For nine straight years, IBM i shops named cybersecurity their biggest worry. This year, something passed it.
In the 2026 Fortra IBM i Marketplace Survey, 69% of shops named IBM i skills their single biggest concern, ahead of security at 64%. That’s the first time in nearly a decade the top spot changed hands. The platform didn’t get less secure. The people who understand it started leaving faster than anyone is replacing them.
If you run manufacturing IT on an AS/400, you already know this story from the inside. You have a dev team of three to five people. At least one of them holds knowledge that exists nowhere else. And you’ve done the retirement math in your head more than once.
Here’s what the numbers say, and a practical way to gauge how exposed you actually are.
The Numbers Behind the IBM i Skills Shortage
The survey data reads like an actuarial table for institutional knowledge:
-
- 72% of IBM i developers are now over 50, and roughly 36% are over 60
-
- 91% of shops still run RPG in production, with no meaningful replacement pipeline behind the people who write it
-
- 21% of shops run on just three to five developers, a number that hasn’t moved in ten years
-
- 66% have fewer than three system admins; 10% have none at all
Meanwhile, more than 100,000 companies still run these systems in production worldwide. They survived four decades because they work, and because the cost of leaving always looked higher than the cost of staying.
That math held for 30 years. It doesn’t anymore, and we’ll get to why. But first, the part most teams underestimate.
Concentration Is the Real Risk, Not the Platform
The AS/400 itself is famously reliable. Ask anyone who runs one; the box doesn’t go down. What goes down is the number of people who can safely change what runs on it.
Decades of custom RPG carry the real logic of the business: how orders actually flow, how the plant actually schedules, what that one subroutine from 1998 actually does during month-end close. When that knowledge lives in two heads and zero documents, you have a single point of failure wearing a retirement countdown.
And it quietly constrains everything else. Enhancement backlogs grow because fewer people can touch the code. Integrations become workarounds. AI initiatives stall in the pilot phase because the data and logic they need are locked inside a system nobody dares disturb. Fortra’s survey shows AI and machine learning interest jumping from 30% to 42% in a single year; the appetite is real, and the platform is the blocker.
The exposure compounds on a schedule you don’t control. Every year, the bench gets shorter, the contractors get more expensive, and the option space gets narrower.
Waiting Is Also a Decision
Plenty of shops respond to all this with a reasonable-sounding position: it works, why touch it?
That position assumes waiting is neutral. It isn’t. There’s some evidence the market knows it, too: 70% of IBM i shops plan a hardware or software upgrade in 2026, a record in the survey’s history. Budgets are moving.
What changed the calculus is that the migration math itself changed. Large language models can now read the RPG dialects that kept these systems frozen for 30 years. Documenting what a system does used to be the step that made every modernization conversation stall. It went from a multi-year archaeology project to a tractable engineering task. What used to be a leap of faith can now be a measured, incremental program.
You don’t have to believe that today. This piece has one job: to argue that knowing your exposure is worth a half hour of your time, because every option you have, including staying put, gets better when you understand where the risk actually sits.
How Exposed Are You? A Five-Question Self-Check
Answer honestly. Give yourself a point for each “yes.”
-
- Bus factor: If your most knowledgeable RPG developer left tomorrow, could at least two other people safely change your most critical application?
- Horizon: Will the people who maintain your RPG today still be working for you in five years?
- Documentation: Does the knowledge of how your core system works exist anywhere outside people’s heads, in documentation or tests that someone new could actually use?
- Pipeline: If you posted an RPG role today, are you confident you could fill it within 90 days at a salary you’d approve?
- Change safety: Can you make a change to your core system and prove nothing else broke, without relying on one person’s memory of what connects to what?
Zero or one point: you’re on the cliff’s edge. The exposure is already shaping what your team can and can’t do, whether or not anyone has said it out loud. Mapping the risk should be this quarter’s problem, not next year’s.
Two or three points: you have time, but you’re spending it. Start capturing knowledge now, while the people who hold it are still in the building.
Four or five points: you’re in better shape than most of the installed base. Keep the documentation and cross-training habits that got you here.
The skills cliff doesn’t announce itself. There’s no outage, no alert, no audit finding. There’s just a Tuesday when the person who knew is gone, and the system that runs your business becomes the system nobody can touch. The teams that come through it well are the ones who measured their exposure while they still had choices.
If your score landed lower than you’d like, the next step starts with a clear read of where your risk and cost actually sit, not a migration decision. That’s a conversation we have every day, and we’re happy to share what we’ve learned.
