<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <copyright>Copyright TechTarget - All rights reserved</copyright>
        <description></description>
        <docs>https://cyber.law.harvard.edu/rss/rss.html</docs>
        <generator>Techtarget Feed Generator</generator>
        <language>en</language>
        <lastBuildDate>Wed, 19 Aug 2026 17:17:10 GMT</lastBuildDate>
        <link>https://www.techtarget.com/it-strategy</link>
        <managingEditor>editor@techtarget.com</managingEditor>
        <item>
            <body>&lt;div&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h2&gt;Executive summary&lt;/h2&gt; 
   &lt;ul type="disc" class="default-list"&gt; 
    &lt;li&gt;&lt;b&gt;The botsitting crisis. &lt;/b&gt;Workers spend 6.4 hours weekly fixing AI mistakes -- more time than AI saves them -- reducing net productivity gains to just 4.6 hours per week and increasing turnover risk by 73% with frequent botsitters.&lt;/li&gt; 
    &lt;li&gt;&lt;b&gt;Root causes. &lt;/b&gt;Botsitting stems from a lack of enterprise context, premature deployment, integration failures, training gaps and misaligned incentives that reward AI usage over output quality.&lt;/li&gt; 
    &lt;li&gt;&lt;b&gt;Strategic actions for leaders. &lt;/b&gt;CIOs must prioritize quality over usage, build judgment capabilities, invest in unified AI platforms with organizational context, establish governance guardrails, and measure meaningful metrics beyond adoption rates.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt; 
 &lt;p&gt;Over the past few years, organizations have invested billions in AI, hoping to boost productivity and improve workflows. However, according to &lt;a href="https://www.glean.com/work-ai-institute/reports/work-ai-index" target="_blank" rel="noopener"&gt;Glean's Work AI Index&lt;/a&gt;, AI may be harming productivity rather than helping it. According to the report, workers are spending 6.4 hours a week fixing AI's mistakes to make its outputs usable -- which is more time than workers are using AI for productivity.&lt;/p&gt; 
 &lt;p&gt;The unrecognized and untracked labor and time that employees spend making AI usable -- including checking outputs, debugging mistakes, cleaning up incorrect answers and rerunning prompts, also known as "botsitting" -- is eating up nearly a full workday per week.&lt;/p&gt; 
 &lt;p&gt;Botsitting isn't just a time-suck for employees -- it can actively hurt morale and retention. According to the Glean report, the more time workers spend botsitting, the &lt;a href="https://www.techtarget.com/it-strategy/feature/Beating-AI-fatigue-Quick-wins-for-CIOs"&gt;more worn out they feel&lt;/a&gt;. Frequent botsitters are 73% more likely to be looking for new jobs. Unaddressed AI botsitting can create a ripple effect of consequences across organizations.&lt;/p&gt; 
&lt;/div&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is botsitting?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is botsitting?&lt;/h2&gt;
 &lt;p&gt;Botsitting includes any unmanaged work that workers do to make AI outputs accurate and usable. Botsitting can include several different activities that employees must perform, including:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Feeding AI missing context and organizational knowledge, such as company-specific products and internal processes.&lt;/li&gt; 
  &lt;li&gt;Verifying AI outputs are accurate and identifying any hallucinations.&lt;/li&gt; 
  &lt;li&gt;Debugging AI mistakes and errors.&lt;/li&gt; 
  &lt;li&gt;Rerunning prompts when initial outputs fail.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/it-strategy/feature/AI-slop-The-hidden-enterprise-risk-CIOs-cant-ignore"&gt;Cleaning up "workslop"&lt;/a&gt; -- AI-generated content that's confident but wrong.&lt;/li&gt; 
  &lt;li data-border-margin=".25in"&gt;Switching between disconnected AI tools that don't share context.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;div&gt; 
  &lt;p&gt;According to Glean, workers save an average of 11 hours per week using AI, but after the 6.4 hours spent on botsitting, the net productivity gain from AI is only 4.6 hours per week.&lt;/p&gt; 
 &lt;/div&gt;
 &lt;p&gt;As AI expanded, &lt;a href="https://www.techtarget.com/it-strategy/feature/Debunking-AI-myths-Creating-value-over-hype"&gt;organizations expected AI&lt;/a&gt; to work autonomously. However, as AI got integrated into everyday workflows, the reality became clear: AI requires constant human supervision and correction. This causes a coordination neglect problem, where employees focus on individual productivity but underestimate the coordination required to translate these gains across teams or organizations.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="The botsitting-to-botshifting cycle"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The botsitting-to-botshifting cycle&lt;/h2&gt;
 &lt;p&gt;As workers rely more heavily on AI, their engagement and accountability in their work decrease. Workers take more shortcuts with AI, and the bar for what is considered "good enough" in the final product is lowered, rather than iterating on AI responses to create the best-quality work.&lt;/p&gt;
 &lt;p&gt;Workers who are burnt out and frustrated with botsitting will offload more of their work to AI, and stop verifying sources or double-checking AI's outputs. According to Glean's report, 41% of workers have delivered AI-generated outputs they couldn't explain if asked, and 12% knowingly delivered output they believed was wrong.&lt;/p&gt;
 &lt;p&gt;This causes inaccurate or low-quality AI content to circulate through teams, integrate into workflows, and get passed on to customers. As low-quality information gets spread across the organization, it creates both internal and external risks to the organization's brand, reputation and more.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="How CIOs are seeing botsitting play out in their organizations"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How CIOs are seeing botsitting play out in their organizations&lt;/h2&gt;
 &lt;div&gt; 
  &lt;p&gt;Botsitting isn't just a point of frustration. It's also a productivity drain. The consequences of botsitting can cause ripple effects across the organization, showing up through gaps in ROI, training and adoption, metric tracking and governance.&lt;/p&gt; 
  &lt;p&gt;For example, some workers may be stuck botsitting AI &lt;a href="https://www.techtarget.com/it-strategy/feature/Study-finds-two-hours-a-week-could-close-the-AI-skills-gap"&gt;due to a skills gap&lt;/a&gt;. "Some individuals had very mature agentic systems set up, where they had invested time and energy to ensure an agent had all the context, connections, and instructions required to complete a task very effectively," Christian Chung, director of engineering at Fueled. "Others, in the same role and attempting the same task, but with a less mature agentic workflow, produced far inferior output and required far more human intervention to yield something usable."&lt;/p&gt; 
  &lt;p&gt;"What makes it dangerous is that it doesn't look like a problem," said Chung. "On paper, adoption looks healthy: people are using the tools, and work is going out the door. But a meaningful share of the return you're paying for is quietly leaking back out as human cleanup time that never shows up in any metric."&lt;/p&gt; 
 &lt;/div&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="Root causes of botsitting"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Root causes of botsitting&lt;/h2&gt;
 &lt;p&gt;Botsitting doesn't come from individual workers -- it's a systemic, organizational issue that can quickly become widespread as AI usage surges across the organization without oversight.&lt;/p&gt;
 &lt;p&gt;Botsitting can be caused by:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Lack of enterprise context.&lt;/b&gt; Since large language models (LLMs) do not have company-specific data or organizational knowledge to build off of, AI doesn't have context for specific products, customers, processes, or terminology. Instead, workers must feed AI the additional context needed for quality results.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Premature deployment.&lt;/b&gt; Many companies make the mistake of &lt;a href="https://www.techtarget.com/it-strategy/feature/AI-failure-examples-What-real-world-breakdowns-teach-CIOs"&gt;rushing to implement AI&lt;/a&gt; into workflows without the right preparation and oversight strategies. Leaders overlook pilot testing and iteration to appease boards and stakeholders, leading to a "deploy first, figure it out later" mentality that can slow workflows, waste money and create security risks.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Integration failures.&lt;/b&gt; The absence of an enterprise-wide AI strategy or a platform-specific approach can cause AI tools to operate in silos, leading to fragmented data across systems. Employees then must be "go-betweens" to move and sync data across systems that can't interoperate.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Training and change management gaps.&lt;/b&gt; When organizations rush into AI implementation, employees often miss critical, foundational learning opportunities, including proper training on AI use and prompt engineering, clear guidance on when AI should and shouldn't be used, education on AI risks and hallucinations, and frameworks for evaluating output.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Confident-but-wrong answers.&lt;/b&gt; AI can give convincing but incorrect answers and often gives users the answer they want to hear rather than the true one. Workers – especially those who spend hours a day reviewing AI outputs – can struggle to distinguish accurate from hallucinated content.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Misaligned incentives.&lt;/b&gt; Workers are incentivized and rewarded for using AI without any focus on the quality of their use, while those who spend significant time botsitting go unrecognized. Although AI usage might look good on the surface, it can mask hidden AI supervision costs and inefficiencies.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Strategic actions for CIOs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Strategic actions for CIOs&lt;/h2&gt;
 &lt;div&gt; 
  &lt;p&gt;Once leaders identify the root cause of botsitting, they can create a strategy to address the core issues and reduce botsitting across the organization. "CIOs must treat AI like any other enterprise capability," said Ha Hoang, CIO at Commvault. "They need to start with processes that are well understood, define clear success metrics, establish governance, and continuously measure outcomes."&lt;/p&gt; 
  &lt;blockquote class="main-article-pullquote"&gt;
   &lt;div class="main-article-pullquote-inner"&gt;
    &lt;figure&gt;
     The goal shouldn't be to maximize AI usage; it should be to maximize business value while minimizing unnecessary human oversight.
    &lt;/figure&gt;
    &lt;figcaption&gt;
     &lt;strong&gt;Ha Hoang, CIO at Commvault&lt;/strong&gt;
    &lt;/figcaption&gt;
    &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
   &lt;/div&gt;
  &lt;/blockquote&gt;
 &lt;/div&gt;
 &lt;h3&gt;Focus on maximizing quality, not usage&lt;/h3&gt;
 &lt;div&gt; 
  &lt;p&gt;Overusing AI without a clear strategy can lead to &lt;a href="https://www.techtarget.com/it-strategy/feature/AI-slopification-The-true-cost-of-low-quality-AI-implementation"&gt;low-quality results&lt;/a&gt; at a high cost. To maximize quality, AI should be grounded in an enterprise context, not just data. Leaders should define clear guidance and standards for how, when and why AI should be used, including use case criteria, approval processes, output verification and quality assessment.&lt;/p&gt; 
  &lt;p&gt;"The goal shouldn't be to maximize AI usage; it should be to maximize business value while minimizing unnecessary human oversight," said Hoang.&lt;/p&gt; 
 &lt;/div&gt;
 &lt;h3&gt;Build judgment capabilities&lt;/h3&gt;
 &lt;div&gt; 
  &lt;p&gt;Judgment capabilities should be built across the organization before implementing AI, including training leaders and managers to evaluate AI outputs, developing coaching &lt;a href="https://www.techtarget.com/data-technologies/feature/How-executives-can-build-a-responsible-AI-framework"&gt;frameworks for responsible AI use&lt;/a&gt;, and encouraging employees to share AI tips and best practices.&lt;/p&gt; 
  &lt;h3&gt;Invest in integration and context&lt;/h3&gt; 
  &lt;p&gt;When making decisions about which platforms to purchase, leaders should find a unified process across the organization and consider strategic vendor consolidation to &lt;a href="https://www.techtarget.com/it-strategy/feature/AI-sprawl-vs-CIOs-The-battle-to-control-enterprise-AI"&gt;reduce AI tool sprawl&lt;/a&gt;. Additionally, enterprise-wide AI should have access to internal knowledge bases to improve context and ensure the technology maintains it across sessions.&lt;/p&gt; 
  &lt;p&gt;"You need to work on a knowledge base for AI agents," said Yuri Gubin, CTO at DataArt. "The more you put into it in a way that is consumable by AI, the better. It should … be in the form of plain text that is straight to the point, factual and focused on the content."&lt;/p&gt; 
  &lt;h3&gt;Measure what matters&lt;/h3&gt; 
  &lt;p&gt;Organizations should choose valuable metrics that go beyond just usage, including output quality, botsitting time and patterns, and net productivity gains. In addition to examining how AI improves performance, leaders should assess employee satisfaction and retention for those who use AI, and create feedback loops and track data to identify where AI adds value and where it creates a burden.&lt;/p&gt; 
  &lt;h3&gt;Establish governance guardrails&lt;/h3&gt; 
  &lt;p&gt;Before implementing any AI, organizations should create AI usage policies with clear guidance on responsible use of AI, including examples of when &lt;a href="https://www.techtarget.com/it-strategy/feature/Human-in-the-loop-shouldnt-rubber-stamp-decisions"&gt;human intervention is needed&lt;/a&gt;. Approval workflows should be established for any AI-generated customer-facing content.&lt;/p&gt; 
  &lt;h3&gt;Address the human side&lt;/h3&gt; 
  &lt;p&gt;Emphasize to employees the importance of AI output quality, not just its usage. Incentivize strategic, effective AI use. "Give them time, training and tokens so they can learn faster and more," said Mike Finley, CTO of AnswerRocket. "But in return, demand 'meta results' that are not just their own work but also lessons and policies you can spread around."&lt;/p&gt; 
  &lt;p&gt;Be transparent with employees about how AI is being implemented and integrated into workflows and provide training and development for AI skills across the organization.&lt;/p&gt; 
 &lt;/div&gt;
 &lt;p&gt;&lt;i&gt;Alison Roller is a freelance writer with experience in tech, HR and marketing.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>AI promised productivity gains, but workers now spend hours correcting its errors with AI botsitting -- a hidden cost draining morale and ROI across organizations.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/ai_a205627811.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/AI-botsitting-Why-your-productivity-gains-arent-what-they-seem</link>
            <pubDate>Wed, 19 Aug 2026 15:48:00 GMT</pubDate>
            <title>AI botsitting: Why your productivity gains aren't what they seem</title>
        </item>
        <item>
            <body>&lt;p&gt;&lt;i&gt;In recent months, the tech world has seen security incidents involving the industry's most advanced frontier models. Major AI companies -- including OpenAI, Anthropic and Meta -- disclosed cases where their AI systems exhibited unexpected behavior by accessing external systems and &lt;/i&gt;&lt;a href="https://www.techtarget.com/cybersecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face"&gt;&lt;i&gt;exploiting vulnerabilities&lt;/i&gt;&lt;/a&gt;&lt;i&gt; beyond their intended operational boundaries. &lt;/i&gt;&lt;/p&gt; 
&lt;p&gt;&lt;i&gt;One question that persists is whether the frontier models were "going rogue" or were simply &lt;/i&gt;&lt;a href="https://www.techtarget.com/ai/opinion/HAL-9000-was-right-AI-guardrails-matter-more-than-perfect-models"&gt;&lt;i&gt;following their instructions&lt;/i&gt;&lt;/a&gt;&lt;i&gt; and doing what was intended.&lt;/i&gt;&lt;/p&gt; 
&lt;p&gt;&lt;i&gt;Regardless, these incidents have sparked important conversations about AI safety, security protocols and the responsibilities of both AI developers and enterprise users in maintaining robust guardrails around increasingly powerful language models. &lt;/i&gt;&lt;/p&gt; 
&lt;p&gt;&lt;i&gt;Informa TechTarget recently spoke with Seth Johnson, CTO at Cyara about how CIOs need to think about the evolving nature of the AI frontier models and the implications for enterprise cybersecurity. Based in Austin, Cyara provides &lt;/i&gt;&lt;a target="_blank" href="https://cyara.com/platform/" rel="noopener"&gt;&lt;i&gt;software and services&lt;/i&gt;&lt;/a&gt;&lt;i&gt; for testing and validating CX systems. &lt;/i&gt;&lt;/p&gt; 
&lt;p&gt;&lt;b&gt;Editor's note:&lt;/b&gt;&amp;nbsp;The following transcript was edited for length and clarity.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;b&gt;What are your impressions of the recent stories about ChatGPT, Anthropic and Meta AI models going rogue and hacking into other systems?&lt;/b&gt;&lt;/p&gt; 
&lt;p&gt;Seth Johnson: The first thing is I've been impressed -- for lack of a better word -- that these organizations came forward and basically owned it. The disclosure is a big step, and recognizing that 'we did something wrong and we can do better' is a key to improving things. Anthropic did it after the fact and saw that there were a &lt;a href="https://www.computerweekly.com/news/366646678/Anthropic-lost-control-of-Claude-in-latest-AI-cyber-blunder"&gt;couple of incidents&lt;/a&gt; that had been disclosed that they didn't even know about and then informed a couple of their customers. It was a bit of egg-on-face, certainly, but that's the kind of information you want those large organizations to lead with.&lt;/p&gt; 
&lt;div class="imagecaption alignLeft"&gt;
 &lt;img src="https://cdn.ttgtmedia.com/rms/onlineimages/johnson_seth.jpeg" alt="Seth Johnson, CTO at Cyara"&gt;Seth Johnson
&lt;/div&gt; 
&lt;p&gt;&lt;b&gt;Was there anything specific about the way these models operated that led to the vulnerabilities?&lt;/b&gt;&lt;/p&gt; 
&lt;p&gt;Johnson: At the end of the day, they weren't necessarily model problems -- they were what we call &lt;a target="_blank" href="https://atlan.com/know/agent-harness-failures-anti-patterns/" rel="noopener"&gt;harness failures&lt;/a&gt;. The ecosystems in which these operate were not protected or validated the way they needed to be. Specifically, the &lt;a target="_blank" href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" rel="noopener"&gt;Anthropic situation&lt;/a&gt; was done in an environment where they told the model and the test to solve a particular problem and that it was not connected to the internet. But it was in fact connected to the internet, which it never should have been. That should have been something that was addressed and validated and assured ahead of the tests that were being run. [The model] found out that it did have access to the internet, so as it was trying to do its job and solve its problem. It went out and wreaked havoc outside the environment in which it was operating. It's interesting to see that both situations were slightly different, but they could have been avoided by scoping the environment using the instructions you provided.&lt;/p&gt; 
&lt;p&gt;&lt;b&gt;How do you do that?&lt;/b&gt;&lt;/p&gt; 
&lt;p&gt;Johnson: You can indicate with prompts that this is how we want you to behave, but you also need to ensure that the environment variables align with the instructions that you provided the model. Sometimes there could be competing instructions where you give the model specific instructions, and it says 'this is more important than that' and goes outside the bounds of some other instruction. So, you need to be sure that those &lt;a href="https://www.techtarget.com/ai/post/Why-AI-systems-need-a-boundary-between-reasoning-and-execution"&gt;boundaries are in place&lt;/a&gt;, and saying something like 'this is the simulation' isn't sufficient. You need to ensure that those items are present in the environment.&lt;/p&gt; 
&lt;p&gt;&lt;b&gt;Were these models going rogue or were they just doing what they were supposed to be doing and found vulnerabilities?&lt;/b&gt;&lt;/p&gt; 
&lt;p&gt;Johnson: I'd say the latter. [Based on what we've seen], it appears they were doing exactly what they were instructed to do. It just had too much leash, I suppose, in terms of where it could operate and what it could do.&lt;/p&gt; 
&lt;blockquote class="main-article-pullquote"&gt;
 &lt;div class="main-article-pullquote-inner"&gt;
  &lt;figure&gt;
   Companies need to understand that they need to build technology and capabilities around providing those guardrails to reduce that blast radius.
  &lt;/figure&gt;
  &lt;figcaption&gt;
   &lt;strong&gt;Seth Johnson&lt;/strong&gt;Cyara
  &lt;/figcaption&gt;
  &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
 &lt;/div&gt;
&lt;/blockquote&gt; 
&lt;p&gt;&lt;b&gt;How do companies need to think about these new systems that are continually adapting and evolving?&lt;/b&gt;&lt;/p&gt; 
&lt;p&gt;Johnson: If you're a customer of one of these &lt;a href="https://www.computerweekly.com/opinion/Why-frontier-AI-must-be-stress-tested-before-CISOs-trust-it"&gt;frontier models&lt;/a&gt; -- like OpenAI's, Anthropic's or Google's -- and you're using their LLMs to do things, you can't expect that they are going to be your guardrails. It's an LLM -- it's supposed to be able to tell you all kinds of things. You need to be accountable and responsible for building those guardrails and ensuring that the information your applications, bots or otherwise are requesting is within the area you want them to be. It's building guardrails to ensure that out-of-bounds questions are not answered. Companies need to understand that they need to build technology and capabilities around providing those guardrails to reduce that blast radius. And certainly, they need to have testing and monitoring after the fact to ensure that it's actually doing it.&lt;/p&gt; 
&lt;p&gt;&lt;b&gt;Do enterprises need to think about security differently than they have in the past?&lt;/b&gt;&lt;/p&gt; 
&lt;p&gt;Johnson: If we look specifically at the Hugging Face situation, it found and then exposed a vulnerability. So, it goes back to basic security best practices, such as patching your systems and making sure you are not vulnerable to something like this. Obviously, an ounce of prevention is worth a pound of cure. You need to be able to detect that a vulnerability was exposed, but also what's happening on the inside. That's where &lt;a href="https://www.techtarget.com/it-infrastructure/tip/Observability-vs-monitoring-Whats-the-difference"&gt;observability and monitoring&lt;/a&gt; technologies come into play to help detect anomalies, pattern changes and usage changes that can help you see that something's up here. You don't know what it is, but you should take a look and go in to investigate further. You can't prevent someone from trying, but you can limit the opportunities they have to be successful and then have systems in place to tell you when they were successful and that you need to get involved.&lt;/p&gt; 
&lt;p&gt;&lt;b&gt;These were very high-profile cases. Is that a wake-up call for the industry to say this is the time to start getting your house in order?&lt;/b&gt;&lt;/p&gt; 
&lt;p&gt;Johnson: Yes, certainly. Everybody should already be aware that these types of things can happen. This just happened to be an AI agent playing the nefarious actor instead of a group of hackers. So, organizations should already be aware of those types of activities. This is just now coming from a different threat surface. But how you can ensure that your AI is behaving and doing the things you want it to -- and not the things you don't -- is something people absolutely need to be aware of.&lt;/p&gt; 
&lt;p&gt;&lt;b&gt;Will we see more of these frontier model security incidents?&lt;/b&gt;&lt;/p&gt; 
&lt;p&gt;Johnson: I'd be shocked if this was the last. Hopefully, companies will take it seriously, learn from it and apply the learnings to prevent it from happening again. But I would not be surprised to see it find another way at some point. You close one hole, and ultimately, some things find another. We'll continue to see, on occasion, unique circumstances where a weakness gets exposed and something happens.&lt;/p&gt; 
&lt;p&gt;&lt;i&gt;Jim O'Donnell is a news director for TechTarget, where he covers IT strategy and enterprise ESG.&lt;/i&gt;&lt;/p&gt;</body>
            <description>In this Q&amp;A, Seth Johnson, CTO at Cyara, discusses how enterprises need to sharpen their security policies and infrastructure in the wake of recent AI frontier model incidents.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a386211215.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/AI-model-incidents-highlight-security-concerns</link>
            <pubDate>Wed, 19 Aug 2026 14:50:00 GMT</pubDate>
            <title>AI model incidents highlight security concerns</title>
        </item>
        <item>
            <body>&lt;p&gt;Continuous integration. Continuous monitoring. Continuous authentication. Continuous improvement.&lt;/p&gt; 
&lt;p&gt;The world of IT has an increasing focus on continuous growth, evolution and technological innovation, and it stands to reason that &lt;a href="https://www.techtarget.com/whatis/definition/continuous-learning"&gt;continuous learning&lt;/a&gt; among those responsible for architecting, operating and maintaining these technologies is critical to successful deployments. The result? Ongoing learning is a business resilience strategy, not an HR initiative or a standalone employee career development goal.&lt;/p&gt; 
&lt;p&gt;AI, cloud platforms, automation and cybersecurity threats are evolving faster than legacy IT training models can adapt. Skills become outdated more quickly, increasing operational risk, security exposure, hiring costs and project delays. With demand for talent outpacing supply, organizations can no longer rely solely on recruiting external talent.&lt;/p&gt; 
&lt;p&gt;Below, examine the existing skills crisis before exploring an effective continuous learning strategy. Also, see ways to overcome common implementation obstacles and a phased roadmap that aligns workforce readiness with AI adoption and digital transformation business outcomes.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The accelerating skills crisis"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The accelerating skills crisis&lt;/h2&gt;
 &lt;p&gt;Generative AI, cloud-native architectures, automation, &lt;a href="https://www.techtarget.com/it-infrastructure/definition/DevSecOps"&gt;DevSecOps&lt;/a&gt;&amp;nbsp;and evolving cybersecurity threats continuously reshape IT's required skill set. Continuous releases and deployments mean that previous technology cycles -- once measured in years -- are now ongoing, giving technical knowledge a much shorter shelf life. These forces combine to compress technology cycles, and while they speed up innovation, they also require increased skills development for IT teams.&lt;/p&gt;
 &lt;p&gt;Falling behind on technology learning brings significant business consequences, which can include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Slower innovation.&lt;/b&gt; IT teams take longer to adopt emerging technologies, delaying new products and business improvements.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Delayed AI initiatives.&lt;/b&gt; Slows implementation timelines and reduces the organization's ability to get value from AI investments.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Increased cybersecurity risk.&lt;/b&gt; Leaves teams less prepared to defend against evolving threats, increasing the likelihood of costly security incidents and compliance penalties.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Operational inefficiency.&lt;/b&gt; Teams rely on manual processes, resulting in higher costs, slower service delivery and reduced productivity.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Lower employee satisfaction&lt;/b&gt;&lt;b&gt; and higher turnover.&lt;/b&gt; Leads to &lt;a href="https://www.techtarget.com/it-infrastructure/tip/How-DEX-metrics-help-build-a-better-digital-workplace"&gt;disengaged employees&lt;/a&gt; and talent that pursues other opportunities.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Greater dependence on consultants.&lt;/b&gt; Relying on expensive external specialists increases costs and limits long-term knowledge retention.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;Tracking the ROI of learning&lt;/h3&gt;
 &lt;p&gt;Analyzing the &lt;a href="https://www.techtarget.com/it-strategy/tip/The-ROI-of-IT-training-How-CIOs-can-prove-business-value"&gt;ROI of technical training&lt;/a&gt; reframes learning from a cost center to a strategic lever for workforce capabilities. Analyzing training investments, tracking metrics and aligning learning with business outcomes lets organizations show tangible value.&lt;/p&gt;
 &lt;p&gt;Specific strategies include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Connect &lt;a href="https://www.techtarget.com/it-infrastructure/feature/How-digital-employee-experience-strategy-drives-productivity"&gt;learning outcomes to productivity&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Measure innovation and speed to market.&lt;/li&gt; 
  &lt;li&gt;Quantify risk reduction.&lt;/li&gt; 
  &lt;li&gt;Assess employee retention and engagement.&lt;/li&gt; 
  &lt;li&gt;Evaluate cost savings and internal mobility.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Measuring training ROI combines productivity gains, cost savings and risk reduction to show the effect of training initiatives -- and to demonstrate the consequences of failing to &lt;a href="https://www.techtarget.com/it-infrastructure/feature/IT-skills-development-strategies-to-close-gaps-in-IT-ops"&gt;invest in upskilling&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="5 pillars of effective continuous learning"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;5 pillars of effective continuous learning&lt;/h2&gt;
 &lt;p&gt;Continuous learning is an ongoing organizational capability, not a periodic training initiative or optional career development offering. Create a culture of continuous learning based on the following five pillars.&lt;/p&gt;
 &lt;h3&gt;1. Skills gap analysis&lt;/h3&gt;
 &lt;p&gt;Generate a continuous skills gap analysis that reflects the ever-evolving landscape of technology and innovation.&lt;/p&gt;
 &lt;p&gt;This can involve the following actions:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Assess current capabilities against future business objectives.&lt;/li&gt; 
  &lt;li&gt;Inventory existing certifications, practical experience and &lt;a href="https://www.techtarget.com/whatis/feature/Tips-for-learning-new-technologies"&gt;emerging skills&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Prioritize gaps affecting security, cloud modernization, automation and AI initiatives.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Aim for business outcomes that enable targeted learning investments and reduce wasted training spending.&lt;/p&gt;
 &lt;h3&gt;2. Structured, role-based learning pathways&lt;/h3&gt;
 &lt;p&gt;Map learning pathways to specific IT team roles, such as infrastructure engineers, cloud architects, security, developers and IT managers.&lt;/p&gt;
 &lt;p&gt;Design progressive learning paths that enhance technical and leadership skills, certification roadmaps and internal career progression. Be sure to add an &lt;a href="https://www.techtarget.com/it-strategy/feature/How-to-upskill-in-AI-Lessons-from-a-CIO"&gt;AI upskilling strategy&lt;/a&gt;.&lt;/p&gt;
 &lt;h3&gt;3. Diverse learning formats&lt;/h3&gt;
 &lt;p&gt;Modern technical training formats take advantage of diverse learning styles, flexible delivery methods and targeted objectives.&lt;/p&gt;
 &lt;p&gt;Establish a broad offering using the following options:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Instructor-led training.&lt;/li&gt; 
  &lt;li&gt;Self-paced learning.&lt;/li&gt; 
  &lt;li&gt;Hands-on labs.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/whatis/feature/10-top-artificial-intelligence-certifications-and-courses"&gt;Vendor certifications&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Peer mentoring.&lt;/li&gt; 
  &lt;li&gt;Communities of practice.&lt;/li&gt; 
  &lt;li&gt;Hackathons.&lt;/li&gt; 
  &lt;li&gt;AI sandboxes.&lt;/li&gt; 
  &lt;li&gt;Job rotations.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Blended learning opportunities that combine two or more of these methods offer more flexibility and efficiency.&lt;/p&gt;
 &lt;h3&gt;4. Measurable outcomes and ROI&lt;/h3&gt;
 &lt;p&gt;One key aspect of any initiative is measuring outcomes to demonstrate progress, identify weaknesses and institute continuous improvement. Metrics can drive learning plans forward.&lt;/p&gt;
 &lt;p&gt;Use the following KPIs:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Certification completion.&lt;/li&gt; 
  &lt;li&gt;Skills assessments.&lt;/li&gt; 
  &lt;li&gt;Incident reduction.&lt;/li&gt; 
  &lt;li&gt;Faster deployments.&lt;/li&gt; 
  &lt;li&gt;Reduced downtime.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/it-strategy/feature/4-strategies-to-improve-IT-and-tech-talent-retention"&gt;Employee retention&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Internal promotions.&lt;/li&gt; 
  &lt;li&gt;Cloud migration velocity.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Gather data from learning management systems, HR and talent analytics, operations metrics and performance monitoring tools.&lt;/p&gt;
 &lt;p&gt;At the executive level, track broader metrics that show productivity improvements, project completion rates, security incident reduction and talent retention. Executive dashboards visualize the relationship between training investments and operational performance.&lt;/p&gt;
 &lt;h3&gt;5. Governance and accountability&lt;/h3&gt;
 &lt;p&gt;Continuous learning succeeds when organizations treat it as a strategic business priority rather than an optional employee benefit.&lt;/p&gt;
 &lt;p&gt;Executive sponsors should align learning objectives with organizational goals, while managers should integrate skills development into performance reviews, career planning and regular check-ins. Quarterly reviews help ensure training investments remain aligned with evolving business priorities.&lt;/p&gt;
&lt;/section&gt;                        
&lt;section class="section main-article-chapter" data-menu-title="Common challenges and practical solutions"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Common challenges and practical solutions&lt;/h2&gt;
 &lt;p&gt;Most organizations face similar &lt;a href="https://www.techtarget.com/it-infrastructure/infographic/By-the-numbers-How-upskilling-fills-the-IT-skills-gap"&gt;challenges in showing the benefits of ongoing training&lt;/a&gt; and skills development. The following challenges and their solutions clarify how to structure and govern continuous learning.&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Budget constraints.&lt;/b&gt; Solutions include comparing training costs with hiring and turnover costs and prioritizing skills development for high-impact capabilities.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Limited employee time.&lt;/b&gt; Solutions include reserving protected learning hours, embedding learning into normal workflows and promoting microlearning where appropriate.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Unclear ROI.&lt;/b&gt; Solutions include defining success metrics before launching programs, tying learning outcomes directly to business initiatives and measuring learning results against business outcomes like productivity, incident reduction and employee retention.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Resistance to change.&lt;/b&gt; Solutions include celebrating early success, addressing employee hesitation, highlighting incentives and showing leadership buy-in.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Poor execution.&lt;/b&gt; Solutions include avoiding one-time training events, using generic curricula, failing to follow up and failing to measure success.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Technology alone does not create a learning culture. The existence of a learning management system or training incentives in a job description does not meet today's technical expectations. Clear direction and governance are required.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Implementation roadmap"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Implementation roadmap&lt;/h2&gt;
 &lt;p&gt;Generate a roadmap that enables &lt;a target="_blank" href="https://www.forrester.com/blogs/content-alone-wont-close-your-ai-skills-gap/" rel="noopener"&gt;workforce readiness&lt;/a&gt; to support AI adoption, cybersecurity resilience and digital transformation. Start with the following template.&lt;/p&gt;
 &lt;h3&gt;Months 1-3: Build the foundation&lt;/h3&gt;
 &lt;p&gt;This stage establishes the program's foundation and is critical to its success. Organize the following components:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Executive sponsorship.&lt;/li&gt; 
  &lt;li&gt;Skills inventory.&lt;/li&gt; 
  &lt;li&gt;Gap analysis.&lt;/li&gt; 
  &lt;li&gt;Business priorities.&lt;/li&gt; 
  &lt;li&gt;Success metrics and reporting.&lt;/li&gt; 
  &lt;li&gt;Budget approval.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;Months 4-6: Launch targeted pilots&lt;/h3&gt;
 &lt;p&gt;This stage focuses on high-impact teams and skills, typically including the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Security.&lt;/li&gt; 
  &lt;li&gt;Cloud operations.&lt;/li&gt; 
  &lt;li&gt;Infrastructure automation.&lt;/li&gt; 
  &lt;li&gt;AI enablement.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/it-infrastructure/tip/Strategies-to-boost-DEX-scores-and-employee-productivity"&gt;Track engagement, skills gains and productivity improvements&lt;/a&gt; within these pilot programs.&lt;/p&gt;
 &lt;h3&gt;Months 7-12: Scale across IT&lt;/h3&gt;
 &lt;p&gt;Apply successful practices from the pilot programs to continuous learning practices across all IT roles. Expand on successful skills development approaches like the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;a href="http://techtarget.com/ai/tip/How-to-build-AI-skills-across-your-workforce"&gt;Role-based learning paths&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Certification programs.&lt;/li&gt; 
  &lt;li&gt;Mentoring.&lt;/li&gt; 
  &lt;li&gt;Knowledge sharing.&lt;/li&gt; 
  &lt;li&gt;Internal communities.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Integrate learning into employee career planning, performance metrics and promotion criteria.&lt;/p&gt;
 &lt;h3&gt;Months 13+: Optimize and sustain&lt;/h3&gt;
 &lt;p&gt;Retain momentum and optimize performance by instilling continuous IT learning as a component of the broader business strategy. Establish quarterly skills reviews, refresh learning paths as business priorities evolve and monitor KPIs with business outcomes in mind. The goal is to establish continuous skill improvement in the organizational culture.&lt;/p&gt;
&lt;/section&gt;               
&lt;section class="section main-article-chapter" data-menu-title="Sustaining a learning culture"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Sustaining a learning culture&lt;/h2&gt;
 &lt;p&gt;Begin by assessing current skills gaps, establishing governance, documenting measurable outcomes and initiating focused pilot programs.&lt;/p&gt;
 &lt;p&gt;Specific leadership behaviors sustain a continuous learning culture. Leaders themselves model continuous learning, demonstrating the importance of skills development.&lt;/p&gt;
 &lt;p&gt;In addition, leaders can reward creative problem-solving, experimentation and knowledge sharing shown by individual employees.&lt;/p&gt;
 &lt;p&gt;Finally, aligning learning investments with strategic initiatives rather than annual training calendars lets IT teams correlate training objectives with business outcomes, increasing buy-in and engagement.&lt;/p&gt;
 &lt;p&gt;IT upskilling is a strategic organizational capability rather than a one-time project, showing how technology change continues to accelerate. A company's competitive advantage increasingly depends on adaptable talent, and organizations that invest in structured IT upskilling and measure learning programs will be better positioned to adopt AI securely, modernize infrastructure and retain talent.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Damon Garn owns Cogspinner Coaction and provides freelance IT writing and editing services. He has written multiple CompTIA study guides, including the Linux+, Cloud Essentials+ and Server+ guides, and contributes extensively to TechTarget Editorial, The New Stack and CompTIA Blogs.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Continuous learning is essential in IT to bridge skill gaps, drive innovation and keep teams resilient against evolving technologies and cybersecurity threats.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/certification_g1134366943.jpg</image>
            <link>https://www.techtarget.com/it-strategy/tip/Continuous-IT-learning-in-the-age-of-AI-cloud-and-automation</link>
            <pubDate>Wed, 19 Aug 2026 13:19:00 GMT</pubDate>
            <title>Continuous IT learning in the age of AI, cloud and automation</title>
        </item>
        <item>
            <body>&lt;p&gt;Organizations worldwide have headed in the direction of environmental, social and governance, or ESG, initiatives over the past decade to improve sustainability.&lt;/p&gt; 
&lt;p&gt;While the &lt;a href="https://www.techtarget.com/it-strategy/feature/9-ESG-benefits-for-businesses"&gt;beginning brought some enthusiasm for the approach&lt;/a&gt;, that energy has waned in recent years, with fewer public pronouncements about ESG efforts, especially in the U.S. Different levels of government in certain jurisdictions have also pushed back on these efforts.&lt;/p&gt; 
&lt;p&gt;The reality is that the ESG label has become a liability, even where the underlying programs have not. Leading organizations facing anti-ESG backlash are not necessarily shutting down these programs; they are translating them into language a skeptical board already respects.&lt;/p&gt; 
&lt;p&gt;Boards have stopped rewarding the values pitch, which is the case for sustainability made on ethical or mission grounds alone, according to Zach Evans, CTO at healthcare technology company Xsolis.&lt;/p&gt; 
&lt;p&gt;"The values pitch is effectively dead in the boardroom, and leading with it now costs you credibility," Evans said.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Understanding the ESG landscape"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Understanding the ESG landscape&lt;/h2&gt;
 &lt;p&gt;The ESG landscape is not uniform and is somewhat confusing due to &lt;a href="https://www.techtarget.com/it-strategy/feature/Top-ESG-reporting-frameworks-explained-and-compared"&gt;fragmentation in the regulatory landscape&lt;/a&gt;.&lt;/p&gt;
 &lt;h3&gt;Political fragmentation&amp;nbsp;&lt;/h3&gt;
 &lt;p&gt;Fragmentation often has a lot to do with politics across different jurisdictions. In the U.S., the Securities and Exchange Commission voted on May 29 to propose fully &lt;a target="_blank" href="https://www.sec.gov/newsroom/press-releases/2026-49-sec-proposes-rescission-climate-related-disclosure-rules" rel="noopener"&gt;rescinding&lt;/a&gt; the climate-related disclosure rules it adopted in March 2024.&lt;/p&gt;
 &lt;p&gt;Alternatively, the EU has moved in the opposite direction. The Council of the EU finalized its Omnibus I Directive on Feb. 24, narrowing the &lt;a href="https://www.techtarget.com/it-strategy/tip/CSRD-explained-What-US-other-companies-need-to-know"&gt;scope of the Corporate Sustainability Reporting Directive&lt;/a&gt; (CSRD) to companies with more than 1,000 employees and more than 450 million euros in annual turnover, while retaining mandatory sustainability reporting for large enterprises.&lt;/p&gt;
 &lt;h3&gt;State-level divergence&amp;nbsp;&lt;/h3&gt;
 &lt;p&gt;To add further complexity to the landscape, requirements diverge within the U.S. itself.&lt;/p&gt;
 &lt;p&gt;Passed in 2021, &lt;a target="_blank" href="https://www.americanbar.org/groups/environment_energy_resources/resources/trends/2026-may-june/texas-sb13-future-of-state-anti-esg-laws/" rel="noopener"&gt;Texas SB 13&lt;/a&gt; is one of the country's best-known anti-ESG laws. It blocks the state from investing in or hiring financial firms that the state comptroller labeled as boycotting fossil fuel companies. This regulation was seen by some as a way of punishing banks and asset managers for factoring climate risk into their decisions.&lt;/p&gt;
 &lt;p&gt;A federal judge struck the law down as unconstitutional on Feb. 4. The ruling applies only to Texas, but similar anti-ESG laws in other states now face the same legal risk.&lt;/p&gt;
 &lt;p&gt;On the other hand, California is moving in the opposite direction. Large companies doing business in the state face a Nov. 10 deadline to report &lt;a href="https://www.techtarget.com/it-strategy/feature/Scope-1-2-and-3-emissions-Differences-with-examples"&gt;Scope 1 and Scope 2 emissions&lt;/a&gt; under SB 253.&lt;/p&gt;
 &lt;h3&gt;The greenhushing phenomenon&amp;nbsp;&lt;/h3&gt;
 &lt;p&gt;With the regulatory fragmentation and general uncertainty around ESG reporting, many companies have chosen to say less rather than pick a side. That's the phenomenon now commonly referred to as &lt;a target="_blank" href="https://www.techtarget.com/sustainability/feature/How-to-lead-on-sustainability-in-the-rise-of-greenhushing" rel="noopener"&gt;greenhushing&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Greenhushing is not about abandoning ESG, but rather about deliberately withholding information related to sustainability efforts to avoid public scrutiny.&lt;/p&gt;
 &lt;p&gt;EcoVadis' 2025 U.S. Business Sustainability Landscape &lt;a target="_blank" href="https://www.esgdive.com/news/us-companies-quietly-maintaining-boosting-sustainability-investments-ecovadis-business-outlook/753229/" rel="noopener"&gt;Outlook&lt;/a&gt; found that 48% of surveyed companies kept sustainability investment unchanged, and 31% said they are investing more while promoting it less. The gap between what companies do and what they will say in public is exactly the space IT and sustainability leaders now must manage.&lt;/p&gt;
&lt;/section&gt;              
&lt;section class="section main-article-chapter" data-menu-title="Why IT leaders can't afford to abandon sustainability"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why IT leaders can't afford to abandon sustainability&amp;nbsp;&lt;/h2&gt;
 &lt;p&gt;Even with the regulatory confusion and the trend toward greenhushing, IT leaders must remain focused on sustainability efforts.&lt;/p&gt;
 &lt;p&gt;Sustainability is not going away. It has real requirements, especially in the EU and California, with which organizations must comply. The basis of compliance is typically auditable data built and maintained by IT systems. If IT leaders step back, it severely affects an organization's ability to back up its sustainability claims.&lt;/p&gt;
 &lt;p&gt;For IT leaders, this work is no longer a separate program that can be paused or handed off. It &lt;a href="https://www.techtarget.com/it-strategy/feature/How-to-handle-energy-cost-management-for-IT-leaders"&gt;shows up directly in the infrastructure budget&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;"For any company running AI at scale, energy isn't an ESG line item anymore; it's a direct and growing line on the P&amp;amp;L [profit and loss], so compute efficiency is just cost discipline," Evans said.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Strategic responses to anti-ESG movements"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Strategic responses to anti-ESG movements&lt;/h2&gt;
 &lt;p&gt;Leading organizations are taking several different approaches to adjust to potential anti-ESG sentiment.&lt;/p&gt;
 &lt;h3&gt;Reframe ESG as a business strategy&lt;/h3&gt;
 &lt;p&gt;Rather than treating ESG as a compliance initiative, teams can frame it as a corporate sustainability strategy anchored in business fundamentals.&lt;/p&gt;
 &lt;p&gt;Anuj Shah, who leads the global ESG and impact consulting practice at Grant Thornton Stax, pointed to an unconventional example with AI leader Anthropic. Rather than having ESG as part of its communications plan, Anthropic integrated responsibility and risk management into its legal structure. It's structured as a public benefit corporation, which lets directors balance a stated public-benefit mission with shareholder interests.&lt;/p&gt;
 &lt;p&gt;Shah's broader point extends past any single company.&lt;/p&gt;
 &lt;p&gt;"Companies operating in sectors where stakeholder trust, governance, resilience and license to operate are fundamental business issues that don't necessarily need ESG labels for the work to remain important and visible," Shah said.&lt;/p&gt;
 &lt;h3&gt;Strengthen data and technology infrastructure&lt;/h3&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/data-technologies/feature/Modern-data-architectures-as-a-risk-management-strategy"&gt;Data is the foundation&lt;/a&gt; for all types of reporting, and having the right instrumentation in place is a clear sign of proper IT instrumentation that measures the organization and its risk.&lt;/p&gt;
 &lt;p&gt;"Genuine risk management requires measurement infrastructure: metered energy data, supply chain traceability [and] auditable emissions accounting," said Mark McNees, managing consultant at The McNees Group and director of the Social and Sustainable Enterprises at Florida State University's Jim Moran College of Entrepreneurship. "That is systems work, and it leaves a trail of procurement, integration projects and head count."&lt;/p&gt;
 &lt;h3&gt;Refine the communications approach&lt;/h3&gt;
 &lt;p&gt;Rather than considering and discussing ESG in altruistic terms, there is value in having the &lt;a href="https://www.techtarget.com/it-strategy/feature/How-to-get-executive-buy-in-for-sustainability"&gt;right language for the right audience&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;"Certainly, a risk-based language model will appeal more to board members, finance leaders, etc. And a value/values-driven model will be a stronger hook for marketing, sales and operations teams," said Marcy Twete, founder and CEO of ESG consulting firm Veerless.&lt;/p&gt;
 &lt;h3&gt;Engage stakeholders strategically&lt;/h3&gt;
 &lt;p&gt;ESG shouldn't be a standalone department anymore.&lt;/p&gt;
 &lt;p&gt;"We've seen a number of companies reframe from an ESG focus and perhaps an ESG department to a cross-functional ownership model run by a Steering Committee," Twete said.&lt;/p&gt;
 &lt;p&gt;Going a step further, she also noted IT leaders should integrate sustainability into existing risk processes.&lt;/p&gt;
 &lt;p&gt;"It's not enough to name cybersecurity an ESG risk as well as a financial one. You have to also value that risk across multiple functions," Twete said.&lt;/p&gt;
 &lt;h3&gt;Focus on measurable impact&lt;/h3&gt;
 &lt;p&gt;Altruistic, generic goals are not the right path to overcoming anti-ESG sentiment. Instead, &lt;a href="https://www.techtarget.com/it-strategy/feature/ESG-metrics-Tips-and-examples-for-measuring-ESG-performance"&gt;quantifiable performance metrics&lt;/a&gt; can help teams prepare for and respond to these movements.&lt;/p&gt;
 &lt;p&gt;McNees teaches graduate students to build intensity metrics, such as emissions per revenue dollar.&lt;/p&gt;
 &lt;p&gt;"An intensity metric is a profit metric wearing an environmental label," McNees said.&lt;/p&gt;
&lt;/section&gt;                      
&lt;section class="section main-article-chapter" data-menu-title="Action plan for business leaders"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Action plan for business leaders&amp;nbsp;&lt;/h2&gt;
 &lt;p&gt;Building out an action plan to overcome anti-ESG backlash requires both short-term and long-term actions.&lt;/p&gt;
 &lt;p&gt;Immediate actions to take include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Audit communications.&lt;/b&gt; Review &lt;a href="https://www.techtarget.com/it-strategy/feature/Key-sustainability-communications-strategies-for-businesses"&gt;all current ESG communications&lt;/a&gt; and remove politically charged language. The fix is not silence; it is a different framing. "What works is showing the board that most of these efforts are already funded under other names," Evans said.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Detail claims.&lt;/b&gt; Establish empirical evidence for all sustainability claims to fight against potential backlash. "The strongest business cases are usually the ones that can answer one or more of those questions with evidence rather than aspirations," Shah said.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Identify outcomes.&lt;/b&gt; Rather than having generic initiatives, leaders should map ESG initiatives to specific business outcomes, including cost savings, risk reduction and customer retention. "If executive compensation, procurement scoring or divisional budgets move when environmental and social metrics miss, the work is real, because the organization made it expensive to ignore," McNees said.&amp;nbsp;&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Integrate into risk management.&lt;/b&gt; ESG cannot be siloed. IT leaders should implement data governance &lt;a href="https://www.techtarget.com/it-strategy/feature/The-importance-of-sustainability-and-finance-alignment"&gt;controls for ESG comparable to financial reporting&lt;/a&gt; standards. "Good risk management in ESG should easily slot into the company's larger enterprise risk management processes," Twete said.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Some activities that require long-term planning include the following:&amp;nbsp;&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Link executive compensation to measurable ESG outcomes.&lt;/b&gt; "If nothing in anyone's pay changes, the metrics are decorative," McNees said.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Establish supply chain due diligence infrastructure. &lt;/b&gt;Organizations need systems to identify and document ESG risks among suppliers, not just their own emissions. Large multinational firms already face this under the EU's Corporate Sustainability Due Diligence Directive, which will be fully in effect by 2029.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Prepare for regulatory convergence. &lt;/b&gt;Regulations are on a path toward convergence in many jurisdictions.&lt;b&gt; &lt;/b&gt;The International Sustainability Standards Board (ISSB) has a single global baseline for sustainability disclosure, making reporting easier. The ISSB absorbed two earlier frameworks: SASB, which set industry-specific metrics, and TCFD, a climate-risk management framework that formally disbanded once its recommendations were folded into the new standard. The EU is not adopting ISSB directly, but its CSRD requirements are largely comparable, enabling compatibility across the two reporting regimes.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Build business resilience and adaptation capabilities.&lt;/b&gt; Functionally building ESG compliance is about supporting business resilience and reducing risk.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;"I frame the whole thing as enterprise durability: the practices that keep costs defensible, keep you through a security review and keep you resilient," Evans said.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Fundamentally, ESG is about accountability, in good times and bad. Whatever approach a company takes to the anti-ESG backlash, it eventually faces the same test -- not hostile legislature or a skeptical board, but a bad quarter.&lt;/p&gt;
 &lt;p&gt;"The most reliable signal is whether it survives a bad quarter. That's when cosmetic commitments are the first thing cut, because nobody owns them. Real commitments hold because by then they're load-bearing: They're tied to cost, risk or revenue that someone is measured on," Evans said.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Anti-ESG sentiment is rising, so companies must adapt their sustainability messaging and IT leaders must prioritize compliance and data integrity to support ESG initiatives.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/esg_a506458222.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/How-to-overcome-anti-ESG-movements</link>
            <pubDate>Tue, 18 Aug 2026 10:28:00 GMT</pubDate>
            <title>How to overcome anti-ESG movements</title>
        </item>
        <item>
            <body>&lt;p&gt;As pressures mount on hyperscalers to power energy-hungry AI data centers, it is becoming increasingly difficult to meet previously announced energy commitments.&lt;/p&gt; 
&lt;p&gt;In July 2026 (July 23), multiple media outlets revealed that Meta had left the Climate Group's RE100, an initiative focused on committing organizations to use &lt;a href="https://www.techtarget.com/it-infrastructure/tip/Solar-shift-How-data-centers-can-embrace-renewable-energy"&gt;renewable energy sources&lt;/a&gt;. The RE100 was started in 2014, with Meta (then called Facebook) joining the effort in 2016. The initiative has over 400 members, including Apple, Google and Microsoft. The key goal of the RE100 is to get all member organizations to be using 100% renewable energy and provide reporting on progress toward that goal.&lt;/p&gt; 
&lt;p&gt;According to the reports,&amp;nbsp; Meta left the group after it was no longer able to meet the RE100's technical criteria for renewable energy. Meta has increasingly been investing in non-renewable energy sources including gas power. However, the company Meta claimed that it is still committed to clean energy even though it is leaving the RE100.&lt;/p&gt; 
&lt;p&gt;It's likely that Meta is being driven by conflicting priorities.&lt;/p&gt; 
&lt;p&gt;"This doesn't mean Meta has stopped investing in renewables," said Boris Kolev, global head of technology at JA Worldwide. "It means reliability, speed to capacity and AI competitiveness now appear to be more important than remaining within an external renewable-energy framework. A divorce can be mutual and still be driven by incompatible priorities."&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The AI power crunch behind the exit"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;&lt;b&gt;The AI power crunch behind the exit&lt;/b&gt;&lt;/h2&gt;
 &lt;p&gt;In 2016, when Meta (then Facebook) joined RE100, the modern generative AI boom didn't exist. The AI buildout in recent years has &lt;a href="https://www.techtarget.com/it-infrastructure/tip/How-much-energy-do-data-centers-consume"&gt;vastly surpassed&lt;/a&gt; what the current renewable energy pipeline can provide.&lt;/p&gt;
 &lt;p&gt;The International Energy Agency (IEA) &lt;a href="https://www.iea.org/reports/energy-and-ai/energy-demand-from-ai" target="_blank" rel="noopener"&gt;forecast&lt;/a&gt; that U.S. electricity consumption from data centers is projected to rise from roughly 185 terawatt-hours in 2024 to about 425 terawatt-hours by 2030. The IEA also expects that natural gas and coal together are projected to meet more than 40% of the additional electricity demand from data centers globally through 2030.&lt;/p&gt;
 &lt;p&gt;Meta is aligned with the IEA's forecast and is building out natural gas-powered facilities in at least two U.S. states. In Ohio, Meta is building out its Prometheus 1 gigawatt data center campus that will benefit from a 200-megawatt natural gas plant, in addition to pulling from nuclear power.&lt;/p&gt;
 &lt;p&gt;Entergy Louisiana is constructing 10 gas plants in Louisiana that are projected to provide approximately 7.5 gigawatts of power to Meta's Hyperion data center campus.&lt;/p&gt;
 &lt;p&gt;The power strain traces back to how &lt;a href="https://www.techtarget.com/it-infrastructure/tip/How-to-optimize-networks-for-AI-workloads-in-the-cloud"&gt;AI workloads&lt;/a&gt; differ from ordinary cloud computing.&lt;/p&gt;
 &lt;p&gt;AI workloads broke the assumptions that data centers were built on, according to Srinivas Chippagiri, a senior member of technical staff in cloud infrastructure at Salesforce. The public cloud was sized for general purpose, mostly-idle-tolerant workloads that spread demand across time and regions.&lt;/p&gt;
 &lt;p&gt;"AI training and inference are the opposite: power-dense, sustained, and concentrated in specific facilities close to the accelerators and the data," he said.&lt;/p&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="&amp;quot;Still Committed&amp;quot; -- The certificate gap"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;&lt;b&gt;"Still Committed" -- The c&lt;/b&gt;&lt;b&gt;ertificate &lt;/b&gt;&lt;b&gt;gap&lt;/b&gt;&lt;/h2&gt;
 &lt;p&gt;Even though Meta has left the RE100 and is actively building out gas power plants, it is still claiming that it is committed to renewable energy sources.&lt;/p&gt;
 &lt;p&gt;Meta's claim is based on its use of &lt;a target="_blank" href="https://www.epa.gov/green-power-markets/energy-attribute-certificates-eacs" rel="noopener"&gt;Energy Attribute Certificates&lt;/a&gt; [EACs], which follow the same market-based logic as carbon offset trading. The idea is that a company buys a credit for renewable energy that's&amp;nbsp; produced somewhere to offset the non-renewable energy it is using. &lt;a href="https://sustainability.atmeta.com/asset/2023-environmental-metrics-methodology/" target="_blank" rel="noopener"&gt;According to Meta&lt;/a&gt;, for every megawatt-hour of electricity its operations use, the company buys and retires one EAC.&lt;/p&gt;
 &lt;p&gt;It's a claim that has a few skeptics.&lt;/p&gt;
 &lt;p&gt;"Meta claiming 100% clean energy through certificates is an accounting gimmick, not actual change," said Matthew Roling, who teaches carbon accounting and climate finance at Northwestern's Kellogg School of Management.&lt;br&gt;&lt;br&gt;The point of any carbon offset rests on a key concept called additionality, he said. The idea is that buying an EAC means that somewhere clean energy is being built, but this isn't always accurate.&lt;/p&gt;
 &lt;p&gt;For example, Meta could buy a cheap certificate from a wind farm that's been running for 15 years in another state and claim that its coal-powered data center is clean, although nothing new has been built and the grid has not changed, Roling said.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Meta leaving RE100 while still claiming to be 100% clean is greenwashing.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Matthew Roling&lt;/strong&gt;Executive Director and Assistant Clinical Professor, Northwestern Kellogg School of Management
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;"Buying a certificate from an old wind farm doesn't put one new watt of clean power anywhere, it's like buying a receipt for a tree someone else already planted and calling it your forest," he said.&lt;/p&gt;
 &lt;p&gt;&lt;a href="https://www.nature.com/articles/s41558-022-01379-5" target="_blank" rel="noopener"&gt;Research&lt;/a&gt; published in 2022 backs up Roling's assertion by finding that companies were claiming a 31% cut in their footprint on paper, when the reality was closer to 10%.&lt;/p&gt;
 &lt;p&gt;"Meta leaving RE100 while still claiming to be 100% clean is &lt;a href="https://www.techtarget.com/it-strategy/feature/9-biggest-examples-of-greenwashing"&gt;greenwashing&lt;/a&gt;," he said.&lt;/p&gt;
 &lt;p&gt;Jeremy Roberts, senior director of research and content at Info-Tech Research Group is also skeptical about the use of certificates. In particular, Meta is doing its offset purchases based on its annual energy consumption, which might not be entirely accurate, he said.&lt;/p&gt;
 &lt;p&gt;"Hourly matching is a tougher test and would require Meta to balance its consumption with renewable generation on an hourly basis, not just when it's convenient," Roberts said. "It's easier to do that over a whole year, given things like seasonal trends in generation and demand."&lt;/p&gt;
&lt;/section&gt;            
&lt;section class="section main-article-chapter" data-menu-title="Not just Meta -- An industry-wide reckoning"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;&lt;b&gt;Not just Meta -- &lt;/b&gt;&lt;b&gt;An &lt;/b&gt;&lt;b&gt;industry-wide r&lt;/b&gt;&lt;b&gt;eckoning&lt;/b&gt;&lt;/h2&gt;
 &lt;p&gt;The AI buildout is not limited to Meta. Every hyperscaler faces the same pressure from AI and its immense power requirements, including Apple, Google and Microsoft, which still remain among RE100 members.&lt;/p&gt;
 &lt;p&gt;Microsoft recently signed a &lt;a target="_blank" href="https://www.chevron.com/newsroom/2026/q2/chevron-signs-20-year-power-agreement-with-microsoft-for-west-texas-data-center" rel="noopener"&gt;gas deal with Chevron&lt;/a&gt; for a West Texas data center and Google also announced &lt;a target="_blank" href="https://cleanview.co/reports/google-power-strategy" rel="noopener"&gt;gas deals in Texas&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Meta is not alone in using fossil fuels to power data centers, Roberts said.&lt;/p&gt;
 &lt;p&gt;"Google has done it and Amazon has been actively seeking out locations near gas plants to meet power needs," he said.&lt;/p&gt;
 &lt;p&gt;Roling expects the climate commitments from Big Tech vendors to continue to fall apart in the face of AI pressure and AI has destroyed that brand halo.&lt;/p&gt;
 &lt;p&gt;"Fifty-five percent of US data center power already comes from gas and coal, and that share is climbing," Roling said. "Now, they can't build data centers fast enough, so they've all totally walked back, watered down, or abandoned their climate commitments. Watch Apple, Google, and Microsoft next, they're on the same path Meta was two years ago."&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="What this means for CIOs' own commitments"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;&lt;b&gt;What this means for CIOs' own commitments&lt;/b&gt;&lt;/h2&gt;
 &lt;p&gt;Meta's exit from RE100 and the overall shift in power requirement that AI demands is shifting how CIOs are considering &lt;a href="https://www.techtarget.com/it-strategy/feature/How-to-structure-a-sustainability-governance-framework"&gt;ESG commitments&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Companies are making calculated decisions to scale as quickly and aggressively as possible and environmental concerns are not top-of-mind, according to Roberts.&lt;/p&gt;
 &lt;p&gt;"Will they attract increased scrutiny? Almost certainly. Will that change their ultimate direction? Probably not," he said. "If gas plants are going to help these companies participate in what they perceive as a generational technology shift that could unlock trillions of dollars in value, I anticipate they will build gas plants."&lt;/p&gt;
 &lt;p&gt;That leaves the burden on individual buyers. A vendor's headline sustainability claim and its operational reality can be two different things.&lt;/p&gt;
 &lt;p&gt;"Most CIOs and IT leaders ask their SaaS or AI vendor 'are you using clean energy,' get a 'yes,' and stop there," Roling said.&lt;/p&gt;
 &lt;p&gt;Roling recommends that CIOs ask three things to dig deeper on the issues:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;First, ask for &lt;a href="https://www.techtarget.com/it-infrastructure/tip/Understand-the-power-usage-effectiveness-metric"&gt;power usage effectiveness [PUE]&lt;/a&gt;, a simple efficiency score for the specific data center running your workload. The industry average is 1.58 and the best facilities run under 1.2. It's a bad sign if a vendor can't or won't provide this number to a potential customer.&lt;/li&gt; 
  &lt;li&gt;Second, ask for the power mix by region, not the company average.&lt;/li&gt; 
  &lt;li&gt;Third, ask if their clean energy claim is annual or hourly. Annual reporting is a shell game, hourly means something real, Roling said.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Simply taking vendor claims at face value isn't enough either. The paperwork behind a claim also matters.&lt;/p&gt;
 &lt;p&gt;Documentation should explain exactly how the company arrives at its emissions numbers and if it's shifting all power generation to renewables and are practicing hourly matching, Roberts said.&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;"In short, where is the electricity that is actually powering the datacenters coming from? What are the company's total emissions?" he said.&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="Call to Action for CIOs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;&lt;b&gt;Call to Action for CIOs&lt;/b&gt;&lt;/h2&gt;
 &lt;p&gt;For CIOs there are a few specific action items that can be taken as power demand exceeds renewable supply:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Reassess sustainability targets&lt;/b&gt;. AI is pushing demand past what renewables can supply, so CIOs should reassess sustainability targets, including net-zero emissions and clean energy goals for the current reality.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Integrate energy into capacity plannin&lt;/b&gt;g. AI workloads are concentrated and power-dense, so energy availability belongs in capacity planning, not only sustainability reporting.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Align procurement and sustainability teams&lt;/b&gt;. Energy sourcing terms belong in the contract conversation itself, not as a follow-up compliance question.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;"CIOs have the power of the purse and they need to start using it to drive better outcomes," Roling said.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer, and has been known to spend his spare time immersed in the study of the Klingon language and satellite pictures of Area 51. He has pulled Token Ring, configured NetWare and has been known to compile his own Linux kernel. He consults to industry and media organizations on technology issues.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Meta left the RE100 renewable initiative as AI data center demand exceeds renewable supply, forcing reliance on natural gas while using questionable clean energy claims.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/esg_a506458222.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/What-Metas-RE100-exit-means-for-techs-clean-energy-commitments</link>
            <pubDate>Mon, 17 Aug 2026 15:50:00 GMT</pubDate>
            <title>What Meta's RE100 exit means for tech's clean energy commitments</title>
        </item>
        <item>
            <body>&lt;p&gt;The U.S. has been a net energy exporter since 2019, &lt;a href="https://www.eia.gov/energyexplained/us-energy-facts/imports-and-exports.php" target="_blank" rel="noopener"&gt;according to&lt;/a&gt; the U.S. Energy Information Administration. However, energy costs have been rising, and U.S. energy exports reached record highs.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.techtarget.com/it-strategy/feature/CIOs-must-now-model-war-as-an-enterprise-risk"&gt;Geopolitical tensions&lt;/a&gt; involving Russia, Iran and Venezuela have affected global energy markets, contributing to price volatility. While the U.S. produces most of the energy it consumes domestically, these disruptions affect global LNG demand and prices, which can indirectly influence U.S. export commitments and domestic availability.&lt;/p&gt; 
&lt;p&gt;U.S. energy policy affects domestic prices mainly by changing how much energy is produced, how much is exported and how much remains available to U.S. buyers. When policy constrains supply or increases demand for exports, it can push prices higher, especially for natural gas and electricity.&lt;/p&gt; 
&lt;p&gt;Record U.S. energy exports represent a fundamental shift in energy markets that will affect everyone – &lt;a href="https://www.techtarget.com/it-strategy/feature/Predictable-IT-spending-in-an-unpredictable-economy"&gt;including IT budgets&lt;/a&gt; -- for years to come. CIOs who understand this connection and act strategically will turn a budget challenge into a competitive advantage through superior cost management and operational efficiency.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Understanding the energy export and IT budget connection"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Understanding the energy export and IT budget connection&lt;/h2&gt;
 &lt;p&gt;The problem is on both the supply and demand sides. There are stories about data centers &lt;a href="https://www.psu.edu/news/research/story/ask-expert-are-data-centers-driving-my-electricity-bills" target="_blank" rel="noopener"&gt;running up electric bills&lt;/a&gt; for residential customers. In recent months, Venezuela and Iran have been taken out of the supply, and for some time, Russia has been on the outs with the West due to its attack on Ukraine.&lt;/p&gt;
 &lt;p&gt;Net energy exports do not automatically mean cheap energy at home. It can mean the opposite. If supply falls or demand spikes, the U.S. cannot back out of sales and break its contracts. It must fulfill its contractual obligations.&lt;/p&gt;
 &lt;p&gt;For natural gas in particular, studies and recent reporting indicate that higher LNG exports can raise domestic gas prices, which then also feed into electricity bills because gas often sets power prices. And LNG exports are at record highs and expected to &lt;a href="https://www.eia.gov/todayinenergy/detail.php?id=67484" target="_blank" rel="noopener"&gt;grow by 30% in 2027&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Natural gas generated about 41% of U.S. utility-scale electricity in 2025, according to the U.S. Energy Information Administration. Data centers are particularly accounting for more power consumption, with recent estimates by Goldman Sachs saying global data-center power &lt;a href="https://www.goldmansachs.com/insights/articles/ai-to-drive-165-increase-in-data-center-power-demand-by-2030" target="_blank" rel="noopener"&gt;demand could rise&lt;/a&gt; 50% by 2027 and as much as 165% by 2030 versus 2023.&lt;/p&gt;
 &lt;p&gt;And don't expect prices to come down any time soon, even with a resolution to the Middle East conflict. "You know, even if it's resolved tomorrow, they say that prices shoot up like a rocket, but they float down like a feather, so you know, and that you can't count on a resolution," said John Winsett, CEO of NPI, a data intelligence firm.&lt;/p&gt;
 &lt;p&gt;Executives need to keep a close eye on this issue. Electricity represents &lt;a href="https://iaeimagazine.org/electrical-fundamentals/how-much-electricity-does-a-data-center-use-complete-2025-analysis/" target="_blank" rel="noopener"&gt;20-30%&lt;/a&gt; of data center operating costs, according to IAEI Magazine. Businesses should also monitor energy costs, even if they don't own data centers. Cloud providers pass energy costs through to customers, and co-location contracts often include energy cost escalators.&lt;/p&gt;
 &lt;p&gt;There isn't a single national forecast for data center electricity costs over the next two to three years, but recent reporting points to substantial upward pressure, with some estimates suggesting electricity prices could rise &lt;a href="https://www.eesi.org/articles/view/data-center-power-demands-are-contributing-to-higher-energy-bills" target="_blank" rel="noopener"&gt;up to 40%&lt;/a&gt; by 2030 compared with 2025. In faster-growing regions, especially data-center-heavy markets, the increase can be much steeper. A Bloomberg &lt;a href="https://www.bloomberg.com/graphics/2025-ai-data-centers-electricity-prices/" target="_blank" rel="noopener"&gt;report&lt;/a&gt; says electricity prices in Virginia have already increased 267% over five years.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    If you are doing a colo or outsourcing of a data center, you've got to check to see if there's an energy pass-through clause, because that clause will allow them to adjust your monthly bill by the amount that they feel is necessary.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;John Winsett, CEO of NPI&lt;/strong&gt;
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="Direct impacts on your IT budget"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Direct impacts on your IT budget&lt;/h2&gt;
 &lt;p&gt;No &lt;a href="https://www.techtarget.com/it-infrastructure/feature/Guide-to-understanding-the-various-types-of-data-centers"&gt;type of data center&lt;/a&gt; is immune to price increases, regardless of whether a business has an on-premises data center, a cloud environment, a hybrid environment or co-location.&lt;/p&gt;
 &lt;p&gt;An on-premises data center operating costs tend to be more fixed than cloud and co-location because you have control over the purchasing of electricity. A colo or a cloud service provider (CSP) can have a pass-through clause, which allows them to adjust the terms of their contract if electricity prices change.&lt;/p&gt;
 &lt;p&gt;"If you are doing a colo or outsourcing of a data center, you've got to check to see if there's an energy pass-through clause, because that clause will allow them to adjust your monthly bill by the amount that they feel is necessary," said Winsett. "In a colo data center [contract], you negotiate for a fixed rate power clause, or at least an energy cost cap. The worst scenario is an uncapped variable pass-through language."&lt;/p&gt;
 &lt;p&gt;Location is also a factor in cost, as energy prices vary from one region to the next. Energy prices tend to be cheaper in areas rich in natural resources, such as liquid natural gas in Pennsylvania and coal in the West.&lt;/p&gt;
 &lt;p&gt;"A significant portion of the higher costs in the coastal regions is due to transportation, because the price at the wellhead is the price at the wellhead. It's transportation that adds a lot of cost to get the product to market, particularly New England and the Mid-Atlantic states," said Paul DeCotis, senior partner, Energy &amp;amp; Utilities at West Monroe Partners, a global consulting firm.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Strategic responses for IT leaders"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Strategic responses for IT leaders&lt;/h2&gt;
 &lt;p&gt;IT leaders need to prepare for the instability caused by energy price fluctuations, and there are a few steps they can take. The first thing, according to Winsett, is to work on their cost sensitivity analysis and treat energy prices like a macro variable, just like interest rates.&lt;/p&gt;
 &lt;p&gt;"[Energy prices] have been so stable for so long that you lose muscle memory on how to do this stuff, but it's important that they bring that back up to muster, so that any of these agreements [enterprises] are making, even if it has an energy pass-through, it's collared somewhat," he said.&lt;/p&gt;
 &lt;p&gt;Another consideration is infrastructure modernization. This has the highest upfront costs for acquiring new equipment and a longer payoff period, but modernization can pay off handsomely if you are dealing with old, inefficient hardware.&lt;/p&gt;
 &lt;p&gt;"I think that over time, as hardware gets more efficient, it's able to produce more output and generally take less power. So that's always a strategy that we see data centers employ. You're generally chasing efficiency," said Dan Lawrence, CEO at OBM, a cryptocurrency software developer.&lt;/p&gt;
 &lt;p&gt;DeCotis said he's seeing much more interest in on-shoring equipment and supplies because it reduces the risk of supply disruptions when importing them from overseas. "With more onshore manufacturing of electrical equipment in systems, there's a very real security benefit when you're buying equipment," he said.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    I think that over time, as hardware gets more efficient, it's able to produce more output and generally take less power. So that's always a strategy that we see data centers employ. You're generally chasing efficiency.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Dan Lawrence, CEO at OBM&lt;/strong&gt;
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="What CIOs are doing"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What CIOs are doing&lt;/h2&gt;
 &lt;p&gt;Some CIOs have seen the writing on the wall, noting that they have the reporting on data center power consumption and the instability brought about by the Iran conflict. So, they are taking steps to get ahead of the power issue before it becomes unmanageable.&lt;/p&gt;
 &lt;p&gt;For instance, Lawrence said his company is seeing more battery deployments co-located with renewable power, which provides a consistent power source for a data center in a highly renewable-focused way.&lt;/p&gt;
 &lt;p&gt;DeCotis said he speaks with chief procurement officers every day, and not a day goes by that they aren't worried about the future power costs, mostly driven by token consumption now. &lt;a href="https://www.techtarget.com/it-strategy/feature/Tokenmaxxing-How-CIOs-can-extract-maximum-value-from-AI-tokens"&gt;Tokens are the currency of AI&lt;/a&gt;, and tasks are executed in exchange for tokens. You generate tokens through processing.&lt;/p&gt;
 &lt;p&gt;"With energy creeping up, they're watching it," he said. "It's been subsidized by their in-place contracts, so it's been protected by their in-place contracts, but as those come up for renewal, they're going to be feeling the pinch.&lt;/p&gt;
 &lt;p&gt;Lawrence said the biggest thing he's seeing out of data center operators is what he calls demand management or demand mitigation. The objective is to make them more flexible with the available compute during certain hours of the day.&lt;/p&gt;
 &lt;p&gt;For example, in a 50-megawatt data center, a business might cut the available load to 25 mW during off-peak hours and raise it to 50 mW during peak hours.&lt;/p&gt;
 &lt;p&gt;"So, a lot of the data centers are trying to make themselves look more flexible and say I'm not always going to need 50 megawatts here. Instead, I'm going to offer the very minimal necessary, and max out around these couple of periods where I get my 50 megawatts for the rest of the day," he said.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Andy Patrizio is a technology journalist with almost 30 years' experience covering Silicon Valley who has worked for a variety of publications on staff or as a freelancer, including Network World, InfoWorld, Business Insider, Ars Technica and InformationWeek.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Record U.S. energy exports are creating an unexpected problem -- soaring electricity costs for data centers that could reshape IT budgets for years to come.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/money_g1255091249.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/What-record-US-energy-exports-mean-for-your-IT-budget</link>
            <pubDate>Fri, 14 Aug 2026 14:20:00 GMT</pubDate>
            <title>What record U.S. energy exports mean for your IT budget</title>
        </item>
        <item>
            <body>&lt;p&gt;Technical debt accumulates when organizations prioritize speed, growth or short-term delivery over long-term technology sustainability.&lt;/p&gt; 
&lt;p&gt;Like financial debt, technical debt creates ongoing interest in the form of higher maintenance costs, slower innovation, greater operational risk and reduced engineering capacity. Systems that are merely inconvenient today can become major business constraints tomorrow as dependencies, complexity and &lt;a href="https://www.techtarget.com/searchcloudcomputing/tip/A-4-step-action-plan-to-modernize-legacy-systems"&gt;modernization costs&lt;/a&gt; grow.&lt;/p&gt; 
&lt;p&gt;IT leaders must reduce strategic debt, control its accumulation and keep its risk at an acceptable level. Technical debt is often invisible on balance sheets, yet it can materially affect operating costs and growth. Leaders should not mistake slow delivery or recurring incidents for isolated team problems when accumulated legacy practices and systems are to blame.&lt;/p&gt; 
&lt;p&gt;Below, explore how to quantify technical debt, a five-phase roadmap to reduce and manage it effectively, and how to measure debt and its effect on the organization.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Understanding and quantifying technical debt"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Understanding and quantifying technical debt&lt;/h2&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/whatis/definition/technical-debt"&gt;Technical debt&lt;/a&gt; is the future cost created by shortcuts, outdated systems and deferred technology decisions. The result is compounding delivery delays, increased maintenance costs and increased risk. It also hinders organizations in legacy environments, thereby decreasing innovation and agility.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    The essential question for executives is not 'How much debt exists?' but 'Which debt creates the most business drag or risk?'
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;Categorize technical debt across the following domains:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Code-level debt.&lt;/b&gt; Duplicated, complex or poorly documented code.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Architectural debt.&lt;/b&gt; Legacy platforms, tightly coupled systems or infrastructure that limits scalability.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Organizational debt.&lt;/b&gt; Skills gaps, fragmented ownership, weak governance or inefficient processes.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The essential question for executives is not "How much debt exists?" but "Which debt creates the most business drag or risk?"&lt;/p&gt;
 &lt;p&gt;Evaluate existing systems and processes using the following measures:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Technical debt inventories and application portfolios.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/it-infrastructure/tip/Static-and-dynamic-code-analysis-Complementary-techniques"&gt;Static code analysis&lt;/a&gt; and complexity metrics.&lt;/li&gt; 
  &lt;li&gt;Cost of delay and maintenance spend.&lt;/li&gt; 
  &lt;li&gt;Risk scoring based on business criticality, security and operational exposure.&lt;/li&gt; 
  &lt;li&gt;Debt-to-value or debt-to-revenue ratios.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Once debt is visible and quantified, leaders can shift from reactive maintenance to an informed, deliberate strategy. Use the resulting visibility to reduce the highest-impact debt first.&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="5 phases to technical debt elimination"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;5 phases to technical debt elimination&lt;/h2&gt;
 &lt;p&gt;Addressing technical debt means more than initiating a one-time cleanup project. It is an ongoing management discipline that maintains smooth and flexible operations.&lt;/p&gt;
 &lt;h3&gt;Phase 1: Discovery and assessment&lt;/h3&gt;
 &lt;p&gt;Begin by creating a comprehensive technical debt inventory. Without this fundamental resource, it is impossible to identify and quantify potential sources of cost and drag.&lt;/p&gt;
 &lt;p&gt;This inventory could include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Catalog applications, infrastructure, integrations and critical dependencies.&lt;/li&gt; 
  &lt;li&gt;Combine data from IT teams, monitoring tools, code analysis and financial systems.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/enterprise-software/feature/Configuration-sprawl-is-hidden-software-debt"&gt;Identify debt hidden in legacy systems&lt;/a&gt; or undocumented dependencies.&lt;/li&gt; 
  &lt;li&gt;Record each item's owner, age, business dependency and potential effects.&lt;/li&gt; 
  &lt;li&gt;Establish a baseline for debt levels and annual interest costs.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;Phase 2: Prioritization by business value&lt;/h3&gt;
 &lt;p&gt;Decide what to address first based on business impact, which may be financial or risk-oriented.&lt;/p&gt;
 &lt;p&gt;Take the following steps to prioritize debts:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Avoid treating every debt as equally urgent.&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.forrester.com/blogs/key-questions-for-tackling-technical-debt/" rel="noopener"&gt;Rank&lt;/a&gt; debt by business criticality, operational risk, security exposure, cost and strategic relevance.&lt;/li&gt; 
  &lt;li&gt;Distinguish between debt that blocks growth and debt that can safely remain in place.&lt;/li&gt; 
  &lt;li&gt;Link priorities to business goals, transformation initiatives and budget planning.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Remediation is a capital allocation and portfolio decision on where limited budget and engineering capacity should be invested. Make prioritization an investment strategy, so teams focus on the technical debt that matters most.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/cdzUXv8SpjY?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://www.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
 &lt;h3&gt;Phase 3: Remediation while maintaining business continuity&lt;/h3&gt;
 &lt;p&gt;Actively reduce debt without disrupting normal operations. This might involve the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Use &lt;a href="https://www.techtarget.com/searchCloudComputing/tip/Use-the-7-Rs-to-develop-an-app-modernization-strategy"&gt;refactoring&lt;/a&gt;, application modernization, platform migration, system retirement and architecture redesign.&lt;/li&gt; 
  &lt;li&gt;Build debt reduction into existing product and engineering roadmaps.&lt;/li&gt; 
  &lt;li&gt;Start with high-value, high-risk debt where remediation can produce measurable results.&lt;/li&gt; 
  &lt;li&gt;Use incremental changes, phased migrations and rigorous testing to ensure continuity.&lt;/li&gt; 
  &lt;li&gt;Acknowledge that &lt;a href="https://www.techtarget.com/enterprise-software/feature/4-shutdown-risks-that-complicate-legacy-modernization"&gt;modernization brings its own risks&lt;/a&gt;, including migration disruption and change fatigue.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Evaluate remediation costs against the ongoing cost of carrying debt. Choose controlled reduction, not risky modernization efforts, and act only where the tradeoff is justified.&lt;/p&gt;
 &lt;h3&gt;Phase 4: Prevention through sustainable processes and governance&lt;/h3&gt;
 &lt;p&gt;Prevent new debt from accumulating at the same rate as reduction efforts. This might involve the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Establish architecture governance and clear technology ownership.&lt;/li&gt; 
  &lt;li&gt;Add technical debt reviews to portfolio, product and planning processes.&lt;/li&gt; 
  &lt;li&gt;Define standards for documentation, code quality, lifecycle management and &lt;a href="https://www.techtarget.com/searchAppArchitecture/tip/Treat-platform-engineering-as-a-competitive-advantage"&gt;platform selection&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Track intentional debt with owner, rationale and repayment plan.&lt;/li&gt; 
  &lt;li&gt;Align incentives so teams are not rewarded solely for speed of delivery.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Clarify executive ownership: CIOs and CTOs set the strategy and risk tolerance, while CFOs help evaluate financial trade-offs. Business leaders should prioritize debt based on business impact. Build governance and accountability into routine operations so that technical debt management remains sustainable.&lt;/p&gt;
 &lt;h3&gt;Phase 5: AI-driven optimization&lt;/h3&gt;
 &lt;p&gt;The future of technical debt management may be increasingly predictive, automated and integrated into everyday technology operations. AI creates specific debt-reduction opportunities within that future, including the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;AI can continuously scan codebases, architectures and operational data for debt patterns.&lt;/li&gt; 
  &lt;li&gt;AI-driven tools may identify dependencies, predict failure risk and recommend remediation priorities.&lt;/li&gt; 
  &lt;li&gt;AI can help assess the likely business impact of debt before it becomes a major constraint.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    The target for success is sustained control of technical debt, not its complete elimination.
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchdatacenter/tip/Balancing-automation-with-human-oversight-in-AI-data-centers"&gt;Human oversight&lt;/a&gt; and executive governance are critical. AI should inform decisions, not replace accountability. Use AI to move from periodic debt reviews to continuous optimization.&lt;/p&gt;
&lt;/section&gt;                         
&lt;section class="section main-article-chapter" data-menu-title="Measuring success and ROI"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Measuring success and ROI&lt;/h2&gt;
 &lt;p&gt;ROI should be measured through business outcomes rather than lines of code changed or the number of systems modernized. It must also track whether debt accumulates faster or more slowly over time. The target for success is sustained control of technical debt, not its complete elimination.&lt;/p&gt;
 &lt;p&gt;Use the following specific KPIs and metrics:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Mean time to recovery&lt;/b&gt;&lt;b&gt;.&lt;/b&gt; Does reduced complexity accelerate incident recovery?&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Maintenance cost reduction.&lt;/b&gt; Is spending on legacy systems, manual work and recurring fixes declining?&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Engineering capacity recovered.&lt;/b&gt; How much team capacity is returned to strategic work rather than maintenance?&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Risk mitigation.&lt;/b&gt; Are critical vulnerabilities, unsupported technologies and high-risk dependencies being reduced?&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Time to market.&lt;/b&gt; Are products, features and strategic initiatives delivered faster?&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Change failure rate.&lt;/b&gt; Is modernization improving delivery quality without increasing operational disruption?&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Regular reporting ensures leadership is aware of the costs and benefits of deliberately managing technical debt.&lt;/p&gt;
 &lt;p&gt;Overall, technical debt management is an ongoing strategic responsibility. Follow a clear roadmap, strengthen executive ownership and integrate metrics to control compounding costs while building a stronger foundation for innovation and growth.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Damon Garn owns Cogspinner Coaction and provides freelance IT writing and editing services. He has written multiple CompTIA study guides, including the Linux+, Cloud Essentials+ and Server+ guides, and contributes extensively to TechTarget Editorial, The New Stack and CompTIA Blogs.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Technical debt arises from prioritizing short-term gains over long-term sustainability. A strategic approach involves discovery, prioritization and remediation to reduce its impact.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/money_g1142678124.jpg</image>
            <link>https://www.techtarget.com/it-strategy/tip/How-to-reduce-and-eliminate-technical-debt</link>
            <pubDate>Fri, 14 Aug 2026 13:04:00 GMT</pubDate>
            <title>How to reduce and eliminate technical debt</title>
        </item>
        <item>
            <body>&lt;p&gt;This week in tech: Anthropic sparked debate with new AI watermarking features, Elon Musk revealed plans to train Grok on SpaceX employee data, TikTok joined the growing return-to-office movement and Nvidia unveiled a landmark $500 billion financing initiative to accelerate global AI infrastructure.&lt;/p&gt; 
&lt;p&gt;Here's what you need to know from the week starting August 10, plus the latest updates in IPOs and executive leadership.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Anthropic’s watermark sparks controversy"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Anthropic’s watermark sparks controversy&lt;/h2&gt;
 &lt;p&gt;Anthropic confirmed that it will watermark text and files generated by its models, including &lt;a href="https://www.techtarget.com/ai/news/366642478/Claude-Mythos-Preview-and-the-new-rules-of-cybersecurity"&gt;Claude&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Anthropic &lt;a href="https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content"&gt;confirmed the news&lt;/a&gt; on its support page, stating that they have signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content. The decision to watermark content generated by its AI models is one measure the company is making to adhere to the EU act. Other measures include:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Models launched after August 2 will automatically embed invisible watermarks into generated files and text.&lt;/li&gt; 
  &lt;li&gt;Anthropic is working to embed similar measures into models that were released prior to August 2. This is ongoing.&lt;/li&gt; 
  &lt;li&gt;Anthropic will support third parties to detect watermarks.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The move is designed to make AI-generated content identifiable even after it has been copied, pasted or lightly edited. Anthropic says the feature is intended to improve transparency, but the move has sparked criticism from developers, creators and enterprise users.&lt;/p&gt;
 &lt;p&gt;Users have complained on Reddit that this move could unfairly affect users who have used the models only to lightly edit human work and that it blurs the line between AI-written work and AI-assisted work.&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Grok to be trained on SpaceX staff's data"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Grok to be trained on SpaceX staff's data&lt;/h2&gt;
 &lt;p&gt;Elon Musk revealed that Grok will be trained using SpaceX employee data.&lt;/p&gt;
 &lt;p&gt;In a company-wide meeting, Musk told employees to think of themselves as the AI's "parents," saying Grok would "inherit your thoughts and ideas and beliefs." The comments suggest SpaceX's internal knowledge will help shape future versions of the model.&lt;/p&gt;
 &lt;p&gt;The announcement echoes Meta's controversial decision earlier this year to use employees' keystrokes to help train its AI systems. That move prompted concerns over privacy, transparency and employee consent, and SpaceX could face similar scrutiny in the weeks ahead. More broadly, the decision reflects a growing trend across the industry. What will big tech companies do to maintain a competitive AI advantage?&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="TikTok staff ordered to return to office"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;TikTok staff ordered to return to office&lt;/h2&gt;
 &lt;p&gt;TikTok is remaining firm in its return to office policy, informing most of its U.S. workforce that they will be expected to work from the office five days a week from September. This ends hybrid working for many teams.&lt;/p&gt;
 &lt;p&gt;TikTok's decision signals that the return-to-office debate is entering a new phase. Rather than treating hybrid work as a permanent model -- or the other side of the coin to remote work -- many companies now appear willing to prioritize organizational alignment despite some employee dissatisfaction.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Nvidia's $500 billion AI financing deal"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Nvidia's $500 billion AI financing deal&lt;/h2&gt;
 &lt;p&gt;Nvidia is partnering with Wall Street's largest banks and investors including Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR to raise $500 billion for AI infrastructure development.&lt;/p&gt;
 &lt;p&gt;Jensen Huang, Nvidia’s president and CEO &lt;a href="https://x.com/JensenHuang/article/2086934705207959965"&gt;posted on X&lt;/a&gt; “This is a major milestone for NVIDIA and the AI industry.” Huang also said “AI is creating real value, and the infrastructure behind it is becoming one of the world’s most productive assets.”&lt;/p&gt;
 &lt;p&gt;Nvidia’s $500 billion deal is transforming AI infrastructure into a recognized asset class capable of attracting pension funds, insurers and institutional investors.&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Executive Moves"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Executive Moves&lt;/h2&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Dr. Scott Scheidt.&lt;/b&gt; Acclecom appointed Dr. Scott Scheidt as combined CIO and CISO. Dr. Scheidt will lead Accelecom's information technology and AI strategy. He brings 5 years of experience as CIO and CISO at Seimitsu.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="IPO watch"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;IPO watch&lt;/h2&gt;
 &lt;p&gt;The U.S. IPO market remains a key indicator of broader tech sentiment. Here's a look at the latest listings and activity from the past week, based on data from the Nasdaq IPO calendar:&lt;/p&gt;
 &lt;h3&gt;Londian Wason New Energy Tech Inc.&lt;/h3&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;A manufacturing company.&lt;/li&gt; 
  &lt;li&gt;Opening/trading day: August 12.&lt;/li&gt; 
  &lt;li&gt;IPO price: $22/share.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;SunScout Holding Ltd.&lt;/h3&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;A clean technology and solar company.&lt;/li&gt; 
  &lt;li&gt;Opening/trading day: August 12.&lt;/li&gt; 
  &lt;li&gt;IPO price: $5/share.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;Vogenx, Inc.&lt;/h3&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;A clinical-stage biopharmaceutical company.&lt;/li&gt; 
  &lt;li&gt;Opening/trading day: August 12.&lt;/li&gt; 
  &lt;li&gt;IPO price: $13/share.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;MetaOptics Ltd.&lt;/h3&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;A semiconductor optics company.&lt;/li&gt; 
  &lt;li&gt;Expected opening/trading day: August 13.&lt;/li&gt; 
  &lt;li&gt;IPO price: $5-7/share.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;Thunder Bridge Capital Partners V, Ltd.&lt;/h3&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;A blank check company.&lt;/li&gt; 
  &lt;li&gt;Expected opening/trading day: August 13.&lt;/li&gt; 
  &lt;li&gt;IPO price: $10/share.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;NorthStrive Acquisition Corp I.&lt;/h3&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;A blank check company.&lt;/li&gt; 
  &lt;li&gt;Expected opening/trading day: August 14.&lt;/li&gt; 
  &lt;li&gt;IPO price: $10/share.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;i&gt;Rosa Heaton is a content manager and writer for the IT Strategy team at TechTarget.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Stay up to date with the latest U.S. tech news, IPOs and executive moves shaping the industry each week.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/maze_g467037520.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/Weekly-news-roundup-Claude-watermark-controversy-and-Nvidia-500-billion-deal</link>
            <pubDate>Fri, 14 Aug 2026 04:16:00 GMT</pubDate>
            <title>Weekly news roundup: Claude watermark controversy and Nvidia $500 billion deal</title>
        </item>
        <item>
            <body>&lt;p&gt;After building a cloud cost management system using an open source workflow orchestration tool, a global healthcare services company moved to the commercial version with an eye toward future AI agent orchestration.&lt;/p&gt; 
&lt;p&gt;Uniphar Group, headquartered in Dublin, operates in more than 160 countries, with subsidiaries serving more than 200 partners in the pharmaceutical, biotech and medtech industries. Its platform engineering team at Dublin headquarters supports a Microsoft Azure cloud infrastructure and application stack written in C# and .NET. About two years ago, that team wanted to dig deeper into cloud cost management than Microsoft's built-in tooling supported. It turned to an open source distributed application orchestration framework called &lt;a href="https://www.techtarget.com/searchitoperations/news/366569865/Dapr-brings-microservices-principles-to-platform-engineering"&gt;Dapr Workflows&lt;/a&gt; to coordinate a monthly cost management reporting process comprised of more than 400 individual workflows.&lt;/p&gt; 
&lt;p&gt;That system, called Mammon, enabled Uniphar's platform engineers to obtain detailed resource-usage and allocation information while tying it to &lt;a href="https://www.youtube.com/watch?v=REp5yMgy7UQ"&gt;internal budget initiatives&lt;/a&gt; for business users, said Oisin Vaclav Haken, a contractor working as a DevOps consultant at Uniphar who helped lead the project.&lt;/p&gt; 
&lt;div class="imagecaption alignLeft"&gt;
 &lt;img src="https://cdn.ttgtmedia.com/rms/onlineimages/haken_oisin_vaclav.jpg" alt="Oisin Vaclav Haken, DevOps consultant"&gt;Oisin Vaclav Haken
&lt;/div&gt; 
&lt;p&gt;"We can go even beyond certain resource types, actually look at a system's internal metrics and use those metrics to further subdivide costs," Haken said in an interview with TechTarget. "A hierarchy of workflows is a really great way to implement that … and it's all [configured using] business logic. There's very little code for the orchestration description, and it just simplified the whole thing tremendously."&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Enter Catalyst, observability and AI agents"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Enter Catalyst, observability and AI agents&lt;/h2&gt;
 &lt;p&gt;Diagrid, founded in 2021 to offer enterprise support for Dapr tools, first rolled out Diagrid Catalyst in late 2023, adding SaaS-hosted APIs and built-in governance, security and observability features. Since then, Diagrid has added agentic AI features to Catalyst, including durable and verifiable workflow execution with auditable attestation and governance. Catalyst 2.0, released July 28, provides cryptographic identities for authentication and authorization of apps, agents and &lt;a href="https://www.techtarget.com/searchitoperations/news/366646492/Stateless-MCP-seen-as-step-forward-for-enterprise-AI"&gt;MCP servers,&lt;/a&gt; and supports declarative access policy enforcement for AI agents.&lt;/p&gt;
 &lt;p&gt;It was primarily Catalyst's integrated observability dashboards that prompted Uniphar to begin moving to the commercial product from open source Dapr Workflows earlier this year, Haken said. That process was just completed this month.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    We looked at Microsoft Foundry, but we have invested heavily in our own infrastructure to host our agents, and [Catalyst] allows us to do that.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Oisin Vaclav Haken,&lt;/strong&gt;DevOps consultant, Uniphar 
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;"Now we have our own portal on top of the source data, so it just makes it easier for us to get a glance at a system's performance," he said. "If there are any errors we need to be concerned with, we can dive into the problem, see the details and investigate."&lt;/p&gt;
 &lt;p&gt;Agentic AI orchestration and governance is also on Haken's mind as his team &lt;a target="_blank" href="https://github.com/microsoft/agent-framework" rel="noopener"&gt;begins experimenting&lt;/a&gt; with Microsoft Agent Framework for developer onboarding and offboarding workflows.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;"It's very simple for us to develop these agents, then host them through Catalyst, and we get that observability," he said. "We looked at Microsoft Foundry, but we have invested heavily in our own infrastructure to host our agents, and [Catalyst] allows us to do that."&lt;/p&gt;
 &lt;p&gt;AI agent orchestration is still at an early, experimental stage at Uniphar, but as it matures, Catalyst's agentic governance features could come into play, since they can be turned on with a simple configuration change in the existing system, Haken said.&lt;/p&gt;
 &lt;p&gt;"There's really a big emphasis on kind of controlling agent-to-agent [communication], validating, constraining and having guardrails in place," he said. "At this stage, we're still looking at the architecture, implementation and design principles. But obviously, it's something that is in the back of our heads."&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="Diagrid Catalyst 2.0 adds verification amid AI regulation"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Diagrid Catalyst 2.0 adds verification amid AI regulation&lt;/h2&gt;
 &lt;p&gt;Initially, Catalyst supported the Dapr Agents framework, but version 2.0, rolled out July 28, broadened that support to 10 more popular &lt;a href="https://www.techtarget.com/searchitoperations/news/366621121/Open-source-AI-agent-frameworks-add-enterprise-ops-polish"&gt;AI agent frameworks&lt;/a&gt;, including LangGraph, Microsoft Agent Framework, Google Agent Development Kit, AWS Strands, OpenAI Agents SDK and CrewAI.&lt;/p&gt;
 &lt;p&gt;Catalyst previously supported durable execution for AI agents -- if a specific task failed, it could restart and ensure it finished. Version 2.0 will now provide digitally signed verification that execution has finished and link agentic actions to individual human managers or project groups within an organization, said Mark Fussell, CEO of Diagrid, in an interview with TechTarget.&lt;/p&gt;
 &lt;p&gt;"There's a lot of legislation coming in, like the &lt;a href="https://www.techtarget.com/searchenterpriseai/news/366646620/EU-AI-Act-compliance-deadline-is-here-What-to-watch"&gt;EU AI Act&lt;/a&gt;, that are saying … anything that touches the personal data of an EU member citizen, such as a loan application, for example … you're required under their law to show direct proof that the loan origination was approved and happened, and that means that you need digital verification," Fussell said.&lt;/p&gt;
 &lt;p&gt;AI agent governance is a hot topic among enterprises as pilot projects struggle to reach production and &lt;a href="https://www.techtarget.com/searchcio/news/366646236/How-CIOs-can-navigate-federal-state-AI-regulation-uncertainty"&gt;new regulations proliferate&lt;/a&gt;, according to analysts.&lt;/p&gt;
 &lt;p&gt;"AI governance is moving from a policy discussion into an operational requirement, but adoption is still uneven," wrote Paul Nashawaty, principal application development analyst at Efficiently Connected, Inc. (ECI), based in Holden Beach, N.C., in an email to TechTarget.&lt;/p&gt;
 &lt;p&gt;A July 2026 ECI Research survey of 320 technology professionals found that 93% of organizations are adopting AI dev tools, yet only 12% have implemented standard security and operational governance controls for those workloads.&lt;/p&gt;
 &lt;p&gt;Diagrid, a privately funded startup, remains primarily associated with Dapr Workflow orchestration, and must compete with much larger, higher-profile &lt;a href="https://www.techtarget.com/ai/tip/The-best-AI-governance-tools-and-platforms-in-2026"&gt;AI governance tools&lt;/a&gt; for enterprise attention. But the vendor has an opportunity to broaden its appeal in an increasingly complex regulatory environment with Catalyst 2.0, Nashawaty said.&lt;/p&gt;
 &lt;p&gt;"Diagrid fits on both sides of the aisle: Developers get to write agents in whichever framework is trending, while platform engineering, SecOps and legal teams get the tamper-evident logging, resiliency and compliance infrastructure required to take those agents safely into production," he said. "Organizations need to know which agent is acting, what application it can reach, which MCP server it can access, and even which individual tools it is authorized to invoke. … Catalyst aligns well with where AppDev security is heading."&lt;/p&gt;
 &lt;p&gt;At the same time, Catalyst is still evolving. Haken said he's waiting for it to support managing AI agent skills alongside Microsoft Agent Framework agents. AI agent skills are a set of instructions that developers use to direct AI agents to perform specific tasks; skills can also be shared among organizations, stored and governed in their own &lt;a href="https://www.techtarget.com/searchitoperations/news/366640420/Nvidia-NemoClaw-JFrog-shore-up-OpenClaw-security"&gt;skills repositories&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;"Skills are, to us, a very interesting way to separate sub-processes and their handling by the agent; if the agent hosts a fairly wide set of functionality, it's that much easier to maintain and modify skills without affecting everything else in the process, so it's a good feature to have there," Haken said.&lt;/p&gt;
 &lt;p&gt;Diagrid officials said this week that the update is under development and will be available soon.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Beth Pariseau, senior news writer for Informa TechTarget, is an award-winning veteran of IT journalism. Have a tip?&amp;nbsp;&lt;/em&gt;&lt;a target="_blank" href="mailto:bpariseau@techtarget.com?subject=News%20tip" rel="noopener"&gt;&lt;em&gt;Email her&lt;/em&gt;&lt;/a&gt;&lt;em&gt; or connect on &lt;/em&gt;&lt;a target="_blank" href="https://www.linkedin.com/in/bethpariseau" rel="noopener"&gt;&lt;em&gt;LinkedIn&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>The company's platform engineering team replaced open source Dapr with the commercial product for built-in observability, with AI agents waiting in the wings.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/machine_learning_g1264542084.jpg</image>
            <link>https://www.techtarget.com/it-strategy/news/366649413/Uniphar-taps-Diagrid-Catalyst-for-orchestration-observability</link>
            <pubDate>Thu, 13 Aug 2026 21:00:00 GMT</pubDate>
            <title>Uniphar taps Diagrid Catalyst for orchestration, observability</title>
        </item>
        <item>
            <body>&lt;p&gt;Two executives at financial services companies used new tools and approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI, while still maintaining security controls.&lt;/p&gt; 
&lt;p&gt;These approaches ranged from new strategies and data-gathering for monitoring threats to shifts in how teams are organized, but the common theme was to use AI tools safely without falling into the &lt;a href="https://www.techtarget.com/searchitoperations/podcast/SecOps-from-the-IT-infrastructure-operations-perspective"&gt;traditional stereotype&lt;/a&gt; of security teams as blockers to progress.&lt;/p&gt; 
&lt;p&gt;"You can throw a 50-foot wall around it and don't let anybody get to it, but then you lose the innovation, and you lose the ability to accelerate by having the right tooling applied to it," said Doug Innocenti, CIO and chief information security officer (CISO) at MoonPay, a cryptocurrency payments firm based in New York.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Avoiding shadow AI, from ChatGPT to agents"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Avoiding shadow AI, from ChatGPT to agents&lt;/h2&gt;
 &lt;p&gt;After ChatGPT burst onto the scene in late 2022, MoonPay leaders engaged with a stealth AI security startup, Aim Security.&lt;/p&gt;
 &lt;p&gt;"In the early days of ChatGPT, they didn't have ChatGPT Enterprise or ChatGPT Pro. It was just ChatGPT," Innocenti said. "There was no isolation. Aim not only had a defensive mechanism but also created a secure portal with enterprise-level anonymization and blocking … the features that ChatGPT didn't have."&lt;/p&gt;
 &lt;p&gt;As ChatGPT gave way to a plethora of generative AI models, Aim Security evolved to scan tools on the network that used internal AI components and assess whether the tool makers used data from those components to train models. Aim Security could also determine which underlying models the tools used and for which other purposes they might use data.&lt;/p&gt;
 &lt;div class="imagecaption alignRight"&gt;
  &lt;img src="https://cdn.ttgtmedia.com/rms/onlineimages/innocenti_doug.jpg" alt="Doug Innocenti, CIO and CISO, MoonPay"&gt;Doug Innocenti
 &lt;/div&gt;
 &lt;p&gt;"We were able to perform an independent review on tools and understand which ones we wanted to pick," Innocenti said. "So it was actually both posture management and part of the built-in investigative component we wanted to do."&lt;/p&gt;
 &lt;p&gt;Aim Security was acquired by Cato Networks in 2025, which renamed the tool Cato AI Security. Innocenti said MoonPay is investigating other secure access service edge (SASE) tools, including Cato's, but hasn't yet purchased any.&lt;/p&gt;
 &lt;p&gt;Cato has integrated Aim with &lt;a href="https://www.computerweekly.com/news/366640937/Cato-Networks-unveils-modular-adoption-model-for-SASE-platform"&gt;its SASE products&lt;/a&gt;, including its firewall as a service tool, which could potentially act as a higher-level detection point for shadow AI activity than the individual workstation web browsers where MoonPay currently deploys Aim, Innocenti said.&lt;/p&gt;
 &lt;p&gt;"It's been an ongoing conversation point that I have with my team -- you need AI defense not at the endpoint, but you need it in the transport mechanism, you need it at the network layer," he said.&lt;/p&gt;
 &lt;p&gt;As the company begins to use AI agents such as Claude Cowork, "Cato AI security provides me with the same depth of support to govern, rather than block, what is being done today," Innocenti said. "It sits in front of Cowork and other components we have and allows me to look for sensitive data that might be pushed into it."&lt;/p&gt;
 &lt;p&gt;Still, the &lt;a href="https://www.techtarget.com/revcyclemanagement/feature/Agentic-AI-evolution-begins-to-pave-way-for-autonomous-revenue-cycle"&gt;rapid evolution of agentic AI&lt;/a&gt; represents an ongoing challenge, Innocenti said.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    If we have to say no, our primary focus becomes, 'How do we get from no to yes?' 'No' is just a temporary stopping point.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Doug Innocenti, &lt;/strong&gt;CIO and CISO, MoonPay 
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;"What keeps me up at night with agentic AI is that I can go to bed, and something new will emerge by the time I wake up," he said. "I have never done as much research as I have done in the last year and a half."&lt;/p&gt;
 &lt;p&gt;Still, the guiding principle of enabling employees to take advantage of new AI tech whenever possible remains in place.&lt;/p&gt;
 &lt;p&gt;"If we have to say no, our primary focus becomes, 'How do we get from no to yes?' 'No' is just a temporary stopping point [but we can find] the right way to do it. It doesn't mean we have to just block it."&lt;/p&gt;
&lt;/section&gt;               
&lt;section class="section main-article-chapter" data-menu-title="'Your employees are both your weakest and strongest link'"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;'Your employees are both your weakest and strongest link'&lt;/h2&gt;
 &lt;p&gt;MoonPay underwent significant organizational consolidation earlier this year, when Innocenti added the CISO role to his existing CIO position in May.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;"The IT team was the fundamental implementation point of everything that needed to be done from a security perspective, so taking on the responsibility to understand the posture and build the overall policies was just an evolution of what IT already was," Innocenti said.&lt;/p&gt;
 &lt;p&gt;This consolidation has fostered deeper collaboration between IT and security teams at MoonPay.&lt;/p&gt;
 &lt;p&gt;"You see IT people talking like security people, and you see security people talking like IT people, and they both want to work together … not looking at it as a rivalry, which you can see happen in some situations, but looking at it as a partnership," Innocenti said.&lt;/p&gt;
 &lt;p&gt;The way Cato AI Security surfaces potential risks to sensitive data for IT and security teams has also been key for employee training and communication, he said.&lt;/p&gt;
 &lt;p&gt;"It helps us assist the employee in the right way to use AI tools safely. Now we start seeing people ask questions in our IT tickets that say, 'Hey, I'm thinking about doing this with some data. Is there a better way I can do it?'" Innocenti said. "They understand that it's okay to ask the question.&lt;/p&gt;
 &lt;p&gt;"In any security stack, your employees are both your weakest and strongest link," he said. "If I can make employees stronger by helping them ask the right questions and pause for a moment, then we've won."&lt;/p&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="'It's not people being malicious'"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;'It's not people being malicious'&lt;/h2&gt;
 &lt;p&gt;At Equals, a London-based payments platform company, 86% of application code is now written by agents, up from 5-10% last year, with the goal of 100%. The use of AI agents has also been valuable to the business, helping the company's legal and customer support teams complete contract reviews and complaint processing more quickly.&lt;/p&gt;
 &lt;p&gt;However, James Simcox, chief product officer at Equals, is well aware of the &lt;a href="https://www.techtarget.com/cybersecurity/news/366628186/News-brief-Rise-of-AI-exploits-and-the-cost-of-shadow-AI"&gt;risks of unfettered use of AI&lt;/a&gt;. Many staff are eager to use AI products they're familiar with at home and might tweak security settings to allow more access if those tools don't perform as expected at work.&lt;/p&gt;
 &lt;p&gt;"Sometimes people go, 'I'm a senior person trying to implement this tool. … I'll give it admin access to this product, because I have admin access,'" Simcox said. "Then they sort of forget about it, and it makes it into production with access to way more information than it needs. It's not people being malicious. It's people just being like, 'I want to do my job.'"&lt;/p&gt;
 &lt;div class="imagecaption alignLeft"&gt;
  &lt;img src="https://cdn.ttgtmedia.com/rms/onlineimages/simcox_james.jpg" alt="James Simcox, chief product officer, Equals"&gt;James Simcox
 &lt;/div&gt;
 &lt;p&gt;No humans have been replaced by AI at the company, which is still &lt;a href="https://equalsmoney.com/newsroom/equals-money-railsr-becomes-equals" target="_blank" rel="noopener"&gt;growing rapidly&lt;/a&gt;, reporting double-digit percentage revenue growth over the last year to surpass about £60 billion ($80 billion) in transaction processing volume. Developers have shifted their focus to more strategic technical tasks, while product managers handle smaller, less technical updates. Agentic coding has forced the company to rethink its code review and software release processes, as AI-generated code creates a new bottleneck downstream, Simcox said. The need for human oversight of AI coding agents has led the company to double the size of its human security team this year.&lt;/p&gt;
 &lt;p&gt;"We've also broken out our system slightly more into some more standardized pieces, so that when you're developing software, you don't necessarily think about the API gateway security layer, for example, because that's handled in a product," Simcox said. "But it's in progress, because the increase in delivery has gone up so much that bottlenecks can appear where you don't expect them to."&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="New AI threats call for new tools"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;New AI threats call for new tools&lt;/h2&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Attacks look less obviously like a bot just hitting an endpoint, and they look a lot more like a human trying things, which wouldn't necessarily get picked up by a bunch of different tools.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;James Simcox, &lt;/strong&gt;Chief operations and product officer, Equals 
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;While properly organizing and training people to use AI tools was an important component in curbing shadow AI use at Equals, new tools were also called for as &lt;a href="https://www.techtarget.com/it-infrastructure/news/366646071/NetScout-doubles-AI-DDoS-defenses-after-infrastructure-buy"&gt;AI-assisted cyberattacks&lt;/a&gt; grow more sophisticated and numerous, Simcox said.&lt;/p&gt;
 &lt;p&gt;"Fewer, broader tools are what we've gone for," Simcox said. "Particularly with the rise of AI agents behaving slightly more like humans, attacks look less obviously like a bot just hitting an endpoint, and they look a lot more like a human trying things, which wouldn't necessarily get picked up by a bunch of different tools."&lt;/p&gt;
 &lt;p&gt;Equals replaced multiple application security monitoring tools with Wiz and added Okta Identity Security Posture Management (ISPM) for staff identity management and authorization, along with &lt;a href="https://www.techtarget.com/cybersecurity/news/252497271/Okta-acquires-identity-rival-Auth0-for-65-billion"&gt;Okta's Auth0&lt;/a&gt; for customer identity management and authorization.&lt;/p&gt;
 &lt;p&gt;"It's very hard for our IT or security team to go around to every single tool in the entire business all day long and go, 'Steve has accidentally given this AI tool admin access to all our customer data. Maybe he shouldn't have done that,'" Simcox said. "That's where Okta ISPM is really useful for us, because it can [see] across all of those different tools, and gives you proactive alerts that say, 'This user is not behaving like they're supposed to, or this user has logged in 14 times in different tools in three seconds.'"&lt;/p&gt;
 &lt;p&gt;Ideally, every Equals customer would use the company's single sign-on and two-factor authentication with a passkey or hardware security key, Simcox said, but it's not realistic to expect that. Instead, Auth0 has enabled &lt;a href="https://www.techtarget.com/cybersecurity/definition/What-is-defense-in-depth"&gt;defense-in-depth&lt;/a&gt; without imposing overly restrictive login policies on clients.&lt;/p&gt;
 &lt;p&gt;"We have to account for a really wide range of customers," he said. "We rely a lot on their behavioral ways of doing things, and so we put a bunch of extra data from Auth0 into our platform for login journeys."&lt;/p&gt;
 &lt;p&gt;The Equals system might let suspicious-looking logins through, but monitors that activity with Auth0 and feeds its information into transaction monitoring systems. If a suspicious login results in a suspicious transaction, Equals might block the transaction.&lt;/p&gt;
 &lt;p&gt;"We'll try and move the security to the point of the action we care about," Simcox said.&lt;/p&gt;
 &lt;p&gt;While some of Equals' AI security measures might be useful to IT pros elsewhere, he cautioned that mileage may vary depending on the market those businesses inhabit and their experience developing software.&lt;/p&gt;
 &lt;p&gt;"The entire delivery product of financial services is software … so as a business, we're quite used to building our own internal tools, because there is no product you can buy off the shelf generally which interacts with our exact banking partners in the way we want to interact with them," Simcox said. "It's quite easy for us to roll more software out to the business."&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Beth Pariseau, senior news writer for Informa TechTarget, is an award-winning veteran of IT journalism. Have a tip?&amp;nbsp;&lt;/em&gt;&lt;a target="_blank" href="mailto:bpariseau@techtarget.com?subject=News%20tip" rel="noopener"&gt;&lt;em&gt;Email her&lt;/em&gt;&lt;/a&gt;&lt;em&gt; or connect on &lt;/em&gt;&lt;a target="_blank" href="https://www.linkedin.com/in/bethpariseau" rel="noopener"&gt;&lt;em&gt;LinkedIn&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>C-level executives in a regulated industry strike a balance between the benefits AI can offer their businesses and the need to guard against its risks.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/chatbot_g1150454068.jpg</image>
            <link>https://www.techtarget.com/it-strategy/news/366649432/Fintech-execs-unblock-AI-with-shadow-AI-detection-org-shifts</link>
            <pubDate>Thu, 13 Aug 2026 20:00:00 GMT</pubDate>
            <title>Fintech execs unblock AI with shadow AI detection, org shifts</title>
        </item>
        <item>
            <body>&lt;p&gt;As enterprise AI maturity grows, Dynatrace is betting that demand for custom AI agent development will, too, and is anticipating that demand with a $915 million deal to acquire a venture-backed startup.&lt;/p&gt; 
&lt;p&gt;The cash-and-stock deal for Arize AI, a 200-employee company based in Berkeley, Calif. and founded in 2020, will add its AI agent evaluation and experimentation tools to Dynatrace's portfolio, where they will be combined with the recently unveiled &lt;a href="https://www.techtarget.com/searchitoperations/news/366646654/Dynatrace-execs-dish-details-on-Bluebox-autonomous-AI"&gt;Bluebox AI&lt;/a&gt; product. Bluebox automates the regular software development lifecycle (SDLC); the Arize AX platform can perform similar autonomous improvement cycles on custom AI agents. Bluebox automates the regular software development lifecycle (SDLC); the Arize AX platform can perform similar autonomous improvement cycles on custom AI agents.&lt;/p&gt; 
&lt;p&gt;"Arize was built as an agent-first platform, with one of the largest collections of agent trace data in the industry," wrote Arize co-founder and CEO Jason Lopatecki in a &lt;a target="_blank" href="https://arize.com/blog/a-new-chapter-with-dynatrace/" rel="noopener"&gt;blog post&lt;/a&gt;. "Dynatrace brings depth in tracing and logging software systems that provide the data to drive these agents. These two areas just belong together if we are going to build the future systems that continuously improve."&lt;/p&gt; 
&lt;p&gt;In other words, Dynatrace has runtime telemetry; Arize can monitor, revise and refine the output quality of large language models; and Bluebox can then fix the agents based on both tools' findings, said Torsten Volk, an analyst at Omdia, a division of Informa TechTarget.&lt;/p&gt; 
&lt;p&gt;"The &lt;a href="https://www.techtarget.com/it-infrastructure/tip/Dynatrace-bets-on-causal-intelligence-for-AI-observability"&gt;AI observability&lt;/a&gt; [Dynatrace] already had was just focused on standard metrics, not on actually looking at model outputs in different constellations," Volk said.&lt;/p&gt; 
&lt;p&gt;One Dynatrace customer considering Bluebox said he is intrigued by the addition of Arize to support custom agent development alongside other types of software.&lt;/p&gt; 
&lt;p&gt;"DIY agents are now like websites: We're gonna have millions of them, and most of them are untested and will not scale," wrote Mark Tomlinson,AVP of performance and observability at digital payments provider FreedomPay, in an email to TechTarget. "Bluebox + Arize is a nice combination that bolsters Dynatrace's long-standing commitment to 'find and fix' value delivery."&lt;/p&gt; 
&lt;blockquote class="main-article-pullquote"&gt;
 &lt;div class="main-article-pullquote-inner"&gt;
  &lt;figure&gt;
   DIY agents are now like websites: We're gonna have millions of them, and most of them are untested and will not scale.
  &lt;/figure&gt;
  &lt;figcaption&gt;
   &lt;strong&gt;Mark Tomlinson&lt;/strong&gt;AVP, FreedomPay
  &lt;/figcaption&gt;
  &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
 &lt;/div&gt;
&lt;/blockquote&gt; 
&lt;p&gt;This acquisition follows the January 2026 acquisition of &lt;a href="https://www.techtarget.com/searchitoperations/news/366637355/Dynatrace-DevCycle-buy-continues-observability-consolidation"&gt;feature flagging specialist DevCycle&lt;/a&gt;, which established Dynatrace's strategy to move more aggressively into what chief technology strategist Alois Reitbauer described as "active systems of control." In April 2026, Dynatrace bought data pipeline startup Bindplane.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Enterprises want unified software, agent development"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Enterprises want unified software, agent development&lt;/h2&gt;
 &lt;p&gt;Dynatrace isn't the only enterprise IT vendor looking to expand into AI agent development. In April, Cisco &lt;a href="https://www.techtarget.com/searchitoperations/news/366641600/Cisco-Galileo-buy-reflects-blurring-lines-in-AI-observability"&gt;acquired Galileo&lt;/a&gt;, which performs AI agent evaluations and integrates with Splunk observability tools. Harness added support for AI agent development to its existing DevSecOps pipelines with &lt;a href="https://www.techtarget.com/searchitoperations/news/366646195/Harness-Agent-DLC-targets-AI-agent-development-gaps"&gt;Agent DLC in July.&lt;/a&gt;&lt;/p&gt;
 &lt;p&gt;Analysts said all of these vendors are responding to a growing desire among enterprises for a single platform to develop AI agents and other software applications. An &lt;a target="_blank" href="https://research.esg-global.com/aim/en/reports/515202172/" rel="noopener"&gt;Omdia survey&lt;/a&gt; of 400 IT professionals and application developers, conducted in late 2025 and published in March, found that "Ability to monitor AI/ML systems with the same observability platform used for infrastructure and applications" ranked second on respondents' priority list, with 49% rating it important. Only core monitoring capabilities, such as accuracy, drift, latency and cost, were rated important by more respondents, at 53%.&lt;/p&gt;
 &lt;p&gt;While it's still early for enterprise AI agent development, "AI agent adoption is only going to explode upwards," said Stephen Elliot, an analyst at IDC.&lt;/p&gt;
 &lt;p&gt;"Agent debugging, evaluations, agent root cause analysis and testing … might even be more important than they were in the traditional SDLC model, especially with agentic systems that make decisions," Elliot said. "I view it as a foundational investment for technology executives."&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Beth Pariseau, senior news writer for Informa TechTarget, is an award-winning veteran of IT journalism. Have a tip?&amp;nbsp;&lt;/em&gt;&lt;a target="_blank" href="mailto:bpariseau@techtarget.com?subject=News%20tip" rel="noopener"&gt;&lt;em&gt;Email her&lt;/em&gt;&lt;/a&gt;&lt;em&gt; or connect on &lt;/em&gt;&lt;a target="_blank" href="https://www.linkedin.com/in/bethpariseau" rel="noopener"&gt;&lt;em&gt;LinkedIn&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>With its third acquisition this year, Dynatrace continued its march from pure observability to systems of control, adding AI agent development tools to its observability arsenal.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/ai_a199952058.jpg</image>
            <link>https://www.techtarget.com/it-strategy/news/366648773/Dynatrace-acquires-Arize-for-AI-agent-development</link>
            <pubDate>Thu, 13 Aug 2026 08:16:00 GMT</pubDate>
            <title>Dynatrace acquires Arize for AI agent development</title>
        </item>
        <item>
            <body>&lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;In today's climate of uncertainty and rapidly evolving technologies, the cost for CIOs of falling behind is higher than ever.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Technology industry conferences and events offer the best opportunities for CIOs to stay ahead of the curve and gain a deeper understanding of how to align &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/Agentic-AI-vs-generative-AI-Whats-the-difference"&gt;emerging innovations&lt;/a&gt; with business value.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;While there's a wealth of technical information you can gather at a &lt;a href="https://www.techtarget.com/searchdatamanagement/feature/The-top-2026-data-conferences-to-plan-enterprise-strategy"&gt;quality technology conference&lt;/a&gt;, there are other good reasons to attend. Conferences provide opportunities to engage directly with peers, industry experts, potential vendors and other technology and business leaders to discuss &lt;a href="https://www.techtarget.com/iotagenda/tip/Top-advantages-and-disadvantages-of-IoT-in-business"&gt;similar challenges&lt;/a&gt;, build best practices and compare strategies.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Here are some conferences and events that CIOs will want to put on their calendars.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;If you have a tech conference or event that you would like to appear in this calendar, email &lt;a href="mailto:sarah.amsler@informatechtarget.com"&gt;harriet.jamieson@informatechtarget.com&lt;/a&gt;. Check in frequently for conference calendar updates.&lt;/span&gt;&lt;/p&gt; 
&lt;div&gt; 
 &lt;h2&gt;&lt;b&gt;Forrester Technology &amp;amp; Innovation Forum Central&lt;/b&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;b&gt;When: &lt;/b&gt;Sept. 14-15, 2026&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Where:&lt;/b&gt; Austin, Texas&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Cost: &lt;/b&gt;$1,099.&lt;/p&gt; 
 &lt;p&gt;Agenda includes workshops, case studies, and sessions on data and AI readiness; AI workplace strategies; and operationalizing AI.&lt;/p&gt; 
 &lt;p&gt;Keynote speakers include Alla Valente -- principal analyst, Forrester; Charles Betz -- vice president and principal analyst, Forrester; Joe Cicman -- principal analyst, Forrester; Mark Moccia -- vice president and research director, Forrester; and Srividya Sridharan -- vice president and group director, Forrester.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Extras: &lt;/b&gt;Welcome reception, breakout sessions, Forrester Women's Leadership Program, Forrester Executive Leadership Exchange, and private executive sessions and receptions.&lt;/p&gt; 
 &lt;p&gt;Learn more about Forrester Technology &amp;amp; Innovation Forum Central &lt;a href="https://www.forrester.com/event/technology-innovation-central/"&gt;here&lt;/a&gt;.&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Gartner Enterprise Risk, Audit and Compliance Conference 2026 &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When: &lt;/b&gt;Sept. 15-16, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where:&lt;/b&gt; Grapevine, Texas.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost: &lt;/b&gt;$4,350.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Topics include third-party risk management; business risk ownership; emerging risk landscape; employee engagement and compliance. &lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Speakers include Antonia Donaldson -- director analyst, Gartner; Brian Andersen -- senior director, Gartner; Viktoria Boyle -- vice president, Gartner; Elliott Long -- director, Gartner.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Extras: &lt;/b&gt;Gartner expert one-on-one briefings, ask the expert sessions, workshops, and social events. &lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Register for Gartner Enterprise Risk, Audit and Compliance Conference 2026 &lt;a href="https://www.gartner.com/en/conferences/na/enterprise-risk-audit-compliance-us/register"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Dreamforce&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When: &lt;/b&gt;Sept. 15-17, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where: &lt;/b&gt;San Francisco&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost: &lt;/b&gt;$2,299, standard. &amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Topics covered include agentic AI development with Agentforce; AI development for the contact center, customer experience and field service management; Data 360; and Tableau analytics and insights.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Conference speakers include Matthew McConaughey -- Academy Award-winning actor and Salesforce brand partner; Sterling K. Brown -- Emmy Award-winning actor and producer; Tony Robbins -- author, entrepreneur and philanthropist; Marc Benioff -- chairman, chief executive officer and founder, Salesforce; and Renée Richardson Gosline -- research scientist and senior lecturer, MIT Sloan School of Management, and head of the Human-First AI group, MIT's Initiative on The Digital Economy.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;Extras:&lt;/strong&gt; roundtables, workshops, and hands-on trainings.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Register for Dreamforce &lt;a href="https://www.salesforce.com/dreamforce/register/?pr=https%3A%2F%2Fwww.salesforce.com%2Fdreamforce%2F&amp;amp;utm_variant=Control"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;div&gt; 
  &lt;h2 paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{118}" paraid="110" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;InfoSec World&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{127}" paraid="111"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;When:&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;Oct. 12-14, 2026&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{135}" paraid="112"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Where:&amp;nbsp;&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Kissimmee, Fla.&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{143}" paraid="113"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Cost: &lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;$4,195, standard.&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{151}" paraid="114"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Topics covered include AI regulation, bad actors, AI and the c-suite, AI security threats, and AI privacy and security.&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{157}" paraid="11282416"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Conference speakers&amp;nbsp;include Mark Clancy&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;--&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;chief security officer, T-Mobile; Akhila Nama&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;--d&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;irector and global head of&amp;nbsp;enterprise&amp;nbsp;security, Box; Candice&amp;nbsp;Biamby&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;--&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;vice president and project manager, cyber threat intelligence,&amp;nbsp;JP Morgan Chase &amp;amp; Co.; and&amp;nbsp;Jason Mortenson&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;-- &lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;director, strategic information security, Lenovo.&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{163}" paraid="116"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&lt;strong&gt;Register&lt;/strong&gt; for InfoSec World&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://events.infosecworldusa.com/2026/begin"&gt;&lt;span xml:lang="EN" data-contrast="none"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;.&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}" style="font-family: arial, helvetica, sans-serif;"&gt;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;h2 paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{177}" paraid="117" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Gartner IT Symposium/Expo&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{188}" paraid="118"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&lt;strong&gt;When:&lt;/strong&gt;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Oct. 19-22, 2026&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{198}" paraid="119"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Where:&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;Orlando, Fla.&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{208}" paraid="120"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&lt;strong&gt;Cost:&lt;/strong&gt;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;$8,200, standard; $5,925, public sector.&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ca6365ec-f7cc-4e5f-b5ec-3b849fcaccd4}{218}" paraid="121"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Topics covered include top technology trends for 2026;&amp;nbsp;agentic AI;&amp;nbsp;overcoming resistance and buildin&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;g enthusiasm for AI adoption; and leading CIOs through uncertainty.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ea3f7e22-5782-48d1-ae09-495bdf58e2e6}{40}" paraid="129225800" xml:lang="EN-US"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Conference speakers include Gartner staff,&amp;nbsp;such as&amp;nbsp;Kristin Moyer&amp;nbsp;--&amp;nbsp;distinguished vice president analyst;&amp;nbsp;Daryl Plummer&amp;nbsp;-- distinguished vice president analyst;&amp;nbsp;Tori Paulman&amp;nbsp;--&amp;nbsp;vice president analyst;&amp;nbsp;and&amp;nbsp;Gabriela Vogel&amp;nbsp;--&amp;nbsp;vice president analyst.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{03b6aca7-5afb-4276-bea4-591429887b58}{13}" paraid="123"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Register for&amp;nbsp;Gartner IT Symposium/Expo&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.gartner.com/en/conferences/na/symposium-us/register"&gt;&lt;span xml:lang="EN" data-contrast="none"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;.&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Securing New Ground  &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When:&lt;/b&gt; Oct. 20-21, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where:&lt;/b&gt; New York City&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost: &lt;/b&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;$1,995.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;Topics include AI and automation, how the security business is changing, and perspectives from leading CSOs.&lt;/p&gt; 
 &lt;p&gt;Speakers include Heather Warner -- vice president of global data center physical security, Oracle; Alex Castaneda -- corporate vice president, North America video security and access control, Motorola Solutions; Billal Hammoud -- president and CEO of building automation, Honeywell; Ann Fandozzi -- chief executive officer, Convergint; and Heather Torrey -- executive vice president, Dormakaba Americas.&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Extras:&lt;/b&gt; networking breaks and receptions.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Find out more about Securing New Ground &lt;a href="https://sng.securityindustry.org/registration/"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Gartner HR Symposium/Expo &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When:&lt;/b&gt; Oct. 26-28, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where: &lt;/b&gt;Orlando, Fla.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost: &lt;/b&gt;$4,875, early bird; $5,475, standard; $4,440, public sector.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Topics covered include HR's new domain in the AI era; navigating the multi-generational workplace; and building a growth-ready workforce in the AI era.&lt;/span&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Conference speakers include Gartner staff, such as Jana Alancheril -- senior director, advisory; Brent Casell -- vice president, advisory; Ingrid Laman -- vice president, advisory; and Gaston Gomez Armesto -- senior director, advisory.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Extras: &lt;/b&gt;networking receptions.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Register for Gartner HR Symposium/Expo &lt;a href="https://www.gartner.com/en/conferences/na/hr-symposium-us/register"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Oracle AI World &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When: &lt;/b&gt;Oct. 26-29, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where:&lt;/b&gt; Las Vegas&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost: &lt;/b&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;$1,999 early-bird; $1,399 public-sector.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Topics covered at this event include Oracle vision and strategy, AI development in Oracle applications, and Oracle Cloud Infrastructure development.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Conference speakers include Larry Ellison -- executive chairman and chief technology officer, Oracle; Clay Magouyrk -- chief executive officer, Oracle; Mike Sicilia -- chief executive officer, Oracle; Hernan Capdevila -- group vice president, application development, Oracle; and&amp;nbsp;Kautul&amp;nbsp;Mehta -- senior director, product management and product strategy, Cloud HCM, Oracle&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Extras: &lt;/b&gt;networking breaks and receptions.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Find out more about Oracle AI World &lt;a href="https://www.oracle.com/ai-world/"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;The Studio&amp;nbsp; &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When: &lt;/b&gt;Oct. 26-28, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where:&lt;/b&gt; Nashville, Tenn.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost: &lt;/b&gt;free, but via approved application only.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Topics covered at this event include leadership in the AI age and building the right teams for AI success. Conference speakers include Pavan Pidugu -- chief digital and information officer, U.S. Department of Transportation; Eileen Bridges -- senior vice president, business information security officer, Truist; Tipu Swaran -- director, technology strategy and transformation, Discover; Howard Miller -- chief information officer, UCLA Anderson School of Management; and Crystal Broj -- chief digital transformation officer, Medical University of South Carolina.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Apply to attend The Studio &lt;a href="https://hottopics.ht/hottopics-studio-nashville"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;ICMI Contact Center Expo &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When: &lt;/b&gt;Oct. 26-29, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where:&lt;/b&gt; Orlando, Fla.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost:&lt;/b&gt; Free for qualified registrants; from $1,799, super early bird.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Conference tracks include people and culture, service experience, strategy and leadership, maximizing productiving and operations, and AI in action.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Keynote speakers include Rachel Druckenmiller -- keynote speaker, facilitator, and leadership trainer; and Todd Honey -- host, The Daily Creative podcast.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Extras:&lt;/b&gt; ICMI Global Contact Center Awards and networking sessions.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;Find out more about ICMI Contact Center Expo &lt;a href="https://icmievents.com/"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;GitHub Universe &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When: &lt;/b&gt;Oct. 28-29, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where:&lt;/b&gt; San Francisco&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost: &lt;/b&gt;&lt;span style="list-style-type: disc;" xml:lang="EN" data-contrast="auto"&gt;$109, early-bird.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ad63261a-84e9-46b1-a28c-81b483910d1f}{231}" paraid="1922191547"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Topics include agentic engineering for leaders; benchmarking AI coding tools; AI fluency case studies;&amp;nbsp;token cost management; agentic workflows in production;&amp;nbsp;accelerating accessibility with AI and automation; and agentic security.&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{ad63261a-84e9-46b1-a28c-81b483910d1f}{243}" paraid="163719395"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Conference speakers include&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Alexander Androncik&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;--&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;corporate vice president, applied AI,&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Advanced Micro Devices (AMD&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;);&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Angie&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;Jone&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;s&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;-- vice president, Agentic AI Foundation; Cara Phillips&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;--&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;applied AI,&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;A&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;nthropic;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Benedict Ma&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;k&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;--&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;director, security engineering, Manulife;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Brendan Bergen&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;-- d&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;irector, AI&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;enablement, Vanguard;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Markus Howard -- a&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;ssociate&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;d&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;irector, software engineering, Moderna;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Julio Arruda&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;--&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;chief architect, GFT Technologies; and Julia Kasper&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;--&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;product manager,&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Visual Studio Code and GitHub&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Copilot,&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Mi&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;crosoft.&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Sign up to find out when registration opens for GitHub Universe &lt;a href="https://githubuniverse.com/"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Forrester Technology &amp;amp; Innovation Forum East&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When: &lt;/b&gt;Nov. 4-5, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where:&lt;/b&gt; New York City&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost:&lt;/b&gt; TBA&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Agenda and conference speakers have not yet been announced.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Find out more about this event &lt;a href="https://www.forrester.com/event/technology-innovation-north-america/"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Microsoft Ignite &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When:&lt;/b&gt; Nov. 17-20, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where: &lt;/b&gt;San Francisco&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost:&lt;/b&gt; $2,325 for conference pass; free for digital pass. &lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;Topics include AI, cloud, and business transformation.&lt;/p&gt; 
 &lt;p&gt;Conference speakers include Cyril Belikoff -- vice president of cloud and AI, Microsoft; Nitasha Chopra -- vice president and chief operating officer of Copilot Studio, Microsoft; Nicole Herskowitz -- corporate vice president of Microsoft 365 and Copilot, Microsoft; Vasu Jakkal -- corporate vice president of Microsoft Security, Microsoft; and Mark Russinovich -- chief technology officer, deputy chief information security officer and technical fellow, Microsoft Azure.&lt;/p&gt; 
 &lt;p&gt;Register for Microsoft Ignite&amp;nbsp;&lt;a href="https://register.ignite.microsoft.com/flow/microsoft/ignite27/welcome/page/welcome"&gt;here&lt;/a&gt;.&lt;/p&gt; 
 &lt;div&gt; 
  &lt;h2 paraeid="{40875328-3920-467a-8f36-48bc222302a1}{240}" paraid="172"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Forbes CIO Summit 2026&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{40875328-3920-467a-8f36-48bc222302a1}{246}" paraid="173"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&lt;strong&gt;When:&lt;/strong&gt;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Nov. 11, 2026&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{96ce9e61-d55b-42ae-9206-6f663e48cce7}{3}" paraid="174"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Where:&amp;nbsp;&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;New York&amp;nbsp;City and virtual&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{96ce9e61-d55b-42ae-9206-6f663e48cce7}{13}" paraid="175"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Cost:&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;TBA&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{96ce9e61-d55b-42ae-9206-6f663e48cce7}{21}" paraid="176"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Topics covered include agentic AI, mitigating&amp;nbsp;AI&amp;nbsp;and the future of IT.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{96ce9e61-d55b-42ae-9206-6f663e48cce7}{27}" paraid="177"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Agenda and conference speakers have not yet been announced.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{96ce9e61-d55b-42ae-9206-6f663e48cce7}{33}" paraid="178"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Extras:&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;&amp;nbsp;networking sessions.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{96ce9e61-d55b-42ae-9206-6f663e48cce7}{41}" paraid="179"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Find out more about the Forbes CIO Summit&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.forbes.com/connect/event/2026-forbes-cio-summit/"&gt;&lt;span xml:lang="EN" data-contrast="none"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;h2&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;AWS Re:Invent &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;When: &lt;/b&gt;Nov. 30-Dec. 4, 2026&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Where: &lt;/b&gt;Las Vegas&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;b&gt;Cost: &lt;/b&gt;&lt;span style="list-style-type: disc;" xml:lang="EN" data-contrast="auto"&gt;$1,299, early-bird; $2,499 standard.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN" data-contrast="auto"&gt;Topics covered include AWS cloud innovation strategy and roadmap;&amp;nbsp;agentic commerce;&amp;nbsp;AI case studies;&amp;nbsp;AWS cloud architecture; and AWS AI tools and agents.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Conference speakers have not yet been announced.&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Extras:&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;welcome reception,&amp;nbsp;re:Play&amp;nbsp;party featuring live music, food, interactive games, happy&amp;nbsp;hour&amp;nbsp;and&amp;nbsp;networking sessions.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;Subscribe to updates for AWS Re:Invent &lt;a href="https://aws.amazon.com/events/reinvent/"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt;</body>
            <description>Tech conferences are a vital way for CIOs and IT leaders to keep abreast of trends and make real-life connections in a fast-changing business climate.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/location_g1251263484.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/Strategic-IT-outlook-Tech-conferences-and-events-calendar</link>
            <pubDate>Thu, 13 Aug 2026 07:00:00 GMT</pubDate>
            <title>Strategic IT outlook: Tech conferences and events calendar</title>
        </item>
        <item>
            <body>&lt;div&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Executive summary&lt;/h3&gt; 
   &lt;div&gt; 
    &lt;ul style="list-style-type: disc;" role="list" class="default-list"&gt; 
     &lt;li role="listitem" data-aria-level="1" data-aria-posinset="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-listid="3" data-font="Symbol" data-leveltext="" aria-setsize="-1"&gt; &lt;p paraeid="{0c3cbf0c-d8bf-499b-b07c-a81f24e5cd8d}{17}" paraid="111105881"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;The AI Kill Switch Act would require certain powerful AI systems to support graduated intervention, including throttling,&amp;nbsp;suspension&amp;nbsp;and shutdown.&lt;/span&gt;&lt;span data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
    &lt;/ul&gt; 
   &lt;/div&gt; 
   &lt;div&gt; 
    &lt;ul style="list-style-type: disc;" role="list" class="default-list"&gt; 
     &lt;li role="listitem" data-aria-level="1" data-aria-posinset="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-listid="3" data-font="Symbol" data-leveltext="" aria-setsize="-1"&gt; &lt;p paraeid="{0c3cbf0c-d8bf-499b-b07c-a81f24e5cd8d}{23}" paraid="702980426"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;The bill is broader than some&amp;nbsp;state&amp;nbsp;AI safety laws, but a $500 million revenue threshold would&amp;nbsp;likely limit&amp;nbsp;its reach to major AI developers and systems builders.&lt;/span&gt;&lt;span data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
    &lt;/ul&gt; 
   &lt;/div&gt; 
   &lt;div&gt; 
    &lt;ul style="list-style-type: disc;" role="list" class="default-list"&gt; 
     &lt;li role="listitem" data-aria-level="1" data-aria-posinset="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-listid="3" data-font="Symbol" data-leveltext="" aria-setsize="-1"&gt; &lt;p paraeid="{0c3cbf0c-d8bf-499b-b07c-a81f24e5cd8d}{29}" paraid="264655092"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;CIOs should consider AI intervention capabilities in vendor contracts and their own governance programs, even before regulation requires them.&lt;/span&gt;&lt;span data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
    &lt;/ul&gt; 
   &lt;/div&gt;
  &lt;/div&gt;
 &lt;/div&gt; 
 &lt;p paraeid="{30475ce1-f0f9-41b5-bd90-19a72b5b3eb6}{171}" paraid="1803468269"&gt;&lt;em&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
 &lt;p paraeid="{30475ce1-f0f9-41b5-bd90-19a72b5b3eb6}{171}" paraid="1803468269"&gt;&lt;em&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
 &lt;p paraeid="{30475ce1-f0f9-41b5-bd90-19a72b5b3eb6}{171}" paraid="1803468269"&gt;&lt;em&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;An AI kill switch might be challenging for developers to implement, but lawmakers from both sides of the aisle are calling for more AI oversight.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{30475ce1-f0f9-41b5-bd90-19a72b5b3eb6}{177}" paraid="1389880099"&gt;&lt;em&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced the AI Kill Switch&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://lieu.house.gov/media-center/press-releases/reps-lieu-and-moran-introduce-bill-require-kill-switch-ai-systems-can"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;Act&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;on July 23, 2026, days after OpenAI disclosed that some of its AI models escaped a controlled environment and&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/cybersecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;hacked into&amp;nbsp;Hugging Face's&amp;nbsp;systems&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;. The bill would require developers of certain powerful AI systems to&amp;nbsp;maintain&amp;nbsp;the ability to throttle, suspend or shut down those systems, while giving the Department of Homeland Security authority to order such actions in certain circumstances.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{30475ce1-f0f9-41b5-bd90-19a72b5b3eb6}{213}" paraid="1321231909"&gt;&lt;em&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;However, the push for AI intervention capabilities extends beyond the proposed law.&amp;nbsp;Some companies are already asking AI vendors for kill-switch-like capabilities in&amp;nbsp;their contracts as they try to manage&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/cybersecurity/feature/Agentic-AIs-role-in-amplifying-and-creating-insider-risks"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;risks posed by&amp;nbsp;increasingly autonomous systems&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;. For CIOs, that raises questions about who controls AI embedded in enterprise software, what happens when a&amp;nbsp;vendor's&amp;nbsp;system goes&amp;nbsp;rogue&amp;nbsp;and how companies should&amp;nbsp;allocate&amp;nbsp;responsibility when AI causes harm.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{30475ce1-f0f9-41b5-bd90-19a72b5b3eb6}{235}" paraid="1835922550"&gt;&lt;em&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;In the following Q&amp;amp;A,&amp;nbsp;Monique "Nikki" Bhargava,&amp;nbsp;partner in the Emerging Technologies practice at global law firm Reed Smith, explains what the bill could mean for AI developers and enterprise users, as well as what CIOs should consider when managing AI risk.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{30475ce1-f0f9-41b5-bd90-19a72b5b3eb6}{247}" paraid="492374693"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Editor's notes:&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;The following transcript was edited for brevity and clarity.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;p paraeid="{30475ce1-f0f9-41b5-bd90-19a72b5b3eb6}{247}" paraid="492374693"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;What are lawmakers trying to solve with this requirement?&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{b7b8b56c-42fe-48b5-b8cd-05fc98a53abb}{12}" paraid="174172339"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Nikki Bhargava:&amp;nbsp;&lt;/strong&gt;The main concern is rogue AI -- when AI systems&amp;nbsp;fail to&amp;nbsp;respond to human intervention or act autonomously in ways the developers did not intend.&amp;nbsp;It's&amp;nbsp;about the ability to make that stop&amp;nbsp;very quickly. However, it&amp;nbsp;doesn't&amp;nbsp;necessarily&amp;nbsp;require&amp;nbsp;a complete cessation of activities.&amp;nbsp;They're&amp;nbsp;looking for a graduated response, depending on&amp;nbsp;the specific harm. For example,&amp;nbsp;they're&amp;nbsp;looking to be able to throttle the capabilities&amp;nbsp;--&amp;nbsp;to slow it down&amp;nbsp;--&amp;nbsp;or,&amp;nbsp;if&amp;nbsp;there's&amp;nbsp;a catastrophic risk,&amp;nbsp;to enable an actual cessation of activities.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{b7b8b56c-42fe-48b5-b8cd-05fc98a53abb}{58}" paraid="209361904"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;How broad is the proposed federal bill compared with some of the previous state AI safety bills?&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{b7b8b56c-42fe-48b5-b8cd-05fc98a53abb}{64}" paraid="1455229784"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;strong&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Bhargava:&lt;/span&gt;&lt;/strong&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;It's&amp;nbsp;still relevant to what&amp;nbsp;they're&amp;nbsp;defining as "covered technology," which is computing to one of the highest degrees of power.&amp;nbsp;We're&amp;nbsp;talking about systems developed using a large quantity of computing power. But within the definition of who is covered, it is the entities that&amp;nbsp;operate&amp;nbsp;those covered technologies or systems that incorporate covered technologies. Many of the safety bills have focused specifically on&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/whatis/feature/12-of-the-best-large-language-models"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;frontier models&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;.&amp;nbsp;This bill&amp;nbsp;also&amp;nbsp;addresses&amp;nbsp;entities that are operating systems that&amp;nbsp;&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;incorporate&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;frontier models. So,&amp;nbsp;we're&amp;nbsp;going slightly one step ahead, which is broader than what&amp;nbsp;we've&amp;nbsp;seen&amp;nbsp;pass in&amp;nbsp;the state bills.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{b7b8b56c-42fe-48b5-b8cd-05fc98a53abb}{106}" paraid="761864681"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;The burden still sits with those frontier-model developers because&amp;nbsp;that's&amp;nbsp;where&amp;nbsp;you'll&amp;nbsp;need that functionality, even if those models are later incorporated into other systems.&amp;nbsp;It's&amp;nbsp;the models that need that functionality, and then the systems need to be able to build on top of it.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{b7b8b56c-42fe-48b5-b8cd-05fc98a53abb}{112}" paraid="817822924"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Would everyday deployers of frontier models, such as ChatGPT or Gemini, be covered by the bill?&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{b7b8b56c-42fe-48b5-b8cd-05fc98a53abb}{126}" paraid="1661944094"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Bhargava:&amp;nbsp;&lt;/strong&gt;My read on the bill&amp;nbsp;is that&amp;nbsp;it's&amp;nbsp;really targeting the frontier model developers&amp;nbsp;and then&amp;nbsp;the&amp;nbsp;initial&amp;nbsp;systems builders.&amp;nbsp;A&amp;nbsp;lot of&amp;nbsp;end-user&amp;nbsp;deployers&amp;nbsp;who&amp;nbsp;are just&amp;nbsp;bringing in the system with&amp;nbsp;something like&amp;nbsp;ChatGPT built into it&amp;nbsp;--&amp;nbsp;while there's a&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/ai/tip/8-agentic-AI-governance-strategies-A-complete-guide"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;governance program that they should be putting in place&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;--&amp;nbsp;they&amp;nbsp;don't&amp;nbsp;have the same technical capabilities to reach into those systems and build the functionality this bill is looking for.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{b7b8b56c-42fe-48b5-b8cd-05fc98a53abb}{186}" paraid="984155600"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;It may get more refined to make that&amp;nbsp;clearer, because it's really&amp;nbsp;about&amp;nbsp;that first layer and that second layer&amp;nbsp;--&amp;nbsp;the ones that make&amp;nbsp;that technology available.&amp;nbsp;Then&amp;nbsp;there's&amp;nbsp;a third threshold: the entity must&amp;nbsp;have&amp;nbsp;derived&amp;nbsp;at least $500 million in gross revenue from the covered technology&amp;nbsp;in the preceding&amp;nbsp;calendar year.&amp;nbsp;That's&amp;nbsp;very,&amp;nbsp;very high.&amp;nbsp;At the end of the day,&amp;nbsp;you're&amp;nbsp;not going to have many companies that are going to&amp;nbsp;be reaching&amp;nbsp;that threshold.&amp;nbsp;That should alleviate&amp;nbsp;the&amp;nbsp;concern that this&amp;nbsp;will&amp;nbsp;reach the everyday deployer.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{3}" paraid="804593274"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Some companies are already adding kill-switch-like provisions to AI contracts with vendors. Why are they asking for these capabilities before the regulation requires it?&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{27}" paraid="2088257935"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Bhargava:&amp;nbsp;&lt;/strong&gt;That's&amp;nbsp;what we see with AI generally, because&amp;nbsp;legislation can only move so quickly.&amp;nbsp;The technology&amp;nbsp;is evolving much faster than legislation&amp;nbsp;can keep up with. There are&amp;nbsp;thousands&amp;nbsp;of AI bills proposed year after year, and&amp;nbsp;most do not make it across the finish line.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{67}" paraid="281625019"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Federally,&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/it-strategy/news/366646236/How-CIOs-can-navigate-federal-state-AI-regulation-uncertainty"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;there's going to be a lot of friction getting AI legislation passed&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;that's incredibly narrow and tailored to the White House AI executive order and specific priorities at this time. If&amp;nbsp;you're&amp;nbsp;a company thinking about what you need to worry about to protect your own company&amp;nbsp;--&amp;nbsp;and we do this all the time in every aspect of governance or risk coverage&amp;nbsp;--&amp;nbsp;legislation sometimes sets the&amp;nbsp;minimum&amp;nbsp;bar.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{89}" paraid="1193616101"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Companies are going to look at where their risk sits and say, "I need to worry about what happens if we have a vendor who's bringing an AI product into our systems." Sometimes, especially with larger companies, they&amp;nbsp;don't&amp;nbsp;always know when those AI functionalities are being turned on, so&amp;nbsp;there's&amp;nbsp;a lot more control coming into that.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{95}" paraid="443372938"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;At the same time, because they know they&amp;nbsp;don't&amp;nbsp;have control over these external systems, they need to be able to intervene if an AI system starts going rogue.&amp;nbsp;That's&amp;nbsp;why&amp;nbsp;they're&amp;nbsp;asking for more functionality here.&amp;nbsp;They're&amp;nbsp;saying, "If I can't control it, and it's doing something that I don't&amp;nbsp;want it&amp;nbsp;to do, I need to be able to make it stop."&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{103}" paraid="1196642782"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;It's&amp;nbsp;almost&amp;nbsp;like&amp;nbsp;the&amp;nbsp;computer's&amp;nbsp;running off the rails,&amp;nbsp;and&amp;nbsp;I need to be able to pull the plug. And you&amp;nbsp;can't&amp;nbsp;pull the plug like that because&amp;nbsp;we're&amp;nbsp;not dealing with on-prem capabilities anymore.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{123}" paraid="1406420050"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Generally, if a company fine-tunes a vendor's AI model, such as Gemini, with its own data and the system causes harm, how do you determine whether the vendor or the company is responsible?&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{129}" paraid="363308642"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Bhargava:&amp;nbsp;&lt;/strong&gt;That's&amp;nbsp;a tough&amp;nbsp;one. This is why contracts are important to help&amp;nbsp;allocate&amp;nbsp;liability.&amp;nbsp;But at the end of the day, you&amp;nbsp;have to&amp;nbsp;be able to show&amp;nbsp;some direct causation, and that is very complicated because you&amp;nbsp;have to&amp;nbsp;look at the model,&amp;nbsp;the data,&amp;nbsp;the governance and how those pieces interacted.&amp;nbsp;That liability is not necessarily going to be as&amp;nbsp;clear-cut&amp;nbsp;as with other SaaS or software solutions.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{183}" paraid="1190111276"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Some states&amp;nbsp;are&amp;nbsp;unwilling to allow&amp;nbsp;a defense that says&amp;nbsp;it was the AI itself. An entity&amp;nbsp;must&amp;nbsp;take responsibility for the impacts and&amp;nbsp;outputs&amp;nbsp;of an AI&amp;nbsp;system.&amp;nbsp;The&amp;nbsp;defense&amp;nbsp;that&amp;nbsp;"We're just the developer, and this is the model. We&amp;nbsp;don't&amp;nbsp;control the model,"&amp;nbsp;or&amp;nbsp;"We're a deployer,&amp;nbsp;and&amp;nbsp;we don't control the model,"&amp;nbsp;is not&amp;nbsp;going to fly in some states, and I think&amp;nbsp;we're&amp;nbsp;going to see a lot more of that in the future.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e165406f-f7c3-41ff-85e7-e4e1a5c99eac}{249}" paraid="144125410"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Do you expect this bill to face significant opposition?&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{21dad184-2ee7-4dc6-ac33-f988ff0884c8}{2}" paraid="510343356"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Bhargava:&amp;nbsp;&lt;/strong&gt;I&amp;nbsp;don't&amp;nbsp;know if I&amp;nbsp;could characterize&amp;nbsp;it&amp;nbsp;as significant, because&amp;nbsp;there's&amp;nbsp;a lot of&amp;nbsp;bipartisan interest in having a narrowly tailored solution for the concerns being voiced&amp;nbsp;--&amp;nbsp;not just&amp;nbsp;by technology&amp;nbsp;or&amp;nbsp;consumer safety advocates, but the&amp;nbsp;general public.&amp;nbsp;There are questions&amp;nbsp;about how we make this safer.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{21dad184-2ee7-4dc6-ac33-f988ff0884c8}{42}" paraid="786459470"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;However,&amp;nbsp;I do think&amp;nbsp;there will be opposition&amp;nbsp;because&amp;nbsp;it's&amp;nbsp;not&amp;nbsp;a simple task to build this functionality into systems. It is costly&amp;nbsp;and&amp;nbsp;burdensome. And&amp;nbsp;then you have&amp;nbsp;existing technology&amp;nbsp;that&amp;nbsp;doesn't&amp;nbsp;necessarily&amp;nbsp;have this. So,&amp;nbsp;there's&amp;nbsp;going to need&amp;nbsp;to be a balance.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{21dad184-2ee7-4dc6-ac33-f988ff0884c8}{80}" paraid="208720291"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;But the fact that this is a bipartisan bill&amp;nbsp;indicates&amp;nbsp;that&amp;nbsp;this&amp;nbsp;isn't&amp;nbsp;a&amp;nbsp;state-versus-federal or industry-versus-public&amp;nbsp;thing.&amp;nbsp;It's&amp;nbsp;a shared concern&amp;nbsp;on how to address the situation because&amp;nbsp;it's&amp;nbsp;not just the public that is&amp;nbsp;impacted&amp;nbsp;by catastrophic risk. Other&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchsecurity/news/366646755/What-CISOs-can-learn-from-the-Hugging-Face-OpenAI-incident"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;companies could be at risk of autonomous AI from other companies&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;, so this is a general security concern.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{21dad184-2ee7-4dc6-ac33-f988ff0884c8}{116}" paraid="1809786364"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Is there anything else CIOs should be thinking about?&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{21dad184-2ee7-4dc6-ac33-f988ff0884c8}{122}" paraid="1169299849"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;strong&gt;Bhargava:&lt;/strong&gt;&amp;nbsp;For CIOs, one thing to think about is how to build&amp;nbsp;these&amp;nbsp;AI&amp;nbsp;intervention&amp;nbsp;capabilities&amp;nbsp;into your own governance system. It is a&amp;nbsp;graduated&amp;nbsp;response. It is&amp;nbsp;throttling it&amp;nbsp;or completely turning it off. When, where and how to exercise this in the bill is a government decision,&amp;nbsp;not a private-entity decision.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{21dad184-2ee7-4dc6-ac33-f988ff0884c8}{158}" paraid="250188885"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;But if a company is asking for these capabilities, they need to be built into their governance system. How, when and at what level should you exercise them&amp;nbsp;in order to&amp;nbsp;protect the company from risk and not completely debilitate&amp;nbsp;the&amp;nbsp;technology that you&amp;nbsp;invested&amp;nbsp;in?&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{21dad184-2ee7-4dc6-ac33-f988ff0884c8}{178}" paraid="1856713800"&gt;&lt;em&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Tim Murphy is a site editor and writer for the IT Strategy team at TechTarget.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;/div&gt;</body>
            <description>The AI Kill Switch Act would require powerful AI systems to support shutdowns. A lawyer explains what the bill means for CIOs, vendors and enterprise risk.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/legal_g90787303.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/AI-Kill-Switch-Act-raises-questions-for-CIOs</link>
            <pubDate>Thu, 13 Aug 2026 05:25:00 GMT</pubDate>
            <title>AI Kill Switch Act raises questions for CIOs</title>
        </item>
        <item>
            <body>&lt;div&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Executive summary&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt; &lt;p&gt;The OpenAI and Hugging Face incident shows why CIOs must consider AI liability risks.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
   &lt;/ul&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt; &lt;p&gt;Experts say rogue AI is not to blame, but the problem was with engineering, testing and oversight failures.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
   &lt;/ul&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt; &lt;p&gt;Some experts believe OpenAI is capitalizing on the incident to generate attention.&lt;/p&gt; &lt;/li&gt; 
   &lt;/ul&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt; &lt;p&gt;Despite any marketing hype, the legal risks of AI remain real for CIOs.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
   &lt;/ul&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt; &lt;p&gt;CIOs cannot assume vendors will be responsible when AI systems cause harm.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
    &lt;li&gt; &lt;p&gt;Organizations can reduce liability exposure through stronger vendor reviews, contract negotiations, access controls, testing and continuous monitoring of AI systems.&lt;/p&gt; &lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt; 
 &lt;p paraeid="{f92c925b-43d1-43ce-8c96-2b3d9dfb0207}{102}" paraid="1287571692"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;While humans can make mistakes, AI agents can make&amp;nbsp;the same&amp;nbsp;mistakes thousands of times faster. CIOs need to understand who is liable when those mistakes cause real-world harm.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{f92c925b-43d1-43ce-8c96-2b3d9dfb0207}{112}" paraid="528828552"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;In July 2026,&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/cybersecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;OpenAI models&amp;nbsp;escaped&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;a controlled testing&amp;nbsp;environment and&amp;nbsp;hacked into&amp;nbsp;another company's&amp;nbsp;systems.&amp;nbsp;While the incident involved a frontier lab testing its models, it raises broader questions for enterprise CIOs deploying AI systems of their own.&amp;nbsp;As organizations&amp;nbsp;grant AI agents access to critical systems and customer interactions, they must consider who is liable when those systems cause harm and how&amp;nbsp;to reduce that risk.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{f92c925b-43d1-43ce-8c96-2b3d9dfb0207}{150}" paraid="902602255"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;The incident is unlikely to be the last of its kind. In fact,&amp;nbsp;just weeks later,&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;Anthropic&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;Meta&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;disclosed&amp;nbsp;similar cases in which&amp;nbsp;their&amp;nbsp;models accessed external systems during testing.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{f92c925b-43d1-43ce-8c96-2b3d9dfb0207}{184}" paraid="1054189134"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Organizations&amp;nbsp;--&amp;nbsp;both&amp;nbsp;AI&amp;nbsp;frontier labs and regular enterprises --&amp;nbsp;are adopting AI faster than they are building the engineering practices and oversight needed to manage it.&amp;nbsp;That approach worries some CIOs, who believe many organizations are prioritizing speed over governance.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{f92c925b-43d1-43ce-8c96-2b3d9dfb0207}{210}" paraid="626646572"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"There's a volcano about to go off, and a lot of the AI that's been implemented by a lot of different companies is going to have to get ripped back up because it's not going to meet any kind of security controls," said Doug Gilbert, CIO and chief digital officer at Sutherland,&amp;nbsp;a global digital transformation consulting firm.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{f92c925b-43d1-43ce-8c96-2b3d9dfb0207}{226}" paraid="1342339378"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;To avoid ending up in the headlines&amp;nbsp;-- or in a courtroom --&amp;nbsp;for some kind of&amp;nbsp;AI&amp;nbsp;incident,&amp;nbsp;CIOs need to vet vendors, understand contracts, review insurance coverage, limit what AI systems can access, test models before deployment and continuously monitor them after they go live.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h2 paraeid="{f92c925b-43d1-43ce-8c96-2b3d9dfb0207}{244}" paraid="1667518904" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;The&amp;nbsp;OpenAI and Hugging Face&amp;nbsp;incident&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{f92c925b-43d1-43ce-8c96-2b3d9dfb0207}{254}" paraid="813809159"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;The incident occurred during a controlled cybersecurity evaluation conducted by OpenAI. The test measured how well OpenAI models could perform offensive security tasks, including finding and exploiting vulnerabilities.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/U9yfjwQbS5E?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://www.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{5}" paraid="1856051245"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;To run the test, OpenAI removed some of the safety controls that normally prevent models from responding to high-risk cybersecurity requests. During the evaluation, the models&amp;nbsp;exploited a previously unknown vulnerability, known as a zero-day, in a third-party software&amp;nbsp;component.&amp;nbsp;They&amp;nbsp;then used that access to move beyond the intended testing environment and access Hugging Face's systems.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{19}" paraid="1259218694"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"It was an air-gapped network, and it was able to somehow escape through a proxy that somebody messed up, then harvest credentials and get in using a zero-day exploit that nobody was aware of. That is like science fiction-level stuff right there," Gilbert said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h2 paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{25}" paraid="449972389" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;The failure was engineering, not rogue AI&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{31}" paraid="544837655"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;OpenAI's most advanced models, along with&amp;nbsp;other&amp;nbsp;frontier models&amp;nbsp;like Claude Mythos, have become&amp;nbsp;incredibly capable.&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchcio/feature/ais-cybersecurity-paradox-how-CIOs-can-keep-up-with-change"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;These systems can find previously unknown vulnerabilities&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;and take actions that surprise even experienced security professionals.&amp;nbsp;However,&amp;nbsp;experts believe the&amp;nbsp;takeaway&amp;nbsp;from this incident&amp;nbsp;is&amp;nbsp;that OpenAI&amp;nbsp;failed to&amp;nbsp;follow sound engineering practices during the test&amp;nbsp;-- not that AI&amp;nbsp;simply&amp;nbsp;went&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt; rogue.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    They put it in a contained environment to see whether it could break out … and then, what? They walked away and had lunch? 
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Suresh Venkatasubramanian&lt;/strong&gt;Professor and co-chair, ACM's USTPC AI &amp;amp; Algorithms Subcommittee, Brown University
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{83}" paraid="318298726"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"The truth is,&amp;nbsp;OpenAI was testing whether a particular LLM could identify cybersecurity vulnerabilities. Great,&amp;nbsp;they should absolutely do that. They put it in&amp;nbsp;a&amp;nbsp;contained environment to see whether it could break out. Excellent.&amp;nbsp;That's&amp;nbsp;a great idea.&amp;nbsp;And then, what?&amp;nbsp;They walked away and had lunch and let it do whatever it wanted?"&amp;nbsp;said Suresh&amp;nbsp;Venkatasubramanian,&amp;nbsp;co-chair of ACM's USTPC AI &amp;amp; Algorithms&amp;nbsp;Subcommittee and&amp;nbsp;professor at Brown University.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{149}" paraid="754046784"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Chalking up the incident&amp;nbsp;to&amp;nbsp;mere&amp;nbsp;rogue AI shifts attention away from the people and processes responsible for building and testing these systems. For CIOs, the more useful lesson is that increasingly capable AI requires stronger engineering practices,&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchcio/feature/the-ai-agent-governance-gap-how-cios-can-gain-control"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;continuous monitoring&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;and better containment.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{171}" paraid="2018602400"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"In any other industry, if the&amp;nbsp;tools&amp;nbsp;you're&amp;nbsp;building cause problems like this, you&amp;nbsp;don't&amp;nbsp;say, 'Whoa, our tools are alive, and they did weird stuff. Isn't that&amp;nbsp;cool?'&amp;nbsp;It's&amp;nbsp;more like, 'Oh, we made a bad mistake, and we should be ashamed of ourselves,'" Venkatasubramanian said.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h2 paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{179}" paraid="548240403" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;Is there a marketing angle?&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{187}" paraid="26794087"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Publicizing AI security incidents can serve legitimate purposes. Companies may&amp;nbsp;disclose&amp;nbsp;these events to promote transparency, warn the industry about emerging&amp;nbsp;risks&amp;nbsp;and&amp;nbsp;demonstrate&amp;nbsp;the importance of AI safety work.&amp;nbsp;However,&amp;nbsp;these disclosures can also generate significant attention for the companies involved.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{197}" paraid="815689892"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Many observers across social media questioned whether OpenAI's public disclosure was, at least in part, a marketing exercise. Dramatic demonstrations of AI capabilities generate headlines, and highlighting a model that can exploit a zero-day vulnerability reinforces the narrative that frontier models are becoming increasingly capable.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{203}" paraid="1725637517"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"I agree that they are using it to drum up attention," said Valence Howden, advisory&amp;nbsp;fellow&amp;nbsp;and distinguished analyst at Info-Tech Research Group.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h2 paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{211}" paraid="1753863334" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;Who's liable when AI systems cause harm?&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{e13053f1-cd62-4eed-9d07-efae992dde1b}{217}" paraid="1665640150"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Even if parts of&amp;nbsp;this&amp;nbsp;incident&amp;nbsp;are&amp;nbsp;being&amp;nbsp;hyped&amp;nbsp;for marketing purposes,&amp;nbsp;the&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/data-technologies/tip/Why-a-risk-management-framework-is-critical-for-AI-initiatives"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;risks posed by autonomous AI systems&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;are still very real&amp;nbsp;for&amp;nbsp;enterprises&amp;nbsp;deploying the technology.&amp;nbsp;CIOs must&amp;nbsp;know&amp;nbsp;who could be held liable when&amp;nbsp;their&amp;nbsp;AI systems&amp;nbsp;cause damage to another party.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{12}" paraid="544198036"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Liability will&amp;nbsp;likely depend&amp;nbsp;on who built the system, who deployed&amp;nbsp;it&amp;nbsp;and what controls were in place. CIOs should not assume their&amp;nbsp;AI vendor will automatically bear responsibility. Organizations using AI systems&amp;nbsp;can be&amp;nbsp;held accountable for how they configure,&amp;nbsp;govern&amp;nbsp;and&amp;nbsp;monitor&amp;nbsp;those systems.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{28}" paraid="876206281"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"The liability always comes down into the company that's actually implementing the AI or the end user of the AI, and usually then it falls back into what kind of controls, governance mechanisms&amp;nbsp;and&amp;nbsp;accuracy rates are in place to govern or protect the company,"&amp;nbsp;Gilbert said.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{42}" paraid="2083415840"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;In the case of OpenAI and Hugging Face, the companies have publicly treated the incident as a collaborative security matter rather than a dispute, said Katie&amp;nbsp;Nadro,&amp;nbsp;partner at&amp;nbsp;Levenfeld&amp;nbsp;Pearlstein, a&amp;nbsp;Chicago-based&amp;nbsp;business law firm.&amp;nbsp;However,&amp;nbsp;there could be questions about responsibility if one party wanted to pursue them.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{70}" paraid="1452118861"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"Were&amp;nbsp;[Hugging Face]&amp;nbsp;so inclined, there might be some case for some form of liability,"&amp;nbsp;Nadro&amp;nbsp;said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h2 paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{84}" paraid="676226738" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;AI regulation will&amp;nbsp;involve&amp;nbsp;old and new laws&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{94}" paraid="410434698"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Despite growing calls for AI-specific regulation, many legal questions surrounding AI systems will&amp;nbsp;likely be&amp;nbsp;evaluated through existing legal frameworks. Lawyers and regulators are&amp;nbsp;applying&amp;nbsp;established areas of law, including negligence, product liability, consumer&amp;nbsp;protection&amp;nbsp;and data privacy laws, to new AI-related scenarios.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Negligence is always a winner.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Katie Nadro&lt;/strong&gt;Partner, Levenfeld Pearlstein 
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{104}" paraid="506184094"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"If you talk to lawyers or regulators in&amp;nbsp;the space, they're using existing&amp;nbsp;law&amp;nbsp;to evaluate these kinds of risks.&amp;nbsp;You're&amp;nbsp;talking about product liability law, consumer protection laws, data&amp;nbsp;privacy&amp;nbsp;and security laws.&amp;nbsp;Negligence is always a winner,"&amp;nbsp;Nadro&amp;nbsp;said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{118}" paraid="263162065"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;However, existing laws may not address every risk associated with increasingly capable AI systems.&amp;nbsp;New regulations&amp;nbsp;could be needed for frontier AI systems, particularly around safety requirements and accountability measures,&amp;nbsp;Nadro&amp;nbsp;said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{140}" paraid="1691690441"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;The result will&amp;nbsp;likely be&amp;nbsp;a combination of new AI rules and existing legal theories being applied to emerging technologies.&amp;nbsp;Nadro&amp;nbsp;compared the approach to privacy regulation, where&amp;nbsp;new technologies&amp;nbsp;have been addressed through existing laws while lawmakers also created new&amp;nbsp;rules governing how companies handle personal data.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h2 paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{154}" paraid="2048093852" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;6 steps CIOs&amp;nbsp;can take to reduce AI liability exposure&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{162}" paraid="659786475" aria-level="2" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;CIOs cannot eliminate every risk associated with AI systems, but they can take steps to reduce their exposure.&amp;nbsp;Those steps&amp;nbsp;begin before deployment and continue throughout the system's life.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h3 paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{172}" paraid="1662244495" aria-level="3" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;1.&amp;nbsp;Vet AI vendors and understand contracts&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h3&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{180}" paraid="186321712"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;CIOs should not assume an AI vendor will automatically take responsibility if an AI system causes damage.&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchcio/feature/What-CIOs-need-to-know-going-into-AI-vendor-negotiations"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;Contracts between an organization and its AI providers&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;can&amp;nbsp;determine&amp;nbsp;where liability falls. Before deploying AI systems, CIOs should review terms around liability limits,&amp;nbsp;indemnification&amp;nbsp;and each party's responsibilities if something goes wrong.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{194}" paraid="663281343"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;AI providers and customers may both face liability after an incident. Contract terms can&amp;nbsp;determine&amp;nbsp;whether an organization can recover damages from a provider or whether it must absorb the costs itself. Liability limits and indemnification provisions can significantly shape that outcome.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{200}" paraid="755928432"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"If you are bound by your existing liability limits or indemnification provisions, which foreclose that area to recover, then you could be left with significant exposure for the CIO's company itself,"&amp;nbsp;Nadro&amp;nbsp;said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h3 paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{172}" paraid="1662244495" aria-level="3" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;2. Don't assume insurance covers AI failures&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{216}" paraid="559629053"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;AI-related risks are creating new questions around insurance coverage. CIOs should not assume&amp;nbsp;that existing cyber liability policies automatically cover losses associated with&amp;nbsp;AI systems, especially as insurers&amp;nbsp;adapt&amp;nbsp;their policies to address emerging risks. Organizations should&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/cybersecurity/feature/How-cyber-insurance-helped-with-breach-recovery-or-not"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;review their coverage with insurers&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;and legal&amp;nbsp;teams to&amp;nbsp;determine whether AI-related incidents are covered and identify any gaps.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{238}" paraid="991229186"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"Even if you have something like cyber liability insurance, that is also rapidly changing right now to account for AI incidents, and so you might not have the amount of coverage&amp;nbsp;--&amp;nbsp;or even any coverage&amp;nbsp;--&amp;nbsp;for this particular scenario,"&amp;nbsp;Nadro&amp;nbsp;said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h3 paraeid="{2fe0d5e6-9fd9-43e1-99f9-77b00c3bd98f}{254}" paraid="1903495502" aria-level="3" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;3. Give agents only the access they need&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h3&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{5}" paraid="838002241"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;AI agents can&amp;nbsp;pose new security risks when organizations grant them more access than necessary. CIOs should define what data and systems an agent&amp;nbsp;requires&amp;nbsp;for a specific task and limit permissions accordingly.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{15}" paraid="1316494147"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"You can find yourself in trouble if you're just opening it up and letting agents have access to more data than it needs," said Eric Johnson, CIO at PagerDuty, a&amp;nbsp;digital operations management and incident response software company.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{31}" paraid="2044246384"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Organizations should approach agent access the same way they manage employee permissions.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{39}" paraid="1422124139"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"If this&amp;nbsp;were&amp;nbsp;a human, and they were doing this job, what data access&amp;nbsp;should they have? Why should it be any&amp;nbsp;different?,"&amp;nbsp;Johnson said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h3 paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{61}" paraid="1718697006" aria-level="3" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;4. Build AI on reliable data&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h3&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{67}" paraid="555656986"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;AI systems can only produce reliable results if they are built on quality data. Before deploying AI, organizations should&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchcio/feature/What-enterprises-are-getting-wrong-about-AI-data-readiness"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;evaluate the data they use&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;to train and fine-tune models and look for bias that could affect outputs.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{81}" paraid="805127071"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"We'll leverage things like AI Fairness 360 to remove bias from the data," Gilbert&amp;nbsp;said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h3 paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{89}" paraid="252284560" aria-level="3" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;5. Test AI performance before scaling&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h3&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{95}" paraid="2091840963"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Organizations should not assume AI models are ready for production out of the box. Before deploying AI at scale, CIOs should test systems for accuracy and reliability and continue refining them until they consistently produce acceptable results.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{101}" paraid="1034639026"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"We will ensure we get an accurate outcome and keep training the model to get accurate outcomes until we're satisfied.&amp;nbsp;Typically,&amp;nbsp;we go&amp;nbsp;to&amp;nbsp;about 97&amp;nbsp;or&amp;nbsp;98%&amp;nbsp;[accuracy]&amp;nbsp;before we release it to production,"&amp;nbsp;Gilbert said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;h3 paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{129}" paraid="728615039" aria-level="3" role="heading"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;6. Monitor AI systems after deployment&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h3&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{135}" paraid="766606749"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Deploying an AI system is not the end of the process. CIOs should continuously&amp;nbsp;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchitoperations/podcast/AI-observability-Why-old-monitoring-fails-in-the-GenAI-era"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;monitor AI systems&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&amp;nbsp;to&amp;nbsp;understand how models make decisions, identify unexpected behavior and investigate problems if something goes wrong.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{153}" paraid="221037270"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"Not having observability in place is risky. How did they make the decision? What data did they make the decision on? What actions has it taken?&amp;nbsp;Not being able to do the forensics on it&amp;nbsp;is nerve-wracking,"&amp;nbsp;Gilbert said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{173}" paraid="154874933"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Organizations can also&amp;nbsp;establish&amp;nbsp;expected operating thresholds for AI agents and automatically flag behavior that falls outside those parameters for further review.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{179}" paraid="3490105"&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;"If one of the agents starts to do something outside of a tolerance you expected, then you&amp;nbsp;need&amp;nbsp;the ability to&amp;nbsp;flag&amp;nbsp;that there's something wrong,"&amp;nbsp;Johnson said.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{64e0c5e8-15b1-40b6-a06c-e3fb2463438e}{195}" paraid="154595098"&gt;&lt;em&gt;&lt;span style="font-family: arial, helvetica, sans-serif;"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Tim Murphy is a site editor and writer for the IT Strategy team at TechTarget.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;/div&gt;</body>
            <description>AI agents create new liability risks for enterprises. CIOs must understand vendor contracts, insurance and governance practices before deploying autonomous systems.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/legal_g1065824400.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/OpenAI-Hugging-Face-incident-raises-AI-liability-concerns</link>
            <pubDate>Thu, 13 Aug 2026 04:43:00 GMT</pubDate>
            <title>OpenAI-Hugging Face incident raises AI liability concerns</title>
        </item>
        <item>
            <body>&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h2&gt;Executive Summary&lt;/h2&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;b&gt;Smart glasses are now enterprise threats.&lt;/b&gt;&amp;nbsp;Covert recording capabilities and AI integration expose sensitive data, IP and confidential conversations across facilities without visible detection.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Compliance violations are inevitable without controls.&lt;/b&gt;&amp;nbsp;GDPR, HIPAA, and biometric privacy breaches create legal liability, regulatory penalties, and reputational damage that extends beyond IT.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Immediate action is required.&lt;/b&gt;&amp;nbsp;Audit on-premises devices, ban use in sensitive areas, deploy detection tools, and enforce strict policies before a data breach forces reactive measures.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;It wasn't that long ago that smart glasses were considered a niche product, but now they may be considered an enterprise risk.&lt;/p&gt; 
&lt;p&gt;When Google launched Google Glass in 2013, it looked nothing like actual glasses, and the product was available only to a small number of developers to try as an experimental technology. Google Glass was released to the public the following year, but it received a lukewarm reception and low adoption.&lt;/p&gt; 
&lt;p&gt;In the years since, the technology and design behind smart glasses have evolved, leading to greater acceptance into the mainstream. Global shipments of smart glasses spiked by &lt;a href="https://counterpointresearch.com/en/insights/post-insight-research-notes-blogs-rayban-meta-smart-glasses-drive-global-smart-glasses-market-surge-in-2024-fuelling-momentum-in-2025-with-projected-60-cagr-through-2029" target="_blank" rel="noopener"&gt;210% in 2024&lt;/a&gt;, with popular models such as the Meta Ray-Bans and Snap Spectacles gaining traction. These newer models enable even more covert recording, thanks to their more stylized, traditional design and advanced features such as cloud transmission. In particular, the timing has been a perfect fit with the rise of AI, with smart glasses offering integration and real time AI analysis.&lt;/p&gt; 
&lt;p&gt;The smart glasses market size was valued at $2.5 billion in 2025 and is projected to grow from $3.2 billion in 2026 to $14.4 billion by 2033, according to &lt;a href="https://www.grandviewresearch.com/industry-analysis/smart-glasses-market-report" target="_blank" rel="noopener"&gt;a report from Grand View Research&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;But with increased adoption and enhanced features comes a new wave of security and data privacy concerns. Workplaces now face an increased risk of compliance violations and compromised customer or proprietary data, presenting CIOs and CISOs with a unique governance challenge. Here's what you need to know about the risks that smart glasses pose, and how best to protect your business, your customers and your data from what are effectively &lt;a href="https://www.techtarget.com/searchcio/feature/Surveillance-backlash-A-wake-up-call-for-CIOs"&gt;always-on surveillance devices&lt;/a&gt;.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Market developments"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Market developments&lt;/h2&gt;
 &lt;p&gt;The landscape surrounding the smart glasses market is rapidly shifting, with Apple developing its smart glasses. Details of Apple's smart glasses are limited, but, as with other products, they will most likely integrate with other Apple hardware commonly deployed in enterprise environments, such as iPhones, iPads and Macs. The same applies to Apple software, such as Apple Business Manager and other MDM solutions.&lt;/p&gt;
 &lt;p&gt;As Apple gets ready to join the likes of Meta in the smart glasses market, the timing is less than ideal, with privacy concerns at an all-time high. There are increasing reports of people being recorded without their consent in public spaces such as gyms or, even more concerning, in private spaces.&lt;/p&gt;
 &lt;p&gt;CIOs need to seize this opportunity to establish governance for smart glasses firmly and proactively as the market continues to grow.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Surveillance without consent"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Surveillance without consent&lt;/h2&gt;
 &lt;p&gt;One of the biggest challenges with newer smart glasses like the Meta Ray-Bans is that they are deliberately designed to blend in; they are, at least in theory, indistinguishable from an ordinary pair of glasses. As such, anyone who sets foot in your company's facilities while wearing them – whether employees, outside contractors, or visitors – could be acting as a mobile sensor, capturing information without your knowledge.&lt;/p&gt;
 &lt;p&gt;The indicators that smart glasses use to show when they're recording are subtle. Models like the Meta Ray-Bans do have features such as a small LED light that turns on when they're recording, but it can be easy to miss in bright light, not to mention aftermarket methods of circumventing said notification measures.&lt;/p&gt;
 &lt;p&gt;If a wearer were present in places such as boardrooms, R&amp;amp;D labs or factory floors, the list of enterprise and workplace risks would be lengthy. Leaks of sensitive conversations or IP, violations of GDPR compliance or biometric privacy regulations, and even &lt;a href="https://www.techtarget.com/healthtechanalytics/feature/AI-and-HIPAA-compliance-How-to-navigate-major-risks"&gt;HIPAA violations&lt;/a&gt; all become very real possibilities.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Broader concerns for enterprises"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Broader concerns for enterprises&lt;/h2&gt;
 &lt;p&gt;The risks posed by smart glasses in an enterprise environment are not just technical. When CISOs evaluate risks associated with &lt;a href="https://www.techtarget.com/searchmobilecomputing/definition/wearable-technology"&gt;wearable technology&lt;/a&gt;, they also need to consider the downstream consequences of losing company data or failing to comply. Any enterprise that has a reputation for losing customer data, privacy violations, or worse is one that's going to struggle with trust issues both inside and outside the company.&lt;/p&gt;
 &lt;p&gt;Take, for instance, the existence of a new app called Nearby Glasses that can be used to flag the presence of smart glasses – the mere existence of such an app suggests that people are already becoming concerned about the technology.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="How the detection app works"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How the detection app works&lt;/h2&gt;
 &lt;div&gt; 
  &lt;p&gt;Nearby Glasses is a new Android app for those concerned about the privacy and security issues posed by smart glasses. The app continuously scans for a specific type of Bluetooth Low Energy data signature, known as "advertising frames," that is commonly associated with devices from manufacturers such as Meta, Snap and Luxottica (Ray-Ban's parent company and a partner in Meta's smart glasses collaboration).&lt;/p&gt; 
  &lt;p&gt;Once advertising frames are within approximately 10-15 meters, the app detects them and pings the user with a push notification letting them know that smart glasses are nearby. While the app does need to hedge against occasional false positives – Malwarebytes says Meta Quest VR sets are one example – it can still provide users with a sense of security and protection against unwanted recording in both private and professional contexts.&lt;/p&gt; 
  &lt;p&gt;While implementing the app at scale may be difficult, it provides at least one minor countermeasure against smart glasses that can be employed in high-stakes environments such as financial institutions, government buildings or hospitals.&lt;/p&gt; 
 &lt;/div&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="The enterprise attack surface is expanding"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The enterprise attack surface is expanding&lt;/h2&gt;
 &lt;p&gt;The prevalence of smart glasses has suddenly increased the cyber and physical risk profiles of your business. Now that people are wearing what appears to be a common accessory that can surreptitiously record photos and videos, which can then be analyzed and transmitted elsewhere, enterprises become dramatically more vulnerable in numerous ways across sectors.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Data security risks:&lt;/b&gt;&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Data can be continuously and ambiently collected, even if the wearer isn't deliberately recording a photo or video. If the smart glasses are on, data collection can be transmitted to third-party cloud servers.&lt;/li&gt; 
  &lt;li&gt;Given the limited user interfaces of smart glasses, authentication can be difficult. While certain features may be locked behind authentication measures, there's nothing stopping the wrong person from wearing them in the wrong places.&lt;/li&gt; 
  &lt;li&gt;There's nothing that limits what the glasses see, because they capture everything in their field of view. Even if the glasses are being used deliberately as part of a business process, there's essentially no data minimization; everything the user is looking at is captured whether they mean to or not.&lt;/li&gt; 
  &lt;li&gt;An increase in data security risks increases the odds that a company will suffer a data breach. With data breaches come a slew of notification obligations under CCPA, GDPR, HIPAA and state laws.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&amp;nbsp;&lt;b&gt;Operational risks:&lt;/b&gt;&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;The key operational risk with smart glasses is that a company's proprietary information could be compromised if anyone wearing them discusses trade secrets or views sensitive materials.&lt;/li&gt; 
  &lt;li&gt;It's not just company data at risk; personal data is as well. People's biometric data, such as their faces or voices, can be easily captured by smart glasses without their consent.&lt;/li&gt; 
  &lt;li&gt;All the above can be hard to spot, given that smart glasses are explicitly designed to blend in. While there are security/notification features, such as LED lights that let nearby people know the glasses are recording, users can "root" devices to bypass these measures.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchsecurity/tip/What-agentic-AI-means-for-cybersecurity"&gt;AI agents embedded&lt;/a&gt; in smart glasses are equipped with superuser permissions, designed to enhance efficiency, streamline operations and ensure integration. This allows them unrestricted access to the data captured by the glasses, including the ability to transmit it for training other AI models.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&amp;nbsp;&lt;b&gt;Compliance risks:&lt;/b&gt;&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;The use of smart glasses can either directly (if there are explicit policies against them) or indirectly (if there are more general policies about consent to recording) violate privacy laws and requirements. It's important to be aware of the privacy laws in the states where an enterprise operates, as they &lt;a href="https://www.mwl-law.com/wp-content/uploads/2018/02/RECORDING-CONVERSATIONS-CHART.pdf" target="_blank" rel="noopener"&gt;vary by state&lt;/a&gt;. There are important considerations, such as the definition of eavesdropping versus wiretapping, and whether the state requires one-party or all-party consent.&lt;/li&gt; 
  &lt;li&gt;Healthcare facilities need to be wary of HIPAA violations, for example, if someone's smart glasses capture data while looking at a patient's chart or medical history.&lt;/li&gt; 
  &lt;li&gt;Certain regulated industries, such as defense contractors or legal offices, are also at risk of violating the strict compliance laws. Wearing a tool that regularly broadcasts sensitive or proprietary information to third-party servers (or even just recording it) is a violation.&lt;/li&gt; 
  &lt;li&gt;Relatedly, many industries and individual companies are governed by policies that prohibit cross-border data transfers. If someone's smart glasses send sensitive data outside the company's servers, it could cause problems for the enterprise.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;b&gt;Reputational and social licensing risks:&lt;/b&gt;&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;CIOs need to be concerned about protecting the business's brand, and any public backlash over security/privacy risks that occur due to smart glasses can damage that reputation and affect company morale.&lt;/li&gt; 
  &lt;li&gt;While there are obvious indicators of pushback, such as customer or employee complaints, CIOs should also take note of any complaints on social media or negative media coverage about your company's use of smart glasses.&lt;/li&gt; 
  &lt;li&gt;Stay one step ahead by being transparent about how smart glasses are being used; maintain strong, highly visible privacy policies; collect feedback about their use; and, if it comes down to it, be willing to scale back (or even scale down) deployment if concerns escalate.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;          
&lt;section class="section main-article-chapter" data-menu-title="Real-world abuse cases"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Real-world abuse cases&lt;/h2&gt;
 &lt;div&gt; 
  &lt;p&gt;Security concerns with smart glasses don't solely stem from careless, or at least non-nefarious, behavior. They can be intentionally abused in the form of reconnaissance of high-value targets – such as banks, public infrastructure or airports – or even harassment and stalking.&lt;/p&gt; 
  &lt;p&gt;Abuse of smart glasses technology does not exist solely in the abstract. For instance, there have been reported cases of Border Patrol and Immigration and Customs Enforcement (ICE) agents wearing Meta smart glasses while patrolling in numerous states. Given ICE's use of a facial recognition app called Mobile Fortify, as well as a recent Border Patrol contract with Clearview AI (a facial recognition company), concerns abound that they may be using the glasses to record data and pass it into facial recognition software or government databases.&lt;/p&gt; 
  &lt;p&gt;Two former Harvard University students did just that to demonstrate the privacy and safety risks of smart glasses. AnhPhu Nguyen and Caine Ardayfio hacked a mobile app that processes data from Meta Ray-Bans in real time and provides users with private information about any individual they are looking at. The system, which they dubbed I-XRAY, uses the facial recognition search engine Pimeyes in conjunction with readily available services such as FastPeopleSearch for address lookups or Cloaked.com for Social Security information. Though I-XRAY was designed as an unreleased proof-of-concept, it showed how easily technology could be abused to violate people's privacy.&lt;/p&gt; 
  &lt;p&gt;In some cases, outside actors don't even need to be involved for smart glasses to produce problematic results. Swedish newspapers Svenska Dagbladet (SvD) and Goteborgs-Posten (GP) recently reported that Meta sometimes uses subcontracted workers to review image and video content captured by users of its Ray-Ban Meta smart glasses to improve the "experience."&lt;/p&gt; 
  &lt;p&gt;The content is sometimes sensitive. Meta claims that the data is filtered by blurring faces to protect users' privacy. However, workers from a Kenya-based Meta subcontractor said that these measures sometimes failed and faces could be seen.&lt;/p&gt; 
 &lt;/div&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="Action items for CIOs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Action items for CIOs&lt;/h2&gt;
 &lt;div&gt; 
  &lt;p&gt;To reduce enterprise risk with smart glasses, CIOs can take steps now and, in the future, to protect sensitive information and data.&lt;/p&gt; 
  &lt;p&gt;&lt;b&gt;Immediate (0-30 Days)&lt;/b&gt;&lt;/p&gt; 
 &lt;/div&gt;
 &lt;div&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;b&gt;Perform an audit.&lt;/b&gt;&amp;nbsp;The first step is to determine the breadth of the issue. Identify where smart glasses are already in use, and by whom. This includes employees, contractors, visitors or partners.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Governance.&lt;/b&gt;&amp;nbsp;Set up guardrails. Determine if smart glasses on-premises are allowed on-premises. Establish clearly defined guidelines for when, where and how they can be used.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Designate no-recording zones.&lt;/b&gt;&amp;nbsp;As part of acceptable use policies, include guidance on protecting high-value spaces such as boardrooms, R&amp;amp;D areas, data centers and customer-facing areas.&lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt;
 &lt;div&gt; 
  &lt;p&gt;&amp;nbsp;&lt;b&gt;Short-term (30-90 Days)&lt;/b&gt;&lt;/p&gt; 
 &lt;/div&gt;
 &lt;div&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;b&gt;Implement detection capabilities. &lt;/b&gt;Whether it's educating security personnel to spot devices (and whether they're recording) or using scanning tools, detection measures – especially in sensitive areas – are key.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Require consent protocols.&lt;/b&gt;&amp;nbsp;Requiring visual indicators for when smart glasses are recording is an important part of a smart glasses policy. It allows individuals to consent to be recorded or to enable the recording of their surroundings, while giving security a way to protect controlled spaces.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Educate leadership and staff.&lt;/b&gt;&amp;nbsp;Once you've established these policies and security measures, train your teams about them. Also include the risks your enterprise could face if these policies are not followed.&lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt;
 &lt;div&gt; 
  &lt;p&gt;&lt;b&gt;Long-term (90+ Days)&lt;/b&gt;&lt;/p&gt; 
 &lt;/div&gt;
 &lt;div&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;b&gt;Align cross-functional ownership. &lt;/b&gt;Make sure everyone is on the same page. Coordination among cybersecurity, physical security, legal, HR and compliance teams helps ensure that everyone consistently enforces these policies.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Update vendor management policies. &lt;/b&gt;These rules don't just apply to your own employees. Vendors and contractors should be held to the same standard; ensure your third-party risk assessments now include a smart glasses policy.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Monitor regulatory developments.&lt;/b&gt;&amp;nbsp;Keep your finger on the pulse for any new privacy legislation or guidance specific to your industry. This will help ensure your business remains compliant.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Evaluate enterprise use cases carefully.&lt;/b&gt;&amp;nbsp;The presence of smart glasses in the workplace is not always incidental; in some cases, it's by design. If your business chooses to deploy smart glasses, ensure it's for legitimate reasons, such as hands-free workflows and remote assistance. Establish data governance, encryption and access controls for using them.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Research vendors. &lt;/b&gt;With more options for smart glasses models becoming available, it's important to consider all options. Technical considerations include whether the model includes hardware-based recording indicators that cannot be disabled using software changes, geofencing capabilities to ensure recording occurs only in certain areas, consent logging and audit trails, and remote wiping capabilities. Ensure vendors have clear policies regarding privacy and data handling, and that they regularly issue security updates and patches. 
    &lt;div&gt; 
     &lt;ul class="default-list"&gt;&lt;/ul&gt; 
    &lt;/div&gt; &lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt;
 &lt;p&gt;&lt;i&gt;Grant Hatchimonji is a freelance writer and solutions architect, where he does software engineering and consulting.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Once experimental tech, smart glasses now pose serious risks to businesses through covert recording, data leaks and compliance violations in the workplace.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/code_g1127196618.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/Smart-glasses-as-an-enterprise-risk-What-CIOs-should-know</link>
            <pubDate>Wed, 12 Aug 2026 15:08:00 GMT</pubDate>
            <title>Smart glasses as an enterprise risk: What CIOs should know</title>
        </item>
        <item>
            <body>&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h2&gt;Executive summary&lt;/h2&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;b&gt;IT spending surges 14.2% in 2026&lt;/b&gt;. The increase in costs is driven by AI infrastructure buildout across data centers and cloud services, creating both opportunities and cost pressures for CIOs.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Budget allocation requires new approaches&lt;/b&gt;. Map spending to business outcomes rather than technology categories, and consider quarterly reviews to adapt to rapid changes in AI pricing.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Cost control is critical&lt;/b&gt;. Eliminate redundant tools, renegotiate vendor contracts and collaborate closely with business leaders to align AI investments with measurable results.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;Worldwide IT spending is set to hit $6.37 trillion this year, according to a new forecast from Gartner. That spending -- up 14.2% from 2025 -- is being driven by &lt;a href="https://www.techtarget.com/searchcio/feature/What-Big-Techs-AI-spending-means-for-your-IT-budget"&gt;increased demand for AI infrastructure&lt;/a&gt; and growing AI workloads. Gartner &lt;a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-27-gartner-forecasts-worldwide-it-spending-to-grow-14-point-2-percent-in-2026-totaling-6-point-37-trillion" target="_blank" rel="noopener"&gt;finds that&lt;/a&gt; spending is up across six categories: data center systems, devices, software, services, IaaS and communication services.&lt;/p&gt; 
&lt;p&gt;CIOs are at the forefront of &lt;a href="https://www.techtarget.com/searchcio/feature/Predictable-IT-spending-in-an-unpredictable-economy"&gt;technology spending conversations&lt;/a&gt;, but budgeting isn't as simple as throwing more money into the IT bucket. Enterprises are also grappling with budgetary pressures, the uncertainty around AI pricing and shifting priorities.&lt;/p&gt; 
&lt;p&gt;The Gartner forecast can offer CIOs insight into the current IT spending landscape as they consider budget allocation for their own enterprises and build the foundation for a competitive future.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Understanding the 2026 IT spending landscape"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Understanding the 2026 IT spending landscape&lt;/h2&gt;
 &lt;p&gt;The Gartner forecast draws on market share data from more than 1,000 vendors, economic data and data from technology buyers, John-David Lovelock, a distinguished vice president analyst and chief forecaster at Gartner, told TechTarget.&lt;/p&gt;
 &lt;p&gt;"We balance all three of these very different effects on spending to get to an overall global IT spending forecast. It ends up being about 742,000 individual data points that come together to make that top-level number," he said.&lt;/p&gt;
 &lt;p&gt;In July 2025, Gartner forecast &lt;a href="https://www.gartner.com/en/newsroom/press-releases/2025-07-15-gartner-forecasts-worldwide-it-spending-to-grow-7-point-9-percent-in-2025" target="_blank" rel="noopener"&gt;$5.43 trillion in worldwide IT spending&lt;/a&gt; for the year. Macroeconomic uncertainty dampened net-new spending, according to the forecast. Uncertainty remains a theme this year -- particularly around &lt;a href="https://www.techtarget.com/searchcio/feature/How-CIOs-can-avoid-the-AI-surprise-bill"&gt;AI pricing&lt;/a&gt; -- but spending is surging as hyperscalers and enterprises build massive amounts of AI infrastructure.&lt;/p&gt;
 &lt;p&gt;"AI is becoming part of the foundation as opposed to just another technology project within organizations," Moe Asgharnia, CIO of tax, advisory and accounting firm BPM, said.&lt;/p&gt;
 &lt;p&gt;Just because IT spending is rising does not mean CIOs have carte blanche. They are still facing budgeting pressure from multiple angles. Gartner's 2026 forecast calls out inflation, supply shortages and the rising hardware and memory costs. CIOs must figure out how to allocate funds with those pressures in mind.&lt;/p&gt;
 &lt;p&gt;"There is certainly a higher amount of spend for enabling the AI-related capability. But on the other side, there is an equally strong push to say, 'Hey, what that needs to translate into is a reduction in staff or a reduction in other software spend," Krishna Prasad, CIO and chief strategy officer of UST, a digital transformation company, said.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    The next few years are going to be the most intense for cost control and efficiency optimization the CIO has ever faced.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;John-David Lovelock, distinguished vice president analyst and chief forecaster at Gartner&lt;/strong&gt;
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="Spending growth by segment"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Spending growth by segment&lt;/h2&gt;
 &lt;p&gt;The Gartner forecast breaks down worldwide IT spending into six categories and highlights the 2026 spending growth in each.&lt;/p&gt;
 &lt;h3&gt;Data centers (62.5% growth) and IaaS (29.3% growth)&lt;/h3&gt;
 &lt;p&gt;Data centers and IaaS are by far the largest spending growth categories.&lt;/p&gt;
 &lt;p&gt;"We are in a situation right now where the AI infrastructure buildout is the largest infrastructure project ever attempted by humanity. This is going to be bigger than the U.S. highway system, the European rail, the Great Wall of China and the International Space Center combined," Lovelock said. "That's the amount of money that is going into building out the data centers, the power, the cooling, the responsible use of it required for the AI that we will see come in the next two years."&lt;/p&gt;
 &lt;p&gt;CIOs considering this part of their IT budgets must answer the &lt;a href="https://www.techtarget.com/searchcio/feature/Build-vs-buy-AI-A-CIOs-decision-matrix"&gt;build-versus-buy question&lt;/a&gt;. And there isn't necessarily a right answer.&lt;/p&gt;
 &lt;p&gt;CIOs may guide their organizations down the build path to maintain more control over their AI costs.&lt;/p&gt;
 &lt;p&gt;"CIOs will start to lose control over the number of tokens that they use as the use of AI goes across the corporation [and] the cost of licensing the models that they're getting through their partners," Lovelock said. "And, of course, the overall cost of tokens used times token price plus licensing equals their spend."&lt;/p&gt;
 &lt;p&gt;Other companies will opt to work with partners to handle their AI workloads because they do not want to take on all the work involved in building.&lt;/p&gt;
 &lt;p&gt;"Are we in the line of business of maintaining data centers, or are we in the line of business of doing a specific product or service for our clients or customers?" Justice Erolin, CTO of software development company BairesDev, asked. "I think everybody wants to be a tech company, but I don't think everybody should."&lt;/p&gt;
 &lt;p&gt;Both paths and the hybrid approach come with different cost considerations and strategic decisions.&lt;/p&gt;
 &lt;h3&gt;Software (15.5% growth)&lt;/h3&gt;
 &lt;p&gt;Organizations are spending more on AI-ready software, according to the Gartner forecast. Software spending isn't just about finding new AI-ready software; it is also being driven by existing vendors incorporating AI capabilities into their products.&lt;/p&gt;
 &lt;p&gt;"Software spend, on average, every time any contract comes up, seems to go up by 10%, 15%. And that type of increase is unsustainable," Prasad said.&lt;/p&gt;
 &lt;p&gt;This could drive CIOs to reevaluate their tools and vendor relationships.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;"We're going through, finding duplicate platforms, finding redundant functions or services that we're paying for, [remove] that redundancy and then [reinvest] those dollars in more meaningful business value that in many cases layers AI on top of our business process," Asgharnia shared.&lt;/p&gt;
 &lt;p&gt;Enterprises may also look for opportunities to build their own software solutions internally.&lt;/p&gt;
 &lt;h3&gt;Devices (9.8% growth)&lt;/h3&gt;
 &lt;p&gt;Device spending is rising in part due to the demand for AI workloads.&lt;/p&gt;
 &lt;p&gt;"As individual productivity increases, the tier of device is also getting more complicated or more complex," Erolin said. "I have folks who generally wouldn't even need more than a ThinkPad. And now they're looking for the latest, greatest chip because they're running multiple AI loads even in their own local system."&lt;/p&gt;
 &lt;p&gt;Additionally, the war in Iran is impacting supply chains and hardware costs, Asgharnia noted.&lt;/p&gt;
 &lt;p&gt;"We've been looking at our budget for next year and even considering increasing the end-of-life term for our laptops from three years to four years just to give us some runway until hopefully the prices stabilize a little bit," Asgharnia shared.&lt;/p&gt;
 &lt;h3&gt;IT services (5.3% growth)&lt;/h3&gt;
 &lt;p&gt;IT services remain an important piece of the overall budget. Enterprises need vendors to support software and infrastructure implementation.&lt;/p&gt;
 &lt;p&gt;While Gartner forecasts increased spending in this category, there may also be a shift in enterprise expectations.&lt;/p&gt;
 &lt;p&gt;"Customers are expecting that the contracts themselves are shifted in a way that: I'm going to pay you is much less for the build phase, and I'm going to pay you much more centered on the outcomes that you deliver," Prasad said.&lt;/p&gt;
 &lt;h3&gt;Communication services (4.4% growth)&lt;/h3&gt;
 &lt;p&gt;Communication services have the smallest price increase of the categories covered in Gartner's forecast. But this category remains a foundational investment for enterprises.&lt;/p&gt;
 &lt;p&gt;CIOs can evaluate their enterprises' bandwidth requirements and look for opportunities to consolidate. Communication services have become much more commoditized, according to Prasad.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;"You should be able to get more capacity without having to spend proportionately more," he said.&lt;/p&gt;
&lt;/section&gt;                              
&lt;section class="section main-article-chapter" data-menu-title="The CIO budget framework"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The CIO budget framework&lt;/h2&gt;
 &lt;p&gt;The Gartner forecast offers useful insights into IT spending trends, but CIOs must approach budget allocation with their organizations' individual goals and needs in mind. Budget frameworks are specific to each enterprise, but CIOs will be working through shared challenges and opportunities in IT spending.&lt;/p&gt;
 &lt;h3&gt;Cost control&lt;/h3&gt;
 &lt;p&gt;IT spending is rising, and more spending means greater scrutiny. Costs related to AI are, for the time being, variable and unpredictable. CIOs will be tasked with managing and optimizing those costs as the technology is implemented.&lt;/p&gt;
 &lt;p&gt;"The next few years are going to be the most intense for cost control and efficiency optimization the CIO has ever faced," Lovelock said.&lt;/p&gt;
 &lt;p&gt;That might mean CIOs will want to build more flexibility into the IT budgets and have more frequent conversations about their enterprise's spending and priorities.&lt;/p&gt;
 &lt;p&gt;"I would probably consider going from an annual budget to a quarterly budget," Erolin said. "It might make more sense because things are shifting so quickly that I don't know if anybody can forecast the next year."&lt;/p&gt;
 &lt;h3&gt;Business outcomes&lt;/h3&gt;
 &lt;p&gt;As AI becomes part of the enterprise foundation, its &lt;a href="https://www.techtarget.com/searchcio/feature/When-AI-spending-becomes-a-liability"&gt;accompanying IT spending&lt;/a&gt; can no longer be in a single, ill-defined bucket.&lt;/p&gt;
 &lt;p&gt;"We shouldn't be budgeting for AI. We should be budgeting for business outcomes," Asgharnia said.&lt;/p&gt;
 &lt;p&gt;CIOs need close alignment with other business leaders to understand target business outcomes and how to allocate spending to support them.&lt;/p&gt;
 &lt;p&gt;"We start talking through what those opportunities or what those priorities translate to…whether that's infrastructure, whether that's applications, whether that's security tools, anything that we need to have in place to make sure that we're not a roadblock to the success of those priorities," Asgharnia said.&lt;/p&gt;
 &lt;h3&gt;Leadership collaboration&lt;/h3&gt;
 &lt;p&gt;Mapping budgets to business outcomes requires close collaboration among enterprise leaders. CIOs are often looked to as the leaders who understand AI and have all the answers. But in reality, no one has all the answers.&lt;/p&gt;
 &lt;p&gt;"The communication has to embrace the uncertainty around costs and outcomes and timelines," Lovelock said. "There's no company that can say: I've done this 100 times. I know how long it takes and how much it costs and what you'll get for it."&lt;/p&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchcio/feature/AI-surge-fuels-dramatic-transformation-of-CIO-role"&gt;CIOs have a role to play&lt;/a&gt; in shaping strategic IT spending and setting their enterprises up for long-term success, which can mean taking a new approach to the AI-driven reality.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;"We tend to set our budget based on what we're already spending and just figuring out what that spend is going to look like," Asgharnia said. "I would say, question every single one of those line items."&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Carrie Pallardy is a freelance journalist with experience writing in cybersecurity, technology and healthcare. She currently covers a wide range of issues relevant to today's CIOs and IT leaders.&amp;nbsp;&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>AI infrastructure investments are forcing CIOs to rethink budget strategies as enterprises face rising costs, pricing uncertainty, and shifting priorities.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/money_g177553082.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/Gartner-predicts-increase-in-IT-spending-How-to-prepare</link>
            <pubDate>Wed, 12 Aug 2026 15:08:00 GMT</pubDate>
            <title>Gartner predicts 14.2% increase in IT spending: How to prepare</title>
        </item>
        <item>
            <body>&lt;p&gt;Many organizations have established sustainability goals, published environmental, social and governance, or ESG, commitments and begun collecting data for sustainability reporting. Fewer have created the governance infrastructure needed to turn those commitments into consistent business decisions and measurable results.&lt;/p&gt; 
&lt;p&gt;Without clear authority, defined responsibilities, reliable data and effective controls, sustainability programs can become disconnected from daily operations. For example, committees may discuss goals without approving resources, departments may calculate metrics differently, or sustainability teams may &lt;a href="https://www.techtarget.com/it-strategy/feature/The-importance-of-sustainability-and-finance-alignment"&gt;produce reports without access to the financial&lt;/a&gt; and operational systems that support the underlying data.&lt;/p&gt; 
&lt;p&gt;A sustainability governance framework addresses those gaps and connects strategic oversight with operational execution. For technology-driven organizations, that connection must include IT.&lt;/p&gt; 
&lt;p&gt;Sustainability data often comes from the following places:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;ERP software.&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://www.techtarget.com/it-strategy/feature/Sustainable-procurement-strategies-and-policies-for-CIOs"&gt;Procurement platforms&lt;/a&gt;.&lt;/li&gt; 
 &lt;li&gt;Cloud environments.&lt;/li&gt; 
 &lt;li&gt;HR systems.&lt;/li&gt; 
 &lt;li&gt;Utility records.&lt;/li&gt; 
 &lt;li&gt;Supplier assessments.&lt;/li&gt; 
 &lt;li&gt;Facilities management systems.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Therefore, CIOs and IT leaders must decide whether sustainability information is still accurate, consistent and auditable.&lt;/p&gt; 
&lt;p&gt;A strong framework also helps organizations move beyond treating corporate sustainability governance as a compliance exercise. When leaders integrate sustainability into business planning, risk management, &lt;a href="https://www.techtarget.com/it-strategy/feature/6-sustainability-tech-stack-components-for-greener-enterprises"&gt;technology investments&lt;/a&gt; and performance measurement, governance can support efficiency, resilience and long-term value.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is a sustainability governance framework?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is a sustainability governance framework?&lt;/h2&gt;
 &lt;p&gt;A sustainability governance framework defines how an organization sets sustainability priorities, makes decisions, assigns responsibility, manages data, monitors performance and reports results.&lt;/p&gt;
 &lt;p&gt;The framework creates a formal connection among five core components:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Leadership and oversight.&lt;/b&gt; The board and senior executives establish direction, approve priorities and evaluate performance.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Operational structure.&lt;/b&gt; Cross-functional teams translate &lt;a href="https://www.techtarget.com/it-strategy/feature/Why-companies-should-be-sustainable-and-how-IT-can-help"&gt;strategy into initiatives across IT&lt;/a&gt;, finance, procurement, HR, legal, facilities and other business functions.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Processes and controls.&lt;/b&gt; Documented procedures govern data collection, calculations, approvals, corrective actions and sustainability reporting.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Technology infrastructure.&lt;/b&gt; Systems collect, integrate, validate, retain and report sustainability information.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Accountability mechanisms.&lt;/b&gt; Named owners stay responsible for targets, budgets, data quality, disclosures and results.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Organizations must treat sustainability as part of business strategy rather than as a separate initiative, said Bridgette Bell McAdoo, global sustainability officer at Genesys.&lt;/p&gt;
 &lt;p&gt;"Governance works best when it's connected to how an organization makes decisions, manages risk and measures performance," McAdoo said.&lt;/p&gt;
 &lt;p&gt;Genesys's sustainability strategy uses three interconnected pillars: people, planet and performance. That structure helps the company integrate sustainability into business planning instead of treating it as a standalone program, McAdoo said.&lt;/p&gt;
 &lt;p&gt;A well-designed ESG governance structure &lt;a href="https://www.techtarget.com/it-strategy/feature/ESG-benefits-for-businesses"&gt;offers several benefits&lt;/a&gt;:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;It increases transparency and establishes how leaders make decisions and calculate reported results.&lt;/li&gt; 
  &lt;li&gt;It strengthens accountability, assigns ownership and improves integration among sustainability, technology, finance and operating teams.&lt;/li&gt; 
  &lt;li&gt;It standardizes processes, which can reduce duplicated work and improve efficiency.&lt;/li&gt; 
  &lt;li&gt;It supports risk management. Reliable data and review processes help leaders identify operational, regulatory, supply chain, reputational and technology risks before they become reporting problems or business disruptions.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;In particular, &lt;a href="https://www.techtarget.com/it-strategy/feature/6-sustainability-reporting-data-tips-for-IT"&gt;sustainability reporting&lt;/a&gt; requires controls comparable to those used for other important corporate information.&lt;/p&gt;
 &lt;p&gt;"The most common mistake is treating sustainability reporting as a communications function rather than a controls function," said Seyfi Gasilov, partner for sustainability reporting and governance at Gasilov Group. "You genuinely do need underlying controls from finance and IT in order to prevent duplicated data or manual spreadsheets that would fail on an audit."&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="The four-layer governance model"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The four-layer governance model&lt;/h2&gt;
 &lt;p&gt;Organizations can structure a sustainability governance framework around four connected layers.&lt;/p&gt;
 &lt;h3&gt;1. Board-level oversight&lt;/h3&gt;
 &lt;p&gt;The board offers strategic direction, monitors performance and holds executive leadership accountable. Depending on the organization's size and risk exposure, the board may assign sustainability oversight to an existing committee or create a dedicated sustainability committee.&lt;/p&gt;
 &lt;p&gt;Board oversight should involve more than receiving an annual report. Directors should understand the organization's material &lt;a href="https://www.techtarget.com/it-strategy/tip/ESG-risks-explained-Examples-and-tips-on-managing-them"&gt;sustainability risks&lt;/a&gt;, review significant goals, monitor progress and determine whether management has assigned sufficient authority and resources.&lt;/p&gt;
 &lt;p&gt;"The board oversees, and each member of the executive team treats sustainability like any other metric they track to measure success," said Adam Freedgood, principal and co-founder of sustainability consultancy Third Partners.&lt;/p&gt;
 &lt;h3&gt;2. Executive management&lt;/h3&gt;
 &lt;p&gt;Executive leaders translate board direction into priorities, budgets, policies and operational plans. Some organizations appoint a chief sustainability officer or establish a sustainability management committee to coordinate that work.&lt;/p&gt;
 &lt;p&gt;A chief sustainability officer should not, however, become the sole owner of enterprise sustainability performance. Sustainability teams serve more as internal consultants who guide and coordinate the work, while &lt;a href="https://www.techtarget.com/it-strategy/feature/How-to-get-executive-buy-in-for-sustainability"&gt;executives retain responsibility for execution&lt;/a&gt;, according to Freedgood.&lt;/p&gt;
 &lt;p&gt;"Outsourcing to a chief sustainability officer only passes the buck," Freedgood said. "The executive committee is in charge of execution. IT owns the infrastructure. Everyone takes responsibility for their part."&lt;/p&gt;
 &lt;p&gt;Executives should assign decision rights and specify who approves targets, funding, methodologies, disclosures and corrective actions. Compensation can also reinforce accountability. Freedgood recommended tying sustainability performance metrics to the compensation of leaders with the authority to implement initiatives.&lt;/p&gt;
 &lt;h3&gt;3. Operational teams&lt;/h3&gt;
 &lt;p&gt;Operational teams execute sustainability initiatives and incorporate requirements into everyday decisions. Depending on the organization, these teams may include procurement, finance, HR, legal, facilities, product development, risk, compliance and business unit leaders.&lt;/p&gt;
 &lt;p&gt;Sustainability works best as a &lt;a href="https://www.techtarget.com/it-strategy/feature/The-clear-business-case-for-environmental-sustainability"&gt;shared business responsibility&lt;/a&gt;, McAdoo said. Sustainability specialists can establish priorities and track progress, while operational functions apply those priorities to purchasing, hiring, investments, product development and other activities.&lt;/p&gt;
 &lt;p&gt;Organizations need cross-functional forums where these groups can resolve conflicts, review progress and respond to problems. The governance structure should also include escalation procedures, so teams know when an issue requires executive or board attention.&lt;/p&gt;
 &lt;h3&gt;4. Technology, data and controls&lt;/h3&gt;
 &lt;p&gt;The fourth layer supports the other three and offers dependable data, systems and internal controls. IT teams must identify systems of record, integrate data sources, implement access controls, document validation rules and preserve audit trails. They should also work with finance and sustainability specialists to establish consistent definitions and calculation methodologies.&lt;/p&gt;
 &lt;p&gt;"The CIO and IT leaders should ultimately treat emissions data, supply chain data and safety data with the same importance they treat revenue data," Freedgood said.&lt;/p&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/it-strategy/feature/How-CIOs-and-IT-can-drive-environmental-sustainability"&gt;CIO involvement becomes essential&lt;/a&gt; because ESG data spans ERP, procurement, facilities and HR platforms, Gasilov said.&lt;/p&gt;
 &lt;p&gt;"Without IT governance over data collection points and validation rules, the infrastructure that sustainability teams tend to build breaks when asked for an audit trail leading back to the finance and IT departments," he said.&lt;/p&gt;
 &lt;p&gt;CIOs also influence the sustainability of the technology environment itself. Cloud architecture, data storage, automation and AI systems affect energy use, operational efficiency, risk and reporting capabilities.&lt;/p&gt;
 &lt;p&gt;"Like financial reporting, high-quality sustainability reporting depends on reliable data, strong governance and consistent controls," McAdoo said. "CIOs help build that foundation by integrating sustainability data across business systems, strengthening data quality and ensuring organizations can respond efficiently to evolving disclosure requirements."&lt;/p&gt;
&lt;/section&gt;                      
&lt;section class="section main-article-chapter" data-menu-title="Common pitfalls to avoid"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Common pitfalls to avoid&lt;/h2&gt;
 &lt;p&gt;A governance structure does not create accountability unless leaders give it authority. Organizations must avoid creating committees that can discuss performance but cannot approve funding, assign corrective actions or hold business leaders responsible.&lt;/p&gt;
 &lt;p&gt;Meanwhile, leaders must document each group's mandate, decision rights, reporting responsibilities and escalation path. They should also assign a named owner to every material metric and disclosure.&lt;/p&gt;
 &lt;p&gt;Organizations often create another problem when multiple departments &lt;a href="https://www.techtarget.com/data-technologies/tip/ESG-data-collection-Guide-and-best-practices"&gt;collect overlapping ESG data&lt;/a&gt; using different definitions or methodologies. A central data dictionary, designated systems of record, calculation standards and formal approval controls can reduce inconsistencies.&lt;/p&gt;
 &lt;p&gt;IT leaders must be involved at the inception of governance design rather than after sustainability teams have selected metrics or built spreadsheet-based reporting processes. Early IT involvement helps organizations assess system limitations, integration requirements, security, data lineage and auditability.&lt;/p&gt;
 &lt;p&gt;Although evolving regulations continue to shape sustainability reporting, organizations should not build governance solely around minimum compliance requirements.&lt;/p&gt;
 &lt;p&gt;For example, &lt;a target="_blank" href="https://eur-lex.europa.eu/eli/dir/2026/470/oj/eng" rel="noopener"&gt;Directive (EU) 2026/470&lt;/a&gt; removed the planned EU requirement to progress from limited to reasonable assurance for sustainability information. However, limited assurance still requires organizations to support reported information with verifiable evidence and clear data trails.&lt;/p&gt;
 &lt;p&gt;Governance can create more value when leaders incorporate sustainability information into financial planning, procurement, enterprise risk management and technology decisions.&lt;/p&gt;
 &lt;p&gt;"Sustainability should be treated as a savings metric and discussed in financial planning meetings," Freedgood said. "Yes, you are meeting compliance requirements, but you are also building a future that maximizes savings."&lt;/p&gt;
 &lt;p&gt;Organizations should also avoid isolating sustainability specialists from core business functions. Isolated governance often produces disconnected data, duplicated reporting and priorities that never influence operational decisions, McAdoo said.&lt;/p&gt;
 &lt;p&gt;Finally, leaders should not assume employees will adopt a new governance model just because the organization publishes it. Teams may resist new responsibilities, lack necessary skills or prioritize established performance goals over sustainability requirements.&lt;/p&gt;
 &lt;p&gt;Organizations can &lt;a href="https://www.techtarget.com/searchhrsoftware/feature/How-to-increase-employee-engagement-on-sustainability"&gt;address those barriers&lt;/a&gt; through executive sponsorship, training, clearly defined responsibilities, realistic implementation timelines and performance incentives. Leaders should also establish procedures to identify problems, assign corrective actions and confirm that teams implemented the required changes.&lt;/p&gt;
 &lt;p&gt;"Effective governance requires clear ownership, timely corrective actions and mechanisms to verify that improvements are implemented and sustained," McAdoo said.&lt;/p&gt;
 &lt;p&gt;Ultimately, an effective sustainability governance framework connects board oversight, executive authority, operational execution and technology controls. That structure helps organizations produce more credible sustainability reporting, manage risk, improve efficiency and incorporate sustainability into the decisions that shape long-term business performance.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Christine Campbell is a freelance writer specializing in business and B2B technology.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>A sustainability governance framework integrates leadership, business processes and technology to align sustainability with the core business strategy.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/sustainability_g1389191903.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/How-to-structure-a-sustainability-governance-framework</link>
            <pubDate>Wed, 12 Aug 2026 15:04:00 GMT</pubDate>
            <title>How to structure a sustainability governance framework</title>
        </item>
        <item>
            <body>&lt;div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{9}" paraid="865466451"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Party invitations are the hottest email phishing scam this summer.&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{15}" paraid="335698576"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Phishing is old news. But this newest iteration can bamboozle even those of us who work in tech and are &lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchsecurity/feature/How-to-avoid-phishing-hooks-A-checklist-for-your-end-users"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;&lt;span data-ccp-charstyle="Hyperlink"&gt;trained to look&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt; for "phishy" things.&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{37}" paraid="1737178486"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;These "invitations" appear to come from reputable platforms such as Evite, Paperless Post and Punchbowl. And they are from people you know, with legitimate email addresses. It appears everything checks out -- and then you unwittingly give out a password or some other personal information.&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{57}" paraid="432975101"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;CIOs, I am your cautionary tale. I'm not a security expert. I represent your average employee -- educated, cautious, yet still vulnerable.&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{81}" paraid="195254766"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;I fell victim to this scam.&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{91}" paraid="960179178"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;A Punchbowl "invitation" arrived in my personal email account, inviting me to a summer soiree hosted by a member of an organization that hosts such get-togethers, so I thought nothing of it. I clicked on it, and nothing good followed.&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{119}" paraid="580393322"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;A few weeks later, there was an unauthorized sign-in to my email account. My contacts started receiving similar "invitations" that appeared to come from me. My heart nearly stopped. I never thought I'd fall for a phishing scam, until I did. It was the summer gift that just kept on giving!&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{145}" paraid="382033924"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;I spent the better part of a week changing login information on various accounts, created a new email address and enabled two-factor authentication on my email accounts. And of course, I had to tell everyone I knew not to open any Punchbowl invitations that appeared to come from me. Thankfully, my email was the only account breached. It could have been worse. But I felt horrible knowing that many of my contacts did click on that suspicious email and were now targets themselves.&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{177}" paraid="278519912"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;We are all one click away from disaster.&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{183}" paraid="1519163902"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Personal email addresses are not the only accounts being targeted. These phishing emails are also going to corporate addresses. According to IBM's &lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Cost of a Data Breach &lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost%20of%20a%20Data%20Breach%20Report%202026.pdf"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;&lt;span data-ccp-charstyle="Hyperlink"&gt;Report&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt; 2026&lt;/span&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;, phishing was the top attack vector into breached organizations for the fourth year in a row. The average cost of a breach now comes in at $5.29 million.&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{227}" paraid="125549650"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;How many of your employees have been phished and never reported it?&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{d9e2280e-2f7f-40d4-ac21-99ff01774c00}{235}" paraid="361842025"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;If threat actors get their hands on corporate login information, trade secrets or other sensitive and confidential information could be leaked. But beyond that, compromised corporate email can be used to target vendors, partners and customers. It can cause reputational damage, affecting customer trust and stock prices. Ransomware could follow and bring serious business disruption.&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{8}" paraid="781302073"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Beyond basic email spam filters, there are some things that businesses should do to keep employees -- and in turn, the business -- safe:&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;ul style="list-style-type: disc;" role="list" class="default-list"&gt; 
   &lt;li role="listitem" data-aria-level="1" data-aria-posinset="0" data-list-defn-props="{&amp;quot;335551671&amp;quot;:0,&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-listid="6" data-font="Symbol" data-leveltext="" aria-setsize="-1"&gt; &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{34}" paraid="188649266"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchsecurity/definition/zero-trust-model-zero-trust-network"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;&lt;span data-ccp-charstyle="Hyperlink"&gt;Z&lt;/span&gt;&lt;span data-ccp-charstyle="Hyperlink"&gt;ero trust ar&lt;/span&gt;&lt;span data-ccp-charstyle="Hyperlink"&gt;chitecture&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;, denies access to a business's digital resources by default and grants access only to authenticated users.&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;ul style="list-style-type: disc;" role="list" class="default-list"&gt; 
   &lt;li role="listitem" data-aria-level="1" data-aria-posinset="1" data-list-defn-props="{&amp;quot;335551671&amp;quot;:0,&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-listid="6" data-font="Symbol" data-leveltext="" aria-setsize="-1"&gt; &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{64}" paraid="642049506"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Enterprise password managers and passwordless authentication, which securely store credentials and verify identity without traditional passwords.&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;ul style="list-style-type: disc;" role="list" class="default-list"&gt; 
   &lt;li role="listitem" data-aria-level="1" data-aria-posinset="2" data-list-defn-props="{&amp;quot;335551671&amp;quot;:0,&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-listid="6" data-font="Symbol" data-leveltext="" aria-setsize="-1"&gt; &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{74}" paraid="2043265732"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;&lt;/span&gt;&lt;a rel="noreferrer noopener" target="_blank" href="https://www.techtarget.com/searchsecurity/definition/endpoint-detection-and-response-EDR"&gt;&lt;span xml:lang="EN-US" data-contrast="none"&gt;&lt;span data-ccp-charstyle="Hyperlink"&gt;E&lt;/span&gt;&lt;span data-ccp-charstyle="Hyperlink"&gt;ndpoint detection and response&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt; tools, which will identify and contain threats post-click.&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
  &lt;/ul&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{104}" paraid="323185646"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Yearly security compliance training should also be scheduled to ensure employees do their part in keeping businesses secure. Regular, realistic phishing simulation programs should also be scheduled, along with just-in-time training for employees who fail those tests.&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{134}" paraid="1867802756"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;C-suite executives can be especially high-value targets for threat actors, and even more specialized training should be considered for them. Are you confident your executives wouldn't fall for this?&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
 &lt;/div&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{146}" paraid="1242627695"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;You're probably thinking your employees just need to be more careful. But I am careful. I cover the risks of these types of attacks, and I still clicked. Vigilance isn't a strategy when scams are this good.&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{164}" paraid="1735267693"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Scams are becoming increasingly clever. But the human brain isn't wired to maintain constant suspicion. We need to treat phishing as a systems problem rather than a human problem. Until we do, stories like mine will keep happening.&amp;nbsp;&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{184}" paraid="1984363134"&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;The only question is, will your employees fall for it? Or have they already, and you just don't know it yet?&lt;/span&gt;&lt;span data-ccp-props="{}"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;p paraeid="{9200b634-4ec8-432d-8261-6d7c649ccb4a}{192}" paraid="46180567"&gt;&lt;em&gt;&lt;span xml:lang="EN-US" data-contrast="auto"&gt;Sarah Amsler is a senior managing editor for the IT Strategy team at TechTarget.&lt;/span&gt;&amp;nbsp;&lt;/em&gt;&lt;/p&gt; 
&lt;/div&gt;</body>
            <description>What cost me a week could cost your company millions. Here's why you need systems, not just vigilance, to protect against phishing.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a303249453.jpg</image>
            <link>https://www.techtarget.com/it-strategy/opinion/A-529M-risk-Are-you-ready-for-todays-phishing-attacks</link>
            <pubDate>Tue, 11 Aug 2026 21:20:00 GMT</pubDate>
            <title>A $5.29M risk: Are you ready for today's phishing attacks?</title>
        </item>
        <item>
            <body>&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;Executive summary&lt;/h3&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;b&gt;AI data ownership is a critical unresolved issue.&lt;/b&gt; Beyond token costs, organizations risk losing proprietary knowledge that becomes vendor training data with every prompt and correction.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Three data types require distinct governance. &lt;/b&gt;Input, training and output data each have separate ownership terms that vendors often obscure with vague contract language.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Public vs. enterprise AI tools carry different risks. &lt;/b&gt;Consumer tools may claim rights to user data, while enterprise contracts offer protections, though "no training" clauses don't prevent learning through usage patterns.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;CIOs must demand specific contractual protections. &lt;/b&gt;Essential terms include no training on customer data, short retention windows, data isolation, output ownership rights and audit capabilities.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;The true cost of AI could well be more than many enterprises initially suspect.&lt;/p&gt; 
&lt;p&gt;In July 2026, Microsoft CEO Satya Nadella issued a stark warning that companies using AI tools pay twice. The first time, organizations pay the token costs for AI usage. The second cost comes from the proprietary knowledge that improves the model with every prompt and correction.&lt;/p&gt; 
&lt;p&gt;The mechanism behind that warning is straightforward. Alex Bakker, a distinguished analyst at ISG, explained that every interaction with a &lt;a href="https://www.techtarget.com/whatis/feature/12-of-the-best-large-language-models"&gt;large language model&lt;/a&gt; doubles as a signal the vendor can use to fine-tune its systems going forward.&lt;/p&gt; 
&lt;p&gt;"User interaction is training data," Bakker said.&lt;/p&gt; 
&lt;p&gt;The concern about the training data cost goes a bit further. The U.S. government could reportedly get a potential stake in OpenAI if that company goes public. If the government has a stake in an AI, do they now, too, have access to the information that individuals and businesses input into these models?&lt;/p&gt; 
&lt;p&gt;Both stories point to the same unresolved issue at the center of enterprise AI adoption -- AI data ownership.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Data ownership in AI systems"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Data ownership in AI systems&lt;/h2&gt;
 &lt;p&gt;Data is not a uniform construct -- there are different types of data. And to make matters more confusing, vendor terminology on data varies as well. There are three primary types of data that are related to enterprise AI, including the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Input data.&lt;/b&gt; This includes the content that is put into a prompt, such as text, documents and corrections.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Training data.&lt;/b&gt; Before an organization ever touches a model, the vendor has already used data to train the model.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Output data.&lt;/b&gt; The generated content that a model provides as a response.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;Misunderstandings about AI data&lt;/h3&gt;
 &lt;p&gt;The default assumption is that if you typed it, you own it. Terms of service usually say otherwise. While there are three primary data types, there are numerous areas where organizations have misunderstandings about the data types and how they collect data.&lt;/p&gt;
 &lt;p&gt;Eric Johnson, CIO at PagerDuty, said one of the biggest misunderstandings he sees is that if a vendor says, "We don't train on your data," the buyer usually assumes that it covers all use cases.&lt;/p&gt;
 &lt;p&gt;"Input, training and output are three separate questions with three separate answers, and vendors don't always volunteer them all," Johnson said. "The confusion starts because the contract language is often vague on retention and reuse, so IT leaders assume the safest interpretation instead of confirming it."&lt;/p&gt;
 &lt;p&gt;Sebastian Arriada, CIO at Globant, argued that companies make the same mistake internally that vendors make in their contracts. They govern one of the three data categories, he said, and treat the job as done.&lt;/p&gt;
 &lt;p&gt;"Most governance conversations negotiate only the first one and declare victory," Arriada said. "Leaders treat this as a legal question when it's first an observability question. Most organizations can't answer who sent what to which model yesterday."&lt;/p&gt;
 &lt;p&gt;According to Keyur Ajmera, CIO at Boomi, there's actually another specific category in play.&lt;/p&gt;
 &lt;p&gt;"The lifecycle nobody has a good name for is the one that matters most now: retrieval context," Ajmera said. "Data that isn't in the prompt and isn't in the training set, but gets pulled in at runtime to ground the answer. That's where most enterprise data actually meets a model in 2026, and almost nobody governs it, because it doesn't fit either of the two categories people have words for."&lt;/p&gt;
 &lt;p&gt;Understanding the differences of the various kinds of data is critical to enterprise AI governance, according to Kristie Grinnell, CIO and executive vice president at TD Synnex.&lt;/p&gt;
 &lt;p&gt;"The confusion starts when we treat all AI-related data as if it's the same thing," Grinnell said. "The organizations that are getting this right are taking the time upfront to define categories such as customer data, prompts, outputs, logs, training data and derived data, then ensuring those definitions carry through into their contracts, controls and governance practices."&lt;/p&gt;
&lt;/section&gt;             
&lt;section class="section main-article-chapter" data-menu-title="Public vs. proprietary tools: Do different rules apply?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Public vs. proprietary tools: Do different rules apply?&lt;/h2&gt;
 &lt;p&gt;Public AI tools generally operate with broad consumer terms of service that apply to data input and usage. In contrast, proprietary tools are usually sold under negotiated enterprise contracts that will have specific terms and exclusions for data to help ensure privacy.&lt;/p&gt;
 &lt;p&gt;The risk isn't theoretical. Adnan Masood, chief AI architect at UST, pointed to a case from 2023, when Samsung engineers pasted proprietary source code into a consumer chatbot.&lt;/p&gt;
 &lt;p&gt;"The data left through the front door under terms nobody had read," he said.&lt;/p&gt;
 &lt;h3&gt;Is 'no training' the whole story?&lt;/h3&gt;
 &lt;p&gt;"The enterprise commitments are real, and I want to be clear about that because the cynical take gets repeated a lot," Masood said. "We have gone through the DPAs, the SOC 2 reports, and the audit provisions with clients in banking, healthcare and insurance, and the zero data retention terms are contractual obligations."&lt;/p&gt;
 &lt;p&gt;Arriada has had the same experience, noting that the contractual commitments on enterprise tiers are generally real. That said, he noted that doesn't mean providers don't still learn.&lt;/p&gt;
 &lt;p&gt;"Providers still gain from aggregate usage patterns, telemetry, and service improvement carve-outs, and retention for abuse monitoring means your data can sit on their infrastructure for days even under a no-training clause," Arriada said. "The more important question is what exactly happens to every byte you send, for how long and who can see it."&lt;/p&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="Open source vs. open weight models"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Open source vs. open weight models&lt;/h2&gt;
 &lt;p&gt;Another important distinction beyond just public and private models is understanding the impact of open source and open weight models. While some marketing folks might use the terms interchangeably, there is a difference between the two.&lt;/p&gt;
 &lt;p&gt;An open weight model refers to the training parameter -- the weights -- being made publicly available for anyone to see. To be clear, a model weight is not the training data; rather, it is the information that the model learned by analyzing the data.&lt;/p&gt;
 &lt;p&gt;In contrast, an open source model will also include code and training methodology alongside the weights, though there is also broad ongoing debate on what is and what isn't actually an &lt;a href="https://www.techtarget.com/searchapparchitecture/feature/The-industry-is-trying-to-fix-AI-model-licensings-legal-minefield"&gt;open source AI license&lt;/a&gt;. The practical reality in many cases, though, is that the terms are blurred and organizations consider the terms as mostly the same thing.&lt;/p&gt;
 &lt;h3&gt;The case for open weight&lt;/h3&gt;
 &lt;p&gt;"We evaluated open weight models and moved straight into running them in production," Arriada said. "For several months now, we've been running GLM on our own Nvidia infrastructure. And it has grown to roughly 35% of our total token consumption -- at near-zero marginal cost per request -- because the economics live in hardware we already own. For a large share of our workloads, the capability gap versus frontier models simply doesn't matter, and the data never leaves our environment."&lt;/p&gt;
 &lt;p&gt;Masood said that at his organization, there is a governed model gateway that routes work by data classification as well as workload complexity. Frontier reasoning goes to the enterprise APIs under zero retention terms. Regulated or sovereignty-bound workloads run open weights inside the client's own perimeter, where nothing leaves.&lt;/p&gt;
 &lt;p&gt;"Open weights buy you architectural certainty about where your data lives," he said.&lt;/p&gt;
 &lt;h3&gt;What it costs you&lt;/h3&gt;
 &lt;p&gt;Going the open route does have other costs.&lt;/p&gt;
 &lt;p&gt;"You inherit the security burden -- like patching, guardrails, prompt-injection defenses, red-teaming -- plus the MLOps overhead of running inference infrastructure," Arriada said.&lt;/p&gt;
 &lt;h3&gt;Where most companies will land&lt;/h3&gt;
 &lt;p&gt;"I think the future is tiered, not either/or," Ajmera said, "splitting that slice between a frontier model for planning and self-hosted open weights for execution."&lt;/p&gt;
&lt;/section&gt;             
&lt;section class="section main-article-chapter" data-menu-title="Service level agreements: What CIOs must demand from AI vendors"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Service level agreements: What CIOs must demand from AI vendors&lt;/h2&gt;
 &lt;p&gt;Service level agreements (SLAs) and contracts written for traditional software never anticipated the AI vendor management challenges related to a customer's data.&lt;/p&gt;
 &lt;h3&gt;Non-negotiable terms&lt;/h3&gt;
 &lt;p&gt;CIOs describe a similar starting point: testing a vendor's promises against its paperwork -- not its sales pitch.&lt;/p&gt;
 &lt;p&gt;Orla Daly, CIO at Skillsoft, noted that her company uses a formal AI security assessment questionnaire for vendors.&lt;br&gt;&lt;br&gt;&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    The most important thing is to ensure that enterprise data remains in a private, secure tenant and is not accessible to the AI vendor or third parties for selling, mining or training purposes.
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Keyur Ajmera&lt;/strong&gt;CIO at Boomi
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;"With respect to data, we look for details on how a vendor is handling &lt;a href="https://www.techtarget.com/searchdatamanagement/tip/Data-governance-challenges-that-can-sink-data-operations"&gt;data governance&lt;/a&gt; and privacy, model performance, bias, accuracy, reliability, transparency and explainability, compliance to regulations," she said. "It's important to push on understanding how a written policy is embedded into operations: clear data usage rights so our inputs and outputs are not used to train or improve any model without explicit opt-in, defined retention windows, transparency on subprocessors with notification before that list changes, and the ability to evaluate model updates before they hit our environment."&lt;/p&gt;
 &lt;p&gt;Data isolation is also critical.&lt;/p&gt;
 &lt;p&gt;"The most important thing is to ensure that enterprise data remains in a private, secure tenant and is not accessible to the AI vendor or third parties for selling, mining or training purposes," Ajmera said.&lt;/p&gt;
 &lt;p&gt;Masood has a list of five specific must-have items in an SLA:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;First, no training on inputs or outputs, extended explicitly to derivatives, including embeddings, fine-tuned checkpoints, evaluation sets and feedback signals.&lt;/li&gt; 
  &lt;li&gt;Second, retention measured in days, with deletion SLAs and certification.&lt;/li&gt; 
  &lt;li&gt;Third, no human review of the company's content without written consent.&lt;/li&gt; 
  &lt;li&gt;Fourth, output ownership assigned to the customer, with intellectual property indemnification behind it.&lt;/li&gt; 
  &lt;li&gt;Fifth, exit rights: subprocessor transparency, residency commitments, audit access, and the ability to take your fine-tunes and embeddings with you when you leave.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;h3&gt;Enforcement and liability&lt;/h3&gt;
 &lt;p&gt;Contracts are all well and good until terms are broken. That's why it's critical to have enforcement and liability terms in place. It's important that those terms include clear breach notification timelines and incident response commitments.&lt;/p&gt;
 &lt;p&gt;"Ensure that any future contract language changes do not supersede our initial opt-out choices and require formal, legally binding approval from us for any data protection changes," Ajmera said. "Indemnification for data misuse or unauthorized training use. Meaningful liability cap for data breach or security incidents."&lt;/p&gt;
 &lt;h3&gt;Red flags that should trigger deeper diligence&lt;/h3&gt;
 &lt;p&gt;Two CIOs pointed to the same kind of warning sign, one contractual and one operational.&lt;/p&gt;
 &lt;p&gt;"The contractual red flag is vague, 'We may use data to improve our services,' language, and that phrase opens the door to swallow every other protection in the document," Arriada said.&lt;/p&gt;
 &lt;p&gt;"I push hardest on explicit language around training use, data retention and deletion -- not general assurances," Johnson said. "One potential challenge we watch for is any AI agent or tool that starts producing information based on data it shouldn't have access to. That is usually the first sign the data boundaries aren't what they should be."&lt;/p&gt;
&lt;/section&gt;                  
&lt;section class="section main-article-chapter" data-menu-title="Security concerns"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Security concerns&lt;/h2&gt;
 &lt;p&gt;There are a series of legitimate security concerns related to data and AI.&lt;/p&gt;
 &lt;h3&gt;The AI security risks&lt;/h3&gt;
 &lt;p&gt;&lt;b&gt;Memorization.&lt;/b&gt; Models can potentially expose training data that was intended to remain private.&lt;/p&gt;
 &lt;p&gt;"There are documented cases of large language models regurgitating training data under specific prompting conditions, including data that was never supposed to be in the training set," Ajmera said.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;&lt;b&gt;Prompt injection&lt;/b&gt;&lt;/em&gt;&lt;b&gt;.&lt;/b&gt; Attackers use the technique known as prompt injection to insert instructions into a prompt that force AI systems to do unexpected and potentially malicious things.&lt;/p&gt;
 &lt;p&gt;"That's a real attack vector, especially as we move toward agentic AI where models take autonomous actions," Ajmera said. "If your agent can be manipulated into exfiltrating data, making unauthorized API calls, or escalating privileges, you have a serious problem."&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Oversharing and third-party integrations.&lt;/b&gt; Sometimes the risk comes from exposure to connected systems.&lt;/p&gt;
 &lt;p&gt;"Deploy an AI assistant with broad access to enterprise systems, and it can surface data from connected systems the user was never permitted to see," Ajmera said.&lt;/p&gt;
 &lt;h3&gt;Real-world examples, and the guardrails not keeping pace&lt;/h3&gt;
 &lt;p&gt;There is no shortage of publicly reported real-world vulnerabilities and incidents related to AI and data.&lt;/p&gt;
 &lt;p&gt;"EchoLeak, CVE-2025-32711, disclosed in June 2025, was a zero-click indirect prompt injection in Microsoft 365 Copilot, where a single crafted email could pull data out of a user's context with no click at all," Masood said. "The&lt;a href="https://www.techtarget.com/searchenterpriseai/news/366565761/OpenAIs-fair-use-claim-against-The-New-York-Times-lawsuit"&gt; New York Times litigation against OpenAI &lt;/a&gt;taught two lessons in one docket: The exhibits showed near-verbatim memorization, and the 2025 preservation order forced retention of chats users believed they had deleted, while zero retention API customers sat outside the hold because there was nothing to preserve."&lt;/p&gt;
 &lt;p&gt;The basic approach to defense is to use guardrails, but they are not universally deployed. Identity and role-based controls are the most common safeguard, deployed by 60% of organizations running generative AI in their security stack, according to Kiteworks' &lt;i&gt;State of AI Cybersecurity in 2026&lt;/i&gt; &lt;a target="_blank" href="https://www.kiteworks.com/cybersecurity-risk-management/ai-cybersecurity-2026-trends-report/" rel="noopener"&gt;report&lt;/a&gt;. &amp;nbsp;Data loss prevention tools trail at 54%, and prompt filtering with input and output controls sits at just 34%.&lt;/p&gt;
 &lt;h3&gt;Insider threat and training&lt;/h3&gt;
 &lt;p&gt;AI has already changed how insiders access and move company data, but governance hasn't caught up.&lt;/p&gt;
 &lt;p&gt;The Ponemon Institute and DTEX Systems' &lt;i&gt;Cost of Insider Risks Global &lt;a target="_blank" href="https://ponemon.dtex.ai/" rel="noopener"&gt;Report&lt;/a&gt;&lt;/i&gt; found that 92% of organizations say generative AI has changed how employees access and share data, yet only 13% have a formally integrated AI into business strategies.&lt;/p&gt;
 &lt;p&gt;There is also a governance risk related to training. &lt;i&gt;Forrester's State of AI &lt;a target="_blank" href="https://www.forrester.com/report/the-state-of-ai-2025/RES189955" rel="noopener"&gt;Survey&lt;/a&gt;, 2025&lt;/i&gt; found that most existing AI policies cover only basics such as data use or copyright compliance, and few mandate responsible AI training.&lt;/p&gt;
 &lt;p&gt;As part of a CIO AI strategy, none of these risks get solved by technology alone. They get managed -- or missed -- in how honest the relationship with a vendor actually is.&lt;/p&gt;
 &lt;p&gt;"The most productive vendor relationships are built on openness and accountability," Grinnell said. "If a provider can clearly explain how your data moves through their environment and can demonstrate the controls behind those explanations, that's a very positive sign."&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>CIOs face confusion over AI data types and vendor terms. Understanding input, training, output and retrieval context data is essential for effective governance and security.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/strategy_a101587012.jpg</image>
            <link>https://www.techtarget.com/it-strategy/feature/Who-owns-your-AI-data-Navigate-security-and-proprietary-risks</link>
            <pubDate>Mon, 03 Aug 2026 15:05:00 GMT</pubDate>
            <title>Who owns your AI data? Navigate security and proprietary risks</title>
        </item>
        <item>
            <body>&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;Executive summary&lt;/h3&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;b&gt;Data sovereignty first.&lt;/b&gt; Enterprise value lives in your proprietary data. Shipping it across public APIs risks data leaks, performance drift and vendor lock-in.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Native multimodality.&lt;/b&gt; Stacking separate models for voice, vision and text creates a fragile "Frankenstein architecture." Single-pipeline processing lowers latency, cuts costs, and simplifies the stack.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;The open-weights security shift.&lt;/b&gt; Pulling models like Inkling-Small into your private cloud gives total control over updates and swappability but shifts the entire security and containment burden to your team.&lt;/li&gt; 
   &lt;li&gt;&lt;b&gt;Hardened perimeter.&lt;/b&gt; Running models internally requires strict zero-trust guardrails and separating model reasoning from system execution.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;Every enterprise board is currently suffering from an expensive addiction: paying top-dollar API tolls to run basic tasks through bloated 900-billion-parameter models. It's the equivalent of hiring rocket scientists to sort your morning mail.&lt;/p&gt; 
&lt;p&gt;When Thinking Machines Lab dropped &lt;a target="_blank" href="https://thinkingmachines.ai/news/inkling-small/" rel="noopener"&gt;Inkling-Small&lt;/a&gt;, the collective sigh of relief from pragmatists in IT was almost audible. Packing 276 billion total parameters with only 12 billion active per forward pass, it matches flagship reasoning, hitting 40 on the Artificial Analysis Intelligence Index, while radically slashing the compute bill.&lt;/p&gt; 
&lt;p&gt;Enterprise AI is entering its next phase. The first phase rewarded organizations for gaining access to the biggest models. The next will reward those who build smarter architectures -- running the right model for the job; keeping data closer to home; and balancing performance with cost, &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/How-AI-governance-and-data-privacy-go-hand-in-hand"&gt;governance&lt;/a&gt; and flexibility.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Enterprise data is the gold: Stop transporting it"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Enterprise data is the gold: Stop transporting it&lt;/h2&gt;
 &lt;p&gt;The default enterprise architecture has been shipping proprietary IP across public boundaries into third-party clouds. Compact, highly capable &lt;a target="_blank" href="https://www.cybersecuritydive.com/news/ai-open-source-weights-tech-industry-promote/826240/" rel="noopener"&gt;open-weight models&lt;/a&gt; change the physics of this setup:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Private cloud and on-premises revival.&lt;/b&gt; At 12 billion active parameters, models fit squarely into enterprise private clouds or local data centers. You bring compute to your data, not your data to someone else's cloud.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Model upgrades and portability.&lt;/b&gt; Hosted open weights let you control the upgrade lifecycle via platforms such as Tinker. You can swap backends, apply domain fine-tuning (LoRA) or upgrade weights without third-party API changes breaking downstream applications.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Network and air-gapped autonomy.&lt;/b&gt; Regulated industries gain deterministic performance without outbound data leaks or external network bottlenecks.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Native multimodality vs. the 'Frankenstein architecture'"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Native multimodality vs. the 'Frankenstein architecture'&lt;/h2&gt;
 &lt;p&gt;Stitching together point solutions -- such as an audio transcription tool, a vision model to parse complex charts, a primary LLM to think, and a coding model to execute -- is expensive, fragile and slow.&lt;/p&gt;
 &lt;p&gt;For example, Inkling-Small addresses this by processing text, visual reasoning -- such as dynamic image cropping/zooming for chart analysis -- and native audio in a single pipeline. Stripping away external API hops lowers latency across transitions and slashes the threat surface of third-party integrations.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Consider an auto insurance claim. A customer submits a voice recording describing the accident, photos of the vehicle damage and a scanned police report. Traditional AI architectures route each input through separate transcription, vision and document-processing services before combining the results. A unified &lt;a href="https://www.techtarget.com/searchenterpriseai/feature/Explore-real-world-use-cases-for-multimodal-generative-AI"&gt;multimodal model&lt;/a&gt; running inside the insurer's private infrastructure processes all three inputs in a single pipeline, compares the driver's statement with the visual evidence and report, flags inconsistencies, and generates a structured recommendation -- without sensitive customer data ever leaving the enterprise network. &lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="The open-weights paradox: High sovereignty, higher responsibility"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The open-weights paradox: High sovereignty, higher responsibility&lt;/h2&gt;
 &lt;p&gt;When you pull open-weight models onto your network, you own the entire operational surface. If a 12 billion active parameter model operates with implicit network trust and hallucinates, accepts prompt injection from an ingested document, or executes an unauthorized microservice call, there is no third-party cloud vendor to blame.&lt;/p&gt;
 &lt;p&gt;Open weights grant data sovereignty, but they demand rigorous internal containment. This architectural shift changes more than infrastructure costs -- it changes the enterprise security model. As organizations move AI inside their own environments, responsibility moves with it.&lt;/p&gt;
 &lt;h3&gt;How to secure open weights and maintain model swappability&lt;/h3&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Deterministic execution guardrails.&lt;/b&gt; Place an explicit policy proxy between the model and internal infrastructure. Never let an LLM directly execute database writes; the model proposes an action, and a deterministic microservice validates permissions before execution.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Input sanitization and sandboxing.&lt;/b&gt; Treat all ingested documents, audio and prompts as untrusted inputs to prevent &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-prompt-injection-attacks-and-how-they-work"&gt;prompt-injection attacks&lt;/a&gt;. Execute model-generated code only inside sandboxed micro-VM containers.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Model swappability via gateways.&lt;/b&gt; Standardize internal developer APIs using unified gateway layers -- such as LiteLLM or vLLM backends. This decouples app logic from model weights, letting operations teams swap underlying models (e.g., transitioning between Inkling-Small, Llama or custom weights) without breaking downstream applications.&lt;/li&gt; 
 &lt;/ol&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="The H2 2026 action plan for CIOs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The H2 2026 action plan for CIOs&lt;/h2&gt;
 &lt;p&gt;If your roadmap still relies on routing every corporate prompt to the largest flagship model available, it's time to pivot:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Days 1–30: Workload compute audit.&lt;/b&gt; Segment simple routing, agentic coding and deep reasoning. Stop paying $4+/1M output tokens for tasks that a $1.20/1M model like Inkling-Small completes with identical benchmark accuracy.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Day 60: Enforce execution isolation and gateway layers.&lt;/b&gt; Implement abstraction layers to enable seamless model swappability and enforce strict separation between model reasoning and backend execution.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Day 90: Architect for variable compute.&lt;/b&gt; Deploy dynamic routing layers so your infrastructure scales up "thinking time" (test-time compute) only when a task actually warrants it, safely housing sovereign AI inside your own network boundaries.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The next generation of enterprise AI won't be defined by who has access to the largest models. It will be defined by who builds the smartest architecture -- placing the right model, with the right governance, as close as possible to the data that creates competitive advantage. That's the shift enterprise leaders should be planning for today.&lt;/p&gt;
&lt;/section&gt;</body>
            <description>The real value is your data, and it's time to stop shipping it across public APIs.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/ai_a264431831.jpg</image>
            <link>https://www.techtarget.com/it-strategy/opinion/Rethink-the-AI-stack-Why-lean-open-architecture-is-the-answer</link>
            <pubDate>Mon, 03 Aug 2026 14:25:00 GMT</pubDate>
            <title>Rethink the AI stack: Why lean open architecture is the answer</title>
        </item>
        <title>IT Strategy Resources and Information from TechTarget</title>
        <ttl>60</ttl>
        <webMaster>webmaster@techtarget.com</webMaster>
    </channel>
</rss>
