Back to blog
August 7, 2026Stackmint Editorial

Bounded Agency: Why Enterprise AI Needs Governance Before Autonomy

Enterprise leaders are struggling with AI adoption right now. They face a multitude of options, frameworks, and governance challenges. Flo Boymond, CEO of Stackmint, sat down with Matthew Skelton, co-author of the highly influential book Team Topologies, CEO at Conflux, and the originator of Bounded™, the AI-native operating model toolkit, to explore the issues.

Bounded Agency: Why Enterprise AI Needs Governance Before Autonomy

Flo Boymond: Welcome, Matthew. It is a privilege to host you today. As the founder and CEO at Conflux, I know you consult with C-suite leaders globally. At Stackmint, we are building the governed execution infrastructure for enterprise AI, and we consistently see executives struggling to deploy Agentic AI safely. From your vantage point, what are the primary business problems CIOs and COOs face when trying to adopt Agentic AI, particularly within highly regulated environments?

Matthew Skelton: Thank you, Florian. It is a pleasure to be here. The conversations I have with business leaders and executives are remarkably consistent from one organization to the next; they come to us on a weekly basis with questions that are practically identical. Most organizations are still struggling to convert AI adoption into measurable enterprise value. MIT NANDA’s 2025 research found that 95% of organizations in its study were getting zero return from GenAI initiatives, while McKinsey’s 2025 survey found that only 39% of respondents reported enterprise-level EBIT impact from AI.The most glaring business problem is that a staggering 80% of firms (or more) currently report absolutely no benefit from their AI initiatives. This failure stems from treating AI as a technology-first initiative rather than starting with business outcomes, which inevitably leads to C-suite distrust.

Beyond the lack of ROI, there is deep operational anxiety. A COO simply cannot sleep soundly at night knowing they have 10,000 AI agents operating 24/7 without rigorous oversight. Meanwhile, the CISO is struggling to reason about the immense security risks that stem from Agentic AI. The core problem in these highly regulated contexts—like financial services and healthcare—is the naive desire from some leaders to grant AI tools unbounded read and write access to all data stores and applications across the enterprise. We would never grant a human unbounded access to every system because it would inevitably lead to disaster, yet organizations are rushing to do exactly this with probabilistic models. Security boundaries exist not just to protect data, but to protect domain fidelity. If domain fidelity is lost because an AI agent operates outside its bounds, the very intent of the business systems is corrupted.

Flo Boymond: That resonates with our core philosophy at Stackmint. We frequently say that giving a probabilistic reasoning engine direct authority over deterministic business systems is not an innovation; it is an unmanageable liability. This leads perfectly into your new initiative, Bounded™. How do the core principles of Bounded™ and Team Topologies directly address these critical governance and operational challenges?

Matthew Skelton: Bounded™ is an AI-native operating model toolkit specifically designed for organizations where "vibes are not enough". It is built from the ground up for enterprises with strict regulatory obligations and financial audit requirements. Our foundational principle is that "Bounded Agency" is the absolute core of success with AI. This means we must implement deliberate, designed limits to an agent’s scope of operation. If you are already organizing your human teams for bounded agency, you will have a relatively straightforward job adopting Agentic AI because you have already solved the hardest organizational problems. Conversely, the primary reason 80% of organizations fail with AI is that they are not organized for bounded agency in their human workforce.

We utilize Team Topologies as the "infrastructure for agency". It provides the rules, principles, and guardrails that empower groups of humans and AI agents to act as effective stewards of value flow. A vital concept here is cognitive load, or what we call "cognitively scoped stewardship". If a domain cannot fit inside a human's head, they cannot possibly be a good steward of it. We see a direct parallel with AI: a context window is effectively the cognitive load boundary of an AI system; if you exceed it, the agent loses coherence and begins to hallucinate connections that do not exist. Therefore, to safely deploy AI, we must design for audit and traceability first, treat AI as infrastructure rather than as human equivalents for financial tracking, and build organizational observability to strictly define our boundaries.

Flo Boymond: It is not an accident how closely that aligns with Stackmint’s technical architecture, because we were inspired by many of your ideas in Team Topologies. We focus heavily on active governance by explicitly separating the Intelligence Domain from the Execution Engine. Before any action is taken, it must pass through a Governed Gateway that checks circuit breakers, API budgets, and human-in-the-loop requirements. From your perspective, how does a platform like Stackmint fit into the Bounded™ operating model and enforce these principles?

Matthew Skelton: I think Stackmint is a great example of the execution layer for AI-native operating models like Bounded™. What Stackmint has built is exactly what the industry needs to enforce "Bounded Agency" technically. You recognize that you cannot rely on a probabilistic model to enforce strict regulatory compliance; if guardrails are merely written as instructions in a markdown file, the model will inevitably ignore them a certain percentage of the time. If that model has access to execute actions, it might issue an unauthorized financial refund without any human oversight. I like how Stackmint addresses this by enforcing human-in-the-loop checkpoints, budget restrictions, and routing policies directly at the tool level via your Governed Gateway. This provides the deterministic boundaries that C-suite leaders are actively demanding.

Flo Boymond: Exactly. We believe that enterprises do not want to buy loose scripts; they want governed, deterministic outcomes. By combining your strategic frameworks with our execution infrastructure, we can help service providers and consultancies package their expertise into highly governed AI capabilities. As a final thought, how should large institutions begin this journey to ensure they can scale AI safely and successfully?

Matthew Skelton: The very first step—what I call the "zero thing"—is to start with outcomes and work backwards; never start with the technology. Technology-first initiatives always fail because they do not prioritize value delivery. Next, you must build trust, and trust in human teams and trust in AI both is founded on bounded agency, which provides the necessary clarity to operate securely.

Organizations must abandon the naive idea of granting unbounded access to enterprise data. Instead, they need to empower teams of humans to be effective stewards of long-lived value streams using the clear boundaries and diagnostic language defined by Team Topologies. Finally, we must actively diffuse learning and innovation across the enterprise, as I explore in my new book Adapt Together. The speed of technology change is currently outstripping the speed of organizational learning, and without an active approach to sharing knowledge, implementations will stall. By pairing a robust operating model like Bounded™ with a rigorously governed execution platform like Stackmint, highly regulated enterprises can finally move beyond risky AI experimentation and safely achieve the deterministic, recurring business value they have been promised.