惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
G
Google Developers Blog
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
N
Netflix TechBlog - Medium
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Engineering at Meta
Engineering at Meta
B
Blog
博客园_首页
量子位
博客园 - 叶小钗
L
LangChain Blog
T
The Blog of Author Tim Ferriss
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
F
Fortinet All Blogs
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
D
DataBreaches.Net
雷峰网
雷峰网
The Cloudflare Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Last Week in AI
Last Week in AI
P
Proofpoint News Feed
TaoSecurity Blog
TaoSecurity Blog
罗磊的独立博客
MongoDB | Blog
MongoDB | Blog
The GitHub Blog
The GitHub Blog
I
Intezer
H
Help Net Security
The Hacker News
The Hacker News
The Register - Security
The Register - Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
AWS News Blog
AWS News Blog
V
V2EX
Microsoft Security Blog
Microsoft Security Blog
T
Tenable Blog
Spread Privacy
Spread Privacy
A
Arctic Wolf
P
Proofpoint News Feed
T
Threat Research - Cisco Blogs
Schneier on Security
Schneier on Security
C
CERT Recently Published Vulnerability Notes
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Last Watchdog
The Last Watchdog
Latest news
Latest news
T
Troy Hunt's Blog
L
LINUX DO - 热门话题

informationweek

2026 tech company layoffs How Sedgwick scaled AI in legacy claims workflows InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO AI on trial: The Workday case that CIOs can The AI infrastructure boom is coming for enterprise budgets How CIOs can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy, Cleveland Clinic CIOs on scaling AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce Non-human identity sprawl is agentic AI's real risk Anthropic's Mythos forces a rethink of vulnerability management Outsourcing contracts weren't built for AI. CIOs are renegotiating now The AI spend hangover companies didn't plan for The power of CIO networking in the competitive AI world Why CIOs see AI projects stall: Speed without structure kills scale IT leaders should never let a good crisis go to waste SFO's digital twin maps airport operations from the curb to takeoff CIOs caught in the middle as AI startups disrupt vertical Saas Submit an IT Leadership column to InformationWeek Podcast: Rightsizing AI frameworks to avoid failure modes The invisible labor crisis inside IT: AI work the org chart can't see Why AI teams treat training data like capital Ask the Experts: How CIOs can identify and overcome cultural barriers to innovation Nobody told legal about your RAG pipeline -- why that's a problem Meta's new 'AI Zuckerberg' is a mirror for every C-suite Will the music stop for AI's funding dance? Rethink tech talent: Local is the smartest play for IT InformationWeek Podcast: Catching errors in AI-powered code CIOs can combat talent scarcity with AI-augmented leadership -- Gartner How Bellevue, Wash., is applying AI to streamline a broken permitting process Ignore the hype: Smarter tech bets at speed of change Who controls the fix? Colorado's repair fight tests CIO power Ask the Experts: The red flags that signal an AI project isn't worth pursuing The hidden high cost of training AI on AI Red Hat's Marco Bill: Resource control is key for AI sovereignty InformationWeek Podcast: New IT architecture, cloud, edge and AI Enterprises need Tier 1 provider relationships to deliver on AI How CIOs run and rebuild the business at the same time in the AI era It's not your tech stack, it's your structure -- fix it Confidential computing resurfaces as security priority for CIOs FinOps: Helpful tool, or a cloud control placebo for CIOs? Cleveland's open data overhaul: From sticky notes to public dashboards As Microsoft expands Copilot, CIOs face a new AI security gap Why build vs. buy doesn't fit modern IT systems InformationWeek Podcast: Is quantum computing slumbering? Your AI vendor is now a single point of failure Vibe coding: Speed without security is a liability A practical guide to controlling AI agent costs before they spiral AI fuels a new wave of technical debt The sunsetting of Sora: A hard lesson in AI portfolio resilience HP pushes broad internal AI use after early productivity gains Why value-based pricing is inevitable InformationWeek Podcast: Safeguarding ecosystems from outsiders Why AI scaling is so hard -- and what CIOs say works Humans are the North Star for AI-native workplaces -- Gartner How IT leaders build a culture for what comes next Compliance costs risk widening the AI gap AI-driven layoffs add new demands on CIOs to prove value AI transformation: Early wins are not enough for CIOs Why CIOs can't let users wait on IT Memory shortage doesn't have to spell disaster for IT budgets Accelerate AI adoption: 3 reasons for adopting MCP How techno-nationalism is complicating IT resilience and supply chains for CIOs InformationWeek Podcast: Compliance crackdown on AI and BYOD Workday’s AI reset: Agents and the race to remake SaaS Why enterprise AI initiatives keep dying before production Metrics of meaning: What do we really measure in AI? Techno-nationalism is reshaping CIO infrastructure strategy Using AI to pick team leaders -- without crossing legal or ethical lines What Oracle's layoffs reveal about running IT with fewer people Chief AI Officer on course-correcting when AI moves too fast Large enterprises need high-performing networks to scale AI InformationWeek Podcast: When do smaller AI models make sense? The future belongs to AI-driven IT Ways AI supercharges risk awareness and data insights for CIOs How automation prepares you for agentic NetOps Should the CIO, CFO or CEO hold the kill switch on AI? The CIO's new mandate: Redesign work itself Ask the Experts: CIOs say they wouldn’t pull workloads back from the cloud How AI is Reshaping the Enterprise
The AI contract gaps the Google-Pentagon deal just made visible
Madeleine Streets · 2026-05-01 · via informationweek

On Tuesday, Google signed a deal permitting the U.S. Department of Defense to use its Gemini AI models for classified military work, under terms allowing "any lawful government purpose." The restrictions reportedly written into the agreement -- no domestic mass surveillance, no autonomous weapons without human oversight -- are not contractually binding. And Google has limited ability to monitor or restrict how those systems are ultimately applied.

The geopolitical and ethical implications of that arrangement will be debated at length, but for enterprise CIOs, the contract's more immediate relevance lies elsewhere. The structure of the master service agreement (MSA) exposes familiar pressure points: contracts that signal intent without enforcing it; limited visibility into how systems behave in production; and a governance model that struggles to keep pace with how AI is actually used.

None of these issues are unique to defense. What the Google–DoD relationship illustrates is how quickly they surface once AI systems are deployed at scale.

Related:CIOs need control before AI gains accountability

Contracts that don't constrain behavior

Enterprise AI contracts often contain detailed language around acceptable use, data handling and safeguards. On paper, these provisions can appear robust; in practice, they frequently operate as expressions of intent rather than enforceable constraints.

Chris Hutchins, founder and CEO of Hutchins Data Strategy Consulting and strategic advisor to Reliath AI, said this disconnect is built into how enterprise organizations  think about their AI vendor contracts in the first place. 

"Contracts are only as good as the control mechanisms that govern them," he said. "An MSA  is not a control mechanism. It is a snapshot of what the vendor said on that day."

That snapshot quickly becomes outdated in an environment where models evolve continuously. Hutchins said enterprises often treat clauses on data use or model behavior as if they provide ongoing assurance, but legacy SaaS governance frameworks can't be simply transposed onto AI models. 

"If you believe the clause stating that the training data will not be used is a control mechanism, you are mistaken," he said.

The gap becomes more pronounced when looking at how contracts handle downstream use. Hutchins said many agreements contain exceptions that materially weaken their protections. "You would be surprised what 'improvements, abuse, safety and evaluation, and research' actually mean," he said, noting that these categories can create pathways for secondary use of data that customers did not anticipate. 

Related:Gen Z is booing AI: Why it's a workforce problem for CIOs

"Anyone signing that clause without reviewing the exceptions is signing a contract that is almost the opposite of the one in their minds," he warned.

Simon Ratcliffe, fractional CIO at Freeman Clarke, framed the issue more broadly. "The overarching problem with AI governance is enterprises are trying to apply static governance tools -- contracts, policies, controls -- to something inherently dynamic,"  he said. "This is a mismatch with potential for disaster."

He was more direct on the limits of policy as a control mechanism. "At scale, pure control is a fiction," Ratcliffe said. "Policies can define intent, boundaries and consequences, but they cannot fully govern behavior in distributed, API-driven, often employee-led adoption environments."

The gray areas in these contracts are not simply a matter of poor drafting. They reflect a long-held assumption that contractual language can still meaningfully shape behavior in systems that are continuously updated, integrated, and repurposed. The Google–DoD agreement makes clear how limited that assumption can be when applied at scale.

“Contracts are only as good as the control mechanisms that govern them.”
-- Chris Hutchins, CEO, Hutchins Data Strategy Consulting

Related:How Sedgwick scaled AI in legacy claims workflows

The observability gap in production

If contracts define intent, enforcement depends on visibility. This is where many enterprise AI strategies begin to break down.

Most governance frameworks are established at the point of procurement or initial deployment. Risk assessments, usage policies and approval processes are designed to shape how systems should be used. But as Ratcliffe said, "AI risk actually materializes during operation, when we see how models behave with real data, how prompts evolve, how outputs are used downstream."

The problem is that few organizations have the infrastructure to observe those dynamics in real time. "The largest gap is runtime visibility," Ratcliffe said. Policies may prohibit sensitive data from being shared with external models, but "production systems pass metadata, logs or user inputs that violate that principle."

Hutchins described a similar divide between documented policy and operational reality. "What policy you have, what you have published in slide decks, is policy intent," he said. "The reality of what you have in production is in another policy file." Without sufficient monitoring, organizations are effectively operating on assumptions about how their AI systems behave, rather than empirical evidence.

In highly controlled environments -- such as classified networks -- the problem becomes more visible because it is more extreme. But the underlying dynamic is consistent across enterprise contexts. Once AI systems are integrated into business processes, both vendors and customers can lose sight of how they are being used. 

"Users copy outputs into the next tool down the line, and the chain of custody is lost," Hutchins said.

That raises a practical question for CIOs: if governance depends on the ability to observe and intervene, what happens when that visibility is incomplete by design?

Strengthening AI contracts in practice

When faced with increasingly inadequate  contracts, the response is not to abandon them altogether, but to rethink what they are expected to do and how they are structured.

Ratcliffe argued that organizations need to move from what he described as "service assurance" to "outcome assurance." In practice, that means shifting away from general commitments and toward mechanisms that account for how models evolve over time.

This is an area that Hutchins flags as being currently under-addressed in AI agreements. "The AI vendor retains the right to swap out models, and change prompts and filters, meaning your implementation may change with no notice," he said. "Changes may occur overnight, and a new version of the AI may perform in a completely different manner with no explanation."

To combat this, Ratcliffe recommends that contracts include model change notification clauses with defined impact thresholds, along with versioning guarantees or the ability to pin to specific model versions. This returns some of the control over model application to the enterprise.

Data handling is another area where specificity matters. Ratcliffe said organizations should define clear data boundaries, including zero-retention options and indemnity around misuse. Hutchins, meanwhile, pointed to the need to scrutinize exceptions within data clauses, where secondary use is often permitted under broad categories.

Observability also needs to be addressed contractually, not just technically. Ratcliffe said enterprises should embed audit and observability rights, including access to logs, evaluation metrics, and testing environments. Without those rights, enforcing governance policies becomes significantly more difficult.

Finally, both experts emphasized the importance of planning for an exit or a total renegotiation. Ratcliffe highlighted the need for portability of prompts, workflows and embeddings, while Hutchins emphasized timing. "Renewal is when the most options are available," he said. "Don't wait for some crisis to act."

From governance as policy to governance as system

The combined effect of these dynamics is a shift in how AI governance needs to be approached. Contracts, policies and upfront controls remain necessary, but they are no longer sufficient on their own.

Ratcliffe argues for a move toward runtime governance, where monitoring, evaluation and intervention are continuous rather than episodic. He said organizations that are making progress are treating AI not as a feature, but as "an operational risk surface." 

"We need to change our thought process because organizations that still think in terms of prohibition or rigid approval models will either fail or drive usage underground," he warned.

That shift comes at a price. Hutchins did not shy away from the potential ramifications of a more tightly governed AI deployment framework: the visible costs of equipping a small team to inventory, evaluate, and monitor governance and runtime; the delay in project approval; the change in how vendors need to sell their AI-enhanced products.

Despite this, he unequivocally recommends taking action.

"The biggest cost will come from delaying this decision, because the alternatives are an irrational system with unclear processes, class action lawsuits and government inquiries," he said. "The math for this decision is easy."

About the Author

Madeleine Streets

Senior Editor, InformationWeek

Madeleine Streets is a senior editor at InformationWeek, where she shapes stories and contributes news analysis through a CIO lens. 

She comes to InformationWeek from TechTarget’s Learning Content team, in which she authored explainers and features on a range of enterprise IT topics. Before moving to the field of enterprise technology, Madeleine spent several years covering retail, consumer finance, and ecommerce technology for fashion trade publication Footwear News. She has also been published in Women’s Wear Daily, TIME, Associated Press, SELF, and Observer, among others. The thread that ties her coverage together is a commitment to honest, impactful storytelling -- and insatiable curiosity.

Outside of writing, Madeleine can be found studying wine, singing in her local choir, and working her way towards her annual reading goal of 100 books. She is based in New York City, US.