Tag: AI governance

  • The Enterprise AI Time Bomb Is Ticking.  Cisco Shares Its Plan.

    The Enterprise AI Time Bomb Is Ticking. Cisco Shares Its Plan.

    At Cisco Live in Las Vegas this week, the company delivered a sobering security message for enterprise buyers. AI helps the bad actors move faster, and the window to get ahead of it is closing quickly.

    “AI changes the speed of defense. The bad corollary to that is it’s empowering our adversaries at a pace that we’ve never seen in our careers. These models are as bad today as they’re ever going to be,” Cisco CEO Chuck Robbins told the packed keynote audience — a line that landed with more weight than a typical tech conference applause line. He wasn’t talking about AI being ineffective. He was talking about it being weaponized.

    A New Kind of Threat

    The cybersecurity industry has spent years warning about AI-powered attacks. What’s changed in 2026 is that frontier AI models — particularly Anthropic’s Claude Mythos have made those warnings concrete.

    What sets Mythos apart from prior AI models is not general intelligence but what it can do in a cybersecurity context. According to Anthropic, it can autonomously identify and exploit software vulnerabilities at a level that outpaces almost all human security experts. In controlled testing, the model has been shown to identify thousands of zero-day vulnerabilities over several weeks — a pace no human security researcher or team could match.

    The dual-use nature of that capability is what makes Mythos a defining moment for enterprise security. The same model that can find and patch vulnerabilities at unprecedented speed can, in the wrong hands, find and exploit them. CrowdStrike’s 2026 Global Threat Report found an 89% increase in attacks by adversaries using AI — and Mythos-class capability represents a meaningful step change in what those adversaries can bring to bear.

    Anthropic has acknowledged that “models of this capability level require stronger cyber safeguards before they can be generally released,” which is why public access has been withheld while safety work continues. But what this tells us is that enterprises must prepare for a post-Mythos threat environment where any number of increasingly capable open and commercial models can and will help bad actors exploit vulnerabilities in legacy or unpatched systems. We can also see that patching isn’t enough.

    Robbins warned that the capability floor for AI-assisted attacks had just risen significantly and will not come back down. The most alarming shift is speed. Where it once took days or weeks for bad actors to move from a disclosed vulnerability to a working exploit, that timeline has compressed to minutes. Cisco’s own security team demonstrated the flip side of that same capability. Robbins said in the past eight weeks, Cisco used AI to scan 1.8 billion lines of code across 25 programming languages. Before these models existed, Robbins said, that would have taken approximately eight years.

    The implication is uncomfortable but unavoidable. The same technology accelerating legitimate security work is accelerating attacks at the same pace. Neither side has an obvious advantage, and the defender’s job — protecting a complex, distributed enterprise — is structurally harder than the attacker’s.

    Agents Make Everything Harder

    If AI-powered threats were the only problem, that would be manageable. But Cisco’s President and Chief Product Officer, Jeetu Patel, outlined a second, compounding challenge: the rapid proliferation of AI agents is creating an attack surface that enterprises are almost entirely unprepared for.

    The AI industry evolved from chatbots that respond to questions to AI agents that can act autonomously. Patel said Cisco’s research found that a single AI agent generates roughly 450% more network traffic than a human performing the same task. Multiply that by thousands of agents running across an enterprise, and the infrastructure and security implications are significant.

    More importantly, agents have access to tools. Agents call APIs, query databases, submit code, and interact with external services. The goal of an agentic AI system is to perform tasks without a human in the loop. Patel’s framing was blunt: “Agents are like teenagers. They’re supremely intelligent, but they have no fear of consequence.”

    Agentic AI creates new attack vectors that aren’t easy to manage with existing solutions. For example, prompt injection attacks can manipulate an agent’s behavior. Data poisoning can corrupt its decision-making. Meanwhile, bad actors can perform tasks at high speed with a compromised agent  before anyone notices anything is wrong.

    While agentic AI has great potential, most enterprises lack the proper visibility, security and management to handle agents. Companies need a systematic way to know how many agents are running in their environment, what those agents are authorized to do, or whether they are behaving as intended. This is one security gap Cisco is racing to close alongside other security companies, hyperscalers, and startups.

    The Identity Problem Nobody Has Solved

    Businesses are just waking up to the problem of non-human identity posed by AI agents. Every person accessing a corporate system has an identity with a role, credentials, and permissions. Machines, services, and AI agents largely do not, at least not in any consistent or governed way.

    In May, Cisco acquired Astiix Security, an AI company focused on the non-human identity category.  Before enterprises can enforce meaningful controls on agent behavior, they need a reliable way to know which agents exist, what they have access to, and what they should be allowed to do. The platform helps organizations discover, govern, and protect machine identities, preventing unauthorized access and securing AI agents from malicious attacks. Cisco can integrate this technology into its Cisco Identity Intelligence and zero-trust products, such as Duo and Secure Access, to safely manage the proliferation of AI agents.

    This is not a theoretical future problem. Enterprises are deploying agents today, and most are doing so without the right identity infrastructure to govern them. If they deploy agents within a specific SaaS stack, permissions and governance are typically handled by that software. Once we start discussing multi-agent workflows that cross applications, the challenge becomes more complex. Astrix gives Cisco more capabilities to support identity for an agentic future.

    Cisco’s Response In Three Moves

    Beyond the Asterix acquisition, Cisco announced a set of products and capabilities aimed directly at the threat landscape it described.

    1. AI Defense, extended for agents. Cisco launched AI Defense roughly 18 months ago to provide visibility and guardrails for AI models and applications. The updated version adds capabilities specifically for agentic deployments: adaptive testing, behavioral guardrails, security for agentic supply chains, and support for all major agent platforms, including Claude, Codex, and OpenAI.
    2. Zero trust that gets an update for AI agents. The traditional zero trust model is built around access control: verify identity, grant minimum necessary permissions, and monitor behavior. Cisco correctly argues that today’s access control is insufficient for agents. What enterprises need is action control — the ability to intercept and verify every action an agent takes, not just whether it was authorized to log in. This is a meaningful architectural shift, and one that Cisco is embedding into its platform rather than offering as a standalone product.
    3. An agentic SOC. The cybersecurity talent shortage is severe. Approximately 4 million positions go unfilled annually in the US alone, according to Cisco. The volume of security alerts already exceeds human capacity to investigate. Cisco’s answer is an AI-powered Security Operations Center where agents autonomously triage alerts, identify anomalies, and, in time, predict and prevent breaches. The foundation is Cisco Data Fabric, a Splunk-powered platform that ingests petabyte-scale telemetry from network, security, application, and third-party sources.

    The Galileo Acquisition: Watching the Watchers

    Governing AI agents requires knowing what they are doing — not just whether they are authorized to act, but whether they are producing the outcomes they were designed for. This is the observability problem, and it is harder than it sounds.

    To address it, Cisco acquired Galileo, an AI observability company founded by researchers who previously worked with Google and DeepMind. Galileo’s technology powers what Cisco calls full-stack agent observability. This is visibility into infrastructure performance, model behavior, application runtime, and agent output quality. It also includes whether agents consume tokens at a sensible rate.

    That last point surfaced repeatedly during the keynote and reflects a real operational concern. A runaway agent that has been misconfigured or has drifted from its intended behavior can consume an entire organization’s annual AI budget in a matter of days. Token cost management is not a glamorous feature, but it is required for this new era of infrastructure.

    Cisco Cloud Control: The Platform Beneath All of It

    One of the more surprising announcements was the newly launched Cisco Cloud Control. For anyone who’s followed networking and Cisco for years, the concept of a true unified management console has been discussed for many years, and it’s devilishly difficult to execute. Every part of the portfolio had its own management tools that were loosely coupled at best, if at all. Cisco Cloud Control aims to be a new unified management platform that consolidates the company’s entire product portfolio under a single interface with single sign-on. Cloud Control is the operational layer through which Cisco intends to deliver its AI security and observability strategy.

    The security-specific capabilities embedded in Cloud Control, such as agent security monitoring, cross-domain threat correlation, and policy enforcement in natural language, represent a meaningful shift from how enterprise security tools have historically operated. Rather than logging into separate dashboards for networking, security, and operations, administrators can query their entire infrastructure environment in natural language and receive correlated, actionable insights across domains.

    The demos made it look like Cisco had finally cracked the code. Whether that vision holds up at enterprise scale remains to be tested. But the architecture Cisco described — silicon to semantics, from custom networking chips to AI agents operating on top of them — reflects a deliberate bet that the company’s control of the full infrastructure stack is a genuine competitive advantage in an AI-defined security landscape.

    The Reality. Enterprise AI Threats Are Real.

    Cisco’s keynote was, of course, a product announcement. But stripped of the stage production, the underlying argument is sound and worth taking seriously.

    AI is compressing attack timelines. Agents are expanding the attack surface in ways that existing security architectures can’t handle. The cybersecurity workforce is not growing fast enough to compensate. And most enterprises are deploying agents today without the governance infrastructure to know what those agents are doing, let alone control them.

    The organizations that will navigate this well are not necessarily the ones that move fastest. They are the ones that treat agent governance — identity, authorization, behavioral monitoring, and action control — as a first-class infrastructure concern rather than an afterthought. Enterprise technology leaders want and need their existing technology stack providers to evolve their security and management stacks to support AI threats. Cisco is making a significant bet that enterprises will pay for that infrastructure. Given the threat landscape it described, the bet seems rational.

    This article was originally published on Forbes.com.

  • Amazon Connect Is Now a Family of Products That Adds Agentic AI  to CX, HCM, Supply Chain and Healthcare

    Amazon Connect Is Now a Family of Products That Adds Agentic AI to CX, HCM, Supply Chain and Healthcare

    AWS is betting that Amazon Connect agentic AI belongs in supply chain, hiring, and healthcare — not just customer service. The branding is smart. Here’s my quick take. 

    For years, Amazon Connect meant one thing: contact center software. As of this week, it means four products, three new markets, and a bet that agentic AI is ready to run business operations — not just answer customer calls.

    At its “What’s Next with AWS” event, Amazon Web Services announced the expansion of the Amazon Connect name into a family of agentic business solutions. The original contact center product is now called Amazon Connect Customer. Three new products join it: Amazon Connect Decisions (supply chain and demand planning), Amazon Connect Talent (high-volume hiring), and Amazon Connect Health (clinical documentation and patient coordination). All four products sit under the Connect name. All four are agentic by design.

    The naming will raise eyebrows — more on that shortly. But the strategic logic is sound, and enterprise buyers should pay attention.

    What “Agentic by Design” Actually Means Here

    It’s worth being precise about what makes these products different from the AI-infused software most enterprises already live with.

    Agentic AI doesn’t just surface recommendations. It plans a sequence of actions, executes them, monitors the results, and adjusts. The word “connect” is doing double duty in this brand: it references both the product family name and the agents’ actual function — connecting to your systems, your data, and your workflows to get something done without waiting for a human to click “approve” at every step.

    The original Amazon Connect spent the last year being rebuilt on this principle. In 2025, AWS introduced what it called “next generation connect” — adding AI across the full customer journey, not just within a single interaction. Sentiment analysis, agent assist, post-call wrap-up, outbound communication, and full transcription all came along. The shift from the original Connect to Connect Customer is a shift from AI as a feature to AI as the operating model.

    The three new products start from that same premise, except they aren’t retrofits. They were built from scratch for agentic execution.

    Three Reasons the Benefits Case Is Credible

    Vendor AI announcements are easy to be skeptical of. This one has a few things working in its favor.

    Scale. Amazon Connect Customer handled 20 million interactions per day and processed 12 billion AI-powered minutes of conversation last year. That’s not a pilot. The new products are built on the same infrastructure. For enterprise buyers who have watched AI proofs of concept collapse under production load, operational scale at this level is a legitimate differentiator.

    Domain expertise embedded in the product. Amazon didn’t hire supply chain consultants to build Connect Decisions. It extracted the models and decision frameworks from its own retail and logistics operations — systems managing demand planning across more than 400 million SKUs. Connect Talent draws from Amazon’s process for hiring 250,000 seasonal workers in a single season. Connect Health is built on the clinical AI running at One Medical, which has now processed more than one million ambient documentation visits. This is proprietary operational knowledge baked into the product, not a general-purpose LLM applied to a new domain. That distinction matters for buyers evaluating whether a product will actually understand their problem.

    Integration with existing AWS infrastructure. For organizations already running on AWS, these products inherit the identity management, access controls, audit logging, and compliance certifications already in place. Buyers don’t start from zero on security posture or governance. That’s a real reduction in implementation risk, particularly in regulated industries like healthcare and financial services.

    On the Branding: Confusing Short-Term, Coherent Long-Term

    The name “Amazon Connect” has strong recognition in the enterprise market specifically as a contact center product. Adding supply chain, hiring, and healthcare products under the same name will require education.

    That said, the decision is defensible. The Connect products share a common architecture and a common design philosophy. AWS is calling that philosophy “Humorphism” — building products designed around how humans and AI agents collaborate, rather than how humans use static tools. Agents ask clarifying questions. They capture the reasoning behind manual edits. They improve over time as they learn from user decisions. Every Connect product is designed to work this way.

    The naming creates a coherent category: all Connect products are agentic, all are built on Amazon’s internal operational experience, and all are designed for line-of-business adoption rather than IT-led implementation. That’s a real product strategy, not just a logo change.

    Buyers evaluating these products should simply be explicit in conversations with AWS about which Connect product they mean. In the short term, that’s a small friction. In the long term, a unified family brand is cleaner than four separate product names with no connective tissue.

    The Open Questions That Need Answers

    Pricing is TBD. AWS did not address how these products will be priced or licensed. For supply chain and hiring products competing with established enterprise software, pricing model matters significantly. Per-transaction, per-user, and consumption-based models all create different budget implications. Enterprise buyers should not evaluate these products without getting pricing clarity first.

    The ERP and HCM question is unresolved. Connect Decisions targets supply chain planning. Connect Talent targets high-volume hiring. Both markets have entrenched incumbents — SAP and Oracle on the ERP side, Workday and Oracle HCM on the talent side — that already hold enterprise data and run existing workflows.

    The question isn’t whether Amazon can build better AI. The question is how Connect Decisions and Connect Talent interact with the systems enterprises already have. A few scenarios are possible, and AWS hasn’t clarified which one applies. The existing ERP or HCM system could become a data source that feeds the Connect agents. The incumbent vendor could build its own agents that call Connect products as tools. Or both systems end up running parallel agent workflows that need to be orchestrated together. Each of these plays out differently for buyers in terms of integration complexity, data governance, and total cost of ownership.

    The demos shown at the event depict Connect Decisions and Connect Talent operating as primary systems of action — generating demand plans, running interviews, surfacing candidate assessments. That implies some displacement of existing workflow software, at minimum for the activities these agents handle. Whether that displacement requires wholesale replacement of incumbent systems, or whether it can coexist alongside them, is not clear from what was announced. Buyers who already run SAP or Workday should press AWS specifically on this before evaluating further.

    What to Do With This Information

    If you’re an existing Amazon Connect customer, evaluate what the next-generation Connect Customer capabilities mean for your current deployment before looking at the new products. The AI-across-the-journey architecture is a meaningful shift from the original product, and understanding it fully is the right starting point.

    If you’re in supply chain, high-volume hiring, or healthcare and are currently underserved by your existing software, these products are worth a serious look. The domain expertise and scale credentials are real. Get pricing clarity and understand the integration model before committing.

    If you’re running SAP, Workday, or another incumbent system in these domains, don’t assume this announcement is irrelevant to you. The better question to ask your existing vendor is: what is your agent strategy, and how does it interact with what AWS just announced?

    The question isn’t whether Amazon Connect should be a family of products. The question is whether or how to make your current stack work alongside it.

    Subscribe to my AI with Maribel Lopez podcast on your channel of choice at https://www.buzzsprout.com/194744.

  • Four Enterprise AI Spending Pitfalls  and How to Avoid Them

    Four Enterprise AI Spending Pitfalls and How to Avoid Them

    By Maribel Lopez, Lopez Research

    A few practical thoughts on where AI spending goes wrong — and what separates the organizations getting it right. Most organizations aren’t failing at AI because the technology doesn’t work. They’re failing because of decisions made before a single model was deployed. Decisions such as how to scope and fund an initiative, what success was supposed to look like, and whether anyone was measuring whether they got there. I recently joined Tom McHale, CFO and VP of Business Operations at SunStream Business Services and Apptio, an IBM company, for a webinar conversation about where spend management goes wrong.   McHale shared how he has navigated technology trade-off decisions as a CFO for years. Our observations converge on the same patterns. Here are the four pitfalls McHale and I spoke about during the session — and what organizations can do about them. 

    Pitfall 1: The Board Issues an AI Mandate Without Funding the Foundation

    Seventy-two percent of companies Lopez Research surveyed had received a directive from their board or senior management to implement AI last year. Most of those mandates arrived without acknowledging the trade-offs required to fulfill them. The pressure is real, and organizations that don’t leverage AI within their apps and services will fall behind. The problem is fixating on the technology without resourcing the operational requirements underneath it. To move into AI effectively, you need data quality, governance, and a clear plan for budgeting for ongoing costs. Boards often ask for AI outcomes without understanding the foundational work it takes to deliver them. There is also a funding gap that sneaks up on organizations. Many companies attempted to fund AI by reallocating from existing cloud or operations budgets. That worked at the margins. It does not work at scale. Internal capital reallocation as the primary AI funding source jumped from 50% to 67% in a single year in Apptio’s 2026 Technology Investment Management Report. At some point, there is not enough money in the couch cushions to do what is being asked. McHale also shared that most management teams expect first-class technology at bargain-basement prices. He brought up the reality many organizations face when he shared an example: you can’t always make trade-offs between technologies, such as funding a batch scheduler in a mainframe environment or investing in AI. You need both. What to do: Before responding to an AI mandate, attempt to map the real cost. That means data preparation, governance infrastructure, security review, and ongoing model costs — not just tool licenses.  Bring that full picture to leadership. The conversation about tradeoffs is easier to have before you start spending than after you have run out of budget. 

    Pitfall 2: Failing to Define Problems and Measurable Outcomes

    In the early days of AI adoption, running experiments made sense. Organizations needed to learn what the technology could do. That phase is over. In 2026, no one should be running an AI proof of concept without a production path and a timeline. In research Lopez Research conducted in mid-2025, 85% of companies said they were struggling to find AI ROI. When we looked at why, three causes kept surfacing. First, there was a data quality problem. Second, the use case was too vague to measure. Third, there were no metrics, monitoring, or observability in place to gauge whether the initiative was working. The fourth issue is that fewer than half of the organizations had a governance strategy, which tends to create downstream compliance and legal exposure. All these solutions are foundational solutions that require time and money. And we didn’t even discuss the cybersecurity concerns, which is always one of the top three technology spending categories. Selecting AI technology solutions before defining what you are trying to accomplish is like buying a full set of hammers, screwdrivers, and impact drivers before knowing what you are building. The tools are not the strategy. What to do: Understand what specific organizational strategic goal or KPI you’re trying to achieve before you start. “Improve customer experience” is too vague. Whereas something specific enough to measure, like reducing billing errors by 80% to improve customer satisfaction, or improving deployable software development velocity by 15%, allows you to understand the impact and the metrics, and provides a set of requirements for AI tool selection. If you cannot define success before you deploy, you are not ready to deploy. Note: I am researching the merits and detriments of an “AI use cases” versus “creating reusable AI skills/capabilities with AI agents”. See the March Newsletter on Yumm Brands for more on this. Given that I don’t yet have solid guidance on how to build and scale reusable AI skills, I maintain that you need to understand which real business problems you need to apply AI to, which helps winnow the platform selection. 

    Pitfall 3: Assuming the Budget You Can See Is the Actual Spend

    Shadow AI is this year’s shadow IT. Every technology wave produces a version of this problem. Employees find tools that help them work faster, stand them up without IT involvement, and pay for them however they can — personal credit cards, discretionary budget lines, expense reports. It adds up quickly and never shows up in the official budget. McHale shared a real example from a prior role. After conducting a full audit of actual spend at a Fortune 500 organization, the actual IT budget was double the official number. Shadow IT had been absorbing that difference for years. With AI tools accessible to anyone with a credit card and a browser, the same dynamic is accelerating. The financial risk is significant. An employee can spend $20 to $300 per month on AI tools, such as ChatGPT and Claude Code. Untracked AI spend scales fast across an organization. But the non-financial risk may be more serious. Unvetted tools accessing company data, unapproved models processing sensitive customer or employee information, and no audit trail if something goes wrong. The governance and security risks posed by shadow AI are not hypothetical. McHale put it well: defining clear objectives at the start, having someone accountable for documenting them, and treating governance as an ongoing discipline rather than a one-time checkbox is what separates organizations that can scale AI from those that cannot. Organizations that lack centralized visibility into AI spend will discover this the hard way. When it comes time to request a budget increase for next year, leadership will ask why more money is needed, given that things seemed to work fine with what was available. The answer — that it was all going on personal credit cards — is not a conversation anyone wants to have. What to do: Treat AI spend tracking as an urgent priority, not a future initiative. Establish a process for centralizing AI tool procurement now, or at least provide guardrails for AI spending. This is not about restricting what employees can use. It is about knowing what is being used, what it costs, and what data it can access. Shadow AI that stays invisible today becomes a budget and compliance problem tomorrow. 

    Pitfall 4: Confusing Operational Maturity with Technical Maturity

    This is one of the more subtle pitfalls, and it trips up organizations that are genuinely sophisticated technically. A company can have strong cloud infrastructure, capable engineering teams, and real AI experience — and still be operationally immature in managing AI investment. The gap is most evident in IT financial management. IBM Apptio’s survey data shows that 59% of ITFM professionals are confident their forecasts are highly accurate. The tools and processes many teams rely on to produce those forecasts were not designed for the pace or variability of AI spend. AI costs scale with usage in ways that are difficult to predict. They appear across every function in the organization. They change as models are updated, as usage grows, and as new capabilities are deployed. Managing that with processes built for a slower-moving environment creates real risk, even when the people running those processes are skilled and confident. Yet the potential visibility gap is where budget surprises live. What to do: Audit your financial management practices against the specific demands of AI spend. Variable usage-based costs, multi-cloud workloads, hybrid AI, and distributed AI tools across business units require practices built for that environment. The goal is not to find fault with what you have been doing. The goal is to identify where the current setup leaves gaps that AI spending will widen. 

    The Pattern Behind the Pitfalls

    These pitfalls are not independent. These pitfalls interconnect. An AI mandate without a real budget forces organizations to fund initiatives on the margins, leading to cuts in data, governance, observability, and security. Without visibility into spend, shadow AI accumulates, and real costs stay invisible. Without defined success metrics, there is no way to know whether cutting those corners mattered. The organizations that are getting AI right did not avoid these problems by being smarter. They avoided them by doing the less exciting work first: defining use cases clearly, understanding true costs before committing, building governance before it was required, and measuring outcomes from day one.While the technology changes,  the adoption challenges remain remarkably consistent. Every wave has its version of the couch cushions problem — organizations moving fast on an exciting new capability without the financial and operational discipline to sustain what they are building. Focus on the foundation first. The shiny AI tools can follow. Subscribe to my LinkedIn newsletter here. Also, you can subscribe to the AI with Maribel Lopez podcast on your channel of choice here.

     

  • NemoClaw, OpenClaw, and the Real Reason Enterprises Haven’t Deployed AI Agents Yet

    NemoClaw, OpenClaw, and the Real Reason Enterprises Haven’t Deployed AI Agents Yet

    

    NVIDIA’s NemoClaw adds enterprise security to OpenClaw. What it does, what it doesn’t, and what CIOs should do before deploying.

    FULL SHOW NOTES

    OpenClaw became the fastest-growing open-source project in history. Enterprise buyers watched from the sidelines — not because the technology wasn’t useful, but because an autonomous agent with access to corporate file systems, credentials, and external communication channels is a governance and security problem that no one had solved at the enterprise level.

    At NVIDIA’s GTC 2026 conference, Jensen Huang announced NemoClaw: a reference stack that adds enterprise security controls to OpenClaw. In this solo episode, Maribel Lopez breaks down what NemoClaw actually does, why the SaaS partner ecosystem matters as much as the technology itself, and where the hype is running ahead of the reality.

    WHAT WE COVER

    •       Why OpenClaw created a shadow IT problem before NemoClaw existed

    •       What OpenShell, the Privacy Router, and Nemotron models actually do for enterprise buyers

    •       Why Salesforce, ServiceNow, SAP, Cisco, and CrowdStrike being in the ecosystem matters

    •       The hardware dependency NVIDIA’s marketing glosses over

    •       Why “working with NVIDIA” and “ready to deploy” are not the same thing

    •       The three questions every CIO should answer before touching any of this

    TIMESTAMPS

    00:00  —  Why enterprise IT teams were watching OpenClaw from the sidelines

    01:45  —  What OpenClaw is and why it created an enterprise security problem

    04:00  —  What NemoClaw actually does: OpenShell, Privacy Router, Nemotron

    06:30  —  The SaaS ecosystem: Salesforce, ServiceNow, SAP, Cisco, CrowdStrike

    08:30  —  Where the hype is ahead of the reality

    10:15  —  Three questions CIOs should answer before deploying

    RESOURCES MENTIONED

    •       NemoClaw announcement and NVIDIA Agent Toolkit: build.nvidia.com

    •       Full written analysis: NemoClaw Brings Enterprise-Grade Security Controls to OpenClaw — lopezresearch.com

    •       NVIDIA GTC 2026 Jensen Huang keynote

    ABOUT THIS PODCAST

    AI with Maribel Lopez covers enterprise AI adoption, agentic systems, AI governance, and AI-driven customer experience. Maribel Lopez is founder and principal analyst at Lopez Research, a technology research and strategy firm.

    Subscribe on Apple Podcasts, Spotify, or your platform of choice here: https://www.buzzsprout.com/1947446

    KEYWORDS

    enterprise AI agents, agentic AI security, NemoClaw NVIDIA, OpenClaw enterprise deployment, AI agent governance, enterprise AI strategy, AI governance enterprise, agentic AI risks

  • Agentic AI Beyond the Hype: How Banks Are Actually Deploying It

    Agentic AI Beyond the Hype: How Banks Are Actually Deploying It

    Keywords
    AI, agentic AI, Work Fusion, RPA, intelligent automation, compliance, machine learning, LLMs, automation, enterprise technology

    Episode Summary
    Agentic AI dominated industry conversation in 2025. But in 2026, enterprise leaders are asking a harder question: How do we deploy AI agents safely, accurately, and in production environments?
    In this episode, Maribel Lopez speaks with Peter Cousins, CTO of WorkFusion a UiPath company, about how AI agents evolved from RPA and intelligent automation into production-ready “digital workers.” The discussion focuses on regulated industries, where explainability, auditability, and risk controls matter as much as automation gains.
    Rather than hype, this conversation explores what it takes to operationalize AI agents: governance frameworks, confidence thresholds, human oversight, and model risk management.

    Sound Bites

    • “2025 was the big agentic AI year.”
    • “You can't just throw it in and it's good to go.”
    • “It's been great talking to you.”

    Chapters

    00:00
    Introduction to Agentic AI and Work Fusion

    02:00
    Transitioning from RPA to AI Agents

    04:38
    Operationalizing AI Agents in Business

    09:21
    Navigating the Hype of Agentic AI

    12:04
    The Role of LLMs in Regulated Environments

    14:47
    Multi-Agent Orchestration and Collaboration

    17:21
    Improving AI Agents through Learning

    21:01
    The Importance of Non-Human Identity in AI

    24:06
    Closing Thoughts on Adopting Agentic AI

  • AI Meets Cybersecurity: Protecting Critical Infrastructure with Black & Veatch’s Ian Bramson

    In this episode of AI with Maribel Lopez, Maribel sits down with Ian Bramson, Vice President of Global Industrial Cybersecurity at Black & Veatch, to explore the growing intersection between artificial intelligence and operational technology (OT) security.

    From power grids and oil refineries to manufacturing plants, critical infrastructure systems are becoming increasingly connected—and therefore more vulnerable. Ian shares how Black & Veatch is helping industrial organizations rethink cybersecurity from the ground up, integrating protection early in the design and build process rather than bolting it on later.

    Together, Maribel and Ian discuss the evolution of OT threats, the rise of AI in both defense and attack scenarios, and why cybersecurity must be seen as a core business function, not an afterthought.

    🧩 Key Discussion Topics

    1. The Evolution of Industrial Cybersecurity

    • Ian’s unconventional career path—from Coca-Cola to futurist consulting with Alvin Toffler to leading cybersecurity initiatives.
    • Why Black & Veatch launched its dedicated industrial cybersecurity practice and how it’s integrated across engineering, procurement, and construction (EPC).

    2. IT vs. OT Cybersecurity: What’s the Difference?

    • IT focuses on data protection; OT focuses on physical safety and uptime.
    • The rising threat of cyber-physical attacks on power, water, and manufacturing systems.
    • How the increasing connectivity of devices—from pumps to sensors to AI controllers—creates new risks.

    3. Foundational Security: Basics Still Matter

    • Start with asset inventory—knowing what you need to protect.
    • Identify vulnerabilities and train your “human layer.”
    • Build security in from day one instead of bolting it on later.

    4. The Expanding Threat Landscape

    • Why ransomware is still relevant but no longer the only concern.
    • The growing risks of supply chain attacks, remote operations, and super dependencies (as seen in the CrowdStrike outage).
    • How attackers are weaponizing AI to accelerate attacks—and how defenders can use AI for faster detection and response.

    5. AI and OT: A Double-Edged Sword

    • How AI is reshaping the attack surface for industrial systems.
    • Why every company is already “in the AI game,” whether they realize it or not.
    • The three layers of AI to consider: AI used in cybersecurity, AI inside your operations, and AI in the wild used by partners and adversaries.

    6. The Biggest Misconceptions About OT Security

    • The “myth of the air gap”—why physical isolation no longer guarantees safety.
    • Common organizational blind spots: board confusion between IT and OT, fragmented responsibility, and lack of lifecycle thinking.
    • The need for Cyber Asset Lifecycle Management (CALM) to ensure long-term resilience.

    7. Building a Resilient Future

    • Why early planning and a holistic approach are key to managing future risks.
    • The importance of embedding security, governance, and ethics into every new AI or industrial project.
  • Verint Executive Reveals: The 3 Best Starting Points for Enterprise Agentic AI Adoption

    Episode Overview

    In this episode, Maribel Lopez sits down with David Singer, Global Vice President and Go-To-Market Strategy at Verint, to explore the rapid evolution from generative AI to agentic AI and how organizations can successfully implement AI solutions that deliver real business outcomes.


    Key Topics Discussed


    The Evolution from Generative to Agentic AI

    • Generative AI: Excellent at answering questions and synthesizing information from knowledge sources
    • Agentic AI: Takes the next step by actually executing actions autonomously, not just providing recommendations
    • The critical difference: autonomous decision-making versus rules-based automation


    Building Trust in Autonomous AI Systems

    • Start with human-in-the-loop monitoring for training and validation
    • Gradually reduce oversight from constant monitoring to spot checks
    • Apply quality monitoring practices to AI agents similar to human agents
    • Consider AI agents as “silicon-based employees” requiring training, access controls, and performance management


    Successful AI Implementation Strategies

    Start with Clear Outcomes: Define specific business goals before selecting technology

    • Focus on solutions that deliver outcomes, not just impressive technology
    • Begin with well-understood processes that can be enhanced rather than completely reimagined

    Three Proven Starting Points:

    1. Call Wrap-up Automation: AI-powered summarization reduces agent workload
    2. IVR Modernization: Convert top call flows to agentic conversational AI
    3. Quality Management: Scale from monitoring 1-3% of calls to near 100% coverage


    Vendor Selection Criteria

    • Proven outcomes at scale: Look for vendors with demonstrated success stories and customer references
    • Technology adaptability: Choose providers who can evolve with the rapidly changing AI landscape
    • Production readiness: “POCs are easy, production is hard” – prioritize vendors with production deployment experience


    Change Management for AI Adoption 

    • Deploy solutions that genuinely help employees first
    • Build internal champions through positive early experiences
    • Scale gradually to maintain trust and adoption


    Key Insights

    • Employee Experience Drives Customer Experience: AI solutions that improve employee satisfaction often lead to better customer outcomes
    • Observability is Critical: Comprehensive monitoring and quality management become essential as AI systems gain autonomy
    • Outcomes Over Technology: Success comes from focusing on business results rather than being enamored with the latest AI capabilities


    About the Guest

    David Singer is the Global Vice President and Go-To-Market Strategy at Verint, where he focuses on delivering AI-powered outcomes for customer experience automation. Verint has been incorporating AI into their platform for over a decade, evolving from call recording and workforce management to comprehensive CX automation solutions. 

    You can follow David here: https://www.linkedin.com/in/dwsinger/

    You can follow Maribel here: 

    Closing Thoughts

    Singer emphasizes two crucial points for organizations embarking on AI initiatives:

    1. Avoid spending significant resources on new technology only to use it exactly as you did before
    2. Always start with outcomes first – let business goals drive vendor selection, implementation strategy, and change management approaches