SPARK’s inaugural Harness AI Forum brought technology and digital leaders together to examine what organisations must build to deploy agentic AI safely, securely and at enterprise scale.
For the past two years, much of the focus has been on experimentation: identifying use cases, testing copilots and evaluating new models. But as AI evolves from tools that assist people into agents capable of executing tasks, accessing enterprise systems and coordinating workflows, the central question is shifting.
It is no longer simply: what can AI do?
It is: what needs to exist around AI for organisations to trust it with real work?
That question was at the centre of SPARK’s inaugural Harness AI Forum: Architecting the Frontier-Ready Enterprise Agentic Control Plane, which examined the architecture, governance, security and organisational changes required for the next phase of enterprise AI.
Organisations are not short of AI ideas. The greater challenge is creating the enterprise scaffolding that allows those ideas to move safely from experimentation into production.
AI needs a harness, not just a model
A model may provide the intelligence, but enterprise AI also depends on infrastructure, data access, applications, permissions, security controls and monitoring.
The AI harness is the governance and support environment surrounding AI agents. It is the control architecture that gives organisations enough flexibility to innovate while maintaining the visibility, accountability and safeguards needed to manage risk.
Building this environment is a shared responsibility. CIOs and CTOs must establish the technology architecture. Boards need to determine risk appetite. CFOs have to decide which AI investments should be funded, scaled or stopped. CISOs must ensure that greater autonomy does not create unmanaged exposure.
As AI expands into enterprise-wide orchestration and customer or citizen-facing applications, explainability, traceability, identity, permissions and governance become increasingly important.
Software development offers an early view of what comes next
In his masterclass at the Forum, Chang Sau Sheong of GovTech Singapore explored how AI-assisted development is moving beyond simple code generation. The progression now spans prompt engineering, context engineering, harness engineering, loop engineering and, increasingly, graph engineering.
Each layer adds a different capability: better instructions, richer context, access to tools and permissions, iterative feedback, and eventually coordination across larger workflows.
As AI takes on more execution, the human role begins to shift towards orchestration, verification and judgement. The challenge becomes less about producing more output and more about determining whether that output is correct, useful and aligned with organisational goals.
This shift could lead to AI-augmented squads, smaller teams that own specific outcomes and federated organisations operating on common, centrally governed agent platforms. Agentic AI may not simply improve existing teams. It could reshape how teams are structured, how work is managed and how performance is measured.
Security has to move with the agent
Greater autonomy also creates a different security environment.
AI agents interact with applications, APIs, data and enterprise systems, while attackers are also gaining access to increasingly capable AI tools. Together, these developments expand the attack surface and make visibility and runtime controls more important.
A technology demonstration by Uri Dorot of Radware explored automated API discovery, business-logic mapping, pre-production testing and runtime protection. These capabilities can help organisations identify shadow APIs and manage risks when agents interact with applications.
Jarret Kolthoff of Akamai Technologies focused on another key control point: the browser. As work increasingly takes place across SaaS platforms and generative AI services, browser-level visibility can help organisations identify shadow AI, prevent sensitive information from entering unauthorised tools and manage risks created by malicious extensions.
The broader lesson is that AI governance cannot remain only a policy exercise. Controls increasingly need to be embedded within the environments through which AI operates.
From pilots to platforms
A widening gap remains between AI experimentation and enterprise deployment.
Organisations are already testing generative AI across legal, education, government and enterprise use cases. But concerns around data exfiltration, intellectual property, cybersecurity, compliance and model behaviour continue to determine how quickly leaders are prepared to scale.
Closing that gap requires more than another proof of concept.
It requires an enterprise control plane capable of supporting AI as an organisation-wide capability. This includes clear architecture, secure data access, approved toolchains, monitoring, model lifecycle management, role-based competencies and meaningful measures of business value.
The strategic opportunity is therefore not simply to make an existing process slightly faster. It is to ask whether AI allows the process itself to be redesigned.
The next phase of AI will be an architecture challenge
Enterprises have spent the first phase of generative AI learning what the technology can do.
The next phase will be about determining what organisations are willing to let it do, and building the architecture that makes that possible.
That means balancing autonomy with accountability, innovation with security, and speed with governance.
The organisations that move furthest will not necessarily be those with access to the most powerful model. They will be those that build the strongest environment around it.
As AI moves from assistant to agent, the defining enterprise capability may no longer be simply the ability to adopt AI.
It will be the ability to harness it.



