Visualização normal

Antes de ontemCybersecurity News
  • ✇Security | CIO
  • Salesforce offers more Agentforce credits to drive adoption
    Salesforce is updating some of the editions, or pricing tiers, of Agentforce Sales and Agentforce Service, a year after their rebrand from Sales Cloud and Service Cloud. The top three now bundle AI agents, analytics, Slack, security, and support with larger allocations of Flex Credits; two of the tiers are also increasing in price. The Core edition replaces the old Enterprise edition, and its price goes up from $175 per user per month to $195, and now includes 500,000 Flex
     

Salesforce offers more Agentforce credits to drive adoption

4 de Setembro de 2026, 11:21

Salesforce is updating some of the editions, or pricing tiers, of Agentforce Sales and Agentforce Service, a year after their rebrand from Sales Cloud and Service Cloud. The top three now bundle AI agents, analytics, Slack, security, and support with larger allocations of Flex Credits; two of the tiers are also increasing in price.

The Core edition replaces the old Enterprise edition, and its price goes up from $175 per user per month to $195, and now includes 500,000 Flex Credits. Advanced edition costs $395 per user per month and includes 1 million credits, replacing the $350 per month Unlimited edition. The Max edition replaces the old Agentforce 1 tier and now includes 2.75 million credits instead of 1 million for the same $550 per month fee, Salesforce said in a blog post.

The lowest tiers, Starter and Pro Suite, remain unchanged in features and price, although there is a hint that Salesforce is renaming the latter to Professional edition.

What is new in Agentforce Sales?

The new editions bring several capabilities to the base subscription of Agentforce Sales that were previously sold separately: The Core edition now includes Momentum, Slack Business+, and Tableau Next, while the Advanced edition adds Sales Programs, the Premier Success Plan, and additional security and data-protection capabilities. Max edition adds Agentforce for Sales, Agentforce Coworker, Salesforce Spiff, Sales Planning, Sales Programs, Salesforce Maps, Slack Enterprise+, and additional Tableau Next capabilities.

Under the previous Enterprise and Unlimited editions, Sales Programs was an add-on, Tableau Next was available through a separate Tableau+ purchase, and Agentforce itself had to be purchased separately.

What is new in Agentforce Service?

The new editions of Agentforce Service also incorporate capabilities that previously required additional purchases.

The Core edition includes case management, self-service Help Center, Slack Business+, and Slackbot; Advanced adds Agentforce Help Agent, Premier Success Plan, full sandbox, Backup & Recover, and Data Detect, and Max adds Service Rep Assistant, Workforce Engagement, Quality Management, IT Service, unmetered Agentforce Coworker access, and a library of service agent templates.

Under the previous Enterprise and Unlimited editions, Agentforce was available as a separate purchase, while capabilities such as additional security, data protection, and workforce-management tools were also packaged separately or reserved for higher-tier offerings.

Procurement simplicity could come at the cost of visibility

Salesforce said the new editions deliver from 50% to 70% greater value than those they replace, but realizing that value may not be straightforward, analysts warned, particularly as enterprises move from experimenting with Agentforce to deploying agents at scale.

While bundling more AI, analytics, security, Slack, and support capabilities into the subscriptions could simplify procurement of Salesforce products for enterprises, the economics could become more complicated once customers start consuming their included Flex Credits, said Manoj Chandra Jha, principal analyst at Nord-IQ Research.

That is because bundling more capabilities into a single subscription reduces the line-item visibility CIOs previously relied on, and most enterprise finance teams are still learning how to forecast for credit consumption, he said.

Without that visibility CIOs will find it hard to assess how Salesforce’s offerings compare with competing products, particularly when they are trying to determine the cost of specific capabilities or decide which components of a broader bundle are delivering value, he said.

Salesforce may be exaggerating the real value of the new editions, said Pareekh Jain, principal analyst at Pareekh Consulting.

“While CIOs may get more capabilities in a single package, they will still need to assess how much of that functionality employees actually use. A package may offer 60% more theoretical value, but that benefit can disappear if much of the bundled functionality or Flex Credits goes unused,” he said.

Overuse is also a problem, said Jha: As agent usage grows, enterprises could consume their included Flex Credits more quickly and eventually need to purchase additional credits, making actual usage a more important measure of value that CIOs should follow rather than the headline savings attached to the new editions, Jha noted.

New editions targeted at accelerating adoption

While Salesforce talks of value for money, analysts see its real goal with the new editions as accelerating Agentforce adoption.

Investment analysts raised concerns about questioned Agentforce’s customer traction in July, citing enterprise data readiness and the product’s maturity as factors holding back broader adoption. Salesforce, however, has pushed back, pointing instead to growth in deployments and usage.

Nevertheless, said Jha, “With Agentforce running at only a fraction of Salesforce’s 150,000-plus customer base, and analysts pinning the drag on messy enterprise data, folding security and analytics into every tier looks like Salesforce neutralizing the objection before a prospect can raise it.”

Salesforce said last month that its customers had increased their average number of agents from five in February 2025 to 13 by April 2026, while the average number of agent actions per account grew at a 31% compound monthly growth rate over the same period.

Jha sees the updated editions as aimed primarily at Salesforce’s existing customer base, giving companies already using its products more incentives and capacity to expand their use of Agentforce, rather than as a draw for new customers.

Salesforce said the new editions for Agentforce Sales and Agentforce Service are already available, and will soon be joined by new editions for Agentforce Industry.

Existing Agentforce 1 edition customers can upgrade to the new Max edition at no additional cost, the company said, adding that in the future, Max editions across its Sales and Service offerings will also include an allocation for Headless 360.

  • ✇Security | CIO
  • Why AI TCO is so tricky — and how to start calculating it
    Achieving return on investment is impossible without knowing the total cost of ownership (TCO) of an initiative — and when it comes to AI, CIOs are finding cost calculations anything but straightforward. Subscription and token costs are a big part of the calculus, but several other factors go into the cost of AI projects, says Ben Schein, chief AI and analytics officer at AI data platform provider Domo. Chief among those are cloud infrastructure costs and the human time in
     

Why AI TCO is so tricky — and how to start calculating it

27 de Agosto de 2026, 07:01

Achieving return on investment is impossible without knowing the total cost of ownership (TCO) of an initiative — and when it comes to AI, CIOs are finding cost calculations anything but straightforward.

Subscription and token costs are a big part of the calculus, but several other factors go into the cost of AI projects, says Ben Schein, chief AI and analytics officer at AI data platform provider Domo. Chief among those are cloud infrastructure costs and the human time involved in guiding or correcting AI outputs, he notes.

In addition, many organizations have multiple divisions using different AI tools for vastly different purposes.

“There’s not like a single ledger,” Schein says. “Right now, and maybe for the foreseeable future, there’s sort of like a multiple ledger approach to how all this works.”

A shifting paradigm

While token costs have dropped significantly in the past two years, costs vary wildly between models and AI providers, and the price drops are often offset by increased usage. And AI providers have also explored other kinds of consumption-based pricing, including API calls, compute time, or documents processed.

All this makes it difficult to measure TCO, Schein says.

“You have sort of these subscriptions, you have the consumption and the tokenization, you have some of the infrastructure you might be paying for,” he says. “There’s also a human tax that introduces new time for verification and review, and if the AI is sloppy or creating slop, you might be inadvertently adding to your costs without knowing it.”

It’s difficult to measure TCO because AI doesn’t have a single cost center, agrees Shane Cronin, head of FinOps and ITAM services at systems integrator SHI.

“By the time you’re looking at the bill, you’re dealing with token consumption, cloud infrastructure, multiple AI models, governance tooling, integration work and, increasingly, autonomous agents making decisions across systems,” he says.

IT leaders at many organizations still define AI success through narrow technical metrics instead of prioritizing business outcomes, Cronin adds.

“Calculating token costs is relatively straightforward,” he adds. “Calculating whether those tokens actually created measurable business value is much harder. That’s where most CIOs are today.”

Unpredictability and hidden costs

Michael Moran, chief technology and information officer at contact center outsourcing provider NQX, sees several other factors leading to further unpredictability over AI costs.

For example, data center costs are rising, AI vendors are starting to shift from subsidized pricing to profitability, and organizations have increasingly complex AI use cases, he says.

“IT leaders should temper expectations that AI inherently reduces costs,” he adds. “Instead, it’s important to understand that full automation is likely to be prohibitively expensive for most enterprises, and that brands will need to balance AI investment with human engagement strategies that improve long-term value rather than cut costs in the short term.”

If AI implementations work exactly as expected right out of the grate, TCO should be relatively easy to calculate, he says. But agentic AI implementations often require much more human training and intervention than expected.

“These are the hidden costs that are often underestimated or ignored altogether when initially calculating TCO,” Moran adds.

Visibility is the first step

Chris Cagnazzi, chief innovation officer at IT solutions provider Presidio, is one IT leaders seeking to get a handle on the complexity of calculating AI TCO by applying playbooks from the cloud migration era.

Cagnazzi has adapted Presidio’s cloud cost optimization platform, PRISM, to track AI costs internally and to help customers do the same.

The first step toward tracking AI costs is visibility, he says. IT leaders should know every model running across their organizations, the cost per user per month, and what kinds of prompts each user is writing, he explains, adding that Presidio is using real telemetry to track internal AI use, as well as internal tools to direct prompts to cost-efficient AI models.

The second, more difficult, step is turning visibility into action, he adds. “You have to think about mapping the usage back to the owners, whether it’s users or groups,” he says. “Then you look at, what are some of the anomalies? And if you’re looking at those anomalies, do you have governance in place around overspend?”

What Presidio has found is that the bill for AI services represents only about 30% of the total cost, Cagnazzi notes.

“The other costs really lie in areas around the hidden AI stack,” he says. “Those things around orchestration or retrieval, observability of the guardrails, or the rereads and the redos. There’s a lot of cost that people are missing.”

While traditional IT costs can be fairly predictable, AI costs are driven by usage and can increase because employees are repeatedly using inefficient prompts, Cagnazzi says.

“The spend is hard to forecast; it’s hard to see the true hidden costs behind the bill,” he adds. “If that prompt is less efficient, it might produce a bill that’s 100% higher than what it should be.”

The good news, says Domo’s Schein, is that IT leaders have a lot of variables to play with to control AI spending. They can encourage users to use more cost-efficient AI models, they can track employee usage of AI, and they can test different prompts and other interactions for cost effectiveness, he says.

“The price spread on the different models is crazy,” he says. “You could say, ‘I have no ROI on this investment; if I could get the same outcome with a model that costs one-30th as much, I may have ROI.’”

  • ✇Security | CIO
  • Salesforce, Anthropic partner to deliver Claudeforce
    Salesforce and Anthropic today announced they have expanded their strategic partnership to deliver Claudeforce, enabling customers of both companies to leverage Salesforce data, workflows, business logic, actions, and governance within Claude. “What we’re seeing is that when people stop using Salesforce through the traditional human interface and start using it through an agentic interface, it dramatically increases the value of Salesforce,” Patrick Stokes, president of
     

Salesforce, Anthropic partner to deliver Claudeforce

26 de Agosto de 2026, 17:23

Salesforce and Anthropic today announced they have expanded their strategic partnership to deliver Claudeforce, enabling customers of both companies to leverage Salesforce data, workflows, business logic, actions, and governance within Claude.

“What we’re seeing is that when people stop using Salesforce through the traditional human interface and start using it through an agentic interface, it dramatically increases the value of Salesforce,” Patrick Stokes, president of Applications & Marketing at Salesforce, told CIO.com on Wednesday. “They’re using Salesforce more than they ever have before.”

Stokes explained that momentum around the Claudeforce partnership began building after Salesforce’s TDX 2026 developer conference earlier this year. At the conference, Salesforce announced Headless 360, a platform that packaged Salesforce’s AI and developer tools into a headless, API-driven layer designed to help enterprise teams build agent-first workflows. It allowed AI clients like Claude or ChatGPT to read, write, and reason over Salesforce data without the traditional browser-based UI.

“It was a very popular decision among developers,” Stokes said. “Salesforce was actively endorsing people using Salesforce through an agentic interface rather than through the UI that we have had in place for 27 years.”

Developers immediately started hooking MCP servers up to their own agents. And Salesforce watched them struggle to scale their efforts.

“How do you do it for 100 or 1,000 users?” Stokes asked. “How do you deal with managed authentication to make sure it’s using the permissions of the user inside Salesforce? All the things that are necessary in order to scale this out weren’t really in place.”

Anthropic, the company behind Claude, was seeing the same thing. Its sales teams were using Salesforce through Claude and struggling to scale it. The two companies worked together to create a solution and decided to productize the result as Claudeforce.

Prebuilt sales skills and token consumption

The first fruit of the Claudeforce partnership is Salesforce in Claude, a plugin with 37 prebuilt sales skills. Stokes said these skills will enable sellers and agents to reason over live revenue context, automate pipeline updates, and take governed action within Claude. Claude-powered agents can access Salesforce data, workflows, and rules directly.

“We’ve been using it internally and so has Anthropic and some pilot customers for some time,” Stokes said. “It’s really highlighting what we think is a new way to work where the user is way faster than they’ve ever been before.”

According to Stokes, Salesforce users are leveraging Claudeforce to vibe code their own CRM interfaces, creating purpose-built command centers for how they want to run their teams. They’ve also been using it for forecasting.

“You just ask the question, and it’s going to go out and analyze the data and use its intelligence to try to tell you what to do,” he said.

He did note that customers will have to evaluate their own appetite for token consumption when it comes to leveraging Claudeforce.

“We’re starting to see early signs of what the token use looks like,” he said. “The token consumption is certainly not zero, but it is nowhere close to approaching the amount of consumption that you would find in a development use case.”

As part of the Claudeforce partnership, Salesforce is embedding Claude directly into Slack. Claude will be the default model for Slack, powering Slackbot, augmenting team decision-making via Claude Tag, and accelerating multiplayer coding through Slack Code.

The partners plan to introduce more integrations across Claude, Salesforce, and Slack over time. The Salesforce in Claude elements of Claudeforce are available to some pilot customers now and the partners said they expect to launch an open beta in September. They will launch additional prebuilt skills starting in the third quarter.

WhatsApp Just Added 3 New Ways to Protect Your Account

26 de Agosto de 2026, 10:44

WhatsApp is adding stronger two-step verification, multiple passkeys and more context for unknown callers as it expands protections against scams.

The post WhatsApp Just Added 3 New Ways to Protect Your Account appeared first on TechRepublic.

  • ✇Security | CIO
  • The clock is now a control surface: AI’s impact on time synchronization in OT
    A factory can forgive a late email. It won’t forgive a robot arm that arrives three milliseconds after the conveyor. That sounds absurdly small. Three milliseconds barely qualify as waiting. Yet inside operational technology, tiny gaps can carry heavy consequences. A protection relay trips late. A vision system pairs an image with the wrong product. Two controllers record the same event in opposite order. The machines keep moving, but the story they tell about what happ
     

The clock is now a control surface: AI’s impact on time synchronization in OT

26 de Agosto de 2026, 09:00

A factory can forgive a late email. It won’t forgive a robot arm that arrives three milliseconds after the conveyor.

That sounds absurdly small. Three milliseconds barely qualify as waiting. Yet inside operational technology, tiny gaps can carry heavy consequences. A protection relay trips late. A vision system pairs an image with the wrong product. Two controllers record the same event in opposite order. The machines keep moving, but the story they tell about what happened begins to split.

I learned long ago that clocks in OT aren’t office furniture. They’re part of the control system.

Now AI is moving into that system, watching clock drift, network delay, oscillator health and odd timing patterns. The promise sounds attractive. Spot trouble earlier. Explain it faster. Correct it before operations feel the pain.

Then comes the awkward question.

What happens when a system built on probability begins advising infrastructure that depends on certainty?

Time is a control input

In IT, poor timekeeping often creates irritation. Logs don’t match. Certificates complain. Investigators lose an afternoon and develop strong views about whoever configured NTP.

In OT, the consequences can leave the screen.

Industrial devices need a common sense of time because they act together. Controllers, sensors, relays, drives and switches may sit in different cabinets, yet they must agree on when an event occurred and when the next action should begin. IEEE 1588 Precision Time Protocol exists for this reason. It gives networked measurement and control systems a shared clock with far greater precision than ordinary business systems usually need.

Power automation makes the point with little room for poetry. IEC/IEEE 61850-9-3 defines a PTP profile for power utility systems that must meet demanding synchronization classes.

That shared clock supports more than speed. It preserves sequence.

Suppose a pump fails, an alarm fires and an operator changes a setting. If three devices disagree on time, investigators may see the response before the warning and the warning before the fault. Every log can be accurate on its own while the combined record remains false.

That’s the quiet danger. Bad time can turn good evidence into fiction.

What AI can see

Traditional timing systems distribute time and measure variance. They follow rules. They don’t always explain why a clock has started to wander or why packet delay changed after lunch.

AI can watch the behaviour around the clock.

Oscillators drift as temperature changes, components age and workloads shift. Networks add delay through congestion, routing changes and uneven paths. Those effects don’t always arrive as clean threshold breaches. They creep. A model trained on normal device behaviour may spot the curve before an operator sees the cliff.

Research has already explored clock architectures that account for thermal change and non-stationary delay variation in industrial networks. Other work has used deep learning to improve clock synchronization where propagation delays and frequency offsets make classic methods struggle.

The practical use is simple. AI can estimate when a device is moving outside tolerance, compare its behaviour with peer devices and suggest the likely cause.

It may notice that a clock loses accuracy only when a cabinet warms. It may connect rising offset with a new network path. It may flag a grandmaster change that looks valid in protocol terms but strange in context.

This matters because most alarms report symptoms. Operators need causes.

“The clock is wrong” starts a search.

“The clock began drifting after the switch update, and the pattern matches path asymmetry” starts a decision.

That’s a better use of machine learning. Not an oracle. A sharper witness.

From fixed rules to context

Many timing controls treat every device according to a fixed schedule. Synchronize at this interval. Alert at that threshold. Escalate after so many failures.

Fixed rules are useful because people can understand them. They also assume the system behaves tomorrow as it did when the rule was written.

Factories rarely honour that assumption.

A robotic cell under full load behaves differently from one at rest. A substation during a fault does not resemble a quiet Tuesday morning. A clock that stays stable for months may need less attention than one mounted beside a heat source and fed through a changing network path.

AI can help vary monitoring based on context. It can recommend closer checks for unstable assets and reduce needless traffic around devices that remain steady. It can compare clock offset, packet delay, temperature and process state without forcing each signal into a separate queue.

But the word “recommend” carries weight.

Changing a monitoring interval is one thing. Correcting the clock that governs a protection function is another. The first may save bandwidth. The second may change how physical equipment behaves.

You need a boundary between insight and authority.

Without it, a useful model becomes a hidden controller.

The security problem hiding in the timestamp

Attackers don’t need to stop a process if they can make the process misunderstand time.

A forged signal can shift timestamps. A delay attack can make a legitimate clock appear accurate while pushing dependent devices away from the true reference. GPS spoofing can corrupt systems that trust satellite time. Research on time attacks in power grids has shown effects on fault detection, voltage monitoring and event location. Work on PTP delay attacks has also shown how targeted path asymmetry can move clocks without easy detection.

AI may help detect these patterns. It can compare timing behaviour across paths, devices and physical states. A sudden offset may look different from thermal drift. A slow malicious delay may leave a different trail from congestion.

Yet AI also adds targets.

An attacker may poison the data used to train the model. They may alter timing telemetry, suppress alerts or feed the system enough false anomalies that operators stop listening. They may tamper with a model update and teach the detector that hostile behaviour is normal.

That last risk deserves attention. OT teams often fear the loud attack. The subtler attack edits the baseline.

Once the model learns the lie, silence looks healthy.

When probability meets determinism

This is where enthusiasm needs adult supervision.

A timing protocol performs a defined function. A model estimates. Those are different forms of machinery.

If the model predicts drift incorrectly, it may request needless corrections, mask a real fault or make stable clocks chase one another. If operators can’t explain why it acted, they may hesitate at the exact moment speed matters.

The answer isn’t to ban AI from timing. That would confuse caution with wisdom. The answer is to place it where uncertainty can help without governing the final truth.

Keep approved time sources, PTP, NTP, local clocks, holdover capability and redundant grandmasters at the core. Let AI sit around that core and observe. It can score health, spot anomalies, connect signals and propose action.

Then bind it.

Set hard tolerances that the model cannot rewrite. Require human approval before material timing changes. Record every recommendation and the evidence behind it. Make sure the model’s loss does not stop the plant from keeping time.

NIST’s OT security guidance stresses that controls must respect OT’s distinct performance, safety and availability needs. Its work on positioning, navigation and timing also calls for organizations to identify dependencies, detect manipulation and prepare to respond when timing services fail.

The principle is plain. The clock must keep working when the clever layer goes missing.

A sensible route into production

Start with the timing estate, not the model.

Map every grandmaster, reference source, protocol, dependent asset and fallback path. Ask which processes need milliseconds, which need microseconds and which merely need logs that agree. Many firms can name their critical servers faster than they can name the clock those servers trust.

That inventory often exposes an uncomfortable fact. The plant has several sources of time, but no owner for timing risk. Everyone consumes the clock. Nobody governs the dependency. That is how a technical detail becomes an enterprise blind spot.

Then choose a narrow use case.

Drift detection is a good opening move. So is anomaly detection across redundant time paths. Incident correlation can also create value without touching live clock control.

Run the model in observation mode. Let it watch, report and explain. Compare its calls with engineering judgement. Test it during temperature shifts, network congestion, GNSS loss, grandmaster failure and planned maintenance.

Don’t test only the model. Test the disagreement.

What happens when the protocol says healthy and the model says danger? Who decides? What evidence do they see? How quickly can they restore the known state?

Scale only after those questions have real answers.

The clock should never need faith

AI can make OT timing easier to see. It can reveal drift before thresholds break, connect weak signals and help investigators rebuild events with less guesswork. Used with care, it may give operators something they rarely receive from industrial clocks: an explanation.

But explanation must not become sovereignty.

The safest design keeps time deterministic and makes oversight richer. Protocols distribute the clock. Engineers define the limits. AI watches the edges, where heat, delay, ageing and attack begin to bend the truth.

That arrangement may sound less dramatic than handing the system control. Good. OT has enough drama already.

A clock is trusted because everyone agrees to organize action around it. Once machines lose that agreement, the plant may still look busy. Motors turn. Screens glow. Logs fill.

Yet beneath the motion, cause and effect have started to divorce.

AI may help keep them together.

It should never be allowed to officiate the clock.

  • ✇Security | CIO
  • Snowflake adds dynamic model routing to Cortex AI Gateway to cut enterprise AI costs
    Snowflake on Tuesday unveiled a dynamic model routing capability for its Cortex AI Gateway, designed to help enterprises reduce AI spending by automatically directing workloads to the most appropriate model based on cost, performance, and latency requirements. The new capability, which is expected to be in private preview soon, will allow enterprises to define which models they approve for use and the tradeoffs they want the system to prioritize, such as cost, performan
     

Snowflake adds dynamic model routing to Cortex AI Gateway to cut enterprise AI costs

18 de Agosto de 2026, 10:00

Snowflake on Tuesday unveiled a dynamic model routing capability for its Cortex AI Gateway, designed to help enterprises reduce AI spending by automatically directing workloads to the most appropriate model based on cost, performance, and latency requirements.

The new capability, which is expected to be in private preview soon, will allow enterprises to define which models they approve for use and the tradeoffs they want the system to prioritize, such as cost, performance, and latency, for an individual application or workload, CEO Sridhar Ramaswamy wrote in a blog post.

Once those policies are defined, Cortex AI Gateway then evaluates each task against those policies and real-world model performance and cost data to determine which model should handle the workload in the most efficient manner, Ramaswamy added.

Further, the CEO pointed out that Cortex AI Gateway also creates a feedback loop by evaluating the quality of a model’s output after it completes a task, which allows the routing system to adjust its decisions as model capabilities, pricing, and performance change, with the aim of continuously optimizing the balance between quality, cost, and latency.

According to Snowflake’s internal benchmarks, the new capability can improve token efficiency compared with using a frontier model for every task.

In one internal test, agents using dynamic routing built a dbt pipeline with up to three times greater token efficiency than a frontier-model-only approach while maintaining the same quality, the company said in a statement. In another test, engineering teams completed the same number of pull requests with 25% greater token efficiency, it added.

Routing could lower AI costs, but adds governance complexity

The new capability will have the largest impact on high-volume, low-complexity workloads where many requests do not require frontier-model reasoning, like classification, extraction, summarization, routine data engineering, and repetitive agent steps, said Stephanie Walter, practice lead of AI stack at HyperFRAME Research. “Routing those requests to smaller models could materially reduce inference costs while preserving expensive models for genuinely difficult tasks,” said Stephanie Walter, practice lead of AI stack at HyperFRAME Research.

Agentic applications could specifically benefit from dynamic model routing, said Advait Patel, senior site reliability engineer (SRE) at Broadcom.

“An agent loop spends most of its steps on plumbing, reading a file, parsing a result, and picking the next call. Very few of those need deep reasoning, but they all hit the same model today. When I pulled telemetry on our own coding agent usage, the spend wasn’t in the hard problems at all. It was the volume of ordinary calls,” Patel said.

However, Walter cautioned that enterprises should not treat token efficiency as the same as cost savings, especially in agentic applications, despite Snowflake’s “promising” internal benchmarks.

“Enterprises must also measure retries, failed tasks, latency, human correction, and the cost of operating the routing layer,” Walter noted.

More so because routing, despite removing the repetitive model-selection work from individual applications, shifts operational complexity into the orchestration and governance layer and doesn’t eliminate it completely, according to Phil Fersht, CEO of HFS Research.

“Enterprises would still need to determine which models are approved, establish routing policies, monitor quality, control costs, and manage security and compliance,” Fersht said, adding that if policies are not defined well, the system can make a poor decision, which at scale, could either produce inconsistent outcomes or unnecessary costs.

That shift of operational complexity into the governance layer, according to Manoj Chandra Jha, principal analyst at Nord-IQ Research, could be challenging for most enterprises: “Short-term complexity can rise, since most teams lack the governance and monitoring maturity routing now requires.”

Routing also adds a new variable for developers to track

The governance burden also has implications for developers, who will have to account for routing decisions as another variable when building and troubleshooting applications.

“Dynamic routing makes visibility essential. If different requests go to different models, developers need to know which model handled a request, why it was selected, and whether the result met expected quality and performance levels,” said Robert Kramer, managing partner at KramerERP.

“When something breaks, they need to determine quickly whether the fault came from the application, the model, or the routing decision. That third failure mode is new, and it is the one teams are least equipped to diagnose today,” Kramer added.

Snowflake, however, is looking to address concerns around changes in routing decisions driven by model pricing changes.

It would integrate Cortex AI Gateway with its AI coding assistant CoCo’s existing role-based access and tagging framework, which will allow enterprise administrators to set default models, attribute AI usage to teams or cost centers, establish per-user quotas, and receive alerts as consumption approaches predefined limits.

These controls could help enterprises maintain visibility into how routing decisions affect AI spending as models, pricing, and workloads change, the company said.

Model routing becomes a new battleground in the AI stack

That enterprise focus on controlling AI spending via model selection and routing hasn’t escaped the attention of other vendors.

Nvidia has been expanding its efforts around model routing, while Cloudflare and OpenRouter have also emerged as players in the space, reflecting growing interest in helping enterprises route workloads across multiple models based on factors such as cost, performance, and capability.

The shift, according to Fersht, is partly a consequence of the growing number of models available to enterprises and the differences between them in cost, performance, latency, and capabilities.

That shifts the strategic value towards the layer that decides which model to use and orchestrates it across enterprise workflows, Fersht noted.

However, Patel cautioned that enterprises should evaluate model routers based on the level of control and transparency they provide.

  • ✇Security | CIO
  • Using functional AI to automate document workflows
    A recent study conducted by Nitro found that 75-95% of the employees and executives surveyed use AI for document processing—including data extraction, PDF tasks, and contract summaries. However, when these individuals don’t have access to the right kind of AI tools, they report turning to unapproved—or shadow IT—solutions to speed up workflows, which creates security and compliance risk. Read the report To reinforce the importance of providing teams with the right A
     

Using functional AI to automate document workflows

13 de Agosto de 2026, 17:28

A recent study conducted by Nitro found that 75-95% of the employees and executives surveyed use AI for document processing—including data extraction, PDF tasks, and contract summaries.

However, when these individuals don’t have access to the right kind of AI tools, they report turning to unapproved—or shadow IT—solutions to speed up workflows, which creates security and compliance risk.

Read the report

To reinforce the importance of providing teams with the right AI tool for the right job, let’s look at the difference between chatbots and functional AI in terms of automating document workflows.

Chatbots are great for ad hoc tasks that follow a pre-programmed set of actions, but they aren’t designed to enforce consistent rules for formatting, redaction, or compliance, or to extract data hidden deep in document tables, images, or free text.

Unlike chatbots, functional AI can physically execute redaction, conversion, and data extraction tasks directly within business processes and systems, rather than simply responding to prompts.

This guide explains why scaling document workflows requires both conversational AI to answer common questions and functional AI to perform repeatable tasks on a high volume of documents with consistency, control, and predictable cost.

Chatbots vs. functional AI: What’s the difference?

Chatbot AI and functional AI play distinct roles in document workflows: AI-assisted chatbots answer questions and help users understand documents through conversation. Functional AI performs tasks directly on documents, such as redaction, data extraction, and file conversion.

What chatbots and functional AI do best:

Chatbots:

  • Respond to prompts and questions
  • Help summarize or generate content
  • Improve individual productivity

Functional AI:

  • Execute document tasks automatically
  • Process files at scale
  • Integrate into workflows and systems

Benefits of using functional AI to automate document workflows at scale

Using Functional AI to Automate Document Workflows - image 2

Nitro

Functional AI tools autonomously execute editing, redaction, conversion, and data extraction tasks within workflows, not just through user prompts. This intelligent automation provides several benefits for teams that process a high volume of documents:

Improve redaction and compliance

AI can identify and remove sensitive information across large document sets, applying consistent rules without relying on manual review.

Simplify conversion and document handling

Users can reduce friction and save time using the same tool to convert files, edit PDFs, and standardize formats within a single workflow.

Extract structured and unstructured data

Functional AI can pull key data from contracts, forms, tables, handwritten notes, and PDFs, turning static documents into usable information.

Reduce tool sprawl and shadow IT

By consolidating document tasks into a single platform, functional AI reduces the need for multiple point solutions and unapproved tools.

Perfectly provision license utilization

Universal access to core document features allows organizations to align licenses with actual usage instead of over- or under-provisioning.

Create more predictable software costs

Replacing fragmented tools that incur usage-based overages with a functional AI solution that offers a controllable pricing structure makes costs easier to forecast and control.

How Nitro’s AI-powered tools fit into document workflows

Nitro understands the importance of giving your team the right AI tools at the right time. So, we offer both generative AI and functional AI solutions that support and simplify document workflow automation.

Nitro’s AI assistants improve how teams interact with documents

Nitro’s AI-assisted solutions, like Document Assistant and Knowledge Assistant, reduce time spent searching for information or learning how to use our solutions.

  • Document Assistant: Allows users to ask questions about a PDF, summarize content, or translate information
  • Knowledge Assistant: Provides real-time help with product features and workflows

Nitro’s functional AI tools automate document tasks at scale

Nitro’s functional AI tools reduce manual effort, improve accuracy, and allow teams to handle higher document volumes without increasing workload.

  • Nitro Smart Redact: Identifies sensitive information in documents and flags it for removal, reducing manual review time
  • Form Extract: Pulls key information from PDFs and converts it into structured data
  • Table Extract: Transforms table data into clean, usable spreadsheets
  • Form Create: Converts static documents into fillable forms
  • Field Detection: Automatically places signature and input fields for document workflows

All Nitro AI-powered solutions include enterprise-grade security and compliance that safeguards sensitive data throughout the document lifecycle. Visit the Nitro Trust Center to learn more.

Functional AI is setting the standard for document workflow automation

Using Functional AI to Automate Document Workflows - image 3

Nitro

Our research is clear: When AI provides specific, measurable benefits to your document workflows, the results are high adoption, time savings, and measurable ROI.

If you want to transform and automate your document workflows, Nitro’s functional AI solutions are a top choice for high-volume document processing, consistent, rules-based automation, and reduced reliance on manual work.

Discover Nitro’s AI workflow tools.

  • ✇Security | CIO
  • Manual vs. AI-powered PDF redaction: protecting sensitive data in 2026
    Research shows that humans play a role in 60% of breaches that expose sensitive data. That “role” often involves an employee falling for a phishing scam or using PASSWORD for their login credentials, but data exposure can also be a result of how your business redacts sensitive and personally identifiable information (PII) in your documents.   Historically, manual, “black-box” redaction was considered best-practice, but this approach only obscures data, it doesn’t permanent
     

Manual vs. AI-powered PDF redaction: protecting sensitive data in 2026

13 de Agosto de 2026, 17:27

Research shows that humans play a role in 60% of breaches that expose sensitive data. That “role” often involves an employee falling for a phishing scam or using PASSWORD for their login credentials, but data exposure can also be a result of how your business redacts sensitive and personally identifiable information (PII) in your documents.  

Historically, manual, “black-box” redaction was considered best-practice, but this approach only obscures data, it doesn’t permanently remove it. 

As regulations governing data security get stricter and AI-powered redaction solutions become more accessible, organizations—especially those in highly regulated industries—are re-evaluating their PDF redaction solutions.

How manual PDF redaction is different from AI-powered PDF redaction

The primary difference between manual and AI-powered PDF redaction is who (or what) you rely on to do the heavy lifting.

Manual redaction defined

Manual redaction is a human-driven process where individuals visually scan text, select content, and apply black boxes or remove the text before sharing or storing the file.

Manual redaction is only as effective as the reviewer, which makes outcomes highly variable, especially under time pressure or high document volume.

AI-powered redaction defined

AI-powered redaction uses machine learning and natural language processing (NLP) to automatically detect and remove sensitive information from documents. The system is trained to recognize patterns, language cues, and contextual signals in PDFs as well as scanned images, handwritten notes, text-heavy documents, metadata, and embedded scripts.

For example, Nitro Smart Redact can identify structured data, like Social Security numbers and bank accounts in a payroll document, as well as unstructured, free-form data, like “in April 2022, Sarah was diagnosed with cardiovascular disease.”

How to choose the right redaction solution for your organization

Manual vs. AI-Powered PDF Redaction - image 2

Nitro

Manual redaction may work for small organizations that handle a low volume of documents. But for most businesses, an AI-powered PDF redaction solution that will scale as your needs change is a smart investment.

Here are six factors to consider when evaluating AI-powered redaction solutions:

Document volume and size: Look for a solution that can handle your current document load and scale to meet future demand without slowing down processing times or requiring additional manual effort.

Data type: YourPDF redaction tool must be able to accurately identify a wide range of sensitive information—from PII to financial data.

Data location: The solution should detect sensitive data in visible and hidden layers, like metadata, embedded text, annotations, comments, form fields, and image-based content.

Compliance requirements: Choose a solution that supports compliance with your industry’s regulatory obligations, such as GDPR, HIPAA, or other data protection standards.

Integration with existing systems: Pick a PDF redaction tool that integrates with your existing document management systems, cloud storage, and workflows to maintain productivity and reduce the need for additional tools.

Data security and AI training policies: Verify how the redaction solution handles your data. Look for clear policies that protect sensitive information, prevent data reuse, and keep your content private and secure.

Why Nitro is a top choice for AI-powered PDF redaction

Manual vs. AI-Powered PDF Redaction - image 3

Nitro

Nitro Smart Redact is an AI-powered PDF redaction solution that balances speed and accuracy with control and security, allowing teams to redact sensitive information quickly while maintaining full oversight and compliance.

  • Detects over 30 categories of regulated PII in seconds
  • Uses advanced NLP to identify unstructured PII that manual or pattern-based methods miss
  • Finds and redacts PII in scanned documents, image files, and handwritten notes
  • Gives users the ability to manually add, adjust, or remove redactions
  • Integrates with existing tools, including Microsoft 365, Salesforce, and cloud storage
  • Processes documents in secure, temporary sessions 
  • Permanently removes hidden data, including metadata and embedded scripts
  • Never uses your documents to train or improve external AI models

The best solution? AI-powered PDF redaction, but keep people in the loop

The most effective way to identify and permanently remove sensitive data from PDFs is a solution that uses AI to quickly find information hidden deep in documents and humans to manually review and adjust results for accuracy. 

Speak with a Nitro team member to learn how Nitro’s AI-driven Smart Redact technology provides a faster, safer way to prepare documents for secure sharing.

  • ✇Security | CIO
  • Professional PDF solutions for teams: scale without breaking your budget
    Why do so many PDF editing and eSignature tools fail to scale across teams? Three persistent problems stand out: Unpredictable pricing that becomes more expensive as usage increases Limited access to advanced PDF features Difficulty automating document workflows across teams The good news is that even teams that process a high volume of documents can reduce their costs and get more value from their PDF solutions by selecting solutions with built-in AI, predic
     

Professional PDF solutions for teams: scale without breaking your budget

13 de Agosto de 2026, 17:27

Why do so many PDF editing and eSignature tools fail to scale across teams? Three persistent problems stand out:

  • Unpredictable pricing that becomes more expensive as usage increases
  • Limited access to advanced PDF features
  • Difficulty automating document workflows across teams

The good news is that even teams that process a high volume of documents can reduce their costs and get more value from their PDF solutions by selecting solutions with built-in AI, predictable pricing, flexible licensing, and scalable, automated document workflows.

In this article, we’ll cover:

  • Why you’re paying too much for too few features
  • How AI makes PDF editing, eSigning, and redaction tools accessible to everyone on your team
  • What to look for in a scalable, cost-efficient PDF solution

Why many incumbent PDF tools are expensive and inefficient at scale

Many PDF tools were designed for individuals or small teams rather than scaling teams. As organizations expand usage, these tools become harder to manage, more expensive to maintain, and less effective at supporting high-volume document workflows.

Here are three ways PDF tools can impact your budget and your team’s productivity:

Unpredictable pricing increases total cost of ownership

If your PDF solutions rely on per-user licensing, feature-based tiers, or usage caps that trigger additional fees, as demand for the tool increases, your costs become harder to forecast and control.

Limited access to features reduces productivity

When full PDF editing functionality is restricted to a small group of licensed users, other team members start looking for (often unsanctioned) workarounds or waste time waiting to complete basic tasks like editing, converting, or compressing documents.

Rigid licensing leads to over- and under-provisioning

Legacy licensing models rarely align with how teams actually work. As a result, organizations often over-purchase licenses to avoid bottlenecks or under-provision and create access constraints.

How AI makes PDF tools more scalable (and more affordable)

Professional PDF Solutions for Teams - image 2

Nitro

AI-powered PDF tools improve scalability by automating repetitive tasks, simplifying complex workflows, and making advanced features accessible to all users.

Automated document workflows reduce manual effort

These tools automate tasks like table and data extraction, form processing, and file conversion, allowing teams to process higher document volumes without increasing headcount.

Natural language document interaction removes complexity

Natural language processing (NLP) lets business users edit, summarize, or extract information from PDFs using simple prompts. This eliminates the need for specialized expertise and reduces reliance on a small group of advanced users.

Intelligent data recognition and redaction improves efficiency and security

Advanced AI tools can identify, extract, and redact sensitive information from structured and unstructured data sources. This speeds up document review and compliance workflows while reducing the risk of human error.

How Nitro’s PDF solutions reduce cost and increase scalability with AI

Nitro’s AI-powered PDF solutions are designed to solve the cost and scalability challenges tools like Adobe Acrobat create.

Key benefits of Nitro’s AI-driven PDF solutions

  • Predictable pricing models: WithNitro’s flexible pricing plans there are no overerages, no forced bundles, and no per-seat penalties.
  • Flexible licensing: Nitro’s licensing models are designed to match how people actually use PDF tools, so it’s easier to give everyone the access they need without paying for unused capacity.
  • Built-in AI: Every Nitro plan includes AI tools, so your whole team gets AI-powered document capabilities without increasing cost or training requirements.
  • Administrative control: The Nitro Admin Portal lets IT provision users, reassign licenses, and manage feature and AI access by department in real time, so entitlements move as fast as the business does.
  • Expert support: Whether you’re a five-person team or a global enterprise, our dedicated support specialists are available 24/7—from deployment planning to daily troubleshooting.
  • Enterprise-grade security and compliance: Built-in protections such as encryption, access controls, and audit trails help safeguard sensitive data throughout the document lifecycle. Visit the Nitro Trust Center to learn more.
  • Proven customer satisfaction: Nitro has a 95%+ customer satisfaction rate and was selected as a TechRadar #1 PDF Editor for Businesses. 

Professional PDF tools don’t have to blow your budget

Professional PDF Solutions for Teams - image 3

Nitro

You don’t have to choose between affordable PDF tools and scalability. Nitro’s AI-powered PDF tools give you cost control and the features you need. Replacing your legacy PDF tools with Nitro solutions that are designed for high-volume document workflows, your team can reduce costs, improve productivity, and expand access to essential tools without adding complexity.

Let the Nitro team show you why 67% of the Fortune 500 trust our AI-powered PDF editing, eSign, and redaction solutions. See plans and pricing or get in touch with sales today.

  • ✇Security | CIO
  • Docusign alternatives for teams: what to look for (and what to avoid)
    Choose Nitro Sign for predictable pricing & fewer surprises Free Trial Docusign may be the most widely used eSignature platform, but many teams run into the same issue as they scale—the more documents they send, the harder it is to predict what they’ll actually pay. The risk of high overage costs paired with complex pricing structure is driving teams to look for an alternative to Docusign in 2026. This buyer’s guide bre
     

Docusign alternatives for teams: what to look for (and what to avoid)

13 de Agosto de 2026, 17:26

Choose Nitro Sign for predictable pricing & fewer surprises

Docusign may be the most widely used eSignature platform, but many teams run into the same issue as they scale—the more documents they send, the harder it is to predict what they’ll actually pay. The risk of high overage costs paired with complex pricing structure is driving teams to look for an alternative to Docusign in 2026.

This buyer’s guide breaks down why those challenges matter, what to look for in an eSignature solution, and how leading Docusign alternatives—like Nitro Sign—compare for teams that send a high volume of documents but want simpler pricing and fewer surprises.

Docusign Alternatives for Teams - image 2

Nitro

Why some teams are looking for alternatives to Docusign

Three trends drive teams to look beyond Docusign:

  • Bills that increase unpredictably as usage grows
  • Difficulty understanding what features are included vs. which are paid add-ons
  • Pricing models that don’t scale well with high document volume

Here’s a more detailed look at each of these challenges.

Docusign bills become unpredictable as usage grows

Many organizations encounter unexpected costs as usage increases. Envelope limits, counting methods, and per-transaction pricing can quickly turn a straightforward Docusign subscription into an unpredictable expense.

Impacts may include:

  • Budget overruns tied directly to business growth
  • Paying for documents that are sent but never completed
  • Difficulty forecasting total cost at scale

Docusign pricing doesn’t clearly indicate which features are included

As platforms expand into broader “agreement management” offerings, pricing and packaging become harder to navigate.

Common issues include:

  • Paying for features that aren’t widely used across the business
  • Add-ons or higher tiers required for AI-enabled capabilities
  • More complex setup, onboarding, and contract evaluation

Docusign pricing models don’t scale as volume increases

For teams that process a high volume of documents, how usage is counted matters as much as price. Counting envelopes when sent, rather than when completed, accelerates usage limits and increases costs.

This often leads to:

  • Rising costs as document volume grows
  • Paying for incomplete or abandoned agreements
  • Misalignment between pricing and actual business value

What to Look for in a Docusign Alternative

When evaluating alternatives to Docusign, focus on eSignature solutions that offer these four capabilities:

Pricing that scales with your usage

Look for pricing models that:

  • Don’t penalize you for sending more documents
  • Scale efficiently as adoption increases
  • Are based on completed agreements where possible

Transparent licensing and contract terms

Choose platforms where:

  • Pricing is easy to understand upfront
  • Key features—such as SSO, support, and analytics—are included
  • Renewal terms are clear and unambiguous

The right level of functionality (not just the most features)

Your eSignature platform should match how your team actually works—whether that’s simple document signing or more complex workflows.

Security and compliance you can trust

Any alternative must meet eSignature security standards, including:

  • Secure document handling and encryption
  • Audit trails for tracking activity
  • Compliance with relevant regulations and standards
Docusign Alternatives for Teams - image 3

Nitro

Docusign alternatives for teams in 2026

SolutionOverviewStrengthsPricing Considerations
Nitro SigneSignature platform focused on simplicity and cost controlPredictable pricing, counts only completed agreements, key features like SSO and support included as standardTransparent cost structures without overage surprises
Adobe Acrobat SignPart of the Adobe ecosystemStrong feature setCan inherit similar complexity and cost challenges as other Adobe products
Dropbox SignStraightforward eSignature solutionSimple setup and user-friendly interfaceBest suited for smaller teams, but may lack scalability for high-volume use
PandaDocCombines eSignature with document creation and sales workflowsStrong for sales-driven organizationsPricing can increase as features and usage expand
Foxit eSigneSignature solution within the Foxit ecosystemLightweight, flexible deploymentMay require evaluation for enterprise-scale needs

 How to choose the right Docusign alternative for your organization

Here are five specific factors to consider when evaluating alternatives to Docusign:

  • How does the platform charge for usage?
  • How predictable are costs as your volume grows?
  • Are essential features included, or sold separately?
  • Does the platform match how your team actually uses eSignature today?
  • How easy is it to scale across teams without increasing complexity?

Nitro Sign offers a full suite of eSigning features at a lower price than Docusign, plus:

  • Only completed agreements count
  • Twice as many envelopes allowed per user
  • SSO, support, and analytics are included without add-on fees
  • Pricing is designed for high volumes and predictable costs
  • No penalties for exceeding usage limits
Docusign Alternatives for Teams - image 4

Nitro

Curious why teams that want to control costs without sacrificing features or security choose Nitro Sign a top alternative to Docusign?

Speak with one of our eSignature experts or sign up for a free trial of Nitro Sign.

  • ✇Security | CIO
  • Nitro Smart Redact: the complete guide to automated AI redaction
    Get Smart Redact and Protect Sensitive Data Learn more Too many businesses in highly regulated industries—such as healthcare, government, legal services, and insurance—still rely on manual, “black-box” redaction workflows. This approach may obscure sensitive information, but it doesn’t permanently remove it, which can lead to compliance violations, potential litigation, or regulatory fines. Nitro Smart Redact is an AI-po
     

Nitro Smart Redact: the complete guide to automated AI redaction

13 de Agosto de 2026, 17:24

Get Smart Redact and Protect Sensitive Data

Too many businesses in highly regulated industries—such as healthcare, government, legal services, and insurance—still rely on manual, “black-box” redaction workflows.

This approach may obscure sensitive information, but it doesn’t permanently remove it, which can lead to compliance violations, potential litigation, or regulatory fines.

Nitro Smart Redact is an AI-powered solution that removes sensitive data from documents with permanent, untraceable redactions. It combines automated PII detection to surface regulated data along with manual controls for sensitive business information, allowing teams to flag content, automatically redact documents, and manually customize reviews that need human oversight.

In this guide we explore how Smart Redact:

  • Simplifies permanent, irreversible redaction
  • Identifies sensitive structured and unstructured data
  • Provides enterprise-grade security
  • Reduces turnaround times with automation
  • Minimizes human error

How is Smart Redact different from other automated AI redaction solutions?

Pattern-based matching tools, like those used in Adobe Acrobat, use predefined formats and keyword matching to locate sensitive data. This approach often misses information in free-form text, like “John lives on Main Street” or “her social ends in 5678.” Smart Redact catches it because it understands context.

AI-only platforms—like Redactable—offer automation, but they require teams to maintain a separate redaction tool. That means two subscriptions, two interfaces, and double the work.

Nitro Smart Redact does things differently, with built-in features that support the full document lifecycle all in one place:

  • Instantly detects over 30 categories of regulated Personally Identifiable Information (PII)
  • Uses advanced natural language processing (NLP) to detect unstructured PII that manual or basic pattern searches miss
  • Automatically finds and redacts sensitive PII from scanned documents, image files, and handwriting
  • Groups suggested redaction by category and quality-tests them for precision
  • Provides total visibility and complete control to instantly add, adjust, or remove redactions
  • Integrates with the tools your team already uses, including Microsoft 365, Salesforce, and cloud storage
  • Manages AI documents in a temporary session with no storage or data retention
  • Removes visible and hidden data, like metadata and scripts
Nitro Smart Redact: The Complete Guide to Automated AI Redaction - image 1

Nitro

Does Smart Redact provide enterprise-grade security and compliance?

Absolutely. Smart Redact has security built into every layer to support companies operating under strict regulatory oversight:

  • Processes documents in temporary sessions
  • Encrypts files in transit and at rest
  • Deletes document data after processing
  • Never uses content for generative AI training
  • Identifies and removes hidden metadata, annotations, and scripts
  • Adheres to international security standards: ISO 27001, SOC 2, HIPAA, and the EU-U.S. Data Privacy Framework

Visit the Trust Center to learn more about Nitro’s commitment to responsible AI development and data privacy.

Why is Smart Redact the best automated AI redaction solution for regulated industries?

Nitro Smart Redact is built on the same trusted Nitro infrastructure that powers the document workflows of over 67% of Fortune 500 firms.

Legal

Legal teams use Smart Redact to maintain privilege, meet discovery deadlines, and reduce manual review time by:

  • Using NLP to find PII buried in extensive legal documents
  • Automatically identifying sensitive data, even in scanned documents or images
  • Validating redactions with confidence scoring
  • Supporting manual edits when required

Government

Public sector organizations rely on Smart Redact to balance information transparency with data protection by:

  • Automating detection of over 30 PII categories
  • Using NLP to understand context, not just patterns
  • Grouping results by category and confidence level to quickly isolate high-risk items
  • Providing manual override tools and real-time previews

Healthcare

Smart Redact helps healthcare professionals protect patient privacy without disrupting care by:

  • Automating de-identification of direct identifiers like names, addresses, and dates of birth
  • Permanently and irreversibly redacting Safe Harbor elements, such as full dates of treatment and precise geography
  • Integrating OCR to redact structured and unstructured content, including handwritten notes and image files

Insurance

Smart Redact helps insurance teams act quickly while maintaining visibility and control of sensitive data by:

  • Automatically identifying and redacting account numbers, birthdates, and contact information
  • Centralizing litigation preparation, internal reviews, and regulatory reporting
  • Accelerating processing time and reducing risk

AI-powered redaction is changing how we handle sensitive information

Nitro Smart Redact: The Complete Guide to Automated AI Redaction - image 2

Nitro

From legal confidentiality to sunshine laws to HIPAA compliance, Smart Redact is built for accurate, fast, and secure data redaction. By combining AI automation, NLP, OCR, and manual control, Smart Redact helps businesses in highly regulated industries avoid compliance violations, regulatory fines, or litigation.

Learn how Nitro’s AI-driven Smart Redact technology provides a faster, safer way to prepare documents for secure sharing, or contact a Nitro expert to get started.

  • ✇Security | CIO
  • Adobe Acrobat alternatives for teams in 2026
    Try Nitro PDF today Learn more If your team is re-evaluating Adobe Acrobat’s place in your 2026 tech stack, the question isn’t just what the software can do, but whether it aligns with your evolving budget and productivity goals. Including Acrobat in your stack is becoming increasingly expensive and difficult to manage due to: Frequent price increases Overlapping licenses that add overhead Underutilized features t
     

Adobe Acrobat alternatives for teams in 2026

13 de Agosto de 2026, 17:20

Try Nitro PDF today

If your team is re-evaluating Adobe Acrobat’s place in your 2026 tech stack, the question isn’t just what the software can do, but whether it aligns with your evolving budget and productivity goals.

Including Acrobat in your stack is becoming increasingly expensive and difficult to manage due to:

  • Frequent price increases
  • Overlapping licenses that add overhead
  • Underutilized features that waste resources

As a result, the conversation is shifting away from “How do we navigate rising costs, complexity, and AI compliance requirements?” to, simply, “Is there a better alternative to Adobe Acrobat?

In this guide, we break down:

  • How to stop overpaying for licenses that aren’t being used
  • How to select a PDF editing solution that does exactly what you need it to do
  • Why Nitro PDF is emerging as a leading choice for organizations focused on experience, value, and scalability for IT and procurement-led buying decisions
Adobe Acrobat Alternatives for Teams in 2026 - image 1

Nitro

Why teams are looking for Adobe Acrobat alternatives in 2026

For organizations that use Adobe Acrobat, frustrations tend to build over time—and they usually come down to the same three things:

Rising costs that keep climbing

What starts as a manageable per-seat subscription becomes harder to justify as Adobe raises prices and layers in paid add-ons. The AI tools, advanced features, and admin tools that should be standard all require extra cost or higher priced plans.

Licenses that are hard to manage

Adding or removing users, adjusting seat counts, or untangling Adobe from a broader Creative Cloud agreement is rarely straightforward. The result is overspend on unused seats and a licensing structure that doesn’t flex with the business.

Tools that take time to master

Adobe has its own unique UI, meaning new users need training. This inevitably extends onboarding and impacts productivity when teams grow or employees leave.

Adobe Acrobat alternatives for teams in 2026

SolutionOverviewStrengthsPricing Considerations
Nitro PDFComplete PDF and eSign suite with a powerful admin portal and built-in AIPredictable pricing, integrated PDF editing and eSign capabilities, AI-driven redactionReduces cost variability and eliminates overage-driven spend
Adobe Acrobat ProPopular, comprehensive PDF editing solutionDeep integration within the Adobe ecosystemTiered, per-user pricing with add-ons increases cost unpredictability
Foxit PDF EditorLightweight, flexible alternative to AcrobatFast performance, broad feature coverage for general business useAdd-ons and scaling usage can introduce cost variability
PDFelementUser-friendly, focused on accessibility and ease of useSolid core editing and annotation capabilities, good for smaller teamsMay lack enterprise-level governance, scalability, and standardization
Kofax Power PDFBusiness-focused, strong document control and automation capabilitiesAdvanced document automation, conversion tools, and security and compliance features  Implementation complexity and configuration requirements can impact total cost of ownership

Why Nitro PDF is the smart alternative to Adobe Acrobat

Adobe Acrobat Alternatives for Teams in 2026 - image 2

Nitro

Nitro PDF eliminates the high costs, confusing licensing, and forced bundling often associated with Adobe Acrobat:

Transparent pricing without overage surprises

Nitro addresses one of the biggest Acrobat pain points—cost unpredictability—with clearer, more controllable pricing structures that often save businesses up to 30% compared to Adobe.

Simplified licensing and reduced vendor sprawl

By combining PDF and eSignature capabilities with AI intelligence in every plan, Nitro makes it easy to provision users, reassign licenses, and control feature access by department with no minimum seat commitments, reducing the need for multiple vendors and minimizing license sprawl.

Intuitive interface that accelerates time to value

Nitro PDF’s user-friendly interface mirrors the Microsoft Office ribbon UI and Apple toolbar, providing an intuitive experience for both Windows and Mac users.

Strong governance/data privacy

Nitro meets internationally recognized data protection standards and certifications, including ISO 27001, SOC 2, HIPAA, and the EU–U.S. Data Privacy Framework. Visit the Nitro Trust Center to learn more.

Administrative control and expert support included

With powerful analytics, admin tools, and 24/7 expert support included in every plan, you can track ROI, turn document data into actionable insights, and manage licenses, users, and services with no separate admin console fees required.

Adobe Acrobat Alternatives for Teams in 2026 - image 3

Nitro

Proven customer satisfaction

With Nitro’s 95% customer satisfaction rate and distinction as a TechRadar #1 PDF Editor for Businesses, we’re proud to be the trusted choice for 67% of the Fortune 500.

How to choose the right Adobe Acrobat alternative for 2026 and beyond

If your team is looking for an alternative to Adobe Acrobat in 2026, Nitro PDF can help you balance PDF editing capabilities with long-term affordability and ease of growth. To discover how Nitro PDF’s straightforward licensing, simplified tech stack, and AI-powered automation can lower costs, boost workflow efficiency, and provide greater control over how documents move through your businessspeak with one of our PDF experts or sign up for a free trial of Nitro PDF.

  • ✇Security | CIO
  • 4 RPA lessons that still hold true in the AI boom
    Enterprises of all sizes in all industries are rapidly deploying generative and agentic AI to automate processes. But the efforts aren’t always panning out. Some reasons are new and unique to this technology. But others are related to issues we should’ve been prepared for because we saw them during the age of RPA. And in the rush to adopt new tech, some of these lessons are being forgotten. “This new era of agents puts the same challenges again in front of us, and we ne
     

4 RPA lessons that still hold true in the AI boom

12 de Agosto de 2026, 07:00

Enterprises of all sizes in all industries are rapidly deploying generative and agentic AI to automate processes. But the efforts aren’t always panning out.

Some reasons are new and unique to this technology. But others are related to issues we should’ve been prepared for because we saw them during the age of RPA. And in the rush to adopt new tech, some of these lessons are being forgotten.

This new era of agents puts the same challenges again in front of us, and we need to think about the things we faced back when that revolution happened years ago,” says Agustin Huerta, SVP of digital innovation and VP of technology at Globant, a digital transformation company.

Those challenges often include selecting the right processes for automation, setting up systems to manage those processes, making sure automated processes get the right inputs, and managing the wider impacts of automation, including cultural.

1. Automating the right processes

All the lessons of RPA are carrying over, says Stephanie Bova, digital transformation officer at Novo Nordisk, including the biggest one that just because you can automate something, does it mean you should.

“We think hard before we start creating something,” she says. “Who’s going to maintain it, and where is it documented?”

And of course, is the process itself a good process. “Nothing gets built on a process that hasn’t been optimized anymore,” she adds. “We haven’t done a technology deployment on an unoptimized process for two years.”

And the company is now a lot more selective about how much automation it rolls out, but that wasn’t always the case with RPA. “At one point, everyone who wanted a piece of automation could get something built for them,” she says. “That’s not the case on how we’re approaching agents.”

There has to be real business benefit to the project, she says. “If you can show me the business outcome, we’ll consider it,” she continues. “But we don’t want or need hundreds or thousands of agents deployed. We want them all standardized and monitored, controlled, and auditable.”

Something similar happened a decade ago with RPA, says Huerta, when easy-to-use automation tools became available to people.

“When they were deployed without proper governance, systems got exposed,” he says. “They started stressing the overall infrastructure of the company, and some robots weren’t created in a way for a return on investment. The process ran faster, but consumed more in the cloud, so you ended up putting all the money you saved in the process into your cloud infrastructure, and the total ROI was zero.”

2. It’s not “set and forget”

Legal services company Purpose Legal uses the same basic approach for gen AI-based automation as it did with the previous generation of automation, based on ML, human oversight, and careful validation of the automated processes.

Take for example legal discovery, where documents are produced and shared with the opposing party in a legal case.

“Inadvertent production of sensitive data is a nightmare,” says Jeff Johnson, Purpose Legal’s chief innovation officer. “We always have to evaluate the data. Especially in the legal services context, we need people in the guardrails to make sure the process is on track.”

Without that oversight, problems can escalate quickly.

“If you make a bad decision you may get chastised by the court, lose the case, or lose the client entirely,” he says. “That happened in the past if you trusted automation too much.”

The AI tools today may be more sophisticated, he says, but they’re not perfect. “Even in the world of gen AI, it’s still something we need to watch out for,” he adds.

If anything, the oversight is even more important because of the scale at which AI can work, and how authoritative it can seem.

“Attorneys are more inclined to trust automation now because it interacts with them much more like a person would,” Johnson says. “It’s actually giving attorneys summaries of documents that look like another attorney wrote it, but that doesn’t mean it’s right.”

3. Reaping what’s sown

The need for good inputs goes back to the beginning of the computing era, if not earlier. “If we aren’t proving good inputs and putting good guardrails in place about where the AI gets its input, we get bad decisions,” says Johnson.

After all, data quality is a concern for any company rolling out automation, whether RPA or gen AI.

“Agentic AI won’t solve the entire data quality issue,” says Sabrina Joos, director of program and lifecycle management for new systems for the Americas at Siemens. But there are some differences, she says, in how it plays out.

In the RPA world, data quality was mostly about structured data and stable inputs. So, for example, if the data was formatted in a way the RPA didn’t expect, it might not execute.

“With agentic AI, the data quality issue becomes much more complex,” she says. “It’s no longer just about whether the data is correct, but if it’s complete and meaningful in context.”

AI systems can accept unstructured inputs or ambiguous data and make sense of it, but it doesn’t always interpret that data correctly.

“We don’t care too much about the format or typos since that’s not as much of an issue anymore,” Joos says. “But if there are assumptions that aren’t right, the process or workflow will still be executed. And this is where you have a risk that it will scale.”

For example, an AI can mix up two projects because they sound similar, she says. “Or, working on manufacturing solutions, it might not recognize the physical constraints of a system and will try to optimize and do something that a machine can’t do.”

Or two people might have a different understanding of an issue, and there might not even be an objective truth.

“You need to know where the interpretations are going to be made because there’s not enough information,” she says. “If we can identify this, we can trigger clarification questions. If I get a description from a customer, I might have a different view of it than you.” Solving the problem could involve additional conversations with the sales team, or double-checking with the original sources.

These data quality issues need to be considered early, says Jon Knisley,

director of AI value management at ABBYY.

“It’s really easy to run a pilot when it’s not in production,” he says. “But when you try to move it there, you get data issues. Where is the data coming from, and what’s the risk component?”

That’s also when the governance problems arise, as well as other challenges. These are all fundamentals that companies needed to learn in the previous era of automation and RPA, he says, since we’ve seen this technology cycle before.

4. Respecting change management

The biggest thing being forgotten about is change management, says Knisley.

“An AI project isn’t going to fail because of the model,” he says. “It’ll fail based on people and process. And there’s not that balance yet between the technology, people, and the process. Especially in North America, we want to solve every problem with technology. And that’s just not how the world operates.”

Back in 2019, according to a Forrester survey conducted on behalf of UiPath, 82% of respondents said change management was a challenge for RPA deployments. The same is true today. In a recent Kyndryl survey of over 1,100 business leaders, the speed of AI has outpaced workforce, governance, and operating models for 79% of organizations, and only 9% of organizations have implemented change management, redesigned roles around AI, and built workforce readiness.

“The biggest challenge we had in any digital transformation — and still have — is change management,” says Rahul Chhabra, director of applied AI at Herbert Smith Freehills Kramer, a leading global law firm.

And it’s gotten harder. With AI in particular, the technology is evolving so fast that change management is a quickly moving target.

“With RPA, it was sort of simple,” Chhabra says. “We had frameworks we could use to train people. We still have those learnings, but we have to enhance those processes.”

Something that works today might no longer work tomorrow, either. “You have to constantly iterate,” he adds. “What has worked can fail fast and only work in modules. So don’t try to solve the entire problem in one go.”

And employees don’t just have to keep learning new skills and adapting their work processes. Knowledge workers in particular also have to face the constant fear that AI will make them irrelevant. It doesn’t help when AI leaders amplify these fears. For example, Dario Amodei, CEO of Anthropic, predicted that AI will be capable of doing most or all jobs, not just entry level, in less than five years.

“Today, if lawyers do 10 tasks, maybe four of them will become obsolete,” says Chhabra. But that doesn’t mean four out of every 10 lawyers will be laid off. Even if most of the work is automated, Chhabra adds, there’ll be more for lawyers to do, not less.

“Today, a litigation matter might be worth $1 million,” he says. “But if it’s just $150,000, then a lot more matters are brought forward. So there’s going to be an increase in litigation and, therefore, more work for lawyers.”

RPA isn’t dead

So is RPA over? RPA wasn’t smart, says Traci Gusher, data and analytics leader at EY Americas. “It was useful, but it wasn’t intelligent. You couldn’t rewrite the process with RPA because it wasn’t technologically advanced enough.”

So, about 15 years ago, during the big RPA wave, organizations looked for ways to use RPA inside their processes, but the benefits were extremely limited.

“It was never so demonstrative that it would catch investors’ eyes,” she says. “It never got to that level of impact.”

Today, many companies are making the same mistakes with AI, she says. Instead of adding AI to existing processes, they need to rebuild them from scratch. “If you’re chunking it, you’re not going to get the results you want because it’s too small and incremental. That’s why I think over a period of time, RPA died a slow death.”

But AI can actually bring RPA back to relevance, she adds.

“There’s still very much a place for RPA in the AI wave,” she says. “You can use RPA for tasks and transaction-level activities, and integrate with agents. That might be the most cost-effective way.”

Unlike agentic AI, RPA is deterministic and completely predictable, it can run on-prem without leaking any sensitive data, and it incurs no token costs.

“We’ve seen consultants say we need to do this with agentic AI,” says ABBYY’s Knisley. “And they don’t have any reliability or governance. What they’re ultimately trying to do they could’ve done with regex for a tenth of the price, and 10 times the efficiency. You’ve got to figure out when you need to use agentic, script, or regex.”

So instead of throwing out RPA and going all-in on agentic AI, many companies are taking a more nuanced approach, using traditional RPA for processes that don’t require intelligence. Meanwhile, they use AI to help set up, test, manage, and upgrade the RPA, getting the best of both worlds.

“I think RPA is a very powerful technology and it has a place in the world today,” says Chhabra. “Especially on things that need to be deterministic, or you’re automating high risk or compliance workloads. You can mask the PII, but it’s still a risk to the company, so I’d rather use a script or some form of RPA automation.”

And a lot of governance will be rules-based, he adds, or based on RPA.

“There’s a lot of marketing speak that RPA is dead,” he says. “I don’t think that. Even the AI vendors are using RPA in the back, but now they’re calling it workflow automation.”

  • ✇Security | CIO
  • SAP dodges German antitrust investigation over data extraction
    SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation. The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a dynamic market, it said in a news release. It launched its investigation int
     

SAP dodges German antitrust investigation over data extraction

3 de Agosto de 2026, 10:02

SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation.

The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a dynamic market, it said in a news release.

It launched its investigation into SAP’s practices following complaints by software companies including Celonis, a developer of process mining tools, alleging that SAP makes it difficult for customers and third parties to access data from its ERP systems and favors its own Signavio process mining tool.

“Companies must generally also be able to use their own data in third-party applications. With large software platforms, in particular, non-discriminatory access to data is crucial to effective competition,” said Bundeskartellamt President Andreas Mundt. “Our preliminary investigation has found that there are currently sufficient data extraction options available and that there have so far been no indications of exclusionary practices that may be relevant under competition law.”

SAP changed its policies on accessing data held in its applications via APIs in April, prompting customer pushback.

But, said Mundt, the Bundeskartellamt found that despite the API policy change, data extraction options that were previously permissible are still available.

Data extraction is possible

SAP welcomed the Bundeskartellamt decision, saying that “as the authority states, SAP customers and partners have sufficient and permissible technical options to extract data from SAP systems and use it in solutions from other providers. The SAP API Policy does not restrict these capabilities.”

Celonis also issued a statement, noting that the Bundeskartellamt ruling underlined the continued importance of unrestricted data access, and warning, “The decision is based on the key premise that data extraction for software from providers such as Celonis will remain possible even under SAP’s new API policy — a premise that SAP has been unwilling to confirm to date.”

The Celonis statement continued, “We remain steadfast in our conviction that company data belongs entirely to the customers who generate it. No provider should restrict a company’s right to extract its own information or prevent users from working with third-party providers such as Celonis that offer added value to customers.”

Celonis is also attacking SAP’s policies on data extraction in court in California. It filed a complaint in March 2025 alleging that SAP was leveraging its software to “prevent SAP customers from sharing their own data with third-party providers, including Celonis, without paying prohibitively expensive fees.” The judge dismissed some of the claims in that case, leaving three to be tested in a trial then scheduled for December 2026. Celonis has since amended its complaint to include 10 claims, and the trial has been rescheduled for 2027, the company said.

“Our litigation continues to uncover evidence of SAP’s unlawful behavior, including anticompetitive conduct and theft of intellectual property, and we are confident in the evidence that we will present at trial,” Celonis said following the German authority’s decision.

The Bundeskartellamt’s failure to find sufficient evidence to open a ‘formal abuse of dominance proceeding’ is a small win for SAP, said Scott Bickley, advisory fellow at Info-Tech Research, but “CIOs should not mistake it for a validation of SAP’s data access model.”

Although SAP recognizes customers’ right to decide they use their data, it does not make it easy for them to do so, he said. “CIOs may technically retain vendor choice but be faced with expensive replication architectures, API rate and volume restrictions, additional platform costs, performance lags and data migration costs, all with a dependency on an SAP-approved technical pattern, which can be a moving target.”

Data ownership as a procurement issue

Justin Greis, CEO of consulting firm Acceligence, sees the decision as an instructive one for enterprise CIOs.

“This isn’t a reason to stop asking hard questions of your ERP vendor. Whether it’s SAP, Oracle, Microsoft, Salesforce, or anyone else, enterprises should continue to evaluate how easy it is to access their own operational data, integrate third-party applications, and migrate workloads if business priorities change. Those questions are becoming strategic procurement issues, not just technical ones,” Greis said.

CIOs should consider data portability early in the procurement process, said Kaan Dincer, CEO of data migration vendor Settle: “Negotiate export rights, API access on reasonable terms, and documentation of the data model before signing and test a real extraction while the vendor still wants your renewal. The cost of your eventual exit is set on the day you implement, not the day you leave. ERP data now feeds analytics and automation outside the system of record, so access friction that used to be an IT annoyance is becoming a strategy constraint.”

In the SAP case, he said, “the regulator answered a narrow legal question, not the operational one. Declining to open proceedings means the friction was not shown to be anticompetitive. It does not mean the friction is not real. The Bundeskartellamt’s own findings acknowledge that extracting large data volumes is technically demanding and it said explicitly that it will keep watching as access mechanisms and license models evolve. That is not a clean bill of health. It is a decision to hold fire.”

Srinivasulu Reddy Battu, a senior software engineer with cloud vendor ZT Systems, said the big takeaway is the difference between difficult and impossible. SAP’s argument is that the data migration outside of its environment is possible, but Battu said it can be a time-consuming and expensive process.

“When the ruling says ‘various permissible and viable options’ exist, that’s technically true, but it glosses over how much expertise it actually takes to use them,” Battu said. “CIOs should still watch how process mining gets packaged in their contracts. If Signavio comes included by default, teams will naturally start using it and that quietly reduces your negotiating power with other vendors over time. This isn’t just about SAP: Oracle, Microsoft, every major ERP vendor sits on a massive amount of your business data. If any of them decided to tighten their API policies tomorrow, most companies would be scrambling.”

  • ✇Security | CIO
  • Frontier AI will not break finance. Slow cyber decisions will
    The scariest thing about frontier AI is that it gives lazy criminals better legs. That sounds flippant until you watch how cyber failure works. I have seen that weakness in many costumes: A server waiting for a patch, an access path nobody wants to touch, a supplier marked “low risk” because the contract said so, and a legacy system kept alive by one person who retired years ago. It is a known weakness with no owner. Frontier AI only needs to find them faster, joi
     

Frontier AI will not break finance. Slow cyber decisions will

3 de Agosto de 2026, 07:00

The scariest thing about frontier AI is that it gives lazy criminals better legs.

That sounds flippant until you watch how cyber failure works. I have seen that weakness in many costumes: A server waiting for a patch, an access path nobody wants to touch, a supplier marked “low risk” because the contract said so, and a legacy system kept alive by one person who retired years ago.

It is a known weakness with no owner.

Frontier AI only needs to find them faster, join them better and act before the committee has finished admiring the heat map.

On 15 May 2026, the Bank of England, the FCA and HM Treasury warned that frontier AI models carry serious cyber and operational resilience implications for regulated firms and financial market infrastructures. Cyber capability is getting faster and cheaper to scale.

The European Systemic Risk Board (ESRB) warned in June 2026 that frontier AI models with cyber capabilities can discover vulnerabilities, generate working exploits and execute attacks at a speed, scale and accuracy beyond those of earlier models. It also warned that this may reduce response time, increase concentration risk and weaken resilience across the financial system. Three weeks earlier, a US executive order directed the Treasury, along with CISA and the NSA, to establish an AI cybersecurity clearinghouse and a pre-release evaluation framework for frontier models with advanced cyber capabilities.

The clock has changed

For years, cyber programmes lived on borrowed time.

A weakness appeared. Someone logged it. Technology needed a change window. Procurement checked the supplier. Legal asked what could be said. Everyone was busy. Nobody was idle. Yet the decision moved like a suitcase with one broken wheel.

Frontier AI punishes that rhythm.

The Institute of International Finance (IIF) staff paper says frontier AI has lowered the barriers to discovering, exploiting and combining vulnerabilities. It also says the answer is not a new risk framework, but faster use of existing ones, with more senior ownership and faster remediation.

A patching process that looked mature when attackers needed weeks may look quaint when exploitation can follow in hours. A vulnerability backlog that once looked like a queue can become a menu. And menus are for customers. Not attackers.

When firm weakness becomes market fragility

In finance, a cyber incident can travel.

A bank does not sit alone. A payment system does not hum in a private corner. A firm and financial market infrastructure (FMI) does not clear and settle trades as a hobby. These institutions share technology, suppliers, market data, cloud services, open-source code, identity systems and habits. When one pipe shakes, another pipe may feel the vibration.

That is why the ESRB treats frontier AI as a systemic risk, rather than a security issue. It points to shared technology stacks, common service providers, open-source dependencies and the risk of incidents spreading across critical functions. It also warns about asymmetry: Some firms and jurisdictions will have better skills, tools and access than others, while attackers may benefit sooner than defenders.

For FMIs, the useful question is blunt: What failure would stop the market completing the day? Not “which system is red?” Not “which supplier scored medium?” If this breaks, who cannot pay, clear, settle, price, report or trust?

In finance, one firm’s backlog can become another firm’s outage.

Governance means naming the decision

There will be a new policy. A renamed committee. A dashboard that tells directors what everyone already knows: the risk is high.

Fine. Keep the dashboard. But do not confuse it with movement.

Supervisors have already moved this to the top table. On 7 July 2026, the ECB, as banking supervisor, has asked significant institutions to assess the changed threat environment without delay and to deliver a full action plan by 31 October 2026. The ESRB says financial authorities should ensure boards are fully committed to mitigating frontier-AI-driven cyber risks, with clear governance, planned, timely responses and internal investment.

Governance should name the decisions before the incident names them for you. Which important services are most exposed? Which vulnerabilities must be fixed first? Which patching risks will the board accept to avoid a worse cyber risk? Which suppliers can hurt the firm? Which defensive AI tools are safe enough to use, and under whose authority?

Each important business service should have a Frontier AI Cyber Risk Position. One page. Service. Scenario. Owner. Gap. Decision. Funding. Date. Proof.

If it cannot fit on one page, it may not be due to complexity. It may be fog.

A policy says the firm noticed. A decision says the firm moved.

Threat modelling must grow up

Old threat models ask what an attacker might do. Useful, yes. But frontier AI adds a sharper question: What does the model make easier?

The Frontier Model Forum says cyber risk frameworks use capability thresholds, capability assessments and extra safeguards when models reach levels that could enable serious harm. Two thresholds matter for finance: Models that give meaningful uplift to less-skilled attackers, and systems that can carry out parts or all of an attack chain with little human direction.

So do not only ask whether phishing improves. Ask whether a novice can now perform work that once needed a specialist. Ask whether vulnerabilities can be discovered, chained, tested and used against hardened targets.

The Frontier AI Risk Management Framework offers a useful lens: Deployment environment, threat source and enabling capability. In plain English: Where is the tool, who can misuse it and what does it let them do that they could not do before?

Patching is now a resilience test

Patching used to be treated like hygiene. Necessary, dull and easy to postpone.

Not anymore.

The ESRB warns that current patching practices in finance are largely reactive. They rely on periodic updates and ad hoc responses. That may fail if frontier AI increases the volume of critical vulnerabilities. Firms may then face an ugly choice: Leave systems exposed or reduce patch testing, risking outages.

The IIF paper adds another sting. A published patch can become a signal. Attackers can inspect the fix, infer the weakness and move faster than firms can test and deploy it. In that world, “we are waiting for the next maintenance window” starts to sound less like discipline and more like hope in a suit.

Firms need a patch-wave model: Asset visibility tied to critical services, component visibility, exploitability scoring, attack-path analysis, emergency change lanes, rollback plans and senior visibility when the clock collapses.

Do not let CVSS become theatre. A lower-scored weakness on a live path to a critical service may matter more than a higher-scored weakness buried in a corner.

A patch is not always the end of the story. Under pressure from frontier AI, it can be the starting gun.

Your supplier map is part of your attack surface

No firm owns its full risk anymore.

Some of it sits on cloud platforms, in managed services and in open-source packages maintained by tired volunteers, software vendors and AI providers whose access decisions may depend on governments, export rules or commercial priorities.

The IIF paper notes that weaknesses now being surfaced are not unique to financial services. They live in operating systems, browsers, cloud platforms and open-source software used across the wider economy. The capacity to fix many of them sits with technology developers, platform firms and governments.

A contract clause does not patch a supplier. A right-to-audit clause does not restore settlement at 3 a.m. A service credit does not rebuild confidence.

Firms and FMIs need sharper dependency maps. Which providers support important services? Which have production access? Which hold sensitive data? Which supplier failure would stop the day?

Ask for proof. Patch proof. Incident routes. Recovery test results. Component lists. Exit options that can survive contact with reality.

Procurement should not buy what resilience cannot recover. Your perimeter ends at the contract. The attacker’s path does not.

Use AI for defence, but keep humans in authority

Frontier AI can help search code, correlate signals, support testing and speed up triage. The ESRB accepts the defensive value, but warns that offensive gains may arrive sooner than defensive maturity. The IIF paper says firms that move faster to build defensive capability will be better placed as the threat shifts.

So yes, use AI to test, find weak paths, help the SOC cut noise and scan code before deployment.

But do not let speed smuggle in authority.

If a containment action could affect payments, settlement, customer access or market operations, a named human must own the call. AI can suggest. AI can rank. AI can warn. It should not inherit a mandate by accident.

Agents that write code, test controls, scan infrastructure or act in workflows need scoped permissions, monitoring, logs and kill switches. They also need owners who understand what the agent can touch.

Use AI to gain speed. Do not let it become the ghost in the control room.

Assurance must reconstruct the story

After an incident, the question will not be, “Did you have controls?”

It will be sharper. What did you know? When did you know it? Who decided? What did they reject? Why was the choice reasonable? Where is the proof?

Assurance means following the decision trail from threat signal to board action to funding to remediation to test result. Evidence should include board papers, risk decisions, expired acceptances, supplier attestations, incident timelines, recovery tests and lessons learned.

The scrutiny will keep moving. The ESRB will reassess these risks at each quarterly meeting of its General Board. Supervisors are calibrating expectations to the trajectory of AI capability because anything anchored to today’s models will be stale before it lands.

One caution runs the other way. Firm-level disclosure of live vulnerabilities can itself concentrate targeting information. Push for aggregate reporting where the rules allow, and remediate before you broadcast.

Internal audit should ask one brutal question: Could a competent stranger reconstruct the decision six months later? If the answer is no, you may have done work rather than built defensibility.

Conclusion

Frontier AI will not break finance by magic. It will test whether finance can move before its own processes turn against it.

Frontier AI will punish firms that treat it as a chore and reward those that treat the next 12 months as a decision problem with a clock on it.

The EU and the US reached the same conclusion by different routes: The rulebook already exists. DORA, the AI Act and the new US clearinghouse point to frameworks in place today. The variable is the speed, ownership and evidence with which firms apply them.

The board questions are plain. Do we know our important services? Do we know the paths that can break them? Which suppliers and which models can hurt us? Can we patch in hours? Can we contain without guessing? Can we recover within tolerance? Can we prove who decided what, when and why?

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

  • ✇Security | CIO
  • Earnings from SAP, ServiceNow, and IBM challenge the SaaSpocalypse narrative
    The first wave of quarterly earnings from major enterprise software vendors suggests that while AI is beginning to reshape enterprise technology spending, it has yet to produce the sharp decline in software demand that some industry observers have dubbed the “SaaSpocalypse.” The latest results (Q2) from ServiceNow, SAP, and IBM, read against several prior quarters, showed continued growth in cloud and software businesses, though IBM reported that some software transactions
     

Earnings from SAP, ServiceNow, and IBM challenge the SaaSpocalypse narrative

28 de Julho de 2026, 09:01

The first wave of quarterly earnings from major enterprise software vendors suggests that while AI is beginning to reshape enterprise technology spending, it has yet to produce the sharp decline in software demand that some industry observers have dubbed the “SaaSpocalypse.”

The latest results (Q2) from ServiceNow, SAP, and IBM, read against several prior quarters, showed continued growth in cloud and software businesses, though IBM reported that some software transactions slipped as customers prioritized spending on AI infrastructure instead.

Executives at all three companies said enterprises continue to invest in core software platforms while embedding AI capabilities into those environments.

SAP addressed the debate directly during its earnings call.

“While there has been… massive noise around the alleged SaaS apocalypse over the last quarters, the underlying trajectory of our business remains fully intact,” CFO Dominik Asam said, citing continued growth in SAP’s cloud backlog.

Enterprise software demand continues

ServiceNow’s subscription revenue growth has risen for five straight quarters, from a low of 19% in early 2025 to 23% in constant currency in the quarter reported July 22, according to the company’s earnings releases.

Current remaining performance obligations grew 21.5%, AI annual contract value exceeded $1 billion for the first time, and the company’s renewal rate held at 98%, executives said during the company’s earnings call.

Similarly, SAP reported 24% cloud revenue growth, 26% growth in current cloud backlog and 27% growth in Cloud ERP Suite revenue. Its cloud revenue has remained in a narrow band of 25% to 27% growth at constant currency for four straight quarters. SAP’s CEO Christian Klein said AI and SAP Business Data Cloud were included in more than 90% of the company’s 50 largest customer deals during the quarter, while Asam said SaaS and platform-as-a-service revenue continued to grow “far above the overall market.”

IBM’s software revenue growth, however, decelerated the sharpest of the three, slowing to 5% after peaking at 14% in the fourth quarter of 2025. That softness traced to one product line: Transaction Processing revenue, the license-based software tied to IBM’s Z mainframe line, fell during the quarter, while Data revenue grew 19% and Hybrid Cloud, which includes Red Hat, grew 11%, the company said in its Q2 results statement.

“The vast majority of our software business, about 80% of that revenue, is recurring in nature and delivered healthy growth in the quarter, reflecting the demand for our offerings and giving us confidence in our growth opportunity,” IBM CEO Arvind Krishna said during the earnings analyst call.

The earnings also showed increasing adoption of AI capabilities within existing enterprise software platforms.

ServiceNow said the number of customers with agentic AI in production increased ninefold over the past nine months. Its CEO Bill McDermott said the percentage of renewal customers purchasing agentic AI for the first time doubled both sequentially and year over year.

“When will customer deployment of AI mark an inflection point for ServiceNow’s growth? Here’s the answer. It already has,” McDermott said during the analyst call.

SAP said customer demand for its autonomous enterprise strategy expanded following its Sapphire conference, while beta programs for Business AI Platform and Joule Work were oversubscribed shortly after launch.

The earnings, however, do not necessarily mean enterprise software consumption is unchanged, according to George Brocklehurst, managing vice president at Gartner.

“The market should not confuse stable SaaS revenue with stable SaaS business models,” Brocklehurst said. “Agentic AI changes how value is consumed, and that transition can begin well before it becomes visible in aggregate revenue numbers.”

AI changes enterprise buying patterns

IBM’s earnings offered an early indication of how AI infrastructure investments are beginning to influence enterprise purchasing decisions.

The company’s chief financial officer Jim Kavanaugh said some customers redirected spending toward servers, storage and memory to secure AI infrastructure, delaying enterprise licence agreements that are typically treated as capital expenditure. Subscription and consumption-based software, which customers generally classify as operating expenditure, continued to perform well, he said during the call.

Krishna said IBM expects long-term enterprise value to shift toward software that orchestrates AI models, governs enterprise data and manages AI deployments across hybrid environments rather than toward foundation models themselves.

Sanchit Vir Gogia, founder and chief analyst at Greyhound Research, said IBM’s quarter illustrates changing technology spending priorities rather than a broad decline in enterprise software demand.

“Infrastructure spending is growing several times faster, yet software expenditure keeps rising,” Gogia said. “The sharper reallocation is happening inside the application estate itself. Strategic systems of record are being protected. Duplicate copilots, marginal point tools and unused licences are being challenged.”

Gogia said traditional SaaS metrics such as backlog and renewal rates should be interpreted alongside measures of AI adoption and software utilization because they reflect contractual commitments rather than how enterprises ultimately consume software.

“Strong backlog proves commitment rather than fresh demand, and a 98% renewal rate does not reveal what was conceded to win it,” he said. “The decisive measure is no longer how many people log into software; it is how much governed work the software completes.”

Brocklehurst said the industry’s transition is likely to unfold over several years rather than through a sudden collapse in enterprise software demand.

“The ‘SaaSpocalypse’ will not begin when enterprises stop buying software,” he said. “It will begin when enterprises stop paying for access and start paying for execution.”

Meta Adds WhatsApp Usernames: Here’s What You Need to Know

30 de Junho de 2026, 12:36

WhatsApp is rolling out usernames so people can chat without sharing phone numbers. Here’s how reservations, username keys, and rules work.

The post Meta Adds WhatsApp Usernames: Here’s What You Need to Know appeared first on TechRepublic.

❌
❌