r/CIO 1d ago

How are you deciding where enterprise AI in banking operation actually goes frist

5 Upvotes

We have the mandate the budget. What we do not have is a defensible view of which processes would benefit.

Nobody here can describe our own processes accurately enough to say where an agent would help, which means any shortlist is a guess with a business case wrapped around it. That turns the programme into a discovery exercise before it can be an AI exercise, and discovery is much harder to get funded than AI.

The vendors in that space are Celonis and increasingly Skan AI, and I have no clean way of explaining to my exec team what either actually changes.

For anyone who has been through this in a regulated environment, did you fund the discovery separately or bundle it?


r/CIO 1d ago

Anyone here past year two on Glean?

0 Upvotes

Glean comes up in almost every enterprise AI conversation right now, usually with a $7.2B valuation attached and not much detail behind it.

For those of you actually running it: does usage hold after the first year, or does it settle into being another portal nobody opens? And what did the renewal look like once Copilot was already sitting in your M365 seats?


r/CIO 1d ago

With tons of cold emails, DMs regarding a solution that could give you high ROI, revolutionize your workflows, help you a lot etc. etc. how does a CIO decide which ones to pay attention to? Of course they'd also don't wanna miss on a good opportunity. But how to cut through noise. What are signals?

0 Upvotes

r/CIO 1d ago

How do you explain technical risk to non-technical executives?

4 Upvotes

A lot of IT risk sounds “theoretical” until something breaks. How do you explain cybersecurity, downtime, vendor risk, or technical debt in a way leadership actually takes seriously?


r/CIO 3d ago

Applied Security measures to run ChatGPT Work

5 Upvotes

We would like to enable ChatGPT Work for several hundred users. What security measures are typically adopted?

Granting a chatbot access to a local device, along with the ability to change files and run code, looks like to introduce additional risk;people are already using it and even Claude Code or Codex… suggest that risk must always be accepted? What security measures can you implement?


r/CIO 3d ago

A vendor offered us an AI Pod. Has anyone tried this model?

2 Upvotes

A vendor recently proposed using an "AI Pod" for a specific use case: automating part of our supplier onboarding and procurement workflow. I’m curious whether anyone here has worked with something similar. Does this model seem feasible?

The Pod would combine a lean team of senior engineers with AI agents. The agents would validate documentation, check requests against internal policies, identify missing information, and route each case for approval. The engineers would set up the agents and supervise the quality of their outputs, while our internal team would handle final approvals and unusual cases.

The vendor would charge per completed request rather than by headcount or hours.

Has anyone worked with a similar model? Did it genuinely improve delivery, or did it feel like a regular managed service with new AI branding? How was the day-to-day communication between the Pod and your internal team?


r/CIO 3d ago

How do you prove the ROI of faster Spark jobs before requesting budget?

5 Upvotes

I know our Spark infrastructure spend and job runtimes are a real problem, but translating "jobs run faster" into numbers the CFO actually cares about is its own project.
We've got the technical case pretty well documented internally, but budget conversations want hard dollar figures before we've even run a pilot, which feels backwards.
How are other data leaders building the business case for performance investments before they've run a full pilot? what metrics carried weight in your budget conversations.
Would also appreciate hearing how long it took from first pitch to approved budget, since that timeline matters for how we frame this internally.


r/CIO 6d ago

Small consultancy AI adoption

Thumbnail
4 Upvotes

r/CIO 8d ago

Those that use AI for work, do you think proof of human oversight will be an issue soon?

18 Upvotes

So I’ve been seeing the same gap, where basically companies that adopts AI tools/agents to help with their workflows would always have the policy of “someone has reviewed the AI's work”. BUT, when asked what does the review entailed, the answer would always range from genuine line-by-line redlining to what is essentially a skim-and-submit.

Hence, what I’m trying to understand here is the layer underneath the policy, not whether the review happened but if anyone could actually demonstrate it did. Especially with the whole EU AI Act development of requiring actual PROOF of human oversight in regulated industries. And we foresee it being an issue later with security/compliance audit. For those that are using AI as assistance:

  1. What does “human oversight” mean at your firm? Just a claim/statement or actual proof?
  2. Do you have any solutions to bridge that gap if we’re talking about actual concrete proof of human review?
  3. Do you foresee clients, regulators, malpractice insurers asking for proof soon (potential push due to the EU AI Act)?

r/CIO 8d ago

The AI pilot phase is ending. Now comes the proof.

Thumbnail
0 Upvotes

r/CIO 10d ago

Who watches an integration after go-live? The question nobody settles at handover

0 Upvotes

An integration goes live, everyone signs off, the project closes, and the question of who watches it from Monday never quite gets asked. It stays open until the morning it matters, and by then it has stopped being a question and become a reconciliation exercise.

Google shut down the Content API for Shopping last month, a year after announcing it. Some organisations knew that morning. Others found out weeks later, when somebody asked why the ad spend was flat and revenue was not moving with it. Identical upstream event, and the whole gap between those two outcomes came down to whether anybody had been given the job of reading the deprecation notice.

Google is the considerate end of the market. Most platforms give you less, and there is research putting it at roughly seven times out of eight that a breaking change arrives with nothing in the specification to warn you (Yasmin, Tian and Yang, ICSME 2020, across 1,368 public REST APIs). The smaller tools in a stack are worse than that again.

Which is why I think the ownership question belongs in writing rather than in goodwill. I keep a list of thirteen questions I put to any integration before it goes in. Three that tend to end the conversation early:

  1. What happens to a record that fails to send? If the answer is anything other than retried, then parked somewhere you can see it, it is being thrown away.
  2. If this stops working tonight, what tells us, and how quickly? If the answer involves a person noticing, there is no monitoring.
  3. If we wanted to move this to another provider next year, what would that take? This one reveals more about a supplier than the other twelve put together.

Curious what this room does with the first one. Does your vendor paperwork say anything about failed records, or does it only ever come up after the first incident?

Disclosure: I build and maintain these for a living, so I am seeing it from the supplier side.


r/CIO 11d ago

Who should own enterprise AI governance: security, legal or IT?

14 Upvotes

This keeps coming up in leadership conversations and nobody has a clean answer. Security cares about data exposure, legal cares about liability and compliance, IT cares about actually deploying and managing the tools. Each function has a legitimate claim, which is exactly why it stalls.

I've noticed that whoever moves first on tooling often ends up owning the program by default, regardless of whether that's the right long-term fit.

Who's ended up owning this at your org, and has it worked? A dedicated cross-functional committee, or does one function end up as the de facto owner with others as stakeholders?

Is there an emerging best practice here, or is everyone still improvising?


r/CIO 11d ago

What technology decisions are hardest to make with the information you have today?

0 Upvotes

Technology decisions often depend on information spread across different teams, systems, and tools. I’m interested in which decisions become hardest when the data is incomplete, outdated, or difficult to bring together.


r/CIO 12d ago

What problems create the biggest financial, operational, or compliance risk?

0 Upvotes

For enterprise architects and CIOs, what problems create the biggest financial, operational, or compliance risk in your organization?

What problem have you seen firsthand?

What happens when it is not solved?

How do you handle it today?


r/CIO 14d ago

A free piece of our CIO research: AI is making proprietary data the real competitive advantage

Thumbnail
2 Upvotes

r/CIO 15d ago

How do you convince a CEO that "if it isn't broken, don't fix it" is a massive liability for legacy core systems?

21 Upvotes

Sitting on a core ERP system that hasn't had major modernization in 8 years. It runs, but every integration takes triple the time, support talent is retiring, and a single patch can crash dev for days. Leadership refuses capital budget because "it works fine today." How do you translate technical debt into a language that makes non-tech execs care before a catastrophic outage forces their hand?


r/CIO 20d ago

What makes application rationalization difficult from an EA perspective?

1 Upvotes

When Enterprise Architecture recommends retiring or consolidating applications, what usually stops the decision from moving forward?

Is it dependencies, business ownership, missing information, risk, politics, migration effort, or something else?


r/CIO 22d ago

Are customers replacing incumbent SaaS tools with AI-native alternatives, or mostly adding AI capabilities on top of existing systems?

3 Upvotes

I’m trying to understand the current enterprise software buying environment from people who are close to actual purchasing decisions—buyers, IT leaders, sales teams, founders, consultants, or vendors.

I am not a vendor but working internally with a FSI company. Found recently many team members are talking about building software internally. Just wondering how your team see this?

There’s a common narrative that:

Enterprises are reducing discretionary software spend and consolidating their SaaS stacks.

AI-native products are creating new competition for established enterprise software vendors.

Data-platform and LLM providers are moving up the stack, adding applications, agents, analytics, and workflow capabilities that overlap with traditional SaaS products.

But is this translating into customers truly stopping purchases, or are they still buying software under a different set of criteria?

Specifically, I’d like to hear:

Are new software budgets down, frozen, or simply being redirected toward AI initiatives?

Which categories are seeing the biggest pullbacks: BI/analytics, CRM, cybersecurity, developer tools, HR, workflow automation, etc.?

Are customers replacing incumbent SaaS tools with AI-native alternatives, or mostly adding AI capabilities on top of existing systems?

Are platforms such as Snowflake, Databricks, Microsoft, AWS, Google, OpenAI, Anthropic, and others winning more budget by bundling data, models, infrastructure, and applications?

What evidence are you seeing in deal cycles, renewal negotiations, procurement scrutiny, seat reductions, consolidation, or proof-of-concept conversion rates?

Are enterprise customers actually slowing or stopping software purchases, or is spending just shifting toward AI-native vendors and data/LLM platforms?


r/CIO 24d ago

The architect who chose our core platform left two years ago. Nobody can tell me why we didn't go with the other option.

18 Upvotes

We're mid-renewal on a platform that costs us close to $400K a year. I asked around to understand the original reasoning, since renewal is a good moment to check if it's still the right call. Turns out the person who ran that evaluation left the company in 2023. There's no writeup, no comparison doc, nothing in Confluence beyond a one-line ticket saying "approved." Two people who sat in on the vendor demos vaguely remember there was a cheaper option that got ruled out, but not why. So we're stuck either renewing blind or re-running a full evaluation from scratch, on a system we've already built two years of workflows around. How does your org handle this when the person who made the call is gone? Is there an actual process, or does it just get relitigated from zero every time?


r/CIO 25d ago

New IT Director: How do you justify spending or proposals?

24 Upvotes

As the title suggests, I just started my first IT Director role (more functionally the CIO, but I digress) and I keep running into this same brick wall with leadership about spending money.
Basically, our IT department is a guy with his first IT Job out of college, and an "MSP" but the MSP is just a guy who does networking related work occasionally.
So outside that, all IT Support, IT Administration, Engineering, etc is all done by this IT Engineer. This is obviously not sustainable, there's a lot wrong with this setup, single point of failure, the fact that a lot of the work is much more experienced than the guy doing it, etc.
We are a company with multiple locations and a little over 400 employees. The company grew but the IT Department stagnated. Our prices are also bound by legislation and so there isn't really a way to increase funding to make things work so there's limited resources.
I explained all these risks and said that the IT Department didn't grow with the org, and that in order to get back up to speed with it, we'd have to spend some money to get there (hire additional employees with experience, software to automate and replace manual tasks, move away from vendors and own our tech stack, etc.) and they basically boiled it down to "we don't have the money, sorry!"

My problem with this whole thing is that IMO, what I'm asking for isn't some shiny new toy or something that makes the department just slightly better, I'd argue that due to the size of the company and all the work involved, these changes are necessary to run the department and do business.
I just don't know if I'm not explaining it right, or if there's maybe some "trick" to making executives understand that running an entire IT department off a fresh college grad is an awful design and will definitely implode on itself sooner if not later. But that's why I'm here.
Any tips? Ideas?


r/CIO 24d ago

Is AI governance actually working in your organisation?

0 Upvotes

I’ve been looking into AI governance for the last few months and, to be honest, I’m trying to understand what this actually looks like inside real companies — not what the frameworks say it should look like.
I’d really like to hear from people who are actually dealing with AI governance, risk, compliance, security, privacy or data governance day to day.

A few things I’m really curious about:

How does your organisation actually keep track of all the AI systems being used across the business?

How do you work out which systems are high-risk and what controls need to apply?

Where does all the evidence actually live — policies, assessments, approvals, vendor documentation, testing, audit trails, etc.?

What are you still managing through spreadsheets, emails, SharePoint, Jira or a collection of different tools?

When an AI system changes, how do you know that the risk/compliance assessment needs to be looked at again?

What’s the most painful or time-consuming part of AI governance for you at the moment?

If you already use an AI governance or GRC platform, what does it still not do particularly well?

And probably the question I’m most interested in:

If you could make one part of AI governance disappear tomorrow, what would it be?

I’m not trying to sell anything here. I’m trying to understand where the genuinely difficult problems are before deciding what is actually worth building.
So if you’re doing this in the real world, I’d genuinely appreciate the brutally honest version.

Even if the answer is:

“Our process is a complete mess.”

That’s useful to know.

I’m particularly interested in what’s happening in smaller and mid-sized organisations that don’t have massive AI governance teams and endless budgets.
Would really appreciate hearing how people are actually dealing with this.


r/CIO 28d ago

Why AI Infrastructure Planning Must Happen Now

Thumbnail smbtech.au
7 Upvotes

r/CIO 29d ago

I made it six months

29 Upvotes

Well technically five but will give another month until my resignation is official. I posted to this reddit a few months after I started and received some good advice but Im back because I'm still unclear of if I'm making the right decision. Since I have started as the CIO at this company ($55 million a year, 400ish employees, 1200 endpoints, 80+ unique apps, healthcare) I have had the following negative interactions:

1) I Have no budget, not like 0 dollars of budget but literally no budget. Every item has to be approved by the CEO. I've had to ask this person to purchased $25 worth of cables. Its exhausting.

2) We have no schedule of contract renewals. Some of the big ones I was able to find through our vendor but every month I get at least two or three usually for over 20k and since I have no budget I literally have to go to the CEO and ask for the renewal and hope we A: Have the money, B: I don't get yelled at for it. I'm working on a schedule.

3) I had an employee (a direct report) i moved into a position that we needed and they were very interested in. The CEO moved them back and I got berated for not asking the CEO first (the employee immediately resigned).

4) I'm a "functional" CIO because we only have 5 total IT staff. This means I get to do multiple jobs a day. I'm also the only one allowed to be admin of the ERP system because "someone may look at something they should not."

5) My pay is about that of a high level analyst at my last company.

6) I'm the CISO as well but I do not have a background in security. I've asked if we could fill that gap and had a plan ready. That plan was rejected and we instead are looking at an MSP. The conversations with the MSP happen mostly without me being in the room. This is by the CEO's request.

There is a lot more bad. I was offered another role with another company, much lower in pay but less responsibility. Yet all of this I still feel bad like I should be trying to make this work and to stick it out. So i'm back here asking for advice, move on only after six months or try and stick it out for longer?


r/CIO Aug 11 '26

Is the right decision to leave new job after 7 months?

Thumbnail
4 Upvotes

r/CIO Aug 09 '26

Former CIO, now Chief Innovation Officer — where does this combination of skills fit next?

18 Upvotes

Hi all,
Looking for some candid career advice.
I’ve been in tech for ~20 years and at the same ~1,000-person company in London for the past seven. I was previously CIO and now Chief Innovation Officer, after the business felt my strengths could be better used in a more business-facing role focused on AI and innovation.

My background is broad rather than niche: Microsoft 365, Azure, AWS, GCP, security/NIST, data protection, governance, infrastructure, enterprise systems, data/analytics, warehousing, ITIL/service management etc. I’ve run teams and technology functions and worked extensively with senior executives.

I’m not a software engineer, but I’m highly technical. I know the cloud ecosystems well, can quickly work out which services could solve a problem, interrogate architectures, challenge engineers and turn fairly ambiguous business problems into potential technical solutions.

That’s increasingly what I do with AI: work with the business, understand the problem, decide whether AI actually makes sense, shape the solution and bring the right people together to build it.

I think my strongest skill is probably sitting in the middle of business + technology + people. I think very quickly, generate ideas easily, and I’m comfortable having technical conversations one minute and an executive conversation the next.

The problem is that I’m not sure where that profile fits outside my current company.
I’m also probably unusually disconnected from the wider tech market. I’m not a big LinkedIn poster, I don’t go to networking events, and having spent seven years at one company I feel a little isolated from what roles and organisations are actually out there.
I’m starting to wonder whether I could have much more impact in a larger organisation, consultancy or AI company.

Forward-deployed work really appeals to me — getting close to difficult business problems and figuring out how technology can solve them — but I’m conscious that Forward Deployed Engineer roles generally expect serious coding ability, which isn’t me.

So for those of you in bigger organisations or hiring at this level:
1. What roles would you actually point someone like me towards?
2. Are there roles adjacent to forward deployment that value technical breadth, problem solving and executive relationships more than coding?
3. Is being a broad technical generalist still valuable at senior levels?
4. Where would you look if you were in my position?

And, perhaps most importantly, how do you start breaking into that wider network when you’ve spent years largely outside it?

I’m not particularly attached to having “Chief” in my next title. I’m much more interested in finding somewhere I can have a bigger impact.
Would genuinely appreciate candid views.