Skip to content

AI NewsPublished 6 min read

CBTS Unveils Blueprint: Rollout Claims to Weigh

nodes passing glowing task tokens along branching paths
Listen to this article · 9:27 · AI-generated narration
0:00 / 9:27
Chapters

CBTS ran the rollout on its own staff first

CBTS, a North American technology services company, unveiled its blueprint for 100% agentic delivery for mid-market companies on September 23, 2026, Business Wire reported.

The blueprint draws on an enterprise-wide rollout of Claude Enterprise by Anthropic across the company's own workforce, Vmblog reported on September 23, 2026. CBTS scaled the Anthropic model across 2,300 employees, testing it on its own complex business first, Vmblog said. The deployment covered Claude for research and drafting, Claude Code for technical and engineering tasks, Cowork for cross-functional projects, and Claude Design, according to Vmblog.

Digitaljournal reported on September 23, 2026, that CBTS acted as its own "Client Zero", using internal operations as a proving ground before extending the approach to customers. The company has said the breadth of the rollout let it identify where AI generated measurable value and where human oversight remained critical, Digitaljournal reported.

The short version

CBTS unveiled a blueprint for fully agentic delivery at mid-market companies on September 23, 2026, Business Wire reported. Vmblog reported the company built it after scaling Anthropic's Claude Enterprise across 2,300 of its own employees. CBTS says the program reached return on investment in under three months with no major security incidents to date, Digitaljournal reported.

  • Vmblog reported that CBTS defines mid-market as firms with annual revenues between $300 million and $3 billion.
  • Digitaljournal reported that CBTS acted as its own Client Zero before extending the approach to customers.
  • CBTS CEO Kristin Russell said the goal is parity with companies ten times the size of mid-market buyers, Vmblog reported.
  • Chris DeBrunner, CISO at CBTS, said vendor evaluation, threat testing and governance come before any agent reaches production.
  • AOL reported that industry leaders formed the Blueprint Alliance on September 22, 2026, to secure AI agents.

The blueprint aims at a specific revenue band

Mid-market companies, defined as firms with annual revenues between $300 million and $3 billion, have not had the budget to experiment, fail and try again, Vmblog said. Those firms frequently lack the financial resources and specialist expertise available to global enterprises, Digitaljournal reported.

Bdtonline, which carried the announcement on September 23, 2026, said the approach is designed to help organizations move beyond AI pilots with the governance, security, infrastructure and operating model needed to scale adoption across the business.

CBTS CEO Kristin Russell tied the release to competitive parity for smaller buyers. "The goal is to give mid-market companies across North America the tools to compete on equal footing with companies ten times their size," Russell said in the announcement carried by Vmblog. Russell also said that with CBTS, all companies can now access world-class AI knowledge, security, consulting frameworks and analytics once reserved for large corporations.

Vmblog reported that the target state means every business function across sales, operations, security, delivery, IT and beyond runs on agentic AI.

CBTS reports payback in under three months

The program reached return on investment in under three months while recording no major security incidents to date, according to the company, Digitaljournal reported. Digitaljournal published those figures alongside the blueprint release and attributed them to CBTS; they have not been confirmed elsewhere.

Security and governance were a board mandate from day one because agentic AI touched every part of the business, Vmblog reported. The company packages that work as CBTS Forge AI, Vmblog said.

"Our comprehensive approach spans vendor evaluation, threat testing, and governance across the attack surface before any agent reaches production," said Chris DeBrunner, CISO at CBTS, in remarks carried by Vmblog. DeBrunner framed the underlying question as how a mid-market CISO uses AI to do more with less without opening a door that cannot be closed.

A separate agent security alliance formed a day earlier

Industry leaders formed the Blueprint Alliance in Las Vegas on September 22, 2026, a cross-industry coalition meant to help organizations operate their agentic stack as a unified, governed system, AOL reported on September 23, 2026.

Founding members aligned on principles that include treating every agent as a first-class identity, scoping access to the task rather than granting standing access, keeping delegation traceable, monitoring runtime behavior continuously, and enabling containment that is instant and reversible, AOL reported. The coalition is turning a reference architecture first introduced in March 2026 into an open, multi-vendor standard that answers where an organization's agents are and what they can do, according to AOL.

Gartner predicts that by 2028 an average global Fortune 500 enterprise will have over 150,000 agents in use, while only 13% of organizations think they have the right AI agent governance in place, AOL reported. GE Appliances and World Central Kitchen will serve as strategic advisors helping the Alliance refine and validate the approach to securing AI, AOL said.

Mandar Deo, Chief Digital Technology Officer at GE Appliances, said unlocking that value at scale requires strong governance and clear visibility into where agents operate, what they can access and how they make decisions.

Tron's take

My read is that two different things shipped on the same day, and only one of them is verifiable today. The Blueprint Alliance principles AOL described, such as scoping agent access to a task and keeping delegation traceable, are testable controls a small IT team can apply this quarter. The CBTS payback figure is a self-reported result about the company's own 2,300-person workforce, and I would treat it as a vendor claim until the measurement method is published.

Most readers of this site sit below the revenue floor CBTS names, so the blueprint reads to me as a reference point rather than a product built for them. That cuts both ways. The part I find useful is the sequencing: governance and security settled before agents reach production, not after. The part I would not copy is the goal of running every function on agents, which is a services company's bet on its own product line.

My advice is narrower. Before adding any agent that can act on email, files or code, write down which identity it uses, what it can reach, and how a person revokes it. That is an access review, and XL.net sells that work as part of its security assessments and managed IT services, so weigh the recommendation accordingly. XL.net's AI Desk has tracked the same control gap in recent stories, including Google's confirmed Gemini hack. Waiting a quarter to see whether CBTS clients report similar results costs a mid-sized firm very little. That is my reading of the news, not a reported result.

Questions I'd expect

What did CBTS announce on September 23, 2026?

CBTS unveiled a blueprint for fully agentic delivery aimed at mid-market companies, Business Wire reported.

How large was the internal deployment?

Vmblog reported that CBTS scaled Anthropic's Claude Enterprise across 2,300 employees before extending the approach to clients.

Which companies does CBTS count as mid-market?

Vmblog reported that CBTS uses annual revenues between $300 million and $3 billion to define the mid-market buyers the blueprint targets.

Where does the return-on-investment figure come from?

Digitaljournal reported the under-three-months payback and the absence of major security incidents as figures the company stated about its own deployment; the results have not been confirmed elsewhere.

What is the Blueprint Alliance?

AOL reported it is a cross-industry coalition formed on September 22, 2026, in Las Vegas to build a shared, multi-vendor architecture for securing AI agents.

All AI news