{"id":873334,"date":"2025-09-16T01:12:36","date_gmt":"2025-09-16T06:12:36","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2025\/09\/16\/could-gen-ai-radically-change-the-power-of-the-sla\/"},"modified":"2025-09-16T01:12:36","modified_gmt":"2025-09-16T06:12:36","slug":"could-gen-ai-radically-change-the-power-of-the-sla","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2025\/09\/16\/could-gen-ai-radically-change-the-power-of-the-sla\/","title":{"rendered":"Could gen AI radically change the power of the SLA?"},"content":{"rendered":"<article id=\"post-4054080\">\n<div>\n<div>\n<div>\n<h2>\n\t\t\t\tEnforcement of service level agreements (SLAs) could be supercharged through real-time alerts flagging violations and risky behavior. But generative AI\u2019s potential to revolutionize third-party agreements has its limits.\t\t\t<\/h2>\n<\/p><\/div>\n<div id=\"remove_no_follow\">\n<p><body><\/p>\n<div>\n<p>By outsourcing business functions, CIOs can reap cost and, in some cases, expertise benefits, but they also reallocate risk from in-house talent to employees of third-party firms largely beyond their oversight.<\/p>\n<p><a href=\"https:\/\/www.cio.com\/article\/274740\/outsourcing-sla-definitions-and-solutions.html\">Service level agreements (SLAs)<\/a> can provide CIOs with assurances against this reallocation of risk, but traditional SLA metrics and conditions can leave gaps and reporting lags that can fail to capture real-time operational risks or threats until it\u2019s too late.<\/p>\n<p>Take <a href=\"https:\/\/www.csoonline.com\/article\/4027266\/clorox-sues-cognizant-for-380m-over-alleged-helpdesk-failures-in-cyberattack.html)\">Clorox\u2019s recent lawsuit against Cognizant<\/a>. The multinational CPG giant, which had outsourced its service desk operations to Cognizant, alleges that Cognizant help desk workers gave out passwords to Clorox systems without using mandatory authentication procedures, resulting in a 2023 breach attributed to Scattered Spider.\u00a0<\/p>\n<\/div>\n<div>\n<p>Clorox\u2019s lawsuit cites transcripts of help desk calls as evidence of Cognizant\u2019s negligence, but what if those calls been captured, transcribed, and analyzed to send real-time alerts to Clorox management? Could the problem behavior have been discovered early enough to thwart the breach?<\/p>\n<p>Here, generative AI could have a significant impact, as it delivers the capability to capture information from a wide range of communication channels \u2014 potentially actions as well via video \u2014 and analyze for deviations from what a company has been contracted to deliver. This could deliver near-real-time alerts regarding problematic behavior in a way that could spur a rethinking of the SLA as it is currently practiced.\u00a0<\/p>\n<p>\u201cThis is flipping the whole idea of SLA,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/hallkevincissp\/\" rel=\"nofollow\">Kevin Hall<\/a>, CIO for the Westconsin Credit Union, which has 129,000 members throughout Wisconsin and Minnesota. \u201cYou can now have quality of service rather than just performance metrics.\u201d<\/p>\n<\/div>\n<div>\n<p>Of course, Hall also cautioned that under such a scenario CIOs would need to be prepared for a fierce fight from third parties when trying to apply SLA penalties.\u00a0<\/p>\n<p>\u201cMy first big worry is enforcement. You might have a lot of work to claim an SLA violation. [Third parties] will look awfully hard for every example where they are exempt,\u201d Hall said. \u201cWhen it\u2019s time to collect, that process is going to be painful, a very uphill battle.\u201d<\/p>\n<p>As a practical matter, Hall suggested that CIOs would probably only pursue major violations. \u201cYou\u2019ll need to have really big ticket items, so you\u2019ll have clear arguments to make,\u201d he said.<\/p>\n<\/div>\n<div>\n<p>Zachary Lewis, CIO of the 160-year-old University of Health Sciences and Pharmacy in St. Louis, also sees potential from this shift in SLA enforcement.<\/p>\n<p>\u201cWith this approach, we could get a really good handle on insider threats. The system could trigger on likely insider threats immediately,\u201d Lewis said. \u201cOr if they laugh about their lack of security or talk smack about their clients, we could be alerted right away.\u201d<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/cameronpowell1\/\" rel=\"nofollow\">Cameron Powell<\/a>, a technology attorney with the law firm Gregor Wynne Arney, also sees the upside of such an approach for countering legal and compliance risks.<\/p>\n<\/div>\n<div>\n<p>\u201cYou will be able to scan Zoom meetings, looking for risk issues. It could look for phrases such as \u2018Let\u2019s keep this off email,\u2019\u201d Powell said, giving the example of one of several communication channels where the approach could be applied. \u201cWhy not find these issues in real-time before a third party sues you or a whistleblower reports you?\u201d\u00a0<\/p>\n<h2 id=\"friction-and-additional-risks\">Friction and additional risks<\/h2>\n<p>While generative AI, used in this way, could supercharge SLA enforcement, UHSP St. Louis\u2019 Lewis also noted that it would likely meet significant implementation friction.<\/p>\n<p>\u201cAre we going to need another AI to monitor all of the first AI\u2019s data monitoring? If so, then gen AI becomes its own third-party risk,\u201d Lewis said. Will third-party companies avoid this new monitoring by trying to \u201csandbox themselves from their customers\u201d?\u00a0<\/p>\n<\/div>\n<div>\n<p>Lewis also questioned how long such an approach would last. \u201cAre we going to have to do this indefinitely?\u201d<\/p>\n<p>Westconsin Credit Union\u2019s Hall sees upside in the call center, where customers sometimes complain and ask that their complaints be properly registered and logged. \u201cIf I am at the call center and [the customer] is complaining about me, the odds of my reporting that are low,\u201d Hall said. \u201cThis would change that.\u201d<\/p>\n<p>But such monitoring approaches raise privacy and regulatory concerns, especially for healthcare and financial firms. To tackle this, Hall said the first step would be to make sure real-time transcripts were sanitized to remove any protected information, such as health records or payment details.\u00a0<\/p>\n<\/div>\n<div>\n<p>\u201cIt is kind of a [compliance] nightmare as it would be on us to sanitize. How do you trust and verify that [the gen AI system] is properly doing it without constant auditing?\u201d Hall asked. \u201cIt might have so many little holes for leaking [protected data] that I would be hardpressed to go to the board. They would ask, \u2018How much risk are you taking on and what is the reward?\u2019\u201d<\/p>\n<p>But, Hall said, he could make an argument to the board that this approach had the potential to sharply improve third-party compliance, thereby strengthening the company\u2019s compliance posture.\u00a0<\/p>\n<p>\u201cIf I could convince them with strategy and culture arguments, it could land with the board,\u201d Hall said.\u00a0<\/p>\n<\/div>\n<div>\n<p>Still, attorney Powell \u2014 and others \u2014 stressed that generative AI is far from perfect. There\u2019s a difference between flagging a problem and having sufficiently reliable evidence to do something about it.<\/p>\n<p>For example, gen AI \u201cdoesn\u2019t understand empathy\u201d or when people need to say something \u201cto calm a customer down or make a nice connection,\u201d Powell said.\u00a0<\/p>\n<p>Powell also suggested other use cases, such as video-capture to analyze every aspect of a driver\u2019s delivery process. Was the package delivered when time-stamped? Did the driver steal anything after delivering the package?<\/p>\n<\/div>\n<div>\n<p>\u201cIt could turn today\u2019s SLA from a service level agreement to a surveillance level agreement,\u201d Powell said.<\/p>\n<h2 id=\"what-about-privacy\">What about privacy?<\/h2>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/raschcyber\/\" rel=\"nofollow\">Mark Rasch<\/a>, a former federal prosecutor who specializes in technology legal issues, argues that companies need to figure out how to take advantage of this source of ubiquitous data.\u00a0<\/p>\n<p>\u201cYou can now do things that were impossible just a couple of years ago. Before, at most, you could do some spot-checks,\u201d said Rasch, who today serves as a professorial lecturer in law at George Washington University Law School and as legal counsel for Unit 221B, a data privacy and security compliance consulting firm. \u201cBut what you cando and what is reasonableto do are two very different things.\u201d<\/p>\n<\/div>\n<div>\n<p>Rasch, and other attorneys interviewed, said the law is also slowly learning to function along with gen AI so it\u2019s not yet clear how much this analysis will eventually be allowed by courts.\u00a0<\/p>\n<p>He pointed to a 2011 United States Supreme Court decision called Sorrell, which explored how much privacy physicians can expect and <a href=\"https:\/\/www.scotusblog.com\/cases\/case-files\/sorrell-v-ims-health-inc\/\" rel=\"nofollow\">decided they don\u2019t have much<\/a>.\u00a0<\/p>\n<p>Another risk was referenced by <a href=\"https:\/\/www.linkedin.com\/in\/fvillanustre\/\" rel=\"nofollow\">Flavio Villanustre<\/a>, CISO for LexisNexis Risk Solutions Group.\u00a0<\/p>\n<\/div>\n<div>\n<p>Villanustre said the prudent move is for executives to scan the transcript, but place much more trust in the captured audio. That is because gen AI often hallucinates within transcripts.<\/p>\n<p>Of course, gen AI could just as easily create a bogus audio capture, Villanustre pointed out, as it\u2019s not yet clear that video or audio processed by gen AI can be trusted, forcing CIOs to need direct audio backups that can be trusted and are ostensibly incapable of being changed by gen AI.<\/p>\n<p>\u201cIn more complex cases, gen AI can mislead,\u201d Villanustre said.<\/p>\n<\/div>\n<div>\n<p>As for healthcare, attorney Powell said, \u201cEvery recording is creating new PHI [protected health information]. Who can access that recording? You may have to create a whole new HIPAA trail for these recordings.\u201d<\/p>\n<p>Similar issues would exist for all other highly regulated enterprises, including financial institutions, energy, transportation, and pharmaceuticals.<\/p>\n<p>If audio or video captures are being analyzed for real-time alerts, could law enforcement or other government agencies demand access? Could a request be placed to listen for someone\u2019s voice and alert authorities if it is detected?<\/p>\n<\/div>\n<div>\n<h2 id=\"beyond-the-sla\">Beyond the SLA<\/h2>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/gwlongsine\/\" rel=\"nofollow\">Gary Longsine<\/a>, CEO at IllumineX, believes the privacy fear may be moot because \u201cclients are recording those calls as well, so that ship has kind of sailed.\u201d<\/p>\n<p>Moreover, gen AI capabilities to track and manage third parties for SLA enforcement could also be applied to an enterprise\u2019s in-house workforce.\u00a0<\/p>\n<p>Consider when a<a href=\"https:\/\/www.cio.com\/article\/3612442\/macys-154-million-hidden-accounting-mess-shows-the-limits-of-todays-audit-grc-and-accounting-systems.html\"> Macy\u2019s accountant successfully hid $154 million<\/a> for three years, forcing the retailer to delay and then restate an earnings report. Instead of the audit systems the accountant sidestepped, a gen AI system could perform audits differently \u201cand it would have flagged this right away,\u201d said IDC President<a href=\"https:\/\/my.idc.com\/getdoc.jsp?containerId=PRF000086\" rel=\"nofollow\"> Crawford Del Prete<\/a>.<\/p>\n<p>HR might also find it useful, Powell added, to identify employees who are about to resign.<\/p>\n<\/div>\n<div>\n<p>\u201cYou can internalize internal chat to see who is about to leave. People tend to disengage well before they actually leave. There is a change in language and tone that signals disengagement,\u201dhe said, adding that gen AI is the first system that could detect that quickly enough to potentially make a change in time.<\/p>\n<\/div>\n<p><\/body><\/div>\n<\/p><\/div>\n<div id=\"rightrail-wrapper\">\n<p>\n\t\t\t\tSUBSCRIBE TO OUR NEWSLETTER\t\t\t<\/p>\n<h3>\n\t\t\t\tFrom our editors straight to your inbox\t\t\t<\/h3>\n<p>\n\t\t\t\tGet started by entering your email address below.\t\t\t<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> Margarete Mcnaught <br \/><a href=\"https:\/\/www.cio.com\/article\/4054080\/could-gen-ai-radically-change-the-power-of-the-sla.html\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enforcement of service level agreements (SLAs) could be supercharged through real-time alerts flagging violations and risky behavior. But generative AI\u2019s potential to revolutionize third-party agreements has its limits. By outsourcing business functions, CIOs can reap cost and, in some cases, expertise benefits, but they also reallocate risk from in-house talent to employees of third-party firms<\/p>\n","protected":false},"author":1,"featured_media":873335,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1812,91771],"tags":[5049,7423],"class_list":["post-873334","post","type-post","status-publish","format-standard","has-post-thumbnail","category-could","category-radically","tag-could","tag-radically"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/873334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=873334"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/873334\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/873335"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=873334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=873334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=873334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}