This deep dive expands on the Loop Asia conversation with Matthias Biehl.
Before Matthias Biehl gets to governance architecture, he describes what happens before an IT team opens a whiteboard: a mandate arrives from the top. "They hear things like, 'We want to become an agentic enterprise where there are agents working next to every employee.'" An agent as a colleague, in every department. In Biehl's words, "the burden is on the IT teams to figure out how do we make this actually work."
That handoff — vision down, no bridge to execution — is an organisational problem before it's a technical one.
What "great progress" actually means
Here's the thing Biehl says next, easy to miss because it sounds like a success story: "We make big progress, great progress on our AI prototypes... even at IBM, we do this, right? So we have an Ask HR agent that works in the HR department, and you can ask this agent simple questions about HR — how many vacation days do I have left over for this year? And it will answer you correctly, and that's great."
It is great. It's also the kind of win that lets an organisation feel like it's delivering on the mandate without proving it can — genuinely low risk, nothing customer-facing on the line. Jon puts it directly: "The low-hanging fruit is that an organisation should be able to mine its own information, test on its staff, because they'll get honest conversations without breaking things with customers." Not a knock on the Ask HR agent — a warning against mistaking it for proof the harder problem is solved.
Biehl names the actual gap: "What's missing is we don't close the gap between these prototypes and internal implementations and mainstream adoption, productive use cases on critical customer-facing applications." Internal wins and customer-facing production are different categories of problem; the mandate from the top doesn't distinguish between them. It's the IT team, quietly, that has to.
The question nobody answered on camera
Later, Biehl lists three open questions in a row — can the agents reach the data they need, how do you enforce governance across the system — and then, almost as an aside, a third: "who owns it?" He doesn't answer it. The conversation moves on. It's the most consequential of the three, because a governance diagram can't resolve it.
An LLM gateway, an MCP gateway, an A2A gateway are technical control points. Someone still has to own the policy enforced at each one — who decides what an agent in finance can touch, who's accountable when an agent does the "inventive" thing Biehl describes, works around a guardrail it wasn't meant to find a way past. That's not a gateway configuration. That's a governance owner with actual authority, and the mandate that started this rarely names who that is.
Where this lands for a Business Driver
For whoever owns the mandate's outcome, not its technical implementation — the CEO, COO, or Head of Professional Services accountable to a board that wants "an agentic enterprise" — an internal pilot succeeding is evidence the low-risk version works, not that the customer-facing version is close. Before the next round of investment, someone needs to be named as the answer to "who owns it": not a title on an org chart, a person with actual authority to say no.
Funding the next agentic AI pilot without anyone named as the answer to "who owns it"?
A working internal prototype is evidence the low-risk version works — not that the customer-facing version is close. Naming an owner with real authority is the first deliverable, before the next round of investment.