While AI has swiftly become a pillar of business strategy across the globe, a new report from F5 reveals that the overwhelming majority of enterprises remain unprepared to scale its use securely and sustainably. The 2025 State of AI Application Strategy Report, based on a survey of 650 global IT leaders and 150 AI strategists from companies with revenues above $200 million, finds that only 2% of organisations are truly ready to scale AI across operations with the right security and governance in place.
The report identifies a gaping readiness gap between AI experimentation and operational maturity—exposing how most enterprises, though eager adopters of generative AI, have yet to confront the governance, security, and infrastructural demands of enterprise-scale deployment.
“As AI becomes core to business strategy, readiness requires more than experimentation—it demands security, scalability, and alignment,” said John Maddison, Chief Product and Corporate Marketing Officer at F5. “This report highlights actionable steps for organisations to operationalise AI with confidence.”
Moderate adoption, major gaps
According to the study, 77% of companies fall into the ‘moderate readiness’ category, actively deploying AI—including generative AI—across roughly one-third of their applications. Yet, despite this adoption, most lack dedicated AI protections, clear data governance processes, and the infrastructure to manage AI workloads securely across hybrid environments.
Only 21% of companies are classified as having low readiness—often limiting AI use to pilot programmes or isolated experiments. These organisations tend to embed AI into less than a quarter of their applications, typically in disconnected or siloed environments.
In contrast, the top-performing 2%—those with ‘high readiness’—are characterised by mature frameworks, AI security protocols, and near-saturation of AI usage across their application portfolios.
AI’s expanding footprint without guardrails
F5’s findings suggest a rapid expansion in the use of AI across application stacks. Today, on average, 25% of enterprise applications utilise AI, and most companies are leveraging a mix of paid and open-source models. Popular open-source tools include Meta’s Llama variants, Mistral AI, and Google’s Gemma, alongside widely adopted paid models like OpenAI’s GPT-4.
Most organisations use at least three models across multiple environments, indicating an increasingly complex AI ecosystem that raises significant integration and governance challenges. This diversity of models, while promising for innovation, also widens the attack surface, particularly for enterprises lacking AI-specific security measures.
Security falling behind AI ambitions
Despite the enthusiasm for AI, the report sounds a clear alarm about cybersecurity maturity. While 71% of respondents already use AI to enhance their security operations, only 18% of moderately ready companies have deployed an AI firewall—a critical layer of protection against threats targeting AI workflows.
Other red flags include:
- Data governance gaps: Just 24% of companies practise continuous data labelling, raising concerns about transparency, accuracy, and vulnerability to adversarial attacks.
- Hybrid-cloud inconsistencies: As businesses spread AI workloads across multiple clouds and on-premise environments, governance becomes fractured—leaving workflows and sensitive data exposed.
- Lack of control over open-source tools: Without rigorous security frameworks, the increasing use of open-source models introduces further risk.
“Without mature governance and purpose-built protections, enterprises risk amplifying threats,” warned Maddison.
AI in the Middle East: Growing use, growing risk
Mohammed Abukhater, Regional Vice President for the Middle East, Türkiye, and Africa at F5, noted that these findings echo what the company is seeing in the region.
“Many organisations across the Middle East are integrating AI into their operations, often without all the necessary governance or safeguards,” said Abukhater. “While most demonstrate moderate AI readiness, they must enhance their cross-cloud security strategies and internal governance to avoid significant risk exposure.”
He added that F5 is actively supporting regional clients in implementing the report’s AI Readiness Index to assess their maturity and build secure, scalable AI operations.
Charting the road to readiness
To help organisations close the gap, F5’s AI Readiness Index outlines six key pillars of operational maturity—ranging from infrastructure alignment to security integration and cross-functional governance.
The report recommends three immediate actions:
- Diversify AI models intelligently: Use both paid and open-source tools, but establish strong governance and control protocols.
- Embed AI across the enterprise: Shift from pilot programmes to integrating AI within operations, analytics, and cybersecurity.
- Deploy AI-specific security solutions: Use AI firewalls and standardised data labelling to guard against emerging threats.
F5’s call to action is clear: Enterprises must move beyond the hype and experiment phase and build the operational spine to support AI securely and strategically.
AI is no longer a future vision—it’s an operational reality. But as F5’s 2025 report shows, the gap between adoption and readiness remains stark. Enterprises are embracing AI’s promise but falling short on the foundations needed to deliver it safely and at scale.
Those that act now—prioritising secure, cross-cloud infrastructure and mature governance—will be best positioned to harness AI for innovation, resilience, and growth. Those that don’t risk not only operational inefficiencies but also the amplification of cyber threats in an increasingly automated world.

