Summary
- BMC’s global survey of more than 1,300 mainframe practitioners and decision-makers found 94% expect continued investment in the platform and 45% rank AI implementation among their top priorities.
- Respondents were considerably more comfortable with AI recommending operational actions than executing them, including a 40% versus 23% split for code-management tasks.
- Cost, security, data integration, compliance, and certificate management remain obstacles as AI gains access to systems underpinning large-scale financial, government, retail, and corporate workloads.
Enterprise enthusiasm for autonomous AI becomes more restrained once software reaches systems that process critical transactions, with BMC’s latest mainframe research showing organisations increasingly prepared to let AI recommend operational changes while remaining reluctant to let it carry them out unaided.
The 21st annual survey from BMC, based on responses from more than 1,300 mainframe practitioners and decision-makers globally, suggests AI adoption on the platform is moving beyond experimentation without producing an equivalent appetite for unrestricted automation. Responses were collected between 24 March and 20 April 2026.
Confidence in the underlying platform remains high. Ninety-four per cent of respondents described the mainframe as either a long-term platform or one attracting new workloads, while the same proportion said their organisations were continuing to invest. Sixty-nine per cent reported growth in general-purpose mainframe capacity, challenging the assumption that newer cloud and AI infrastructure automatically displaces established enterprise systems.
AI is becoming part of that investment rather than a substitute for it. Forty-five per cent of respondents identified implementing AI technologies as a top priority, with applications ranging from performance tuning and problem detection to database management, development assistance, documentation, and operational support.
The sharper finding, however, lies in what organisations are unwilling to delegate. When asked about code management, 40% were comfortable with AI recommending an action, while only 23% would allow the technology to complete it. For database reorganisations, 43% preferred a recommendation, compared with 21% willing to let AI execute the work itself.
That difference separates technical capability from operational authority. A system may be capable of identifying a problem and proposing a remedy, but organisations running critical infrastructure still have to decide whether the model has enough context, reliability, and accountability to make the corresponding change without another person checking its reasoning.
Agents reach systems that cannot improvise
Mainframes remain heavily associated with workloads where errors can propagate quickly into financial transactions, customer records, public services, logistics, billing, and other processes whose value depends partly on predictable operation. That makes the platform a useful test for the idea that increasingly capable agents should also be given increasingly broad autonomy.
BMC’s respondents are not rejecting agentic technology. Thirty-six per cent plan to invest in creating agents to manage the mainframe, while 32% expect to invest in third-party agents, indicating that automation is moving deeper into the operating environment even as businesses preserve human approval around consequential actions.
The pattern resembles control models emerging elsewhere in enterprise software, where generative systems interpret requests, assemble information, or recommend decisions while deterministic workflows retain authority over transactions, approvals, and policy-sensitive actions. The practical dividing line is not between organisations that use agents and those that do not, but between the tasks an agent can perform independently and those where its output becomes an input to somebody else’s decision.
Mainframe operations make that boundary particularly visible because the cost of an incorrect intervention can be much higher than the inconvenience caused by a poor summary or an inaccurate productivity assistant. Performance tuning, database restructuring, code changes, and recovery operations all interact with systems whose availability is closely managed, leaving organisations with little incentive to maximise autonomy simply because a model can produce a plausible recommendation.
The survey also shows that implementation problems remain familiar despite the maturity of the infrastructure involved. Forty-one per cent identified implementation cost as an AI concern, followed by security and privacy at 39%, data integration at 37%, and regulatory or compliance requirements at 22%.
AI adds another identity problem
As more AI applications and agents connect to mainframe data, the security question extends beyond model behaviour into the ordinary mechanics of authenticating machines and protecting connections. BMC highlights digital certificate management as one area where existing operating practices may come under pressure as the number of automated services increases.
Forty-three per cent of respondents said their organisations use internally developed automation to manage certificates, while 31% use product-based automated systems and 25% still rely on manual work. Those approaches face additional pressure as the permitted lifetime of publicly trusted TLS certificates falls, increasing how often certificates have to be issued, renewed, monitored, and replaced.
That work may appear removed from the more visible discussion around agentic AI, although the two are increasingly connected. An autonomous or semi-autonomous service accessing corporate data needs an authenticated and secured route into the relevant system, and multiplying those machine-to-machine relationships creates operational work regardless of how capable the AI itself becomes.
The mainframe survey consequently captures a broader feature of enterprise AI adoption: deploying models into established environments tends to expose conventional infrastructure problems rather than remove them. Identity, data quality, access management, recovery, testing, integration, auditability, and change control all remain necessary once AI becomes another participant in a production system.
Data recovery has also risen in prominence in BMC’s findings, with respondents citing recovery points, recovery times, and backup automation among their concerns. Adding intelligence to an infrastructure platform does not reduce the consequences of basic operational failure; connecting more automated systems to critical data can increase the need to understand how an error can be contained and reversed.
Trust becomes an operating model
BMC describes the shift as a move from enthusiasm towards pragmatism, although the survey is produced by a vendor with a commercial interest in mainframe automation and should be read in that context. Its value lies less in establishing a precise global rate of enterprise AI adoption than in showing how practitioners responsible for established production systems are dividing recommendation from execution.
That division becomes more important as agentic products spread through the rest of the technology estate. Human oversight is often presented as a governance principle, but implementing it requires much more precise decisions about which actions need approval, who can provide it, what evidence they receive, how quickly they have to respond, and what happens when an automated recommendation is wrong.
There is also a productivity trade-off. If every agent action ultimately requires a person to inspect and approve it, automation can create another queue of decisions rather than remove work. Conversely, handing an agent broad authority simply to maximise labour savings can introduce operational risk that outweighs the efficiency gained.
The likely progression is therefore more granular. Organisations can permit autonomous action first where outcomes are reversible, rules are well understood, monitoring is strong, and potential damage is contained, while retaining human approval for changes affecting production systems, sensitive data, or regulated processes. Reliability demonstrated over time can then alter that boundary.
Mainframes provide an unusually clear environment in which to see that negotiation because the systems themselves are mature while the AI layer being attached to them is comparatively new. BMC’s survey shows investment continuing in both rather than one replacing the other, with organisations trying to use AI to modernise operations without discarding the controls built around systems they already depend upon.
The result is a less dramatic version of agentic computing than the idea of autonomous software workers independently managing corporate infrastructure, but a more plausible one for systems where an incorrect action can affect thousands or millions of transactions. AI appears to be earning operational authority incrementally — first by identifying problems, then by recommending what should happen, and only later, where reliability can be demonstrated, by being allowed to act.












