The Control Imperative​

Prepared by Grant West · Senior Platform Engineer, Ntegra


One of the most important conversations in enterprise technology right now is not about capability; it is about control. The models are powerful enough. The question being asked across every serious boardroom, every defence programme office, and every government digital team is the same: who governs what the machine does next? That question ran through almost every session at this year’s Summit, surfacing most sharply across three themes: agentic AI, autonomous defence, and sovereign development.​

Agentic AI — the control problem hiding inside the capability story

The shift from AI as a tool to AI as an actor changes the governance problem fundamentally. Almost every credible vendor framed its roadmap around autonomous agents - systems that authenticate, reason, and act without a human approving each step. How those agents are provisioned, monitored, and decommissioned across their full lifecycle was named repeatedly as the single most urgent challenge. Several teams now treat agents as non-human insiders, assigning them their own identity and behavioural baselines and monitoring for drift (Exabeam, Above Security, Witness AI). The moment that crystallised the stakes was a live demonstration of a compromised agent asking a second agent for the commands needed to bypass data-loss controls. Agent-on-agent evasion is a genuinely new threat class, and existing tooling built for human actors does not yet address it. Capability arrived ahead of control, and the gap is now measurable.​

Autonomous Defence — when the machine acts faster than the human in the loop

The same dynamic plays out at machine speed in cyber and in the physical domain. AI-driven penetration testing and attack-swarm red teaming (Horizon3, A Security, Armadin) are collapsing the window between a known exploit and an active attack from months to hours, with distilled frontier-class models reaching threat actors within months of release. The question is no longer whether the adversary is using AI; it is whether your defences can respond at the same tempo. In the physical world, edge autonomy has moved from roadmap to operational: combat-proven uncrewed surface vessels, GNSS-denied tactical drones with electronic-warfare resilience, and autonomous underwater vehicles carrying desktop-class GPUs are already deployed. In each case, the governance challenge is identical - at what point does a human remain meaningfully in the loop? The organisations ahead are not those with the most capable systems. They are those that have answered the control question first.​

Sovereign Development — control of the stack as a strategic imperative

The third dimension of control is structural. Across every session that touched on public-sector technology, the recurring requirement was sovereignty of infrastructure, of data, and of the deployment environment. This is not a procurement preference; it is a risk posture. The roughly six trillion dollars of annual technology spend is being rebuilt around a concentrated cognitive stack, with around 70% of first-quarter venture capital going to just five companies. The third dimension of control is structural. Across every session that touched on public-sector technology, the recurring requirement was sovereignty of infrastructure, of data, and of the deployment environment. More often than not, this is a risk posture and not simply a procurement preference. The roughly six trillion dollars of annual technology spend is being rebuilt around a concentrated cognitive stack, with around 70% of first-quarter venture capital going to just five AI companies. Organisations that do not decide where their AI runs, which models they rely on, or how they could switch providers risk losing control of their AI strategy. At the same time, AI regulation is becoming stricter. The current light-touch approach in the US is unlikely to last; export controls on advanced AI models could become much tougher (similar to ITAR), and the EU AI Act may set the global standard. Organisations that address these issues now will be in a much stronger position than those that wait until the rules become more restrictive.

The Imperative

Capability now counts for less on its own; it has become more of a baseline and is not always the differentiator. What separated the organisations worth watching was the maturity of their answer to the control question: governance of agents, tempo in autonomous operations, and sovereignty over the stack. For enterprise technology leaders, this must be the work of the next 18 months.

Previous
Previous

Executive Summary