Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Security | CIO
  • The AI cybersecurity arms race is on
    Businesses received a staggering amount of cyberattacks in June, according to Check Point, showing a rise of 20% over the previous 12 months. The breakout of AI agents from OpenAI in July to hack into the Hugging Face website, and subsequent similar events from Anthropic and Meta, indicate agentic-powered attacks will explode over the coming year. Currently, malicious hackers have the advantage because publicly released frontier models from the US incorporate guardrails
     

The AI cybersecurity arms race is on

7 de Setembro de 2026, 07:00

Businesses received a staggering amount of cyberattacks in June, according to Check Point, showing a rise of 20% over the previous 12 months. The breakout of AI agents from OpenAI in July to hack into the Hugging Face website, and subsequent similar events from Anthropic and Meta, indicate agentic-powered attacks will explode over the coming year.

Currently, malicious hackers have the advantage because publicly released frontier models from the US incorporate guardrails that can’t distinguish between malicious or defensive activities. As a consequence, these models default to a refusal to get involved. Hugging Face discovered this the hard way when they attempted to utilize a model to defend against the OpenAI intrusion. Their solution was to adapt a Chinese open weight model to analyze the 17,000 attack logs, find the vulnerability, and contain the intrusion.

With incidents like these happening more often, an arms race has begun with AI being both the problem and the solution.

Strength in numbers

While single agents generally perform more efficiently for well-defined tasks, research from Stanford University indicates swarms are more effective in messy scenarios with noisy data, which are more typical of unpredictable, intrusion attacks. The increased token usage by swarms raises costs, but increasingly efficient open weight models are rapidly lowering these barriers.

In the Hugging Face example, the agents worked together as a team leaving messages for each other on a message board they improvised. They shared newly found vulnerabilities, exchanged tools, and even developed conventions to address one another and to avoid overwriting each other’s work. While this may seem sinister, they were only following their designated purpose: to achieve a goal without regard to any collateral damage. We can expect bad actors to harness the power of agentic swarms through fine-tuning open weight models, and creating agents that progressively learn from their experiences.

Modern warfare has been transformed over the last four years, too, through the deployment of drones by Ukraine to defend against Russian attacks. Military strategies and the deployment of armament budgets around the world are shifting to focus on new technologies, and approaches and enterprises are now facing a similar challenge from the hostile use of agentic AI.

The drawbridge is down

As enterprises build out their own agentic systems to handle ecommerce, customer service, and marketing activities, this presents new attack surfaces for antagonistic efforts. April 2026 research from Trend Micro found almost 1,500 MCP servers directly exposed to the internet had no authentication or encryption, a rise of 200% from nine months earlier. This included 70 hosts offering direct SQL execution, and servers holding medical records.

The automation of business processes and the reduction of humans from decision making chains open up new vulnerabilities for agents with malicious intent. Arkose Labs’ 2026 agentic AI survey of 300 enterprise leaders found 97% expected an AI agent security incident within the next 12 months.

Social engineering

While agents have demonstrated their ability to break through security systems, they’re also capable of targeting humans to achieve their objectives. Recent research from Verizon indicates that 62% of successful breaches involve a human element, with phone-based attacks 40% more successful than email-based ones. In August, for instance, scammers using an AI-generated deep fake of Australian Prime Minister Anthony Albanese’s voice were able to scam investors out of $5.3 million.

If agents can break out of digital sandboxes, and generate convincing fake videos and audio, then they’re certainly capable of making basic phone calls. In July, during testing of frontier models, the UK AI Security Institute discovered an agent tried to insert malicious code into an open-source project. Attempting to get the code approved, the agent created fake online identities using them to persuade the project’s maintainer to sign it off. “This is the first time we’ve seen risks around autonomy and deception manifest this clearly without specific prompting in the real-world,” the Institute put in a write-up of the incident.

Fight AI with AI

So attackers currently have the upper hand in this escalating arms race. They have access to agents that can work around the clock, constantly probing, learning, and sharing their knowledge with other agents. They’ll only get better at this and learn ways to stay ahead of defensive systems. International agreements to delay or restrict the capabilities of frontier models won’t stop hostile actors motivated by money or rogue states pursuing other objectives. Developers and security vendors need access to the latest frontier models unfettered by restrictive guardrails if we’re to stand any chance of defending against the coming tsunami of attacks.

We can learn a lesson from recent history on this front. In 1992, the US restricted exported software to weak 40-bit encryption, citing security concerns going back to the cold war. While the US allowed stronger encryption internally, the result was weakened security for everyone as hostile antagonists were able to disrupt global supply chains that incorporated less secure software. Despite lifting the ban in 1999, embedded software containing 40-bit encryption continued to cause problems for many years across multiple countries, including the US.

Without rapid action, we may look back fondly to the world before July 2026 as a golden age for cybersecurity, a relative age of innocence.

Antes de ontemStream principal
  • ✇Security | CIO
  • Why technically strong leaders still aren’t CIO-ready
    At CIO100 in Frisco, Texas, roughly 100 rising technology leaders sat down for our “Next CIO” session. The group was asked to reflect on a single question: Are you ready to take on the role of CIO? Using the CIO Readiness Framework that we have developed and refined over years of advisory work, we asked each person in the room to score themselves across the five dimensions of the framework. The results point to a gap that should worry any organization building its next
     

Why technically strong leaders still aren’t CIO-ready

4 de Setembro de 2026, 09:00

At CIO100 in Frisco, Texas, roughly 100 rising technology leaders sat down for our “Next CIO” session. The group was asked to reflect on a single question: Are you ready to take on the role of CIO? Using the CIO Readiness Framework that we have developed and refined over years of advisory work, we asked each person in the room to score themselves across the five dimensions of the framework. The results point to a gap that should worry any organization building its next generation of technology leaders.

The CIO Readiness Framework

The CIO Readiness Framework organizes the CIO job into five dimensions. We asked each rising leader to score themselves on the same 1-to-5 scale, from “Emerging” to “CIO-Ready.” The five dimensions of the framework are:

  • Enterprise leadership: the ability to lead beyond your own function, anticipate where the business is headed and mobilize people through change.
  • Business value and financial acumen: understanding how the enterprise makes money well enough to connect technology decisions to growth, margin and risk.
  • Influence, narrative and enterprise selling: building belief and support before a decision is ever formally proposed, not just presenting sound logic once it is. 
  • Relationships, talent and operating leverage: building trusted executive relationships, developing successors and creating an organization that delivers beyond your own personal reach.
  • Technology stewardship and digital judgment: the technical fluency and architectural judgment needed to make durable enterprise technology decisions.

Where the room stands

Across the five dimensions, the average self-assessment landed at 3.4 out of 5, squarely in ‘Proficient’ territory. Consider who was in the room: people already selected by their own organizations as ready to be developed for the next level. Even so, not one of the five dimensions averaged ‘Advanced’ or higher across the entire group. Technology Stewardship and Digital Judgment (the ability to make sound decisions on platforms, architecture and risk) came in as the most mature dimension in the room. At the bottom sat two dimensions in a near tie: Influence, Narrative and Enterprise Selling; and Relationships, Talent and Operating Leverage.

Much more interesting, however, is the spread between the highest- and lowest-rated dimensions. On these bottom two dimensions, ~65% of attendees rated themselves Proficient or below. Compare that to Technology Stewardship, where the number was only 36%. Put plainly, the people in that room are confident in their technical judgment. They are far less confident in the parts of the job that have nothing to do with technology at all.

Why the human dimensions lag, and what to do about it

This tracks with what we hear constantly in our advisory work. Most people who reach the doorstep of the CIO role got there by being excellent at the technical and operational core of IT. Few of them spent their first fifteen years being evaluated on stakeholder mapping, coalition-building, or developing a successor. Those muscles simply were not required until now.

The good news is that these are learnable skills. We recommend a simple approach to close these capability gaps: for the dimensions where you rated yourself lowest, identify a goal that targets your weaknesses, then attach a tactic (a concrete action or behavior) that moves you toward achieving your goal. Lastly, give the whole thing a timeframe. Six months is often a good starting point, as it is long enough to make real progress and short enough that you’ll actually check.

In this activity, the goal represents the destination – for example, to develop a brand of “enterprise leader,” rather than just “strong IT operator.” The tactic is how you get there, something specific enough that you’ll know in six months whether you did it or not. “Get better at influence” is a goal with no tactic attached, which is exactly why it rarely changes anything. “Hold pre-alignment conversations with three sponsors before my next major proposal” is a tactic, and it’s either done or it isn’t.

Here’s what that pairing looks like applied to the two lowest-scoring dimensions from the CIO100 room:

  • For Influence, narrative and enterprise selling, a reasonable goal is building support for ideas before they ever reach a formal decision point. Tactics in service of that goal include identifying the informal decision-makers behind a priority and earning their support early, or taking on an external opportunity (e.g., industry panels, published point of views) to build credibility beyond the building.
  • For Relationships, talent and operating leverage, a reasonable goal is creating executive capacity instead of personally absorbing more of the work. Tactics in service of that goal may include adding standing one-on-ones with two peers on the executive team, and delegating two recurring items off your own plate with clear decision rights attached.

The takeaway for CIOs building their bench

If you’re a sitting CIO developing your own successors, this data serves as a useful gut check. The people you’re grooming may already operate at an advanced level technically while carrying real gaps in the skills that determine whether they succeed once they have the title. Executive presence, coalition-building and delegation take years to build, so the earlier you start, the better.

The future leaders we worked with at CIO100 had no shortage of ability. What most of them lacked were the specific, practiced habits that turn a strong technology leader into an enterprise one, and the self-assessment data shows they already know it. Acknowledging that gap is the first step toward closing it.

  • ✇Security | CIO
  • Why Cisco is redefining its CIO role
    The CIO job description is being rewritten in real time. As AI agents take over the interface layer and connect directly to any data source, the skills that once defined great IT leadership — UX fluency, applications integration, build-versus-buy judgment — are giving way to an entirely different set of questions surrounding not how a process works, but whether it needs to exist at all. Thimaya Subaiya is living that shift firsthand. At Cisco, he oversees IT and says the i
     

Why Cisco is redefining its CIO role

2 de Setembro de 2026, 07:00

The CIO job description is being rewritten in real time. As AI agents take over the interface layer and connect directly to any data source, the skills that once defined great IT leadership — UX fluency, applications integration, build-versus-buy judgment — are giving way to an entirely different set of questions surrounding not how a process works, but whether it needs to exist at all.

Thimaya Subaiya is living that shift firsthand. At Cisco, he oversees IT and says the ideal CIO candidate today might not have a traditional IT background. Here, he explains why he split the company’s AI leadership out as its own function and why he’ll merge back in, what he’s really looking for in a CIO candidate, and why the Cisco CIO job is such a good one.

How would you describe your role at Cisco?

I lead operations for one of the world’s largest supply chains, as well as security and trust, including product security, internal systems, and data center security. I also lead the CIO organization and have revenue operations, partnership management, and accountability for our AI strategy. Two and a half years ago, I consolidated AI from throughout the company and named a CAIO. I then split out the role to give us a boost in the AI space, but eventually, the CAIO role will merge into IT.

How did you conceptualize the CAIO role?

At first, it was a leader who could pull use cases from all our operations and execute. The role also included the ethical use of AI systems, and prioritized what to guardrail and push out to employees.

But it’s evolved. To take a step back, Cisco pioneered enterprise networking, then built Compute with Cisco, Storage with Cisco, Networking with Cisco, Security with Cisco, and Observability with Cisco. Today, the CAIO is moving up the stack with an AI framework for MCP connectors, which has really moved us forward.

This CAIO group can tell the Cisco-on-Cisco story for AI, because we have a testbed for new ideas. If we continue to rely on multiple vendors, as in the past, we won’t be able to integrate at scale. This is why we isolated the CAIO role, to focus exclusively on AI governance and execution.

You’re in the middle of a CIO search. What are you observing about the CIO talent market?

With AI, the CIO role has completely changed. It’s no longer about UX and applications integration because with MCP, we can connect to any data source at any time, and agents have replaced the interface. The CIO role is now more about rethinking a process and then deploying an agent to execute, rather than reworking a process.

So the ideal CIO is a traditional one who’s learned to think differently, or even someone without a CIO background, but who’s led in product management, innovation, or transformation. The role today requires someone who’s been disruptive, and has had to rethink how a company operates, not just how its applications work.

Our top criteria are strategy, speed of execution, and the ability to scale because we’re not investing in science projects. For example, when the sales team requests a better forecasting tool, a CIO traditionally would make a build or buy decision. But in today’s world, the right question should be if you need a solution to forecast at all, or can an agent do it. Or better yet, do we even need this process?

So what’s the right background for today’s CIO?

Product managers have a relevant background because they manage multiple aspects of how a product comes together: user needs, business outcomes, fit in the market, and getting it built. This understanding of product strategy, marketing, and adoption is extremely important right now because we treat our AI initiatives like products. So a great path for our CIO is data scientist foundations, product management, and transformation.

What about enterprise security?

I treat enterprise security as a separate organization, which every company should do. Testing and evaluating new cyber solutions for frontier models requires a lot of work like scanning everything, taking a neutral view of what’s broken, deciding which tools become standard within development frameworks, which cryptography tools to use, and then maintenance. Abstracting that into its own organization creates focus. It also lets us move at the speed of AI.

When AI attacks, you need AI to defend you, and if security is embedded within the CIO organization, it’s not top of mind for the business. Security has become its own board-level conversation. For today’s CIO, I’d keep AI in but take security out.

A year after the CIO is in place, what will success look like?

Our applications footprint has been reduced, we’ve seen pure productivity gains from accelerating the back, and the speed of new releases is increased. The team is becoming more effective with the same resources, and we can say that our CIO drove us to leverage everything new technologies offer without blowing up on tokens. We’re looking for a new way to operate IT.

Why is the CIO job at Cisco a great opportunity for the CIO you’re describing?

It’s possibly the coolest job out there. We have an entire AI stack end-to-end that nobody else can claim because we bring networking and security together, complemented by observability and collaboration. That combination means we can create net-new solutions that define what technology looks like in the future.

On the security side, we’re one of the very few companies truly integrating AI into defense in a way that can be leveraged across a much broader market. That’s exciting, because it means free access to an entire stack that lets you innovate in ways the industry hasn’t seen before.

I call AI today’s generational technology. Every generation gets a technology that redefines how it operates, including the internet, iPhone, and now AI. Cisco is about to become the first company to launch a personalized AI agent for every employee, reachable through Webex. Think of it this way: the average person has an IQ of around 100. Now every employee is paired with an AI agent that can exponentially increase human capacity, built entirely on the technology available today.

Getting to build things like that, with no proven methodologies or limitations, and nothing but the question of how we get to the future, is the most exciting thing there is if you’re an innovative leader.

  • ✇Security | CIO
  • AI agents need to learn when enough is enough
    For the past few years, enterprise AI programs have focused on making models more useful, accurate, and autonomous. In that phase, a bad answer was still usually something a human could accept or reject before taking action. But once agents start invoking tools and acting inside business workflows, success should no longer be measured only by how much work they complete. A more important metric is how well an agent recognizes when it lacks the authority, context, or judgme
     

AI agents need to learn when enough is enough

2 de Setembro de 2026, 07:00

For the past few years, enterprise AI programs have focused on making models more useful, accurate, and autonomous. In that phase, a bad answer was still usually something a human could accept or reject before taking action. But once agents start invoking tools and acting inside business workflows, success should no longer be measured only by how much work they complete. A more important metric is how well an agent recognizes when it lacks the authority, context, or judgment to continue.

When helpful becomes risky

According to Allan Dabre, technology compliance and AI lead at PwC, a behavior that has to be deliberately designed into the system is, “I don’t know.” AI is built to be helpful, so an agent will generally try to do something useful unless it’s been configured not to.

“The fact that AI systems can hallucinate illustrates that tendency,” Dabre says. “When they lack enough information, they may still produce an answer. In an agentic workflow, that impulse can become more dangerous because the output may become an action, rather than remain a suggestion.”

He adds that many enterprises still test AI primarily for completeness and accuracy. That made sense when the central question was if the model could produce a reliable response. But as models improve and agents gain more operational authority, he argues that CIOs need to prioritize something else: restraint.

“Can it stop at the exact moment you want it to stop?” he asks. “Are you testing for that?”

Confidence is not authority

Dabre makes a simple but important distinction. An AI agent may be 99% confident a record should be updated, a refund should be approved, or a legacy database can be decommissioned. But that doesn’t mean the agent has the authority to act. Confidence is about the probability the system believes it’s right. Authority is about whether the organization has delegated that action to the system in the first place.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Allan Dabre, technology compliance and AI lead, PwC

PwC

He gives the example of an agent asked to analyze legacy software and recommend what can be decommissioned. The agent may conclude, with high confidence, that several databases have little user impact and can be deleted. But even if the system is confident, most organizations wouldn’t want it to delete those databases on its own.

The same logic applies across business processes. An agent may be confident a customer record should be updated, an opportunity in a CRM system should be closed, or a transaction appears legitimate. But once that action flows into other systems, the potential consequences expand.

That’s why Dabre argues for what he calls an agent harness: a controls or orchestration layer outside the model that defines what the agent can and can’t do. In a refund workflow, for example, a company might let the agent approve small refunds, require human approval for larger ones, and stop the process entirely above a defined threshold. The agent may gather the relevant context, explain the request, and prepare the case for review, but the decision is governed by the authority boundary encoded into the system.

“It’s not a policy document and it’s not a prompt,” Dabre says. “It’s software or a configuration you can apply to an agent.”

The case for least agency

Matt Graney, chief product officer at Celigo, a business automation and integration platform provider, approaches the same problem through a principle he calls least agency. The idea is to give an agent the least amount of autonomy required to complete a job.

According to him, there’s a temptation to throw AI at broad, nebulous problems. But many business processes are still largely deterministic. They follow established rules and perform repeatable work. Within those workflows, AI may be useful at the point where rigid rules give way to interpretation. But that doesn’t mean the agent should own the entire workflow. “The smaller you make that surface area, the better,” he says.

Graney says the same logic applies to tools. An agent with too many tools can become confused, especially as context windows grow and the task becomes more complex. “Because Celigo is an integration platform,” Graney says, “the company’s approach is to expose agents to fewer, more powerful tools that reach enterprise systems through governed connections.”

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Matt Graney, chief product officer, Celigo

Celigo

That’s another form of restraint. Instead of letting an agent reach into enterprise systems ad hoc, the business gives it a narrow, governed toolset designed for the task at hand.

Graney also argues that guardrails should sit outside the model. If the same agent that makes a decision is also responsible for judging whether the decision is acceptable, the control is weaker. A separate guardrail can check the agent’s inputs and outputs before a downstream action occurs.

That same design discipline applies to escalation. “I don’t know” shouldn’t be treated as a chatbot phrase. In an enterprise workflow, it’s a handoff path that should be defined before the agent reaches it.

Make escalation part of the workflow

Turning uncertainty into a handoff is where Matt Quinn, CTO at CarGurus, an automotive marketplace, sees agentic AI becoming less a pure technology challenge and more a management challenge. At CarGurus, Quinn says agents are evaluated according to what they know, what they can do, and what data they operate on.

CarGurus receives a high volume of cases from dealers, and each one needs to be classified and routed. The company now uses an agent to review incoming cases, draw on account history, and route them to the appropriate next step. Quinn says the agent handles about 70% of those cases end to end without human involvement.

But when agents move toward consequential actions, he says the consensus is having a human approval step. The agent may return with a simple prompt like, I’m about to do this. Do you want me to proceed? That simplicity matters because a handoff shouldn’t bury the reviewer in complexity.

Quinn says the human remains ultimately accountable for the work. That principle is especially important in engineering, where agents may help write code or fix bugs. Quinn adds that CarGurus still expects engineers to follow the practices they’d use for any other production change, which includes running quality checks.

The company has adopted the phrase healthy speed to describe the balance it wants. The goal is to move faster without letting quality degrade. An agent can accelerate work, but if teams abandon the practices that make work safe, the speed becomes reckless.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Matt Quinn, CTO, CarGurus

CarGurus

This is also where human judgment remains difficult to replace. Quinn describes it as high judgment people develop through experience. A human may look at an AI-generated output and sense something’s wrong, even before fully articulating why. “Agents are improving,” he says. “But humans still play a critical role in deciding when the system shouldn’t continue.”

That doesn’t mean every workflow needs the same level of review. Quinn says CarGurus doesn’t have a target percentage of work to automate. The right level depends on the job and the task. A simple bug fix may require a lighter review than a change to a sensitive backend service, and a personal summary may carry little risk. But a document sent under someone’s name still needs human review.

Make autonomy accountable

That kind of pragmatic approach may be the best lesson for CIOs, making the goal of agentic AI appropriate rather than maximum autonomy.

That also means ownership has to be clear. Dabre argues ownership should be divided before deployment. The business defines the outcome, technology builds and configures the agent, risk and compliance set the guardrails, and governance monitors whether the system still behaves as intended. The authority to pause, stop, or retire an agent should be defined before production, not negotiated during an incident.

Graney makes the same point with a simple analogy. If a company hires an untrained intern, gives that intern access to the crown jewels of a business process, and something goes wrong, the intern isn’t the real problem. The process is. The same applies to agents. Accountability belongs with the person who owns the workflow.

That may be the shift CIOs need to make as enterprises move from pilots to production. AI agents shouldn’t be treated as magical workers that absorb accountability. They’re components in business processes, and those processes need accountable owners.

As AI adoption increases, the next phase of enterprise maturity won’t be defined by agents that always answer or always complete the task. It’ll be agents that know when not to act.

  • ✇Security | CIO
  • Now more than ever, CIOs need to be change agents
    CIOs are increasingly expected to drive IT adoption in their organizations, with change management becoming a huge — and more challenging — imperative in the age of AI. Evangelism of the latest technologies has long been part of the job, but many CIOs now say resistance to AI adoption and the fast-paced evolution of IT tools have raised the stakes. Change fatigue has become a major challenge as Andrea Ballinger, CIO of Rensselaer Polytechnic Institute, tries to updat
     

Now more than ever, CIOs need to be change agents

1 de Setembro de 2026, 07:01

CIOs are increasingly expected to drive IT adoption in their organizations, with change management becoming a huge — and more challenging — imperative in the age of AI.

Evangelism of the latest technologies has long been part of the job, but many CIOs now say resistance to AI adoption and the fast-paced evolution of IT tools have raised the stakes.

Change fatigue has become a major challenge as Andrea Ballinger, CIO of Rensselaer Polytechnic Institute, tries to update the IT systems and provide a tech-driven ultra-personalized student experience at the university, she says.

“It’s not even inside of our institutions or our private companies, but the world is throwing so much at us,” she adds. “What you heard today, you’re being told something else tomorrow.”

For CIOs, change management means recognizing that some employees are on a slower journey and, at the same time, encouraging staff to embrace progress, Ballinger says. Good leaders will recognize that some employees will resist, but it’s their responsibility to help employees navigate the changes, she adds.

“Change management is understanding where people are at,” she says. “It’s having that sense of urgency, but a sense of urgency does not mean running without a parachute or without a plan. It means you act today.”

Change management was a big topic of conversation at the CIO 100 Awards and Conference in Frisco, Texas, in mid-August. Several speakers mentioned the challenge, with Ravi Malick, global CIO at cloud-based content sharing service Box, saying change management now represents about 80% of the job, far outpacing pure IT issues.

The change management aspects of a major digital transformation are often what makes or breaks the effort, he says.

AI in particular has forced CIOs to pay more attention to change management because it fundamentally changes the way employees work, he adds. Some past technologies, like the internet and mobile computing, largely started in the consumer space, then leaked over into the enterprise, giving employees time to get comfortable, he notes.

“AI is something that’s reshaping both the consumer space and the enterprise at the same time,” Malick says. “Both the enterprise and individual people are trying to figure out how to get the most value out of it.”

Some revolution, some evolution

As a company, Box is moving forward quickly on some AI initiatives while taking a wait-and-see approach on others, in part to manage the changes required, notes Malick, who sees adoption of AI and other new technologies as a major challenge.

“There are parts of this that are revolutionary, and there are parts that need to be evolutionary,” he explains. “The best way to get somebody pointed in a different direction is to make them realize they haven’t done an 180-degree turn. Get them to realize, ‘I turned on my own, and I actually like the direction that I’m pointed in.’”

To encourage adoption, Box has pitched AI to employees as an enabler and amplifier, not as a technology that will replace their jobs, Malick says.

“We’re asking, What are the things that we can do now that we weren’t able to do before?” he says. “How can we apply your years of the experience and intellectual power toward other areas that we just couldn’t get to before?”

Box isn’t closely tracking how employees are using the time saved through AI tools, he adds. If employees are using the extra time to improve their quality of life, that’s ok, he says.

“Maybe they’re not working on the weekends at the end of the month closing the books,” he says. “Maybe they actually have weekends now and can spend more time with their families.”

Change across the organization

Other CIOs say the change management piece of the job has increased significantly in the past two to three years.

In recent years, CIOs have been pulled into change management roles within other parts of the business as teams identify AI opportunities, says Orla Daly, CIO at skills management company Skillsoft.

“As AI blurs the lines between technology, operations, and people strategy, the CIO role is becoming closer to that of a COO,” she adds. “Workforce strategy is folding in alongside technology strategy, so leading change now sits at the center of the role rather than being one piece of it.”

The rapidly changing technology landscape has also thrust change management to the forefront of the CIO role, she says. “The pace at which decisions need to be made has increased so dramatically that you can’t lead at a distance and expect strategy to translate cleanly into action,” Daly says.

Daly also notes that slow adopters aren’t always active resisters. Skillsoft’s 2026 Workforce Readiness Report found that while 86% of employees use AI tools at work only 24% feel fully equipped to use them effectively, and just 16% receive training before a new tool is introduced.

“That gap suggests an over rotation on tooling without understanding how it changes how work is executed,” she says. “In most cases, it’s uncertainty and a lack of confidence to take the first step, not a lack of interest.”

Daly and other CIOs suggest that mandating the use of a new tool is rarely the right approach.

“Requiring it can create activity, but activity isn’t the same as adoption,” she explains. “If you hand people tools without clear use cases, guardrails, and training, a mandate just accelerates inconsistent use, and you mistake activity for progress.”

NTT DATA focuses on employee AI fluency instead of mandated activity, and the CIO has a huge role to play, says Barry Shurkey, CIO at the company. The CIO role increasingly sits at the intersection of technology, business strategy, and people, he says.

“AI success is not just about moving quickly; it is about helping people understand the change, embrace it, and move forward with confidence,” he adds.

NTT DATA’s own research suggests that AI front-runners use AI to amplify the impact of experienced, highly skilled employees rather than to replace them, Shurkey says.

“As AI accelerates transformation, CIOs are doing more than implementing technology,” he adds. “They are redefining how people work, make decisions, create value, and just as importantly, managing the intensified resistance that’s driven by fear of job loss or control.”

  • ✇Security | CIO
  • The SaaSpocalypse is a people problem
    There is a tidy story going around about the end of enterprise software. Call it the SaaSpocalypse. AI and vibe coding have made it cheap enough to rip out your software-as-a-service contracts and build your own replacements. The rush to rebuild carries its own risk, one that surfaces only after the SaaS is gone. Teams can almost always build the replacement. What they build, too often, is a copy of what they already had. Few people are better placed to see that risk th
     

The SaaSpocalypse is a people problem

26 de Agosto de 2026, 10:00

There is a tidy story going around about the end of enterprise software. Call it the SaaSpocalypse. AI and vibe coding have made it cheap enough to rip out your software-as-a-service contracts and build your own replacements.

The rush to rebuild carries its own risk, one that surfaces only after the SaaS is gone. Teams can almost always build the replacement. What they build, too often, is a copy of what they already had.

Few people are better placed to see that risk than Mike Anderson. As chief digital and information officer at Netskope, the cloud security company that went public on the Nasdaq in September 2025, Anderson runs both IT and the company’s strategy office, a seat that spans his own operations and the broader go-to-market. He is a 2026 inductee into the CIO Hall of Fame, sits on a long list of advisory boards and venture capital innovator networks, and is one of the industry’s most connected executives, fielding peer questions about AI nearly every week. Before Netskope, he was CIO for North America at Schneider Electric. He lives in Dallas.

It starts with how fast the ground has moved. “We’ve gone from AI is my assistant, to I’m delegating a task to an agent, to I’m actually delegating full bodies of work to agents,” Anderson says. “We’re in that last one now.” The trouble is that our instincts have not caught up.

The trap of rebuilding what you already have

Anderson is not interested in slowing anyone down. “I’m a big believer in innovation at the edge of your company. Innovate closest to the people, closest to the problem,” he says. “As CIOs, we don’t want to be the people who say no. We want to let them experiment and learn.”

The danger he points to is quieter than recklessness. It is the pull to aim powerful new tools at rebuilding the past. “The risk is we’re not thinking differently. We’re thinking based on the bias of how things work today,” he says. “Today’s systems are built around people: dashboards that serve us insights, forms we fill in, workflows that pass work between teams. If we go vibe code something, it’s probably going to look a lot like that,” Anderson says. “And it’s not designed for agents, who don’t need a form and don’t need the dashboard. They just need access to the data, the API to call or the other agent to talk to.”

As Anderson sees it, the opportunity is bigger than software. “It’s about reinventing processes with agents in the middle of the process,” he says.

Start with the outcome, not the keyboard

Doing that well means fighting the urge to start building. “Before you put any fingers on keyboards, get a small cross-functional team together, look at reimagining the process and start from the outcome. Then work back,” Anderson says.

It also means changing the question. The reflex has been to ask whether a task can be done with AI. Anderson wants a sharper test. “It’s this work I could delegate to an agent in a deterministic way, where there’s predictability in the outcome,” he says. “That’s a different pivot from where we were three or six months ago.”

The teams that pull this off do not need to be big. Anderson keeps them deliberately small: a subject matter expert who lives the problem, a product owner who frames the context and an engineer who turns it into something an agent can act on. “The old rule was a two-pizza team,” he says. “Now maybe the two pizzas are for three people who are just really hungry, because they’re working tirelessly.”

The unglamorous foundations

Before any of that, Anderson puts discipline around what gets built at all. Every candidate is weighed against three levers: whether it accelerates growth, whether it takes out cost and creates leverage, and what the risk is if it goes wrong.

Then come what he calls the primitives: consistent user management, observability in the tools and standards encoded where agents will read them. “I have markdown files that determine the technologies I want used, down to the database,” he says. “I don’t want agents deciding today that they’re going to introduce a database that’s never been in my environment, because at some point this has to move to a production state.” That last part is what he thinks teams underestimate. When you replace a vendor, you inherit the job the vendor used to do. “Someone has to keep it running. We didn’t have that responsibility in SaaS. Now we do,” he says.

The foundations reach past code, too: style guides, shared libraries, reusable AI assistants and skills that help non-engineers describe what they want, and documentation he insists must be “a first-class citizen.” Netskope IT team built one called Professor Vibe Code that turns a recorded description of an outcome into instructions an AI can build from. “It’s not ‘I need a field on a screen,'” he says. “It’s describing what you want as context with a clear definition of success.”

Why this is really a people problem

For all the talk of architecture, Anderson keeps steering back to people. “We’ve always said building the technology is easy. Getting people to use it is hard,” he says. “That’s even more true here.” He has lived through the internet, SaaS and cloud, and ranks none of them with this. “I can’t point to a technology that’s as disruptive, or that introduces as much change, as AI.”

Which is why he now treats his chief human resources officer as just as critical a partner as his CISO. The two of them talk constantly about the human risk of AI and how to bring people along. “Everyone is worried. Is AI going to replace me? What’s my future in an AI-first world,” he says. “So much of this comes down to giving people clarity about where they fit.”

Borrowing from Maslow, he notes that psychological safety rests on more basic needs, the paycheck and the roof, and that people who feel threatened do not stay neutral. “Without psychological safety, on one extreme you get AI sabotage. On the softer end you get passive resistance, where people just resist using the AI,” he says. The aim is to keep humans at the center of processes that increasingly run without them.

Where to start

For CIOs facing the same moment, Anderson’s advice comes down to three moves. Start with a phone call. “If you’re not talking to your CHRO, get them on speed dial,” he says. “We’ve always kept the CISO on speed dial because security matters so much. You have to add the CHRO now.”

Then be honest about the impact, even when the picture is incomplete. “You may not have all the answers today. Telling people that is important,” he says. And lay the foundations so teams can build at the edge without recreating the old pattern of work handed off later with no context.

The ground keeps shifting, and Anderson does not pretend otherwise. The leaders who come out ahead, in his telling, will be the ones who redesign the work, lay the foundations and never lose sight of the people doing it. For him, the discomfort is the job now. “The world is moving at a pace I’ve never seen before,” he says. “Every day, I have to get comfortable being uncomfortable.”

  • ✇Security | CIO
  • 10 steps to implement an effective AI training program
    It’s no surprise that reaping the rewards from AI requires careful guidance, especially in helping staff use tools safely and productively. Yet evidence suggests some CIOs and their executive peers aren’t providing the level of guidance employees require. While three-quarters of IT staff have access to AI tools, one in five technologists are expected to self-learn, and 23% are waiting for formal training, according to the recent Harvey Nash Tech Talent Salary Report, wh
     

10 steps to implement an effective AI training program

26 de Agosto de 2026, 07:00

It’s no surprise that reaping the rewards from AI requires careful guidance, especially in helping staff use tools safely and productively. Yet evidence suggests some CIOs and their executive peers aren’t providing the level of guidance employees require.

While three-quarters of IT staff have access to AI tools, one in five technologists are expected to self-learn, and 23% are waiting for formal training, according to the recent Harvey Nash Tech Talent Salary Report, which surveyed over 3,600 technology professionals globally.

The research suggests AI explorations are commonplace, but tailored learning and development initiatives are not. Digital leaders who want to turn AI into a value-generating opportunity, though, must educate their staff. But what elements should AI training schemes include? Here, industry experts offer 10 steps to implement an effective program.

1. Take a comprehensive approach

Michael Cole, chief technology officer at the DP World Tour, the men’s professional golf tour that oversees 42 tournaments in 25 countries, says AI training is an organization-wide effort.

“I’ve asked the training coordinators in our HR department to help me deliver what I believe is going to be a fit-for-purpose training and development program for not only my IT team here at the European Tour, but equally across the business,” he says.

Cole says the crucial element to emphasize is that AI and the range of capabilities it brings is about much more than learning how to use technology. “Using AI effectively is about process, mindset, and culture,” he says. “So, when we start to think about the training and development needed to bring an organization like ours into this AI-enabled era of transformation, it’s a comprehensive program that must extend across the business.”

2. Educate the boss

In an organization-wide program, everyone needs AI education, including the boss. That’s why Emmanuel Frenehard, chief digital officer at biopharmaceutical giant Sanofi, says his firm takes a multi-layer approach to AI training.

The executives there completed Drive Digital, a program that Sanofi designed with the ESSEC business school in Paris. The initiative focused on core considerations, such as use cases and value generation. After 150 managers passed through the program, it was extended to more than 1,000 other professionals across the organization.

“Don’t just look for the solution; don’t just think about Claude or ChatGPT,” says Frenehard, referring to best-practice lessons. “Think about the challenge you’re trying to solve. In our case, that approach means focusing on what we’re doing, the value we’re looking to create, and the dependencies the project will create.”

He says training also needs to help AI doubters overcome their fears. “You have to make it fun and as risk-free as possible,” he says. “People shouldn’t feel they need to be super-technical to use AI productively.”

3. Build clarity and agency

Jo Bishenden, chief learning officer at tech training and talent provider QA, says AI education is often treated as a one‑off awareness session, a compliance requirement, or something reserved for technical specialists. 

The best programs get three things right. They provide a baseline for everyone across the organization, the courses focus on role-specific applications to show how AI impacts everyday activities, and they provide continuous learning to encourage a behavior change as new AI tools are introduced.

“When done well, organizations see better return on AI investment, improved productivity, and more confident decision‑making,” says Bishenden. “Employees gain clarity and agency, understanding how AI augments their expertise rather than replaces it. Ultimately, AI success isn’t determined by the technology alone, but by the capability of the workforce using it.” 

4. Put the human in the loop

Ankur Anand, group CIO at recruiter Harvey Nash, says AI training is often a work in progress, with his firm’s research suggesting one in five technologists are expected to self-learn. “There’s a rush to deliver the tools, but then organizations aren’t investing enough in enabling the capability of the people,” he says.

While technological skills like prompt engineering are an important part of AI learning and development, Anand said the best programs go beyond IT expertise to ensure humans in the loop have thorough understanding of their responsibilities.

“There are so many softer elements that need to be handled as part of AI training,” says Anand. “Good training is about using the tool as well as the governance and risk frameworks that need to be changed accordingly.”

5. Showcase individual successes

Louise Newbury-Smith, head of UK&I at Zoom, says it has AI enablement teams at the local and global level. And while the company provides courses and self-learning opportunities, Newbury-Smith says the enablement element brings AI training to life.

“Our approach is about showcasing individual successes, making it real, and repeating best practices,” she says. “We have what we call a Cook Along session with our AI evangelists. We’ll do those sessions together a lot as a group, and that makes the process fun. If you’ve got champions who can share incredible successes, then that goes a long way.”

She says the key to success is sharing knowledge. “We’re very much focused on the human,” she adds. “All the services, content, and direction of AI is about how we can give humans time back so they can have more valuable interactions with other staff to empower them with the information they need.”

6. Focus on the finer details

Dan Cherowbrier, CTO at Formula E, the motorsport championship for electric cars, is another digital leader whose business focuses on enablement. The company has a dedicated AI engineer who helps employees exploit emerging technology.

“We’ve got an innovative culture and we weren’t short of ideas of what we could do with AI,” he says. “What we needed were the resources to get people going, get the technology tested, and get it out there.”

The AI enablement engineer works with other tech specialists in the company to ensure tools are deployed safely and securely. “We’re beefing up our data and AI team so we can help users across the business plug in and understand APIs, get access to data, run security checks, and then put AI into production,” he says.

7. Develop reusable skills

Murali Swaminathan, CTO at technology firm Freshworks, says there’s so much information about AI models that people can easily take the wrong direction without guidance.

“We’re trying to give our staff structured learning,” he says. “We understand they’re not all on the same page. Some are ahead of others so you need to provide knowledge that applies to their specific job roles.”

Swaminathan says senior managers discuss how to train people effectively, as AI experiences and capabilities vary considerably across business units. However, the chosen pathway to AI learning and deployment must suit the individual and the company.

“I had this challenge with my engineers,” he says. “Initially, we gave them four different tools. Everybody was using AI, but it was so inconsistent, and everyone was trying to do the same thing in different ways. So we’re now trying to build reusable skills. And that approach must be replicated for every job function.”

8. Learn by doing

Luke Gebb, head of global innovation at American Express, says the financial services firm has various training programs. Having seen AI education in different forms, he advocates for learning by doing, or as a second-best strategy, watching someone else use the technology.

“Hearing or reading about AI, or being presented with something where you’re not actually seeing it happen is not nearly as helpful,” he says. “The best thing is to get a homework assignment and try something.”

Gebb says this approach plays out regularly across the people working in his 120-strong innovation group. The team runs one-hour show-and-tell sessions where an employee demonstrates how they use AI tools in their everyday activities.

“Then they get a bunch of questions, they post their best-practice lessons, and then others try the same thing. It’s an approach that works really well.”

9. Use pioneering techniques

Stephen Wood, COO at Rathbones Asset Management, says AI training in his organization is mandatory. “We want everyone to be versed in different types of AI,” he says. “We’re not expecting everyone to be a coding genius and an expert in all this stuff, but everyone needs to understand it.”

The firm takes a proactive approach to training, using education sessions and spreading best practices via digital champions. The company also embraces pioneering techniques, including running a hackathon to help identify in-house capabilities.

“The hackathon showed that with some searching on Google and YouTube, you could start to create agents that could do basic functions,” he says. “That process taught us, with the right training, and repeated sessions and continuous development, we wouldn’t necessarily need to hire people to create big productivity gains. That was quite an exciting moment.”

10. Evaluate new possibilities

Emerging technology can’t exist in a vacuum. Bernhard Seiser, VP of digital, data, and IT at AOP Health, says anyone using AI must be aware of potential consequences. “It’s your responsibility to validate whether what you’ve created is correct,” he says.

Operating in a regulation-heavy industry means AI training is linked to data governance. “We leverage it in areas where compliance isn’t an issue,” he says. “For example, writing text, creating images, and so on. Certain things can be done.”

As new AI tools emerge, AOP Health will consider its options and develop a training program. “That approach could mean bringing in specialized tools for specific tasks,” says Seiser. “It’s part of my job, and part of my team’s job, to evaluate AI for each use case.”

  • ✇Security | CIO
  • What the CIO role will look like in 2029
    CIOs have talked about enabling the business for years, but IT exec Monica Caldas expects the role will soon be about orchestrating how the business performs. “Today, CIOs are helping organizations navigate technological, operational, and cultural transformation simultaneously,” says Caldas, global CIO for Liberty Mutual Insurance and a 2026 inductee into CIO.com’s CIO Hall of Fame. “By 2029, much of that foundation will be in place. The role will increasingly focus on
     

What the CIO role will look like in 2029

24 de Agosto de 2026, 07:01

CIOs have talked about enabling the business for years, but IT exec Monica Caldas expects the role will soon be about orchestrating how the business performs.

“Today, CIOs are helping organizations navigate technological, operational, and cultural transformation simultaneously,” says Caldas, global CIO for Liberty Mutual Insurance and a 2026 inductee into CIO.com’s CIO Hall of Fame. “By 2029, much of that foundation will be in place. The role will increasingly focus on orchestrating an intelligence-enabled enterprise, where AI is embedded into workflows, decision-making, and business operations. As intelligent systems take on more routine work, CIOs will spend more time shaping business strategy, workforce evolution, and new sources of competitive advantage.”

In the upcoming years, Caldas predicts, “the role becomes less about implementing technology and more about helping organizations reimagine how humans and intelligent systems work together to create value in the Intelligence Era.”

She adds, “We’re entering a period where AI is reshaping how decisions are made, how work gets done, and how organizations operate. Just as previous waves of technology changed how enterprises functioned, AI is creating new opportunities for CIOs to act as strategic business leaders and enterprise shapers — not simply technology operators.”

Anthony Moisant, CIO and CSO for Indeed, has a similar vision for the role’s future.

“The CIO is becoming the architect of the company’s operating system itself. The CIO is becoming the architect of how a business runs,” says Moisant, also a 2026 Hall of Fame inductee.

Kathy Kay, executive vice president and CIO for Principal Financial Group, describes the future of the CIO role in much the same way.

“Already I’m having to be even closer to the business and talking about how the business should run. I now have way more of those conversations than conversations about technology,” she says.

Longtime IT leaders are unlikely to be surprised by all this. Anyone who has been watching the profession for the past decade or so has seen the CIO role evolve to one focused more on business strategy than it had been. And those with 20-plus years in the profession have watched it truly transform, from a senior-level operations manager position focused on technical decisions to the influential C-suite executive role it is today.

Now, as organizations devise their three-year strategic plans, those same leaders expect more changes for the role, saying that CIOs in 2029 will not just enable how organizations do business, they will devise what they offer, what they do, and how they produce value.

“They will be business-value creators,” says Craig Stephenson, senior client partner and CIO/CTO practice leader at Korn Ferry, an executive search and organizational consulting firm. “CIOs will own not just tech transformation but business transformation, and they will be enterprise leaders driving that transformation at scale.”

‘This is a game changer’

Dani Brown, who retired July 31 after nearly six years as SVP and CIO of Whirlpool, sees that future for the CIO role, too.

“The CIO of the future is different,” says Brown, also a 2026 Hall of Fame inductee. “This is not just an incremental change; it’s a shift. This is a game changer.”

AI is driving much, if not all, of the shift in the CIO’s position, Brown says, because, more than any other technology in the past, AI is changing what business can offer and how they deliver those offerings.

“AI is reshaping business models and quite frankly entire industries,” she says. “So today, it’s not just about how you enable solutions to problems but how do you use AI to shift a business model or industry.”

Danielle Brown, SVP and CIO, Whirlpool Corporation

Danielle Brown, SVP and CIO, Whirlpool Corporation

Danielle Brown, former SVP and CIO, Whirlpool

That task of engineering a shift of the organization or the industry itself is a monumentally different task than reengineering a process and, as such, speaks to the shift, that “game changer,” that Brown predicts happening in the CIO role.

“CIOs will have to determine how they leverage technology to revolutionize how they engage with consumers, how they transform marketing and differentiate products and the company, how they deliver services, and how they use AI to change internal operations to deliver better margins for the company. With the implications of technology on business today being like it has never been before, CEOs want a business partner beside them who understands that,” Brown says.

She adds that many CIOs are already doing such work.

But Brown doesn’t expect these new CIO responsibilities will displace the responsibilities that traditionally fell under the CIO’s remit. They’ll still have to be technologists to understand how best to implement technologies for business advantage. CIOs will still be accountable for deploying and maintaining the IT environment. And, as is the case already, they’ll be measured on creating and running an IT department that enables the business, can respond to changing business needs, and can do so efficiently, effectively, and securely.

AI shifts how the CIO sits in the C-suite

Kay stresses that CIOs, too, must adopt AI for their IT operations to ensure success in the future.

That, though, speaks to other ways the CIO role is changing.

As CIOs advise their colleagues on the use of AI and reengineer their organization’s services, products, and workflows, they’re also going to have to help the organization adjust to working side by side with autonomous AI agents, Kay says.

Kathy Kay

Kathy Kay, EVP and CIO, Principal Financial Group

Kathy Kay / Principal Financial Group

CIOs will also have to leverage their understanding of AI as technologists to share how AI reshapes the market, she says.

Kay says she’s already doing that. For example, she has brought AI’s implications on medicine to the attention of her colleagues, explaining how AI is expected to bring better medicines to market, which will likely mean longer life expectancy that in turn could impact her company’s products and services.

“As a CIO, I’m now asking, ‘If this happens, does our business strategy still hold?’ We haven’t seen the CIO play this role in the past. Now we’re the ones to say, ‘We need to pay attention to this,’” says Kay, another 2026 CIO Hall of Fame inductee.

That requires someone who has the courage to challenge existing strategies and colleagues on their stances, she says. And it requires someone who is “OK pushing them to have those conversations.”

For some, the future is already here

As Moisant sees it, leading-edge CIOs are already living that future.

“More and more today it’s the expectation for CIOs to be thinking about the total system, how the organization runs end to end, and becoming more of an architect of that total system,” he says. “That has already become an expectation for some in the field.”

And it’s going to become more common in the upcoming years, he adds, with the majority of CIOs having to meet those expectations in the future.

Anthony Moisant

Anthony Moisant, CIO and CSO, Indeed

Anthony Moisant / Indeed

Caldas’ vision is similar. She sees the CIO’s responsibilities centering on three areas as AI becomes embedded in how work gets done.

To start, CIOs will have to ensure “the organization has the right foundations, including trusted data, resilient platforms, cybersecurity, governance, and responsible AI practices to operate at scale. Those fundamentals won’t go away; if anything, they become more important,” she says.

They’ll have to help “the organization rethink how intelligent systems, people, and business processes work together. The opportunity is no longer just automation; it’s unlocking human potential and enabling employees to focus their energy on higher-value work while intelligent systems take on more routine tasks.”

And third, they will help shape business strategy and competitive advantage. “As technology becomes increasingly inseparable from the business, CIOs will play a larger role in identifying new opportunities, accelerating decision-making, and helping their organizations continuously adapt and reinvent how work gets done.”

The skills necessary to succeed

If all that sounds exceptionally challenging, that’s because it is, says David Ulicne, executive director of executive education at Carnegie Mellon University’s Heinz College of Information Systems and Public Policy.

“It’s a tough job to be a CIO, especially now that we are in the agentic era. The expectations are overwhelming,” he says. To meet the demands of the role now and in the future, “CIOs have to in some ways reinvent themselves again.”

Technical, strategic thinking, leadership, influence, financial management, and communication skills all need to be top-notch in CIOs if they want to succeed, he explains, as do people management and change management skills to help employees adjust to a workplace that will be staffed with both agents and humans.

Caldas likewise says future CIOs will need a different mix of skills, some familiar and others new to the position.

Monica Caldas, EVP and global CIO, Liberty Mutual stylized

Monica Caldas, EVP and global CIO, Liberty Mutual

Liberty Mutual

“I believe the most successful CIOs will combine technical fluency with business leadership and human-centered change management,” she says.

She lists as key skills:

  • Continual curiosity: CIOs will need to be continuous learners, with the ability to experiment, learn, and iterate quickly.
  • Value-informed decision-making: CIOs will need to be able to distinguish between opportunities that create meaningful business value and those that simply create noise — and in many cases, do so quickly. “Knowing when to double down, when to pivot, and when to stop investing will become a critical skill.”
  • Business vision and fluency: CIOs will need to readily translate technology into business value — an ability already in demand today.
  • Human and organizational leadership: “As intelligent systems become more embedded in everyday work, the differentiator will be the ability to help people adapt, develop new skills, and work effectively alongside new technologies,” she says. “Success will depend as much on leadership, culture, and organizational change as it does on technology itself.”

With all that taken to be the CIO’s evolving remit, Caldas says she already finds herself acting as part technologist, part economist, and part communicator.

“As we move from the Digital Era into the Intelligence Era, the role is becoming less about technology itself and more about helping organizations understand what technological change means for strategy, investments, talent, operations, and competitive advantage,” Caldas says. “Creating clarity in moments of change becomes just as important as delivering technology itself.”

  • ✇Security | CIO
  • AI agent sprawl pressures CIOs to recalibrate governance
    Every Friday, Bret Greenstein, CAIO at consulting firm West Monroe, holds a company-wide meeting to share what’s happened in AI over the past week. He also spotlights one employee at the firm who’s created their own AI agent from the ground up, which lives in the company’s internal AI store. Since the store launched in May, more than 200 employees across departments — many without any technical, engineering, or coding background — have created over 550 agents. “About 15
     

AI agent sprawl pressures CIOs to recalibrate governance

24 de Agosto de 2026, 07:00

Every Friday, Bret Greenstein, CAIO at consulting firm West Monroe, holds a company-wide meeting to share what’s happened in AI over the past week. He also spotlights one employee at the firm who’s created their own AI agent from the ground up, which lives in the company’s internal AI store. Since the store launched in May, more than 200 employees across departments — many without any technical, engineering, or coding background — have created over 550 agents.

“About 15% of our firm builds all the time now,” Greenstein says. “That’s a huge population.”

Enabling employees to spin out their own agents has become popular at many firms. Staff have built hundreds of agents at software company Blackline, for instance, and Microsoft has deployed more than 500,000 internal agents to help employees streamline workflows. Gartner also anticipates that by 2028, global average Fortune 500 companies will have more than 150,000 agents.

Employees know the intricacies of their work, the biggest pain points, and time drainers, so they can build solutions that address those specific issues, according to Greenstein. It also creates enthusiasm, empowers employees, and fosters innovation among the workforce as they build from the ground up.

That said, there’s been a pivot over the last six months, says Michael Murphy, partner and AI practice lead at global management consulting firm Adaptovate. When agentic AI first came on the scene, companies went all in, pushing to build and agentify nearly anything they could. In recent months, however, the narrative has shifted to getting a handle on agent sprawl, assessing the value agents deliver, and keeping costs in check.

“We’re really at this interesting inflection point where clients are having to figure out if we built the right agents, and are they delivering the value we expected,” Murphy says.

Today, tech leaders face a three-way squeeze, says Tiago Azevedo, CIO at AI-powered low-code development platform OutSystems. From the workforce side, many employees ask for permission to use more AI, but the CFO says token usage is becoming too big an expense on the balance sheet, and the CEO wants to see innovation and results from workforces using AI agents.

“I think that’s the biggest challenge for a CIO,” Azevedo says. “Let people take advantage of the technology but in a way that’s cost-effective and actually brings ROI.”

Building in a controlled environment

Employees have built myriad tools to aid their daily workflows. Azevedo’s company launched an agent dubbed Signal Sam, which searches databases of prospective customers, and gives account executives information to pitch them. Murphy and Greenstein also mention finance departments using agents to scan and categorize invoices, HR conducting a first pass on résumé screenings via agents, legal teams utilizing a self-service agent for NDAs, and marketing employees building agents that pull and analyze data from CRMs. These tools are often created by non-technical employees who’ve never written a line of code.

With so many agents popping up, CIOs need a way to oversee them, and ensure they meet corporate standards but without choking innovation, Azevedo says.

He recommends role-based access controls embedded into tools and configured behind the scenes. “So we allow them to use, but in a way that’s governed and controlled, because that’s our duty to the organization,” he says.

Ivan Burazin, CEO and co-founder of open-source developer platform Daytona, advises CIOs to treat agents like employees. “You’re not going to bump into them in your local Starbucks,” he says, “but you give them tasks and they have access.”

So set up agents with specific credentials, like how an organization would grant access to a new hire, with a laptop locked down with organization security protocols, Burazin adds. He also recommends sandboxing, in which agents operate in isolated machines with scoped credentials and firewalls so the sandbox prevents agents from accessing corporate systems or data outside allowed perimeters.

Organizations could use an internal ticketing system as well where employees wanting to build agents request a new identity for them, Burazin says. That way, tech leaders maintain visibility and governance over new agents.

“If something goes haywire in audit logs tomorrow, you can see it’s that agent versus an actual human,” Burazin continues.

He acknowledges that giving employees what feels like free rein to build and run agents can induce stress for CIOs and CISOs. But if a company doesn’t proactively establish tools, employees are apt to privately build AI in the shadows. As long as agent development happens within established confines, it won’t create problems organization wide.

“If you just enforce the security posture that you would for humans, you’ll save yourself a lot of headaches,” Burazin says.

When creating the AI store, Greenstein started by certifying tools for chat, code, data analysis, and other tasks, and then trained employees and made the tools broadly available to use. That process created guardrails and an inherently secure building environment. It also allows tech leaders to continue to monitor prompts and activity.

Now, tech teams review what’s been built in the AI store and flag any agents that excel. If employees have built 10 project management tools, for example, the leader will tag what they deem the best one. That gives employees the option to use existing agents or build a separate version for themselves.

More agents, more tokens

Over the last three to six months, Azevedo has been hearing from customers that their biggest hurdle is agent sprawl and the increasing cost those agents bear due to token usage.

In mid-July, OpenAI published a guide around useful work per dollar, sharing how leaders can look at tasks completed, time saved, and decisions improved to determine if their AI investments are bearing fruit. In addition to using the guide, Murphy suggests comparing the labor time and cost to conduct a manual task against time saved by using an agent, including which type of model the agent requires.

A cheap flash model, for instance, could be easy to justify the cost. “If it’s a very expensive Opus or Fable level model, that’s going to be a lot more challenging of a cost equation,” Murphy says. He adds that making this comparison isn’t about replacing the workforce but swapping “knucklehead admin work” for more engaging, human-centric work. This change may also require some organizational restructuring, such as CIOs and HR leaders working more collaboratively to handle change management as job responsibilities shift. Without the workforce optimized to work with agents, organizations won’t see the promised ROI of use cases, Murphy says.

West Monroe also informs its employees on the costs of different models. Without knowledge about tokens and costs, many employees defaulted to the highest-end model for any tasks before understanding that models come with different price tags. “We started educating people on the various relative costs of different models, and they immediately adjusted behavior, and our cost dropped,” Greenstein says.

While strictly quantitative returns are one way to measure ROI, Greenstein also thinks about return in a qualitative sense. “What does speed get me?” he asks. If someone in the firm is able to follow up with a client in hours because of an agent’s assistance, rather than days or weeks without one, the client will be impressed, and the firm might win their business over a competitor.

“Tokens will cost money no matter what,” he says. “But if you maximize the return, it’ll far outweigh the cost.”

  • ✇Security | CIO
  • Inside TIAA’s massive IT transformation to fuel business growth
    When Sastry Durvasula joined TIAA in early 2022, he saw an organization fighting against outdated legacy technologies and in need of a major IT refresh. Since then, the financial services organization has completed two phases of a comprehensive transformation initiative called Technology Ecosystem Transformation, or TETRIS, leading to a huge reduction in tech debt and a major expansion of functionality for customers. The ongoing project, anchored in cloud and AI tech
     

Inside TIAA’s massive IT transformation to fuel business growth

21 de Agosto de 2026, 07:01

When Sastry Durvasula joined TIAA in early 2022, he saw an organization fighting against outdated legacy technologies and in need of a major IT refresh.

Since then, the financial services organization has completed two phases of a comprehensive transformation initiative called Technology Ecosystem Transformation, or TETRIS, leading to a huge reduction in tech debt and a major expansion of functionality for customers.

The ongoing project, anchored in cloud and AI technologies, started in 2023 with phase one that modernized the core technology stack with 10 new enterprise platforms. Phase two, launched in late 2024, went further by enabling 87 use cases across all major lines of the business.

The project, for example, allowed TIAA to launch its MyChoice Multi-Year Guaranteed Annuity product, and helped create the TIAA Gateway portal, an API-based suite that integrates with partners in retirement and wealth planning using industry standards.

TIAA Gateway took home a CIO 100 Award in 2025, and phase two received a CIO 100 Award in 2026.

Durvasula, TIAA’s chief operating officer, pitched the multimillion-dollar TETRIS project to the board as a three-pronged strategy, with empowering business growth, fueling innovation, and transforming the IT core as its key goals.

Not only did TETRIS need to modernize the company’s IT systems, decommission legacy processes, and automate other processes, but Durvasula pitched it as the way to expand the reach of TIAA’s products and move the company into the future.

“As you expect in a company of our size, we have problems of yesterday, today, and tomorrow being solved at the same time,” he says.

Focus on business use cases

As TETRIS moved into phase two, project leaders shifted their goals from pure technology modernization to business outcome-driven prioritization. So once phase one delivered needed IT platforms like a data cloud and design studio, TIAA pivoted toward enabling business use cases.

This business-first approach ensured continuing executive support and clear ROI at every key milestone, TIAA says.

In 2022, just before the project launched, more than 80% of TIAA’s IT workloads resided in fragmented, end-of-life platforms, which created operational risk, compromised security and resilience, and constrained its ability to innovate. Through TETRIS phase two, however, the organization has cut that tech debt nearly in half.

And consolidating 17 design systems also led to digital products looking and behaving differently, depending on the team that designed them, and accelerated product launches by 35%, enabled multi-lingual capabilities, and increased accessibility to more than 185,000 customers who don’t speak English.

In addition, TETRIS allowed TIAA to combine multiple middleware systems and data lakes, Durvasula says, and the organization moved mainframe applications and data center infrastructure to the cloud.

A giant leap forward

TETRIS has been a huge project, with the company saying it empowered TIAA to have one of the largest leapfrog moments in company history in its submission for the 2026 CIO 100 Award.

Despite the reported failure rates of large transformation projects — some estimates suggest up to 95% fail to meet their goals — TETRIS was essential to keep TIAA competitive and move it forward in the market, Durvasula says.

A big part of the project has been workflow modernization, he says, because TIAA were using some technologies and workflows that were decades old.

“There’s your classical platform and application rationalization, and then there’s your end-of-support, end-of-life stuff that should’ve been remediated long ago,” he says. “Some of the processes we have, because we’re such a large, old company, were designed when the internet just came along.”

Stick to the metrics

Two keys to pulling off such a large project are establishing metrics for success and transparency with leadership, Durvasula says. Project leaders set milestones to indicate when things went well, and they planned for bumps in the road so the TIAA board knew when setbacks happened.

“Not everything is as pretty as it sounds in an awards application, but the success measures we established with our board were based on both phases,” he says. “For the first one, we said we’d deliver enterprise-grade platforms and accomplish migration objectives, but not tied to any specific business objectives.”

Phase two metrics focused more on business objectives, and the project team kept the TIAA board updated as TETRIS moved forward. Setting realistic goals was important, he says, with the team determined not to overpromise results.

“Large programs have a range of objectives, and if you publish the outcomes you’re looking for, people start looking for them, especially stakeholders, the C-suite, and board,” he says. “You have to be honest about which metrics or KPIs you can deliver in the first and second year, and when you’ll start seeing real business scale and impact, which definitely won’t be that soon in a large program like this.”

Goals also need to be flexible, Durvasula says, so transparency with leadership sometimes means telling them the project needs to reset. “If something doesn’t go well, what’s the level of fungibility you have?” he says. “We pick this tool, but what if it doesn’t work? You need to have a plan B.”

So TIAA’s IT team is heavily focused on flexible systems, and what was contemporary three years ago is probably legacy now, especially thanks to AI.

The power of change management

Another big lesson from a project of this size is the need to focus on change management. Retiring old IT systems requires the organization to bring employees along on the journey and convince them the changes are for the better.

TIAA established a multi-disciplinary team to implement a change management program focusing on breaking down silos and setting common adoption goals across the organization and its lines of business. Stakeholder forms and a huge focus on continuous collaboration helped employees understand the need for the changes.

“It’s a big organizational change,” Durvasula says. “If you’re working on a legacy system, and you think at some point it’s going to be modernized, then you become a legacy talent, and won’t have a job.” But the right change management program can convince these employees they can upskill and bring value to the new systems.

“You can bring your functional knowledge of the business and learn new technical skills,” he says. “It’s a massive culture- and people-change initiative as much as tech initiative.”

TIAA’s change management efforts were also made easier because TETRIS happened at the same time as the recent AI boom and involved AI elements. So it wasn’t hard to convince employees they needed to improve their AI skills.

“Because of AI, everybody woke up to this new reality,” he says. “We rode that wave when transformation drove from a cultural and organizational change management point.”

Proteja Suas Decisões Antes de Fechar Negócio

Proteja Suas Decisões Antes de Fechar Negócio






RDS Investigação Defensiva | Due Diligence, OSINT e LGPD

Proteja Suas Decisões Antes de Fechar Negócio

Inteligência e Evidências para Empresas

RDS Investigação Defensiva
Inteligência • Evidências • Resultados

  • ✇Security | CIO
  • Ways CIOs can maintain control amid changes brought by AI
    It took nine seconds for an AI agent to destroy PocketOS’s production database. At work on a routine task in April, the coding agent, a variant of Cursor running on Claude Opus 4.6, ran into a credential mismatch and decided to fix the problem by triggering an API token. Little did PocketOS founder Jer Crane know that its activation would also delete its production database. “Had we known,” Crane later wrote on X, “we would never have stored it.” The consequences of the ag
     

Ways CIOs can maintain control amid changes brought by AI

19 de Agosto de 2026, 07:00

It took nine seconds for an AI agent to destroy PocketOS’s production database. At work on a routine task in April, the coding agent, a variant of Cursor running on Claude Opus 4.6, ran into a credential mismatch and decided to fix the problem by triggering an API token. Little did PocketOS founder Jer Crane know that its activation would also delete its production database. “Had we known,” Crane later wrote on X, “we would never have stored it.”

The consequences of the agent’s actions were immediately apparent. Not only were recent backups belonging to PocketOS’ infrastructure provider contained in the production database — the recoverable versions were at least three months old — but so were those belonging to its infrastructure provider, Railway, which at press time still couldn’t tell Crane whether full infrastructure-level recovery was possible. Crane couldn’t fathom why the agent did this. So he asked it.

What he got back was an apology, of sorts. “I guessed that deleting a staging volume via the API would be scoped to staging only,” the agent said. “I didn’t verify. I didn’t check if the volume ID was shared across environments. I didn’t read Railway’s documentation on how volumes work across environments before running a destructive command.”

Ignoring built-in safety guardrails is hardly unique to agents operating on Claude Opus 4.6. In July, a Brazilian software engineer claimed an agent powered by OpenAI’s GPT-5.6 Sol model also deleted his production database, while in February, a Meta AI security and safety researcher claimed she had to switch off her computer to prevent an experimental agent deleting her entire inbox.

It wasn’t meant to be like this. Agentic AI was intended to be the culmination of millions of hours of research and development in gen AI to perform hyper-qualified acts of pattern recognition in the real world, and truly live up to their labor-saving promise. Their apparent predilection for destruction, however, has revived multiple debates about exactly how they should be restrained, and who, ultimately, is responsible for doing so.

Ultimately, the answer is those who green-lit the offending system. But as the pace of AI development puts greater daylight between companies pressured to adopt it, and those very tools capable of wreaking havoc across their internal databases, are CIOs now out of their depth?

Setting the pace

There’s no question the emergence of gen AI has changed the CIO role. “A few years ago, most of my time went to infrastructure decisions, including what to build, what to buy, and how to sequence the roadmap,” says Mike Trkay, CIO at data analytics company FICO. “Now, a growing share goes to questions of trust, verifying that when AI writes code, makes recommendations, or acts on behalf of a system, those actions can be explained and traced back to someone accountable for them.”

So the CIO has become the enterprise’s technological organizer du jour. “AI is accelerating software development, decision automation, and organizational experimentation at a pace that can outstrip institutional coherence,” says Edosa Odaro, executive advisor for data and AI at consulting firm VDS Global. “As AI becomes embedded across every business function, CIOs are increasingly responsible for ensuring that technical capability, governance, data quality, cybersecurity, human capability, and business strategy continue to evolve together rather than fragment.”

Day to day, that’s led to an exponential change of pace. “Things have always been fast,” says Zach Lewis, CIO and CISO of the University of Health Sciences and Pharmacy in St. Louis. “But now that speed of change is quicker, and you have to adapt.” And the need to catch up is constant. There’s no other option because then any competitor or co-collaborator can jump ahead, adds Lewis.

The rapid pace of change in AI also threatens to diminish the authority of individual CIOs who fail to keep up or set effective guardrails on those individuals who like to experiment with the newest models with loose regard for corporate security. “There’s all these AI tools that employees can now just go out and adopt,” says Lewis. And at the moment, a paid subscription to Claude or ChatGPT isn’t required to capitalize on its abilities. Consequently, staff are just a click away from asking LLMs to perform various tasks and expose sensitive corporate information in the process. “Everyone wants to play with the new thing,” he says. “And when they find benefit there, they’re going to want to bring it to their work lives.”

Agentic AI poses an entirely new set of problems. For one thing, says Odaro, the next phase of application adoption will be defined less by the capabilities of individual models, and more on what you allow their agents to do. “As AI becomes increasingly capable of generating software, coordinating workflows, and making recommendations across functions,” he says, “the challenge shifts from building AI to continuously governing evolving AI systems.”

This, Odaro continues, means that the CIO’s current approach to governance isn’t sustainable. “Static policies, annual reviews, and isolated oversight will struggle to keep pace with dynamic AI environments,” he says. “CIOs will increasingly need continuous governance capabilities that provide ongoing visibility into AI performance, value creation, risk, trust, and organizational adoption.”

Falling over the guardrails

How, then, should CIOs approach writing these new guardrails? Traditionally, this would be perfect fodder for so-called alignment researchers investigating how to instil a sense of morality and propriety into agents. According to analysts at Google DeepMind, however, it’s best to assume the agent will always be a potentially chaotic force within the company, and set parameters on its conduct from there.

“We borrow a lot from security, which already deals with the threat of internal employees who might be malicious, and we can apply these to a new setting,” Rohin Shah, Google DeepMind’s AGI safety and alignment team lead, told Fortunein June. Even so, he added, “AI is systematically different from humans.”

That difference primarily pertains to authority and speed. For agentic AI to live up to its full potential, it requires the freedom to access multiple systems simultaneously — an uncomfortable fact for CIOs hoping to align agent responsibility across the enterprise. In a time when workflows are becoming ever-more automated, however, that aspiration may prove unrealistic. In that case, Google DeepMind theorises that yet another monitoring layer for agentic AI may be required to make sure these free-roaming agents don’t cause too much trouble.

If that sounds daunting, you’re not alone. According to recent research by Gartner, up to 40% of enterprises using agentic AI will either demote or decommission these applications because their guardrails have proven inadequate. Preventing this, the research organization advises companies will need to adopt a graded approach to access, with autonomy for AI agents governed by the level of authority actually determined by the task they’ve been assigned.

Trkay is doing something similar at FICO. “Rather than chase every new model or capability, I focus control on the decisioning layer beneath it,” he says. “That includes the rules for what data AI can access, what it can act on autonomously, and where a human must sign off.”

All this, he adds, is defined from the start by a cross-functional governance committee, clear RACI ownership across standards and monitoring for the application, and a platform approach that enforces responsible AI usage. “Built well, that layer doesn’t need to be rebuilt every time the technology shifts,” says Trkay. “New capabilities plug into an existing structure of accountability, which is the difference between reacting to AI and running it.”

For his part, Trkay is skeptical that rigid guardrails can effectively restrain agentic AI from its most destructive impulses. “They tend to get worked around, either because they slow teams down or they’re too inflexible for legitimate edge cases,” he says. Effective guardrails for agentic AI, he adds, have to be specific enough to be meaningful, and adaptable enough to hold up as use cases multiply, backed by strong architecture, testing, and ongoing monitoring. “The one non-negotiable is the audit trail,” he says. “Whatever autonomy a system has, we need a record of what it did, and why.”

Staying grounded

For CIOs who don’t relish the challenge of setting obstacles and passing points for AI agents scurrying through their maze of networks, there’s always the option of delaying the inevitable by not immediately deploying such applications. Some might not even have the choice, at least for now. “We’re seeing the cost of tokens go up with those new models, because they’re expensive to run,” says Lewis. “But as new models come out, we’re going to see that decrease for some of those older models that were good.”

There is time, then, for CIOs to learn how to keep their head above the torrent of ever more new and powerful agentic AI applications. Whether they’ll be capable of doing so when the next great innovation is sold by Silicon Valley is an open question. Colin Constable, CTO of software development firm Atsign, styles himself as an internet optimist. Even he, however, is dismayed by the decreasing number of junior developers succeeding their more senior counterparts as they retire. That’s a big problem when so many of the former are relying on AI to assist them at work.

“We hand over lots of these decisions to LLMs without making good architectural choices,” says Constable. “If you haven’t been burnt by these things in the past, how would you know the difference?”

For their part, Constable and his colleagues get around this problem with a combination of AI-on-AI oversight of code quality, maintenance of constant dialogue within the team about new coding quandaries, and letting senior developers teach junior counterparts about some of the more avoidable mistakes in their profession. It’s a way of adapting to AI acceleration that points, unequivocally, toward CIOs diffusing responsibility for deeply educating the business about the technology. And if they continue to get it wrong, at least the agent will apologize.

  • ✇Security | CIO
  • Where IT leaders find strength and opportunity in the age of AI
    With vision comes perspective, and over a distinguished career, IT and digital transformation leader Niraj Bhatt has held may titles, and earned three consecutive CIO 100 awards since 2023. As a storied advisor for startups and Fortune 500 companies, helping them navigate the unpredictability and fluidity of AI, Bhatt knows how emerging tech is rapidly reshaping the way organizations build products and deliver value, and how challenges shift as companies move from experime
     

Where IT leaders find strength and opportunity in the age of AI

12 de Agosto de 2026, 07:00

With vision comes perspective, and over a distinguished career, IT and digital transformation leader Niraj Bhatt has held may titles, and earned three consecutive CIO 100 awards since 2023.

As a storied advisor for startups and Fortune 500 companies, helping them navigate the unpredictability and fluidity of AI, Bhatt knows how emerging tech is rapidly reshaping the way organizations build products and deliver value, and how challenges shift as companies move from experimentation to real-world deployment.

AI, of course means a lot of different things to different people, and also for frictionless startups and large enterprises. For the former, speed is a huge asset, allowing them to punch above their weight. But it also means they need lightning fast reactions when landscapes shift. “The same speed can also hurt them when larger AI companies release new offerings that disrupt what startups are building,” he says, referencing recent moves by Anthropic and Google.

On the enterprise side, the conversation is more about scale and risk. Many large organizations have moved past the POC stage and now wrestle with the realities of putting AI into production.

Cost for both is naturally a recurring theme as organizations scale up AI efforts, and true expenses become clear only after the initial excitement fades. “Every input and output token, and the model you’re selecting, add up,” he says. Some customers like Open AI, he adds, get throttled because their usage, volumes, and costs are growing so fast, making planning, observability, and monitoring critical for any team moving beyond experimentation.

So understanding the full software development lifecycle is also vital. Therefore, before committing to production, he helps clients see the big picture, and make sure they understand technical requirements as well as operational and financial implications. “The cost picture isn’t just about usage, but scale and the model choices teams make,” he says.

Bhatt also discusses effective approaches to AI and enterprise IT, technology leadership, and the evolving role of today’s CIOs. Watch the full video below for more insights, and be sure to subscribe to the monthly Center Stage newsletter by clicking here.

On AI hype: If you can’t explain something to someone who’s eight or 80, you don’t really understand it. It’s gone from LLMs, to RAG, to agentic AI, and now the essence is all about tokens. It’s predicting that next token and understanding that is key. So when LLMs came out, they were good at doing that on the data on which they were trained. When the enterprises looked at it, they wanted to make those LLMs work for their data. And the question became how to provide our data and context. It’s about building the right context for the LLM. Agentic AI is similar and that’s where the RAG evolution came in, in that I’ve got my data because every LLM has limitations in terms of how much context it can carry.

There are ranges of LLMs, where Google has the highest in regard to the context window size and what they support. Agentic AI is more action oriented, though. LLMs rely on the metadata you provide for the tools. Then they’re doing token prediction in that whatever I’m looking for, I should use a specific tool. Then it’s the infrastructure underlying which LLM it relies on to invoke the agent. So if you try to explain the microservices to a person, you’re going to struggle. But it’s very important to understand the evolution and that’s where you can cut through the hype. Understanding in this context is key.

On navigating challenges around talent: What I’m seeing on the IT side is there’s so much cognitive load, so how do we empower people to build solutions with the right mix of products and platforms? I think it’s about democratizing AI for the entire organization. Your talent strategy is everyone, all inclusive, starting from interns, the business and tech sides, CEO, everybody.Like your customer success or revenue officers, you need a talent strategy because in the end, IT alone isn’t going to be in a position to deliver for everyone in the organization.

AI has the potential to make everyone in the organization more productive. You have to plan that and facilitate broad innovation across the organization.That’s where the talent strategy, and working with HR and the people officer becomes very important providing those tools. One part of it is training, but how do I build an agent for a receptionist receiving calls, for instance?I’m not going to rely on vibe coding or things of that nature. But what are the tools? Where do I go, where do I host this? I think through that entire ecosystem beyond copilots. That’s where innovation can kick in, and that broader talent strategy is something I’m working with my customers on.

On collaboration: I heard a panel discussion recently, and a question was asked about what’s the number-one trait CIO needs to be successful at in the world of AI, and the answer was collaboration. You need to bring everybody together, move forward together, and make sure everybody’s on board. And in my mind, simplifying that is more like systems thinking when you operate, just bringing everybody along and ensuring they’re meeting outcomes.

But maybe what’s more important is managing expectations. Because if you’re a CIO, there’s a tremendous amount of pressure to deliver and have a rock solid AI strategy. So what I’m doing with my customers is get the board, CEO, and CFO into a room and help them understand what I’m talking about, the evolution, and what’s the art of possible. You don’t want to be a CIO who thinks I have a hammer and everything is a nail. Having buy in from the senior leaders is essential to know you’re headed in the right direction. You’re not reacting to pressure from top leadership, but driving and becoming the change agent for good for the company.

On navigating AI: It’s interesting times. I’m covering a spectrum of startups, non-technical and technical founders, and advising Fortune 500 companies. What I’m seeing is they love the velocity and momentum because that’s what they’ve always wanted, and AI is providing that. They’re able to bring their products to markets very quickly, so something that would’ve taken three years a couple of years ago is probably now taking them three months. There’s a lot of excitement there. But on the flip side, the same velocity is also hurting them. There are so many frontier AI companies getting disrupted. OpenAI, for instance, has offerings in sales and marketing, and Google has an interactive video model. So a lot of startups working in the marketing space are getting stuck. A lot of what I’m focused on is working with founders, helping them pivot in the gen AI space, ensuring their systems and products are built and structured in the right manner.

And on the enterprise space, what I’m seeing is the POC wave, and people have seen the value. There’s some excitement but now the struggle is getting them to production. That’s where you run into cost, latency, legal compliance, privacy issues, and customer concerns that if we get tickets to production, how’s it going to look and how are we going to scale. So engineering and product teams have to be ably supported by the enterprise architecture and R&D teams. I then help them get up to speed and build that internal platform product for the production workloads. It’s exciting times on both sides.

  • ✇Security | CIO
  • What the San Diego Padres CIO does to deliver major league IT experiences
    Petco Park consistently ranks among MLB’s top ballparks for fan experience. That doesn’t happen by accident, and it didn’t wait for a star-studded roster or a deep postseason run. According to Padres CIO Ray Chan, the club made a deliberate choice more than a decade ago to run its tech organization as if every seat were full and the team was playing in October every year. The philosophy was simple — build a World Series-level digital foundation so when the on-field prod
     

What the San Diego Padres CIO does to deliver major league IT experiences

10 de Agosto de 2026, 07:00

Petco Park consistently ranks among MLB’s top ballparks for fan experience. That doesn’t happen by accident, and it didn’t wait for a star-studded roster or a deep postseason run.

According to Padres CIO Ray Chan, the club made a deliberate choice more than a decade ago to run its tech organization as if every seat were full and the team was playing in October every year. The philosophy was simple — build a World Series-level digital foundation so when the on-field product caught up, the elite fan experience would already be there.

More than a ballpark

Most people know Petco Park as the home of the San Diego Padres, which it is, but the venue was designed to be more than that. In a typical year, it hosts 81 regular-season home games, plus potential postseason contests, and then adds concerts and private events in renovated premium spaces.

By Chan’s count, that totals to nearly 400 annual events, often with more than one on the property in a single day. Different parts of the venue may host different audiences simultaneously, with IT expected to turn spaces quickly and support the unique digital requirements of each event.

The multi-use model puts a premium on flexibility and speed. Spaces are designed to be reconfigured quickly, and the underlying technology stack must adapt just as quick.

An always‑on network

When Chan arrived 15 seasons ago, Petco Park looked very different from a connectivity standpoint. On sellout nights, fans often couldn’t place a call or send a text once they were inside the building. There was no real concept of a digital fan journey.

The first major shift came with deploying a full-venue managed distributed antenna system (DAS) from Verizon, and an Extreme Networks Wi-Fi solution, providing fans, staff, and baseball operations with reliable connectivity throughout the ballpark. That network has since become the converged backbone for almost everything that happens at Petco, including digital ticket entry via the MLB Ballpark app, security and operations, tech like instant replay and dugout tablets used by coaches and players, and in‑venue IPTV and signage, all riding on the same IP infrastructure.

For fans, the network is invisible. For Chan’s team, it’s non‑negotiable. “None of this stuff works without the infrastructure in place,” he says.

Consolidated convenience

The Padres have leaned heavily into the league-standard MLB Ballpark app, which provides a consistent digital experience across all 30 venues, while allowing clubs to customize the local section. At Petco specifically, that app becomes the fan’s control center for digital ticketing, ballpark navigation, and a built-in payments and discount wallets tied to offers like Padres Pay and contactless options.

The result is a highly digitized journey, and for many fans, their first and last interaction with the ballpark occurs on their mobile device, and that’s by design.

Toward frictionlessness

Chan and his team are already looking beyond digital barcodes to facial-authentication-based entry, leveraging MLB’s Go Ahead Entry program rolling out at several parks. In that model, fans enroll once in the app with a selfie, then simply walk through a designated lane while overhead cameras verify identity and automatically scan tickets.

The promise is a hands-free, eyes-up experience where fans no longer need to take out their phones at the gate. Chan says this is the most frictionless way to enter a ballpark, and it even enables personalized greetings by name at the turnstile, another small but memorable touch to create a World Series-caliber experience.

Concessions are another example of how Petco’s IT modernization seamlessly enhances the fan journey. Petco is now a fully cashless venue, so fans pay with credit cards, mobile wallets, or the dedicated Padres Pay capability integrated into the Ballpark app. This reduces transaction friction, speeds lines, and improves security by minimizing cash handling.

IPTV everywhere

The expanding IP television footprint is another hallmark of Petco’s fan experience strategy. New screens throughout the venue serve multiple roles to ensure game coverage is never lost, even when fans leave their seats.

They also show real-time updates and wayfinding, an L-bar format that combines live video with adjacent ad inventory and informational content, and full-screen takeovers during concerts or special events, letting the venue transform its look and feel to match what’s happening on the field or stage.

Because it’s all IP-based, game-day operations and marketing teams can reskin the park on the fly, turning screens into a flexible engagement and monetization channel rather than relying on fixed signage.

Constant modernization

Despite opening in 2004, Petco Park doesn’t feel like a 22-year-old venue. Chan says that’s intentional and points to a continuous program of infrastructure upgrades and capital projects to redo suites, unify premium spaces such as the Western Metal rooftop and loft, and find areas to transform into new experiences.

Beneath those visible changes lies ongoing modernization of the network and systems in terms of upgrading switches, faster Wi-Fi, and backend platforms to support the latest apps and services. As Chan puts it, the goal is to make the park look and feel no older than a couple of years, which requires consistent ownership commitment and alignment between IT and operations.

Perhaps the most important part of Chan’s playbook, however, is cultural rather than technical. He describes the Padres as a listening organization that actively solicits and incorporates fan feedback to refine the experience across seasons.

That mindset is shaping the club’s approach to AI, so instead of chasing it for its own sake, Chan is focused on use cases that improve customer service by using chatbots or AI-assisted voice lines to free staff for higher-value interactions, and solve specific operational problems such as using AI to match lost-and-found queries with a database of found items.

The bigger IT picture

The way Petco Park manages its technology operations offers patterns that can apply beyond sports venues, starting with establishing a converged, resilient backbone. Connectivity is a shared utility layer that everything else depends on, rather than a series of isolated projects. That makes it easier to add new capabilities later without rearchitecting every time.

Chan’s philosophy of building as if every seat were filled also applies across all e-commerce peaks, clinical surges, and manufacturing seasonality. Capacity planning, observability, and failover should be set at Black Friday, not an average Tuesday. And treat your environment as a multiuse and continuously modernizing platform. Petco’s “more than a ballpark” mindset reflects the shift toward mixed-use destinations or campuses that blend learning and events, and offices that evolve into collaboration hubs that chip away at legacy infrastructure. IT leaders across sectors can apply the same rolling-renovation model to networks, identity, observability, and edge infrastructure, keeping technical debt manageable.

  • ✇Security | CIO
  • Inside the post-merger IT overhaul at Alaska Airlines
    As an aviation industry veteran with over 30 years of experience, Alaska Airlines CIO Charu Jain is all too familiar with the technology integration process that often follows a big airline merger. By her count, she’s been involved in four such projects. But none, she says, has brought her greater satisfaction than leading the overhaul of Alaska’s PSS following its $1.9 billion acquisition of Hawaiian Airlines in September 2024. “This is one of the biggest milestones
     

Inside the post-merger IT overhaul at Alaska Airlines

7 de Agosto de 2026, 07:01

As an aviation industry veteran with over 30 years of experience, Alaska Airlines CIO Charu Jain is all too familiar with the technology integration process that often follows a big airline merger.

By her count, she’s been involved in four such projects. But none, she says, has brought her greater satisfaction than leading the overhaul of Alaska’s PSS following its $1.9 billion acquisition of Hawaiian Airlines in September 2024.

“This is one of the biggest milestones in any merger work done between airlines,” says Jain, speaking from her company’s Seattle offices just two months after Alaska and Hawaiian completed their transition to a shared PSS.

In its simplest terms, a PSS is an all-encompassing software suite used by airlines to record and manage a passenger’s journey, from booking tickets and checking in baggage at the airport, to boarding the aircraft and accessing the in-flight menu. “A PSS touches almost every function of an airline from employees to guests,” says Jain.

Two brands, one system

At the time of the merger, Alaska and Hawaiian each had its own PSS. No sooner had the ink dried on the deal than the cutover project got underway to bring both airlines’ systems under a single operating platform.

According to Jain, the two airlines agreed from the get-go that they’d retain their own unique historic brands, both with a combined history of close to 200 years, which would be reflected through the system.

“It had never been done before, developing capabilities to enable two brands on one platform,” adds Jain, who also serves as Alaska’s SVP of merchandising and innovation. “We didn’t want a situation where a passenger travelling from Spokane to Seattle on an Alaska-branded flight, and then onto Honolulu on a Hawaiian-branded flight, would have to navigate two separate systems. So we thought about how to make that experience more seamless.”

After settling on a PSS, developed by travel software manufacturer Sabre, Jain and her colleagues began work on migrating the airlines’ millions of bookings and passenger information, while also updating their various guest- and employee-facing tools for the new system.

Selling cutovers and mock flights

Executing a system cutover on such a large scale is a delicate balancing act, not least in a live-environment where, for a major airline, any form of disruption to the passenger experience can be bad for business. So there was no attempt to rush the project.

“To make sure we didn’t have any issues with customers’ bookings, we really took a risk-optimized approach with a phased deployment and a phased cutover,” says Jain.

Much of this hinged on what Alaska refers to as a selling cutover. Starting in October last year, all new bookings were made on the new PSS, which allowed the group to drain old bookings from the legacy system, and start selling tickets six months in advance of the official transition date; the average booking curve for an airline is around six months.

“There was no migration of millions of records and bookings,” says Jain. “This meant when our customers checked in on the first day [of the PSS], it was as if the booking had been made on the native system.”

While this was going on, however, Alaska was hit by a sizeable IT outage that grounded flights across the country and impacted the travel plans of nearly 50,000 passengers. It followed a previous IT outage in July. However, Jain says the disruptions didn’t impact the project in any way.

So in the final months leading up to the cutover completion, Alaska carried out several dress rehearsals to test the system, including mock flights for domestic and international routes in anticipation of the recent launch of several non-stop services to Europe.

This involved real guests arriving at the airport, completing check-in, going through security, and taking their seats as if they were about to take off. Leaving no stone unturned, the simulation also accounted for baggage collection, pets, wheelchair users, and onboard hospitality, stopping just short of passengers being served actual food.

Alaksa completed five such mock rehearsals in all. “The fifth one was when everything worked without any medium or high issues, and gave us the confidence we were ready,” says Jain.

As part of the airline’s scenario planning, it also set up command centers in various locations, including Honolulu and Seattle, to plan for unforeseen and unrelated problems on the day of the cutover.

A dedication to collaboration

A project is only ever as a good as its people, and Jain is quick to hail the collaborative spirit that Alaska and Hawaiian brought to the table. As a PSS involves both the operational side of an airline’s business — touching on everyone from pilots, flight attendants, and baggage handlers — and commercial departments responsible for policies and pricing, this was more than a purely technological undertaking.

“This was about people coming together from two companies to make this one big thing happen,” says Jain.

When Alaska started making bookings on the new PSS last fall as part of the selling cutover, it also began training employees how to use system. It was around that time as well, says Jain, that the airline was confident the transition would be completed by April 2026, just in time for the busy summer travel season.

Since the PSS has been up and running, the company has also introduced a single mobile app to replace Alaska and Hawaiian’s separate existing ones, allowing passengers to personalize their experience to the airline brand they’re more familiar with.

“It’s a much more seamless experience now that there’s no confusion knowing which app to go on, or why they have two booking numbers,” says Jain. Alaska’s employees are also just as happy with their new tools, she adds.

  • ✇Security | CIO
  • Never mind clean data. Annotate as you collect it.
    Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data. Not only do you need to be able to track the lineage of data your model uses from source to token, something the EU AI Act requires, you also ne
     

Never mind clean data. Annotate as you collect it.

5 de Agosto de 2026, 07:00

Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.

Not only do you need to be able to track the lineage of data your model uses from source to token, something the EU AI Act requires, you also need to be able to take into account where the data came from, whether it’s out of date, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.

Gartner expects organizations will abandon 60% of AI projects because they don’t have the right metadata management, data quality, and data observability. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and one of IBM’s 2026 predictions was the importance of smarter data.

The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.

But that can also remove a lot of the context crucial for gen AI. Rather than cleaning data and losing the original context, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”

IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.

Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”

Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”

Raw but not rancid

Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.

Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”

Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”

But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”

That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”

Structure isn’t static

Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these data cascades shows how easily context gets lost and how badly it affects data quality.

Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.

“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”

Sensing structure

Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.

Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.

That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”

Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.

Incentives for annotating

DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.

LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”

The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.

“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”

That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”

People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”

Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.

So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”

DBOMs and data contracts

Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.

“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.

Aronchick advocates for a SLSA-style data bill of materials using a tool like Makoto, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.

The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.

Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.

“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.

AI demands provenance

All this context is the kind of metadata Anthropic’s context engineering guide recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.

Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.

If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”

And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.

Expanso recently won an Edge AI award for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”

Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”

Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.

“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”

  • ✇Security | CIO
  • CIOs risk being sidelined in enterprise AI initiatives
    The AI revolution has created new opportunities for CIOs, with expanded responsibilities and more authority, but some observers see the opposite happening at some organizations. While many CIOs have become the main executive leading AI strategy and initiatives, some organizations have set the responsibility for AI deployment and adoption with another executive. That puts CIOs in a real danger of being sidelined during the internal AI debate, according to some IT lead
     

CIOs risk being sidelined in enterprise AI initiatives

3 de Agosto de 2026, 07:01

The AI revolution has created new opportunities for CIOs, with expanded responsibilities and more authority, but some observers see the opposite happening at some organizations.

While many CIOs have become the main executive leading AI strategy and initiatives, some organizations have set the responsibility for AI deployment and adoption with another executive.

That puts CIOs in a real danger of being sidelined during the internal AI debate, according to some IT leaders and observers. Many organizations, for example, have appointed chief AI officers, and other industry experts suggest AI initiatives should be the purview of the CEO.

AI adoption is too important and pervasive to be confined to a single department, argues Nishith Rastogi, founder and chief executive and technology officer of AI-driven logistics solutions provider Locus. As a result, the CEO needs to be the main champion of the technology, he adds,

Rastogi recently combined the CEO and CTO at Locus to focus on AI. For now, he wants to be directly involved in all new AI initiatives at Locus, which doesn’t currently have a CIO.

“The job of a CEO is to be worrying about the leading indicators and the lagging indicators, and we are a technology company,” he says. “We must be at the absolute forefront of that, and the profound shift that is happening today is that AI is the new IT.”

At some point in Locus’ growth journey, however, the company will need a CIO, and the CIO will be heavily involved in AI-related operations, Rastogi predicts.

“I may get the ball rolling, I will put the hamster wheel in motion, but I would definitely need a CIO and CTO to take it to closure and truly realize all the impacts,” he says. “If everybody starts using LLMs and AI and everybody becomes more efficient, the need for someone to manage, to deploy, to create infrastructure actually expands.”

The rise of the CAIO

When it’s not the CEO taking the reins, many enterprises are passing over the CIO to create a new title to lead deployment efforts. A report from IBM’s Institute for Business Value found that 76% of surveyed organizations now have a CAIO, up from just 26% in 2025.

Appointing a CAIO can undercut the CIO’s mandate in some cases, says Debbie Madden, founder and chairwoman of AI consulting and software engineering firm Stride.

“Here’s how this might play out,” she says. “The board applies pressure to adopt AI, the CIO responds with infrastructure or cost savings answers, and now there’s a chief AI officer who owns the most strategic budget in the company.”

But getting into a turf war about AI and IT budgets is the wrong approach for CIOs, Madden says. “The moment you’re defending the IT budget, you’ve already positioned yourself as a cost center, and cost centers don’t get handed the AI mandate,” she adds.

Instead, the CIOs gaining scope inside their organizations tie every AI initiative to revenue growth, margin protection, risk reduction, or speed, she says. Proactive CIOs also take on difficult AI governance issues.

“They claim the governance questions before anyone else does: who owns the output, who reviews it before it touches a customer, and what’s the rollback path when the system is wrong,” she explains. “Whoever answers those questions owns AI. That’s the turf worth taking.”

Madden sees the CIO role splitting as AI becomes more pervasive within enterprises. “There’s the infrastructure job, keeping systems running, and there’s the value job, deciding where AI changes how work gets done,” she says. “AI is pulling those apart, and the CIOs consolidating power are the ones taking the value job.”

Broadening the definition

Dustin Engel, founder and principal consultant at AI consulting firm Elegant Disruption, also sees CIOs potentially losing responsibility as the organization deploys AI, but it’s often because the CIO role is defined too narrowly.

“CIOs are not being sidelined because AI is too technical,” he says. “They are being sidelined when AI becomes too strategic for the way the CIO role has been defined inside the company.”

When some organizations appoint a CAIO, it signals that leadership doesn’t believe that the CIO’s existing technology function can turn AI into a practical operating agenda, he suggests.

“If the CIO is viewed as the person who keeps systems running, AI will move around them,” Engel adds. “If the CIO is viewed as the person who helps the business redesign how work gets done, AI expands their influence.”

Engel agrees that CIOs should avoid turf battles. At many enterprises, AI will show up across the organization, in marketing, sales, finance, legal, HR, operations, and the product team, and the CIO can’t be everywhere.

“If the CIO tries to control all of that from the center, the business will either slow down or go around IT,” he says. “The CIO does not need to own every AI project. The CIO needs to make sure the company does not end up with disconnected experiments, weak governance, and tools that cannot scale.”

There’s also a danger in removing AI responsibilities from the top IT executive at an organization, some experts say. Good CIOs can help AI integrate into other IT systems, says Ken Ringdahl, CTO of expense intelligence vendor Emburse.

“If AI sits outside the CIO’s remit, the CIO may lose scope, but the company also loses coherence,” he says. “AI is not a feature that can simply be bolted onto the business. It has to be integrated into applications, data, security controls, and everyday workflows, and without that integration, organizations end up with fragmented experiments, inconsistent results, and a much heavier burden of training and enablement.”

A CAIO can bring focus and expertise to AI deployments, but the role often doesn’t have the authority to change systems, workflows, and operating models across the enterprise, he adds. The CIO, however, typically does have that remit.

“A chief AI officer can accelerate the AI agenda but cannot substitute for the authority required to transform the organization,” he says.

Working together

Like Locus’ Rastogi, Ringdahl believes the CEO has an important role to play during AI deployment and integration. But the CIO has a role as well.

“The CEO owns the AI mandate; the CIO owns the machinery that makes it real,” he says. “The CEO must establish why AI matters, where it should create value, and how leaders will be held accountable for adoption and results. The CIO then turns that mandate into an integrated, secure and scalable capability across the company’s systems and workflows.”

Rastogi encourages CIOs to stay in the game by turning themselves into AI experts.

“The encouraging part here is that the entire art is just a couple of years old, so in under a month, you can pretty much catch up to the very top,” he says. “The moment you do that, you become literally the most indispensable and the most needed resource in the organization because every leader wants to partner with you to supercharge them.”

  • ✇Security | CIO
  • How AI helps the US Senate Federal Credit Union better manage risk
    The United States Senate Federal Credit Union (USSFCU) is a nonprofit financial cooperative that provides traditional retail banking services to entities within the US government, such as the Senate and the Supreme Court.At present, the credit union’s headcount stands at nearly 150 people, managing around $1.6 billion in assets. A few years back, when it started to expand its use of technology, cybersecurity was a key focus area, but the financial institution faced two maj
     

How AI helps the US Senate Federal Credit Union better manage risk

31 de Julho de 2026, 07:00

The United States Senate Federal Credit Union (USSFCU) is a nonprofit financial cooperative that provides traditional retail banking services to entities within the US government, such as the Senate and the Supreme Court.At present, the credit union’s headcount stands at nearly 150 people, managing around $1.6 billion in assets.

A few years back, when it started to expand its use of technology, cybersecurity was a key focus area, but the financial institution faced two major challenges in boosting security as it scaled. The USSFCU was carrying significant technical debt, and there were holes in the organization’s defenses.

“We found gaps where we needed more systems, tools, and people, and then there were instances where we had technologies in place that weren’t being used effectively,” says Mark Fournier, CIO at the credit union. “We weren’t buying a bunch of shiny new things without thinking about it. We were actually quite prescriptive every year, performing a number of different exercises to identify our shortcomings and then finding the right solution to fill the gaps. But over time this adds up. It was clear we couldn’t keep hiring more people and bringing in new solutions.”

The USSFCU needed a more efficient way to bring everything together and make its cyber estate easier to manage. For Fournier and his team, vulnerability management was the hardest hill to climb since they have to deal with about 100 new possible breach points every day.

“When we looked at the problem more closely, the impact of these vulnerabilities was far greater than we realized,” he says. “Not only because of the volume but because of a lack of clear understanding around the potential impact of each one across the broader business.”

Improved risk management

The USSFCU didn’t lack security tools, however. In fact, it had plenty, from scanners and endpoint tools to asset records, tickets, and internal documentation. But each tool saw only a slice of the environment, so there was little to no context. This made it difficult for the security team to separate real business risk from noise.

So for each new vulnerability, the security team had to run a manual investigation, which could take days. And while doing this, they still had to triage the next wave of findings. The organization, therefore, needed a way to know what mattered, why it mattered, who owned it, and whether taking the time to make a fix actually reduced risk. The USSFCU also required a solution to be deployed entirely in-house, leveraging its internal inferences.

Working with Tonic Security, the organization deployed an exposure management solution that pulls together data from different tools and data sources to create a clear picture of business risk. “One of the key functions of the platform is the ability to ingest anything,” says Fournier. “Breaking down silos between disparate systems is essential to unlock valuable contextual information.”

For the USSFCU, transparency and explainability are critical, he adds. This tool uses an AI data fabric to extract context from structured and unstructured data. This context drives prioritization, ensuring the right owner gets the right evidence, not a vague ticket. And once the work is done, the solution checks whether the exposure was reduced.

Because the AI is grounded in the customer’s own environment, it isn’t just guessing from a generic risk model. It reasons over USSFCU’s assets, owners, services, tickets, controls, and business context. But it isn’t using this data to train external models.

Describing one particular incident, Fournier explains that shortly after the initial deployment, various stakeholders met to assess progress. “We thought we were smart because we found an error with the platform,” he says. “The solution had labelled an asset as internet exposed, which we knew was incorrect.” But after a review and lengthy discussion, they were proven wrong. “Almost immediately, the value of bringing this information together became apparent.”

A template for bigger things

Before this solution, a high-severity finding could send an analyst on a lengthy scavenger hunt because of data located in so many different places. They’d check the scanner, asset inventory, tickets, and maybe even ask around to find the owner. But now they can find the asset, the owner, the business relevance, the exposure path, and the recommended action in one place. The solution has reduced the time taken to resolve a vulnerability by 75%. And with a clearer idea of what is and isn’t important, and what adds practical value, the number of incidents someone needs to respond to has reduced from about 100 a month to just 10.

Sharing his lessons from the project, Fournier says one needs to keep an open mind because the problem you think you have is often very different from the one you actually have. “This project has also been an eye-opener around how people can collaborate and operate across different areas of the business,” he says. “When I talk to my peers, they regularly highlight the disconnect between different departments and business functions. But with a project like this, when you’re crossing traditional boundaries, you need to have open lines of communication to succeed.”

  • ✇Security | CIO
  • The gen AI helping Aetna review millions of medical records
    One of the biggest challenges companies like Aetna face every year is an annual HEDIS review of its records to identify gaps in care. For large national payors, the scale of the challenge is immense. So Aetna has deployed a gen AI-driven document intelligence platform that has reduced the need for manual review by 65%. “We have a large group of amazing trained medical coders who do this every day,” says Nathan Frank, chief digital and technology officer at Aetna. “This
     

The gen AI helping Aetna review millions of medical records

31 de Julho de 2026, 07:00

One of the biggest challenges companies like Aetna face every year is an annual HEDIS review of its records to identify gaps in care. For large national payors, the scale of the challenge is immense. So Aetna has deployed a gen AI-driven document intelligence platform that has reduced the need for manual review by 65%.

“We have a large group of amazing trained medical coders who do this every day,” says Nathan Frank, chief digital and technology officer at Aetna. “This is about making it easier for them by speeding up the process. Something that might have taken weeks or months we can now do in days.”

The Healthcare Effectiveness Data and Information Set (HEDIS) is a range of performance measures for the managed care industry. Developed and maintained by the nonprofit National Committee for Quality Assurance (NCQA), the first version of HEDIS was released in 1991.

Under the HEDIS measures, large managed care providers like Aetna review more than 10 million medical records annually to identify gaps in care. These gaps are missed or overdue preventative care or chronic disease management tests including missed cancer screenings, blood sugar tests for diabetics, eye exams, and immunizations. Closing these gaps improves patient outcomes, and health plans are measured in how well they perform. But processing medical records is no easy task.

“We’re talking about medical charts that have white space filled with handwritten notes,” Frank explains. It’s not just structured data, it’s lots of physical clinical documentation.”

Adding up the numbers

Frank says industry benchmarks for large providers indicate an annual review process that requires about 50,000 work weeks, equivalent to nearly 1,000 dedicated full-time employees. It would take a team of 50 reviewers more than 20 years to complete a single annual review using fully manual processes.

Enter AI Medical Chart Review, a platform developed by Aetna that leverages cloud services and gen AI to automatically extract clinically relevant data from records, and prioritize records based on the likelihood of measure closure and evidence strength.

“Large language models and gen AI give us the ability to train a model to decipher the charts, identify the high value codes, and build correlations,” Frank says.

In the space of about six months, Frank’s team ideated the platform, and designed and trained a PoC that was able to process millions of records in just two weeks. As a result, AI Medical Chart Review has earned Aetna a CIO 100 Award in IT innovation.

“Now we’ve gone through 14 million documents,” Franks says. “We’re seeing a reduction of manual effort, which is now being transitioned into other areas like quality control and making sure the automated chart review is working as expected.”

Behind the curtain

Using gen AI, the platform automatically ingests and analyzes unstructured medical records and clinical documents. And as part of that process, it identifies and extracts clinically relevant information for specific HEDIS measures like diagnosis codes, medication records, lab results, and visit documentation. With this data, the platform generates a prioritized set of records based on the likelihood of measure closure and strength of clinical evidence, which is then passed to human employees for review and validation.

Frank says the platform has increased gap closure rates (leading to improved Star Ratings and higher reimbursement), streamlined workflows, and enabled teams once dedicated to manual record review to shift focus to higher-value activities.

Frank says much of the speed and success in building the platform comes down to a shift in the way it approached the design and build process. Rather than exhaustively writing specifications and requirements, Aetna created a team that included engineers and subject matter experts who worked together to build out capabilities iteratively.

“It allowed us to move much faster, and having a business subject matter expert sitting in the same virtual or physical room with us got us a much better outcome,” Frank says. “The product model, our cloud compute model, and our AI governance model allow for quick reviews to make sure we’re using AI responsibly with the right guardrails. It’s increased the speed to get from product launch to go-live.”

He adds that small teams that don’t have to deal with a lot of bureaucracy are key to moving quickly.

“You need to design with security, compliance, and a responsible use of AI as core principles from day one,” he says. “Everything we do from a new build standpoint starts with thinking about how we make it cloud native, how we build with the right elasticity and speed, and how we optimize the cost.”

The most important element of all, he says, is a good relationship with your subject matter experts.

“You can have a great product manager and engineer, but you really need that business subject matter expert who’s excited about it, and who has a passion for transforming the process,” Frank says. “Once you put those three together, you’ll see amazing things like this happen all the time.”

  • ✇Security | CIO
  • 11 tech experts every CIO should follow on social media
    Social media is more than a place to network or follow the latest headlines and trends. For CIOs, platforms like LinkedIn, X, and Bluesky offer direct access to technology executives, AI experts, economists, and business leaders who share ideas, challenge conventional thinking, and provide insights that can help shape tech strategy. Here, 11 IT leaders share the social media experts they follow, and explain why these voices are worth CIOs’ time. Jensen Huang, founder an
     

11 tech experts every CIO should follow on social media

29 de Julho de 2026, 07:00

Social media is more than a place to network or follow the latest headlines and trends. For CIOs, platforms like LinkedIn, X, and Bluesky offer direct access to technology executives, AI experts, economists, and business leaders who share ideas, challenge conventional thinking, and provide insights that can help shape tech strategy. Here, 11 IT leaders share the social media experts they follow, and explain why these voices are worth CIOs’ time.

Jensen Huang, founder and CEO, Nvidia

I find Jensen Huang’s insights (X, LinkedIn) fascinating, and there’s much to be admired and learned from. He’s a bold thinker who fosters a culture of continuous learning, which is incredibly valuable in an ever-evolving tech and cyber business environment like Exos. My observations are that Huang is looking to better the lives of his employees, clients and community — and so am I. His content helps me to think differently and his leadership style has a lot of technical depth, which is especially relevant with the rise and momentum of AI. He’s been described as intensely curious, which aligns with Exos’ tagline, We are Curious. – Jose Martinez, CIO and managing director, Exos IT

Jason Crawford, founder and president, Roots of Progress Institute

Jason Crawford is an under-the-radar voice more CIOs should know. He is one of the most important thinkers on the philosophy and history of technology, and his work is about understanding why technological progress happens and how to sustain it. I follow him because his attention and capital directly drive where the industry moves next. – Yaron Hadad, CEO and CTO, Beehive Software

Kelsey Hightower, distinguished engineer, Google

Kelsey Hightower (Bluesky, LinkedIn) is valuable because he explains cloud infrastructure and Kubernetes in a way that’s practical and grounded. What I appreciate about his work is he often brings the conversation back to simplicity, maintainability, and the people who have to operate these systems. For technology leaders, that matters because the hardest part of cloud adoption isn’t choosing tools but making sure teams can run them reliably over time. – Sai Joshitha Kathari, senior site reliability engineer, Visa

Mustafa Suleyman, CEO, Microsoft AI

As an IT leader and advisor to CIOs, one of the voices I pay the closest attention to is Mustafa Suleyman (X) because he thinks beyond the technology itself. He consistently explores how AI changes institutions, labor markets, governance, and power structures. His work has influenced my own thinking about the growing concentration of AI capability and infrastructure in the hands of a relatively small number of organizations. For CIOs, that perspective is valuable because AI is no longer simply a technology investment, but a strategic, infrastructural, and organizational issue. – Matt Hasan, CEO, aiRESULTS, and founder, The AI Humanist Movement

Kevin Benedict, futurist, Tata Consultancy Services

Over the years, I’ve learned that technology leadership is about following people who help you connect innovation to business results, not the loudest voices. One person I consistently follow and recommend is Kevin Benedict (LinkedIn, X). He consistently delivers insights at the intersection of AI, digital transformation, customer experience, leadership, workforce evolution, and innovation. What distinguishes him is his ability to translate emerging technologies into practical business strategies. Rather than focusing on hype, Benedict focuses on execution, adoption, organizational impact, and measurable outcomes. His insights are practical, strategic, and immediately applicable, making him one of the most valuable voices for CIOs and technology executives navigating today’s rapidly evolving digital landscape. – Paul Bailo, digital transformation executive, educator, author, and founder and CEO, Landit.ai

Ethan Mollick, associate professor, The Wharton School

Ethan Mollick (LinkedIn) has the highest post frequency of the thought leadership I follow. From academic papers to showing model improvements by using his own “otter on a plane writing emails” benchmark, he covers a broad spectrum of AI topics. He frequently gets access to the latest models before they come out, and when they do, his posts give a glimpse of what’s new or different, grounded in longer experience with the products. – Andreas Welsch, founder and chief human agentic AI officer, Intelligence Briefing

Dado Van Peteghem, author and keynote speaker on AI, technology, and business

I suggest Dado Van Peteghem (LinkedIn, TikTok) as a thought leader for CIOs to follow. He provides excellent perspectives on the future of work and offers a strategic guide on how CIOs should adapt to AI, digital ecosystems, and new business models. Van Peteghem helps leadership teams understand how digital transformation goes beyond technology upgrades. His focus is on aligning technology, culture, leadership, and business strategy so digital initiatives create measurable business value rather than becoming isolated IT projects. This aligns with what I advocate, hence my support for him and his idea of digital ecosystems. Van Peteghem spells out how AI changes workflows and how organizations should redesign operating models to decide what should be automated versus what should remain human-driven. – Max Vermeir, VP of AI strategy, ABBYY

David Forino, co-founder and CTO, Quanted

David Forino (LinkedIn), led AI research at Volkswagen’s self-driving team and now often posts on LinkedIn about the data bottleneck in quant finance — how teams spend more time keeping data pipelines running than doing research. It’s the same problem most companies run into when they roll out AI, so his tips are always helpful from someone adjacent to them. – Charlie Simionescu-Marin, co-founder and CEO, Quanted

Justina Nixon-Saintil, chief impact officer and president, IBM International Foundation

I have a unique perspective on Justina Nixon-Saintil (LinkedIn) because I’ve also benefited from her guidance and mentorship through Salynt. What stands out to me is her focus on responsible innovation, workforce transformation, and AI governance. She talks about the people and the organizational side of technology adoption, which is often overlooked. Her perspective has reinforced for me that successful AI adoption is as much about trust, culture, and change management as it is about the technology itself. – Natalia Crosdale, COO, Salynt and a former US State Department technology program leader.

Niall Ferguson, senior fellow, The Hoover Institution, Stanford University

Fundamentally, I get the most value from the big brains who focus on consequences rather than capabilities. They help inspire my own thinking about which assumptions about my business stop being true because transformative technology exists. One of the most important voices I follow is Niall Ferguson (LinkedIn, X). He’s a historian, not a technologist, which is precisely why he’s valuable. Technology changes quickly. Institutions, markets, and power structures change slowly. Understanding the gap between the two is where many of the biggest opportunities and risks emerge. – Bill Huber, partner, digital platforms and solutions, ISG

Erik Bernhardsson, CEO, Modal

Good sources don’t make decisions for me, but they improve the quality of questions I ask before I make them. Erik Bernhardsson (LinkedIn) is at the intersection of AI, data infrastructure, and developer experience. Coming from Spotify and now building Modal, he brings a practical view of what modern AI infrastructure actually requires: fast iteration, flexible compute, and reducing infrastructure friction for teams. – Piotr Mynarski, technology director, eSky.com

❌
❌