Enterprise AI is moving quickly from systems that generate answers to systems that can take action. That shift raises a much harder question for companies: how do you control what autonomous AI is actually allowed to do in real time?
I recently spoke with Manoj Saxena, Founder and CEO of Trustwise, about why he believes traditional AI governance is no longer enough for the agentic era. Trustwise is building what it calls an AI Control Plane, designed to govern AI execution at runtime rather than simply monitor what happened after the fact.
In our conversation, we discussed Trust Posture Management, the risks that emerge as agents gain more authority, why observability alone is not enough, and what it will take for enterprises to move autonomous AI out of pilots and into production safely.
Trust posture management isn’t a term most people have heard yet. Walk me through the specific moment that made you realize the existing vocabulary, governance, compliance, and safety wasn’t cutting it anymore.
The breakthrough moment came when enterprise AI crossed a structural boundary: moving from returning text to taking autonomous action. Chatbots converse; agents execute. A chatbot gives a wrong answer; an agent takes the wrong action.
When an AI system moves from an advisor summarizing a PDF to an authorized actor invoking APIs, updating CRM databases, or executing financial transactions, the entire risk calculus changes. Existing approaches fall short because policies often live on paper, guardrails filter text inputs and outputs, and observability records logs after the event. None answer the question that matters at the exact millisecond of execution: should this action be allowed right now?
When you see an autonomous agent given authority to alter enterprise state, or even physical infrastructure like data-center cooling settings, you realize autonomy without runtime control is undeployable. That realization is why we defined Trust Posture Management, or TPM: continuously determining what AI is allowed to do, controlling what it actually does, and proving what happened while the system is operating.
Give me a plain definition of Trustwise.
Trustwise is the AI Control Plane for enterprise AI. It controls runtime execution, discovers value, and proves outcomes across enterprise AI systems, from single agents to multi-agent fleets. It ensures each AI workload runs on the best admissible AI chain, meeting enterprise requirements for security, reliability, and policy compliance while continuously optimizing cost and performance.
We call this Trust Posture Management, the continuous control, discovery, and proof layer for AI behavior, serving as the system of record for what AI is allowed to do and evidence that it stayed within bounds. Just as Wiz defined Cloud Security Posture Management for cloud infrastructure, Trustwise defines Trust Posture Management for agent infrastructure.
What does inline runtime enforcement actually look like inside a live system?
Architecturally, the Trustwise AI Control Plane sits directly in the execution path between enterprise AI systems and the tools, data, models, workflows, and systems they can affect. When an agent proposes a consequential action, such as calling a SQL database, invoking a third-party API, or executing a refund, the Trustwise AI Control Plane evaluates it before execution against enterprise policy, authority, risk, and approved operating boundaries.
The decision is assessed across progressively narrowing authority levels, ensuring each AI action stays within approved enterprise boundaries before it is allowed to proceed.
Trustwise then deterministically applies the appropriate runtime intervention: allow, block, modify, escalate, require approval, degrade, quarantine, or suspend. Every decision produces a reproducible, audit-grade record linking intent, authority, policy basis, intervention, execution path, and outcome. For high-throughput applications, evaluation occurs inline with 10–300ms response latency.
Most AI governance tools ship policy documents. Trustwise enforces in real time. What’s the technical or business reason that the gap exists in the market right now?
Technically, traditional GRC platforms and observability tools were designed for static software or post-hoc monitoring. They inspect systems before deployment or analyze telemetry after execution. But autonomous agents dynamically interpret context, chain tools, delegate work, and adapt mid-task. Reading a log after an agent modifies a database doesn’t prevent the damage.
The architectural mistake is assuming probabilistic AI behavior can be safely controlled only through more probabilistic interpretation. Enterprise control itself has to be deterministic.
Foundation-model vendors like OpenAI, Anthropic, or Google understandably build safety mechanisms around their own models. But enterprise AI is multi-model, multi-agent, multi-vendor, and multi-cloud. Model providers build increasingly powerful engines. Enterprises still need an independent control plane deciding which model, toolchain, and execution path may be used for this workload, under these conditions, at this moment.
Without naming the client, tell me about one company that adopted Trustwise, what specifically worried them before, and what changed after.
A major Tier-1 US retail bank is developing an agentic commerce experience in which AI can move from a customer request such as “find the best laptop under $1,200 and buy it” through product search, merchant selection, checkout, payment, fraud checks, approval, and fulfillment.
The challenge is that a single customer intent can create multiple possible execution chains across agents, models, merchants, payment processors, and tools. Some may be cheaper or faster but fail enterprise requirements around approved merchants, protected payment data, customer authority, fraud controls, jurisdiction, or human approval.
With the Trustwise AI Control Plane in the execution path, the bank can evaluate those candidate chains before execution, eliminate any that fail hard enterprise gates, and select the best admissible AI chain—meeting security, reliability, authority, and policy requirements while optimizing cost and performance.
Trustwise then controls each consequential action as the chain executes. If a merchant changes the price after approval, raw payment data is exposed, or an agent attempts to route protected data to an unauthorized model, the system can block, modify, substitute, or require renewed approval before the action reaches the enterprise. Every decision produces verifiable evidence from the original customer intent through the final outcome.
Parts of this control architecture are already operating in production across the bank’s AI environment, with additional Commerce Agent capabilities and broader chain-level controls now being added as the system expands.
What’s a number or data point that surprised you?
What surprised me was how much AI cost is actually a control problem and not a model routing problem.
Across enterprise deployments, we have seen AI operating-cost reductions ranging from roughly 40% to more than 80% by eliminating unnecessary retries and loops, reducing context and model overuse, and selecting more efficient execution paths without relaxing safety or policy requirements.
The important lesson is that trust and economics are not opposing objectives. Once enterprise requirements become hard admissibility gates, Trustwise can optimize aggressively for cost and performance inside that safe operating envelope.
What’s the most common thing a company gets wrong about AI trust before they talk to you, something you find yourself correcting in nearly every first conversation?
The most common misconception is confusing testing with control and observability with runtime control.
Companies assume that if they red-team a model before deployment or put a text guardrail on prompts, the system is safe. Testing tells you what might happen under particular conditions. Observability tells you what did happen after the event. Runtime control determines what is allowed to happen while the system is operating.
A secondary misconception is viewing shadow AI primarily as a discovery problem—tracking who’s using ChatGPT. In the agentic era, shadow AI is a shadow-authority problem: unvetted authority granted to autonomous systems through tools, data access, delegation rights, spending limits, and enterprise applications.
If I asked you a year ago what enterprise AI trust would look like in 2026 or 2027, how far off would you have been?
A year ago, much of the industry assumed trust would be solved natively at the model layer—that as foundation models grew larger and smarter, they’d automatically become safer.
What surprised many was how quickly the agent explosion occurred. Autonomous task durations moved from single-turn interactions toward long-running workflows involving dozens of models, APIs, and tools.
Smarter AI does not automatically mean safer AI. As intelligence rises, enterprises grant AI more authority, and authority expands the consequence surface. Trust is ultimately an architectural control problem, not a model-scaling parameter. Probabilistic intelligence requires deterministic control.
Where’s the real risk sitting right now? Is it model behavior, data handling, or something nobody’s talking about yet?
While public attention focuses on prompt injection and hallucinations, the primary operational risk increasingly lies in control integrity and authority drift across execution chains.
In complex environments, Agent A passes work to Agent B, which delegates to Agent C, which invokes an external API or changes a system of record. No single human observes the entire chain. A subtle error or authority violation can propagate downstream into data mutations, unauthorized transactions, or financial loss.
The unit of control is therefore increasingly the execution chain: the models, agents, tools, data, approvals, fallbacks, and infrastructure converting intent into outcome. Enterprises need to determine whether the entire chain is admissible and continuously control consequential steps as context changes.
What would meaningful progress look like for Trustwise over the next 12 months?
A win means establishing Trust Posture Management as a recognized enterprise software category, much as posture management became foundational in cloud security.
Success also means seeing major enterprises move out of pilot purgatory and safely scale autonomous AI across multi-vendor environments, proving that runtime control unlocks both risk reduction and measurable economic value.
And it means the Trustwise AI Control Plane becoming the enterprise system of record for AI runtime decisions: what AI attempted, what the enterprise permitted, what executed, what it cost, and what outcome followed.
Every controlled workload adds to that customer-specific record. Over time, it becomes a proprietary operational evidence base that generic AI wrappers, public datasets, and passive observability platforms cannot recreate because the evidence exists precisely because Trustwise was in the decision path making the control decision. The architectural moat creates the data moat.
You were the first General Manager of IBM Watson and helped build the first commercial cognitive systems, back when trusted AI wasn’t even a category yet. What did those early Watson years teach you about trust that most people building AI today still haven’t learned?
The central lesson from the early cognitive-computing era was simple: demos look like magic, but production is messy.
You could build impressive demos that wowed boardrooms. But when non-deterministic systems encountered complex enterprise environments such as clinical healthcare or tax audits, they struggled without clear operational boundaries and verifiable evidence.
Many AI builders are repeating that pattern today—focusing heavily on impressive intelligence while underestimating the infrastructure required to place hard operational boundaries around probabilistic systems.
The lesson I carried from Watson into Trustwise is simple: intelligence gets AI into the demo; control gets it into production.
Jordan French is the Founder and Executive Editor of Grit Daily Group , encompassing Financial Tech Times, Smartech Daily, Transit Tomorrow, BlockTelegraph, Meditech Today, High Net Worth magazine, Luxury Miami magazine, CEO Official magazine, Luxury LA magazine, and flagship outlet, Grit Daily. The champion of live journalism, Grit Daily’s team hails from ABC, CBS, CNN, Entrepreneur, Fast Company, Forbes, Fox, PopSugar, SF Chronicle, VentureBeat, Verge, Vice, and Vox. An award-winning journalist, he was on the editorial staff at TheStreet.com and a Fast 50 and Inc. 500-ranked entrepreneur with one sale. Formerly an engineer and intellectual-property attorney, his third company, BeeHex, rose to fame for its “3D printed pizza for astronauts” and is now a military contractor. A prolific investor, he’s invested in 50+ early stage startups with 10+ exits through 2023.




