Visualização de leitura

The AI cybersecurity arms race is on

Businesses received a staggering amount of cyberattacks in June, according to Check Point, showing a rise of 20% over the previous 12 months. The breakout of AI agents from OpenAI in July to hack into the Hugging Face website, and subsequent similar events from Anthropic and Meta, indicate agentic-powered attacks will explode over the coming year.

Currently, malicious hackers have the advantage because publicly released frontier models from the US incorporate guardrails that can’t distinguish between malicious or defensive activities. As a consequence, these models default to a refusal to get involved. Hugging Face discovered this the hard way when they attempted to utilize a model to defend against the OpenAI intrusion. Their solution was to adapt a Chinese open weight model to analyze the 17,000 attack logs, find the vulnerability, and contain the intrusion.

With incidents like these happening more often, an arms race has begun with AI being both the problem and the solution.

Strength in numbers

While single agents generally perform more efficiently for well-defined tasks, research from Stanford University indicates swarms are more effective in messy scenarios with noisy data, which are more typical of unpredictable, intrusion attacks. The increased token usage by swarms raises costs, but increasingly efficient open weight models are rapidly lowering these barriers.

In the Hugging Face example, the agents worked together as a team leaving messages for each other on a message board they improvised. They shared newly found vulnerabilities, exchanged tools, and even developed conventions to address one another and to avoid overwriting each other’s work. While this may seem sinister, they were only following their designated purpose: to achieve a goal without regard to any collateral damage. We can expect bad actors to harness the power of agentic swarms through fine-tuning open weight models, and creating agents that progressively learn from their experiences.

Modern warfare has been transformed over the last four years, too, through the deployment of drones by Ukraine to defend against Russian attacks. Military strategies and the deployment of armament budgets around the world are shifting to focus on new technologies, and approaches and enterprises are now facing a similar challenge from the hostile use of agentic AI.

The drawbridge is down

As enterprises build out their own agentic systems to handle ecommerce, customer service, and marketing activities, this presents new attack surfaces for antagonistic efforts. April 2026 research from Trend Micro found almost 1,500 MCP servers directly exposed to the internet had no authentication or encryption, a rise of 200% from nine months earlier. This included 70 hosts offering direct SQL execution, and servers holding medical records.

The automation of business processes and the reduction of humans from decision making chains open up new vulnerabilities for agents with malicious intent. Arkose Labs’ 2026 agentic AI survey of 300 enterprise leaders found 97% expected an AI agent security incident within the next 12 months.

Social engineering

While agents have demonstrated their ability to break through security systems, they’re also capable of targeting humans to achieve their objectives. Recent research from Verizon indicates that 62% of successful breaches involve a human element, with phone-based attacks 40% more successful than email-based ones. In August, for instance, scammers using an AI-generated deep fake of Australian Prime Minister Anthony Albanese’s voice were able to scam investors out of $5.3 million.

If agents can break out of digital sandboxes, and generate convincing fake videos and audio, then they’re certainly capable of making basic phone calls. In July, during testing of frontier models, the UK AI Security Institute discovered an agent tried to insert malicious code into an open-source project. Attempting to get the code approved, the agent created fake online identities using them to persuade the project’s maintainer to sign it off. “This is the first time we’ve seen risks around autonomy and deception manifest this clearly without specific prompting in the real-world,” the Institute put in a write-up of the incident.

Fight AI with AI

So attackers currently have the upper hand in this escalating arms race. They have access to agents that can work around the clock, constantly probing, learning, and sharing their knowledge with other agents. They’ll only get better at this and learn ways to stay ahead of defensive systems. International agreements to delay or restrict the capabilities of frontier models won’t stop hostile actors motivated by money or rogue states pursuing other objectives. Developers and security vendors need access to the latest frontier models unfettered by restrictive guardrails if we’re to stand any chance of defending against the coming tsunami of attacks.

We can learn a lesson from recent history on this front. In 1992, the US restricted exported software to weak 40-bit encryption, citing security concerns going back to the cold war. While the US allowed stronger encryption internally, the result was weakened security for everyone as hostile antagonists were able to disrupt global supply chains that incorporated less secure software. Despite lifting the ban in 1999, embedded software containing 40-bit encryption continued to cause problems for many years across multiple countries, including the US.

Without rapid action, we may look back fondly to the world before July 2026 as a golden age for cybersecurity, a relative age of innocence.

Why technically strong leaders still aren’t CIO-ready

At CIO100 in Frisco, Texas, roughly 100 rising technology leaders sat down for our “Next CIO” session. The group was asked to reflect on a single question: Are you ready to take on the role of CIO? Using the CIO Readiness Framework that we have developed and refined over years of advisory work, we asked each person in the room to score themselves across the five dimensions of the framework. The results point to a gap that should worry any organization building its next generation of technology leaders.

The CIO Readiness Framework

The CIO Readiness Framework organizes the CIO job into five dimensions. We asked each rising leader to score themselves on the same 1-to-5 scale, from “Emerging” to “CIO-Ready.” The five dimensions of the framework are:

  • Enterprise leadership: the ability to lead beyond your own function, anticipate where the business is headed and mobilize people through change.
  • Business value and financial acumen: understanding how the enterprise makes money well enough to connect technology decisions to growth, margin and risk.
  • Influence, narrative and enterprise selling: building belief and support before a decision is ever formally proposed, not just presenting sound logic once it is. 
  • Relationships, talent and operating leverage: building trusted executive relationships, developing successors and creating an organization that delivers beyond your own personal reach.
  • Technology stewardship and digital judgment: the technical fluency and architectural judgment needed to make durable enterprise technology decisions.

Where the room stands

Across the five dimensions, the average self-assessment landed at 3.4 out of 5, squarely in ‘Proficient’ territory. Consider who was in the room: people already selected by their own organizations as ready to be developed for the next level. Even so, not one of the five dimensions averaged ‘Advanced’ or higher across the entire group. Technology Stewardship and Digital Judgment (the ability to make sound decisions on platforms, architecture and risk) came in as the most mature dimension in the room. At the bottom sat two dimensions in a near tie: Influence, Narrative and Enterprise Selling; and Relationships, Talent and Operating Leverage.

Much more interesting, however, is the spread between the highest- and lowest-rated dimensions. On these bottom two dimensions, ~65% of attendees rated themselves Proficient or below. Compare that to Technology Stewardship, where the number was only 36%. Put plainly, the people in that room are confident in their technical judgment. They are far less confident in the parts of the job that have nothing to do with technology at all.

Why the human dimensions lag, and what to do about it

This tracks with what we hear constantly in our advisory work. Most people who reach the doorstep of the CIO role got there by being excellent at the technical and operational core of IT. Few of them spent their first fifteen years being evaluated on stakeholder mapping, coalition-building, or developing a successor. Those muscles simply were not required until now.

The good news is that these are learnable skills. We recommend a simple approach to close these capability gaps: for the dimensions where you rated yourself lowest, identify a goal that targets your weaknesses, then attach a tactic (a concrete action or behavior) that moves you toward achieving your goal. Lastly, give the whole thing a timeframe. Six months is often a good starting point, as it is long enough to make real progress and short enough that you’ll actually check.

In this activity, the goal represents the destination – for example, to develop a brand of “enterprise leader,” rather than just “strong IT operator.” The tactic is how you get there, something specific enough that you’ll know in six months whether you did it or not. “Get better at influence” is a goal with no tactic attached, which is exactly why it rarely changes anything. “Hold pre-alignment conversations with three sponsors before my next major proposal” is a tactic, and it’s either done or it isn’t.

Here’s what that pairing looks like applied to the two lowest-scoring dimensions from the CIO100 room:

  • For Influence, narrative and enterprise selling, a reasonable goal is building support for ideas before they ever reach a formal decision point. Tactics in service of that goal include identifying the informal decision-makers behind a priority and earning their support early, or taking on an external opportunity (e.g., industry panels, published point of views) to build credibility beyond the building.
  • For Relationships, talent and operating leverage, a reasonable goal is creating executive capacity instead of personally absorbing more of the work. Tactics in service of that goal may include adding standing one-on-ones with two peers on the executive team, and delegating two recurring items off your own plate with clear decision rights attached.

The takeaway for CIOs building their bench

If you’re a sitting CIO developing your own successors, this data serves as a useful gut check. The people you’re grooming may already operate at an advanced level technically while carrying real gaps in the skills that determine whether they succeed once they have the title. Executive presence, coalition-building and delegation take years to build, so the earlier you start, the better.

The future leaders we worked with at CIO100 had no shortage of ability. What most of them lacked were the specific, practiced habits that turn a strong technology leader into an enterprise one, and the self-assessment data shows they already know it. Acknowledging that gap is the first step toward closing it.

Why Cisco is redefining its CIO role

The CIO job description is being rewritten in real time. As AI agents take over the interface layer and connect directly to any data source, the skills that once defined great IT leadership — UX fluency, applications integration, build-versus-buy judgment — are giving way to an entirely different set of questions surrounding not how a process works, but whether it needs to exist at all.

Thimaya Subaiya is living that shift firsthand. At Cisco, he oversees IT and says the ideal CIO candidate today might not have a traditional IT background. Here, he explains why he split the company’s AI leadership out as its own function and why he’ll merge back in, what he’s really looking for in a CIO candidate, and why the Cisco CIO job is such a good one.

How would you describe your role at Cisco?

I lead operations for one of the world’s largest supply chains, as well as security and trust, including product security, internal systems, and data center security. I also lead the CIO organization and have revenue operations, partnership management, and accountability for our AI strategy. Two and a half years ago, I consolidated AI from throughout the company and named a CAIO. I then split out the role to give us a boost in the AI space, but eventually, the CAIO role will merge into IT.

How did you conceptualize the CAIO role?

At first, it was a leader who could pull use cases from all our operations and execute. The role also included the ethical use of AI systems, and prioritized what to guardrail and push out to employees.

But it’s evolved. To take a step back, Cisco pioneered enterprise networking, then built Compute with Cisco, Storage with Cisco, Networking with Cisco, Security with Cisco, and Observability with Cisco. Today, the CAIO is moving up the stack with an AI framework for MCP connectors, which has really moved us forward.

This CAIO group can tell the Cisco-on-Cisco story for AI, because we have a testbed for new ideas. If we continue to rely on multiple vendors, as in the past, we won’t be able to integrate at scale. This is why we isolated the CAIO role, to focus exclusively on AI governance and execution.

You’re in the middle of a CIO search. What are you observing about the CIO talent market?

With AI, the CIO role has completely changed. It’s no longer about UX and applications integration because with MCP, we can connect to any data source at any time, and agents have replaced the interface. The CIO role is now more about rethinking a process and then deploying an agent to execute, rather than reworking a process.

So the ideal CIO is a traditional one who’s learned to think differently, or even someone without a CIO background, but who’s led in product management, innovation, or transformation. The role today requires someone who’s been disruptive, and has had to rethink how a company operates, not just how its applications work.

Our top criteria are strategy, speed of execution, and the ability to scale because we’re not investing in science projects. For example, when the sales team requests a better forecasting tool, a CIO traditionally would make a build or buy decision. But in today’s world, the right question should be if you need a solution to forecast at all, or can an agent do it. Or better yet, do we even need this process?

So what’s the right background for today’s CIO?

Product managers have a relevant background because they manage multiple aspects of how a product comes together: user needs, business outcomes, fit in the market, and getting it built. This understanding of product strategy, marketing, and adoption is extremely important right now because we treat our AI initiatives like products. So a great path for our CIO is data scientist foundations, product management, and transformation.

What about enterprise security?

I treat enterprise security as a separate organization, which every company should do. Testing and evaluating new cyber solutions for frontier models requires a lot of work like scanning everything, taking a neutral view of what’s broken, deciding which tools become standard within development frameworks, which cryptography tools to use, and then maintenance. Abstracting that into its own organization creates focus. It also lets us move at the speed of AI.

When AI attacks, you need AI to defend you, and if security is embedded within the CIO organization, it’s not top of mind for the business. Security has become its own board-level conversation. For today’s CIO, I’d keep AI in but take security out.

A year after the CIO is in place, what will success look like?

Our applications footprint has been reduced, we’ve seen pure productivity gains from accelerating the back, and the speed of new releases is increased. The team is becoming more effective with the same resources, and we can say that our CIO drove us to leverage everything new technologies offer without blowing up on tokens. We’re looking for a new way to operate IT.

Why is the CIO job at Cisco a great opportunity for the CIO you’re describing?

It’s possibly the coolest job out there. We have an entire AI stack end-to-end that nobody else can claim because we bring networking and security together, complemented by observability and collaboration. That combination means we can create net-new solutions that define what technology looks like in the future.

On the security side, we’re one of the very few companies truly integrating AI into defense in a way that can be leveraged across a much broader market. That’s exciting, because it means free access to an entire stack that lets you innovate in ways the industry hasn’t seen before.

I call AI today’s generational technology. Every generation gets a technology that redefines how it operates, including the internet, iPhone, and now AI. Cisco is about to become the first company to launch a personalized AI agent for every employee, reachable through Webex. Think of it this way: the average person has an IQ of around 100. Now every employee is paired with an AI agent that can exponentially increase human capacity, built entirely on the technology available today.

Getting to build things like that, with no proven methodologies or limitations, and nothing but the question of how we get to the future, is the most exciting thing there is if you’re an innovative leader.

AI agents need to learn when enough is enough

For the past few years, enterprise AI programs have focused on making models more useful, accurate, and autonomous. In that phase, a bad answer was still usually something a human could accept or reject before taking action. But once agents start invoking tools and acting inside business workflows, success should no longer be measured only by how much work they complete. A more important metric is how well an agent recognizes when it lacks the authority, context, or judgment to continue.

When helpful becomes risky

According to Allan Dabre, technology compliance and AI lead at PwC, a behavior that has to be deliberately designed into the system is, “I don’t know.” AI is built to be helpful, so an agent will generally try to do something useful unless it’s been configured not to.

“The fact that AI systems can hallucinate illustrates that tendency,” Dabre says. “When they lack enough information, they may still produce an answer. In an agentic workflow, that impulse can become more dangerous because the output may become an action, rather than remain a suggestion.”

He adds that many enterprises still test AI primarily for completeness and accuracy. That made sense when the central question was if the model could produce a reliable response. But as models improve and agents gain more operational authority, he argues that CIOs need to prioritize something else: restraint.

“Can it stop at the exact moment you want it to stop?” he asks. “Are you testing for that?”

Confidence is not authority

Dabre makes a simple but important distinction. An AI agent may be 99% confident a record should be updated, a refund should be approved, or a legacy database can be decommissioned. But that doesn’t mean the agent has the authority to act. Confidence is about the probability the system believes it’s right. Authority is about whether the organization has delegated that action to the system in the first place.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Allan Dabre, technology compliance and AI lead, PwC

PwC

He gives the example of an agent asked to analyze legacy software and recommend what can be decommissioned. The agent may conclude, with high confidence, that several databases have little user impact and can be deleted. But even if the system is confident, most organizations wouldn’t want it to delete those databases on its own.

The same logic applies across business processes. An agent may be confident a customer record should be updated, an opportunity in a CRM system should be closed, or a transaction appears legitimate. But once that action flows into other systems, the potential consequences expand.

That’s why Dabre argues for what he calls an agent harness: a controls or orchestration layer outside the model that defines what the agent can and can’t do. In a refund workflow, for example, a company might let the agent approve small refunds, require human approval for larger ones, and stop the process entirely above a defined threshold. The agent may gather the relevant context, explain the request, and prepare the case for review, but the decision is governed by the authority boundary encoded into the system.

“It’s not a policy document and it’s not a prompt,” Dabre says. “It’s software or a configuration you can apply to an agent.”

The case for least agency

Matt Graney, chief product officer at Celigo, a business automation and integration platform provider, approaches the same problem through a principle he calls least agency. The idea is to give an agent the least amount of autonomy required to complete a job.

According to him, there’s a temptation to throw AI at broad, nebulous problems. But many business processes are still largely deterministic. They follow established rules and perform repeatable work. Within those workflows, AI may be useful at the point where rigid rules give way to interpretation. But that doesn’t mean the agent should own the entire workflow. “The smaller you make that surface area, the better,” he says.

Graney says the same logic applies to tools. An agent with too many tools can become confused, especially as context windows grow and the task becomes more complex. “Because Celigo is an integration platform,” Graney says, “the company’s approach is to expose agents to fewer, more powerful tools that reach enterprise systems through governed connections.”

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Matt Graney, chief product officer, Celigo

Celigo

That’s another form of restraint. Instead of letting an agent reach into enterprise systems ad hoc, the business gives it a narrow, governed toolset designed for the task at hand.

Graney also argues that guardrails should sit outside the model. If the same agent that makes a decision is also responsible for judging whether the decision is acceptable, the control is weaker. A separate guardrail can check the agent’s inputs and outputs before a downstream action occurs.

That same design discipline applies to escalation. “I don’t know” shouldn’t be treated as a chatbot phrase. In an enterprise workflow, it’s a handoff path that should be defined before the agent reaches it.

Make escalation part of the workflow

Turning uncertainty into a handoff is where Matt Quinn, CTO at CarGurus, an automotive marketplace, sees agentic AI becoming less a pure technology challenge and more a management challenge. At CarGurus, Quinn says agents are evaluated according to what they know, what they can do, and what data they operate on.

CarGurus receives a high volume of cases from dealers, and each one needs to be classified and routed. The company now uses an agent to review incoming cases, draw on account history, and route them to the appropriate next step. Quinn says the agent handles about 70% of those cases end to end without human involvement.

But when agents move toward consequential actions, he says the consensus is having a human approval step. The agent may return with a simple prompt like, I’m about to do this. Do you want me to proceed? That simplicity matters because a handoff shouldn’t bury the reviewer in complexity.

Quinn says the human remains ultimately accountable for the work. That principle is especially important in engineering, where agents may help write code or fix bugs. Quinn adds that CarGurus still expects engineers to follow the practices they’d use for any other production change, which includes running quality checks.

The company has adopted the phrase healthy speed to describe the balance it wants. The goal is to move faster without letting quality degrade. An agent can accelerate work, but if teams abandon the practices that make work safe, the speed becomes reckless.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Matt Quinn, CTO, CarGurus

CarGurus

This is also where human judgment remains difficult to replace. Quinn describes it as high judgment people develop through experience. A human may look at an AI-generated output and sense something’s wrong, even before fully articulating why. “Agents are improving,” he says. “But humans still play a critical role in deciding when the system shouldn’t continue.”

That doesn’t mean every workflow needs the same level of review. Quinn says CarGurus doesn’t have a target percentage of work to automate. The right level depends on the job and the task. A simple bug fix may require a lighter review than a change to a sensitive backend service, and a personal summary may carry little risk. But a document sent under someone’s name still needs human review.

Make autonomy accountable

That kind of pragmatic approach may be the best lesson for CIOs, making the goal of agentic AI appropriate rather than maximum autonomy.

That also means ownership has to be clear. Dabre argues ownership should be divided before deployment. The business defines the outcome, technology builds and configures the agent, risk and compliance set the guardrails, and governance monitors whether the system still behaves as intended. The authority to pause, stop, or retire an agent should be defined before production, not negotiated during an incident.

Graney makes the same point with a simple analogy. If a company hires an untrained intern, gives that intern access to the crown jewels of a business process, and something goes wrong, the intern isn’t the real problem. The process is. The same applies to agents. Accountability belongs with the person who owns the workflow.

That may be the shift CIOs need to make as enterprises move from pilots to production. AI agents shouldn’t be treated as magical workers that absorb accountability. They’re components in business processes, and those processes need accountable owners.

As AI adoption increases, the next phase of enterprise maturity won’t be defined by agents that always answer or always complete the task. It’ll be agents that know when not to act.

Now more than ever, CIOs need to be change agents

CIOs are increasingly expected to drive IT adoption in their organizations, with change management becoming a huge — and more challenging — imperative in the age of AI.

Evangelism of the latest technologies has long been part of the job, but many CIOs now say resistance to AI adoption and the fast-paced evolution of IT tools have raised the stakes.

Change fatigue has become a major challenge as Andrea Ballinger, CIO of Rensselaer Polytechnic Institute, tries to update the IT systems and provide a tech-driven ultra-personalized student experience at the university, she says.

“It’s not even inside of our institutions or our private companies, but the world is throwing so much at us,” she adds. “What you heard today, you’re being told something else tomorrow.”

For CIOs, change management means recognizing that some employees are on a slower journey and, at the same time, encouraging staff to embrace progress, Ballinger says. Good leaders will recognize that some employees will resist, but it’s their responsibility to help employees navigate the changes, she adds.

“Change management is understanding where people are at,” she says. “It’s having that sense of urgency, but a sense of urgency does not mean running without a parachute or without a plan. It means you act today.”

Change management was a big topic of conversation at the CIO 100 Awards and Conference in Frisco, Texas, in mid-August. Several speakers mentioned the challenge, with Ravi Malick, global CIO at cloud-based content sharing service Box, saying change management now represents about 80% of the job, far outpacing pure IT issues.

The change management aspects of a major digital transformation are often what makes or breaks the effort, he says.

AI in particular has forced CIOs to pay more attention to change management because it fundamentally changes the way employees work, he adds. Some past technologies, like the internet and mobile computing, largely started in the consumer space, then leaked over into the enterprise, giving employees time to get comfortable, he notes.

“AI is something that’s reshaping both the consumer space and the enterprise at the same time,” Malick says. “Both the enterprise and individual people are trying to figure out how to get the most value out of it.”

Some revolution, some evolution

As a company, Box is moving forward quickly on some AI initiatives while taking a wait-and-see approach on others, in part to manage the changes required, notes Malick, who sees adoption of AI and other new technologies as a major challenge.

“There are parts of this that are revolutionary, and there are parts that need to be evolutionary,” he explains. “The best way to get somebody pointed in a different direction is to make them realize they haven’t done an 180-degree turn. Get them to realize, ‘I turned on my own, and I actually like the direction that I’m pointed in.’”

To encourage adoption, Box has pitched AI to employees as an enabler and amplifier, not as a technology that will replace their jobs, Malick says.

“We’re asking, What are the things that we can do now that we weren’t able to do before?” he says. “How can we apply your years of the experience and intellectual power toward other areas that we just couldn’t get to before?”

Box isn’t closely tracking how employees are using the time saved through AI tools, he adds. If employees are using the extra time to improve their quality of life, that’s ok, he says.

“Maybe they’re not working on the weekends at the end of the month closing the books,” he says. “Maybe they actually have weekends now and can spend more time with their families.”

Change across the organization

Other CIOs say the change management piece of the job has increased significantly in the past two to three years.

In recent years, CIOs have been pulled into change management roles within other parts of the business as teams identify AI opportunities, says Orla Daly, CIO at skills management company Skillsoft.

“As AI blurs the lines between technology, operations, and people strategy, the CIO role is becoming closer to that of a COO,” she adds. “Workforce strategy is folding in alongside technology strategy, so leading change now sits at the center of the role rather than being one piece of it.”

The rapidly changing technology landscape has also thrust change management to the forefront of the CIO role, she says. “The pace at which decisions need to be made has increased so dramatically that you can’t lead at a distance and expect strategy to translate cleanly into action,” Daly says.

Daly also notes that slow adopters aren’t always active resisters. Skillsoft’s 2026 Workforce Readiness Report found that while 86% of employees use AI tools at work only 24% feel fully equipped to use them effectively, and just 16% receive training before a new tool is introduced.

“That gap suggests an over rotation on tooling without understanding how it changes how work is executed,” she says. “In most cases, it’s uncertainty and a lack of confidence to take the first step, not a lack of interest.”

Daly and other CIOs suggest that mandating the use of a new tool is rarely the right approach.

“Requiring it can create activity, but activity isn’t the same as adoption,” she explains. “If you hand people tools without clear use cases, guardrails, and training, a mandate just accelerates inconsistent use, and you mistake activity for progress.”

NTT DATA focuses on employee AI fluency instead of mandated activity, and the CIO has a huge role to play, says Barry Shurkey, CIO at the company. The CIO role increasingly sits at the intersection of technology, business strategy, and people, he says.

“AI success is not just about moving quickly; it is about helping people understand the change, embrace it, and move forward with confidence,” he adds.

NTT DATA’s own research suggests that AI front-runners use AI to amplify the impact of experienced, highly skilled employees rather than to replace them, Shurkey says.

“As AI accelerates transformation, CIOs are doing more than implementing technology,” he adds. “They are redefining how people work, make decisions, create value, and just as importantly, managing the intensified resistance that’s driven by fear of job loss or control.”

Shrewd IT hiring strategies have never been more critical

Major shortages of qualified professionals for key IT roles will lead to huge competitive challenges for organizations that fail to prioritize tech recruiting over the next couple of years, industry observers say.

Hiring the right staff has always been a prime concern for IT leaders, but the pressure to find the right candidates has never been higher, with qualified AI, cybersecurity, and data science professionals especially difficult to find.

Worse, those three domains, along with business/IT automation and risk management, make up the top five areas where CIOs are hiring today, according to CIO.com’s State of the CIO survey. Everyone appears to be hunting the same scarce resources — a market condition that’s already undercutting enterprise opportunities, around AI in particular.

As a result, IT hiring practices over the next 18 months to two years could make or break companies, with laggards risking a huge competitive disadvantage, experts suggest.

Organizations need to think both about hiring outside workers and retraining existing employees to cover gaps, says Adam Wachtel, CTO at employee onboarding platform provider Click Boarding. IT leaders should think wholistically about building capabilities in their teams, he suggests.

“The market for pure AI specialists is volatile and expensive and keeps shifting,” he notes. “What separates organizations right now is whether they’re building AI capability into the team they already have or waiting to buy it fully formed from outside; those building make progress while those waiting are falling behind, and it’s only becoming more expensive.”

There are major implications for organizations that fall behind, Wachtel adds.

“The most immediate risk is technical debt you can’t see accumulating until it’s expensive to fix,” he says. “I’ve lived through rebuilding a team and a platform from a thin, overstretched state, and the lesson that stuck with me is that understaffing or misaligned hiring fails quietly through slower development, more fragile systems, engineer burnout, and more time fixing versus building — it’s not fun for anyone.”

There are several implications for botched hiring efforts, notes Henry Vassal Jones, CIO at outsourcing provider Emapta.

“If you don’t have the people and capabilities to execute, transformation slows, product releases get pushed out, and existing teams carry more of the burden,” he says.

Risk of failure

Critical AI initiatives can fail without the right people in place, Jones notes. “Companies can invest heavily in AI platforms, but without people who understand the business processes, data, governance, and security behind those tools, much of that investment will never reach its potential,” he says.

Jones agrees that employee training, as well as strategic hiring practices, plays an important role in keeping organizations reaching their capacities.

Successful companies will broaden their approaches beyond constrained local or regional talent markets and develop their existing people, he says.

“Those that don’t risk seeing the gap between what the business needs and what their technology teams can deliver continue to widen,” Jones adds. “For CIOs and CTOs, this is no longer simply about filling open positions; it’s about building a talent model that gives the organization access to the right capabilities when needed.”

How to approach the talent challenge

When it comes to developing that talent model, Konstantinos Dolkas, CTO of cybersecurity upskilling and workforce development company Hack The Box, calls for IT leaders to broaden their geographic horizons. While talent is distributed, most hiring strategies still aren’t, he says.

He also advocates employee upskilling. “Recruiting externally can’t be the entire solution,” he says. “Build the majority, buy the scarcity. That could mean a few genuinely senior external hires to set patterns and mentor.”

Given shortages in AI and cybersecurity skills, hiring leaders should also focus more on demonstrated skills from outside hires than the titles they’ve held, Dolkas suggests.

“The best strategy is to hire for demonstrated ability, not credentials,” he says. “Put candidates in a hands-on environment and watch them work. It’s the only screen that survives contact with reality.”

Assessing AI security skills can be particularly difficult in a field that reinvents itself every quarter, Dolkas adds. Another challenge is separating genuine AI fluency from tool familiarity: “Prompting an assistant is not the same as securing an agentic system,” he says.

Anticipate the market and focus on future needs

In addition to building from within, smart IT leaders are focusing on the capabilities their organizations need one to three years from now, says Tom Ioele, CEO at recruiting firm TalentBridge.

IT leaders involved with hiring decisions should think about building talent communities before the demand exists, he says. Organizations should continuously identify and engage with people who have the skills they know they will need, instead of starting to search when a requisition opens, he advises.

“The biggest mistake companies make is treating hard-to-find technology talent like a traditional requisition,” Ioele says. “By the time an AI engineer, cybersecurity expert, or data scientist hits the open market, every company is competing for the same person.”

The companies that win won’t necessarily have the largest recruiting teams, but they will have the best talent intelligence and the ability to activate it faster than their competitors, he adds. Successful organizations will build talent capacity before they need it, he says.

“We’re entering a market where the skills companies need are changing faster than traditional workforce planning cycles,” Ioele says. “Organizations that continue operating through a simple post-a-job, screen resumes, fill-a-seat model will constantly be reacting to yesterday’s demand.”

See also:

Tableau certification guide: How to boost your data analytics skills

Data visualization platform Tableau is one of the most widely used tools in the rapidly growing business intelligence (BI) space, and individuals with skills in Tableau are in high demand.

In its Data Visualization Tools Market Report 2026, released in July, The Business Research company forecast the global data visualization tools market would grow from $10.73 billion in 2026 to $17.33 billion in 2030 at a compound annual growth rate of 12.7%, driven by growing adoption of augmented analytics, rising demand for embedded analytics solutions, expansion of cloud-native data platforms, increasing use of visualization in AI-driven insights, and a growing focus on predictive and prescriptive analytics.

Tableau is consistently listed as a leader in the BI industry, helping business users better access, prepare, and present data insights. And with the market for data visualization rising, and Tableau’s position well established, certification for Tableau skills can present a lucrative path to career growth. Here’s a guide to Tableau’s array of certifications.

Why get Tableau certified?

According to Pearson VUE’s 2026 Value of IT Certification Employer Report, 99% of the 500 global IT and HR leaders surveyed said their organization measures ROI of certifications, and 93% reported positive results. Estimated per-employee value averaged about $17,500 annually and 88% of respondents said they expect certifications will matter more to their organization in three to five  years.

Tableau’s certifications, in particular, focus on performance-based testing rather than theory in an effort to verify a candidate’s ability to apply the subject matter in a real work environment.

Benefits of Tableau certification

Individuals who’ve obtained Tableau certification say Tableau skills remain in-demand in the job market, and adding Tableau certification to their CVs has helped them gain the attention of hiring managers.

Tableau has also become the go-to tool for data visualization in many enterprises. Nothing outdoes knowledge and experience when it comes to actually landing a job, but a certification can help you stand out and get an interview in the first place. Even those who use Tableau in their jobs regularly say that preparing for the certification exams has helped them learn new capabilities of the tool, and challenged them to think through design and storytelling in different ways.

Tableau says certification has key benefits such as learning in-demand data skills, helping your company be more data-driven, gaining confidence and data literacy, and increasing earning potential.

Career opportunities with Tableau certification

The high demand for data visualization in the enterprise translates into high demand for Tableau professionals. Tableau roles in high demand include:

  • Tableau analyst: These professionals use Tableau software to create reports and presentations to communicate complex information.
  • Tableau developer: Those who create interactive dashboards and reports.
  • Tableau architect: This role designs and maintains the technical infrastructure to effectively use Tableau in the enterprise.
  • Tableau consultant: Consultants focus on integrating Tableau’s capabilities within organizations.
  • Tableau software trainer: These people enhance data literacy across organizations so employees can make better use of Tableau.
  • Tableau visualization expert: These professionals combine analytics and art to make interactive dashboards pop.
  • Tableau BI manager: These leaders drive BI strategy, combining technical know-how and strategic vision to give senior management a view of critical business metrics.

A Tableau certification can help you gain and enhance numerous skills demanded by data-driven enterprises, including:

  • Data visualization and storytelling: The core capability of a Tableau data analyst is communicating complex data in a clear, engaging manner. They can create visualizations that help stakeholders intuitively grasp insights from data.
  • Technical proficiency: Preparing for certification helps data analysts grasp the depth and breadth of Tableau’s capabilities, with understanding of elements like data blending, custom geocoding, and advanced calculations.
  • Analytical and critical thinking: Certification requires candidates understand data preparation, cleaning, and transformation, and they must be skilled in SQL, data warehousing processes, and ETL processes.

Tableau certification salaries

Here are some of the most popular job titles related to Tableau certifications and average salary for each position, according to 2026 data from PayScale:

  • Data analyst: $56,000-$99,000 (median $74,000)
  • Data visualization specialist: $68,000-$149,000 (median $96,000)
  • Business intelligence analyst: $62,000-$111,000 (median $82,000)
  • Senior data analyst: $77,000-$128,000 (median $98,000)
  • BI developer: $72,000-$124,000 (median $93,000)
  • Data scientist: $77,000-$142,000 (median $101,000)
  • Analytics manager: $82,000-$136,000 (median $109,000)
  • Analytics consultant: $81,000-$133,000 (median $92,000)

Tableau certification levels

Tableau offers five certifications, including an associate certification — Certified Tableau Desktop Foundations — and four professional certifications: Certified Tableau Architect, Certified Tableau Consultant, Certified Tableau Data Analyst, and Certified Tableau Server Administrator. The associate certification is for entry-level candidates and demonstrates basic knowledge. The professional certifications are for candidates with a higher level of expertise. They require advanced skills and a deeper understanding of Tableau’s features.

Which is the right Tableau certification level for your career goals?

Choosing a Tableau certification to pursue depends on your career goals. As an associate certification, the Certified Tableau Desktop Foundations certification is likely the certification you should pursue.

From there, it depends on your professional goals. The more advanced certifications are:

  • Certified Tableau Data Analyst: Choose this if you’re a data analyst, business analyst, or other business user using Tableau to analyze data and make business decisions.
  • Certified Tableau Server Administrator: Choose this if you’re an IT professional, systems administrator, or consultant focused on installing, configuring, and administering Tableau Server.
  • Certified Tableau Consultant: Choose this if you’re a consultant focused on helping customers design an analytics solution within the Tableau platform.
  • Certified Tableau Architect: Choose this if you’re an experienced professional focused on implementing Tableau, as well as best practices and maintenance of the overall Tableau ecosystem.

Certified Tableau Foundations

The Certified Tableau Desktop Foundations certification, formerly Tableau Desktop Specialist certification, validates a foundational knowledge of Tableau Desktop and data analytics to solve problems. It demonstrates understanding of Tableau core concepts and terminology, and the ability to connect to, prepare, explore, and analyze data, as well as share insights. Candidates must have at least three months of experience applying their knowledge in Tableau Desktop. The certification doesn’t expire.

Exam: 70-minute exam consisting of 40 multiple-choice and multiple-select questions.

Cost: $75

Training and practice tests: There are no prerequisites, but several training resources can help you prepare:

Certified Tableau Server Administrator

The Certified Tableau Server Administrator certification, formerly Tableau Server Certified Associate, is intended for people with a comprehensive understanding of Tableau Server functionality in a single-machine environment, and approximately six months of experience. Typical roles include system administrators and consultants. Individuals with this title can plan a deployment; install and configure Tableau Server; administer users, groups, projects, and content; and backup, restore, upgrade, and troubleshoot Tableau Server problems. The title is active for two years from the date achieved.

Exam: 90-minute exam consisting of 55 multiple-choice and multiple-response questions.

Cost: $200

Training and practice tests: There are no prerequisites, but several training resources can help you prepare:

Certified Tableau Data Analyst

This certification, formerly the Tableau Certified Data Analyst certification, is part of the analyst learning path. The exam measures the candidate’s knowledge of the capabilities of Tableau Desktop, Tableau Prep, and either Tableau Server or Tableau Online. People with this cert have proven ability to connect to data sources, perform data transformations, explore and analyze data, and create meaningful visualizations that answer key business questions. The Tableau Certified Data Analyst title is active for two years from the date achieved.

Exam: A 105-minute exam of 60 multiple-choice and multiple select questions, as well as five non-scored questions.

Cost: $200

Training and practice tests: There are no prerequisites, but several training options can help you prepare for the exam:

Certified Tableau Consultant

The Certified Tableau Consultant certification, formerly the Tableau Certified Consultant certification, is for those who engage with customers and lead the design of an analytics solution with the Tableau platform. It validates core Tableau knowledge and development skills of employees, partners, customers, and freelancers who need to work with Tableau products like Tableau Prep, Desktop, Cloud, Server, and Bridge. There are no prerequisites to the exam and the certification is valid for two years.

Exam: 105-minute exam consisting of 60 multiple-choice and multiple-select items, and up to five non-scored questions.

Cost: $200

Training and practice tests: There are no prerequisites, but several training resources can help you prepare:

  • The Certified Tableau Consultant Exam Guide provides information about the target audience, the recommended training and documentation, and a complete list of exam objectives.
  • The curriculum of the Analyst Learning Path training includes getting started with Tableau, connecting to and transforming data, creating views and dashboards, exploring and analyzing data, and publishing and managing content.
  • The Designer Learning Path curriculum includes getting started with Tableau Desktop, Tableau fundamentals, Tableau intermediate, visual analytics, and dashboard design.

Certified Tableau Architect

The Certified Tableau Architect certification, formerly the Tableau Certified Architect certification, is intended for experienced professionals who lead the design of a Tableau Server deployment or a Tableau Cloud migration. They have skills and experience designing, deploying, monitoring, and maintaining a scalable Tableau platform and migrations to Tableau Cloud. They also implement complex deployments of Tableau Server in enterprise-level environments. The certification validates core Tableau knowledge and hands-on development skills. There are no prerequisites to the exam and the certification is valid for two years.

Exam: 105-minute exam consisting of 59 multiple-choice and multiple-select items.

Cost: $400

Training and practice tests: There are no prerequisites, but several training resources can help you prepare:

  • The Site Admin Learning Path training includes getting started with Tableau Server and Tableau Cloud basics, introduction to site administration, site management, site monitoring and maintenance, and content ownership.
  • The Server Admin Learning Path includes getting started with Tableau Server and server administration.
  • The Server Architect Learning Path includes getting started with Tableau Basics and Tableau Server Enterprise Deployment Guide.

Tips and strategies to pass the Tableau certification exam

Tableau offers free exam prep guides for its certification exams. These guides provide overviews of each exam and its structure, how it’s scored, and a list of recommended training and resources. The guide explains the skills the exam measures along with some sample questions. Use the list of skills measured as a checklist of the subjects you need to study for the exam.

The recommended training and resources include Tableau’s learning paths and videos designed to train candidates for a particular role.

Real-world examples to practice your Tableau skills

Tableau has published a set of five common advanced analytics scenarios and resources to show how Tableau can be used for data analysis. These include:

For more detail, Tableau has published a whitepaper on advanced analytics with Tableau.

20 in-demand cloud roles companies are hiring for

Organizations continue to invest heavily in the cloud, with IT leaders reporting that 26% of their IT budget will be allocated to cloud computing within the next year, according to the 2026 Foundry Cloud Computing Study.

The survey also found that 74% of IT leaders have accelerated cloud migrations in the past 12 months compared to 70% in 2025 and 63% in 2024. Three in four (73%) also said cloud capabilities have helped their organizations achieve “increased and sustainable revenue over the past 12 months.” Overwhelmingly, 80% of respondents from North America and APAC noted that their cloud strategies have helped accelerate the adoption of AI, while that number drops to 68% for the EMEA region.

This growth in cloud adoption, along with accelerated interest in AI, has sparked an increased demand for certain cloud roles. Here are the roles companies are most likely to have added to support their cloud investments, according to Foundry’s research.

And for those looking to break into this lucrative IT pathway, see “Where to begin a cloud career” and “18 best entry-level IT certifications to launch your career,” which includes several good cloud-related credentials to get started with.

2026 Cloud Computing Survey: Slide 41 Cloud Roles

Foundry

AI/ML engineer

The role of AI/ML engineer is in high demand as organization expand their AI strategies. These professionals design and implement AI and machine learning systems, overseeing them in operation to identify opportunities for improvement, ways to better automate processes, and how to better inform decision-making across the organization.

Skills: Skills for this role include programming, knowledge of machine learning, data science, data engineering, and experience building AI systems using APIs. See also: “The hidden skills behind the AI engineer.”

Role growth: 36% of companies have added AI/machine learning engineers as part of their cloud investments, according to Foundry’s survey.

AI platform engineer

An AI platform engineer is responsible for building and running the internal systems that businesses use to build and scale AI tools and initiatives. As organizations increasingly adopt AI internally, they’re hiring professionals to help navigate the daily operations of internal developer platforms (IDPs) that use AI to boost productivity and drive automation.

Skills: Skills for this role include understanding of cloud infrastructure, programming languages, and orchestration and container technology, including Kubernetes and Docker.

Role growth: 27% of companies have added AI platform engineers as part of their cloud investments.

Cloud architect

As cloud computing grows increasingly complex, cloud architects have become vital for navigating the nuances of implementing and maintaining cloud environments. These IT pros can help organizations avoid cloud security risks, while also ensuring a smooth transition to the cloud. With 65% of IT leaders choosing cloud-based services by default when upgrading technology, cloud architects will only become more important for enterprise success. For those interested in this role, see “IT career roadmap: Cloud architect.”

Skills: Skills for this role include knowledge of application architecture, automation, ITSM, governance, security, and leadership.

Role growth: 21% of companies have added cloud architect roles as part of their cloud investments.

Cloud software engineer

Cloud software engineers are tasked with developing and maintaining software applications that run on cloud platforms, ensuring they are built to be scalable, reliable, and agile. Companies that have migrated to the cloud often need IT pros who can build company-specific services and applications to make the most of the cloud environment. For more on this career path, see “IT career roadmap: Cloud engineer.”

Skills: Relevant skills for a cloud software engineer include Python, Java, C#, JavaScript, microservices architecture, serverless computing, APIs and SKDs, DevOps, cybersecurity, and knowledge of the agile methodology.

Role growth: 20% of companies have added cloud software engineer roles as part of their cloud investments.

Cloud developer

Cloud developer is a vital role for developing and deploying software in cloud environments. These IT pros are tasked with designing, creating, and deploying applications designed to run on cloud platforms, with a focus on building scalable, reliable, and cost-effective solutions to meet business needs.

Skills: Relevant skills for a cloud developer include programming languages such as Java, C#, and Python as well as knowledge of popular cloud platforms, microservices architecture, database storage, agile methodology, APIs and SKDs, and containers and orchestration.

Role growth: 20% of companies have added cloud developer roles as part of their cloud investments.

Security engineer

Security engineers are tasked with overseeing the security of an organization’s systems, networks, and data, to make sure they’re protected from cybersecurity threats. For organizations investing in the cloud, security engineers can help ensure services, applications, and data running on cloud platforms are secure and compliant with any government regulations.

Skills: Network security, IAM, encryption, vulnerability management, security architecture, cloud security, automation, and infrastructure design and optimization.

Role growth: 19% of companies have added security engineer roles as part of their cloud investments.

Cloud consultant

With the rapid adoption and move to the cloud, organizations look for professionals who can leverage cloud technologies to meet business needs, grow the business, and improve efficiency. Cloud consultants are cloud experts who stay on top of the latest innovations in cloud technology to better advise business leaders.

Skills: Knowledge of architecture and solution design, DevOps, automation, project management, cloud security, compliance, cloud migration, and knowledge of popular cloud platforms.

Role growth: 16% of companies have added cloud consultants as part of their cloud investments.

Security architect

Security architects are responsible for building, designing, and implementing security solutions in the organization to keep IT infrastructure secure. For security architects working in a cloud environment, the focus is on designing and implementing security solutions that protect cloud-based infrastructure, data, and applications.

Skills: Security architecture design, network security, security compliance and governance, incident response and forensics, data encryption, IAM, automation, and DevSecOps.

Role growth: 16% of businesses have added security architect roles as part of their cloud investments.

Cloud product manager

With cloud adoption often comes an increase in in-house development of cloud-based services. A cloud product manager can help cloud teams develop effective solutions aimed at fulfilling business objectives. They’re also tasked with using their deep understanding of product management within the cloud environment to work closely with key stakeholders, identify and define requirements from users or customers, develop product roadmaps, and oversee the QA process to gain feedback on how to improve product offerings. 

Skills: Product management, UX design, communication and collaboration, and a strong technical background.

Role growth: 16% of organizations have added cloud product manager roles as part of their cloud investments.

Cloud governance/compliance manager

Cloud governance and compliance managers help companies navigate the complexities of security, governance, international regulation, and internal policies. They identify potential risks, implement automated tools to oversee security and compliance, and help businesses maintain secure cloud operations.

Skills: A strong knowledge of regulatory policies such as GDPR, HIPAA, PCI DSS, and other international data protection laws. Additional skills include knowledge of tools such as CSPM, Azure, AWS, Microsoft Purview Compliance Manager, and other IT governance tools.

Role growth: 16% of businesses have added cloud governance and compliance manager roles as part of their cloud investments.

Cloud network engineer

Cloud network engineers are responsible for the design, implementation, and management of an organization’s cloud-based networks. These IT pros are tasked with overseeing network management, virtualization and virtual LAN, wide area networks, TCP/IP, HTTP, network security, and the integration of hybrid cloud and multicloud deployments.

Skills: Relevant skills for this role include knowledge of cloud platforms such as Azure, AWS, Google Cloud, along with networking fundamentals, virtualization, project management, security, automation and scripting, and collaboration.

Role growth: 15% of companies have added cloud network engineer roles as part of their cloud investments.

Data architect

data architect’s focus is seeing that an organization’s data is structured so it can be easily accessed, secured, and efficiently stored, and that it meets business needs. Data has become a primary way for businesses to conduct analysis and assist with business decision-making, and most of that data is now stored in the cloud.

Skills: Data warehousing, scalability and performance optimization, automation and virtualization, data governance and cloud security, data migration, and knowledge of hybrid cloud solutions.

Role growth: 14% of businesses have added data architect roles as part of their cloud investments.

Prompt engineer/AI application developer

Prompt engineering and AI application development go hand in hand, and they’ve become vital skills for organizations that have embraced AI and plan to implement AI-focused services and into daily workflows. Prompt engineers are responsible for designing and refining the instructions and structural queries, while an AI application developer builds software system and user-interfaces for AI-ready software and services.

Skills: Skills for this role include programming languages, database management, API integration, and software engineering. See also: “How to get started with prompt engineering” and “Prompt engineering courses and certifications tech companies want.”

Role growth: 14% of companies have added prompt engineering and AI application developer roles as part of their cloud investments.

Cloud platform engineer/platform ops

Cloud platform engineers, who often work in platform operations, are responsible for building and maintaining cloud tools, automated systems, self-service portals, and other software that developers use to test code. In this capacity, they’re responsible for creating user-friendly platforms for other engineers in the company to build and test their own software for clients and customers.

Skills: Skills for this role include infrastructure as code (IaC), containerization and orchestration, scripting and coding, and Linux and networking.

Role growth: 14% of companies have added cloud platform engineering roles as part of their cloud investments.

MLOps engineer/AI operations engineer

The role of MLOps engineer or AIOps engineer has been developed to help close the gap between data science and IT operations. It’s a role that has emerged as the use of AI increases, as organizations need a point person who has expertise in IT operations and machine learning, and is comfortable collaborating with data scientists, developers, IT operations staff, and key stakeholders.

Skills: Skills for this role include programming, DevOps, cloud tools, containerization and orchestration, and knowledge of ML tools.

Role growth: 13% of companies have added MLOps engineers as part of their cloud investments.

Cloud sysadmin

Cloud systems administrators are charged with overseeing the general maintenance and management of cloud infrastructure. Whether that means implementing cloud-based policies, deploying patches and updates, or analyzing network performance, these IT pros are skilled at navigating virtualized environments. Cloud sysadmin is likely the most entry-level-friendly role on this list.

Skills: An understanding of implementation and integration, security, configuration, and knowledge of popular cloud software tools such as Azure, AWS, GCP, Exchange, and Office 365.

Role growth: 13% of companies have added cloud systems admin roles as part of their cloud investments.

DevOps engineer

DevOps focuses on blending IT operations with the development process to improve IT systems and act as a go-between in maintaining the flow of communication between coding and engineering teams. It’s a role that focuses on the deployment of automated applications, maintenance of IT and cloud infrastructure, and identifying potential risks and benefits of new software and systems.

Skills: Automation, Linux, QA testing, security, containerization, and knowledge of programming languages such as Java and Ruby.

Role growth: 11% of companies have added DevOps engineer roles as part of their cloud investments.

FinOps/cloud cost optimization practitioner

FinOps and cloud cost optimization practitioners combine knowledge of finance, technology, and businesses to help oversee the increasingly complex landscape of cloud investments. Cloud computing is integral to AI, so as more organizations invest in it, they’re also revisiting investments in cloud infrastructure. FinOps and cloud cost optimization practitioners can help guide organizations to make the right financial decisions around technology investments that’ll impact the business.

Skills: Knowledge of finance, business, and technology along with skills using tools and platforms including AWS, Azure, GCP, and cloud-native FinOps platforms.

Role growth: 9% of companies have added FinOps and cloud cost optimization practitioner roles as part of their cloud investments.

Site reliability engineer

For any organization implementing cloud strategies, there’s a significant focus on reliability and scalability, ensuring that data can be accessed from the cloud and on-demand as needed. Site reliability engineers (SREs) are responsible for overseeing automation of IT infrastructure, application monitoring, and system management. Cloud infrastructure requires frequent software updates, and services must be able to scale with the organization’s growth.

Skills: Change management, IT infrastructure management, emergency incident response, process improvement, and application monitoring.

Role growth: 8% of companies have added site reliability engineer roles as part of their cloud investments.

FinOps lead/FinOps manager

FinOps leads and FinOps managers are tasked with overseeing the intersection of engineering, finance, and business. As more organizations build cloud services and tools, they’re looking for FinOps professionals with technical knowledge to help bridge the gap between finance and tech, bringing better insights into ways to cut costs and stay on budget while implementing innovative technology.

Skills: FinOps leads and managers need a strong understanding of engineering, finance, and technology. Additional skills include knowledge of cloud platforms, basic coding skills, and data analytics.

Role growth: 6% of companies have added FinOps lead and FinOps manager roles as part of their cloud investments.

As cloud experience becomes more critical to organizations hosting AI-powered services, tools, and software, these cloud roles and skills will become increasingly in-demand. Now is an opportune time to seek out valuable cloud certifications and other relevant AI and ML certifications to boost your resume, and set yourself up for these emerging and established career paths.

The SaaSpocalypse is a people problem

There is a tidy story going around about the end of enterprise software. Call it the SaaSpocalypse. AI and vibe coding have made it cheap enough to rip out your software-as-a-service contracts and build your own replacements.

The rush to rebuild carries its own risk, one that surfaces only after the SaaS is gone. Teams can almost always build the replacement. What they build, too often, is a copy of what they already had.

Few people are better placed to see that risk than Mike Anderson. As chief digital and information officer at Netskope, the cloud security company that went public on the Nasdaq in September 2025, Anderson runs both IT and the company’s strategy office, a seat that spans his own operations and the broader go-to-market. He is a 2026 inductee into the CIO Hall of Fame, sits on a long list of advisory boards and venture capital innovator networks, and is one of the industry’s most connected executives, fielding peer questions about AI nearly every week. Before Netskope, he was CIO for North America at Schneider Electric. He lives in Dallas.

It starts with how fast the ground has moved. “We’ve gone from AI is my assistant, to I’m delegating a task to an agent, to I’m actually delegating full bodies of work to agents,” Anderson says. “We’re in that last one now.” The trouble is that our instincts have not caught up.

The trap of rebuilding what you already have

Anderson is not interested in slowing anyone down. “I’m a big believer in innovation at the edge of your company. Innovate closest to the people, closest to the problem,” he says. “As CIOs, we don’t want to be the people who say no. We want to let them experiment and learn.”

The danger he points to is quieter than recklessness. It is the pull to aim powerful new tools at rebuilding the past. “The risk is we’re not thinking differently. We’re thinking based on the bias of how things work today,” he says. “Today’s systems are built around people: dashboards that serve us insights, forms we fill in, workflows that pass work between teams. If we go vibe code something, it’s probably going to look a lot like that,” Anderson says. “And it’s not designed for agents, who don’t need a form and don’t need the dashboard. They just need access to the data, the API to call or the other agent to talk to.”

As Anderson sees it, the opportunity is bigger than software. “It’s about reinventing processes with agents in the middle of the process,” he says.

Start with the outcome, not the keyboard

Doing that well means fighting the urge to start building. “Before you put any fingers on keyboards, get a small cross-functional team together, look at reimagining the process and start from the outcome. Then work back,” Anderson says.

It also means changing the question. The reflex has been to ask whether a task can be done with AI. Anderson wants a sharper test. “It’s this work I could delegate to an agent in a deterministic way, where there’s predictability in the outcome,” he says. “That’s a different pivot from where we were three or six months ago.”

The teams that pull this off do not need to be big. Anderson keeps them deliberately small: a subject matter expert who lives the problem, a product owner who frames the context and an engineer who turns it into something an agent can act on. “The old rule was a two-pizza team,” he says. “Now maybe the two pizzas are for three people who are just really hungry, because they’re working tirelessly.”

The unglamorous foundations

Before any of that, Anderson puts discipline around what gets built at all. Every candidate is weighed against three levers: whether it accelerates growth, whether it takes out cost and creates leverage, and what the risk is if it goes wrong.

Then come what he calls the primitives: consistent user management, observability in the tools and standards encoded where agents will read them. “I have markdown files that determine the technologies I want used, down to the database,” he says. “I don’t want agents deciding today that they’re going to introduce a database that’s never been in my environment, because at some point this has to move to a production state.” That last part is what he thinks teams underestimate. When you replace a vendor, you inherit the job the vendor used to do. “Someone has to keep it running. We didn’t have that responsibility in SaaS. Now we do,” he says.

The foundations reach past code, too: style guides, shared libraries, reusable AI assistants and skills that help non-engineers describe what they want, and documentation he insists must be “a first-class citizen.” Netskope IT team built one called Professor Vibe Code that turns a recorded description of an outcome into instructions an AI can build from. “It’s not ‘I need a field on a screen,'” he says. “It’s describing what you want as context with a clear definition of success.”

Why this is really a people problem

For all the talk of architecture, Anderson keeps steering back to people. “We’ve always said building the technology is easy. Getting people to use it is hard,” he says. “That’s even more true here.” He has lived through the internet, SaaS and cloud, and ranks none of them with this. “I can’t point to a technology that’s as disruptive, or that introduces as much change, as AI.”

Which is why he now treats his chief human resources officer as just as critical a partner as his CISO. The two of them talk constantly about the human risk of AI and how to bring people along. “Everyone is worried. Is AI going to replace me? What’s my future in an AI-first world,” he says. “So much of this comes down to giving people clarity about where they fit.”

Borrowing from Maslow, he notes that psychological safety rests on more basic needs, the paycheck and the roof, and that people who feel threatened do not stay neutral. “Without psychological safety, on one extreme you get AI sabotage. On the softer end you get passive resistance, where people just resist using the AI,” he says. The aim is to keep humans at the center of processes that increasingly run without them.

Where to start

For CIOs facing the same moment, Anderson’s advice comes down to three moves. Start with a phone call. “If you’re not talking to your CHRO, get them on speed dial,” he says. “We’ve always kept the CISO on speed dial because security matters so much. You have to add the CHRO now.”

Then be honest about the impact, even when the picture is incomplete. “You may not have all the answers today. Telling people that is important,” he says. And lay the foundations so teams can build at the edge without recreating the old pattern of work handed off later with no context.

The ground keeps shifting, and Anderson does not pretend otherwise. The leaders who come out ahead, in his telling, will be the ones who redesign the work, lay the foundations and never lose sight of the people doing it. For him, the discomfort is the job now. “The world is moving at a pace I’ve never seen before,” he says. “Every day, I have to get comfortable being uncomfortable.”

10 steps to implement an effective AI training program

It’s no surprise that reaping the rewards from AI requires careful guidance, especially in helping staff use tools safely and productively. Yet evidence suggests some CIOs and their executive peers aren’t providing the level of guidance employees require.

While three-quarters of IT staff have access to AI tools, one in five technologists are expected to self-learn, and 23% are waiting for formal training, according to the recent Harvey Nash Tech Talent Salary Report, which surveyed over 3,600 technology professionals globally.

The research suggests AI explorations are commonplace, but tailored learning and development initiatives are not. Digital leaders who want to turn AI into a value-generating opportunity, though, must educate their staff. But what elements should AI training schemes include? Here, industry experts offer 10 steps to implement an effective program.

1. Take a comprehensive approach

Michael Cole, chief technology officer at the DP World Tour, the men’s professional golf tour that oversees 42 tournaments in 25 countries, says AI training is an organization-wide effort.

“I’ve asked the training coordinators in our HR department to help me deliver what I believe is going to be a fit-for-purpose training and development program for not only my IT team here at the European Tour, but equally across the business,” he says.

Cole says the crucial element to emphasize is that AI and the range of capabilities it brings is about much more than learning how to use technology. “Using AI effectively is about process, mindset, and culture,” he says. “So, when we start to think about the training and development needed to bring an organization like ours into this AI-enabled era of transformation, it’s a comprehensive program that must extend across the business.”

2. Educate the boss

In an organization-wide program, everyone needs AI education, including the boss. That’s why Emmanuel Frenehard, chief digital officer at biopharmaceutical giant Sanofi, says his firm takes a multi-layer approach to AI training.

The executives there completed Drive Digital, a program that Sanofi designed with the ESSEC business school in Paris. The initiative focused on core considerations, such as use cases and value generation. After 150 managers passed through the program, it was extended to more than 1,000 other professionals across the organization.

“Don’t just look for the solution; don’t just think about Claude or ChatGPT,” says Frenehard, referring to best-practice lessons. “Think about the challenge you’re trying to solve. In our case, that approach means focusing on what we’re doing, the value we’re looking to create, and the dependencies the project will create.”

He says training also needs to help AI doubters overcome their fears. “You have to make it fun and as risk-free as possible,” he says. “People shouldn’t feel they need to be super-technical to use AI productively.”

3. Build clarity and agency

Jo Bishenden, chief learning officer at tech training and talent provider QA, says AI education is often treated as a one‑off awareness session, a compliance requirement, or something reserved for technical specialists. 

The best programs get three things right. They provide a baseline for everyone across the organization, the courses focus on role-specific applications to show how AI impacts everyday activities, and they provide continuous learning to encourage a behavior change as new AI tools are introduced.

“When done well, organizations see better return on AI investment, improved productivity, and more confident decision‑making,” says Bishenden. “Employees gain clarity and agency, understanding how AI augments their expertise rather than replaces it. Ultimately, AI success isn’t determined by the technology alone, but by the capability of the workforce using it.” 

4. Put the human in the loop

Ankur Anand, group CIO at recruiter Harvey Nash, says AI training is often a work in progress, with his firm’s research suggesting one in five technologists are expected to self-learn. “There’s a rush to deliver the tools, but then organizations aren’t investing enough in enabling the capability of the people,” he says.

While technological skills like prompt engineering are an important part of AI learning and development, Anand said the best programs go beyond IT expertise to ensure humans in the loop have thorough understanding of their responsibilities.

“There are so many softer elements that need to be handled as part of AI training,” says Anand. “Good training is about using the tool as well as the governance and risk frameworks that need to be changed accordingly.”

5. Showcase individual successes

Louise Newbury-Smith, head of UK&I at Zoom, says it has AI enablement teams at the local and global level. And while the company provides courses and self-learning opportunities, Newbury-Smith says the enablement element brings AI training to life.

“Our approach is about showcasing individual successes, making it real, and repeating best practices,” she says. “We have what we call a Cook Along session with our AI evangelists. We’ll do those sessions together a lot as a group, and that makes the process fun. If you’ve got champions who can share incredible successes, then that goes a long way.”

She says the key to success is sharing knowledge. “We’re very much focused on the human,” she adds. “All the services, content, and direction of AI is about how we can give humans time back so they can have more valuable interactions with other staff to empower them with the information they need.”

6. Focus on the finer details

Dan Cherowbrier, CTO at Formula E, the motorsport championship for electric cars, is another digital leader whose business focuses on enablement. The company has a dedicated AI engineer who helps employees exploit emerging technology.

“We’ve got an innovative culture and we weren’t short of ideas of what we could do with AI,” he says. “What we needed were the resources to get people going, get the technology tested, and get it out there.”

The AI enablement engineer works with other tech specialists in the company to ensure tools are deployed safely and securely. “We’re beefing up our data and AI team so we can help users across the business plug in and understand APIs, get access to data, run security checks, and then put AI into production,” he says.

7. Develop reusable skills

Murali Swaminathan, CTO at technology firm Freshworks, says there’s so much information about AI models that people can easily take the wrong direction without guidance.

“We’re trying to give our staff structured learning,” he says. “We understand they’re not all on the same page. Some are ahead of others so you need to provide knowledge that applies to their specific job roles.”

Swaminathan says senior managers discuss how to train people effectively, as AI experiences and capabilities vary considerably across business units. However, the chosen pathway to AI learning and deployment must suit the individual and the company.

“I had this challenge with my engineers,” he says. “Initially, we gave them four different tools. Everybody was using AI, but it was so inconsistent, and everyone was trying to do the same thing in different ways. So we’re now trying to build reusable skills. And that approach must be replicated for every job function.”

8. Learn by doing

Luke Gebb, head of global innovation at American Express, says the financial services firm has various training programs. Having seen AI education in different forms, he advocates for learning by doing, or as a second-best strategy, watching someone else use the technology.

“Hearing or reading about AI, or being presented with something where you’re not actually seeing it happen is not nearly as helpful,” he says. “The best thing is to get a homework assignment and try something.”

Gebb says this approach plays out regularly across the people working in his 120-strong innovation group. The team runs one-hour show-and-tell sessions where an employee demonstrates how they use AI tools in their everyday activities.

“Then they get a bunch of questions, they post their best-practice lessons, and then others try the same thing. It’s an approach that works really well.”

9. Use pioneering techniques

Stephen Wood, COO at Rathbones Asset Management, says AI training in his organization is mandatory. “We want everyone to be versed in different types of AI,” he says. “We’re not expecting everyone to be a coding genius and an expert in all this stuff, but everyone needs to understand it.”

The firm takes a proactive approach to training, using education sessions and spreading best practices via digital champions. The company also embraces pioneering techniques, including running a hackathon to help identify in-house capabilities.

“The hackathon showed that with some searching on Google and YouTube, you could start to create agents that could do basic functions,” he says. “That process taught us, with the right training, and repeated sessions and continuous development, we wouldn’t necessarily need to hire people to create big productivity gains. That was quite an exciting moment.”

10. Evaluate new possibilities

Emerging technology can’t exist in a vacuum. Bernhard Seiser, VP of digital, data, and IT at AOP Health, says anyone using AI must be aware of potential consequences. “It’s your responsibility to validate whether what you’ve created is correct,” he says.

Operating in a regulation-heavy industry means AI training is linked to data governance. “We leverage it in areas where compliance isn’t an issue,” he says. “For example, writing text, creating images, and so on. Certain things can be done.”

As new AI tools emerge, AOP Health will consider its options and develop a training program. “That approach could mean bringing in specialized tools for specific tasks,” says Seiser. “It’s part of my job, and part of my team’s job, to evaluate AI for each use case.”

What the CIO role will look like in 2029

CIOs have talked about enabling the business for years, but IT exec Monica Caldas expects the role will soon be about orchestrating how the business performs.

“Today, CIOs are helping organizations navigate technological, operational, and cultural transformation simultaneously,” says Caldas, global CIO for Liberty Mutual Insurance and a 2026 inductee into CIO.com’s CIO Hall of Fame. “By 2029, much of that foundation will be in place. The role will increasingly focus on orchestrating an intelligence-enabled enterprise, where AI is embedded into workflows, decision-making, and business operations. As intelligent systems take on more routine work, CIOs will spend more time shaping business strategy, workforce evolution, and new sources of competitive advantage.”

In the upcoming years, Caldas predicts, “the role becomes less about implementing technology and more about helping organizations reimagine how humans and intelligent systems work together to create value in the Intelligence Era.”

She adds, “We’re entering a period where AI is reshaping how decisions are made, how work gets done, and how organizations operate. Just as previous waves of technology changed how enterprises functioned, AI is creating new opportunities for CIOs to act as strategic business leaders and enterprise shapers — not simply technology operators.”

Anthony Moisant, CIO and CSO for Indeed, has a similar vision for the role’s future.

“The CIO is becoming the architect of the company’s operating system itself. The CIO is becoming the architect of how a business runs,” says Moisant, also a 2026 Hall of Fame inductee.

Kathy Kay, executive vice president and CIO for Principal Financial Group, describes the future of the CIO role in much the same way.

“Already I’m having to be even closer to the business and talking about how the business should run. I now have way more of those conversations than conversations about technology,” she says.

Longtime IT leaders are unlikely to be surprised by all this. Anyone who has been watching the profession for the past decade or so has seen the CIO role evolve to one focused more on business strategy than it had been. And those with 20-plus years in the profession have watched it truly transform, from a senior-level operations manager position focused on technical decisions to the influential C-suite executive role it is today.

Now, as organizations devise their three-year strategic plans, those same leaders expect more changes for the role, saying that CIOs in 2029 will not just enable how organizations do business, they will devise what they offer, what they do, and how they produce value.

“They will be business-value creators,” says Craig Stephenson, senior client partner and CIO/CTO practice leader at Korn Ferry, an executive search and organizational consulting firm. “CIOs will own not just tech transformation but business transformation, and they will be enterprise leaders driving that transformation at scale.”

‘This is a game changer’

Dani Brown, who retired July 31 after nearly six years as SVP and CIO of Whirlpool, sees that future for the CIO role, too.

“The CIO of the future is different,” says Brown, also a 2026 Hall of Fame inductee. “This is not just an incremental change; it’s a shift. This is a game changer.”

AI is driving much, if not all, of the shift in the CIO’s position, Brown says, because, more than any other technology in the past, AI is changing what business can offer and how they deliver those offerings.

“AI is reshaping business models and quite frankly entire industries,” she says. “So today, it’s not just about how you enable solutions to problems but how do you use AI to shift a business model or industry.”

Danielle Brown, SVP and CIO, Whirlpool Corporation

Danielle Brown, SVP and CIO, Whirlpool Corporation

Danielle Brown, former SVP and CIO, Whirlpool

That task of engineering a shift of the organization or the industry itself is a monumentally different task than reengineering a process and, as such, speaks to the shift, that “game changer,” that Brown predicts happening in the CIO role.

“CIOs will have to determine how they leverage technology to revolutionize how they engage with consumers, how they transform marketing and differentiate products and the company, how they deliver services, and how they use AI to change internal operations to deliver better margins for the company. With the implications of technology on business today being like it has never been before, CEOs want a business partner beside them who understands that,” Brown says.

She adds that many CIOs are already doing such work.

But Brown doesn’t expect these new CIO responsibilities will displace the responsibilities that traditionally fell under the CIO’s remit. They’ll still have to be technologists to understand how best to implement technologies for business advantage. CIOs will still be accountable for deploying and maintaining the IT environment. And, as is the case already, they’ll be measured on creating and running an IT department that enables the business, can respond to changing business needs, and can do so efficiently, effectively, and securely.

AI shifts how the CIO sits in the C-suite

Kay stresses that CIOs, too, must adopt AI for their IT operations to ensure success in the future.

That, though, speaks to other ways the CIO role is changing.

As CIOs advise their colleagues on the use of AI and reengineer their organization’s services, products, and workflows, they’re also going to have to help the organization adjust to working side by side with autonomous AI agents, Kay says.

Kathy Kay

Kathy Kay, EVP and CIO, Principal Financial Group

Kathy Kay / Principal Financial Group

CIOs will also have to leverage their understanding of AI as technologists to share how AI reshapes the market, she says.

Kay says she’s already doing that. For example, she has brought AI’s implications on medicine to the attention of her colleagues, explaining how AI is expected to bring better medicines to market, which will likely mean longer life expectancy that in turn could impact her company’s products and services.

“As a CIO, I’m now asking, ‘If this happens, does our business strategy still hold?’ We haven’t seen the CIO play this role in the past. Now we’re the ones to say, ‘We need to pay attention to this,’” says Kay, another 2026 CIO Hall of Fame inductee.

That requires someone who has the courage to challenge existing strategies and colleagues on their stances, she says. And it requires someone who is “OK pushing them to have those conversations.”

For some, the future is already here

As Moisant sees it, leading-edge CIOs are already living that future.

“More and more today it’s the expectation for CIOs to be thinking about the total system, how the organization runs end to end, and becoming more of an architect of that total system,” he says. “That has already become an expectation for some in the field.”

And it’s going to become more common in the upcoming years, he adds, with the majority of CIOs having to meet those expectations in the future.

Anthony Moisant

Anthony Moisant, CIO and CSO, Indeed

Anthony Moisant / Indeed

Caldas’ vision is similar. She sees the CIO’s responsibilities centering on three areas as AI becomes embedded in how work gets done.

To start, CIOs will have to ensure “the organization has the right foundations, including trusted data, resilient platforms, cybersecurity, governance, and responsible AI practices to operate at scale. Those fundamentals won’t go away; if anything, they become more important,” she says.

They’ll have to help “the organization rethink how intelligent systems, people, and business processes work together. The opportunity is no longer just automation; it’s unlocking human potential and enabling employees to focus their energy on higher-value work while intelligent systems take on more routine tasks.”

And third, they will help shape business strategy and competitive advantage. “As technology becomes increasingly inseparable from the business, CIOs will play a larger role in identifying new opportunities, accelerating decision-making, and helping their organizations continuously adapt and reinvent how work gets done.”

The skills necessary to succeed

If all that sounds exceptionally challenging, that’s because it is, says David Ulicne, executive director of executive education at Carnegie Mellon University’s Heinz College of Information Systems and Public Policy.

“It’s a tough job to be a CIO, especially now that we are in the agentic era. The expectations are overwhelming,” he says. To meet the demands of the role now and in the future, “CIOs have to in some ways reinvent themselves again.”

Technical, strategic thinking, leadership, influence, financial management, and communication skills all need to be top-notch in CIOs if they want to succeed, he explains, as do people management and change management skills to help employees adjust to a workplace that will be staffed with both agents and humans.

Caldas likewise says future CIOs will need a different mix of skills, some familiar and others new to the position.

Monica Caldas, EVP and global CIO, Liberty Mutual stylized

Monica Caldas, EVP and global CIO, Liberty Mutual

Liberty Mutual

“I believe the most successful CIOs will combine technical fluency with business leadership and human-centered change management,” she says.

She lists as key skills:

  • Continual curiosity: CIOs will need to be continuous learners, with the ability to experiment, learn, and iterate quickly.
  • Value-informed decision-making: CIOs will need to be able to distinguish between opportunities that create meaningful business value and those that simply create noise — and in many cases, do so quickly. “Knowing when to double down, when to pivot, and when to stop investing will become a critical skill.”
  • Business vision and fluency: CIOs will need to readily translate technology into business value — an ability already in demand today.
  • Human and organizational leadership: “As intelligent systems become more embedded in everyday work, the differentiator will be the ability to help people adapt, develop new skills, and work effectively alongside new technologies,” she says. “Success will depend as much on leadership, culture, and organizational change as it does on technology itself.”

With all that taken to be the CIO’s evolving remit, Caldas says she already finds herself acting as part technologist, part economist, and part communicator.

“As we move from the Digital Era into the Intelligence Era, the role is becoming less about technology itself and more about helping organizations understand what technological change means for strategy, investments, talent, operations, and competitive advantage,” Caldas says. “Creating clarity in moments of change becomes just as important as delivering technology itself.”

AI agent sprawl pressures CIOs to recalibrate governance

Every Friday, Bret Greenstein, CAIO at consulting firm West Monroe, holds a company-wide meeting to share what’s happened in AI over the past week. He also spotlights one employee at the firm who’s created their own AI agent from the ground up, which lives in the company’s internal AI store. Since the store launched in May, more than 200 employees across departments — many without any technical, engineering, or coding background — have created over 550 agents.

“About 15% of our firm builds all the time now,” Greenstein says. “That’s a huge population.”

Enabling employees to spin out their own agents has become popular at many firms. Staff have built hundreds of agents at software company Blackline, for instance, and Microsoft has deployed more than 500,000 internal agents to help employees streamline workflows. Gartner also anticipates that by 2028, global average Fortune 500 companies will have more than 150,000 agents.

Employees know the intricacies of their work, the biggest pain points, and time drainers, so they can build solutions that address those specific issues, according to Greenstein. It also creates enthusiasm, empowers employees, and fosters innovation among the workforce as they build from the ground up.

That said, there’s been a pivot over the last six months, says Michael Murphy, partner and AI practice lead at global management consulting firm Adaptovate. When agentic AI first came on the scene, companies went all in, pushing to build and agentify nearly anything they could. In recent months, however, the narrative has shifted to getting a handle on agent sprawl, assessing the value agents deliver, and keeping costs in check.

“We’re really at this interesting inflection point where clients are having to figure out if we built the right agents, and are they delivering the value we expected,” Murphy says.

Today, tech leaders face a three-way squeeze, says Tiago Azevedo, CIO at AI-powered low-code development platform OutSystems. From the workforce side, many employees ask for permission to use more AI, but the CFO says token usage is becoming too big an expense on the balance sheet, and the CEO wants to see innovation and results from workforces using AI agents.

“I think that’s the biggest challenge for a CIO,” Azevedo says. “Let people take advantage of the technology but in a way that’s cost-effective and actually brings ROI.”

Building in a controlled environment

Employees have built myriad tools to aid their daily workflows. Azevedo’s company launched an agent dubbed Signal Sam, which searches databases of prospective customers, and gives account executives information to pitch them. Murphy and Greenstein also mention finance departments using agents to scan and categorize invoices, HR conducting a first pass on résumé screenings via agents, legal teams utilizing a self-service agent for NDAs, and marketing employees building agents that pull and analyze data from CRMs. These tools are often created by non-technical employees who’ve never written a line of code.

With so many agents popping up, CIOs need a way to oversee them, and ensure they meet corporate standards but without choking innovation, Azevedo says.

He recommends role-based access controls embedded into tools and configured behind the scenes. “So we allow them to use, but in a way that’s governed and controlled, because that’s our duty to the organization,” he says.

Ivan Burazin, CEO and co-founder of open-source developer platform Daytona, advises CIOs to treat agents like employees. “You’re not going to bump into them in your local Starbucks,” he says, “but you give them tasks and they have access.”

So set up agents with specific credentials, like how an organization would grant access to a new hire, with a laptop locked down with organization security protocols, Burazin adds. He also recommends sandboxing, in which agents operate in isolated machines with scoped credentials and firewalls so the sandbox prevents agents from accessing corporate systems or data outside allowed perimeters.

Organizations could use an internal ticketing system as well where employees wanting to build agents request a new identity for them, Burazin says. That way, tech leaders maintain visibility and governance over new agents.

“If something goes haywire in audit logs tomorrow, you can see it’s that agent versus an actual human,” Burazin continues.

He acknowledges that giving employees what feels like free rein to build and run agents can induce stress for CIOs and CISOs. But if a company doesn’t proactively establish tools, employees are apt to privately build AI in the shadows. As long as agent development happens within established confines, it won’t create problems organization wide.

“If you just enforce the security posture that you would for humans, you’ll save yourself a lot of headaches,” Burazin says.

When creating the AI store, Greenstein started by certifying tools for chat, code, data analysis, and other tasks, and then trained employees and made the tools broadly available to use. That process created guardrails and an inherently secure building environment. It also allows tech leaders to continue to monitor prompts and activity.

Now, tech teams review what’s been built in the AI store and flag any agents that excel. If employees have built 10 project management tools, for example, the leader will tag what they deem the best one. That gives employees the option to use existing agents or build a separate version for themselves.

More agents, more tokens

Over the last three to six months, Azevedo has been hearing from customers that their biggest hurdle is agent sprawl and the increasing cost those agents bear due to token usage.

In mid-July, OpenAI published a guide around useful work per dollar, sharing how leaders can look at tasks completed, time saved, and decisions improved to determine if their AI investments are bearing fruit. In addition to using the guide, Murphy suggests comparing the labor time and cost to conduct a manual task against time saved by using an agent, including which type of model the agent requires.

A cheap flash model, for instance, could be easy to justify the cost. “If it’s a very expensive Opus or Fable level model, that’s going to be a lot more challenging of a cost equation,” Murphy says. He adds that making this comparison isn’t about replacing the workforce but swapping “knucklehead admin work” for more engaging, human-centric work. This change may also require some organizational restructuring, such as CIOs and HR leaders working more collaboratively to handle change management as job responsibilities shift. Without the workforce optimized to work with agents, organizations won’t see the promised ROI of use cases, Murphy says.

West Monroe also informs its employees on the costs of different models. Without knowledge about tokens and costs, many employees defaulted to the highest-end model for any tasks before understanding that models come with different price tags. “We started educating people on the various relative costs of different models, and they immediately adjusted behavior, and our cost dropped,” Greenstein says.

While strictly quantitative returns are one way to measure ROI, Greenstein also thinks about return in a qualitative sense. “What does speed get me?” he asks. If someone in the firm is able to follow up with a client in hours because of an agent’s assistance, rather than days or weeks without one, the client will be impressed, and the firm might win their business over a competitor.

“Tokens will cost money no matter what,” he says. “But if you maximize the return, it’ll far outweigh the cost.”

Inside TIAA’s massive IT transformation to fuel business growth

When Sastry Durvasula joined TIAA in early 2022, he saw an organization fighting against outdated legacy technologies and in need of a major IT refresh.

Since then, the financial services organization has completed two phases of a comprehensive transformation initiative called Technology Ecosystem Transformation, or TETRIS, leading to a huge reduction in tech debt and a major expansion of functionality for customers.

The ongoing project, anchored in cloud and AI technologies, started in 2023 with phase one that modernized the core technology stack with 10 new enterprise platforms. Phase two, launched in late 2024, went further by enabling 87 use cases across all major lines of the business.

The project, for example, allowed TIAA to launch its MyChoice Multi-Year Guaranteed Annuity product, and helped create the TIAA Gateway portal, an API-based suite that integrates with partners in retirement and wealth planning using industry standards.

TIAA Gateway took home a CIO 100 Award in 2025, and phase two received a CIO 100 Award in 2026.

Durvasula, TIAA’s chief operating officer, pitched the multimillion-dollar TETRIS project to the board as a three-pronged strategy, with empowering business growth, fueling innovation, and transforming the IT core as its key goals.

Not only did TETRIS need to modernize the company’s IT systems, decommission legacy processes, and automate other processes, but Durvasula pitched it as the way to expand the reach of TIAA’s products and move the company into the future.

“As you expect in a company of our size, we have problems of yesterday, today, and tomorrow being solved at the same time,” he says.

Focus on business use cases

As TETRIS moved into phase two, project leaders shifted their goals from pure technology modernization to business outcome-driven prioritization. So once phase one delivered needed IT platforms like a data cloud and design studio, TIAA pivoted toward enabling business use cases.

This business-first approach ensured continuing executive support and clear ROI at every key milestone, TIAA says.

In 2022, just before the project launched, more than 80% of TIAA’s IT workloads resided in fragmented, end-of-life platforms, which created operational risk, compromised security and resilience, and constrained its ability to innovate. Through TETRIS phase two, however, the organization has cut that tech debt nearly in half.

And consolidating 17 design systems also led to digital products looking and behaving differently, depending on the team that designed them, and accelerated product launches by 35%, enabled multi-lingual capabilities, and increased accessibility to more than 185,000 customers who don’t speak English.

In addition, TETRIS allowed TIAA to combine multiple middleware systems and data lakes, Durvasula says, and the organization moved mainframe applications and data center infrastructure to the cloud.

A giant leap forward

TETRIS has been a huge project, with the company saying it empowered TIAA to have one of the largest leapfrog moments in company history in its submission for the 2026 CIO 100 Award.

Despite the reported failure rates of large transformation projects — some estimates suggest up to 95% fail to meet their goals — TETRIS was essential to keep TIAA competitive and move it forward in the market, Durvasula says.

A big part of the project has been workflow modernization, he says, because TIAA were using some technologies and workflows that were decades old.

“There’s your classical platform and application rationalization, and then there’s your end-of-support, end-of-life stuff that should’ve been remediated long ago,” he says. “Some of the processes we have, because we’re such a large, old company, were designed when the internet just came along.”

Stick to the metrics

Two keys to pulling off such a large project are establishing metrics for success and transparency with leadership, Durvasula says. Project leaders set milestones to indicate when things went well, and they planned for bumps in the road so the TIAA board knew when setbacks happened.

“Not everything is as pretty as it sounds in an awards application, but the success measures we established with our board were based on both phases,” he says. “For the first one, we said we’d deliver enterprise-grade platforms and accomplish migration objectives, but not tied to any specific business objectives.”

Phase two metrics focused more on business objectives, and the project team kept the TIAA board updated as TETRIS moved forward. Setting realistic goals was important, he says, with the team determined not to overpromise results.

“Large programs have a range of objectives, and if you publish the outcomes you’re looking for, people start looking for them, especially stakeholders, the C-suite, and board,” he says. “You have to be honest about which metrics or KPIs you can deliver in the first and second year, and when you’ll start seeing real business scale and impact, which definitely won’t be that soon in a large program like this.”

Goals also need to be flexible, Durvasula says, so transparency with leadership sometimes means telling them the project needs to reset. “If something doesn’t go well, what’s the level of fungibility you have?” he says. “We pick this tool, but what if it doesn’t work? You need to have a plan B.”

So TIAA’s IT team is heavily focused on flexible systems, and what was contemporary three years ago is probably legacy now, especially thanks to AI.

The power of change management

Another big lesson from a project of this size is the need to focus on change management. Retiring old IT systems requires the organization to bring employees along on the journey and convince them the changes are for the better.

TIAA established a multi-disciplinary team to implement a change management program focusing on breaking down silos and setting common adoption goals across the organization and its lines of business. Stakeholder forms and a huge focus on continuous collaboration helped employees understand the need for the changes.

“It’s a big organizational change,” Durvasula says. “If you’re working on a legacy system, and you think at some point it’s going to be modernized, then you become a legacy talent, and won’t have a job.” But the right change management program can convince these employees they can upskill and bring value to the new systems.

“You can bring your functional knowledge of the business and learn new technical skills,” he says. “It’s a massive culture- and people-change initiative as much as tech initiative.”

TIAA’s change management efforts were also made easier because TETRIS happened at the same time as the recent AI boom and involved AI elements. So it wasn’t hard to convince employees they needed to improve their AI skills.

“Because of AI, everybody woke up to this new reality,” he says. “We rode that wave when transformation drove from a cultural and organizational change management point.”

How a new AI value framework and stakeholder focus keep Zoetis ahead of the pack

Most AI investment strategies fail not because the tool or platform underperforms, but because organizations didn’t clearly define what success looks like before they started building.

Through a new approach to measuring value, Zoetis chief digital and technology officer Keith Sarbaugh and his business partners have leveraged a value-driven framework to scale AI solutions across research, manufacturing, and customer experience. And they measure every investment against goals before, during, and after the deployment.

In addition, his team rolled out a model-agnostic gen AI platform now used by nearly 95% of employees, which turned early experimentation into enterprise-wide adoption. Sarbaugh’s current focus now is partnering with Zoetis’ CHRO to advance the $9 billion global company’s capabilities in managing organizational AI adoption.

How are you integrating AI into your growth plans at Zoetis?

We have an umbrella program we call AI@Zoetis, where we unify our AI work under an enterprise purview, which spans research and development, manufacturing, commercial operations, customer and colleague experience, and other business functions. We manage AI collectively to enable grassroots innovation.

For example, we made our generative AI platform available to everyone, so as many people as possible can experiment and innovate. Our colleagues have access to 10 different LLMs, and we’ve seen over 95% adoption rate among our user community, and more than 11,000 colleague-built agents.

One popular AI use case is helping colleagues build their own development plans. The agent guides a colleague through a conversational, coach-like experience to map out their career aspirations against Zoetis’ competency framework, which was key to its wide adoption. This idea came from people not in HR, illustrating the point that some of the best use cases come from our broader employee base.

What’s an AI use case that directly impacts customers?

We have millions of customer interactions across our channels. Our sales force is out talking to them, who are also in our digital platforms, and we receive thousands of calls through customer service. We’ve been using the industry standard Net Promoter Score (NPS) to measure customer loyalty and satisfaction, but NPS is a measure that can take longer to generate. Zoetis has accelerated our awareness of customer feedback into real-time listening, using AI to understand these customer interactions in a holistic way, and at a scale we couldn’t achieve before. NPS still matters for tracking long-term trends and maintaining a consistent industry benchmark. We simply use AI to listen, learn, and act quicker.

Our AI customer experience platform also lets us look across all our customer touchpoints like calls, emails, and websites in real time, immediately identify issues and insights, and then be smart about how we address them. We now have more than 10 times the feedback signals we had in the past. We see trends sooner and act faster, and as humans, we can’t do that without AI.

How are you deciding where to make your AI investments?

We use different lenses. One is AI for the masses, which is our generative AI platform for colleagues; second is our middle lens, where we drive value in a particular function; and the third is enterprise-wide transformation, the big bets that’ll fundamentally change our business. We don’t do many, but we do them in a smart way.

With the transformative investments, we focused on both our commercial business and R&D, which we knew had the highest probability of serious returns. We started with seven golden use cases and knew that if we hit on two or three, it would be a big deal. Of the original seven use cases, six of them exceeded their value target and went from PoC to scale.

Since those earlier days, we’ve broadened to include manufacturing and supply chain, and our enabling functions.

Overall, we didn’t go out of the gate looking for productivity gains. We thought about business transformation right from the start. Today, we’re scaling up those first-mover investments and continue to leverage our value-driven framework to identify more use cases.

Are you creating new value frameworks so you and the rest of the ELT are unified in your investment strategy?

We developed a business value realization framework, which isn’t as sophisticated as it sounds. Before we make a tech investment, we ask what category of benefit we expect to receive, whether it’s revenue uplift, cost reduction, productivity, or whatever. We predict what success will look like and how we’ll measure it. 

Because with AI, we’re trying to move fast. We put a value case together at this early stage and do a PoC, and if it hits its target, we update the value case and decide whether to scale. A key element of the framework is real-time measurement. Are we seeing what we wanted, and if not, how do we pivot for more value?

The speed of iteration and scaling decisions make AI investments unique, so we can’t use our traditional value frameworks for digital investments, generally. Measuring outcomes post-implementation has become even more important.

How is your CHRO partnership impacting AI value?

Our CHRO and I partner closely to ensure enterprise enablement. When driving new ways of working that impact your workforce, you need a comprehensive approach, clear communications, and genuine buy-in. Colleagues adopt faster when they help shape the change. We’re prioritizing our workforce strategy, understanding what AI means for jobs at Zoetis, identifying skills that matter most, and building a plan to upskill people.

Another focus area is organizational change management (OCM). We reviewed our first AI investments to learn from our mistakes, and one consistent theme was that we shortchanged OCM. We thought naively that what we build will be so compelling, adoption will just come. But we didn’t do the right communication and stakeholder management. We recognize our need to develop OCM as a core competency, so our CHRO and I are building an enterprise playbook for AI change.

What’s your pragmatic advice to other CIOs when it comes to OCM?

When you’re wrapped up in a change program, you know what’s coming, but no one else does. When you impact your entire workforce, you need a smart approach to stakeholder management and communications. Involving colleagues in the creation of something new will aid in adoption. Have a deliberate and intentional communications plan and cadence, and have the discipline and objectivity to measure and learn. Our first tries weren’t perfect, but we listened to feedback and pivoted, and those pivots drove further commitment.

Has your communication at the board level changed?

When I talk to my peers about their board conversations, half focus on risk and compliance, and the other half talk about transformation and revenue generation. I’m fortunate that our board cares about both and has great energy around generating revenue, and how AI will give us a competitive advantage. By managing risk and compliance, we can spend our time focusing on potential drug candidates and getting to market quicker. Our board conversation is both about enablement and compliance.

What advice would you give to tomorrow’s CIOs?

The role is now about orchestration, understanding the business, and realizing value from technology investments. If you want to work with the best technology and bleeding-edge innovation, you’ll get some of that as a CIO, but the focus is broader, centered much more on processes and complex business problems than ever.

My advice is if you love working with technology, you’ll get that as a CIO. If you love delivering meaningful outcomes for the business and the customers you serve, it’s a truly rewarding role, and you’ll be an even more successful CIO.

Ways CIOs can maintain control amid changes brought by AI

It took nine seconds for an AI agent to destroy PocketOS’s production database. At work on a routine task in April, the coding agent, a variant of Cursor running on Claude Opus 4.6, ran into a credential mismatch and decided to fix the problem by triggering an API token. Little did PocketOS founder Jer Crane know that its activation would also delete its production database. “Had we known,” Crane later wrote on X, “we would never have stored it.”

The consequences of the agent’s actions were immediately apparent. Not only were recent backups belonging to PocketOS’ infrastructure provider contained in the production database — the recoverable versions were at least three months old — but so were those belonging to its infrastructure provider, Railway, which at press time still couldn’t tell Crane whether full infrastructure-level recovery was possible. Crane couldn’t fathom why the agent did this. So he asked it.

What he got back was an apology, of sorts. “I guessed that deleting a staging volume via the API would be scoped to staging only,” the agent said. “I didn’t verify. I didn’t check if the volume ID was shared across environments. I didn’t read Railway’s documentation on how volumes work across environments before running a destructive command.”

Ignoring built-in safety guardrails is hardly unique to agents operating on Claude Opus 4.6. In July, a Brazilian software engineer claimed an agent powered by OpenAI’s GPT-5.6 Sol model also deleted his production database, while in February, a Meta AI security and safety researcher claimed she had to switch off her computer to prevent an experimental agent deleting her entire inbox.

It wasn’t meant to be like this. Agentic AI was intended to be the culmination of millions of hours of research and development in gen AI to perform hyper-qualified acts of pattern recognition in the real world, and truly live up to their labor-saving promise. Their apparent predilection for destruction, however, has revived multiple debates about exactly how they should be restrained, and who, ultimately, is responsible for doing so.

Ultimately, the answer is those who green-lit the offending system. But as the pace of AI development puts greater daylight between companies pressured to adopt it, and those very tools capable of wreaking havoc across their internal databases, are CIOs now out of their depth?

Setting the pace

There’s no question the emergence of gen AI has changed the CIO role. “A few years ago, most of my time went to infrastructure decisions, including what to build, what to buy, and how to sequence the roadmap,” says Mike Trkay, CIO at data analytics company FICO. “Now, a growing share goes to questions of trust, verifying that when AI writes code, makes recommendations, or acts on behalf of a system, those actions can be explained and traced back to someone accountable for them.”

So the CIO has become the enterprise’s technological organizer du jour. “AI is accelerating software development, decision automation, and organizational experimentation at a pace that can outstrip institutional coherence,” says Edosa Odaro, executive advisor for data and AI at consulting firm VDS Global. “As AI becomes embedded across every business function, CIOs are increasingly responsible for ensuring that technical capability, governance, data quality, cybersecurity, human capability, and business strategy continue to evolve together rather than fragment.”

Day to day, that’s led to an exponential change of pace. “Things have always been fast,” says Zach Lewis, CIO and CISO of the University of Health Sciences and Pharmacy in St. Louis. “But now that speed of change is quicker, and you have to adapt.” And the need to catch up is constant. There’s no other option because then any competitor or co-collaborator can jump ahead, adds Lewis.

The rapid pace of change in AI also threatens to diminish the authority of individual CIOs who fail to keep up or set effective guardrails on those individuals who like to experiment with the newest models with loose regard for corporate security. “There’s all these AI tools that employees can now just go out and adopt,” says Lewis. And at the moment, a paid subscription to Claude or ChatGPT isn’t required to capitalize on its abilities. Consequently, staff are just a click away from asking LLMs to perform various tasks and expose sensitive corporate information in the process. “Everyone wants to play with the new thing,” he says. “And when they find benefit there, they’re going to want to bring it to their work lives.”

Agentic AI poses an entirely new set of problems. For one thing, says Odaro, the next phase of application adoption will be defined less by the capabilities of individual models, and more on what you allow their agents to do. “As AI becomes increasingly capable of generating software, coordinating workflows, and making recommendations across functions,” he says, “the challenge shifts from building AI to continuously governing evolving AI systems.”

This, Odaro continues, means that the CIO’s current approach to governance isn’t sustainable. “Static policies, annual reviews, and isolated oversight will struggle to keep pace with dynamic AI environments,” he says. “CIOs will increasingly need continuous governance capabilities that provide ongoing visibility into AI performance, value creation, risk, trust, and organizational adoption.”

Falling over the guardrails

How, then, should CIOs approach writing these new guardrails? Traditionally, this would be perfect fodder for so-called alignment researchers investigating how to instil a sense of morality and propriety into agents. According to analysts at Google DeepMind, however, it’s best to assume the agent will always be a potentially chaotic force within the company, and set parameters on its conduct from there.

“We borrow a lot from security, which already deals with the threat of internal employees who might be malicious, and we can apply these to a new setting,” Rohin Shah, Google DeepMind’s AGI safety and alignment team lead, told Fortunein June. Even so, he added, “AI is systematically different from humans.”

That difference primarily pertains to authority and speed. For agentic AI to live up to its full potential, it requires the freedom to access multiple systems simultaneously — an uncomfortable fact for CIOs hoping to align agent responsibility across the enterprise. In a time when workflows are becoming ever-more automated, however, that aspiration may prove unrealistic. In that case, Google DeepMind theorises that yet another monitoring layer for agentic AI may be required to make sure these free-roaming agents don’t cause too much trouble.

If that sounds daunting, you’re not alone. According to recent research by Gartner, up to 40% of enterprises using agentic AI will either demote or decommission these applications because their guardrails have proven inadequate. Preventing this, the research organization advises companies will need to adopt a graded approach to access, with autonomy for AI agents governed by the level of authority actually determined by the task they’ve been assigned.

Trkay is doing something similar at FICO. “Rather than chase every new model or capability, I focus control on the decisioning layer beneath it,” he says. “That includes the rules for what data AI can access, what it can act on autonomously, and where a human must sign off.”

All this, he adds, is defined from the start by a cross-functional governance committee, clear RACI ownership across standards and monitoring for the application, and a platform approach that enforces responsible AI usage. “Built well, that layer doesn’t need to be rebuilt every time the technology shifts,” says Trkay. “New capabilities plug into an existing structure of accountability, which is the difference between reacting to AI and running it.”

For his part, Trkay is skeptical that rigid guardrails can effectively restrain agentic AI from its most destructive impulses. “They tend to get worked around, either because they slow teams down or they’re too inflexible for legitimate edge cases,” he says. Effective guardrails for agentic AI, he adds, have to be specific enough to be meaningful, and adaptable enough to hold up as use cases multiply, backed by strong architecture, testing, and ongoing monitoring. “The one non-negotiable is the audit trail,” he says. “Whatever autonomy a system has, we need a record of what it did, and why.”

Staying grounded

For CIOs who don’t relish the challenge of setting obstacles and passing points for AI agents scurrying through their maze of networks, there’s always the option of delaying the inevitable by not immediately deploying such applications. Some might not even have the choice, at least for now. “We’re seeing the cost of tokens go up with those new models, because they’re expensive to run,” says Lewis. “But as new models come out, we’re going to see that decrease for some of those older models that were good.”

There is time, then, for CIOs to learn how to keep their head above the torrent of ever more new and powerful agentic AI applications. Whether they’ll be capable of doing so when the next great innovation is sold by Silicon Valley is an open question. Colin Constable, CTO of software development firm Atsign, styles himself as an internet optimist. Even he, however, is dismayed by the decreasing number of junior developers succeeding their more senior counterparts as they retire. That’s a big problem when so many of the former are relying on AI to assist them at work.

“We hand over lots of these decisions to LLMs without making good architectural choices,” says Constable. “If you haven’t been burnt by these things in the past, how would you know the difference?”

For their part, Constable and his colleagues get around this problem with a combination of AI-on-AI oversight of code quality, maintenance of constant dialogue within the team about new coding quandaries, and letting senior developers teach junior counterparts about some of the more avoidable mistakes in their profession. It’s a way of adapting to AI acceleration that points, unequivocally, toward CIOs diffusing responsibility for deeply educating the business about the technology. And if they continue to get it wrong, at least the agent will apologize.

How to level up from IT management to IT leadership

Oliver Galicki no longer needs to envision what it would be like to ascend to the CIO role. He’s just landed one.

On Aug. 10, Galicki transitioned from VP of clinical applications and engineering at Memorial Hermann Health System to become deputy CIO and VP of applications at Medstar Health System. He attributes his new job to having cultivated a combination of technical and soft skills over the course of his career.

“The foundation of understanding technology and having done some hands-on work earlier in my career has helped me be able to ask the right questions and help drive the right business value and outcomes for our clinical operators,” Galicki says. “But in the second half of my career, it’s been more around the soft skills; the relationship building, the creation of trust. How do you solve problems for the organization that takes it to the next level.”

That combination is essential for IT leaders today, says Peter Birch, director of technology and digital executive search at Harvey Nash.

Stand-out candidates for C-suite tech exec roles must have “a deep and broad track record of driving change and transformation underpinned by innovative tech-based solutions,” Birch says. “These leaders are also required to be highly commercial operators, able to master corporate engagement, and speak the language of the board.”

Moreover, climbing the IT leadership ladder requires demonstrating “the value return they can bring to the CIO role for the wider business enterprise,” he adds.

That means taking on big initiatives, learning from mistakes, developing business acumen, and finding strong mentors along the way.

Here, Galicki and recipients of CIO.com’s inaugural Next CIO Awards discuss what it takes to level up from mid-level IT management to senior IT leadership positions today.

Leading with business acumen

Trista Huang says that what has helped her stand out from the “majority of technologists” is her business acumen and her drive learn more.

“I always have taken extra certificate courses in the field that I worked on,” she says.

After receiving an undergraduate marketing degree and then an MBA, Huang’s career trajectory was more business-focused, with stints as a business analyst, portfolio manager, and project manager.

portrait of Trista Huang

Trista Huang, VP of technology and analytics, Blackstone Real Estate Hotels and Resorts

BRE Hotels and Resorts

Along the way, however, Huang “learned my way into the technical side” by taking programming classes at New York University and getting certifications in project management, as well as agile and waterfall methodologies.

Now vice president of technology and analytics at Blackstone Real Estate Hotels and Resorts, Huang aspires to become a CIO change-maker.

“I want to show the business and help the business to generate competitive advantage to create something that business couldn’t do before, leveraging technology and leveraging data,” she says.

Huang attributes her rise in leadership in part to her ability to communicate.

“You don’t dive down to nitty-gritty details — or you dive into the very nitty-gritty details — but tailor your answer to the audience and you never, never sound condescending,” she says.

Tone is important, Huang adds, as is using laymen’s terms and giving straightforward answers, “not running people in circles. That is also important as you rise to a leadership level.”

So is gaining a deep understanding of the business. Here is where Huang’s experience on the business side has paid off, as most technologists who rely heavily on their business counterparts for guidance have to wait for those business colleagues to tell them what to do.

“You can’t think outside the box if you don’t know the business,” she says, advising aspiring leaders to emphasize team building and empathy as well. “That takes soft skills — how you talk to people, get buy in.”

The strategic impact of technical experience

Jerry Imsand has taken a more technical route to IT leadership.

With more than three decades in IT, Imsand’s experience spans infrastructure, cybersecurity, identity and access management, enterprise architecture, master data management, business intelligence, digital services, and now AI.

That broad technical resume gives him a unique perspective on how interconnected IT systems can advance the organizational mission.

portrait of Jerry Imsand

Jerry Imsand, deputy CTO, Tennessee Department of Finance and Administration Strategic Technology Solutions

Tennessee Department of Finance and Administration

“Throughout my career, I have intentionally sought opportunities to understand not just the technology itself, but how technology enables business and government to better serve people,” says Imsand, deputy CTO for the Tennessee Department of Finance and Administration Strategic Technology Solutions.

“My career has evolved from being deeply technical to leading organizations where strategy, innovation, and developing people are every bit as important as the technology itself,” he adds.

Imsand aspires to be a CTO or CIO due to the opportunity those roles have to shape organizational strategy, build high-performing teams, and ensure technology investments create measurable value for citizens, customers, and the organization.

Having a just-do-it attitude

Kari Johnson, deputy CIO and chief data and analytics officer for the City of Scottsdale, Ariz., has worked in IT for about 20 years — since before it was called IT, she says.

Her early career focused on data and systems, and eventually, Johnson went back to school to get a bachelor’s degree in computer science.

Consulting work enabled her to become involved in all aspects of the business — from setting up email systems to ordering and installing fiber.

portrait of Kari Johnson

Kari Johnson, deputy CIO and CDAO, City of Scottsdale

City of Scottsdale

“I would see things and say, ‘We could improve this, add more people, make something more enterprise,’” Johnson recalls, adding that this problem-solving capacity and curiosity have been vital to her career.

“I’m a just-do-it kind of person. If I see something that can be improved or improves the life of someone else … I make it a point to learn about it and see what I can do to help improve it,” she says.

Johnson wants to keep moving up the leadership ladder, but she doesn’t necessarily tie fulfillment and value to titles. “I just keep aspiring to be that leader that brings other people along, because someone brought me along,” she says.

Taking big swings — and learning from mistakes

For most ascending IT professionals, the stretch assignment marks a rite of passage. Moving up from mid-level IT management to IT leadership is often accompanied by a big (potentially make or break) project to lead and learn from. Galicki, this involved being tasked with taking on the $400 million-plus implementation of Memorial Hermann’s Epic electronic health records system. It was a two-year project with a team of roughly 350 to 400 IT people.

In hindsight, there were things he would have done differently, Galicki says.

“We could have a done a more timely job [of] deployment,” he notes.

portrait of Oliver Galicki

Oliver Galicki, deputy CIO and VP of applications, Medstar Health System

Medstar Health System

IT added 9,000 mobile devices and rolled out the Epic system the same day. That created “a very confused end-user nurse experience.”

“I’ve looked back on that and thought, ‘Man, that should not have been our biggest distraction on day one of our big go live,’” he says.

Galicki also gained greater perspective as a result of the experience.

“What I’ve learned is you have to take a step back. You have to remember that a health system is never doing just one thing — even if it’s the biggest objective,” he says. “Step back and put yourself in the perspective of end-users that you’re bringing change to.” Echoing Huang, Galicki says empathy is essential because every tech project brings a layer of change.

For Imsand, focusing on building the right technical solution has also taught him the importance of ensuring everyone understands why the intended change matters.

“I learned that even the best technology can struggle if stakeholders are not engaged early and often,” he says. “Today, I spend considerably more time communicating the vision, listening to concerns, building alignment, and creating ownership before implementation begins.”

Imsand has also learned that not every opportunity needs to be pursued immediately.

“Prioritization is just as important as innovation,” he stresses. “Some of the best leadership decisions involve knowing what not to do so the organization can focus its time, resources, and energy on what creates the greatest value.”

As for her learning experiences, Huang points to failed projects that didn’t make it to production.

Most mistakes were made by “overly trusting the information people gave on timelines,” she says, as well as not fully understanding why certain milestones hit delays and giving stakeholders too much confidence that a team would be able to conquer a roadblock.

“I could have dived deeper,” she admits, noting that not taking the extra step caused delays that had domino effects.

Finding great mentors

Often, IT managers don’t get to where they are on their own. Galicki attributes his rise in leadership to having great mentors along the way.

“You don’t grow in leadership in general, but certainly in the IT world within a health system, without learning why decisions were made, how to lead, how to work within the organization, and I think IT leadership is no different,” he says. “You’ve got to go out and build trust from that.”

Learning from mentors is critical, but so is building alignment with the end-users, Galicki adds.

Huang agrees, saying her mentor is her CTO and boss Amol Kale.

“He’s a very big part of my growing journey,” she says. “He has given me lot of tips on how to manage down and being a good manager.” Learning how to manage down is equally important to managing up, Huang notes.

Kale has also made Huang aware of her tone of voice. Noting that she is a New Yorker who talks fast, Huang says Kale often tells her to slow down. Sometimes, Huang says, she doesn’t recognize that “my tone can come across as a little harsh, a little too fast.”

Feedback like that can be vital — and sometimes hard to come by. Huang and others advise aspiring IT leaders to seek that out by first building trust.

“Definitely someone that you trust and you constantly get feedback from is very important,” she says.

How to rise from IT manager to IT leadership

Candidates for IT leadership roles generally spend between five and 10 years operating in a director-level capacity, perhaps reporting to a CIO, Harvey Nash’s Birch notes.

“If the candidate has the drive, broad technology understanding, commercial expertise, and the ability to inspire and lead diverse groups of professionals, then they may well be approached for their first C-suite position,” he says. “Perhaps they would move from being a direct report of a global CIO in a large corporate, complex business to being a CIO themselves.”

While many organizations focus on succession management to ensure that when their CXO departs there is someone ready to step into the role for a seamless transition, internal promotion is not always appropriate, Birch notes. “Often, with a change at the board level or across the C-suite, there is an appetite to bring in alternative technology leadership who can deliver new ideas and ways of doing things.”

Regardless, there are measures IT managers can take to make themselves more visible and valuable. Huang and Imsand both advise building relationships across the organization, not just within IT.

“Spend time forming human connections. That goes a long way. Technology, you can always learn online — we forget the human connection,” Huang says. “Show genuine interest in other people; that’s the best way to form connections. People like to talk about themselves. That’s how you learn.”

Galicki is a firm believer in getting outside of IT to learn more about the changes and problems businesspeople are trying to solve.

“If you sit behind a desk,” he says, “you’re losing out on at least half the picture of what we do day to day.” He also advises asking questions. “The more you ask about the business of healthcare, the more you can support” business units. “Don’t be an order taker.”

Also, Imsand advises against defining yourself by your current job title. Like Johnson, he says you should become known as someone who consistently solves organizational problems.

“Develop expertise beyond technology,” Imsand adds. “Learn how budgets are built, understand procurement, governance, risk management, and business strategy.”

Johnson recommends doing the job you aspire to — with executive buy-in. She also stresses not to dwell on mistakes. “We all mess up every day up to highest level, and if you don’t put yourself out there, you’re not going to go anywhere,” she says.

Imsand also believes it’s worth investing in your communication skills. “Senior leaders spend far more time explaining, influencing, mentoring, and aligning people than configuring technology.”

And IT managers should invest in developing others, he says.

“As your career progresses, your success becomes less about what you accomplish personally and more about what your team accomplishes because of your leadership,” Imsand explains.

What leadership is really about

Johnson has a more philosophical perspective on what it takes to become a leader.

“Leadership isn’t your title or job assignments, it’s what you do to bring other people on board and move mountains to get things done,” she says. “The best leaders I’ve known … it’s literally the essence of who they are.”

Even as she doesn’t emphasize job titles, Johnson admits that when the right opportunity comes along, she wants to become a CIO. But she believes there is more room in the C-suite for other tech executives — and she wouldn’t mind a title with AI in it.

“I think we’re going to end up realizing at the CIO level there is another job of that same C-suite level that is enterprise data and CIO,” since the CIO can’t do everything, Johnson says. “There’s all the data and infrastructure to take care of and more of the business.” That might leave room for an equitable C-level position that’s concentrated on data and AI, she says.

“Maybe we stop calling things ‘data’ and ‘AI’ and we start calling that enterprise information,” Johnson muses. “Maybe I will invent another title for myself.”

See also:

Where IT leaders find strength and opportunity in the age of AI

With vision comes perspective, and over a distinguished career, IT and digital transformation leader Niraj Bhatt has held may titles, and earned three consecutive CIO 100 awards since 2023.

As a storied advisor for startups and Fortune 500 companies, helping them navigate the unpredictability and fluidity of AI, Bhatt knows how emerging tech is rapidly reshaping the way organizations build products and deliver value, and how challenges shift as companies move from experimentation to real-world deployment.

AI, of course means a lot of different things to different people, and also for frictionless startups and large enterprises. For the former, speed is a huge asset, allowing them to punch above their weight. But it also means they need lightning fast reactions when landscapes shift. “The same speed can also hurt them when larger AI companies release new offerings that disrupt what startups are building,” he says, referencing recent moves by Anthropic and Google.

On the enterprise side, the conversation is more about scale and risk. Many large organizations have moved past the POC stage and now wrestle with the realities of putting AI into production.

Cost for both is naturally a recurring theme as organizations scale up AI efforts, and true expenses become clear only after the initial excitement fades. “Every input and output token, and the model you’re selecting, add up,” he says. Some customers like Open AI, he adds, get throttled because their usage, volumes, and costs are growing so fast, making planning, observability, and monitoring critical for any team moving beyond experimentation.

So understanding the full software development lifecycle is also vital. Therefore, before committing to production, he helps clients see the big picture, and make sure they understand technical requirements as well as operational and financial implications. “The cost picture isn’t just about usage, but scale and the model choices teams make,” he says.

Bhatt also discusses effective approaches to AI and enterprise IT, technology leadership, and the evolving role of today’s CIOs. Watch the full video below for more insights, and be sure to subscribe to the monthly Center Stage newsletter by clicking here.

On AI hype: If you can’t explain something to someone who’s eight or 80, you don’t really understand it. It’s gone from LLMs, to RAG, to agentic AI, and now the essence is all about tokens. It’s predicting that next token and understanding that is key. So when LLMs came out, they were good at doing that on the data on which they were trained. When the enterprises looked at it, they wanted to make those LLMs work for their data. And the question became how to provide our data and context. It’s about building the right context for the LLM. Agentic AI is similar and that’s where the RAG evolution came in, in that I’ve got my data because every LLM has limitations in terms of how much context it can carry.

There are ranges of LLMs, where Google has the highest in regard to the context window size and what they support. Agentic AI is more action oriented, though. LLMs rely on the metadata you provide for the tools. Then they’re doing token prediction in that whatever I’m looking for, I should use a specific tool. Then it’s the infrastructure underlying which LLM it relies on to invoke the agent. So if you try to explain the microservices to a person, you’re going to struggle. But it’s very important to understand the evolution and that’s where you can cut through the hype. Understanding in this context is key.

On navigating challenges around talent: What I’m seeing on the IT side is there’s so much cognitive load, so how do we empower people to build solutions with the right mix of products and platforms? I think it’s about democratizing AI for the entire organization. Your talent strategy is everyone, all inclusive, starting from interns, the business and tech sides, CEO, everybody.Like your customer success or revenue officers, you need a talent strategy because in the end, IT alone isn’t going to be in a position to deliver for everyone in the organization.

AI has the potential to make everyone in the organization more productive. You have to plan that and facilitate broad innovation across the organization.That’s where the talent strategy, and working with HR and the people officer becomes very important providing those tools. One part of it is training, but how do I build an agent for a receptionist receiving calls, for instance?I’m not going to rely on vibe coding or things of that nature. But what are the tools? Where do I go, where do I host this? I think through that entire ecosystem beyond copilots. That’s where innovation can kick in, and that broader talent strategy is something I’m working with my customers on.

On collaboration: I heard a panel discussion recently, and a question was asked about what’s the number-one trait CIO needs to be successful at in the world of AI, and the answer was collaboration. You need to bring everybody together, move forward together, and make sure everybody’s on board. And in my mind, simplifying that is more like systems thinking when you operate, just bringing everybody along and ensuring they’re meeting outcomes.

But maybe what’s more important is managing expectations. Because if you’re a CIO, there’s a tremendous amount of pressure to deliver and have a rock solid AI strategy. So what I’m doing with my customers is get the board, CEO, and CFO into a room and help them understand what I’m talking about, the evolution, and what’s the art of possible. You don’t want to be a CIO who thinks I have a hammer and everything is a nail. Having buy in from the senior leaders is essential to know you’re headed in the right direction. You’re not reacting to pressure from top leadership, but driving and becoming the change agent for good for the company.

On navigating AI: It’s interesting times. I’m covering a spectrum of startups, non-technical and technical founders, and advising Fortune 500 companies. What I’m seeing is they love the velocity and momentum because that’s what they’ve always wanted, and AI is providing that. They’re able to bring their products to markets very quickly, so something that would’ve taken three years a couple of years ago is probably now taking them three months. There’s a lot of excitement there. But on the flip side, the same velocity is also hurting them. There are so many frontier AI companies getting disrupted. OpenAI, for instance, has offerings in sales and marketing, and Google has an interactive video model. So a lot of startups working in the marketing space are getting stuck. A lot of what I’m focused on is working with founders, helping them pivot in the gen AI space, ensuring their systems and products are built and structured in the right manner.

And on the enterprise space, what I’m seeing is the POC wave, and people have seen the value. There’s some excitement but now the struggle is getting them to production. That’s where you run into cost, latency, legal compliance, privacy issues, and customer concerns that if we get tickets to production, how’s it going to look and how are we going to scale. So engineering and product teams have to be ably supported by the enterprise architecture and R&D teams. I then help them get up to speed and build that internal platform product for the production workloads. It’s exciting times on both sides.

Why the CIO is becoming the most commercial role in the boardroom

My mum has asked me the same question for almost 30 years.

“So…what is it you actually do?”

I’ve explained it hundreds of times. I lead the team that look after the network, the servers, the applications and cyber security that help the business work. And more recently, AI. She’d smile politely, nod and then ask another question that made it painfully obvious she still thought I spent my day writing computer programs. My dad was a programmer, so in her mind I did the same thing, just in a nicer office. I never dared explain that it’s now called software engineering. Her head might explode.

The funny thing is, I don’t think she was the one struggling to understand the role. I think our industry is.

When I started my career, technology was largely a support function. We built systems, maintained infrastructure, kept the lights on and delivered projects. Success was measured by uptime, budgets and whether the latest implementation made it into production. Technology enabled the business, but it rarely shaped it. My job was largely about delivering technology successfully.

Today, every organization depends on technology to create value. Revenue growth relies on digital products and customer experience. Margin depends on automation, data and operational efficiency, while resilience depends on cyber security, recovery planning and the ability to respond when – not if – something goes wrong. Technology hasn’t simply become more important over the last thirty years; it has become part of the business itself. In many organizations it is impossible to separate commercial strategy from technology strategy because one simply cannot succeed without the other.

That is why I believe the role of the CIO has fundamentally changed. In fact, I’d argue it has quietly become one of the most commercial roles in the boardroom.

We all work in technology now

Over the past decade we’ve seen an explosion of technology leadership titles. CIOs, CTOs, Chief Digital Officers, Chief Data Officers, Chief AI Officers and Chief Transformation Officers have all emerged to solve different organizational challenges. Organizations have continued to reorganize their technology functions as digital, data and AI have become increasingly important, but I’ve gradually realized the titles themselves aren’t really the story.

Whether you’re responsible for technology, data, digital, cyber or AI, you’re ultimately trying to achieve the same outcome: helping the business deliver its strategy. Recent research from McKinsey’s Global Tech Agenda 2026 describes CIOs as becoming “strategy architects”, recognising that leading technology executives are increasingly shaping enterprise strategy rather than simply delivering it. The highest-performing organizations are no longer treating technology as a support function; they’re building business strategy around it.

That certainly reflects my own experience. The conversations I have with CEOs and boards rarely begin with technology. They begin with growth, profitability, customer experience, acquisitions, operational resilience and competitive advantage. Technology is simply one of the most powerful levers available to achieve those ambitions.

In fact, I genuinely believe we all work in technology now. The finance director relies on technology to improve forecasting and financial control. HR depends on it to attract and retain talent. Sales teams use it to understand customers and drive growth. Operations rely on automation and data to improve efficiency. Marketing depends on digital platforms to reach new audiences. Technology is no longer a department sitting alongside the business; it has become the operating system that underpins almost every commercial decision.

My job comes down to two questions

Over the years I’ve found myself simplifying my own role. Rather than thinking about the dozens of responsibilities that typically appear in a CIO job description, I’ve reduced everything to two questions.

  1. Is our technology strategy supporting the business strategy?
  2. Are we delivering it against the priorities that matter most?

Every major decision I make comes back to those two questions. Whether I’m reviewing investment, deciding whether to modernize a platform, introducing AI or discussing a major transformation programme with the board, the conversation always starts there. If the technology isn’t helping the organization achieve what it set out to achieve, then we’ve already lost sight of the objective.

I’ve also become increasingly ruthless about another simple test. If an initiative isn’t helping us grow revenue, improve margin or strengthen resilience, why are we doing it? That doesn’t mean every project needs an immediate financial return. Some investments reduce operational risk, others improve employee experience or prepare the organization for future growth, but every decision should ultimately contribute towards creating business value.

Somewhere along the way, I think many of us forgot that. We’ve become exceptionally good at discussing architectures, cloud platforms, AI models and technology roadmaps, yet the people sitting around the board table aren’t interested in technology for its own sake. They want better commercial outcomes. They want technology investments that help the organization grow, become more efficient or become more resilient. That’s what they should expect from us.

I sometimes hear people describe the CIO as the bridge between technology and the business. I understand the analogy, but I no longer think it’s true. There isn’t a bridge anymore because there aren’t two separate places to connect. Technology is woven into every part of the organization. As technology leaders, we’re no longer translating between IT and the business – we’re helping lead the business itself.

AI hasn’t changed the role. It’s exposed it

If there’s one topic dominating every boardroom conversation today, it’s AI. Every organization wants to understand how quickly it should adopt it, where it creates value and how to avoid falling behind competitors. Yet I don’t believe AI has fundamentally changed the role of the CIO. If anything, it has exposed what the role had already become.

The difficult part isn’t choosing the technology. It never has been. The difficult part is deciding where AI genuinely creates competitive advantage, where it introduces unnecessary risk and where it simply adds another layer of complexity. Cloud did the same thing. Mobile did. Digital transformation did. Every major technology wave promised transformation, and every one of them left organizations with technical debt, integration challenges, security risks and difficult investment decisions. AI is moving faster than anything we’ve seen before, but the leadership challenge remains remarkably familiar.

Gartner’s latest assessment of CIO priorities reflects this shift. The biggest challenges facing technology leaders today are scaling generative and agentic AI, optimising technology investment and defending organizations against increasingly sophisticated AI-driven cyber threats. Those aren’t purely technical challenges. They’re commercial decisions that require balancing opportunity, investment, risk and resilience.

The same message comes through in Microsoft’s 2026 Work Trend Index, which argues that every leader now has a responsibility to rethink how work is organized in an AI-enabled world. That isn’t simply about deploying another technology platform. It’s about redesigning operating models, helping people adapt and ensuring technology creates measurable business value rather than becoming another expensive experiment.

The future doesn’t belong to the most technical CIO. It belongs to the technology leader who understands how organizations create value, can influence commercial decisions, earn the confidence of the board and know when technology is the answer—and when it isn’t.

Which brings me back to my mum.

If she asked me today what I do, I think my answer would finally be much simpler.

I help organizations make better business decisions through technology.

Sometimes that means AI. Sometimes it means strengthening cyber resilience. Sometimes it’s simplifying an operating model, stopping a programme that no longer creates value or helping a leadership team make difficult investment decisions. The technology will continue to evolve, just as it always has, but the role itself has become remarkably consistent.

The best CIOs are no longer measured by the technology they deliver.

They’re measured by the commercial outcomes they create.

What the San Diego Padres CIO does to deliver major league IT experiences

Petco Park consistently ranks among MLB’s top ballparks for fan experience. That doesn’t happen by accident, and it didn’t wait for a star-studded roster or a deep postseason run.

According to Padres CIO Ray Chan, the club made a deliberate choice more than a decade ago to run its tech organization as if every seat were full and the team was playing in October every year. The philosophy was simple — build a World Series-level digital foundation so when the on-field product caught up, the elite fan experience would already be there.

More than a ballpark

Most people know Petco Park as the home of the San Diego Padres, which it is, but the venue was designed to be more than that. In a typical year, it hosts 81 regular-season home games, plus potential postseason contests, and then adds concerts and private events in renovated premium spaces.

By Chan’s count, that totals to nearly 400 annual events, often with more than one on the property in a single day. Different parts of the venue may host different audiences simultaneously, with IT expected to turn spaces quickly and support the unique digital requirements of each event.

The multi-use model puts a premium on flexibility and speed. Spaces are designed to be reconfigured quickly, and the underlying technology stack must adapt just as quick.

An always‑on network

When Chan arrived 15 seasons ago, Petco Park looked very different from a connectivity standpoint. On sellout nights, fans often couldn’t place a call or send a text once they were inside the building. There was no real concept of a digital fan journey.

The first major shift came with deploying a full-venue managed distributed antenna system (DAS) from Verizon, and an Extreme Networks Wi-Fi solution, providing fans, staff, and baseball operations with reliable connectivity throughout the ballpark. That network has since become the converged backbone for almost everything that happens at Petco, including digital ticket entry via the MLB Ballpark app, security and operations, tech like instant replay and dugout tablets used by coaches and players, and in‑venue IPTV and signage, all riding on the same IP infrastructure.

For fans, the network is invisible. For Chan’s team, it’s non‑negotiable. “None of this stuff works without the infrastructure in place,” he says.

Consolidated convenience

The Padres have leaned heavily into the league-standard MLB Ballpark app, which provides a consistent digital experience across all 30 venues, while allowing clubs to customize the local section. At Petco specifically, that app becomes the fan’s control center for digital ticketing, ballpark navigation, and a built-in payments and discount wallets tied to offers like Padres Pay and contactless options.

The result is a highly digitized journey, and for many fans, their first and last interaction with the ballpark occurs on their mobile device, and that’s by design.

Toward frictionlessness

Chan and his team are already looking beyond digital barcodes to facial-authentication-based entry, leveraging MLB’s Go Ahead Entry program rolling out at several parks. In that model, fans enroll once in the app with a selfie, then simply walk through a designated lane while overhead cameras verify identity and automatically scan tickets.

The promise is a hands-free, eyes-up experience where fans no longer need to take out their phones at the gate. Chan says this is the most frictionless way to enter a ballpark, and it even enables personalized greetings by name at the turnstile, another small but memorable touch to create a World Series-caliber experience.

Concessions are another example of how Petco’s IT modernization seamlessly enhances the fan journey. Petco is now a fully cashless venue, so fans pay with credit cards, mobile wallets, or the dedicated Padres Pay capability integrated into the Ballpark app. This reduces transaction friction, speeds lines, and improves security by minimizing cash handling.

IPTV everywhere

The expanding IP television footprint is another hallmark of Petco’s fan experience strategy. New screens throughout the venue serve multiple roles to ensure game coverage is never lost, even when fans leave their seats.

They also show real-time updates and wayfinding, an L-bar format that combines live video with adjacent ad inventory and informational content, and full-screen takeovers during concerts or special events, letting the venue transform its look and feel to match what’s happening on the field or stage.

Because it’s all IP-based, game-day operations and marketing teams can reskin the park on the fly, turning screens into a flexible engagement and monetization channel rather than relying on fixed signage.

Constant modernization

Despite opening in 2004, Petco Park doesn’t feel like a 22-year-old venue. Chan says that’s intentional and points to a continuous program of infrastructure upgrades and capital projects to redo suites, unify premium spaces such as the Western Metal rooftop and loft, and find areas to transform into new experiences.

Beneath those visible changes lies ongoing modernization of the network and systems in terms of upgrading switches, faster Wi-Fi, and backend platforms to support the latest apps and services. As Chan puts it, the goal is to make the park look and feel no older than a couple of years, which requires consistent ownership commitment and alignment between IT and operations.

Perhaps the most important part of Chan’s playbook, however, is cultural rather than technical. He describes the Padres as a listening organization that actively solicits and incorporates fan feedback to refine the experience across seasons.

That mindset is shaping the club’s approach to AI, so instead of chasing it for its own sake, Chan is focused on use cases that improve customer service by using chatbots or AI-assisted voice lines to free staff for higher-value interactions, and solve specific operational problems such as using AI to match lost-and-found queries with a database of found items.

The bigger IT picture

The way Petco Park manages its technology operations offers patterns that can apply beyond sports venues, starting with establishing a converged, resilient backbone. Connectivity is a shared utility layer that everything else depends on, rather than a series of isolated projects. That makes it easier to add new capabilities later without rearchitecting every time.

Chan’s philosophy of building as if every seat were filled also applies across all e-commerce peaks, clinical surges, and manufacturing seasonality. Capacity planning, observability, and failover should be set at Black Friday, not an average Tuesday. And treat your environment as a multiuse and continuously modernizing platform. Petco’s “more than a ballpark” mindset reflects the shift toward mixed-use destinations or campuses that blend learning and events, and offices that evolve into collaboration hubs that chip away at legacy infrastructure. IT leaders across sectors can apply the same rolling-renovation model to networks, identity, observability, and edge infrastructure, keeping technical debt manageable.

There are two completely different roles called ‘FDE’

There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different things depending on the business you’re running.

I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.

Figure: Nature of work vs. product leverage.

Kabir Sial

The product builder: The OG Palantir version

The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.

The platform operator: Solutions + technical customer success

The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.

Which FDE is right for you

Figure: Customer size.

Kabir Sial

For most situations, hiring product builder FDEs is a mistake.

At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.

Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.

There are, however, situations when your FDEs should be the product builder archetype.

1. You have very large customers (F500 scale)

Technical complexity: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.

Organizational inertia and trust: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.

2. You have many ICPs and workflows

If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.

Figure: "Overfit" products.

Kabir Sial

Note: see Palantir Foundry’s architecture here.

This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the Forward Deployed Software Engineer job profiles as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “Ontology”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.

Who you should hire

Figure: Who you hire.

Kabir Sial

Figure: Why hire one vs. the other.

Kabir Sial

Platform operator: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.

Product builder: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.

Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.

  1. Culture of building at the edge: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.
  2. Cult built around mission: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.

As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.

What FDEs should be doing (regardless of archetype)

You’ve hired the right people. How do you best leverage your team of FDEs?

FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.

  1. Find the most critical workflows: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.
  2. Build around nondeterminism: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases using evals and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.

❌