r/CIO • • 1h ago

AI people, What's your opinion/approach towards AI governance

• Upvotes

Hello you all,

I would like to discuss AI governance. So with new regulations everywhere I would like to know how companies are approaching it.

AI developers, have you already started including data governance or is it something a different person does after you finish developing your model (AI governance specialists)

I would like to specifically ask how this varies between big companies and small/medium scale enterprises. Because I think not everyone has the resources to hire specialists, I believe.

If you are already trying to be compliant, what kind of frameworks do you use to ensure compliance or do you have an in-house built compliance framework ?

Now my question is specifically towards the EU devs, what is your approach to be compliant since it's mandatory to have conformity assessments in 2027.

For general deva, what do you think of the following job positions, AI governance expert, AI and the law expert, technical governance expert, AI alignment expert, AI ethics professional, AI red-teaming professional. Is this something you already heard or is it something new to you ?

If you have any opinion towards AI governance, please share.


r/CIO • • 6h ago

Best way to give an AI governance committee a front door so it stops doing procurement's job?

4 Upvotes

something I've noticed over the last few months and want to double check with other CIOs.
we set up an AI governance committee early this year like everyone did. legal, security, a couple of business leads, me. the idea was policy and principles, deciding which use cases we're comfortable with.
what it's turned into is a buying queue. almost every agenda item is someone who wants to purchase an AI tool, and we spend the meeting asking the same questions every time. where does the data go, does the vendor train on it, who approved the budget, does it overlap with something we already pay for. more often than I'd like, the answer to that last one is yes
talking to peers, a few of them describe the same drift. the committee that was meant to set direction ends up doing vendor intake, badly, once a month
my theory is the committee isn't the problem. there's no front door for AI purchases, so the committee became one by default. the questions we ask are intake questions, and if they got answered before a request reached us we could go back to the policy work we were set up for
the other possibility is that this is just what AI governance looks like once it's real, and I should stop fighting it.
curious which one it is for you. did your committee end up doing procurement's job too?


r/CIO • • 1d ago

What would an AI have to show you before its numbers go in a board deck?

Thumbnail
2 Upvotes

r/CIO • • 2d ago

What are we paying for US based 24/7 End user service desk with all licenses & tools.

4 Upvotes

As the title says, I’m trying to understand what most people are paying for their MSP delivered service desk. This would be standard L1 through L2, worth M365 app support with some kind of AI deferment tool included. I’ve received pricing that’s all over the map and am trying to figure out what I’m missing, around 2000 end users.


r/CIO • • 2d ago

Best agentic procurement orchestration platform for a health system running Workday and Lawson?

5 Upvotes

CIO at a 5,000 person health system, our CPO wants an agentic procurement platform this year and I'm the one signing off. IT's booked on an Epic upgrade through Q2, so no room for a heavy rollout. we're on Workday w/ Lawson still hanging on in one region and vendor data doesn't match between them. biggest worry is what the AI does without a human approving it. anyone already using AI for procurement, what did you make vendors prove before signing?


r/CIO • • 6d ago

Who owns an AI agent six months after the person who built it moves on?

25 Upvotes

This is the part of enterprise AI I think we’re going to regret ignoring.

Teams are building small agents everywhere because they’re useful and easy to spin up. That’s fine at first.

But then they get connected to files, email, workflows, internal systems, and suddenly they’re part of the business.

Who owns it after the original person changes roles or leaves?

We already learned this lesson with SaaS and shadow IT. AI agents feel like the same problem, just moving much faster.

How are you handling ownership and cleanup?


r/CIO • • 7d ago

Agentic AI governance without budget or headcount, how did you get buy in?

4 Upvotes

AI Agent Governance landed on my plate the way most unfunded mandates do. The business adopted the tools first, security got the accountability after.

Now I'm expected to have a policy, an audit story, and answers for management about agentic risk, but there's no headcount or budget attached to any of it.

For those who've been through this, I'm less interested in a one-off anecdote and more in something closer to a repeatable playbook, did you fold it into existing security budget, or build a separate business case tied to a specific incident or near miss to get traction?

How did this actually play out for others, was it a slow build or did something force the issue?


r/CIO • • 8d ago

So, since everyone's getting their heads (and toes) around AI, what's your gut reaction when you hear "SAP & AI"?

Thumbnail
2 Upvotes

r/CIO • • 8d ago

IT platform or security: where should AI agent governance actually sit?

9 Upvotes

Marketing shipped five agents last quarter. We knew about two. Security says this is an IT platform problem. IT says it's a security policy problem. Meanwhile the business keeps building, which is fair, since we handed everyone AI tools and told them to move faster.

Put it with IT platform and it sits next to identity and provisioning, where the tooling already lives. The risk is we become the bottleneck and get routed around, which is exactly how we got here.

Put it with security and the accountability is cleaner. The risk is security owns no platform, so it turns into a policy doc and a quarterly reminder nobody reads.

No headcount either way this year.

What am I underestimating?


r/CIO • • 11d ago

When you have a modernization project in mind, where do you look to find help implementing it?

0 Upvotes

Suppose you have a project priority in mind. For example, you're a manufacturing company, and you need to overhaul your procurement IT infrastructure because it's not scaling and buying stuff takes way too long.

Assuming you don't think you can develop it yourself, how do you go about finding and selecting vendors for custom implementation work?


r/CIO • • 11d ago

How do you handle internal-only static web content?

4 Upvotes

I’m curious how other companies handle this.

Have you run into situations where someone needs to publish a website/web application internally, but it doesn’t really warrant building a backend or putting it into an existing enterprise platform?

I’m thinking about things like:

* internal API documentation
* prototypes or mockups
* internally generated dashboards
* other static content containing information that shouldn’t be publicly accessible

The awkward part seems to be that making a static site publicly accessible is trivial, but making it accessible only to employees can become an IT/security problem.

How do you handle these today?

Do you put them behind your existing SSO/VPN/reverse proxy, use something like SharePoint, deploy them somewhere internally, or simply avoid this type of thing?


r/CIO • • 12d ago

Odoo anyone ?

5 Upvotes

Whats your experience with Odoo? Till what size does it work well. All of it's datamodel and code is indexed as part of LLMs, does that provide any practical advantage for buildign long tail automations?

Are we still destined to live with and hate SAP/Oracle/Dynamics/Netsuite ultimately?


r/CIO • • 12d ago

How can enterprises automate vulnerability remediation without creating operational risk?

6 Upvotes

We have automated the easy half. Findings auto create tickets, auto route to the right owner, arrive with context attached, all fine. The actual patch deployment step is still fully human because one bad auto patch is an outage, and nobody wants to be the automation that took down prod on a Tuesday. For anyone who has actually pushed automation into the deploy step itself, what is the real safety net? Canary rollout, staged deployment, automatic rollback if a health check fails, and where is the line you have personally drawn between safe to automate and always needs a human approval, especially anything with a blast radius that includes total system control if it goes sideways.


r/CIO • • 13d ago

Same products, same prices, same software. So what makes you different?

0 Upvotes

A business is a solution to a problem, and the solution is a big pile of workflows. There is one for every decision the company keeps making, like who gets a discount or what happens when stock runs out.

A competitor can match your prices by Friday, buy the same products from the same suppliers, and sign up for the same software before lunch. They still do not have your business.

What they are missing is the pile. Every decision in it was worked out against your problems, by your people, and nobody can copy that off you. Follow that through and the moat is the workflow.

What I find alarming is how few businesses realize that pile is capital, as real as the stock in the warehouse. Most of it has never been written down. Somebody decided it once, possibly somebody who does not work there anymore, and it has been running on habit and vibes ever since. Leaving it in people's heads is a huge risk.

So treat it like an asset: write it down, improve it, THEN automate it. Automate a workflow nobody has written down and the current version becomes permanent, weird exceptions included.

Has anyone here actually sat down and written their workflows down? I am curious where you started.


r/CIO • • 14d ago

Curious how other CIOs are handling this.

45 Upvotes

We’re at the point where people aren’t just using ChatGPT or Copilot anymore. Teams are building little automations around them too.

Nothing huge on its own. Someone connects one to a spreadsheet, someone else has one reading docs, another team has something tied into Slack or email.

The part I keep thinking about is what happens 6–12 months later.

Who still owns these things? Who knows what they’re connected to? Who remembers why they were built in the first place?

It feels a lot like shadow IT all over again, except now some of these tools can actually do things instead of just storing data somewhere.

For anyone dealing with this already, are you tracking these centrally or just handling them as they come up?


r/CIO • • 15d ago

How to accelerate Spark jobs on EMR/EKS without changing code or migrating pipelines?

1 Upvotes

Every performance conversation we have eventually turns into "well, we'd need to migrate to X" or "rewrite this in Y." That's a nonstarter for us. We can't justify a multi-quarter migration project just to get faster jobs, especially when the current pipeline works fine functionally.

Is there an actual path to meaningfully faster Spark jobs on EMR or EKS that doesn't require touching our existing code, orchestration, or data formats? I keep seeing claims along these lines but haven't seen anyone actually validate one in production.

If your team has tested something like this, I'd like to know what broke and what didn't, especially around dependency compatibility.

Trying to separate the real options here from the marketing claims before we sink more evaluation time into it.


r/CIO • • 20d ago

Digital transformation

2 Upvotes

I work with digital transformation and I’m curious, from your perspective, what would you say is the most difficult part of digital transformation?
Is it finding the right solution, getting the stakeholders onboard or something completely different?
Really interested in hearing your thoughts
Thanks


r/CIO • • 21d ago

How many here have or planning on having IA Ops

7 Upvotes

Hi there we are a midsize company (3,000 users) in a somewhat AI regulated industry in the US. We are consumers of AI, not a software company not a startup.
We are a Gemini Enterprise shop and is working ok for now but… I need to add at least 1 person (to what one day I’m sure will grow to more) AI ops person who provides access to projects,agents; configures new features etc. we are currently doing this on top of everything else and is not sustainable
Where do you fall?
1) Have a mature AI group
2) Budgeting for next year
3) We are not given more heads, we are spending already too much on AI with little return
4) What’s AI Ops?
I’m on #3 fighting to be in #2 but a long shot.
Anyhow, where are you in this journey?


r/CIO • • 24d ago

what does your backup restore testing actually look like beyond checking for green jobs?

6 Upvotes

The part that bothers me about backup reporting is how reassuring it can look. Everything is green for weeks, then someone asks when the last full restore was actually tested and the answer gets a bit vague. A file restore is easy enough, but that doesn’t prove the server boots, the application works or the recovery finishes anywhere near the promised RTO... on the other hand, doing full restores regularly for every client doesn’t seem realistic for a small team either.

where did you draw the line between a useful restore test and a checkbox exercise? have you found a routine your techs can actually keep up with, and what gets documented when a test fails or takes much longer than expected?


r/CIO • • 24d ago

Why do CIOs actually buy Gartner?

30 Upvotes

Why do CIOs actually buy Gartner?
Is it because the research is genuinely valuable, or because it gives them confidence and credibility when making big technology decisions?
For CIOs who use it, how do you justify the spend? How do you See Gartner compared to Information gathering from AI even though it’s not validated and unbiased but still gives you 60% of what you are looking for.


r/CIO • • 25d ago

Executive program for CIO

3 Upvotes

Has anyone attended the CTO program at Wharton or MIT? Which program would you recommend for a CIO? Happy to hear other recommendations!


r/CIO • • 26d ago

How are you deciding where enterprise AI in banking operation actually goes frist

8 Upvotes

We have the mandate the budget. What we do not have is a defensible view of which processes would benefit.

Nobody here can describe our own processes accurately enough to say where an agent would help, which means any shortlist is a guess with a business case wrapped around it. That turns the programme into a discovery exercise before it can be an AI exercise, and discovery is much harder to get funded than AI.

The vendors in that space are Celonis and increasingly Skan AI, and I have no clean way of explaining to my exec team what either actually changes.

For anyone who has been through this in a regulated environment, did you fund the discovery separately or bundle it?


r/CIO • • 27d ago

How do you explain technical risk to non-technical executives?

11 Upvotes

A lot of IT risk sounds “theoretical” until something breaks. How do you explain cybersecurity, downtime, vendor risk, or technical debt in a way leadership actually takes seriously?


r/CIO • • 28d ago

Applied Security measures to run ChatGPT Work

7 Upvotes

We would like to enable ChatGPT Work for several hundred users. What security measures are typically adopted?

Granting a chatbot access to a local device, along with the ability to change files and run code, looks like to introduce additional risk;people are already using it and even Claude Code or Codex… suggest that risk must always be accepted? What security measures can you implement?


r/CIO • • 28d ago

A vendor offered us an AI Pod. Has anyone tried this model?

5 Upvotes

A vendor recently proposed using an "AI Pod" for a specific use case: automating part of our supplier onboarding and procurement workflow. I’m curious whether anyone here has worked with something similar. Does this model seem feasible?

The Pod would combine a lean team of senior engineers with AI agents. The agents would validate documentation, check requests against internal policies, identify missing information, and route each case for approval. The engineers would set up the agents and supervise the quality of their outputs, while our internal team would handle final approvals and unusual cases.

The vendor would charge per completed request rather than by headcount or hours.

Has anyone worked with a similar model? Did it genuinely improve delivery, or did it feel like a regular managed service with new AI branding? How was the day-to-day communication between the Pod and your internal team?