Governing Enterprise AI

Read Time:

5

Minutes

Artificial Intelligence & Machine Learning

August 25, 2026

The Control Imperative: Governing Enterprise AI

One of the most important conversations in enterprise technology right now is not about capability; it is about control. AI models are powerful enough for enterprise operations. But the question being asked across every serious boardroom, every defence programme office, and every government digital team is the same: who governs what the machine does next?

That question ran through almost every session at this year’s Summit, surfacing most sharply across three themes: agentic AI, autonomous defence, and sovereign development.

Agentic AI — the control problem hiding inside the capability story.

The shift from ‘AI as a tool’ to ‘AI as an actor’ changes the governance problem fundamentally. Almost every application vendor framed its roadmap around autonomous agents - systems that authenticate, reason, and act without a human approving each step. How those agents are provisioned, monitored, and decommissioned across their full lifecycle was named repeatedly as the single most urgent challenge. Several teams now treat agents as non-human insiders, assigning them their own identity and behavioural baselines and monitoring for drift (Exabeam, Above Security, Witness AI). The moment that crystallised the stakes was a demonstration of a compromised agent asking a second agent for the commands needed to bypass data-loss controls. Agent-on-agent evasion is a genuinely new threat class, and existing tooling built for human actors does not yet address it. Capability arrived ahead of control, and the gap is now measurable.

Autonomous Defence — when the machine acts faster than the human in the loop

The same dynamic plays out at machine speed in cybersecurity and in the physical domain. AI-driven penetration testing and attack-swarm red teaming (Horizon3, A Security, Armadin) are closing the window between a known exploit and an active attack from months to hours. Adversaries are already using AI to move at operational pace and scale, so the real test is whether your defences can respond at the same tempo. In the physical world, AI and autonomy at the ‘edge’ is a deployment use case that is now mature. For example, combat-proven uncrewed surface vessels, GNSS-denied tactical drones and autonomous underwater vehicles carrying desktop-class GPUs are already operational. In each case, the governance challenge is identical - at what point does a human remain meaningfully in the loop? The organisations forging ahead are not those with the most capable systems, but they are those that have answered the control question first.

Sovereign Development — control of the stack as a strategic imperative

The third dimension of control is structural. Across every session that touched on public-sector technology, the recurring requirement was sovereignty of infrastructure, of data, and of the deployment environment. More often than not, this is a risk posture and not simply a procurement preference. The roughly six trillion dollars of annual technology spend is being rebuilt around a concentrated cognitive stack, with around 70% of first-quarter venture capital going to just five AI companies. Organisations that do not decide where their AI runs, which models they rely on, or how they could switch providers risk losing control of their AI strategy. At the same time, AI regulation is becoming stricter. The current light-touch approach in the US is unlikely to last; export controls on advanced AI models could become much tougher (similar to ITAR), and the EU AI Act may set the global standard. Organisations that address these issues now will be in a much stronger position than those that wait until the rules become more restrictive.

The Imperative

Capability now counts for less on its own; it has become more of a baseline and is not always the differentiator. What separated the organisations worth watching was the maturity of their answer to the control question: governance of agents, tempo in autonomous operations, and sovereignty over the stack. For enterprise technology leaders, this must be the work of the next 18 months.

Grant West, Senior Platform Engineer at Ntegra

Frequently asked questions

What is the control imperative?
It is the shift in enterprise AI from asking what a system can do to asking who governs what it does next. Across this year's Summit, the maturity of an organisation's answer to that question separated the leaders from the rest.

Why is agentic AI a governance problem rather than a capability one?
Agents authenticate, reason, and act without a human approving each step, so the challenge moves to how they are provisioned, monitored, and decommissioned across their lifecycle. Several teams now treat agents as non-human insiders, giving them their own identity and behavioural baselines and watching for drift.

What is agent-on-agent evasion?
It is a new threat class where one compromised agent asks another for the commands needed to bypass controls such as data-loss prevention. Tooling built for human actors does not yet address it.

What does sovereign development mean in practice?
Control over infrastructure, data, and the deployment environment. For most public-sector work, this is a risk posture, covering where AI runs, which models an organisation depends on, and how it could switch providers if needed.

How urgent is this for technology leaders?
The article frames governance of agents, tempo in autonomous operations, and sovereignty over the stack as the work of the next 18 months, ahead of AI regulation tightening.

Tell us about your project

Contact Us