control ai agent stack

As enterprises accelerate adoption of AI agents, Cohere is warning that unmanaged agent stacks introduce serious risks spanning security gaps, unintended autonomous actions, and compliance failures. The company’s position reflects a broader concern that most organizations are deploying AI agents without adequate control over the full technology stack driving those systems.

The full AI agent stack includes foundation models, orchestration frameworks, external tools, enterprise data sources, infrastructure, and governance controls. Foundation models serve as decision-making engines, while an orchestration layer manages tool planning, multi-step workflows, and response generation. A tool layer extends beyond retrieval-augmented generation to support read and write operations across enterprise applications. Governance and access-control mechanisms sit across all of these layers, defining roles, permissions, and information-sharing rules for agents operating throughout an organization.

The AI agent stack spans foundation models, orchestration, tools, data, and governance — each layer essential to enterprise control.

When enterprises fail to manage this stack cohesively, the consequences are significant. Fragmented control across models, tools, and data sources creates gaps in security, auditability, and compliance. Unmonitored agent autonomy increases the risk of unintended actions, data exfiltration, and policy violations in production environments. Without method-level access control to AI APIs, agents can become over-permissioned, expanding the attack surface for adversarial exploitation.

Insufficient observability across agent workflows also hampers incident response and failure analysis. Vendor lock-in becomes an additional concern when enterprises cede strategic control over core stack components to external providers.

To address these risks, Cohere has developed what it describes as an agent foundry called Cohere North, designed to support the creation of agents and automations for enterprise use cases. The platform includes an underlying governance layer that allows organizations to define roles and access controls for agents interacting with organizational data. The system specifies which information agents can access, use, and share, and guarantees that access rules cascade appropriately through agent configurations.

Governance mechanisms are embedded directly into the agent-building workflow, positioning safety and control as design-time requirements rather than post-deployment considerations.

Safety testing at Cohere operates on two levels. The company conducts in-house safety evaluations at the modeling level to assess foundation model behavior across diverse scenarios. It also performs system-level testing to evaluate end-to-end agent behavior, tool interactions, and governance effectiveness.

This dual-layer approach reflects recognition that risks arise both from model capabilities and from how models integrate with external tools and data. Safety protocols are designed to detect harmful, non-compliant, or policy-violating outputs before agents reach large-scale deployment. The Cohere API supports chat, embed, and rerank endpoints across v1 and v2 versions, giving enterprises programmatic access to the core model capabilities that underpin agent workflows.

Cohere’s broader message to enterprises is that control over the AI agent stack cannot be treated as secondary. As agents take on more complex, autonomous tasks within organizations, the absence of structured governance, access controls, and multi-layer safety testing creates compounding risk that grows with each new deployment and integration point.

You May Also Like

Meta Launches Muse Spark 1.1 and Its First Paid AI Model API

Introducing Meta’s most capable AI yet, Muse Spark 1.1 promises to reshape enterprise automation—but the real story lies in what comes next.

Gartner Predicts Autonomous AI Will Handle 25% of IT Operations Work by 2030

Curious about how autonomous AI will reshape IT operations by 2030, handling a quarter of all work—discover what this means for your team.