AI is a prime-time conversation in every walk of life. No longer just a buzzword. AI is changing the Enterprise Security model, so I ask, “ Are you ready for this IT transformation? ” Organizations everywhere are accelerating artificial intelligence initiatives at a rapid pace and scale.
Most conversations focus on what AI can do for business today and how fast it will be deployed. AI drives automated workflows, autonomous efficiencies, supply chain improvements, faster time to market, and productivity. True modernization comes from constantly reviewing how things are done, embracing new tools, protocols, and working practices to improve how we get things done.
Traditional enterprise systems were designed around methodical human interactions. Users logged into applications, followed defined workflows behind a green screen or nightly batch process, and operated within a single data center. To develop code to support these new fast-moving AI initiatives, we will adopt tools like IBM Bob to modernize legacy code and develop new workflows. Modernization will improve applications, strengthen security, simplify maintenance, and drive strong business outcomes.
Data today is scattered across private and public clouds, multiple databases, platforms, and geographies. With AI agents deployed from multiple access points inside and outside your organization, what data are you comfortable exposing in real time to your customers to conduct business? While staying aware of phishing scams or, worse, hackers.
Data Access Must Align With Transformation To Support AI
In enterprise environments, our data often spans IBM Power systems, both IBM i and AIX, hybrid clouds, SaaS platforms, and edge infrastructure. This creates enormous opportunity, but also introduces a completely new layer of operational risk. Today’s AI platforms, copilots, and autonomous agents do interact dynamically across databases, APIs, platforms, operational tooling, and infrastructure environments, likely simultaneously.
Moving to modern architecture represents one of the most fundamental shifts in IBM i modernization. Service-oriented architecture (SOA) and hyperscale microservices let you break up traditional applications into smaller, more manageable components that communicate through well-defined interfaces.
This architectural shift lets you expose IBM i business logic as APIs or web services that web applications, mobile apps, or partner systems can consume. This also enables easier, more productive integration with the generation of AI assistants hitting our Power Systems. The benefits extend beyond integration; modular architecture makes applications easier to maintain, test, and evolve.
Enabling Applications To Be Cloud Ready
The legacy business model of employees just sitting at their desks, connected to systems through local trusted 5250 workstations and networks, has fundamentally changed. Today’s workforce expects to access information from anywhere, whether at the office, roaming the warehouse, at or a customer site, or even traveling abroad.
Cloud computing has transformed how organizations think infrastructure, offering flexibility and capabilities to enterprises of all sizes. Cloud access to IBM i applications can offer benefits that extend far beyond remote connectivity. It enables you to scale resources dynamically based on demand, rather than provisioning for peak capacity that sits idle most of the time. Cloud facilitates disaster recovery and business continuity by providing geographic redundancy without the cost of maintaining multiple physical data centers.
Cloud access doesn’t mean abandoning your IBM i platform or migrating everything off premises. Cloud deployment simplifies partner and customer access, letting you provide secure, controlled access to specific applications without complex network protocols. Some organizations may also adopt hybrid approaches, keeping core systems on premises while using cloud services to extend access and capabilities and embrace AI. This flexibility lets you modernize at your own pace while maintaining security and maximizing agility.
AI – Security Posture
Your mission critical applications and data are the lifeblood of your business, and your customers trust you to keep their information secure. Review your current AI security posture to maintain situational awareness of your deployed security baseline.
Your IBM Power systems are only as secure as their baseline configurations, which may have been appropriate years ago but likely no longer meet today’s requirements. Assess all system-wide security settings, user-level permissions, exit points, and audit journaling. IBM i security follows a “ Deny by Default” model, meaning access to applications and data is denied unless explicitly authorized.
Some organizations once relied on system defaults because their systems operated within the controlled boundaries of an on-premises data center. As a result, library-based objects may allow any user to read or even modify data. Directory and library objects may likewise grant all users permission to read, modify, or delete them. Today, access methods such as ODBC, SSH, DRDA, and HTTP extend far beyond the tightly controlled 5250 environments of the past, potentially leaving organizational data highly exposed in the era of cloud computing and AI.
Deny by default is the expected security strategy.
Data is vulnerable when not secured.
*PUBLIC authority is *EXCLUDE for library-based objects and DTAAUT(*EXCLUDE) OBJAUT(*NONE) for IFS objects.
Data classification determines how information must be protected. For example, Deny by default or allow read-only access and determines whether it must be encrypted in transit and at rest. It also defines authorized uses, including whether the data may be used to train AI models. A sobering thought: Classification reflects the data’s value to the organization and helps ensure it is handled securely and appropriately throughout its lifecycle. The data owner is responsible for setting these requirements. Classification is not a one-time exercise; as AI evolves, organizations should review all classifications annually.
Auditing Posture To Monitor The Muscle Of AI
Audit and compliance requirements are typically driven by the organization’s industry (such as healthcare or finance), the type of data being stored or processed, or the laws of the specific country governing data. The data owner and/or application architect should know the requirements of the data your application provides access to and should be able to support these security access requirements. IBM Authority collection is a capability available on IBM i that captures data that is associated with the runtime authority checking that is built into the IBM i system. The system logs this data into a repository, and interfaces are available to display and analyze it. By using the authority collection capability, you avoid excess authority and improve the overall security of the objects used by an application.
Furthermore, use SIEM (Security Information and Event Management) collection to analyze log data across your digital infrastructure in real time, detect and respond to threats, and even analyze access AI patterns. Test and remediate your security policies to validate the baseline, reexamine denial of access and data classification with a security incident policy roadmap.
To complete your security AI roadmap, perform an external IBM i penetration test to identify open ports and unsecured services beyond access to the data itself, providing an actionable list of ranked, exploitable issues and objective proof of vulnerabilities.
IT Resilience In The AI Evolution
Systems of record that once ran in the background are now exposed to real-time connections. To keep business systems available, IT must deliver protected, commercial-ready ERP applications, scalable throughput, on-demand analytics, and secure mobile and social capabilities.
IT resilience today requires more than just nightly backups for a complete data protection strategy. Businesses need a Highly Available reference architecture and effective technology solutions, including Continuous Data Protection (CDP), SAN Tooling with Global Mirror and PowerHA, and DB2 Mirror , bundled with Immutable Backups and Disaster Recovery to deliver the best resiliency available. Being able to recover to the journal commitment boundary in minutes before an unauthorized or unintentional database update or failover to your active database on another IBM Power system host is the new resiliency expectation.
CDP uses journaling technology to track all transactions, while Db2 Mirror uses remote direct memory access (RDMA) across two paired nodes to create a synchronous environment. With Db2 Mirror, automated clones, and global mirror, iASP keeps production environments online during planned maintenance with near-zero data loss, as any DB and System updates are automatically mirrored to another server.
These are powerful tools for building IT resilience; when combined with orchestration capabilities, they enable multiple recovery points. RTO and RPO today are measured in minutes and hours rather than days – IT must align their systems availability and data protection schemes operationally (with proven Runbooks) and strategically with their business goals for business continuity, high availability, and disaster recovery.
AI Taking Center Stage
Cloud strategies will continue to evolve, with more businesses shifting away from “ cloud-first ” silos toward application workload-specific deployments in multiple clouds to support AI initiatives. Businesses recognize the importance of flexibility in where and how they deploy workloads; therefore, cloud portability is needed to access data and meet the challenges of digital AI evolution.
Many employees are already using AI tools to summarize documents, analyze data, emails, record and summarize sales calls, generate code, or troubleshooting issues without formal governance policies or approved organizational boundaries. However, in some organizations, sensitive business data may already be flowing through AI systems without leadership teams fully understanding the exposure. This is why AI governance cannot be treated as a future initiative. The time is NOW ! This is rapidly becoming a core operational discipline alongside cybersecurity, compliance, disaster recovery, and infrastructure governance. AI will take center stage, transforming how companies manage their data while demonstrating resiliency, scalable performance, and security.
Organizations should begin by asking:
What systems should AI access?
What data should remain restricted?
How AI interactions being monitored / audited?
Governance – Reporting
How do Data Protection strategies support AI-driven threats?
These are mission critical realities that will increasingly affect enterprise resiliency and security posture. The good news is that organizations do not need to abandon existing enterprise platforms to participate in the AI era. IBM i is secure and ready for this transformation. Environments like IBM i are exceptionally well positioned because they already serve as systems of record with mature business logic, transactional integrity, and integrated security controls. Now we must add observability to how we operate and protect the data we manage.
The organizations that succeed with AI will not simply be the fastest adopters. They will be the companies that build AI strategies on a foundation of visibility, operational control, resiliency, governance, and trust. AI is an enabler . What’s your play in this transformational technology?
Richard Dolewski is vice president of hybrid cloud and infrastructure services at Lightedge He is a recognized IBM Power Champion with decades of experience helping organizations modernize, protect, and optimize mission-critical IBM i environments. His expertise spans cloud strategy, business continuity, disaster recovery, high availability, security, and infrastructure modernization.
Thinking Moving IBM i To The Cloud? Don’t Start With The Quote
Lightedge To Start Selling IBM PowerVS to IBM i Customers
Lightedge Acquires Connectria To Round Out Each Other’s Power Play
In The IBM i Trenches With: Lightedge Solutions
NGS And Lightedge Provide New Entry To The Cloud
Lightedge Shops A “True Cloud” To IBM i Users
Iowa MSP Teams with Vision for Hosted HA
AWS Inks Deal With Connectria To Have a Power Play
Connectria And Curbstone In Payment Tie-Up
Connectria, Now A Top AWS Partner, Primed For Hybrid Push
Getting Started With Connectria’s Hybrid IBM i And AIX Architecture
A Year Later: Diving Deeper into How Connectria Brings IBM i Workloads Closer to AWS
Profound and Connectria Hook Up in Cloud-Modernization Push
Cloud Provider Connectria In Major Partnership Push
Your IBM Power Cloud Strategy Should Start With “Why?”
Moving IBM i to the cloud isn’t just an infrastructure decision.
A hardware refresh, data center exit, IBM i skills gap, disaster recovery requirement, or broader cloud initiative can each lead to a very different architecture.
At Lightedge, we start by understanding what you’re trying to accomplish. Then we look at the workload, application dependencies, resiliency requirements, operating model, and long-term strategy to determine where that workload belongs.
Managed IBM Power cloud? IBM Power Virtual Server? DR in the cloud? A hybrid architecture connecting IBM Power with AWS or Azure?
There isn’t one right answer for every IBM i environment.
Start with the business requirement. Understand the workload. Then decide where it belongs.
Explore IBM Power cloud, managed services, and hybrid solutions from Lightedge.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
