The Risk Wheelhouse
The Risk Wheelhouse is designed to explore how RiskTech is transforming the way companies approach risk management today and into the future. The podcast aims to provide listeners with valuable insights into integrated risk management (IRM) practices and emerging technologies. Each episode will feature a "Deep Dive" into specific topics or research reports developed by Wheelhouse Advisors, helping listeners navigate the complexities of the modern risk landscape.
The Risk Wheelhouse
From Passive GRC To Autonomous IRM
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Your risk platform might be perfectly secure, perfectly organized, and completely useless at the moment risk actually happens. We start with a blunt diagnosis of legacy GRC and integrated risk management software: it records history after the work is done, creating a dangerous latency gap between operations and compliance. Then we lay out the shift that is reorganizing the enterprise risk technology market, the agentic control plane, where the system can sense an anomaly, decide on a response, execute an intervention, and produce immutable proof in real time.
We ground the concept in hard signals from cybersecurity, including OpenAI’s Daybreak expansion and what “closed loop” really looks like when an agent moves from discovery to remediation and gets patches accepted upstream by human maintainers. From there, we follow the vertical push into high-stakes regulated workflows, from TCS role-based agents for clinical trials and pharmacovigilance to Lia’s Maestro-style orchestration across legal, procurement, and finance. Along the way, we introduce the customer proof gap and a practical proof hierarchy so you can separate press-release capability from verified outcome evidence.
Finally, we confront the infrastructure reality behind stalled deployments: data governance, regulatory control, and why so many enterprises are pulling AI workloads back from public cloud. We wrap with a buyer playbook you can take into the boardroom, including action boundaries, policy inheritance, evidence by design, reversibility, proof maturity, and portability, plus one provocative question about whether humans can even audit the volume of evidence autonomous agents will generate. Subscribe, share this with your risk or security team, and leave a review with the one control you think every autonomous system must have.
Visit www.therisktechjournal.com and www.rtj-bridge.com to learn more about the topics discussed in today's episode.
Subscribe at Apple Podcasts, Spotify, or Amazon Music. Contact us directly at info@wheelhouseadvisors.com or visit us at LinkedIn or X.com.
Our YouTube channel also delivers fast, executive-ready insights on Integrated Risk Management. Explore short explainers, IRM Navigator research highlights, RiskTech Journal analysis, and conversations from The Risk Wheelhouse Podcast. We cover the issues that matter most to modern risk leaders. Every video is designed to sharpen decision making and strengthen resilience in a digital-first world. Subscribe at youtube.com/@WheelhouseAdv.
Why Legacy GRC Feels Passive
Sam JonesWhen you look back at the history of enterprise software, especially, you know, the massive platforms we all rely on to manage risk and compliance, you are essentially looking at an evolution of, well, digital filing cabinets. Right. And like as an executive listening to this, whether you are a chief risk officer, a CISO, or a compliance leader, you know exactly what I'm talking about here. You spend, I mean, millions of dollars and years of organizational capital implementing these governance, risk, and compliance or GRC systems.
Ori WellingtonOh, easily millions. And they take forever to roll out.
Sam JonesYeah, and they are highly organized, they are incredibly secure, and frankly, they are phenomenally expensive, but fundamentally they are entirely passive.
Ori WellingtonThat's the key word passive.
Sam JonesRight. You do the actual work of the business somewhere else in a totally different system, and then eventually somebody on your team comes back to that central cabinet to just, you know, file the poker work proving the work was done correctly.
Ori WellingtonAaron Powell It is a profoundly reactive posture. And I mean it creates this massive latency gap in enterprise operations. Think about the daily reality for a Fortune 500 company.
Sam JonesSure.
Ori WellingtonA network engineer patches a vulnerable server, or a clinical researcher approves a trial protocol, or uh a procurement officer signs off on a third-party vendor agreement.
Sam JonesAll happening in totally different applications.
Ori WellingtonExactly. All of those actions happen in specialized operational tools. Then, days or sometimes weeks after the fact, an analyst logs into the centralized GRC system just to check a box, you know, upload an attestation, and close out a compliance ticket.
Sam JonesSo the work is already ancient history by the time it gets recorded.
Ori WellingtonRight. The system of record is completely divorced from the system of action.
Sam JonesWelcome to this deep dive on the Risk Wheelhouse platform. As analysts here at Wheelhouse Advisors, our mandate is to really track the tectonic shifts in how global enterprises manage risk.
Ori WellingtonAnd today we are looking at a seismic rupture in that standard operating procedure we just described.
Sam JonesAaron Powell We really are. Our mission for the next hour or so is to unpack exactly why the uh what we call the agentic control
What An Agentic Control Plane Is
Sam Jonesplane is completely disrupting traditional integrated risk management technology.
Ori WellingtonAaron Powell It's a total tear down of the old way of doing things.
Sam JonesAaron Powell It is. So we are analyzing the August 2026 Risk Tech Journal Market Analysis, and we are going to dissect major market-moving announcements from OpenAI, IBM, TCS, Oracle, PwC, and Cloudera.
Ori WellingtonAaron Powell And the scope of what we are analyzing today, it really cannot be overstated. We are not talking about a new feature update or like a better user interface for your existing compliance dashboard.
Sam JonesNo, definitely not a UI tweak.
Ori WellingtonNo. We are documenting the transition away from passive systems of record toward active autonomous risk orchestration systems. Trevor Burrus, Jr.
Sam JonesAutonomous being the operative word there. Aaron Powell Right.
Ori WellingtonWe are entering an era where the system itself senses an anomaly, decides on a course of action, executes that action, and this is the crazy part, cryptographically proves what happened in real time.
Sam JonesAaron Powell To really grasp the magnitude of the shift as an executive, you need to visualize the difference between recording history and actually making it.
Ori WellingtonI like that analogy.
Sam JonesYeah, think of traditional integrated risk management like a military historian. So the historian sits in a quiet, secure tent days or maybe weeks after a major battle has concluded. Safe and sound. Safe and sound, they interview the surviving soldiers, they review the communication logs, they analyze the map movements, and they write this comprehensive, highly accurate report of what transpired.
Ori WellingtonWhich is useful, but yeah.
Sam JonesRight. That report is incredibly valuable for the next battle, but it does absolutely nothing to change the outcome of the battle that just happened. It just records the autopsy of the event.
Ori WellingtonAaron Powell And that autopsy model is failing right now because the speed of modern business, especially with the introduction of generative AI into operational workflows, has completely outpaced the historian's ability to keep up.
Sam JonesAaron Powell So if the legacy GRC platform is the historian, this new agenc control plane we are exploring today is like the battlefield general.
Ori WellingtonExactly.
Sam JonesImagine a general standing right on the front line. They are receiving real-time signal intelligence, they are making split-second tactical decisions, and they are ordering immediate defensive action.
Ori WellingtonIn the heat of the moment.
Sam JonesYeah. But and here is the crucial part for our compliance leaders tuning in. They are doing all of this while simultaneously documenting the exact legal, ethical, and strategic justification for every single order, right as the artillery is firing.
Ori WellingtonWhich is wild to think about.
Sam JonesIt is. The system is no longer just observing the work, it is physically doing the work and generating the irrefutable proof simultaneously.
Ori WellingtonAnd that mechanism doing the work and generating the proof in the exact same motion that is the core thesis we really have to explore today, the entire enterprise software market is reorganizing around this agentic control plane.
Sam JonesIt's shifting everything.
Ori WellingtonIt represents a brand new layer of architecture that connects intelligence, intervention, and evidence into one continuous unbreakable loop.
Sam JonesUnbreakable loop, right?
Ori WellingtonYeah. And the hard truth for the legacy platforms out there is stark. If your platform remains a passive repository, if its only value proposition is storing compliance data after the fact, it risks becoming an obsolete archive. It will completely lose the operational center of gravity.
Sam JonesI want to pull on that thread for a second. The operational center of gravity. Because, well, where does gravity actually reside in a modern enterprise?
Ori WellingtonAaron Powell Where the money is made, usually.
Sam JonesRight. It isn't in the compliance department's database. It is where the friction of the business actually occurs. It is in the cyber defense platforms actively blocking intrusions. It is in the procurement systems routing millions of dollars across borders. It is in the clinical safety workflows monitoring patient health.
Ori WellingtonAaron Powell And those operational hubs are where the risk actually materializes. We are moving from a paradigm of recording controls to orchestrating decisions. And this creates, honestly, an existential strategic question for every single integrated risk management provider today.
Sam JonesAaron Powell Existential is the right word.
Ori WellingtonThink about the life cycle of an AI agent operating in your business right now. The agent receives an initial signal, say uh an anomalous login attempt from a foreign IP.
Sam JonesOkay, pretty standard.
Ori WellingtonRight. It makes a decision to investigate, it takes an action to isolate the endpoint, it remediates the threat by revoking the access keys, and finally, it retains the evidence of that entire chain.
Sam JonesAaron Powell So it does the whole life cycle.
Ori WellingtonThe whole thing. Yeah. So the question for the market is who owns the space between that initial signal and the final retained evidence?
Sam JonesAaron Powell Look, if I am putting my chief risk officer hat on right now, I am looking at my budget and I'm sweating.
Ori WellingtonOh, absolutely.
Sam JonesLet's say I have spent four years and $10 million of organizational capital implementing this massive monolithic central GRC application. I built that entirely so my global teams can reconstruct events and prove our compliance posture to regulators.
Ori WellingtonIt was a nightmare to implement.
Sam JonesThe biggest headache of my career. If the center of gravity is moving to these active AI agents, am I supposed to just abandon that central system entirely? Like, are you telling me my multimillion dollar GRC investment is now just a glorified digital paperweight?
Ori WellingtonWell, abandoning the foundation would be organizational malpractice, honestly. You can't just rip it out. But you absolutely have to re-evaluate where that system sits in the evolutionary chain.
Sam JonesOkay, so how do we map that out?
Ori WellingtonAt Wheelhouse Advisors, we use what we call the IRM navigator model to track how risk management matures inside an enterprise. You have to locate your current posture on this map.
Sam JonesWalk us through the map.
Ori WellingtonSure. It starts at the foundational stage. This is exactly what you just described: a centralized static library of risks and controls. It is a necessary baseline, but it is entirely manual.
Sam JonesAnd I mean,
The IRM Navigator Curve Explained
Sam Jonesmost companies spend years just trying to get their disparate spreadsheets into that foundational stage. Just getting off Excel is a win for a lot of orgs.
Ori WellingtonOh, yeah, which is why the transition is so painful. But once you're there, the next stage is coordinated. This is where different departments, say IT, security, and HR, they start sharing that foundational data instead of operating in their own little silos.
Sam JonesAaron Powell So they're talking to each other, but it's still passive.
Ori WellingtonAaron Powell Exactly. Then we move to embedded. And this is a critical leap. This is where controls are physically built in to the software interfaces themselves.
Sam JonesGive me an example of that.
Ori WellingtonSo instead of asking a developer to log into a separate system to confirm they ran a security check, the software development pipeline simply will not compile the code unless the security check is passed.
Sam JonesAh, okay. The control is embedded in the workflow.
Ori WellingtonAaron Powell Right. We have seen that heavily in FineOps and DevSecOps. The system enforces the rule mechanically. You literally can't move forward without passing the check.
Sam JonesAaron Powell That makes sense. It stops the bad action before it happens.
Ori WellingtonAaron Powell Then we reach the extended stage, which pushes those embedded controls out to your third-party vendors and your supply chain. But, and this is where we are today, the absolute endpoint of this entire evolutionary model, the paradigm shift we are witnessing right now, is autonomous IRM.
Sam JonesAaron Powell Autonomous IRM.
Ori WellingtonYes. The goal isn't just having a complete control library sitting in a database waiting to be queried by an auditor in six months. The goal is managing risk entirely inside the flow of work without human bottlenecking.
Sam JonesLet's break down the logic of that because you know the physics of risk management dictate that speed is security. A control that only confirms completion after an action has taken place is inherently weaker than a control that influences the decision before the execution happens. Right. So if an AI agent is drafting a vendor contract with a supplier in, let's say, a sanctioned country, a passive system will only flag that violation during a quarterly audit long after the money is moved.
Ori WellingtonAnd by then the damage is done. You're facing fines.
Sam JonesExactly. But an autonomous system interrupts the workflow. It stops the digital signature. It flags the Office of Foreign Assets Control Policy violation. It suggests an alternative supplier. And it logs the entire intervention for the compliance team automatically.
Ori WellingtonAaron Powell The Center of Gravity completely shifts from the system of record to the system of action.
Sam JonesIt sounds incredibly compelling in theory, but it is very easy for this to sound like science fiction or, you know, worse, just vendor marketing fluff.
Ori WellingtonAaron Powell Well, there is plenty of fluff out there.
Sam JonesRight. So as analysts, we need to ground this in reality for the executives listening. Let's look at the hard technical signal that proves the shift is happening right now out in the wild.
Ori WellingtonAaron Powell Okay, let's do it.
Sam JonesTo do that, we have to examine the space where AI agents are already being forced to take immediate high-stakes action because the environment is simply too fast for humans. And that is cybersecurity.
Ori WellingtonAaron Powell Cybersecurity is universally the tip of the spear for enterprise technology adoption. Always has been. The adversarial loop is the tightest there. If a human analyst has
Cybersecurity Proves The Closed Loop
Ori Wellingtonto manually review every single log, you get breached.
Sam JonesYou just can't keep up.
Ori WellingtonYou can't. That reality forces innovation. And that brings us directly to OpenAI's August 10th expansion of their daybreak platform.
Sam JonesThis announcement, I mean, it completely changes the landscape. OpenAI introduced blue and red tears to daybreak.
Ori WellingtonWhich is huge.
Sam JonesYeah. For the executives listening who might not live in the security operations center every day, blue means defensive security, right? Protecting the castle. Red means offensive security, actively trying to break into the castle to find weaknesses.
Ori WellingtonClassic red team, blue team dynamic.
Sam JonesExactly. And specifically, they rolled out a model called GPT 5.6 Cyber. And this is critical, this isn't a general purpose chatbot that you ask to write a marketing email or summarize a PDF review.
Ori WellingtonNo, this is highly specialized.
Sam JonesHighly specialized, positioned explicitly for defensive discovery, validation, and remediation workflows.
Ori WellingtonAnd because of this, we finally have concrete, verifiable data to show what an autonomous control plane looks like in practice.
Sam JonesTell us about the data.
Ori WellingtonSo OpenAI ran an open source remediation program called Patch the Planet. They ran this in partnership with Trail of Bits, which is a highly respected security research firm. They unleashed this GPP 5.6 cyber model on real production grade code.
Sam JonesNot a fanbox, real code.
Ori WellingtonReal code. And the metrics they reported are staggering. They unleashed the agent across 41 different code bases under review, and it reported 858 security findings.
Sam JonesOkay, I want to pause and truly unpack what 858 security findings across 41 code bases actually means in human terms.
Ori WellingtonIt's a lot of caffeine.
Sam JonesIt really is. For anyone who has ever managed a team of penetration testers or software engineers, analyzing an entire code base line by line is brutal grinding work. You are looking for complex logic flaws, race conditions, memory leaks, things that aren't obvious syntax errors.
Ori WellingtonAaron Powell A spell checker won't catch this stuff.
Sam JonesRight. A human team might spend months analyzing just one of those code bases. To scale that across 41 different projects and find 858 legitimate flaws is a monumental reduction in discovery time.
Ori WellingtonAaron Powell It is. But discovery is only the first step. Finding the flaw is just sensing. The agenti control plane requires action.
Sam JonesRight, it has to fix it.
Ori WellingtonExactly. The system then moved to the decision and action phases. It produced 263 actual patches. Wow. It didn't just highlight the bad code and say, hey, look here, it actually wrote the replacement code to fix the vulnerabilities. And of those 263 patches, 143 were accepted upstream.
Sam JonesLet's explain accepted upstream because I really think that is the most important phrase in this entire segment.
Ori WellingtonIt's the ultimate validation.
Sam JonesIt is. When you contribute to an open source project, you don't just force your code into the main software. You submit what is called a pull request. Right. A human maintainer and usually a deeply cynical, highly experienced senior developer reviews your code to see if it actually works, if it adheres to their standards, and if it breaks anything else.
Ori WellingtonThey don't mess around.
Sam JonesThey absolutely do not. When we say 143 patches were accepted upstream, we mean human experts scrutinized the AI's work and concluded this is correct, this solves the vulnerability, merge it into the production software.
Ori WellingtonThe AI proved its competence to human gatekeepers. And we are not talking about trivial spelling errors in the documentation here. The data specifically highlights that the model discovered two previously unknown vulnerabilities in V8.
Sam JonesOh man, the V8 engine. For context, V8 is the open source WebAssembly and JavaScript engine developed by the Chromium Project. It powers Google Chrome, it powers Node.js.
Ori WellingtonIt powers basically the internet.
Sam JonesBasically. It is arguably one of the most heavily scrutinized, rigorously tested pieces of software on the planet. Finding a zero-day vulnerability in V8 is the holy grail for security researchers. Whole careers are built on finding just one.
Ori WellingtonAnd OpenAI's autonomous agent found two.
Sam JonesTwo, including TUEE 2026-15903, which was so severe that Google actively had to push an emergency fix for it.
Ori WellingtonAnd then you look at the statements from early access enterprise customers like SpecterOps. They reported that this new agentic model completed work in less than a day that earlier AI models like GPT-4 had entirely failed to resolve after weeks of prompting and human hand holding.
Sam JonesSo, as an executive, why should you care about VA vulnerabilities and open source pull requests on a risk management deep dive?
Ori WellingtonRight. Why does it matter to the CRO?
Sam JonesBecause this is the mechanical proof of the agentic control pane in action.
Ori WellingtonIt proves the existence of a closed operational loop. This is a so what that completely redefines how we evaluate risk software moving forward. We are no longer talking about a copilot.
Sam JonesCopilots are old news.
Ori WellingtonA copilot sits next to a human, gives suggestions, and waits for the human to hit approve. A copilot is still a system of record waiting for a human action. What we are seeing with daybreak is an AI system operating entirely inside a closed loop.
Sam JonesMeaning no human needed to push the button.
Ori WellingtonExactly. It independently identifies an exposure, it tests mathematical hypothesis about how to exploit that exposure. It proposes a corrective action, it executes the patch, and critically, for our compliance audience, it retains the cryptographic evidence of that entire process.
Sam JonesIt is sensing, deciding, acting, improving completely without human intervention.
Ori WellingtonThat is the new baseline.
Sam JonesOkay, I'm gonna throw a massive flag on the play here.
Ori WellingtonThrow it.
Sam JonesI have to channel the skepticism of a seasoned enterprise buyer right now. Aaron Powell Fair enough. These are incredible numbers, yes, but they are entirely vendor-reported figures. OpenAI is obviously gonna highlight their most spectacular wins.
Ori WellingtonThey're not gonna issue a press release about the times it failed.
Sam JonesOf course not. And a frame like SpecterOps is a named early access partner. They are highly sophisticated, they employ elite engineers, and
Healthy Skepticism About Vendor Claims
Sam Jonesthey are likely receiving white glove concierge support from OpenAI. Can we realistically take their word for it as broad market proof that autonomous AI is ready to be plugged into a standard Fortune 500 risk environment today?
Ori WellingtonWell, that skepticism is not just healthy, it is completely mandatory. You cannot build enterprise risk architecture on press releases.
Sam JonesYou get fired quickly.
Ori WellingtonHowever, we have to separate the scale of the claim from the capability being demonstrated.
Sam JonesWhat do you mean by that?
Ori WellingtonEven if we assume these numbers represent the absolute best case scenario, the cherry pick triumphs of a massive compute run. What the daybreak announcement proves is that the underlying architecture as the loop actually functions.
Sam JonesAh, okay. The engine turns on.
Ori WellingtonThe engine turns on and the car drives. We have moved out of the theoretical white paper phase and into production environments where actual code is being patched in the wild. The physics of risk management have fundamentally changed. The fact that an AI can discover a flaw, test it, patch it, and log the evidence autonomously, it shatters the premise that risk management must remain a slow, manual, retroactive process.
Sam JonesThat is a vital distinction to make. It's not about whether your mid-market manufacturing firm can replicate this exact open AI workflow tomorrow. It's about recognizing that the technological ceiling has been completely blown off.
Ori WellingtonThe limit does not exist anymore.
Sam JonesThe closed loop is a reality. So if the technical capability is proven in the horizontal layer of cybersecurity, what happens when these autonomous agents start moving into highly regulated industry-specific verticals?
Ori WellingtonThat's where things get really interesting.
Sam JonesBecause patching a JavaScript engine is one thing. What happens when an AI agent touches patient health data or executes corporate finance transactions?
Ori WellingtonThe horizontal capability is rapidly verticalizing. The technology is moving from the IT department directly into the core revenue-generating operations of the business.
Sam JonesAnd we have a perfect example of this.
Ori WellingtonWe do. On August 17th, Tata Consultancy Services, or TCS, made an announcement that brings this agentic control plane right into the heart of the life sciences industry. They launched ADD Agent Hub.
Sam JonesLet's dissect this TCS announcement because the stakes in life sciences make cybersecurity look almost simple by comparison.
Ori WellingtonAaron Powell It's life or death, literally.
Sam JonesIt is. TCS is deploying role-based
Life Sciences And Finance Go Agentic
Sam JonesAI agents specifically for clinical trial and pharmacovigilance work.
Ori WellingtonAnd we should probably define that for everyone.
Sam JonesYes. For our listeners outside the pharmaceutical space, pharmacovigilance is the science and activities relating to the detection, assessment, understanding, and prevention of adverse effects or any other medicine-related problem.
Ori WellingtonPost-market surveillance.
Sam JonesExactly. Once a drug is licensed and out in the public, you have to monitor millions of patients to see if anyone develops an unexpected side effect.
Ori WellingtonAnd the specific workflows TCS is automating with these agents are the absolute bedrock of drug safety. We are talking about safety case intake, medical coding, literature analysis, protocol digitization, clinical data review, and medical monitoring.
Sam JonesI want to hammer this point home for the executives. These are not peripheral administrative tasks.
Ori WellingtonNo, this is the core function.
Sam JonesThis isn't an AI summarizing an email thread or scheduling a meeting for you. These are highly regulated, strictly audited workflows governed by agencies like the FDA in the US and the EMA in Europe.
Ori WellingtonThey don't mess around with compliance.
Sam JonesNot at all. In pharmacovigilance, medical coding involves translating complex, unstructured doctor's notes into standardized global medical terminology. If an AI agent has a missed signal, let's say it fails to recognize a subtle pattern of adverse liver reactions buried in a massive data set of patient narratives, or if it misclassifies a severe symptom as a mild one, the exposure is catastrophic.
Ori WellingtonA misclassification in that workflow leads to direct patient harm. It leads to massive regulatory fines, product recalls, and devastating financial liability for the company.
Sam JonesAnd crucially, if there is an untraceable intervention, meaning the AI made a decision to flag or ignore a case, but the compliance officer cannot prove to an FDA auditor exactly why the AI made that decision, you fail the audit instantly.
Ori WellingtonWhich is precisely why TCS is aggressively emphasizing that their platform operates with defined oversight and rigorous auditability. They understand the regulatory environment they're selling into.
Sam JonesThey have to.
Ori WellingtonAnd they are claiming that ADD Agent Hub delivers up to 40% greater clinical data management efficiency and up to 30% lower end-to-end safety case processing costs.
Sam JonesThose are wild numbers for that industry. We are seeing the same vertical ambition in legal and finance, too.
Ori WellingtonAbsolutely.
Sam JonesJust a few days prior to the TCS news on August 13th, we tracked the partnership announcement between Leah, Oracle, and PWC.
Ori WellingtonLia's Agenic OS is a perfect example of this verticalization. This system is designed to execute legal, contracting, procurement, and finance workflows. The architectural standout here is their maestro component.
Sam JonesMaestro, I love the branding.
Ori WellingtonIt fits perfectly. Maestro acts as a primary orchestrator for an entire swarm of specialized sub agents.
Sam JonesThat actually wor mechanically? Let's say uh a company is using Leah to process a massive procurement contract for a new cloud service provider. Walk us through it.
Ori WellingtonOkay, so Maestro receives the initial request, it then delegates the workout. It spins up one agent whose sole job is to review the vendor's cybersecurity posture and their SOC2 reports.
Sam JonesOkay, so a cyber agent.
Ori WellingtonRight. Then it spins up a second agent trained strictly on legal compliance to analyze the indemnification clauses and liability caps. It spins up a third agent to query the ERP system and verify the budget allocation.
Sam JonesSo you have three distinct AI agents working in parallel.
Ori WellingtonYes. Maestro coordinates all of these disparate analyses, synthesizes the findings, resolves any conflicts between the agents, and then either approves the contract automatically or slags specific clauses for human renegotiation.
Sam JonesAnd Leah is claiming over 400 enterprise customers are utilizing their platform right now. They are projecting up to 30% better platform performance and up to 40% lower cloud operating costs by shifting these workloads onto Oracle's infrastructure.
Ori WellingtonThose are massive claims. And this raises an absolute critical issue for our audience. As analysts, when we see TCS claiming 40% efficiency gains and Leah projecting 40% cost reductions, we have to introduce a framework we call the customer proof gap.
Sam JonesThe ultimate reality check for the enterprise buyer.
Ori WellingtonYes. The market is currently experiencing an environment where AI announcements and press releases are arriving significantly faster than credible audited evidence.
Sam JonesWe are drowning in press releases.
Ori WellingtonWe really are. If you are an executive evaluator, you cannot take a 40% efficiency claim at face value. You must apply a strict proof hierarchy. There are three distinct levels of proof you must demand from any vendor selling an agentic control plane.
Sam JonesWalk us through the hierarchy. What is level one?
Ori WellingtonLevel one is announced capability. This is simply what the vendor says the system can do in a vacuum. It is the press release, the slide deck, the polished demo video.
Sam JonesThe theoretical best case.
Ori WellingtonRight. It proves intent and architectural theory, but it proves absolutely zero operational reality.
Sam JonesOkay. What is level two?
Ori WellingtonLevel two is controlled production adoption. This means the vendor can point to a real named enterprise customer who is actually using the system in a bounded live workflow.
Sam JonesBounded being the keyword.
Ori WellingtonExactly. The system is out of the laboratory, but it is heavily monitored, usually with a mandatory human oversight at every single decision gate. It proves the technology functions in the real world, but not necessarily at scale or autonomously.
Sam JonesAnd the gold standard, level three.
Ori WellingtonLevel three is verified outcome evidence. This requires measurable, sustained results. It requires a clearly defined historical baseline, meaning the customer can prove exactly how long a process took before the AI was introduced.
The Customer Proof Gap Framework
Ori WellingtonAaron Ross Powell Oh, I like this one.
Sam JonesYeah. So level one, announced capability, is the concept car spinning slowly on the velvet pedestal under the bright lights. The manufacturer claims it runs on hydrogen, gets a thousand miles to the gallon, and drives itself. Aaron Powell Looks beautiful, but it looks amazing, but it has no engine and you can't actually drive it off the showroom floor.
Ori WellingtonRight.
Sam JonesLevel two, controlled production adoption is taking that car to a closed private test track with a professional driver behind the wheel. The car functions, the brakes work, but it is not facing unpredictable real-world traffic or weather. Trevor Burrus, Jr.
Ori WellingtonIt's protected.
Sam JonesExactly. Level three, verified outcome evidence is the five-star crash test rating from the National Highway Traffic Safety Administration after the car has been driven a hundred thousand miles on public highways in the snow and the rain.
Ori WellingtonThat's the one you actually buy.
Sam JonesRight. Right now in the agentic AI space, the market is flooded with concept cars. Enterprise executives need crash test ratings before they put their company's entire regulatory risk profile in the passenger seat.
Ori WellingtonThat visual captures the current market dynamic perfectly. Let's apply that hierarchy back to our sources today. Let's do it. In the TCS announcement regarding SARMACOVIGilance, they name no specific customer achieving those metrics. They provide no historical baseline for that 40% efficiency claim, no explanation of the measurement methodology, and no independent validation.
Sam JonesSo they are firmly level one.
Ori WellingtonFirmly. The capabilities they describe are incredibly relevant to the industry's pain points, but the outcome claims remain unverified. They are at level one. Similarly, with Leah, those 30% performance and 40% cost figures are their own internal expectations for their strategic move to Oracle infrastructure, they are not observed, retroactive results from their 400 customers.
Sam JonesSo we have the horizontal technical capability proven by OpenAI in the cybersecurity space. We have massive vertical ambition demonstrated by TCS in Life Sciences and LIA in finance. Right. But this brings us to a massive logistical hurdle. Who is actually going to build, integrate, and govern these wildly complex autonomous systems inside a Fortune 500 enterprise?
Ori WellingtonAaron Powell That is the million-dollar question or the $10 million question.
Sam JonesAaron Powell, you do not just buy agentic AI off the shelf with a corporate credit card, download an executable file, and plug it into your legacy mainframe.
Ori WellingtonIt doesn't work like that.
Sam JonesThere is a massive integration gap. This introduces the architects of the control plane, the global services firms, and the deep infrastructure providers.
Ori WellingtonAaron Powell This is where we see the market structure truly crystallize. Building the model is one thing, distributing it safely is entirely different.
Sam JonesDistribution is everything.
Ori WellingtonOn August 13th, IBM announced a massive dedicated open AI practice. They are staffing this practice with thousands of consultants, data scientists, and engineers.
Sam JonesThousands.
Ori WellingtonThousands. Their strategy is to create forward-deployed units focusing specifically on cybersecurity and AI risk frameworks, utilizing a methodology they're calling IBM Autonomous Security.
Sam JonesThere is a critical nuance in this IBM announcement that I think a lot of casual industry observers completely missed, but it is vital for understanding how the control plane will actually be sold and implemented.
Ori WellingtonYeah, I know what you're gonna say here.
Sam JonesIBM did not announce a product integration with open pages. For context, open pages is IBM's flagship, massive enterprise GRC software platform.
Ori WellingtonThe omission of open pages in an AI risk announcement is incredibly significant.
Sam JonesIt's glaring.
Ori WellingtonIf we look at the broader strategic landscape, treating this IBM news simply as an update to their existing software portfolio completely overstates the maturity of the software and misses the actual strategic play. This
Who Implements This At Scale
Ori Wellingtonmove by IBM is fundamentally about distribution and change management, not just selling a software license.
Sam JonesLet's explore that. Why is human distribution and consulting more important than a direct software integration at this stage of the market?
Ori WellingtonBecause enterprise transformation is violently messy. It's the truth. You cannot just drop a frontier AI model from OpenAI into the core operational workflow of a global bank or a sprawling hospital network without causing massive organizational friction.
Sam JonesNo, the antibodies would attack it immediately.
Ori WellingtonExactly. The legacy systems will reject it, the compliance officers will block it, the employees won't even know how to prompt it correctly. Services firms like IBM and similarly PwC are essentially acting as the distribution engine for the AI revolution.
Sam JonesThey grease the wheels.
Ori WellingtonThey have the deep pre-existing relationships with the C-suite. They can carry these highly volatile frontier models directly into the core operations of an enterprise, and they wrap those models in custom implementation services, bespoke security protocols, and massive enterprise change management frameworks.
Sam JonesSo they are acting as the necessary translation layer between the raw mathematics of the AI model and the rigid compliance reality of the business.
Ori WellingtonExactly that. And because these services firms are the ones actually mapping the domain processes, defining the workflows, and writing the implementation code, they're going to exert massive influence over platform selection.
Sam JonesThey hold the keys.
Ori WellingtonThey are the ones who will ultimately dictate the design of these enterprise control layers. A chief risk officer might not buy an autonomous agent directly from a startup. They will buy an autonomous transformation engagement from PwC or IBM. And the services firm will select the underlying technology.
Sam JonesLet's bring this discussion directly to the immediate visceral pain points of the executive listener because right now there is a brutal collision happening between the ambition of these AI projects and the harsh reality of enterprise infrastructure and data governance.
Ori WellingtonIt's a bloodbath out there for these projects.
Sam JonesIt really is. The data on this collision is eye-opening. We need to look at the August 11th survey sponsored by Cloudera. They surveyed 1,500 enterprise technology leaders across nine different global markets. Aaron Powell Wait, 95%. That is a near total failure rate for deployment. And what were the primary culprits? Data governance, compliance hurdles, or regulatory challenges?
Ori WellingtonAaron Powell The survey goes deeper too. 73% of those leaders stated that the introduction of AI is actually making data governance more complex, not easier.
Sam JonesAaron Powell But the most revealing and frankly shocking statistic from the report is this 66% of these enterprises have actively moved AI workloads away from the public cloud, repatriating them back to private clouds or physical on-premises environments. I have to play the devil's advocate here. Look at the narrative we have built over the last half hour. If these tools are so incredibly powerful, if OpenAI's daybreak is patching zero-day vulnerabilities in a matter of hours instead of months, and TCS is promising a 40% efficiency gain in clinical trials, why on earth are 95% of enterprise leaders slamming on the brakes?
Ori WellingtonIt's a great question.
Sam JonesAnd why are they doing the one thing that technology companies have spent a decade telling them never to do, which is pulling workloads out of the infinitely scalable public cloud? It feels completely contradictory.
Ori WellingtonIt seems contradictory only if you ignore the infrastructure reality of compliance. This is the ultimate friction point. Enterprise buyers require absolute uncompromising architectural
Why AI Projects Stall In Reality
Ori Wellingtoncontrol. Trevor Burrus, Jr.
Sam JonesControls everything.
Ori WellingtonWhen you empower an AI agent to make decisions that carry legal or financial liability, you need total control over the proprietary data it is trained on. You need control over the geographic environment where it is deployed. You need granular control over the identity and access management of the agent itself, knowing exactly what databases it can and cannot query.
Sam JonesRight.
Ori WellingtonYou need control over the policies it follows, and you must maintain absolute custody of the evidence it generates.
Sam JonesAnd the harsh reality is you cannot get that level of architectural control if your multi-agent workflows are scattered to the wind across three different multi-tenant public clouds.
Ori WellingtonYou absolutely cannot. Consider a European financial institution. They are bound by GDPR and strict sovereign data laws. They cannot risk an AI agent pulling sensitive customer data, processing it in a public cloud server located in a different jurisdiction, and then passing that context to another agent in yet another cloud.
Sam JonesIt's a regulatory nightmare.
Ori WellingtonA centralized legacy GRC application cannot possibly govern an AI agent if the workloads are fragmenting across public clouds, private on-prem servers, and specialized sovereign clouds. This is why you see companies like Oracle Building distributed cloud options specifically to address this panic.
Sam JonesThey see the writing on the wall.
Ori WellingtonThe enterprise is collectively saying we desperately want the margin benefits of AI, but we absolutely cannot survive the regulatory and data privacy risks of losing control over where our data lives and how these autonomous decisions are being made.
Sam JonesThat is the driving force behind the repatriation of workloads to private environments where the CISO can actually enforce strict governance.
Ori WellingtonExactly.
Sam JonesOkay. We have diagnosed the core problem. The market is shifting from passive recording to active autonomous orchestration. We have identified the massive roadblock, severe governance, and infrastructure friction, causing 95% of projects to stall.
Ori WellingtonSo what do we do about it?
Sam JonesRight. Let's deliver on the promise of this deep dive. Let's give the executive listener the actual playbook. If you are sitting in a boardroom next week and a vendor is pitching you an agentic risk management tool or an autonomous AI compliance platform, how do you cut through the marketing noise?
Ori WellingtonYou have to ask the hard questions.
Sam JonesWhat are the essential criteria you must demand to ensure you are buying a true control plane and not just a dangerous toy?
Ori WellingtonBased on our deep analysis of this market shift, we have defined five essential criteria that must be rigorously met for any system claiming to be a credible agentic control plane.
Sam JonesOkay, let's hear them.
Ori WellingtonCriterion number one is action boundaries.
Sam JonesDefine an action boundary in a technical sense. Like how does an executive actually mandate this?
Ori WellingtonAn action boundary is the explicit coded definition of the AI's autonomy. You must be able to clearly and dynamically define which decisions an agent is allowed to make independently, which physical actions it is authorized to execute in your environment, and exactly where human approval becomes a hard mandatory gate.
Sam JonesSo no rogue agents.
Ori WellingtonIf a vendor cannot show you the dashboard where you definitively constrain the AI's reach, the system is too dangerous to deploy in a regulated environment.
Sam JonesLet me give a concrete example of this using the cybersecurity scenario we discussed earlier.
Ori WellingtonYeah, that helps.
Sam JonesYou might configure an action boundary that states the AI agent is fully authorized to autonomously scan the code base, identify a vulnerability, and draft the code for a patch. That is a highly autonomous workflow. Right. However, the action boundary strictly prohibits the AI from actually deploying that patch into the live production environment. The deployment requires a human site reliability engineer to review the code and physically click approve. The boundary separates the autonomous drafting from the
A Buyer Playbook For Control Planes
Sam Joneshuman-gated deployment.
Ori WellingtonAnd that human-in-the-loop threshold must be easily configurable by the compliance team, not just hard-coated by a developer somewhere where you can't reach it.
Sam JonesMakes total sense.
Ori WellingtonExactly. Let's say an authorized agent moves from a highly secure private cloud application to pull supplementary data from a public cloud SaaS tool like Salesforce or Workday. The agent cannot suddenly lose its compliance parameters just because it crossed a network boundary.
Sam JonesRight.
Ori WellingtonThe controls must be sticky. The agent must inherit the rules of the new environment and the sensitivity of the data it touches while maintaining its core corporate restrictions.
Sam JonesThis is a massive vulnerability in early AI deployments. If I have a strict data privacy policy regarding European customer data, and my AI agent is summarizing a massive global data set, the agent must inherently know and apply the GDPR masking restrictions to the European data points automatically.
Ori WellingtonIt shouldn't be an afterthought.
Sam JonesExactly. The compliance officer shouldn't have to manually inject a GDPR prompt into every single query the agent makes. The policy must be inherited by the agent's core operational logic.
Ori WellingtonPrecisely. Which leads us to criteria number three. And this is perhaps the most critical demand for the audit and legal professionals listening. Evidence by design. A black box is an automatic audit failure. Full stop.
Sam JonesRight.
Ori WellingtonEvidence by design means it is an absolute architectural necessity for the system to natively, automatically, and immutably retain every single piece of the decision-making process.
Sam JonesAaron Powell Like an airplane's black box, ironically.
Ori WellingtonYes. Think about what an auditor needs. The system must log the initial human prompt or the system trigger. It must log the full context of the data the agent analyzed. It must record every API or tool call the agent made to other software systems. It must log the specific probability matrix or logic tree it used to arrive at a conclusion.
Sam JonesThat's a lot of data.
Ori WellingtonIt is. It must record any human approvals it received, the exact changes it executed, any exceptions or errors it encountered, and the final outcome.
Sam JonesAnd crucial to this criterion, it must retain all of this telemetry in a format that a human audit team can actually read, interpret, and present to a regulator.
Ori WellingtonYes. If the FDA comes knocking on the door of a pharmaceutical company and asks, why was this specific adverse drug reaction classified as minor instead of severe, you cannot look the federal auditor in the eye and say, well, the neural network decided it was minor.
Sam JonesThey would shut you down.
Ori WellingtonInstantly. You must be able to pull the design evidence log that shows exactly what clinical literature the AI referenced, the weighting it gave to the patient's pre-existing conditions, and the digital signature of the human supervisor who signed off on the workflow. If the AI cannot mathematically show its work, it cannot be trusted with regulated operations.
Sam JonesWhich brings us to criterion number four, reversibility.
Ori WellingtonReversibility is the enterprise kill switch, but is also the granular undo button.
Sam JonesOkay, explain that.
Ori WellingtonThe executive evaluator must ask, can an agent's actions be stopped mid-flight if an anomaly is detected? Can a completed automated sequence be rolled back entirely to its previous state? Or can the agent and its outputs be instantly isolated into a quarantine environment if the underlying evidence changes, or if your confidence in the AI model's accuracy suddenly drops?
Sam JonesThis is critical because AI models are not static. They experience model drift. Their accuracy can degrade over time as they ingest new data or external information changes.
Ori WellingtonAll the time.
Sam JonesLet's look back at the Lia Maestro procurement example we used earlier. Imagine that multi-agent system autonomously executed 50 supplier contracts based on a predictive pricing model.
Ori WellingtonOkay.
Sam JonesSuddenly, your finance team realizes the pricing model was flawed due to a corrupted data feed. You need a mechanism to instantly halt any further automated purchasing, identify the 50 contracts the agent already executed, and roll back or quarantine those specific agreements for human renegotiation. Right.
Ori WellingtonWithout reversibility, an autonomous mistake scales infinitely and permanently.
Sam JonesAnd finally, criterion number five, proof maturity. This refers back to the hierarchy of proof we established earlier.
Ori WellingtonRight, the auto show.
Sam JonesWhen evaluating an agentic tool, you must aggressively demand to know the exact status of the vendor's claims. Do not accept marketing literature as operational fact. Ask them directly: are we buying an announced feature, a bounded production deployment, or a verified customer outcome supported by baseline data?
Ori WellingtonDemand to see the crash test ratings, not just the concept car. But as we analyze the procurement dynamics of this space, there is actually a sixth, often unspoken rule that we need to add to this executive playbook, and that rule is portability.
Sam JonesI am so glad you brought this up because portability addresses the reality of the future enterprise tech stack. No enterprise is going to rely on just one single AI model for everything.
Ori WellingtonNo, it's going to be a mix.
Sam JonesIt is a heterogeneous future. You are going to use open AI's models for complex coding and cybersecurity. You might use an open source model like Meta's Llama for internal, highly secure document search. You will use a highly specialized, fine-tuned medical model for pharmacovigilance. Right. And you are going to be running these various models across AWS, Azure, Google Cloud, and Oracle.
Ori WellingtonThe ecosystem will be massively fragmented. And if you allow your risk controls and your evidence logs to become natively locked into one specific model provider or one specific cloud application, you are walking into a trap.
Sam JonesA huge trap.
Ori WellingtonYou are simply recreating the exact same fragmented silos and trapped beta that the entire integrated risk management industry was originally invented to solve 20 years ago. Procurement teams must test whether the agentic control plane is agnostic. It must be able to preserve policies and evidence, regardless of which underlying model is executing the task.
Sam JonesLet me drive this portability point home with an absolute nightmare scenario for the executives.
Ori WellingtonOh, this should be good.
Sam JonesImagine you are negotiating a massive multi-year enterprise software contract. You are utilizing a cutting-edge multi-agent system from a specific vendor to review the terms. The AI agent makes a critical, autonomous mistake. It completely misses a massive liability loophole regarding beta breaches.
Ori WellingtonOkay. So the AI missed it.
Sam JonesThe AI missed it. The contract is finalized and signed. Six months later, your company suffers a massive data breach, and you discover you are entirely on the hook
Portability And The Audit Log Nightmare
Sam Jonesfor millions of dollars in damages because of that loophole. Yeah. When the federal regulators or your own board of directors demand to know how this happened, you have to pull the audit logs to prove you had action boundaries and reversibility in place.
Ori WellingtonRight. You need your proof.
Sam JonesBut what if during those intervening six months, your company decided to switch AI vendors because a cheaper model came out? If your control plane and your evidence logs were natively locked, the specific AI vendor that made the original mistake, and you've since terminated that contract, can you even access the historical audit logs?
Ori WellingtonOh wow. That is the ultimate compliance nightmare. If your control plane is not portable and structurally independent from the operational models doing the actual work, your critical compliance evidence might simply vanish when your vendor relationships change.
Sam JonesPoof, gone.
Ori WellingtonThe control plane must sit a layer above the AI models, governing them universally and retaining the evidence independently.
Sam JonesSo as we synthesize all of the technical signals, the vertical market movements, and the infrastructure realities we have discussed today, what is the core defining takeaway for the enterprise evaluators and the market analysts who are trying to navigate this transition?
Ori WellingtonThe overarching takeaway is a fundamental redefinition of the market standard. The standard of risk management technology is irrevocably moving from a posture of a test to a posture of act.
Sam JonesA test to act.
Ori WellingtonAdding a generic, generative AI chat interface onto a legacy GRC platform so a user can query old policies faster, that is not an agentic control plane. No. The winning architecture in this new market will be the platform that simplifies and seamlessly integrates the entire operational path. From the initial sensing of a signal to the AI's contextual decision, to the automated execution of the action, the subsequent remediation of the risk, and the irrefutable, cryptographically secure proof of compliance. It has to do it all. Market leadership in the next decade is going to follow demonstrated autonomous risk agency, not just the latest update to marketing vocabulary.
Sam JonesIt is a profound structural shift in how businesses operate. We are truly moving from passively observing the battle to actively commanding the field. But as we wrap up this deep dive into the agentic control plane, I want to leave you, our listeners, with a final, somewhat provocative thought to mull over as you look at your own organizational roadmaps.
Ori WellingtonYeah, let's leave them with something to think about. As we rapidly build and deploy these incredibly complex systems where AI agents are empowered to sense, decide, and act autonomously, while simultaneously generating massive, complex logs of audit evidence to prove their own compliance, we really have to confront a looming human limitation. Which is the sheer volume, velocity, and mathematical complexity of the evidence generated by thousands of AI agents making millions of micro decisions every day, it will quickly surpass the cognitive capacity of human audit teams.
Sam JonesThey just won't be able to read it all.
Ori WellingtonExactly. Human auditors simply won't be able to read fast enough to keep up. So the question we have to ask is how long before we are forced to build an entirely separate, independent tier of AI agents whose sole, dedicated purpose is just to audit and verify the evidence created by the operational AI agents.
Sam JonesWow. So are we building a perfectly self regulating, incredibly efficient digital loop, or are we just constructing an infinite, inescapable hall of mirrors? It is certainly something to think about as you sit down to evaluate your next enterprise risk platform. Thank you for joining us on this deep dive on Risk Wheelhouse. We'll see you next time.