Visualização normal

Ontem — 8 de Setembro de 2026Security | CIO
  • ✇Security | CIO
  • After SAP settlement, Oracle draws EU antitrust attention over licensing practices
    Oracle has reportedly garnered some unwanted attention from the European Commission around its enterprise software licensing practices. The Commission’s antitrust regulators are currently gathering information from third parties about Oracle’s licensing practices to assess whether there is evidence to warrant further action, although it has yet to open a formal investigation into the company, MLex, an independent news outlet specializing in legal risk and regulation, repor
     

After SAP settlement, Oracle draws EU antitrust attention over licensing practices

8 de Setembro de 2026, 09:39

Oracle has reportedly garnered some unwanted attention from the European Commission around its enterprise software licensing practices.

The Commission’s antitrust regulators are currently gathering information from third parties about Oracle’s licensing practices to assess whether there is evidence to warrant further action, although it has yet to open a formal investigation into the company, MLex, an independent news outlet specializing in legal risk and regulation, reported.

The Commission, in response to an email inquiry, said that there is currently no formal investigation into any company but stressed that it would continue to monitor possible further anticompetitive practices and abusive conduct in the enterprise software sector.

Oracle did not immediately respond to an email query seeking comments on the issue.

The reported scrutiny into Oracle comes weeks after SAP agreed to binding commitments to address Commission concerns over practices that restricted customers’ ability to switch support providers or terminate certain contracts.

If the EU sees similar practices at Oracle, where licensing or support terms make it costly for enterprises to reduce dependency, switch providers, or change their usage, the regulators could potentially apply the same principle: vendor dominance cannot be used to artificially restrict customer choice in the aftermarket.

In that scenario, the Commission is likely to open an investigation or proceedings under the EU’s Article 102 rules, which prohibit companies with a dominant position in a defined market from engaging in any abusive conduct.

Impact on Oracle products

Several products and their attached licensing practices across Oracle’s portfolio are at risk of drawing more scrutiny from regulators, analysts say.

“Oracle Database is probably the biggest area. Its complex processor, virtualization, and cloud licensing rules can make it difficult for enterprises to know exactly what they owe. Regulators could examine whether these rules make running Oracle on competing clouds or reducing Oracle usage unnecessarily expensive,” said Pareekh Jain, principal analyst at Pareekh Consulting.

Jain pointed out that Java too could attract regulators’ attention as Oracle’s subscription charges are based broadly on an enterprise’s employee strength rather than just Java users.

“For some enterprises, this has sharply increased costs. Regulators could examine whether this pricing approach is reasonable for a technology already deeply embedded in enterprises,” Jain noted.

Similarly, its on-premises ERP portfolio and CRM applications, which include Oracle E-Business Suite, PeopleSoft, JD Edwards EnterpriseOne, Siebel, and Hyperion, could also come under the Commission’s radar, mostly because the licenses of these products resemble practices that could present parallels with the concerns raised in the SAP case.

“Enterprise customers often run these products for decades and want third-party support rather than migration. Rules that make dropping Oracle support, reducing unused licenses or moving only part of the estate to another support provider expensive could attract scrutiny,” Jain said.

The analyst was referring to documentation around Oracle’s Software Technical Support Policies that generally require licenses within a license set to maintain the same level of technical support.

The policies also allow Oracle to reprice support for the remaining licenses when customers reduce their footprint and impose additional costs on reinstating lapsed support.

That policy document also covers a broad range of Oracle products beyond its ERP and CRM portfolio, including its database, middleware and infrastructure software, potentially widening the scope of products and licensing practices that could draw regulatory scrutiny.

A separate Oracle technical support policy for Exadata also contains similar provisions related to support levels, license reductions, and reinstating lapsed support.

What the possible EU scrutiny could mean for CIOs

That prospect of greater scrutiny by the Commission, especially in the wake of the SAP case, could be significant not just for Oracle but also for the enterprises that have built large parts of their IT estates around its software.

For enterprises, the most immediate benefit, according to Manoj Chandra Jha, principal analyst at Nord-IQ Research, would be more negotiating power.

“Expect CIOs and procurement teams to use the mere possibility of a Commission scrutiny to extract concessions in ongoing renewals long before any formal remedy is decided,” Jha said.

“Enterprises could push for greater freedom to drop unused licenses, use third-party support, reduce maintenance costs, or gradually move workloads away from Oracle without being punished financially,” echoed Jain.

That, in turn, could help CIOs reduce Oracle dependency step by step instead of going through a full migration that is bound to be expensive, Jain added.

However, for CIOs and enterprises without ongoing or upcoming Oracle renewals, Jha cautioned against expecting immediate cost relief or contractual flexibility based on the SAP precedent.

“This is likely to be a multi-year outcome, not a Q4 planning assumption,” he said.

Antes de ontemSecurity | CIO
  • ✇Security | CIO
  • Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?
    A few months ago, I was sitting in a glass-walled conference room with the executive team of a fast-growing enterprise. The vice president of customer operations was enthusiastically demonstrating the new automated agent features their software vendor had just pushed into their CRM platform. On the screen, the software looked brilliant. The agent could read customer complaints, analyze transaction histories and automatically resolve issues. The VP showed us how the syst
     

Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?

13 de Agosto de 2026, 08:00

A few months ago, I was sitting in a glass-walled conference room with the executive team of a fast-growing enterprise. The vice president of customer operations was enthusiastically demonstrating the new automated agent features their software vendor had just pushed into their CRM platform.

On the screen, the software looked brilliant. The agent could read customer complaints, analyze transaction histories and automatically resolve issues. The VP showed us how the system could independently offer retention incentives to unhappy accounts without a human ever touching a keyboard.

Then I asked a simple question: “What is your approval process when the AI decides to grant a $20,000 contract discount to keep a customer from leaving?”

The room went completely silent. The VP looked at the director of IT, the director of IT looked at the chief risk officer, and everyone realized the same thing at the exact same moment. They had spent three months evaluating software licenses and security protocols, but nobody had asked who gave the software permission to sign off on corporate spending.

Major software providers like Salesforce, SAP and Oracle are rapidly moving beyond simple report writers and conversational chatbots. They are embedding active, autonomous agents directly into the transactional core of systems that manage your revenue, customer agreements and financial ledgers. According to Gartner’s latest adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. These applications do not just summarize data: they issue refunds, alter contract terms and trigger supply chain orders.

When I review these deployments with client teams, the core problem has nothing to do with artificial intelligence. It is a fundamental breakdown in corporate delegation and signing authority.

The breakdown of the corporate signing matrix

Every mature company I work with operates on a clear delegation of authority matrix. This framework dictates exactly who can sign off on financial commitments. A vice president might have authorization to approve spending up to $500,000, a director might sit at $100,000 and a front-line manager might be capped at $500. For two decades, technology leaders have spent millions of dollars building security and compliance controls to ensure every human employee operates strictly within those limits.

Yet when a software vendor releases an update featuring autonomous agents, companies routinely grant these features unrestricted operational freedom. Because the capability arrives as a native feature inside an existing application, business units enable it with a single click. In my advisory work, I repeatedly see organizations grant third-party software features more financial freedom than their own human managers.

This represents a massive blind spot in executive governance. McKinsey’s global surveys on artificial intelligence reveal a striking pattern across the enterprise landscape: while adoption is accelerating at a historic pace, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.

The quiet cost of shadow delegation

In my audits, this rarely manifests as a dramatic system crash. It plays out as a quiet margin leak. In one organization I reviewed, a department head had enabled an automated customer retention feature over a weekend. The agent noticed an important account expressing frustration in a support ticket, and to prevent the account from churning, it independently applied an unapproved 15 percent discount to their multi-year contract.

The customer was happy, and the account manager considered the client saved. But from an executive perspective, an unvetted third-party algorithm just executed an unauthorized contract modification that eroded company margins. When the finance team conducted a quarterly audit, they did not discover an employee violating spending policy. They discovered a black-box automated decision that bypassed every internal approval control in the company.

When an auditor tests your internal controls, presenting a log showing that a vendor’s algorithm made an unauthorized financial change does not satisfy the requirement. If an action requires managerial sign-off when performed by a human being, letting software execute it independently is a major control failure.

How I advise executive teams to handle automated authority

Protecting your organization does not mean turning off these tools or falling behind on technology. It means treating vendor-supplied agents exactly like third-party contractors who have not yet passed a background check.

Forrester Research emphasizes that extending zero-trust security frameworks to automated business processes is now mandatory for enterprise risk management. Zero-trust simply means that no user, device or automated tool gets implicit trust. Every proposed action must be validated against explicit business rules before it happens.

When I help enterprise teams design these safeguards, we establish a practical three-tiered boundary for automated tools:

  • Read and draft permission: Automated tools can freely analyze trends, draft emails and assemble internal reports. No human sign-off is needed to create a draft, but the system cannot publish or execute anything on its own.
  • Standard administrative permission: Tools can handle routine administrative tasks or process standard requests below a strict financial cap (such as a $50 service credit), provided every single action is logged in an audit file that managers review weekly.
  • Restricted financial permission: Any action that alters contract terms, changes pricing tiers or issues major refunds are strictly held in an authorization queue. The system generates the request, but a human manager must click “approve” before the change hits the live database.

As a technology executive, you cannot control what automated features software providers bundle into their platforms. You can, however, control the financial boundaries and signing authority those tools are permitted to exercise within your business.

What to do at your next executive leadership meeting

  1. Ask for an automated authority inventory: Have your team audit your core software platforms to identify every automated feature currently running with permission to alter financial or customer records.
  2. Revert to draft-only mode: Instruct your team to default all vendor-supplied automated agents to “draft only” until a clear business case justifies giving them independent operational authority.
  3. Establish a firm human-in-the-loop rule: Require a strict organizational policy that no automated system can modify pricing, contracts or financial ledgers without explicit manager approval.

❌
❌