In the past year, many companies have made headlines for massive job cuts because of AI automation. And while these cuts have quickly reduced headcounts and employee expenses, they haven’t all been effective. Studies show that about a third of companies that have laid off employees because of AI have already hired people to fill some of those vacated roles, and about half will make similar moves by 2027, writes Forbes senior contributor Rachel Wells.Figuring out the proper balance between employees and technology is difficult—especially at this stage in the hype cycle, when there may be a gap between what it appears AI can do and what it actually takes for AI to do it at a company. I talked to Eric Helmer, CTO at third-party enterprise software support provider Rimini Street, about how to actually do the math on this problem—and convince other executives your plan is best. An excerpt from our conversation is later in this newsletter.Until next time. This is the published version of Forbes’ CIO newsletter, which offers the latest news for chief innovation officers and other technology-focused leaders. Click here to get it delivered to your inbox every Thursday.CybersecuritygettyWhile it’s well known that AI adds cybersecurity risk, Kiteworks’ 2026 Data Security and Compliance Risk Annual Survey Report, shared exclusively with Forbes, adds stark numbers showing how vulnerable most enterprises are—and how much they have already lost. The report shows that most companies are nowhere near ready for the risks AI poses. Kiteworks evaluated companies based on their operational controls on a scale from 1 to 100. For combined data and AI governance—in a measurement called the Data Security and Compliance Readiness Index—the average score was 16.2. But even without that score, the study found incidents increasing. Four out of five organizations had at least one security or AI-related incident in the last 12 months.“Organizations have deployed AI far faster than they’ve built the governance infrastructure to manage it,” Kiteworks Chief Strategy Officer Tim Freestone said in a statement.The biggest problems Kiteworks found are a lack of AI governance strategy and visibility into the system. Nearly 70% of organizations have no behavioral monitoring of AI systems, and close to three-quarters cannot trace AI outputs to source data. Meanwhile, close to two-thirds discovered employees using shadow AI tools—with a third of them finding employees input sensitive data including company login credentials, personal and HR data and customer and client data. There is a long way to go for improvement, and Kiteworks recommends several steps to get on the right track. These include classifying and tagging sensitive data, adding controls so it can be tracked in your system and cannot be moved to personal AI; automatically logging everything that happens with sensitive data; building auditable tracking of AI actions; making AI data governance someone’s full-time job; consolidating sensitive data platforms; and testing AI kill switches to ensure they work.Artificial IntelligenceA week after OpenAI and Hugging Face disclosed a non-human-directed AI-led cybersecurity attack, CEO Sam Altman is stirring controversy with his conclusion about it. On a podcast this week, Altman said, “We are now, like, in the singularity.” But, Forbes contributor Robert Szczerba writes, many find that proclamation up for debate. AI singularity refers to the point when AI advances beyond human abilities to predict or control it, but there’s no agreed-upon milestone for this threshold. (Szczerba points out Altman’s own definition is more nuanced, representing a period of compounding progress.) Forbes contributor Ron Schmelzer writes that several other AI leaders—including Elon Musk and Google DeepMind CEO Demis Hassabis—are likely to agree with Altman. But other researchers are not so sure, saying that AI in general is still continually learning, and AI use in enterprises is far from complete. Forbes contributor Lutz Finger writes the OpenAI hack wasn’t evidence of singularity, but rather a failure to control the AI. Schmelzer and Szczerba both share that true singularity shouldn’t be represented by a single event. But tech professionals should take this as a warning: The technology continues to approach that threshold, so governance should be getting ready to deal with it.Bits + BytesHow To Avoid Excessive AI Job CutsRimini Street CTO Eric Helmer.Rimini Street, GettyI spoke with Rimini Street CTO Eric Helmer about how companies can determine how AI will actually impact their workforce size and make only the cuts (or additions) they need. This conversation has been edited for length, clarity and continuity. What are companies not looking at when they are moving from the ‘we could use AI for this’ phase to when they are actually making job cuts?Helmer: The cost to actually get the AI fully into production is the real enterprise. They get a demo—maybe they get a proof of concept on a particular workflow or use case they want to do or an outcome that they want to get—and they see, ‘Wow, look how cheap this is and how well it works. And I’ve got this process to go from a week down to minutes.’ And they start taking the victory lap around the parking lot. OK, you’re not done. You’ve got to now get it through all the way into production. This is the reason why all AI projects are stuck right now. Most people are starting to realize: That worked in that one single use case for that one single user, department or country. But now if we want to get that out into the real world, we’ve got to look at real data engineering, prepping the environment and systems integration. Now data’s got to come from someplace. Then you have all the testing and change management and modeling and training of people, and then all the governance and compliance on top of it. And where does human oversight come into it? The other problem is that people think it’s a one-time purchase; once they go and implement something, it’s ‘set it and forget it,’ and they’re onto the next thing. They don’t really understand. It’s a living, breathing thing in that it has to be continuously monitored and tuned and secured, and it’s got to be absorbed and accepted into the everyday workflows. And of course they underestimate it. I think most people just calculate the human costs. They think they’re super-smart. They take their burden costs, the benefits. Plus they put in some incremental stuff for training, turnover management, management oversight and then think, ‘OK, we’ve got the full costs.’ But that’s not really the math. The math is scalability over time. The human expense is linear. As you scale, you’re adding another head count, another head count, another head count. Your costs literally scale up as well. Where AI is going to make good sense is when you want to be able to reduce that cost at scale. Where AI comes in really great is for high volume that is expected to even increase more over time. AI’s got that huge upfront cost with the build, integration, governance and security, but it scales almost infinitely with minimal incremental costs over time. That’s where you’re going to get your return on investment. You’re not going to get it for like-for-like human-to-AI comparison.Right now, when an executive is trying to make AI-versus-personnel decisions, what should they be thinking about?Faster doesn’t always equal return to a business. Even if I did get that process down from a week to minutes, did the implementation and all the stuff that goes around that really help with return on investment? Or, even though I know a week may not be optimal, maybe that human-conducted week was cheaper than the few minutes of the AI technology, and maybe the week is better. I also think we have to assume failure from the beginning. We have to understand and calculate the failure costs. We’ve got to realize the agents are not going to be 100%, so we’ve got to understand our tolerance and the costs of that failure. We have to understand the probability of regulatory exposure, audit risk and any kind of brand damage—especially if it’s customer facing—and understand minimum error cost. If you can take a 20% or 30% error rate then OK, but if you have a process where a single failure is catastrophic, I would reconsider the application altogether. If you want to start figuring out what use case is better, you can put things in two buckets. Is this efficiency work or is this judgment work? Put the judgment work on the back burner, and just work on the efficiency work right now. And then there is explainability, auditability, audit trails, traceability and things like that from the very beginning. The reason is not only for legal protections and auditors and that stuff, but if you can’t really understand how it made its decision, you can’t improve on it. If it’s a very mission-critical operation, you want to make sure there’s reversibility built in and a human override. Take a step back, get out a spreadsheet and really understand the true costs and returns of variability. It’s not just human head count and salaries. It’s a better security profile, risk profile, adherence to compliance, accuracy, reduction of errors. There are many cases when people are smart enough to take that step back, they go in with the initial thought that 80% of operations are going to be able to be automated with AI, it reduces to about 20% in actuality.What advice would you give a CIO who has done this math, but walks into a meeting with other executives who are resolute in the decision to make staffing cuts?Put together a clear, articulated project plan and rollout that is executive-level ready to show you’ve got a plan—but a two-year plan, not a one-month plan. You have to be able to do this correctly, safely and in a way that is economically responsible to the organization.AI projects often uncover situations where AI is not the solution. Agentic AI conversations are forcing people to really look at their business processes down to each individual detail, and they’re identifying different ways to question the business process. What you really find is low-hanging fruit to rearchitect the business process from the very beginning, without any additional technology. You’re going to get more juice out of that squeeze than you will applying any technology.Think of agentic AI implementation as almost the last resort. AI companies are coming in: ‘We can get your order-to-cash process. We can decrease your financial close from seven days to three.’ But they start really looking at it and going, ‘I don’t even really need you because I'm seeing all these problems that I can do natively in my business process.’ Comings + GoingsInvestment firm B Capital appointed Dr. Andrew Jackson as general partner and chief AI officer. Jackson joins the firm from G42, where he worked as chief AI officer, and he founded and served as CEO of AI lab Inception prior to that.Entertainment and hospitality company the Marcus Corporation promoted Rajiv W. Castellino to chief information officer, effective August 2. Castellino has been chief technology officer of Marcus Hotels & Resorts since 2017, and he will succeed Kim M. Lueck, who is retiring after nearly 30 years with the firm.AI cloud provider IREN selected Eric Hammersley to be its chief information security officer. Hammersley steps into the role from Nutanix, where he worked as vice president of engineering and chief product security officer.Strategies + AdviceFollowing the OpenAI-Hugging Face hack, many are questioning the safety of AI agents. Here are some tips to keep your AI agents under control and doing only the tasks you want them to.As AI plays a bigger role in the workplace, it may be diminishing the number of human connections you make. Here are five ways to make sure you're still interacting with people while working. QuizBlackRock announced this week it plans to take an 80% stake in a huge planned AI data center campus owned by which company?A. MicrosoftB. OpenAIC. MetaD. OracleSee if you got the answer right here.