Enterprise AI’s Biggest Risk Is Agent Chain Complexity
Gravitee CEO Rory Blundell argues enterprise AI risks come from tangled agent chains, weak ownership, permission creep and absent real-time enforcement.
Summary
In a sponsored argument published August 27, 2026, Gravitee CEO Rory Blundell says enterprise AI’s central risk is not autonomous agents individually, but fleets calling APIs, other agents and applications never designed for machine decision makers. A second agent adds one connection, while a tenth can create dozens of possible paths and cascading calls. A support ticket may cross four agents before human review, creating unapproved decision points. A ticket summarizer granted broad API access can reach the payments system six months later, while ownership becomes unclear when five agents share a workflow and step four fails.
Blundell proposes giving every agent a unique identity, scoped authority and named human sponsor, then tracing actions and downstream effects across the entire chain in real time. Quarterly reports and after-the-fact monitoring are insufficient: finding an out-of-scope call during a review three weeks later, or showing a breach five minutes after it happened, cannot replace enforcement that blocks the call before execution. He argues enterprises need both visibility and preventive control to achieve “Human-Agent Harmony,” where autonomy and accountability scale together. Without them, 100 agents acting as designed can interact in combinations nobody planned, keeping enterprise AI trapped in pilots instead of production.
Positives
- A unique identity, scoped authority and named human sponsor would make each agent independently accountable.
- Real-time chain tracing would reveal what an agent triggered downstream and where the action ended.
- Pre-execution enforcement could block out-of-policy API calls instead of merely recording completed breaches.
- Human-Agent Harmony would let enterprises expand agent fleets without trading accountability for scale.
Risks & concerns
- A tenth agent can create dozens of possible interaction paths rather than merely ten connections.
- One support ticket may pass through four agents before human review, multiplying unapproved decision points.
- Six months after receiving broad API access, a ticket summarizer may gain a path into the payments system.
- Five agents touching one workflow can leave nobody accountable when the fourth step fails.
- Quarterly reports, three-week reviews and alerts arriving five minutes late provide monitoring without preventive control.
- One hundred agents behaving as designed can still interact in unplanned combinations that keep deployments stuck in pilots.