Get the full report
One email and the rest of the report opens, plus the weekly roundup. No vendor spin, unsubscribe anytime.
The 2026 State of Enterprise Infrastructure
Independent analysis of the forces reshaping how enterprises run infrastructure. Built on cited public data.
Executive Summary
Enterprise infrastructure is in its largest reset in a decade. Three forces drive it at once. Broadcom’s takeover of VMware started a migration wave. Kubernetes became the default for new workloads. Then AI arrived and took the power, the budget, and the attention. Analysts agree on the direction. Most organizations are reducing their VMware footprint slowly, not in one cut, and very few have finished.
The pattern shows up in what gets signed. AI capacity deals are measured in gigawatts of power now, not server counts, and power sets the schedule. Sovereign cloud spending is forecast to climb from 80.4 billion dollars in 2026 to 110 billion in 2027, as sovereignty moves from policy slide to procurement gate. Most organizations have already absorbed a supply chain incident. The common thread is that capacity, power, and exit terms are now decided together.
These are not three separate stories. They are one story, and it is reshaping the entire stack. Everything below comes from public data, survey results, analyst forecasts, and hyperscaler capital plans. Where the numbers disagree, the report says so.
In this report: The migration wave · AI & the power crunch · Sovereignty · Development & platform engineering · Security · What to do

The migration wave is real, but it is slow
The stampede that everyone predicted after Broadcom acquired VMware did not happen. What happened is quieter and more durable. Organizations are not leaving in a rush. They are reducing their footprint steadily, phase by phase, while the price pressure keeps building.
Where workloads are going
The destination is telling. Most migrating workloads are not jumping to another hypervisor. They are going to the cloud or to a platform that already blends compute and containers.
| Destination | Share of migrating workloads |
|---|---|
| Public cloud IaaS | 72% |
| Microsoft Hyper-V / Azure stack | 43% |
| SaaS alternatives | 34% |
Why it is not moving faster
| Barrier | Share citing it |
|---|---|
| Migration complexity / risk | 25% |
| Unexpected costs | 23% |
| Technical limitations | 21% |
The typical timeline to resolve years of process dependencies is 18 to 24 months. This is a multi-year unwind, not a migration event.
AI is the new constraint on compute
Continue reading
Read the 2026 State of Enterprise Infrastructure report
You have read the first two sections. Tell me where to send the rest and it opens right here. No spam, unsubscribe anytime.
AI did not just add another workload. It changed what the whole platform has to be. GPU nodes cost more than the rest of the cluster put together. Training jobs run for days and cannot be interrupted. Your scheduler treats every pod as disposable, and it was never built for hardware that bills by the hour.
The bottleneck is not chips. It is power. Grid access is now the limiting factor on where AI capacity can grow, and utilities cannot expand fast enough to keep up. For infrastructure leaders, this makes power security the new battleground.
Kubernetes has become the common denominator for AI inference. Two-thirds of organizations running generative AI use it to serve those models. That is why the platform decision and the AI decision are now the same decision.
Sovereignty is becoming a procurement gate
Data sovereignty is no longer a compliance checkbox. It decides who gets the contract. Regulators mandate local storage, and buyers now restrict which providers they will work with at all.
The spectrum of sovereign options
Sovereignty is a spectrum, not a yes or no. At the light end, a public cloud with strict data-residency boundaries. At the heavy end, physically isolated infrastructure run by in-country personnel under local law, with no dependencies on non-EU systems.
| Level | What it means |
|---|---|
| Light | Data stays in-region, but the provider is a foreign corporation subject to its own law |
| Medium | Dedicated regional infrastructure with local support and personnel |
| Heavy | Physically isolated, in-country operated, local legal incorporation, no external dependency |
It comes down to one legal reality. Under the US CLOUD Act, a US-headquartered provider can be compelled to disclose data it holds outside the United States. A European data center run by a US provider is not automatically a European sovereign option.
Platform engineering has become the operating layer
Platform engineering crossed from emerging practice to organizational imperative. Dedicated platform teams are now the norm, and they report high up the org chart. The reason is simple. Developer productivity is a strategic asset, not an operational convenience.
Maturity drives outcomes
The correlation is stark. Organizations with mature platform engineering report far better outcomes with AI than those without.
| Metric | Mature orgs | Less mature orgs |
|---|---|---|
| Say platform maturity drives AI success | 73% | 44% |
| Report mature governance | 79% | 14% |
| Express trust in AI outputs | 81% | 48% |
Maturity is not about buying more tools. It is about treating the platform as a product, with roadmaps, user research, and measured self-service. High-performing platform teams track time from repo to production, mean time to recover, and golden-path adherence.
Security is a supply chain problem now
Software supply chain incidents are nearly universal, and the risk has shifted. AI-generated code is now the top concern, ahead of third-party code and dependencies.
The most common attack is not a zero-day. It is an exploit of a known vulnerability in third-party software that sat in a dependency tree for months because nobody owned the upgrade.
What actually helps
Of eleven security tool categories, only one was rated very effective by a majority of organizations. Hardened container images and secure container services. That is a practical signal. If you are not using verified, minimal base images, you are behind the curve.
| Measure | Value |
|---|---|
| Incidents exploiting known vulnerabilities | 38% |
| High-severity vulnerabilities among observed CVEs | 63% |
| Vulnerability instances outside the top 20 projects | 97% |
| Say SBOMs speed vulnerability mitigation | 73% |
What this means for you
If you are making an infrastructure decision in the next 12 months, here is how the data points you.
The platform decision is an AI decision
You are not choosing a tool to carry your old workloads. You are choosing a foundation for your old workloads and your AI workloads at once. The scheduler must understand GPUs. Power access must be part of the plan. And the choice has to keep your exit options open.

Sovereignty is a filter, not a footnote
If you operate in Europe or sell to regulated buyers, the residency question is now a gate. Map where your data lives, which laws can reach it, and whether a sovereign option is a competitive requirement before you write the budget.
Maturity is the multiplier
Every area of this report gets easier with a mature platform. Governance, trust, AI autonomy, security, and developer speed all track with platform maturity. Investment in the platform layer compounds.
Harden the long tail
Most vulnerability risk sits outside the top 20 projects. You need visibility across the whole dependency graph, not just the components you touch directly. Minimal base images, SBOMs, and policy-as-code are the practical levers.
This is the shortest possible version of a much larger story. For the full analysis behind these numbers, including unit economics, migration roadmaps, and the vendor-by-vendor breakdown, download the complete report.
Related reading. Enterprise AI Infrastructure Runs on Four Layers goes deeper on the stack under the model. Hardware, the operating system and runtime, shared GPU scheduling, and the development loop.
Sources: CloudBolt survey (Jan 2026) · IDC (2024) · Gartner forecasts for data center power (2025-2030) · Gartner sovereign cloud IaaS forecast (Feb 2026) · CNCF Annual Cloud Native Survey (2026) · Omdia software supply chain report (2026) · Puppet / Perforce State of Platform Engineering (2026). All figures are public and cited from the named research. Nothing here implies any analyst firm endorses a vendor.
