Trust Before Autonomy
Earlier this year, we announced our first patent covering Systems and Methods of Agentic Policy Enforcement. At the time, much of the conversation around enterprise AI centered on model capability. Could large language models reason well enough? Would they hallucinate? Could AI agents become productive members of an enterprise team?
Over the past several months, I’ve noticed those conversations changing.
Today, I rarely hear customers questioning whether AI agents are capable. The pace of innovation has been remarkable. AI agents are investigating security incidents, writing software, interacting with enterprise applications, invoking tools, coordinating with other agents, and performing increasingly sophisticated work with very little human supervision. Whether you’re excited about that future or cautious about it, I think most people have accepted that autonomous systems are going to become an important part of how enterprises operate.
The questions have become much more practical. Organizations aren’t asking whether AI agents can perform useful work anymore. They’re asking where those agents should be trusted to operate, what decisions they should be allowed to make, and how those decisions remain aligned with organizational policy as work becomes increasingly autonomous. I think that’s an important shift because it changes the architectural problem we’re trying to solve.
Traditional enterprise security has largely been built around controlling access. Identity determines who can access a system. Authorization determines whether that identity can perform a particular action. More recently, we’ve seen model gateways, AI proxies, and model brokers emerge to control which models, tools, and services autonomous systems are permitted to use. Those are all important capabilities, and every enterprise deploying AI will need them. They answer questions about identity, access, and connectivity.
Autonomous systems introduce another set of questions.
Unlike traditional software, autonomous systems continuously make decisions while they’re executing. They determine which tools to invoke, what information they need, whether another agent should participate, how work should be delegated, and how execution should adapt as new information becomes available. Traditional software executes logic that developers wrote ahead of time. Autonomous systems determine the next step while they’re running. Once software begins making decisions instead of simply executing instructions, it is no longer sufficient to control what the system can access. The system also has to determine whether each successive action should be allowed given the current task, the current execution context, organizational policy, and everything that has already happened.
That’s a fundamentally different architectural problem.
I think the mistake many people make is assuming governance is something evaluated before autonomous work begins. I don’t think that’s sufficient. As autonomous systems become more capable, governance has to become part of the execution architecture itself.
From the beginning, that’s the problem we’ve been trying to solve.
Our first Agentic Policy Enforcement patent introduced the principle that autonomous actions should be evaluated against organizational policy before they execute. Today, I’m excited to share that the U.S. Patent and Trademark Office has issued a Notice of Allowance for Bricklayer’s second patent in our Agentic Policy Enforcement family.
What’s exciting to me isn’t simply another patent. It’s how our thinking has evolved as autonomous systems have become more capable.
Our first patent introduced the idea that autonomous systems should be governed through runtime policy enforcement rather than relying solely on traditional access controls. Instead of making a one-time authorization decision before work begins, policy becomes an active participant in execution, continuously evaluating autonomous actions against organizational policy.
As we’ve continued building Bricklayer, we’ve learned that governance becomes increasingly important as autonomous systems become more sophisticated. Agents don’t simply invoke tools. They collaborate with one another, delegate work, adapt execution as conditions change, operate across organizational boundaries, and continuously create new information throughout the course of their work.
This continuation expands that architecture significantly. It extends governance beyond evaluating individual execution decisions to governing autonomous execution itself. As autonomous systems collaborate, delegate work, adapt workflows, operate across organizational boundaries, and create new information, governance becomes an active participant in execution rather than a control evaluated before execution begins.
Rather than asking only, “Should this action be allowed?”, we’re now asking the broader architectural question: “How should autonomous work itself be governed while it’s being performed?”
I believe that’s where enterprise AI is heading. As autonomous systems become more sophisticated, governance can no longer be limited to evaluating isolated requests. It has to remain engaged throughout execution, continuously ensuring autonomous work remains aligned with organizational policy as systems collaborate, adapt, and make decisions in real time. Governance becomes part of the execution architecture rather than something evaluated before execution begins.
One realization I’ve come to over the past year is that capability and governance solve two very different problems. Advances in foundation models determine what autonomous systems are technically capable of doing. Governance determines what organizations are actually willing to trust those systems to do inside enterprise environments. As model capability continues to improve, I think trust, not intelligence, becomes the limiting factor for enterprise adoption.
Consider something as straightforward as a security investigation. An autonomous system may retrieve alerts, collect endpoint telemetry, query threat intelligence, invoke security tools, collaborate with other agents, create a ticket, recommend containment, and ultimately execute portions of the response. Identity determines whether that agent can authenticate to those systems. A model gateway may determine which model it uses. Neither determines whether the next action should be allowed based on the current investigation, the organization’s policies, the sensitivity of the information involved, and everything that has already happened during execution.
That’s where policy enforcement becomes essential.
Governance defines the organization’s policies and intent. Policy enforcement continuously applies those policies as autonomous work is being performed, evaluating every action in the context of the work itself rather than treating each decision as an isolated request. As autonomous systems become more dynamic, governance can no longer be a checkpoint. It has to become an active participant in execution.
Every enterprise has business processes that are trusted because they consistently operate within established policy. Security investigations, incident response, software deployment, infrastructure operations, financial approvals, compliance reporting, and countless other operational processes exist because organizations know they’ll execute consistently and predictably. As AI continues to mature, autonomous systems will become capable of participating in many of these processes. Capability alone won’t drive enterprise adoption. Organizations will only delegate trusted business processes to autonomous systems they trust to continuously operate within organizational policy throughout execution.
Since founding Bricklayer, we’ve viewed enterprise autonomous systems through three foundational architectural capabilities: Work, Intelligence, and Governance. Work defines how autonomous systems coordinate to accomplish complex objectives. Intelligence defines how they acquire, apply, and continuously improve organizational expertise. Governance defines the policies, controls, and enforcement mechanisms that ensure autonomous work continuously remains aligned with organizational intent.
Together, these three capabilities establish what we believe is the architectural foundation for enterprise autonomous systems.
I’ve spent a lot of time thinking about what will ultimately determine whether enterprise AI succeeds. I don’t think it’ll be who builds the largest model. I don’t think it’ll be who builds the most autonomous agent. I think it’ll be who builds the architecture that gives organizations enough confidence to trust autonomous systems with increasingly important work.
For me, this continuation isn’t simply another patent. It’s another step toward an architectural model I’ve become increasingly convinced enterprise AI will require. Autonomous systems won’t be trusted because they’re intelligent. They’ll be trusted because every decision they make remains continuously aligned with organizational policy while work is being performed. I believe that’s the foundation enterprises will ultimately require before they delegate their most important work to autonomous systems, and it’s the architectural problem we’ll continue investing in for years to come.


