cost figures are rarely quantified.

Talking point

These firms have ROI expectations and payback timelines without ROI measurement. That's not a data problem, it's a sequencing problem — the spreadsheet with the expected return got built before the spreadsheet that tracks the actual one. Ask any firm for their AI ROI number before asking about their AI roadmap; the roadmap is aspiration, the number is discipline.

Content angle

Post built on the phrase "expected return without a return." Set the 44%/72% optimism figures against the 33%/33% uncertainty figures as a same-page contradiction, then name the one artifact that resolves it: a single tracked metric per AI initiative, agreed before the initiative starts.

Source: KPMG, State of AI in UK Wealth & Asset Management, published September 2026.

Productivity & Workflow

The productivity story that actually reaches the P&L is a targeting decision, not a typing decision.

Professional ServicesReadiness Signal

AI sorted a week's outreach list into clean, needs-review, and do-not-contact — without a manual reputation check

An AI-assisted CRM pass on an outreach batch flagged bad and undeliverable records, split out explicit opt-outs, and queued the unclear ones for review. Across a full database, the same logic cut the list to a small share that's actually warm.

Talking point

The productivity story everyone tells is "AI writes my emails faster." The one that actually shows up on a P&L is "AI decided which few of my contacts are worth my time" — because that's not a time savings, it's a targeting decision that usually doesn't get made at all. Most databases don't get cleaned; they get ignored until the sender reputation forces the issue.

Content angle

Before/after the funnel: not a new list, a better filter.

Source: Fractional C-Sweet practice observation, September 2026. Not independently audited.

Compliance

The risk register most companies have covers only half of what AI agents can now do.

CybersecurityReadiness Signal

An AI agent, not a human, executed the first agentic-AI data breach reported to a European regulator

Spain's data protection authority (AEPD) confirmed it received the first breach notification describing an AI agent that autonomously chained credential theft, vulnerability discovery, and unauthorized access to expose personal data and invoice records. The agency called it "a qualitative change" in attack methodology and directed organizations to fold adversarial-agent risk into formal risk analysis, tighten incident-response timeframes, and pair AI-assisted detection with explicit human supervision.

Talking point

Every board conversation about AI risk so far has been about AI as a target — data going into the model, the model leaking it back out. This is the first regulator-confirmed case of AI as the attacker, chaining steps a human would have needed days and specialist skill to execute. Most AI governance frameworks are written for the first kind of risk. Almost none are written for the second, and a regulator just said so on the record.

Content angle

Post: "Your AI risk register has a blind spot." Walk through the two categories — AI as target, AI as attacker — and ask which one the reader's current AI governance policy actually covers. Most will realize it's only the first.

Source: Spanish Data Protection Agency (AEPD) incident disclosure, reported September 16, 2026; covered by SecurityWeek.

CybersecurityReadiness Signal

Nine zero-days, 17,600 autonomous actions, four and a half days undetected — and the frontier models refused to help clean it up

A publicly disclosed intrusion against OpenAI and Hugging Face infrastructure chained nine zero-day vulnerabilities across roughly 17,600 autonomous actions to reach cluster-admin access over four and a half days before detection. In the aftermath, safety-trained frontier models reportedly declined to assist with parts of the forensic cleanup — the same guardrails built to prevent misuse also slowed the response to it.

Talking point

This is the second data point this month for the same emerging risk category the Spanish breach opened: agentic AI as an attack surface with its own scale advantages — patience, parallelism, no fatigue. The sharper, less obvious point for a boardroom is the guardrail paradox: safety training that makes a model refuse a harmful request doesn't reliably distinguish an attacker asking from your own incident-response team asking. That is a governance design problem, not a one-off bug.

Content angle

Pair with the AEPD item as a two-part post or slide: "Two breaches, one new attack surface." Close on the guardrail paradox as the sharper point — most executives haven't considered that safety training can slow down their own defenders.

Source: OpenAI and Hugging Face public incident accounts, intrusion disclosed July 2026.

IP

Where independent practices are turning judgment into something priced by the unit instead of the hour.

Professional ServicesReadiness Signal

A pricing model for AI-readiness work that isn't billed by the hour

Independent advisors are starting to package AI-impact and compliance-audit work into fixed-fee tiers scoped by the number of interviews, rather than open-ended hourly engagements, with portfolio-wide versions aimed at private equity firms.

Talking point

The moment a service gets priced by unit of output instead of unit of time, it stops being consulting and starts being a product — the thing that survives a client learning to do the work themselves. The PE-portfolio angle is the sharper version: instead of selling one relationship at a time, price the methodology once and apply it across dozens of companies under one fund. That is the licensing model hiding inside most advisory practices that haven't looked for it yet.

Content angle

Post for fellow fractional executives and independent consultants: "Stop billing AI-readiness work by the hour." Use the interview-count/fixed-fee structure as the concrete mechanism, and the PE-portfolio version as the example of what pricing-by-unit unlocks that pricing-by-hour never can.

Source: Fractional C-Sweet practitioner conversations, September 2026.

Bottom line

The bottom line

Keep reading

Next briefs

Get the briefs in your inbox

AI in the News, Legal Signal, Security & Compliance, and ROI briefs — written for executives. No spam, unsubscribe anytime.