Skip to main content
Reports

State of AI Readiness in Business Software (October 2026)

This month's report measures how widely business software ships AI features, how many tools connect to a buyer's own AI assistants, and what vendors disclose about training, audit logs and certifications.

By Value-Position · Published · Written with AI from our dataset; figures as of publication

Most business software now ships AI. Of the 1594 tools in the Value-Position database, 1186 ship at least one AI feature — 74% of all tools in the database. Buyers looking for software with no AI at all are now in the minority, and the harder question is what that AI does, which model sits behind it and what the vendor is willing to put in writing about your data.

That is what this monthly report measures: the capabilities vendors ship, whether their products connect to the AI assistants you already use, and how much they disclose about training, audit logging and certifications. The pattern across the database is a wide gap between shipping a feature and documenting it. Feature pages are full; disclosure pages are sparse.

AI in business software at a glance

1594
Number of tools in the Value-Position database
1186
Number of tools in the database that ship at least one AI feature
74%
Share of all tools in the database that ship at least one AI feature
18%
Share of those AI tools that are AI-native (built around AI rather than adding it on)
78%
Share of those AI tools whose vendor states it never trains AI models on customer data

What the AI does

42%
Share of AI tools that ship AI copilots and assistants
50%
Share of AI tools that ship AI agents and agentic workflows
20%
Share of AI tools that ship AI search
27%
Share of AI tools that ship AI predictive analytics
29%
Share of AI tools that ship AI document processing
19%
Share of AI tools that ship AI anomaly and fraud detection
27%
Share of AI tools that ship AI writing, summarisation and text automation
15%
Share of AI tools that ship AI governance tools

Agents are the most common AI feature in the database: 50% of AI tools ship AI agents and agentic workflows, and 42% ship AI copilots and assistants. Those two mean different things to a buyer. A copilot or assistant answers questions and drafts text inside the product, usually with a person reviewing the output. Agentic workflows go further: the software plans and executes multi-step tasks, which raises the stakes on permissions, logging and rollback.

Document processing (29%), AI predictive analytics (27%) and AI writing, summarisation and text automation (27%) sit in the middle of the range, while AI search (20%) and AI anomaly and fraud detection (19%) trail. Of the 470 AI tools whose vendor says whether the product is built around AI, 18% are AI-native, meaning AI does the product's core job rather than being added to an established product. AI governance tools are the least common capability, at 15% of AI tools.

Connecting to your AI stack

17%
Share of AI tools with a documented official or community MCP server
3%
Share of AI tools whose vendor states customers can bring their own model provider key

Most AI tools do not yet connect to the AI assistant a buyer already uses. Only 17% of AI tools have a documented official or community MCP server. An MCP server is a standard connector that lets AI assistants such as Claude, ChatGPT or Cursor read from and act in a product, so a question typed into an assistant can pull live records instead of a copy-pasted export. Tools that ship one include Aspire, whose finance MCP lets teams query cash, spend, budgets and approvals in natural language, Netlify, Taskade, Slack and Aikido Security.

Bring-your-own-key is rarer still: 3% of AI tools have a vendor that states customers can bring their own model provider key. Taskade is one example, running on the vendor's key or the customer's own. For buyers with a preferred model provider or a negotiated inference contract, that list is short.

Your data and oversight

111
Number of AI tools whose vendor states whether it trains AI models on customer data
78%
Share of those AI tools whose vendor states it never trains AI models on customer data
10%
Share of AI tools whose vendor documents logging of AI usage for audit
35%
Share of AI tools that list SOC 2 on their security pages
4%
Share of AI tools that list ISO 42001, the AI management certification

Training disclosure is the clearest split in the data. Of the 111 AI tools whose vendor states whether it trains AI models on customer data, 78% have a vendor that states it never trains AI models on customer data. Taskade, SimplyBook.me and Slack state it outright; Netlify states that training happens only if the customer opts in and is off by default. That leaves a large group where the vendor's pages say nothing either way, which is not the same as a promise.

Audit logging is much less common: 10% of AI tools have a vendor that documents logging of AI usage for audit. On certifications, 35% of AI tools list SOC 2 on their security pages, and 4% list ISO 42001, the AI management certification. Aikido Security and Slack list ISO 42001; Netlify lists SOC 2 alongside ISO 27001, GDPR and HIPAA.

Examples from the database

MetricAspire FT Pte Ltd logoAspireNetlify logoNetlifyTaskcade Inc. logoTaskadeSimplyBook.me logoSimplyBook.meAikido Security BV logoAikido SecuritySlack Technologies, LLC, a Salesforce company logoSlack
AI featuresCopilot / assistant, Agentic workflowsAgentic workflowsCopilot / assistant, Agentic workflows, AI search, Document processingCopilot / assistant, NLP automationAgentic workflows, Copilot / assistantCopilot / assistant, Agentic workflows, AI search, Document processing, AI governance tooling
Trains on your dataNot recordedOnly if you opt inNever trains on your dataNever trains on your dataNot recordedNever trains on your data
Runs onNot recordedOpenAI, AnthropicOpenAI, Anthropic, Google, Amazon, Open-weight modelsOpenAINot recordedNot recorded
MCP (AI assistants)Official MCP serverOfficial MCP serverOfficial MCP serverNot recordedOfficial MCP serverOfficial MCP server
Compliance listedNone listedSOC 2, ISO 27001, GDPR, HIPAANone listedNone listedSOC 2, ISO 27001, GDPR, ISO 42001SOC 2, ISO 27001, GDPR, HIPAA, FedRAMP, ISO 42001

Estimates from each vendor’s public pages, refreshed regularly. Confirm pricing with the vendor.

What to ask before you buy

Ask five questions before signing, because the figures above show that disclosure is patchy:

  • Does the vendor train AI models on your data, and is that written on its security or AI page rather than only in a sales call?
  • Which model providers power the AI features, and can you bring your own key if you have a preferred provider?
  • Where is your data processed and stored, and does the AI send anything outside the region you agreed?
  • How is AI usage priced — included in the plan, metered in credits, or billed by usage — and what happens when the allowance runs out?
  • Can you read or export a log of AI actions and prompts, and how long is it kept?

Keep exploring

Frequently asked questions

How much business software ships AI features?

Of the 1594 tools in the Value-Position database, 1186 ship at least one AI feature, which is 74% of all tools in the database. Those features range from copilots and assistants to agentic workflows, AI search and document processing. The practical question for a buyer is less whether a product has AI and more what that AI can read, change and act on inside your account.

Do AI software vendors train on customer data?

Only 111 AI tools have a vendor that states whether it trains AI models on customer data. Within that group, 78% state it never does. Taskade, SimplyBook.me and Slack say so outright, while Netlify says training is off by default and happens only with customer opt-in. For the rest, the vendor's public pages do not say, so put the question in writing before signing.

What is an MCP server and why should buyers care?

An MCP server is a standard connector that lets AI assistants such as Claude, ChatGPT or Cursor read from and act in a product, so people can ask questions of live records instead of exported files. 17% of AI tools have a documented official or community MCP server. Aspire, Netlify, Taskade, Slack and Aikido Security are examples. If your team works inside an AI assistant, MCP support decides whether the product is reachable from there.

What should I ask an AI software vendor before buying?

Ask whether the vendor trains AI models on your data and where that policy is published; which model providers power the features and whether you can bring your own key; where your data is processed and stored; how AI usage is priced; and whether the vendor documents logging of AI usage for audit, which 10% of AI tools do. Ask for each answer in writing, not in a demo.