Visualização de leitura

Salesforce offers more Agentforce credits to drive adoption

Salesforce is updating some of the editions, or pricing tiers, of Agentforce Sales and Agentforce Service, a year after their rebrand from Sales Cloud and Service Cloud. The top three now bundle AI agents, analytics, Slack, security, and support with larger allocations of Flex Credits; two of the tiers are also increasing in price.

The Core edition replaces the old Enterprise edition, and its price goes up from $175 per user per month to $195, and now includes 500,000 Flex Credits. Advanced edition costs $395 per user per month and includes 1 million credits, replacing the $350 per month Unlimited edition. The Max edition replaces the old Agentforce 1 tier and now includes 2.75 million credits instead of 1 million for the same $550 per month fee, Salesforce said in a blog post.

The lowest tiers, Starter and Pro Suite, remain unchanged in features and price, although there is a hint that Salesforce is renaming the latter to Professional edition.

What is new in Agentforce Sales?

The new editions bring several capabilities to the base subscription of Agentforce Sales that were previously sold separately: The Core edition now includes Momentum, Slack Business+, and Tableau Next, while the Advanced edition adds Sales Programs, the Premier Success Plan, and additional security and data-protection capabilities. Max edition adds Agentforce for Sales, Agentforce Coworker, Salesforce Spiff, Sales Planning, Sales Programs, Salesforce Maps, Slack Enterprise+, and additional Tableau Next capabilities.

Under the previous Enterprise and Unlimited editions, Sales Programs was an add-on, Tableau Next was available through a separate Tableau+ purchase, and Agentforce itself had to be purchased separately.

What is new in Agentforce Service?

The new editions of Agentforce Service also incorporate capabilities that previously required additional purchases.

The Core edition includes case management, self-service Help Center, Slack Business+, and Slackbot; Advanced adds Agentforce Help Agent, Premier Success Plan, full sandbox, Backup & Recover, and Data Detect, and Max adds Service Rep Assistant, Workforce Engagement, Quality Management, IT Service, unmetered Agentforce Coworker access, and a library of service agent templates.

Under the previous Enterprise and Unlimited editions, Agentforce was available as a separate purchase, while capabilities such as additional security, data protection, and workforce-management tools were also packaged separately or reserved for higher-tier offerings.

Procurement simplicity could come at the cost of visibility

Salesforce said the new editions deliver from 50% to 70% greater value than those they replace, but realizing that value may not be straightforward, analysts warned, particularly as enterprises move from experimenting with Agentforce to deploying agents at scale.

While bundling more AI, analytics, security, Slack, and support capabilities into the subscriptions could simplify procurement of Salesforce products for enterprises, the economics could become more complicated once customers start consuming their included Flex Credits, said Manoj Chandra Jha, principal analyst at Nord-IQ Research.

That is because bundling more capabilities into a single subscription reduces the line-item visibility CIOs previously relied on, and most enterprise finance teams are still learning how to forecast for credit consumption, he said.

Without that visibility CIOs will find it hard to assess how Salesforce’s offerings compare with competing products, particularly when they are trying to determine the cost of specific capabilities or decide which components of a broader bundle are delivering value, he said.

Salesforce may be exaggerating the real value of the new editions, said Pareekh Jain, principal analyst at Pareekh Consulting.

“While CIOs may get more capabilities in a single package, they will still need to assess how much of that functionality employees actually use. A package may offer 60% more theoretical value, but that benefit can disappear if much of the bundled functionality or Flex Credits goes unused,” he said.

Overuse is also a problem, said Jha: As agent usage grows, enterprises could consume their included Flex Credits more quickly and eventually need to purchase additional credits, making actual usage a more important measure of value that CIOs should follow rather than the headline savings attached to the new editions, Jha noted.

New editions targeted at accelerating adoption

While Salesforce talks of value for money, analysts see its real goal with the new editions as accelerating Agentforce adoption.

Investment analysts raised concerns about questioned Agentforce’s customer traction in July, citing enterprise data readiness and the product’s maturity as factors holding back broader adoption. Salesforce, however, has pushed back, pointing instead to growth in deployments and usage.

Nevertheless, said Jha, “With Agentforce running at only a fraction of Salesforce’s 150,000-plus customer base, and analysts pinning the drag on messy enterprise data, folding security and analytics into every tier looks like Salesforce neutralizing the objection before a prospect can raise it.”

Salesforce said last month that its customers had increased their average number of agents from five in February 2025 to 13 by April 2026, while the average number of agent actions per account grew at a 31% compound monthly growth rate over the same period.

Jha sees the updated editions as aimed primarily at Salesforce’s existing customer base, giving companies already using its products more incentives and capacity to expand their use of Agentforce, rather than as a draw for new customers.

Salesforce said the new editions for Agentforce Sales and Agentforce Service are already available, and will soon be joined by new editions for Agentforce Industry.

Existing Agentforce 1 edition customers can upgrade to the new Max edition at no additional cost, the company said, adding that in the future, Max editions across its Sales and Service offerings will also include an allocation for Headless 360.

What Nvidia’s $13B acquisition of Hugging Face means for AI model choice

When Nvidia said Thursday that it plans to pay $13 billion to acquire Hugging Face, the question arose of whether the open AI platform would remain open when it becomes a unit of Nvidia. And the current lack of a single viable open alternative that does everything Hugging Face does for enterprises adds further complications for CIOs.

Rumors of the pending deal have been circulating for at least a week. 

In its announcement, Nvidia said, “Hugging Face will remain an open platform for the entire AI ecosystem. Developers will choose the models they want, the frameworks they want, the clouds and inference service providers they want and the computing platforms they want. Nvidia compute will not be required to build on or deploy through Hugging Face.”

It added that Hugging Face will continue to support open source and open weight models from every model builder, and “continue to support multi-cloud and multi-accelerator development and deployment, so builders can use the hardware and infrastructure that best fit their work.”

Hugging Face CEO Clément Delangue took to his X account to also reassure customers, noting, “open-source AI is at an inflection point” and pointing out that, for the business to scale, it needs “more compute, more support, more collaboration and more visibility. That’s why we went to talk to [Nvidia CEO] Jensen [Huang], who offered to do exactly that with us.”

Preserving the Hugging Face team

Nvidia is also attempting to retain some of the Hugging Face workforce. As part of the deal, according to Nvidia’s 8-K filing, the purchase price is $11.9 billion, with “approximately $1 billion” earmarked for “an equity-based retention program” for Hugging Face employees who agree to join Nvidia. It has yet to be announced how many members of the Hugging Face workforce, estimated to be almost 750, will be offered roles at Nvidia.

But despite the reassurances from Nvidia about maintaining the open nature of Hugging Face, analysts and consultants suggested that the truth may not be known until months, or even a year, after the acquisition finalizes sometime next year; the transaction is expected to close “in the first half of 2027.”

Cause for optimism

Enterprise CIOs can only wait and see what Nvidia will ultimately do. 

But in the meantime, there is cause for optimism, given the history of recent open source acquisitions, said Jason Andersen, principal analyst at Moor Insights & Strategy. 

“There is always a ‘sky is falling’ narrative” with these transactions, Andersen said, but in recent years, open source acquisitions have often turned out quite well.

“What happened to Red Hat after IBM bought it? Things got better,” Andersen said. “The same can be said for GitHub after Microsoft bought it. Or Google’s acquisition of Gemma. There are just too many examples of it going the right way.”

Justin Greis, CEO of consulting firm Acceligence, also sees this acquisition as potentially good news for enterprise CIOs. 

“If Nvidia turned [Hugging Face] into a walled garden or an obvious funnel toward Nvidia hardware, it could undermine the community and network effects it just paid nearly $13 billion to acquire,” he pointed out. “Nvidia is being unusually explicit that Hugging Face will remain model-, framework-, cloud- and accelerator-agnostic, including saying that Nvidia compute will not be required.” 

And, he added, Nvidia could indeed make Hugging Face even more enterprise friendly. 

“Nvidia itself points to the opportunity to improve Hugging Face’s reliability, safety, model evaluation, inference, and deployment capabilities. That is potentially a very big deal,” Greis said, noting that enterprises don’t simply need access to more models, they need confidence that those models can operate within complex environments with governance, security, performance, resilience, and lifecycle management around them.

Those needs make the combination compelling, he said: “Nvidia has the engineering depth, infrastructure expertise and ecosystem reach to significantly raise that bar. Hugging Face has been enormously successful as a developer and open-model platform. Nvidia now has the opportunity to help make it much more enterprise-grade: a place where companies can discover models, datasets, and AI components, but also increasingly evaluate, test, secure, operationalize, and deploy them with the level of confidence and rigor expected inside a large enterprise.”

Avoid a single dependency

Still, said Shashi Bellamkonda, a principal research director at Info-Tech Research Group, there are various practical steps that CIOs can and should soon take to preserve what they have already created within Hugging Face.

“This should be a clarion call for CIOs to treat Hugging Face and open source models as part of their enterprise supply chain, and if a production system depends on an artifact hosted on Hugging Face, keep a verified copy in a second registry, whether that is GitLab, Amazon S3, or an internal artifact store,” he said. “Enterprises should also consider the source for open models and develop a fallback plan such as the model developer’s own repository or another hub, because Hugging Face is the dominant platform today, but no enterprise should depend on one company’s availability, governance, or roadmap.”

Bellamkonda also pointed out that, by owning Hugging Face, Nvidia would gain valuable visibility into which models are gaining traction, how developers are deploying them, and which hardware ecosystems they run on. It would then “hold a powerful position in the distribution of new open models, so that combination of infrastructure ownership, market intelligence, and hardware influence should factor into CIO planning,” he said.

Mike Wilkes, enterprise CISO at Aikido Security, added that one of the factors that makes a CIO’s 2027 contingency planning in the face of Hugging Face’s new ownership difficult is that there are not that many large open source companies that could directly replace Hugging Face for an enterprise.

“No true replacement exists for Hugging Face at its scale, but there are ways to avoid making it a single point of dependency,” he said. “Azure AI Foundry is probably the closest enterprise alternative regarding model breadth, now advertising more than 11,000 models and supporting models from OpenAI, Anthropic, Meta, Mistral and others. AWS SageMaker JumpStart is another option, as enterprises can create private curated model hubs with their own governance controls. Google’s Model Garden is a third viable choice and supports both managed and self-deployed open models inside the customer’s own cloud environment.”

But adopting any of those alternatives means a move from an independent Hugging Face to Microsoft, Amazon, or Google, “so they change the concentration risk rather than eliminating it,” Wilkes noted. “The best enterprise strategy is not to search for another Hugging Face, but to separate model discovery from model custody. We can continue using Hugging Face to discover and evaluate models while mirroring approved models into an internal repository or registry under our control.”

Risk of increasing AI control by Nvidia

IDC’s Ashish Nadkarni, a group VP, said CIOs must also remember that the Nvidia move could give it various levers to even further tighten its control over global AI developments. 

“Hugging Face is like GitHub for AI. It is the default front door for open AI innovation: it’s where data scientists, machine learning engineers, and developers discover pretrained models, fine-tune them, and push them into production, or find open datasets to train their own models,” he said. “Owning that front door gives Nvidia a major position in the mindshare of today’s AI development personas.”

Consultant Brian Levine, executive director of FormerGov, also advised CIOs to stay alert. He predicted that Nvidia will exert greater control over Hugging Face efforts, but it will happen so gradually that it might not be noticed.

“The risk isn’t a dramatic reverse course. It’s a slow drift, where the Nvidia-optimized path quietly becomes the easy path, and everything else becomes the friction path,” he said. “Stop treating Hugging Face as a vendor-neutral utility and start treating it as a strategically-owned platform. That doesn’t mean leave. It means keep your options real and tested, not theoretical.”

Unanswered questions

And, from an enterprise CIO’s perspective, there’s another worry.

“Nvidia’s openness commitment is precise where it is cheap, and silent where it is expensive,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “The release promises that Nvidia compute will not be required, that multi-cloud and multi-accelerator support continues, and that developers choose their own models, each of which is a commitment about availability rather than about terms. Nothing in it addresses ranking, search placement, or default routing, and those are what decide which models a developer ever sees. Nobody has to be banned for the field to tilt. Gravity is enough and gravity is the part the pledge does not mention.”

This article originally appeared on InfoWorld.

Citrix buys company that containerizes Windows desktop apps independently of the OS

Citrix on Tuesday announced that it has completed the acquisition of longtime partner Numecent, producer of technology that containerizes and manages Windows applications.

The acquisition builds on joint efforts to integrate Numecent’s management tool, Cloudpager, with Citrix Desktop-as-a-Service (DaaS) after an integration announced in April let administrators natively publish and manage the application containers through familiar Citrix workflows.

Numecent’s other product, Cloudpaging, packages Windows applications into isolated application containers independent of the underlying operating system, streaming them to Windows endpoints on demand rather than requiring them to be included in a desktop image. 

Citrix plans to further integrate the technology into its platform, while also continuing Cloudpaging and Cloudpager support for physical Windows devices.

“Enterprise customers have told us for years that application management is one of the most painful parts of running a Windows environment,” said Shawn Bass, SVP and GM of Citrix DaaS, in the announcement of the acquisition. “Numecent has solved this in a genuinely elegant way. By bringing Cloudpaging and Cloudpager into Citrix, we can make this capability native to every DaaS and physical desktop deployment so IT teams get back the time they spend wrestling with images and app conflicts.”

Analysts and consultants said the move will help enterprise IT to some extent, but will also increase vendor lock-in with Citrix while potentially exposing enterprises to data security risks.

Good for Citrix customers

Gartner VP Analyst Stuart Downes said, “overall, this is a positive for Citrix customers,” but he stressed that the promised conversions “are not 100% compatible.” 

He said, “low-level integrations into the kernel are generally not successful” because code that needs the lowest level of OS integration usually needs direct links to the hardware. Still, he estimated that applications at the low level probably account for only 2% of enterprise applications. 

For the more typical apps, Downes said that there will likely be “north of 90% compatibility. It varies. There are quite a lot of complex factors in app virtualization.” But he emphasized that Numecent offers two components: Cloudpager and Cloudpaging, and “we have yet to see how Citrix will integrate both.”

Justin Greis, CEO of consulting firm Acceligence, also sees a lot of potential savings for the enterprise.

“Large companies can have thousands of Windows applications, including legacy, custom, industry-specific, and highly specialized applications,” he said. “Many have dependencies on particular versions of Windows, libraries, configurations, or desktop images. Every major desktop refresh, Windows migration, VDI program, cloud move, acquisition, or infrastructure modernization effort can therefore create another application testing and repackaging cycle. The ability to abstract more of the application layer from the environment underneath it can remove a meaningful amount of that friction.”

Noah Kenney, principal consultant at Digital 520, added that the theoretical advantage that Citrix can now offer has great enterprise potential.

But, he argued, this likely amounts to an enterprise IT pay less now, pay more later situation.

“There are operational savings here, which is why customers will adopt it, but the bill comes due when they try to leave,” Kenney said. “This is a good acquisition for Citrix and probably bad for enterprise leverage over time. Citrix can now lose the desktop and still keep the customer. Every application moved into Cloudpager raises the cost of the next migration. Customers get the simplification now and Citrix gets the switching cost later.”

Half right

Sanchit Vir Gogia, chief analyst at Greyhound Research, said that he reads the containerization pitch as half right. “The packaging premise is valid. The cross-operating-system execution premise is not,” he said.

Gogia pointed out that Numecent Cloudpaging packages a Windows application with its dependencies and streams it to a Cloudpaging Player on a physical or virtual Windows endpoint, where it executes locally. “A Mac or Linux user reaches that application through Citrix’s remote delivery, where it still executes on Windows. That is cross-platform access, not cross-platform execution,” he said. “A Windows application does not become a Mac application merely because its pixels arrive on a Mac. The container is a packaging promise and the boundary of that promise is Windows.”

That said, he noted that there is still a lot of value in the Citrix arrangement, because Cloudpaging separates an application from a particular Windows image and carries that package across physical and virtual Windows environments, including Arm-based devices. 

“The real advance is not escaping Windows,” Gogia explained. “It is making application change less dependent on desktop change. Microsoft’s own App Assure data puts enterprise application compatibility above 99.7%, and Cloudpaging’s commercial logic lives almost entirely inside the fraction that remains. At enterprise scale, the final 1% of applications can carry far more than 1% of the business risk.”

But, he added, “Existing Numecent customers need binding answers on entitlements, migration and exit. Citrix has bought control of a useful Windows application lifecycle. Control now has to prove itself, and the proof it owes customers is less complexity, not merely more control for Citrix.”

Possible risk

However, consultant Brian Levine, executive director of FormerGov, pointed out that the nature of these new Citrix capabilities could expose users to serious security issues, including the risk of data exfiltration. 

He sees Cloudpager as “essentially a privileged switch that can push software to every Windows endpoint at once, which is precisely the kind of mass-distribution channel that produced SolarWinds and Kaseya. Bolting it onto Citrix, whose NetScaler gear has been a favorite ransomware target through repeated ‘CitrixBleed’ flaws, may leave CIOs and organizations wondering who will focus on security for the combined entity, and how will it prevent the type of attacks we’ve seen against Citrix.”

Citrix was asked to comment on these security questions, but did not do so by publication time. 

This article originally appeared on Computerworld.

Federal judge rules for Anthropic in Pentagon dispute, nullifies government supply chain risk designation

The Trump Administration’s decision to punish Anthropic for its stance forbidding Claude’s use in domestic surveillance and autonomous weapons by identifying it as a supply chain risk to national security was “arbitrary and capricious,” a federal judge ruled on Thursday.

US District Court Judge Rita Lin said federal authorities had no legitimate reason to tell companies with government contracts that they couldn’t work with Anthropic.

“The undisputed record shows that the challenged actions constituted unlawful retaliation in violation of the First Amendment and that Anthropic was denied the pre-deprivation process required under the Fifth Amendment,” Lin said in her ruling, calling the designation “arbitrary and capricious.”

She stressed that the government action seemed punitive, and was not based on legal and national security risks.

The government’s words and deeds “confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model,” Lin wrote.

She pointed out, “a few days before the challenged actions began, Secretary Hegseth proposed applying the Defense Production Act to Anthropic, which would mean the company was essential to national security rather than a threat to it. Even now, the government is discussing collaboration with Anthropic on its new model, Mythos, in an array of sensitive contexts. None of that is consistent with a genuine fear that Anthropic is a saboteur [that] would poison its software to harm national security.”

The judge added that the stated government fears made no sense, noting that the usage policy applicable to Pentagon work is a purely contractual limit. “Anthropic is incapable of enforcing it technologically, and does not have direct visibility into how DoW [Department of War] uses its model,” she pointed out.

“Nothing in the Administrative Record describes, even at a high level, what technological means would give rise to the so-called ‘backdoors’ or could otherwise allow Anthropic to ‘disable’ or affect Claude during a DoW operation,” the judge wrote. “Anthropic has submitted unrebutted evidence that it lacks any technological means to access or control deployed models.”

Lawyers, consultants, and analysts who looked at the decision were confident that the case would be appealed, and that it will end up in the US Supreme Court. 

Alan Webber, program VP for national security, defense, and intelligence at IDC, said that Lin’s ruling “was that the label [supply chain risk] was retaliation for Anthropic refusing to loosen safety guardrails DoD [Department of Defense, aka the Department of War] wanted lifted, dressed up in national security language. Put another way, a government customer tried to use a supply chain risk designation as leverage in a contract dispute over model behavior and application, and not because of an actual vulnerability.”

Implications for CIOs

Webber said the implications for CIO strategy are concerning.

“If a government CIO is relying on a vendor’s contractual guardrails, this case says those commitments can potentially become the trigger for exactly the kind of blacklisting that risk registers are supposed to protect against,” Webber said, noting that anyone who paused Claude usage or froze a subcontract because of the DoD mandate has a legal basis to resume the initiatives. “But obviously that doesn’t mean they will, or even should, as this will be appealed.”

He added that competing AI vendors have been using the government action as a sales tool, and with this ruling, the argument that Anthropic is a designated supply chain risk ”just got weaker, which could lead to contract award disputes.”

Consultant Brian Levine, executive director of FormerGov, recommended that CIOs do what they should have always done: Evaluate all products based solely on their merits. 

“CIOs should focus on using the frontier models that they believe make the most sense for their business, considering factors such as effectiveness, cost, security, safety, and confidentiality,” he said. “Anthropic and the other large frontier models each have too much market share to make retaliation for their use realistic, and the administration seems to have already moved on from this particular battle.”

Justin Greis, CEO of consulting firm Acceligence, agreed that this case has profound implications for CIOs and their AI decisions. 

What the federal judge did was reject the leap from a commercial and policy disagreement to an expansive supply chain risk designation without a sufficiently grounded technical rationale or process, Greis pointed out.

“The court found that Anthropic did not have the ability to access, alter, or shut down models once deployed in the government environment, and that the government ultimately conceded Anthropic’s technology was not inherently riskier than other comparable black box AI models,” he said.

“I think that distinction matters enormously for CIOs and CISOs,” he stressed. “As AI becomes part of the operating fabric of an enterprise, ‘We don’t trust the vendor’ cannot become a substitute for a defined risk model. Organizations need to be able to articulate what the actual technical risk is, how it manifests, what controls exist, and whether the response is proportional to that risk.”

“That becomes particularly important with AI,” he added, “because people can easily conflate disagreements over model behavior, usage policies, ethics, contractual restrictions, and cybersecurity into one amorphous category called ‘AI risk.’”

Original government edict still problematic

Mark Rasch, a former federal prosecutor who is now general counsel at Unit221B, a threat intel and security consulting company, said he was surprised by how quickly government attorneys surrendered on this case. 

“One of the things that struck me is that the government appears to have abandoned any rationale it might have had for its decision about Anthropic,” he said. The government “came back with all these reasons, but then they abandoned them all when they had to prove them.”

But, he said, the government instruction to all government contractors to also shun Anthropic was problematic. 

“It’s one thing for the government to say ‘We’re not going to do business with you.’ It’s quite another thing to say ‘Nobody we do business with can do business with you either,’” Rasch said. “This says that if you are disfavored by the administration, they’re not just going to blacklist you and say they won’t do business with you. They’re going to say that nobody can do business with you.”

Supreme Court arguments will likely be very different

Rasch predicted that the legal arguments in the Supreme Court will be quite different, and will potentially sidestep the lack of evidence.

“In the Supreme Court, [the government’s] biggest argument will not be that ‘We are right that it is a supply chain risk,’ but that, ‘Whether we’re right or wrong is irrelevant. We get to make that [supply chain risk designation] decision, not the court.’”

That would mean that the Supreme Court Justices could avoid exploring whether the government made the right decision, and instead focus on whether the government has the unlimited right to decide who is a national security risk.

This article originally appeared on Computerworld.

Salesforce, Anthropic partner to deliver Claudeforce

Salesforce and Anthropic today announced they have expanded their strategic partnership to deliver Claudeforce, enabling customers of both companies to leverage Salesforce data, workflows, business logic, actions, and governance within Claude.

“What we’re seeing is that when people stop using Salesforce through the traditional human interface and start using it through an agentic interface, it dramatically increases the value of Salesforce,” Patrick Stokes, president of Applications & Marketing at Salesforce, told CIO.com on Wednesday. “They’re using Salesforce more than they ever have before.”

Stokes explained that momentum around the Claudeforce partnership began building after Salesforce’s TDX 2026 developer conference earlier this year. At the conference, Salesforce announced Headless 360, a platform that packaged Salesforce’s AI and developer tools into a headless, API-driven layer designed to help enterprise teams build agent-first workflows. It allowed AI clients like Claude or ChatGPT to read, write, and reason over Salesforce data without the traditional browser-based UI.

“It was a very popular decision among developers,” Stokes said. “Salesforce was actively endorsing people using Salesforce through an agentic interface rather than through the UI that we have had in place for 27 years.”

Developers immediately started hooking MCP servers up to their own agents. And Salesforce watched them struggle to scale their efforts.

“How do you do it for 100 or 1,000 users?” Stokes asked. “How do you deal with managed authentication to make sure it’s using the permissions of the user inside Salesforce? All the things that are necessary in order to scale this out weren’t really in place.”

Anthropic, the company behind Claude, was seeing the same thing. Its sales teams were using Salesforce through Claude and struggling to scale it. The two companies worked together to create a solution and decided to productize the result as Claudeforce.

Prebuilt sales skills and token consumption

The first fruit of the Claudeforce partnership is Salesforce in Claude, a plugin with 37 prebuilt sales skills. Stokes said these skills will enable sellers and agents to reason over live revenue context, automate pipeline updates, and take governed action within Claude. Claude-powered agents can access Salesforce data, workflows, and rules directly.

“We’ve been using it internally and so has Anthropic and some pilot customers for some time,” Stokes said. “It’s really highlighting what we think is a new way to work where the user is way faster than they’ve ever been before.”

According to Stokes, Salesforce users are leveraging Claudeforce to vibe code their own CRM interfaces, creating purpose-built command centers for how they want to run their teams. They’ve also been using it for forecasting.

“You just ask the question, and it’s going to go out and analyze the data and use its intelligence to try to tell you what to do,” he said.

He did note that customers will have to evaluate their own appetite for token consumption when it comes to leveraging Claudeforce.

“We’re starting to see early signs of what the token use looks like,” he said. “The token consumption is certainly not zero, but it is nowhere close to approaching the amount of consumption that you would find in a development use case.”

As part of the Claudeforce partnership, Salesforce is embedding Claude directly into Slack. Claude will be the default model for Slack, powering Slackbot, augmenting team decision-making via Claude Tag, and accelerating multiplayer coding through Slack Code.

The partners plan to introduce more integrations across Claude, Salesforce, and Slack over time. The Salesforce in Claude elements of Claudeforce are available to some pilot customers now and the partners said they expect to launch an open beta in September. They will launch additional prebuilt skills starting in the third quarter.

S/4HANA’s hidden migration challenge: SAP expert retirement


While many companies are busy switching from ECC to S/4HANA, an even more critical migration is looming: A large amount of SAP knowledge and experience will soon be lost to retirement.

Computerwoche spoke with Uwe Hartmann, founder of FITS-P GmbH, who was responsible for SAP systems as CIO at ABB for many years, about this pending knowledge drain as many SAP experts wind down their careers, as well as ways IT leaders can leverage process mining to help.

‘S/4HANA creates a solid foundation … but nothing more.’

Computerwoche: Many companies are facing a generational shift, as baby boomers, including numerous SAP experts, are retiring. How great is the risk of this vital enterprise knowledge being lost?

Uwe Hartmann: You have to look at the topic from different perspectives. The knowledge of experienced employees is not limited to technical operation, but above all includes an understanding of how a company’s processes function and how they are controlled in the SAP system.

Generating an order confirmation, for example, is relatively simple. But when this results in a delivery, special labels with barcodes are printed, financial accounting is integrated, and receivables or liquidity planning is initiated, then we are moving into a significantly more complex environment.

These connections aren’t understood overnight. It requires years of experience and in-depth knowledge of the company. The problem I currently see in many companies is that key personnel are retiring, and often there’s no successor yet.

Does the fact that many companies are in the midst of their S/4HANA transformation increase the pressure?

Absolutely. According to current figures, more than half of companies have not yet finished their migration to S/4HANA. If experienced employees leave, significant risks arise.

Studies by Gartner and McKinsey show that a large proportion of S/4HANA projects fail to meet their original cost or timeline targets. Every company faces a real challenge here.

What about after a successful S/4HANA migration? Will SAP experts leaving the workforce have less of an impact then?

No, not at all. The migration to S/4HANA alone won’t solve the problem. Many companies see it primarily as a prerequisite for continued maintenance and support from SAP. But this is similar to a smartphone update: You have the latest version and remain technically up-to-date, but the real added value doesn’t automatically materialize. This is precisely the question many companies are asking themselves: What does S/4HANA offer us beyond the mere maintenance requirement?

In my opinion, the real work begins here. Looking at the evolution of artificial intelligence, one can see how rapidly requirements are changing. Two years ago, AI was still an abstract topic for many. Today, it is increasingly being used productively in business processes. At the same time, SAP is also continuously developing its platform and has invested heavily in AI technologies in recent months.

But it is crucial to use these opportunities judiciously. AI only unfolds its full potential when it is meaningfully integrated into processes. Business processes in companies will very likely look completely different in three or four years than they do today. S/4HANA creates a solid foundation for this, but nothing more. Companies must build on this foundation. This will continue to require experienced employees who understand business processes and can effectively utilize new technologies with the necessary expertise.

‘The only solution then is process mining’

 With time running out, what challenges do you see for organizations still postponing migration?

A successful S/4HANA migration begins long before the project starts. It requires intensive preparation. Companies must first clarify the scope of the migration. They need to determine what investments are necessary and what goals they want to achieve. Only once these foundations are in place should implementation begin.

To do that, companies must have a precise understanding of their existing SAP landscape. How complex is the company? In which countries is it active? Which processes deviate from the standard? How extensively has the system been customized? What in-house developments still exist? How good is the quality of the master data?

Individual customizations and in-house developments are often underestimated. Added to this are master data problems, which affect almost every company. Even seasoned SAP experts cannot know every intricacy of a system by heart.

In such cases, process mining is the only solution. It’s like putting an X-ray machine on the ERP system, revealing hidden risks, dependencies, or special developments within the SAP system. This is crucial because during a migration, it’s the inconspicuous details that often become major problems. The goal is to uncover these blind spots early on, before they become a cost or time trap.

At Sapphire, SAP presented numerous AI agents designed to support S/4HANA migrations by analyzing and documenting processes. What’s your assessment of this development?

That’s definitely a useful addition. But we’re also seeing AI frequently portrayed as a panacea. People forget that this requires a solid data foundation to work.

AI can only deliver meaningful results if the underlying data models are well-structured. You can’t just give a chatbot access to an ERP system and expect it to automatically find optimization potential.

Only process mining platforms with a consistent data model create the conditions for AI to recognize patterns and identify potential improvements.

Darstellung Prozess-Flow in Process Mining Tool
Only SAP experts—or a process mining tool—know the intricacies of these process paths.

FITS-P GmbH

‘The emotional component cannot be replaced.’

Returning to retirement: What can companies do when experienced SAP experts leave the workforce? Is that knowledge irretrievably lost?

Part of it, yes. With every employee, not only is expertise lost, but also personal experience and a strong connection to the company. This emotional component cannot be replaced. Technical knowledge, on the other hand, can at least be partially preserved and made traceable.

With a data-driven approach, new employees can gain an overview. Process mining helps them see how processes run through the system, which customization settings have been made, and which in-house developments are in use. This enables them to form their own opinion and formulate targeted questions, instead of having the entire system explained to them step by step.

A personal handover is of course advisable if possible. But the major advantage is that it is no longer mandatory.

Is the loss of SAP know-how primarily a problem for medium-sized companies, or does it also affect large corporations?

This affects both equally — albeit for different reasons. In large companies, there is often a risk that the focus on details is lost as the company grows. Medium-sized companies, on the other hand, often struggle with more limited personnel resources and are more dependent on individual knowledge holders.

Regardless of company size, I see S/4HANA migration not just as an IT project, but as a strategic opportunity. Of course, the technical migration is the initial focus. But behind it lies a much larger task: Companies need to rethink their processes.

We are currently witnessing changes in processes across almost all areas of life. From digital tickets for public transport and apps for visiting swimming pools to AI-powered services — digital processes are becoming the norm. This trend will continue in businesses and public administration as well.

Therefore, the S/4HANA migration should be used to prepare the company for these changes. Making one’s own processes transparent often leads to a better understanding of the company than before and creates the foundation for adopting new technologies and ways of working more quickly.

At the same time, such a transformation project offers the opportunity to develop new talent. Companies that involve committed employees in the migration early often develop precisely the leaders who will drive the company forward in the next five or ten years. For me, that’s the true vision behind an S/4HANA migration: not just to introduce a new ERP system, but to future-proof the company.

‘What matters is not the number of consultants, but their quality’

What typical errors do you observe in knowledge management in SAP projects?

The true meaning of SAP know-how is often underestimated. I repeatedly encounter projects where employees are deployed who, while dedicated, lack the necessary technical and professional foundation. Anyone who can neither read ABAP code nor understand SAP customizing can hardly assess the numerous customer-specific extensions of a system.

Many believe that documenting processes graphically is sufficient. This is helpful, but it represents only a small part of reality. In practice, hundreds or even thousands of variations may exist for a single business process. These differences can be recognized only by understanding the processes themselves and the underlying system logic.

Equally important is professional project management. Every company should employ an experienced and certified project manager who works according to a clear phase and approval model. Before a project moves to the next phase, all prerequisites must be met.

I personally experienced a project that had to be stopped just two weeks before the planned go-live because the final test revealed that essential business processes had never been fully tested. This wasn’t a technical problem, but an organizational oversight.

That sounds more like a problem for medium-sized companies, correct?

Not necessarily. I see similar challenges in corporations as well. There, the greater risk is that projects will lose touch with operational reality.

My most important advice is: Rely on experienced project managers with sound project management training and bring the necessary SAP expertise on board early. The crucial factor is not the number of consultants, but their quality. Companies should not hesitate to seek external expertise in the early stages of a project. This is usually significantly cheaper than having to correct errors shortly before go-live.

One last question: Some companies are considering having their existing SAP systems maintained by third-party providers instead of migrating directly to S/4HANA. Is this a viable strategy?

I don’t personally know any clients who are taking this approach, but I can understand why companies are considering it. When studies by Gartner or McKinsey show that a large proportion of S/4HANA projects miss their deadlines or budgets, then their reluctance is understandable. After all, those who miss the deadline usually exceed their budget.

Furthermore, many consulting firms are operating at full capacity. Companies are therefore rightly asking themselves whether they can get the best resources for such a project right now, or whether a later date would be more sensible.

Those who still have sufficient support for their existing system and only need to make a few changes can consider using the remaining time strategically. However, it is crucial not to let this time go to waste.

In my view, there’s no way around S/4HANA in the long run. But speed alone isn’t a guarantee of success. Companies that have some leeway today can invest that time to prepare their organization: by training employees, strengthening IT staffing, building the necessary expertise, and refining their own strategy.

In recent years, many companies have paid a high price for their migration projects. By 2028, more tools will be available, and the experience gained from the first large-scale projects will benefit everyone. Therefore, careful preparation can be more sensible than a rushed start.

My advice would therefore be: Use the remaining time wisely. Build expertise, attract the right employees, and align your IT so that it can still successfully support the company in five or ten years. The S/4HANA migration should be part of a long-term future strategy — not just a project to meet a deadline.

See also:

Nvidia to hike prices by 15%, on top of an even larger increase in July

On top of July’s 30% price hikes across almost all of its product lines, Nvidia is reportedly preparing to raise prices of servers, including those powered by Vera Rubin and Grace Blackwell chips, by 15%, due to skyrocketing memory prices.

That 15% increase for systems being delivered in early 2027, reported by Bloomberg and other business media, is seen as part of a series of expected price hikes throughout AI deployments.

Scott Bickley, advisory fellow at Info-Tech Research Group, said that he sees Nvidia’s move as one that is only passing along its own rapidly increasing costs. But rather than price gouging because of its close-to-monopoly market control, Bickley’s calculations suggest that Nvidia is likely eating some of its costs, and is only passing along a fraction of them to its largest customers.

But not all AI-related costs are increasing; per-token prices appear to be dropping, he said. That gives CIOs a potential strategy to manage costs by pushing approaches that will reduce the reliance on memory.

“The workload cost is going down per token while the underlying hardware and infrastructure costs are going up,” Bickley said. “If you are directly building out your own clusters, this is an automatic uplift to an already egregiously expensive solution. If you are buying your own hardware, you’re going to have to suck it up. You are not going to negotiate your way out of this.”

But, he added, CIOs should also be able to get more mileage out of the clusters they are currently running, via techniques such as model routing, compression, and batch processing.  

Gaurav Gupta, VP analyst at Gartner, noted that the Nvidia price hikes are reflective of the many pricing increases throughout the AI environment. 

“Memory prices are going up, especially HBM and LPDDR5, but there are other aspects, like leading-edge foundry wafers, advanced packaging, and other component shortages,” Gupta said, adding that those issues generate “longer lead-times, which typically translates to higher prices.” And he does not expect the situation to improve any time soon. 

“In the current environment of strong demand and limited supply, we expect this situation to continue in the near to mid-term,” he said. “This means higher costs for those deploying these servers/systems and for those renting compute in the cloud, including software vendors/model builders, and others.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, agreed.

“This is a supply and demand problem, and it’s likely to reach a plateau and eventually improve once memory production ramps up to meet the current demand due to AI, but I don’t think this will happen in the next few months,” Villanustre said. “For now, CIOs will need to contend with the current market conditions.”

But he also agreed with Bickley’s suggestion that CIOs try to squeeze more value from the RAM they already have.

“Some AI model vendors are adapting their models to run better in memory constrained environments,” Villanustre noted. “For example, Gemma E4B and similar models by Google now use a hierarchical tiered model that allows them to pull only the necessary parts of the model into memory instead of holding the entire model in RAM. These models have a much larger effective number of parameters than the memory that they require.”

And, added Mike Wilkes, enterprise CISO at Aikido Security, this means that the Nvidia price hikes may do some good if they convince enterprises to adopt a more thoughtful approach to AI deployments. 

“Enterprises have spent the last few years treating frontier-model tokens almost as an infinitely elastic utility, sending workloads to the biggest model whether or not the task required frontier-level reasoning,” he said. “Higher infrastructure and token costs should force much better workload discrimination.”

He observed that the right enterprise AI architecture is increasingly hybrid: reserve 10% for frontier model consumption for problems that genuinely require it, while pushing classification, extraction, summarization, routine agent actions, and other bounded workloads toward small language models (SLMs) and open-weight models running on infrastructure that the enterprise controls.

“That gives CIOs leverage against price gouging or unilateral price setting,” he pointed out.

This article originally appeared on NetworkWorld.

Mars consolidates complex data infrastructure in hybrid cloud

Brands like Snickers, M&M’s, and Twix are familiar to most consumers, but Mars Inc. doesn’t just produce snacks. The family-owned company, with a revenue of approximately $65 billion, is also one of the largest manufacturers of pet food and ready meals, and its more than 100 production facilities operate around the clock. Of course, this places considerable demands on its IT.

“Our team must ensure that every system, including production lines, runs at maximum performance so we can continuously deliver the products and services our customers value,” says Luciano Batista, the company’s VP of enterprise services delivery.

However, Batista and his team realized that the existing data infrastructure could no longer reliably support operations, especially during peak periods such as Halloween and the pre-Christmas shopping season. So with the support of hybrid, multi-cloud data storage service Everpure, Mars is rebuilding its data and IT infrastructure.

“The Everpure platform met all our requirements,” says Batista. “It’s a scalable platform that futureproofs our operations and integrates seamlessly with our hybrid cloud infrastructure.”

Unified storage environment 

Mars initially consolidated its complex network of storage systems for business-critical databases like Oracle and applications like SAP onto a single Everpure Flash Array system. These software-defined, all-flash storage arrays are available in versions for different workloads, and typical use cases include databases, virtualized environments, SAP applications, and AI and analytics applications. 

Mars has since expanded its flash array infrastructure and now supports mixed workloads, including VMware, Windows, and Linux in areas of production, development, and quality assurance. It also uses Everpure Flash Blade as the basis for the global SAP file system. And while Flash Array is optimized for structured data, the scale-out systems of the Flash Blade series are designed for unstructured information.

“At peak times, Everpure supports up to 300,000 IOPS without any performance degradation,” says Lincoln Silva, product owner for Linux and on-prem storage at Mars. From his perspective, another point speaks favorably of the new platform in that he estimates his team saves approximately three months of planning time thanks to the Evergreen subscription model. This is because the vendor provides regular updates for the storage platform’s hardware and software. As a result, Mars’ IT professionals can focus on more critical tasks. 

Basis for hybrid cloud strategy

Mars also works with choice vendors to implement its approach to cloud. Dedicated local storage capabilities, for instance, are being integrated into Microsoft Azure cloud workloads, which simplifies restore processes and increases resilience.

Snapshots from the local environment can be replicated to the cloud, too. Recovery point objectives (RPEs) of four to 24 hours are available, depending on system priority. “Our success is also the success of our partners,” Batista says. “We embrace a spirit of reciprocity to get the most out of our collaboration.”

The hybrid cloud allows Mars to run VMware workloads and extend its IT infrastructure to the cloud as needed. And the company aims to expand its use of cloud-native applications via Microsoft Azure at a lower cost.

“We’re seeing a data reduction ratio of 18 to one. That’s nine times the expected compression rate,” Batista adds. “This puts us on track to save up to 50% on cloud storage costs. We can now work more efficiently and make better decisions thanks to intelligent solutions and automation.”

Fewer racks and lower power consumption

By consolidating on the flash platform, Mars has also reduced the space requirements and power consumption of its data centers so they only use one sixth of the power, and the number of racks has decreased significantly.

“We’re shaping a sustainable future by changing the way we work,” says Batista. “The decisions we make today will impact the world we leave behind, and Everpure aligns with our commitment to thinking in generations, not just business quarters.”

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco.

The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June, and there are fears that they could have found a new target.

Reco has named the latest campaign of attacks “City-Forum,” after a domain name associated with the attackers’ IP address. While it bears similarities to Shiny Hunters’ past exploits, there are also differences. This time around the attacker penetrated the systems through the UI-API layer, an attack point that Reco had not seen used before, and had also created its own toolset to carry out the attack. It is also targeting a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open-source tools.

The threat is particularly noteworthy, Reco said, as the attackers have studied the services to map different common data-leak vectors, a sign of an advanced approach.

A Salesforce spokesperson said that it was aware of the campaign in which malicious actors are exploiting customers’ overly permissive Experience Cloud guest user configurations in the campaign to potentially access more data than targeted organizations intended.

“This issue highlights risks stemming from misconfigurations, such as overly permissive guest user profiles, and not from a Salesforce vulnerability,” the spokesperson said.

Regardless of who the attackers were and how the attack was carried out, one thing should be clear: Organizations should be increasingly careful about who they give login credentials to.

This article first appeared on CSO.

Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?

A few months ago, I was sitting in a glass-walled conference room with the executive team of a fast-growing enterprise. The vice president of customer operations was enthusiastically demonstrating the new automated agent features their software vendor had just pushed into their CRM platform.

On the screen, the software looked brilliant. The agent could read customer complaints, analyze transaction histories and automatically resolve issues. The VP showed us how the system could independently offer retention incentives to unhappy accounts without a human ever touching a keyboard.

Then I asked a simple question: “What is your approval process when the AI decides to grant a $20,000 contract discount to keep a customer from leaving?”

The room went completely silent. The VP looked at the director of IT, the director of IT looked at the chief risk officer, and everyone realized the same thing at the exact same moment. They had spent three months evaluating software licenses and security protocols, but nobody had asked who gave the software permission to sign off on corporate spending.

Major software providers like Salesforce, SAP and Oracle are rapidly moving beyond simple report writers and conversational chatbots. They are embedding active, autonomous agents directly into the transactional core of systems that manage your revenue, customer agreements and financial ledgers. According to Gartner’s latest adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. These applications do not just summarize data: they issue refunds, alter contract terms and trigger supply chain orders.

When I review these deployments with client teams, the core problem has nothing to do with artificial intelligence. It is a fundamental breakdown in corporate delegation and signing authority.

The breakdown of the corporate signing matrix

Every mature company I work with operates on a clear delegation of authority matrix. This framework dictates exactly who can sign off on financial commitments. A vice president might have authorization to approve spending up to $500,000, a director might sit at $100,000 and a front-line manager might be capped at $500. For two decades, technology leaders have spent millions of dollars building security and compliance controls to ensure every human employee operates strictly within those limits.

Yet when a software vendor releases an update featuring autonomous agents, companies routinely grant these features unrestricted operational freedom. Because the capability arrives as a native feature inside an existing application, business units enable it with a single click. In my advisory work, I repeatedly see organizations grant third-party software features more financial freedom than their own human managers.

This represents a massive blind spot in executive governance. McKinsey’s global surveys on artificial intelligence reveal a striking pattern across the enterprise landscape: while adoption is accelerating at a historic pace, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.

The quiet cost of shadow delegation

In my audits, this rarely manifests as a dramatic system crash. It plays out as a quiet margin leak. In one organization I reviewed, a department head had enabled an automated customer retention feature over a weekend. The agent noticed an important account expressing frustration in a support ticket, and to prevent the account from churning, it independently applied an unapproved 15 percent discount to their multi-year contract.

The customer was happy, and the account manager considered the client saved. But from an executive perspective, an unvetted third-party algorithm just executed an unauthorized contract modification that eroded company margins. When the finance team conducted a quarterly audit, they did not discover an employee violating spending policy. They discovered a black-box automated decision that bypassed every internal approval control in the company.

When an auditor tests your internal controls, presenting a log showing that a vendor’s algorithm made an unauthorized financial change does not satisfy the requirement. If an action requires managerial sign-off when performed by a human being, letting software execute it independently is a major control failure.

How I advise executive teams to handle automated authority

Protecting your organization does not mean turning off these tools or falling behind on technology. It means treating vendor-supplied agents exactly like third-party contractors who have not yet passed a background check.

Forrester Research emphasizes that extending zero-trust security frameworks to automated business processes is now mandatory for enterprise risk management. Zero-trust simply means that no user, device or automated tool gets implicit trust. Every proposed action must be validated against explicit business rules before it happens.

When I help enterprise teams design these safeguards, we establish a practical three-tiered boundary for automated tools:

  • Read and draft permission: Automated tools can freely analyze trends, draft emails and assemble internal reports. No human sign-off is needed to create a draft, but the system cannot publish or execute anything on its own.
  • Standard administrative permission: Tools can handle routine administrative tasks or process standard requests below a strict financial cap (such as a $50 service credit), provided every single action is logged in an audit file that managers review weekly.
  • Restricted financial permission: Any action that alters contract terms, changes pricing tiers or issues major refunds are strictly held in an authorization queue. The system generates the request, but a human manager must click “approve” before the change hits the live database.

As a technology executive, you cannot control what automated features software providers bundle into their platforms. You can, however, control the financial boundaries and signing authority those tools are permitted to exercise within your business.

What to do at your next executive leadership meeting

  1. Ask for an automated authority inventory: Have your team audit your core software platforms to identify every automated feature currently running with permission to alter financial or customer records.
  2. Revert to draft-only mode: Instruct your team to default all vendor-supplied automated agents to “draft only” until a clear business case justifies giving them independent operational authority.
  3. Establish a firm human-in-the-loop rule: Require a strict organizational policy that no automated system can modify pricing, contracts or financial ledgers without explicit manager approval.

Nvidia’s $500B AI investment pool could impact enterprise chip pricing, availability

Nvidia and six financial partners are creating a $500 billion investment pool to help Nvidia customers including frontier AI labs, AI clouds, and other enterprises buy its chips on credit. 

The impact of such a cash infusion on enterprise AI is uncertain, but analysts fear that it could both further increase enterprise AI infrastructure costs and exacerbate the shortage of AI chips for data centers

The announcement from Nvidia and financial partners Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR said that their memorandums of understanding describe a fund “to establish the first compute financing platforms of their kind at global scale to enable the AI infrastructure buildout across Nvidia’s ecosystem, including leading frontier AI labs, enterprises and AI clouds.”

The group added that the fund would “create dedicated pools of capital at significant scale at attractive rates for Nvidia customers.”

Although the statement said the goal was to help AI infrastructure “across Nvidia’s ecosystem, including leading frontier AI labs, enterprises and AI clouds,” analysts and consultants agreed that it is highly unlikely any of these funds would be dispensed directly to enterprises, but would instead impact the overall AI supply chain.

Even the precise amount of money earmarked for the fund was unclear, with the statement merely saying that the amount would be more than $500 billion. 

Nvidia did not respond to requests for clarification about details of the proposed fund, but one financial partner did comment on the amount.

“We can clarify that this is a number that’s been totaled up by Nvidia,” said Simon Maine, managing director for communications at Brookfield Asset Management, in an email. “The finance partners are not collaborating together on this, but rather it is a series of individual partnerships. We therefore cannot comment on how the total figure has been arrived at.”

CIO concerns: chip pricing, availability

The top concern for CIOs around such a fund is the question of whether it would impact chip pricing along with that of components and devices using those chips, and if it would impact chip availability. Almost all of the analysts and consultants willing to speculate on that agreed that it would likely increase prices and worsen chip shortages. However, one optimistic interpretation of the fund was that it could help reduce chip shortages. 

“It remains to be seen what kind of downstream impact this initiative will have on enterprise spend,” said Ashish Nadkarni,  a group VP for IDC, but “there is an assumption here that these investments will go toward building fab capacity, and that the fabs will produce chips to address a chip shortfall.”

Other analysts disagreed, and argued that the fund would likely make the chip shortage worse, at least initially. 

“The current chip demand is taking all of the capacity and there is only so much chip fabrication capacity available,” said Mark Tauschek, a distinguished analyst at Info-Tech Research Group. “It will also take years to build new chip fabs. [The proposed Nvidia fund] will probably exacerbate the shortage.”

In fact, for enterprises, Tauschek projected a 15%-20% cost hike.

Sanchit Vir Gogia, chief analyst at Greyhound Research, agreed with Tauschek on both counts. 

He estimated that AI chip prices would be roughly the same for another year, and increasingly only at a good price if customers sign a long-term commitment. “The discount for committing is shrinking, not growing,” he said.

Thus, he pointed out, “more financing therefore means more new capacity is spoken for before it exists, and the open market gets whatever is left. The queue is no longer sorted by who can pay. It is sorted by who will commit.”

But he added that these numbers will likely improve eventually. “It does add real capacity in the end,” he noted. “Enterprises planning for 2028 will benefit. Those reacting to 2026 will not.”

Mike Wilkes, enterprise CISO at Aikido Security, said that one of the key impacts of the fund will be the way in which enterprises should view AI financing. That change, he argued, is both good and bad.

The improved availability of funds could “finance the AI buildout at much greater scale. That could accelerate enterprise access to compute, but it could also connect AI infrastructure much more tightly to the financial system,” Wilkes said. “This financing is likely to lower the cost of getting access to AI infrastructure in the near term, but not necessarily lower the price enterprises ultimately pay for AI.”

He suggested that potential enterprise impact will vary over time.

For large enterprises, the infusion of funds would allow their infrastructure vendors to build large datacenters without requiring financial help from the enterprise, he said, and this added capacity should eventually put downward pressure on the unit cost of compute.

“But,” he noted, “in the next few years, I would expect vendors to use cheaper financing primarily to build faster and lock customers into longer-term capacity contracts, rather than simply pass all of those savings through. In other words, enterprises may get more AI for the same dollar before they get the same AI for fewer dollars. So I think the biggest effect on enterprise readers is that this could remove one bottleneck while creating another.”

He expects that capital may cease to be the limiting factor in building AI infrastructure, giving CIOs considerably more capacity and more financing options available to them. “But,” he said, “the resulting competition may increasingly focus on who can persuade enterprises to make the longest and largest commitments to future AI consumption. If hundreds of billions of dollars of infrastructure are financed based on assumptions about future utilization, somebody ultimately has to pay when those assumptions prove wrong.”

Things will brighten, but not for awhile

Justin Greis, CEO of consulting firm Acceligence,  agreed that the short-term impact of this agreement may not be good for enterprise IT. 

“My view is that this financing will accelerate the creation of AI infrastructure, but it will not provide meaningful near-term price relief for most enterprises. In fact, I think the next 12-18 months could remain a period of elevated costs and constrained availability as the market absorbs this new wave of investment,” Greis said. The reason, he noted, is that the limiting factor today is not capital, it is the physical capacity to manufacture components.

“Adding hundreds of billions of dollars of available financing will create more buyers with the ability to compete for those resources,” he said. “My expectation is that the largest AI infrastructure providers and hyperscalers will continue to secure a significant share of available capacity because they have the scale, existing relationships, and ability to commit to long-term purchases.”

But eventually he believes that the enterprise picture should brighten. 

“Where I do expect enterprises to see benefits is further out. As this capital turns into actual infrastructure capacity, the market should become more competitive and enterprises should have more options in how they access compute,” Greis said.

“From a CIO perspective, I would not respond to this announcement by trying to secure more hardware. That is likely to become an expensive race that most enterprises cannot win.”

This article originally appeared on NetworkWorld.

Agentic AI workforce is more than doubling year on year, says Salesforce

Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters.

It compiled data from customers who had activated agents in production every month of the analysis period to determine how their use of the technology has evolved between February 2025 and April 2026, as well as incorporating data from May 2026 Salesforce research studies.

It found that businesses grew their agentic workforces from an average of five agents in February 2025 to 13 by April 2026, a 7% compound monthly growth rate (CMGR). In April 2026, it only took an average of 1.9 days to deploy an agent into production, a 53% decrease since the beginning of the report period.

Not only were agents deployed more quickly, they have been progressively taking on more work once in use; over the 15 months, the average number of actions per account had a CMGR of 31%.

“These agents are expanding beyond their initial scope to really become cross-functional,” said Caila Schwartz, Salesforce’s head of agentic commerce insights, during a media briefing.

Salesforce has attempted to measure how much work agents perform, rather than how many tokens they consume, creating its own Agentic Work Unit (AWU) metric, although analysts have criticized the measure as being unrelated to business outcomes. Nevertheless, Salesforce said that as of April, Agentforce agents had performed 734 million AWUs, a number growing at about 15% each month.

The research also showed that agents are acting across multiple cloud domains which, the company said, “underscores the practical necessity of a headless architecture. By decoupling the agent’s logic from traditional front-end user interfaces, agents can process tasks, execute actions, and trigger workflows anywhere.”

Within the company, Salesforce itself has seen explosive growth in AI agent use, said Joe Inzerillo, president of enterprise & AI technology at Salesforce, with a threefold increase in sessions between February 2025 and April 2026. He said that the AI agent in Slack, Slackbot, saves the average employee five hours per week, with 83% of the company having adopted it.

But Schwartz pointed out that different industries are approaching agentic AI in different ways, some more sophisticated than others. To measure that, Salesforce developed a Sophistication Index, a five-point scale scoring the cognitive complexity of an agent’s actions. Levels 1- 3  are assigned to tasks such as record lookups, drafting emails, or summarizing documents, while levels 4 and 5 include more complex functions such as updating database fields.

The data showed that manufacturing, financial services, and healthcare and life sciences have built more sophisticated agent networks than what it called traditional AI frontrunners such as technology and retail.

However, Inzerillo said, the most common use case industry wide, and the best place to start, is the service use case, which provides “far and away the best ROI to start with.”

He also noted that, as people have become more conscious of what agents can do, they are asking agents to perform tasks, rather than simply answer questions.

“Now what you’re starting to see people do is very action oriented. So instead of asking ’how do I file a form to request my vacation’ from our employee agent, they’re telling the employee agent, ‘hey I’m taking a vacation, you need to enter this form for me, and here’s the details,’” he said, adding that this bias towards action represents the evolution of agentic use.

Never mind clean data. Annotate as you collect it.

Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.

Not only do you need to be able to track the lineage of data your model uses from source to token, something the EU AI Act requires, you also need to be able to take into account where the data came from, whether it’s out of date, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.

Gartner expects organizations will abandon 60% of AI projects because they don’t have the right metadata management, data quality, and data observability. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and one of IBM’s 2026 predictions was the importance of smarter data.

The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.

But that can also remove a lot of the context crucial for gen AI. Rather than cleaning data and losing the original context, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”

IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.

Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”

Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”

Raw but not rancid

Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.

Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”

Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”

But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”

That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”

Structure isn’t static

Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these data cascades shows how easily context gets lost and how badly it affects data quality.

Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.

“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”

Sensing structure

Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.

Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.

That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”

Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.

Incentives for annotating

DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.

LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”

The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.

“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”

That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”

People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”

Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.

So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”

DBOMs and data contracts

Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.

“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.

Aronchick advocates for a SLSA-style data bill of materials using a tool like Makoto, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.

The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.

Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.

“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.

AI demands provenance

All this context is the kind of metadata Anthropic’s context engineering guide recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.

Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.

If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”

And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.

Expanso recently won an Edge AI award for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”

Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”

Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.

“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”

SAP dodges German antitrust investigation over data extraction

SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation.

The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a dynamic market, it said in a news release.

It launched its investigation into SAP’s practices following complaints by software companies including Celonis, a developer of process mining tools, alleging that SAP makes it difficult for customers and third parties to access data from its ERP systems and favors its own Signavio process mining tool.

“Companies must generally also be able to use their own data in third-party applications. With large software platforms, in particular, non-discriminatory access to data is crucial to effective competition,” said Bundeskartellamt President Andreas Mundt. “Our preliminary investigation has found that there are currently sufficient data extraction options available and that there have so far been no indications of exclusionary practices that may be relevant under competition law.”

SAP changed its policies on accessing data held in its applications via APIs in April, prompting customer pushback.

But, said Mundt, the Bundeskartellamt found that despite the API policy change, data extraction options that were previously permissible are still available.

Data extraction is possible

SAP welcomed the Bundeskartellamt decision, saying that “as the authority states, SAP customers and partners have sufficient and permissible technical options to extract data from SAP systems and use it in solutions from other providers. The SAP API Policy does not restrict these capabilities.”

Celonis also issued a statement, noting that the Bundeskartellamt ruling underlined the continued importance of unrestricted data access, and warning, “The decision is based on the key premise that data extraction for software from providers such as Celonis will remain possible even under SAP’s new API policy — a premise that SAP has been unwilling to confirm to date.”

The Celonis statement continued, “We remain steadfast in our conviction that company data belongs entirely to the customers who generate it. No provider should restrict a company’s right to extract its own information or prevent users from working with third-party providers such as Celonis that offer added value to customers.”

Celonis is also attacking SAP’s policies on data extraction in court in California. It filed a complaint in March 2025 alleging that SAP was leveraging its software to “prevent SAP customers from sharing their own data with third-party providers, including Celonis, without paying prohibitively expensive fees.” The judge dismissed some of the claims in that case, leaving three to be tested in a trial then scheduled for December 2026. Celonis has since amended its complaint to include 10 claims, and the trial has been rescheduled for 2027, the company said.

“Our litigation continues to uncover evidence of SAP’s unlawful behavior, including anticompetitive conduct and theft of intellectual property, and we are confident in the evidence that we will present at trial,” Celonis said following the German authority’s decision.

The Bundeskartellamt’s failure to find sufficient evidence to open a ‘formal abuse of dominance proceeding’ is a small win for SAP, said Scott Bickley, advisory fellow at Info-Tech Research, but “CIOs should not mistake it for a validation of SAP’s data access model.”

Although SAP recognizes customers’ right to decide they use their data, it does not make it easy for them to do so, he said. “CIOs may technically retain vendor choice but be faced with expensive replication architectures, API rate and volume restrictions, additional platform costs, performance lags and data migration costs, all with a dependency on an SAP-approved technical pattern, which can be a moving target.”

Data ownership as a procurement issue

Justin Greis, CEO of consulting firm Acceligence, sees the decision as an instructive one for enterprise CIOs.

“This isn’t a reason to stop asking hard questions of your ERP vendor. Whether it’s SAP, Oracle, Microsoft, Salesforce, or anyone else, enterprises should continue to evaluate how easy it is to access their own operational data, integrate third-party applications, and migrate workloads if business priorities change. Those questions are becoming strategic procurement issues, not just technical ones,” Greis said.

CIOs should consider data portability early in the procurement process, said Kaan Dincer, CEO of data migration vendor Settle: “Negotiate export rights, API access on reasonable terms, and documentation of the data model before signing and test a real extraction while the vendor still wants your renewal. The cost of your eventual exit is set on the day you implement, not the day you leave. ERP data now feeds analytics and automation outside the system of record, so access friction that used to be an IT annoyance is becoming a strategy constraint.”

In the SAP case, he said, “the regulator answered a narrow legal question, not the operational one. Declining to open proceedings means the friction was not shown to be anticompetitive. It does not mean the friction is not real. The Bundeskartellamt’s own findings acknowledge that extracting large data volumes is technically demanding and it said explicitly that it will keep watching as access mechanisms and license models evolve. That is not a clean bill of health. It is a decision to hold fire.”

Srinivasulu Reddy Battu, a senior software engineer with cloud vendor ZT Systems, said the big takeaway is the difference between difficult and impossible. SAP’s argument is that the data migration outside of its environment is possible, but Battu said it can be a time-consuming and expensive process.

“When the ruling says ‘various permissible and viable options’ exist, that’s technically true, but it glosses over how much expertise it actually takes to use them,” Battu said. “CIOs should still watch how process mining gets packaged in their contracts. If Signavio comes included by default, teams will naturally start using it and that quietly reduces your negotiating power with other vendors over time. This isn’t just about SAP: Oracle, Microsoft, every major ERP vendor sits on a massive amount of your business data. If any of them decided to tighten their API policies tomorrow, most companies would be scrambling.”

How AI helps the US Senate Federal Credit Union better manage risk

The United States Senate Federal Credit Union (USSFCU) is a nonprofit financial cooperative that provides traditional retail banking services to entities within the US government, such as the Senate and the Supreme Court.At present, the credit union’s headcount stands at nearly 150 people, managing around $1.6 billion in assets.

A few years back, when it started to expand its use of technology, cybersecurity was a key focus area, but the financial institution faced two major challenges in boosting security as it scaled. The USSFCU was carrying significant technical debt, and there were holes in the organization’s defenses.

“We found gaps where we needed more systems, tools, and people, and then there were instances where we had technologies in place that weren’t being used effectively,” says Mark Fournier, CIO at the credit union. “We weren’t buying a bunch of shiny new things without thinking about it. We were actually quite prescriptive every year, performing a number of different exercises to identify our shortcomings and then finding the right solution to fill the gaps. But over time this adds up. It was clear we couldn’t keep hiring more people and bringing in new solutions.”

The USSFCU needed a more efficient way to bring everything together and make its cyber estate easier to manage. For Fournier and his team, vulnerability management was the hardest hill to climb since they have to deal with about 100 new possible breach points every day.

“When we looked at the problem more closely, the impact of these vulnerabilities was far greater than we realized,” he says. “Not only because of the volume but because of a lack of clear understanding around the potential impact of each one across the broader business.”

Improved risk management

The USSFCU didn’t lack security tools, however. In fact, it had plenty, from scanners and endpoint tools to asset records, tickets, and internal documentation. But each tool saw only a slice of the environment, so there was little to no context. This made it difficult for the security team to separate real business risk from noise.

So for each new vulnerability, the security team had to run a manual investigation, which could take days. And while doing this, they still had to triage the next wave of findings. The organization, therefore, needed a way to know what mattered, why it mattered, who owned it, and whether taking the time to make a fix actually reduced risk. The USSFCU also required a solution to be deployed entirely in-house, leveraging its internal inferences.

Working with Tonic Security, the organization deployed an exposure management solution that pulls together data from different tools and data sources to create a clear picture of business risk. “One of the key functions of the platform is the ability to ingest anything,” says Fournier. “Breaking down silos between disparate systems is essential to unlock valuable contextual information.”

For the USSFCU, transparency and explainability are critical, he adds. This tool uses an AI data fabric to extract context from structured and unstructured data. This context drives prioritization, ensuring the right owner gets the right evidence, not a vague ticket. And once the work is done, the solution checks whether the exposure was reduced.

Because the AI is grounded in the customer’s own environment, it isn’t just guessing from a generic risk model. It reasons over USSFCU’s assets, owners, services, tickets, controls, and business context. But it isn’t using this data to train external models.

Describing one particular incident, Fournier explains that shortly after the initial deployment, various stakeholders met to assess progress. “We thought we were smart because we found an error with the platform,” he says. “The solution had labelled an asset as internet exposed, which we knew was incorrect.” But after a review and lengthy discussion, they were proven wrong. “Almost immediately, the value of bringing this information together became apparent.”

A template for bigger things

Before this solution, a high-severity finding could send an analyst on a lengthy scavenger hunt because of data located in so many different places. They’d check the scanner, asset inventory, tickets, and maybe even ask around to find the owner. But now they can find the asset, the owner, the business relevance, the exposure path, and the recommended action in one place. The solution has reduced the time taken to resolve a vulnerability by 75%. And with a clearer idea of what is and isn’t important, and what adds practical value, the number of incidents someone needs to respond to has reduced from about 100 a month to just 10.

Sharing his lessons from the project, Fournier says one needs to keep an open mind because the problem you think you have is often very different from the one you actually have. “This project has also been an eye-opener around how people can collaborate and operate across different areas of the business,” he says. “When I talk to my peers, they regularly highlight the disconnect between different departments and business functions. But with a project like this, when you’re crossing traditional boundaries, you need to have open lines of communication to succeed.”

Microsoft doubles down on multi-model AI as it builds a Copilot super app

All of the major AI providers want you to use, and ideally stay within, their super apps, and now Microsoft is looking to capture that attention, too.

During an earnings call this week, CEO Satya Nadella confirmed that the tech giant is building a Copilot ‘super app’ that will be rolled out this quarter. The new platform will bring together various Copilot tools, including chat, Cowork, long-running Autopilot agents, and the always-on Microsoft Scout, powered by OpenClaw.

Microsoft said the super app will be wired into many of its other governance platforms, including Agent 365, IT Ops, SecOps, FinOps, and business processes. And, it said, CRM and ERP systems will “serve as skills and plug-ins that go into core work.”

“You’re able to take that enterprise-wide workflow and wire it into the super app,” Nadella said, describing it as “the coming together of a new way to work.”

With this move, Microsoft will compete with OpenAI’s ChatGPT Work, Claude Cowork, and a growing number of others trying to capture as much of a user’s workflow as possible. It could prove a strong contender, as everyday Copilot “usage intensity” is at the same level as that of Outlook or Teams, Nadella said, and paid seats now surpass 30 million.

Every model should be ‘swappable’

Even as it builds a super app to bridge workflows, Microsoft is acknowledging enterprise demand for model choice. Customers are making it clear that they don’t want to be locked into one model; they want the ability to move between open, closed, and frontier options based on the best tool for the job.

This trend is reflected in Redmond’s own usage statistics: Since the beginning of the year, it has tracked a 5x increase in the number of customers building with models from multiple providers featured on its platform.

The company claims it has the broadest model catalog in the cloud, offering more than 11,000 models from OpenAI, Anthropic, Mistral, its own MAI family, and others.

“We are building a new model system, where the harness, context, memory, and action space are separate from any one model family, thereby moving the frontier on the cost-to-outcome curve,” Nadella said. “That’s really the enterprise design architecture that we are going to evangelize.”

He described enterprises as “learning machines” that need their own internal learning machines, and said that they will be evaluating how providers are helping them reach their business goals and support knowledge creation.

“The models are an input, not some extraction of the knowledge of the enterprise,” Nadella said. “This is not going to be about, ‘come in and take all my knowledge and benefit yourself, [and] I am not getting anything out of it.’”

The key is in balancing the advantages of frontier models with lower-cost options, open weights with closed weights, and having the ability to train internal models based on outputs, traces, and context. “You should and you can use frontier models,” Nadella said. “There’s no reason not to.”

However, he said, any given model at any given time should be swappable to democratize design.

For instance, data from cybersecurity evaluation framework CyberGym showed that Microsoft’s new MAI-Cyber-1-Flash coding agent achieved Claude Mythos-level performance at 50% of the cost. This is because 90% of tasks were completed by Cyber-1-Flash and 10% by frontier models from OpenAI, Anthropic, and others. 

This ability to use the right model for the right task in what is essentially a pipeline job is a “super important characteristic,” Nadella said. Microsoft Copilot, Security Copilot, and GitHub Copilot are all built to support movement between different models based on the task.

This strategy is also reflected in the company’s new Project Perception cybersecurity offering. The platform features three specialized types of agent (red, blue, and green), and the underlying harness decides which AI model is best suited for a given task. Guided by specialized playbooks, red team agents discover vulnerabilities, blue team agents triage, and green team agents propose remediation plans.

“You create your own agentic system that’s continuously operating to create the cyber defense you need,” Nadella explained. “Especially in cyber[security], it becomes critical to have that multi-model approach.”

Nadella also pointed to the recent Hugging Face incident, in which an OpenAI model went rogue, broke out of its sandbox, and launched an attack against the popular open-source platform, noting that enterprises will likely need to use multiple models to offset and remediate the various challenges of each, and should not be “subject to the refusals of one model.”

“We talk about the frontier as if it’s one thing,” Nadella said. “The frontier is about every firm having a frontier, the choice, the cost control, and the capability that they need in order to be able to control their destiny.”

Increased push to usage-based pricing, closing demand gaps

As Microsoft emphasizes its model-agnostic architecture, it is also shifting from per-seat to per-seat-plus-consumption pricing; the company recently added usage-based billing to Cowork and Agent 365, and plans to continue that trend across its products.

While these moves have resulted in sticker shock and ‘tokenmaxxing’ at many companies, Nadella framed it as a revenue driver. “We are advancing the frontier on the cost-to-outcome curve, ensuring every customer can turn tokens into business results.”

Meanwhile, Microsoft said it will continue to close data demand-capacity gaps.

The company added 88 data centers in FY 2026, including 31 across five continents this past quarter. It contended that it is bringing capacity online “faster than ever,” reducing dock-to-live times for new GPUs in its largest regions by nearly 50% over the fiscal year.

However, CFO Amy Hood acknowledged during the earnings call, “the situation is obviously that demand exceeds available supply in a relatively extreme moment.”

Reflecting this, revenue for Azure and other cloud services grew by 43% in Microsoft’s fiscal year ended June 30, and the company expects similar revenue growth (45%) in fiscal year ‘27.

Hood said that Microsoft remains “focused on delivering efficiencies,” including in its CPU and GPU fleets, and engineers are also working on process improvements. The company added another gigawatt of capacity this quarter and is on track to roughly double its overall capacity in two years.

“We are also getting more from the infrastructure we already have by optimizing across silicon, systems, and software,” Hood said.

11 tech experts every CIO should follow on social media

Social media is more than a place to network or follow the latest headlines and trends. For CIOs, platforms like LinkedIn, X, and Bluesky offer direct access to technology executives, AI experts, economists, and business leaders who share ideas, challenge conventional thinking, and provide insights that can help shape tech strategy. Here, 11 IT leaders share the social media experts they follow, and explain why these voices are worth CIOs’ time.

Jensen Huang, founder and CEO, Nvidia

I find Jensen Huang’s insights (X, LinkedIn) fascinating, and there’s much to be admired and learned from. He’s a bold thinker who fosters a culture of continuous learning, which is incredibly valuable in an ever-evolving tech and cyber business environment like Exos. My observations are that Huang is looking to better the lives of his employees, clients and community — and so am I. His content helps me to think differently and his leadership style has a lot of technical depth, which is especially relevant with the rise and momentum of AI. He’s been described as intensely curious, which aligns with Exos’ tagline, We are Curious. – Jose Martinez, CIO and managing director, Exos IT

Jason Crawford, founder and president, Roots of Progress Institute

Jason Crawford is an under-the-radar voice more CIOs should know. He is one of the most important thinkers on the philosophy and history of technology, and his work is about understanding why technological progress happens and how to sustain it. I follow him because his attention and capital directly drive where the industry moves next. – Yaron Hadad, CEO and CTO, Beehive Software

Kelsey Hightower, distinguished engineer, Google

Kelsey Hightower (Bluesky, LinkedIn) is valuable because he explains cloud infrastructure and Kubernetes in a way that’s practical and grounded. What I appreciate about his work is he often brings the conversation back to simplicity, maintainability, and the people who have to operate these systems. For technology leaders, that matters because the hardest part of cloud adoption isn’t choosing tools but making sure teams can run them reliably over time. – Sai Joshitha Kathari, senior site reliability engineer, Visa

Mustafa Suleyman, CEO, Microsoft AI

As an IT leader and advisor to CIOs, one of the voices I pay the closest attention to is Mustafa Suleyman (X) because he thinks beyond the technology itself. He consistently explores how AI changes institutions, labor markets, governance, and power structures. His work has influenced my own thinking about the growing concentration of AI capability and infrastructure in the hands of a relatively small number of organizations. For CIOs, that perspective is valuable because AI is no longer simply a technology investment, but a strategic, infrastructural, and organizational issue. – Matt Hasan, CEO, aiRESULTS, and founder, The AI Humanist Movement

Kevin Benedict, futurist, Tata Consultancy Services

Over the years, I’ve learned that technology leadership is about following people who help you connect innovation to business results, not the loudest voices. One person I consistently follow and recommend is Kevin Benedict (LinkedIn, X). He consistently delivers insights at the intersection of AI, digital transformation, customer experience, leadership, workforce evolution, and innovation. What distinguishes him is his ability to translate emerging technologies into practical business strategies. Rather than focusing on hype, Benedict focuses on execution, adoption, organizational impact, and measurable outcomes. His insights are practical, strategic, and immediately applicable, making him one of the most valuable voices for CIOs and technology executives navigating today’s rapidly evolving digital landscape. – Paul Bailo, digital transformation executive, educator, author, and founder and CEO, Landit.ai

Ethan Mollick, associate professor, The Wharton School

Ethan Mollick (LinkedIn) has the highest post frequency of the thought leadership I follow. From academic papers to showing model improvements by using his own “otter on a plane writing emails” benchmark, he covers a broad spectrum of AI topics. He frequently gets access to the latest models before they come out, and when they do, his posts give a glimpse of what’s new or different, grounded in longer experience with the products. – Andreas Welsch, founder and chief human agentic AI officer, Intelligence Briefing

Dado Van Peteghem, author and keynote speaker on AI, technology, and business

I suggest Dado Van Peteghem (LinkedIn, TikTok) as a thought leader for CIOs to follow. He provides excellent perspectives on the future of work and offers a strategic guide on how CIOs should adapt to AI, digital ecosystems, and new business models. Van Peteghem helps leadership teams understand how digital transformation goes beyond technology upgrades. His focus is on aligning technology, culture, leadership, and business strategy so digital initiatives create measurable business value rather than becoming isolated IT projects. This aligns with what I advocate, hence my support for him and his idea of digital ecosystems. Van Peteghem spells out how AI changes workflows and how organizations should redesign operating models to decide what should be automated versus what should remain human-driven. – Max Vermeir, VP of AI strategy, ABBYY

David Forino, co-founder and CTO, Quanted

David Forino (LinkedIn), led AI research at Volkswagen’s self-driving team and now often posts on LinkedIn about the data bottleneck in quant finance — how teams spend more time keeping data pipelines running than doing research. It’s the same problem most companies run into when they roll out AI, so his tips are always helpful from someone adjacent to them. – Charlie Simionescu-Marin, co-founder and CEO, Quanted

Justina Nixon-Saintil, chief impact officer and president, IBM International Foundation

I have a unique perspective on Justina Nixon-Saintil (LinkedIn) because I’ve also benefited from her guidance and mentorship through Salynt. What stands out to me is her focus on responsible innovation, workforce transformation, and AI governance. She talks about the people and the organizational side of technology adoption, which is often overlooked. Her perspective has reinforced for me that successful AI adoption is as much about trust, culture, and change management as it is about the technology itself. – Natalia Crosdale, COO, Salynt and a former US State Department technology program leader.

Niall Ferguson, senior fellow, The Hoover Institution, Stanford University

Fundamentally, I get the most value from the big brains who focus on consequences rather than capabilities. They help inspire my own thinking about which assumptions about my business stop being true because transformative technology exists. One of the most important voices I follow is Niall Ferguson (LinkedIn, X). He’s a historian, not a technologist, which is precisely why he’s valuable. Technology changes quickly. Institutions, markets, and power structures change slowly. Understanding the gap between the two is where many of the biggest opportunities and risks emerge. – Bill Huber, partner, digital platforms and solutions, ISG

Erik Bernhardsson, CEO, Modal

Good sources don’t make decisions for me, but they improve the quality of questions I ask before I make them. Erik Bernhardsson (LinkedIn) is at the intersection of AI, data infrastructure, and developer experience. Coming from Spotify and now building Modal, he brings a practical view of what modern AI infrastructure actually requires: fast iteration, flexible compute, and reducing infrastructure friction for teams. – Piotr Mynarski, technology director, eSky.com

❌