As enterprises move from early experiments with generative AI to building agentic, goal-driven systems, the questions leaders are asking have shifted. The emphasis has moved away from what AI can do and toward how it can be trusted, controlled and integrated into how a business actually runs. Insights shared by Craig Wiley, a senior product leader at Databricks who previously led machine-learning products at AWS and Google Cloud, help illustrate how leading organisations are approaching this next phase.
From experiments to systems leaders can trust
Early on, many organisations struggled to use generative AI in genuinely useful ways, in part because a lot of business processes are deterministic while early GenAI was not. Agents change that balance: by wrapping models in structured workflows, teams can build systems that behave in a near-deterministic way and reason more deliberately about accuracy. The result is a shift from open-ended chat toward dependable systems that can be relied on for specific tasks such as supply-chain, customer service or operations.
Getting data ready
The least glamorous answer to “where do we start” remains the right one: the data. Two broad approaches tend to work. A bottom-up path modernises data foundations broadly, made easier by tools that now simplify moving data out of older systems, sometimes with AI assistance in writing the migration code. A use-case-driven path starts from a specific ambition, asks what data that goal actually requires, and modernises just those pieces first. Neither is universally better; a bottom-up approach preserves flexibility later, while a use-case approach can be faster when the need is urgent. The only real mistake is failing to give data the time and attention it needs.
Where early wins are emerging
Early adopters have gradually moved beyond marketing and other creative use cases, where a model’s generative nature was forgiving of imperfection, toward more operational applications where reliability matters more. That progression reflects growing confidence that agentic systems can be constrained and measured well enough for higher-stakes work.
Governance when agents become users
Governance becomes harder once agents act as users of systems rather than tools operated by a person. A useful way to frame the challenge is around three questions. Who is the actor? This calls for strong identity and detection that works for both human and non-human actors. What are they allowed to do? This requires governance over the APIs and data an agent can reach. And how do they know what to do? This depends on good documentation and metadata describing what a table contains or what an API does. When identity and documentation are solid, an agent can be pointed at a task and make progress quickly and safely.
Building capability before chasing ROI
Over the next one to two years, many organisations remain stuck on the build-versus-buy question. The argued view is that companies with developers should plan to build internal capability rather than outsource all software development, and that in the near term the priority is whether teams can actually build and deliver these systems, with return on investment following once that capability exists. In practice this means treating agentic AI as a muscle to develop rather than a product to purchase outright.
The mindset that separates winners
A common misconception slows progress: because early GenAI felt easy, people expect it to stay easy. Building strong AI systems is hard, failures are expected, and success comes from continuous improvement rather than getting everything right the first time. The organisations most likely to succeed treat early projects as ways to build their teams’ experience, not just to hit an immediate metric.
What to watch
The views above come largely from one vendor’s product perspective, so they should be weighed alongside independent evidence and an organisation’s own context; a supplier naturally emphasises capabilities its platform supports. Even so, the underlying themes are widely echoed: agentic AI rewards unglamorous groundwork on data quality, identity, access governance and documentation, and it punishes shortcuts. Treating agents as privileged users means their access, permissions and auditability need the same rigour applied to human employees, if not more, because an agent can act quickly and at scale. Leaders should be wary of both over-hyped ROI promises and the temptation to skip the hard foundational work, and should invest early in internal skills while measuring reliability, not just novelty. These themes connect closely to the rise of dedicated AI leadership roles and to enterprise efforts to manage the risks of deploying AI agents. Broader perspective on enterprise AI is available from Databricks.