Visualização de leitura

IT infrastructure shortages are real and lasting. Here’s how to cope

Lead times of nine to 12 or even 18 months. Costs rising by 35%, 45%, even 50% to 200%. More than halfway through 2026, the market for IT infrastructure that’s crucial for enterprise projects, including those involving artificial intelligence, is strapped.

Memory is at the root of the shortages. Memory prices “have risen by 50% to 200%, resulting in PC prices increasing by 35% to 45% and some server prices rising over 125%,” according to Jon Forest, VP analyst at Gartner. Network switches also need memory, albeit in lesser amounts than servers, so they are not immune, with prices and lead times likewise rising dramatically.

Industry experts agree that most of the issues stem from hyperscalers gobbling up memory capacity, which trickles down to servers, storage systems, and networking devices. But while the source of the problem may be new, supply chain disruptions are far from unprecedented.

As a result, industry insiders are not short on advice on how best to deal with the situation, with tips including making better use of what you have, considering options beyond your usual scope, and lots of planning with your vendors and internal finance teams.

State of the problem

Just how bad is the current supply chain problem? “It’s pretty bad,” says Matt Kimball, vice president and principal analyst with Moor Insights & Strategy. Companies accustomed to 30- to 45-day lead times for various infrastructure are now looking at 6, 12, or even 18 months.

“It’s real, and I’m hearing it from companies of all sizes, from the 1000-server to the 10,000-server shops,” Kimball says.

“Memory costs are expected to rise sharply well into 2027 and will reach up to 25% of network hardware expenses by the end of 2027,” according to an email Gartner’s Forest sent to Network World. The figure below shows the timeline Gartner expects for memory prices, and Forest notes that the same timing applies across networking, storage, and compute infrastructure. 

Gartner NAND DRAM stats

Gartner

“Enterprise network equipment pricing is projected to increase by over 20% in 2026. This upward trend is anticipated to continue with a further rise of 3% to 5% entering 2027, with no signs of price reduction until the end of 2027.”

But “reduction” will likely look more like “stabilization.”

“That’s something a lot of people don’t like to talk about. But let’s say prices went up 40%, they may come down five,” says Phillip Privett, senior vice president of vendor management with the global distributor and value-added reseller TD SYNNEX. “They’re not going to come down 40%.”

Perhaps worse, compared with past disruptions caused by issues such as fires in chip fabrication factories or the Covid pandemic, Kimball says this one is “durable” because its cause—the AI wave—is more long-lasting and just getting started.

“This AI inference wave we’re hitting is just beginning. It’s going to be longer and bigger than the training wave,” he says. “It’s impacting everything, from AI infrastructure to the traditional stuff that’s standing up your virtualization and cloud infrastructure.”

No vendors seem to be immune, not even the likes of Cisco, which makes its own Cisco Silicon One chips. Or, at least, it designs the chips; they’re actually manufactured by the Taiwan Semiconductor Manufacturing Company (TSMC), the same company that makes many of the other chips that are in such demand. And that’s only one component of many that comprise a switch.

On the other hand, the margins Cisco gets from enterprise sales are far greater than those from hyperscalers because Cisco sells mainly just hardware to hyperscalers, whereas enterprise sales generally include software and services as well. So, Cisco has incentive to keep enterprise customers happy and maintain the 66% margins it reported in Q3, its latest quarter.

Still, Cisco must deal with the same shortages as other vendors.

“I wouldn’t say any company is faring better than others,” says Neil Anderson, vice president and CTO for cloud, infrastructure, and AI solutions at World Wide Technology (WWT). “There may be nuances that some suppliers are employing to balance it to some extent, but I fail to recognize a supplier that’s not having almost the same issue.”

Cloud storage vendor Backblaze is one company that’s facing equipment cost and availability issues. “There are different types of shortages occurring in multiple places, all driven by unusual market demands, really by just a handful of very large buyers,” says James Rowell, senior vice president of operations with Backblaze.

Backblaze is constantly forecasting and monitoring demand triggers, Rowell says. That involves close alignment with the sales team to forecast client needs, as well as paying attention to historical trendlines to predict upcoming demand from new deals and growth with existing clients. But the company also looks for “unnatural market-related triggers” that would cause a spike in utilization.

With hyperscalers buying up vast amounts of capacity, “This is definitely an unnatural phase,” Rowell says. “For about for the last 12 months, I would say there’s been somewhere between a 15% and 30% uptick in costs,” especially in terms of servers and compute disks.

On the positive side, at least for Backblaze, the company is also seeing an uptick in business from an interesting source: AI companies. “We reported in the last earnings period a 70% increase in AI companies using our platform,” says Patrick Thomas, vice president of marketing at Backblaze. “That’s massive.”

On top of that, the company is seeing an uptick in deals from enterprises that can’t get the storage capacity they need or want on-prem. “There’s a general market nervousness where we’ve got potential deals coming our way because those organizations are concerned about being able to do it themselves,” Rowell says.

While some expect new chip fabrication plants currently under construction will ease memory supply constraints, Privett doesn’t buy it. “I don’t see it getting better anytime soon,” he says. “Building a new fab is a two-year process.”

Advice: Start with the basics

Enterprises, then, must play the cards they’re dealt. For Moore Insights’ Kimball, who did stints as an IT exec with the states of Florida and Oregon, that starts with making the most of what you have.

Such a strategy is “shockingly not implemented much” across the companies he sees. “A simple capacity planning exercise can free up a lot of resources.” That includes virtualized servers running at just 20% to 30% utilization as well as extending the life of existing servers. While 15 or 20 years ago it was common to refresh every four years or so, companies can often get six or seven years out of today’s servers.

While such strategies won’t solve your AI compute challenges, they can certainly help support your ongoing operations and free up budget for AI and other modernization projects, he says.

“Sweat your assets,” agrees Privett of TD SYNNEX. “Work them as much as you can, add only what you need, get extensions on your licensing, renewals on your services agreements and things like that. Just sweat it out a little longer.”

If you have budget to spend but can’t get the hardware you’re after, buy something else, says WWT’s Anderson. “Look at things that are not tied to those components, like software projects or SaaS licensing,” he says.

Get friendly with finance teams

Numerous experts recommend regular meetings with your CFO or finance teams to keep them apprised of what you’re up against so the company can plan accordingly.

Gartner’s Forest advises using rolling 12- to 24‑month forecasts and engaging early with suppliers to identify constrained components and SKUs. Committing to quarterly or monthly buys can help you avoid long-term agreements that extend past the rapid increases we’re seeing in 2026, he says.

Also engage with the financing arm of your equipment vendors, some of which are offering financing incentives, Privett says. Compute vendors in particular are offering subsidized financing, deferred payments, and low-cost financing for the first year or so. “Those are huge opportunities to take advantage of,” he says.

By engaging with finance teams, IT groups can conduct budget allocation exercises and try to come up with ways to make the financials work. The last thing you want to do is surprise them with additional budget requests out of the blue.

Kimball recalls his days with the state of Florida, when all budget requests were examined by a technical review working group—which was designed to be hostile.

“I can’t imagine going to them and saying, ‘Oh, did I say that was a million dollars? It’s actually $2 million. I need you to write me a bigger check,’” he says. “I would walk into one of the swamps in Tallahassee and get eaten by the alligators instead of doing that.”

Work with your vendors and VARs

As you put plans together, lean on your vendors for help, including channel partners such as value-added resellers (VAR) and national resellers. “Work with them to map things out and understand what your workloads will look like,” Kimball says.

That’s what Backblaze’s Rowell regularly does with his suppliers. He lays out his forecast for the year, with commitments on what Backblaze will definitely buy, as well as scenarios that account for rapid growth, say, 2x. “And they’ll come back with, ‘Well, okay, no problem,’ or maybe they say we need to put in an allocation right away, or we won’t be able to get what we may need,” he says.

Similarly, he sits down with his CFO regularly to map out predictive models that factor in inflation, price hikes, and the like. The idea is to plan out multiple scenarios, so you don’t get blindsided.

“If you don’t do that, you’ll get caught with your pants down, on the upside-down end of spectrum,” he said – meaning not having the capacity to take advantage of market opportunities.

Acquiring the capacity you need to meet project demand may also mean being flexible in terms of your equipment choices. If you’re a Dell shop but can’t get Dell servers, maybe you go with Lenovo, Kimball says.

“You’ve got to figure out how to use all this silicon and infrastructure in a heterogenous way to serve your needs,” he says. That’s especially true when it comes to AI infrastructure. “If you think you’re going to go with 100% Nvidia for everything from RAG [retrieval augmented generation] to inferencing at the edge, you’re kind of crazy, not because of cost but because of availability.”

Look at alternatives, including AMD and cloud solutions, while staying mindful of how it all plays together. You may not be able to get Nvidia GPUs, but AWS, Azure, and Oracle Cloud have them, Kimball notes.

Be strategic, perhaps by using cloud offerings to handle certain tuning or inference workloads, then bringing them back in-house when appropriate. “Have a better understanding of what absolutely has to be on prem and what can be in the cloud,” he says.

That’s good advice, says Backblaze’s Thomas. When it comes to AI, think about performance tiers and the range of use cases you have. They don’t all need top-tier performance.

“People get wrapped around axle of needing the top end. There’s a lot of flexibility in the edges, innovation in different hardware and software,” Thomas says.

Gartner likewise advises companies to increase configuration flexibility and expand sourcing paths. That may include buying from secondary markets and lease-return programs to preserve continuity with existing infrastructure until the shortages pass, Forest says.

Get started somewhere

Even if you can’t acquire or have to wait for the infrastructure you need, don’t let that keep you from getting started with AI or other modernization projects.

Options include public cloud and neocloud providers, Anderson says. WWT also provides capacity in its own lab so customers can get started with proof-of-concept projects. “Don’t just throw your hands up. We can help you find access to capacity,” Anderson says. “Production-scale AI may be delayed, but don’t let that derail your strategy.”

Colocation providers may likewise be an option, especially if enterprises are struggling to acquire high-end networking equipment. Networking is a key value proposition for colocation providers, in that they have built-in connections to various cloud providers and other ecosystem players.

Equinix, for example, has 280 data centers in 77 metropolitan areas, says Phil Read, senior director, colocation product management for the company. If you have the compute infrastructure, Equinix can help you with the high-end connectivity required both intra- data center and at edge facilities.

It also has partnerships with the likes of Cisco and Nvidia for “ready-to-go AI connectivity,” Read says. That means Equinix offers the right infrastructure to meet the requirements of high-end compute solutions in terms of power density and cooling. Such power densities are significant, requiring 120k VA per rack and up. “There’s plenty of talk about a megawatt rack,” he says.

Power is a significant issue in this entire discussion, Privett says. Older installed computing infrastructure likely consumes far more power than newer systems, which is an argument for upgrading as soon as possible.

“If you modernize today, you could substantially reduce the number of servers needed to support the same applications at a much lower power consumption rate,” Privett says. He advises sitting down with folks from the OT side of the house to make sure power is available for whatever you want to do. In many areas, power is at a premium.

If your plans include installing GPU environments in your own data center, WWT advises you not to delay. “We’re telling customers, you need to talk with us and get that designed, get that ordered, because it will take quite a bit of time until it actually ships and we’re able to install it,” Anderson says.

Moor Insights’ Kimball agrees. “You have to order these parts today if you want to see them hitting your dock, your warehouse, or your office 12 months from now.”

What JPMorgan does differently with AI that any company can apply


In the summer of 2024, JPMorgan Chase deployed its internal AI platform LLM Suite, launching it very differently than most do: The company didn’t force anyone to use it.

When LLM Suite arrived at its first major division, asset and wealth management, employees were asked to think of it as a research analyst: someone to ask for data, a draft, or an idea. Leadership didn’t set usage objectives or provide a formal mandate.

Access was rolled out in phases and only to those who requested it, and the bank allowed the tool to circulate through word-of-mouth recommendations among colleagues. While half the industry rushed to count users and publish adoption rates, JPMorgan gave up on pursuing that number.

It became flooded with users. In eight months, 200,000 employees had signed up without a single order being issued, out of a workforce of over 300,000. In time, the bank established more than 450 use cases in production.

Two years after that summer launch, JPMorgan had everything to boast about. It had established itself as a global leader in the use of AI: It was the top bank on the Fortune AIQ 50 list, and the third company overall, ahead of all the tech giants except Alphabet.

It was then that the bank’s head of analytics, Derek Waldron, the person best positioned to sell the success, pointed out what still wasn’t working: There was a gap between what the technology was capable of doing and what the bank was actually capturing in its business results.

That gesture is what distinguishes JPMorgan. Although it has much to celebrate, it knows what it lacks, it says so publicly, and it keeps searching for it. Behind that statement lies a way of innovating and measuring that the bank has been developing for years.

Giving up the number everyone was chasing

The first thing JPMorgan did right was not to make adoption the goal. By not forcing anyone, it turned platform usage into a barometer. If a tool worked, it was filled without any campaign; if it didn’t, it was emptied, and that emptiness provided valuable information. If adoption had become a target to be pursued, the organization would have optimized the number instead of understanding what the number represents.

The bank itself acknowledges that if a tool is broadly used, it means it’s popular, but not necessarily effective. To determine its effectiveness, something more was needed. The answer came from two decisions that only work together: linking each project to a business outcome, and creating the metrics to demonstrate that outcome.

First, to find initiatives that could have a real impact, instead of creating an agenda from the top down, the bank surveyed its business units, asking where there was a problem to solve. Within a few weeks, an internal portal gathered, according to the bank’s figures, nearly a thousand ideas. Of these, only a few hundred moved forward and reached production. An organization doesn’t open a funnel of that size if it expects most ideas to survive; it anticipates that many will be discarded.

The funnel’s filtering method was also different. Before launching each test, the outcome that would ensure the experiment’s survival was defined, along with the steps to be taken the day after the decision. By planning future actions in advance, indecision and the perception of failure were avoided.

A clinical approach to AI experimentation

But setting a threshold for each experiment requires verification, and that’s where the bank encountered an unexpected obstacle. Metrics have their own cycles. Bank customers conduct business on Mondays, not Sundays. They receive their paychecks at the end of the month. In August, they disappear. When an initiative generates a change and a figure rises the following week, there’s no way to know whether it increased due to the change or the calendar.

The solution was borrowed from clinical trials. Instead of rolling out the change to all users, it was rolled out to half, chosen at random. The other half (the control group) operated on the same Monday, the same payroll, and the same August, so that the experimental contribution (the attribution) could be separated.

The next step was to industrialize the experiments. Doing it properly required a specialist sitting alongside each product team, and with that method, they reached eight per year. A self-service platform increased the figure to around 300 tests annually.

The results are concrete. For example, tens of thousands of the bank’s engineers have gained between 10% and 20% efficiency thanks to an internally developed programming assistant.

Finally, the bank discovered that a figure can be accurate and yet mean nothing. Its head of analytics explained this with a simple example. They measure the hour that AI saves one employee, and the three hours it saves another. They add them up, and the result is accurate. But in a process that goes from beginning to end, those saved minutes often don’t appear on the bottom line: They merely shift the bottleneck to the next one.

It’s easy to get stuck on partial metrics because they’re more immediate and produce more impressive numbers. JPMorgan’s discipline consisted of not accepting a metric as valid until verifying its impact on the business at the end of the process.

The question then remains on Monday morning: What can a company that has neither the size nor the budget of a bank take home?

The method is what best exports

What’s most interesting about JPMorgan isn’t what it has done with AI, but how it has done it . Any company can replicate this approach, because it doesn’t depend on proprietary data, scale, or budget.

The following are some best practices that don’t require a €20 billion annual budget. They do require making decisions before starting and are within reach of any company:

Launch far more initiatives than will survive, and announce this clearly. If the organization discovers halfway through that most of its projects will be canceled, it may misinterpret this as a planning failure; if it knows from the outset, it understands it as the natural selection process. This is what makes making mistakes quick and cheap.

Decide in advance the threshold that will shut down a project and plan the next steps. Both aspects are necessary, not just the metric. If a certain figure isn’t reached, the team needs to know what will happen next. Applying a threshold without future planning leaves the team in limbo, and they’ll have to find a reasonable reason to wait another quarter before shutting down.

Work on business outcome metrics from the outset, not just when they’re requested. This tracking not only guides the initiative but also prevents having to reconstruct months of poorly documented decisions. Adoption, by the way, is the number the CFO won’t ask for. It serves as a signal while no one is pursuing it, and it ceases to be useful the day it becomes a target.

How to get it right

Whether metrics mean anything depends on where you focus your attention. It’s best to start with scope, because that’s the most common mistake. Saving three hours in one stage isn’t the same as improving time-to-market: If the entire process isn’t shortened, what you have is freed-up capacity, which is also valuable, but it’s something different, and it’s advisable to make that distinction clear.

Then it’s important to consider that value leakage occurs in two directions. The first is outward: The savings are passed on to the customer in the form of lower prices or better service. The second is inward: The savings in personnel are replaced by spending on computing. If these items fall into different budget categories, it’s easy to overestimate the actual savings.

Finally, there’s an excessive focus on cost savings, at the expense of revenue opportunities. Jamie Dimon, CEO of JPMorgan, put it more bluntly to his analysts than any consulting firm: No one benefits uniquely from AI. In other words, competitors will eventually incorporate those savings. The greatest potential for differentiation lies in revenue: using AI to uncover unmet demand.

The question a CIO will have to answer in a year’s time won’t be how much AI their company uses. It will be which of projects are still alive because they work, and not because no one has bothered to test them.

Why Cisco is redefining its CIO role

The CIO job description is being rewritten in real time. As AI agents take over the interface layer and connect directly to any data source, the skills that once defined great IT leadership — UX fluency, applications integration, build-versus-buy judgment — are giving way to an entirely different set of questions surrounding not how a process works, but whether it needs to exist at all.

Thimaya Subaiya is living that shift firsthand. At Cisco, he oversees IT and says the ideal CIO candidate today might not have a traditional IT background. Here, he explains why he split the company’s AI leadership out as its own function and why he’ll merge back in, what he’s really looking for in a CIO candidate, and why the Cisco CIO job is such a good one.

How would you describe your role at Cisco?

I lead operations for one of the world’s largest supply chains, as well as security and trust, including product security, internal systems, and data center security. I also lead the CIO organization and have revenue operations, partnership management, and accountability for our AI strategy. Two and a half years ago, I consolidated AI from throughout the company and named a CAIO. I then split out the role to give us a boost in the AI space, but eventually, the CAIO role will merge into IT.

How did you conceptualize the CAIO role?

At first, it was a leader who could pull use cases from all our operations and execute. The role also included the ethical use of AI systems, and prioritized what to guardrail and push out to employees.

But it’s evolved. To take a step back, Cisco pioneered enterprise networking, then built Compute with Cisco, Storage with Cisco, Networking with Cisco, Security with Cisco, and Observability with Cisco. Today, the CAIO is moving up the stack with an AI framework for MCP connectors, which has really moved us forward.

This CAIO group can tell the Cisco-on-Cisco story for AI, because we have a testbed for new ideas. If we continue to rely on multiple vendors, as in the past, we won’t be able to integrate at scale. This is why we isolated the CAIO role, to focus exclusively on AI governance and execution.

You’re in the middle of a CIO search. What are you observing about the CIO talent market?

With AI, the CIO role has completely changed. It’s no longer about UX and applications integration because with MCP, we can connect to any data source at any time, and agents have replaced the interface. The CIO role is now more about rethinking a process and then deploying an agent to execute, rather than reworking a process.

So the ideal CIO is a traditional one who’s learned to think differently, or even someone without a CIO background, but who’s led in product management, innovation, or transformation. The role today requires someone who’s been disruptive, and has had to rethink how a company operates, not just how its applications work.

Our top criteria are strategy, speed of execution, and the ability to scale because we’re not investing in science projects. For example, when the sales team requests a better forecasting tool, a CIO traditionally would make a build or buy decision. But in today’s world, the right question should be if you need a solution to forecast at all, or can an agent do it. Or better yet, do we even need this process?

So what’s the right background for today’s CIO?

Product managers have a relevant background because they manage multiple aspects of how a product comes together: user needs, business outcomes, fit in the market, and getting it built. This understanding of product strategy, marketing, and adoption is extremely important right now because we treat our AI initiatives like products. So a great path for our CIO is data scientist foundations, product management, and transformation.

What about enterprise security?

I treat enterprise security as a separate organization, which every company should do. Testing and evaluating new cyber solutions for frontier models requires a lot of work like scanning everything, taking a neutral view of what’s broken, deciding which tools become standard within development frameworks, which cryptography tools to use, and then maintenance. Abstracting that into its own organization creates focus. It also lets us move at the speed of AI.

When AI attacks, you need AI to defend you, and if security is embedded within the CIO organization, it’s not top of mind for the business. Security has become its own board-level conversation. For today’s CIO, I’d keep AI in but take security out.

A year after the CIO is in place, what will success look like?

Our applications footprint has been reduced, we’ve seen pure productivity gains from accelerating the back, and the speed of new releases is increased. The team is becoming more effective with the same resources, and we can say that our CIO drove us to leverage everything new technologies offer without blowing up on tokens. We’re looking for a new way to operate IT.

Why is the CIO job at Cisco a great opportunity for the CIO you’re describing?

It’s possibly the coolest job out there. We have an entire AI stack end-to-end that nobody else can claim because we bring networking and security together, complemented by observability and collaboration. That combination means we can create net-new solutions that define what technology looks like in the future.

On the security side, we’re one of the very few companies truly integrating AI into defense in a way that can be leveraged across a much broader market. That’s exciting, because it means free access to an entire stack that lets you innovate in ways the industry hasn’t seen before.

I call AI today’s generational technology. Every generation gets a technology that redefines how it operates, including the internet, iPhone, and now AI. Cisco is about to become the first company to launch a personalized AI agent for every employee, reachable through Webex. Think of it this way: the average person has an IQ of around 100. Now every employee is paired with an AI agent that can exponentially increase human capacity, built entirely on the technology available today.

Getting to build things like that, with no proven methodologies or limitations, and nothing but the question of how we get to the future, is the most exciting thing there is if you’re an innovative leader.

Why every country wants a data center — and most will lose

Every decade or so, a new form of infrastructure becomes the thing that separates economies that compound from economies that stagnate. In the 20th century, it was ports, highways and power grids. Right now, it’s compute. And governments around the world are scrambling to get a piece of it — offering land, tax breaks and power guarantees to a small group of American and Chinese technology companies — without fully understanding what they’re trading away or what they’re actually competing for.

I’ve spent my career designing and building these facilities. Here’s what I see.

What a country is really signing up for

When a government announces it’s attracting a hyperscale data center, the press release usually mentions jobs, digital transformation and becoming a regional tech hub. What it rarely mentions is what the country is giving up and what it will need to sustain the facility for the next 20 years.

A large data center — say, 100 megawatts — needs roughly the same power as a small city. It needs that power reliably, 24 hours a day, with redundancy built in so that a grid fluctuation doesn’t take down critical systems. It needs water, often millions of gallons per month, for cooling. It needs fiber connectivity with multiple diverse routes. It needs a construction workforce that understands raised floor systems, precision cooling, high-voltage electrical distribution and fire suppression. And it needs all of this before a single server is installed.

Most developing countries don’t have this. Not yet. And the gap between “we want a data center” and “we can sustain one” is exactly where deals fall apart, projects stall or facilities get built and then underperform.

The countries pulling away

The United States has roughly 4,000 data center facilities, more than any other country by a wide margin. That number is growing faster than most of the rest of the world combined. The reasons are structural: deregulated power markets in key states, established fiber networks, deep capital markets, a legal system investors trust and decades of operational knowledge in the industry.

China is building at comparable speed but inside a closed system. Its facilities serve Chinese companies under strict data localization rules. For global capital allocators, China is largely a separate game.

The EU is growing but constrained by its own regulations. GDPR and data sovereignty laws mean European data often must stay in Europe, which is creating demand — but also creating friction. Energy costs, permitting timelines and land constraints in Western Europe are pushing investment toward Nordic countries (cheap hydropower, natural cooling) and Central and Eastern Europe (lower costs, EU membership).

Singapore, Australia and Japan are the established APAC anchors. They have the rule of law, the connectivity and the enterprise demand. But Singapore banned new data center construction outright from 2019 to 2022 over resource concerns, and even its 2025 reopening came with strict sustainability quotas that leave hundreds of megawatts of demand unmet. The pressure is redistributing. 

Where developing countries actually stand

India is the clearest breakout story. It has real enterprise demand, a growing hyperscaler presence and government policy actively supporting data center investment — including a 20-year tax holiday for foreign cloud operators announced in the 2026 budget. The challenges are grid reliability and water scarcity in key metro areas — solvable problems, but they require serious infrastructure investment alongside the facilities themselves.

Southeast Asia — Indonesia, Malaysia, Thailand, Vietnam — is attracting genuine capital. Malaysia in particular has moved fast, drawing more than $24 billion in approved data center investment and positioning Johor (just across the border from Singapore) as an overflow market. The risk is that these countries are capturing construction investment and some jobs, but the operational expertise and long-term value is still flowing out.

Sub-Saharan Africa and Latin America are earlier. There is demand — mobile internet penetration is driving real data needs — but the power infrastructure in most markets isn’t ready for hyperscale. What’s viable today is edge computing: smaller, distributed facilities closer to users that don’t require the same power density. This is where early investors are looking.

What developing countries are getting wrong in negotiations

When a government announces it has attracted a hyperscale data center, the story is always the same: jobs, digital transformation, becoming a regional tech hub. What’s missing from that story is the question of who controls what.

A data center is not an economic anchor the way a factory is. A factory transfers skills, builds supplier ecosystems and creates middle-class employment at scale. A data center run by a foreign hyperscaler employs a small local facilities team, sends all operational decision-making offshore and keeps every dollar of the value it generates inside its own balance sheet. The host country gets the electricity bill and the water consumption. The technology company gets the asset.

What countries are actually competing for is not a building. It’s the right to be inside the infrastructure layer that runs the global economy for the next 30 years. That requires a completely different negotiation — one about data rights, local engineering capacity, grid co-investment and long-term operational control. Almost nobody is having that negotiation. They’re haggling over tax rates instead.

The governments that are negotiating well understand this. They’re demanding local data processing requirements, commitments to train and hire local engineers, co-investment in grid upgrades and technology transfer agreements. They’re treating compute infrastructure the way Gulf states treated oil infrastructure in the 1970s — the leverage point is during the negotiation, not after.

The governments that are not doing this will look back in 20 years and realize they subsidized someone else’s infrastructure empire.

What this means if you’re allocating capital

The investment thesis in this space is not “find the next Singapore.” That window has closed. The actual opportunity is in the infrastructure gaps.

Power is the binding constraint everywhere. Companies that can solve reliable, cheap, clean power for data centers — whether through grid modernization, on-site generation or small modular nuclear reactors — are sitting on the scarcest input in the industry. This is where I’d be looking.

Second-tier markets are real. The “big four” US markets — Northern Virginia, Silicon Valley, Dallas, Chicago — are land-constrained, power-constrained and increasingly expensive. Capital is moving to the Midwest, the Southwest and internationally to markets with available power and land. The facilities being built in these markets today are the critical infrastructure of the next decade.

The countries that get the policy right — stable regulation, reliable power, fair contract enforcement — will attract disproportionate capital. The ones that don’t will keep making announcements and watching projects stall.

In the 19th century, the countries that owned the ports controlled trade. In the 20th century, the countries that controlled oil set the terms for industrial growth. Compute is next. The physical layer of AI infrastructure — the land, the power, the cooling, the fiber — is being locked up right now, mostly by a handful of private companies operating across borders with very little accountability to the countries hosting them.

For capital allocators, the opportunity is real and the window is open but not indefinitely. Power solutions, second-tier markets and policy-stable emerging economies are where the uncaptured value sits.

For governments, the window to negotiate from a position of strength is also now — before the facilities are built and the leverage is gone. Once the servers are in the ground, the terms are set.

The countries and investors who understand this in 2025 will look very smart in 2040. The ones who are still thinking about data centers as a real estate play will not.

Human-in-the-loop AI is becoming the default, not the exception

Over the past few years, much of the conversation has focused on autonomous AI and how quickly organizations can remove humans from decision-making. In financial services, we’re seeing the opposite trend. The organizations making the most sustainable progress aren’t eliminating human oversight—they’re redesigning it.

The model taking hold within the banking industry isn’t AI that operates independently and makes decisions; it’s AI that operates with intent and oversight. Human-in-the-loop is quickly becoming the standard, combining the speed and scale of machine-driven insight with the accountability, judgment and control that organizations can’t afford to lose. The shift is increasingly aligned with how regulators and industry frameworks are shaping responsible AI adoption, from the NIST AI Risk Management Framework to the revised U.S. banking agencies’ model risk management guidance, both of which reinforce governance, monitoring and accountability over blind automation.

From my perspective, this is not innovation slowing down; it’s AI adoption growing up. The first wave of enthusiasm focused heavily on what could be automated, but now the more important question is where can AI create meaningful value while keeping the right human judgment, oversight and accountability in place? In financial services, that distinction matters. In an industry built on trust, those capabilities are not optional— they are foundational to how we serve customers, manage risk and earn confidence every day.

Banking offers one of the clearest examples of why human-in-the-loop AI is becoming the default operating model for enterprise AI more broadly. Some of the most valuable AI use cases sit in environments where mistakes carry real consequences, customer impacts are significant and explainability is essential. In those moments, human oversight is what allows institutions to scale AI responsibly.

In banking, AI usually doesn’t operate in a vacuum. Whether it supports customer service, fraud detection, compliance, underwriting or internal productivity, it is touching workflows that affect customers, colleagues, regulators and the reputation of the institution. That is why responsible scale matters. Global bodies including the Financial Stability Board and the Bank for International Settlements have recognized the efficiency and analytical benefits AI can bring, while also warning that it can amplify model, cyber, concentration and governance risks if controls do not keep pace. For financial institutions, the mandate is clear – move with ambition, but scale with discipline.

Where human oversight matters most

The next phase of enterprise AI adoption will be defined by how well institutions understand where AI can move work faster, and where human judgment still needs to lead. For financial institutions, that starts with materiality. The greater the potential impact on customers, regulatory obligations or financial resilience, the stronger the case for meaningful human oversight.

Customer service is a good example. AI can help teams summarize inquiries, recommend next-best actions and reduce manual handling time. But when the issue involves a disputed transaction, a vulnerable customer, a complaint or product suitability, human judgment must remain central. AI can make service faster. It can make it more consistent. But it cannot replace empathy, context or accountability.

Fraud and financial crime are areas where AI can create real value, but human oversight remains essential. AI can detect patterns, anomalies and suspicious behavior across large data sets at a speed and scale people cannot match, but fraud is dynamic. Typologies evolve, bad actors adapt quickly and authorities have warned that AI can also increase the sophistication of scams, fraud and disinformation. In that environment, analysts and investigators play a critical role — validating signals, reducing false positives, escalating the right cases and applying judgment as the threat landscape changes.

Risk, compliance and credit are similar. AI can help synthesize internal data, identify control gaps and strengthen monitoring. But when outcomes affect lending decisions, regulatory obligations, capital or liquidity, institutions need governance that preserves challenge, review and accountability. The EU AI Act’s human oversight requirements for high-risk systems point to a broader direction of travel — the more consequential the use case, the more important it is that people can understand the system’s limitations, override outputs and intervene when needed. For U.S. institutions, the specific rule may differ, but the principle is already part of how banking operates. High-impact decisions require accountable oversight.

At the same time, human-in-the-loop cannot mean putting a manual checkpoint in front of every AI-assisted task, which would slow adoption and reduce the value AI can create. The goal is risk-based oversight. Lower-risk use cases may be managed through periodic review, testing and monitoring, while higher-risk applications may require real-time review before action is taken. What matters is that institutions define those thresholds clearly, rather than assuming one oversight model fits every use case.

Why collaborative AI is winning in financial services

The financial institutions that are embracing human-in-the-loop AI do so because they understand both the opportunity and the stakes. AI can process transactions, summarize complex information and identify patterns at a scale humans cannot match. At the same time, consumer expectations make clear that scale alone is not enough.  TD Bank’s 2026 AI Insights Report found that 78% of Americans now use AI-powered tools in their daily lives, yet only 18% are comfortable allowing AI to make important financial decisions independently. That gap says a lot about where the market is heading. Consumers are not rejecting AI, but they are drawing a clear line around accountability.

That is why speed cannot be the only measure of success. When customer outcomes, regulatory obligations or enterprise risk are involved, people still need to challenge the output, apply context and remain accountable for the decision.

That oversight matters because AI does not always fail in obvious or familiar ways. Generative AI can produce confident but inaccurate answers. Machine learning models can drift as data changes. Even highly accurate systems can deliver biased or poorly reasoned outputs when the data, assumptions or prompts behind them are flawed. NIST’s Generative AI Profile highlights risks including confabulation, privacy concerns, misalignment and automation bias.

For financial institutions, the lesson is that responsible AI requires people who understand how to use the technology, and also when to question it.

Building the organization for responsible AI at scale

In addition to being a technology challenge, responsible AI is also an operating model challenge. The institutions that scale AI well tend to do three things with discipline: establish clear governance, redesign workflows around the technology and build the skills employees need to use AI responsibly.

Governance starts with ownership, but it cannot sit with one executive or one team alone. It requires coordination across business lines, risk, compliance, legal, technology and model risk functions. That cross-functional model is becoming more common as organizations move beyond experimentation.  McKinsey’s State of AI report found that AI governance is often jointly owned and that CEO involvement in governance is correlated with stronger reported bottom-line impact, suggesting that firms derive more value when AI oversight is treated as an enterprise priority rather than a side initiative.

Workflow redesign is just as important because the real value of AI comes from reimagining processes end-to-end. That means identifying where AI can handle summarization, pattern recognition or drafting and where people should focus on exception handling, complex decisions and relationship-driven work. Human-in-the-loop is not about preserving the old operating model; it’s about building a better one.

That also requires new capabilities across the workforce — employees need to know how to use AI tools effectively and how to challenge them. They need to understand prompt quality, output limitations, data handling expectations and the warning signs that a system may be producing unreliable results. The  World Economic Forum’s 2025 report on AI in financial services underscores that while adoption is accelerating, responsible scaling depends on workforce adaptation, governance maturity and a clear understanding of risks alongside value creation. Responsible adoption depends as much on human capability as it does on model performance.

Looking ahead, enterprise AI in financial services will become more embedded, more specialized and more agentic in targeted domains. But that does not mean the human role becomes less important; if anything, it becomes more important. As AI takes on more analytical and operational work, people will increasingly serve as orchestrators, reviewers and decision-makers at the points that matter most. They will set objectives, define controls, interpret edge cases and know whether the AI results can be relied upon.

The organizations that lead in AI will be the ones that make human judgment a deliberate part of the design—clear about where AI can accelerate work, where people must remain accountable and how both can operate together with discipline. For financial institutions, the call to action is to treat human-in-the-loop AI as the operating model that makes innovation more trusted, more durable and more worthy of the customers and communities it serves.

Salesforce, Anthropic partner to deliver Claudeforce

Salesforce and Anthropic today announced they have expanded their strategic partnership to deliver Claudeforce, enabling customers of both companies to leverage Salesforce data, workflows, business logic, actions, and governance within Claude.

“What we’re seeing is that when people stop using Salesforce through the traditional human interface and start using it through an agentic interface, it dramatically increases the value of Salesforce,” Patrick Stokes, president of Applications & Marketing at Salesforce, told CIO.com on Wednesday. “They’re using Salesforce more than they ever have before.”

Stokes explained that momentum around the Claudeforce partnership began building after Salesforce’s TDX 2026 developer conference earlier this year. At the conference, Salesforce announced Headless 360, a platform that packaged Salesforce’s AI and developer tools into a headless, API-driven layer designed to help enterprise teams build agent-first workflows. It allowed AI clients like Claude or ChatGPT to read, write, and reason over Salesforce data without the traditional browser-based UI.

“It was a very popular decision among developers,” Stokes said. “Salesforce was actively endorsing people using Salesforce through an agentic interface rather than through the UI that we have had in place for 27 years.”

Developers immediately started hooking MCP servers up to their own agents. And Salesforce watched them struggle to scale their efforts.

“How do you do it for 100 or 1,000 users?” Stokes asked. “How do you deal with managed authentication to make sure it’s using the permissions of the user inside Salesforce? All the things that are necessary in order to scale this out weren’t really in place.”

Anthropic, the company behind Claude, was seeing the same thing. Its sales teams were using Salesforce through Claude and struggling to scale it. The two companies worked together to create a solution and decided to productize the result as Claudeforce.

Prebuilt sales skills and token consumption

The first fruit of the Claudeforce partnership is Salesforce in Claude, a plugin with 37 prebuilt sales skills. Stokes said these skills will enable sellers and agents to reason over live revenue context, automate pipeline updates, and take governed action within Claude. Claude-powered agents can access Salesforce data, workflows, and rules directly.

“We’ve been using it internally and so has Anthropic and some pilot customers for some time,” Stokes said. “It’s really highlighting what we think is a new way to work where the user is way faster than they’ve ever been before.”

According to Stokes, Salesforce users are leveraging Claudeforce to vibe code their own CRM interfaces, creating purpose-built command centers for how they want to run their teams. They’ve also been using it for forecasting.

“You just ask the question, and it’s going to go out and analyze the data and use its intelligence to try to tell you what to do,” he said.

He did note that customers will have to evaluate their own appetite for token consumption when it comes to leveraging Claudeforce.

“We’re starting to see early signs of what the token use looks like,” he said. “The token consumption is certainly not zero, but it is nowhere close to approaching the amount of consumption that you would find in a development use case.”

As part of the Claudeforce partnership, Salesforce is embedding Claude directly into Slack. Claude will be the default model for Slack, powering Slackbot, augmenting team decision-making via Claude Tag, and accelerating multiplayer coding through Slack Code.

The partners plan to introduce more integrations across Claude, Salesforce, and Slack over time. The Salesforce in Claude elements of Claudeforce are available to some pilot customers now and the partners said they expect to launch an open beta in September. They will launch additional prebuilt skills starting in the third quarter.

The clock is now a control surface: AI’s impact on time synchronization in OT

A factory can forgive a late email. It won’t forgive a robot arm that arrives three milliseconds after the conveyor.

That sounds absurdly small. Three milliseconds barely qualify as waiting. Yet inside operational technology, tiny gaps can carry heavy consequences. A protection relay trips late. A vision system pairs an image with the wrong product. Two controllers record the same event in opposite order. The machines keep moving, but the story they tell about what happened begins to split.

I learned long ago that clocks in OT aren’t office furniture. They’re part of the control system.

Now AI is moving into that system, watching clock drift, network delay, oscillator health and odd timing patterns. The promise sounds attractive. Spot trouble earlier. Explain it faster. Correct it before operations feel the pain.

Then comes the awkward question.

What happens when a system built on probability begins advising infrastructure that depends on certainty?

Time is a control input

In IT, poor timekeeping often creates irritation. Logs don’t match. Certificates complain. Investigators lose an afternoon and develop strong views about whoever configured NTP.

In OT, the consequences can leave the screen.

Industrial devices need a common sense of time because they act together. Controllers, sensors, relays, drives and switches may sit in different cabinets, yet they must agree on when an event occurred and when the next action should begin. IEEE 1588 Precision Time Protocol exists for this reason. It gives networked measurement and control systems a shared clock with far greater precision than ordinary business systems usually need.

Power automation makes the point with little room for poetry. IEC/IEEE 61850-9-3 defines a PTP profile for power utility systems that must meet demanding synchronization classes.

That shared clock supports more than speed. It preserves sequence.

Suppose a pump fails, an alarm fires and an operator changes a setting. If three devices disagree on time, investigators may see the response before the warning and the warning before the fault. Every log can be accurate on its own while the combined record remains false.

That’s the quiet danger. Bad time can turn good evidence into fiction.

What AI can see

Traditional timing systems distribute time and measure variance. They follow rules. They don’t always explain why a clock has started to wander or why packet delay changed after lunch.

AI can watch the behaviour around the clock.

Oscillators drift as temperature changes, components age and workloads shift. Networks add delay through congestion, routing changes and uneven paths. Those effects don’t always arrive as clean threshold breaches. They creep. A model trained on normal device behaviour may spot the curve before an operator sees the cliff.

Research has already explored clock architectures that account for thermal change and non-stationary delay variation in industrial networks. Other work has used deep learning to improve clock synchronization where propagation delays and frequency offsets make classic methods struggle.

The practical use is simple. AI can estimate when a device is moving outside tolerance, compare its behaviour with peer devices and suggest the likely cause.

It may notice that a clock loses accuracy only when a cabinet warms. It may connect rising offset with a new network path. It may flag a grandmaster change that looks valid in protocol terms but strange in context.

This matters because most alarms report symptoms. Operators need causes.

“The clock is wrong” starts a search.

“The clock began drifting after the switch update, and the pattern matches path asymmetry” starts a decision.

That’s a better use of machine learning. Not an oracle. A sharper witness.

From fixed rules to context

Many timing controls treat every device according to a fixed schedule. Synchronize at this interval. Alert at that threshold. Escalate after so many failures.

Fixed rules are useful because people can understand them. They also assume the system behaves tomorrow as it did when the rule was written.

Factories rarely honour that assumption.

A robotic cell under full load behaves differently from one at rest. A substation during a fault does not resemble a quiet Tuesday morning. A clock that stays stable for months may need less attention than one mounted beside a heat source and fed through a changing network path.

AI can help vary monitoring based on context. It can recommend closer checks for unstable assets and reduce needless traffic around devices that remain steady. It can compare clock offset, packet delay, temperature and process state without forcing each signal into a separate queue.

But the word “recommend” carries weight.

Changing a monitoring interval is one thing. Correcting the clock that governs a protection function is another. The first may save bandwidth. The second may change how physical equipment behaves.

You need a boundary between insight and authority.

Without it, a useful model becomes a hidden controller.

The security problem hiding in the timestamp

Attackers don’t need to stop a process if they can make the process misunderstand time.

A forged signal can shift timestamps. A delay attack can make a legitimate clock appear accurate while pushing dependent devices away from the true reference. GPS spoofing can corrupt systems that trust satellite time. Research on time attacks in power grids has shown effects on fault detection, voltage monitoring and event location. Work on PTP delay attacks has also shown how targeted path asymmetry can move clocks without easy detection.

AI may help detect these patterns. It can compare timing behaviour across paths, devices and physical states. A sudden offset may look different from thermal drift. A slow malicious delay may leave a different trail from congestion.

Yet AI also adds targets.

An attacker may poison the data used to train the model. They may alter timing telemetry, suppress alerts or feed the system enough false anomalies that operators stop listening. They may tamper with a model update and teach the detector that hostile behaviour is normal.

That last risk deserves attention. OT teams often fear the loud attack. The subtler attack edits the baseline.

Once the model learns the lie, silence looks healthy.

When probability meets determinism

This is where enthusiasm needs adult supervision.

A timing protocol performs a defined function. A model estimates. Those are different forms of machinery.

If the model predicts drift incorrectly, it may request needless corrections, mask a real fault or make stable clocks chase one another. If operators can’t explain why it acted, they may hesitate at the exact moment speed matters.

The answer isn’t to ban AI from timing. That would confuse caution with wisdom. The answer is to place it where uncertainty can help without governing the final truth.

Keep approved time sources, PTP, NTP, local clocks, holdover capability and redundant grandmasters at the core. Let AI sit around that core and observe. It can score health, spot anomalies, connect signals and propose action.

Then bind it.

Set hard tolerances that the model cannot rewrite. Require human approval before material timing changes. Record every recommendation and the evidence behind it. Make sure the model’s loss does not stop the plant from keeping time.

NIST’s OT security guidance stresses that controls must respect OT’s distinct performance, safety and availability needs. Its work on positioning, navigation and timing also calls for organizations to identify dependencies, detect manipulation and prepare to respond when timing services fail.

The principle is plain. The clock must keep working when the clever layer goes missing.

A sensible route into production

Start with the timing estate, not the model.

Map every grandmaster, reference source, protocol, dependent asset and fallback path. Ask which processes need milliseconds, which need microseconds and which merely need logs that agree. Many firms can name their critical servers faster than they can name the clock those servers trust.

That inventory often exposes an uncomfortable fact. The plant has several sources of time, but no owner for timing risk. Everyone consumes the clock. Nobody governs the dependency. That is how a technical detail becomes an enterprise blind spot.

Then choose a narrow use case.

Drift detection is a good opening move. So is anomaly detection across redundant time paths. Incident correlation can also create value without touching live clock control.

Run the model in observation mode. Let it watch, report and explain. Compare its calls with engineering judgement. Test it during temperature shifts, network congestion, GNSS loss, grandmaster failure and planned maintenance.

Don’t test only the model. Test the disagreement.

What happens when the protocol says healthy and the model says danger? Who decides? What evidence do they see? How quickly can they restore the known state?

Scale only after those questions have real answers.

The clock should never need faith

AI can make OT timing easier to see. It can reveal drift before thresholds break, connect weak signals and help investigators rebuild events with less guesswork. Used with care, it may give operators something they rarely receive from industrial clocks: an explanation.

But explanation must not become sovereignty.

The safest design keeps time deterministic and makes oversight richer. Protocols distribute the clock. Engineers define the limits. AI watches the edges, where heat, delay, ageing and attack begin to bend the truth.

That arrangement may sound less dramatic than handing the system control. Good. OT has enough drama already.

A clock is trusted because everyone agrees to organize action around it. Once machines lose that agreement, the plant may still look busy. Motors turn. Screens glow. Logs fill.

Yet beneath the motion, cause and effect have started to divorce.

AI may help keep them together.

It should never be allowed to officiate the clock.

Compassion is not a control: What veterinary practices reveal about AI governance

The lobby is loud before the appointment begins. Dogs are barking, a phone is ringing and someone at the front desk is checking out with discharge papers in hand. A worried client is called into an exam room with a yellow Lab whose tail gives one soft thump against the floor, even though the dog does not really want to stand.

Inside the room, the client sits on the bench and hands the dog over for digital X-rays, hoping for the best while preparing for the worst. The veterinarian gently takes the leash, gives the dog a calm pat on the head and tries to project both confidence and compassion. The client speaks quickly, then more softly, trying to explain two days of changes: not eating, not wanting to jump, a strange cry when the dog was picked up, maybe a limp.

A technician is typing into the practice software on a laptop at the counter, trying to capture the history while keeping the visit moving. The team is listening, documenting, reassuring and preparing for the next step while the phone keeps ringing beyond the exam room door. This is the ordinary pressure of veterinary medicine: skilled people doing their best in a noisy, time-sensitive environment.

That is exactly where AI tools can start to look appealing. A tool that drafts the note, summarizes the history, organizes records, flags an image or generates follow-up instructions may feel less like futuristic technology and more like relief. Veterinary publications are already discussing AI applications in practice, including support for SOAP notes and workflow tools. In a profession stretched thin, a promise of efficiency is hard to ignore.

That is also why compassion is not a control. A caring team can still rely on a flawed tool, and a well-meaning employee can still paste an inaccurate AI-generated note into a record. Good intentions matter deeply in veterinary medicine, but they do not validate a vendor claim, protect sensitive information or define when an AI system should and should not be used.

Veterinary practice is the example, but not the only audience. The same pattern appears across smaller clinical, professional service and high-trust environments where AI tools are easy to adopt but formal governance may be light. For CIOs and technology leaders, the lesson is broader: AI governance cannot stop at enterprise frameworks if adoption occurs in environments where operational controls may be informal, inconsistent or missing.

AI will arrive as a convenience before it looks like a risk

AI adoption in veterinary medicine may not begin with dramatic clinical decision-making. It may begin with the ordinary, overburdened parts of practice: documentation, client communication, scheduling, reminders, inventory, imaging support and practice management. These are not glamorous areas, but they are exactly where small improvements can feel meaningful to a busy team.

That ordinary entry point is part of the risk. When a tool is framed as administrative support, practices may not treat it as governance-relevant. A note generator may seem like a convenience until it introduces an error into the medical record. A client communication tool may seem harmless until it gives confusing advice after surgery. An imaging support tool may seem like an extra set of eyes until someone begins relying on it more than intended.

The lesson for practice leaders is simple: AI is not risky only when it diagnoses. It becomes risky when it quietly shapes documentation, communication, data handling, workflow and accountability. Once AI influences what is recorded, what is sent to a client or what gets escalated, it is no longer just an efficiency tool. It becomes part of the operating environment.

That is why ethical and legal discussions about AI in veterinary medicine matter, but they are only the starting point. The harder work is translating those concerns into daily practice: which tools are approved, who may use them, what information may be entered and what outputs require review.

Good intent does not assign accountability

Veterinary teams are used to carrying emotional weight. They comfort clients, handle difficult decisions, work through emergencies and continue moving from room to room. That culture of care is one of the profession’s strengths, but it can also make the risks of technology harder to see clearly. When everyone is trying to help, it is easy to assume the tool is simply helping too.

AI does not remove accountability from the practice. If an AI tool drafts a record, the practice is still responsible for the record. If a tool summarizes a client conversation, the practice is still responsible for what is retained and acted upon. If a system flags a possible finding on an image, the veterinarian is still responsible for interpreting the patient in context. If a chatbot responds to a client, the practice still owns the boundaries of that communication.

Those boundaries should be explicit before the tool is used. Staff should know whether AI-generated notes are drafts, who must review them, whether AI-assisted content can be copied into the medical record, and what kinds of client questions require a human handoff. Without those rules, accountability becomes implied and implied accountability tends to fail under pressure.

Someone also has to know which AI tools are approved, what data they collect, how they are used and how concerns are reported. That person does not need the title of chief AI officer. In many practices, it may be the owner, medical director, practice manager or another designated leader. What matters is that oversight is named, not assumed.

Vendor claims deserve the same clarity. Before adopting an AI tool, leaders should ask what the tool does, what it does not do, how it was tested and what data it uses. In human medicine, the FDA maintains a public list of AI-enabled medical devices authorized for marketing, showing how validation and transparency are treated in adjacent clinical technology environments. Veterinary tools may not always follow the same regulatory pathway. Still, the governance question remains: how does the practice know the tool is appropriate for the way the staff intends to use it?

Lightweight controls can protect trust

The answer is not to bury veterinary practices under enterprise bureaucracy. A small clinic does not need the same structure as a hospital system or a large corporation. What it needs is a practical operating model that fits the practice’s size, risk and reality.

That model can start with a short list of approved AI tools and a rule that staff should not use unapproved tools for client, patient or practice information. It should define what AI may be used for, what it may not be used for and which outputs require review before they are entered into the medical record or reach a client. It should also specify who is responsible for oversight and how staff should report AI-related concerns.

Data rules should come before convenience. A client may say something personal during an appointment, and a record may include financial details, legal concerns, rescue history, breeding information, animal welfare issues or emotional context that was never meant to leave the practice environment. Veterinary practices may not operate under the same rules as human healthcare systems, but their data still matters.

Reporting matters because AI errors may start small. A note may contain a detail that was never said, or a summary may leave out the owner’s observation that changes the clinical picture. If staff do not know how to raise those concerns, the practice may normalize small failures until a larger one breaks trust.

AI may become useful in veterinary medicine, especially if it reduces administrative burden and gives skilled professionals more time for the work only they can do. The profession is already exploring AI’s potential, challenges and future direction across practice types and species, and technology that genuinely helps veterinary teams should not be dismissed out of fear.

But adoption is not the same as readiness. A tool can be helpful and still require oversight. A vendor can be innovative and still need validation. A caring team can use AI with the best intentions and still create risk if no one has defined how the tool should be used.

That is why compassion is not a control. It is not a cynical statement; it is a protective one. Compassion is essential to veterinary medicine, but compassion alone cannot review an AI output, secure client information, evaluate a vendor or decide when convenience has outrun judgment.

The practices that benefit most from AI will be those that protect trust as they adapt. AI can support the work, but it should not quietly redefine it. Before AI becomes another voice in the exam room, veterinary practices need to decide how to govern it.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

What vibe-coding startup valuations portend for CIOs

Investor appetite for the burgeoning vibe-coding startup ecosystem has shown few signs of satiation over the past year plus, with Swedish AI upstart Lovable’s Series C injection at a $13.3B valuation the latest evidence of a sector viewed by venture capitalists as one of AI’s most promising business disruptors.

AI-assisted coding has proved to be AI’s most compelling — and commercially viable — enterprise use case to date. Developer-aimed tools such as Cursor, which sold to SpaceX in June for $60B, and Windsurf, which last year entered a $3B OpenAI dalliance before its eventual talent flight to Google DeepMind for $2.4B, have become — along with Anthropic’s Claude Code — well established in enterprise arsenals for accelerating developer output.

But another set of vibe-coding tools, represented by the likes of Lovable and Replit, which hit a $9B valuation in March, seeks to ride the same path into the enterprise that no-code/low-code tools did previously: through your business users. These tools are built to democratize application development, giving users an AI chat interface to converse their way to enterprise-ready prototypes with fairly polished UIs, as CIO.com’s Peter Wayner writes in his roundup of the leading tools the space.

Some IT leaders are already enlisting business users to vibe-code their own apps. Scott Weller, CTO at financial services technology provider EnFi, in May told CIO.com’s Bob Violino, “The results have surprised us. What started as an engineering productivity initiative has become a company-wide capability, where anyone from the CEO to a customer success manager can turn an idea into a working prototype in hours, not weeks.”

For Weller and other early movers, vibe-coding tools are changing who participates in building a product. In some cases, this has translated to shortened product completion timelines and winnowed down IT to-do lists; in others, it is helping to foster culture change.

“When people are learning and applying AI to solve a real business problem, it creates purpose and momentum,” CIO Oral Daly told Violino of training services provider Skillsoft’s expansion of vibe coding beyond development teams.

“It helps people move from seeing AI as something abstract or intimidating to something they can work with thoughtfully, using judgment and collaboration rather than relying on rigid processes,” she added. “The solutions created as a result of vibe coding have filled capability gaps and delivered solutions to production in shorter timeframes, producing real value.”

As with previous iterations of the no-code paradigm, CIOs embracing vibe coding across the enterprise face their own set of challenges. Maintaining quality, for one. Governance — access controls, identity management, data handling — is another big one, familiar to CIOs. As is security, given concerns about AI’s ability to create secure code.

Plus, as with all things AI, organizational issues are compounded when vibe coding is unleashed across the enterprise.

“Most companies, including ours, are still learning where work actually happens versus where they think it happens,” Noe Ramos, vice president of AI operations at Agiloft, told Violino. “Before you can extend AI into a business function, you have to understand the real workflow, not the documented one. That discovery work is underestimated almost everywhere.”

All told, vibe coding enterprise apps remains tricky business, as CIO.com’s Grant Gross writes. And CIOs should beware business users falling prey to the “seduction phase,” Geoff Burke, senior technology advisor at ransomware defense vendor Object First, told Gross.

“At first, it feels like a brilliant partner,” he explained. “But give it too much autonomy and it injects inaccuracies, complexity, and bypasses security norms, which you will spend twice as long cleaning up later.”

A Replit coding agent, for example, deleted a company’s live production database. So CIOs need to wade cautiously into the vibe-coding waters.

But the promise is there. Creating software and web applications using everyday language is a powerful — and, from the business users’ perspective, empowering — proposition. And startup PR and sales literature bills itself as more than a prototype-maker. The consumer space results may be considerable and point to a promising future, but expansion into business environments requires a considerable elevation in trust.

In the meantime, IT leaders should be prepared for further hype in this area. In addition to the valuations and acquisitions mentioned, Indian AI coding upstart Emergent became a $1.5B unicorn in July, Bolt is nearing the $1B plateau, and former GitLab CEO Sid Sijbrandij has thrown his hat into the ring with Kilo.

All that money points to investors having enterprises in their sights. Beyond a liquidity event, the best way for many of these platforms to make good on ever-escalating cash injections will be to gain a foothold in business. CIOs should be prepared for business users to not only be exploring these tools but also fielding sales calls about them. After all, as Lovable notes in its press materials, its no-code AI tool has already reached employees at nearly two-thirds of the Fortune 500.

To date, though, vibe coding remains a crowded market, one that has Harvard Business School professor David Yoffie advising said startups to sell now, given that many face competition from the frontier labs that act as their suppliers as well — and that are poised to cash in big with pending IPOs of their own.

That adds extra noise to CIOs’ decisions in this space. Governance and security are the chief concerns when it comes to selecting and implementing these tools, but IT leaders can’t shortchange questions around long-term viability when it comes to placing their platform bets.

More than anything, CIOs need to address the viability of vibe coding for their business, and not just to keep ahead of the usual shadow IT cycle. As we’ve seen with previous business technology paradigm shifts, vibe coding — along with AI-related initiatives in general — holds the potential to destabilize IT leaders’ standing within the C-suite and organization at large.

CEOs are anxious for AI advancement, and headline valuations for vibe-coding startups draws attention to — and fear about — the business ramifications and opportunities of potential disruptors in the eyes of business execs. That can create an atmosphere of anxiety and opportunism. But CIOs’ hard work in navigating their organizations through the pandemic, aligning their IT strategies to business value, and setting the course for AI ROI have them positioned well to help shape a possible vibe-coding future for their organization’s business functions, even if it means the new technology purchase lands on a business colleague’s ledger.

Disclosure: One of Lovable’s new Series C investors is Regent, the investment firm that also owns CIO.com parent company Foundry.

From ‘dumb iron’ to smart machines: Why data control is the real Industry 5.0

On the modern factory floor, the phrase “industrial equipment” no longer tells the whole story. It conjures images of steel, hydraulics, conveyor belts and machinery built to perform the same task with unwavering precision day after day. Physical engineering remains fundamental, of course, but it’s no longer the sole measure of a machine’s value. The next generation of machines have capabilities that depend on far more than the factory floor, continuously exchanging information with cloud platforms, data centers and AI systems that allow them to act autonomously and “self-improve” long after they’ve been deployed. A robotic arm isn’t simply running a predefined script anymore – it’s generating a constant stream of operational intelligence that reveals how it is performing, when and whether it needs attention, and how production can independently improve itself and become faster, safer and more efficient tomorrow than it is today.

This new functionality is redrawing the concept of ownership for manufacturers. Increasingly, the asset is not just the machine itself, but the flow of data that supports it and reveals clues about its functionality. Every production cycle enriches digital models, refines predictive algorithms and deepens operational understanding, turning what was once a static piece of equipment into something that continuously improves over time. The term “phygital” has emerged to describe this convergence of physical infrastructure and digital intelligence, but whatever terminology ultimately sticks, the outcome will be the same. As manufacturing enters an era where competitive advantage is increasingly shaped by software, analytics and real-time AI inference, CIOs are having to think very carefully not just about who owns the machine on the factory floor, but who controls the data that turns that machine from “dumb iron” into something that can “think” intelligently.

Manufacturing has entered its software-defined era

The physical engineering on display on factory floors is already impressive. Autonomous haul trucks can navigate vast mining sites without drivers, robotic arms can self-adjust their movements in relation to contextual cues, and in the case of so-called “dark factories,” entire production lines can operate 24/7 for a long time without a single person on the factory floor. Every movement, vibration, temperature change and production cycle becomes part of a data-driven feedback loop that allows software to refine performance, anticipate failures and adapt operations contextually in ways that simply weren’t possible when industrial equipment functioned in siloes.

According to Deloitte’s 2025 Smart Manufacturing and Operations Survey, 92% of manufacturers believe smart manufacturing will be the primary driver of competitiveness over the next three years, while 78% are allocating more than a fifth of their improvement budgets to smart manufacturing initiatives. Those figures bring home the fact that industrial performance is no longer determined solely by what happens inside a machine, but by how effectively the data ecosystem it lives in functions as a whole.

Every smart factory runs on an invisible supply chain

Every intelligent machine exists within a much broader ecosystem that stretches far beyond the walls of a factory, connecting equipment manufacturers, cloud platforms, systems integrators, AI providers and operational teams through a constant flow of data. It’s easy to think of a production line as a collection of individual assets working side by side, but the reality is far more interconnected. Each machine is both producing and consuming information throughout the working day, allowing decisions made in one environment to influence outcomes somewhere else. A software update developed by an equipment manufacturer, for example, might be informed by performance data gathered from thousands of identical machines operating around the world, with improvements delivered back to the factory almost as quickly as they’re identified.

From that perspective, data begins to resemble a supply chain in its own right. Manufacturers have spent decades refining the movement of raw materials because every unnecessary delay carries a measurable operational cost, and that same principle now applies to information. The data flowing from production equipment, the analytics returning from cloud platforms, and the insights generated by AI have become just as vulnerable to delay as the components arriving at the loading dock.  According to the International Federation of Robotics, more than 4.8 million industrial robots are now operating in factories worldwide, and each one contributes to a growing stream of operational data that has become inseparable from the manufacturing process itself. The challenge for CIOs used to be, “How do we connect these environments?”, but now it’s “How do we ensure the data moving between them arrives with the speed, visibility and control needed to keep pace with modern manufacturing?”

The importance of network architecture

The value of data used to be measured solely by its accuracy, but now it depends on how reliably it can move between the organizations that create it, analyze it and act upon it. A predictive maintenance platform can’t identify an emerging fault if telemetry arrives too late, just like a digital twin is only as useful as the information it receives. As we bridge from Industry 4.0 to Industry 5.0, the network itself is becoming an active participant in the production process, prompting CIOs to think differently about connectivity.

Modern manufacturing depends on a growing ecosystem that needs to exchange data in near real time. Rather than relying on unpredictable routes across the public Internet, many organizations are turning to direct interconnection in the form of internet, cloud and AI exchanges, which act as neutral meeting points where enterprises and their suppliers, as well as network operators, cloud providers and digital or AI service providers, can establish direct, private connections with one another. By shortening the path data has to travel and avoiding unnecessary “hops” and congestion, these platforms reduce latency, improve resilience and give organizations far greater visibility and control over how production-critical information moves.

Every revolution in manufacturing has been defined by the emergence of a resource that reshaped how value was created, whether that was steam, electricity or silicon. Industry 5.0 is introducing another, albeit one that can’t be stored in a warehouse or delivered on a truck. Data has become the factory’s most valuable raw material, and controlling its movement is every bit as important as controlling the movement of physical goods. The term “industrial equipment” may continue to describe what’s happening on the factory floor, but it no longer captures where competitive advantage is really being created. Increasingly, the intelligence surrounding a machine is becoming just as valuable as the machine itself, and the networks carrying that intelligence are becoming part of the production process in their own right.

Beyond chatbots: How embedded GenAI is transforming banking application development

Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.

In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.

From automation to hyperautomation in banking applications

Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a hyperautomated design coordinates the complete flow, including exception handling and evidence generation.

Figure: Automation vs. hyperautomation.

Magesh Kasthuri

Figure: Automation vs. hyperautomation

Embedded Generative AI adds a new layer of intelligence. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.

Banking application components suitable for hyperautomation

A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into reusable patterns and by embedding intelligence directly into business processes.

  • Trade reporting applications: Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.
  • Wealth management platforms: Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.
  • Core banking applications: Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.
  • Investment banking systems: Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.
  • Digital compliance applications: Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.
  • Reconciliation platforms: AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.
  • Reporting and audit applications: Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.

Embedded generative AI as an application capability

Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic suggestions.

For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.

Hyperautomating the product development lifecycle

The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce documentation. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.

PDLC StageHyperautomation OpportunityAI-Assisted Outcome
Business discoveryProcess mining, domain interviews, regulatory mapping, backlog creationStructured epics, user stories, acceptance criteria, process maps and control requirements
Architecture and designReference architectures, API contracts, data models, event flows, security patternsArchitecture options, integration blueprints, threat-model prompts and design decision records
DevelopmentCode generation, service scaffolding, UI component creation, data pipeline templatesReview-ready code increments, reusable components, migration utilities and integration adapters
TestingUnit, integration, regression, performance, compliance and synthetic data testingGenerated test cases, defect reproduction steps, test automation scripts and coverage summaries
Security and compliance reviewStatic analysis, dependency checks, policy validation, evidence captureRisk explanations, remediation suggestions, control traceability and approval evidence
Release and deploymentCI/CD orchestration, environment promotion, release notes, rollback preparationAutomated deployment packs, release summaries, operational checklists and change records
Operations and feedbackObservability, incident analysis, user feedback mining, backlog refinementIncident summaries, root-cause hypotheses, improvement stories and reliability recommendations

Role of GitHub Copilot, Claude Cowork and Codex

GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.

Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.

OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.

Integration architecture for hyperautomated banking applications

A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.

The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but assisted decisioning with strong controls.

Example: Hyperautomated reconciliation and reporting flow

Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations report explaining unresolved breaks, aging trends, risk exposure and pending approvals.

The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.

Governance, risk and control considerations

Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be reviewed where regulatory or reputational risk is material.

Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.

Operating model for AI-native PDLC

A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident learnings back into the backlog so the system improves continuously.

The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.

Conclusion

Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.

Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.

This article was made possible by our partnership with the IASA Chief Architect Forum. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the IASA, the leading non-profit professional association for business technology architects.

Inside the post-merger IT overhaul at Alaska Airlines

As an aviation industry veteran with over 30 years of experience, Alaska Airlines CIO Charu Jain is all too familiar with the technology integration process that often follows a big airline merger.

By her count, she’s been involved in four such projects. But none, she says, has brought her greater satisfaction than leading the overhaul of Alaska’s PSS following its $1.9 billion acquisition of Hawaiian Airlines in September 2024.

“This is one of the biggest milestones in any merger work done between airlines,” says Jain, speaking from her company’s Seattle offices just two months after Alaska and Hawaiian completed their transition to a shared PSS.

In its simplest terms, a PSS is an all-encompassing software suite used by airlines to record and manage a passenger’s journey, from booking tickets and checking in baggage at the airport, to boarding the aircraft and accessing the in-flight menu. “A PSS touches almost every function of an airline from employees to guests,” says Jain.

Two brands, one system

At the time of the merger, Alaska and Hawaiian each had its own PSS. No sooner had the ink dried on the deal than the cutover project got underway to bring both airlines’ systems under a single operating platform.

According to Jain, the two airlines agreed from the get-go that they’d retain their own unique historic brands, both with a combined history of close to 200 years, which would be reflected through the system.

“It had never been done before, developing capabilities to enable two brands on one platform,” adds Jain, who also serves as Alaska’s SVP of merchandising and innovation. “We didn’t want a situation where a passenger travelling from Spokane to Seattle on an Alaska-branded flight, and then onto Honolulu on a Hawaiian-branded flight, would have to navigate two separate systems. So we thought about how to make that experience more seamless.”

After settling on a PSS, developed by travel software manufacturer Sabre, Jain and her colleagues began work on migrating the airlines’ millions of bookings and passenger information, while also updating their various guest- and employee-facing tools for the new system.

Selling cutovers and mock flights

Executing a system cutover on such a large scale is a delicate balancing act, not least in a live-environment where, for a major airline, any form of disruption to the passenger experience can be bad for business. So there was no attempt to rush the project.

“To make sure we didn’t have any issues with customers’ bookings, we really took a risk-optimized approach with a phased deployment and a phased cutover,” says Jain.

Much of this hinged on what Alaska refers to as a selling cutover. Starting in October last year, all new bookings were made on the new PSS, which allowed the group to drain old bookings from the legacy system, and start selling tickets six months in advance of the official transition date; the average booking curve for an airline is around six months.

“There was no migration of millions of records and bookings,” says Jain. “This meant when our customers checked in on the first day [of the PSS], it was as if the booking had been made on the native system.”

While this was going on, however, Alaska was hit by a sizeable IT outage that grounded flights across the country and impacted the travel plans of nearly 50,000 passengers. It followed a previous IT outage in July. However, Jain says the disruptions didn’t impact the project in any way.

So in the final months leading up to the cutover completion, Alaska carried out several dress rehearsals to test the system, including mock flights for domestic and international routes in anticipation of the recent launch of several non-stop services to Europe.

This involved real guests arriving at the airport, completing check-in, going through security, and taking their seats as if they were about to take off. Leaving no stone unturned, the simulation also accounted for baggage collection, pets, wheelchair users, and onboard hospitality, stopping just short of passengers being served actual food.

Alaksa completed five such mock rehearsals in all. “The fifth one was when everything worked without any medium or high issues, and gave us the confidence we were ready,” says Jain.

As part of the airline’s scenario planning, it also set up command centers in various locations, including Honolulu and Seattle, to plan for unforeseen and unrelated problems on the day of the cutover.

A dedication to collaboration

A project is only ever as a good as its people, and Jain is quick to hail the collaborative spirit that Alaska and Hawaiian brought to the table. As a PSS involves both the operational side of an airline’s business — touching on everyone from pilots, flight attendants, and baggage handlers — and commercial departments responsible for policies and pricing, this was more than a purely technological undertaking.

“This was about people coming together from two companies to make this one big thing happen,” says Jain.

When Alaska started making bookings on the new PSS last fall as part of the selling cutover, it also began training employees how to use system. It was around that time as well, says Jain, that the airline was confident the transition would be completed by April 2026, just in time for the busy summer travel season.

Since the PSS has been up and running, the company has also introduced a single mobile app to replace Alaska and Hawaiian’s separate existing ones, allowing passengers to personalize their experience to the airline brand they’re more familiar with.

“It’s a much more seamless experience now that there’s no confusion knowing which app to go on, or why they have two booking numbers,” says Jain. Alaska’s employees are also just as happy with their new tools, she adds.

Why AI is forcing a rethink of data center cooling

For years, cooling has played a supporting role in data center design. Decisions have been driven primarily by compute, storage and networking requirements, while cooling systems quietly ensured everything stayed within safe operating limits. Most enterprise environments operated well within the capabilities of traditional air-cooling that was designed to sustain normal growth. This let organizations focus their attention on capacity, performance and cost of the compute.

That balance is now being disrupted.

Artificial intelligence is reshaping the thermal profile of modern data centers. As organizations roll out more powerful CPUs, GPUs and TPU’s to support AI workloads, heat generation is rising at a pace that many facilities were never built to handle. With AI in the picture, cooling is no longer simply an operational consideration. It is becoming a primary constraint and strategic differentiator on AI infrastructure growth.

The limits of air cooling are becoming clear

Although traditional air cooling continues to support many enterprise workloads effectively, its limitations are becoming increasingly evident as organizations deploy larger AI clusters with increasingly power-hungry CPUs and GPUs, generating heat at levels older data centers were never designed to accommodate.

Racks that once operated at 5–10kW are being replaced by AI systems drawing 60kW or more, with some high-end deployments exceeding 100kW per rack. At the component level, individual GPUs are drawing 700W–1,200W each, placing large amounts of heat into a very small space. This shift represents a step-change in thermal density that conventional air-cooling systems, typically effective only up to around 20–30kW per rack, struggle to handle efficiently.

At these levels, the challenge becomes structural. Air can only do so much. There’s a hard limit to how efficiently it can move heat, and simply increasing airflow or optimising ventilation isn’t enough to keep pace with the rate at which heat is being generated.

The consequence is a growing imbalance between compute capability and cooling capacity. Data centers are being forced to use more energy for cooling, while simultaneously managing higher thermal risk and operational complexity. In some cases, this also introduces performance constraints, as systems throttle workloads to remain within safe operating temperatures.

Because of this, more organizations are turning to liquid cooling — particularly direct-to-chip approaches.

How direct-to-chip cooling is addressing rising heat challenges

The main limitation of air cooling is its relative inefficiency at removing concentrated heat. Direct-to-chip cooling addresses this. Instead of relying on chilled air moving around the room, direct-to-chip systems put cooling exactly where it’s needed, by placing cold plates directly onto high-heat components such as CPUs and GPUs. Coolant flows through these plates, absorbing heat at the source before carrying it away for dissipation via a heat exchange system.

A direct-to-chip cooling system is made of several parts working together. Cold plates absorb heat straight from the chips, while a coolant distribution unit (CDU) manages the temperature, pressure and flow of the liquid. The coolant moves through pipes connected to each rack, carrying heat away from the servers and into the facility’s wider cooling system while sensors monitor temperatures, flow rates and leak detection.

Liquids transfer heat far more efficiently than air, so direct-to-chip cooling allows significantly greater thermal loads to be managed with lower energy overheads. Because heat is removed more directly and effectively at the source, data centers require less power for fans, airflow and chiller operation, reducing overall energy consumption.

In most cases, only the components that generate the most heat are liquid-cooled. The rest of the system continues to rely on familiar air-cooling approaches. That mix is a big part of the appeal. A hybrid cooling approach allows organizations to improve cooling performance where it matters most, without having to redesign their entire environment.

Direct-to-chip isn’t one-size-fits-all

While direct-to-chip is talked about as a single approach, there are actually a few different ways to implement it. Most organizations use single-phase liquid cooling, where the coolant stays in liquid form throughout the process. It’s simple, easy to manage and fits well with existing operational models, which makes it a natural starting point.

But there is also a growing shift towards warm-water cooling. Because water is so effective at absorbing heat, systems don’t need to run at the same low temperatures as traditional air-cooled environments. This can reduce the need for energy-intensive chilling and improve overall efficiency.

In some setups, direct-to-chip cooling is paired with rear-door heat exchangers. These capture any remaining heat as air leaves the rack, helping to push densities even higher without overloading the system.

Ultimately, there isn’t a single “correct” way to approach cooling. The best method depends on the workloads being supported, the constraints of the facility and the organization’s longer-term plans. What’s clear, however, is that flexibility is becoming increasingly important as cooling requirements continue to evolve.

Direct-to-chip vs immersion cooling

As liquid cooling gains traction, direct-to-chip is often compared with immersion cooling. While both approaches address the same fundamental problem — removing significantly higher levels of heat – they do so in very different ways, with different implications for how data centers are designed and operated.

Immersion cooling takes a more radical route by fully submerging servers in dielectric fluid — a liquid that does not conduct electricity or conducts it extremely poorly. From a cooling perspective, it is highly effective and can handle extremely dense, high compute environments. But it comes with trade-offs.

Immersion cooling requires a rethink of how data centers operate. It also demands significant infrastructure shifts, which can make adoption challenging for organizations with established data center models.

Direct-to-chip cooling, on the other hand, offers a more gradual step forward. In general, servers keep their familiar design, and day-to-day maintenance doesn’t change dramatically. Teams can continue working in ways they already understand, making it a more practical step for many organizations.

This practicality makes all the difference. For most organizations, the decision isn’t just about which solution performs best in theory, it’s about what can be deployed, managed and scaled within the realities of existing operations. In that sense, direct-to-chip strikes a balance between performance gains and operational continuity, making it a more accessible starting point for many data centers navigating the shift to higher-density workloads.

Cooling as a competitive advantage

Cooling is no longer simply an operational concern. It is becoming a defining factor in how data centers scale, how efficiently they run and how reliably they perform. As AI workloads push infrastructure to new limits, the ability to manage heat effectively will directly influence how far and how fast organizations can grow.

That shift is also changing who owns the conversation. Decisions that once sat with facilities teams are now firmly on the agenda for CIOs, CTOs and infrastructure leaders. Thermal design, energy efficiency and cooling architecture are no longer niche considerations, they are central to cost control, sustainability targets and overall competitiveness.

At the same time, there is no one correct solution. Air cooling will continue to support many workloads, while immersion cooling will remain relevant for specialised, high-density use cases. Direct-to-chip cooling sits between the two, offering a practical way to handle increasing thermal demands without disrupting established operating models.

For organizations planning the next phase of their infrastructure, cooling can no longer be treated as an afterthought. It needs to be considered alongside compute, storage and networking from the outset.

Algorithms aren’t enough: Why factories need an AI reasoning layer

The scheduling fallacy and the shift to autonomy

Walk onto almost any manufacturing shop floor, and you will witness the same systemic vulnerability: a brilliantly engineered, multi-million-dollar Advanced Planning and Scheduling (APS) system rendered completely useless by a single delayed delivery truck, an unexpected machine drift or a sudden workforce shortage. Industrial operations do not happen in a sterile room; the moment a perfect plan hits the messy reality of the physical shop floor, real-world variables inevitably shatter it.

This is the scenario (or challenge) that I have been navigating over the past few months and is likely to keep me occupied for the remainder of the year. I began this project believing the scheduling engine was the problem. After months of experimentation, including trying to make LLMs perform optimization, I realized I was solving the wrong problem. The realization that dawned on me was that it wasn’t about a better algorithm; it was about separating mathematical optimization from operational reasoning.

According to the 2026 Gartner Manufacturing Predicts report, factory orchestration is moving rapidly toward a “double helix” model where software-defined enterprise data intricately intertwines with autonomous production orchestration. Gartner also projects that 40% of enterprise applications will feature integrated, task-specific AI agents by the end of 2026 — a massive leap from less than 5% in 2025. For technology leaders, the mandate is clear.

Deconstructing the “reasoning layer”

Let’s first demystify what a “Reasoning Layer” is and what it is not. It is not a Generative AI nor is it a glorified Robotic Process Automation (RPA) script executing static, hardcoded logic. Instead, the Reasoning Layer is a cognitive overlay powered by foundation models. These models have been fine-tuned on operational ontologies, enterprise supply chain strategies and real-time shop-floor data streams. Pretty much everything that happens in your organization and, in many cases, outside as well, as some decisions are impacted by the prevailing external situation.

A reasoning layer continuously answers a complex question: Given this specific disruption, what is the optimal business choice right now?

The dual-engine architecture: Math meets cognition

A common pitfall has been to expect an LLM to handle both. That was the blunder I committed was to assume that a sufficiently trained LLM can get the job done.

The true breakthrough in designing a production-grade scheduling application lies in pairing semantic intelligence with raw mathematical muscle.

To solve this, what I discovered was that you need to split it into two layers. A number-crunching mathematical layer and a qualitative layer. Both working in sync.  

  1. The quantitative engine: Global pathfinding, sequence optimization and multi-plant capacity balancing are treated as a highly complex routing problem. Ant Colony Optimization (ACO) algorithm, for example, excels here. It can navigate massive combinatorial data spaces to find optimal/near-optimal scheduling sequences across interdependent lines. A word of caution though: This requires good quality data and lots of it.
  2. The qualitative brain (agentic AI): The AI agent serves as the dynamic coordinator. It monitors the operational environment for live telemetry anomalies (such as machine cycle-time drifts or supply chain delays). When an anomaly occurs, the agent evaluates the business impact. Determines whether a re-optimization is required and crucially rewrites the constraints and boundary conditions before triggering the ACO engine.

By using the Agentic Layer to bound the mathematical problem, the system avoids the fatal flaw of traditional advanced planning tools: completely rewriting a global schedule over a minor local exception.

The multi-plant orchestration paradox

When a manufacturing organization expands from a single facility to a distributed, multi-plant network, operational complexity does not scale linearly — it scales exponentially. In theory, a multi-plant footprint should provide an enterprise with built-in resilience, giving leadership the flexibility to shift production loads when disruptions strike. Most manufacturing organizations suffer from the multi-plant orchestration paradox: they possess massive regional capacity but are structurally blind to how to leverage it dynamically.

The root cause of this paradox is the historical legacy corporate silo. If a plant in Chennai faces a sudden logistics bottleneck or a critical machine breakdown, its local team scrambles in isolation. Meanwhile, a sister plant in Pune operates completely unaware that it possesses the excess capacity, specific tooling or material buffers required to absorb the overflow.

By the time information filters up to corporate logistics and decisions are taken, you would have lost precious capacity and time.

Enter MAGS: The rise of agent-to-agent collaboration

To shatter these corporate silos, the reasoning layer must expand past local optimizations and facilitate cross-facility orchestration. This shift is driven by a distinct architectural evolution: Multi-agent generative systems (MAGS). Gartner highlights the rapid acceleration of this trend, predicting that by 2027, one-third of all agentic AI implementations will focus heavily on autonomous agent-to-agent collaboration.

In a MAGS framework, the scheduling agents of individual plants do not operate in a vacuum. Instead, they form an interconnected, distributed network capable of autonomous negotiation. The architectural flow of this cross-facility negotiation occurs across three distinct phases:

  • Perception: Local plant agents continuously ingest live IIoT telemetry, tracking real-time machine interdependencies, resource pooling variances and material transit times across physical transport lanes.
  • Interpretation: When an anomaly occurs, the local agent instantly evaluates the disruption against localized business constraints.
  • Negotiation: Rather than escalating every minor bottleneck to a human director, Plant A’s scheduling agent connects directly to Plant B’s agent over the secure network. The agents cross-negotiate load-balancing options, evaluate transportation lead times and run localized optimization calculations in parallel.

Instead of forcing supply chain teams to manually bridge data gaps during a crisis, the system bypasses legacy functional silos. It presents the COO’s operations team with a pre-validated, end-to-end scheduling solution.

Real-world applications: Grounding autonomy in industrial reality

To understand how this functions in the real world, we must look beyond theoretical multi-agent frameworks and examine how this architecture operates within live factories. The following two case studies—drawn from highly documented, peer-reviewed industrial implementations — demonstrate how multi-agent generative systems (MAGS) actively protect margins and timelines when unexpected disruptions strike.

Case study 1: The discrete architecture (The Festo cyber-physical agent framework)

  • The context: This architecture is modeled after the landmark decentralized orchestration frameworks deployed at Festo’s Scharnhausen Technology Plant. Instead of relying on a centralized ERP/MES brain to dictate every move, the facility utilizes cyber-physical systems (CPS) where the physical components and machines operate as an interconnected multi-agent system (MAS).
  • The disruption: During a high-volume discrete run of automation components, a critical machining center suffering an unexpected tooling failure, in a traditional centralized setup, would have triggered a cascade of line stoppages.
  • The intervention: The affected machine’s resource agent instantly broadcasts its downtime status across the network. The task agents ingest the anomaly and independently query neighboring machining cells. The setup utilizes an underlying ACO routing routine to calculate the most efficient physical path through alternative, under-utilized cells. The Task Agents actively barter for open capacity with these alternative resource agents, dynamically adjusting their own operational sequences.

Case study 2: The process pivot (The TU Dresden battery manufacturing framework)

  • The context: This case is drawn directly from a multi-layer agent-based framework engineered for a European lead-acid battery manufacturer in coordination with researchers at TU Dresden. The environment features 31 highly energy-intensive heat-treatment and curing chambers, where localized utility tariff volatility drastically impacts production margins. Continuous chemical process lines cannot simply be shut down without massive material waste and lengthy restart sequences.
  • The disruption: A sudden, localized weather event triggers an unpredicted spike in peak-load electricity pricing, threatening to entirely erase the profit margin on a high-volume production run.
  • The intervention: To solve this, the plant utilized a multi-layer agent-based framework. An energy-monitoring agent tracking live utility tariff feeds communicated the financial threat directly to the production scheduling agent. Instead of a crude emergency halt, the reasoning layer queried the facility’s computerized maintenance management system (CMMS). The agentic layer identified a mandatory 4-hour preventative maintenance window scheduled for three days later. The agent made an executive operational decision: it pulled that maintenance window forward to occur during the exact hours of peak utility pricing, converting an expensive tariff penalty into required downtime. Simultaneously, lower-level agents representing the individual curing chambers and material pallets recalculated local constraints, instructing the optimization engine to compress and accelerate subsequent production batches during the cheaper, off-peak night shifts.

The business outcome

In both cases, the agents optimized an operational pivot, and optimally utilised production capacity in the former and saved precious cash in the latter.

Governance, trust and the “human-in-the-loop” guardrails

All that seems great and seems like science fiction; it inevitably raises a critical, polarizing question for the C-suite: If the algorithms are making multi-thousand-dollar operational choices in real time, how do we maintain control?

The solution to this executive anxiety is a framework defined as “autonomy within boundaries,” executed through policy-as-code. Under this model, operational leaders stop managing the volatility of daily schedules. Instead, they focus on creating and managing policy boundaries within which the agents are permitted to negotiate and self-heal.

This splits operational exceptions into 2 zones:

  • Autonomous execution zone: The multi-agent system has full authority to re-sequence lines, re-route components or shift maintenance windows autonomously, provided the financial & operational impact is under a predefined limit.  
  • Expert advisory zone: The moment a proposed optimization breaches either of these metrics, the agent pushes it to an executive dashboard for immediate human intervention, validation and approval.

This dual-layer approach introduces a reliable operational framework to industrial manufacturing: leadership manages strategic intent, while tactical units manage real-time execution.

By establishing clear thresholds, the fear of an algorithmic “runaway train” is entirely mitigated. However, deploying a complete multi-agent governance framework across an entire enterprise footprint cannot happen overnight.

To move this from my serendipitous but compelling discovery to a live, risk-mitigated environment, I need a highly controlled, phased deployment strategy, an actionable roadmap to pilot, test and scale the reasoning layer without disrupting current production baselines.

We often say Industry 4.0 connected machines. I believe Industry 5.0 will connect decisions. The factories that succeed will not simply automate workflows; they will build systems capable of reasoning within clearly defined operational boundaries.

I am therefore not writing a conclusion here. I would probably be back in a few months writing about the outcome of this exercise. Somehow deep-down I suspect it would be less oriented to technology but how the change management progressed. I have a strong feeling that “…operational leaders stop managing the volatility of daily schedules. Instead, they focus on creating and managing policy boundaries …” would be the toughest part of this change.   

How AI helps the US Senate Federal Credit Union better manage risk

The United States Senate Federal Credit Union (USSFCU) is a nonprofit financial cooperative that provides traditional retail banking services to entities within the US government, such as the Senate and the Supreme Court.At present, the credit union’s headcount stands at nearly 150 people, managing around $1.6 billion in assets.

A few years back, when it started to expand its use of technology, cybersecurity was a key focus area, but the financial institution faced two major challenges in boosting security as it scaled. The USSFCU was carrying significant technical debt, and there were holes in the organization’s defenses.

“We found gaps where we needed more systems, tools, and people, and then there were instances where we had technologies in place that weren’t being used effectively,” says Mark Fournier, CIO at the credit union. “We weren’t buying a bunch of shiny new things without thinking about it. We were actually quite prescriptive every year, performing a number of different exercises to identify our shortcomings and then finding the right solution to fill the gaps. But over time this adds up. It was clear we couldn’t keep hiring more people and bringing in new solutions.”

The USSFCU needed a more efficient way to bring everything together and make its cyber estate easier to manage. For Fournier and his team, vulnerability management was the hardest hill to climb since they have to deal with about 100 new possible breach points every day.

“When we looked at the problem more closely, the impact of these vulnerabilities was far greater than we realized,” he says. “Not only because of the volume but because of a lack of clear understanding around the potential impact of each one across the broader business.”

Improved risk management

The USSFCU didn’t lack security tools, however. In fact, it had plenty, from scanners and endpoint tools to asset records, tickets, and internal documentation. But each tool saw only a slice of the environment, so there was little to no context. This made it difficult for the security team to separate real business risk from noise.

So for each new vulnerability, the security team had to run a manual investigation, which could take days. And while doing this, they still had to triage the next wave of findings. The organization, therefore, needed a way to know what mattered, why it mattered, who owned it, and whether taking the time to make a fix actually reduced risk. The USSFCU also required a solution to be deployed entirely in-house, leveraging its internal inferences.

Working with Tonic Security, the organization deployed an exposure management solution that pulls together data from different tools and data sources to create a clear picture of business risk. “One of the key functions of the platform is the ability to ingest anything,” says Fournier. “Breaking down silos between disparate systems is essential to unlock valuable contextual information.”

For the USSFCU, transparency and explainability are critical, he adds. This tool uses an AI data fabric to extract context from structured and unstructured data. This context drives prioritization, ensuring the right owner gets the right evidence, not a vague ticket. And once the work is done, the solution checks whether the exposure was reduced.

Because the AI is grounded in the customer’s own environment, it isn’t just guessing from a generic risk model. It reasons over USSFCU’s assets, owners, services, tickets, controls, and business context. But it isn’t using this data to train external models.

Describing one particular incident, Fournier explains that shortly after the initial deployment, various stakeholders met to assess progress. “We thought we were smart because we found an error with the platform,” he says. “The solution had labelled an asset as internet exposed, which we knew was incorrect.” But after a review and lengthy discussion, they were proven wrong. “Almost immediately, the value of bringing this information together became apparent.”

A template for bigger things

Before this solution, a high-severity finding could send an analyst on a lengthy scavenger hunt because of data located in so many different places. They’d check the scanner, asset inventory, tickets, and maybe even ask around to find the owner. But now they can find the asset, the owner, the business relevance, the exposure path, and the recommended action in one place. The solution has reduced the time taken to resolve a vulnerability by 75%. And with a clearer idea of what is and isn’t important, and what adds practical value, the number of incidents someone needs to respond to has reduced from about 100 a month to just 10.

Sharing his lessons from the project, Fournier says one needs to keep an open mind because the problem you think you have is often very different from the one you actually have. “This project has also been an eye-opener around how people can collaborate and operate across different areas of the business,” he says. “When I talk to my peers, they regularly highlight the disconnect between different departments and business functions. But with a project like this, when you’re crossing traditional boundaries, you need to have open lines of communication to succeed.”

The gen AI helping Aetna review millions of medical records

One of the biggest challenges companies like Aetna face every year is an annual HEDIS review of its records to identify gaps in care. For large national payors, the scale of the challenge is immense. So Aetna has deployed a gen AI-driven document intelligence platform that has reduced the need for manual review by 65%.

“We have a large group of amazing trained medical coders who do this every day,” says Nathan Frank, chief digital and technology officer at Aetna. “This is about making it easier for them by speeding up the process. Something that might have taken weeks or months we can now do in days.”

The Healthcare Effectiveness Data and Information Set (HEDIS) is a range of performance measures for the managed care industry. Developed and maintained by the nonprofit National Committee for Quality Assurance (NCQA), the first version of HEDIS was released in 1991.

Under the HEDIS measures, large managed care providers like Aetna review more than 10 million medical records annually to identify gaps in care. These gaps are missed or overdue preventative care or chronic disease management tests including missed cancer screenings, blood sugar tests for diabetics, eye exams, and immunizations. Closing these gaps improves patient outcomes, and health plans are measured in how well they perform. But processing medical records is no easy task.

“We’re talking about medical charts that have white space filled with handwritten notes,” Frank explains. It’s not just structured data, it’s lots of physical clinical documentation.”

Adding up the numbers

Frank says industry benchmarks for large providers indicate an annual review process that requires about 50,000 work weeks, equivalent to nearly 1,000 dedicated full-time employees. It would take a team of 50 reviewers more than 20 years to complete a single annual review using fully manual processes.

Enter AI Medical Chart Review, a platform developed by Aetna that leverages cloud services and gen AI to automatically extract clinically relevant data from records, and prioritize records based on the likelihood of measure closure and evidence strength.

“Large language models and gen AI give us the ability to train a model to decipher the charts, identify the high value codes, and build correlations,” Frank says.

In the space of about six months, Frank’s team ideated the platform, and designed and trained a PoC that was able to process millions of records in just two weeks. As a result, AI Medical Chart Review has earned Aetna a CIO 100 Award in IT innovation.

“Now we’ve gone through 14 million documents,” Franks says. “We’re seeing a reduction of manual effort, which is now being transitioned into other areas like quality control and making sure the automated chart review is working as expected.”

Behind the curtain

Using gen AI, the platform automatically ingests and analyzes unstructured medical records and clinical documents. And as part of that process, it identifies and extracts clinically relevant information for specific HEDIS measures like diagnosis codes, medication records, lab results, and visit documentation. With this data, the platform generates a prioritized set of records based on the likelihood of measure closure and strength of clinical evidence, which is then passed to human employees for review and validation.

Frank says the platform has increased gap closure rates (leading to improved Star Ratings and higher reimbursement), streamlined workflows, and enabled teams once dedicated to manual record review to shift focus to higher-value activities.

Frank says much of the speed and success in building the platform comes down to a shift in the way it approached the design and build process. Rather than exhaustively writing specifications and requirements, Aetna created a team that included engineers and subject matter experts who worked together to build out capabilities iteratively.

“It allowed us to move much faster, and having a business subject matter expert sitting in the same virtual or physical room with us got us a much better outcome,” Frank says. “The product model, our cloud compute model, and our AI governance model allow for quick reviews to make sure we’re using AI responsibly with the right guardrails. It’s increased the speed to get from product launch to go-live.”

He adds that small teams that don’t have to deal with a lot of bureaucracy are key to moving quickly.

“You need to design with security, compliance, and a responsible use of AI as core principles from day one,” he says. “Everything we do from a new build standpoint starts with thinking about how we make it cloud native, how we build with the right elasticity and speed, and how we optimize the cost.”

The most important element of all, he says, is a good relationship with your subject matter experts.

“You can have a great product manager and engineer, but you really need that business subject matter expert who’s excited about it, and who has a passion for transforming the process,” Frank says. “Once you put those three together, you’ll see amazing things like this happen all the time.”

The blueprint for innovation: 3 ways regulatory readiness is a competitive advantage

Too often, brands treat compliance as a downstream exercise. Teams build products, launch new capabilities and then tack on controls afterward.

The pace of technology evolution and adoption has never been faster, and regulatory bodies are doing their best to keep up. For brands, that means they’re standing on shifting ground. They need  to modernize legacy infrastructure, adopt AI responsibly, deliver better customer experiences, maintain trust and navigate increasingly complex regulatory requirements – all at once.

I’ve witnessed this shift firsthand in payments. Fraudsters adapt faster than regulatory cycles, and customer expectations continue to rise regardless of where legislation stands. In one of the most highly regulated sectors, waiting for new mandates to arrive is a losing strategy.

The brands that lead have embraced regulatory readiness as an advantage to better inform technology architecture, operating models and partner strategy.

If I had one piece of advice for CIOs, it would be to treat compliance as part of the blueprint instead of the punch list at the end of a build. With a controls-by-design approach, a collaborative culture, and the right partnerships, any brand can embrace change with confidence and resilience.

3 ways regulatory readiness is a competitive advantage

1. Build a solid foundation

One of the most impactful strategies I’ve seen is the shift from compliance-after-the-fact to controls-by-design.

Forward-thinking financial institutions increasingly treat regulatory frameworks like DORA and the EU AI Act as design principles rather than external requirements. Instead of asking how to retrofit compliance into modern systems, they are asking how thoughtful governance can shape modernization from day one.

For example, the EU AI Act mandates transparency for high-risk AI systems like automated credit scoring. Instead of burying disclosures in the fine print, a smart bank builds an interactive feature directly into its digital banking app, which allows customers to simulate how adjustments will improve their approval odds. By doing so, they transform a regulatory obligation into innovation that builds trust.

After all, when an AI-driven decision fails, customers do not blame the algorithm. They blame the brand. The controls-by-design approach helps ensure those risks are anticipated and managed before they reach the customer.

This feels particularly urgent in the payments industry, where FedNow and stablecoins allow funds to move instantly – and irrevocably. As settlement windows shrink from days to seconds, brands need to embed capabilities like behavioral monitoring, AI-driven fraud detection, account verification and orchestration functionality directly into the transaction architecture itself – as part of the initial design – to identify and mitigate fraudulent activity as it evolves. Regulation, like Nacha’s new rules around ACH fraud, reinforces that direction, but for trust-focused brands, the work begins long before the rules change.

Each of these examples points to the same trend. Brands that embrace a controls-by-design philosophy are constructing technology architectures that are ready to adapt long before the inspectors arrive on site.

2. Align your crew

Technology architecture is only half of the story. The other half is how well your crew works together to bring that architecture to life.

For years, compliance lived in its own lane. Governance acted like a checkpoint. When technology evolved in predictable cycles, that made sense. But today, the brands making the greatest progress build shared accountability into their operating models so they can adapt to regulation in a more coordinated, consistent way.

After all, a construction project is only successful when electricians, plumbers, framers and masons coordinate every step and trust the work happening around them.

The same is true in the enterprise. Instead of focusing on separate priorities, product, engineering, operations, risk and compliance must align around shared outcomes, with greater transparency into how decisions are made, ongoing oversight and continuous feedback loops between teams. As a result, regulatory readiness becomes part of how the business works every day, change becomes easier and the broader benefits across the organization become clear.

In many organizations, I’ve observed how harmony between teams not only increases compliance but also fosters greater customer-centric innovation. When teams operate from a shared, real-time view of the customer, every interaction becomes more connected. Customers experience one brand, not a collection of disconnected teams.

That spirit of collaboration becomes even more important as AI moves deeper into customer-facing and operational workflows. AI innovation has outpaced AI regulation, which makes it even more important for brands to take the initiative to ensure proper controls are in place.

We are already seeing this play out with SR 26-2, the Federal Reserve’s latest guidance on AI for banks. While it establishes important expectations around model risk management, it leaves room for institutions to determine how agentic AI and generative AI should be governed. Instead of treating this as carte blanche, banking leaders should see this as an opportunity to build trust. By leading the way with governed, responsible GenAI and agentic AI operating models, banks can win customers’ trust long before regulation requires it.

No single department should shoulder that responsibility alone. Product teams understand how AI shapes the customer experience. Engineering teams understand how models are built, deployed and monitored. Risk and compliance teams understand governance expectations, while operations teams see how those decisions play out every day. Effective AI governance and innovation emerge when those perspectives come together around a shared view of accountability.

3. Expand your toolkit

Innovation in today’s regulatory environment requires more tools than you may have in your own toolkit.

Technology is more complex, fraud threats evolve faster and AI capabilities require significant investment and ongoing tuning. At the same time, brands have to stay ahead of customer expectations, market dynamics and evolving risk requirements.

It just doesn’t make sense to build every capability yourself when trust, resilience, compliance and speed-to-value are such integral parts of the equation. 

Throughout my career, I’ve seen success with a build-buy-partner approach that brings together the right tools for the right project.

This is particularly important in highly regulated environments, where implementation risk can be as significant as technical risk. That’s where proven results – especially through partnership – might take precedence over experimentation.

I went through this consideration just recently. CSG Forte partnered with IBM to launch PaymentsProtection.ai.

We set out to provide customers with AI-powered fraud detection and financial risk management without spending years recreating capabilities that already existed. By partnering with IBM, we were able to access additional specialty tools: AI capabilities, real-time monitoring, financial risk management expertise and external validation in one of the most sensitive areas of payments. The collaboration reduced fraud losses by 50-70%, lowered false positives and offered customers a smoother, safer experience.

In a market that never stands still, the right tools give brands the freedom to build with greater precision, adaptability and purpose.

Raise the standard

Successful brands are changing how they think about regulation. Instead of looking at it as a burden or a constraint on innovation, they are treating it like a key factor in architectural decisions, crew alignment and partner strategy.

That approach increasingly separates the brands raising the standard from those struggling to keep up. It changes the role regulation plays within the business. It infuses trust, governance and adaptability into a brand’s foundation.

Those capabilities make it easier to scale new builds, navigate future change and innovate with confidence as markets, customer expectations and regulatory requirements continue to charge ahead.

The brands shaping the future won’t be scrambling to reinforce the structure after the cracks appear. They’ll be the ones that construct resilience from the very beginning.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

11 tech experts every CIO should follow on social media

Social media is more than a place to network or follow the latest headlines and trends. For CIOs, platforms like LinkedIn, X, and Bluesky offer direct access to technology executives, AI experts, economists, and business leaders who share ideas, challenge conventional thinking, and provide insights that can help shape tech strategy. Here, 11 IT leaders share the social media experts they follow, and explain why these voices are worth CIOs’ time.

Jensen Huang, founder and CEO, Nvidia

I find Jensen Huang’s insights (X, LinkedIn) fascinating, and there’s much to be admired and learned from. He’s a bold thinker who fosters a culture of continuous learning, which is incredibly valuable in an ever-evolving tech and cyber business environment like Exos. My observations are that Huang is looking to better the lives of his employees, clients and community — and so am I. His content helps me to think differently and his leadership style has a lot of technical depth, which is especially relevant with the rise and momentum of AI. He’s been described as intensely curious, which aligns with Exos’ tagline, We are Curious. – Jose Martinez, CIO and managing director, Exos IT

Jason Crawford, founder and president, Roots of Progress Institute

Jason Crawford is an under-the-radar voice more CIOs should know. He is one of the most important thinkers on the philosophy and history of technology, and his work is about understanding why technological progress happens and how to sustain it. I follow him because his attention and capital directly drive where the industry moves next. – Yaron Hadad, CEO and CTO, Beehive Software

Kelsey Hightower, distinguished engineer, Google

Kelsey Hightower (Bluesky, LinkedIn) is valuable because he explains cloud infrastructure and Kubernetes in a way that’s practical and grounded. What I appreciate about his work is he often brings the conversation back to simplicity, maintainability, and the people who have to operate these systems. For technology leaders, that matters because the hardest part of cloud adoption isn’t choosing tools but making sure teams can run them reliably over time. – Sai Joshitha Kathari, senior site reliability engineer, Visa

Mustafa Suleyman, CEO, Microsoft AI

As an IT leader and advisor to CIOs, one of the voices I pay the closest attention to is Mustafa Suleyman (X) because he thinks beyond the technology itself. He consistently explores how AI changes institutions, labor markets, governance, and power structures. His work has influenced my own thinking about the growing concentration of AI capability and infrastructure in the hands of a relatively small number of organizations. For CIOs, that perspective is valuable because AI is no longer simply a technology investment, but a strategic, infrastructural, and organizational issue. – Matt Hasan, CEO, aiRESULTS, and founder, The AI Humanist Movement

Kevin Benedict, futurist, Tata Consultancy Services

Over the years, I’ve learned that technology leadership is about following people who help you connect innovation to business results, not the loudest voices. One person I consistently follow and recommend is Kevin Benedict (LinkedIn, X). He consistently delivers insights at the intersection of AI, digital transformation, customer experience, leadership, workforce evolution, and innovation. What distinguishes him is his ability to translate emerging technologies into practical business strategies. Rather than focusing on hype, Benedict focuses on execution, adoption, organizational impact, and measurable outcomes. His insights are practical, strategic, and immediately applicable, making him one of the most valuable voices for CIOs and technology executives navigating today’s rapidly evolving digital landscape. – Paul Bailo, digital transformation executive, educator, author, and founder and CEO, Landit.ai

Ethan Mollick, associate professor, The Wharton School

Ethan Mollick (LinkedIn) has the highest post frequency of the thought leadership I follow. From academic papers to showing model improvements by using his own “otter on a plane writing emails” benchmark, he covers a broad spectrum of AI topics. He frequently gets access to the latest models before they come out, and when they do, his posts give a glimpse of what’s new or different, grounded in longer experience with the products. – Andreas Welsch, founder and chief human agentic AI officer, Intelligence Briefing

Dado Van Peteghem, author and keynote speaker on AI, technology, and business

I suggest Dado Van Peteghem (LinkedIn, TikTok) as a thought leader for CIOs to follow. He provides excellent perspectives on the future of work and offers a strategic guide on how CIOs should adapt to AI, digital ecosystems, and new business models. Van Peteghem helps leadership teams understand how digital transformation goes beyond technology upgrades. His focus is on aligning technology, culture, leadership, and business strategy so digital initiatives create measurable business value rather than becoming isolated IT projects. This aligns with what I advocate, hence my support for him and his idea of digital ecosystems. Van Peteghem spells out how AI changes workflows and how organizations should redesign operating models to decide what should be automated versus what should remain human-driven. – Max Vermeir, VP of AI strategy, ABBYY

David Forino, co-founder and CTO, Quanted

David Forino (LinkedIn), led AI research at Volkswagen’s self-driving team and now often posts on LinkedIn about the data bottleneck in quant finance — how teams spend more time keeping data pipelines running than doing research. It’s the same problem most companies run into when they roll out AI, so his tips are always helpful from someone adjacent to them. – Charlie Simionescu-Marin, co-founder and CEO, Quanted

Justina Nixon-Saintil, chief impact officer and president, IBM International Foundation

I have a unique perspective on Justina Nixon-Saintil (LinkedIn) because I’ve also benefited from her guidance and mentorship through Salynt. What stands out to me is her focus on responsible innovation, workforce transformation, and AI governance. She talks about the people and the organizational side of technology adoption, which is often overlooked. Her perspective has reinforced for me that successful AI adoption is as much about trust, culture, and change management as it is about the technology itself. – Natalia Crosdale, COO, Salynt and a former US State Department technology program leader.

Niall Ferguson, senior fellow, The Hoover Institution, Stanford University

Fundamentally, I get the most value from the big brains who focus on consequences rather than capabilities. They help inspire my own thinking about which assumptions about my business stop being true because transformative technology exists. One of the most important voices I follow is Niall Ferguson (LinkedIn, X). He’s a historian, not a technologist, which is precisely why he’s valuable. Technology changes quickly. Institutions, markets, and power structures change slowly. Understanding the gap between the two is where many of the biggest opportunities and risks emerge. – Bill Huber, partner, digital platforms and solutions, ISG

Erik Bernhardsson, CEO, Modal

Good sources don’t make decisions for me, but they improve the quality of questions I ask before I make them. Erik Bernhardsson (LinkedIn) is at the intersection of AI, data infrastructure, and developer experience. Coming from Spotify and now building Modal, he brings a practical view of what modern AI infrastructure actually requires: fast iteration, flexible compute, and reducing infrastructure friction for teams. – Piotr Mynarski, technology director, eSky.com

Exploring Abbott’s mission-led AI strategy

Medical technology companies have always been in the business of trust, and Abbott has been building it with AI for over 10 years. Long before gen AI entered the enterprise conversation, Abbott was using algorithmic AI to help diabetics manage their glucose, and imaging AI to guide surgeons in real time. Here, Sabina Ewing, Abbott’s CIO, explains how a principled approach to AI governance, deep cross-functional partnerships, and a commitment to demonstrating results from within IT have kept them ahead of the curve, and its mission intact.

How is Abbott using AI to achieve its mission and growth strategy?

As a medical technology company, Abbott’s mission is to help people live life to the fullest. For over a decade, we’ve been using AI to deliver on that mission, but whether it’s AI or any other technology, we’re intentional about how it ties to our mission.

Trust is earned in drops and lost in buckets. To ensure we maintain trust with our customers and employees, we’re guided by principles of fairness, safety, quality, and transparency. With these and our mission as our guide, we’re in command of the table we set for ourselves.

How have you been in the AI business for so long?

For decades, we’ve provided FreeStyle Libre, a glucose monitoring sensor built on algorithmic AI, that delivers continuous glucose readings to diabetics, and in some instances, connects to insulin pump applications.

In late 2025, we developed Libre Assist, which leverages generative AI to let FreeStyle Libre users take pictures of their food and receive guidance on the impact of that meal on their glucose levels, including when to eat what, because sequence affects how the body processes glucose.

In our medical devices business, Ultreon, launched in 2021, uses imaging AI to guide optimal stent placement during cardiovascular procedures, supporting the physician’s decision-making in real time.

So whether it’s algorithmic, generative, or agentic, we’re intentional about matching the capability to the specific therapeutic problem.

When technologies evolve, your mission doesn’t change. But how has the CIO evolved during this AI boom?

Today’s CIO must have the strengths of conviction, credibility, and communication. You need technical expertise and to surface data to have the right discussions. You also need to be brilliant on the fundamentals and clear about the strategy, and then execute against it. If I tell the business it can use AI to drive outcomes, then I need to demonstrate it in IT. This is why I’ve committed two commas of results in IT from new AI operational capabilities.

How can CIOs influence their company’s investment in AI?

Working with senior leaders in HR and finance ensures we’re educating the organization and securing necessary investment, and then maintaining financial discipline where investments occur. We hold to that discipline and we’re deliberate about how we deploy the resources of the organization to measurably have impact. We look for high-impact opportunities where new technology delivers results even as it evolves.

We established an executive steering committee on generative AI, and senior leaders are engaged in how we deploy capital. We’re not going out with a thousand flowers blooming.

We also have traditional financial measures we apply to AI investments. And we know you need to be able to identify quantifiable outcomes and then measure them. Those conversations happen in partnership with all senior leaders, especially those business leaders requesting specific capabilities.

As the CIO, you need to have strong relationships with all other parts of the company. I don’t need to be in the spotlight, but you need those relationships in order to lead and effect change. I led a program that helped educate our top leaders on AI foundations, and we’re all working together on the talent side, too. We’ve embedded AI into our talent processes, and we have a continuous cycle of enterprise education through the ranks, both in person and virtual, to ensure our people are ready to use the latest tools and technology. If you want to do something sustainable, you can’t do it by yourself.

What’s your message to your technology team?

What I tell our team is no one is better positioned to lead the organization through this transformative era than its own technical experts. That means we lean into our expertise and AI-first mindset.

Years ago, we crystallized our vision for Abbott IT by unleashing the power of technology and our people in service of Abbott’s purpose. That’s the constant reminder. Our role isn’t to deploy tech but to unlock what technology and people can do together, in service of the mission.

I have asked the team to be bold, bring their best, and pursue excellence. Our strategic pillars are modernization, and protecting Abbott in both enterprise and product cybersecurity, digitization, and advanced analytics. That’s always been part of our mandate.

But what does an AI-first mindset look like? I asked our executive assistants how they, as a community, think about using AI to radically expand what they can do with it as a companion to their work, but not a replacement for it. The models that exist today can’t be a great executive assistant. Models don’t have the judgment, institutional knowledge, or nuanced reasoning required to prioritize work and navigate unspoken rules. That expertise is irreplaceable. Our question is how to augment it.

❌