As enterprises accelerate their agentic AI ambitions, success will depend less on deploying increasingly sophisticated models and more on establishing the governance, automation and infrastructure needed to run autonomous AI safely at scale.
Speaking to iTNews Asia, Steve Shirkey, Director, AI Platform, Red Hat Asia Pacific and Chip McClelland, Ansible Platform Leader, Red Hat Asia Pacific, both argued that organisations should view agentic AI as an operational and infrastructure challenge rather than simply another AI application. They should start by preparing their environments for autonomous systems that require continuous oversight, secure identities and governed execution.
While interest in agentic AI is growing rapidly, Shirkey believes many organisations are still not operationally prepared to scale it.
He said many enterprises remain trapped in what he described as a "chatbot loop," where AI initiatives struggle to progress beyond conversational assistants into systems capable of delivering measurable business outcomes.
"Some think of agentic AI as an application problem, but it is actually an infrastructure problem inside of a larger operating model challenge," he said.
Rather than locking customers into a single AI framework, he said strategies like Red Hat's "Bring Your Own Agent" (BYOA) enables organisations to build agents using their preferred frameworks while relying on enterprise capabilities to manage identity, observability, lifecycle management and security.
Autonomous AI requires a new governance model
Unlike traditional enterprise systems that authenticate users once before executing predefined workflows, agentic AI operates continuously, making governance a far more dynamic challenge.
Shirkey said AI agents should be treated as Non-Human Identities (NHIs) with their own permissions, accountability and audit trails. "Traditional governance and security controls usually validate and approve an employee just once, but agentic AI introduces autonomous, continuous processing.”
For instance, he noted that Red Hat assigns every agent session a cryptographic identity, enabling its Model Context Protocol (MCP) Gateway to determine what data and tools each agent is authorised to access under zero-trust principles.
As AI agents begin executing real-world tasks, Shirkey said organisations must also prepare for new failure modes, including prompt injection attacks that could manipulate agents into invoking sensitive APIs or performing unauthorised actions.
"The moment you break out of the chatbot loop and give AI the capability to execute real-world, end-to-end tasks, the failure modes change completely," he said.
Rather than relying solely on prompting techniques, he said enterprises should adopt defence-in-depth security, including isolated execution environments that limit the impact of compromised or malfunctioning agents.
Shirkey also believes agentic AI should prompt organisations to redesign business processes rather than simply overlay intelligence onto existing workflows.
He compared today's transition to the industry's move from monolithic applications to microservices, arguing that organisations must first "agent-proof" their APIs, authentication systems and data layers before autonomous agents can safely execute work.
Without unified, real-time visibility across enterprise environments, he warned, autonomous agents introduce unnecessary operational risk instead of efficiency.
Traditional automation remains the enterprise backbone
Despite growing interest in agentic AI, McClelland said traditional automation continues to deliver the greatest value across enterprise IT. He categorised automation into task-based, event-driven and AI-driven modes, with task-based automation still accounting for the majority of enterprise use cases.

Traditional automation continues to outperform agentic approaches particularly in mission-critical environments and regulated industries where trust, consistency and efficiency are key.
- Chip McClelland, Ansible Platform Leader, Red Hat Asia Pacific
Shirkey added that deterministic automation remains the preferred option for repetitive tasks.
"If you need to patch 1,000 servers identically, you want a static script, not a reasoning agent," he said.
Instead, he sees AI agents orchestrating complex workflows while established automation executes governed operational tasks.
Your infrastructure will underpin AI’s success
Rather than model performance, Shirkey believes the differentiator for enterprise AI is becoming what he calls the "agentic substrate", which is the combination of data, orchestration and infrastructure supporting AI execution.
He argued that open models are reducing differentiation at the model layer, making enterprise architecture increasingly important.

Even the most sophisticated model will struggle to deliver business outcomes if it cannot access the right data, understand context, or interact safely with enterprise systems.
- Steve Shirkey, Director, AI Platform, Asia Pacific, Red Hat.
He added that bringing AI models closer to enterprise data within hybrid cloud environments improves governance, lowers latency and reduces costs.
Multi-mode automation needs a common platform
As enterprises combine traditional automation with AI agents, both executives believe organisations will need common platforms and shared governance rather than isolated automation strategies.
McClelland said organisations can avoid fragmented automation strategies by using a common platform that supports task-based, event-driven and AI-driven automation. He said this improves automation reuse while providing AI agents with approved actions and clear security boundaries.
Shirkey added that the shift extends beyond technology. "IT teams are transitioning from being builders of workflows to architects of the agentic substrate," he said.
Rather than focusing solely on writing automation logic, IT teams will increasingly define governance policies, manage non-human identities and establish the security and observability guardrails that allow AI agents to operate safely regardless of the underlying model or framework.
Looking ahead, Shirkey said organisations should prioritise narrow, high-value use cases including developer productivity, incident response and cybersecurity where agentic AI is already demonstrating measurable returns.
At the same time, he urged CIOs to strengthen the underlying governance and infrastructure needed to support broader enterprise adoption. "The best way to escape the chatbot loop is to stop treating AI as an application problem and start treating it as an infrastructure mandate," Shirkey said.
He argued that organisations investing today in secure identity, governance and automation will be better positioned to scale agentic AI as autonomous systems become a core part of enterprise operations.





