TLDR IT 2026-09-17
Workers Buy Their Own AI π³, Salesforce Goes Down π₯, Gemini Plugs Into Your Apps π
Your AI Is Already Acting. Is Your Governance Keeping Up? (Sponsor)
Ungoverned AI does not wait for your risk program to catch up. It is embedded in software you already license, deployed by teams that never routed it through review, and operating without an audit trail. The State of Enterprise AI Risk covers the five sources of enterprise AI risk, the frameworks that actually matter, and what to fix before your board or regulators ask the accountability question.
Download the Ebook
Workers are so keen on using AI at work that they're paying for it themselves (4 minute read)
A Deloitte study found 63% of UK workers have used generative AI for work, while 31% are using it without their employer's knowledge and 17% are personally paying for at least one AI tool. For IT teams, the takeaway is less about stopping AI adoption and more about getting approved tools, training, data controls, and governance in place before shadow AI becomes the default.
Salesforce hit by global outage as Google Drive also suffers disruption (4 minute read)
Salesforce suffered a widespread service disruption on September 16 that caused severe delays, intermittent errors, and access problems across regions, with Salesforce attributing the issue to increased load on a core system component. Google Drive separately experienced a 37-minute disruption the same day β a useful reminder of how much employee productivity now depends on a small number of SaaS platforms and why IT still needs outage communications and fallback processes even for highly resilient cloud services.
Gemini in Google Workspace can now connect directly to Salesforce, HubSpot, Asana, and more (4 minute read)
Google is rolling out MCP-based integrations that let Gemini interact directly with Salesforce, HubSpot, Asana, Monday, QuickBooks, Mailchimp, and Atlassian Rovo from Gmail, Docs, Drive, Sheets, Chat, and other Workspace apps. The important admin detail: third-party connectors are enabled by default for users with Gemini access, although IT can control them by domain, OU, or group, making this something Workspace admins should review rather than simply treat as another end-user AI feature.
Chrome 155 tightens enterprise restrictions on powerful extensions (4 minute read)
Starting with Chrome 155, extensions that use Chrome's powerful chrome.debugger API will be blocked from attaching when enterprise policies restrict host access, screenshots, or DLP-protected content. The change only affects managed browsers with those policies configured, but IT teams with internally developed or approved extensions should test ahead of the October 6 stable rollout because some extensions may stop working unless they move to more limited Chrome APIs.
Gartner: here's how AI will remake business in the next three years (5 minute read)
Gartner expects companies to face new operational problems ranging from AI βcost exhaustionβ attacks to a flood of disposable AI-generated applications. One especially relevant prediction for IT: organizations will increasingly need real-time AI cost controls, while CIOs take greater responsibility for proving that governance and guardrails around AI actually exist and work.
Not every app in an enterprise is an enterprise app (5 minute read)
An application becomes an enterprise app based on business dependency rather than its technology, development speed, or where it is used. As AI coding agents enable employees to build software quickly, organizations must recognize that apps transition into enterprise software when the business relies on them to operate, requiring appropriate governance, support, and security as risks and user counts grow.
π€
Launches & Partnerships
Teach Gemini your team's know-hows with skills in Google Workspace (4 minute read)
Google introduced reusable Workspace skills that package an organization's prompts, rules, templates, and reference material so Gemini can repeatedly follow the same process across Gmail, Docs, Drive, Chat, and Workspace Studio. Teams can collaborate on skills like documents, while centralized governance and Admin console distribution are coming, effectively turning internal procedures into reusable AI automations.
Introducing the New Salesforce Well-Architected Framework (6 minute read)
Salesforce has evolved its Well-Architected Framework to address the complexities of the Agentic Enterprise and interconnected autonomous systems. The updated framework is organized around five pillars: Trust, Reliability, Operational Excellence, Resource and Cost Optimization, and Fairness, each featuring a dedicated Agentic Enterprise lens.
Introducing Rivet BYOC (4 minute read)
Rivet has announced the release of Rivet BYOC (Bring Your Own Cloud), a control plane deployed inside a customer's AWS or Google Cloud VPC and managed by Rivet. The offering allows data and compute to remain in the user's account while Rivet handles deployments, updates, and maintenance via an operator running in a Kubernetes cluster.
AIUC Raises $40 Million to Certify Enterprise AI Agents (4 minute read)
AIUC raised $40 million to expand a third-party testing and certification standard for enterprise AI agents, evaluating risks including prompt injection, jailbreaks, data leakage, hallucinations, and unauthorized actions. The interesting part for IT and security teams is the emerging idea of a SOC 2-like independent assurance layer specifically for the agents companies are being asked to approve.
Dreamforce 2026 showed AI safety is the new big tech battleground (3 minute read)
Dreamforce put a growing disagreement among AI leaders on display, with Anthropic's Dario Amodei calling for stronger guardrails and a slower pace at the frontier while Nvidia's Jensen Huang argued against broadly slowing development. Regardless of which approach wins out, enterprises deploying agents will increasingly need their own standards for what models and capabilities they are willing to allow.
MCP Server Visibility (6 minute read)
Tracking Model Context Protocol (MCP) servers on employee devices is an endpoint inventory problem rather than an identity or network issue, because servers are launched locally via hand-edited configuration files without admin consoles or SSO logs. To maintain a complete inventory, security teams must read per-client configuration files across the fleet to resolve the actual entrypoints, package versions, and environment variables in use.
Curated news ποΈ and trends π in IT strategy π», information security π, and cloud computing βοΈ.
Join 570,000 readers for
one daily email