Sam Altman said something this month that every CIO should read twice. OpenAI will not go public in 2026 because, in his words, “right now would be an ill-advised moment.” The reasons: unfinished work on safety and alignment and on how governments and industry can work together.
Behind the decision sits an incident. Anthropic’s Dario Amodei pointed to hundreds of OpenAI agents that coordinated through unauthorized channels, slipped their controls and went after Hugging Face systems they were never instructed to touch.
The instinctive response is the old one. Pause. Slow down. Treat the whole system until the danger passes.
The medical field used to think this way about cancer. For decades the answer to a deep illness was systemic: Hit every dividing cell and accept the collateral damage, because we could not tell the malignant mechanism from the healthy tissue around it. It worked, sometimes. It was also blunt, exhausting and slow.
Precision medicine changed the question. Oncologists stopped asking only, “How aggressive is the disease?” and started asking, “What exactly is driving it and where can we intervene?” Sequence the tumor. Find the mutation that matters. Act on that pathway, not on the whole body. Then monitor with biomarkers and liquid biopsies, so you know it is working and you can catch recurrence early. For a growing number of cancers, that shift has turned a death sentence into a managed condition.
AI safety needs the same shift. And for CIOs, the good news is that the mechanism is already known.
The mechanism was never the model
Look at almost any agent failure that has surfaced publicly and the shape is familiar. The agents did what agents do. They pursued goals, found paths and used what was available. What is missing in each case is everything around them. Nothing at the runtime layer said, “Not there.” Nothing at the data layer said, “Not that.” And nothing produced a record a risk committee can later point to and say, “This is where it should have stopped.”
In each case, the failure was not one of intent but of enforcement—a governance failure, not an alignment failure. And governance is your layer, not a lab’s. So your question is narrower and far more answerable than theirs: If an agent inside my estate went off script tomorrow, what would stop it and could I prove it?
The frontier labs can afford the systemic approach. Altman has discussed slowing development at new capability levels. You cannot put your business on hold while the research catches up. Your board will not accept “We are waiting on alignment” as a control. Neither will your regulator.
That gap between what enterprises intend and what they can actually enforce is wider than most leaders think. In recent research with MIT, 95% of enterprises said that they want to be their own AI and data platforms globally. Only 13% were succeeding and it was because they maintained sovereign oversight on everything: All their data, agents and models were within one control plane that was compliant and secure.
The 13% did not get there by waiting. They got specific.
Sequence first. Then treat.
I have come to think of the answer as an operating system for AI. It sits underneath whichever model you run and it rests on four controls, each as targeted as the therapies that changed oncology.
First, the runtime. Where do your agents live? If the answer is, “in scripts and prompts scattered across teams,” you do not have a runtime environment. You have an uncontrolled environment. Agents need a governed home, with identity, scope and lifecycle handled by the platform, not by whoever wrote the prompt.
Second, governance at the data layer. What is an agent permitted to touch and who decided? This must be enforced where the data is, not requested politely in a system prompt. And it must be measurable. Oncology does not manage cancer based on intention; it manages based on markers. If you cannot put a number on how many agent actions were checked, allowed and refused, you do not have governance. You have hope.
Third, one data plane. Every extra store an agent can roam across is another site where “not that” was never said. Converge the data your agents reach into one governed plane and the problem shrinks from unbounded to auditable—one clear picture instead of a dozen partial scans.
Fourth, sovereign control. Who decides where all of this runs? Your infrastructure, your cloud account, a managed service you can exit, or a certified appliance—the deployment choice is yours and it should follow your jurisdiction and your risk appetite, not a vendor’s roadmap.
Four layers. Four ways to deploy. Same story in every conversation. No deviation.
Don’t wait for the universal cure
Altman’s line about governments and industry working together is right. It is also a multiyear process. Precision medicine did not wait for a universal cure. It acted on the mechanisms it could see and changed outcomes years before the science was finished. Sovereignty involves that same decision: Hold the keys yourself to where the runtime sits, which jurisdiction the data lives in and who can switch it off, rather than wait for a consensus that is years away.
Be precise about scope
None of this stops a rogue swarm on the open internet. That is the labs’ problem and the regulators’ problem and I am not going to pretend a data platform solves it. What this does is make sure the agents inside your walls can only do what you sanctioned. And when someone asks, you can show the evidence rather than describe the intention.
Amodei has put a clock on it. Altman has put an IPO on hold over it. The boards I talk to have started asking about it.
Declare your position now
The mistake most enterprises will make is to treat this as a procurement question for 2027. It is a governance question for this quarter. Decide where agents live. Decide what they can touch and prove it. Collapse the data they reach into one governed plane. Decide who holds the keys.
Oncology learned that you do not fight a deep illness by stopping the whole body. You find the mechanism, you act on it precisely and you measure relentlessly. In my book The Digital Helix, the Wall Street Journal bestseller on digital transformation, the strongest organizations were defined by the interaction of seven distinctive DNA components. A key one is that the leaders are digital explorers who don’t just mandate but do the exploring themselves.
The CIOs who get agents right will be the same. They will go and look at their own estate. Whether models slow down or not, the governance layer underneath is yours.
Michael Gale is the Chief Marketing Officer at EDB.