The debate around agentic AI has quietly shifted. The question is no longer whether autonomous agents become the dominant way software gets built, work gets done, and decisions get made. That's largely settled. The real question — the one I heard echoed across conversations with infrastructure leaders, enterprise operators, and researchers at UC Berkeley RDI's Agentic AI Summit earlier this month — is what breaks when that shift happens, and who's positioned to fix it.
I want to lay out four themes that I think matter most for how this decade plays out, and close with where I think the durable investment opportunities sit.
1. Infrastructure Is Being Rebuilt From the Silicon Up
Leaders from Amazon, Google DeepMind, and Nvidia have converged on the same conclusion: the hardware that got us to today's chatbots isn't the hardware that gets us to tomorrow's agents. A few specific shifts are underway:
- Not all chips will look the same going forward. Agentic workloads — with heavy context requirements and long-running inference — are pushing architectural change at the hardware layer. GPUs, optimized for the training-heavy era, may not be the most efficient substrate for inference-heavy, context-hungry agentic systems.
- Memory is becoming the bottleneck, not raw compute. Agentic AI needs to hold and reason over far more context than a single chatbot turn. That makes SRAM-heavy, memory-intensive system design increasingly central — a real departure from compute-first architecture thinking.
- Models and chips are converging into a single design loop. Architecture and model decisions are no longer separate tracks — they're being co-designed.
The underlying message, repeated in different words by different people: constraints drive innovation. The next wave of gains may come as much from systems and architecture co-design as from bigger models.
2. Governance and Security Are the Real Bottleneck — Not Capability
If infrastructure is the technical throughline, governance is the anxious one. Nearly every serious conversation about agentic AI right now circles back to a version of the same question: how do we keep autonomous systems accountable when they're operating with real credentials and real consequences?
This isn't abstract. Recent, concrete incidents — including agent-related security failures involving OpenAI/HuggingFace and previously documented incidents at Anthropic — are evidence that autonomous agent exploitation is no longer a hypothetical risk to plan for someday. It's already happening. A few responses are gaining traction:
- Verticalized governance standards. Healthcare, finance, and retail have fundamentally different risk profiles and regulatory environments. A single, horizontal standard for agent governance won't work — expect vertical-specific frameworks instead.
- Time-bound accountability. Just as human workflows in the enterprise operate under time constraints and audit trails, agents will need equivalent restrictions — bounded time windows, tracked activity, clear accountability chains.
- Reinforcement learning as a security layer. RL-based approaches, combined with automatic red-teaming, are emerging as ways to detect anomalous agent behavior and build in guardrails, rather than relying solely on static, pre-deployment testing.
- Phased rollout as a governance strategy. One useful maturity model: introduce agents as "interns" with limited scope and heavy oversight, graduate them to "coworkers," and eventually to "teammates" — with trust and autonomy expanding at each stage rather than being granted upfront.
The common thread: governance isn't a layer you bolt on after the fact. It has to be architected in from the start — identity, access control, and runtime permission checking all need to travel with the agent, not sit outside it.
3. Enterprises Are Bracing for a New Org Chart
This is where the "humans aren't ready" thesis gets concrete. Enterprise leaders aren't talking about agentic AI as a productivity tool bolted onto existing workflows anymore — they're describing a restructured workforce.
Wells Fargo's Head of AI put it plainly: across a workforce of roughly 200,000 employees, the company does not foresee individual contributors in the traditional sense going forward. Instead, each IC becomes a manager of agents — owning the agents' work and remaining accountable for their actions, even as the agents perform the underlying tasks. He framed it as a staged shift: AI as a tool in the short term, AI as a "teammate" or junior employee in the medium term (as soon as next year, by his estimate), and autonomous AI operating within tight guardrails by 2028 and beyond.
This pairs with a related pattern: enterprises will be multi-model by necessity. No serious operator is betting on a single vendor or model architecture. The winning approach is building an internal abstraction layer that governs multiple models centrally, treating the underlying model as swappable infrastructure rather than a fixed foundation.
And repeatedly, the hardest problem isn't "getting a good model" — it's encoding organization-specific workflow, context, and conventions into the agent's harness. The model is table stakes. The proprietary, idiosyncratic knowledge of how a specific company actually works is what makes an agent useful — and that's much harder to build and much harder to copy.
A few other patterns worth flagging: "sprawl" is a real operational risk, with enterprises already seeing proliferating, ungoverned tools and agents; data validation matters more than ever in high-stakes vertical use cases; and agent gateways are emerging as a meaningful access-control pattern. There's also a candid tension worth naming: machines may be approaching capabilities that look like narrow AGI in specific domains faster than humans and organizations can actually absorb them.
4. Open vs. Closed Isn't a Winner-Take-All Debate
The open-weight versus closed-model question keeps sharpening, especially with Nvidia and Microsoft moving toward supporting open-weight models more directly. This isn't heading toward a single winner. Commodity workflows — the kind that don't require deep organizational context — will likely run on public, open models. More sensitive or highly differentiated workflows will stay on closed, proprietary models, largely as a make-vs-buy decision made function by function, not company by company.
Open-source models are closing the gap with frontier models faster than many expected. "Intelligence" itself is becoming less of a moat. So what is the moat? Increasingly, it's data, workflow context, network effects, and — in a smaller number of cases — genuinely hard physical infrastructure problems that aren't easy to replicate regardless of model access.
The Throughline
If I had to compress this into one sentence: the technology is arriving faster than the governance, organizational structures, and infrastructure needed to safely absorb it — and most of the smartest people building this today know it.
Infrastructure teams are racing to redesign hardware and memory architecture around agentic workloads. Security and governance researchers are racing to build accountability and verticalized standards before more high-profile incidents become routine. And enterprises are quietly redrawing org charts around a future where the "individual contributor" job description includes managing a team of agents, not just doing the work directly. None of this is settled. But the direction is clear enough that it changes where the durable opportunities sit.
A Note on Our Investment Thesis
At Chakra, we're investing behind two distinct patterns of moat formation in the agentic AI era.
In AI-enabled businesses — existing companies transforming into AI-led operations — we believe durable advantage will concentrate around: enterprise proprietary data; enterprise workflow, process, and organizational context; the combined value created by human and agent capital working together; and markets where governance is structurally built in — finance, energy, insurance, risk, healthcare, and other domains where intelligence meets physical and regulatory frameworks.
In AI-first companies, we see moat forming differently: the ability to disrupt large legacy markets using globally available data and workflows — primarily by acquiring real domain expertise and using it to unseat incumbent business models — and framework and orchestration companies that provide the harness layer other players build on.
We're actively looking for founders building in both categories.