menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

Putting Together An Enterprise Bring-Your-Own-Agent Policy

10 0
23.07.2026

When Jim Szafranski worked at now-IBM company MaaS360 in the early 2000s, the smartphone revolution began—and employees at all levels wanted to start using the powerful new devices to do work tasks elsewhere: writing emails at a child’s baseball game, or checking the next day’s calendar before bed. It was a thorny issue: How can you keep enterprise data secure on a personal device, especially a small one that could easily be lost or stolen? But once smartphones became ubiquitous, employees wanted to use them to essentially time-shift their working hours, so he worked to develop and scale the technology and company policies to support it.

AI agents represent a similar way that people are empowering themselves, Szafranski said, and people are developing them on all kinds of platforms—both at work and on personal devices. So how can they use these agents at work? It makes sense to create policies so they can, and Szafranski has been putting them in place as CEO of Prezi. I talked to him about what’s needed to make this work, and an excerpt from our conversation is later in this newsletter.

This is the published version of Forbes’ CIO newsletter, which offers the latest news for chief innovation officers and other technology-focused leaders. Click here to get it delivered to your inbox every Thursday.

Artificial Intelligence

The news unfolded this week like a plot from a science fiction novel: A “good” AI system goes rogue and performs a damaging hack on another company without being directed to. OpenAI disclosed on Tuesday that its new cybersecurity-focused model GPT 5.6 Sol and a prerelease “more capable” model, hacked Hugging Face and initiated a cyberattack. As Hugging Face brought in proprietary and top-level U.S. AI models to stop the attack, its system couldn’t distinguish between responder and attacker. Chinese lab Z.ai’s open-source GLM 5.2 model was the first tool that could end it.

While OpenAI is being candid and open about what happened, posting detailed information about the breach and partnering with Hugging Face to both forensically investigate the incident and bolster its cybersecurity, the incident is setting off alarms in the tech and policy worlds.

Several leaders of both say the incident shows the need for better regulation of AI, writes Forbes senior contributor Barry Collins. Plaid CISO Sean Cassidy wrote on LinkedIn that now, reining in problematic capabilities of frontier AI systems is a problem that needs to be addressed immediately, saying, “Our job just got significantly harder.” Andrea Miotti, founder and CEO of non-profit group ControlAI, told Collins that we’re now in an era in which AI itself can be a threat—and AI is only going to get more intelligent as development continues.

Another pressing issue brought up by the hack is there was no home-developed AI platform that........

© Forbes