Skip to content
Article

Autonomous IT Operations: Everyone Wants It, Who Is Ready?

90% of enterprises plan autonomous IT operations within two years, yet only 19% of IT ops are automated today. Here is how to close the readiness gap.

Oğuzhan Gerçek··7 min read
Autonomous IT Operations: Everyone Wants It, Who Is Ready?

Short answer: The road to autonomous IT operations is built with operational discipline, not by purchasing an AI model. According to Riverbed's global survey published in October 2026, 90% of organizations aim to reach autonomous or human-supervised IT operations with agentic AI within two years; yet today only 19% of IT operations are automated on average, and just 17% of organizations have unified visibility across networks, applications and endpoints. The gap to close before delegating authority to agents is not AI capability. It is the organization's telemetry quality, runbook maturity and governance framework.

What the numbers say: the gulf between ambition and reality

Riverbed's survey, published on October 6, 2026, polled 1,200 business and IT leaders across seven countries in July 2026. The findings, which also received broad coverage in the Turkish IT press, draw a sharp line between intent and readiness:

  • 90% of respondents are targeting autonomous IT operations with agentic AI, and 76% rate it a critical part of their future IT strategy.
  • Yet only 19% of IT operations are automated today on average, and just 9% of AI initiatives are deployed enterprise-wide.
  • 77% of leaders are reluctant to let AI make operational decisions without human approval.
  • The data picture is even more sobering: only 21% rate their data quality as excellent, and unified visibility stands at just 17%.

ITPro's analysis of the same study reaches a similar conclusion: organizations are investing in the idea of autonomous operations, but they are not yet convinced about handing over control.

How well do agents actually perform in the field?

Step outside the marketing decks and look at measured data, and there is concrete reason for caution. ITBench, a study presented by IBM researchers at ICML 2025, tested AI agents on 102 real-world IT scenarios. The result: even the best agents running on state-of-the-art models solved only 11.4% of SRE (site reliability engineering) scenarios and 25.2% of compliance and security operations scenarios.

This does not mean agents are useless. It means the job description must be drawn correctly. In alert enrichment, correlation, first-line triage and root-cause hypothesis generation, agents already deliver real value today. When it comes to making unsupervised changes in production, the industry is measurably not ready yet.

A real operator's experience teaches the same lesson. NTT DoCoMo put an AI agent that accelerates root-cause analysis into production in February 2026, within an operation monitoring more than one million devices; yet in an assessment published on SDxCentral, the company is explicit that confidence thresholds, human approval layers and gradual autonomy levels sit at the center of its model. Within TM Forum's autonomous network levels framework, most operators are described as still being at level three.

The picture in Türkiye: adoption is further behind, the opportunity is bigger

If the global numbers are ambitious, it should be no surprise that Türkiye's starting point is further back. According to TurkStat's Artificial Intelligence Statistics bulletin published in October 2025, only 7.5% of Turkish enterprises with 10 or more employees use any AI technology. The figure was 2.7% in 2021; growth is fast, but the base is low. Scale changes the picture: usage reaches 24.1% among enterprises with 250 or more employees, while it stays at 6.6% for enterprises with 10 to 49 employees.

This data says two things. First, the autonomous operations conversation has already begun inside Türkiye's large enterprises; IT teams have put agentic tools on their evaluation lists. Second, most mid-sized companies do not have the in-house maturity to enter this transition on their own. The prerequisites of AI-assisted operations, meaning monitoring infrastructure, telemetry standardization and incident management discipline, still rest on a single expert's shoulders in many Turkish organizations. The cost of downtime is not shrinking either: New Relic's 2025 Observability Forecast estimates that high-impact IT outages cost organizations a median of 76 million dollars per year.

Why the gap persists: the problem is the ground, not the model

Put the Riverbed findings side by side and the pattern becomes clear. The top three obstacles slowing the move to autonomy are security and compliance concerns (55%), the risk of operational disruption (45%) and lack of trust in AI decisions (39%). All three point to the same root cause: the ground the agent would decide on is not solid.

  • Telemetry is fragmented. 87% of organizations have not integrated their monitoring tools. An agent fed from five separate consoles sees five separate half-truths. Consolidating the observability layer onto a single standard is the first step of the autonomy journey; we covered this in depth in our observability guide with Prometheus and Grafana.
  • Runbooks are not written down. Before an agent can be authorized to "clean up that disk bloat", the operation needs a runbook written, tested and bounded by a human. What cannot be delegated to automation is, in truth, the process that was never defined.
  • Authority boundaries and audit trails are undefined. 92% of respondents believe AI observability and governance will become a critical IT domain. Which agent may take which action on which system, how the decision is logged, and when it hands over to a human must be designed up front. We examined the accountability framework in Türkiye in our article on AI governance.

From human in the loop to human on the loop

The model the industry is converging on is not full autonomy but gradual delegation of authority. 2026 assessments in the incident management space describe this shift as moving from "human in the loop" to "human on the loop": the agent gathers the data, forms the hypothesis and proposes the action; the human approves and manages the boundary conditions. Trust is extended step by step as successful approved actions accumulate.

In practice this means autonomy is not a product feature but a function of operational maturity. The same agent creates value in an environment with standardized telemetry and written runbooks, and merely accelerates mistakes in a messy one. One detail in the Riverbed study is striking here: only 36% of technical specialists have high confidence in their own organization's AI governance. The people closest to the field know the state of the ground best.

The managed services model offers a structural advantage at this point. The prerequisites of autonomous operations (standardized monitoring, written and tested runbooks, incident management discipline, change control) are layers an MSP already runs every single day. Taking over a ready operational foundation instead of building maturity from scratch shortens the time for agentic tools to start producing value. The same foundation also makes the agent's authority boundaries and audit trail defined from day one: which action runs automatically and which waits for approval is written down as part of the service level agreement.

Five steps you can start on Monday morning

An IT team with an autonomous operations goal has a known set of questions to answer first. In order:

  1. Take a visibility inventory. How many monitoring tools do you run, how many of them talk to each other, and can you trace a single incident end to end on one screen?
  2. List your 10 most recurring incidents. Pull the most repeated incidents from the last six months of alert history; these are automation's first candidates.
  3. Write and test runbooks for those 10 incidents. No incident that humans cannot resolve consistently can be delegated to an agent.
  4. Define the authority matrix. Which action is fully automatic, which requires approval, and which always stays with a human? No agent should go live before this classification exists.
  5. Start small, measure, expand. Limit the initial scope to read-only analysis (triage, correlation, root-cause suggestions); measure the approved-action rate and false positives, and widen authority gradually.

The industry says it will reach autonomous operations within two years; the measured reality shows that timeline holds only for those whose foundation is ready. Teams that start preparing the ground today will be in the minority that can delegate authority with confidence once the agents mature.