The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.
A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.
Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail
AI that classifies, routes, and prioritises incidents while automating root cause diagnosis. Includes intelligent ticket routing and automated fault tree analysis; distinct from automated remediation which takes corrective action rather than diagnosing.
AI-driven incident triage and root cause analysis is a proven practice with a mature vendor ecosystem, GA tooling from multiple platforms, and documented ROI at enterprise scale. The core value proposition — classifying and routing incidents automatically while diagnosing why failures occur, not merely that they occurred — has been validated through years of production deployments at organisations ranging from Fortune 500 to Tier-1 service providers. The question for most teams is no longer whether these tools work, but how to implement them without drowning in integration complexity and alert noise. That distinction matters: despite broad vendor capability and strong MTTR reduction evidence, a persistent adoption paradox has emerged. Organisations overwhelmingly invest in AIOps platforms yet struggle to operationalise AI-assisted triage beyond initial pilots, particularly in the mid-market. LLM-assisted diagnosis is accelerating vendor roadmaps, but research reveals systematic reliability gaps that prompt engineering alone cannot resolve. The practice is mature and accessible; the barrier is execution, not technology.
The vendor ecosystem is broad and GA-ready. Splunk ITSI, BigPanda, Moogsoft (Dell), IBM Instana, and Logz.io all ship LLM-assisted triage and root cause suggestion as production features; BigPanda's AI Incident Assistant and Microsoft's RCA Agent via Copilot Studio represent the latest wave of generative-AI-native releases. Named deployments continue to demonstrate measurable impact: ServiceNow's NBA Workplace Service Delivery achieved 51% annual ROI with 30-50% MTTR reduction and 99.2% noise suppression; Thoughtworks reports RCA cycles compressed from hours to minutes across 16+ client engagements, with L1/L2 ticket volume down 35-40%. Incident.io documents 37% faster MTTR through AI-automated post-mortems, saving teams roughly 75 minutes per incident. Türk Telekom achieved 49% improvement in service outages and Vodafone reduced alarm noise by over 70%.
As of July 2026, mainstream production adoption is confirmed: a Futurum survey (n=839 decision makers) documents 57% of organizations deploying automated RCA in production, with 45.3% using AI-assisted log analysis in operational environments. Multi-platform benchmarking confirms MTTR gains at scale: Techwrix's 12-platform AIOps study documents BT Group achieving 2-hour-to-85-second MTTR reduction, PayPal 60% triage-time compression, and LinkedIn 70% MTTR improvement with 90-95% alert volume suppression across production environments. Agentic RCA reaches maturity: Splunk ITSI 5.0 GA includes Event iQ Diagnose with confidence-scored LLM root cause and CMDB/change context; Splunk Agentic Observability and New Relic Autopilot ship out-of-the-box SRE agents for autonomous incident triage and remediation guidance. Production deployment evidence diversifies: BigPanda's AI Incident Assistant achieves 200% RCA time savings (20-30 minutes per incident) from beta customers; Tencent Cloud deployed LLM-powered alert aggregation achieving ~75% accuracy on 12,000+ weekly alerts; PagerDuty's SRE Agent diagnosed AI-specific tool-selection degradation in production; Elastic's work with Cisco ISE demonstrates ML-assisted RCA compressing diagnostic time from 20 minutes to seconds; Japanese fintech LayerX deployed Datadog Bits Investigation for autonomous investigation of metrics/logs/traces/change data; Microsoft's Digital Crimes Unit used AI-assisted RCA (Copilot) to decompose malware code and identify C2 infrastructure during Operation Endgame law-enforcement action. Research advances continue: peer-reviewed frameworks propose graph-agnostic RCA and multi-agent orchestration; OpenRCA and ORCA benchmarks show reasoning ability—not data availability—is the bottleneck, with structured multi-agent approaches outperforming single-agent LLMs.
These gains coexist with a striking adoption gap and persistent technical barriers that resist architectural solutions. Production accuracy remains constrained: ORCA-bench (production-fidelity benchmark on 50GB telemetry across 6 days) achieved 25.3% accuracy on medium-difficulty RCA tasks and 10% on hard tasks; removing source code access dropped accuracy 9-16 percentage points. A critical architectural trend is emerging: practitioner experience is shifting from autonomous agentic RCA toward deterministic, curated-context designs. ZenML and Incident.io, after real production deployments, scrapped autonomous agent approaches due to unpredictability and high operational cost; the industry consensus is now that data pipeline quality and context curation matter more than raw model capability. Data quality remains the fundamental blocker, not model capability. Virima's July 2026 production incident analysis documented RCA failure on a P2 outage: the AI co-pilot processed the alert in 8 seconds but recommended rollback on a decommissioned load balancer (ghost CI), wasting 22 of 40 minutes because the replacement device existed only in live infrastructure with no CMDB record. A Sumo Logic survey of 500+ security leaders found that 90% consider AI important for security purchases, yet only 9% have deployed it for incident triage. Operational toil rose 30% in 2025 despite 51% of companies deploying AI tools; a SANS survey found 63% of organizations report significant AI shortcomings in threat detection and response (up from 45% prior year), and 73% of organisations experienced outages from ignored alerts. Pilot failure rate stands at 95%, driven by data quality issues; mid-market RCA projects face severe cost overruns—one insurance deployment reached $4.7M against a $1.2M budget—and 94% of IT leaders cite vendor lock-in as a concern. On the technical side, LLM-based RCA shows systematic failures: a February 2026 study found hallucinated data interpretation and incomplete exploration persist across all model tiers regardless of capability level, requiring human review. Five critical data quality barriers block deployment: incomplete work order history, inconsistent asset naming, missing failure classifications, data silos between observability systems, and inconsistent technician data entry—costing organisations $12.9M annually. Alert-fatigue RCA approaches face fundamental limitations: alert-only correlation inherits blind spots of existing alerting rules and cannot recover weak signals that don't trigger thresholds, plateauing without evidence-rich foundations (metrics, traces, logs) as the diagnostic source. Novel attack vectors threaten deployment: Cloud Security Alliance's June 2026 threat assessment documented Gaslight (DPRK-linked malware using prompt injection to disable LLM-assisted triage), LLMjacking (stolen AI compute for autonomous attacks), and ShareLock (MCP tool poisoning)—the first documented malware targeting AI analyst triage workflows. Security governance adds friction: 98% of CISOs in one survey report delaying AI agent deployments due to insufficient controls. The governance and trust barriers remain acute: a 1,000+ IT leader survey found 61% adoption of AI for accelerated RCA but 71% still manually verify outputs and 62% struggle trusting recommendations, capturing an implementation gap where teams receive AI insights but lack confidence or governance frameworks to act on them directly. The tooling works; the organisational, technical, and governance scaffolding to deploy it reliably is what most teams still lack.
— Futurum survey (n=839): 57% of organizations deployed automated RCA in production; 45.3% deployed AI-assisted log analysis. Mainstream enterprise adoption signal.
— ORCA-bench production-fidelity RCA benchmark: 25.3% accuracy on medium tasks, 10% on hard; removing source access drops accuracy 9-16pp. Advocates copilot over autonomous.
— SANS survey (n=536 practitioners): 63% report significant AI shortcomings in threat detection/response (up from 45%); only 27% call deployment mature. Adoption outpacing capability.
— Industry shift from agentic to deterministic RCA pipelines: practitioners (ZenML, Incident.io) scrapping autonomous designs for curated context and repeatable approaches.
— Production incident triage: SRE Agent diagnosed AI-specific tool-selection degradation by filtering Arize traces and pattern-matching root cause in output quality metrics.
— BigPanda AI Incident Assistant production deployment: 200% RCA time savings, 20-30 min per-incident manual work reduction; quantified from beta customer testimonials.
— OpenRCA benchmark: required evidence present in most failures; bottleneck is reasoning ability not data access. Structured multi-agent RCA outperforms single-agent LLM and classical methods.
— Tencent Cloud production RCA system: LLM-powered alert aggregation achieving ~75% accuracy on 12,000+ alerts/week using vector embeddings and historical case retrieval.