Enterprise AI has reached the point where the hard problem is no longer whether an agent can do the work. It is whether anyone can prove, after the fact, what it did and why it was permitted to do it. Most large organizations have spent two years running agentic pilots that impressed executives and went nowhere, and the reason is rarely the model. It is the absence of any structure capable of holding an autonomous system accountable once it touches real customers, real money, and real regulatory exposure. Vishy Kasinadhuni, an enterprise architect working on agentic systems at scale, argues that control in this context is not a review process or a human staring at a queue. It is architecture, and companies that treat it as anything softer will spend the next three years stuck in demo mode while their boards ask why nothing has shipped.
Control Is Architectural, Not Procedural
The default corporate instinct is to put a person in front of every agent decision and call that governance. Vishy dismisses it flatly. “That is not control, that is a bottleneck that will get bypassed,” he says. The failure mode is predictable: route everything to a human, and the human rubber-stamps everything. He calls it human approval theater, “latency with extra steps.” Worse, it teaches the organization that the control layer is decorative, which guarantees someone eventually routes around it.
What replaces it is a hard architectural boundary. The deterministic core of the business stays deterministic. “Policy, pricing, underwriting, financials, customer commitments, those do not become probabilistic because an agent is involved,” Vishy says. Autonomy lives at the edges, in research, synthesis, drafting, and triage, while every state change passes through a deterministic executor. Agents hold broad read access and narrow or zero write access. They do not carry credentials to core systems. They propose; they do not apply. Each one gets its own identity and least privilege by default, with a full record of what it saw, what it proposed, who approved it, and what executed. His test is blunt: “If you cannot replay it, you do not control it.”
Why Pilots Succeed And Production Does Not
The gap between a working pilot and a production system is not a scaling problem. It is a reckoning. “Pilots succeed because they are allowed to cheat,” Vishy says. “Production fails when the cheating has to stop.” In the pilot, the agent writes directly to Salesforce, to the core system, to email. In production that is unacceptable, and almost nobody has designed the deterministic executor, the approval queue, or the narrow write credentials that would make it acceptable. The project stalls or ships on a risky exception.
The other failure points follow the same pattern of borrowed time coming due. Pilots are judged by demo, so teams never build an evaluation harness, which means no regression testing, no replay, no versioned prompts and policies, and no way to prove the system still works after the next model update. Grounding degrades the moment the curated spreadsheet gives way to the lakehouse, the policy documents, and the tribal knowledge, with missing keys, stale snapshots, and no provenance. “The agent is confident and wrong,” Vishy says. Add a shared service account with broad read, and security kills the project, correctly. Add no named owner, no runbook, and no kill switch anyone trusts, and the first 2 a.m. exception sends the whole thing back to manual. His conclusion is the one most AI programs resist: “Scale does not fail on the model. It fails on the missing control plane around the model.”
Governance As A System Property
Boards and regulators have moved AI oversight onto the agenda, and the standard corporate response is a framework deck. Vishy thinks that answer is dead on arrival. “Boards do not need another framework deck. They need proof of control, on demand.” Enterprise architecture earns its seat by converting the claim into something demonstrable. That starts with an inventory with teeth: every agentic system registered with its data access, its write permissions, its risk tier, and its owner. If it is not in the registry, it does not run. Shadow agents are the first thing regulators ask about.
The mechanism that makes this work is separating intent from action. “Agents do not execute. They submit a signed intent: who, what, on which entity, with which grounded evidence, under which policy version.” A single gateway validates that intent against policy as code before anything happens, fails closed, and writes to an immutable decision ledger on every call. Audit stops being an extra step and becomes a byproduct of running. “The agent cannot lie about what happened because it never performed the write,” Vishy says. Approvals are then tiered by risk rather than applied uniformly: low risk auto-approves within policy, medium requires dual control, and high risk or financial decisions require a human with evidence attached. “Route by risk, not by fear. That is how you avoid the bottleneck.” Grounding is pinned to content-hashed snapshots rather than live queries someone can dispute later. When a regulator asks why a decision was made, the answer is not a meeting note. It is a replayable ledger entry. “Bottlenecks happen when governance is a human reading a ticket. Auditable systems happen when governance is a gateway writing a ledger.”
That architecture is also the competitive argument. Vishy’s position on where to spend now is unambiguous: stop funding disconnected pilots and build the enterprise agent control plane, with shared agent identity, a tool registry, a policy-as-code gateway, grounded evidence, and an immutable ledger. “Pilots do not compound. The control plane compounds.” Each new agent ships faster because identity, policy, approvals, and audit are already solved, and each new domain inherits the trust the last one earned with risk, legal, and regulators. The winners over the next two to three years will not be the firms with the most agents. They will be the ones whose agents can survive a security review. “Agents are enterprise infrastructure, not project tooling,” he says. “The alternative is 20 agent silos, 20 control models, and a board asking why none of it can go live.”
Follow Vishy Kasinadhuni on LinkedIn for more insights on enterprise architecture, agentic AI governance, and scaling autonomous systems in regulated environments.