What Enterprise CTOs Want from AI Now: Governed Data, Secure Execution and Measurable Value

Enterprise AI is entering a different conversation. Access to powerful models is becoming easier. Knowing what those models can see, what agents can do, and whether the work is worth the cost remains much harder.
At GoPomelo’s first CTO roundtable on Running AI Agents in Production, we expected to spend most of our time on the transition from experimentation to deployment: orchestration failures, tool-calling security and unpredictable token bills. Those topics mattered. But over four hours with five enterprise CTOs, a Google Cloud CTO and GoPomelo CTO Bryan Chua, a more fundamental shift emerged.
The leaders in the room already had access to capable AI. Their engineers were using advanced coding tools. AI was also arriving inside workplace applications their organisations already used. Offering another route to a model, or another demonstration of an agent, was becoming less compelling than answering the operational questions those tools left behind.
Our subsequent CTO roundtable with Microsoft and Ingram Micro sharpened that question. The discussion moved into company-specific knowledge, shadow AI, token controls and expert-curated test datasets. Together with the data governance and security concerns raised through our ongoing GoAgentic coffee chats, a common challenge emerges: how can an enterprise turn individual AI capability into something the organisation can trust and manage?
The next enterprise AI advantage is the ability to put powerful models to work with the right knowledge, the right permissions and evidence that the work delivers value.
Two roundtables, one practical question
The series brought technology leaders together in Bangkok for small, focused discussions about production AI. The Google Cloud roundtable took place on 20 August 2026, followed by the Microsoft roundtable on 23 September. The second event’s programme featured Bryan Chua, GoPomelo’s Chief Technology Officer; Parinya Sinkuakul, Microsoft’s Senior Partner Solution Sales Manager, Cloud & AI Platforms; and Supakit Tiyawatchalapong, Managing Director of Ingram Micro Thailand.
Customer participants in the August conversation included technology leaders from MK Group, Ookbee and LINE MAN Wongnai, bringing perspectives from food service, digital content and consumer technology. The discussion connected different industries through a shared responsibility: making AI useful inside a real business.
That format matters. A product presentation can show an ideal workflow. A conversation among people responsible for live systems can expose what happens when the source document is wrong, an employee changes roles, a model is updated or a useful experiment starts generating an unexplained bill.
GoAgentic coffee chats extend that conversation beyond the event itself. They give us a way to keep listening as enterprises work through their own data governance and security concerns. Their value is the depth of the questions they surface and the architecture decisions those questions demand.

Technology leaders at GoPomelo’s Google Cloud CTO roundtable in Bangkok, 20 August 2026.
1. The knowledge problem is also a permissions problem
A frontier model can reason well and still produce a poor business answer. It may be using an outdated policy, missing an exception, or retrieving a document that the employee should never have been able to read.
Enterprise knowledge is distributed across shared drives, collaboration platforms, business systems and the people who know how those systems really work. Making that information searchable is only part of the job. An AI system also needs a reliable way to distinguish current guidance from obsolete material, approved content from a working draft, and company-wide information from restricted knowledge.
This is why data governance becomes a product requirement. Once information is indexed or copied into an AI knowledge layer, the original access boundary can become harder to see. If a permission changes in the source system, the AI layer must handle that change too. An answer that reveals restricted information remains a security failure even when every sentence is factually correct.
The September discussion made the preparation problem concrete: domain-specific knowledge, such as sales history or finance material, needs to be digested and organised before agents can retrieve it effectively. Simply connecting an agent to a folder of PDFs leaves the burden of finding, interpreting and reconciling the evidence inside every request. Better knowledge preparation can improve retrieval and reduce repeated work, but the permissions must travel with that knowledge.
GopoBrain: Business-aware enterprise knowledge built for AI.
GopoBrain structures enterprise knowledge around industry expertise and business needs, with governed access and rule-based updates from connected systems. It enables fast AI retrieval and team-specific sub-brains and analytics built on a shared knowledge foundation.
Consider an internal policy assistant. Every employee may need the general travel policy. A regional finance team may also need country-specific rules, while individual employee records remain restricted. A useful knowledge architecture supports those distinctions instead of putting everything into one undifferentiated repository.
Implementing that architecture also requires ownership: who approves a source, who keeps it current, and what happens when it expires or access is revoked? GoPomelo can help customers establish these rules alongside the knowledge layer. The result to aim for is an answer that can be traced to an appropriate source, delivered within the user’s permissions, with a clear path for correcting the underlying knowledge.
2. Security depends on where work happens—and where data goes
When an employee uploads a file into an AI tool, several different activities may follow. The file may be stored, parsed, indexed, passed to a model, included in a tool call or retained in a conversation log. Asking only “Where is the application hosted?” leaves most of that journey unanswered.
Enterprises need to distinguish control over the workspace from control over inference. They also need to distinguish permission to read information from permission to take action with it. An agent that can summarise a customer record should not automatically inherit permission to change that record or send it to an external recipient.
The second roundtable also explored the human side of this boundary. Employees are already using personal AI accounts to get work done. Discussion ranged from controlled device environments and browser-level detection to open check-ins with departments. The lesson is that shadow AI is partly a workflow problem: if the approved route cannot support the work, people have an incentive to find another one. A governed workspace needs to be useful enough to become the everyday route.
GopoShell: A secure, governed AI harness for your workforce.
GopoShell provides a secure AI execution environment on enterprise-owned hardware or in the company’s cloud. It brings employee AI subscriptions and enterprise-assigned access under company governance through supported integrations, with central control over identity, data access and tool execution.
The architecture gives organisations a place to keep document storage, preparation and supported tool execution within their chosen environment. It also provides a basis for applying policies to what information is allowed to reach an external model. Those policies need to cover retrieved passages, tool results and logs as well as the original upload.
Local execution and local model inference are different promises. A cloud-hosted model still processes the prompts and context sent to its endpoint. Keeping all processing within an enterprise boundary requires an appropriate model deployment as well as a locally hosted workspace.
For example, an organisation might prepare a document locally and send only an approved excerpt to an enterprise AI endpoint. Another workflow may require inference inside a controlled environment because no document content is permitted to leave. These are different deployment choices, and the data flow should make the difference explicit. A “not used for training” policy or a retention agreement answers a separate question from where inference happens.
Flexibility in model access matters too. GopoShell supports business AI APIs and provider-supported account connections, subject to the provider’s integration rules and the organisation’s own policies. A personal AI subscription should never be assumed to include API rights, enterprise privacy controls or permission for arbitrary third-party use.
For a customer, the practical benefit is a clearer operating boundary: approved people working with approved knowledge and tools, through approved model connections. Making that boundary real requires more than checking an email domain. Identity verification, user provisioning and revocation, tool permissions and audit records all belong in the implementation.
3. AI spend is difficult to govern when nobody owns the whole journey
One of the clearest concerns in the first roundtable was financial visibility. Consumption was spread across teams, tools and vendors. Budgets were difficult to set, and it was harder still to explain which spend had produced useful work.
Agentic workflows make that problem more complex. A single request can trigger retrieval, planning, tool calls, retries and further model requests. A lower token price can coexist with a higher workflow cost if the system repeats work or sends excessive context. Equally, a more expensive model can be economical when it completes a difficult task reliably with less rework.
The September session brought practical mechanisms into focus: request gateways, shared token pools, daily usage limits and ongoing monitoring. These controls should give teams room to experiment while making consumption visible and bounded. The appropriate limit depends on the workflow; copying another organisation’s token cap is no substitute for understanding your own workload.
GopoGate: One AI gateway for model access, usage and cost.
Powered by Routero
GopoGate centralises access to AI models, routes requests across providers and monitors usage by user and team. With budget controls and visibility into token consumption, it helps enterprises reduce waste and manage the cost of AI across connected applications and workflows.
That creates a practical starting point for reducing waste: understand which workflows consume resources, assign ownership, then examine where a different model, a smaller context or a better execution path can do the same job. Savings should be measured against the customer’s own workload and quality requirements, rather than presented as a universal percentage.
The most useful unit of value is often the completed business task. For an internal assistant, that might mean a correctly resolved request. For a document workflow, it might mean an accepted extraction that needs little human correction. Token usage helps explain the bill; cost per successful outcome helps explain the business case.
A gateway also has a clear visibility boundary. It can govern the traffic routed through it. An enterprise-wide view requires the relevant applications and connections to be integrated, while subscription costs and activity outside the gateway need to be accounted for separately.

Discussing the economics of running AI at GoPomelo’s Microsoft CTO roundtable, Bangkok, 23 September 2026.
4. Trust needs to be tested every time the system changes
The first roundtable surfaced another uncomfortable gap: customers were being sold autonomy without a dependable way to verify it. A convincing demonstration provided little assurance that an agent would behave correctly next month, after a model update, a connector change or a new set of documents.
Our view is that evaluation belongs alongside knowledge, execution and cost controls. It is an ongoing engineering discipline. The test set should represent the work the business actually expects the agent to do, including situations where the correct response is to refuse, escalate or ask for clarification.
The second roundtable described a useful starting point: a “golden” test dataset curated by domain experts. People who understand the business define representative inputs and acceptable outcomes, creating a baseline against which model and workflow changes can be assessed. That baseline helps reveal regressions; it does not make a probabilistic system deterministic or remove the need for review on high-impact decisions.
For the policy assistant, useful tests go beyond whether it can find the right paragraph. Can it respect different employee permissions? Recognise an outdated document? Resist instructions embedded in retrieved material? Avoid taking an action outside its authority? Still meet the agreed quality, latency and cost thresholds after an update?
GoPomelo’s agent security and performance evaluation work can help customers define those baselines and introduce regression checks. The three product layers support the operating environment; evaluation provides evidence about how the complete workflow behaves. None of the layers, on its own, proves that an agent is trustworthy.

Technology leaders exchange perspectives on enterprise AI at GoPomelo’s Microsoft CTO roundtable, Bangkok, 23 September 2026.
How the three layers work together
Consider an illustrative workflow: a sales employee needs to prepare a proposal from approved service information and account context.
GopoBrain supplies the governed knowledge. A sales team’s sub-brain brings together approved service information and account knowledge, refreshed from connected systems according to defined rules. The workflow retrieves material the employee is allowed to use, organised around the business terminology and needs of the proposal.
GopoShell provides the governed execution environment. The employee works under their corporate identity, with files and supported processing in the enterprise’s chosen environment. The deployment policy determines which context may be sent to which inference endpoint and which actions require human approval.
GopoGate manages supported model calls. Usage can be attributed to the relevant user or team, with budgets and routing decisions applied to connected traffic. Model selection should be judged against the proposal workflow’s quality requirements.
Evaluation closes the loop. The business checks whether the proposal is accurate, respects access rules and saves useful time after review. It also tests whether the workflow remains acceptable as its components change.
This illustrative workflow shows why the layers belong together: knowing what AI may read, controlling how it works and understanding what it costs are interconnected decisions.
Start with a workflow that can earn the right to scale
For enterprises considering their next step, our recommendation is to choose a bounded workflow with a business owner, identifiable knowledge sources and a measurable result. The objective is to establish a repeatable way to operate AI before expanding its reach.
Define success. Agree what a correct outcome looks like, what human review remains necessary and which failures are unacceptable.
Map knowledge and permissions. Identify authoritative sources, owners, user groups and the process for handling stale or revoked access.
Draw the data and action boundaries. Record where files, prompts, retrieved context, outputs and logs are processed, and which actions the agent may take.
Measure the full workflow. Track quality, latency, intervention and cost per accepted outcome; test changes before widening deployment.
This approach also makes conversations with security, finance and business teams more productive. Each can assess a concrete workflow, a defined boundary and a set of results. Governance becomes part of making useful work repeatable.
The organisational lessons from the September roundtable are equally relevant: give AI initiatives accountable leaders, dedicate people to adoption, connect goals to business-unit metrics and keep change management active. A faster draft means little if approval still takes the same time or the output creates more rework downstream. Measure what improves across the process, then use those results to decide where to expand.
Credibility comes from operating AI ourselves
One of Bryan Chua’s strongest reflections from the first roundtable was that the conversations moved forward when there was something real to show. GoPomelo’s own use of GopoBrain with Gemini Enterprise, and Routero to manage token spend, gives our teams practical experience to bring into those discussions.
That experience is valuable when we can explain how a workflow operates, what has been measured and where its limits remain. It creates a better starting point than a capability presentation alone—and it gives customers permission to ask harder questions.
Across our CTO roundtables and GoAgentic coffee chats, data governance and security keep returning to the centre of the conversation. The implication for us is clear: help enterprises build the conditions under which AI can be used with confidence, then demonstrate that confidence through evidence.
GopoBrain, GopoShell and GopoGate powered by Routero form three complementary layers for enterprise AI: governed knowledge, enterprise-controlled execution and accountable model usage. Together with integration and evaluation work, they provide a practical way to connect AI capability to business responsibility.
Bring a real workflow to the next conversation. Explore GoAgentic and talk with GoPomelo about the knowledge, security and cost decisions behind your next production AI initiative. Or join a GoAgentic coffee chat to compare challenges with the people working through them.
Start with a 30-min call
Free 30-minute scoping call
Engineers, not sales reps, on the call
Avg. response: under 4 hours, business days


