NextFin News - Guillermo Rauch says the AI industry has already moved past the “build anything” phase and into a harder one: deciding how agents should be controlled once they reach production. In a recent interview tied to Vercel’s ShipNYC conference, the Vercel chief argued that the central problem is no longer model capability alone, but the control layer around it — the permissions, logs, sandboxes, and policy gates that separate a useful agent from a risky one.
His view comes with real scale behind it. Vercel says it now handles 6 million deployments a day, with half of them triggered by coding agents, and more than 1 trillion tokens flow through its AI gateway daily. That makes Vercel a useful lens on where the market is heading: agents are no longer just a research concept or a demo layer. They are generating production traffic, touching real systems, and forcing companies to decide how much autonomy they are willing to tolerate.
Rauch’s core point is that the industry is splitting into two distinct questions. The first is how capable the model is. The second is how safely the agent can act on that capability. That distinction matters because an agent that writes code, calls tools, and reaches into enterprise data creates a different set of risks than a chatbot that only answers questions. Once software can act on its own, companies need to know exactly what it accessed, what it changed, and what it tried to send outside the sandbox.
The result is a shift from experimentation to operations. Rauch said last year was the era of prototypes, when teams tried to “unleash the agents” and see what happened. This year is about production realities. The question is no longer whether autonomous workflows are possible. It is whether they can be governed well enough to survive contact with enterprise security, compliance, and reliability requirements.
That is why the current contest around agents looks less like a model race and more like a platform race. The firms that win may not be the ones with the flashiest model demos. They may be the ones that can make agent behavior observable, auditable, and policy-aware at scale.
Vercel’s Numbers Show How Fast Agents Are Entering Production
The headline figures from Vercel are important because they show that agent traffic is already large enough to matter operationally. Six million deployments a day is not a pilot program. It is industrial throughput. And if half of those deployments are now triggered by coding agents, then machine-generated software creation is no longer an edge case inside the company’s ecosystem.
That matters for the broader AI stack because coding agents are one of the clearest commercial use cases. They can produce code, accelerate engineering output, and raise the volume of software flowing through deployment pipelines. But they also increase the amount of machine activity that has to be inspected, tested, and secured before it reaches production.
Rauch described coding agents and internal agents as the two “killer apps” of the category. The first writes software. The second helps run the company. The second is the more sensitive one, because internal agents are the ones most likely to encounter proprietary code, confidential business data, and operational systems that cannot be exposed casually.
That is where Vercel’s gateway framing becomes useful. If more than 1 trillion tokens move through a company’s AI gateway every day, the gateway is no longer a thin technical wrapper. It is a major control point. It becomes the place where enterprises decide which prompts are allowed, which tools can be invoked, which outputs can leave the environment, and which actions must be blocked or reviewed.
“How do you get a trail of all of the tool calls and access controls that the agent had to incur in order to get a job done?”
That question is the operational heart of the agent debate. A model can be brilliant and still be unusable if a security team cannot trace its behavior. A platform can be less glamorous and still win if it gives companies the evidence they need to trust automation.
The Real Fight Is Over the Control Plane, Not Just the Model
Rauch’s comments point to an important shift in how AI products are being judged. Early conversations were dominated by benchmark scores, model size, and raw capability. The newer conversation is about what happens after the model responds. Once the system begins taking actions, the value of the surrounding infrastructure rises sharply.
That is why the “split” Rauch talks about matters. The model can supply intelligence, but the agent needs policy. The model can generate a plan, but the enterprise needs a record. The model can suggest actions, but the organization needs permissioning, sandboxing, and audit trails before any action becomes real.
His second quote captures that balance directly:
“It can have the freedom still to do to express its intelligence, but then you can apply policy on what data it can access and what data can leave the sandbox.”
In practical terms, that means the next phase of AI infrastructure will be judged on whether it can preserve usefulness while limiting exposure. Too much openness and companies fear data loss. Too much restriction and agents stop being useful. The winning platform, in Rauch’s view, is the one that can thread that needle.
That also explains why platform companies are increasingly adjacent to the major model labs rather than merely downstream from them. Labs own the model layer. Platforms own the execution layer. As agents become more common in production, the execution layer gains leverage because it is where the enterprise actually experiences risk, compliance, and control.
For Vercel, that is a strategic opportunity. The company’s core business has always been about making deployment simpler. In the agent era, that same simplicity becomes a way to sell governance. If an enterprise can deploy an agent, trace its behavior, and constrain its access in one place, it is more likely to trust the workflow enough to scale it.
What This Means for the Next Phase of AI Adoption
Rauch’s comments suggest that the market is entering a more mature stage of AI adoption. The first wave was about curiosity and speed. The next wave is about process, oversight, and repeatability. That tends to favor companies that can sell not just intelligence, but control, observability, and policy enforcement.
It also changes the way enterprises are likely to buy. Instead of asking only which model is strongest, buyers will ask which system lets them manage identities, permissions, logs, and outputs without stitching together too many separate tools. That is a much more operational question, and it pushes the market toward infrastructure that can sit between the model and the business.
The broader implication is that the most important AI products may increasingly be the ones that are hardest to notice. They will not always be the consumer-facing chat products or the most dramatic demos. They will be the gateways, sandboxes, and audit layers that make autonomous software safe enough for real work.
Rauch’s argument is ultimately a sober one: AI is becoming more powerful, but power is not the same as deployability. The companies that can separate intelligence from action — and then tightly govern the space between them — may define the next phase of the market. The ones that cannot may end up with impressive models that enterprises still will not trust.
Explore more exclusive insights at nextfin.ai.
