Why enterprise software needs a new foundation, not a new feature. 

Eighteen months ago, we started putting Digital Workers into production alongside human operators inside some of the world’s largest industrial companies. This was not a pilot or a demo — a running system, in live operations, in aerospace, defense, heavy materials and manufacturing. Most of the heavily regulated industries, in other words, where getting it wrong is expensive. 

What I want to talk about isn’t the deployment lessons. It’s the higher-order lesson: what the next enterprise software stack actually looks like, and what’s left to defend once you’ve built it. 

Here’s why that second question matters to me: My background is startups – five of them. In every one, the same problem came up: we have 30 people, and the enterprise we’re competing with has 1,000. How do you compete? The answer was always speed, and a very focused area of building. 

Generative AI has taken that game away from me, and from everyone else. The barrier to development is now one. You have 1,000 people. I have 30. My 30 might be much better than your 1,000, because we have far better tools. Haves and have-nots are no longer defined by budget, but learning speed. We’re on an even keel. 

So if you’re running a 10- or 20-year-old organization: where does your moat, your durable competitive advantage, go? 

The iPhone moment in enterprise software 

Start with the moat that’s already gone. For fifty years, the rules lived in the UI. Thirty bespoke applications, ERP, CRM, FSM, approvals, admin, each with its own screens, and every policy quietly welded into them. That arrangement just collapsed, for four reasons.

1. Asking humans to learn bespoke apps is so 2025. 

If you can’t talk to an application, nobody is going to use it. That’s the norm in 2026. 

2. The new users aren’t always human. 

Agents speak API, MCP, A2A and CLI. They do not click. It’s already the first question we’re asked in every deal: are you API compliant, do you have an MCP server, do you have a CLI. 

3. Muscle memory is a tax. 

A generation of workers should not have to learn thirty UIs to do one job. There is no moat left in a better UX. 

4. Adoption is survival. 

This isn’t nice-to-have anymore. Your competitors are getting more advantage because they’re using AI, so you can’t take a pause on it. 

What replaces it is one conversational surface, and the work comes to you rather than you going to the work. You’re in Teams, in Slack, in email, that’s where it should arrive. Fixed UI is dead; ephemeral UI takes its place. Ask for your riskiest POs and the application no longer looks like anything: it answers, cites, charts, and hands you the next action. 

But notice the problem this creates. Every policy that used to live in those screens is now invisible to the entity that matters most – the agent. Which means it no longer governs anything at all. So where do the rules go. 

Four layers take it’s place 

The agentic enterprise stack: author the world, not the screens. 

Infrastructure is a given. Databases, storage, compute, if you don’t have it, you don’t have a product and you don’t have a company, and nobody gives you brownie points for it. 

Intelligence is world knowledge plus your own. Public models are part of it, but they cannot be your differentiating factor, because your competitor can rent the same ones tomorrow. 

The Context Layer is the keystone, and it’s the layer people underestimate. Your organization is not one application, you have a CRM, an ERP, HR systems, engineering systems, each with its own ontology, and somewhere there’s one person who understands how they link together. Writing that down gives you a context graph: entities, tools, relationships, and the business and role-based policies the agent must operate within. 

That is what grounds an agent. It defines the boundary of operation, and therefore what counts as a hallucination and what doesn’t. Get it right and building an agent in any harness becomes easy, Claude, OpenAI, open source, because the domain knowledge is already grounded. 

The Work Orchestration Fabric is where outcomes get produced. Work used to happen in the ERP: read an email, go fill in a form. Now it happens here. 

A new workforce 

On top of that stack sits something genuinely new: a workforce that doesn’t sleep. But you don’t hand it the keys on day one, any more than you would a new hire. 

Digital Workers earn autonomy the way people do, through evals, coaching, and memory that compounds. 

Ambient agents watch, triage and act inside declared boundaries. Assisted means a human in the loop, invited when judgment has to be borrowed, not to click through steps. Autonomous is end-to-end execution within policy: a Digital Worker that is a member of the workforce, not a tool. 

You used to bring an intern in, give them process documents, put them through training, and over time they became an expert. Same journey. It just doesn’t happen on day one. 

So what’s actually left to defend? 

Use the latest, greatest, cheapest public models the day they ship. Rent the world’s intelligence, there’s no advantage in building it yourself. But two things have to stay inside, because together they are your only true moat. 

Contain. Curate. Compound. 

The first is organizational memory. Say a supplier calls me from Greece. A few people in my organization know how to deal with suppliers from Greece. A few others know how to deal with suppliers from Texas. No one person has all of it, and if the agent doesn’t know this, it won’t understand the difference. That difference is your moat. 

Organizational memory is the observable, correctable collective memory of every judgment your employees have ever made: episodic, semantic and process memory, accumulating value with every deployment. As you deploy agents, be very careful about how you capture it, because the next Digital Worker you spawn needs to know every decision your people made in the past. We use vector graphs heavily for this. 

The second is process intelligence. Take Pepsi, take Coke, they differentiate on how efficiently they run their supply chain, and nothing else. Now imagine handing that to an agent. You give it your process documents, you put a human in the loop for exceptions, and over time it becomes an expert. But you’ve also handed all that knowledge to a public model — and not just the process, also the guardrails that prove whether the process was executed right or wrong. You wouldn’t discuss any of it with someone outside your company. 

I’m a cautious person. I wouldn’t do that. So, we use two models: one to run the process, a separate one for evals and guardrails. Is that good enough? Not really. So, we also run a constant process of distillation. Every time a process runs cleanly, we collect the data and fine-tune a smaller model that gets better and better at that one micro-process. Over time you accumulate those micro-processes and combine them into a mixture of experts, a bigger model, specific to your organization, that you can replicate as often as you want. Public models can inform; private memory decides. 

That’s yours to keep. It’s not Anthropic’s. It’s not OpenAI’s. That is your moat. 

Speed is life — and every corner is a blind corner 

“Speed is life.” 

Mark Moffat, CEO, IFS 

Not going fast is not the safer choice. It is the losing one. But at this velocity you can’t see around anything, so you protect the vehicle. Four layers of defense, and every one of them is non-negotiable. 

Defense 01 
LLM security layer 

Run inference behind your perimeter and screen what leaves it, prompt injection, model and data poisoning, PII leakage. Use a small local model so it stays fast; heavy handling on every prompt slows everything down. 

Defense 02 
Observable by default 

Every decision logged, attributable, and traceable to the pattern that drove it. Any platform without this, don’t use it, and not only for security. Without observability you aren’t capturing what you need to fine-tune. 

Defense 03 
Human in the loop 

Escalation for novel situations, low confidence, or any action above a configured risk ceiling. And remember: every exception is a memory sitting in somebody’s head that you’re otherwise not capturing. 

Defense 04 
Governed rollout 

Significant pattern updates reviewed before deployment. No dark launches. No silent regressions. 

And then the computer stops sitting on your desk 

One last thought. Everyone has seen the videos of robots dancing, let’s be serious about it. The robot is the new computer. The difference is that your computer today tells you what decision to make; a robot goes and solves the problem. 

From words, to sight, to action — the wave that closes the loop between decision and deed. 

Things are moving really fast. So, make sure your stack is adapting not just to today’s models, but to a world where the computer is no longer sitting on your desktop. 

The winners of the next decade won’t be the ones who talk about AI. They’ll be the ones whose machines already act on it. It’s coming sooner than you think.