AI brings both risk and opportunity to businesses. Stu Bradley, the senior vice president for risk, fraud and compliance for data management and analytics platform SAS, sees both up close. SAS has integrated AI into its platform, allowing deeper data analysis and better solutions. But many SAS customers are in regulated industries with highly protected data—including financial services and healthcare—so the company has a keen eye on potential problems.During the SAS Innovate conference in Washington, D.C. last month, I got to talk to Bradley about the cybersecurity threats AI poses for all industries—not just the highly regulated ones—as well as how to make sure you’re set to get the best value from your company’s AI investment. An excerpt from our conversation is later in this newsletter. Until next time.This is the published version of Forbes’ CIO newsletter, which offers the latest news for chief innovation officers and other technology-focused leaders. Click here to get it delivered to your inbox every Thursday.Artificial IntelligencegettyWhile CMOs are working to revamp company websites and online content for AI agents, many are running into a technical problem. New research from BrightEdge shows only 3% of websites are set up for easy reading by agents in optimized formats such as the simple text language Markdown—meaning content on 97% of websites isn’t easily found and surfaced by AI chatbots. If it is, it’s only after agents have spent a long time scouring the website, adding tremendously to the bandwidth and compute the site uses.“We really think about this as the rise of almost like a second web: this layer of how agents play a huge role in helping customers, consumers, and B2B buyers really be able to navigate brands and services out there,” BrightEdge founder and CEO Jim Yu told me.Yu said companies basically need to produce their sites for the AI agent audience—a format that isn’t built for people, but will inform the responses that people get when they query AI. This takes more than adding to a schema, Yu said. It’s actually more programming work to do in-house or with a third party. But it’s worthwhile. In a pilot done by BrightEdge, sites made more accessible to AI agents had an uncontested advantage over competitors that had not, and saw a site payload reduction of 90%.The companies that have added Markdown so far, Yu said, are ones that likely think more about efficiency. WordPress, Mixpanel, ElevenLabs and Palantir are among the early movers—but so is Greenpeace, which Yu said is probably thinking more about the energy savings.Yu said the likely reason so few companies have taken this step is that AI is moving so quickly and CIOs are unaware of it. However, he said, this doesn’t mean that company websites need to be completely overhauled. What they already have—optimized for traditional search and human consumption—is still working and should stay in place. “You need to do both,” he told me. “You need to keep one for what is your core for users and for classic search, but you also need to, in parallel, have something that’s synchronized and serves the things to the agents that they want to see.”From The HeadlinesNvidia reasserted its dominance twice in the last 24 hours. The world’s most valuable company reported another blockbuster quarter after markets closed on Wednesday, and the company reportedly intends to buy Hugging Face for $12.9 billion.Nvidia, which shatters expectations every quarter, posted eye-popping numbers on Wednesday evening. The company reported $96.2 billion in revenue—up 106% year over year—and forecast $108 billion in revenue for the current quarter. And on the call with analysts, CFO Colette Kress said Nvidia doesn’t expect that to stop anytime soon.“The surge in AI demand is driving a global infrastructure buildout supported by an expanding and diverse set of growth opportunities spanning hyperscalers, AI labs, AI natives, enterprises, and sovereign customers,” Kress said. “We expect to grow revenue by approximately 70% in fiscal 2028.”The earnings boosted not only Nvidia’s stock—up more than 7.5% so far today—but also helped other AI stocks. Intel saw a 2.9% lift Thursday morning, while Broadcom was up 3.3%. Many tech stocks had seen their values flag in recent weeks due to concerns about high infrastructure costs and how to finance them.But with the reported agreement to buy Hugging Face, first reported by The Information, Nvidia is showing strength in another area of the AI ecosystem. The AI open-weight hosting platform would be one of Nvidia’s biggest deals yet. Nvidia CEO Jensen Huang has repeatedly defended open AI models, using his first-ever post on X to tout their ability to strengthen safety, cybersecurity, innovation and sovereignty. He also shared a letter signed by several big tech companies stating open weights enhance competition—which keeps AI’s gains broadly shared.Bits + BytesHow To Boost Your AI Security And ValueSAS Senior Vice President for Risk, Fraud and Compliance Solutions Stu Bradley.SASAI is full of contradictions. It’s a game-changer for efficiency, but a doorway to deep risks. It can boost revenues, but it can also be a financial black hole. I talked to SAS Senior Vice President for Risk, Fraud and Compliance Solutions Stu Bradley about how to keep your use of AI on the upside. This conversation has been edited for length, clarity and continuity.Where do you see the biggest cybersecurity issues right now?Bradley: There’s a couple things worth mentioning. First, if you look at the external threat from an AI standpoint, commercial organizations and government agencies aren’t the only ones using AI. Enterprise criminal organizations are using AI extensively to modify threats and to get around security defenses. The most troubling factor is when you look at organizations that are deploying AI, they are under regulatory scrutiny. They have an internal audit. They have initiatives around responsible innovation. Organized criminal enterprises don’t have any of that. They’ve got unlimited budgets. They’re not encumbered by regulations or trustworthy innovation, so they’re able to proliferate and innovate at a much faster pace than commercial organizations and government entities are able to deploy into production their ability to defend. We did a survey with the Association of Certified Fraud Examiners. Of all individual fraud fighters, 75% have seen an increasing rate of AI-driven threats, and over half expect that to continue to accelerate into next year. Those statistics really paint that story around how AI is being used as a technology against us faster than we’re able to use it to protect us.The other thing is the rate of change of AI is increasing. I sometimes describe this as the entropy is increasing. The level of chaos in the environment, the hype cycles are more vicious than they’ve ever been before. And you’re jumping from topic to topic. Two years ago, it was generative AI. Last year, it was agentic AI going through the hype cycles. And now we’re onto quantum AI. I’m fortunate to engage with chief risk officers across the globe. Several years ago, the conversations were, ‘How do I better manage my assets and liabilities?’ ‘How do I better prepare for my exposure to credit loss?’ ‘How do I better stress test my environment so I’m ready for the confluence of risk factors we face?’Those are all still important topics. But they’re now asking me, ‘How do I manage my AI risk internally in deployment and utilization to drive efficiency and automation?’ ‘How do I need to be prepared for patching my environments?’ The proliferation of the security threats are coming much more quickly. In general, how are companies doing now on AI governance and use of the technology?They’re getting better at it, I think because of the generative AI experience many organizations had, where CFOs were left asking their technology partners, ‘Where’s my return on investment?’ The fact that very few pilots actually made their way into production is forcing executives to think about how they invest too much. One of the biggest learnings was it was a very technology-driven approach, meaning we’ve got this great new technology and we’re going to apply it to every use case under the sun. What they failed to think through is, ‘I need to start with a business problem. What is the use case? What is the outcome I’m looking to generate? And more importantly, is this tool the right technology I should be employing to generate that outcome?’ All of the hype created a disconnect. Organizations are taking a step back and starting to think differently around use cases and outcomes first. Then they’re looking at a portfolio of analytic or AI approaches they should be using, aligned to generating that outcome. So whether it’s a deterministic model, an anomaly detection model, a neural network or generative AI, they all have their purpose. I think too many organizations got away from aligning the tools to what they are actually good at. They’re getting better in that regard. The other thing they’re doing is starting to take governance pretty seriously. We did a survey last year with IDC that highlighted that those organizations that have a defined and documented AI governance strategy are more likely to generate double the return on their AI initiatives, which was pretty significant.My interpretation is that executives that have defined this are using it as a platform for innovation, and they’re innovating much more quickly than organizations that don’t. If you get that foundation set up properly, you can innovate with confidence because you know where your data's coming from. You know your model ops process and you have the ability to monitor what the outcomes of those models will be. It’s forcing them to think a little bit differently in those couple of ways.What advice do you have for CIOs or CISOs about being secure in the age of AI?First and foremost, don’t do it alone. Leverage the communities that are out there. Network within those communities. Tackle it as an industry and cross-industry initiative. Through that knowledge sharing, you’re going to get a better understanding of the risks that we face as industries, as society. That will allow you to have the knowledge that will help drive more strategic intent within the program. Establish a framework for innovation. Organizations are different. Some come with massive budgets for innovation. If you can do a better job of harnessing your data and setting architectural and governance standards to drive innovation, [you can] be driving innovation on [your] own. Other organizations that don’t have the budgets and resources need to think differently about partnerships with other institutions and their vendor community to ensure they’re driving the innovation and getting the capabilities they need.Strategies + AdviceHuge strides are being made in the humanoid robot sector, but with the FCC’s ban on foreign-made “advanced robotic devices,” will U.S. industry get to reap the benefits? Eight experts weigh in on what this means for companies.Personal care company Kimberly-Clark is using AI throughout its operations, but that technology isn’t everything. Here’s why the company’s CIO says operating models matter more.QuizPower-hungry AI data centers are popping up worldwide, but the U.S. is driving the sector’s growth. According to a recent report from the Energy Institute, about what percentage of the energy used worldwide for AI data centers does the U.S. consume?A. 30%B. 40%C. 50%D. 60%See if you got the answer right here.
How To Close The AI Security Gap
Also in the Forbes CIO newsletter: Most websites aren’t speaking AI agents’ language, Nvidia dominates in earnings and intends to buy Hugging Face.







