Is Your Strategic Planning Outdated? 9 Assumptions CIOs Can't Afford to Make
Key Highlights
- Many technology strategies rely on assumptions that once seemed stable but are becoming less predictable in today's operating environment.
- External forces such as power constraints, geopolitical shifts, and regulatory fragmentation can reshape technology priorities and budgets unexpectedly.
- Emerging risks, including shadow AI agents, misinformation, and AI cost volatility, require new planning assumptions and governance models.
- The most resilient organizations continuously challenge their assumptions and adapt before changing conditions force them to do so.
Most strategic plans fail for the same reason: they're built on assumptions that no longer hold up.
For years, CIOs could safely assume cloud capacity would be available, regulations would evolve gradually, global technology ecosystems would remain connected and vendors would operate under predictable conditions.
Those assumptions are becoming much less dependable. AI, energy constraints, geopolitical fragmentation, regulatory divergence and digital sovereignty requirements are changing the environment faster than traditional planning cycles can adapt.
Here are nine outdated assumptions worth re-examining before CIOs and other IT leaders enter the next strategic planning cycle.
1. Assumption: Vendor location doesn’t matter
Most organizations still evaluate technology vendors primarily on functionality, cost and security.
But that’s changing. Increasingly, where a supplier is headquartered, where data is processed and which governments have legal authority over that data can become strategic considerations.
As geopolitical tensions, tariffs, digital sovereignty requirements and regional regulations continue to evolve, vendor geography is becoming part of risk management. Gartner’s 2026 CIO and Technology Executive Survey found growing concern around digital sovereignty, geopolitical risk, and vendor geography as factors shaping sourcing decisions (see sidebar).
Strategic implication. A supplier that looks ideal today could create compliance, operational or sourcing/geopolitical challenges tomorrow. CIOs may need to evaluate vendors not just on capabilities but also on jurisdictional exposure and resilience.
2. Assumption: Compute is what limits AI
Many AI roadmaps assume that enough compute capacity will be available when needed. But that assumption isn’t valid anymore.
Preparing for Geopolitical Fragmentation: 5 Actions CIOs Should Take
Trade tensions, wars, digital sovereignty laws, international AI competition and regional regulations are making the global technology landscape more complicated. Instead of assuming business will operate the same way everywhere, CIOs should build flexibility into their strategic plans so they can respond quickly when conditions change.
Don’t try to predict the next geopolitical disruption. Make sure your organization can adapt when a geopolitical disruption happens. These five planning steps can help.
- Map technology dependencies. Identify where critical data is stored, processed and supported, and understand which nations have legal jurisdiction over those assets.
- Reduce concentration risk. Avoid relying on a single cloud provider, AI vendor, region or critical supplier for essential services.
- Prepare for regional requirements. Design architectures that can adapt to differing data residency, privacy and AI governance regulations.
- Stress-test geopolitical scenarios. Evaluate the impact of sanctions, trade restrictions, supply-chain disruptions or cross-border data transfer limitations.
- Build strategic optionality. Favor technology, sourcing and governance decisions that can be adjusted quickly as business and regulatory conditions change.
The bigger constraint now is power. Utility interconnection delays, grid limitations and growing data center power demand are turning electricity into a strategic planning issue rather than a facilities issue. In fact, IDC’s FutureScape 2026 Predictions research highlights how infrastructure decisions are being reshaped by a combination of economic, regulatory and geopolitical pressures that increasingly affect data center capacity and technology deployment.
Strategic implication. For enterprises planning significant AI expansion, future growth probably will depend as much on energy availability and location strategy as on access to GPUs and cloud services.
3. Assumption: Employees can distinguish real content from AI-generated content
Most security programs are built to identify and stop deceptive communications such as phishing emails and impersonation attempts.
What's changing is the speed, scale and realism of deception. AI can generate convincing fake executive communications, synthetic audio, manipulated video and large-scale misinformation campaigns that make authenticity harder to verify during high-pressure situations. So, organizations should address these risks in their strategic planning efforts.
Here’s the blind spot. A future disruption may depend less on whether attackers breach systems and more on whether employees, customers and partners can trust what they see and hear.
Questions to ask for strategic planning:
- How would your organization verify the authenticity of communications during a crisis?
- Can employees distinguish between real and AI-generated content?
- Does incident response include reputation manipulation scenarios?
4. Assumption: Compliance is a one-time project
Most IT leaders budget for compliance as they would for any large implementation effort.
But that’s changing. What’s becoming harder is operating across multiple, conflicting regulatory frameworks simultaneously. Privacy laws, AI regulations, cybersecurity reporting requirements and data residency rules are increasingly diverging across regions instead of converging.
Ultimately, strategic planning is an exercise in managing assumptions.
Strategic implication. If it hasn’t already, compliance likely will become a permanent operating cost rather than a periodic initiative. Tech architectures may also need to vary by geography. And multiple, complex regulatory frameworks can affect architecture decisions, operating costs, cloud strategies, governance models, product deployment plans and more.
Questions to ask for strategic planning:
- Can the organization operate under different AI rules in different markets?
- Are compliance costs being modeled as ongoing operational expenses rather than one-time projects?
5. Assumption: AI agents will be deployed through formal IT channels
Organizations are accustomed to shadow IT. Few have fully considered shadow AI agents. Business units are beginning to deploy AI agents independently, often outside traditional governance structures.
This means IT leaders can lose visibility into how decisions are being made, what data is being accessed, and which permissions agents have been granted.
Strategic implication. Over time, organizations may find themselves managing an increasingly large digital workforce that was never formally planned or governed. This needs to be part of a strategic plan.
6. Assumption: Supply chain risk ends with direct suppliers
Most CIOs understand the risks associated with critical technology vendors. What many strategic plans overlook are the layers of dependencies that exist beyond those direct relationships.
That assumption no longer holds up. Modern enterprises rely on complex ecosystems of cloud providers, telecommunications networks, AI model providers, identity platforms, SaaS vendors and the suppliers that support them. As organizations become more interconnected, they also inherit risk from providers they never selected and may not even know exist.
Here’s the blind spot. A disruption affecting a fourth-party or fifth-party provider can quickly become your operational problem, even when your organization has no direct contract or visibility into that supplier. By the time the issue becomes visible, the impact may already be cascading across multiple business functions.
Strategic implication. Supply-chain resilience is no longer just about evaluating key vendors. CIOs may need a clearer understanding of the broader ecosystems that support critical business services and identify where hidden concentrations of risk could create operational vulnerabilities.
7. Assumption: Risks happen one at a time
Many strategic plans evaluate risks individually. But the real world rarely works that way.
Disruptions increasingly arrive in combinations, often causing a chain reaction where an initial problem triggers a series of secondary and tertiary failures across interconnected systems — like falling dominos. Examples include:
- Geopolitical conflict + sanctions + vendor disruption + regulatory changes + cost increases.
- Extreme weather + power shortages + cyberattacks.
- AI-generated misinformation + social unrest + operational disruption.
- Misinformation + existing operational disruptions + reputational damage.
Strategic implication. Organizations often are prepared for individual disruptions but remain vulnerable to several events occurring at once. That's often where strategic plans tend to break down.
8. Assumption: AI will get cheaper over time
Many AI business cases quietly assume falling costs.
But even if model costs decline, governance, security, orchestration, monitoring, compliance and energy costs may offset those savings.
Strategic implication. Projects that appear financially attractive now could look quite different a few years from now. Strategic plans should account for multiple AI cost scenarios rather than a single forecast.
Disruptions increasingly arrive in combinations, often causing a chain reaction where an initial problem triggers a series of secondary and tertiary failures.
9. Assumption: Existing governance models will remain effective
Enterprise leaders often assume the governance structures that worked for traditional tech projects will also work for AI initiatives.
That assumption is becoming riskier. As AI adoption accelerates, the pace of decisions increases. New use cases, data sources, vendors, regulatory requirements and business opportunities emerge faster than many approval processes were designed to handle.
The challenge is no longer simply governance. It's decision-making architecture: who can make decisions, how quickly they can make them, what can be delegated and when escalation is required. Organizations using similar AI technologies may achieve vastly different outcomes based on how efficiently they make and execute decisions.
IDC's FutureScape research argues that success increasingly depends on orchestration, governance and organizational decision-making capabilities rather than technology alone.
Strategic implication. AI advantage may depend less on which models an organization deploys and more on whether leaders can make timely decisions about investments, risks, policies and operational changes. Governance that slows every decision can become a competitive disadvantage.
Questions to ask for strategic planning:
- How long does it take to approve a major AI initiative?
- Which decisions require executive approval, and which can be delegated?
- Are governance processes designed to accelerate responsible adoption or primarily to prevent risk?
Planning is really about managing assumptions
The organizations that adapt fastest won't necessarily have better forecasts. They'll recognize when an assumption is no longer true and adjust before competitors do.
Many assumptions that felt stable just a few years ago, from global technology access to power availability and regulatory consistency, are becoming less predictable.
For CIOs, strategic planning isn’t about predicting the future. It's about identifying which assumptions could break and preparing the organization to adapt when they do.
About the Author

Theresa Houck
Contributor
Theresa Houck is an award-winning B2B journalist with more than 35 years of experience covering industrial markets, strategy, policy, and economic trends. As Senior Editor at EndeavorB2B, she writes about IT, OT, AI, manufacturing, industrial automation, cybersecurity, energy, data centers, healthcare, and more. In her previous role, she served for 20 years as Executive Editor of The Journal From Rockwell Automation magazine, leading editorial strategy, content development, and multimedia production including videos, webinars, eBooks, newsletters, and the award-winning podcast “Automation Chat.” She also collaborated with teams on social media strategy, sales initiatives, and new product development.
Before joining EndeavorB2B, she was an Industry Analyst at Wolters Kluwer in its human resources book publishing operation. Before that, she spent 14 years with the Fabricators & Manufacturers Association, Intl., serving as Executive Editor of four magazines in the sheet metal forming and fabricating sector, where she managed and executed editorial strategy, budgets, marketing, book publishing, and circulation operations, and negotiated vendor contracts.
Houck holds a Master of Arts in Communications from the University of Illinois Springfield and a Bachelor of Arts in English from Western Illinois University.
Resources
Quiz
Stay ahead of the curve with weekly insights into emerging technologies, cybersecurity, and digital transformation. TechEDGE brings you expert perspectives, real-world applications, and the innovations driving tomorrow’s breakthroughs, so you’re always equipped to lead the next wave of change.


