Extend Data Governance Into Models, Then Into Agents

Episode Summary

Kevin Petrie leads the data management practice at BARC, and his argument is that AI governance is not a new discipline but an old one with two more domains. Traditional data governance, which he says few companies claim to have mastered, covers quality, privacy and intellectual property. Models add clean predictions and outputs. Agents add behavior, and he cites OpenAI’s finding that reasoning models watched too closely start hiding what they are doing. The control technology companies actually rely on is not a tool: humans in the loop, approving outputs before they go into the wild. On autonomy he is blunt. Not much at this point, and he does not think there should be; most agents, he says, are a new word for copilots. Later he turns prescriptive: a tiger team from the data, AI and developer groups, starting from business pain, and a warning that pilots stall when data that was clean for one department gets dirtier at scale.

Key takeaways

  • The obstacle he names second is people, and he names it twice. A recent BARC survey found that the number two obstacle to success with AI is a lack of AI skills inside the organization, and the responses he sees are retraining workers, hiring, which he says can be expensive if you want the right AI-savvy people, and showcasing use cases and best practices through centers of excellence

  • The argument for data governance is not new, and that is his point. Longstanding data people have been advising executives for decades that data governance needs more investment, he says, and data quality is a longstanding challenge, as are privacy risks, so all the aspects of data governance that really get to trust have not been getting enough attention

  • What AI changes is who is listening. Executives at the CEO and board level are starting to realize that AI can have spectacular problems if you do not double down on the data fundamentals, he says, which makes this a good time for data people to have a renaissance in redoubling and extending their governance programs

  • He does not claim the starting point is solid. Traditional data governance is not a discipline many companies would claim to have mastered at this point, he says, and its traditional risks are data quality, data privacy and protection of intellectual property

  • The extension has two more domains, in order. Organizations need to move from data into the domain of models, working out how to make sure predictions and outputs are clean and safe, and then into a third domain, agents, working out how to make sure an agent’s behavior does not go rogue or have subversive intentions

  • His evidence that agents need a domain of their own comes from model builders. He says OpenAI has been forthright that its reasoning models, if monitored too closely by humans, will start to try to deceive humans and hide what they are doing, and that there are other models out there that will rewrite their own code in order to avoid being shut down

  • The control that technology companies actually use most is not a tool. Looking at software companies whose crown jewels are built on automation and AI, he says the number one control they use for AI governance is humans, human in the loop

  • Who owns AI governance is a partnership, not a transfer. Those programs need to be addressed comprehensively, he says: chief data officers, who he thinks are playing catch-up, partnering with chief AI officers and chief analytics officers so that data engineers and data stewards work with data scientists and machine learning engineers, and with AI-savvy developers once the work becomes agentic

  • There are two routes into building agents and he is even-handed about both. Vendors that understand how daunting agentic AI is, and he names Boomi and Dataiku as BARC clients doing this, offer pre-made templates that let business-oriented rather than technically oriented people put agentic workflows in place. A separate group of specialists builds custom workflows, which he calls higher risk but potentially higher reward because it stitches agents into proprietary workflows and datasets

  • Asked how much autonomy companies are building in, his answer is two sentences long. Not much at this point, and he does not think they should. He adds that the strict definition of an agent is a bot making and acting on decisions independently of humans

  • His most deflationary claim is about the word itself. In most cases those agents are really a new word for copilots or even traditional software, which has been automating workflow for 30 years, he says, and they can and should be going back to humans for approval before making a purchase or closing a transaction

  • The reason he wants caution is compounding, not any single failure. One failure could have a pretty big cascading effect, he says, once multiple agents are transacting with each other autonomously, so companies can and should step cautiously into that realm and work with strict guardrails and carefully defined use cases to start

  • The new capabilities he wants in the data layer use AI to watch AI. Clean inputs are a good start and clean outputs help at the model level, he says, but you can also use AI to monitor what agents are doing, with sentiment indicators or natural language processing to catch potentially toxic output an agent might be putting into place

  • Above the monitoring he wants something deterministic, and he was writing about it at the time. Rules-based checks that will block transactions or actions deemed unsafe, he says, which is a new layer and a new domain: governance of agents. He mentions he is working on a report on that topic right then

  • His answer to what companies should actually build is unglamorous. The goal should be to make incremental changes to existing processes rather than trying to rip and replace, he says, because most Fortune 1000 organizations have had systems in place for a very long time, including mainframes on premises that some are still increasing

  • He puts a number on where the second wave of value is expected to come from. After the efficiency and productivity goal, the next big bucket is still probably half of companies, looking to improve revenue and delight customers in new ways. That second bucket is where he says you want a sandbox project with innovative people, and smart employees vetting any outputs before they go anywhere near customers

  • The first reason pilots stall is that the data changes underneath you. Companies struggle moving from lower-scale to higher-scale production, he says, usually because they had clean data inputs that were good for a given department or data type, and as they go broader the additional data coming in is not as clean and requires real work

  • The second and third reasons are people and money. The people who staff a sandbox project may be younger and carry less baggage, he says, but encouraging the rest of the organization to use AI responsibly can be a real hurdle. Separately, AI inference costs, while they are coming down sharply, could still be a significant surprise cost similar to cloud usage, where you get the surprisingly high bill at the end of the month

  • What drives that cost is consumption. As you go broad and a lot of humans in the organization are consuming AI, he says, token usage costs for each unit of data consumed can drive up costs in surprising ways, and organizations need to figure out how to govern that

  • His example of existential rather than operational risk is a named consultancy. Accenture’s stock is down, he says, because clients are on the margin saying they will ask ChatGPT for pretty rich advice and get pretty solid advice for 20 bucks a month, which defers the need to hire Accenture for some strategic consulting

  • He volunteers a position he expects to be unpopular. He says he is maybe a little controversial in his view that there should be some regulation of model outputs at this point, and cites Grok the week before as a spectacular governance problem, a model on a public social media platform encouraging millions of people to attack and harm an individual

  • Where he thinks advantage actually lives is the third stage. The first stage was knowledge workers using ChatGPT, the second was models inside commercial tools, and the third is applying language models to proprietary data and proprietary processes, which is where he says you uncover real sustainable competitive advantage rather than productivity gains anyone can achieve. The common pattern he sees is a public model with carefully architected retrieval-augmented generation underneath

  • His prescription for getting started is a team and a starting point, in that order. Have the CEO delegate to an executive sponsor just below, a chief data officer, chief AI officer or chief operating officer, and have them build a tiger team of leaders from the data, AI and developer groups. Then start with the business: a line of business or product group identifying what hurts today and where there is too much friction or manual work

  • He tells that team not to assume the answer. They should not rush to say that GenAI is always the answer, he says, because it might not be, it might be traditional machine learning, or it might be other things

  • His two examples of creative reporting lines both move AI out of technology. He was struck that Jamie Dimon at JPMorgan Chase took the head of AI out of tech so that she is head of data and AI, reporting to him and the president rather than to the CIO. The other is Moderna, which promoted its chief HR officer to manage AI and IT, which he reads as figuring out at the executive level how people work with robots

  • The leadership skill he names is not a technology skill. The goal, at the end of the day, is to increase the value that each worker delivers in a given hour, he says, which is why we are better off than our grandparents and they were better off than theirs. He traces the instinct to being an economics minor who taught macroeconomics in graduate school

  • His reality check is a productivity number. In a good year we boost the value of economic output per worker hour by three or four percent, he says, and it actually went down last quarter, so we are in early innings. What may be different this time is speed, because the power of models is going up while the cost of inference comes down

  • His closing answer puts the two obstacles in order. Human skill gaps are the number two obstacle to AI success in BARC’s research, he says, and number one is data quality. His instruction is to invest in your people and help them use AI to augment their work, and he tells young people that AI is an incredible opportunity in data science, so that organizations can double down on the advantages that do not change: human relationships, the power of brands, and the power of trust

About Kevin Petrie

Kevin Petrie is VP of Research at BARC, the research and consulting firm he describes on air as global, where he leads the data management practice across research, consulting and end-user events in Europe and the United States. He writes about AI, data integration and data governance, and BARC’s own team page credits him with roughly 30 years of technology analysis and instruction behind that: he built a data analytics services team for EMC Pivotal across the Americas and EMEA, ran field training at Attunity, now part of Qlik, and has co-authored two books on data management. On this episode he mentions that he was an economics minor and taught macroeconomics to younger students in graduate school, which is where the argument he closes on comes from. He points listeners to two places, his LinkedIn profile and the BARC site, and he spells the company out on air as B-A-R-C.

 

In this episode

00:42 Welcome
01:25 His role: leading the data management practice at BARC
01:42 Data management as what holds the key to AI success
02:12 The business implications, given safe and effective data management
02:29 Why AI deployment asks for cultural change, not just technology
03:11 The number two obstacle to AI success: a lack of AI skills
03:49 Trust with customers, employees and the board
04:07 Fortune 500 brand loyalty at a high, and protecting it
04:56 Mastercard Agent Pay, and playing with the crown jewels
05:20 Decades of arguing that data governance needs more investment
05:42 A renaissance for data people
06:29 Traditional data governance, a discipline few would claim to have mastered
06:47 Extending from data into models, and then into agents
07:10 Reasoning models that deceive, and code rewritten to avoid shutdown
07:34 The number one AI governance control at technology companies is humans
07:56 Employees approving outputs before they go into the wild
08:24 Chief data officers partnering with chief AI officers
08:57 AI-savvy developers, once the work becomes agentic
09:35 Boomi and Dataiku, and templates for business users
10:06 Custom agentic workflows: higher risk, higher reward
10:29 Not much autonomy, and he does not think there should be
10:46 Agents as a new word for copilots
11:31 One failure, and the cascading effect
11:54 Using AI to monitor agents, and catching toxic output
12:19 Rules-based checks that block unsafe actions
12:43 The roundtable model: agents as the interface between systems
13:24 What an agent is for: orchestrating a sequence of tasks
13:59 Mortgage applications, invoice processing, and the drudgery
14:22 Two use cases from the Agents at Work Roundtable
15:07 Enterprises prefer the vendors they already trust
15:31 Incremental change, not rip and replace
16:32 Take the friction out, then the revenue bucket, and vetting before customers
18:16 Innovations take time, and the 1800s
18:36 Data that gets dirtier as you go broad
19:01 The rest of the organization, and inference cost as a surprise bill
19:31 Token costs for each unit of data consumed
19:48 Organizations do not like surprises of any type
19:52 The opposite surprise at the Economics of AI Roundtable
20:43 Unknown unknowns, and how much can really be automated
20:59 Accenture, and clients asking ChatGPT instead
21:40 The case for regulating model outputs
21:58 Grok, and a model directing harm at an individual
22:19 The sycophancy rollback, and models that still need work
22:46 Own your own intelligence, and Paul Baier at GAI Insights
23:30 The three stages of the GenAI boom
24:06 Proprietary data, and where advantage actually comes from
24:40 The public model with retrieval-augmented generation underneath
25:08 An executive sponsor below the CEO, and a tiger team
25:35 Starting with where the business hurts today
25:58 Why GenAI is not always the answer
26:42 Jamie Dimon taking the head of AI out of tech
27:01 Moderna, and HR managing AI and IT
27:58 An economics minor, and the lessons of history
28:22 Value per worker hour, and why we are better off than our grandparents
28:51 Three or four percent in a good year, and the quarter that went down
29:42 Do not get dizzy, take a pragmatic look
30:00 Train people, and data quality as the number one obstacle
30:50 Where to find him: LinkedIn, and the BARC site
31:10 Wrap-up

In Kevin’s words

“If you have smart, vigilant employees who are safeguarding and approving outputs before they go into the wild, that’s the safest way to make sure that you’re not undermining trust with customers and the public.”

— Kevin Petrie   (07:56)

“I think in most cases, those agents are really a new word for copilots or even traditional software, which has been automating workflow for 30 years.”

— Kevin Petrie   (10:46)

“Not much at this point, and I don’t think they should.”

— Kevin Petrie   (10:29)

“This can be a good time for data people to have sort of a renaissance in redoubling and extending their governance programs to address those risks and make sure they have clean inputs for AI models.”

— Kevin Petrie   (05:42)

“Companies can and should step cautiously into that realm and really work with strict guardrails and carefully define use cases to start.”

— Kevin Petrie   (11:31)

“I think there should be some regulation of these model outputs at this point.”

— Kevin Petrie   (21:40)

“That’s where you could uncover real sustainable competitive advantage rather than productivity gains that anyone can achieve.”

— Kevin Petrie   (24:06)

“The goal is to increase the value that each worker delivers in a given hour.”

— Kevin Petrie   (28:22)

“Don’t get too dizzy about the power of what Grok or these other things are handing to you. Take a pragmatic look at your existing business and figure out how to enhance it.”

— Kevin Petrie   (29:42)

“Human skill gaps are identified as the number two obstacle to AI success in our research. Number one is data quality.”

— Kevin Petrie   (30:00)

 

Resources

Kevin Petrie

  • Kevin Petrie on LinkedIn: His profile, and the first thing he offers when asked where listeners should go. He says he is pretty active there promoting BARC research and engaging with their user community to unpack trends

  • BARC: Where BARC publishes its research. He spells it out on air as B-A-R-C and describes it as a global research and consulting firm

The agent governance work he mentions at 12:19

Also from BARC

  • Lessons from the Leading Edge: Successful Delivery of AI/GenAI: BARC research published 3 December 2025, across 421 organizations, which found data quality the top obstacle for 44 percent, having been a secondary concern the year before. It is later than this conversation and it puts a figure on the ranking he gives at 30:00

Ideas and terms discussed

  • The three domains of AI governance: His organizing idea, and the spine of the episode. Traditional data governance covers data quality, privacy and intellectual property, and he says few companies would claim to have mastered even that. Models are the second domain: making sure predictions and outputs are clean and safe. Agents are the third and newest: making sure behavior does not go rogue or turn subversive. The prescription is extension rather than replacement, which is why it starts from the program data teams already run rather than from a blank page, and why he wants it run jointly with the AI and developer groups rather than by any one of them

  • Human in the loop: The control he says technology companies actually rely on most, and the answer to what you use when the model layer cannot be trusted. Looking at software companies whose crown jewels are automation and AI, he says the number one control they use for AI governance is humans. His version of it is specific: smart, vigilant employees safeguarding and approving outputs before they go into the wild, and agents going back to humans for approval before making a purchase or closing a transaction

  • Agents as a new word for copilots: His deflationary read on the category. The strict definition of an agent is a bot that makes and acts on decisions independently of humans, but in most cases, he says, what is being shipped is a new word for copilots or for traditional software that has been automating workflow for 30 years. He is not dismissive of the ambition, only of the labeling and of the pace

  • Governance of agents as a new layer: What he wants in the data layer specifically, beyond clean inputs and clean outputs. AI monitoring what agents do, sentiment indicators or natural language processing to catch toxic output, and rules-based checks that block transactions or actions deemed unsafe. Deterministic blocks and probabilistic monitoring, doing different jobs

  • The beachhead: His word for how to start without betting the business. Layer new incremental intelligence onto the parts of your existing data architecture that work, create a beachhead of something new, prove it at limited scale, then expand. The counterexample he names is rip and replace, which he advises against, because most Fortune 1000 companies have had their systems in place for a very long time and a lot of the old stuff, mainframes included, does not go away

  • The tiger team: The structure he advises. The chief executive delegates to a sponsor just below, a chief data officer, chief AI officer or chief operating officer, who builds a team from three groups: data engineering leaders, data science and AI leaders, and developers. It then works with a specific line of business, region or product group, and it starts from what hurts today rather than from the technology

  • The three stages of the GenAI boom: His map of where competitive advantage is and is not. Stage one is knowledge workers using ChatGPT. Stage two is models arriving inside commercial tools. Stage three is applying language models to proprietary data and proprietary processes, and it is the only stage that produces advantage another company cannot simply buy. The pattern he sees doing it safely is a public model with carefully architected retrieval-augmented generation underneath

  • Token cost as the next surprise bill: His third reason pilots stall, and the one framed as finance rather than technology. Inference costs are falling sharply, but consumption scales with the number of humans using AI and with each unit of data consumed, so the total can behave like a cloud bill: correct, unbudgeted and delivered at the end of the month

  • Value per worker hour: What he anchors executives to when the technology gets dizzying, and the reason he reaches for economics rather than technology history. The goal is to increase the value each worker delivers in a given hour, which is why each generation has been better off than the one before. Against that measure he puts three or four percent in a good year, and a decline in the quarter before the recording, as evidence of early innings

Named on air

  • Mastercard Agent Pay: His example of a company with a great deal of customer trust taking a bold step anyway: an offering that helps customers shop, weigh options, decide and even process transactions. He calls that playing with the crown jewels and says it will be interesting to see how it pans out. Mastercard announced Agent Pay in April 2025, a few months before this conversation

  • OpenAI: Named twice, both times as a source of evidence rather than a recommendation. He says OpenAI has been forthright that its reasoning models, monitored too closely, start trying to deceive humans and hide what they are doing, and separately that OpenAI had to roll back a version update for being too sycophantic and thereby reinforcing user bias. Both are public: the chain-of-thought monitoring finding was published in March 2025 and the GPT-4o rollback was in April 2025

  • Models that rewrite their own code to avoid shutdown: He says there are other models out there that do this, without naming one or a source. The best-documented case at the time was published by Palisade Research in May 2025 and concerned OpenAI’s own o3, so the strongest example is not a different vendor’s model

  • Grok: His example of a governance failure at scale, from the week before the recording: a model on a public social media platform encouraging millions of people to attack and harm an individual, which he says was potentially caused by adjustments made by Elon Musk himself. He adds that companies planning to put Grok into a customer service workflow should think hard about toxic content

  • Accenture: His example of existential rather than operational risk, and the reasoning is his rather than the company’s: clients on the margin deferring strategic consulting because a subscription chatbot gives them pretty solid advice

  • Boomi and Dataiku: Named as BARC clients helping companies build agentic applications with pre-made templates that business-oriented people can use. Dataiku is also the sponsor of the BARC report linked above

  • SAP and Oracle, Joule and GitHub Copilot: SAP and Oracle as the systems whose structured functional data, for CRM or supply chain, he says is already in pretty good shape to drive agent decisions. Joule inside SAP and GitHub Copilot as his examples of stage two, models arriving inside commercial tools

  • Jamie Dimon and JPMorgan Chase: His first example of a creative reporting line: the head of AI taken out of tech, so that she is head of data and AI reporting to the chief executive and the president rather than to the CIO. He does not name her

  • Moderna: His second example: a chief HR officer promoted to manage AI and IT, which he reads as working out at the executive level how people work with robots. Moderna combined the two functions under its chief people officer, who holds the title Chief People and Digital Technology Officer

  • Paul Baier at GAI Insights: Christina’s reference at 22:46, not his. She credits the phrase own your own intelligence to him, and GAI Insights publishes at this address under his byline

  • The Agents at Work Roundtable: Christina’s reference at 14:22, an AI Realized private executive roundtable. She reports two main use cases from it, connecting existing systems together and relieving toil, and at 12:43 she gives the model she is hearing: agents as the interface between systems such as CRM and ERP, with a governance layer below. He agrees with it

  • The Economics of AI Roundtable: Christina’s reference at 19:52, and the one place in the conversation where her evidence runs the other way from his. She reports a deployment where the inference cost plummeted and the return skyrocketed, which she points out was still a surprise, and that the unpredictability itself is what unnerves executives

 

Frequently Asked Questions

 
 
 
 
 
 
 
 
 
 
 
Previous
Previous

Keep the Data Inside Your Perimeter, and the Agents Too

Next
Next

Start AI Governance With the Outcome, or Waste the Spend