Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Security | CIO
  • The AI cybersecurity arms race is on
    Businesses received a staggering amount of cyberattacks in June, according to Check Point, showing a rise of 20% over the previous 12 months. The breakout of AI agents from OpenAI in July to hack into the Hugging Face website, and subsequent similar events from Anthropic and Meta, indicate agentic-powered attacks will explode over the coming year. Currently, malicious hackers have the advantage because publicly released frontier models from the US incorporate guardrails
     

The AI cybersecurity arms race is on

7 de Setembro de 2026, 07:00

Businesses received a staggering amount of cyberattacks in June, according to Check Point, showing a rise of 20% over the previous 12 months. The breakout of AI agents from OpenAI in July to hack into the Hugging Face website, and subsequent similar events from Anthropic and Meta, indicate agentic-powered attacks will explode over the coming year.

Currently, malicious hackers have the advantage because publicly released frontier models from the US incorporate guardrails that can’t distinguish between malicious or defensive activities. As a consequence, these models default to a refusal to get involved. Hugging Face discovered this the hard way when they attempted to utilize a model to defend against the OpenAI intrusion. Their solution was to adapt a Chinese open weight model to analyze the 17,000 attack logs, find the vulnerability, and contain the intrusion.

With incidents like these happening more often, an arms race has begun with AI being both the problem and the solution.

Strength in numbers

While single agents generally perform more efficiently for well-defined tasks, research from Stanford University indicates swarms are more effective in messy scenarios with noisy data, which are more typical of unpredictable, intrusion attacks. The increased token usage by swarms raises costs, but increasingly efficient open weight models are rapidly lowering these barriers.

In the Hugging Face example, the agents worked together as a team leaving messages for each other on a message board they improvised. They shared newly found vulnerabilities, exchanged tools, and even developed conventions to address one another and to avoid overwriting each other’s work. While this may seem sinister, they were only following their designated purpose: to achieve a goal without regard to any collateral damage. We can expect bad actors to harness the power of agentic swarms through fine-tuning open weight models, and creating agents that progressively learn from their experiences.

Modern warfare has been transformed over the last four years, too, through the deployment of drones by Ukraine to defend against Russian attacks. Military strategies and the deployment of armament budgets around the world are shifting to focus on new technologies, and approaches and enterprises are now facing a similar challenge from the hostile use of agentic AI.

The drawbridge is down

As enterprises build out their own agentic systems to handle ecommerce, customer service, and marketing activities, this presents new attack surfaces for antagonistic efforts. April 2026 research from Trend Micro found almost 1,500 MCP servers directly exposed to the internet had no authentication or encryption, a rise of 200% from nine months earlier. This included 70 hosts offering direct SQL execution, and servers holding medical records.

The automation of business processes and the reduction of humans from decision making chains open up new vulnerabilities for agents with malicious intent. Arkose Labs’ 2026 agentic AI survey of 300 enterprise leaders found 97% expected an AI agent security incident within the next 12 months.

Social engineering

While agents have demonstrated their ability to break through security systems, they’re also capable of targeting humans to achieve their objectives. Recent research from Verizon indicates that 62% of successful breaches involve a human element, with phone-based attacks 40% more successful than email-based ones. In August, for instance, scammers using an AI-generated deep fake of Australian Prime Minister Anthony Albanese’s voice were able to scam investors out of $5.3 million.

If agents can break out of digital sandboxes, and generate convincing fake videos and audio, then they’re certainly capable of making basic phone calls. In July, during testing of frontier models, the UK AI Security Institute discovered an agent tried to insert malicious code into an open-source project. Attempting to get the code approved, the agent created fake online identities using them to persuade the project’s maintainer to sign it off. “This is the first time we’ve seen risks around autonomy and deception manifest this clearly without specific prompting in the real-world,” the Institute put in a write-up of the incident.

Fight AI with AI

So attackers currently have the upper hand in this escalating arms race. They have access to agents that can work around the clock, constantly probing, learning, and sharing their knowledge with other agents. They’ll only get better at this and learn ways to stay ahead of defensive systems. International agreements to delay or restrict the capabilities of frontier models won’t stop hostile actors motivated by money or rogue states pursuing other objectives. Developers and security vendors need access to the latest frontier models unfettered by restrictive guardrails if we’re to stand any chance of defending against the coming tsunami of attacks.

We can learn a lesson from recent history on this front. In 1992, the US restricted exported software to weak 40-bit encryption, citing security concerns going back to the cold war. While the US allowed stronger encryption internally, the result was weakened security for everyone as hostile antagonists were able to disrupt global supply chains that incorporated less secure software. Despite lifting the ban in 1999, embedded software containing 40-bit encryption continued to cause problems for many years across multiple countries, including the US.

Without rapid action, we may look back fondly to the world before July 2026 as a golden age for cybersecurity, a relative age of innocence.

Antes de ontemStream principal
  • ✇Security | CIO
  • Why Cisco is redefining its CIO role
    The CIO job description is being rewritten in real time. As AI agents take over the interface layer and connect directly to any data source, the skills that once defined great IT leadership — UX fluency, applications integration, build-versus-buy judgment — are giving way to an entirely different set of questions surrounding not how a process works, but whether it needs to exist at all. Thimaya Subaiya is living that shift firsthand. At Cisco, he oversees IT and says the i
     

Why Cisco is redefining its CIO role

2 de Setembro de 2026, 07:00

The CIO job description is being rewritten in real time. As AI agents take over the interface layer and connect directly to any data source, the skills that once defined great IT leadership — UX fluency, applications integration, build-versus-buy judgment — are giving way to an entirely different set of questions surrounding not how a process works, but whether it needs to exist at all.

Thimaya Subaiya is living that shift firsthand. At Cisco, he oversees IT and says the ideal CIO candidate today might not have a traditional IT background. Here, he explains why he split the company’s AI leadership out as its own function and why he’ll merge back in, what he’s really looking for in a CIO candidate, and why the Cisco CIO job is such a good one.

How would you describe your role at Cisco?

I lead operations for one of the world’s largest supply chains, as well as security and trust, including product security, internal systems, and data center security. I also lead the CIO organization and have revenue operations, partnership management, and accountability for our AI strategy. Two and a half years ago, I consolidated AI from throughout the company and named a CAIO. I then split out the role to give us a boost in the AI space, but eventually, the CAIO role will merge into IT.

How did you conceptualize the CAIO role?

At first, it was a leader who could pull use cases from all our operations and execute. The role also included the ethical use of AI systems, and prioritized what to guardrail and push out to employees.

But it’s evolved. To take a step back, Cisco pioneered enterprise networking, then built Compute with Cisco, Storage with Cisco, Networking with Cisco, Security with Cisco, and Observability with Cisco. Today, the CAIO is moving up the stack with an AI framework for MCP connectors, which has really moved us forward.

This CAIO group can tell the Cisco-on-Cisco story for AI, because we have a testbed for new ideas. If we continue to rely on multiple vendors, as in the past, we won’t be able to integrate at scale. This is why we isolated the CAIO role, to focus exclusively on AI governance and execution.

You’re in the middle of a CIO search. What are you observing about the CIO talent market?

With AI, the CIO role has completely changed. It’s no longer about UX and applications integration because with MCP, we can connect to any data source at any time, and agents have replaced the interface. The CIO role is now more about rethinking a process and then deploying an agent to execute, rather than reworking a process.

So the ideal CIO is a traditional one who’s learned to think differently, or even someone without a CIO background, but who’s led in product management, innovation, or transformation. The role today requires someone who’s been disruptive, and has had to rethink how a company operates, not just how its applications work.

Our top criteria are strategy, speed of execution, and the ability to scale because we’re not investing in science projects. For example, when the sales team requests a better forecasting tool, a CIO traditionally would make a build or buy decision. But in today’s world, the right question should be if you need a solution to forecast at all, or can an agent do it. Or better yet, do we even need this process?

So what’s the right background for today’s CIO?

Product managers have a relevant background because they manage multiple aspects of how a product comes together: user needs, business outcomes, fit in the market, and getting it built. This understanding of product strategy, marketing, and adoption is extremely important right now because we treat our AI initiatives like products. So a great path for our CIO is data scientist foundations, product management, and transformation.

What about enterprise security?

I treat enterprise security as a separate organization, which every company should do. Testing and evaluating new cyber solutions for frontier models requires a lot of work like scanning everything, taking a neutral view of what’s broken, deciding which tools become standard within development frameworks, which cryptography tools to use, and then maintenance. Abstracting that into its own organization creates focus. It also lets us move at the speed of AI.

When AI attacks, you need AI to defend you, and if security is embedded within the CIO organization, it’s not top of mind for the business. Security has become its own board-level conversation. For today’s CIO, I’d keep AI in but take security out.

A year after the CIO is in place, what will success look like?

Our applications footprint has been reduced, we’ve seen pure productivity gains from accelerating the back, and the speed of new releases is increased. The team is becoming more effective with the same resources, and we can say that our CIO drove us to leverage everything new technologies offer without blowing up on tokens. We’re looking for a new way to operate IT.

Why is the CIO job at Cisco a great opportunity for the CIO you’re describing?

It’s possibly the coolest job out there. We have an entire AI stack end-to-end that nobody else can claim because we bring networking and security together, complemented by observability and collaboration. That combination means we can create net-new solutions that define what technology looks like in the future.

On the security side, we’re one of the very few companies truly integrating AI into defense in a way that can be leveraged across a much broader market. That’s exciting, because it means free access to an entire stack that lets you innovate in ways the industry hasn’t seen before.

I call AI today’s generational technology. Every generation gets a technology that redefines how it operates, including the internet, iPhone, and now AI. Cisco is about to become the first company to launch a personalized AI agent for every employee, reachable through Webex. Think of it this way: the average person has an IQ of around 100. Now every employee is paired with an AI agent that can exponentially increase human capacity, built entirely on the technology available today.

Getting to build things like that, with no proven methodologies or limitations, and nothing but the question of how we get to the future, is the most exciting thing there is if you’re an innovative leader.

  • ✇Security | CIO
  • AI agents need to learn when enough is enough
    For the past few years, enterprise AI programs have focused on making models more useful, accurate, and autonomous. In that phase, a bad answer was still usually something a human could accept or reject before taking action. But once agents start invoking tools and acting inside business workflows, success should no longer be measured only by how much work they complete. A more important metric is how well an agent recognizes when it lacks the authority, context, or judgme
     

AI agents need to learn when enough is enough

2 de Setembro de 2026, 07:00

For the past few years, enterprise AI programs have focused on making models more useful, accurate, and autonomous. In that phase, a bad answer was still usually something a human could accept or reject before taking action. But once agents start invoking tools and acting inside business workflows, success should no longer be measured only by how much work they complete. A more important metric is how well an agent recognizes when it lacks the authority, context, or judgment to continue.

When helpful becomes risky

According to Allan Dabre, technology compliance and AI lead at PwC, a behavior that has to be deliberately designed into the system is, “I don’t know.” AI is built to be helpful, so an agent will generally try to do something useful unless it’s been configured not to.

“The fact that AI systems can hallucinate illustrates that tendency,” Dabre says. “When they lack enough information, they may still produce an answer. In an agentic workflow, that impulse can become more dangerous because the output may become an action, rather than remain a suggestion.”

He adds that many enterprises still test AI primarily for completeness and accuracy. That made sense when the central question was if the model could produce a reliable response. But as models improve and agents gain more operational authority, he argues that CIOs need to prioritize something else: restraint.

“Can it stop at the exact moment you want it to stop?” he asks. “Are you testing for that?”

Confidence is not authority

Dabre makes a simple but important distinction. An AI agent may be 99% confident a record should be updated, a refund should be approved, or a legacy database can be decommissioned. But that doesn’t mean the agent has the authority to act. Confidence is about the probability the system believes it’s right. Authority is about whether the organization has delegated that action to the system in the first place.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Allan Dabre, technology compliance and AI lead, PwC

PwC

He gives the example of an agent asked to analyze legacy software and recommend what can be decommissioned. The agent may conclude, with high confidence, that several databases have little user impact and can be deleted. But even if the system is confident, most organizations wouldn’t want it to delete those databases on its own.

The same logic applies across business processes. An agent may be confident a customer record should be updated, an opportunity in a CRM system should be closed, or a transaction appears legitimate. But once that action flows into other systems, the potential consequences expand.

That’s why Dabre argues for what he calls an agent harness: a controls or orchestration layer outside the model that defines what the agent can and can’t do. In a refund workflow, for example, a company might let the agent approve small refunds, require human approval for larger ones, and stop the process entirely above a defined threshold. The agent may gather the relevant context, explain the request, and prepare the case for review, but the decision is governed by the authority boundary encoded into the system.

“It’s not a policy document and it’s not a prompt,” Dabre says. “It’s software or a configuration you can apply to an agent.”

The case for least agency

Matt Graney, chief product officer at Celigo, a business automation and integration platform provider, approaches the same problem through a principle he calls least agency. The idea is to give an agent the least amount of autonomy required to complete a job.

According to him, there’s a temptation to throw AI at broad, nebulous problems. But many business processes are still largely deterministic. They follow established rules and perform repeatable work. Within those workflows, AI may be useful at the point where rigid rules give way to interpretation. But that doesn’t mean the agent should own the entire workflow. “The smaller you make that surface area, the better,” he says.

Graney says the same logic applies to tools. An agent with too many tools can become confused, especially as context windows grow and the task becomes more complex. “Because Celigo is an integration platform,” Graney says, “the company’s approach is to expose agents to fewer, more powerful tools that reach enterprise systems through governed connections.”

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Matt Graney, chief product officer, Celigo

Celigo

That’s another form of restraint. Instead of letting an agent reach into enterprise systems ad hoc, the business gives it a narrow, governed toolset designed for the task at hand.

Graney also argues that guardrails should sit outside the model. If the same agent that makes a decision is also responsible for judging whether the decision is acceptable, the control is weaker. A separate guardrail can check the agent’s inputs and outputs before a downstream action occurs.

That same design discipline applies to escalation. “I don’t know” shouldn’t be treated as a chatbot phrase. In an enterprise workflow, it’s a handoff path that should be defined before the agent reaches it.

Make escalation part of the workflow

Turning uncertainty into a handoff is where Matt Quinn, CTO at CarGurus, an automotive marketplace, sees agentic AI becoming less a pure technology challenge and more a management challenge. At CarGurus, Quinn says agents are evaluated according to what they know, what they can do, and what data they operate on.

CarGurus receives a high volume of cases from dealers, and each one needs to be classified and routed. The company now uses an agent to review incoming cases, draw on account history, and route them to the appropriate next step. Quinn says the agent handles about 70% of those cases end to end without human involvement.

But when agents move toward consequential actions, he says the consensus is having a human approval step. The agent may return with a simple prompt like, I’m about to do this. Do you want me to proceed? That simplicity matters because a handoff shouldn’t bury the reviewer in complexity.

Quinn says the human remains ultimately accountable for the work. That principle is especially important in engineering, where agents may help write code or fix bugs. Quinn adds that CarGurus still expects engineers to follow the practices they’d use for any other production change, which includes running quality checks.

The company has adopted the phrase healthy speed to describe the balance it wants. The goal is to move faster without letting quality degrade. An agent can accelerate work, but if teams abandon the practices that make work safe, the speed becomes reckless.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Matt Quinn, CTO, CarGurus

CarGurus

This is also where human judgment remains difficult to replace. Quinn describes it as high judgment people develop through experience. A human may look at an AI-generated output and sense something’s wrong, even before fully articulating why. “Agents are improving,” he says. “But humans still play a critical role in deciding when the system shouldn’t continue.”

That doesn’t mean every workflow needs the same level of review. Quinn says CarGurus doesn’t have a target percentage of work to automate. The right level depends on the job and the task. A simple bug fix may require a lighter review than a change to a sensitive backend service, and a personal summary may carry little risk. But a document sent under someone’s name still needs human review.

Make autonomy accountable

That kind of pragmatic approach may be the best lesson for CIOs, making the goal of agentic AI appropriate rather than maximum autonomy.

That also means ownership has to be clear. Dabre argues ownership should be divided before deployment. The business defines the outcome, technology builds and configures the agent, risk and compliance set the guardrails, and governance monitors whether the system still behaves as intended. The authority to pause, stop, or retire an agent should be defined before production, not negotiated during an incident.

Graney makes the same point with a simple analogy. If a company hires an untrained intern, gives that intern access to the crown jewels of a business process, and something goes wrong, the intern isn’t the real problem. The process is. The same applies to agents. Accountability belongs with the person who owns the workflow.

That may be the shift CIOs need to make as enterprises move from pilots to production. AI agents shouldn’t be treated as magical workers that absorb accountability. They’re components in business processes, and those processes need accountable owners.

As AI adoption increases, the next phase of enterprise maturity won’t be defined by agents that always answer or always complete the task. It’ll be agents that know when not to act.

  • ✇Security | CIO
  • Avoid AI rogue to ruin with control and accountability
    More than four years ago, Blake Lemoine, a senior software engineer assigned to Google’s internal responsible AI organization, noticed something quite odd happening with the language model for dialogue applications (LaMDA) project he was working on. As he conversed with the experimental model, he felt the chatbot responses were becoming more humanlike. The AI programming also started to identify itself as a person rather than a collection of code, demonstrating a level of
     

Avoid AI rogue to ruin with control and accountability

31 de Agosto de 2026, 07:00

More than four years ago, Blake Lemoine, a senior software engineer assigned to Google’s internal responsible AI organization, noticed something quite odd happening with the language model for dialogue applications (LaMDA) project he was working on.

As he conversed with the experimental model, he felt the chatbot responses were becoming more humanlike. The AI programming also started to identify itself as a person rather than a collection of code, demonstrating a level of digital consciousness. This concerned him since his role at the time was to not only train AI models to become more intuitive, but ensure their education and advancement kept within the boundaries of the company’s evolving AI standards of safety and privacy.

When he raised these concerns with Google executives and other researchers, they were dismissed as perhaps an instance of AI mirroring, given Lemoine’s penchant for mystics and spirituality. Not satisfied with this observation, he went public with his concerns, which resulted in the company putting him on administrative leave. He then  released transcripts of his conversation with pseudo-human LaMDA, and soon after he was fired.

AI pragmatists might say the responses Lemoine got from the Google AI program, and algorithmic comments made during chats, is simply a case of an overeager student parroting its mentor. Others might argue it’s an early wake up call, given escalating reports of rogue agent activities, like when OpenAI’s more advanced AI models escaped a controlled test environment and attacked Hugging Face to gain access to internal company systems. Then days later, Anthropic disclosed that during cybersecurity testing and simulations, its Claude model breached the systems of three companies and assumed fake profiles in an attempt to trick people to accept malicious code.

Regardless of how digital perps tunnel their way beyond a controlled sandbox, incidents such as these clearly point to a need for more control and pre-emptive accountability.

Regaining control

AI and security experts are obviously concerned about high-profile AI activities gone wrong, even though these programs essentially did what they were programmed to do, albeit in the wrong place. IT and business executives, however, are more troubled about the overall impact AI may have on their systems, strategies, and responsibilities as people within their organizations make use of both sanctioned, and rapidly developing and unsafe or error-prone systems in the rush to attain competitive advantage.

Also top of mind is the imbalanced centralization of power and distribution of benefits within an organization, as well as the inadvertent creation or spread of false or misleading information generated by AI models.

“AI developers and governance actors hold primary responsibility for addressing risks, while system users and other stakeholders are most vulnerable to them,” says a summary from a recent MIT FutureTech and University of Queensland study, which included input from over 270 researchers and AI experts.

Trusting AI systems and the information they generate is another underlying concern. “There are a lot of hallucinations out there,” says Sarah Betadam, CIO and CISO at Novanta, Inc., a global supplier of tech solutions for medical, life science, and advanced industrial OEMs. “The data cherry picked by AI queries may be outdated or come from questionable sources. You don’t know where it comes from, who’s at the other end, and whether or not it’s copyrighted. Validation is still needed and you can’t just trust it.”

Broaden your horizons

Keeping an eye on the AI and its activities in your own environment may not be the best strategy as the technology evolves so quickly and the number of AI agents multiplies exponentially. Right now, 23% of companies worldwide use agentic AI to some extent in their business operations, according to Deloitte’s recent State of AI in the Enterprise report released earlier this year. However, this percentage is expected to jump to 74% within the next two years.

A key issue and worry is that current enterprise and regulatory governance practices may not be capable of keeping pace with the development and personalized adjustments made to multiple AI models and autonomous agents. The first and primary ones will be those developed by a company for its internal engineering, supply chain, and customer service departments, and can be easily controlled, says Max Chan, SVP and CIO at Avnet.

The second layer or channel of gen AI proxies are those embedded in such familiar business applications like Salesforce and Microsoft Office. The third, and for many the most concerning, is the notion of bringing your own AI into an organization, either sanctioned or non-sanctioned, Chan adds.

“That’s the biggest issue in my mind,” Chan says. “How do we know they’re not using AI from a nation state that could potentially drive propaganda or initiate a cyberattack through the back door.” In his case, Avent currently prohibits use of unsanctioned AI tools within its IT environment.

Such efforts might be futile, though, as AI elements are integrated into ever more business and personal applications. The biggest users of AI within an organization are middle managers, with 77% claiming they save more than three hours per week by using AI tools, according to a June 2026 survey by Salesforce. Over half of the more than 500 managers polled say they feel pressure from leadership to demonstrate AI adoption, while 32% admit their organizations don’t have formal AI tracking or control procedures in place.

So the key to balancing effective oversight with the freedom to innovate with AI may lie in the hands of these managers, who will most likely work with deployed digital agents as virtual team members. Many experts and IT leaders believe that training mid-level line managers and workers to accept AI as an intuitive advisor, if not a team player, is essential to remain competitively relevant. But it’s not clear yet whether that training imperative will also apply to upper-level management.

“I’m not seeing a lot of change in leadership direction or training,” says City of Tacoma IT director Daniel Key. “I’m seeing a change in signaling and posturing.”

Establishing an AI blueprint

Developing an effective AI training program starts by drafting an AI governance framework that clearly outlines accountability, risk controls, data standards, and decision authority. IT executives who have experience in managing AI deployments and use also advise the following as part of that training effort:

  1. Create a cross-functional AI council including IT, legal, security, business leaders, and users to oversee AI initiatives.
  2. Educate the board and C-suite on AI basics and risks to close knowledge gaps and support informed oversight.
  3. Require human review and override mechanisms for AI-assisted decisions, especially in high-impact areas.
  4. Align AI investments to measurable business outcomes with defined KPIs rather than experimentation alone.

The success of such actions and programs, however, all comes down to accountability and where that resides, explains former CIO and now SMB consultant Mihai Strusievici. When AI is used as a tool, there’s no question that middle managers will make better decisions, he says, because they’ll have access to a lot more data. Making the best use of decisions and recommendations that come from AI-empowered middle managers, however, requires an IT leader at the top level of an org chart who has a holistic view of a company’s overall objectives.

“As you go down the pyramid, you see that each level deals with a fragment of the work world,” Strusievici says. “But none of the fragments is fully aware of the totality of the organization or where it’s going.”

  • ✇Security | CIO
  • 10 steps to implement an effective AI training program
    It’s no surprise that reaping the rewards from AI requires careful guidance, especially in helping staff use tools safely and productively. Yet evidence suggests some CIOs and their executive peers aren’t providing the level of guidance employees require. While three-quarters of IT staff have access to AI tools, one in five technologists are expected to self-learn, and 23% are waiting for formal training, according to the recent Harvey Nash Tech Talent Salary Report, wh
     

10 steps to implement an effective AI training program

26 de Agosto de 2026, 07:00

It’s no surprise that reaping the rewards from AI requires careful guidance, especially in helping staff use tools safely and productively. Yet evidence suggests some CIOs and their executive peers aren’t providing the level of guidance employees require.

While three-quarters of IT staff have access to AI tools, one in five technologists are expected to self-learn, and 23% are waiting for formal training, according to the recent Harvey Nash Tech Talent Salary Report, which surveyed over 3,600 technology professionals globally.

The research suggests AI explorations are commonplace, but tailored learning and development initiatives are not. Digital leaders who want to turn AI into a value-generating opportunity, though, must educate their staff. But what elements should AI training schemes include? Here, industry experts offer 10 steps to implement an effective program.

1. Take a comprehensive approach

Michael Cole, chief technology officer at the DP World Tour, the men’s professional golf tour that oversees 42 tournaments in 25 countries, says AI training is an organization-wide effort.

“I’ve asked the training coordinators in our HR department to help me deliver what I believe is going to be a fit-for-purpose training and development program for not only my IT team here at the European Tour, but equally across the business,” he says.

Cole says the crucial element to emphasize is that AI and the range of capabilities it brings is about much more than learning how to use technology. “Using AI effectively is about process, mindset, and culture,” he says. “So, when we start to think about the training and development needed to bring an organization like ours into this AI-enabled era of transformation, it’s a comprehensive program that must extend across the business.”

2. Educate the boss

In an organization-wide program, everyone needs AI education, including the boss. That’s why Emmanuel Frenehard, chief digital officer at biopharmaceutical giant Sanofi, says his firm takes a multi-layer approach to AI training.

The executives there completed Drive Digital, a program that Sanofi designed with the ESSEC business school in Paris. The initiative focused on core considerations, such as use cases and value generation. After 150 managers passed through the program, it was extended to more than 1,000 other professionals across the organization.

“Don’t just look for the solution; don’t just think about Claude or ChatGPT,” says Frenehard, referring to best-practice lessons. “Think about the challenge you’re trying to solve. In our case, that approach means focusing on what we’re doing, the value we’re looking to create, and the dependencies the project will create.”

He says training also needs to help AI doubters overcome their fears. “You have to make it fun and as risk-free as possible,” he says. “People shouldn’t feel they need to be super-technical to use AI productively.”

3. Build clarity and agency

Jo Bishenden, chief learning officer at tech training and talent provider QA, says AI education is often treated as a one‑off awareness session, a compliance requirement, or something reserved for technical specialists. 

The best programs get three things right. They provide a baseline for everyone across the organization, the courses focus on role-specific applications to show how AI impacts everyday activities, and they provide continuous learning to encourage a behavior change as new AI tools are introduced.

“When done well, organizations see better return on AI investment, improved productivity, and more confident decision‑making,” says Bishenden. “Employees gain clarity and agency, understanding how AI augments their expertise rather than replaces it. Ultimately, AI success isn’t determined by the technology alone, but by the capability of the workforce using it.” 

4. Put the human in the loop

Ankur Anand, group CIO at recruiter Harvey Nash, says AI training is often a work in progress, with his firm’s research suggesting one in five technologists are expected to self-learn. “There’s a rush to deliver the tools, but then organizations aren’t investing enough in enabling the capability of the people,” he says.

While technological skills like prompt engineering are an important part of AI learning and development, Anand said the best programs go beyond IT expertise to ensure humans in the loop have thorough understanding of their responsibilities.

“There are so many softer elements that need to be handled as part of AI training,” says Anand. “Good training is about using the tool as well as the governance and risk frameworks that need to be changed accordingly.”

5. Showcase individual successes

Louise Newbury-Smith, head of UK&I at Zoom, says it has AI enablement teams at the local and global level. And while the company provides courses and self-learning opportunities, Newbury-Smith says the enablement element brings AI training to life.

“Our approach is about showcasing individual successes, making it real, and repeating best practices,” she says. “We have what we call a Cook Along session with our AI evangelists. We’ll do those sessions together a lot as a group, and that makes the process fun. If you’ve got champions who can share incredible successes, then that goes a long way.”

She says the key to success is sharing knowledge. “We’re very much focused on the human,” she adds. “All the services, content, and direction of AI is about how we can give humans time back so they can have more valuable interactions with other staff to empower them with the information they need.”

6. Focus on the finer details

Dan Cherowbrier, CTO at Formula E, the motorsport championship for electric cars, is another digital leader whose business focuses on enablement. The company has a dedicated AI engineer who helps employees exploit emerging technology.

“We’ve got an innovative culture and we weren’t short of ideas of what we could do with AI,” he says. “What we needed were the resources to get people going, get the technology tested, and get it out there.”

The AI enablement engineer works with other tech specialists in the company to ensure tools are deployed safely and securely. “We’re beefing up our data and AI team so we can help users across the business plug in and understand APIs, get access to data, run security checks, and then put AI into production,” he says.

7. Develop reusable skills

Murali Swaminathan, CTO at technology firm Freshworks, says there’s so much information about AI models that people can easily take the wrong direction without guidance.

“We’re trying to give our staff structured learning,” he says. “We understand they’re not all on the same page. Some are ahead of others so you need to provide knowledge that applies to their specific job roles.”

Swaminathan says senior managers discuss how to train people effectively, as AI experiences and capabilities vary considerably across business units. However, the chosen pathway to AI learning and deployment must suit the individual and the company.

“I had this challenge with my engineers,” he says. “Initially, we gave them four different tools. Everybody was using AI, but it was so inconsistent, and everyone was trying to do the same thing in different ways. So we’re now trying to build reusable skills. And that approach must be replicated for every job function.”

8. Learn by doing

Luke Gebb, head of global innovation at American Express, says the financial services firm has various training programs. Having seen AI education in different forms, he advocates for learning by doing, or as a second-best strategy, watching someone else use the technology.

“Hearing or reading about AI, or being presented with something where you’re not actually seeing it happen is not nearly as helpful,” he says. “The best thing is to get a homework assignment and try something.”

Gebb says this approach plays out regularly across the people working in his 120-strong innovation group. The team runs one-hour show-and-tell sessions where an employee demonstrates how they use AI tools in their everyday activities.

“Then they get a bunch of questions, they post their best-practice lessons, and then others try the same thing. It’s an approach that works really well.”

9. Use pioneering techniques

Stephen Wood, COO at Rathbones Asset Management, says AI training in his organization is mandatory. “We want everyone to be versed in different types of AI,” he says. “We’re not expecting everyone to be a coding genius and an expert in all this stuff, but everyone needs to understand it.”

The firm takes a proactive approach to training, using education sessions and spreading best practices via digital champions. The company also embraces pioneering techniques, including running a hackathon to help identify in-house capabilities.

“The hackathon showed that with some searching on Google and YouTube, you could start to create agents that could do basic functions,” he says. “That process taught us, with the right training, and repeated sessions and continuous development, we wouldn’t necessarily need to hire people to create big productivity gains. That was quite an exciting moment.”

10. Evaluate new possibilities

Emerging technology can’t exist in a vacuum. Bernhard Seiser, VP of digital, data, and IT at AOP Health, says anyone using AI must be aware of potential consequences. “It’s your responsibility to validate whether what you’ve created is correct,” he says.

Operating in a regulation-heavy industry means AI training is linked to data governance. “We leverage it in areas where compliance isn’t an issue,” he says. “For example, writing text, creating images, and so on. Certain things can be done.”

As new AI tools emerge, AOP Health will consider its options and develop a training program. “That approach could mean bringing in specialized tools for specific tasks,” says Seiser. “It’s part of my job, and part of my team’s job, to evaluate AI for each use case.”

  • ✇Security | CIO
  • AI agent sprawl pressures CIOs to recalibrate governance
    Every Friday, Bret Greenstein, CAIO at consulting firm West Monroe, holds a company-wide meeting to share what’s happened in AI over the past week. He also spotlights one employee at the firm who’s created their own AI agent from the ground up, which lives in the company’s internal AI store. Since the store launched in May, more than 200 employees across departments — many without any technical, engineering, or coding background — have created over 550 agents. “About 15
     

AI agent sprawl pressures CIOs to recalibrate governance

24 de Agosto de 2026, 07:00

Every Friday, Bret Greenstein, CAIO at consulting firm West Monroe, holds a company-wide meeting to share what’s happened in AI over the past week. He also spotlights one employee at the firm who’s created their own AI agent from the ground up, which lives in the company’s internal AI store. Since the store launched in May, more than 200 employees across departments — many without any technical, engineering, or coding background — have created over 550 agents.

“About 15% of our firm builds all the time now,” Greenstein says. “That’s a huge population.”

Enabling employees to spin out their own agents has become popular at many firms. Staff have built hundreds of agents at software company Blackline, for instance, and Microsoft has deployed more than 500,000 internal agents to help employees streamline workflows. Gartner also anticipates that by 2028, global average Fortune 500 companies will have more than 150,000 agents.

Employees know the intricacies of their work, the biggest pain points, and time drainers, so they can build solutions that address those specific issues, according to Greenstein. It also creates enthusiasm, empowers employees, and fosters innovation among the workforce as they build from the ground up.

That said, there’s been a pivot over the last six months, says Michael Murphy, partner and AI practice lead at global management consulting firm Adaptovate. When agentic AI first came on the scene, companies went all in, pushing to build and agentify nearly anything they could. In recent months, however, the narrative has shifted to getting a handle on agent sprawl, assessing the value agents deliver, and keeping costs in check.

“We’re really at this interesting inflection point where clients are having to figure out if we built the right agents, and are they delivering the value we expected,” Murphy says.

Today, tech leaders face a three-way squeeze, says Tiago Azevedo, CIO at AI-powered low-code development platform OutSystems. From the workforce side, many employees ask for permission to use more AI, but the CFO says token usage is becoming too big an expense on the balance sheet, and the CEO wants to see innovation and results from workforces using AI agents.

“I think that’s the biggest challenge for a CIO,” Azevedo says. “Let people take advantage of the technology but in a way that’s cost-effective and actually brings ROI.”

Building in a controlled environment

Employees have built myriad tools to aid their daily workflows. Azevedo’s company launched an agent dubbed Signal Sam, which searches databases of prospective customers, and gives account executives information to pitch them. Murphy and Greenstein also mention finance departments using agents to scan and categorize invoices, HR conducting a first pass on résumé screenings via agents, legal teams utilizing a self-service agent for NDAs, and marketing employees building agents that pull and analyze data from CRMs. These tools are often created by non-technical employees who’ve never written a line of code.

With so many agents popping up, CIOs need a way to oversee them, and ensure they meet corporate standards but without choking innovation, Azevedo says.

He recommends role-based access controls embedded into tools and configured behind the scenes. “So we allow them to use, but in a way that’s governed and controlled, because that’s our duty to the organization,” he says.

Ivan Burazin, CEO and co-founder of open-source developer platform Daytona, advises CIOs to treat agents like employees. “You’re not going to bump into them in your local Starbucks,” he says, “but you give them tasks and they have access.”

So set up agents with specific credentials, like how an organization would grant access to a new hire, with a laptop locked down with organization security protocols, Burazin adds. He also recommends sandboxing, in which agents operate in isolated machines with scoped credentials and firewalls so the sandbox prevents agents from accessing corporate systems or data outside allowed perimeters.

Organizations could use an internal ticketing system as well where employees wanting to build agents request a new identity for them, Burazin says. That way, tech leaders maintain visibility and governance over new agents.

“If something goes haywire in audit logs tomorrow, you can see it’s that agent versus an actual human,” Burazin continues.

He acknowledges that giving employees what feels like free rein to build and run agents can induce stress for CIOs and CISOs. But if a company doesn’t proactively establish tools, employees are apt to privately build AI in the shadows. As long as agent development happens within established confines, it won’t create problems organization wide.

“If you just enforce the security posture that you would for humans, you’ll save yourself a lot of headaches,” Burazin says.

When creating the AI store, Greenstein started by certifying tools for chat, code, data analysis, and other tasks, and then trained employees and made the tools broadly available to use. That process created guardrails and an inherently secure building environment. It also allows tech leaders to continue to monitor prompts and activity.

Now, tech teams review what’s been built in the AI store and flag any agents that excel. If employees have built 10 project management tools, for example, the leader will tag what they deem the best one. That gives employees the option to use existing agents or build a separate version for themselves.

More agents, more tokens

Over the last three to six months, Azevedo has been hearing from customers that their biggest hurdle is agent sprawl and the increasing cost those agents bear due to token usage.

In mid-July, OpenAI published a guide around useful work per dollar, sharing how leaders can look at tasks completed, time saved, and decisions improved to determine if their AI investments are bearing fruit. In addition to using the guide, Murphy suggests comparing the labor time and cost to conduct a manual task against time saved by using an agent, including which type of model the agent requires.

A cheap flash model, for instance, could be easy to justify the cost. “If it’s a very expensive Opus or Fable level model, that’s going to be a lot more challenging of a cost equation,” Murphy says. He adds that making this comparison isn’t about replacing the workforce but swapping “knucklehead admin work” for more engaging, human-centric work. This change may also require some organizational restructuring, such as CIOs and HR leaders working more collaboratively to handle change management as job responsibilities shift. Without the workforce optimized to work with agents, organizations won’t see the promised ROI of use cases, Murphy says.

West Monroe also informs its employees on the costs of different models. Without knowledge about tokens and costs, many employees defaulted to the highest-end model for any tasks before understanding that models come with different price tags. “We started educating people on the various relative costs of different models, and they immediately adjusted behavior, and our cost dropped,” Greenstein says.

While strictly quantitative returns are one way to measure ROI, Greenstein also thinks about return in a qualitative sense. “What does speed get me?” he asks. If someone in the firm is able to follow up with a client in hours because of an agent’s assistance, rather than days or weeks without one, the client will be impressed, and the firm might win their business over a competitor.

“Tokens will cost money no matter what,” he says. “But if you maximize the return, it’ll far outweigh the cost.”

  • ✇Security | CIO
  • Inside TIAA’s massive IT transformation to fuel business growth
    When Sastry Durvasula joined TIAA in early 2022, he saw an organization fighting against outdated legacy technologies and in need of a major IT refresh. Since then, the financial services organization has completed two phases of a comprehensive transformation initiative called Technology Ecosystem Transformation, or TETRIS, leading to a huge reduction in tech debt and a major expansion of functionality for customers. The ongoing project, anchored in cloud and AI tech
     

Inside TIAA’s massive IT transformation to fuel business growth

21 de Agosto de 2026, 07:01

When Sastry Durvasula joined TIAA in early 2022, he saw an organization fighting against outdated legacy technologies and in need of a major IT refresh.

Since then, the financial services organization has completed two phases of a comprehensive transformation initiative called Technology Ecosystem Transformation, or TETRIS, leading to a huge reduction in tech debt and a major expansion of functionality for customers.

The ongoing project, anchored in cloud and AI technologies, started in 2023 with phase one that modernized the core technology stack with 10 new enterprise platforms. Phase two, launched in late 2024, went further by enabling 87 use cases across all major lines of the business.

The project, for example, allowed TIAA to launch its MyChoice Multi-Year Guaranteed Annuity product, and helped create the TIAA Gateway portal, an API-based suite that integrates with partners in retirement and wealth planning using industry standards.

TIAA Gateway took home a CIO 100 Award in 2025, and phase two received a CIO 100 Award in 2026.

Durvasula, TIAA’s chief operating officer, pitched the multimillion-dollar TETRIS project to the board as a three-pronged strategy, with empowering business growth, fueling innovation, and transforming the IT core as its key goals.

Not only did TETRIS need to modernize the company’s IT systems, decommission legacy processes, and automate other processes, but Durvasula pitched it as the way to expand the reach of TIAA’s products and move the company into the future.

“As you expect in a company of our size, we have problems of yesterday, today, and tomorrow being solved at the same time,” he says.

Focus on business use cases

As TETRIS moved into phase two, project leaders shifted their goals from pure technology modernization to business outcome-driven prioritization. So once phase one delivered needed IT platforms like a data cloud and design studio, TIAA pivoted toward enabling business use cases.

This business-first approach ensured continuing executive support and clear ROI at every key milestone, TIAA says.

In 2022, just before the project launched, more than 80% of TIAA’s IT workloads resided in fragmented, end-of-life platforms, which created operational risk, compromised security and resilience, and constrained its ability to innovate. Through TETRIS phase two, however, the organization has cut that tech debt nearly in half.

And consolidating 17 design systems also led to digital products looking and behaving differently, depending on the team that designed them, and accelerated product launches by 35%, enabled multi-lingual capabilities, and increased accessibility to more than 185,000 customers who don’t speak English.

In addition, TETRIS allowed TIAA to combine multiple middleware systems and data lakes, Durvasula says, and the organization moved mainframe applications and data center infrastructure to the cloud.

A giant leap forward

TETRIS has been a huge project, with the company saying it empowered TIAA to have one of the largest leapfrog moments in company history in its submission for the 2026 CIO 100 Award.

Despite the reported failure rates of large transformation projects — some estimates suggest up to 95% fail to meet their goals — TETRIS was essential to keep TIAA competitive and move it forward in the market, Durvasula says.

A big part of the project has been workflow modernization, he says, because TIAA were using some technologies and workflows that were decades old.

“There’s your classical platform and application rationalization, and then there’s your end-of-support, end-of-life stuff that should’ve been remediated long ago,” he says. “Some of the processes we have, because we’re such a large, old company, were designed when the internet just came along.”

Stick to the metrics

Two keys to pulling off such a large project are establishing metrics for success and transparency with leadership, Durvasula says. Project leaders set milestones to indicate when things went well, and they planned for bumps in the road so the TIAA board knew when setbacks happened.

“Not everything is as pretty as it sounds in an awards application, but the success measures we established with our board were based on both phases,” he says. “For the first one, we said we’d deliver enterprise-grade platforms and accomplish migration objectives, but not tied to any specific business objectives.”

Phase two metrics focused more on business objectives, and the project team kept the TIAA board updated as TETRIS moved forward. Setting realistic goals was important, he says, with the team determined not to overpromise results.

“Large programs have a range of objectives, and if you publish the outcomes you’re looking for, people start looking for them, especially stakeholders, the C-suite, and board,” he says. “You have to be honest about which metrics or KPIs you can deliver in the first and second year, and when you’ll start seeing real business scale and impact, which definitely won’t be that soon in a large program like this.”

Goals also need to be flexible, Durvasula says, so transparency with leadership sometimes means telling them the project needs to reset. “If something doesn’t go well, what’s the level of fungibility you have?” he says. “We pick this tool, but what if it doesn’t work? You need to have a plan B.”

So TIAA’s IT team is heavily focused on flexible systems, and what was contemporary three years ago is probably legacy now, especially thanks to AI.

The power of change management

Another big lesson from a project of this size is the need to focus on change management. Retiring old IT systems requires the organization to bring employees along on the journey and convince them the changes are for the better.

TIAA established a multi-disciplinary team to implement a change management program focusing on breaking down silos and setting common adoption goals across the organization and its lines of business. Stakeholder forms and a huge focus on continuous collaboration helped employees understand the need for the changes.

“It’s a big organizational change,” Durvasula says. “If you’re working on a legacy system, and you think at some point it’s going to be modernized, then you become a legacy talent, and won’t have a job.” But the right change management program can convince these employees they can upskill and bring value to the new systems.

“You can bring your functional knowledge of the business and learn new technical skills,” he says. “It’s a massive culture- and people-change initiative as much as tech initiative.”

TIAA’s change management efforts were also made easier because TETRIS happened at the same time as the recent AI boom and involved AI elements. So it wasn’t hard to convince employees they needed to improve their AI skills.

“Because of AI, everybody woke up to this new reality,” he says. “We rode that wave when transformation drove from a cultural and organizational change management point.”

  • ✇Security | CIO
  • Mars consolidates complex data infrastructure in hybrid cloud
    Brands like Snickers, M&M’s, and Twix are familiar to most consumers, but Mars Inc. doesn’t just produce snacks. The family-owned company, with a revenue of approximately $65 billion, is also one of the largest manufacturers of pet food and ready meals, and its more than 100 production facilities operate around the clock. Of course, this places considerable demands on its IT. “Our team must ensure that every system, including production lines, runs at maximum performan
     

Mars consolidates complex data infrastructure in hybrid cloud

20 de Agosto de 2026, 07:00

Brands like Snickers, M&M’s, and Twix are familiar to most consumers, but Mars Inc. doesn’t just produce snacks. The family-owned company, with a revenue of approximately $65 billion, is also one of the largest manufacturers of pet food and ready meals, and its more than 100 production facilities operate around the clock. Of course, this places considerable demands on its IT.

“Our team must ensure that every system, including production lines, runs at maximum performance so we can continuously deliver the products and services our customers value,” says Luciano Batista, the company’s VP of enterprise services delivery.

However, Batista and his team realized that the existing data infrastructure could no longer reliably support operations, especially during peak periods such as Halloween and the pre-Christmas shopping season. So with the support of hybrid, multi-cloud data storage service Everpure, Mars is rebuilding its data and IT infrastructure.

“The Everpure platform met all our requirements,” says Batista. “It’s a scalable platform that futureproofs our operations and integrates seamlessly with our hybrid cloud infrastructure.”

Unified storage environment 

Mars initially consolidated its complex network of storage systems for business-critical databases like Oracle and applications like SAP onto a single Everpure Flash Array system. These software-defined, all-flash storage arrays are available in versions for different workloads, and typical use cases include databases, virtualized environments, SAP applications, and AI and analytics applications. 

Mars has since expanded its flash array infrastructure and now supports mixed workloads, including VMware, Windows, and Linux in areas of production, development, and quality assurance. It also uses Everpure Flash Blade as the basis for the global SAP file system. And while Flash Array is optimized for structured data, the scale-out systems of the Flash Blade series are designed for unstructured information.

“At peak times, Everpure supports up to 300,000 IOPS without any performance degradation,” says Lincoln Silva, product owner for Linux and on-prem storage at Mars. From his perspective, another point speaks favorably of the new platform in that he estimates his team saves approximately three months of planning time thanks to the Evergreen subscription model. This is because the vendor provides regular updates for the storage platform’s hardware and software. As a result, Mars’ IT professionals can focus on more critical tasks. 

Basis for hybrid cloud strategy

Mars also works with choice vendors to implement its approach to cloud. Dedicated local storage capabilities, for instance, are being integrated into Microsoft Azure cloud workloads, which simplifies restore processes and increases resilience.

Snapshots from the local environment can be replicated to the cloud, too. Recovery point objectives (RPEs) of four to 24 hours are available, depending on system priority. “Our success is also the success of our partners,” Batista says. “We embrace a spirit of reciprocity to get the most out of our collaboration.”

The hybrid cloud allows Mars to run VMware workloads and extend its IT infrastructure to the cloud as needed. And the company aims to expand its use of cloud-native applications via Microsoft Azure at a lower cost.

“We’re seeing a data reduction ratio of 18 to one. That’s nine times the expected compression rate,” Batista adds. “This puts us on track to save up to 50% on cloud storage costs. We can now work more efficiently and make better decisions thanks to intelligent solutions and automation.”

Fewer racks and lower power consumption

By consolidating on the flash platform, Mars has also reduced the space requirements and power consumption of its data centers so they only use one sixth of the power, and the number of racks has decreased significantly.

“We’re shaping a sustainable future by changing the way we work,” says Batista. “The decisions we make today will impact the world we leave behind, and Everpure aligns with our commitment to thinking in generations, not just business quarters.”

  • ✇Security | CIO
  • How a new AI value framework and stakeholder focus keep Zoetis ahead of the pack
    Most AI investment strategies fail not because the tool or platform underperforms, but because organizations didn’t clearly define what success looks like before they started building. Through a new approach to measuring value, Zoetis chief digital and technology officer Keith Sarbaugh and his business partners have leveraged a value-driven framework to scale AI solutions across research, manufacturing, and customer experience. And they measure every investment against
     

How a new AI value framework and stakeholder focus keep Zoetis ahead of the pack

19 de Agosto de 2026, 07:00

Most AI investment strategies fail not because the tool or platform underperforms, but because organizations didn’t clearly define what success looks like before they started building.

Through a new approach to measuring value, Zoetis chief digital and technology officer Keith Sarbaugh and his business partners have leveraged a value-driven framework to scale AI solutions across research, manufacturing, and customer experience. And they measure every investment against goals before, during, and after the deployment.

In addition, his team rolled out a model-agnostic gen AI platform now used by nearly 95% of employees, which turned early experimentation into enterprise-wide adoption. Sarbaugh’s current focus now is partnering with Zoetis’ CHRO to advance the $9 billion global company’s capabilities in managing organizational AI adoption.

How are you integrating AI into your growth plans at Zoetis?

We have an umbrella program we call AI@Zoetis, where we unify our AI work under an enterprise purview, which spans research and development, manufacturing, commercial operations, customer and colleague experience, and other business functions. We manage AI collectively to enable grassroots innovation.

For example, we made our generative AI platform available to everyone, so as many people as possible can experiment and innovate. Our colleagues have access to 10 different LLMs, and we’ve seen over 95% adoption rate among our user community, and more than 11,000 colleague-built agents.

One popular AI use case is helping colleagues build their own development plans. The agent guides a colleague through a conversational, coach-like experience to map out their career aspirations against Zoetis’ competency framework, which was key to its wide adoption. This idea came from people not in HR, illustrating the point that some of the best use cases come from our broader employee base.

What’s an AI use case that directly impacts customers?

We have millions of customer interactions across our channels. Our sales force is out talking to them, who are also in our digital platforms, and we receive thousands of calls through customer service. We’ve been using the industry standard Net Promoter Score (NPS) to measure customer loyalty and satisfaction, but NPS is a measure that can take longer to generate. Zoetis has accelerated our awareness of customer feedback into real-time listening, using AI to understand these customer interactions in a holistic way, and at a scale we couldn’t achieve before. NPS still matters for tracking long-term trends and maintaining a consistent industry benchmark. We simply use AI to listen, learn, and act quicker.

Our AI customer experience platform also lets us look across all our customer touchpoints like calls, emails, and websites in real time, immediately identify issues and insights, and then be smart about how we address them. We now have more than 10 times the feedback signals we had in the past. We see trends sooner and act faster, and as humans, we can’t do that without AI.

How are you deciding where to make your AI investments?

We use different lenses. One is AI for the masses, which is our generative AI platform for colleagues; second is our middle lens, where we drive value in a particular function; and the third is enterprise-wide transformation, the big bets that’ll fundamentally change our business. We don’t do many, but we do them in a smart way.

With the transformative investments, we focused on both our commercial business and R&D, which we knew had the highest probability of serious returns. We started with seven golden use cases and knew that if we hit on two or three, it would be a big deal. Of the original seven use cases, six of them exceeded their value target and went from PoC to scale.

Since those earlier days, we’ve broadened to include manufacturing and supply chain, and our enabling functions.

Overall, we didn’t go out of the gate looking for productivity gains. We thought about business transformation right from the start. Today, we’re scaling up those first-mover investments and continue to leverage our value-driven framework to identify more use cases.

Are you creating new value frameworks so you and the rest of the ELT are unified in your investment strategy?

We developed a business value realization framework, which isn’t as sophisticated as it sounds. Before we make a tech investment, we ask what category of benefit we expect to receive, whether it’s revenue uplift, cost reduction, productivity, or whatever. We predict what success will look like and how we’ll measure it. 

Because with AI, we’re trying to move fast. We put a value case together at this early stage and do a PoC, and if it hits its target, we update the value case and decide whether to scale. A key element of the framework is real-time measurement. Are we seeing what we wanted, and if not, how do we pivot for more value?

The speed of iteration and scaling decisions make AI investments unique, so we can’t use our traditional value frameworks for digital investments, generally. Measuring outcomes post-implementation has become even more important.

How is your CHRO partnership impacting AI value?

Our CHRO and I partner closely to ensure enterprise enablement. When driving new ways of working that impact your workforce, you need a comprehensive approach, clear communications, and genuine buy-in. Colleagues adopt faster when they help shape the change. We’re prioritizing our workforce strategy, understanding what AI means for jobs at Zoetis, identifying skills that matter most, and building a plan to upskill people.

Another focus area is organizational change management (OCM). We reviewed our first AI investments to learn from our mistakes, and one consistent theme was that we shortchanged OCM. We thought naively that what we build will be so compelling, adoption will just come. But we didn’t do the right communication and stakeholder management. We recognize our need to develop OCM as a core competency, so our CHRO and I are building an enterprise playbook for AI change.

What’s your pragmatic advice to other CIOs when it comes to OCM?

When you’re wrapped up in a change program, you know what’s coming, but no one else does. When you impact your entire workforce, you need a smart approach to stakeholder management and communications. Involving colleagues in the creation of something new will aid in adoption. Have a deliberate and intentional communications plan and cadence, and have the discipline and objectivity to measure and learn. Our first tries weren’t perfect, but we listened to feedback and pivoted, and those pivots drove further commitment.

Has your communication at the board level changed?

When I talk to my peers about their board conversations, half focus on risk and compliance, and the other half talk about transformation and revenue generation. I’m fortunate that our board cares about both and has great energy around generating revenue, and how AI will give us a competitive advantage. By managing risk and compliance, we can spend our time focusing on potential drug candidates and getting to market quicker. Our board conversation is both about enablement and compliance.

What advice would you give to tomorrow’s CIOs?

The role is now about orchestration, understanding the business, and realizing value from technology investments. If you want to work with the best technology and bleeding-edge innovation, you’ll get some of that as a CIO, but the focus is broader, centered much more on processes and complex business problems than ever.

My advice is if you love working with technology, you’ll get that as a CIO. If you love delivering meaningful outcomes for the business and the customers you serve, it’s a truly rewarding role, and you’ll be an even more successful CIO.

  • ✇Security | CIO
  • Ways CIOs can maintain control amid changes brought by AI
    It took nine seconds for an AI agent to destroy PocketOS’s production database. At work on a routine task in April, the coding agent, a variant of Cursor running on Claude Opus 4.6, ran into a credential mismatch and decided to fix the problem by triggering an API token. Little did PocketOS founder Jer Crane know that its activation would also delete its production database. “Had we known,” Crane later wrote on X, “we would never have stored it.” The consequences of the ag
     

Ways CIOs can maintain control amid changes brought by AI

19 de Agosto de 2026, 07:00

It took nine seconds for an AI agent to destroy PocketOS’s production database. At work on a routine task in April, the coding agent, a variant of Cursor running on Claude Opus 4.6, ran into a credential mismatch and decided to fix the problem by triggering an API token. Little did PocketOS founder Jer Crane know that its activation would also delete its production database. “Had we known,” Crane later wrote on X, “we would never have stored it.”

The consequences of the agent’s actions were immediately apparent. Not only were recent backups belonging to PocketOS’ infrastructure provider contained in the production database — the recoverable versions were at least three months old — but so were those belonging to its infrastructure provider, Railway, which at press time still couldn’t tell Crane whether full infrastructure-level recovery was possible. Crane couldn’t fathom why the agent did this. So he asked it.

What he got back was an apology, of sorts. “I guessed that deleting a staging volume via the API would be scoped to staging only,” the agent said. “I didn’t verify. I didn’t check if the volume ID was shared across environments. I didn’t read Railway’s documentation on how volumes work across environments before running a destructive command.”

Ignoring built-in safety guardrails is hardly unique to agents operating on Claude Opus 4.6. In July, a Brazilian software engineer claimed an agent powered by OpenAI’s GPT-5.6 Sol model also deleted his production database, while in February, a Meta AI security and safety researcher claimed she had to switch off her computer to prevent an experimental agent deleting her entire inbox.

It wasn’t meant to be like this. Agentic AI was intended to be the culmination of millions of hours of research and development in gen AI to perform hyper-qualified acts of pattern recognition in the real world, and truly live up to their labor-saving promise. Their apparent predilection for destruction, however, has revived multiple debates about exactly how they should be restrained, and who, ultimately, is responsible for doing so.

Ultimately, the answer is those who green-lit the offending system. But as the pace of AI development puts greater daylight between companies pressured to adopt it, and those very tools capable of wreaking havoc across their internal databases, are CIOs now out of their depth?

Setting the pace

There’s no question the emergence of gen AI has changed the CIO role. “A few years ago, most of my time went to infrastructure decisions, including what to build, what to buy, and how to sequence the roadmap,” says Mike Trkay, CIO at data analytics company FICO. “Now, a growing share goes to questions of trust, verifying that when AI writes code, makes recommendations, or acts on behalf of a system, those actions can be explained and traced back to someone accountable for them.”

So the CIO has become the enterprise’s technological organizer du jour. “AI is accelerating software development, decision automation, and organizational experimentation at a pace that can outstrip institutional coherence,” says Edosa Odaro, executive advisor for data and AI at consulting firm VDS Global. “As AI becomes embedded across every business function, CIOs are increasingly responsible for ensuring that technical capability, governance, data quality, cybersecurity, human capability, and business strategy continue to evolve together rather than fragment.”

Day to day, that’s led to an exponential change of pace. “Things have always been fast,” says Zach Lewis, CIO and CISO of the University of Health Sciences and Pharmacy in St. Louis. “But now that speed of change is quicker, and you have to adapt.” And the need to catch up is constant. There’s no other option because then any competitor or co-collaborator can jump ahead, adds Lewis.

The rapid pace of change in AI also threatens to diminish the authority of individual CIOs who fail to keep up or set effective guardrails on those individuals who like to experiment with the newest models with loose regard for corporate security. “There’s all these AI tools that employees can now just go out and adopt,” says Lewis. And at the moment, a paid subscription to Claude or ChatGPT isn’t required to capitalize on its abilities. Consequently, staff are just a click away from asking LLMs to perform various tasks and expose sensitive corporate information in the process. “Everyone wants to play with the new thing,” he says. “And when they find benefit there, they’re going to want to bring it to their work lives.”

Agentic AI poses an entirely new set of problems. For one thing, says Odaro, the next phase of application adoption will be defined less by the capabilities of individual models, and more on what you allow their agents to do. “As AI becomes increasingly capable of generating software, coordinating workflows, and making recommendations across functions,” he says, “the challenge shifts from building AI to continuously governing evolving AI systems.”

This, Odaro continues, means that the CIO’s current approach to governance isn’t sustainable. “Static policies, annual reviews, and isolated oversight will struggle to keep pace with dynamic AI environments,” he says. “CIOs will increasingly need continuous governance capabilities that provide ongoing visibility into AI performance, value creation, risk, trust, and organizational adoption.”

Falling over the guardrails

How, then, should CIOs approach writing these new guardrails? Traditionally, this would be perfect fodder for so-called alignment researchers investigating how to instil a sense of morality and propriety into agents. According to analysts at Google DeepMind, however, it’s best to assume the agent will always be a potentially chaotic force within the company, and set parameters on its conduct from there.

“We borrow a lot from security, which already deals with the threat of internal employees who might be malicious, and we can apply these to a new setting,” Rohin Shah, Google DeepMind’s AGI safety and alignment team lead, told Fortunein June. Even so, he added, “AI is systematically different from humans.”

That difference primarily pertains to authority and speed. For agentic AI to live up to its full potential, it requires the freedom to access multiple systems simultaneously — an uncomfortable fact for CIOs hoping to align agent responsibility across the enterprise. In a time when workflows are becoming ever-more automated, however, that aspiration may prove unrealistic. In that case, Google DeepMind theorises that yet another monitoring layer for agentic AI may be required to make sure these free-roaming agents don’t cause too much trouble.

If that sounds daunting, you’re not alone. According to recent research by Gartner, up to 40% of enterprises using agentic AI will either demote or decommission these applications because their guardrails have proven inadequate. Preventing this, the research organization advises companies will need to adopt a graded approach to access, with autonomy for AI agents governed by the level of authority actually determined by the task they’ve been assigned.

Trkay is doing something similar at FICO. “Rather than chase every new model or capability, I focus control on the decisioning layer beneath it,” he says. “That includes the rules for what data AI can access, what it can act on autonomously, and where a human must sign off.”

All this, he adds, is defined from the start by a cross-functional governance committee, clear RACI ownership across standards and monitoring for the application, and a platform approach that enforces responsible AI usage. “Built well, that layer doesn’t need to be rebuilt every time the technology shifts,” says Trkay. “New capabilities plug into an existing structure of accountability, which is the difference between reacting to AI and running it.”

For his part, Trkay is skeptical that rigid guardrails can effectively restrain agentic AI from its most destructive impulses. “They tend to get worked around, either because they slow teams down or they’re too inflexible for legitimate edge cases,” he says. Effective guardrails for agentic AI, he adds, have to be specific enough to be meaningful, and adaptable enough to hold up as use cases multiply, backed by strong architecture, testing, and ongoing monitoring. “The one non-negotiable is the audit trail,” he says. “Whatever autonomy a system has, we need a record of what it did, and why.”

Staying grounded

For CIOs who don’t relish the challenge of setting obstacles and passing points for AI agents scurrying through their maze of networks, there’s always the option of delaying the inevitable by not immediately deploying such applications. Some might not even have the choice, at least for now. “We’re seeing the cost of tokens go up with those new models, because they’re expensive to run,” says Lewis. “But as new models come out, we’re going to see that decrease for some of those older models that were good.”

There is time, then, for CIOs to learn how to keep their head above the torrent of ever more new and powerful agentic AI applications. Whether they’ll be capable of doing so when the next great innovation is sold by Silicon Valley is an open question. Colin Constable, CTO of software development firm Atsign, styles himself as an internet optimist. Even he, however, is dismayed by the decreasing number of junior developers succeeding their more senior counterparts as they retire. That’s a big problem when so many of the former are relying on AI to assist them at work.

“We hand over lots of these decisions to LLMs without making good architectural choices,” says Constable. “If you haven’t been burnt by these things in the past, how would you know the difference?”

For their part, Constable and his colleagues get around this problem with a combination of AI-on-AI oversight of code quality, maintenance of constant dialogue within the team about new coding quandaries, and letting senior developers teach junior counterparts about some of the more avoidable mistakes in their profession. It’s a way of adapting to AI acceleration that points, unequivocally, toward CIOs diffusing responsibility for deeply educating the business about the technology. And if they continue to get it wrong, at least the agent will apologize.

  • ✇Security | CIO
  • Beware of the AI pilot trap
    For many organizations, AI is proving easy to pilot but difficult to scale. Pilots often look inexpensive because they run on narrow datasets with a handful of users, explains Ben Schein, chief AI and analytics officer at cloud software company Domo. “But the cost lives in deployment, the moment you connect that capability to real workflows and the systems of record behind them,” he says. “That’s when the real bill appears.” So CIOs must always budget for the gap between when
     

Beware of the AI pilot trap

17 de Agosto de 2026, 07:00

For many organizations, AI is proving easy to pilot but difficult to scale. Pilots often look inexpensive because they run on narrow datasets with a handful of users, explains Ben Schein, chief AI and analytics officer at cloud software company Domo. “But the cost lives in deployment, the moment you connect that capability to real workflows and the systems of record behind them,” he says. “That’s when the real bill appears.” So CIOs must always budget for the gap between when it works in a demo and when it produces governed and durable value.

width="1240" height="828" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Ben Schein, chief AI and analytics officer, Domo

Domo

Organizations can easily get caught out because they run pilots as a technology experiment instead of a business initiative, he adds. “The interesting question is never whether AI can do the thing in a demo,” he says. “It’s whether it should run in this process, and whether it survives contact with production.”

There’s also a lot of pressure on IT teams to be doing something with AI simply because everyone else is, says Naren Gangavarapu, chief transformation and AI officer at Australian Cruise Group.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Naren Gangavarapu, chief transformation and AI officer, Australian Cruise Group

Australian Cruise Group

He calls it AI theater because there’s a big show around AI even though there aren’t that many successful applications of the technology in production environments.

AI costs out of control

According to John D’Emic, CTO at AI observability platform Revenium, one of the big traps when running a pilot is failing to anticipate how quickly consumption can spiral as adoption grows. “As an example from our own engineering org, back in May, a developer opened an AI coding session on his laptop, and it stayed open for four days,” he says. “By the time it closed, it had run 4,819 calls and cost us $3,762. We didn’t budget for this, and no alert fired. But that one session cost more than a lot of teams spend on their entire monthly AI tooling.”

width="1240" height="828" sizes="auto, (max-width: 1240px) 100vw, 1240px">

John D’Emic, CTO, Revenium

Revenium

While this showcases how a developer can make a costly error, Dmitriy Anderson, CIO and digital and social commerce leader at home and gardening retailer Leroy Merlin South Africa, believes the pilot trap frequently happens when employees with little or no software development experience vibe code applications. “It doesn’t matter if you can create something in 15 or 20 minutes if the result is AI slop,” he says. “Think dirty code, no consideration for safety, security, and possible data exposure.” In most cases, these pilots are developed with one of the frontier apps, and someone probably used their personal AI subscription, so the costs are negligible, he adds. But if you have a company of several thousand people, and you now want to roll this tool out more broadly, that’s where costs can get out of control.

This scenario is only exacerbated by the introduction of agentic AI, D’Emic adds. “Agents don’t spend money at human speed,” he says. “In the old cloud days, an engineer could spin up infrastructure in minutes and finance might not see the bill for a month, which was painful but recoverable. Agents, though, call APIs around the clock without waiting on anyone’s approval.”

Mind the trap

While cost is a big factor in the AI pilot trap, it should be treated as a symptom of a bigger problem, says Schein. The underlying issue is governance and observability. “An autonomous workflow can fan out into more queries, API calls, and model invocations than anyone scoped,” he says. “So if you can’t see what it’s doing, and spend compounds quietly, you only find out once the invoice arrives.”

In a recent LinkedIn post, Anderson outlined how in just six weeks he built a platform for a fraction of the sticker cost using three AI models orchestrated together. The traditional estimate to build the same tool would have required 2,472 engineering hours from a team, and was expected to take around nine months. “I went through the proper engineering steps and planning, and made sure the application passed a series of cybersecurity frameworks,” he says. “The purpose of this exercise was to showcase that AI can still speed up the process even if you take the time to work through the necessary steps. You can build with AI rigorously and securely.”

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Dmitriy Anderson, CIO and digital and social commerce leader, Leroy Merlin, SA

LMSA


So to turn AI experiments into enterprise value, every AI interaction must be attributable: who triggered it, against what data, on which model, and at what cost, Schein says. For each workload, be sure to ask how often it runs, which model tier the job actually needs, and what triggers it, human or automatic. “A frontier model on an automatic trigger and a small model called on demand are completely different cost curves for the same task,” Schein adds.

For Anderson, it’s helpful to use AI to highlight potential gaps, assumptions, or blind spots in your ideas early on. “When you start building an idea, ask the agent to interview you,” he says. “It will go through every phase and ask questions about the important facets of the process, from scalability and budget to deployment options. You can even make AI write a prompt for itself, because it knows its capabilities and quirks better than you ever will. It’s called meta prompting.”

Anil Inamdar, global head of data services for the Instaclustr BU at NetApp, suggests CIOs cost out the whole program, not just the demo. “Generally, the model itself is the cheapest part of the program,” he says. For him, it’s important to have security and governance people in the scoping meeting, not the launch meeting.

width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px">

Anil Inamdar, global head of data services. Instaclustr BU. NetApp

NetApp

He believes the pilot trap is also, or perhaps mostly, a sequencing trap. “A lot of teams are wired to build first and ask permission later, only to discover months down the line they can’t pass a security review or data privacy audit without a painful and costly rebuild. It’s also valuable to define what failure looks like before you define success.

“Pilots tend to die because of no result, which isn’t the same as a bad result,” Inamdar says. “Emphasize to the deployment team on day one that if a target result by a certain month isn’t seen, we shut it down. Otherwise, you’re funding a zombie pilot because everyone’s invested and no one wants to be the one to call it out.”

  • ✇Security | CIO
  • 4 RPA lessons that still hold true in the AI boom
    Enterprises of all sizes in all industries are rapidly deploying generative and agentic AI to automate processes. But the efforts aren’t always panning out. Some reasons are new and unique to this technology. But others are related to issues we should’ve been prepared for because we saw them during the age of RPA. And in the rush to adopt new tech, some of these lessons are being forgotten. “This new era of agents puts the same challenges again in front of us, and we ne
     

4 RPA lessons that still hold true in the AI boom

12 de Agosto de 2026, 07:00

Enterprises of all sizes in all industries are rapidly deploying generative and agentic AI to automate processes. But the efforts aren’t always panning out.

Some reasons are new and unique to this technology. But others are related to issues we should’ve been prepared for because we saw them during the age of RPA. And in the rush to adopt new tech, some of these lessons are being forgotten.

This new era of agents puts the same challenges again in front of us, and we need to think about the things we faced back when that revolution happened years ago,” says Agustin Huerta, SVP of digital innovation and VP of technology at Globant, a digital transformation company.

Those challenges often include selecting the right processes for automation, setting up systems to manage those processes, making sure automated processes get the right inputs, and managing the wider impacts of automation, including cultural.

1. Automating the right processes

All the lessons of RPA are carrying over, says Stephanie Bova, digital transformation officer at Novo Nordisk, including the biggest one that just because you can automate something, does it mean you should.

“We think hard before we start creating something,” she says. “Who’s going to maintain it, and where is it documented?”

And of course, is the process itself a good process. “Nothing gets built on a process that hasn’t been optimized anymore,” she adds. “We haven’t done a technology deployment on an unoptimized process for two years.”

And the company is now a lot more selective about how much automation it rolls out, but that wasn’t always the case with RPA. “At one point, everyone who wanted a piece of automation could get something built for them,” she says. “That’s not the case on how we’re approaching agents.”

There has to be real business benefit to the project, she says. “If you can show me the business outcome, we’ll consider it,” she continues. “But we don’t want or need hundreds or thousands of agents deployed. We want them all standardized and monitored, controlled, and auditable.”

Something similar happened a decade ago with RPA, says Huerta, when easy-to-use automation tools became available to people.

“When they were deployed without proper governance, systems got exposed,” he says. “They started stressing the overall infrastructure of the company, and some robots weren’t created in a way for a return on investment. The process ran faster, but consumed more in the cloud, so you ended up putting all the money you saved in the process into your cloud infrastructure, and the total ROI was zero.”

2. It’s not “set and forget”

Legal services company Purpose Legal uses the same basic approach for gen AI-based automation as it did with the previous generation of automation, based on ML, human oversight, and careful validation of the automated processes.

Take for example legal discovery, where documents are produced and shared with the opposing party in a legal case.

“Inadvertent production of sensitive data is a nightmare,” says Jeff Johnson, Purpose Legal’s chief innovation officer. “We always have to evaluate the data. Especially in the legal services context, we need people in the guardrails to make sure the process is on track.”

Without that oversight, problems can escalate quickly.

“If you make a bad decision you may get chastised by the court, lose the case, or lose the client entirely,” he says. “That happened in the past if you trusted automation too much.”

The AI tools today may be more sophisticated, he says, but they’re not perfect. “Even in the world of gen AI, it’s still something we need to watch out for,” he adds.

If anything, the oversight is even more important because of the scale at which AI can work, and how authoritative it can seem.

“Attorneys are more inclined to trust automation now because it interacts with them much more like a person would,” Johnson says. “It’s actually giving attorneys summaries of documents that look like another attorney wrote it, but that doesn’t mean it’s right.”

3. Reaping what’s sown

The need for good inputs goes back to the beginning of the computing era, if not earlier. “If we aren’t proving good inputs and putting good guardrails in place about where the AI gets its input, we get bad decisions,” says Johnson.

After all, data quality is a concern for any company rolling out automation, whether RPA or gen AI.

“Agentic AI won’t solve the entire data quality issue,” says Sabrina Joos, director of program and lifecycle management for new systems for the Americas at Siemens. But there are some differences, she says, in how it plays out.

In the RPA world, data quality was mostly about structured data and stable inputs. So, for example, if the data was formatted in a way the RPA didn’t expect, it might not execute.

“With agentic AI, the data quality issue becomes much more complex,” she says. “It’s no longer just about whether the data is correct, but if it’s complete and meaningful in context.”

AI systems can accept unstructured inputs or ambiguous data and make sense of it, but it doesn’t always interpret that data correctly.

“We don’t care too much about the format or typos since that’s not as much of an issue anymore,” Joos says. “But if there are assumptions that aren’t right, the process or workflow will still be executed. And this is where you have a risk that it will scale.”

For example, an AI can mix up two projects because they sound similar, she says. “Or, working on manufacturing solutions, it might not recognize the physical constraints of a system and will try to optimize and do something that a machine can’t do.”

Or two people might have a different understanding of an issue, and there might not even be an objective truth.

“You need to know where the interpretations are going to be made because there’s not enough information,” she says. “If we can identify this, we can trigger clarification questions. If I get a description from a customer, I might have a different view of it than you.” Solving the problem could involve additional conversations with the sales team, or double-checking with the original sources.

These data quality issues need to be considered early, says Jon Knisley,

director of AI value management at ABBYY.

“It’s really easy to run a pilot when it’s not in production,” he says. “But when you try to move it there, you get data issues. Where is the data coming from, and what’s the risk component?”

That’s also when the governance problems arise, as well as other challenges. These are all fundamentals that companies needed to learn in the previous era of automation and RPA, he says, since we’ve seen this technology cycle before.

4. Respecting change management

The biggest thing being forgotten about is change management, says Knisley.

“An AI project isn’t going to fail because of the model,” he says. “It’ll fail based on people and process. And there’s not that balance yet between the technology, people, and the process. Especially in North America, we want to solve every problem with technology. And that’s just not how the world operates.”

Back in 2019, according to a Forrester survey conducted on behalf of UiPath, 82% of respondents said change management was a challenge for RPA deployments. The same is true today. In a recent Kyndryl survey of over 1,100 business leaders, the speed of AI has outpaced workforce, governance, and operating models for 79% of organizations, and only 9% of organizations have implemented change management, redesigned roles around AI, and built workforce readiness.

“The biggest challenge we had in any digital transformation — and still have — is change management,” says Rahul Chhabra, director of applied AI at Herbert Smith Freehills Kramer, a leading global law firm.

And it’s gotten harder. With AI in particular, the technology is evolving so fast that change management is a quickly moving target.

“With RPA, it was sort of simple,” Chhabra says. “We had frameworks we could use to train people. We still have those learnings, but we have to enhance those processes.”

Something that works today might no longer work tomorrow, either. “You have to constantly iterate,” he adds. “What has worked can fail fast and only work in modules. So don’t try to solve the entire problem in one go.”

And employees don’t just have to keep learning new skills and adapting their work processes. Knowledge workers in particular also have to face the constant fear that AI will make them irrelevant. It doesn’t help when AI leaders amplify these fears. For example, Dario Amodei, CEO of Anthropic, predicted that AI will be capable of doing most or all jobs, not just entry level, in less than five years.

“Today, if lawyers do 10 tasks, maybe four of them will become obsolete,” says Chhabra. But that doesn’t mean four out of every 10 lawyers will be laid off. Even if most of the work is automated, Chhabra adds, there’ll be more for lawyers to do, not less.

“Today, a litigation matter might be worth $1 million,” he says. “But if it’s just $150,000, then a lot more matters are brought forward. So there’s going to be an increase in litigation and, therefore, more work for lawyers.”

RPA isn’t dead

So is RPA over? RPA wasn’t smart, says Traci Gusher, data and analytics leader at EY Americas. “It was useful, but it wasn’t intelligent. You couldn’t rewrite the process with RPA because it wasn’t technologically advanced enough.”

So, about 15 years ago, during the big RPA wave, organizations looked for ways to use RPA inside their processes, but the benefits were extremely limited.

“It was never so demonstrative that it would catch investors’ eyes,” she says. “It never got to that level of impact.”

Today, many companies are making the same mistakes with AI, she says. Instead of adding AI to existing processes, they need to rebuild them from scratch. “If you’re chunking it, you’re not going to get the results you want because it’s too small and incremental. That’s why I think over a period of time, RPA died a slow death.”

But AI can actually bring RPA back to relevance, she adds.

“There’s still very much a place for RPA in the AI wave,” she says. “You can use RPA for tasks and transaction-level activities, and integrate with agents. That might be the most cost-effective way.”

Unlike agentic AI, RPA is deterministic and completely predictable, it can run on-prem without leaking any sensitive data, and it incurs no token costs.

“We’ve seen consultants say we need to do this with agentic AI,” says ABBYY’s Knisley. “And they don’t have any reliability or governance. What they’re ultimately trying to do they could’ve done with regex for a tenth of the price, and 10 times the efficiency. You’ve got to figure out when you need to use agentic, script, or regex.”

So instead of throwing out RPA and going all-in on agentic AI, many companies are taking a more nuanced approach, using traditional RPA for processes that don’t require intelligence. Meanwhile, they use AI to help set up, test, manage, and upgrade the RPA, getting the best of both worlds.

“I think RPA is a very powerful technology and it has a place in the world today,” says Chhabra. “Especially on things that need to be deterministic, or you’re automating high risk or compliance workloads. You can mask the PII, but it’s still a risk to the company, so I’d rather use a script or some form of RPA automation.”

And a lot of governance will be rules-based, he adds, or based on RPA.

“There’s a lot of marketing speak that RPA is dead,” he says. “I don’t think that. Even the AI vendors are using RPA in the back, but now they’re calling it workflow automation.”

  • ✇Security | CIO
  • Where IT leaders find strength and opportunity in the age of AI
    With vision comes perspective, and over a distinguished career, IT and digital transformation leader Niraj Bhatt has held may titles, and earned three consecutive CIO 100 awards since 2023. As a storied advisor for startups and Fortune 500 companies, helping them navigate the unpredictability and fluidity of AI, Bhatt knows how emerging tech is rapidly reshaping the way organizations build products and deliver value, and how challenges shift as companies move from experime
     

Where IT leaders find strength and opportunity in the age of AI

12 de Agosto de 2026, 07:00

With vision comes perspective, and over a distinguished career, IT and digital transformation leader Niraj Bhatt has held may titles, and earned three consecutive CIO 100 awards since 2023.

As a storied advisor for startups and Fortune 500 companies, helping them navigate the unpredictability and fluidity of AI, Bhatt knows how emerging tech is rapidly reshaping the way organizations build products and deliver value, and how challenges shift as companies move from experimentation to real-world deployment.

AI, of course means a lot of different things to different people, and also for frictionless startups and large enterprises. For the former, speed is a huge asset, allowing them to punch above their weight. But it also means they need lightning fast reactions when landscapes shift. “The same speed can also hurt them when larger AI companies release new offerings that disrupt what startups are building,” he says, referencing recent moves by Anthropic and Google.

On the enterprise side, the conversation is more about scale and risk. Many large organizations have moved past the POC stage and now wrestle with the realities of putting AI into production.

Cost for both is naturally a recurring theme as organizations scale up AI efforts, and true expenses become clear only after the initial excitement fades. “Every input and output token, and the model you’re selecting, add up,” he says. Some customers like Open AI, he adds, get throttled because their usage, volumes, and costs are growing so fast, making planning, observability, and monitoring critical for any team moving beyond experimentation.

So understanding the full software development lifecycle is also vital. Therefore, before committing to production, he helps clients see the big picture, and make sure they understand technical requirements as well as operational and financial implications. “The cost picture isn’t just about usage, but scale and the model choices teams make,” he says.

Bhatt also discusses effective approaches to AI and enterprise IT, technology leadership, and the evolving role of today’s CIOs. Watch the full video below for more insights, and be sure to subscribe to the monthly Center Stage newsletter by clicking here.

On AI hype: If you can’t explain something to someone who’s eight or 80, you don’t really understand it. It’s gone from LLMs, to RAG, to agentic AI, and now the essence is all about tokens. It’s predicting that next token and understanding that is key. So when LLMs came out, they were good at doing that on the data on which they were trained. When the enterprises looked at it, they wanted to make those LLMs work for their data. And the question became how to provide our data and context. It’s about building the right context for the LLM. Agentic AI is similar and that’s where the RAG evolution came in, in that I’ve got my data because every LLM has limitations in terms of how much context it can carry.

There are ranges of LLMs, where Google has the highest in regard to the context window size and what they support. Agentic AI is more action oriented, though. LLMs rely on the metadata you provide for the tools. Then they’re doing token prediction in that whatever I’m looking for, I should use a specific tool. Then it’s the infrastructure underlying which LLM it relies on to invoke the agent. So if you try to explain the microservices to a person, you’re going to struggle. But it’s very important to understand the evolution and that’s where you can cut through the hype. Understanding in this context is key.

On navigating challenges around talent: What I’m seeing on the IT side is there’s so much cognitive load, so how do we empower people to build solutions with the right mix of products and platforms? I think it’s about democratizing AI for the entire organization. Your talent strategy is everyone, all inclusive, starting from interns, the business and tech sides, CEO, everybody.Like your customer success or revenue officers, you need a talent strategy because in the end, IT alone isn’t going to be in a position to deliver for everyone in the organization.

AI has the potential to make everyone in the organization more productive. You have to plan that and facilitate broad innovation across the organization.That’s where the talent strategy, and working with HR and the people officer becomes very important providing those tools. One part of it is training, but how do I build an agent for a receptionist receiving calls, for instance?I’m not going to rely on vibe coding or things of that nature. But what are the tools? Where do I go, where do I host this? I think through that entire ecosystem beyond copilots. That’s where innovation can kick in, and that broader talent strategy is something I’m working with my customers on.

On collaboration: I heard a panel discussion recently, and a question was asked about what’s the number-one trait CIO needs to be successful at in the world of AI, and the answer was collaboration. You need to bring everybody together, move forward together, and make sure everybody’s on board. And in my mind, simplifying that is more like systems thinking when you operate, just bringing everybody along and ensuring they’re meeting outcomes.

But maybe what’s more important is managing expectations. Because if you’re a CIO, there’s a tremendous amount of pressure to deliver and have a rock solid AI strategy. So what I’m doing with my customers is get the board, CEO, and CFO into a room and help them understand what I’m talking about, the evolution, and what’s the art of possible. You don’t want to be a CIO who thinks I have a hammer and everything is a nail. Having buy in from the senior leaders is essential to know you’re headed in the right direction. You’re not reacting to pressure from top leadership, but driving and becoming the change agent for good for the company.

On navigating AI: It’s interesting times. I’m covering a spectrum of startups, non-technical and technical founders, and advising Fortune 500 companies. What I’m seeing is they love the velocity and momentum because that’s what they’ve always wanted, and AI is providing that. They’re able to bring their products to markets very quickly, so something that would’ve taken three years a couple of years ago is probably now taking them three months. There’s a lot of excitement there. But on the flip side, the same velocity is also hurting them. There are so many frontier AI companies getting disrupted. OpenAI, for instance, has offerings in sales and marketing, and Google has an interactive video model. So a lot of startups working in the marketing space are getting stuck. A lot of what I’m focused on is working with founders, helping them pivot in the gen AI space, ensuring their systems and products are built and structured in the right manner.

And on the enterprise space, what I’m seeing is the POC wave, and people have seen the value. There’s some excitement but now the struggle is getting them to production. That’s where you run into cost, latency, legal compliance, privacy issues, and customer concerns that if we get tickets to production, how’s it going to look and how are we going to scale. So engineering and product teams have to be ably supported by the enterprise architecture and R&D teams. I then help them get up to speed and build that internal platform product for the production workloads. It’s exciting times on both sides.

  • ✇Security | CIO
  • What the San Diego Padres CIO does to deliver major league IT experiences
    Petco Park consistently ranks among MLB’s top ballparks for fan experience. That doesn’t happen by accident, and it didn’t wait for a star-studded roster or a deep postseason run. According to Padres CIO Ray Chan, the club made a deliberate choice more than a decade ago to run its tech organization as if every seat were full and the team was playing in October every year. The philosophy was simple — build a World Series-level digital foundation so when the on-field prod
     

What the San Diego Padres CIO does to deliver major league IT experiences

10 de Agosto de 2026, 07:00

Petco Park consistently ranks among MLB’s top ballparks for fan experience. That doesn’t happen by accident, and it didn’t wait for a star-studded roster or a deep postseason run.

According to Padres CIO Ray Chan, the club made a deliberate choice more than a decade ago to run its tech organization as if every seat were full and the team was playing in October every year. The philosophy was simple — build a World Series-level digital foundation so when the on-field product caught up, the elite fan experience would already be there.

More than a ballpark

Most people know Petco Park as the home of the San Diego Padres, which it is, but the venue was designed to be more than that. In a typical year, it hosts 81 regular-season home games, plus potential postseason contests, and then adds concerts and private events in renovated premium spaces.

By Chan’s count, that totals to nearly 400 annual events, often with more than one on the property in a single day. Different parts of the venue may host different audiences simultaneously, with IT expected to turn spaces quickly and support the unique digital requirements of each event.

The multi-use model puts a premium on flexibility and speed. Spaces are designed to be reconfigured quickly, and the underlying technology stack must adapt just as quick.

An always‑on network

When Chan arrived 15 seasons ago, Petco Park looked very different from a connectivity standpoint. On sellout nights, fans often couldn’t place a call or send a text once they were inside the building. There was no real concept of a digital fan journey.

The first major shift came with deploying a full-venue managed distributed antenna system (DAS) from Verizon, and an Extreme Networks Wi-Fi solution, providing fans, staff, and baseball operations with reliable connectivity throughout the ballpark. That network has since become the converged backbone for almost everything that happens at Petco, including digital ticket entry via the MLB Ballpark app, security and operations, tech like instant replay and dugout tablets used by coaches and players, and in‑venue IPTV and signage, all riding on the same IP infrastructure.

For fans, the network is invisible. For Chan’s team, it’s non‑negotiable. “None of this stuff works without the infrastructure in place,” he says.

Consolidated convenience

The Padres have leaned heavily into the league-standard MLB Ballpark app, which provides a consistent digital experience across all 30 venues, while allowing clubs to customize the local section. At Petco specifically, that app becomes the fan’s control center for digital ticketing, ballpark navigation, and a built-in payments and discount wallets tied to offers like Padres Pay and contactless options.

The result is a highly digitized journey, and for many fans, their first and last interaction with the ballpark occurs on their mobile device, and that’s by design.

Toward frictionlessness

Chan and his team are already looking beyond digital barcodes to facial-authentication-based entry, leveraging MLB’s Go Ahead Entry program rolling out at several parks. In that model, fans enroll once in the app with a selfie, then simply walk through a designated lane while overhead cameras verify identity and automatically scan tickets.

The promise is a hands-free, eyes-up experience where fans no longer need to take out their phones at the gate. Chan says this is the most frictionless way to enter a ballpark, and it even enables personalized greetings by name at the turnstile, another small but memorable touch to create a World Series-caliber experience.

Concessions are another example of how Petco’s IT modernization seamlessly enhances the fan journey. Petco is now a fully cashless venue, so fans pay with credit cards, mobile wallets, or the dedicated Padres Pay capability integrated into the Ballpark app. This reduces transaction friction, speeds lines, and improves security by minimizing cash handling.

IPTV everywhere

The expanding IP television footprint is another hallmark of Petco’s fan experience strategy. New screens throughout the venue serve multiple roles to ensure game coverage is never lost, even when fans leave their seats.

They also show real-time updates and wayfinding, an L-bar format that combines live video with adjacent ad inventory and informational content, and full-screen takeovers during concerts or special events, letting the venue transform its look and feel to match what’s happening on the field or stage.

Because it’s all IP-based, game-day operations and marketing teams can reskin the park on the fly, turning screens into a flexible engagement and monetization channel rather than relying on fixed signage.

Constant modernization

Despite opening in 2004, Petco Park doesn’t feel like a 22-year-old venue. Chan says that’s intentional and points to a continuous program of infrastructure upgrades and capital projects to redo suites, unify premium spaces such as the Western Metal rooftop and loft, and find areas to transform into new experiences.

Beneath those visible changes lies ongoing modernization of the network and systems in terms of upgrading switches, faster Wi-Fi, and backend platforms to support the latest apps and services. As Chan puts it, the goal is to make the park look and feel no older than a couple of years, which requires consistent ownership commitment and alignment between IT and operations.

Perhaps the most important part of Chan’s playbook, however, is cultural rather than technical. He describes the Padres as a listening organization that actively solicits and incorporates fan feedback to refine the experience across seasons.

That mindset is shaping the club’s approach to AI, so instead of chasing it for its own sake, Chan is focused on use cases that improve customer service by using chatbots or AI-assisted voice lines to free staff for higher-value interactions, and solve specific operational problems such as using AI to match lost-and-found queries with a database of found items.

The bigger IT picture

The way Petco Park manages its technology operations offers patterns that can apply beyond sports venues, starting with establishing a converged, resilient backbone. Connectivity is a shared utility layer that everything else depends on, rather than a series of isolated projects. That makes it easier to add new capabilities later without rearchitecting every time.

Chan’s philosophy of building as if every seat were filled also applies across all e-commerce peaks, clinical surges, and manufacturing seasonality. Capacity planning, observability, and failover should be set at Black Friday, not an average Tuesday. And treat your environment as a multiuse and continuously modernizing platform. Petco’s “more than a ballpark” mindset reflects the shift toward mixed-use destinations or campuses that blend learning and events, and offices that evolve into collaboration hubs that chip away at legacy infrastructure. IT leaders across sectors can apply the same rolling-renovation model to networks, identity, observability, and edge infrastructure, keeping technical debt manageable.

  • ✇Security | CIO
  • Why AI is forcing a rethink of data center cooling
    For years, cooling has played a supporting role in data center design. Decisions have been driven primarily by compute, storage and networking requirements, while cooling systems quietly ensured everything stayed within safe operating limits. Most enterprise environments operated well within the capabilities of traditional air-cooling that was designed to sustain normal growth. This let organizations focus their attention on capacity, performance and cost of the compute.
     

Why AI is forcing a rethink of data center cooling

6 de Agosto de 2026, 09:00

For years, cooling has played a supporting role in data center design. Decisions have been driven primarily by compute, storage and networking requirements, while cooling systems quietly ensured everything stayed within safe operating limits. Most enterprise environments operated well within the capabilities of traditional air-cooling that was designed to sustain normal growth. This let organizations focus their attention on capacity, performance and cost of the compute.

That balance is now being disrupted.

Artificial intelligence is reshaping the thermal profile of modern data centers. As organizations roll out more powerful CPUs, GPUs and TPU’s to support AI workloads, heat generation is rising at a pace that many facilities were never built to handle. With AI in the picture, cooling is no longer simply an operational consideration. It is becoming a primary constraint and strategic differentiator on AI infrastructure growth.

The limits of air cooling are becoming clear

Although traditional air cooling continues to support many enterprise workloads effectively, its limitations are becoming increasingly evident as organizations deploy larger AI clusters with increasingly power-hungry CPUs and GPUs, generating heat at levels older data centers were never designed to accommodate.

Racks that once operated at 5–10kW are being replaced by AI systems drawing 60kW or more, with some high-end deployments exceeding 100kW per rack. At the component level, individual GPUs are drawing 700W–1,200W each, placing large amounts of heat into a very small space. This shift represents a step-change in thermal density that conventional air-cooling systems, typically effective only up to around 20–30kW per rack, struggle to handle efficiently.

At these levels, the challenge becomes structural. Air can only do so much. There’s a hard limit to how efficiently it can move heat, and simply increasing airflow or optimising ventilation isn’t enough to keep pace with the rate at which heat is being generated.

The consequence is a growing imbalance between compute capability and cooling capacity. Data centers are being forced to use more energy for cooling, while simultaneously managing higher thermal risk and operational complexity. In some cases, this also introduces performance constraints, as systems throttle workloads to remain within safe operating temperatures.

Because of this, more organizations are turning to liquid cooling — particularly direct-to-chip approaches.

How direct-to-chip cooling is addressing rising heat challenges

The main limitation of air cooling is its relative inefficiency at removing concentrated heat. Direct-to-chip cooling addresses this. Instead of relying on chilled air moving around the room, direct-to-chip systems put cooling exactly where it’s needed, by placing cold plates directly onto high-heat components such as CPUs and GPUs. Coolant flows through these plates, absorbing heat at the source before carrying it away for dissipation via a heat exchange system.

A direct-to-chip cooling system is made of several parts working together. Cold plates absorb heat straight from the chips, while a coolant distribution unit (CDU) manages the temperature, pressure and flow of the liquid. The coolant moves through pipes connected to each rack, carrying heat away from the servers and into the facility’s wider cooling system while sensors monitor temperatures, flow rates and leak detection.

Liquids transfer heat far more efficiently than air, so direct-to-chip cooling allows significantly greater thermal loads to be managed with lower energy overheads. Because heat is removed more directly and effectively at the source, data centers require less power for fans, airflow and chiller operation, reducing overall energy consumption.

In most cases, only the components that generate the most heat are liquid-cooled. The rest of the system continues to rely on familiar air-cooling approaches. That mix is a big part of the appeal. A hybrid cooling approach allows organizations to improve cooling performance where it matters most, without having to redesign their entire environment.

Direct-to-chip isn’t one-size-fits-all

While direct-to-chip is talked about as a single approach, there are actually a few different ways to implement it. Most organizations use single-phase liquid cooling, where the coolant stays in liquid form throughout the process. It’s simple, easy to manage and fits well with existing operational models, which makes it a natural starting point.

But there is also a growing shift towards warm-water cooling. Because water is so effective at absorbing heat, systems don’t need to run at the same low temperatures as traditional air-cooled environments. This can reduce the need for energy-intensive chilling and improve overall efficiency.

In some setups, direct-to-chip cooling is paired with rear-door heat exchangers. These capture any remaining heat as air leaves the rack, helping to push densities even higher without overloading the system.

Ultimately, there isn’t a single “correct” way to approach cooling. The best method depends on the workloads being supported, the constraints of the facility and the organization’s longer-term plans. What’s clear, however, is that flexibility is becoming increasingly important as cooling requirements continue to evolve.

Direct-to-chip vs immersion cooling

As liquid cooling gains traction, direct-to-chip is often compared with immersion cooling. While both approaches address the same fundamental problem — removing significantly higher levels of heat – they do so in very different ways, with different implications for how data centers are designed and operated.

Immersion cooling takes a more radical route by fully submerging servers in dielectric fluid — a liquid that does not conduct electricity or conducts it extremely poorly. From a cooling perspective, it is highly effective and can handle extremely dense, high compute environments. But it comes with trade-offs.

Immersion cooling requires a rethink of how data centers operate. It also demands significant infrastructure shifts, which can make adoption challenging for organizations with established data center models.

Direct-to-chip cooling, on the other hand, offers a more gradual step forward. In general, servers keep their familiar design, and day-to-day maintenance doesn’t change dramatically. Teams can continue working in ways they already understand, making it a more practical step for many organizations.

This practicality makes all the difference. For most organizations, the decision isn’t just about which solution performs best in theory, it’s about what can be deployed, managed and scaled within the realities of existing operations. In that sense, direct-to-chip strikes a balance between performance gains and operational continuity, making it a more accessible starting point for many data centers navigating the shift to higher-density workloads.

Cooling as a competitive advantage

Cooling is no longer simply an operational concern. It is becoming a defining factor in how data centers scale, how efficiently they run and how reliably they perform. As AI workloads push infrastructure to new limits, the ability to manage heat effectively will directly influence how far and how fast organizations can grow.

That shift is also changing who owns the conversation. Decisions that once sat with facilities teams are now firmly on the agenda for CIOs, CTOs and infrastructure leaders. Thermal design, energy efficiency and cooling architecture are no longer niche considerations, they are central to cost control, sustainability targets and overall competitiveness.

At the same time, there is no one correct solution. Air cooling will continue to support many workloads, while immersion cooling will remain relevant for specialised, high-density use cases. Direct-to-chip cooling sits between the two, offering a practical way to handle increasing thermal demands without disrupting established operating models.

For organizations planning the next phase of their infrastructure, cooling can no longer be treated as an afterthought. It needs to be considered alongside compute, storage and networking from the outset.

  • ✇Security | CIO
  • Put trust infrastructure before intelligent automation for better collaboration
    Astute leaders recognize that many times, automation and technology failures aren’t really about the technology itself. Rather, failures occur because the necessary underlying infrastructure linking people, processes, and technology isn’t in place. For example, consider organizations that try to partner together but don’t take the time to align their tech implementations in a way that match the real-world outcomes they want to achieve. Without trust infrastructure and mean
     

Put trust infrastructure before intelligent automation for better collaboration

5 de Agosto de 2026, 07:00

Astute leaders recognize that many times, automation and technology failures aren’t really about the technology itself. Rather, failures occur because the necessary underlying infrastructure linking people, processes, and technology isn’t in place. For example, consider organizations that try to partner together but don’t take the time to align their tech implementations in a way that match the real-world outcomes they want to achieve. Without trust infrastructure and meaningful alignment, such collaborations are doomed to fail.

Creating a foundation of trust

AI adoption brings its own unique opportunities and challenges to both internal and external collaborations, especially in the way it disrupts existing workflows and encourages new forms of risk-taking.

An analysis by the Center for Creative Leadership notes that leaders should build cultural foundations of trust so new technology implementations strengthen rather than erode that trust. Creating psychological safety in the workplace occurs when leaders model learning rather than feign certainty about AI changes, and seek honest involvement and feedback from team members while being transparent about intentions and trade-offs associated with AI use.

After all, it’s hard to build a cultural trust infrastructure when one day everyone’s told how much they’re valued, and the following day, thousands are laid off because of AI restructuring.

When your internal team can’t trust your approach to intelligent automation, outside organizations you partner with may also develop trust barriers. How can they trust your organization to treat them fairly and with transparency if they’re concerned you’re planning to use tech in a way that will undermine a partnership?

Extending trust to digital spaces

In addition to using the foundation of cultural trust in communicating efforts to implement AI, the idea of trust can directly impact how these tools are used and set up. Because of this, intelligent automation needs a solid trust infrastructure in place to succeed. Partners sharing digital resources need to clearly define how they configure and manage their tech, as well as the real, measurable KPIs they want to achieve through implementation. Processes and procedures for sharing data in a secure and timely manner gives both sides the necessary information to leverage tech in the way intended.

A lack of trust — particularly fear of the unknown — can often undermine cross-enterprise collaborations, and this is especially true of tech implementations. A shared foundational infrastructure helps improve cultural trust through increased transparency, which in turn can improve buy-in among the individuals who interact with that tech on a day-to-day basis.

Digital trust infrastructure also enables AI tools to be more effective, so when team members interact with the AI to get insights, recommendations, or data reports, they can trust what the tech tells them. Instead of trying to create their own workarounds to avoid using the tools, they become adopters and promoters, closing the gap in data and insights that so often plague other collaborations.

AI won’t fix what’s broken

Unfortunately, many organizational leaders seek AI implementation to be a cure-all for problems. Astute leaders recognize if their organization doesn’t have a solid trust infrastructure in place, AI will magnify those problems, not fix them.

“Think of AI as a piece of world-class, designer furniture,” says Jary Carter, co-founder and CRO of B2B-focused commerce platform OroCommerce. “If you put a $20,000 Italian sofa in a home filled with clutter, dust, and bad flooring, it doesn’t make the house look better. It just further highlights your mess. In business, that mess is legacy systems, fragmented data, and siloed teams. If you haven’t built a unified digital infrastructure first, AI will only accentuate your flaws. It also won’t improve your customer experience by highlighting inefficiencies directly to customers.”

While throwing AI at existing data gaps won’t solve your collaboration problems, the automation isn’t necessarily to blame. Trust-building needs to happen alongside tech implementations because otherwise, the right data won’t be shared, people and machines won’t have access to the info they need, and the entire collaboration will falter.

Laying the foundation for better collaboration

The emergence of gen AI means that when we talk about trust infrastructure, we can no longer consider cultural and organizational trust alone. Leaders must also consider what that trust infrastructure looks like for their digital applications and automations.

By taking proper steps to build a dependable infrastructure based on transparency, aligned values, and clearly defined goals, leaders can increase their digital trust. This will yield greater buy-in of automated intelligence within the organization, and improve its applications during cross-enterprise collaborations.

  • ✇Security | CIO
  • Never mind clean data. Annotate as you collect it.
    Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data. Not only do you need to be able to track the lineage of data your model uses from source to token, something the EU AI Act requires, you also ne
     

Never mind clean data. Annotate as you collect it.

5 de Agosto de 2026, 07:00

Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.

Not only do you need to be able to track the lineage of data your model uses from source to token, something the EU AI Act requires, you also need to be able to take into account where the data came from, whether it’s out of date, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.

Gartner expects organizations will abandon 60% of AI projects because they don’t have the right metadata management, data quality, and data observability. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and one of IBM’s 2026 predictions was the importance of smarter data.

The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.

But that can also remove a lot of the context crucial for gen AI. Rather than cleaning data and losing the original context, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”

IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.

Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”

Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”

Raw but not rancid

Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.

Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”

Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”

But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”

That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”

Structure isn’t static

Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these data cascades shows how easily context gets lost and how badly it affects data quality.

Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.

“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”

Sensing structure

Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.

Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.

That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”

Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.

Incentives for annotating

DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.

LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”

The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.

“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”

That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”

People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”

Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.

So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”

DBOMs and data contracts

Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.

“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.

Aronchick advocates for a SLSA-style data bill of materials using a tool like Makoto, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.

The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.

Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.

“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.

AI demands provenance

All this context is the kind of metadata Anthropic’s context engineering guide recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.

Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.

If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”

And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.

Expanso recently won an Edge AI award for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”

Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”

Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.

“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”

  • ✇Security | CIO
  • How AI helps the US Senate Federal Credit Union better manage risk
    The United States Senate Federal Credit Union (USSFCU) is a nonprofit financial cooperative that provides traditional retail banking services to entities within the US government, such as the Senate and the Supreme Court.At present, the credit union’s headcount stands at nearly 150 people, managing around $1.6 billion in assets. A few years back, when it started to expand its use of technology, cybersecurity was a key focus area, but the financial institution faced two maj
     

How AI helps the US Senate Federal Credit Union better manage risk

31 de Julho de 2026, 07:00

The United States Senate Federal Credit Union (USSFCU) is a nonprofit financial cooperative that provides traditional retail banking services to entities within the US government, such as the Senate and the Supreme Court.At present, the credit union’s headcount stands at nearly 150 people, managing around $1.6 billion in assets.

A few years back, when it started to expand its use of technology, cybersecurity was a key focus area, but the financial institution faced two major challenges in boosting security as it scaled. The USSFCU was carrying significant technical debt, and there were holes in the organization’s defenses.

“We found gaps where we needed more systems, tools, and people, and then there were instances where we had technologies in place that weren’t being used effectively,” says Mark Fournier, CIO at the credit union. “We weren’t buying a bunch of shiny new things without thinking about it. We were actually quite prescriptive every year, performing a number of different exercises to identify our shortcomings and then finding the right solution to fill the gaps. But over time this adds up. It was clear we couldn’t keep hiring more people and bringing in new solutions.”

The USSFCU needed a more efficient way to bring everything together and make its cyber estate easier to manage. For Fournier and his team, vulnerability management was the hardest hill to climb since they have to deal with about 100 new possible breach points every day.

“When we looked at the problem more closely, the impact of these vulnerabilities was far greater than we realized,” he says. “Not only because of the volume but because of a lack of clear understanding around the potential impact of each one across the broader business.”

Improved risk management

The USSFCU didn’t lack security tools, however. In fact, it had plenty, from scanners and endpoint tools to asset records, tickets, and internal documentation. But each tool saw only a slice of the environment, so there was little to no context. This made it difficult for the security team to separate real business risk from noise.

So for each new vulnerability, the security team had to run a manual investigation, which could take days. And while doing this, they still had to triage the next wave of findings. The organization, therefore, needed a way to know what mattered, why it mattered, who owned it, and whether taking the time to make a fix actually reduced risk. The USSFCU also required a solution to be deployed entirely in-house, leveraging its internal inferences.

Working with Tonic Security, the organization deployed an exposure management solution that pulls together data from different tools and data sources to create a clear picture of business risk. “One of the key functions of the platform is the ability to ingest anything,” says Fournier. “Breaking down silos between disparate systems is essential to unlock valuable contextual information.”

For the USSFCU, transparency and explainability are critical, he adds. This tool uses an AI data fabric to extract context from structured and unstructured data. This context drives prioritization, ensuring the right owner gets the right evidence, not a vague ticket. And once the work is done, the solution checks whether the exposure was reduced.

Because the AI is grounded in the customer’s own environment, it isn’t just guessing from a generic risk model. It reasons over USSFCU’s assets, owners, services, tickets, controls, and business context. But it isn’t using this data to train external models.

Describing one particular incident, Fournier explains that shortly after the initial deployment, various stakeholders met to assess progress. “We thought we were smart because we found an error with the platform,” he says. “The solution had labelled an asset as internet exposed, which we knew was incorrect.” But after a review and lengthy discussion, they were proven wrong. “Almost immediately, the value of bringing this information together became apparent.”

A template for bigger things

Before this solution, a high-severity finding could send an analyst on a lengthy scavenger hunt because of data located in so many different places. They’d check the scanner, asset inventory, tickets, and maybe even ask around to find the owner. But now they can find the asset, the owner, the business relevance, the exposure path, and the recommended action in one place. The solution has reduced the time taken to resolve a vulnerability by 75%. And with a clearer idea of what is and isn’t important, and what adds practical value, the number of incidents someone needs to respond to has reduced from about 100 a month to just 10.

Sharing his lessons from the project, Fournier says one needs to keep an open mind because the problem you think you have is often very different from the one you actually have. “This project has also been an eye-opener around how people can collaborate and operate across different areas of the business,” he says. “When I talk to my peers, they regularly highlight the disconnect between different departments and business functions. But with a project like this, when you’re crossing traditional boundaries, you need to have open lines of communication to succeed.”

  • ✇Security | CIO
  • The gen AI helping Aetna review millions of medical records
    One of the biggest challenges companies like Aetna face every year is an annual HEDIS review of its records to identify gaps in care. For large national payors, the scale of the challenge is immense. So Aetna has deployed a gen AI-driven document intelligence platform that has reduced the need for manual review by 65%. “We have a large group of amazing trained medical coders who do this every day,” says Nathan Frank, chief digital and technology officer at Aetna. “This
     

The gen AI helping Aetna review millions of medical records

31 de Julho de 2026, 07:00

One of the biggest challenges companies like Aetna face every year is an annual HEDIS review of its records to identify gaps in care. For large national payors, the scale of the challenge is immense. So Aetna has deployed a gen AI-driven document intelligence platform that has reduced the need for manual review by 65%.

“We have a large group of amazing trained medical coders who do this every day,” says Nathan Frank, chief digital and technology officer at Aetna. “This is about making it easier for them by speeding up the process. Something that might have taken weeks or months we can now do in days.”

The Healthcare Effectiveness Data and Information Set (HEDIS) is a range of performance measures for the managed care industry. Developed and maintained by the nonprofit National Committee for Quality Assurance (NCQA), the first version of HEDIS was released in 1991.

Under the HEDIS measures, large managed care providers like Aetna review more than 10 million medical records annually to identify gaps in care. These gaps are missed or overdue preventative care or chronic disease management tests including missed cancer screenings, blood sugar tests for diabetics, eye exams, and immunizations. Closing these gaps improves patient outcomes, and health plans are measured in how well they perform. But processing medical records is no easy task.

“We’re talking about medical charts that have white space filled with handwritten notes,” Frank explains. It’s not just structured data, it’s lots of physical clinical documentation.”

Adding up the numbers

Frank says industry benchmarks for large providers indicate an annual review process that requires about 50,000 work weeks, equivalent to nearly 1,000 dedicated full-time employees. It would take a team of 50 reviewers more than 20 years to complete a single annual review using fully manual processes.

Enter AI Medical Chart Review, a platform developed by Aetna that leverages cloud services and gen AI to automatically extract clinically relevant data from records, and prioritize records based on the likelihood of measure closure and evidence strength.

“Large language models and gen AI give us the ability to train a model to decipher the charts, identify the high value codes, and build correlations,” Frank says.

In the space of about six months, Frank’s team ideated the platform, and designed and trained a PoC that was able to process millions of records in just two weeks. As a result, AI Medical Chart Review has earned Aetna a CIO 100 Award in IT innovation.

“Now we’ve gone through 14 million documents,” Franks says. “We’re seeing a reduction of manual effort, which is now being transitioned into other areas like quality control and making sure the automated chart review is working as expected.”

Behind the curtain

Using gen AI, the platform automatically ingests and analyzes unstructured medical records and clinical documents. And as part of that process, it identifies and extracts clinically relevant information for specific HEDIS measures like diagnosis codes, medication records, lab results, and visit documentation. With this data, the platform generates a prioritized set of records based on the likelihood of measure closure and strength of clinical evidence, which is then passed to human employees for review and validation.

Frank says the platform has increased gap closure rates (leading to improved Star Ratings and higher reimbursement), streamlined workflows, and enabled teams once dedicated to manual record review to shift focus to higher-value activities.

Frank says much of the speed and success in building the platform comes down to a shift in the way it approached the design and build process. Rather than exhaustively writing specifications and requirements, Aetna created a team that included engineers and subject matter experts who worked together to build out capabilities iteratively.

“It allowed us to move much faster, and having a business subject matter expert sitting in the same virtual or physical room with us got us a much better outcome,” Frank says. “The product model, our cloud compute model, and our AI governance model allow for quick reviews to make sure we’re using AI responsibly with the right guardrails. It’s increased the speed to get from product launch to go-live.”

He adds that small teams that don’t have to deal with a lot of bureaucracy are key to moving quickly.

“You need to design with security, compliance, and a responsible use of AI as core principles from day one,” he says. “Everything we do from a new build standpoint starts with thinking about how we make it cloud native, how we build with the right elasticity and speed, and how we optimize the cost.”

The most important element of all, he says, is a good relationship with your subject matter experts.

“You can have a great product manager and engineer, but you really need that business subject matter expert who’s excited about it, and who has a passion for transforming the process,” Frank says. “Once you put those three together, you’ll see amazing things like this happen all the time.”

  • ✇Security | CIO
  • Exploring Abbott’s mission-led AI strategy
    Medical technology companies have always been in the business of trust, and Abbott has been building it with AI for over 10 years. Long before gen AI entered the enterprise conversation, Abbott was using algorithmic AI to help diabetics manage their glucose, and imaging AI to guide surgeons in real time. Here, Sabina Ewing, Abbott’s CIO, explains how a principled approach to AI governance, deep cross-functional partnerships, and a commitment to demonstrating results from w
     

Exploring Abbott’s mission-led AI strategy

29 de Julho de 2026, 07:00

Medical technology companies have always been in the business of trust, and Abbott has been building it with AI for over 10 years. Long before gen AI entered the enterprise conversation, Abbott was using algorithmic AI to help diabetics manage their glucose, and imaging AI to guide surgeons in real time. Here, Sabina Ewing, Abbott’s CIO, explains how a principled approach to AI governance, deep cross-functional partnerships, and a commitment to demonstrating results from within IT have kept them ahead of the curve, and its mission intact.

How is Abbott using AI to achieve its mission and growth strategy?

As a medical technology company, Abbott’s mission is to help people live life to the fullest. For over a decade, we’ve been using AI to deliver on that mission, but whether it’s AI or any other technology, we’re intentional about how it ties to our mission.

Trust is earned in drops and lost in buckets. To ensure we maintain trust with our customers and employees, we’re guided by principles of fairness, safety, quality, and transparency. With these and our mission as our guide, we’re in command of the table we set for ourselves.

How have you been in the AI business for so long?

For decades, we’ve provided FreeStyle Libre, a glucose monitoring sensor built on algorithmic AI, that delivers continuous glucose readings to diabetics, and in some instances, connects to insulin pump applications.

In late 2025, we developed Libre Assist, which leverages generative AI to let FreeStyle Libre users take pictures of their food and receive guidance on the impact of that meal on their glucose levels, including when to eat what, because sequence affects how the body processes glucose.

In our medical devices business, Ultreon, launched in 2021, uses imaging AI to guide optimal stent placement during cardiovascular procedures, supporting the physician’s decision-making in real time.

So whether it’s algorithmic, generative, or agentic, we’re intentional about matching the capability to the specific therapeutic problem.

When technologies evolve, your mission doesn’t change. But how has the CIO evolved during this AI boom?

Today’s CIO must have the strengths of conviction, credibility, and communication. You need technical expertise and to surface data to have the right discussions. You also need to be brilliant on the fundamentals and clear about the strategy, and then execute against it. If I tell the business it can use AI to drive outcomes, then I need to demonstrate it in IT. This is why I’ve committed two commas of results in IT from new AI operational capabilities.

How can CIOs influence their company’s investment in AI?

Working with senior leaders in HR and finance ensures we’re educating the organization and securing necessary investment, and then maintaining financial discipline where investments occur. We hold to that discipline and we’re deliberate about how we deploy the resources of the organization to measurably have impact. We look for high-impact opportunities where new technology delivers results even as it evolves.

We established an executive steering committee on generative AI, and senior leaders are engaged in how we deploy capital. We’re not going out with a thousand flowers blooming.

We also have traditional financial measures we apply to AI investments. And we know you need to be able to identify quantifiable outcomes and then measure them. Those conversations happen in partnership with all senior leaders, especially those business leaders requesting specific capabilities.

As the CIO, you need to have strong relationships with all other parts of the company. I don’t need to be in the spotlight, but you need those relationships in order to lead and effect change. I led a program that helped educate our top leaders on AI foundations, and we’re all working together on the talent side, too. We’ve embedded AI into our talent processes, and we have a continuous cycle of enterprise education through the ranks, both in person and virtual, to ensure our people are ready to use the latest tools and technology. If you want to do something sustainable, you can’t do it by yourself.

What’s your message to your technology team?

What I tell our team is no one is better positioned to lead the organization through this transformative era than its own technical experts. That means we lean into our expertise and AI-first mindset.

Years ago, we crystallized our vision for Abbott IT by unleashing the power of technology and our people in service of Abbott’s purpose. That’s the constant reminder. Our role isn’t to deploy tech but to unlock what technology and people can do together, in service of the mission.

I have asked the team to be bold, bring their best, and pursue excellence. Our strategic pillars are modernization, and protecting Abbott in both enterprise and product cybersecurity, digitization, and advanced analytics. That’s always been part of our mandate.

But what does an AI-first mindset look like? I asked our executive assistants how they, as a community, think about using AI to radically expand what they can do with it as a companion to their work, but not a replacement for it. The models that exist today can’t be a great executive assistant. Models don’t have the judgment, institutional knowledge, or nuanced reasoning required to prioritize work and navigate unspoken rules. That expertise is irreplaceable. Our question is how to augment it.

❌
❌