NextFin

Blundell Says AI Must Put Governance, Security, and Control First

Summarized by NextFin AI
  • Gravitee CEO Rory Blundell argued that as AI moves deeper into enterprise workflows, governance, security, and control are becoming as important as model quality and speed.
  • The core enterprise hurdle is shifting from whether AI can generate answers to whether it can act safely within policy, with permissions, audit trails, and shutdown mechanisms required for production use.
  • The article frames AI governance as a structural part of the enterprise AI stack, because greater autonomy increases the need for authorization, monitoring, accountability, and enforceable controls.
  • A credible counter-view is that governance tools could remain niche if firms keep AI in low-risk, read-only use cases; however, broader operational deployment would make control layers commercially important.

NextFin News - The message from Gravitee CEO and co-founder Rory Blundell was straightforward: as AI tools move deeper into business workflows, companies must focus on governance, security, and control. Bloomberg’s Aug. 7, 2026 video interview with Blundell on Bloomberg Brief framed the discussion around that point, underscoring how the AI conversation is widening beyond model quality and speed to the rules that govern what systems can do.

That shift matters because the commercial value of AI depends less on isolated demonstrations and more on whether enterprises can safely let the technology touch internal systems. Once an AI tool is connected to data, applications, and user permissions, the question changes from "Can it generate an answer?" to "Can it act without breaking policy?" The result is a more demanding buying process, where security teams, compliance officers, and operators all have to agree before AI is allowed to move from pilot projects into production workflows.

Bloomberg’s page on the interview says Blundell joined Vonnie Quinn to discuss "the importance of governance, security, and control in the rapidly evolving AI landscape." That wording is notable because it captures the current pivot in enterprise AI: the issue is no longer simply adoption, but safe adoption at scale. The more autonomous AI becomes, the more a company needs a way to approve actions, trace them, and stop them if they go wrong.

The company context reinforces that message. Gravitee has positioned itself around API and platform control, which places it close to the layer of enterprise software that decides who and what can interact with systems. That is where AI governance becomes practical instead of abstract. It is one thing to talk about responsible AI in the abstract; it is another to design a mechanism that prevents a model or agent from acting outside policy, reaching the wrong data, or making changes it should not do.

Blundell’s framing also highlights why governance is becoming part of the core AI stack rather than a side conversation for legal teams. In earlier phases of the AI boom, the market focused on chips, cloud capacity, and model performance. Those are still important, but they do not solve the problem of trust inside the enterprise. A company that cannot explain what an AI system did, or limit what it can do, will struggle to expand its use beyond low-risk tasks. That puts governance, security, and control in the center of the deployment conversation.

Why The Control Layer Is Becoming More Important

The strongest reading of Blundell’s remarks is structural. AI governance is not a temporary response to one incident or one headline. It is an architectural requirement that grows as the technology becomes more capable and more embedded in business operations. A tool that produces text or summaries can be reviewed by a human. An agent that can interact with enterprise systems needs permissioning, logging, and oversight built into the workflow itself.

That is the key mechanism. The more useful AI becomes, the more companies will want it to take actions on their behalf. But action requires authorization, and authorization requires control. That is why governance is moving from policy language into software design. The control problem is not hypothetical: once an AI tool is connected to sensitive data or operational systems, the business must be able to define what is allowed, prove what happened, and shut it down if necessary.

Blundell’s emphasis on accountability fits that logic. In a separate company statement, he said:

"You wouldn't let a person act inside your company without a mechanism for accountability in place," said Rory Blundell, CEO of Gravitee.
The comparison is blunt, but it gets to the heart of the issue. A company would not hand unrestricted authority to a human employee without access controls, audit trails, and supervision. AI agents are now moving toward similar levels of operational reach, which makes governance a prerequisite rather than a luxury.

This is also where the AI debate becomes more than a question of adoption speed. If the first phase of the cycle was about getting access to models, the next phase is about deciding which systems those models can touch. That is a harder problem. Access can be granted quickly. Control must be designed carefully. The enterprise buyer is therefore not just evaluating performance; it is evaluating risk, accountability, and the ability to limit the blast radius of an error.

The cyclical-versus-structural call here is clear. The short-term attention on AI governance is cyclical, driven by the current wave of AI rollout and enterprise experimentation. The need itself is structural, because every new layer of autonomy increases the value of permissions, monitoring, and enforcement. That means the theme may ebb and flow with AI hype, but the underlying demand for control will not disappear unless AI adoption retreats dramatically.

The Counter-View: Why This Could Stay A Niche

The strongest counter-thesis is that governance spending may remain confined to a narrow set of regulated industries. In that view, most companies will limit AI to low-risk, read-only tasks, while only banks, healthcare firms, and large enterprises with complex data environments will need deep control layers. If that happens, governance becomes an important feature of enterprise software, but not a large standalone market.

That argument is credible because not every AI project needs the same level of oversight. A tool that helps draft internal notes does not require the same permissions as one that can update records, trigger workflows, or query sensitive systems. Many organizations will start small precisely because they want to avoid a governance burden before the business case is proven. That would keep the early market for AI control tools narrower than the rhetoric around AI agents suggests.

But the limitation in that view is that it assumes AI remains mostly advisory. The moment AI is allowed to execute tasks, the control requirement expands quickly. Enterprise systems are not built around trust alone; they are built around enforceable rules. If AI moves from suggesting actions to taking them, then policy enforcement, auditability, and revocation become basic operating requirements. The counter-thesis would be proven right if enterprise AI stays stuck in low-risk, human-reviewed use cases and never moves into production workflows that require real authority.

That is the falsifying signal: if, over time, buyers keep AI isolated to read-only use and refuse to connect it to operational systems, the governance layer will remain ancillary. If that happens, Blundell’s warning will still be correct as a principle, but less important as a commercial thesis.

What The Message Means For The Next Phase Of AI

In the short term, the implication is mostly about how companies talk about AI procurement. The buying process is becoming more disciplined. Enterprises now need a story not just for model output, but for policy enforcement, identity control, and incident response. That changes who sits in the room when AI is approved for broader use.

Over the medium term, the message points to a broader shift in software architecture. AI is moving from a feature to a capability embedded inside business systems. Once that happens, the control plane becomes a permanent part of the stack. Companies that supply the software layer for permissions, oversight, and governance are likely to remain relevant even as the front-end AI products change quickly.

Over the longer term, the question is whether AI becomes trusted enough to be used like any other enterprise utility. If it does, governance will not be an edge concern. It will be part of the operating foundation. If it does not, AI adoption will remain concentrated in low-risk tasks, and the gap between experimentation and real deployment will stay wide.

The base case is that governance becomes more important as AI usage broadens. The upside case is that a high-profile incident or tougher regulatory scrutiny accelerates adoption of control tooling. The downside case is that companies decide the risk is not worth it and keep AI boxed into limited use cases. The key watchpoint is simple: whether enterprises start insisting on enforceable controls before they let AI act on their behalf.

Blundell’s point is not that AI is losing momentum. It is that the market is underestimating the price of trust. The next phase of AI growth will belong to the systems that can make autonomy safe.

Explore more exclusive insights at nextfin.ai.

Insights

Why is governance becoming a core part of enterprise AI instead of a side issue for legal teams?

How does AI change from answering questions to taking actions inside business systems?

What technical controls do companies need before letting AI access internal data and applications?

Why are permissioning, logging, and oversight becoming essential for AI agents?

How is the enterprise buying process changing as AI tools move from pilots to production?

What role do security teams, compliance officers, and operators now play in AI adoption?

Why does Blundell argue that trust matters as much as model quality and speed?

How does Gravitee's focus on API and platform control relate to AI governance?

What recent shift in the AI market is pushing governance, security, and control into the spotlight?

What would make AI governance a large market instead of a niche feature for regulated industries?

Why might some companies keep AI limited to low-risk, read-only tasks?

What signals would show that enterprise AI is not moving into real operational workflows?

How could tighter regulation or a major AI incident affect demand for control tools?

What are the main risks if a company cannot explain or limit what its AI system did?

How does the need for AI accountability compare with the controls placed on human employees?

What could the long-term software stack look like if AI becomes a trusted enterprise utility?

Search
NextFinNextFin
NextFin.Al
No Noise, only Signal.
Open App