IT in Minutes
Issue 1 1 to 31 August 2026 · 26 items · about 14 minutes

AI Inference Costs to Climb Fivefold by 2028. Uber Fined Nearly 825 Million Euros. SAP Patches a CVSS 10.0.

Gartner forecasts the cost of running an AI agent per workflow rising more than fivefold through 2028. Budgets built on falling unit prices are the ones to reopen.

A Dutch regulator also fined Uber nearly 825 million euros for deciding things about people with no human in the loop.

🤖
The economics of AI
2 items
01
Gartner forecasts AI inference cost per agentic workflow rising more than fivefold through 2028
Most AI business cases assume the price per unit keeps dropping, so the bill drops with it. Three sets of numbers this month say the bill goes up anyway.

What changed

Gartner forecasts that AI inference costs per agentic workflow will increase more than fivefold through 2028.

For an agent doing a customer service task in banking, token costs frequently represent just 20 to 25 percent of the variable run costs of an AI agent. Human oversight takes most of the rest.

A Gartner survey of 199 service and support leaders, run in April through May 2026, found spending on AI up 38% while overall service and support budgets grew just 2%.

Why this matters for you

The price per token fell. The number of tokens each workflow burns rose faster, and the expensive part was never the tokens.

If your agentic budget treats tokens as the main cost, our read of McKinsey's banking example is that the split runs the other way.

What you can do

Ask for one number before you approve the next AI spend: fully loaded cost per completed task, with human review time counted in. If nobody can produce it, you have your answer.

Watch out for

Gartner's number is a forecast through 2028, not a measurement. The McKinsey split comes from customer service work in banking, so treat it as a shape rather than your number.

Token cost is the small part of running an agent

Variable run costs of an AI agent performing a customer service task in banking

Tokens: 20 to 25%Everything elseToken costsRemaining variable run cost

McKinsey scopes this to an agent performing a customer service task in banking and puts human oversight at 70 to 75 percent of the variable cost.

McKinsey QuantumBlack, 24 Aug 2026

02
McKinsey's most recent State of AI finds 94 percent of businesses have yet to create meaningful value
Deployment climbed this year. Returns stayed flat. McKinsey then studied the small group of companies where returns did move.

What changed

Forty percent of respondents from large organisations, those with annual revenues of more than $1 billion, report scaling AI agents, up from 27 percent last year.

McKinsey's most recent State of AI report puts 94 percent of businesses as having yet to create meaningful value from AI.

Infosys surveyed more than 1,000 US senior executives at large companies.

Nearly three-quarters of respondents say fewer than 25 percent of AI pilots have successfully scaled to enterprise-wide deployment while delivering their intended ROI.

In that sample of 20 companies, EBITDA improved by 20 percent on average.

Why this matters for you

If your board asks why deployment is up and the numbers are flat, you are typical. Say so before someone concludes your team is behind.

Nothing in either study points at the technology as the difference. Our read is that it comes down to what the work was pointed at.

What you can do

Count your live AI initiatives, then rank them by the outcome each is meant to move and who owns it. Stop the ones with no answer to either.

Ask your team which two they would keep if they had to choose today. That question gets further with a CFO than another pilot status report.

Watch out for

Twenty companies is a small sample, and the firms that made AI work are the ones most willing to take part. Read it as what that group had in common.

Infosys surveyed US senior executives at large companies, not a global rate.

Scaling rose at companies above $1 billion

Respondents at organizations with annual revenues over $1 billion who report scaling AI agents

27%Last year40%This year

These bars cover companies above $1 billion in revenue. Separately, McKinsey's most recent State of AI report puts 94 percent of all businesses as having yet to create meaningful value from AI.

McKinsey QuantumBlack, 25 Aug 2026 and McKinsey, 28 Aug 2026

🔒
Security and exposure
1 items
03
SAP's August patch day carries a CVSS 10.0 note in Commerce Cloud
SAP patched a maximum-severity flaw in Commerce Cloud in August. In the same month CISA gave federal agencies three days to fix a maximum-severity Oracle flaw that Oracle patched back in January.

What changed

SAP Security Note #3771065, tagged with a CVSS score of 10.0, patches a critical vulnerability in SAP Commerce Cloud.

Six of the released notes impact a single component: SAP Manufacturing Integration and Intelligence, or MII. That component sits between the plant floor and the ERP system.

CISA added CVE-2026-21962 to its Known Exploited Vulnerability catalog on August 24, giving federal civilian executive branch agencies three days to protect themselves against attacks, the tightest deadline it is authorized to set.

Oracle had disclosed that flaw and shipped patches for it in its updates of January 20, 2026.

Why this matters for you

Six notes landing on one component is a reason to give MII an owner and a patch check, rather than treating each as a one-off.

Check the Oracle flaw first. The patch has been available since January, so the real question is whether you already applied it and can prove it.

What you can do

Pull your January Oracle patch record before your next risk review. Somebody will ask for it.

For SAP, find out who owns MII in your organisation. On most sites nobody does, because it sits between two teams.

Watch out for

Onapsis counts 26 new notes plus 3 released between patch days, and ERP Today also reports an unauthenticated CVSS 10.0 flaw in SAP Commerce Cloud. Work from the severities rather than any single total.

Six of SAP's 26 new August notes hit one component

SAP Security Patch Day, August 2026: 26 new Security Notes plus 3 in-between updates

26 new Security NotesHighest note: CVSS 10.0SAP MII (6)All other components (20)

Note counts published for this patch day differ between analysts, so the severities are the part to work from. Onapsis and ERP Today both report the CVSS 10.0.

Onapsis and SecurityBridge, 11 to 12 Aug 2026

⚖️
Regulation and enforcement
2 items
04
New rules on the transparency of AI systems took effect on 2 August
Two European deadlines passed in August. Coverage this year said the AI Act had slipped, and this part of it did not.

What changed

On 2 August 2026, new rules on the transparency of AI systems take effect.

Goodwin calls this a present-day regulatory requirement for tech companies operating in the EU rather than a future one, subject to one narrow exception covering the labelling of legacy generative systems.

The AI Omnibus recalibrates timelines elsewhere in the Act without altering the substance of these transparency obligations.

It reaches employers too. Article 50(4) requires labelling of deepfakes and AI-generated publications intended to inform the public on matters of public interest, where no human editorial control has been exercised.

Separately, the Netherlands brought two laws into force on 15 August 2026.

The Cyberbeveiligingswet implements NIS2 and sets requirements for more than 8,000 organisations providing essential or important services.

The Wet weerbaarheid kritieke entiteiten implements the CER directive and applies to around 500 organisations across energy, transport, drinking water, healthcare, government, digital infrastructure, banking, chemicals, financial market infrastructure, wastewater, space, nuclear, water management, meteorology and food.

Why this matters for you

From 2 August 2026, Article 50 of the EU AI Act imposes mandatory transparency obligations on providers and deployers of AI systems.

Article 50 binds deployers as well as providers. Which duties land on you depends on what the system does, so check the specific obligation for each one rather than assuming the vendor carries it.

What you can do

Start by listing every place a customer, employee or supplier talks to something automated on your systems. Then work out which of them the transparency rules actually touch, because not all of them will.

If you operate in the Netherlands, check which of the two laws you fall under, because they came into force together and the scopes are different.

05
The Dutch DPA fined Uber nearly 825 million euros over automated decisions about drivers
One regulator has now put a number on deciding things about people without a human in the loop.

What changed

The Autoriteit Persoonsgegevens, the Dutch data protection authority, fined Uber 824,990,000 euros. The regulator has ruled that Uber made fully automated decisions about drivers.

Uber says it will object. The Dutch original records a bezwaar, an objection it has announced rather than an appeal it has filed.

New Zealand set a smaller deadline in the same month. From 3 August 2026, every organisation already using biometric technology has had to meet the Biometric Processing Privacy Code 2025 in full.

Why this matters for you

Software decides things about people well beyond HR and customer service. Credit scoring, supplier screening, fraud blocking and access revocation are all worth checking for the same pattern.

If a system in your estate can cut off a person's income or access with no human reviewing it, that is the pattern the regulator just priced.

What you can do

Ask your HR, risk and fraud teams one question: which of our systems can act against a named individual with no human sign-off? Get that list before somebody else asks for it.

Watch out for

Uber has said it will lodge an objection, so the amount may not survive. Plan against the finding about the practice rather than the number.

The fine, in full

Autoriteit Persoonsgegevens penalty on Uber for fully automated decisions about drivers

€824,990,000

The regulator's own headline calls this nearly 825 million euros. Uber has said it will lodge an objection.

Autoriteit Persoonsgegevens, 21 Aug 2026, English and Dutch pages

🏢
Vendors and negotiation
2 items
06
UpperEdge reports capacity tightening, backlog surging and provider leverage rising in renewals
Cloud providers, system integrators and software vendors each moved the same way this quarter. If you have a renewal coming, the ground under it has shifted.

What changed

UpperEdge reports capacity tightening, backlog surging, and provider leverage in renewal negotiations increasing across all three.

AWS, Azure and Google Cloud all reported accelerating growth in Q2 2026, with AWS up 37%, Azure up 43% and Google Cloud up 82%.

On the integrator side, fixed-price contracts now represent roughly 60% of Accenture's work, and the gap between AI booking volume and demonstrable delivery productivity remains wide.

Software pricing is moving off seats. Vendors expect to charge more, rather than less, as customers hand work to AI agents.

Why this matters for you

Fixed price sounds like it protects you. It also hands your integrator every hour that AI saves them.

All three moves point one way. Our read is that whoever writes the contract keeps the savings, and this quarter that is rarely the buyer.

What you can do

Start renewals earlier than usual this cycle. Time is the one source of leverage you still control.

On any fixed-price transformation bid, ask who keeps the AI productivity gains, and get the answer into the contract rather than the pitch.

On agent pricing, define what counts as a completed outcome before you buy. You get billed against that definition.

All three hyperscalers accelerated in the same quarter

Reported growth, Q2 2026, as UpperEdge summarises the three sets of results

AWS37%Azure43%Google Cloud82%

Growth rates as each provider reported them. The three are not measured on an identical basis, so read the direction rather than the ranking.

UpperEdge, 13 Aug 2026

07
A new contract could take Capgemini to 28 years on HMRC's tax systems
HMRC awarded Capgemini a £37 million contract to help migrate a critical tax system off SAP ECC to S/4HANA, extending a supplier relationship that began in 2004.

The contract runs until 2032, which The Register reports would potentially take Capgemini's involvement with HMRC's tax systems to 28 years.

On the predecessor contract the National Audit Office put cost at £7.9 billion between July 2004 and March 2014, against £1.2 billion of combined profit for Capgemini and Fujitsu, a margin of 15.8 percent.

The NAO measured that margin over a decade that ended twelve years ago, so it describes the old contract rather than this one. A relationship that long is a reason to recalculate what switching would cost, before the next renewal decides it for you.

Before the next renewal, ask your procurement lead whether anyone has priced what changing would cost since the first contract.

Source: The Register
⚙️
Modernisation in practice
2 items
08
Flagstar narrowed 12 core banking candidates to one cloud-native platform
Most modernisation coverage is vendor case studies. These three named the shortlist, the savings figure and the reason for moving.

What changed

Flagstar narrowed a group of 12 candidates to one, Fiserv's Finxact. Its CFO Lee Smith told a May investor conference that core consolidation is expected to generate $40 million to $45 million in annualized cost savings.

Lloyds is running agents in production rather than pilots. In fraud, the bank uses agents to assess potentially fraudulent transactions and drive faster action across its fraud help desk.

Others are moving workloads back on economics rather than on any cloud failure. One CTO told InformationWeek that whatever efficiencies were gained were consumed as profit by the hyperscalers.

Why this matters for you

Twelve candidates is the number worth stealing. A wider field keeps vendors competing for longer, and the cost of that is evaluation effort you can plan for.

On moving workloads back, our read is that this is now expected to be a workload-by-workload cost calculation, and that you may put it to a CFO without conceding that cloud was a mistake.

What you can do

Price your three most predictable, least elastic workloads on-premises this quarter. Steady, predictable load is the case where the comparison is worth running.

If a core system decision is coming, set your shortlist size before the vendors start calling.

09
Research reported by SAP concludes AI could potentially cut about 60% from an ECC to S/4HANA migration
SAP's news site reports research covering roughly 180 typical activities in an SAP ECC to S/4HANA migration.

That research concluded AI could potentially produce about a 60% cost reduction, by compressing effort and letting less experienced people, augmented by AI, do work that previously needed highly experienced staff.

SAP's stated objective is to reduce transformation effort by approximately 35%.

Both figures are SAP's own, published on SAP's channel, and the article names no independent check on either, so treat them as best case rather than a planning input.

If you are scoping that migration this year, ask your integrator to price the same activity list twice, with and without agentic tooling, then compare their answer with SAP's.

📈
Operating model and accountability
4 items
10
CIO.com says it remains unclear who might be accountable when an AI agent goes wrong
Three developments in August circled the same hole. Nobody has closed it.

What changed

CIO.com writes that AI agents are not people who can be fired, sued or criminally prosecuted.

It adds that it remains unclear whether responsibility for the damage they might cause rests with the employees who built them, the company that deployed them, the security teams responsible for containing them, or the AI labs who provided the models.

Investors are already litigating it. AI-related securities filings reached 15 in H1 2026, close to 2025's full-year total of 16.

Glass Lewis reports board oversight of AI at around seven in ten large cap companies in Europe, a significant increase on the previous year.

Workday's own researchers found that deleting information from an AI agent's memory does not always remove it for good.

Why this matters for you

If you have told anyone that agent data can be deleted on request, that claim now has a published counter-example from the vendor's own research team.

The securities angle reaches you fastest. Where an AI claim in an annual report comes from your team, your progress statements become a disclosure question rather than a marketing one.

What you can do

Run one deletion request against an agentic system you own, end to end, and see what comes back.

Before the next results cycle, read your company's public AI statements as though you had to evidence each one. Flag anything you could not.

Watch out for

The Glass Lewis figure covers large-cap Europe, so treat it as a direction for mid-size companies rather than a description of them.

11
Microsoft is moving Dynamics roadmap disclosure off twice-yearly release plans, and release schedules stay as they are
Microsoft says it is retiring the twice-yearly release wave 1 and release wave 2 model in favour of continuous publishing.

Starting in September 2026, Dynamics 365, Power Platform and Dataverse roadmap content joins the AI at Work roadmap as a single destination.

Microsoft says this changes how it communicates upcoming innovation and does not change how products are built, released or deployed, that products with established release schedules keep them, and that Message Center remains the source for tenant-relevant change notifications.

If your planning reads the wave notes twice a year to see what is coming, that rhythm goes. Ask whoever owns your Dynamics roadmap watch how they will track it once no wave note exists.

12
Deloitte finds 16% of leaders say their business processes are prepared for agentic AI
Deloitte surveyed 501 senior managers and C-suite executives in the US this spring, and 61% expect that most AI agents will be largely autonomous, with humans serving primarily in an oversight role. Every organisation in that sample was at least piloting agentic AI, and every respondent was directly involved in its strategy or implementation.

Only 16% of respondents said their business processes were prepared for agentic adoption, and another 5% said they were highly prepared.

The leaders Deloitte interviewed separately pointed to poorly documented and understood processes, inconsistent and fragmented data and systems, and entrenched ways of working.

If your processes are not in that fifth, read the obstacle list twice. Fixing fragmented data may take real spend, but documenting how a process actually runs takes attention more than budget.

Our read is that it is the cheapest of the three to start, and the likeliest to be sitting unowned.

Sources: CIO DiveDeloitte
13
Telstra's CFO has flagged AI costs eating productivity benefits across 380 identified AI use cases
Telstra has deployed a large-scale, real-time AI cost and governance monitoring tool, with senior leadership mandating a more disciplined approach to using the technology.

Chief financial officer Michael Ackland has flagged the risk of AI costs, including software licensing and cloud spend, eating into productivity benefits across the telco's 380 identified AI use cases.

This is the same cost problem as the opening item, seen from inside a company that had already counted its use cases.

If you cannot say how many AI use cases run in your organisation today, get that count first. A control plane governs what you have counted, and nothing else.

🛠️
Delivery reality
4 items
14
PMI reports 31% of complex projects miss their full intended benefits
In the Project Management Institute's 2026 Pulse of the Profession report, researchers report that 31% of complex projects fail to achieve the full scope of their originally intended benefits.

CIO.com notes that some often-quoted reports of a 70% IT project failure rate date back several years, which makes them unreliable reflections of conditions today.

PMI surveyed 2,023 project professionals and 511 senior leaders across 35 countries, weighted to its global database, so the 31% carries a real sample behind it.

If somebody in your organisation still quotes some version of the older 70% figure to justify a governance layer, the honest answer is that the two numbers measure different things. Agree what counts as failure before either gets used.

15
A cyber incident hit certain Boston Scientific systems, including processing and shipping customer orders
Boston Scientific said on August 26 that an incident identified a day earlier affected certain information technology systems and caused a network outage and disruption to its operations.

The company said the incident has impacted access to certain operating systems and business applications, including the ability to process and ship customer orders. Its SEC Form 8-K filing added that the disruption was global.

That is where an IT outage stops being an IT story. If your own incident communications describe certain systems rather than order flow, our read is that your board will want the second version.

16
Travelers unveiled a proprietary large language model called TravelersLLM in June
In June, Travelers, an insurer with more than 30,000 employees that generated revenues of nearly $49 billion in 2025, unveiled a proprietary large language model called TravelersLLM.

Chief technology and operations officer Mojgan Lefebvre says the internal model gives better results than commercially available models on insurance-related questions, and is cheaper to run than frontier models.

She frames the approach as not reaching for the most expensive frontier model where the same question does not need it.

Travelers ran that comparison itself, on its own domain, so read it as a case for matching the model to the question rather than as a benchmark.

If your AI spend goes to one frontier model by default, routing is the cheapest lever you have, and you do not need your own model to start.

17
Gartner says approximately 70% of growth initiatives are platform and monetization work
Gartner's analysis found that just 21% of recent growth initiatives were primarily focused on new product and service innovation, whereas approximately 70% were centred on monetization and platformization strategies.

Gartner examined 1,180 growth-related investments from more than 500 large enterprise firms across 10 industry sectors. If your technology roadmap is mostly new build, expect the question about existing assets before you expect the budget.

Before the next planning round, work out which of your existing platforms and customer relationships could carry revenue. That is the question finance is now asking.

Source: Gartner
Quick hits
9 items
18
Workday's 12-month subscription backlog reached $9.034 billion, up 14.2% year over year

Workday reported total subscription revenue backlog of $27.403 billion, up 8.0% year over year, and 12-month backlog of $9.034 billion, up 14.2%.

The near-term book grew faster than the whole book, which it sits inside. Workday does not attribute that gap to a shift in contract timing, so take it as a growth signal worth knowing before a renewal conversation.

19
Gartner forecasts inference spending passing training spending in 2026

Gartner forecasts that in 2026 global spending on inference, at $23.3 billion, will pass spending on training, at $19 billion. That is a forecast rather than a measurement.

Reach for it when somebody argues AI cost is a one-off build expense rather than a running one.

Source: Gartner
20
Roughly two-thirds had at least one business-critical app outage from a misconfigured policy in the last 12 months

Roughly two-thirds of businesses have had at least one business-critical application outage caused by a misconfigured security policy in the last 12 months.

AlgoSec commissioned that Cloud Security Alliance report, covering 515 IT and security professionals in a May 2026 survey, so read it as the vendor's best case. The interesting part is that a security control failure shows up as downtime.

Source: CIO Dive
21
Isaac Sacolick's forecast covers when the AI bubble bursts, with 10 signs and 7 ways to prepare

Isaac Sacolick argues the AI bubble burst is probably not a question of if, and is more a forecast of when and how hard the fall will be.

This is one practitioner's view rather than research, and it answers the board question about what happens if the money stops.

22
Evanta reports forty percent have operationalized AI in selected business processes

Forty percent of the organizations Evanta asked report that they have operationalized AI in selected business processes, while another 38% are actively piloting or testing AI in specific areas.

Evanta surveyed 750 C-level executives in its own communities in June 2026, so read it as a peer snapshot rather than a market measure.

Source: Evanta
23
The US Treasury launched a Quantum-Readiness Task Force for financial firms

The Treasury Department launched a Quantum-Readiness Task Force to work with financial firms, technology vendors and other agencies on coordinating the adoption of quantum-resistant encryption algorithms.

If you are in financial services, our read is that a regulator will point at this body's output later, so learn it exists before it publishes.

Source: Banking Dive
24
IBM surveyed 2,000 CEOs and equivalent senior leaders and found chief AI officers up from 26% in 2025 to 76%

IBM surveyed 2,000 CEOs and equivalent senior leaders across 33 geographies and 21 industries for its 2026 Rewiring the C-Suite report, and found 76% of organizations have a chief AI officer, up from 26% in 2025. Those are leaders self-reporting a title rather than a measured role.

The question worth settling in your own organisation is who that person reports to.

25
Chubb reports US cyber claim costs up 22% for mid-market and 100% for large companies

In the US the average cost of claims rose 22% for middle-market firms in 2025 against 2024, and 100% for large companies.

Chubb drew those figures from its own 2026 Cyber Claims Report on claims made by large and middle-market companies, so read the direction and not the level.

26
SolarWinds reports 3.2 hours a week saved on issue detection while 52% say workload has increased

SolarWinds reports AI saving an average of 3.2 hours a week on detecting and flagging issues, 3.0 hours on end-user requests and 2.9 hours on ticket triage, while 52% say their overall workload has increased since adopting AI.

SolarWinds surveyed more than 800 technology professionals for its own 2026 State of ITSM report, so it is a vendor's number. Have it ready the next time somebody assumes hours saved turn into headcount saved.