
Agentic Governance : Why Enterprise AI Changes the Rules of Governance
WHAT DOES AGENTIC AI GOVERNANCE REQUIRE?
Agentic AI governance requires more than model approval. Enterprises need use-case accountability, identity and permissions for agents, bounded autonomy, policy enforcement, traceable actions, runtime monitoring, incident response and human escalation. Controls should be proportional to the consequence and reversibility of each action.
KEY TAKEAWAYS
• Governance must operate during execution when agents can choose and perform actions dynamically.
• Identity, authority and explicit boundaries are architectural requirements for autonomous systems.
• Shared semantics, context and provenance help participants reconstruct why a decision or action occurred.
• Policy engines and runtime monitoring complement—not replace—business accountability and human escalation.
• Trust depends on evidence, reversibility and clear responsibility across the full operating model.
SOURCES AND FURTHER READING
NIST Artificial Intelligence Risk Management Framework 1.0: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10
Australian Government agentic AI addendum: https://www.digital.gov.au/policy/ai/agentic-ai-addendum-introduction
Australian Government policy for the responsible use of AI: https://www.digital.gov.au/ai/ai-in-government-policy
RELATED EPISODES
The Agentic Enterprise: https://www.enterprisetechtalk.com/episodes/agentic-enterprise-scaling-ai-controlling-costs-redesigning-work
From Systems to Agents: https://www.enterprisetechtalk.com/episodes/systems-to-agents-enterprise-architecture-ai
AI Engineering Beyond the Hype: https://www.enterprisetechtalk.com/episodes/ai-engineering-harnesses-guardrails-production-realityThe enterprise AI conversation is evolving rapidly.
For the last two years, most organisations have focused on copilots, productivity gains, and experimentation with generative AI. But the next phase is fundamentally different. Enterprises are now beginning to explore agentic systems — AI agents capable of reasoning, collaborating, making decisions, and taking actions autonomously across workflows and platforms.
That shift introduces a much larger question than technology itself:
How do organisations govern systems that are no longer entirely predictable?
In the latest episode of Enterprise Tech Talk, I spoke with Jesper Lowgren, where we unpacked one of the most important emerging enterprise architecture and governance challenges: Agentic Governance.
One of the strongest themes from the conversation was the idea that traditional governance models are increasingly insufficient for autonomous AI ecosystems.
Historically, enterprise governance has largely been reactive. Policies were documented externally. Governance forums reviewed decisions after the fact. Controls were implemented around systems rather than deeply embedded within them.
But agentic systems behave differently.
As Jesper explained during the discussion, once multiple agents begin collaborating and making runtime decisions, governance can no longer sit outside the system. Governance itself must become part of the architecture.
That distinction is profound.
The conversation explored how enterprises are moving from deterministic software models toward systems driven by goals, policies, constraints, and runtime interpretation. Instead of coding every procedural decision, organisations will increasingly define boundaries, intent, and governance guardrails that agents must operate within.
This creates entirely new architectural considerations.
The discussion unpacked concepts such as:
Agentic middleware and shared contextual backbones
Runtime governance and provenance tracking
State-machine driven controls
Policy engines and goal architectures
Ontology and semantic consistency across agents
Explainability and trust in autonomous ecosystems
One particularly important insight was around emergence.
Traditional enterprise systems are largely predictable. Agentic systems are not. Once multiple agents interact, collaborate, negotiate goals, and adapt dynamically, emergent behaviour becomes unavoidable. The governance challenge therefore shifts from controlling static systems to governing dynamic interactions between intelligent entities.
That is a very different operating model.
We also explored the implications for enterprise architecture itself. In many ways, architecture functions may become more important in the agentic era — not less. But their role changes significantly.
Instead of primarily designing static future-state models, architects increasingly need to shape runtime ecosystems: policies, constraints, semantic models, contextual flows, trust frameworks, and orchestration mechanisms.
The conversation also highlighted a practical reality many organisations are still underestimating: technology is not the hardest part of this journey.
Mindset change is.
Many enterprises are attempting to jump directly into autonomous agents and multi-agent systems without fully understanding the operational, governance, and behavioural implications. As Jesper noted, organisations must first build foundational AI fluency across leadership teams, architects, engineers, and operational stakeholders before attempting large-scale autonomous ecosystems.
Perhaps the most important message from the episode was this:
Agentic governance is not an extension of traditional governance. It is a fundamentally new discipline emerging at the intersection of enterprise architecture, AI engineering, operating models, and organisational trust.
And over the next few years, it is likely to become one of the defining capabilities separating enterprises that can scale AI safely from those that cannot.
Episode Transcript
FULL TRANSCRIPT
This transcript is based on the episode’s English auto-captions and has been formatted for readability. Please allow for occasional transcription errors in names, acronyms and specialised terms.
[00:00:00]
So when you're building an agentic system, you are not going to fully understand the risks and that's the complication. How do you govern something where you don't really understand what's going to happen? You have to take the entire governance construct from the outside and you have to put it inside the system. That can't be any separation. Governance is actually lost because of aic systems they are unforgiving. You can't approach an agentic system with technical debt. it will drift immediately. It's a wrong mindset. If you have a set of policies and there's a policy missing, the agent is not going to tell you there's a policy missing. The agent is going to think, okay, there's something missing. I'm still going to make a decision. So, your commission, your thinking, and you bring the context into your middleware and that's an absolutely essential component of the reference architecture. You can't build an aentic system if you don't have the middle. I mean, imagine that you have an agent from the government and you have an agent from an organization and you're doing some kind of transaction in terms of tax that goes wrong. Whose fault is Hello and welcome to the Enterprise Tech Talk podcast. I'm your host Saumitra Kalikar. Now in the last few years, the enterprise AI conversation has evolved rapidly. Organizations are experimenting with agentic systems which can plan and act autonomously.
[00:01:40]
As these agentic systems now get deeply embedded into enterprise workflows, an important question is emerging as to how organizations should effectively govern these systems and what adequate control should be in place without slowing down innovation and that is the focus of today's conversation how to govern agentic systems and to help me unpack this important topic I'm joined today by Jasper Lok Okay, Jesper is the agentic enterprise architecture lead at DXC Technologies. Jesper, welcome to the podcast and great to have you here. >> Thank you. Excited to be here and thank you for inviting me. >> So Jesper, before we take a deep dive um I would love to start with your own journey. Uh you have worked across enterprise architecture, AI strategy and so on. So uh what shaped your journey into enterprise AI and agentic systems?
[00:02:44]
>> I think if you go back in time, I'm a system thinker and when you think in the context of systems, I think you naturally gravitate towards architecture and especially enterprise architecture. So enterprise architect is all about systems on top of systems is making sure that you have an enterprise and all of the components in enterprise that they're working together and they're creating the maximum benefit. So I was very interested in that early on and that's that's how I got into enterprise architecture. started with a business architect. That was my angle in. And then a few years ago, I came in contact with CH GBT3 and I have a YouTube channel and I made my first video on CH GBT3 and I got almost hooked on AI immediately about the potential of what it can do if we can harness its power correctly. And of course, the real problem in harnessing the power is governance. that that is standing block.
[00:03:45]
So I spent the last two two and a half years deeply in the AI space both in terms of my work at DXC technology where I'm driving the thought lead issue and IP development etc in this space but also also personally in my own research my own networks etc. So I've spent a lot of time in the last two years really understanding the nature of an aentic system and most importantly how do we govern it so we can trust it that is doing what we want it to do. >> Um let's start with some grounded conversation um Jasper just to make sure that our audience is on the same page uh before we take a deep dive. Now when you talk about agentic systems to with your business leaders or with your customers um etc. um how do you try to explain that in a more simple and practical uh manner and how do you try to differentiate that with um the traditional automation uh solutions that have been in place including gel radio?
[00:04:49]
>> Yeah. And if I stray it's a big question if I stray you just just to bring me back again. There are a number of different ways that this can be explained. One thing that I like to use when I'm explaining to business and I explain mainly to business leaders, not so much skilled technology leaders and I'm using the agentic maturity construct. So in a typical maturity level, you have five levels going from one two three four five and one is is essentially ad hoc and five is optimized perfect and then you have all these shades in between. That's a very useful structure of AI. At level one, you would have your bot um that we all familiar with. You're going to chat, ask a >> Mhm. >> You get response and that's important for organizations because there's a lot of productivity to be gained with that even if you can't measure it. Then in level two, things are starting to change. This is when we talk about agents. So you can have a particular agent like an onboarding agent um for a call center if you if you're recruiting a new employee and you can use AI to onboard them and train them etc. Uh or you can have a policy agent that is quering policy data. So that's your single agent that sort of fits within the concept of organizations today. You don't need a new operating model. You can take your existing governance infrastructure and you can put it on top of the agent and it will work. It will be a little bit brittle but it will work.
[00:06:26]
>> The real change comes when you go into the next stage level three and I'm calling that agency and agency is a huge work in AI and that is what makes it so different from for example robotic process automation. Agent aid is ultimately about decision rights and what kind of decision rights can be conferred to an agent and how do we make sure that they're sticking with these decision rights. So these are very very new challenges in intent and then number four and now we're going further we're turning on autonomy. So number three is agency number four is autonomy. So agency is really about what kind of decisions are we outsourcing to agents. Autonomy is how far do we allow the agents to go in the decision making. So agency can be seen as a breadth and on top is a depth of the decision making >> and level five is a bit academics. I don't think I don't think that's much talking about that. So when I'm explaining agentic AI to an organization this is how I explain it and a lot of organizations matter of fact everyone today are either on level one and level two and they're experimenting with the agent etc. And the biggest message I have in my conversations is that the gem the jump between level two and level three is exponential. It is that way of shame. That's when we talk about transformation instead of optimization.
[00:07:59]
That's when you need to rethink your business process rather than just improving it. >> Yeah, that's a good way of of explaining this. And if I if I then apply the the a governance l on top of it, Jasper, I would assume and correct me if I'm wrong, but most of the organizations should be comfortable at level one and 11 to today. uh for today's >> um and what fascinates me is uh the the AI governance itself is relatively new only last two three years and most of the organizations are m little bit of maturing there are still figuring out how to do that effectively but at the same time now they are actually um also piloting the agentic systems and multi-agent systems etc right so what's what I'm seeing is that uh there is a widening gap so to speak between the governance majority around AI and the the technology direction the space at which technology is evolving.
[00:09:02]
So maybe it will be good to paint a picture on how the tra now I should say within two three years already the traditional AI governance looks like and when you then start to in your methodology level three onwards um when you companies start talking about the agentic and multi-agentic systems what's the incremental governance aspect they should be considering >> right let's let's go let's get to the core of the problem immediately. >> Yeah. >> So what happens is that this concept of emergence. So we need to stay with that for a second. And emergence can happen in two ways. >> It either happens if you're putting a number of different components together in your system, you always get emergence. And a good example is your car. >> If you keep on driving the car and you don't do anything with it, you only put petrol in it. Some it's going to break down eventually. You don't know where it's going to break down. You don't know the component. you can't actually predict but you know that something is going to break.
[00:10:06]
>> Yeah, >> that's called emergent behavior. The other aspect of emergent behavior that is related to free will uh cognition. When we have free will, we're always going to have emergence. I mean that's the nature of free will is to think independently. When we are putting these two things together, >> we're getting emoj >> and it gets and it gets worse. And this is really the crux is that when you're connecting all of these agents, let's say that you have five agents and 10 agents and they're not sitting on their own doing things with a human in between. They've actually been connected. They're working together. There's no there's no human in the loop. the the entire governance conversation shift. It's not part what happens inside the agents that's it's not irrelevant but it's not as important as what happens in between the agents. It is the collaboration of the agents. It's the traffic in between the agents that is what we need to govern. And the problem here and now now I'm going to crystallize it is that you don't know what emergent behavior is. So when you're building an agentic system you are not going to fully understand the risks and that complication. How do you govern something when you don't really understand what's going to happen when you can't fully quantify the risks? And that is changing the picture completely.
[00:11:35]
And that means that all of the all of the old governance methods uh where you have a governance team and it's sitting outside and they're looking at the result and have the checklist. None of that in this world because of you have this emergence and it happens very quickly. You have to take the entire governance construct from the outside and you have to inside the system. That can't be any separation. Governance is actually the system. And I think that's a bigger thing where we can immediately identify whether someone understands governance or not. Because if you talk about governance as an add-on, okay, we're going to build the governance agent or we're going to build the governance layer that shows that shows that you don't really understand governance in the context of an agent system. Yeah, that's that's well said. uh and um and I wanted to then unpack that further in terms of so understanding what are the important principles any uh organization should consider governance principle when they think of implementing multi- aent systems because as you said traditional governance has always been all about control um right in a way uh a lot of manual processes around those etc and that's >> control after the fact >> yes control after the fact before the fact. >> Yeah, exactly. That and that's a really good good point and u uh so it's more reactive as you said than than being proactive. Um but that's not going to work in the agented uh world, right? Um so when organizations who are used to that kind of governance model and now they're actually thinking of age multi- aent systems etc.
[00:13:30]
If you want to think of what are the key principles or guard rails they should be thinking of in terms of changing the way they do govern. Can you paint a picture to what are the new things they should be thinking of? >> Yeah. And it's actually quite big. And the hardest thing here is not the technology. The hard here is a mindset shift. And I think that we mindset shift has been talked about throughout this entire digital transformation journey that we've been on for the last 15 years or so. But I think now becomes real because the agentic systems are different. When you have a digital system, you actually don't need to adopt all of the digital principles. You can say, I just want a little bit of automation and I'm happy to incur a lot of technical debt and I can I can put in a lot of humans into a process and the process will work. It will be expensive. It will be slow, but it will work.
[00:14:29]
>> Or you can say I'm going to invest a lot of money. I'm going to get a lot of automation and obviously you have less people and more of automation. That's how we think. That is that is how evolution takes place. We are put we're dipping our toe to toe in the water and we take a lot of stuff from the old world with us into the new world with a little bit of new new stuff in it and then we try to evolve from there on that can't happen in this space because of aic system they are unforgiving. You can't approach an agentic system detected or debt it will drift immediately. It's a wrong mindset. You actually have to tighten everything 100% up front and then you need to understand that if you're going to let certain areas of the system drift, you have to be crystal clear on what is going to drift and why it's going to drift so you can get some kind of understanding of the risk whether it is.
[00:15:30]
So it is it's a very different conversation and it starts with it start with understanding how we're designing and thinking about these systems conceptually. So in the past we we're designing a system and then we are coding it. So we are putting all of the rules and the logic actually sits in application code itself and then after the build we are compiling that code and we run it and that code can access all kind of configuration data. So you can change its behavior dynamically but the code is the same. the code doesn't change in the agentic world. Again, everything is changing and I'm I'm going to expand on this a bit, but in the agentic world, you don't code an agent. You don't need to code an agent. The agent is capable of coding. That's a reasonable habit. It can think and reason and do things on its own. So it makes no sense for us to take procedural logic if then else and give that to an agent because the agent can do that already.
[00:16:42]
So we want the agent instead to do to do as much thinking as possible. We we want we want the agent to do what it is what it is really good at. And in order to do that there are few things that we need to think about when we're designing the system. So there couple of concept here I'm going to go through them one by one. One of one of them is is a contact concept of atomicity. >> We build atomic agents. It is so easy to say all right I want an agent to be able to do this and then we want them to do this as well. So we add that onto agent. Wrong thinking. If we give an agent two things to do, it will get confused. >> It might only get a little bit confused, but that's enough for drift. So an agent has to be atomic. It has has to have a single purpose for example. So that that is the design decision. The other design decision coming back to the intelligence and the logic now is that when we're looking at the genetic AI and I find the really good analogy is is a genie in a bottle that's really is so we're pretending we have a genie in a bottle and a genie is obviously the genetic AI we can give the genie an instruction set and say you can do this or you can't do that you can do that the genie is really smart is going to get around that and it's going to do its own thing anyway.
[00:18:14]
>> So we can't use the code or the logic to control the genie. What we need to do is we need to control the bottle with leaning exactly the same in aentic AI. We actually don't try to control the agent directly. We are building a boundary around the agent. So the word bound is a key word in AI. So it's all about understanding the boundary and making sure that the agent stays within that boundary and if it's trying to get out. We are crystal clear about why it's trying to get out, how it's trying to get out, what it's trying to achieve. So we can govern those openings to make sure that the agent is not doing what it's meant to do. Another way of putting this is to say that we are taking governance and we are building governance as infrastructure. And that's what I meant when I said before that governance is the system.
[00:19:13]
It's not it is the system. >> So the mindset shift is really is really about understanding that you don't code in the same way anymore. you're really defining the boundaries and with the boundary you're defining the goals, you're defining the policies, you're defining the constraints and you're defining the evidence and everything the agent needs in the periphery >> in order to do it job. The term being used in the industry is govern governing by intent. Um and it's it's about it's less about um coding or or providing very detailed instructions and procedures to agents but it's more about uh setting the objectives setting the goals and setting the guardrails um which are the key governance aspects in the in the materic. So h how do you see practically we should be um um thinking of setting goals and objectives for for individual atomic agents that you said so that they don't drift and they don't overlap potentially with other other agents.
[00:20:24]
>> Yeah, you actually need systems for this and there are different levers in controlling an agent system and you're right you mentioned them already. It's your goal, it's your policy etc. So all of these are levers that are going to control what the system does and obviously the goal that is going to control the outcome >> and the policies etc. And let's let's say that evidence and constraints are kind of policy the policy is determining the behavior of the system in order to achieve that goal. So what we need in these systems is that in the past a policy can be interpreted by human. If something doesn't make sense in a policy or if it's contradicting something else, a human can resolve that. It's not it's not easy for AI to resolve that. So one of the components or things I'm I'm coming to go in a second is that we need a policy engine and we need a policy model because they're going to be a lot of policies >> and what happens if you have if you have a set of policies and there's a policy missing. The agent is not going to tell you there's a policy missing. The agent is going to think okay there's something missing. I'm still going to make a decision. >> Yeah. What happens if you're creating a policy that is contradicting another policy? The system will drift. So governance extends much much further in agenda. You actually need to govern your policy model and your policy ending to make sure that everything gets put in correctly at design times. It doesn't get confused at runtime. And the goals are similar.
[00:22:04]
So the methodology that we're using at DXA is that we are setting up a goal architecture. So we understanding top goal, we understanding intermediary goals and then we are putting those goals into context. And you have to do that because imagine that you have two agents working together. One is maximizing profits, the other one is uh let's say inventory levels or customer experience. It doesn't matter if you're putting these two agents together and they have two goals and they have no way of relating and prioritizing. I mean, you have no idea what what you're going to end up with. So you need your goal structure in your in your golden goal model where you can model all of your goals and you can create rules in between them to understand the reality importance so that an agent can actually negotiate multiple goals. It was agent priority.
[00:23:05]
>> Yeah. Um I like to move our conversation towards more of the architectural aspects of agentic governance. Um because we have said a couple of times so far that um it's not adequate to have policies just sitting um uh on on in some sharepoint somewhere um right um and it's and it's not only also about committees um right it's it cannot be reactive as you said uh um in the in the agendic it has to be deeply embedded in the platform itself >> right um so the organizations which are now embarking on this on this journey uh who are started thinking of how effectively govern this agentic systems. If you want to draw a reference architecture as to as to what important capabilities or features they should be thinking of for effective governance which are four or five important components come to your mind right let's start with the most important one and we can call it a number of different things I'm calling it I'm calling it the agentic data backbone that's my name it's really an agentic middleware Mhm. >> The agentic middleware is absolutely essential in multi- aent systems because of the context.
[00:24:30]
So what happens is that for an agent to be able to make the right to decision, it needs to have the right context. If you have two or three agents working together to make a decision, they all have to have the same context. If they don't have the same context, they're going to drift. If they have to have the same context, you have two options. You can either put all of the context into all of the agents. So every agent is carry the context of all the other agents that they collaborate with. That might work if you have a two or three agents. If you have 10 agents, it's going to collapse. >> Uh the the weight of that contact is going to be too heavy. So you have to pull that context out of the agent. So the agents are your cognition, your thinking, and you bring the context into your middleware. And that's an absolutely essential component of the reference architecture. You can't build an aentic system if you don't have the middleware and the middleware. That is actually where all of the context is and it's serving the context to the agent.
[00:25:32]
And here we're coming into another aspect of the reference architecture. A to a is an aic antiattern. A to A essentially means that you have you have to have the same context in both agents for them to be able to talk to each other and it's not going to work if you have many agents. So again it's coming back to taking the contact of that agent and put it into the middleware and the middleware manages all the context for all agents that a single source of truth of context and it just ser agents. Soic middleware is critical. There are some other things as well and we're going to come into state machines and protocols because they are really important and we touched a little bit before on where you are designing the system today and then you put and then you're building it and then you're compiling it and then it gets executed at run time. The genic system doesn't work like that.
[00:26:31]
There is no compilation of code. >> What the system does it is compiling everything at runtime. So when we are coming at runtime it's going to look at something okay I'm going to look for policy I have to check it I have to check constraint I have to check the permission I have to do this I have to do that and based on the outcome of this runtime interpretation >> either either be executed or it won't obviously all of that is going into a provenence u record the point is that these systems are not predictable That's why emergence is such a problem today. When you're compiling a system, you know exactly what's going to do. It's not going to make it code. It's not going to make it decision. You know exactly what you get. >> Yeah. >> You don't know. You actually don't know what happens in a in a genic system until it actually runs.
[00:27:30]
>> Yeah. >> Because you have you you have only you you're designing the boundaries, right? You're not designing the car. You're only designing the boundaries. So >> it really depends on what happens around the boundaries at execution time. >> Yeah. >> What the system is doing. >> Yeah. You you mentioned about agentic middleware which is an interesting term. I'm definitely taken note of that. Um now one one thing uh that comes to my mind is yes uh the context building is important also uh agencies to access to different documents. So within the enterprise policy documents of each other, right? But if an agent is serving a a customer, right? For example, how does and and the the fact the it typically is that mo in most of the organizations the doc the information is scattered across multiple >> Yeah. >> Right. Um we you and me as humans would know what is authority, source of authority, source of truth for a particular influential, >> right? agents will search information from different sources but how would they and that's I'm trying to understand the governance aspect to this as well how would they understand which is the more authority in source of information that I should use to serve the customer it's a really good question I can address it from a number of different angles I can I'm going to come back to the So when when we are designing a process today, we we're literally designing a process. We we we stand in front of the whiteboard. We are drawing a BPMN diagram perhaps and say it goes from here, goes here. We have a decision and things happen.
[00:29:24]
That's not what we do in the gentic world because again that that that's like coding if then and else since then we're looking at system as a state machine. So there are certain states that never happens in the system and then between each state there's a protocol and that protocol tells you what are the conditions from going from one uh stage to the next. And when we start formalizing a system this way using formal rules behind a process and our process is constructed, we start building more and more things on that. So we can for example link certain states or certain protocols into certain types of events and certain types of data and certain types of transitions. So you actually control what an agent can and can't do. It's really controlled via the state machine.
[00:30:31]
>> So state machine we know that if if you're going from u let's say that you have done you're fill in a form you're requesting a credit increase and then there there's a process happening and then that's either being being approved or being rejected. In this world that is all controlled in the state machine. Every state is going to know exactly what can happen, what what kind of events can take place, what kind of events can't take place, what kind of policy must be in place for something to go from requested to approved. And that's where the system will know that it it is expecting approval policy 1.113 which is the latest version and if that policy is not there it it will stop it's a kill switch essentially it stops and it will allow the human and say there's something missing in the ecosystem I'm expecting this policy it's not there and it stops so that is how you're build building that control around the agents what they can do and what they can't do and how to behave. It's not through prompt engineering. So prompt engineering is is really anti-agentic as well because prompt I mean it's just a prompt. I mean there's no intelligence. It's almost like unstructured data that you put into an agent. Whereas if you're using state machines and protocols there structured data that you can >> Yeah. Yeah.
[00:32:09]
>> makes sense. Yeah. Absolutely. So what other aspects um you think are important when when you talk about the reference architecture for governance? You talked about data foundations which is I agree absolutely important. >> Um there are other aspects uh maybe worthwhile exploring like a security identities etc. >> Do you want to unpack that as well? >> Uh no I want to go in other direction because it's more >> uh it's more exciting. Yeah, >> security etc. Those things are relatively well thought through. I think if we go in the other direction >> mhm >> other part of the of the reference architecture has to be something to do with autology and semantics. >> Mhm. >> So that's a meaning let's say and you're going to get a laugh out of this the word done >> if you to a developer. Yeah. Yeah. I'm done. If you talk to tester, I'm done.
[00:33:08]
You talk to business user, I'm done. Done in the context of a developer in a tester, a BA, a business person, it means different things. We need to lock down the meaning in a genic system. If there's any kind of ambiguity in the meaning, it's going to drift. So one of the most important aspects of the reference architecture is to understand your ontology and your semantics because this is the meaning layer. This is what the agents they're using for reasoning. So that's they are really important and when I'm talking about ontology and semantics the ontology are all important terms and definitions and relationships in the organization. So if you are a retailer for example it it would be customer it will be product you could say it's a little bit like a data model or an entity relationship diagram in its principle that it looks similar but used so that's your ontology then the semantics that is the interpretation of the ontology for example the word dump it can mean different things in different stages is that's what a uh semantics picks up from. So that picks up all the different meaning and how and how the ontology can be used in so if you're mapping out all of that you can be pretty confident that the agent are going to use the same meaning when I'm making the decision regardless of the agent is coming from. So that is that is your ontology and your semantics. We had talked a little bit about the policy engine already. So the policy must be part of it.
[00:34:59]
>> Uh and then you will have you will have a user experience and you will have a front end of course that someone interacted with. So that's an important part but the most important part is is definitely the data back in the middleware. That's what everyone is missing. Everyone's talking about agents. It's easy to build agents. anyone can build an agent. It is putting them together and trusting in a real >> Yeah, >> that's difficult. >> I agree. I mean the context and memory management are emerging to be probably one of the most important topics right now. So yeah, so having that middleware definitely makes sense. Um let's move our um conversation towards uh other as other area where I wanted to have discussion with you which is around operating model and accountability of of these agents. Okay. Now whenever we talk about agents, one thing uh one question is always asked as to um in this new world who are going to be accountable for for these agents and particularly that is asked in the context of if agents makes wrong decision who is liable who is accountable from from people perspective. right now in your conversations with the customers really how big is this issue and how do you try to address solve this issue for for your customers and I go a bit further than that if we're looking at the operating model >> so that's one part of operating model the other the other part of the operating model starts even earlier so for example let's say that you and I work in the same company and you want to create an agent and I want to create an agent what are the roots of creating an agent Who can create an agent? What kind of data can it access? If I'm creating an agent, who who can renew it? Who can it what happens if I want to change the agent? You know what what what's a process then? What's a process if I want to decommission an agent?
[00:36:59]
So I think the operating model it needs to answer a lot of questions and you're you right in highlighting that we we have the issue of responsibility and accountability when it comes to AI agency and genetic AI and to be really honest I don't have a full answer on those things I think that is something that we are still working through who is ultimately accountable for an agent and in some instances it is probably quite simple but in some instances I think there can be very very very hard questions to answer especially if you talk about for example ecosystems I mean imagine that you have an agent from the government and you have an agent from an organization and you're doing some kind of transaction in terms of tax that goes wrong whose fault is it is >> yeah yeah okay uh you you mentioned a little bit about the importance of trust within this agentic ecosystem which And and I wanted to unpack that as well. Um because um uh regardless of how advanced these systems are, how intelligent these systems are, if they do not make right decisions, um uh that has a direct consequence on the trust that you have with the brand, right? So u how should organizations um think of building that trust around that whole uh auton agentic system? I mean what kind of precautions they can they can think of um before these agentics ecosystems are live in productions and they start serving the real customers.
[00:38:40]
>> I think the first level of trust comes by doing it right in the first place. We talked a little bit about the thing about technical didn't it? >> Worst thing actually let's turn it around. The worst thing an organization can do is to cobble something together sort of as an experiment and then sharing it and people see it not working or what's brittle or or showing different results and then people are thinking this is not working. So I think the first thing is that you have to find the right use case that what I'm saying and you need to do that use case correctly. you're actually not testing the technical viability. It's not that hard to actually build an agent. It's really easy. The hard thing is to govern it. And the governance is not technical governance, it's business governance. And there are just so many business things here that we need to solve. >> When one aspect of building the trust and ensuring the eos ecosystem is well trusted is um uh ability to to explain the outcomes, right? the explanability of agentic systems. Uh and we all know that that is not agentic systems generally are not transparent transparent right um uh so uh how do you how organizations can ensure there is adequate if not 100% explanability um uh when you are actually these agentic systems again are serving uh critical business operations or customer services >> and again but coming back to governance as infrastructure you need to build the governance into the system itself.
[00:40:28]
>> Yeah. >> For that to happen. And there's this concept that's called provenence. And provenence is quite big in a genetic AI. And it means that we can always go back and we can understand exactly what kind of decision was made, how it was made and why it was made. So that is what you're touching more. So we need to have that explanability. So when an agent let's say it's perhaps a mixture of experts or a deeper agent and is do doing reasoning we need we need to be able to see what that reasoning is so we can understand the thought process the agent has gone through but it's actually much more than that we need to for let's take a policy for example policies change over time I mean you might have a policy that is changing every 3 months let's say that you have an agent that made that made a decision four months ago and that is making that decision under previous policy.
[00:41:30]
When you go in and you're looking at that the decision you need to be able to know that you actually have to know exactly what policy what kind of evidence what kind of constraint exactly you was applied on that agent at that exact time of decision or execution. So it's actually quite comp it's actually quite complex picture because you do need to keep track of a lot of different moving parts in your providence record in order to really understand what the agent has done across all the different areas that can potentially drift. So I think that that that is core to trust is to have that holistic view and understand all of the aspect where it can play up essentially. >> Yeah. Um I think as we start u I start wrapping up now there are a couple of questions I definitely want to ask uh JPE now you also have background in enterprise architecture right um uh you have been you has seen the enterprise architecture governance forums how they function etc. Um then there in the organization then there are other forms of governance technology governance like data governance the privacy and the security governance etc. Um in the agentric world how do you see these these forums um and the processes um should evolve um what is the role architecture governance or data governance and this kind of security these kind of forums would play and what value they can add.
[00:43:07]
>> Let's start with I think the hardest question first. Let's let's talk about architect governance. was architect is changing perhaps more than any other role in agentic AI especially the enterprise architect. So what happens is and we have been touching on it. We are essentially moving from a world where we are decide where we're deciding everything at design at build time we are really deciding at runtime instead. And that means that as an architect, especially as an enterprise architect, instead of sitting here on outside doing my capability models and value streams and cruds and all of these beautiful diagrams that we used to, they're not going to be that useful anymore because it doesn't happen there. It happens at runtime now. So that this really big shift and I think I think the business architect and the enterprise architect are going to be the most affected is that we are going from from some of the I call it lag time.
[00:44:19]
>> Mhm. >> If you do something as a business architect or an enterprise architect, it can take a year, it can take two years until you actually see something in the business. >> If you do something as a technology architect, it is probably weeks. So you have this big lag time and that's one of the reasons why it's very difficult to really convince someone about the importance of business and data architecture because it's difficult to measure. But in agentic world is completely different because they don't sit on outside anymore. They actually sit in a nucleus itself. So the business architect, the business architect for example needs to create the systems and the processes and the structure for all of the policies and constraints and evidence etc to make sense at runtime. That's a business architecture view um responsibility. The enterprise architecture is going to need to coordinate everything at runtime from your technology infrastructure data application. These roles are changing fundamentally because of runtime is changing everything. Runtime looks very very different in agenda.
[00:45:28]
>> Yeah, I agree. Okay. So uh a final question probably but um if an organization is just embarking on um this whole agentic journey and they're thinking of the governance to be established around it how what kind of advice you will give to the CIOS or or whoever that the uh other business counterparts as to how they should be thinking of establishing governance and based on your experience what are the key things key mistakes they should avoid. But they can buy my book, of course, but I'm not going to I'm not going to f I think that this is an area where you can't really cheat and I've done a bit of a turn on myself and my thinking in the last few weeks and I've come to the conclusion that we we it's actually really starting people. It's not about the system. It's not about the processes. SMA matter fact, it's nothing about that at all.
[00:46:35]
If I was running an organization and I was serious about doing doing a genetic AI, I would get AI consultants in to sit with my key people and really really make sure that AI is first embedded in the personal workflow so people actually really understand what it is. There are so many people they go into AI conversation and they have never really played with it, experimented with it, they actually don't really know what it is. And I think that putting it putting it in front of everyone and really encouraging and handholding people to use it so they get used to it. It's one of these bas base capability that that absolutely essential. It's like data governance that you mentioned. You can't do anything in AI unless you have data governance. It's almost a it's almost a foundation that you build on. And it's the same thing I think the first foundation train up all your people and not just a training course actually get them into their technology supervise and sit with them where they're sitting there typing into into a chatbot or something and trying to improve their personal productivity workflows. I think that personal understanding is critical and far too many organizations they they want to make the jump they want to go to level two or level three but you you really need to start at level one >> I think that biggest advice um crawl walk and then >> yeah good advice uh Jper and on that note um thanks for joining enterprise tech talk uh this was a fascinating conversation desper and I'm pretty sure audience will really get benefited by your your insights u so thanks again um thanks for joining and it was pleasure hosting you >> thank you pleasure to be here have a great day >> if you found this discussion valuable please follow and subscribe to Enterprise Tech Talk and thanks for listening I look forward to seeing you in the next officer.
