Silicon Valleys Journal
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
No Result
View All Result
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
No Result
View All Result
Silicon Valleys Journal
No Result
View All Result
Home Technology & Industry Agentic

Trust before autonomy: the AI guardrails enterprise IT actually needs

By Barry Angell, CEO and Co-Founder, Juriba

SVJ Thought Leader by SVJ Thought Leader
August 18, 2026
in Agentic, AI, Boardroom & Governance, Enterprise Tech, Leadership & Perspective, Technology & Industry
0
Trust before autonomy: the AI guardrails enterprise IT actually needs

I argued in a recent interview that trust has become one of the most measurable elements of customer experience, because customers increasingly decide on confidence rather than convenience alone. What I did not say is that the same logic runs inward as well as outward, long before any customer sees a result. Before an enterprise can ask its customers to trust an AI-shaped experience, its IT function has to be able to trust its own automation, and to show why.

That is about to get harder to answer. The technology reshaping enterprise IT operations over the next three years is not a chatbot drafting a knowledge article; it is software that decides and then acts across production estates. Worth being precise about the word: in our industry an agent has meant the thing we install on endpoints for twenty years. An AI agent is a different proposition entirely.

Adoption is running well ahead of governance

The gap between enthusiasm and readiness is already documented. Gartner® predicts that “over 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls”. It is the third of those reasons that should occupy IT leaders, because the first two are commercial disappointments, while the third is an operational incident with users and impact attached to it.

Those running enterprise IT are already feeling this. IBM’s Institute for Business Value, surveying 2,000 technology executives in early 2026, found organisations reported an average of 54 AI agent incidents over the previous year that required human intervention or correction, 17% of them high severity, taking more than four hours to contain. Two-thirds of the CIOs and CTOs surveyed said they are held accountable for AI systems they do not fully control, and only 11% believed they were ready for the scale of deployment expected in the year ahead.

The blast radius question, and why it is not theoretical

I run a company that helps large enterprises manage continuous change across the digital workplace: Windows feature updates, application packaging and testing, device refresh, VDI platform transition and security patching. In that world, a single automated decision rarely lands on a single system. It lands on tens of thousands of people trying to start work on Monday morning, so getting it wrong creates not a ticket but an outage in every department depending on what was just released.

We have a relatively recent and unusually well-documented illustration at scale. On 19 July 2024 a CrowdStrike content update disabled an estimated 8.5 million Windows devices, by Microsoft’s own count, and the cyber-risk analytics firm Parametrix put the direct cost to US Fortune 500 companies alone at $5.4 billion, only a fraction of it insured. What makes it instructive is that CrowdStrike’s own root cause analysis named precisely the controls that had been missing.

That document sets out the intended model plainly: “New Template Instances that have passed canary testing are to be successively promoted to wider deployment rings or rolled back if problems are detected.” The remediation list published alongside it reads like a guardrail specification: staged deployment rings, customer control over when updates land, input validation, rollback testing. None of it is exotic engineering, and all of it was missing at the moment it mattered.

None of which is really an AI story; it is a change-at-scale story, and agentic AI is about to increase the volume of change enormously. Uptime Institute’s 2026 outage analysis found configuration and change management failure to be the most common cause of major network-related outages, at 41%. We are now preparing to hand much of that change activity to software that acts faster than anyone can watch it.

Blast radius, then, should determine how much autonomy an AI agent is given. Where a mistake is cheap and quickly reversible, let it run and stop spending scarce engineering attention supervising it. Where the mistake takes out payroll, a trading system or a contact centre, the answer needs to be considerably better than “trust the model”.

Guardrail one: simulate before anything executes

Every agentic action worth automating should run as a simulation first, against real estate data, producing a predicted outcome an engineer can interrogate before anything moves. If an AI agent proposes to promote 3,000 devices into a deployment ring, I want to know which 3,000, what they depend on, which dependencies are unresolved, and what the projected failure rate is. That is not a demonstration feature. It is the difference between a recommendation and a gamble.

A cultural point is buried in the mechanism, and it matters as much. A failure found in simulation is a success rather than a setback, because it surfaces the problem while it is still cheap to fix, and each run adds to the evidence base on how accurate a given AI agent really is in your environment, on your data, with your exceptions. The joint guidance Careful adoption of agentic AI services, co-sealed in 2026 by the UK’s National Cyber Security Centre and five partner agencies, recommends the same discipline in plainer terms: “Deploy sandbox environments to test agent behaviour before production deployment”.

Guardrail two: approval gates sized to the blast radius

Human approval tends to get framed as friction that mature organisations eventually engineer away, and that framing is straightforwardly wrong. Reporting on Gartner’s July 2026 research into AI in IT operations, The Register noted an expectation that the share of AI-suggested actions taken only after human-in-the-loop approval will fall to 20% by 2029, down from 80% in 2025. As a description of where low-risk, high-volume work ends up, that is plausible; as a target to apply uniformly across an estate, it is a recipe for a very bad disaster.

The workable model is graduated, with approval proportional to reversibility, scope and business criticality. Routine, reversible, low-population actions execute automatically with notification; actions touching critical applications, regulated systems or large device populations pause for a named human owner; actions with no clean rollback path go to a change board, as they would today. That joint guidance puts it crisply, advising organisations to “insert human-in-the-loop review or approval checkpoints for actions where the cost of error is high”.

Guardrail three: rollback designed in, not improvised afterwards

The question I ask of any automation we build is not “will this work?” but “when this is wrong, how do we get back?” If the answer involves a restore process, a lost weekend and an apology, it is not ready, however impressive the decision-making looks in a demonstration.

Rollback has to be a first-class design requirement, specified alongside the action and tested with equal rigour: known-good state captured before execution, a bounded reversal path, a defined maximum exposure window. The same joint guidance and the US National Institute of Standards and Technology reach this from different directions, the former asking for “versioning and rollback mechanisms to safely revert a system to known-good agent behaviours”, the latter for mechanisms to “supersede, disengage, or deactivate” AI systems behaving inconsistently with intended use.

The market is pricing this in. Gartner expects that “by 2030, guardian agent technologies will account for at least 10 to 15% of agentic AI markets”, and its analyst Avivah Litan has put the reasoning more bluntly than I would dare: “Agentic AI will lead to unwanted outcomes if it is not controlled with the right guardrails.”

Guardrail four: continuous governance, evidenced

The four guardrails, as Juriba frames them.

Regulators have settled a question many enterprises are still debating internally. Article 14 of the EU AI Act requires high-risk AI systems to be designed so people can effectively oversee them, including the ability to disregard or reverse an output and to halt the system through a stop function that brings it to a safe state. After this summer’s digital omnibus regulation that obligation applies to stand-alone high-risk systems from December 2027, which sounds like breathing room until you consider that the design changes involved cannot be retrofitted in a quarter.

In practice every agentic action needs a durable record: what was proposed, on what data, under which policy, who approved it, what happened, and what the reversal path was. NIST asks much the same, listing “appeal and override, decommissioning, incident response, recovery, and change management” among the things post-deployment monitoring must cover. When a customer, auditor or board member asks why a decision was taken, “the model determined it” is not an answer. Good governance is not about exposing algorithms; it is about demonstrating that decisions are fair, accountable and open to challenge.

Nor is any of this a one-off exercise. Policies have to evolve as the agents, the threats and the estate change around them.

Why we will not ship an unguarded AI agent

The temptation to announce autonomous agents ahead of the guardrails is real, and the market is thick with claims that do not survive inspection. Gartner calls this “agent washing”, describing it as “the rebranding of existing products, such as AI assistants, robotic process automation (RPA) and chatbots, without substantial agentic capabilities”, and estimates that only about 130 of the thousands of vendors making agentic claims are the real article. In our corner of the market, shipping ahead of the controls would be worse than overselling. It would be reckless.

So we are deliberately building agentic capability into our Digital Platform Conductor (DPC) behind simulation, approval and rollback rather than in front of them. That costs us the occasional headline and remains the right call, because although our customers may desire set-and-forget autonomy; they are buying confidence that change will not break their business. An AI agent that is right 95% of the time across 60,000 devices is not a 95% success story. It is 3,000 broken users and a very long Monday.

Governing continuous change from a control tower

The analogy I keep returning to is the ‘supply chain’ control tower. Modern supply chains are not centrally controlled, since thousands of decisions are taken autonomously across suppliers, carriers and warehouses, yet they are centrally visible, with the authority to intervene when a local decision threatens the network. That is the right mental model for governing continuous change across tens of thousands of endpoints, and it reframes the objective usefully: not a human in every loop, but the organisation in the loop.

Concretely, that means one place where every AI agent, automation and change programme is visible, where policy is enforced consistently rather than tool by tool, and where somebody can see the aggregate effect of a hundred individually sensible decisions. In our world, that means relying on a single source of trusted truth across multiple data sources, many of which conflict in the information they supply. Get this right and the investment appears to repay itself: IBM found that organisations embedding controls directly into their AI systems experience 25% fewer incidents than those relying mainly on manual oversight.

Autonomy is earned, not enabled

Trust inside IT behaves much as it does with customers: it accumulates through consistent, demonstrable behaviour, and it is granted incrementally rather than switched on. An AI agent should earn expanded scope by building a verifiable track record in simulation and under supervision, which is what the international guidance has in mind when it recommends “phased deployment with progressively increasing access and autonomy, limiting the action space”.

The organisations that get the most out of agentic AI will not be the ones that removed human oversight fastest. They will be the ones that built enough governance to know exactly which decisions no longer needed it, and could prove it. Trust, in the end, is not a by-product of good technology. It is a design choice.

“The winners will not be the organisations that deploy AI fastest. They will be the ones that can govern continuous change while maintaining transparency, accountability and confidence, because in enterprise IT, autonomy without guardrails is not innovation. It is unmanaged risk with a better user interface.”

Barry Angell, CEO and Co-Founder, Juriba

Editorial pack

Attribution: Barry Angell, CEO and Co-Founder, Juriba

Word count: 1,891 words of body copy; 1,995 including headings and standfirst. Silicon UK range is 800 to 2,000.

Featured image: To be supplied separately, under 500kb, not a logo or profile photo, usage rights held by Juriba. The AI Agent Guardrails infographic is placed in-body at Guardrail four; a 500kb-compliant copy is supplied alongside this draft.

Gartner content share

Gartner-attributed material is 153 words, or 8% of body copy. Gartner’s published Content Compliance Policy sets the limit at 30% (the “30/70 rule”); there is no 20% threshold anywhere in Gartner’s policy, so this draft sits well inside both the actual rule and the stricter internal target.

Gartner item usedSource typeFree to quote?
“Over 40% of agentic AI projects will be canceled by the end of 2027…”Public press release, 25 June 2025Yes, with title, date and live URL
“Agent washing” definition and ~130 vendorsSame press releaseYes
“By 2030, guardian agent technologies will account for at least 10 to 15% of agentic AI markets”Public press release, 11 June 2025Yes
Avivah Litan quote on guardrailsSame press releaseYes
Human-in-the-loop approval falling to 20% by 2029Paywalled report, cited via The RegisterAttributed to The Register’s reporting, not to Gartner directly

All Gartner figures are quoted verbatim, as the policy requires, rather than paraphrased. Note that “canceled” inside the quotation marks is Gartner’s own US spelling and must not be anglicised to “cancelled”; changing a character inside the quote turns it into a paraphrase, which the policy prohibits. Gartner® carries the registered mark on first prominent use.

References cited in text

  • Gartner Press Release, “Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027,” 25 June 2025. https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
  • Gartner Press Release, “Gartner Predicts that Guardian Agents will Capture 10-15% of the Agentic AI Market by 2030,” 11 June 2025. https://www.gartner.com/en/newsroom/press-releases/2025-06-11-gartner-predicts-that-guardian-agents-will-capture-10-15-percent-of-the-agentic-ai-market-by-2030
  • The Register, “AI ops tools will create console sprawl and break IT more often: Gartner,” 20 July 2026, reporting Gartner’s Hype Cycle for AI in IT Operations, 2026. https://www.theregister.com/ai-and-ml/2026/07/20/ai-ops-tools-will-create-console-sprawl-and-break-it-more-often-gartner/
  • IBM Institute for Business Value, study of 2,000 technology executives across 33 geographies, published 8 June 2026. https://newsroom.ibm.com/2026-06-08-new-ibm-study-finds-cios-and-ctos-face-growing-ai-control-gap-as-enterprise-deployment-scales
  • Microsoft, “Helping our customers through the CrowdStrike outage,” 20 July 2024 (8.5 million devices). https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/
  • Parametrix, “CrowdStrike’s impact on the Fortune 500,” 24 July 2024 ($5.4bn direct loss to US Fortune 500, of which $0.54bn to $1.08bn insured). https://www.parametrixinsurance.com/in-the-news/crowdstrike-to-cost-fortune-500-5-4-billion-insured-loss-range-of-540-million-to-1-08-billion
  • CrowdStrike, External Technical Root Cause Analysis, Channel File 291, 6 August 2024. https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
  • The Update That Crashed the World — What the CrowdStrike Outage Teaches Every IT Leader.  The Update That Crashed the World — What the CrowdStrike Outage Teaches Every IT Leader | EmergEdge | EmergEdge
  • Uptime Institute, Annual Outage Analysis 2026, May 2026. https://datacenter.uptimeinstitute.com/rs/711-RIA-145/images/2026.AnnualOutageAnalysis.pdf
  • ASD’s ACSC, CISA, NSA, Canadian Centre for Cyber Security, NCSC-NZ and UK NCSC, Careful adoption of agentic AI services, 2026. https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF
  • UK National Cyber Security Centre, Thinking carefully before adopting agentic AI (companion blog), 15 May 2026. https://www.ncsc.gov.uk/blogs/thinking-carefully-before-adopting-agentic-ai
  • NIST, AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1, 26 January 2023 (subcategories MANAGE 2.4 and MANAGE 4.1). https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
  • EU AI Act, Article 14: Human Oversight, Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/14/
Previous Post

MPLX LP 2025 K-3 tax packages now available on company website

SVJ Thought Leader

SVJ Thought Leader

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

December 30, 2025
The AI Cold War and How to Prepare for It

The AI Cold War and How to Prepare for It

May 1, 2026
AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

November 26, 2025
The UK’s Seed-to-Series A gap is growing. Should we fix it?

The UK’s Seed-to-Series A gap is growing. Should we fix it?

November 25, 2025
The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

1

50 Key Stats on Finance Startups in 2025: Funding, Valuation Multiples, Naming Trends & Domain Patterns

0
CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

0
Clarity Is the New Cyber Superpower

Clarity Is the New Cyber Superpower

0
Trust before autonomy: the AI guardrails enterprise IT actually needs

Trust before autonomy: the AI guardrails enterprise IT actually needs

August 18, 2026

MPLX LP 2025 K-3 tax packages now available on company website

August 18, 2026

Automotive Cybersecurity Market worth $18.86 Billion by 2033 | MarketsandMarkets™

August 18, 2026

Introducing Alvys Foundry: Customizable AI Agents Built Natively into TMS

August 18, 2026

Recent News

Trust before autonomy: the AI guardrails enterprise IT actually needs

Trust before autonomy: the AI guardrails enterprise IT actually needs

August 18, 2026

MPLX LP 2025 K-3 tax packages now available on company website

August 18, 2026

Automotive Cybersecurity Market worth $18.86 Billion by 2033 | MarketsandMarkets™

August 18, 2026

Introducing Alvys Foundry: Customizable AI Agents Built Natively into TMS

August 18, 2026

About & Contact

  • About Us
  • Branding Style Guide
  • Contact Us
  • Help Centre
  • Media Kit
  • Site Map

Explore Content

  • Events
  • Newsletter
  • Press Releases
  • Reports & Guides
  • Topics

Legal & Privacy

  • Advertiser & Partner Policy
  • Communications & Newsletter Policy
  • Contributor Agreement
  • Copyright Policy
  • Privacy Policy
  • Prohibited Content Policy
  • Terms of Service

Tiny Media Brands

  • Silicon Valleys Journal
  • The AI Journal
  • The City Banker
  • The Wall Street Banker
  • World Lifestyler
  • About
  • Privacy & Policy
  • Contact

© 2025 Silicon Valleys Journal.

No Result
View All Result

© 2025 Silicon Valleys Journal.