The AI and digital transformation winners in 2027 will not be the earliest adopters, believes Stephen George, Sr. Associate Director, HSBC. Rather the winners will be the organizations that scaled AI safely, measurably and with trust built in. In an exclusive conversation with Bhavya Bagga, Business Reporter, CXO Media & APAC Media, George advises CIOs to build an AI operating model covering governance, platforms and accountability, fix the data foundation, start a cryptographic inventory, simplify the application portfolio and reskill at scale.
Organizations are under pressure to modernize legacy technology while keeping costs, security and business continuity in check. What are the biggest challenges technology leaders face in this transition, and how is AI changing the approach to application modernization?
The hardest part of modernization is rarely technology. It is the hidden dependencies. Core systems built over decades carry undocumented business rules, tightly coupled integrations and a shrinking pool of people who understand them. We must modernize while the business keeps running, with no tolerance for downtime and budgets still weighted towards “keeping the lights on.”
Three challenges dominate:
- Lost knowledge. Critical logic nobody can fully explain.
- Big-bang risk. Large cutovers that put continuity at stake.
- A hard business case. Costs arrive early and benefits arrive late.
AI is changing economics. Generative AI can now read legacy code, extract business rules, generate documentation and test cases, and suggest refactored services. Discovery that once took months now takes weeks. For example, a bank can use AI to map its mainframe batch jobs, find unused code and retire it before migrating anything. That shrinks both cost and risk.
The approach shifts from “lift and shift” to continuous, incremental modernization: API layers around the core, replacing capabilities one at a time, and AI-assisted conversion with engineers validating every release. My advice is to modernize by business capability, not by system. Measure success in release speed and fewer incidents, not migration milestones.
As enterprises adopt generative AI and AI-powered automation at scale, what should technology leaders prioritize to ensure data security, governance, compliance and operational resilience?
Leaders must treat AI as a new class of critical infrastructure, not a productivity tool. I would prioritize five things:
- Data before models. Classify data, track where it comes from, and enforce access rights. If an internal AI assistant uses retrieval, it must respect existing permissions. A branch employee should never be able to surface board papers through a clever prompt.
- Guardrails by design. Protect against prompt injection, filter outputs, prevent data leakage, and block sensitive data from reaching public models.
- Governance proportionate to risk. Keep an inventory of every model and use case. Tier them by impact, and require human review for decisions affecting customers, credit or compliance.
- Regulatory alignment. Map controls to frameworks such as India’s DPDP Act, the RBI’s FREE-AI guidance and the EU AI Act. Make explainability and audit trails standard.
- Operational resilience. Treat AI providers as critical third parties. Build fallback modes and a “kill switch,” and test what happens when a model degrades or becomes unavailable.
One practical step is an AI risk council. It brings technology, risk, legal and business together to approve use cases in weeks, not months. Good governance should speed up adoption, not slow it down.
Infrastructure, cybersecurity, automation and application management are increasingly becoming interconnected. How do you see these areas evolving as enterprises move towards AI-driven IT operations and more autonomous systems?
These areas are merging into a single, intelligent operating fabric. The old silos (infrastructure team, security team, application support) cannot keep pace with hybrid cloud, microservices and AI workloads that change by the minute.
Observability becomes the nervous system. Unified telemetry across infrastructure, applications and security events lets AI correlate signals that humans would miss. A latency spike, an unusual login and a configuration change may be one incident, not three tickets.
I see autonomy maturing in stages:
- Observe.
- Recommend.
- Act with approval.
- Act on its own for low-risk tasks.
Examples are already real: certificates that renew themselves before they expire, infrastructure that scales ahead of predicted demand, and security playbooks that isolate a compromised endpoint within seconds.
Two shifts matter. First, security must be built into automation itself. Every AI agent is a new identity with privileges, and it must be governed like one. Second, the role of people changes from operators to supervisors. Teams will write policies as code, set guardrails and handle the exceptions.
The goal is not “lights-out IT.” It is resilient IT: systems that heal routine faults on their own so engineers can focus on architecture, customer experience and innovation.
Many organizations have experimented with AI but continue to face challenges when moving projects into production. What technology, data and organisational capabilities are needed to turn AI initiatives into measurable business outcomes?
Most AI initiatives do not fail on the algorithm. They fail on everything around it. Escaping “pilot purgatory” takes three sets of capabilities.
Technology: a shared AI platform rather than one-off builds. That means reusable components, evaluation frameworks, monitoring for drift and hallucination, and cost controls. Every new use case should get faster and cheaper to deliver.
Data: trusted, well-governed data products with clear owners, quality standards and secure access. An AI model built on fragmented data only produces errors faster.
Organization: this is the decisive factor.
- Each use case needs a business owner, not just a technology sponsor.
- Define the baseline and the success measure before building. For example, an AI claims-triage tool should be judged on reduced handling time and leakage, not model accuracy.
- Fund outcomes through product teams, not short projects.
- Invest in change management, so frontline staff trust and actually use the tools. • Set clear criteria for stopping use cases that don’t deliver.
I recommend a portfolio approach: a few high-value, end-to-end use cases taken all the way into production, rather than fifty proofs of concept. Scale comes from repeatable success, and credibility with the board comes from measured outcomes.
Looking ahead to 2027, which technologies or trends do you expect to have the biggest impact on enterprise IT? What should CIOs and technology leaders be doing now to prepare for the next phase of digital and AI transformation?
Five trends will shape enterprise IT by 2027:
- Agentic AI. We are moving from AI that answers to AI that acts: agents running multi step workflows in onboarding, procurement and IT operations.
- AI-native software delivery. AI will write, test and secure much of the code, which changes team structures and productivity benchmarks.
- Post-quantum cryptography. “Harvest now, decrypt later” threats make cryptographic migration an urgent risk for regulated industries, not a distant one.
- Identity-first security. Machine and AI-agent identities will vastly outnumber human ones. Deepfake-driven fraud will test every verification process.
- AI economics and sovereignty. Compute costs, energy use and data-residency rules will drive hybrid, sovereign cloud strategies and financial discipline over AI spending.
What should CIOs do now?
- Build an AI operating model covering governance, platforms and accountability.
- Fix the data foundation. It remains the biggest constraint.
- Start a cryptographic inventory. You cannot migrate what you cannot see.
- Simplify the application portfolio to free up funding.
- Reskill at scale. Every role, from engineer to analyst, will work alongside AI.
The winners in 2027 will not be the earliest adopters. They will be the organizations that scaled AI safely, measurably and with trust built in.










































