Where Do We Go?

Back in the day - say 20 years ago - I attended a software testing course at the University. The lecturer used a story about studying an alien lifeform. Let’s assume we encountered a new alien species. The first question for the researcher was this: would you catch the alien, open it up, and look at what it is made of (dissection) or would you observe it in its natural habitat (ethology)?

Naturally, the first option would probably kill the alien and we would lose the option to just observe it. This story kept returning to my mind while contemplating the current state of AI-driven software development and systems. Apparently we still do not fully know how GenAI works internally: how does it work so well?

Luckily, in the case of AI agents, studying them internally does not kill them. But since I am not a data scientist but more like a systems architect, it is more natural for me to focus on the environment, the platform, where these entities should operate.

Culture first > Platform first > Data first > AI first

Engineering discipline is the safety

Some years ago I wrote emphatically about safety being the main driver of DevOps, which, in turn, is about speed to market. For me, DevOps represents first and foremost safety: psychological and technological. Safe failures enable rapid learning, development, and innovation. This same safety is even more needed nowadays and its success lives at the heart of the engineering culture.

Think about the following. An engineer who hits ambiguity slows down, asks a colleague, checks the docs, and might avoid the problem. The machine AI agent hits ambiguity and continues, with confidence, at machine speed. Hallucination is the loud failure. The dangerous one is silent: correct reasoning in subtly wrong context. The agent did its job perfectly. The context it was given was slightly off. Nobody noticed because the output was fluent. Policy people call AI outrunning regulators the pacing problem. The same asymmetry lives inside your platform: the agent outruns the reviewer. Call it the speed asymmetry.

But wait! If we cannot trust non-deterministic AI to handle everything in the system, why should we trust a non-deterministic human engineer? In a sense, we don’t: we have been building platforms and their guardrails for human operators for a while now. What has changed is that AI agents execute at a higher speed than humans. It’s time for zero-trust - it’s time to evolve!

The infrastructure house of cards. Change something below and watch what happens.

AI Governance

AI governance, in the definition we use, is the system of rules, practices, processes and tools that keeps an organisation's use of AI aligned with its strategy, its values, the law and its own ethics. The word to notice is tools. The definition places technology inside governance itself: governance is not only a document, it is also a mechanism. We agree.

Unbounded variance kills predictability. Lack of predictability introduces risks. We at Kanto can be that partner who helps to mitigate those risks. Not only by knowing why to bound agentic actors but also by how: stochastic core, deterministic envelope. Machines can be responsible for verification. They cannot be accountable for it.

If AI governance answers the why via policies, then the AI gateway answers the how via mechanism. And here’s what we do: cost attribution for FinOps, decision provenance for the EU AI Act, routing-by-model-size for energy (and the metering point for whoever upstream reports under CSRD), and last but not least, routing for sovereignty: local models or model locality.

Buyers now have to decide whether the control point belongs inside a vendor's security suite or inside an open project no single vendor owns - and the one party you should be listening to is the one who isn't selling either answer: a vendor-neutral architect.

Who guards the guardrails?

If you get the culture right, the platform emerges from shared values and needs. If the platform is right, data flows and is governed properly. If data is well-governed, AI becomes a natural capability rather than a bolted-on experiment. Conway’s Law states that software systems reflect the communication structure of the organisation that builds them.

We argue that the AI platform is not that different from the platform used by humans. The platform has been absorbing non-human actors for twenty years: scripts, cron, CI/CD pipelines with production credentials, Kubernetes operators that take autonomous actions against observed state, autoscalers that make consequential decisions.

But let’s rewind a bit. Why do we even build these systems? Maybe your organisation has valuable competitive information or processes? Maybe sensitive personal data that should be accessed in a secure manner? If this is the case, then why would you give an AI agent your credentials and full access to your data? Not to mention sending that data through someone else's API - under terms they can change, in a jurisdiction you did not choose? The moat transfer is happening. Who or what can you trust?

The main outcome of constraints is creativity. To be clear: wrong constraints make things worse, right constraints create productive boundary conditions. This is why paintings have frames, this is why safety, built by clear communication and guardrails, enables creativity and speed.

Closing the loop

Humans were the first non-deterministic system. Cloud was the second. AI is the third. In the cloud, the invisible thing was cost and carbon. AI did not make either of them visible. It is the same cloud, one API further away: the same kind of data centres, the same carbon, the meter on the other side of the API. Now the invisible thing is token spend, the energy behind it, agent behaviour, and whether any of it is actually producing business value.

FinOps was "who approved this spend." AI governance becomes "who approved this context." Same muscle with higher abstraction. FinOps doesn't fail because the tools are bad or the strategy is wrong. It fails because nobody has Tuesday afternoons blocked for it. It gets eaten by feature work. We’d argue that AI governance could face the same death but with a bigger bill.

As an industry, FinOps went through three waves. The first wave was adoption. The second wave was optimisation. The third wave - the one that actually mattered - was asking which workloads should exist in the first place. The AI industry is currently riding the second wave with token cost optimisation, but we already focus on the third wave.

Our mission has never been about fighting the technology, but instead making better use of it: safely and sustainably. We help to protect your information and energy.

PS. Can you guess the fourth non-deterministic system? It was here before the other three, and it is the reason we are called Kanto.

Next
Next

Taimi - The AI Market Intelligence