Tag: CIO

  • The Hard Part of Agentic AI Isn’t Building the Agent. It’s the Space Between Your Tools

    The Hard Part of Agentic AI Isn’t Building the Agent. It’s the Space Between Your Tools

    AWS spent its New York Summit keynote on the problem agent demos skip: getting work across the boundaries between your systems.

    By Maribel Lopez, Lopez Research | June 2026

    The agentic AI conversation has progressed through three stages over about two years, and the AWS New York Summit discussed aspects of the third wave.

    The first stage was to define the concept of an AI agent and provide companies with tools to build one. The second, where most vendors have spent the past year, was building the scaffolding to run agents in production, such as testing, observability, identity, memory, and governance. AWS calls its version Bedrock AgentCore. Microsoft and Google have built their own platforms, and NVIDIA’s NemoClaw added a security layer for open agents. Phase two solves important parts of the agentic AI landscape, and the industry is still working through these problems. Dr. Swami Sivasubramanian, VP of Agentic AI at AWS, named directly: “too many agents are stuck between prototype and production.”

    The third stage requires breaking down the data siloes and getting the various tools to work together. Sivasubramanian stated the problem plainly when he said, “The problem is not any single tool per se, it is the space between them.” It’s the fragments you need to finish a task that are scattered across Slack, email, a dashboard you haven’t opened in days, and a doc someone shared last week. Every login is, in his words, “another place where context goes to die.” And every time you’re the one connecting the dots, your momentum stalls.

    Today, you can get AI agents to work within specific boundaries such as your CRM, ERP, and Talent applications. The challenge arises when you need to get agents to work across various applications and data sources. The data is in different formats, lives in many places, and the ways it can be shared or accessed vary by source. When an employee is trying to complete a task, it’s a human orchestration engine with permissions that allow them to gather, synthesize, and complete tasks across the varied landscape. Eliminating the friction is exactly where AI agents become genuinely useful and genuinely risky at the same time because it crosses your data boundaries on your behalf.

    What made the problem statement credible at the AWS Summit wasn’t simply Amazon saying it. It was the buyer saying the same thing independently on stage. Lauren Woods, EVP and CIO of Southwest Airlines, described what the 2022 Winter Storm Elliott disruption taught her team: “It’s not just about systems working; it’s about how systems work together at speed and at scale.” Her systems did what they were designed to do. They just weren’t built to keep pace across the whole operation at once. That is the buyer-side version of the space-between-tools problem.

    From Copilots to Cross-System Work

    It helps to trace the path because the industry is solving these problems in sequence.

    We started with AI chat assistants and copilots. We gave them chat windows, connected them to a few tools, and they answered one question and forgot it. They worked in isolation. The original copilots were, in effect, better search bars. Useful, but bounded. Swami’s version of the same point: the promise was intelligence, but “what we got was a slightly faster search bar, and faster search doesn’t compound, it flatlines.” A faster search bar solves one problem, but the real work requires moving between islands without a human acting as the orchestration layer. To get to the next level, we need AI agents that operate across all your systems with identity, security, observability, and governance in place.

    Why Compounding Momentum Changes the ROI Math

    AWS’s term for what that unlocks is “compounding momentum”. The value of an agent isn’t the first task it completes. It’s the slope of improvement after that. Swami’s framing: “context is what makes your agent’s 10th decision better than its first.” Describing the organizations pulling ahead, he added: “Every task that their agents complete makes the next one smarter.”

    For a CIO, that reframes the business case. You aren’t buying a one-time productivity bump. You’re buying an asset whose return depends on accumulated context. It also means the cost of a stalled or siloed agent compounds in the other direction. Every month it isn’t crossing your systems is a month it isn’t getting smarter.

    The plumbing for this is the knowledge graph. AWS describes Quick service as “an agentic search layer that works across your entire data estate,” and the company reports its internal semantic store already handles more than 1.8 million requests a day. AWS also announced a new managed service, AWS Context, that “automatically builds a knowledge graph from all your existing data.” Amazon’s goal is to create the connective tissue among raw data, knowledge bases, and business relationships and deliver a single governed context layer that agents query at runtime. The context layer should be able to operate with multiple models, allowing agents to provide a more accurate answer versus a confident but incorrect answer.

    AWS Positioned Amazon Quick as an Overlay, Not a Walled Garden

    AWS spent real stage time on Amazon Quick, and the strategic pitch was explicit. Swami framed the market as a false choice between agents trapped inside a “walled garden” that only see their own productivity suite, and open tools that reach across systems but bring no governance, identity boundaries, or control over where data goes. His claim: “This is a false choice. Quick doesn’t ask you to choose.” Quick is positioned as a governed overlay that works across systems you already run, including Slack, Google Drive, OneDrive, Snowflake, and Databricks, with each action carrying its own audit trail.

    This is good positioning with real merit, and I’ve tested the functionality. It appears to work. Lauren Woods said she uses Quick “every single day,” and offered a concrete buyer outcome. The Southwest Airlines teams are “moving from looking at data after the fact to interacting with it in real time.” AWS also cited customer proof points, including GoDaddy saving a reported 15,000 hours of manual work annually.

    But the questions that decide whether an overlay lands in the enterprise aren’t answered by a demo. They’re answered by economics and commitment:

    • Licensing cost at full scale. An overlay that touches everything has to be priced so that “everything” is affordable across a large organization. This is the variable that quietly kills horizontal tools, and it’s the one buyers should model first.
    • Durability of the investment. Enterprise buyers have watched products get announced but then not maintained. It’s a fair question to ask whether Amazon treats Quick as a long-lived product line or an evolving AI moment. If it gets enterprises genuinely engaged, it’s a strong business for AWS, which is a reason for optimism about its staying power.
    • The adoption track record. Microsoft and Google have spent considerable effort getting copilots deployed broadly, and it’s been an uphill climb. To be fair, both have meaningfully advanced their offerings in recent months so that the pattern may be shifting. AWS enters a competitive landscape alongside other hyperscalers and solutions from model providers such as Anthropic’s Claude Cowork. Each solution from each vendor has its own merits and detriments, which also makes it hard to compare apples to apples.

    None of that argues against Quick. It argues for evaluating it on what demos never show. For any solution, you need to consider the total cost at full deployment, whether it integrates with other tools you use, and whether you believe the vendor will still be investing in the product in three years. Building an agent is no longer the hard part. With the right tools and experimentation, you can build an AI agent that works. The connective tissue, such as memory, persistent context, the knowledge graph, and governed cross-system access, is what determines whether an agent finishes the job or stalls at the first boundary. The question isn’t whether agents can do the work. The question is whether your data, your identity, and your governance strategies are ready for software that crosses all of them on your behalf.

  • The Enterprise AI Time Bomb Is Ticking.  Cisco Shares Its Plan.

    The Enterprise AI Time Bomb Is Ticking. Cisco Shares Its Plan.

    At Cisco Live in Las Vegas this week, the company delivered a sobering security message for enterprise buyers. AI helps the bad actors move faster, and the window to get ahead of it is closing quickly.

    “AI changes the speed of defense. The bad corollary to that is it’s empowering our adversaries at a pace that we’ve never seen in our careers. These models are as bad today as they’re ever going to be,” Cisco CEO Chuck Robbins told the packed keynote audience — a line that landed with more weight than a typical tech conference applause line. He wasn’t talking about AI being ineffective. He was talking about it being weaponized.

    A New Kind of Threat

    The cybersecurity industry has spent years warning about AI-powered attacks. What’s changed in 2026 is that frontier AI models — particularly Anthropic’s Claude Mythos have made those warnings concrete.

    What sets Mythos apart from prior AI models is not general intelligence but what it can do in a cybersecurity context. According to Anthropic, it can autonomously identify and exploit software vulnerabilities at a level that outpaces almost all human security experts. In controlled testing, the model has been shown to identify thousands of zero-day vulnerabilities over several weeks — a pace no human security researcher or team could match.

    The dual-use nature of that capability is what makes Mythos a defining moment for enterprise security. The same model that can find and patch vulnerabilities at unprecedented speed can, in the wrong hands, find and exploit them. CrowdStrike’s 2026 Global Threat Report found an 89% increase in attacks by adversaries using AI — and Mythos-class capability represents a meaningful step change in what those adversaries can bring to bear.

    Anthropic has acknowledged that “models of this capability level require stronger cyber safeguards before they can be generally released,” which is why public access has been withheld while safety work continues. But what this tells us is that enterprises must prepare for a post-Mythos threat environment where any number of increasingly capable open and commercial models can and will help bad actors exploit vulnerabilities in legacy or unpatched systems. We can also see that patching isn’t enough.

    Robbins warned that the capability floor for AI-assisted attacks had just risen significantly and will not come back down. The most alarming shift is speed. Where it once took days or weeks for bad actors to move from a disclosed vulnerability to a working exploit, that timeline has compressed to minutes. Cisco’s own security team demonstrated the flip side of that same capability. Robbins said in the past eight weeks, Cisco used AI to scan 1.8 billion lines of code across 25 programming languages. Before these models existed, Robbins said, that would have taken approximately eight years.

    The implication is uncomfortable but unavoidable. The same technology accelerating legitimate security work is accelerating attacks at the same pace. Neither side has an obvious advantage, and the defender’s job — protecting a complex, distributed enterprise — is structurally harder than the attacker’s.

    Agents Make Everything Harder

    If AI-powered threats were the only problem, that would be manageable. But Cisco’s President and Chief Product Officer, Jeetu Patel, outlined a second, compounding challenge: the rapid proliferation of AI agents is creating an attack surface that enterprises are almost entirely unprepared for.

    The AI industry evolved from chatbots that respond to questions to AI agents that can act autonomously. Patel said Cisco’s research found that a single AI agent generates roughly 450% more network traffic than a human performing the same task. Multiply that by thousands of agents running across an enterprise, and the infrastructure and security implications are significant.

    More importantly, agents have access to tools. Agents call APIs, query databases, submit code, and interact with external services. The goal of an agentic AI system is to perform tasks without a human in the loop. Patel’s framing was blunt: “Agents are like teenagers. They’re supremely intelligent, but they have no fear of consequence.”

    Agentic AI creates new attack vectors that aren’t easy to manage with existing solutions. For example, prompt injection attacks can manipulate an agent’s behavior. Data poisoning can corrupt its decision-making. Meanwhile, bad actors can perform tasks at high speed with a compromised agent  before anyone notices anything is wrong.

    While agentic AI has great potential, most enterprises lack the proper visibility, security and management to handle agents. Companies need a systematic way to know how many agents are running in their environment, what those agents are authorized to do, or whether they are behaving as intended. This is one security gap Cisco is racing to close alongside other security companies, hyperscalers, and startups.

    The Identity Problem Nobody Has Solved

    Businesses are just waking up to the problem of non-human identity posed by AI agents. Every person accessing a corporate system has an identity with a role, credentials, and permissions. Machines, services, and AI agents largely do not, at least not in any consistent or governed way.

    In May, Cisco acquired Astiix Security, an AI company focused on the non-human identity category.  Before enterprises can enforce meaningful controls on agent behavior, they need a reliable way to know which agents exist, what they have access to, and what they should be allowed to do. The platform helps organizations discover, govern, and protect machine identities, preventing unauthorized access and securing AI agents from malicious attacks. Cisco can integrate this technology into its Cisco Identity Intelligence and zero-trust products, such as Duo and Secure Access, to safely manage the proliferation of AI agents.

    This is not a theoretical future problem. Enterprises are deploying agents today, and most are doing so without the right identity infrastructure to govern them. If they deploy agents within a specific SaaS stack, permissions and governance are typically handled by that software. Once we start discussing multi-agent workflows that cross applications, the challenge becomes more complex. Astrix gives Cisco more capabilities to support identity for an agentic future.

    Cisco’s Response In Three Moves

    Beyond the Asterix acquisition, Cisco announced a set of products and capabilities aimed directly at the threat landscape it described.

    1. AI Defense, extended for agents. Cisco launched AI Defense roughly 18 months ago to provide visibility and guardrails for AI models and applications. The updated version adds capabilities specifically for agentic deployments: adaptive testing, behavioral guardrails, security for agentic supply chains, and support for all major agent platforms, including Claude, Codex, and OpenAI.
    2. Zero trust that gets an update for AI agents. The traditional zero trust model is built around access control: verify identity, grant minimum necessary permissions, and monitor behavior. Cisco correctly argues that today’s access control is insufficient for agents. What enterprises need is action control — the ability to intercept and verify every action an agent takes, not just whether it was authorized to log in. This is a meaningful architectural shift, and one that Cisco is embedding into its platform rather than offering as a standalone product.
    3. An agentic SOC. The cybersecurity talent shortage is severe. Approximately 4 million positions go unfilled annually in the US alone, according to Cisco. The volume of security alerts already exceeds human capacity to investigate. Cisco’s answer is an AI-powered Security Operations Center where agents autonomously triage alerts, identify anomalies, and, in time, predict and prevent breaches. The foundation is Cisco Data Fabric, a Splunk-powered platform that ingests petabyte-scale telemetry from network, security, application, and third-party sources.

    The Galileo Acquisition: Watching the Watchers

    Governing AI agents requires knowing what they are doing — not just whether they are authorized to act, but whether they are producing the outcomes they were designed for. This is the observability problem, and it is harder than it sounds.

    To address it, Cisco acquired Galileo, an AI observability company founded by researchers who previously worked with Google and DeepMind. Galileo’s technology powers what Cisco calls full-stack agent observability. This is visibility into infrastructure performance, model behavior, application runtime, and agent output quality. It also includes whether agents consume tokens at a sensible rate.

    That last point surfaced repeatedly during the keynote and reflects a real operational concern. A runaway agent that has been misconfigured or has drifted from its intended behavior can consume an entire organization’s annual AI budget in a matter of days. Token cost management is not a glamorous feature, but it is required for this new era of infrastructure.

    Cisco Cloud Control: The Platform Beneath All of It

    One of the more surprising announcements was the newly launched Cisco Cloud Control. For anyone who’s followed networking and Cisco for years, the concept of a true unified management console has been discussed for many years, and it’s devilishly difficult to execute. Every part of the portfolio had its own management tools that were loosely coupled at best, if at all. Cisco Cloud Control aims to be a new unified management platform that consolidates the company’s entire product portfolio under a single interface with single sign-on. Cloud Control is the operational layer through which Cisco intends to deliver its AI security and observability strategy.

    The security-specific capabilities embedded in Cloud Control, such as agent security monitoring, cross-domain threat correlation, and policy enforcement in natural language, represent a meaningful shift from how enterprise security tools have historically operated. Rather than logging into separate dashboards for networking, security, and operations, administrators can query their entire infrastructure environment in natural language and receive correlated, actionable insights across domains.

    The demos made it look like Cisco had finally cracked the code. Whether that vision holds up at enterprise scale remains to be tested. But the architecture Cisco described — silicon to semantics, from custom networking chips to AI agents operating on top of them — reflects a deliberate bet that the company’s control of the full infrastructure stack is a genuine competitive advantage in an AI-defined security landscape.

    The Reality. Enterprise AI Threats Are Real.

    Cisco’s keynote was, of course, a product announcement. But stripped of the stage production, the underlying argument is sound and worth taking seriously.

    AI is compressing attack timelines. Agents are expanding the attack surface in ways that existing security architectures can’t handle. The cybersecurity workforce is not growing fast enough to compensate. And most enterprises are deploying agents today without the governance infrastructure to know what those agents are doing, let alone control them.

    The organizations that will navigate this well are not necessarily the ones that move fastest. They are the ones that treat agent governance — identity, authorization, behavioral monitoring, and action control — as a first-class infrastructure concern rather than an afterthought. Enterprise technology leaders want and need their existing technology stack providers to evolve their security and management stacks to support AI threats. Cisco is making a significant bet that enterprises will pay for that infrastructure. Given the threat landscape it described, the bet seems rational.

    This article was originally published on Forbes.com.

  • Four Enterprise AI Spending Pitfalls  and How to Avoid Them

    Four Enterprise AI Spending Pitfalls and How to Avoid Them

    By Maribel Lopez, Lopez Research

    A few practical thoughts on where AI spending goes wrong — and what separates the organizations getting it right. Most organizations aren’t failing at AI because the technology doesn’t work. They’re failing because of decisions made before a single model was deployed. Decisions such as how to scope and fund an initiative, what success was supposed to look like, and whether anyone was measuring whether they got there. I recently joined Tom McHale, CFO and VP of Business Operations at SunStream Business Services and Apptio, an IBM company, for a webinar conversation about where spend management goes wrong.   McHale shared how he has navigated technology trade-off decisions as a CFO for years. Our observations converge on the same patterns. Here are the four pitfalls McHale and I spoke about during the session — and what organizations can do about them. 

    Pitfall 1: The Board Issues an AI Mandate Without Funding the Foundation

    Seventy-two percent of companies Lopez Research surveyed had received a directive from their board or senior management to implement AI last year. Most of those mandates arrived without acknowledging the trade-offs required to fulfill them. The pressure is real, and organizations that don’t leverage AI within their apps and services will fall behind. The problem is fixating on the technology without resourcing the operational requirements underneath it. To move into AI effectively, you need data quality, governance, and a clear plan for budgeting for ongoing costs. Boards often ask for AI outcomes without understanding the foundational work it takes to deliver them. There is also a funding gap that sneaks up on organizations. Many companies attempted to fund AI by reallocating from existing cloud or operations budgets. That worked at the margins. It does not work at scale. Internal capital reallocation as the primary AI funding source jumped from 50% to 67% in a single year in Apptio’s 2026 Technology Investment Management Report. At some point, there is not enough money in the couch cushions to do what is being asked. McHale also shared that most management teams expect first-class technology at bargain-basement prices. He brought up the reality many organizations face when he shared an example: you can’t always make trade-offs between technologies, such as funding a batch scheduler in a mainframe environment or investing in AI. You need both. What to do: Before responding to an AI mandate, attempt to map the real cost. That means data preparation, governance infrastructure, security review, and ongoing model costs — not just tool licenses.  Bring that full picture to leadership. The conversation about tradeoffs is easier to have before you start spending than after you have run out of budget. 

    Pitfall 2: Failing to Define Problems and Measurable Outcomes

    In the early days of AI adoption, running experiments made sense. Organizations needed to learn what the technology could do. That phase is over. In 2026, no one should be running an AI proof of concept without a production path and a timeline. In research Lopez Research conducted in mid-2025, 85% of companies said they were struggling to find AI ROI. When we looked at why, three causes kept surfacing. First, there was a data quality problem. Second, the use case was too vague to measure. Third, there were no metrics, monitoring, or observability in place to gauge whether the initiative was working. The fourth issue is that fewer than half of the organizations had a governance strategy, which tends to create downstream compliance and legal exposure. All these solutions are foundational solutions that require time and money. And we didn’t even discuss the cybersecurity concerns, which is always one of the top three technology spending categories. Selecting AI technology solutions before defining what you are trying to accomplish is like buying a full set of hammers, screwdrivers, and impact drivers before knowing what you are building. The tools are not the strategy. What to do: Understand what specific organizational strategic goal or KPI you’re trying to achieve before you start. “Improve customer experience” is too vague. Whereas something specific enough to measure, like reducing billing errors by 80% to improve customer satisfaction, or improving deployable software development velocity by 15%, allows you to understand the impact and the metrics, and provides a set of requirements for AI tool selection. If you cannot define success before you deploy, you are not ready to deploy. Note: I am researching the merits and detriments of an “AI use cases” versus “creating reusable AI skills/capabilities with AI agents”. See the March Newsletter on Yumm Brands for more on this. Given that I don’t yet have solid guidance on how to build and scale reusable AI skills, I maintain that you need to understand which real business problems you need to apply AI to, which helps winnow the platform selection. 

    Pitfall 3: Assuming the Budget You Can See Is the Actual Spend

    Shadow AI is this year’s shadow IT. Every technology wave produces a version of this problem. Employees find tools that help them work faster, stand them up without IT involvement, and pay for them however they can — personal credit cards, discretionary budget lines, expense reports. It adds up quickly and never shows up in the official budget. McHale shared a real example from a prior role. After conducting a full audit of actual spend at a Fortune 500 organization, the actual IT budget was double the official number. Shadow IT had been absorbing that difference for years. With AI tools accessible to anyone with a credit card and a browser, the same dynamic is accelerating. The financial risk is significant. An employee can spend $20 to $300 per month on AI tools, such as ChatGPT and Claude Code. Untracked AI spend scales fast across an organization. But the non-financial risk may be more serious. Unvetted tools accessing company data, unapproved models processing sensitive customer or employee information, and no audit trail if something goes wrong. The governance and security risks posed by shadow AI are not hypothetical. McHale put it well: defining clear objectives at the start, having someone accountable for documenting them, and treating governance as an ongoing discipline rather than a one-time checkbox is what separates organizations that can scale AI from those that cannot. Organizations that lack centralized visibility into AI spend will discover this the hard way. When it comes time to request a budget increase for next year, leadership will ask why more money is needed, given that things seemed to work fine with what was available. The answer — that it was all going on personal credit cards — is not a conversation anyone wants to have. What to do: Treat AI spend tracking as an urgent priority, not a future initiative. Establish a process for centralizing AI tool procurement now, or at least provide guardrails for AI spending. This is not about restricting what employees can use. It is about knowing what is being used, what it costs, and what data it can access. Shadow AI that stays invisible today becomes a budget and compliance problem tomorrow. 

    Pitfall 4: Confusing Operational Maturity with Technical Maturity

    This is one of the more subtle pitfalls, and it trips up organizations that are genuinely sophisticated technically. A company can have strong cloud infrastructure, capable engineering teams, and real AI experience — and still be operationally immature in managing AI investment. The gap is most evident in IT financial management. IBM Apptio’s survey data shows that 59% of ITFM professionals are confident their forecasts are highly accurate. The tools and processes many teams rely on to produce those forecasts were not designed for the pace or variability of AI spend. AI costs scale with usage in ways that are difficult to predict. They appear across every function in the organization. They change as models are updated, as usage grows, and as new capabilities are deployed. Managing that with processes built for a slower-moving environment creates real risk, even when the people running those processes are skilled and confident. Yet the potential visibility gap is where budget surprises live. What to do: Audit your financial management practices against the specific demands of AI spend. Variable usage-based costs, multi-cloud workloads, hybrid AI, and distributed AI tools across business units require practices built for that environment. The goal is not to find fault with what you have been doing. The goal is to identify where the current setup leaves gaps that AI spending will widen. 

    The Pattern Behind the Pitfalls

    These pitfalls are not independent. These pitfalls interconnect. An AI mandate without a real budget forces organizations to fund initiatives on the margins, leading to cuts in data, governance, observability, and security. Without visibility into spend, shadow AI accumulates, and real costs stay invisible. Without defined success metrics, there is no way to know whether cutting those corners mattered. The organizations that are getting AI right did not avoid these problems by being smarter. They avoided them by doing the less exciting work first: defining use cases clearly, understanding true costs before committing, building governance before it was required, and measuring outcomes from day one.While the technology changes,  the adoption challenges remain remarkably consistent. Every wave has its version of the couch cushions problem — organizations moving fast on an exciting new capability without the financial and operational discipline to sustain what they are building. Focus on the foundation first. The shiny AI tools can follow. Subscribe to my LinkedIn newsletter here. Also, you can subscribe to the AI with Maribel Lopez podcast on your channel of choice here.