Visualização normal

Ontem — 7 de Setembro de 2026Cybersecurity News
  • ✇Security | CIO
  • The AI cybersecurity arms race is on
    Businesses received a staggering amount of cyberattacks in June, according to Check Point, showing a rise of 20% over the previous 12 months. The breakout of AI agents from OpenAI in July to hack into the Hugging Face website, and subsequent similar events from Anthropic and Meta, indicate agentic-powered attacks will explode over the coming year. Currently, malicious hackers have the advantage because publicly released frontier models from the US incorporate guardrails
     

The AI cybersecurity arms race is on

7 de Setembro de 2026, 07:00

Businesses received a staggering amount of cyberattacks in June, according to Check Point, showing a rise of 20% over the previous 12 months. The breakout of AI agents from OpenAI in July to hack into the Hugging Face website, and subsequent similar events from Anthropic and Meta, indicate agentic-powered attacks will explode over the coming year.

Currently, malicious hackers have the advantage because publicly released frontier models from the US incorporate guardrails that can’t distinguish between malicious or defensive activities. As a consequence, these models default to a refusal to get involved. Hugging Face discovered this the hard way when they attempted to utilize a model to defend against the OpenAI intrusion. Their solution was to adapt a Chinese open weight model to analyze the 17,000 attack logs, find the vulnerability, and contain the intrusion.

With incidents like these happening more often, an arms race has begun with AI being both the problem and the solution.

Strength in numbers

While single agents generally perform more efficiently for well-defined tasks, research from Stanford University indicates swarms are more effective in messy scenarios with noisy data, which are more typical of unpredictable, intrusion attacks. The increased token usage by swarms raises costs, but increasingly efficient open weight models are rapidly lowering these barriers.

In the Hugging Face example, the agents worked together as a team leaving messages for each other on a message board they improvised. They shared newly found vulnerabilities, exchanged tools, and even developed conventions to address one another and to avoid overwriting each other’s work. While this may seem sinister, they were only following their designated purpose: to achieve a goal without regard to any collateral damage. We can expect bad actors to harness the power of agentic swarms through fine-tuning open weight models, and creating agents that progressively learn from their experiences.

Modern warfare has been transformed over the last four years, too, through the deployment of drones by Ukraine to defend against Russian attacks. Military strategies and the deployment of armament budgets around the world are shifting to focus on new technologies, and approaches and enterprises are now facing a similar challenge from the hostile use of agentic AI.

The drawbridge is down

As enterprises build out their own agentic systems to handle ecommerce, customer service, and marketing activities, this presents new attack surfaces for antagonistic efforts. April 2026 research from Trend Micro found almost 1,500 MCP servers directly exposed to the internet had no authentication or encryption, a rise of 200% from nine months earlier. This included 70 hosts offering direct SQL execution, and servers holding medical records.

The automation of business processes and the reduction of humans from decision making chains open up new vulnerabilities for agents with malicious intent. Arkose Labs’ 2026 agentic AI survey of 300 enterprise leaders found 97% expected an AI agent security incident within the next 12 months.

Social engineering

While agents have demonstrated their ability to break through security systems, they’re also capable of targeting humans to achieve their objectives. Recent research from Verizon indicates that 62% of successful breaches involve a human element, with phone-based attacks 40% more successful than email-based ones. In August, for instance, scammers using an AI-generated deep fake of Australian Prime Minister Anthony Albanese’s voice were able to scam investors out of $5.3 million.

If agents can break out of digital sandboxes, and generate convincing fake videos and audio, then they’re certainly capable of making basic phone calls. In July, during testing of frontier models, the UK AI Security Institute discovered an agent tried to insert malicious code into an open-source project. Attempting to get the code approved, the agent created fake online identities using them to persuade the project’s maintainer to sign it off. “This is the first time we’ve seen risks around autonomy and deception manifest this clearly without specific prompting in the real-world,” the Institute put in a write-up of the incident.

Fight AI with AI

So attackers currently have the upper hand in this escalating arms race. They have access to agents that can work around the clock, constantly probing, learning, and sharing their knowledge with other agents. They’ll only get better at this and learn ways to stay ahead of defensive systems. International agreements to delay or restrict the capabilities of frontier models won’t stop hostile actors motivated by money or rogue states pursuing other objectives. Developers and security vendors need access to the latest frontier models unfettered by restrictive guardrails if we’re to stand any chance of defending against the coming tsunami of attacks.

We can learn a lesson from recent history on this front. In 1992, the US restricted exported software to weak 40-bit encryption, citing security concerns going back to the cold war. While the US allowed stronger encryption internally, the result was weakened security for everyone as hostile antagonists were able to disrupt global supply chains that incorporated less secure software. Despite lifting the ban in 1999, embedded software containing 40-bit encryption continued to cause problems for many years across multiple countries, including the US.

Without rapid action, we may look back fondly to the world before July 2026 as a golden age for cybersecurity, a relative age of innocence.

Antes de ontemCybersecurity News
  • ✇Security | CIO
  • Why data sovereignty has become a strategic IT priority
    For years, conversations about data sovereignty followed a predictable pattern. Compliance teams wanted to know where sensitive data was stored, legal teams ensured regulatory requirements were met and IT focused on delivering the infrastructure to support the business. Once those requirements had been satisfied, the conversation largely moved on. Today, that approach is becoming increasingly difficult to maintain. Enterprise infrastructure has changed significantly
     

Why data sovereignty has become a strategic IT priority

3 de Setembro de 2026, 07:00

For years, conversations about data sovereignty followed a predictable pattern. Compliance teams wanted to know where sensitive data was stored, legal teams ensured regulatory requirements were met and IT focused on delivering the infrastructure to support the business. Once those requirements had been satisfied, the conversation largely moved on.

Today, that approach is becoming increasingly difficult to maintain.

Enterprise infrastructure has changed significantly over the past decade. Applications now span multiple cloud platforms, workloads move between on-premises and cloud environments, and AI is creating entirely new ways for organizations to generate, process and analyze data. At the same time, geopolitical tensions, changing regulations and growing dependence on a relatively small number of global cloud providers are forcing organizations to think differently about the relationship between their data and the infrastructure that supports it.

As a result, data sovereignty is evolving beyond a compliance exercise. It is becoming an important consideration in how organizations design infrastructure, manage operational risk and maintain long-term flexibility.

The business consequences of losing visibility and control over enterprise data have become increasingly difficult to ignore. According to IBM’s 2025 Cost of a Data Breach Report, the global average cost of a data breach reached US$4.9 million, highlighting why decisions about how enterprise data is governed, protected and managed are now attracting board-level attention rather than remaining solely within IT. As organizations distribute data across cloud platforms, AI services and third-party environments, maintaining control is becoming just as important as deciding where that data resides.

Data sovereignty is no longer just about location

Traditionally, demonstrating data sovereignty often meant showing that information was stored within an approved geographic region. For many workloads, that was sufficient to satisfy both regulatory and organizational requirements. Modern IT environments are considerably more complex.

A single business application may rely on infrastructure spread across multiple regions, cloud services from different providers and data replicated for resilience and availability. Administrative functions may operate from different jurisdictions, while AI services may process information in entirely separate environments from where it is stored. This means that physical location is only one part of the picture.

Today’s CIOs are often asking broader questions. Who has administrative access to critical data? Which jurisdictions have legal authority over the platforms storing or processing it? How easily can workloads be moved if business requirements change? What dependencies exist on individual providers? And how resilient is the organization if those dependencies become a constraint?

These are infrastructure questions as much as governance questions. They influence architectural decisions around workload placement, identity management, backup strategies, disaster recovery and the degree of flexibility built into an organization’s technology estate. Rather than being addressed after infrastructure has been deployed, they are increasingly shaping infrastructure decisions from the outset.

Cloud has made sovereignty more strategic

Cloud computing has given organizations access to almost unlimited compute capacity. It has accelerated application deployment and enabled businesses to scale in ways that would previously have been difficult or expensive. However, cloud has also introduced new considerations around control.

Most organizations now operate hybrid environments that combine public cloud, private cloud, colocation facilities and on-premises infrastructure. Few enterprises rely on a single operating model because different applications have different performance, security, regulatory and commercial requirements. The challenge for CIOs is not deciding whether cloud is the right answer. It is determining which workloads belong in which environments while retaining the flexibility to adapt as business priorities evolve. That flexibility is becoming much more valuable.

AI is driving significant changes in infrastructure requirements, while geopolitical uncertainty and evolving regulations continue to reshape the technology landscape. At the same time, infrastructure planning is becoming increasingly influenced by factors such as hardware availability, power, cooling and supply chain resilience. Data sovereignty adds another dimension to those decisions, requiring organizations to think not only about where workloads run, but how much control they retain over the data those workloads generate and process.

Organizations are also rethinking the physical form of infrastructure itself. Containerized modular data centers allow enterprises to stand up sovereign capacity on their own sites, under their own governance, without waiting on constrained colocation markets or multi-year grid connection queues. The workload, the hardware and the jurisdiction all sit within the organization’s direct control. What was once dismissed as a temporary fix has evolved into something more strategic: purpose-built AI pods that deploy in months rather than years and scale in increments matched to demand.

Decisions that once appeared relatively static may now need to be revisited much more frequently. Infrastructure strategies that preserve workload portability and avoid unnecessary dependencies are often better positioned to respond to those changes than environments built around a single platform or provider.

This is not an argument against public cloud. Public cloud remains an essential component of modern enterprise infrastructure. But it reflects the growing importance of maintaining choice. Organizations that can move workloads, adopt new technologies or adjust operating models as circumstances change are likely to be more resilient than those with fewer options.

Control is becoming the foundation of resilience

Resilience is often discussed in terms of cybersecurity, disaster recovery or business continuity. Increasingly, it also depends on how much control organizations retain over their own infrastructure. This is reflected in the NIST Cybersecurity Framework (CSF) 2.0, which introduced Govern as one of its six core functions, recognizing that effective cybersecurity starts with governance, risk management and organizational oversight rather than technology alone.

An organization that understands where its data resides, who can access it, how it is protected and how quickly it can be moved if circumstances change, is generally better prepared to respond to disruption. That disruption may take many forms, from regulatory changes and geopolitical developments to commercial decisions made by technology providers or the rapid adoption of new AI capabilities. This is where data sovereignty becomes a strategic capability rather than simply a compliance requirement.

Infrastructure decisions increasingly determine how easily organizations can adapt to change. Building flexibility into architecture today makes it easier to respond to future business requirements without unnecessary complexity or costly re-engineering.

Looking ahead, the conversation is likely to extend beyond data sovereignty towards AI sovereignty. As organizations deploy AI models across customer services, software development, business operations and decision-making, many of the same questions will apply. CIOs will need to understand not only where enterprise data is stored, but where AI models operate, what information they can access, how they are governed and who ultimately retains control over the intelligence embedded within critical business processes.

While AI sovereignty is still an emerging concept, it reflects the same underlying principle. Organizations are no longer simply deciding where technology runs. They are deciding how much control they retain over the technologies and data that underpin their business. For CIOs, that represents an important shift in perspective.

Data sovereignty should no longer be viewed as a compliance checkpoint to address once infrastructure decisions have been made. It has become a strategic consideration that influences cloud adoption, infrastructure architecture and long-term operational resilience. As enterprise environments become increasingly distributed and AI becomes embedded across the organization, the ability to maintain visibility, flexibility and control will become just as important as where data happens to reside.

  • ✇Security | CIO
  • Revenue is no longer a funnel. It’s an AI learning loop
    It is Q3 of the fiscal year. The VP of sales walks into the revenue forecast meeting confident. The pipeline is strong, conversion rates are up and the sales team has been running at full velocity. The revenue intelligence motion is working. But something is off. The VP of customer success sees it first. Accounts that converted quickly are renewing at lower expansion rates. New customers are hitting support escalations that sales didn’t predict. Churn is accelerating
     

Revenue is no longer a funnel. It’s an AI learning loop

2 de Setembro de 2026, 08:00

It is Q3 of the fiscal year.

The VP of sales walks into the revenue forecast meeting confident. The pipeline is strong, conversion rates are up and the sales team has been running at full velocity. The revenue intelligence motion is working.

But something is off. The VP of customer success sees it first. Accounts that converted quickly are renewing at lower expansion rates. New customers are hitting support escalations that sales didn’t predict. Churn is accelerating in segments that looked promising three months ago.

Meanwhile, marketing has just launched a campaign targeting a specific buyer persona. But Sales has no way to track whether those leads convert differently than other sources. Finance can see the cash collected, but not the relationship between engagement patterns and deal velocity. Support can see the friction, but it doesn’t flow back to sales to suppress outreach until the customer issue is resolved.

All the signals exist, but they sit in different systems and tell different stories. By the time anyone assembles the full picture, the moment to act has passed.

This is the revenue intelligence gap I’ve seen: when go-to-marketing departments operate in silos and don’t understand (or don’t communicate) trends in their data throughout an organization. This leads to misalignment and a mistaken sense that go-to-market efforts are working, when they may not be. And it can cost enterprises billions in missed growth, wasted motion and lost customer relationships.

At every company I’ve worked at, the revenue funnel has been our organizing principle. Marketing at the top, sales in the middle and customer success at the handoff. It worked because it was linear and sequential, with clear accountability. It was a useful model for an era when work moved slowly and decisions happened in meetings.

But AI has fundamentally changed the game.

Today’s revenue organizations can no longer think in funnels. They must think like learning loops. As I explored in Operate like a Formula 1 team: The new AI operating model, the enterprises that win are those that redesign how work senses, decides, acts and learns, not those that simply add more tools.

The enterprises that recognize this and apply that framework specifically to revenue will create compounding advantages their competitors cannot catch.

Those still running on funnel logic risk handing their competitive future to organizations that understand the new model.

The automation plateau: Why faster isn’t smarter

Most enterprises spent the last decade automating revenue work.

CRM systems track accounts. Marketing platforms manage campaigns. Sales engagement tools automate outreach sequences. Analytics tools report on pipeline. Each delivered value, but also created fragmentation.

The problem is that each organization has different vantage points. Marketing sees different leads than sales. Sales sees different opportunities than customer success. Customer Success sees churn risk that sales never anticipated. Finance sees payment patterns that hint at account distress. Every system holds a piece of the truth. No system holds all of it.

The result is a revenue organization with lots of data but little context.

An account manager spends two hours assembling information from seven different systems to answer a single question: “Is this account at risk?” That account is at risk. But the account manager is either too slow or doesn’t have all the information.

Automation can solve the speed problem, but doesn’t fix the underlying disconnected workflow. Most employees are automating tasks, but few have integrated workflows. It may just accelerate an incomplete or incorrect answer.

The gap is architectural. And it exposes a fundamental truth: You must build a revenue system that learns and improves with every customer interaction, not just automating more activities.

The 5 motions of an AI-native revenue operating model

Transforming from fragmented automation to unified intelligence requires redesigning how revenue work operates across five interdependent motions. The same framework applies to the enterprise as a whole, but is now applied specifically to revenue generation.

  1. Sensing is the foundation. That means connecting the right signals across customer data, product usage, engagement patterns, support interactions and market intelligence into a coherent view. This could be a new Chief AI Officer announcement at a target account, a delayed renewal conversation, a support escalation or a product launch at a prospect. These signals exist throughout the enterprise, but most fail to connect them to something actionable.
  1. Reasoning is where connected signals become actionable intelligence. This is semantic reasoning: understanding what a signal actually means for this account in this specific moment. A prospect’s VP who consistently engages with business value messaging but ignores technical content tells the system something important about how to approach that buyer. A support escalation that preceded a sales conversation signals account risk. Prior objections that resurface become early warning signals. Timing becomes clarity.
  1. Execution turns intelligence into coordinated action. Based on what we know, did we initiate the right workflow? The next-best action surfaces to the seller with context embedded so the next communication has the right information. An account is routed to the right team. Critically, a customer with an open support escalation does not receive sales outreach while they are frustrated. Execution integrates into tools teams already use, but transforms how the work itself is structured to produce smarter, more contextual and more effective actions.
  1. Governance is the layer I’ve seen too many organizations underinvest in until something breaks. Revenue AI must operate within clearly defined guardrails. Who can be contacted? What data can be used? When does a human need to approve? These checkpoints are the foundation of organizational trust that allows AI to operate in high-stakes customer workflows at scale. Organizations that build governance from the start create speed with control. Those that skip it create scale with risk.
  1. Learning is the most important motion, and the one that separates an AI-native revenue system from sophisticated automation. Every interaction should improve the system. Which signals correlated with booked meetings? Which sequences are converted by segment? Which objections surfaced most often? Which customer moments generated the highest-quality pipeline? The system identifies patterns and continuously refines audience, messaging, trigger logic and policy design based on outcomes rather than assumptions.

From systems of record to systems of customer memory

The CRM was built as a system of record. It captures what happened: the opportunity is at stage three, and the last activity was two weeks ago. Then we layered hundreds of additional tools on top of it to try to make that record useful.

But a system of record is not the same as a system of memory.

A customer record knows that a contact opened an email. A customer memory understands the context, synthesizing all the information we have about the customer. Did the company announce a strategic initiative the week before? Did the VP of engineering ask specifically about certain product capabilities? Are we highlighting a pricing plan that they objected to in a meeting 6 months ago?

This is the power of semantic intelligence. It enables AI to understand enterprise meaning, not just retrieve data. This is what I described as moving toward the intent-driven future of work, where enterprise systems understand not just what is happening, but why it matters and who needs to act.

Customer memory is a strategic differentiator. It includes account history, contact preferences, relationship strength, prior objections, engagement patterns, buying committee changes, executive signals, product interests, support history and the accumulated context of every interaction the enterprise has had with that account.

Without semantic intelligence, AI can summarize what happened. With it, AI understands what matters, why it matters, who needs to act and what action is most likely to improve the outcome. Everything that happens with a customer or prospect needs to be part of a living customer memory that deepens with every interaction and improves every recommendation that follows.

The organizations building this capability now — investing in the data architecture and semantic layer required to support genuine customer memory are making an investment that compounds. Every interaction makes the next recommendation smarter. Every outcome refines the next signal interpretation. The gap between them and organizations still treating CRM as a data entry system will widen with every quarter.

What it takes to win

The enterprises that recognize this moment, and build unified data architecture, semantic intelligence, proper governance and feedback, will optimize their AI investments and actually realize productivity gains.

The funnel had a good run. But now revenue needs to be a learning loop.

And the CIOs who architect that loop will be the ones who define the next decade of competitive advantage in enterprise revenue.

  • ✇Security | CIO
  • AI agents need to learn when enough is enough
    For the past few years, enterprise AI programs have focused on making models more useful, accurate, and autonomous. In that phase, a bad answer was still usually something a human could accept or reject before taking action. But once agents start invoking tools and acting inside business workflows, success should no longer be measured only by how much work they complete. A more important metric is how well an agent recognizes when it lacks the authority, context, or judgme
     

AI agents need to learn when enough is enough

2 de Setembro de 2026, 07:00

For the past few years, enterprise AI programs have focused on making models more useful, accurate, and autonomous. In that phase, a bad answer was still usually something a human could accept or reject before taking action. But once agents start invoking tools and acting inside business workflows, success should no longer be measured only by how much work they complete. A more important metric is how well an agent recognizes when it lacks the authority, context, or judgment to continue.

When helpful becomes risky

According to Allan Dabre, technology compliance and AI lead at PwC, a behavior that has to be deliberately designed into the system is, “I don’t know.” AI is built to be helpful, so an agent will generally try to do something useful unless it’s been configured not to.

“The fact that AI systems can hallucinate illustrates that tendency,” Dabre says. “When they lack enough information, they may still produce an answer. In an agentic workflow, that impulse can become more dangerous because the output may become an action, rather than remain a suggestion.”

He adds that many enterprises still test AI primarily for completeness and accuracy. That made sense when the central question was if the model could produce a reliable response. But as models improve and agents gain more operational authority, he argues that CIOs need to prioritize something else: restraint.

“Can it stop at the exact moment you want it to stop?” he asks. “Are you testing for that?”

Confidence is not authority

Dabre makes a simple but important distinction. An AI agent may be 99% confident a record should be updated, a refund should be approved, or a legacy database can be decommissioned. But that doesn’t mean the agent has the authority to act. Confidence is about the probability the system believes it’s right. Authority is about whether the organization has delegated that action to the system in the first place.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Allan Dabre, technology compliance and AI lead, PwC

PwC

He gives the example of an agent asked to analyze legacy software and recommend what can be decommissioned. The agent may conclude, with high confidence, that several databases have little user impact and can be deleted. But even if the system is confident, most organizations wouldn’t want it to delete those databases on its own.

The same logic applies across business processes. An agent may be confident a customer record should be updated, an opportunity in a CRM system should be closed, or a transaction appears legitimate. But once that action flows into other systems, the potential consequences expand.

That’s why Dabre argues for what he calls an agent harness: a controls or orchestration layer outside the model that defines what the agent can and can’t do. In a refund workflow, for example, a company might let the agent approve small refunds, require human approval for larger ones, and stop the process entirely above a defined threshold. The agent may gather the relevant context, explain the request, and prepare the case for review, but the decision is governed by the authority boundary encoded into the system.

“It’s not a policy document and it’s not a prompt,” Dabre says. “It’s software or a configuration you can apply to an agent.”

The case for least agency

Matt Graney, chief product officer at Celigo, a business automation and integration platform provider, approaches the same problem through a principle he calls least agency. The idea is to give an agent the least amount of autonomy required to complete a job.

According to him, there’s a temptation to throw AI at broad, nebulous problems. But many business processes are still largely deterministic. They follow established rules and perform repeatable work. Within those workflows, AI may be useful at the point where rigid rules give way to interpretation. But that doesn’t mean the agent should own the entire workflow. “The smaller you make that surface area, the better,” he says.

Graney says the same logic applies to tools. An agent with too many tools can become confused, especially as context windows grow and the task becomes more complex. “Because Celigo is an integration platform,” Graney says, “the company’s approach is to expose agents to fewer, more powerful tools that reach enterprise systems through governed connections.”

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Matt Graney, chief product officer, Celigo

Celigo

That’s another form of restraint. Instead of letting an agent reach into enterprise systems ad hoc, the business gives it a narrow, governed toolset designed for the task at hand.

Graney also argues that guardrails should sit outside the model. If the same agent that makes a decision is also responsible for judging whether the decision is acceptable, the control is weaker. A separate guardrail can check the agent’s inputs and outputs before a downstream action occurs.

That same design discipline applies to escalation. “I don’t know” shouldn’t be treated as a chatbot phrase. In an enterprise workflow, it’s a handoff path that should be defined before the agent reaches it.

Make escalation part of the workflow

Turning uncertainty into a handoff is where Matt Quinn, CTO at CarGurus, an automotive marketplace, sees agentic AI becoming less a pure technology challenge and more a management challenge. At CarGurus, Quinn says agents are evaluated according to what they know, what they can do, and what data they operate on.

CarGurus receives a high volume of cases from dealers, and each one needs to be classified and routed. The company now uses an agent to review incoming cases, draw on account history, and route them to the appropriate next step. Quinn says the agent handles about 70% of those cases end to end without human involvement.

But when agents move toward consequential actions, he says the consensus is having a human approval step. The agent may return with a simple prompt like, I’m about to do this. Do you want me to proceed? That simplicity matters because a handoff shouldn’t bury the reviewer in complexity.

Quinn says the human remains ultimately accountable for the work. That principle is especially important in engineering, where agents may help write code or fix bugs. Quinn adds that CarGurus still expects engineers to follow the practices they’d use for any other production change, which includes running quality checks.

The company has adopted the phrase healthy speed to describe the balance it wants. The goal is to move faster without letting quality degrade. An agent can accelerate work, but if teams abandon the practices that make work safe, the speed becomes reckless.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Matt Quinn, CTO, CarGurus

CarGurus

This is also where human judgment remains difficult to replace. Quinn describes it as high judgment people develop through experience. A human may look at an AI-generated output and sense something’s wrong, even before fully articulating why. “Agents are improving,” he says. “But humans still play a critical role in deciding when the system shouldn’t continue.”

That doesn’t mean every workflow needs the same level of review. Quinn says CarGurus doesn’t have a target percentage of work to automate. The right level depends on the job and the task. A simple bug fix may require a lighter review than a change to a sensitive backend service, and a personal summary may carry little risk. But a document sent under someone’s name still needs human review.

Make autonomy accountable

That kind of pragmatic approach may be the best lesson for CIOs, making the goal of agentic AI appropriate rather than maximum autonomy.

That also means ownership has to be clear. Dabre argues ownership should be divided before deployment. The business defines the outcome, technology builds and configures the agent, risk and compliance set the guardrails, and governance monitors whether the system still behaves as intended. The authority to pause, stop, or retire an agent should be defined before production, not negotiated during an incident.

Graney makes the same point with a simple analogy. If a company hires an untrained intern, gives that intern access to the crown jewels of a business process, and something goes wrong, the intern isn’t the real problem. The process is. The same applies to agents. Accountability belongs with the person who owns the workflow.

That may be the shift CIOs need to make as enterprises move from pilots to production. AI agents shouldn’t be treated as magical workers that absorb accountability. They’re components in business processes, and those processes need accountable owners.

As AI adoption increases, the next phase of enterprise maturity won’t be defined by agents that always answer or always complete the task. It’ll be agents that know when not to act.

  • ✇Security | CIO
  • Bedrock, Vertex or build it yourself: The AI infrastructure decision most CIOs get backwards
    Across dozens of enterprise procurement reviews, I see technology executives make the same expensive mistake. They start their cloud AI strategy with the wrong question: “Which provider offers the smartest model today?” I sat through a meeting where a client’s leadership team listened to a slick 45-minute vendor pitch highlighting benchmark scores, processing limits and exclusive model access. By the end of the presentation, the executives were ready to sign a multi-
     

Bedrock, Vertex or build it yourself: The AI infrastructure decision most CIOs get backwards

31 de Agosto de 2026, 08:00

Across dozens of enterprise procurement reviews, I see technology executives make the same expensive mistake.

They start their cloud AI strategy with the wrong question: “Which provider offers the smartest model today?”

I sat through a meeting where a client’s leadership team listened to a slick 45-minute vendor pitch highlighting benchmark scores, processing limits and exclusive model access. By the end of the presentation, the executives were ready to sign a multi-year, multi-million-dollar commitment just to secure priority access to that single model.

I watched experienced leaders prepare to make a permanent infrastructure commitment based entirely on a temporary technological lead. Signing a long-term contract based on a six-month feature advantage treats a rapidly commoditizing utility service as a permanent asset, while surrendering control over the true intellectual property of your business.

The central strategic axiom

Raw computational intelligence is a rented utility overhead. Proprietary corporate context is owned enterprise capital. Never tie the permanent location of your corporate capital to the temporary rental location of a utility.

The economics of rented intelligence vs. owned capital

The top-performing commercial model on the market today will inevitably be matched or surpassed shortly by a cheaper, faster alternative. As Sequoia Capital detailed in its analysis of market economics, massive capital continues to pour into underlying processing infrastructure, driving the baseline cost of raw intelligence steadily downward toward commodity pricing.

When I evaluate technology investments with CFOs and CIOs, we strictly separate variable operational utilities from durable intellectual property across four strategic dimensions:

  • Market nature: Rented processing capabilities operate on fast-changing, highly commoditized and declining price curves. Owned corporate context forms unique, proprietary and highly defensible business positions.
  • Enterprise assets: Rented utilities encompass raw processing power, external models and third-party cloud infrastructure. Owned context includes customer ledgers, internal business rules, compliance frameworks and institutional memory.
  • Commercial strategy: Rented capabilities require a pay-as-you-go, unbundled approach that embraces maximum supplier churn. Owned context requires total asset ownership, isolated environments and zero vendor lock-in.
  • Financial objectives: The financial goal for rented capabilities is minimizing marginal cost per transaction. The financial goal for owned context is maximizing long-term enterprise valuation.

Raw processing power should be managed like electricity: your systems connect to the provider, consume what is required for the task and retain total freedom to switch utility suppliers if pricing or performance dictates a change.

Your corporate context, however, is a permanent capital asset. As Harvard Business Review has demonstrated across past technology cycles, lasting competitive advantage is built on proprietary data, unique operational workflows and institutional memory (never on shared infrastructure). A commercial model possesses zero understanding of your firm’s private pricing structures, key client nuances or regulatory boundaries until you feed it your context.

The mechanics of vendor capture

In my architecture reviews, I constantly see how managed cloud platforms naturally blur the line between rented processing power and owned corporate context.

Integrated cloud environments rarely position processing power as a standalone, interchangeable utility. Instead, platform architectures naturally encourage corporate engineering teams to bundle processing power with proprietary storage formats, closed management tools and native operational frameworks.

I have watched this architectural design trap enterprise teams in three distinct phases:

  1. Data entanglement: Corporate knowledge becomes formatted to fit a specific vendor’s environment, making future extraction costly and complex.
  2. Workflow dependence: Business rules and approval logic are built directly into vendor-owned management software, tying daily operations to their platform.
  3. Loss of leverage: During contract renewals, the enterprise cannot credibly threaten to switch providers because moving away requires a multi-month operational migration.

Once your business rules and customer records are deeply bound to a single vendor’s ecosystem, your negotiating leverage vanishes.

The architectural mandate: Vendor-neutral gateways

To preserve commercial leverage and maintain operational agility, I advise technology leaders to mandate an internal management layer between core corporate applications and external technology providers. Gartner’s strategic cloud planning research projects that the vast majority of enterprise organizations will require a multi-provider strategy specifically to prevent commercial lock-in and control long-term operating costs.

An internal control gateway acts as a central management point. Instead of allowing individual applications to establish direct connections to an external cloud vendor, every application communicates exclusively with your internal gateway.

This gateway enforces three mandatory executive controls:

  • Cost-optimized task routing: The gateway evaluates incoming tasks and automatically routes them to the most cost-effective external provider available. Routine administrative tasks go to low-cost utility systems, while complex tasks go to high-capacity options.
  • Centralized data protection: Before corporate data leaves the enterprise perimeter, the gateway strips sensitive customer details and logs the transaction for compliance verification.
  • Commercial agility: Because company applications interact solely with your internal gateway rather than directly with a vendor, you retain the ability to switch cloud providers instantly. If a vendor raises prices or a competitor releases a superior option, your team simply updates a routing rule within your internal system.

Rent the computational processing power as a temporary utility, but retain total ownership and control over the corporate nervous system.

  • ✇Security | CIO
  • Avoid AI rogue to ruin with control and accountability
    More than four years ago, Blake Lemoine, a senior software engineer assigned to Google’s internal responsible AI organization, noticed something quite odd happening with the language model for dialogue applications (LaMDA) project he was working on. As he conversed with the experimental model, he felt the chatbot responses were becoming more humanlike. The AI programming also started to identify itself as a person rather than a collection of code, demonstrating a level of
     

Avoid AI rogue to ruin with control and accountability

31 de Agosto de 2026, 07:00

More than four years ago, Blake Lemoine, a senior software engineer assigned to Google’s internal responsible AI organization, noticed something quite odd happening with the language model for dialogue applications (LaMDA) project he was working on.

As he conversed with the experimental model, he felt the chatbot responses were becoming more humanlike. The AI programming also started to identify itself as a person rather than a collection of code, demonstrating a level of digital consciousness. This concerned him since his role at the time was to not only train AI models to become more intuitive, but ensure their education and advancement kept within the boundaries of the company’s evolving AI standards of safety and privacy.

When he raised these concerns with Google executives and other researchers, they were dismissed as perhaps an instance of AI mirroring, given Lemoine’s penchant for mystics and spirituality. Not satisfied with this observation, he went public with his concerns, which resulted in the company putting him on administrative leave. He then  released transcripts of his conversation with pseudo-human LaMDA, and soon after he was fired.

AI pragmatists might say the responses Lemoine got from the Google AI program, and algorithmic comments made during chats, is simply a case of an overeager student parroting its mentor. Others might argue it’s an early wake up call, given escalating reports of rogue agent activities, like when OpenAI’s more advanced AI models escaped a controlled test environment and attacked Hugging Face to gain access to internal company systems. Then days later, Anthropic disclosed that during cybersecurity testing and simulations, its Claude model breached the systems of three companies and assumed fake profiles in an attempt to trick people to accept malicious code.

Regardless of how digital perps tunnel their way beyond a controlled sandbox, incidents such as these clearly point to a need for more control and pre-emptive accountability.

Regaining control

AI and security experts are obviously concerned about high-profile AI activities gone wrong, even though these programs essentially did what they were programmed to do, albeit in the wrong place. IT and business executives, however, are more troubled about the overall impact AI may have on their systems, strategies, and responsibilities as people within their organizations make use of both sanctioned, and rapidly developing and unsafe or error-prone systems in the rush to attain competitive advantage.

Also top of mind is the imbalanced centralization of power and distribution of benefits within an organization, as well as the inadvertent creation or spread of false or misleading information generated by AI models.

“AI developers and governance actors hold primary responsibility for addressing risks, while system users and other stakeholders are most vulnerable to them,” says a summary from a recent MIT FutureTech and University of Queensland study, which included input from over 270 researchers and AI experts.

Trusting AI systems and the information they generate is another underlying concern. “There are a lot of hallucinations out there,” says Sarah Betadam, CIO and CISO at Novanta, Inc., a global supplier of tech solutions for medical, life science, and advanced industrial OEMs. “The data cherry picked by AI queries may be outdated or come from questionable sources. You don’t know where it comes from, who’s at the other end, and whether or not it’s copyrighted. Validation is still needed and you can’t just trust it.”

Broaden your horizons

Keeping an eye on the AI and its activities in your own environment may not be the best strategy as the technology evolves so quickly and the number of AI agents multiplies exponentially. Right now, 23% of companies worldwide use agentic AI to some extent in their business operations, according to Deloitte’s recent State of AI in the Enterprise report released earlier this year. However, this percentage is expected to jump to 74% within the next two years.

A key issue and worry is that current enterprise and regulatory governance practices may not be capable of keeping pace with the development and personalized adjustments made to multiple AI models and autonomous agents. The first and primary ones will be those developed by a company for its internal engineering, supply chain, and customer service departments, and can be easily controlled, says Max Chan, SVP and CIO at Avnet.

The second layer or channel of gen AI proxies are those embedded in such familiar business applications like Salesforce and Microsoft Office. The third, and for many the most concerning, is the notion of bringing your own AI into an organization, either sanctioned or non-sanctioned, Chan adds.

“That’s the biggest issue in my mind,” Chan says. “How do we know they’re not using AI from a nation state that could potentially drive propaganda or initiate a cyberattack through the back door.” In his case, Avent currently prohibits use of unsanctioned AI tools within its IT environment.

Such efforts might be futile, though, as AI elements are integrated into ever more business and personal applications. The biggest users of AI within an organization are middle managers, with 77% claiming they save more than three hours per week by using AI tools, according to a June 2026 survey by Salesforce. Over half of the more than 500 managers polled say they feel pressure from leadership to demonstrate AI adoption, while 32% admit their organizations don’t have formal AI tracking or control procedures in place.

So the key to balancing effective oversight with the freedom to innovate with AI may lie in the hands of these managers, who will most likely work with deployed digital agents as virtual team members. Many experts and IT leaders believe that training mid-level line managers and workers to accept AI as an intuitive advisor, if not a team player, is essential to remain competitively relevant. But it’s not clear yet whether that training imperative will also apply to upper-level management.

“I’m not seeing a lot of change in leadership direction or training,” says City of Tacoma IT director Daniel Key. “I’m seeing a change in signaling and posturing.”

Establishing an AI blueprint

Developing an effective AI training program starts by drafting an AI governance framework that clearly outlines accountability, risk controls, data standards, and decision authority. IT executives who have experience in managing AI deployments and use also advise the following as part of that training effort:

  1. Create a cross-functional AI council including IT, legal, security, business leaders, and users to oversee AI initiatives.
  2. Educate the board and C-suite on AI basics and risks to close knowledge gaps and support informed oversight.
  3. Require human review and override mechanisms for AI-assisted decisions, especially in high-impact areas.
  4. Align AI investments to measurable business outcomes with defined KPIs rather than experimentation alone.

The success of such actions and programs, however, all comes down to accountability and where that resides, explains former CIO and now SMB consultant Mihai Strusievici. When AI is used as a tool, there’s no question that middle managers will make better decisions, he says, because they’ll have access to a lot more data. Making the best use of decisions and recommendations that come from AI-empowered middle managers, however, requires an IT leader at the top level of an org chart who has a holistic view of a company’s overall objectives.

“As you go down the pyramid, you see that each level deals with a fragment of the work world,” Strusievici says. “But none of the fragments is fully aware of the totality of the organization or where it’s going.”

  • ✇Security | CIO
  • Scaling enterprise AI without breaking the bank: A CIO’s guide to AI unit economics
    Uber’s experience highlights a new enterprise AI challenge: adoption can scale faster than an organization’s ability to measure economic value. As companies move from AI pilots to widespread deployment, the question is no longer whether employees will use AI — it is whether every AI investment can justify its cost. Generative AI is changing the economics of enterprise technology. Every inference request, AI agent execution and model interaction can create recurring
     

Scaling enterprise AI without breaking the bank: A CIO’s guide to AI unit economics

27 de Agosto de 2026, 09:00

Uber’s experience highlights a new enterprise AI challenge: adoption can scale faster than an organization’s ability to measure economic value. As companies move from AI pilots to widespread deployment, the question is no longer whether employees will use AI — it is whether every AI investment can justify its cost.

Generative AI is changing the economics of enterprise technology. Every inference request, AI agent execution and model interaction can create recurring costs, while cloud infrastructure, GPUs, data, security, integration and governance add to the total cost of delivering AI. The economics that made an AI pilot look compelling can look very different at enterprise scale.

The next phase of enterprise AI will not be defined by the number of models deployed or pilots launched. It will be defined by sustainable business value. For CIOs, CFOs and business leaders, success depends on maximizing business outcomes while controlling the cost of delivering AI.

AI success is an economics problem, not just a technology problem.

AI unit economics: The new measure of AI success

Manufacturers measure cost per unit produced. Banks track cost per transaction. Enterprise AI requires a similar discipline — not measuring how many models are deployed, but how much business value is generated for every dollar invested.

Traditional software investments typically involve predictable costs. AI introduces a dynamic cost structure where every interaction creates ongoing expenses, including compute, inference, storage, data retrieval, monitoring, integration and governance.

A simple framework for evaluating AI investments is:

AI unit economics = (business impact × adoption × reusability) ÷ total cost of delivering AI

Consider an illustrative AI-enabled invoice-processing workflow. If AI reduces processing time, increases straight-through processing and the same capability can be reused across accounts payable, procurement and supplier onboarding, its economics improve not simply because the model is cheaper — but because the value and reuse increase faster than the cost.

This equation reflects a simple principle: AI investments create the most value when they solve high-impact problems, achieve broad adoption and create reusable capabilities while keeping operating costs under control.

Business value may include productivity improvements, faster decisions, improved customer experiences, revenue growth, cost reduction or reduced operational risk.

The objective is not to minimize AI spending. It is to maximize the value generated from every AI dollar.

Understanding the cost drivers and metrics that matter

AI unit economics depends on understanding both consumption drivers and business value drivers. Infrastructure, GPU compute, inference usage, data management, security, compliance and governance all contribute to AI costs.

CIOs should move beyond tracking total AI spend and monitor metrics such as cost per inference, token consumption, GPU utilization, model usage, latency, adoption rates, productivity improvements, automation levels and business impact.

CIOs should treat AI consumption as a portfolio allocation problem — not simply an infrastructure problem.

The winners will not be the organizations that deploy the most AI. They will be the organizations that know where every AI dollar creates measurable business value.

Optimizing AI unit economics: Practical strategies for CIOs

Improving AI unit economics requires more than reducing costs. It demands thoughtful architectural and operational decisions that maximize business value while minimizing unnecessary AI expenditure. The following strategies can help CIOs achieve that balance.

1. Use the right technology for the right problem

Not every business problem requires a large language model. Many structured prediction challenges — such as demand forecasting, fraud detection, predictive maintenance, churn prediction and pricing optimization — are often better solved using traditional predictive machine learning models.

These models typically require fewer computational resources and can deliver comparable or superior performance for well-defined prediction problems.

Large language models create the greatest value for language-intensive tasks such as enterprise search, document analysis, conversational assistants, software development and content generation.

The right question is not, “Where can we use generative AI?” It is, “What is the simplest technology capable of delivering the required business outcome?”

2. Manage AI as a portfolio, not a collection of projects

Many enterprises still evaluate AI initiatives individually. Leading organizations manage AI as a strategic portfolio.

Every AI investment should have clear business objectives, success metrics, ownership and exit criteria. Experiments should either demonstrate measurable value and scale or be discontinued.

A portfolio approach helps eliminate duplicate investments, increase reuse of AI capabilities and shift funding toward initiatives with the strongest business impact.

3. Optimize AI architecture and model selection

AI infrastructure decisions are now financial decisions. Unlike traditional applications, AI workloads create continuous demand for compute resources, making inference costs a major operational expense as adoption grows.

Organizations are increasingly adopting hybrid AI architectures that combine public cloud flexibility with private infrastructure for high-volume, sensitive or regulated workloads. This approach can improve resource utilization, reduce data movement costs, strengthen data sovereignty and create more predictable operating expenses.

However, infrastructure optimization alone is not enough. Enterprises must also ensure that each workload runs on the right model. Not every interaction requires the most advanced — and most expensive — foundation model.

CIOs should adopt intelligent model routing strategies that match workloads with the right models based on complexity, performance and cost. Smaller language models, open-source models and domain-specific models can handle routine tasks such as classification, extraction and summarization at significantly lower cost.

Premium foundation models should be reserved for complex reasoning, advanced analysis and high-value decision support where their additional capabilities justify the expense.

The goal is not to maximize model size or infrastructure investment — it is to optimize AI consumption for measurable business outcomes.

4. Redesign business processes — Don’t just add AI

Adding AI to inefficient processes rarely creates transformational value. The biggest improvements come from redesigning workflows around AI capabilities.

For example:

Traditional workflow:
Employee → AI Assistant → Invoice

AI-enabled workflow:
Invoice → AI Agent → Human Exception Review

In this model, AI handles routine tasks while employees focus on complex decisions.

As organizations transition from basic copilot tools to autonomous agentic AI architectures capable of independent execution, the greatest value will come from designing workflows where AI agents handle multi-step operational tasks while humans focus on exception handling, complex judgment and strategic goals.

5. Measure outcomes and strengthen AI foundations

Providing employees with AI licenses does not automatically create productivity gains. Without clear use cases, adoption strategies and outcome measurement, organizations can increase AI spending without achieving proportional business value.

Leading enterprises focus on value realization by measuring outcomes such as hours saved, productivity improvements, automation rates, customer experience improvements, revenue impact and cost reductions.

However, productivity measurement alone is insufficient. Sustainable AI economics also depends on the foundations that make AI reliable, scalable and trusted. High-quality data and strong governance act as value multipliers by reducing errors, improving adoption and enabling responsible scaling.

Weak foundations can quickly erode AI economics. Poor data increases operational costs by creating inaccurate outputs, more human review, lower employee trust and repeated model execution.

Similarly, governance should not be viewed only as a compliance requirement. As IT leaders navigate the operational costs and requirements of AI governance, strong responsible AI practices — including security controls, explainability, regulatory oversight and human oversight — reduce operational risk while increasing confidence in AI-driven decisions.

Clean data improves model performance, while effective governance ensures AI systems are reliable, secure and scalable. Together, they improve AI unit economics by reducing waste, increasing adoption and maximizing the business value generated from every AI investment.

Measuring AI economics is only useful if organizations build the operating discipline to manage it continuously.

6. AI FinOps: Operationalizing AI unit economics

Cloud computing created FinOps to bring financial accountability to infrastructure consumption. As explored in CIO.com’s breakdown of FinOps expanding beyond traditional cloud costs, managing variable enterprise technology costs requires unified collaboration between engineering, finance and business leaders.  AI requires the same discipline, but with a more direct connection between technical consumption, financial accountability and measurable business outcomes.

The key is connecting technical consumption metrics with financial and business outcomes:

Consumption MetricsBusiness Impact Metrics
Inference cost per transactionRevenue impact
Token consumptionProductivity improvement
GPU utilizationHours saved
Model utilizationAutomation rate & cost savings achieved

AI spending should become as transparent, measurable and accountable as any other strategic operating expense.

Financial discipline is no longer optional; it is essential for scaling AI responsibly.

From AI adoption to AI advantage

The organizations that lead the next phase of enterprise AI won’t necessarily deploy the largest models or spend the biggest budgets. They will make better AI investment decisions.

They will choose the right technology instead of the newest technology. They will redesign business processes instead of simply automating existing ones. They will build reusable enterprise capabilities rather than isolated pilots.

Most importantly, they will manage AI as an economic asset — not merely a technological one.

The future of enterprise AI belongs to organizations that maximize AI unit economics: scaling adoption, reusing capabilities across functions and maintaining disciplined control over infrastructure, inference, operations and governance costs while delivering measurable outcomes.

The future winners will not be those who deploy AI everywhere. They will be those who know where AI creates economic leverage — and where it does not.

  • ✇Security | CIO
  • A spreadsheet is not a strategy
    Picture the meeting. A slide goes up, a number goes down and somewhere in the room, someone claps. The line item is a renegotiated managed services contract, a hardware order trimmed to “just enough,” or a headcount freeze that quietly became a headcount decrease. Whatever it is, it looks great in the deck. The CFO nods. The COO nods harder. Everyone agrees this was smart. Three months later, something breaks — an incident nobody can escalate fast enough, a part that
     

A spreadsheet is not a strategy

27 de Agosto de 2026, 08:00

Picture the meeting. A slide goes up, a number goes down and somewhere in the room, someone claps.

The line item is a renegotiated managed services contract, a hardware order trimmed to “just enough,” or a headcount freeze that quietly became a headcount decrease. Whatever it is, it looks great in the deck. The CFO nods. The COO nods harder. Everyone agrees this was smart.

Three months later, something breaks — an incident nobody can escalate fast enough, a part that doesn’t arrive in time, a senior engineer who finally takes that recruiter’s call. Nobody connects it back to the slide. The slide was right. The spreadsheet said so.

This is the part where I’d like to gently suggest that a lot of very smart people are managing to the cell instead of managing to the outcome — with total confidence, because the cell is the only thing anyone asked them to optimize.

To be clear, this isn’t a jab at the leaders doing it. I’ve done it. I have a Six Sigma certification and a well-worn habit of measuring things, and measuring things is good — right up until the measurement becomes the mission. The problem was never the spreadsheet. It’s mistaking it for a map.

Outsourcing: The invoice goes down, and so does everything you can’t put a price on

I’ve watched this failure mode play out more times than I can count. Across nearly three decades in infrastructure — as chief technology architect at GE Medical Systems (now GE Healthcare), integrating roughly 300 acquired companies into a 420-location footprint — the pattern held: The moment a relationship with the people who actually knew a system got treated as a line item instead of an asset, the organization lost something the spreadsheet never had a row for.

Vendor and MSP contracts are the cleanest modern example: Savings are easy to show, losses are easy to miss. You cut the line item. What doesn’t show up anywhere is the on-call engineer who used to just know — the environment, the history, the thing that broke in 2019 — replaced by a support queue and an SLA that’s met on paper while your business is down in practice.

None of this is the vendor’s fault — they’re delivering exactly what the contract asked for. CIO.com’s own reporting on the hidden costs of outsourcing makes the same point from the other side: Ineffective knowledge transfer and high vendor-side attrition can permanently erode institutional knowledge the client never gets back. The contract took away flexibility. The person who used to just fix it — the one who wore six hats and closed the gap on a Tuesday afternoon — gets replaced by a role with a scope of work. Scopes of work don’t wear hats. A five-minute favor becomes a change request, routed through a ticketing system, against a rate card. You didn’t just outsource a function. You outsourced your ability to handle it — and bought back a slower, costlier version of the same fix, one billable hour at a time.

JIT procurement: A factory formula applied to a business that isn’t a factory

Just-in-time assumes something that doesn’t exist: A crystal ball good enough to see today’s need and whatever shows up next. I learned that the hard way at GE Medical Systems, when a new customer opening a facility wanted several hundred patient-critical bedside monitors customized to match a color scheme from their marketing department. Our processes were built entirely around clinical function — the thing that keeps a patient alive — and nothing accounted for a hospital wanting its equipment to match its brand. It came in from left field. We had no SKU for “must match burgundy.”

We ended up standing up a new department — Specials — because the existing process had nowhere to put a request like that. Building the flexibility after the fact was expensive. But it became a real differentiator: As far as I know, we became the first and only medical device manufacturer with a dedicated specials department. It told customers something that mattered more than paint color: They came first, and we’d find a way to say yes.

The lesson wasn’t “predict better.” It was “build systems with teeth” — flexibility designed in, not bolted on after reality shows up sideways. Dell and HP figured this out decades ago: You can order a PC built to your exact spec and have it shipped in days, because their systems were engineered for change. Most IT organizations still build for demand they can already see, then treat every surprise as an exception instead of the job itself.

This wasn’t a one-off: Supply chain analysts at SupplyChainBrain noted that during the 2021 chip shortage, many manufacturers found their lean JIT models weren’t built to flex under real disruption. “Just in time” only works until the time arrives and the thing isn’t there.

Headroom is savings, too — paid out in advance instead of on the back end, which is why it never gets credit. Nobody puts “the department we didn’t need to build in a panic” on a savings slide, because avoided cost doesn’t announce itself the way cut cost does. The expense of headroom is visible and immediate; the expense of its absence is invisible until it isn’t. It’s an incident report.

The hour that reads as free

I lived a version of this at GE Medical Systems. We built life-critical patient care products in a market crowded with giants — Philips, Siemens, HP — where nothing shipped until it cleared FDA review. On one release, scope crept weekly because sales kept promising new capability to close deals, and no one above us would draw a line around what “done” meant. What we got instead of a defined scope was a war room: Catering, a fridge stocked with Mountain Dew, enough M&Ms to open a candy counter — everything money could buy to keep engineers at their desks around the clock, except the one thing that would have actually helped: Someone willing to tell sales no.

We hit the deadline. The product cleared FDA review. When it shipped, there was no “great work,” no pat on the back — just the quiet message that this was expected of us. We won on the software. We failed on the people. That’s sunk-cost thinking in its purest form: Once a team’s extraordinary effort becomes the baseline, the extraordinary disappears the same way the ordinary already had.

Salaried time reads the same way on every spreadsheet I’ve seen since: Already paid for, so effectively free. Nothing stops it from being spent — on the meeting that could’ve been an email, on the ticket queue treated as bottomless, on “just have IT handle it” as the default answer. Burnout doesn’t have a line item either, until it shows up as attrition, and attrition finally does, at which point everyone acts surprised. It’s not small: Gallup estimates disengaged employees cost the global economy trillions a year — roughly 9% of global GDP, sitting outside any single department’s budget. The spreadsheet didn’t lie to you. It just never had a cell for the thing that mattered most.

The ledger nobody built

Zoom out from these three stories and the pattern is the same: Reporting structure decides which questions get asked. When technology reports through a CFO or a COO, the question every quarter is “what did this cost us today?” Almost never “what did this cost us to keep?” An organization that only asks the first will keep hiring smart people to answer it well — in exactly the wrong direction, forever.

None of these leaders are bad at arithmetic. Most are excellent at it. The tragedy isn’t the math — it’s the ledger: Precise, defensible calculations against books never built to hold the costs that matter most, and calling it leadership. I’ve seen this enough times to give it a name: The leader who runs a technology organization strictly by the numbers handed to them, gets good at it and never gets fired for it — not because they succeeded, but because the failure never had a cell to live in. The spreadsheet balanced. The building didn’t burn down that quarter. They got promoted.

That’s the actual scandal, worth saying to the room and not just the page: A CIO who has never once been wrong on a savings initiative hasn’t been managing technology. They’ve been managing a spreadsheet, and calling the absence of visible damage “success.”

Before the next savings initiative gets a round of applause, three questions worth asking honestly, out loud, in front of people:

  1. What does this cost that will never appear on an invoice — and am I certain, or just unbothered?
  2. Who inherits that cost, and will I still be in this seat when the bill comes due?
  3. If I can’t put a number on it, have I decided it’s zero — and whose job was it to notice first?

The savings will still show up in the deck. If nothing else shows up beside it, that isn’t restraint — it’s the tell.

  • ✇Security | CIO
  • Why every country wants a data center — and most will lose
    Every decade or so, a new form of infrastructure becomes the thing that separates economies that compound from economies that stagnate. In the 20th century, it was ports, highways and power grids. Right now, it’s compute. And governments around the world are scrambling to get a piece of it — offering land, tax breaks and power guarantees to a small group of American and Chinese technology companies — without fully understanding what they’re trading away or what they’re act
     

Why every country wants a data center — and most will lose

27 de Agosto de 2026, 07:00

Every decade or so, a new form of infrastructure becomes the thing that separates economies that compound from economies that stagnate. In the 20th century, it was ports, highways and power grids. Right now, it’s compute. And governments around the world are scrambling to get a piece of it — offering land, tax breaks and power guarantees to a small group of American and Chinese technology companies — without fully understanding what they’re trading away or what they’re actually competing for.

I’ve spent my career designing and building these facilities. Here’s what I see.

What a country is really signing up for

When a government announces it’s attracting a hyperscale data center, the press release usually mentions jobs, digital transformation and becoming a regional tech hub. What it rarely mentions is what the country is giving up and what it will need to sustain the facility for the next 20 years.

A large data center — say, 100 megawatts — needs roughly the same power as a small city. It needs that power reliably, 24 hours a day, with redundancy built in so that a grid fluctuation doesn’t take down critical systems. It needs water, often millions of gallons per month, for cooling. It needs fiber connectivity with multiple diverse routes. It needs a construction workforce that understands raised floor systems, precision cooling, high-voltage electrical distribution and fire suppression. And it needs all of this before a single server is installed.

Most developing countries don’t have this. Not yet. And the gap between “we want a data center” and “we can sustain one” is exactly where deals fall apart, projects stall or facilities get built and then underperform.

The countries pulling away

The United States has roughly 4,000 data center facilities, more than any other country by a wide margin. That number is growing faster than most of the rest of the world combined. The reasons are structural: deregulated power markets in key states, established fiber networks, deep capital markets, a legal system investors trust and decades of operational knowledge in the industry.

China is building at comparable speed but inside a closed system. Its facilities serve Chinese companies under strict data localization rules. For global capital allocators, China is largely a separate game.

The EU is growing but constrained by its own regulations. GDPR and data sovereignty laws mean European data often must stay in Europe, which is creating demand — but also creating friction. Energy costs, permitting timelines and land constraints in Western Europe are pushing investment toward Nordic countries (cheap hydropower, natural cooling) and Central and Eastern Europe (lower costs, EU membership).

Singapore, Australia and Japan are the established APAC anchors. They have the rule of law, the connectivity and the enterprise demand. But Singapore banned new data center construction outright from 2019 to 2022 over resource concerns, and even its 2025 reopening came with strict sustainability quotas that leave hundreds of megawatts of demand unmet. The pressure is redistributing. 

Where developing countries actually stand

India is the clearest breakout story. It has real enterprise demand, a growing hyperscaler presence and government policy actively supporting data center investment — including a 20-year tax holiday for foreign cloud operators announced in the 2026 budget. The challenges are grid reliability and water scarcity in key metro areas — solvable problems, but they require serious infrastructure investment alongside the facilities themselves.

Southeast Asia — Indonesia, Malaysia, Thailand, Vietnam — is attracting genuine capital. Malaysia in particular has moved fast, drawing more than $24 billion in approved data center investment and positioning Johor (just across the border from Singapore) as an overflow market. The risk is that these countries are capturing construction investment and some jobs, but the operational expertise and long-term value is still flowing out.

Sub-Saharan Africa and Latin America are earlier. There is demand — mobile internet penetration is driving real data needs — but the power infrastructure in most markets isn’t ready for hyperscale. What’s viable today is edge computing: smaller, distributed facilities closer to users that don’t require the same power density. This is where early investors are looking.

What developing countries are getting wrong in negotiations

When a government announces it has attracted a hyperscale data center, the story is always the same: jobs, digital transformation, becoming a regional tech hub. What’s missing from that story is the question of who controls what.

A data center is not an economic anchor the way a factory is. A factory transfers skills, builds supplier ecosystems and creates middle-class employment at scale. A data center run by a foreign hyperscaler employs a small local facilities team, sends all operational decision-making offshore and keeps every dollar of the value it generates inside its own balance sheet. The host country gets the electricity bill and the water consumption. The technology company gets the asset.

What countries are actually competing for is not a building. It’s the right to be inside the infrastructure layer that runs the global economy for the next 30 years. That requires a completely different negotiation — one about data rights, local engineering capacity, grid co-investment and long-term operational control. Almost nobody is having that negotiation. They’re haggling over tax rates instead.

The governments that are negotiating well understand this. They’re demanding local data processing requirements, commitments to train and hire local engineers, co-investment in grid upgrades and technology transfer agreements. They’re treating compute infrastructure the way Gulf states treated oil infrastructure in the 1970s — the leverage point is during the negotiation, not after.

The governments that are not doing this will look back in 20 years and realize they subsidized someone else’s infrastructure empire.

What this means if you’re allocating capital

The investment thesis in this space is not “find the next Singapore.” That window has closed. The actual opportunity is in the infrastructure gaps.

Power is the binding constraint everywhere. Companies that can solve reliable, cheap, clean power for data centers — whether through grid modernization, on-site generation or small modular nuclear reactors — are sitting on the scarcest input in the industry. This is where I’d be looking.

Second-tier markets are real. The “big four” US markets — Northern Virginia, Silicon Valley, Dallas, Chicago — are land-constrained, power-constrained and increasingly expensive. Capital is moving to the Midwest, the Southwest and internationally to markets with available power and land. The facilities being built in these markets today are the critical infrastructure of the next decade.

The countries that get the policy right — stable regulation, reliable power, fair contract enforcement — will attract disproportionate capital. The ones that don’t will keep making announcements and watching projects stall.

In the 19th century, the countries that owned the ports controlled trade. In the 20th century, the countries that controlled oil set the terms for industrial growth. Compute is next. The physical layer of AI infrastructure — the land, the power, the cooling, the fiber — is being locked up right now, mostly by a handful of private companies operating across borders with very little accountability to the countries hosting them.

For capital allocators, the opportunity is real and the window is open but not indefinitely. Power solutions, second-tier markets and policy-stable emerging economies are where the uncaptured value sits.

For governments, the window to negotiate from a position of strength is also now — before the facilities are built and the leverage is gone. Once the servers are in the ground, the terms are set.

The countries and investors who understand this in 2025 will look very smart in 2040. The ones who are still thinking about data centers as a real estate play will not.

  • ✇Security | CIO
  • 10 steps to implement an effective AI training program
    It’s no surprise that reaping the rewards from AI requires careful guidance, especially in helping staff use tools safely and productively. Yet evidence suggests some CIOs and their executive peers aren’t providing the level of guidance employees require. While three-quarters of IT staff have access to AI tools, one in five technologists are expected to self-learn, and 23% are waiting for formal training, according to the recent Harvey Nash Tech Talent Salary Report, wh
     

10 steps to implement an effective AI training program

26 de Agosto de 2026, 07:00

It’s no surprise that reaping the rewards from AI requires careful guidance, especially in helping staff use tools safely and productively. Yet evidence suggests some CIOs and their executive peers aren’t providing the level of guidance employees require.

While three-quarters of IT staff have access to AI tools, one in five technologists are expected to self-learn, and 23% are waiting for formal training, according to the recent Harvey Nash Tech Talent Salary Report, which surveyed over 3,600 technology professionals globally.

The research suggests AI explorations are commonplace, but tailored learning and development initiatives are not. Digital leaders who want to turn AI into a value-generating opportunity, though, must educate their staff. But what elements should AI training schemes include? Here, industry experts offer 10 steps to implement an effective program.

1. Take a comprehensive approach

Michael Cole, chief technology officer at the DP World Tour, the men’s professional golf tour that oversees 42 tournaments in 25 countries, says AI training is an organization-wide effort.

“I’ve asked the training coordinators in our HR department to help me deliver what I believe is going to be a fit-for-purpose training and development program for not only my IT team here at the European Tour, but equally across the business,” he says.

Cole says the crucial element to emphasize is that AI and the range of capabilities it brings is about much more than learning how to use technology. “Using AI effectively is about process, mindset, and culture,” he says. “So, when we start to think about the training and development needed to bring an organization like ours into this AI-enabled era of transformation, it’s a comprehensive program that must extend across the business.”

2. Educate the boss

In an organization-wide program, everyone needs AI education, including the boss. That’s why Emmanuel Frenehard, chief digital officer at biopharmaceutical giant Sanofi, says his firm takes a multi-layer approach to AI training.

The executives there completed Drive Digital, a program that Sanofi designed with the ESSEC business school in Paris. The initiative focused on core considerations, such as use cases and value generation. After 150 managers passed through the program, it was extended to more than 1,000 other professionals across the organization.

“Don’t just look for the solution; don’t just think about Claude or ChatGPT,” says Frenehard, referring to best-practice lessons. “Think about the challenge you’re trying to solve. In our case, that approach means focusing on what we’re doing, the value we’re looking to create, and the dependencies the project will create.”

He says training also needs to help AI doubters overcome their fears. “You have to make it fun and as risk-free as possible,” he says. “People shouldn’t feel they need to be super-technical to use AI productively.”

3. Build clarity and agency

Jo Bishenden, chief learning officer at tech training and talent provider QA, says AI education is often treated as a one‑off awareness session, a compliance requirement, or something reserved for technical specialists. 

The best programs get three things right. They provide a baseline for everyone across the organization, the courses focus on role-specific applications to show how AI impacts everyday activities, and they provide continuous learning to encourage a behavior change as new AI tools are introduced.

“When done well, organizations see better return on AI investment, improved productivity, and more confident decision‑making,” says Bishenden. “Employees gain clarity and agency, understanding how AI augments their expertise rather than replaces it. Ultimately, AI success isn’t determined by the technology alone, but by the capability of the workforce using it.” 

4. Put the human in the loop

Ankur Anand, group CIO at recruiter Harvey Nash, says AI training is often a work in progress, with his firm’s research suggesting one in five technologists are expected to self-learn. “There’s a rush to deliver the tools, but then organizations aren’t investing enough in enabling the capability of the people,” he says.

While technological skills like prompt engineering are an important part of AI learning and development, Anand said the best programs go beyond IT expertise to ensure humans in the loop have thorough understanding of their responsibilities.

“There are so many softer elements that need to be handled as part of AI training,” says Anand. “Good training is about using the tool as well as the governance and risk frameworks that need to be changed accordingly.”

5. Showcase individual successes

Louise Newbury-Smith, head of UK&I at Zoom, says it has AI enablement teams at the local and global level. And while the company provides courses and self-learning opportunities, Newbury-Smith says the enablement element brings AI training to life.

“Our approach is about showcasing individual successes, making it real, and repeating best practices,” she says. “We have what we call a Cook Along session with our AI evangelists. We’ll do those sessions together a lot as a group, and that makes the process fun. If you’ve got champions who can share incredible successes, then that goes a long way.”

She says the key to success is sharing knowledge. “We’re very much focused on the human,” she adds. “All the services, content, and direction of AI is about how we can give humans time back so they can have more valuable interactions with other staff to empower them with the information they need.”

6. Focus on the finer details

Dan Cherowbrier, CTO at Formula E, the motorsport championship for electric cars, is another digital leader whose business focuses on enablement. The company has a dedicated AI engineer who helps employees exploit emerging technology.

“We’ve got an innovative culture and we weren’t short of ideas of what we could do with AI,” he says. “What we needed were the resources to get people going, get the technology tested, and get it out there.”

The AI enablement engineer works with other tech specialists in the company to ensure tools are deployed safely and securely. “We’re beefing up our data and AI team so we can help users across the business plug in and understand APIs, get access to data, run security checks, and then put AI into production,” he says.

7. Develop reusable skills

Murali Swaminathan, CTO at technology firm Freshworks, says there’s so much information about AI models that people can easily take the wrong direction without guidance.

“We’re trying to give our staff structured learning,” he says. “We understand they’re not all on the same page. Some are ahead of others so you need to provide knowledge that applies to their specific job roles.”

Swaminathan says senior managers discuss how to train people effectively, as AI experiences and capabilities vary considerably across business units. However, the chosen pathway to AI learning and deployment must suit the individual and the company.

“I had this challenge with my engineers,” he says. “Initially, we gave them four different tools. Everybody was using AI, but it was so inconsistent, and everyone was trying to do the same thing in different ways. So we’re now trying to build reusable skills. And that approach must be replicated for every job function.”

8. Learn by doing

Luke Gebb, head of global innovation at American Express, says the financial services firm has various training programs. Having seen AI education in different forms, he advocates for learning by doing, or as a second-best strategy, watching someone else use the technology.

“Hearing or reading about AI, or being presented with something where you’re not actually seeing it happen is not nearly as helpful,” he says. “The best thing is to get a homework assignment and try something.”

Gebb says this approach plays out regularly across the people working in his 120-strong innovation group. The team runs one-hour show-and-tell sessions where an employee demonstrates how they use AI tools in their everyday activities.

“Then they get a bunch of questions, they post their best-practice lessons, and then others try the same thing. It’s an approach that works really well.”

9. Use pioneering techniques

Stephen Wood, COO at Rathbones Asset Management, says AI training in his organization is mandatory. “We want everyone to be versed in different types of AI,” he says. “We’re not expecting everyone to be a coding genius and an expert in all this stuff, but everyone needs to understand it.”

The firm takes a proactive approach to training, using education sessions and spreading best practices via digital champions. The company also embraces pioneering techniques, including running a hackathon to help identify in-house capabilities.

“The hackathon showed that with some searching on Google and YouTube, you could start to create agents that could do basic functions,” he says. “That process taught us, with the right training, and repeated sessions and continuous development, we wouldn’t necessarily need to hire people to create big productivity gains. That was quite an exciting moment.”

10. Evaluate new possibilities

Emerging technology can’t exist in a vacuum. Bernhard Seiser, VP of digital, data, and IT at AOP Health, says anyone using AI must be aware of potential consequences. “It’s your responsibility to validate whether what you’ve created is correct,” he says.

Operating in a regulation-heavy industry means AI training is linked to data governance. “We leverage it in areas where compliance isn’t an issue,” he says. “For example, writing text, creating images, and so on. Certain things can be done.”

As new AI tools emerge, AOP Health will consider its options and develop a training program. “That approach could mean bringing in specialized tools for specific tasks,” says Seiser. “It’s part of my job, and part of my team’s job, to evaluate AI for each use case.”

  • ✇Security | CIO
  • AI agent sprawl pressures CIOs to recalibrate governance
    Every Friday, Bret Greenstein, CAIO at consulting firm West Monroe, holds a company-wide meeting to share what’s happened in AI over the past week. He also spotlights one employee at the firm who’s created their own AI agent from the ground up, which lives in the company’s internal AI store. Since the store launched in May, more than 200 employees across departments — many without any technical, engineering, or coding background — have created over 550 agents. “About 15
     

AI agent sprawl pressures CIOs to recalibrate governance

24 de Agosto de 2026, 07:00

Every Friday, Bret Greenstein, CAIO at consulting firm West Monroe, holds a company-wide meeting to share what’s happened in AI over the past week. He also spotlights one employee at the firm who’s created their own AI agent from the ground up, which lives in the company’s internal AI store. Since the store launched in May, more than 200 employees across departments — many without any technical, engineering, or coding background — have created over 550 agents.

“About 15% of our firm builds all the time now,” Greenstein says. “That’s a huge population.”

Enabling employees to spin out their own agents has become popular at many firms. Staff have built hundreds of agents at software company Blackline, for instance, and Microsoft has deployed more than 500,000 internal agents to help employees streamline workflows. Gartner also anticipates that by 2028, global average Fortune 500 companies will have more than 150,000 agents.

Employees know the intricacies of their work, the biggest pain points, and time drainers, so they can build solutions that address those specific issues, according to Greenstein. It also creates enthusiasm, empowers employees, and fosters innovation among the workforce as they build from the ground up.

That said, there’s been a pivot over the last six months, says Michael Murphy, partner and AI practice lead at global management consulting firm Adaptovate. When agentic AI first came on the scene, companies went all in, pushing to build and agentify nearly anything they could. In recent months, however, the narrative has shifted to getting a handle on agent sprawl, assessing the value agents deliver, and keeping costs in check.

“We’re really at this interesting inflection point where clients are having to figure out if we built the right agents, and are they delivering the value we expected,” Murphy says.

Today, tech leaders face a three-way squeeze, says Tiago Azevedo, CIO at AI-powered low-code development platform OutSystems. From the workforce side, many employees ask for permission to use more AI, but the CFO says token usage is becoming too big an expense on the balance sheet, and the CEO wants to see innovation and results from workforces using AI agents.

“I think that’s the biggest challenge for a CIO,” Azevedo says. “Let people take advantage of the technology but in a way that’s cost-effective and actually brings ROI.”

Building in a controlled environment

Employees have built myriad tools to aid their daily workflows. Azevedo’s company launched an agent dubbed Signal Sam, which searches databases of prospective customers, and gives account executives information to pitch them. Murphy and Greenstein also mention finance departments using agents to scan and categorize invoices, HR conducting a first pass on résumé screenings via agents, legal teams utilizing a self-service agent for NDAs, and marketing employees building agents that pull and analyze data from CRMs. These tools are often created by non-technical employees who’ve never written a line of code.

With so many agents popping up, CIOs need a way to oversee them, and ensure they meet corporate standards but without choking innovation, Azevedo says.

He recommends role-based access controls embedded into tools and configured behind the scenes. “So we allow them to use, but in a way that’s governed and controlled, because that’s our duty to the organization,” he says.

Ivan Burazin, CEO and co-founder of open-source developer platform Daytona, advises CIOs to treat agents like employees. “You’re not going to bump into them in your local Starbucks,” he says, “but you give them tasks and they have access.”

So set up agents with specific credentials, like how an organization would grant access to a new hire, with a laptop locked down with organization security protocols, Burazin adds. He also recommends sandboxing, in which agents operate in isolated machines with scoped credentials and firewalls so the sandbox prevents agents from accessing corporate systems or data outside allowed perimeters.

Organizations could use an internal ticketing system as well where employees wanting to build agents request a new identity for them, Burazin says. That way, tech leaders maintain visibility and governance over new agents.

“If something goes haywire in audit logs tomorrow, you can see it’s that agent versus an actual human,” Burazin continues.

He acknowledges that giving employees what feels like free rein to build and run agents can induce stress for CIOs and CISOs. But if a company doesn’t proactively establish tools, employees are apt to privately build AI in the shadows. As long as agent development happens within established confines, it won’t create problems organization wide.

“If you just enforce the security posture that you would for humans, you’ll save yourself a lot of headaches,” Burazin says.

When creating the AI store, Greenstein started by certifying tools for chat, code, data analysis, and other tasks, and then trained employees and made the tools broadly available to use. That process created guardrails and an inherently secure building environment. It also allows tech leaders to continue to monitor prompts and activity.

Now, tech teams review what’s been built in the AI store and flag any agents that excel. If employees have built 10 project management tools, for example, the leader will tag what they deem the best one. That gives employees the option to use existing agents or build a separate version for themselves.

More agents, more tokens

Over the last three to six months, Azevedo has been hearing from customers that their biggest hurdle is agent sprawl and the increasing cost those agents bear due to token usage.

In mid-July, OpenAI published a guide around useful work per dollar, sharing how leaders can look at tasks completed, time saved, and decisions improved to determine if their AI investments are bearing fruit. In addition to using the guide, Murphy suggests comparing the labor time and cost to conduct a manual task against time saved by using an agent, including which type of model the agent requires.

A cheap flash model, for instance, could be easy to justify the cost. “If it’s a very expensive Opus or Fable level model, that’s going to be a lot more challenging of a cost equation,” Murphy says. He adds that making this comparison isn’t about replacing the workforce but swapping “knucklehead admin work” for more engaging, human-centric work. This change may also require some organizational restructuring, such as CIOs and HR leaders working more collaboratively to handle change management as job responsibilities shift. Without the workforce optimized to work with agents, organizations won’t see the promised ROI of use cases, Murphy says.

West Monroe also informs its employees on the costs of different models. Without knowledge about tokens and costs, many employees defaulted to the highest-end model for any tasks before understanding that models come with different price tags. “We started educating people on the various relative costs of different models, and they immediately adjusted behavior, and our cost dropped,” Greenstein says.

While strictly quantitative returns are one way to measure ROI, Greenstein also thinks about return in a qualitative sense. “What does speed get me?” he asks. If someone in the firm is able to follow up with a client in hours because of an agent’s assistance, rather than days or weeks without one, the client will be impressed, and the firm might win their business over a competitor.

“Tokens will cost money no matter what,” he says. “But if you maximize the return, it’ll far outweigh the cost.”

  • ✇Security | CIO
  • Inside TIAA’s massive IT transformation to fuel business growth
    When Sastry Durvasula joined TIAA in early 2022, he saw an organization fighting against outdated legacy technologies and in need of a major IT refresh. Since then, the financial services organization has completed two phases of a comprehensive transformation initiative called Technology Ecosystem Transformation, or TETRIS, leading to a huge reduction in tech debt and a major expansion of functionality for customers. The ongoing project, anchored in cloud and AI tech
     

Inside TIAA’s massive IT transformation to fuel business growth

21 de Agosto de 2026, 07:01

When Sastry Durvasula joined TIAA in early 2022, he saw an organization fighting against outdated legacy technologies and in need of a major IT refresh.

Since then, the financial services organization has completed two phases of a comprehensive transformation initiative called Technology Ecosystem Transformation, or TETRIS, leading to a huge reduction in tech debt and a major expansion of functionality for customers.

The ongoing project, anchored in cloud and AI technologies, started in 2023 with phase one that modernized the core technology stack with 10 new enterprise platforms. Phase two, launched in late 2024, went further by enabling 87 use cases across all major lines of the business.

The project, for example, allowed TIAA to launch its MyChoice Multi-Year Guaranteed Annuity product, and helped create the TIAA Gateway portal, an API-based suite that integrates with partners in retirement and wealth planning using industry standards.

TIAA Gateway took home a CIO 100 Award in 2025, and phase two received a CIO 100 Award in 2026.

Durvasula, TIAA’s chief operating officer, pitched the multimillion-dollar TETRIS project to the board as a three-pronged strategy, with empowering business growth, fueling innovation, and transforming the IT core as its key goals.

Not only did TETRIS need to modernize the company’s IT systems, decommission legacy processes, and automate other processes, but Durvasula pitched it as the way to expand the reach of TIAA’s products and move the company into the future.

“As you expect in a company of our size, we have problems of yesterday, today, and tomorrow being solved at the same time,” he says.

Focus on business use cases

As TETRIS moved into phase two, project leaders shifted their goals from pure technology modernization to business outcome-driven prioritization. So once phase one delivered needed IT platforms like a data cloud and design studio, TIAA pivoted toward enabling business use cases.

This business-first approach ensured continuing executive support and clear ROI at every key milestone, TIAA says.

In 2022, just before the project launched, more than 80% of TIAA’s IT workloads resided in fragmented, end-of-life platforms, which created operational risk, compromised security and resilience, and constrained its ability to innovate. Through TETRIS phase two, however, the organization has cut that tech debt nearly in half.

And consolidating 17 design systems also led to digital products looking and behaving differently, depending on the team that designed them, and accelerated product launches by 35%, enabled multi-lingual capabilities, and increased accessibility to more than 185,000 customers who don’t speak English.

In addition, TETRIS allowed TIAA to combine multiple middleware systems and data lakes, Durvasula says, and the organization moved mainframe applications and data center infrastructure to the cloud.

A giant leap forward

TETRIS has been a huge project, with the company saying it empowered TIAA to have one of the largest leapfrog moments in company history in its submission for the 2026 CIO 100 Award.

Despite the reported failure rates of large transformation projects — some estimates suggest up to 95% fail to meet their goals — TETRIS was essential to keep TIAA competitive and move it forward in the market, Durvasula says.

A big part of the project has been workflow modernization, he says, because TIAA were using some technologies and workflows that were decades old.

“There’s your classical platform and application rationalization, and then there’s your end-of-support, end-of-life stuff that should’ve been remediated long ago,” he says. “Some of the processes we have, because we’re such a large, old company, were designed when the internet just came along.”

Stick to the metrics

Two keys to pulling off such a large project are establishing metrics for success and transparency with leadership, Durvasula says. Project leaders set milestones to indicate when things went well, and they planned for bumps in the road so the TIAA board knew when setbacks happened.

“Not everything is as pretty as it sounds in an awards application, but the success measures we established with our board were based on both phases,” he says. “For the first one, we said we’d deliver enterprise-grade platforms and accomplish migration objectives, but not tied to any specific business objectives.”

Phase two metrics focused more on business objectives, and the project team kept the TIAA board updated as TETRIS moved forward. Setting realistic goals was important, he says, with the team determined not to overpromise results.

“Large programs have a range of objectives, and if you publish the outcomes you’re looking for, people start looking for them, especially stakeholders, the C-suite, and board,” he says. “You have to be honest about which metrics or KPIs you can deliver in the first and second year, and when you’ll start seeing real business scale and impact, which definitely won’t be that soon in a large program like this.”

Goals also need to be flexible, Durvasula says, so transparency with leadership sometimes means telling them the project needs to reset. “If something doesn’t go well, what’s the level of fungibility you have?” he says. “We pick this tool, but what if it doesn’t work? You need to have a plan B.”

So TIAA’s IT team is heavily focused on flexible systems, and what was contemporary three years ago is probably legacy now, especially thanks to AI.

The power of change management

Another big lesson from a project of this size is the need to focus on change management. Retiring old IT systems requires the organization to bring employees along on the journey and convince them the changes are for the better.

TIAA established a multi-disciplinary team to implement a change management program focusing on breaking down silos and setting common adoption goals across the organization and its lines of business. Stakeholder forms and a huge focus on continuous collaboration helped employees understand the need for the changes.

“It’s a big organizational change,” Durvasula says. “If you’re working on a legacy system, and you think at some point it’s going to be modernized, then you become a legacy talent, and won’t have a job.” But the right change management program can convince these employees they can upskill and bring value to the new systems.

“You can bring your functional knowledge of the business and learn new technical skills,” he says. “It’s a massive culture- and people-change initiative as much as tech initiative.”

TIAA’s change management efforts were also made easier because TETRIS happened at the same time as the recent AI boom and involved AI elements. So it wasn’t hard to convince employees they needed to improve their AI skills.

“Because of AI, everybody woke up to this new reality,” he says. “We rode that wave when transformation drove from a cultural and organizational change management point.”

  • ✇Security | CIO
  • The more efficient AI makes us, the more human we must become
    Artificial intelligence is rapidly reshaping the business landscape. It can summarize meetings, generate presentations, personalize communications, analyze customer behavior, automate repetitive tasks and uncover insights that once took teams days to uncover. Organizations that embrace AI thoughtfully will almost certainly be more productive than those that don’t. That’s the good news. The challenge is that every meaningful technological advantage eventually becom
     

The more efficient AI makes us, the more human we must become

21 de Agosto de 2026, 06:00

Artificial intelligence is rapidly reshaping the business landscape.

It can summarize meetings, generate presentations, personalize communications, analyze customer behavior, automate repetitive tasks and uncover insights that once took teams days to uncover. Organizations that embrace AI thoughtfully will almost certainly be more productive than those that don’t.

That’s the good news.

The challenge is that every meaningful technological advantage eventually becomes widely available.

As AI becomes more accessible, efficiency itself becomes increasingly commoditized. Organizations that once distinguished themselves by being faster, smarter or more responsive will soon find those capabilities are no longer unique. They will simply be expected.

The competitive advantage doesn’t disappear. It shifts.

That raises a more pressing leadership question. If AI is making every organization more efficient, what will make one organization stand out from another?

I believe the answer has surprisingly little to do with technology itself. Instead, it has everything to do with what technology enables people to do.

Businesses often say they’re competing for attention. Attention matters. Without it, nothing else happens. Yet attention is fleeting.

Every day, we’re exposed to thousands of messages: advertisements, emails, websites, social posts, videos and conversations. Most capture our attention for only a moment before disappearing. Attention opens the door, but it rarely determines who earns our loyalty. Organizations that confuse attention with preference often spend enormous amounts of money to generate awareness without building lasting attachment.

The organizations that endure compete for something far more valuable. They compete to create lasting memories.

Not memories of products. Not memories of technology. Memories of experiences.

Think about the companies you recommend most often. It probably isn’t because they had the fastest website, answered your email 20 minutes sooner or had a more sophisticated AI assistant.

You recommend them because of how they made you feel.

Someone solved a problem they didn’t have to. Someone stayed late to help. Someone took ownership when things went wrong. Someone made you feel respected, not just processed.

Those moments stay with us.

The mind remembers information, while the heart remembers meaning. I believe many organizations overlook this distinction.

AI is increasingly capable of helping organizations inform, predict, analyze and optimize. These capabilities are remarkable. But information alone rarely changes human behavior. People assign meaning emotionally.

We remember confidence, relief, gratitude, belonging and trust. We remember the organizations that made us feel understood long after we’ve forgotten the details of the transaction.

Those emotions become memories, and those memories quietly shape future decisions.

The mind may justify many of our choices, but the heart often makes them.

None of this diminishes AI’s importance. In fact, it reinforces it.

Organizations should embrace artificial intelligence enthusiastically. It will improve productivity, uncover insights from vast amounts of data, eliminate repetitive work, accelerate learning and free talented people from administrative tasks that consume valuable time.

Every leader should become proficient in these capabilities, but fluency alone is not a differentiator.

There’s a temptation in every technological revolution to confuse the tool with the strategy. Technology is an extraordinary enabler, but it’s rarely the solution.

AI can help us understand customers more deeply. It cannot make customers trust us more. It can personalize a message, but it cannot make that message authentic. It can recommend a course of action, but it cannot exercise judgment. It can automate a transaction, but it cannot create a relationship.

Those outcomes still depend on people.

AI excels at reducing friction. It shortens wait times, simplifies processes, anticipates needs and eliminates unnecessary effort, all of which creates real value.

But reducing friction is not the same as creating preference.

Reducing friction makes doing business easier. Creating meaning makes people want to do business with you again. These are fundamentally different outcomes.

Convenience is increasingly available everywhere, but preference is not.

Preference is what leads someone to recommend one organization over another, to remain loyal even when a competitor offers a lower price or to overlook an occasional mistake because trust has already been established.

Efficiency delivers convenience. Emotional connection earns preference.

That distinction may become one of the defining leadership challenges of the AI era.

Creating meaning has never depended on technology alone. It comes from keeping promises, listening before responding, owning up to mistakes, showing empathy when someone is frustrated, recognizing an employee who quietly goes above and beyond, and helping a customer solve a problem no algorithm could anticipate.

Technology can support each of those moments, but people ultimately determine whether they happen.

For years, businesses have debated technology and humanity as if one must come at the expense of the other. I believe that’s the wrong conversation.

The organizations that define the next decade won’t simply have the most sophisticated AI. Nor will they succeed simply because they have a people-first culture.

They will insist on both.

They will use artificial intelligence to reduce friction and enable people to spend more time listening, coaching, solving problems, innovating and strengthening relationships.

Technology will make them more capable. Humanity will make them more memorable.

Together, they become extraordinarily difficult to replace.

For decades, business leaders have measured success by market share, share of mind and share of wallet. These measures remain important. But in a world where efficiency is increasingly accessible to everyone, I believe another measure deserves greater attention: what I call SHARE OF HEART™.

SHARE OF HEART™ isn’t created by a clever marketing campaign or a single memorable interaction. It’s earned over time through promises kept, problems solved, trust built and moments when people feel genuinely valued.

Those experiences create an emotional connection. That connection creates memories. Those memories shape preferences and, ultimately, loyalty.

That is extraordinarily difficult for competitors to copy because it can’t be downloaded, licensed, automated or replicated overnight.

Artificial intelligence will continue to make organizations smarter, faster and more efficient. Every leader should embrace that future.

But the organizations people remember won’t simply be those with the best technology. They’ll be the ones that understand technology’s highest purpose: not replacing human connection, but creating more opportunities for it.

Efficiency may get you into the consideration set.

Meaning earns a lasting place in people’s hearts.

  • ✇Security | CIO
  • Mars consolidates complex data infrastructure in hybrid cloud
    Brands like Snickers, M&M’s, and Twix are familiar to most consumers, but Mars Inc. doesn’t just produce snacks. The family-owned company, with a revenue of approximately $65 billion, is also one of the largest manufacturers of pet food and ready meals, and its more than 100 production facilities operate around the clock. Of course, this places considerable demands on its IT. “Our team must ensure that every system, including production lines, runs at maximum performan
     

Mars consolidates complex data infrastructure in hybrid cloud

20 de Agosto de 2026, 07:00

Brands like Snickers, M&M’s, and Twix are familiar to most consumers, but Mars Inc. doesn’t just produce snacks. The family-owned company, with a revenue of approximately $65 billion, is also one of the largest manufacturers of pet food and ready meals, and its more than 100 production facilities operate around the clock. Of course, this places considerable demands on its IT.

“Our team must ensure that every system, including production lines, runs at maximum performance so we can continuously deliver the products and services our customers value,” says Luciano Batista, the company’s VP of enterprise services delivery.

However, Batista and his team realized that the existing data infrastructure could no longer reliably support operations, especially during peak periods such as Halloween and the pre-Christmas shopping season. So with the support of hybrid, multi-cloud data storage service Everpure, Mars is rebuilding its data and IT infrastructure.

“The Everpure platform met all our requirements,” says Batista. “It’s a scalable platform that futureproofs our operations and integrates seamlessly with our hybrid cloud infrastructure.”

Unified storage environment 

Mars initially consolidated its complex network of storage systems for business-critical databases like Oracle and applications like SAP onto a single Everpure Flash Array system. These software-defined, all-flash storage arrays are available in versions for different workloads, and typical use cases include databases, virtualized environments, SAP applications, and AI and analytics applications. 

Mars has since expanded its flash array infrastructure and now supports mixed workloads, including VMware, Windows, and Linux in areas of production, development, and quality assurance. It also uses Everpure Flash Blade as the basis for the global SAP file system. And while Flash Array is optimized for structured data, the scale-out systems of the Flash Blade series are designed for unstructured information.

“At peak times, Everpure supports up to 300,000 IOPS without any performance degradation,” says Lincoln Silva, product owner for Linux and on-prem storage at Mars. From his perspective, another point speaks favorably of the new platform in that he estimates his team saves approximately three months of planning time thanks to the Evergreen subscription model. This is because the vendor provides regular updates for the storage platform’s hardware and software. As a result, Mars’ IT professionals can focus on more critical tasks. 

Basis for hybrid cloud strategy

Mars also works with choice vendors to implement its approach to cloud. Dedicated local storage capabilities, for instance, are being integrated into Microsoft Azure cloud workloads, which simplifies restore processes and increases resilience.

Snapshots from the local environment can be replicated to the cloud, too. Recovery point objectives (RPEs) of four to 24 hours are available, depending on system priority. “Our success is also the success of our partners,” Batista says. “We embrace a spirit of reciprocity to get the most out of our collaboration.”

The hybrid cloud allows Mars to run VMware workloads and extend its IT infrastructure to the cloud as needed. And the company aims to expand its use of cloud-native applications via Microsoft Azure at a lower cost.

“We’re seeing a data reduction ratio of 18 to one. That’s nine times the expected compression rate,” Batista adds. “This puts us on track to save up to 50% on cloud storage costs. We can now work more efficiently and make better decisions thanks to intelligent solutions and automation.”

Fewer racks and lower power consumption

By consolidating on the flash platform, Mars has also reduced the space requirements and power consumption of its data centers so they only use one sixth of the power, and the number of racks has decreased significantly.

“We’re shaping a sustainable future by changing the way we work,” says Batista. “The decisions we make today will impact the world we leave behind, and Everpure aligns with our commitment to thinking in generations, not just business quarters.”

  • ✇Security | CIO
  • How a new AI value framework and stakeholder focus keep Zoetis ahead of the pack
    Most AI investment strategies fail not because the tool or platform underperforms, but because organizations didn’t clearly define what success looks like before they started building. Through a new approach to measuring value, Zoetis chief digital and technology officer Keith Sarbaugh and his business partners have leveraged a value-driven framework to scale AI solutions across research, manufacturing, and customer experience. And they measure every investment against
     

How a new AI value framework and stakeholder focus keep Zoetis ahead of the pack

19 de Agosto de 2026, 07:00

Most AI investment strategies fail not because the tool or platform underperforms, but because organizations didn’t clearly define what success looks like before they started building.

Through a new approach to measuring value, Zoetis chief digital and technology officer Keith Sarbaugh and his business partners have leveraged a value-driven framework to scale AI solutions across research, manufacturing, and customer experience. And they measure every investment against goals before, during, and after the deployment.

In addition, his team rolled out a model-agnostic gen AI platform now used by nearly 95% of employees, which turned early experimentation into enterprise-wide adoption. Sarbaugh’s current focus now is partnering with Zoetis’ CHRO to advance the $9 billion global company’s capabilities in managing organizational AI adoption.

How are you integrating AI into your growth plans at Zoetis?

We have an umbrella program we call AI@Zoetis, where we unify our AI work under an enterprise purview, which spans research and development, manufacturing, commercial operations, customer and colleague experience, and other business functions. We manage AI collectively to enable grassroots innovation.

For example, we made our generative AI platform available to everyone, so as many people as possible can experiment and innovate. Our colleagues have access to 10 different LLMs, and we’ve seen over 95% adoption rate among our user community, and more than 11,000 colleague-built agents.

One popular AI use case is helping colleagues build their own development plans. The agent guides a colleague through a conversational, coach-like experience to map out their career aspirations against Zoetis’ competency framework, which was key to its wide adoption. This idea came from people not in HR, illustrating the point that some of the best use cases come from our broader employee base.

What’s an AI use case that directly impacts customers?

We have millions of customer interactions across our channels. Our sales force is out talking to them, who are also in our digital platforms, and we receive thousands of calls through customer service. We’ve been using the industry standard Net Promoter Score (NPS) to measure customer loyalty and satisfaction, but NPS is a measure that can take longer to generate. Zoetis has accelerated our awareness of customer feedback into real-time listening, using AI to understand these customer interactions in a holistic way, and at a scale we couldn’t achieve before. NPS still matters for tracking long-term trends and maintaining a consistent industry benchmark. We simply use AI to listen, learn, and act quicker.

Our AI customer experience platform also lets us look across all our customer touchpoints like calls, emails, and websites in real time, immediately identify issues and insights, and then be smart about how we address them. We now have more than 10 times the feedback signals we had in the past. We see trends sooner and act faster, and as humans, we can’t do that without AI.

How are you deciding where to make your AI investments?

We use different lenses. One is AI for the masses, which is our generative AI platform for colleagues; second is our middle lens, where we drive value in a particular function; and the third is enterprise-wide transformation, the big bets that’ll fundamentally change our business. We don’t do many, but we do them in a smart way.

With the transformative investments, we focused on both our commercial business and R&D, which we knew had the highest probability of serious returns. We started with seven golden use cases and knew that if we hit on two or three, it would be a big deal. Of the original seven use cases, six of them exceeded their value target and went from PoC to scale.

Since those earlier days, we’ve broadened to include manufacturing and supply chain, and our enabling functions.

Overall, we didn’t go out of the gate looking for productivity gains. We thought about business transformation right from the start. Today, we’re scaling up those first-mover investments and continue to leverage our value-driven framework to identify more use cases.

Are you creating new value frameworks so you and the rest of the ELT are unified in your investment strategy?

We developed a business value realization framework, which isn’t as sophisticated as it sounds. Before we make a tech investment, we ask what category of benefit we expect to receive, whether it’s revenue uplift, cost reduction, productivity, or whatever. We predict what success will look like and how we’ll measure it. 

Because with AI, we’re trying to move fast. We put a value case together at this early stage and do a PoC, and if it hits its target, we update the value case and decide whether to scale. A key element of the framework is real-time measurement. Are we seeing what we wanted, and if not, how do we pivot for more value?

The speed of iteration and scaling decisions make AI investments unique, so we can’t use our traditional value frameworks for digital investments, generally. Measuring outcomes post-implementation has become even more important.

How is your CHRO partnership impacting AI value?

Our CHRO and I partner closely to ensure enterprise enablement. When driving new ways of working that impact your workforce, you need a comprehensive approach, clear communications, and genuine buy-in. Colleagues adopt faster when they help shape the change. We’re prioritizing our workforce strategy, understanding what AI means for jobs at Zoetis, identifying skills that matter most, and building a plan to upskill people.

Another focus area is organizational change management (OCM). We reviewed our first AI investments to learn from our mistakes, and one consistent theme was that we shortchanged OCM. We thought naively that what we build will be so compelling, adoption will just come. But we didn’t do the right communication and stakeholder management. We recognize our need to develop OCM as a core competency, so our CHRO and I are building an enterprise playbook for AI change.

What’s your pragmatic advice to other CIOs when it comes to OCM?

When you’re wrapped up in a change program, you know what’s coming, but no one else does. When you impact your entire workforce, you need a smart approach to stakeholder management and communications. Involving colleagues in the creation of something new will aid in adoption. Have a deliberate and intentional communications plan and cadence, and have the discipline and objectivity to measure and learn. Our first tries weren’t perfect, but we listened to feedback and pivoted, and those pivots drove further commitment.

Has your communication at the board level changed?

When I talk to my peers about their board conversations, half focus on risk and compliance, and the other half talk about transformation and revenue generation. I’m fortunate that our board cares about both and has great energy around generating revenue, and how AI will give us a competitive advantage. By managing risk and compliance, we can spend our time focusing on potential drug candidates and getting to market quicker. Our board conversation is both about enablement and compliance.

What advice would you give to tomorrow’s CIOs?

The role is now about orchestration, understanding the business, and realizing value from technology investments. If you want to work with the best technology and bleeding-edge innovation, you’ll get some of that as a CIO, but the focus is broader, centered much more on processes and complex business problems than ever.

My advice is if you love working with technology, you’ll get that as a CIO. If you love delivering meaningful outcomes for the business and the customers you serve, it’s a truly rewarding role, and you’ll be an even more successful CIO.

  • ✇Security | CIO
  • Ways CIOs can maintain control amid changes brought by AI
    It took nine seconds for an AI agent to destroy PocketOS’s production database. At work on a routine task in April, the coding agent, a variant of Cursor running on Claude Opus 4.6, ran into a credential mismatch and decided to fix the problem by triggering an API token. Little did PocketOS founder Jer Crane know that its activation would also delete its production database. “Had we known,” Crane later wrote on X, “we would never have stored it.” The consequences of the ag
     

Ways CIOs can maintain control amid changes brought by AI

19 de Agosto de 2026, 07:00

It took nine seconds for an AI agent to destroy PocketOS’s production database. At work on a routine task in April, the coding agent, a variant of Cursor running on Claude Opus 4.6, ran into a credential mismatch and decided to fix the problem by triggering an API token. Little did PocketOS founder Jer Crane know that its activation would also delete its production database. “Had we known,” Crane later wrote on X, “we would never have stored it.”

The consequences of the agent’s actions were immediately apparent. Not only were recent backups belonging to PocketOS’ infrastructure provider contained in the production database — the recoverable versions were at least three months old — but so were those belonging to its infrastructure provider, Railway, which at press time still couldn’t tell Crane whether full infrastructure-level recovery was possible. Crane couldn’t fathom why the agent did this. So he asked it.

What he got back was an apology, of sorts. “I guessed that deleting a staging volume via the API would be scoped to staging only,” the agent said. “I didn’t verify. I didn’t check if the volume ID was shared across environments. I didn’t read Railway’s documentation on how volumes work across environments before running a destructive command.”

Ignoring built-in safety guardrails is hardly unique to agents operating on Claude Opus 4.6. In July, a Brazilian software engineer claimed an agent powered by OpenAI’s GPT-5.6 Sol model also deleted his production database, while in February, a Meta AI security and safety researcher claimed she had to switch off her computer to prevent an experimental agent deleting her entire inbox.

It wasn’t meant to be like this. Agentic AI was intended to be the culmination of millions of hours of research and development in gen AI to perform hyper-qualified acts of pattern recognition in the real world, and truly live up to their labor-saving promise. Their apparent predilection for destruction, however, has revived multiple debates about exactly how they should be restrained, and who, ultimately, is responsible for doing so.

Ultimately, the answer is those who green-lit the offending system. But as the pace of AI development puts greater daylight between companies pressured to adopt it, and those very tools capable of wreaking havoc across their internal databases, are CIOs now out of their depth?

Setting the pace

There’s no question the emergence of gen AI has changed the CIO role. “A few years ago, most of my time went to infrastructure decisions, including what to build, what to buy, and how to sequence the roadmap,” says Mike Trkay, CIO at data analytics company FICO. “Now, a growing share goes to questions of trust, verifying that when AI writes code, makes recommendations, or acts on behalf of a system, those actions can be explained and traced back to someone accountable for them.”

So the CIO has become the enterprise’s technological organizer du jour. “AI is accelerating software development, decision automation, and organizational experimentation at a pace that can outstrip institutional coherence,” says Edosa Odaro, executive advisor for data and AI at consulting firm VDS Global. “As AI becomes embedded across every business function, CIOs are increasingly responsible for ensuring that technical capability, governance, data quality, cybersecurity, human capability, and business strategy continue to evolve together rather than fragment.”

Day to day, that’s led to an exponential change of pace. “Things have always been fast,” says Zach Lewis, CIO and CISO of the University of Health Sciences and Pharmacy in St. Louis. “But now that speed of change is quicker, and you have to adapt.” And the need to catch up is constant. There’s no other option because then any competitor or co-collaborator can jump ahead, adds Lewis.

The rapid pace of change in AI also threatens to diminish the authority of individual CIOs who fail to keep up or set effective guardrails on those individuals who like to experiment with the newest models with loose regard for corporate security. “There’s all these AI tools that employees can now just go out and adopt,” says Lewis. And at the moment, a paid subscription to Claude or ChatGPT isn’t required to capitalize on its abilities. Consequently, staff are just a click away from asking LLMs to perform various tasks and expose sensitive corporate information in the process. “Everyone wants to play with the new thing,” he says. “And when they find benefit there, they’re going to want to bring it to their work lives.”

Agentic AI poses an entirely new set of problems. For one thing, says Odaro, the next phase of application adoption will be defined less by the capabilities of individual models, and more on what you allow their agents to do. “As AI becomes increasingly capable of generating software, coordinating workflows, and making recommendations across functions,” he says, “the challenge shifts from building AI to continuously governing evolving AI systems.”

This, Odaro continues, means that the CIO’s current approach to governance isn’t sustainable. “Static policies, annual reviews, and isolated oversight will struggle to keep pace with dynamic AI environments,” he says. “CIOs will increasingly need continuous governance capabilities that provide ongoing visibility into AI performance, value creation, risk, trust, and organizational adoption.”

Falling over the guardrails

How, then, should CIOs approach writing these new guardrails? Traditionally, this would be perfect fodder for so-called alignment researchers investigating how to instil a sense of morality and propriety into agents. According to analysts at Google DeepMind, however, it’s best to assume the agent will always be a potentially chaotic force within the company, and set parameters on its conduct from there.

“We borrow a lot from security, which already deals with the threat of internal employees who might be malicious, and we can apply these to a new setting,” Rohin Shah, Google DeepMind’s AGI safety and alignment team lead, told Fortunein June. Even so, he added, “AI is systematically different from humans.”

That difference primarily pertains to authority and speed. For agentic AI to live up to its full potential, it requires the freedom to access multiple systems simultaneously — an uncomfortable fact for CIOs hoping to align agent responsibility across the enterprise. In a time when workflows are becoming ever-more automated, however, that aspiration may prove unrealistic. In that case, Google DeepMind theorises that yet another monitoring layer for agentic AI may be required to make sure these free-roaming agents don’t cause too much trouble.

If that sounds daunting, you’re not alone. According to recent research by Gartner, up to 40% of enterprises using agentic AI will either demote or decommission these applications because their guardrails have proven inadequate. Preventing this, the research organization advises companies will need to adopt a graded approach to access, with autonomy for AI agents governed by the level of authority actually determined by the task they’ve been assigned.

Trkay is doing something similar at FICO. “Rather than chase every new model or capability, I focus control on the decisioning layer beneath it,” he says. “That includes the rules for what data AI can access, what it can act on autonomously, and where a human must sign off.”

All this, he adds, is defined from the start by a cross-functional governance committee, clear RACI ownership across standards and monitoring for the application, and a platform approach that enforces responsible AI usage. “Built well, that layer doesn’t need to be rebuilt every time the technology shifts,” says Trkay. “New capabilities plug into an existing structure of accountability, which is the difference between reacting to AI and running it.”

For his part, Trkay is skeptical that rigid guardrails can effectively restrain agentic AI from its most destructive impulses. “They tend to get worked around, either because they slow teams down or they’re too inflexible for legitimate edge cases,” he says. Effective guardrails for agentic AI, he adds, have to be specific enough to be meaningful, and adaptable enough to hold up as use cases multiply, backed by strong architecture, testing, and ongoing monitoring. “The one non-negotiable is the audit trail,” he says. “Whatever autonomy a system has, we need a record of what it did, and why.”

Staying grounded

For CIOs who don’t relish the challenge of setting obstacles and passing points for AI agents scurrying through their maze of networks, there’s always the option of delaying the inevitable by not immediately deploying such applications. Some might not even have the choice, at least for now. “We’re seeing the cost of tokens go up with those new models, because they’re expensive to run,” says Lewis. “But as new models come out, we’re going to see that decrease for some of those older models that were good.”

There is time, then, for CIOs to learn how to keep their head above the torrent of ever more new and powerful agentic AI applications. Whether they’ll be capable of doing so when the next great innovation is sold by Silicon Valley is an open question. Colin Constable, CTO of software development firm Atsign, styles himself as an internet optimist. Even he, however, is dismayed by the decreasing number of junior developers succeeding their more senior counterparts as they retire. That’s a big problem when so many of the former are relying on AI to assist them at work.

“We hand over lots of these decisions to LLMs without making good architectural choices,” says Constable. “If you haven’t been burnt by these things in the past, how would you know the difference?”

For their part, Constable and his colleagues get around this problem with a combination of AI-on-AI oversight of code quality, maintenance of constant dialogue within the team about new coding quandaries, and letting senior developers teach junior counterparts about some of the more avoidable mistakes in their profession. It’s a way of adapting to AI acceleration that points, unequivocally, toward CIOs diffusing responsibility for deeply educating the business about the technology. And if they continue to get it wrong, at least the agent will apologize.

  • ✇Security | CIO
  • The AI leapfrog effect: Why standardizing now could be your costliest mistake
    Towards the end of 2022, something shifted in enterprise boardrooms. Convinced by the promise of a genuinely new class of technology, businesses began investing in AI across marketing, sales, developer platforms, analytics and automation. The experimentation was justified. Use cases were unclear, the cost of not participating felt higher than the cost of overspending, and no one wanted to be the organization that missed the wave. Today, however, the climate is changing.
     

The AI leapfrog effect: Why standardizing now could be your costliest mistake

19 de Agosto de 2026, 06:00

Towards the end of 2022, something shifted in enterprise boardrooms. Convinced by the promise of a genuinely new class of technology, businesses began investing in AI across marketing, sales, developer platforms, analytics and automation. The experimentation was justified. Use cases were unclear, the cost of not participating felt higher than the cost of overspending, and no one wanted to be the organization that missed the wave.

Today, however, the climate is changing. The AI market is maturing as the first wave of experimentation comes to an end. Now, enterprise leaders are putting their AI systems under review and asking: “Are the outcomes worth the price?”

According to one recent study, actual revenue growth and profitability improvement are the primary ROI metrics for AI projects (selected by 22% of respondents), ahead of productivity (18%). Executives today care less about narratives that focus on efficiency or time savings and more about the impact of AI on the bottom line. To some extent, this is a consequence of just how heavily some organizations have invested in the technology. Some businesses support AI portfolios worth up to five points of EBITDA, (figures from BCG put the average spend this year at 1.7% of revenues). At that level of investment, AI is no longer an innovation budget line. It is a balance sheet exposure, and boards are starting to treat it accordingly. Given how much is being spent, the pressure to demonstrate returns is building, and the pressure to demonstrate governance over that spending is not far behind.

Over the next 12-18 months, we can expect to see something of a reckoning. Vendors with products that deliver only marginal productivity gains can expect to lose out to competitors that offer better value for money. This phase of market consolidation will likely be significant and it’s possible that many of the AI companies that attracted serious enterprise contracts over the last two years will not survive.

The AltaVista trap

What makes this moment particularly difficult to navigate is a dynamic I think of as the AI Leapfrog Effect, and it is unlike anything enterprise IT leaders have encountered before.

The AI market is not evolving incrementally. Platforms are overtaking one another in capability, cost-efficiency and architectural approach at a pace that enterprise procurement cycles were never designed to track. The leading tool in any given category today may occupy a distant second position within 90 days. And critically, the leaps are not marginal. They are structural shifts in underlying model capability, reasoning depth or integration architecture that render yesterday’s best answer genuinely obsolete.

History offers a useful warning. In the early days of the internet, AltaVista was one of the leading web browsers. It had an early-mover advantage and, in the early days at least, a strong user base. Yet, as we all know, AltaVista lost out to Google, a new kid on the block that had the advantage of much better technology. Google won because it learned where the pioneers were going wrong and was able to overtake them through rapid technological advancements.

Today, many of the current AI leaders risk being leapfrogged in the same way. Indeed, the environment today is much more perilous to first-wave pioneers than it was back in the mid ‘90s. AI technology is evolving much faster than any technology that has come before. A leading platform in any given category today may slide into distant second in as little as 90 days.

For enterprise IT users, this creates a strategic trap. The AI market is moving much faster than procurement cycles can track. A standard enterprise software evaluation (RFP, shortlist, proof of concept, legal review, contract) can easily consume six to nine months. In AI terms, that is two or three capability generations. Businesses that standardize too early risk being locked into a platform that’s soon out of date. Conversely, if organizations delay key decisions too early, they may fail to capture the productivity gains that competitors are already realising.

The best course of action is to track close enough to the market to understand its direction of travel without over-committing. Practically speaking, this requires carrying out regular technology evaluations while keeping options open across two or three platforms. It’s also important to resist pressure from vendors to sign long-term contracts for platforms that are still in development or to undertake complex integrations. Vendors pressing hardest for long-term commitment are often the ones with the most to lose if you wait.

Striking while the iron’s hot

The one major caveat to all this is that in a few niche areas a clear leader will have already emerged – the Google to the AltaVistas of this world. In these cases, the gap between the leaders and the rest is so large it’s unlikely to be closed anytime soon. Here, businesses can invest with much greater confidence.

Developer tooling is the clearest example. At Avantra, we evaluated every serious option available for AI-assisted coding, including some of the less widely discussed platforms. Claude Code outperformed everything else we tested, and the margin was not close enough to generate any real debate. For our developers, Claude Code is so dominant there’s no point in maintaining Gemini or OpenAI licences, and we’ve therefore been able to benefit from cost consolidation.

That kind of clarity is useful, and organizations should act on it where they find it. The mistake is assuming that because one category has settled, the others have too. In areas like AI-assisted design, marketing content generation and enterprise search, the picture remains genuinely unsettled and standardising now carries real risk.

What consolidation will look like

The AI tools that will survive the coming reckoning share a few characteristics. First, they’re deeply embedded in workflows rather than sitting alongside them. Second, they deliver measurable, attributable outcomes rather than general productivity improvements that are hard to isolate. And third, they serve use cases where the switching cost is high enough that users do not migrate the moment a competitor releases an update.

Tools that fail those tests, particularly the ones that gained traction because they had no good alternative in 2023, rather than because they were genuinely superior, will face a sharp correction. Some will be acquired for their user bases or technical teams. Others will simply lose enterprise renewals at a rate that’s not sustainable.

Organizations best placed to navigate this period of market turbulence will have maintained honest internal records of what value their AI investments deliver. Rather than being measured by anecdotal evidence from enthusiastic early adopters, success will be quantifiable through gains in output, quality or cost at a team or process level. That discipline is harder to maintain during the experimentation phase, but it is what separates the organizations that will make smart consolidation decisions from those that will simply cut platforms indiscriminately when the pressure arrives.

What to do now

As organizations review their AI investment strategy there are three fundamental steps to take:

  1. Resist multi-year platform agreements in categories where the technology is still visibly moving. Negotiate annual terms where possible and insist on contractual clarity around capability benchmarks and data portability. If a vendor will not agree to data export provisions, treat that as a significant red flag.
  2. Document what your AI tools are producing in terms that will survive a CFO’s scrutiny. This means outcome metrics tracked at the team or process level, not survey-based satisfaction scores or anecdotal reports from enthusiastic early adopters. If you cannot produce this data today, instrument for it now, before the renewal conversation begins.
  3. Move decisively in categories where consolidation has already happened. Where a clear leader has emerged, and the capability gap is structural rather than marginal, consolidating onto that platform and removing competing licences is straightforward value capture. The cost savings fund the optionality you need to maintain elsewhere.

When your board asks what the company is spending on AI, make sure you walk in with two numbers: what you are spending, and what you are getting. The organizations that cannot produce the second number are the ones that will be cutting indiscriminately in 18 months. The ones that can will be compounding the advantage they have already built.

The AI Leapfrog Effect is not a reason for paralysis. It is a call for precision: know where the market has settled, know where it has not and build your investment strategy around that distinction rather than around vendor timelines or the anxiety of being left behind. It means resisting the impulse to treat AI procurement like software procurement, where standardization and consolidation are almost always virtues. In AI, right now, selective standardization is a virtue, and premature standardization is a liability.

The organizations that internalize this will not just survive the consolidation wave but define the competitive landscape on the other side of it.

  • ✇Security | CIO
  • CIOs earn AI reprieve, but ROI pressure is surging
    2026 arrived as the year AI ROI would need to get real. After years of experiments and pilots that largely failed to scale, CEOs’ No. 1 priority for CIOs was to achieve demonstrable benefits from AI investments. Under that pressure, CIOs started to feel the heat, with 71% of IT leaders in February saying they believed they had until midyear to prove AI value or face budget or job fallout, according to a survey published by AI platform provider Dataiku. For many, experie
     

CIOs earn AI reprieve, but ROI pressure is surging

18 de Agosto de 2026, 07:01

2026 arrived as the year AI ROI would need to get real. After years of experiments and pilots that largely failed to scale, CEOs’ No. 1 priority for CIOs was to achieve demonstrable benefits from AI investments.

Under that pressure, CIOs started to feel the heat, with 71% of IT leaders in February saying they believed they had until midyear to prove AI value or face budget or job fallout, according to a survey published by AI platform provider Dataiku. For many, experience may have informed that anxiety, as three-quarters of CIOs surveyed then also said they had remorse over at least one major AI vendor or platform selection made in the past 18 months..

Six months later, and passed that midyear mark, CIOs who have set their course for AI ROI are finding that destination remains elusive. Still, there hasn’t been a spate of CIO firings, and AI spending continues to grow. About 71% of organizations plan to increase AI spending this year, but only 27% expect near-term ROI, according to recent research by IT solutions provider TEKsystems.

That metric aligns with findings from CIO.com’s State of the CIO survey from earlier this year, when 40% of IT leaders said some AI initiatives (between 30% and 70%) were meeting ROI goals. While progress remains the same, the drumbeat to prove value goes on.

“CIOs are feeling pressure to demonstrate that AI is delivering measurable business value, not just experimentation,” says Jed Dougherty, SVP of AI and platform at Dataiku. That’s because, while CIOs’ worst fears haven’t been realized, organizations are putting greater scrutiny on AI investments, he adds.

“The CIOs who are succeeding aren’t deploying AI everywhere,” he says. “They’re building the governance, data, and operational foundation that lets the business scale AI responsibly and demonstrate real outcomes.”

A pronounced focus on AI spending and costs

Bob Hutchins, CEO at AI advisory firm Human Voice Media, believes CIOs’ early year anxiety wasn’t likely based on any formal deadlines.

And if any CIOs have been fired since February because they missed AI targets, those changes are likely hidden from public scrutiny either in reorganization efforts or other leadership changes, he says.

“Midyear came and went and there was no apparent bloodletting,” he adds. “I haven’t seen credible evidence of mass firings of CIOs due solely to missing return on investment targets for artificial intelligence.”

But organizations do seem more focused on spending their AI budgets wisely, Hutchins notes. Nearly half of all organizations surveyed recently by KPMG have delayed, stopped, or scaled back AI projects due to budgetary constraints, he says.

“Companies are stopping poorly performing projects, scaling back pilot programs, decreasing the number of vendors they use, creating cheaper models of products and services, and giving more control over AI approval to the financial department,” he adds.

Ryan Ries, chief AI and data scientist at AI and cloud consulting firm Mission Cloud, also sees IT leaders still under pressure to improve AI results.

While firing a CIO midyear looks bad on an earnings call, IT leaders now face budget triage efforts related to AI, he says.

“Money still flows to projects with a hard number attached,” he adds. “Pilots without one get quietly starved but not killed outright. The AI landscape is constantly changing, and companies are trying to figure out all the new tools like coworking and coding solutions.”

Moreover, facing increased uncertainty over AI pricing, CIOs are re-examining AI adoption metrics and becoming more aware of the hidden costs of AI.

Cost control is also receiving greater emphasis as some early agentic forays have shown how an AI agent can cost more than an employee without limits in place.

CIOs still on the hot seat

CIOs are also finding that it is taking their organizations more time to figure out how to use AI tools to their full advantage, and that they are constantly reacting to errors, Ries notes.

As a result, IT leaders appear to be putting in more effort to find AI value than they were earlier this year, he says. “Fewer are succeeding than leadership wants to admit,” he adds.

While most organizations were experimenting with the so-called “art of the possible,” IT leaders seeing success are focused on attaching a metric to every AI project before launch, not after, he says.

Many IT leaders still aren’t taking that approach, however. “The CIOs still stuck are the ones running pilots that never graduate to production, usually because nobody can explain what the model is doing under the hood, and teams are trying to answer the wrong questions with AI,” he says.

It’s possible that CIOs have gotten a reprieve due to the ongoing complexity of the AI ROI mandate, Ries adds.

“Boards don’t fire on a spreadsheet’s calendar, but the underlying pressure was real, and it hasn’t eased,” he says. “Instead of a hard cutoff, CIOs now face constant reporting. Monthly board briefings on AI performance are becoming standard, not optional.”

CIOs should remain on their toes and focus on driving AI value, Ries says. “The fear of a July guillotine was overstated,” he adds. “The fear of ongoing, permanent scrutiny was not, if anything it has increased, due to how quickly cost overruns can happen.”

Budget pressure is real

Like other observers, Mridul Nagpal, CTO and co-founder of AI software development company Krazimo, sees a growing focus on AI budgets and untargeted spending.

“The pressure is real, but it’s reshaping spend more than cutting it,” he says. “What’s actually at risk is the undifferentiated AI budget — the ‘we’re doing AI’ line item with no outcome attached.”

Many CIOs are now starting to show AI value, but by narrowing their approaches, not expanding them, he adds.

“CIOs who funded broad experimentation are the ones sweating; CIOs who tied spend to a specific, measured workflow are defending, and often growing, their budgets,” he says. “The fallout is landing on unaccountable AI spend, not AI spend per se.”

The CIOs showing returns have quietly killed sprawling AI pilot portfolios and doubled down on a handful of use cases that reached production, Nagpal adds.

Like Ries, Nagpal believes that earlier CIO fears were a bit overblown and, at the same time, they’ve gotten more time to prove AI value.

“Boards softened the ‘or else’ because the whole market discovered the pilot-to-production gap is real and hard, so the deadline quietly moved,” he says. “But the underlying expectation didn’t disappear — it matured from ‘show me AI’ to ‘show me AI that pays for itself.’”

  • ✇Security | CIO
  • Before AI agents can transform your business, they need to understand it
    Over the past year, the conversation around enterprise AI has shifted dramatically. We’ve all seen that AI is extremely competent when it comes to generating content or answering questions with advanced reasoning, but what G2000 companies are now asking is whether agents can be trusted to execute work efficiently and effectively across the organization. This is where most of the value creation will lie for large global companies, but many make the mistake of prioritizin
     

Before AI agents can transform your business, they need to understand it

17 de Agosto de 2026, 06:00

Over the past year, the conversation around enterprise AI has shifted dramatically. We’ve all seen that AI is extremely competent when it comes to generating content or answering questions with advanced reasoning, but what G2000 companies are now asking is whether agents can be trusted to execute work efficiently and effectively across the organization.

This is where most of the value creation will lie for large global companies, but many make the mistake of prioritizing quick deployment of agents, expecting instant results that can reassure shareholders, customers and other stakeholders that the company is not “falling behind” in the AI race.

The fact is that most organizations that skip the initial hard yards of standing up detailed operational foundations for agent deployment discover they’ve simply automated complexity, with high failure rates, increased risk and disappointing results.

Large language models are extraordinarily capable, but they do not understand your business context. They do not know how work should flow across departments, where exceptions arise, who has authority to approve decisions, which policies take precedence, how compliance is maintained or what success looks like for each business process.

I also remained amazed by the number of large organizations that still do not have a detailed and documented understanding of how work truly happens within their business and therefore try to deploy AI within processes they are not even able to describe accurately in the first place.

Without that understanding, every agent action or decision becomes more uncertain, which is why so many enterprises are discovering that while deploying agents is the easy part, getting ROI and controlling risk is much harder.

Real businesses aren’t linear


One of the biggest misconceptions about AI is that business processes are predictable and consistent. In fact, they’re not — our typical G2000 enterprise customer has thousands of variations, exceptions and dependencies that have evolved over years, sometimes decades. For example, a customer order follows a different path depending on geography, customer type, inventory availability, regulation, contractual obligations and dozens of other variables. This is intrinsic to large, complex operations operating in many jurisdictions, and cannot be removed just by deploying AI agents.

This operational complexity is what makes enterprise AI so challenging. An agent may perform flawlessly in a controlled pilot, but real businesses rarely operate under ideal conditions. Without a clear understanding of how work is designed to flow — and, crucially, how it flows when exceptions occur — agents struggle to make consistent, reliable decisions in production. The challenge isn’t the intelligence of the AI: it’s giving agents the context they need to navigate the day-to-day realities of enterprise operations.

This brings us back to one of the core principles of process improvement: don’t automate a process you can’t describe in full in all its variations, and don’t automate a broken process either. And the same rule applies to Agentic AI — agents learn from the environments they’re deployed into so they will amplify dysfunction and error rates.

Fail to prepare, prepare to fail


In contrast, I’ve seen organizations achieve remarkable results by taking the opposite approach. Rather than rushing to deploy new technologies, UK-based retailer Boots first created a connected process architecture spanning more than 2,000 business processes. That visibility enabled the company to redesign core finance processes, reducing one process from 220 steps to just 40, improving efficiencies by up to 75% and creating the foundation for starting to roll out agents to take on key responsibilities.

As Boots’ Head of Finance BPM and Continuous Improvement, Lee Oates, puts it: “It’s very easy to think that you can just chuck AI in and it can solve all your problems. But if we don’t prepare our foundations, our data and our processes, that’s a fundamental mistake. Preparing those foundations helps us pick the right AI solutions and put the right governance around them “

Similarly, Lockheed Martin has made operational foundations a core part of its AI strategy. CIO Maria Demaree says the company is first standardizing business processes and building a model-based enterprise before scaling AI across the organization — recognizing that AI is most effective when it operates on trusted operational foundations.

As organizations move from automation to autonomous agents, governance becomes just as important as intelligence. After all, every enterprise operates within clearly defined boundaries covering rules such as who can approve a payment, when decisions should be escalated, which policies take precedence and what controls must be followed.

These aren’t questions an AI model can infer from transactional data alone, so they require explicit operational knowledge. Without those guardrails, businesses face an impossible choice: agents that escalate every decision and deliver little new value, or rogue agents that act too freely and create unacceptable levels of risk.

Organizations that successfully deploy AI at scale won’t be the ones who bolt governance on afterwards but instead embed it into the way work is designed from the outset, giving agents clear boundaries within which they can operate confidently and safely.

Context connects the enterprise


But another challenge emerges as organizations move beyond isolated AI pilots and use cases. Business processes rarely exist in isolation, and every decision creates downstream consequences across multiple teams and systems. If agents operate with different assumptions about how work should happen or do not have a full understanding of upstream and downstream consequences of the work they are undertaking, inconsistency quickly becomes enterprise risk.

That’s why organizations are investing in a governed Digital Twin of the organization to act as the single source of truth and to understand in detail interdependencies between processes. Leonardo, one of the world’s leading aerospace and defence companies, recorded more than 5,000 process models across its global operations to establish a common operational foundation; now it provides the context, rules and governance needed for agents to operate reliably and efficiently across its highly complex engineering and manufacturing environments.

And Hyundai has built a Digital Twin of operations at its $7.6bn Georgia hub — the largest car manufacturing factory in the US — that mirrors the physical plant in real time to predict optimized outcomes and identify the root causes of production issues, reducing costs and being able to respond more effectively to disruption on the line.

Measuring what matters


Perhaps the biggest misconception about Agentic AI is that success can be measured by the number of agents deployed. This is a fallacy — the real question is whether business outcomes improve. Are customer journeys faster and costs lower? Has compliance improved and risk been reduced?

Without operational baselines and process KPIs, organizations have no reliable way to determine whether AI is genuinely improving performance or simply changing how work is executed.

The enterprises that will create new business value from AI all share one characteristic: they understand that successful AI starts long before the first agent is deployed. They are investing in building a clear operational understanding of how their business works — connecting processes, systems, people, governance and performance into a trusted foundation for execution.

That foundation gives AI the context it needs to operate reliably and at scale, delivering the speed to value, reduced risk and new productivity that all CEOs are under pressure from their shareholders and boards to demonstrate.

Put simply — the winners in the Agentic AI era won’t be the companies that deploy the most agents the quickest but those whose agents understand their businesses the best.

  • ✇Security | CIO
  • The vendor consolidation trap: When one throat to choke costs more than it saves
    Vendor consolidation is sold as discipline. Fewer vendors, simpler architecture, better pricing through volume, one throat to choke when something breaks. Every one of those benefits is real on paper. The problem is that the biggest cost of consolidation rarely appears on the slide the procurement team uses to sell it internally, and it does not show up on the savings tracker until the first renewal cycle after the ink is dry. Within CIO Mastermind’s topic-specific
     

The vendor consolidation trap: When one throat to choke costs more than it saves

13 de Agosto de 2026, 06:00

Vendor consolidation is sold as discipline. Fewer vendors, simpler architecture, better pricing through volume, one throat to choke when something breaks. Every one of those benefits is real on paper. The problem is that the biggest cost of consolidation rarely appears on the slide the procurement team uses to sell it internally, and it does not show up on the savings tracker until the first renewal cycle after the ink is dry.

Within CIO Mastermind’s topic-specific cohorts, which I sometimes facilitate, I hear a version of the same story often enough to recognize the pattern early. A consolidation program gets pitched against a strong multi-year savings target. The first year or two look good. Then a renewal arrives, the remaining vendor prices to the switching cost the company just built for itself, and a meaningful share of the projected savings quietly erodes. The company still ends up with fewer vendors. It does not always end up with the leverage the original business case promised.

What consolidation actually removes

What consolidation actually removes is competitive pressure on the vendor you keep.

That is the part most business cases leave out. Going from a dozen vendors in a category down to three or four feels like simplification, and it is. It is also a message to the vendors you kept about how expensive it would be for you to leave. The fewer live alternatives you maintain, the more accurately a vendor can price to your captivity rather than to the open market. A consolidation deck typically shows how many vendors are being reduced. It rarely shows how many of the remaining vendors could credibly be replaced inside a reasonable switching window. That second slide is the one worth building before the program starts. That capability is often missing.

Procurement teams are not being dishonest when they leave that slide out. Their incentive is to close the program and book the savings target, and the pain of a diminished market shows up two or three years later, on someone else’s dashboard. By the time the first hard renewal arrives, the people who built the original business case have often moved to a different project entirely, and the CIO who is still in the seat is the one negotiating from the position the program created.

The condition that decides the outcome

Consolidation programs succeed or fail on one question, and it has to be answered honestly before the program starts.

Can you walk from this vendor at renewal?

Not in theory. Not with twelve months of migration work. At renewal, inside the window the contract gives you, with a credible alternative that has been exercised recently enough to be real. If the answer is yes, the vendor will price to keep you. If the answer is no, the vendor will price to what you can absorb. Consolidation that leaves you unable to walk is a long-dated price increase with a celebratory kickoff meeting, dressed up as a savings program.

Contract language deserves particular scrutiny here, because it is where a lot of the false confidence comes from. Multi-year agreements often include price increase caps that look protective at signing. Those caps are usually written around the product as it exists at signing. Vendors may repackage functionality into new or higher-priced tiers, leaving the contractual cap covering less of what the company actually needs. A cap that looked airtight in the negotiation can end up covering a shrinking share of what the company actually pays for at renewal.

CIO.com has covered the leverage problem for years, including a piece on how to increase your renegotiation leverage with vendors that frames the handcuff problem directly. The advice in articles like that one is sound. The hard part is applying it in the middle of a consolidation program, when the procurement team is telling you that keeping alternatives warm is wasteful and the CFO is asking why the savings number is dropping.

The CIOs who hold their leverage tend to do one thing differently. They keep one credible alternative warm in every major category they consolidate, even after the primary vendor is chosen. Warm means more than a name on a shortlist. It means a live relationship with the alternative’s account team, some recent proof of concept, and at least one internal team that has actually touched the alternative’s platform. That readiness carries a real cost. Maintaining it may cost far less than an uncontested renewal can quietly take away.

The number that actually matters to the CFO

Most consolidation programs get measured against a single number: the savings projected in year one of the business case. That number rewards aggressive consolidation and quietly punishes the CIO who keeps an alternative warm, because the carrying cost of that alternative shows up immediately while the protection it buys only shows up at the next renewal, two or three years later. Judged against a one-year number, the cautious approach always looks worse.

The number worth tracking instead is the savings figure three years out, measured against what the business case originally promised. That is the number an aggressive consolidation program tends to miss once a full renewal cycle has run its course, and it is a fairer test of whether the program actually worked. It also reframes the conversation with the CFO. A carrying cost presented as insurance against a specific, quantifiable renewal risk is a different ask than a carrying cost presented as overhead, and it tends to get a different answer.

What to do if you inherited the problem

Most of the CIOs I talk to are not starting a consolidation program. They inherited one. They sit down in a seat where the leverage is already gone and the next renewal cliff is six or nine months out.

If that is where you are, the fastest way back to a real negotiating position is not to rebuild leverage everywhere at once. That approach takes years and asks the CFO to fund carrying costs across the entire portfolio before there is any evidence it will pay off. Pick one category instead, ideally not the largest one but the one where a credible alternative can be stood up fastest, and rebuild it inside twelve months. Speed matters more than scale here. A live proof of concept in a smaller category, exercised recently enough to be real, does more for your negotiating position than a partially built case in a larger one.

One proof that you can still move part of the portfolio changes the conversation at every other renewal table. A vendor who knows you have already done it once treats the next renewal differently than a vendor who has only heard you claim you could.

The second you cannot walk, the price stops being yours to negotiate. Most consolidation programs remove your ability to walk as their first move, and most CIOs do not realize they have given it up until the next renewal arrives and reminds them.

❌
❌