Opinion

Every AI capability now spawns an industry to contain it

In one week this month, CodeRabbit raised $143 million to help firms cope with AI-generated code, Ethyca launched a platform to watch what agents do with company data, and a Benioff-backed startup emerged from stealth to help enterprises deploy the agents they had already bought.

Each is a reasonable business. Together they describe something less flattering, which is an industry shipping capability and selling the cleanup separately.

The pattern, stated plainly

Capability shippedProblem createdProduct sold to fix it
Agents that write code fastMore changes than anyone can reviewRanked, governed code review
Agents that read company dataNo record of what they readReal-time data governance
Agents acting on systemsNo identity or permission modelIdentity for agents
Agents sold to enterprisesNobody can deploy themDeployment roadmaps
Four categories that exist because the first column shipped without the second being solved.

A technology that needs four industries to make it safe to use has not finished being built. It has finished being sold.

None of this is fraud, and none of these companies are doing anything wrong. Several of them are solving genuine problems well. The pattern is the point, not any individual product in it.

Why AI governance tooling keeps appearing

The incentives make it almost inevitable, and they aren’t hidden. A lab that ships a capable agent captures the upside; the cost of managing that agent lands on the customer, months later, in a different budget.

Reliability is the specific gap. Agents remain capable rather than dependable, and every product in that table is selling insurance against the difference.

Some of the gap is genuinely hard. Research this year kept finding that long-horizon agents fail on context management rather than intelligence, which is not a thing a customer can fix by trying harder.

The money follows the same logic. Skan raised $63 million to map how enterprise work actually gets done, and NewCore raised $66 million on the premise that agents are becoming employees and need identities.

Add those up and roughly a quarter of a billion dollars was committed in ten weeks to making a capability safe to operate, by companies that did not build the capability.

The rest is a choice about sequencing. Identity and audit logging are not research problems; they are the sort of thing enterprise software has shipped with for thirty years, and they were left out because leaving them out was faster.

Who pays, and when

The timing of the costs is what makes this durable rather than self-correcting.

A buyer signs for an agent in the first quarter on a capability demonstration. The review capacity, the governance tooling and the deployment work show up over the following year, in operations budgets nobody attributed to the original decision.

So the purchase looks cheap at the point it is approved and expensive at the point it is running, and the two numbers are rarely compared by the same people.

That is the same accounting problem our piece on what an AI feature actually costs works through at the token level, one layer up.

Vendors are not hiding this. They are simply not asked, because the person evaluating the demo is not the person who will staff the review queue.

The honest counter-argument

Every platform shift works this way, and the specialists who arrive afterwards are usually better at the job than the platform would have been.

Cloud computing shipped without cost management, monitoring or security tooling, and produced large companies in all three. Nobody now argues cloud should have waited.

The regulators are making a version of the same accommodation. Four labs agreed a voluntary testing framework at the White House this month, focused on cyberattack capability, which is oversight arriving after deployment rather than before it.

There’s also a real argument that a general capability plus specialist controls beats one vendor trying to own both, since the controls a bank needs and the ones a startup needs are not the same product.

That argument is strongest where the missing piece is genuinely specialised. It’s weakest where the missing piece is an audit log.

And there is a version of this that ends well. Cloud’s remedial layer eventually became standard practice, with the platforms absorbing the basics and specialists keeping the hard parts, which is a reasonable outcome for everyone except the companies acquired along the way.

What it means if you are buying

Price the whole stack, not the agent. The licence is the visible cost, and the governance layer, the review capacity and the deployment work are the rest of it.

Run a narrow pilot with the controls in place from day one, rather than a broad one you retrofit later. Retrofitting oversight onto a live deployment is how the four categories in that table came to exist in the first place.

Insist on knowing what the agent did, not only what it produced. A log of every tool call with its arguments is the single artefact that makes every downstream control possible, and it costs nothing to require up front.

Then ask each vendor what the product does without the surrounding tools, because the answer tells you whether you’re buying a system or a component sold as one. Our four questions are a decent starting script.

It is also worth checking whether the capability you are buying is the one being improved. Model releases arrive every few weeks now, with Google shipping an entry-level model aimed at agents three weeks after the last one, while the reliability problems the remedial layer addresses move considerably slower.

That mismatch is the whole shape of the market. Capability compounds weekly and the controls around it compound annually, and the difference is being sold back to you as a product category.

The signal to watch in AI governance tooling

The signal to watch is whether these categories get absorbed. If model providers start shipping identity, audit and review as standard, the capability finished maturing. If instead the remedial layer keeps raising larger rounds, that is the market telling you the gap is not closing.

Get the daily rundown

One email each weekday with the AI news that matters, every claim linked to its primary source.

Free, one email each weekday, unsubscribe in one click. We never sell or share your address.

Rundowns AI Desk

The Rundowns AI desk covers artificial intelligence research, tools, business and policy. Every factual claim we publish links to the primary source it came from, so readers can check it themselves.

Leave a Reply

Your email address will not be published. Required fields are marked *