Visualização de leitura

When AI explains its decision, humans may stop thinking independently

AI is known to be confidently wrong, and now it’s influencing humans to be that way, too.

In a new study, researchers tested AI’s influence on humans reviewing innovation proposals, and found that AI recommender tools were persuasive enough to convince the evaluators to reject decisions made by independent human experts, thus causing them to pass on promising innovations. Similarly, they went along with AI approval of ideas that the human experts found sub-par.

Interestingly, reviewers were also more inclined to defer to an incorrect AI decision when the model explained itself. Narrative explanations degraded human judgment, rather than enhancing it. People did better when they weren’t given a reason for the AI’s decision.

“Our findings reveal that LLM explanations do not necessarily improve decision-making,” the researchers, associated with Harvard Business School, MIT, and the University of Washington explained in their findings. “Effective human-AI collaboration requires designs that preserve rather than supplant independent human judgment.”

AI rationale can undermine human judgment

Every enterprise screens proposed projects before pursuing them, but there is always uncertainty, and the risk of trade-offs like false positives (going forward with projects that ultimately fail) or false negatives (rejecting ideas that might have succeeded). For an example of the former, the researchers point to Google Glass or Amazon’s Fire Phone; for the latter, Xerox terminating early Ethernet and PostScript projects.

Because they have limited time and only basic information to go on, decision-makers are increasingly turning to LLMs that use predictive algorithms to generate recommendations and rationales based on context.

The researchers set out to explore AI’s role in what they called “early-stage innovation screening.” They judged how human evaluators were influenced by LLM recommendations, both with and without explanations from the model on how and why it reached its decision.

Their experiment asked 228 experienced evaluators to assess nearly 50 submissions to an MIT challenge. They tested three different scenarios: human-only proposals with no AI assistance; LLM evaluations with a written rationale for the decision; and black-box AI pass-fail recommendations with no accompanying explanation.

Evaluators’ decisions were then compared to those made by four human experts. Those decisions were considered the ‘correct’ baseline. They were judged on whether they outright complied with the LLM’s recommendations, overrode them, or productively overrode them, meaning they independently verified persuasive model outputs before making a decision.

Their decisions were classified as correct (agreeing with human experts’ positive/negative decisions), false positive (supporting submissions that experts would reject), and false negative (rejecting submissions experts would move forward with).

Overall, the evaluators accepted LLM recommendations 67% of the time. They agreed with both black-box and narrative LLM decisions roughly 75% of the time, but only agreed with human decisions 54% of the time.

Seemingly counterintuitively, black-box recommendations improved the quality of decisions (aligning them with human experts) but recommendations with narratives did not. When given an LLM recommendation to reject a submission and an accompanying reason why, evaluators disproportionately agreed, which reduced false positives, but “substantially” increased false negatives.

The researchers posit that this is because narrative explanations “suppress” productive overrides; LLMs provide a convincing argument that is easy to accept, essentially discouraging independent human verification. This contradicts a common assumption that LLM explanations augment human decision-making.

The researchers pointed out that people are cognitively predisposed to weigh negative information more heavily than positive information; the phenomenon is known as ‘negativity bias.’

“Rejection is an active, eliminative decision that feels more consequential and accountable than preserving optionality,” they wrote. It also maintains the status quo, avoids risk and bias, and requires no resource commitment.

LLM explanations provide “ready-made justifications” for going along with rejection decisions without independently verifying them; humans effectively offload their thinking to AI, researchers explained. Evaluators often rely on surface cues such as fluency, coherence, and seeming credibility. LLMs are particularly well-suited to exploit this because they are linguistically fluent and expert-like, creating an “illusion of explanatory depth.”

Thus, “individuals tend to overestimate their understanding of a decision despite limited insight into its reasoning,” the researchers wrote.

Finding a balance in recommendation systems

The researchers pointed out that their findings have “clear implications” for enterprises designing AI-assisted evaluation systems.

Enterprises should be cautious with LLM explanations in high-stakes decision-making, they advised. AI recommendations should not be taken at face value; they should always be tested before any associated deployment. This helps improve accuracy and encourages human reviewers to detect errors and learn how models operate, or potentially can even increase human-AI agreement.

In decision contexts such as quality control, compliance screening, or fraud detection, LLM explanations could support conservative human decision-making, the researchers noted. On the other hand, in tasks like early-stage screening, LLM narratives could undermine performance by “discouraging independent judgment and suppressing productive human override.” In this context, simpler or more opaque recommendations may preserve human discretion and verification.

Future design of explanation systems should factor in the nature of the task and the potential cost of errors made by AI, the researchers advised. Enterprises could experiment with models that support contrasting narratives (reasons to reject an idea alongside reasons to accept it) or uncertainty disclosures based on a fixed threshold, rather than on purely binary decisions. Systems could also be structured to invite human disagreement.

The researchers also noted that there is opportunity to test whether narrative explanations have different impacts at later stages of decision-making, when evaluators have fewer options, more information, and increased incentive to verify outputs and think the problem through.

Ultimately, the researchers emphasized, “organizations should treat AI explanations not as universally beneficial transparency tools, but as behavioral interventions whose effects depend on how evaluators process information under uncertainty.”

CIO 100 Award winners spotlight IT’s power to transform

Each year the CIO 100 Awards showcase outstanding IT initiatives, and every year they illustrate the power and potential of technology to transform how people work, how organizations perform, and the value they offer to customers.

The 2026 cohort of winners is no different. Each one demonstrates how IT executives and their teams successfully move from ideation to deployment to scaling a solution for the future, overcoming challenges and driving adoption along the way to ensure their organization gets a return on its investment.

[ Interested in meeting and learning from all CIO 100 winners? Join us next week at CIO 100 Awards & Conference in Frisco, TX. Limited seats remain! Register here ]

The winning initiatives come from a range of industries and utilize a host of technologies to achieve their goals, as is the case annually. A growing proportion of these stand-out projects leverage artificial intelligence, raising the bar on the art of the possible for all IT departments.

The following 10 award-winning projects serve as representatives for the outstanding work done by all the 2026 honorees.

ABB democratizes AI agent creation and deployment

Organization: ABB

Project: ABBY — AI Agentic Platform for Workforce Transformation

IT leader: Vikke Kandell, CIO

IT leaders at ABB, a manufacturer, had some big hurdles to clear when it came to building an AI strategy.

They had to overcome employee fears that AI would take away jobs, the potentially high cost of AI vendor licenses, and pressure from investors, customers, and executives to advance the use of AI in the enterprise.

“We looked at this and asked, ‘How do we address all this?’ and build something that the company is proud of,” says Babu Kuttala, vice president of data analytics and AI.

The answer is ABBY, an AI agentic platform that enables employees to create and deploy specialized AI agents for specific business tasks.

To build ABBY, Kuttala and his team used best-of-breed LLMs (about 25 in total). They built a centralized orchestration layer using generative AI that integrates internal knowledge bases with external ecosystems, creating a unified platform where agents can access enterprise data, understand required actions, and execute tasks across multiple systems. And they created preconfigured skills so that employees could build agents tailored to their workflows without having to code.

ABBY was rolled out in 2025 to 100 users but is now used by 63,000 (more than 75% of the company’s workforce, Kuttala notes) with an average of 10,000-plus workers using it daily. IT continues to add LLMs and capabilities to expand use of ABBY even further, Kuttala says.

Belcorp modernizes manufacturing with Smart Factory

Organization: Belcorp

Project: QPlant — Smart Factory

IT leader: Venkat Gopalan, Chief Digital, Data, and Technology Officer

Legacy processes were limiting Belcorp’s ability to scale and compete. Its manufacturing relied on ERP-driven processes with limited shop-floor automation and weak connectivity across production, packaging, quality, and maintenance. The company depended heavily on manual records and post-process reconciliation, resulting in fragmented data, limited real-time insight, inefficiencies, and higher risks for errors.

Smart Factory changed all that. The IT initiative reimagined how manufacturing teams work “by creating a connected, data-driven environment where production, quality, maintenance, and operations are aligned around real-time information and standardized execution,” says Venkat Gopalan, chief digital, data, and technology officer.

At Smart Factory’s core is a manufacturing execution system that orchestrates production workflows, quality processes, and operational execution, he explains. IoT-enabled equipment integration and a centralized SCADA platform provide real-time visibility into shop-floor operations, while electronic batch records digitize production execution, strengthen traceability, and reinforce compliance by design.

Integrating those operational technologies with the company’s enterprise platforms was another critical component of success, Gopalan says, creating a trusted flow of real-time data across manufacturing, quality, maintenance, and business systems. “This connected architecture transformed isolated data into actionable insights, enabling faster decision-making, greater operational visibility, and continuous improvement across the manufacturing lifecycle,” he adds.

The initiative generated more than $1 million in financial benefits in its first year alone.

“Most importantly, Smart Factory established the digital foundation for the future of manufacturing at Belcorp,” Gopalan says. “With real-time operational data and connected systems now in place, we’re well positioned to accelerate advanced analytics, AI-driven optimization, predictive maintenance, and other Industry 4.0 capabilities that will continue delivering value for years to come.”

Cohesity replatforms post-acquisition for commercial growth

Organization: Cohesity

Project: Lead to Cash Replatforming Program (Veritas Integration)

IT leader: Brian Spanswick, CIO

Cohesity set an ambitious objective: Complete an enterprise-scale lead-to-cash replatform in under six months.

That’s a tight timeline for any replatforming initiative, but Cohesity’s project had another layer of complexity. It followed Cohesity’s December 2024 acquisition of Veritas, a company twice its size in revenue, leaving Cohesity to integrate the majority of a global enterprise revenue engine into its own operating model without disrupting customers, partners, or sellers.

“We had to bring the two companies together, merge the workforces together, and create an overall harmonized organization and operating infrastructure platform,” says Eric Brown, who as CFO and COO led the project.

The program migrated heavily customized CRM, CPQ, PRM, ERP, and subscription platforms (some of which were “very brittle, very bespoke,” Brown says) to a unified SaaS CRM, CPQ, and ERP environment with uninterrupted selling, billing, and partner operations.

This was no lift-and shift, Brown stresses. “It was a business process optimization project as well. We want to run very efficiently, so we questioned everything and used the migration process to simplify and streamline the business in every possible respect.”

The initiative enabled continuity for 13,000-plus customers, protected revenue during integration, and established a scalable commercial foundation for future growth.

Brown cites several factors that contributed to success. First, leadership was upfront about what it would take to meet the deadline, a process that involved carefully prioritizing the capabilities that would appear in the first iteration. Leadership also streamlined decision-making, establishing office hours that “ran with military precision” to handle issues. And the company selected a specialized partner, requiring its top talent be assigned to Cohesity.

Dairyland Power goes agentic to protect field crews

Organization: Dairyland Power Cooperative

Project: ODIN — Organizational Effectiveness Agentic AI

IT leader: Nate Melby, VP and CIO

Dairyland Power Cooperative had amassed a large collection of field observations, incident reports, near-misses, safety rules, and work methods that could yield insights into processes and practices that could help protect its workers.

But the insights were essentially out of reach, trapped in siloes.

Dairyland’s organizational effectiveness team turned to CIO Nate Melby for help unlocking those insights. Melby then turned to agentic AI, recognizing that the technology could address the team’s need to make better use of its data.

“This was about finding insights on how to work more safely,” Melby says. “It’s about preventing incidents.”

The collaboration between the two teams created ODIN, the first agentic AI implementation of its kind in the electric utility industry.

Focused on worker safety, ODIN autonomously connects the collective safety knowledge of the organization and delivers actionable insights directly to field crews at the moment work is planned.

ODIN was developed through a hybrid approach that combined an agentic AI platform and Dairyland’s internal private generative AI platform called VoltWrite. ODIN leverages LLMs, retrieval-augmented generation, and a coordinated swarm of autonomous agents.

Agents work together to analyze internal safety data, performance history, work practices, and safety rules and then synthesize the information into clear guidance on the safest way to perform specific tasks.

ODIN has produced results, including a reduction in OSHA recordable injuries and improvements in the quality and consistency of pre-job safety briefings.

ODIN was deployed in early 2025 for use by Dairyland’s workers in transmission construction and electrical maintenance, which are the highest-risk work areas. Dairyland is looking to expand ODIN’s use to other teams.

Dow’s digital sustainability ledger drives low-carbon sales

Organization: Dow

Project: Carbon Footprint Ledger

IT leader: Deb Bauler, Chief Information and Digital Officer

Executives at Dow consider the Carbon Footprint Ledger (CFL) as more than a technology or innovative carbon accounting methodology. According to Senior Global IT Director Jeremy Preston, CFL is “a digital business capability that enables Dow to translate sustainability investments into customer value.”

CFL transformed how Dow uses greenhouse gas emissions data. It combines a methodology aligned to international standards with an enterprise-scale digital platform. It also integrates manufacturing, supply chain, commercial, and sustainability data to generate product carbon footprints under enterprise-level governance and management at scale.

In doing so, Preston says it creates “a trusted, traceable link between low-carbon processes and raw materials implemented across its manufacturing network and the lower-carbon products customers seek.”

The technology team worked closely with sustainability and business teams, collaboratively developing the capabilities needed to reconstruct product genealogy, maintain end-to-end data lineage, track low-carbon attributes across interconnected manufacturing processes, and generate product carbon footprints that can support customer offerings and commercial transactions.

CFL was built on Dow’s Integrated Data Hub and in partnership with Boston Consulting Group and Databricks.

The core CFL platform is fully deployed and supports commercial transactions today.

Preston says CFL “enables Dow to turn sustainability investments into customer value, commercial differentiation, and new growth opportunities.” Dow reports that it has driven hundreds of millions of dollars in low-carbon product sales in 2025 and 2026.

The company is now expanding its use. “We are extending adoption across additional products, manufacturing networks, business segments, and customer use cases while continuing to enhance automation, analytics, and integration with commercial processes,” Preston says.

J&J transforms quality management with AI

Organization: Johnson & Johnson

Project: Q&C Strategy

IT leader: Michael Comprelli, Vice President, Head of Technology, Technical Operations, and Risk; Joel O’Connor, Head of Technology, Medtech Quality, and Compliance

Johnson & Johnson is using AI to transform quality management through its Q&C Strategy.

QuIn is an AI-powered digital assistant that fuses human expertise with machine learning, automation, and data-driven insights to boost efficiency, reliability, and worker impact. By embedding gen AI into core quality management systems processes, QuIn proactively gathers actionable insights, increases operational efficiency, and allows teams to focus on high-value, patient-centric work.

Cora is an innovative generative AI platform that provides regulatory intelligence monitoring, impact analysis, and augmented content revision. Cora assists with document analysis, compliance comparison, stakeholder analysis, policy/standard creation, procedural/document updates, and document comparison. Cora is purpose-built for regulated environments, validating outputs against source material and offering a user experience that instills trust in the outcome.

QuIn and Cora, which automate time-intensive tasks and democratize information access, are on track to deliver significant value, with J&J reporting more than $62 million in documented true cost savings by 2028 from QuIn alone. Cora delivered $2 million in cost efficiency in 2025 and will deliver a documented cost savings of $25 million by 2028.

“Our teams proved responsible AI can be applied meaningfully in a highly regulated environment without compromising the rigor, accountability, or human judgment that quality requires,” says Michael Comprelli, vice president, head of technology, technical operations, and risk.

He continues, saying that J&J “moved these ideas beyond experimentation and into products that employees use in their daily work. We did that by bringing together Quality expertise, product management, data engineering, architecture, cybersecurity, user-experience design and AI engineering around a common purpose.”

JLL brings intelligent automation to business services

Organization: JLL

Project: Business Service Digitization

IT leader: Pinak Dash, Global Head of JLL Business Services and Legal Technologies

JLL launched its digitization initiative to drive process redesign as well as systematic AI and RPA deployment across JLL Business Services (JBS).

The initiative was designed to address inefficiencies that hampered scalability and competitive positioning. It was also designed to eliminate manual processes that consumed thousands of hours across finance, HR, legal, procurement, marketing, research, IT, and lease administration.

Pinak Dash, global head of JBS and legal technologies, says the digitization initiative had a dual-strategy combining traditional digitization with generative AI innovation to hundreds of processes.

JLL lists three innovations critical to the program’s success.

First is a hybrid platform that integrates RPA with JLL’s proprietary AI platform called Falcon, which created intelligent automation that adapts and learns. It enables real-time process automation, intelligent document processing with automated extraction/validation, and smart decision-making for continuously optimizing workflows.

The second innovation is its use of ProHance for real-time process monitoring and enabling of data-driven optimization. Sensors capture granular productivity metrics, identify bottlenecks, and provide actionable insights for continuous improvement across automated and manual processes.

Third is its custom AI assistants and transaction agents. Falcon-powered assistants provide intelligent knowledge search while specialized agents execute complex transactions across enterprise SaaS platforms. These handle multisystem workflows, reducing human touchpoints while maintaining accuracy and compliance.

Dash says the initiative has delivered quantifiable benefits through improved efficiency, accuracy, and quality of services provided to clients.

“The initiative delivers on our business goals, makes us more efficient, provides customers better service, and it opens up the capabilities and bandwidth of our people to do what they like to do and to find innovative ways to serve our business,” he adds.

Nationwide partnership platform delivers efficiencies, business growth

Organization: Nationwide

Project: Enterprise Digital Platform (EDP)

IT leader: Michael Carrel, EVP and CTO

Nationwide’s new Enterprise Digital Platform (EDP) gives the company “a scalable way to connect with external partners quickly, securely, and consistently across all areas of our business,” says company EVP and CTO Michael Carrel.

He explains that “instead of treating every integration as a custom effort, EDP creates a common front door for digital products, documentation, onboarding and governance.”

That innovation has produced better experiences for the company’s partners. It saves time for Nationwide teams, partners, and customers. And it supports faster launch times for new products and enables growth across the business.

“EDP changed the model from fragmented, point-to-point integrations into an enterprise platform built around reusable digital products. That shift lets us support a range of integration options in one governed environment, meet partners at different stages of technical maturity, and add new capabilities over time without redesigning every relationship from scratch,” Carrel explains.

EDP uses cloud-native microservices, role-based access control, and advanced analytics. Nationwide IT created modular microservices to make EDP more scalable, resilient, and adaptable. And IT decoupled it from infrastructure-specific dependencies so that it would be a platform-agnostic developer portal. That, Carrel says, reduced operational constraints across environments.

Additionally, IT shifted from a user-specific model to role-based access, which improved security, simplified administration, and better served the needs of different audiences.

Meanwhile, robust analytics delivers visibility into platform usage and performance, which Carrel says helps ensure Nationwide continuously evolves the platform based on measurable outcomes.

The core platform is fully deployed, with Nationwide planning to expand it.

“Our Enterprise Digital Platform is more than a piece of technology,” Carrel notes, “it represents a strategic enabler to support growth objectives across Nationwide’s businesses.”

PITT Ohio fast-tracks shipment requests with AI assist

Organization: PITT Ohio

Project: No Touch Email (N@TE AI)

IT leader: Scott Sullivan, President and CEO (formerly CIO)

As PITT Ohio started its AI journey in 2024, the mandate was clear: Use the technology to solve “real problems,” says Ryan Carner, director of enterprise IT solutions.

“We wanted to hit the ground running and find a problem that was solvable,” Carner says, noting that the company also wanted to use the experience to build in-house AI skills. “The idea was to find a business case for AI that would be our first but not the only one.”

PITT Ohio leaders decided to tackle what Carner describes as a “mundane but very important task for how our business operates”: handling emails to the customer service team.

The need was significant. Customer service representatives were manually processing hundreds of pickup request emails daily, each requiring five to 15 minutes to interpret and re-enter shipment details into the company’s transportation management system (TMS). The emails were complicated, containing a lot of information submitted in nonstandardized ways and varying formats. This repetitive task consumed valuable time, introduced errors, and delayed customer response.

N@TE uses generative AI and natural language processing to transform unstructured email content into structured pickup orders automatically and in real-time. N@TE scans incoming emails, extracts key shipment data, and creates orders directly in the TMS via API integration. It operates seamlessly within existing workflows, requiring no change in customer behavior or retraining of staff.

PITT Ohio deployed N@TE in 2025, and the company also secured a patent for the product that year. N@TE has produced a 30-60X increase in processing speed, 99% accuracy in extracting and populating order data, and a 70% reduction in handling costs per pickup order.

SMU builds AI adoption through grassroots ambassador program

Organization: Southern Methodist University

Project: Scaling AI Without Scaling AI: Organizational AI Scaling Through Willingness

IT leader: Jason Warner, Associate CIO

Like executives in most organizations, leaders at Southern Methodist University encountered mixed attitudes about AI. Some workers had little interest in using the tech, others were afraid it would take jobs, still others were curious about what it could do.

Associate CIO Jason Warner and other leaders decided to leverage that last group, believing the best way to get SMU faculty and staff to embrace AI was to use enthusiasts to help smooth the way.

So, instead of treating AI as a conventional technology rollout, Warner and his colleagues built opt-in communities of practice known as the AI Coalition of the Willing and Operation Copilot.

The goal, Warner says, was to build institutional capability, reduce risk, and generate momentum.

“We knew the fastest way to scale AI was to scale the willingness of people to use the technology, and not talking to people about cost savings and the like,” Warner says, adding that willing users as great ambassadors and evangelists who showcase in formal and informal ways the technology’s potential for hesitant or skeptical colleagues.

Participating faculty members have access to a licensed ChatGPT account as long as they use it. Staff members have access to Copilot accounts after taking a self-paced training course and likewise must use it to keep that access.

Warner says these willing workers are demonstrating the benefits of AI (significant time reclamation, reduced cognitive load, improved quality of outputs, expanded professional capacity).

SMU is now moving to a single solution and scaling AI, confident that its use will deliver returns following in the footsteps of the early adopters.

Interested in meeting and learning from all CIO 100 winners? Join us next week at CIO 100 Awards & Conference in Frisco, TX. Limited seats remain! Register here 

The blueprint for innovation: 3 ways regulatory readiness is a competitive advantage

Too often, brands treat compliance as a downstream exercise. Teams build products, launch new capabilities and then tack on controls afterward.

The pace of technology evolution and adoption has never been faster, and regulatory bodies are doing their best to keep up. For brands, that means they’re standing on shifting ground. They need  to modernize legacy infrastructure, adopt AI responsibly, deliver better customer experiences, maintain trust and navigate increasingly complex regulatory requirements – all at once.

I’ve witnessed this shift firsthand in payments. Fraudsters adapt faster than regulatory cycles, and customer expectations continue to rise regardless of where legislation stands. In one of the most highly regulated sectors, waiting for new mandates to arrive is a losing strategy.

The brands that lead have embraced regulatory readiness as an advantage to better inform technology architecture, operating models and partner strategy.

If I had one piece of advice for CIOs, it would be to treat compliance as part of the blueprint instead of the punch list at the end of a build. With a controls-by-design approach, a collaborative culture, and the right partnerships, any brand can embrace change with confidence and resilience.

3 ways regulatory readiness is a competitive advantage

1. Build a solid foundation

One of the most impactful strategies I’ve seen is the shift from compliance-after-the-fact to controls-by-design.

Forward-thinking financial institutions increasingly treat regulatory frameworks like DORA and the EU AI Act as design principles rather than external requirements. Instead of asking how to retrofit compliance into modern systems, they are asking how thoughtful governance can shape modernization from day one.

For example, the EU AI Act mandates transparency for high-risk AI systems like automated credit scoring. Instead of burying disclosures in the fine print, a smart bank builds an interactive feature directly into its digital banking app, which allows customers to simulate how adjustments will improve their approval odds. By doing so, they transform a regulatory obligation into innovation that builds trust.

After all, when an AI-driven decision fails, customers do not blame the algorithm. They blame the brand. The controls-by-design approach helps ensure those risks are anticipated and managed before they reach the customer.

This feels particularly urgent in the payments industry, where FedNow and stablecoins allow funds to move instantly – and irrevocably. As settlement windows shrink from days to seconds, brands need to embed capabilities like behavioral monitoring, AI-driven fraud detection, account verification and orchestration functionality directly into the transaction architecture itself – as part of the initial design – to identify and mitigate fraudulent activity as it evolves. Regulation, like Nacha’s new rules around ACH fraud, reinforces that direction, but for trust-focused brands, the work begins long before the rules change.

Each of these examples points to the same trend. Brands that embrace a controls-by-design philosophy are constructing technology architectures that are ready to adapt long before the inspectors arrive on site.

2. Align your crew

Technology architecture is only half of the story. The other half is how well your crew works together to bring that architecture to life.

For years, compliance lived in its own lane. Governance acted like a checkpoint. When technology evolved in predictable cycles, that made sense. But today, the brands making the greatest progress build shared accountability into their operating models so they can adapt to regulation in a more coordinated, consistent way.

After all, a construction project is only successful when electricians, plumbers, framers and masons coordinate every step and trust the work happening around them.

The same is true in the enterprise. Instead of focusing on separate priorities, product, engineering, operations, risk and compliance must align around shared outcomes, with greater transparency into how decisions are made, ongoing oversight and continuous feedback loops between teams. As a result, regulatory readiness becomes part of how the business works every day, change becomes easier and the broader benefits across the organization become clear.

In many organizations, I’ve observed how harmony between teams not only increases compliance but also fosters greater customer-centric innovation. When teams operate from a shared, real-time view of the customer, every interaction becomes more connected. Customers experience one brand, not a collection of disconnected teams.

That spirit of collaboration becomes even more important as AI moves deeper into customer-facing and operational workflows. AI innovation has outpaced AI regulation, which makes it even more important for brands to take the initiative to ensure proper controls are in place.

We are already seeing this play out with SR 26-2, the Federal Reserve’s latest guidance on AI for banks. While it establishes important expectations around model risk management, it leaves room for institutions to determine how agentic AI and generative AI should be governed. Instead of treating this as carte blanche, banking leaders should see this as an opportunity to build trust. By leading the way with governed, responsible GenAI and agentic AI operating models, banks can win customers’ trust long before regulation requires it.

No single department should shoulder that responsibility alone. Product teams understand how AI shapes the customer experience. Engineering teams understand how models are built, deployed and monitored. Risk and compliance teams understand governance expectations, while operations teams see how those decisions play out every day. Effective AI governance and innovation emerge when those perspectives come together around a shared view of accountability.

3. Expand your toolkit

Innovation in today’s regulatory environment requires more tools than you may have in your own toolkit.

Technology is more complex, fraud threats evolve faster and AI capabilities require significant investment and ongoing tuning. At the same time, brands have to stay ahead of customer expectations, market dynamics and evolving risk requirements.

It just doesn’t make sense to build every capability yourself when trust, resilience, compliance and speed-to-value are such integral parts of the equation. 

Throughout my career, I’ve seen success with a build-buy-partner approach that brings together the right tools for the right project.

This is particularly important in highly regulated environments, where implementation risk can be as significant as technical risk. That’s where proven results – especially through partnership – might take precedence over experimentation.

I went through this consideration just recently. CSG Forte partnered with IBM to launch PaymentsProtection.ai.

We set out to provide customers with AI-powered fraud detection and financial risk management without spending years recreating capabilities that already existed. By partnering with IBM, we were able to access additional specialty tools: AI capabilities, real-time monitoring, financial risk management expertise and external validation in one of the most sensitive areas of payments. The collaboration reduced fraud losses by 50-70%, lowered false positives and offered customers a smoother, safer experience.

In a market that never stands still, the right tools give brands the freedom to build with greater precision, adaptability and purpose.

Raise the standard

Successful brands are changing how they think about regulation. Instead of looking at it as a burden or a constraint on innovation, they are treating it like a key factor in architectural decisions, crew alignment and partner strategy.

That approach increasingly separates the brands raising the standard from those struggling to keep up. It changes the role regulation plays within the business. It infuses trust, governance and adaptability into a brand’s foundation.

Those capabilities make it easier to scale new builds, navigate future change and innovate with confidence as markets, customer expectations and regulatory requirements continue to charge ahead.

The brands shaping the future won’t be scrambling to reinforce the structure after the cracks appear. They’ll be the ones that construct resilience from the very beginning.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

OpenAI’s New GPT-5.6 Is Coming Sooner Than You Think

OpenAI is set to launch GPT-5.6 after a US security review, raising new questions for enterprise AI access, safeguards, and governance.

The post OpenAI’s New GPT-5.6 Is Coming Sooner Than You Think appeared first on TechRepublic.

Meta Adds WhatsApp Usernames: Here’s What You Need to Know

WhatsApp is rolling out usernames so people can chat without sharing phone numbers. Here’s how reservations, username keys, and rules work.

The post Meta Adds WhatsApp Usernames: Here’s What You Need to Know appeared first on TechRepublic.

iPhone 18 Leak: Apple’s Next Pro Design May Have Appeared Online

Leaked Tata files reportedly show possible iPhone 18 Pro design details, factory images, and supplier records ahead of Apple’s expected September launch.

The post iPhone 18 Leak: Apple’s Next Pro Design May Have Appeared Online appeared first on TechRepublic.

The White House's post-quantum executive order is an important milestone. It’s time to get to work

On June 22, 2026, President Trump signed Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks." The order sets a December 31, 2030, deadline for federal agencies to transition their most sensitive systems to post-quantum encryption, and a December 31, 2031, deadline for post-quantum authentication. The EO also directs federal contractors to comply with post-quantum Federal Information Processing Standards (FIPS) by the end of 2030.

We welcome this executive order. The U.S. government has a long track record of using federal leadership and procurement to drive adoption of new technologies across the broader industry. We've seen this work with IPv6, with routing security and the Resource Public Key Infrastructure (RPKI), and with DNSSEC, and we’re glad to see this tradition continue with post-quantum cryptography.

The EO is especially important at this moment because the timeline for Q-Day, the day that quantum computers can break the public-key cryptography used across the Internet, has been accelerated. In April 2026, Cloudflare moved our own target for full post-quantum security to 2029, following research breakthroughs from Google and Oratomic. This EO updates guidance from 2024, when the National Institute of Standards and Technology (NIST) stated that the classical public key cryptography used across the Internet (namely RSA and Elliptic Curve Cryptography, which can be broken once powerful quantum computers become available) should be deprecated by 2030 and disallowed by 2035. 

The Internet’s transition to post-quantum encryption is well underway, while the transition to post-quantum authentication has only just begun. Today, over two-thirds of browser traffic to Cloudflare's network is protected with post-quantum encryption, and most of our products support post-quantum key agreement. Our SASE platform, Cloudflare One, provides post-quantum encryption across all major on-ramps and off-ramps, including TLS, MASQUE, and IPsec. We've recently started deploying post-quantum authentication and aim to be fully post-quantum secure by 2029. The EO is an excellent foundation and builds on work from the previous two Administrations. We've been doing the work the EO is asking federal agencies to do since 2019, we have some thoughts on what the order gets right, we see opportunities for the Office of Management and Budget (OMB) to strengthen and facilitate cost-effective agency migration, and we provide a roadmap for how organizations and agencies can advance their transition most effectively.

The EO’s requirements for federal systems

The bulk of the EO's binding requirements are aimed at two categories of federal systems: High Value Assets (HVAs) and high impact systems. HVAs are federal information or systems designated by OMB as the government's crown jewels: systems whose compromise would significantly affect national security, foreign relations, or public confidence. These include databases that hold millions of federal employee records, systems that process classified intelligence, or platforms that manage federal financial transactions. Meanwhile, high impact systems are those where confidentiality, integrity, or availability is rated "high" under FIPS 199, meaning a breach could cause severe harm including loss of life, major financial damage, or significant degradation of an agency's ability to carry out its mission.

The EO has the power to bind federal agencies, but not other organizations (i.e., critical infrastructure, state, local, tribal and territorial governments, academia, civil society). That’s why the EO only gives these deadlines to federal agencies:

National Security Systems are explicitly excluded from these deadlines. They are on a separate, classified track managed by the NSA with deadlines between 2030 and 2033 already set in 2022.

Two migrations: encryption and authentication. Both should begin now.

The EO splits the PQC migration into two phases: post-quantum key establishment (encryption) by 2030, and post-quantum digital signatures and certificates (authentication) by 2031. This accurately reflects the availability of post-quantum encryption across the Internet today. Our own deadline for full post-quantum readiness (including authentication) is 2029, but we are amongst the earliest adopters in the industry. 

We are also happy to see the EO focusing on NIST-standardized post-quantum cryptographic algorithms and not Quantum Key Distribution (QKD), since QKD does not operate at Internet scale due to its need for specialized hardware and dedicated physical links between sender and receiver.  

Now let’s have a deeper look at the two migrations called for and required in the EO: post-quantum encryption and post-quantum authentication.

Post-quantum encryption is needed today to stop harvest-now-decrypt-later attacks, where an adversary collects encrypted traffic today and decrypts it later once quantum computers are powerful enough. Post-quantum encryption is especially valuable for organizations handling data that will still have value to adversaries 3-10 years from now, like government agencies, banks, healthcare organizations, defense contractors, and telecom providers.

Post-quantum authentication stops an adversary that has a quantum computer from forging certificates to impersonate servers, generating malicious code signatures, or gaining unauthorized access to systems.  Post-quantum authentication is needed only after Q-Day risk materializes, because it stops attacks that are possible only once a cryptographically-relevant quantum computer (CRQC) exists.

It’s important to put the migration timelines in context with advancements in quantum computing. In addition to yesterday’s EO on post-quantum security, President Trump also signed an EO to accelerate deployment and commercialization of quantum computing, sensing, and networking. The fact that the EO sets a 2031 deadline for post-quantum authentication tells us something important: the U.S. government believes there is a non-negligible chance that a CRQC could be operational around that time. 

Road to Quantum Safety

What about the state of these two technologies? The migration to post-quantum authentication is a bigger challenge than post-quantum encryption for a few reasons, including:

  • Post-quantum ML-DSA digital signatures are larger than classic digital signatures, which could have an impact on performance of some systems, for instance in short-lived TLS connections. That’s why we are working with Google Chrome on Merkle Tree Certificates to solve the performance problem for TLS. 
  • The dependency chain for post-quantum authentication is longer, requiring coordinated upgrades across clients, servers, certificate authorities, certificate transparency logs, root stores, and browsers. 
  • There is only limited ecosystem deployment of post-quantum authentication so far, as compared to the much broader deployment of post-quantum encryption.

It is interesting that the EO sets a one-year gap between the encryption and authentication deadlines. One extra year of calendar time is tight, so this work cannot proceed sequentially. The ecosystem needs to start working on both of these targets concurrently, or we will miss this 2031 deadline. 

Cryptographic deployment across the Internet cannot happen without standards developed by the Internet Engineering Task Force (IETF). They are working to transition their protocols to post-quantum cryptography.  The TLS community is ahead, with the IETF PLANTS working group making good progress on post-quantum certificates for TLS. There is much work to do here, and we look forward to supporting the IETF in its efforts. 

Supply chain pressure that helps everyone

The EO includes requirements for federal contractors, which may turn out to be the most impactful part of the EO. 

Namely, the FAR Council must publish proposed rules requiring "covered contractors" to comply with NIST FIPS incorporating PQC algorithms by December 31, 2030 (Sec. 6(c)). The FAR Council must also publish proposed rules requiring contractors to implement vulnerability disclosure programs that cover cryptographic vulnerabilities (Sec. 6(d)). These proposed rules need to go through notice-and-comment rulemaking, but the EO has a December 31, 2030, target which is still important. This deadline is one year earlier than federal agencies are required to complete their post-quantum authentication migration, so that federal contractors will be ready before agencies hit their own deadlines.

Federal agencies can only migrate to PQC if the products they buy support PQC. To put this into practice, CISA released its Product Categories for Technologies That Use Post-Quantum Cryptography Standards, drawing a clear line between technologies where PQC is already "widely available" versus those still "transitioning." The "widely available" list includes cloud platforms (IaaS, PaaS), web browsers and servers, chat and messaging software, and endpoint security products like full disk encryption. For these categories, CISA's guidance is clear: organizations should procure only PQC-capable products. The "transitioning" list, where PQC is not yet widely available, includes networking hardware (routers, firewalls, switches), identity and access management systems (HSMs, certificate authorities, identity providers), email servers and clients, and database systems.

By telling contractors their products must be PQC-compliant by 2030, and directing agencies to immediately favor PQC-capable vendors in mature markets, the federal framework forces the vendor ecosystem to ship PQC-capable products on a fixed timeline. Products that vendors build to federal requirements will end up used by hospitals, banks, universities, and small businesses, which makes PQC support more broadly available. Cloudflare is among the many vendors subject to these requirements, and because networking software and cloud services are already designated by CISA as widely available PQC categories, we've already shipped post-quantum encryption across most of our products at no extra cost

Critical infrastructure and PQ for everyone

The EO also speaks to critical infrastructure: energy, financial services, water, transportation, telecommunications, healthcare, and other systems whose failure would have a serious or significant impact on the country. While the EO has no hard migration deadline for critical infrastructure owners and operators, the EO directs certain federal agencies to "assist" critical infrastructure owners and operators with their PQC migration plans (Sec. 5(a)).

While the EO focuses mostly on federal agencies and critical infrastructure in the U.S., post-quantum cryptography is important to every Internet-connected individual and organization. Harvest-now-decrypt-later attacks are a risk today. And after Q-Day, the risk of unauthorized access by an adversary armed with a quantum computer will impact any organization, big or small. When we launched free universal SSL in 2014, our CEO Matthew Prince wrote:

Having cutting-edge encryption may not seem important to a small blog, but it is critical to advancing the encrypted-by-default future of the Internet. Every byte, however seemingly mundane, that flows encrypted across the Internet makes it more difficult for those who wish to intercept, throttle, or censor the web.

We feel the same way about post-quantum cryptography. That’s why every post-quantum upgrade we build is available to all customers, on every plan, at no additional cost.

Opportunities for OMB’s implementation guidance

The EO sets the direction, and now OMB has 90 days to provide important clarifications and operational guidance to achieve the most effective PQC migration across federal agencies (Sec. 4(b)). Based on what we've learned from our own PQC migration, here are a few elements that we suggest that guidance should include:

Define what it means to “transition.” The EO requires agencies to "transition" their systems to PQC, but it never defines what "transition" means. Does it mean the system supports PQC algorithms? That it prefers them? Or that classical cryptography has been disabled entirely?

These are very different security postures. A system that supports ML-KEM but still allows a classical-only TLS handshake is vulnerable to downgrade attacks. An adversary capable of intercepting traffic could force the connection back to classical key exchange. The system would have "transitioned" to PQC in name, but still be vulnerable to the same quantum attacks the order is trying to prevent.

History is instructive. When SSLv3 was deprecated after the POODLE attack in 2014, servers kept SSLv3 enabled for backwards compatibility, allowing attackers to force connections to downgrade and then exploit SSLv3's weaknesses. It took years for the ecosystem to actually turn SSLv3 off. To avoid repeating this pattern, we need a clear definition of “done” that includes disabling quantum-vulnerable cryptography to prevent downgrades.

Crypto agility: Crypto agility is the ability to swap cryptographic algorithms without re-architecting your systems. The EO mandates migrating to specific NIST crypto standards, but says nothing about building systems that can swap cryptographic algorithms if these algorithms need to change in the future. Crypto agility doesn't mean supporting every algorithm at once. It means building systems so that when the community converges on a better algorithm in the future, the upgrade is a configuration change, not a re-architecture. The OMB should include this in its guidance.

CBOM or quantum impact inventory? The EO directs CISA and NIST to publish guidance on the minimum elements for a cryptographic bill of materials (CBOM) within 270 days (Sec. 5(d)). A CBOM is an inventory of the cryptographic algorithms, protocols, and implementations used in a given hardware or software product, similar to a software bill of materials (SBOM).

In theory, CBOMs are a good idea. In practice, we'd caution against treating exhaustive cryptographic inventories as a prerequisite for action. A detailed CBOM of every algorithm in every library in every product takes a long time to produce, it can take federal agencies an entire procurement cycle of discovery tooling and consulting, and it potentially becomes stale by the time the inventory is complete. Also, a CBOM doesn’t list systems that should be using cryptography but are not. And a CBOM lists keys without an understanding of their purpose, making them less useful for organizations trying to understand the risk associated with a quantum-vulnerable key.

We think that a quantum impact inventory is a more productive framing. What would be the impact if the system or its data is compromised? How likely is that to happen? What measures can be taken to mitigate the risk, whether a drop-in replacement, a software update, or a compensating control like tunneling traffic over bulk post-quantum connection or isolating it from the Internet? How feasible is each option and what dependency chain does it create? Identifying these informs where to take action first. You can fill in the details of a full CBOM over time if that makes sense for your organization, but you should start by discovering your most exposed and impactful systems.

Making post-quantum cryptography affordable to all. True national resilience fails if post-quantum cryptography is treated as a gated luxury rather than a universal baseline. OMB policy must resist vendor lock-in or toll booths that leave underfunded critical infrastructure behind or increase technical debt at federal agencies. 

What to do now: don't wait for 2030

You do not have to wait for 2030 or an exhaustive cryptographic inventory to start your migration. History has shown that updating cryptography is hard and can take a long time; other organizations should start sorting out their migrations as well. So as we wait for OMB guidance for federal agencies, here’s what we recommend for all organizations:

Protect your Internet traffic now. Start with traffic that crosses the public Internet, because that is the easiest for adversaries to harvest now and the most immediately at risk. If your web traffic flows through Cloudflare, your connections are largely protected with post-quantum encryption. If your enterprise network uses Cloudflare One, your private network traffic is also protected. If your provider doesn't support post-quantum encryption, switch to one that does. Even if the individual applications running inside your network haven't been upgraded yet, start tunneling your traffic through post-quantum encrypted infrastructure to protect it in bulk, even if individual systems are not yet inventoried and upgraded.

Update procurement. Make "post-quantum encryption by default, at no additional cost, with a clear roadmap for post-quantum authentication and crypto agility" a requirement in every technology procurement. If your vendor charges extra for post-quantum security or doesn't have a roadmap or plan, ask why or find another vendor.

Quantum impact inventory. For traffic that stays inside your private network perimeter and is not exposed to the public Internet, the harvest-now-decrypt-later risk is lower because an adversary would need to be on your network to capture it. But you still need to know what cryptography your internal systems use, so you can plan your migration. Use a quantum impact inventory as a tool to prioritize your efforts, for example focusing on systems or connections that handle sensitive data or are exposed on the public Internet. 

Plan for authentication now. The 2031 deadline for post-quantum authentication will come faster than you think. Start identifying your long-lived keys, root certificates, and code-signing infrastructure. These are the highest-priority targets for a quantum attacker, and they have the longest dependency chains to upgrade. Now is a great time to update your software libraries and automate certificate provisioning even if post-quantum certificates are not yet available in your ecosystem. And make sure your vendors are planning to be ready for the looming post-quantum authentication deadline.

Aligning policy and international standards

At the same time, work should also start now on aligning global government policy with international standards. We were glad to see that Section 5(b) directs the State Department to engage foreign governments and industry groups to encourage adoption of NIST-standardized PQC algorithms. 

Here’s why this matters. Cryptography migrations cannot be run in a vacuum, with each country operating within its own borders. A TLS connection between a U.S. person and a server abroad only works if both ends negotiate the same cryptography. NIST has been running open international cryptographic competitions for decades. The AES competition (1997-2001) produced the encryption standard used across the Internet today, selecting a cipher designed by Belgian cryptographers. The SHA-3 competition (2007-2012) produced the latest hash standard, selecting an algorithm designed by a Belgian-Italian team. The PQC competition (2016-2024) followed the same open model: anyone could submit, anyone could analyze, and the winning algorithms were designed by international teams. ML-KEM, the key agreement standard now being deployed across the Internet, was created largely by European cryptographers. These are open, internationally vetted algorithms. NIST organized the competitions, but the results belong to the global cryptographic community. 

The risk ahead is fragmentation. If different jurisdictions mandate different algorithms, the result is cipher bloat and increased attack surface: more code to write, test, and audit, more surface for downgrade attacks, and slower deployment for everyone. We've seen this happen firsthand in IPsec, where the lack of an interoperable standard led vendors to ship proprietary PQ key agreement algorithms that couldn’t interoperate, delaying the migration by years. The TLS community went the opposite way, converging on a single hybrid key agreement (X25519MLKEM768), and deployment followed quickly.

We are big fans of NIST, and especially its leadership in vetting standards globally and standardizing cryptography worldwide. We encourage the Trump Administration to work with Congress to ensure that NIST has appropriate resources, staffing, and tooling to meet current and emerging deliverables in this EO and others, like America's AI Action Plan.

We'd like to see State Department-led engagement drive real alignment: adoption of the same NIST algorithms across allied nations, alignment on timelines, and mutual recognition of cryptographic algorithms and modules. The Internet is one network, and its cryptography should be one standard.

Speeding up CMVP

As a final note, the EO directs NIST to revise the processes used by the Cryptographic Module Validation Program (CMVP) to accelerate validations of cryptographic modules (Sec. 6(b)). Having bumped up against the CMVP program for years, we are extremely happy to see this in the order.

CMVP exists for a good reason. Federal agencies and their contractors need a way to verify that the cryptography inside a product actually does what it claims: that AES is implemented correctly, or that random number generators have enough entropy. CMVP has been tuned for a steady state where cryptography doesn’t change much.

Going forward, CMVP needs to be adjusted to accept the realities of the impending migration. We welcome the FedRAMP update stream that allows updated modules to be used immediately before final validation. This allows faster adoption of post-quantum cryptography, and correction of implementation errors that were missed in validation. Similar allowances for CMVP are essential.

Go forth and PQ all the things

This post-quantum EO is a meaningful step. It sets real deadlines and creates supply chain pressure that will accelerate adoption across the industry. 

For organizations starting their own migration, we suggest you start by protecting your public Internet traffic along with updates to your procurement requirements, followed by a quantum impact inventory to figure out where to focus next. Do not let cryptography inventory slow you down from deploying post-quantum encryption across your most sensitive systems immediately. 

Cryptographic deployment across the Internet depends on standards developed by the IETF. The TLS community is further along, but there is lots more work to do across other protocol communities, and we look forward to supporting those efforts.

Let us go forth and PQ all the things, quickly and together. Free TLS helped encrypt the web. Free post-quantum cryptography will help secure it for what comes next.

You can get started now on Cloudflare by visiting our PQC page.

Watch

❌