In short
The “100,000 agent problem” in enterprises—when many AI agents act autonomously on behalf of employees, trust/governance becomes the bottleneck. Michaels argues agents are probabilistic “enthusiastic interns” that can take unintended actions, so enterprises need fine-grained guardrails beyond identity/access management. He explains agent connectivity via MCP (Model Context Protocol) and why MCP doesn’t solve trust. Barndoor provides an enterprise governance layer and “Tool IQ” to reduce token/context-window issues by exposing only the needed tools. Venn.ai is a single-user version for hooking up email/Slack/calendar/etc.
Guests
Oren Michaels only (co-founder/CEO of Barndoor AI, New York). Background: previously co-founded/runs Mashery (first API-as-a-service; started 2006; sold to Intel in 2013). Also mentions a colleague from UI and an EY contact.
Key claims
2026 is an inflection point as knowledge workers adopt action-mode agents. Governance should manage allowed in/out actions and blast radius per task.
Notable examples
Slack policy blocking posts to “#EXT” channels; blocking AI from posting anything resembling PII; Salesforce logging agent allowed to create call logs but not add new contacts; conference-attendee agent allowed to create contacts. Hotel guest-services personalization use case.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOThe Enthusiasm Behind Agents
0:00 to 0:36
Discussion on the excitement and challenges of implementing agents in enterprises.
“Why you compare agents to enthusiastic interns.”
Oren's Journey and Barndoor AI
0:46 to 2:26
Oren shares his background and the inception of Barndoor AI.
“I was seeing that the world was talking about AI coming into the enterprise, but we weren't seeing much of it actually happen.”
Understanding the 100,000 Agent Problem
2:27 to 6:00
Exploration of how many agents enterprises might need and the complexities involved.
“And when I talk about an agent, I believe an agent is something that actually takes action on behalf of an employee or on behalf of itself.”
The Role of Governance in AI
6:01 to 7:42
Discussion on the necessity of governing AI agents for effective operation.
“But the challenge we have today is that a lot of people still don't know what to do with that because MCP is relatively new.”
Probabilistic Nature of AI
7:43 to 11:17
Insight into how AI systems function probabilistically and the implications.
“Just for listeners that aren't following, MCP is Model Context Protocol, and it's basically a bit of code that allows models to talk to tools or to APIs as well, doesn't it?”
Identity and Governance Challenges
11:18 to 14:00
Discussion on the governance challenges with AI and the importance of human oversight.
“with a bit of skepticism at the beginning.”
Governance and AI Trust
14:00 to 16:20
Explore the balance of trust and governance in AI usage within enterprises.
“And I know that if I do it a lot, I'm going to get fired.”
Quality Assurance for AI Actions
16:20 to 19:16
Learn how double-checking mechanisms can ensure AI reliability and accuracy.
“Although even, I mean, there's something called automation bias where, you know, you run a system 10 times and it does it perfectly each time and pretty soon you stop checking.”
Implementing AI in Enterprises
19:16 to 21:44
Understand how AI tools can be safely integrated into company workflows.
“in a company to hook in their corporate systems and use them with AIs.”
Governance Models for AI Agents
21:44 to 24:18
Discover the importance of governance models in AI agent functionality.
“I wanted to make sure all of them were in our sales force and I knew most of them probably weren't.”
Show all 26 chapters
Challenges of Context Window Exhaustion
24:18 to 28:00
Examine the limitations of AI models with numerous tools and tokens.
“And how do you, is this a page of toggles?”
Optimizing Task Execution with Tools
28:00 to 28:37
Learn how a smart layer of tools enhances efficiency in task execution.
“So the model says to us, hey, I'm trying to do this.”
The Impact of OpenClaw on Agent Technology
28:37 to 31:16
Discover how OpenClaw and its extensions change the landscape of AI agents.
“makes them more useful for them yeah and then then you're not wasting so much of the processing power.”
Enterprise Trust and Control Issues
31:16 to 34:06
Understand the challenges enterprises face in adopting AI agents and maintaining control.
“And I was at a conference with about 50 enterprise CIOs and CISOs last week, and very large companies.”
Competition and Landscape in AI Governance
34:06 to 36:51
Explore the competitive landscape for AI governance solutions and emerging needs.
“So this level or this layer in the stock that Barnador provides, how stiff is the competition for you?”
The Evolving Use of AI in Enterprises
36:51 to 39:36
Examine how AI adoption is progressing across different enterprise roles.
“In the piece I wrote and the conversation we had earlier, I mean, we were talking about how early days this is.”
Future of Agentic AI and Daily Tasks
39:36 to 42:05
Learn about the potential for AI to automate complex processes in the workplace.
“And as a company, I mean, are you seeing a lot of uptake or do you – Definitely our cadence is increasing, which is nice.”
AI's Role in Automating Tedious Tasks
42:05 to 45:05
Learn how AI can take over undesirable tasks to enhance productivity.
“What Quentin said was, you want AI to take on the tasks that you have in your job that you never want your kids doing if it's their job.”
Personalization in Hotel Services Using AI
45:05 to 46:55
Discover how AI can transform guest services through better personalization.
“So we're talking to a major hotel chain right now, and they want to be bringing this capability into their guest services.”
The Evolving Role of AI in Organizations
46:55 to 49:44
Understand the shifting responsibilities and governance of AI in companies.
“You talked about HR department for AI in regards to IT departments.”
Promoting a Culture of AI Success
49:44 to 50:59
Explore the importance of leadership and culture in successful AI adoption.
“We talk about, you know, 95 % of AI projects fail.”
Integration of AI in Theater Production
50:59 to 56:00
Learn how AI and technology are enhancing theater production processes.
“uh to govern ai agents there is uh and and what are you does barn door do to improve on that infrastructure already i mean we've already talked about it think of how you govern humans, right?”
The Role of Technology in Creating Art
56:00 to 57:02
Explore how technology aids in the creative process of musicals.
“And so it's so risky, particularly doing musicals, that you have to use whatever tools are available to you in order to make these things successful.”
Managing Safety in Performance Spaces
57:02 to 58:14
Learn about the importance of managing data and safety in live performances.
“You know, it's early days, but I would be, it would not surprise me if there are elements of managing these services and in particular managing the safety issues, right?”
Consulting and Hackathons in Tech
58:14 to 59:10
Discover how companies utilize hackathons to innovate with APIs.
“We have people here whose job it is to come and work with our customers and bring them ideas.”
The Meaning Behind Barndoor's Name
59:18 to 59:45
Understand the reasoning behind the name Barndoor AI.
“Well, you know, we have a habit in our world of closing the barn door after the horse is already out.”
Transcript
Automatic transcript. May contain errors.0:00Why you compare agents to enthusiastic interns. Why do you think 2026 is an inflection point beyond open thought? While there's a lot of enthusiasm and excitement about agents, very few corporations or enterprises are putting them into production because exactly what you said, the trust issue. These systems are probabilistic. I think that as humans, we're pattern matchers. And so the more we see, the more we want to do. They will absolutely give you an answer. They will absolutely do something when you tell them to. Hi, Craig. I'm Oren Michaels. I'm the co-founder and CEO of Barndoor AI based in New York City.
0:44and I started Barn Door in October of 2024. I was seeing that the world was talking about AI coming into the enterprise, but we weren't seeing much of it actually happen. And I thought that I had something to add and my team had something to add to be a catalyst for AI to actually be successful at the enterprise. Before Barndoor, I co-founded and ran a company called Mashery. We started in 2006. We were the first API as a service company, which we built over the course of seven years and sold to Intel in 2013. Before that, I just had a variety of positions running companies in technology, wine, theater, and various other areas.
1:36yeah i i see the uh the the posters on your wall there you're also a broadway producer i understand i am i am these are all shows that i've that i worked on so yeah yeah that's wonderful very uh eclectic um and so yeah we're going to talk about barn door ai and then also then ai maybe you can explain the relation between them. Sure. And then talk about the 100 ,000 agent problem. And I read an article you wrote, you explained it very clearly with, you know, I can't remember how many employees, each employee has a certain number of agents, suddenly you got 100 ,000. Yeah. Yeah, so we believe that agents are going to become useful in companies.
2:30And when I talk about an agent, I believe an agent is something that actually takes action on behalf of an employee or on behalf of itself. It doesn't necessarily have to be tied to an employee, but most of them usually are at this point. And to take action, an agent doesn't merely do what our chat interface does, which is suggest something that we as the human should go do. But it actually doesn't merely suggest it. It actually takes the action and does it. It interacts with the same tools, the same systems that we use in the enterprise, whether it's something like Salesforce or email or Slack or Snowflake or QuickBooks or whatever it is that you use in your world.
3:16And so in order for that to happen, you need two things. You need the AIs to actually be able to connect to these tools. and you need the humans to trust the AIs will use those tools appropriately and not do things that they shouldn't. And the connectivity is something that's actually not that hard. About a year and a half ago, a protocol called MCP came out that Anthropic brought out, and that solved a decent chunk, not all, but a decent chunk of the connectivity issue. But it didn't do anything about the trust because MCPA is not a security protocol. It's merely a pipe. It's a way of connecting.
4:00And so it's my belief that in order to really trust an agent to act autonomously, you basically have to govern that agent to a point where you're giving the agent a task and the only things it's allowed to do are the things related to that task. so that if it decides to hallucinate or go off the rails or do the things that agents do, that the guardrails in place are keeping the agent narrowly focused on that task at hand. Well, we have lots of tasks, and we're going to have lots of agents doing these tasks. And so each agent that is off doing those tasks on behalf of me as an employee is going to need a different set of guardrails and a different set of rules about what it's allowed to do to carry on that task.
4:46And therein lies this challenge of having lots and lots of agents times lots of employees means tens, hundreds of thousands of agents in your company. And as agents come and go, because obviously we want to have the best possible agent doing the things for us, and new ones come up in the last couple of weeks, we've learned about OpenClaw. Well, nobody really knew about OpenClaw two months ago. and yet it's incredibly powerful and there are folks who are trying to figure out how to make it powerful and trust you know have it be something you can trust but there are going to be lots of it was written by one guy right there's going to be lots of different AIs that come out and you're not going to want to reconnect everything and redo all the rules every time a new interesting agent comes along so we believe that what needs to happen and this is the company that Barndor is We believe what needs to happen is there's a governance layer that manages all of these different agents on behalf of humans or not on behalf of humans.
5:48And what the agents are allowed to do, given the tools they're trying to use, the context, the data they're acting on, what specific task they're doing. And that's what we built at Barndor. And that's a great platform for companies to go and manage that. But the challenge we have today is that a lot of people still don't know what to do with that because MCP is relatively new. And MCP has, while it's taken off a bit on the developer set because it's kind of a technical thing to get up and running, your average finance, HR, salesperson isn't really doing much with it yet. And so because they don't know what it can do, they don't understand the power.
6:31we do. All of us use it every day here at our company because we've been playing with it for a while. But people really need to understand what it can do. And so in order to make that happen more broadly, we've introduced a tool called Venn. And what Venn is, is everything I just described to you, but for one person. So the idea is that you as an individual can come to Venn.ai, sign up, Get started for free. And you can use it to hook up to all those same things, email, Slack, calendar, all the different tools you use, whether at your company or in your personal life. And now some companies will have security that will cause it to not allow you to use vent on corporate systems.
7:16You might have to go get special permission to do it. or you can play with it in your own life on your own personal products and learn the things that you're able to do when you hook your AI up directly to the tools that you use. And our belief is that as people start learning that, that they're going to be able to bring those learnings back to their companies and their companies are going to be more likely to implement something like Barndor in order to allow everyone in the company to benefit from this productivity. Just for listeners that aren't following, MCP is Model Context Protocol, and it's basically a bit of code that allows models to talk to tools or to APIs as well, doesn't it?
8:11And when you refer, you talk about how AI has been in advisor mode and that enterprises are facing action mode where they're actually going to have AI doing things in the enterprise. I spoke to a guy at EY. Sure. I don't know if it's still called Ernst & Young. I think it's EY. In fact, my co-founder, my technical co-founder came from UI. That was his last job. Okay, yeah. Yeah. And he was saying that while there's a lot of enthusiasm and excitement about agents, very few corporations or enterprises are putting them into production because exactly what you said, the trust issue, that these systems are probabilistic.
9:09And even if they do a wonderful job 90 % of the time, there's going to be a small percentage of the time where they do something unintended. Yeah. Can you talk about that and then why you compare agents to enthusiastic interns? I thought that was an interesting. So at their heart, these models, these AIs are probabilistic systems. They basically, you give them a task or you give them a prompt, you tell them something, and with a lot of really, really complicated math, they give you what they feel is the most likely set of words or pixels or video or whatever you're asking for that is to them the most likely answer to the question that you're asking.
10:03And that is different than when you program an API. When you program something that uses an API, the API has certain capabilities and certain ways of using it that are documented. And the programmer writes a program that accesses that and does a specific thing with it. And if you run that program 100 times, it's going to do the exact same thing all 100 times. But probabilistic things don't work that way. And so what you then have is you have these systems that basically say, gosh, I'm being asked this. What's the most likely answer? And the more context you give, the more likely the answer is going to be close to what you intend.
10:45And people are starting to learn to do that. But absent a lot of context and even sometimes with a lot of context, you're still going to come into cases where an instruction is interpreted. not in the way it was intended. And we see that with humans as well. That's why I like to call them enthusiastic interns. They will absolutely give you an answer. They will absolutely do something when you tell them to. Whether it has what you have intended, who knows, right? And so the potential blast radius of this, if you have an intern, you tend to manage them with a bit of skepticism at the beginning. And you say, okay, I want you to go do these things and I'm going to keep an eye on you.
11:30And I'm going to give you, you know, start you on something that's not terribly, you know, important. Or if you screw it up, it's not going to be catastrophic to the company. And as we work together, and I see that you're capable of doing these things without causing a problem, I'll let you do more. And I'll ask you to do more and I'll give you broader access and broader capabilities and broader autonomy as you prove yourself capable of doing it. And I think that that's actually how a lot of people, either intentionally or unintentionally, are embarking on their AI journey. So, you know, you first start using it as basically glorified search.
12:18And then it becomes, you know, it becomes something more than that. when you perhaps ask it to write some code or you perhaps ask it to interpret something for you. And then you get to a thing. One of my colleagues yesterday said that she gets so many Slack messages and at the end of the day she wants to feel like she can log off and go be with her family. So the last thing she does each day is she says, look at all my unread Slack messages and tell me which five are important for me to answer before I quit for the day. And that's something you can't do unless your AI is hooked up to your Slack.
13:03But it is something incredibly useful to her. Yeah. And in the past, access to these systems by software, by more deterministic software, was controlled by identity and access management systems. Yes. And, you know, we've all worked with those. And then there's a higher level in the stack. There's some that kind of sit outside the database and check the identity of who's accessing the database and check what's being taken out of the database and they can have limits and that sort of thing. Why is that not enough for Gentic AI? because identity supposes that you have a human and the human comes with their own governance.
13:55I, as Oren, know that it's stupid to delete Salesforce opportunities. I'm allowed to, but I know I shouldn't. And I know that if I do it a lot, I'm going to get fired. And so that's a level of governance beyond merely identity. And it comes with my role. It comes with my identity. but it also comes with my history of proving to the world that I'm not going to go do stupid stuff. And the nature and identity is generally over-provisioned intentionally because we trust people to a certain point and we don't want to have to rush back and every single time I need to do something in Salesforce, I've got to go to the Salesforce admin and have them flip one more switch for me.
14:40So in general, they say, okay, this guy's been hired and he's shown himself to be reasonably trustworthy. So generally speaking, we're going to give him broad latitude and assume that he's likely to not misbehave.
14:59And you don't want to take that authority away from me as a human just because I'm now using AI. but you also recognize that I as a human probably am not perfect at using AI and I'm probably going to give some instructions that are not necessarily definitive to my AIs. And so my AIs, the AIs I'm using need by definition to have a smaller blast radius than I do. The only thing about AIs is they can cause a lot of trouble really, really quickly. And they're much faster at this than I am. And so it's likely that you want to dial back what these things are capable of doing, certainly at least until you have the opportunity to say, okay, I've given this AI a task.
15:52And now I'm going to look and see how it attempts to carry out that task. And for the things it does, the MCP calls it makes, the requests it makes, if all of those are consistent with the task I've given it, great. I'll turn those capabilities on and let it go do those things. But I probably want to try it that way first and limit how much it's allowed to do before I let it just sort of run autonomously every day and go do stuff for me. Yeah. Although even, I mean, there's something called automation bias where, you know, you run a system 10 times and it does it perfectly each time and pretty soon you stop checking.
16:38because you just assume. But if the thing is 97 % accurate, you're not going to see those 3 % go by where it makes a mistake. So how do you control that? Well, you probably have another agent that checks it. Right? And I think we're going to see a lot. We have that in, we've had that in IT for many, many years. I remember one company I ran was a employee benefits administration sort of online sign up for benefits thing. Very, very complicated data. And we're dealing with dozens of insurance companies and hundreds of client companies. And it was very, very complicated. And so every night we would run a program that basically went through and looked at everything and made sure it all made sense.
17:28Because people would make mistakes or something would get corrupted or whatever. And it just made sense to go through and just have that double check. And I think that as we look at agents being able to take action autonomously, we look at how you QA that. It's the same thing with software. So my software engineers write some code. And the first thing that happens before that code gets committed is another engineer looks at it and blesses the pull request. And in many cases, a bot comes through and does a bunch of QAs and tests on it as well. So I think we have always had a culture of making sure that the work that people do is checked.
18:23You've been a journalist a long time. I'm sure you've had editors and fact checkers and all those sorts of things. And it's something we do. Yeah. Okay, so tell us more about Barn Door and then Venn. I mean, you're really targeting enterprising. You talked about how individuals can use Venn, but you're focused on the enterprise. It's very early days, as I said. Enterprises are very cautious. but last time we spoke you were explaining how I don't know if it's Barndor or Venn allows you to set very narrow Yeah, and Barndor is the enterprise grade product that lets you really do this. So for instance, as you start allowing people in a company to hook in their corporate systems and use them with AIs.
19:27There are various things you know that you don't want to be able to happen. Some of them are company-wide. So for instance, one of the companies we deal with, the first policy they created is no AI is allowed to post to a Slack channel that starts with hash EXT, because those are the channels that include people from other companies. So we're like, for now, let's just limit the blast radius of AI on Slack to inside the company, right? No AI is allowed post to anything that writes, whether it's email or Slack or anything like that, with anything that looks like a social security number, a phone number, an address, you know, anything that resembles PII.
20:12So you sort of filter that stuff out. You basically say, If it's attempting to do that, reject the attempt. So there are some very broad rules you can create. But then when you start getting into the sort of the more narrow rules, if you have a specific, like I have an agent that after I do a sales call, it goes to my calendar, pulls who was on the call, goes to Zoom, gets the transcript, summarizes it, It goes to Salesforce and logs the call with the folks who are there. AIs are not, because they're not determinative, sometimes they're unable to find what they're looking for in Salesforce. So I allow my AI to create this call log, but I don't allow that particular AI to add new contacts to Salesforce.
21:09Because what I found in the past is that sometimes it will say, oh, that person's not in Salesforce. I'm just going to add them. They actually were in Salesforce. They just didn't find them. And what I don't want is 20 of the same person showing up in Salesforce. So I'd rather not complete the task and let me know and have me help it find the person than it goes and makes a bunch of nonsense in our Salesforce instance. And that's a specific thing there. Whereas a different task I have, which would be, for instance, I attended a Wall Street Journal conference last week and I got a list of people who were at the conference.
21:45I wanted to make sure all of them were in our sales force and I knew most of them probably weren't. So I was happy to have this agent go through and actually create contacts for each of them. Yeah. You talk about a difference between safe read actions and destructive write actions for agents. Is this an example when you say, yeah. Absolutely. And the thing about writing is again, I believe that for an agent to actually be an agent and be useful, it has to write. And when people talk about MCP and they talk about the connections in collateral, the terms being used for what is ultimately MCP, most out-of-the-box connections don't allow writing because they don't have the governance.
22:42So if you sign up with Claude and you say, okay, connect to my calendar, it won't actually create calendar events for you. It'll just tell you what's there because they don't have built-in this governance. And so MCP, you sort of touched on it earlier. What MCP is, you have an underlying API which generally can do everything. It has, as long as you have the access and you are allowed to use those capabilities, an API can pretty much do anything that you could do with the user interface. When you create an MCP, the person creating that MCP chooses to expose a subset of that set of capabilities to the model.
23:32So you might have many, many, many, many things that can be done. Some are reads, some are writes, some are deletes, some are drops. They're fairly catastrophic things that one can do programmatically. And the person creating the MCP will rationally say, out of all those things, here is the subset I want to expose. So out of the box, most of these MCPs only expose things that do reading that can't write or overwrite or do things that cause problems because there's no governance that manages that. By using Barn Door or Venn, we provide MCPs that actually do have those capabilities because they come with the governance that allows you to turn on and off the things you don't want them to be able to do.
24:18Right. And how do you, is this a page of toggles? Yeah, so on Venn it is exactly that. It's a page of toggles for every single service that you're signed up for. In Barndor, it's a lot more capable than that because it's an enterprise product. So you can use the toggles. You can write in a language called JSON. You can write a set of very, very specific policies around it. And you can also do that not just through our user interface, but you can do it through our API. Because we believe that there are going to be so many of these agents out there that at a certain point, humans are not going to be able to create and manage all the policies that are going to be necessary.
25:03So you're going to have a series of, you know, whether they're AIs or programmatically driven systems that actually ultimately turn on and off these capabilities based on the context. Yeah. Is there a conversational interface given that, you know, LLMs are pretty good? We actually, yes, we have an MCP. So there is an MCP to Barndor. And so you're able to, using whatever conversational interface you prefer, you can use our MCP to do these various things. Absolutely. Yeah. And talk a little bit about some of the challenges with agents. I mean, what is context window exhaustion? Yeah, you know, that's been a big issue.
25:56And when you think about how your AIs work, the AIs are managed through these things called tokens, which are essentially a measure of how much is coming into the model and a measure of how much is going out. And I talked about the MCP. The MCP is essentially a tool and a user manual on how to use that tool for every tool that you have exposed. So a typical MCP for, let's say, Gmail might have 40 or 50 or 100 different tools, each of which comes with a very significant manual that tells that AI how to access that tool. And so if you open one of these, every time that you say, I need to use this MCP, the first thing it does is it brings in all of those tools and all of those user manuals, which burns lots and lots of tokens, even though you're not going to use most of them.
26:54Let's say you then turn on two or three more MCPs. Now you have calendar, you have mail, you have Slack, you have documents. now you've got so many tools and so many user manuals that you have already used up all the tokens your window allows before you actually do something and that's context window exhaustion and it's why when you and the other the other challenge by the way is with all of these tools it's just confusing it's like walking into home depot and you see a sea of tools in front of you you don't know where the hammer is you don't even know what a hammer is or how to use you're like well, I'll grab the nearest thing.
27:32And what you find in the models is you'll say something like, go to Salesforce and give me information on these three opportunities. And it will say, I will go to your Google Drive and get you information on it. Because it's overwhelmed. And so what we've built is what we call Tool IQ. To the model, all the model sees is a single MCP, and that's ours. and ours then abstracts all the different tools that you have hooked up. So the model says to us, hey, I'm trying to do this. And our tool writer says, okay, if you're trying to do that, here is the small subset of tools you need to go do that. And here's how you use them.
28:14And the model says, thank you very much, makes the call and off it goes. And it's sort of like, you know, you have a task, a chore to do at home and you just get the little tray of tools you need to do it. You're not bringing all of Home Depot with you, right? and so because of that you save a lot on tokens but you also get better response because you're actually having this sort of smart layer in between that that abstracts these tools and makes them more useful for them yeah and then then you're not wasting so much of the processing power. Absolutely. Absolutely. Yeah. Uh, the, uh, you know, we're at this, uh, inflection point.
28:56I, in my mind, particularly because of open claw. Absolutely. That was a huge, huge event for us. Yeah. Do you think, I mean, it just brought the power of agents into some segment of the public consciousness. Can Barndor or Ben run on top of OpenClaw? Absolutely. So OpenClaw by itself doesn't talk to MCP. Part of the ethos of OpenClaw is it shouldn't need to, it should just write whatever program it needs and go off and do whatever it wants. That's sort of the ethos. However, there is an extension to OpenClaw called MCP Ops, or MCPops, as some people call it, which essentially is an extension for OpenClaw, downloads with OpenClaw, and allows OpenClaw to access MCPs.
29:54And so that MCP Ops thing can, of course, access any MCP, including the Venn or the Barn Door Tool IQ MCP. Yeah. A lot of people, me, for example, have been using OpenClaw through something called MyClaw AI. I don't know who owns that. I don't know who did it either, but it's a lovely, it's the cloud for OpenClaw, right? Yeah. And it's just simplifies the, it's installed in the cloud. You just log into it rather than trying to set it up on your own IDE. uh does uh barn door or ven work with my i assume so because it's just a regular version of of open claw and it should be able to run mcpops so i i haven't tried it personally but uh i don't see why it wouldn't yeah and and so what you're saying is that yeah agents are great there's tremendous promise enterprises are scared of them uh and may be experimenting at the margin and that's largely because of a trust and control issue.
31:09And Barndoor provides a layer of control that then provides trust. Is that right? Exactly. Exactly. And I was at a conference with about 50 enterprise CIOs and CISOs last week, and very large companies. And they're all on this journey in various levels. And it's actually interesting to see. There's a lot of companies, even companies that have been around 50, 100 years, that have very active and capable IT teams who are actively experimenting with and building MCPs both to SaaS services they use but also to internal systems. And there's definitely a demand for this. And it seems this is an event I go to twice a year.
32:00And the change between six months ago and this past conference, it's the front of everyone's mind. Absolutely. Yeah. You know, I was at a conference last year with a company called, it was a customer conference for a company called Boomi. Oh, sure. yeah that is integration boomy actually i believe boomy now owns smashery which is the company i found it i think we sold it to intel and intel sold it to tibco and i think tibco may have sold it to boomy i'm but okay obviously not involved anymore but i think they own it yeah so i'm So, you know, that is a platform that connects applications, data, devices, cloud, on-prem.
Read the full transcript
32:58Where would Barndoor sit? So, Boomi would provide the API management layer. I see. It would provide the API that we would sit in front of. Now, Boomi will also, and all of the API management folks are going to have some version of MCP that they do. But the kind of fine-grained access control that I was describing earlier, that's out of the realm of the traditional security and API management world. It's a different level of combining identity with the systems and also the fine-grade access control that really reaches to the management of each of these individual systems. Your CISO doesn't know from Salesforce.
33:46They don't know what someone should or should not be allowed to do specifically in Salesforce. They need a broader level of management for each of these various tools to be governed as they need to be governed in order for successful and safe agent deployments to happen. Yeah. So this level or this layer in the stock that Barnador provides, how stiff is the competition for you? and because this is absolutely needed for enterprises to use agents, do you see an industry forming around this? So I see a few things forming, right? I see the way I look at the landscape in our world. You have incumbent companies, whether they're API management or identity or packet security or whatever.
34:59There is incumbent companies that certainly need to present with something that seems credible here. But by their nature, by the nature of the way incumbents operate, they're going to attempt to sort of bolt this on to the underlying infrastructure of what they have. And what we're finding in the POCs we do, and when we're compared to these, is that those just don't go far enough in creating the kind of management layer that you need. So that's one element, and I think we compete very well with that. And the other version is you have a series of developer tools that are out there. And the concept is you're building some kind of an AI application.
35:44you can have the connections and the governance you need inside your application to manage this. And there are various people who are doing versions of that. The challenge with that are twofold. One is no one in their right mind really trusts AI companies to govern themselves. I think that at this point, we realize that the incentives they have to move quickly are not necessarily consistent with the incentives around governance. But it's also that no CISO or CIO wants to have hundreds of systems in their company that are individually governed. Because every time you bring one of these things in, now you're once again setting up the connections, once again setting up the rules, once again setting up the governance.
36:41And what we've learned from OpenClaw is that new things come along all the time that we're not expecting. And that from that, we're going to have to be able to try and swap things in and out quickly. And that's not something that we do. In the piece I wrote and the conversation we had earlier, I mean, we were talking about how early days this is. We're right at the very beginning, probably, of agentic AI in the enterprise. Probably less than 1 % penetration in production of large enterprises. why do you think 2026 is is an inflection point beyond open phones i think i think that as as humans we're pattern matchers and so the more we see the more we want to do and when ai first came on the scene the folks who were using it to actually do stuff were coders because that's the one job in the enterprise where you actually do spend your time chatting with PhDs, right?
38:03Your code doesn't work. You go to your CTOs, probably a PhD, and say, fix my code. And they do. And now you have an AI that does that for you instead. Great. Then you had, so that was an initial use in that world. And for the rest of us, it was essentially started off being glorified search, and then it became something which has become a part of our lives, but it's still more around a conversation and suggestions of things humans do. Well, then the coders figured out with MCP and such that they could actually get these AIs to not just help them fix their code, but create new code. And that became a thing, and we've all now seen the benefits of that, and that's radically changed how software gets developed.
38:55But that still hadn't yet started to happen elsewhere in the enterprise. And now we're seeing knowledge workers, marketers, salespeople, HR people, attorneys. We're seeing all kinds of people starting to embrace AI to actually get work done. It's new. But the more everybody sees that, the more everybody wants that. And so it's just taken until now for people to see essentially what the potential is and actually see that potential realized. And once they start seeing that, they want it on their own. Yeah. And do you think, how quickly do you think that adoption curve or steep that adoption curve is going to be?
39:43And as a company, I mean, are you seeing a lot of uptake or do you – Definitely our cadence is increasing, which is nice. It's good to see. And I would say the steep uptake really is moments that people see someone solving a problem that they themselves have. So, you know, I saw an article somewhere recently about how you can use AI to help empty your massive inbox of old emails. And we're seeing early users of Venn doing a lot of that. Right? And so, you know, there's when people see that as an example, they sort of go and start doing it. And so part of what we're going to be doing with Venn is watching what folks are doing.
40:42We can't see the actual data. We can't see what you bring through it. But we can see the patterns of use and say, oh, this is probably what folks are doing. And start bringing those to the surface and giving people ideas of how they can use this technology. And if you show someone what they can do with the tool, that's way better than just saying, here's a tool, go play with it. Yeah. On the enterprise side, how advanced, what kinds of processes do you see that could fall to agentic AI? I mean, we talk about, in all of my conversations, it boils down to sort of the daily grind of the knowledge worker, you know, filling out forms, you know, cleaning up or tracking your email, inbox, writing responses.
41:45and there is a lot of talk about you know the the agentic enterprise where where more complex processes are handled by ai but i've never really heard what those processes are yeah yeah so what what do you see what would be an advanced yeah um i'll start with I was on a panel one-on-one chat at a conference last year with someone who might be a former colleague of yours, Quentin Hardy. I don't know if you know Quentin. Oh, yeah. I know Quentin very well. Yeah. So he's a dear friend. And we were on this talk together. What Quentin said was, you want AI to take on the tasks that you have in your job that you never want your kids doing if it's their job.
42:41and uh and and you know so it was that was a good start you know it's sort of like what is it that i hate doing that just makes it and you know as a knowledge juror it keeps me from doing the stuff i really want to do um and and start with those things so that's that's one version of it but i think it also goes further than that. And that is that so much of what we're seeing in AI and agentic AI in these early days are around solving things humans are doing and making it faster and maybe a little more accurate and making it so humans don't have to do it and sort of being a faster human, which is sort of the faster horses thing, the old adage from Henry Ford, right?
43:31And And that's great, but what I think is much more interesting are doing the things that humans aren't and can't do because they're not in our nature to be able to. And so we see it is early days, but it really comes down to understanding what AI is good at and what it's not and sort of figuring out what should be done programmatically, figuring out what should be done non-deterministically by these models, bringing those tasks together and creating new workflows based on them. And it's not the workflows. You look at a Zapier. Zapier is all about, again, automating things we as humans do. It's a lovely product.
44:13We use it all the time. But again, that's faster horses. and we want to and I think what we're going to see exposed in these uh you know in the uses both of Venn and Barndor are things that folks who understand how to sort of abstract a problem and maybe solve it in a different way are going to go off and try to do and succeed in doing because this technology exists and that's that's a lot more important or interesting to me yeah Yeah. I mean, and, and, you know, I'll edit this. So if, if you don't have an answer, that's fine, but can you think of a biz critical business process that, that maybe enterprises you've spoken to would like to automate with agents?
45:05Yeah. So we're talking to a major hotel chain right now, and they want to be bringing this capability into their guest services. So if you think about it, if you stay at a fancy hotel, yeah, that's pretty and there's nice things around. But what really makes the difference is personalization. personalization. And today that personalization is, oh, they have a nice thing in your room or I've had hotels that found a picture of me and my wife and it was our anniversary and they put it in the room, right? That's lovely stuff. But if you can really start personalizing and really start understanding, particularly for returning guests, how they interact with the hotel, how they interact with the systems and anticipate their needs, you can do that in a way humans can't possibly do manually.
45:59And so it comes down to all the things. You think of what AI has been being used for the past five, 10 years really, really effectively feeding us advertisements, right? It's been really, really good at that. Well, we don't necessarily want to be fed advertisements. We want to have really amazing experiences. And as much as the ad companies say, we're giving you a great experience, they're not. But there are so many services and goods that we buy that can be brought to us where we are in the way we want it to be. that companies that succeed in doing that and unlock the data they have and then empower agents to act on that data are going to win based on just giving us humans a better experience.
46:54Yeah. You talked about HR department for AI in regards to IT departments. I mean, who is going to be running agents in the interview? Is it the IT? It's a good question. You know, I now go to chief AI officer conferences, which weren't a thing two years ago, right? So right now, it's the person that the CEO went to and said, you make AI happen, right? And that's, that's, that's, whoever that is, it's often a CIO or a CTO or someone in that world. It is HR sometimes, it is line of business. There's one company, it's a pal of a CEO who had retired a few years ago and was brought back to lead the AI efforts.
47:44So it can be just about anyone. I think over time, it will straddle these organizations kind of in the way that the CIO does. I mean, at most companies, IT has to understand and straddle different parts of the company, and it means different things to different parts of the company. And I think this is going, as does HR, and I think that you're going to see companies that really, really embrace this are going to have AI at the table. Because, you know, when I talk to folks who work for me or in companies I advise, we talk about the difference between a manager and an executive. And a manager has a department to run and their job is to make that thing run really efficiently.
48:41And their focus is largely on delivering the thing their world has to do. An executive has to have the perspective of the entire company. It's often the executive's job to make their own lives more difficult in order to make the company as a whole succeed. And to me, when people start understanding and managing at that level, that's when they become an executive and stop being a manager. And I think that for AI to be successful in the company, the people who are sort of empowering it and deploying it and setting the rules about it and governing it need to have a pretty broad understanding of what's happening in the company and need to understand where more risk can be taken in order for higher reward to happen where it can't be.
49:33and sort of, you know, it's not one size fits all across the company. That's one thing. And the other is you can't expect all the humans in your company to wake up one morning knowing how to make AI hugely successful. We talk about, you know, 95 % of AI projects fail. It's because the project was here, use AI. We now have it. We have a deal with open AI now. You can use it. And people didn't know what it was. It looked like a search box. What do you do with that, right? And so, of course, it failed. And so, you have to also, across the organization, really find and promote and celebrate the people who figure out how to take the business challenges a company has and apply these new tools and technology to solving them.
50:22And that's not everyone in the company. That's right. Yeah. I, I, I, I talked to, uh, BCG periodically and, and their head of their North American tech practice just had an article on LinkedIn about what, what he calls agentic quotient, which is kind of like IQ or EQ. You've got to find people in your organization that have a high. That's a great term. I like that. quote yeah i will steal that to manage these things yeah currently there is uh infrastructure uh to govern ai agents there is uh and and what are you does barn door do to improve on that infrastructure already i mean we've already talked about it think of how you govern humans, right?
51:19So you govern humans, you have certain people whose job it is to let them in the building and let them do various things. You have certain people whose job it is in systems whose job it is to decide what they're allowed to access and when and monitor what they're doing. We are that for the agents, right? And so there are a lot, there are various folks out there who are trying to, companies out there who are trying to manage and govern AI sort of by getting inside its head, its metaphorical head, and understanding what it's doing and governing that. And I don't think that that's very easy. I don't think that you can necessarily do that anymore.
52:02You can get inside my head and govern me. So with a lot of this, I think the governance really needs to be, you know, understand what's going in and what's going out and govern that. That's a big part of it. That's a part that we manage, right? And then there will be other elements that will be managed in terms of adaptations of other things that we have been managing in security for a long time. And most decent companies that are well run have various levels and vectors of security that they deal with because they understand that you only have one security to rule the ball. And what's different with this new concept of AI and agents, it's kind of different than what came before, is that traditionally security's main role was to keep bad people from outside the company out or keep people inside the company from doing things they're not allowed to do.
53:08And that's still really, really important. But there's this new thing where someone who's inside the company and is allowed to be there doing something they're allowed to do with a tool they're allowed to use and bad things still happen. And that's a different vector that has not been the realm of the IT and security folks before. And in order to manage that new concept, that's why new tools are necessary. Yeah. Okay. You know, I'm going to ask a couple of questions that, you know, maybe you're not prepared for, but you straddle creative, the creative world and the sort of hardcore tech world, which are very, very different worlds.
54:00Does any of this apply to theater production at any level? Absolutely. And so, you know, art and creativity have been embracing technology in various ways for a long time. You know, Frank Garius famously said that without computers, he could never have designed the buildings that he designed, right? And so AI is being used today in theater, certainly in marketing and helping us find new audiences. It's used in helping us when you're designing things, whether you're designing sets and lighting. There's a lot of specifications, a lot of data that's involved. You know, it's interesting. You go to a Broadway theater and at the end of every show, they load everything out.
55:01It's an empty building, essentially. When you load in a Broadway show, one of the first things that's loaded in under the stage is basically a data center. And you walk under a Broadway stage and you see racks and racks and racks of servers and computers. because it's a very, they're controlling the lighting, they're controlling the sound, they're controlling the set, all the automations on the stage, all those videos. The technology involved is staggering. And so managing this technology and sort of improving it, and I have a good friend who's a two-time winning Tony lighting designer. I sat with him through tech rehearsal last year for one of his Broadway shows, and his screens across all the things he's seeing, we're sort of going through what each of them was.
55:53And he's like, yeah, two years ago, none of this existed. And the technology continues to evolve, particularly on Broadway because it's so expensive. And so it's so risky, particularly doing musicals, that you have to use whatever tools are available to you in order to make these things successful. And you have to be able to model things and you have to be able to try things. and you have to be able to synthesize an awful lot of information that comes at you very quickly. I was involved in one show. We did an out-of-town trial. We gave everybody surveys. We looked at the reviews. I used to put all that stuff in chat and had it summarize it for me, right?
56:37And that was incredibly helpful. And I was chatting with a director, a longtime Broadway director about it, And he said, yeah, you came up with basically the same conclusions we did after three days in Post-its. Right. And and so, you know, that is a very useful way to to make use of this technology and creating art. Yeah. And what about agentic AI? You know, it's early days, but I would be, it would not surprise me if there are elements of managing these services and in particular managing the safety issues, right? That there's a lot of these systems. I see enough Broadway shows. Every 15 or 20 shows, they stop the show in the middle of the performance, get everybody off the stage because something isn't moving right.
57:38And managing and monitoring these systems, every show before the show, they turn on every light individually and make sure it's working properly. They move everything. But all of these systems kick off data. And understanding and managing this data and proactively scheduling maintenance and scheduling replacements of equipment and things like that to make sure everyone stays safe and make sure the show stays consistent the way it was opening night, I definitely see that coming. Yeah. And you guys are a platform company. Are you also a service company? I mean, do you consult with… We have people here whose job it is to come and work with our customers and bring them ideas.
58:31So back in mastery days, we would run, we had all these companies doing APIs, and many of the companies didn't really know how to spell API, let alone why they were doing them. And so we would come into those companies and essentially run hackathons. We would come over the weekend and get every company together with some food and some beverages and some smart people and some coders and some non-coders and say, okay, you've now got this cool new thing called API. Let's find real business solutions to go solve with it. And we have folks who do the same thing with that here as well. Yeah. Okay. Well, Oren, if people want to explore this, they should go to barndoor.ai.
59:12Barndoor.ai. Barndoor.ai. And if you want to play with your own personal version, that's at ven.ai. And that's ven.ai. Where did the name Barndoor come from? Well, you know, we have a habit in our world of closing the barn door after the horse is already out. We felt that maybe it was early enough in the agentic journey that I felt that for once we had the chance of having the barn door in place before the horse got out. And so that's why I named the company. That's good.
From the publisher
AI agents can now connect to every tool your employees use. The problem is that connecting them and trusting them are two completely different things, and most enterprises have figured out the first without solving the second. Oren Michaels, co-founder and CEO of Barndoor AI, joins Craig Smith to explain why that gap is the defining challenge of the agentic enterprise era. His framework is simple and sharp: agents are like enthusiastic interns. They will absolutely do something when you ask them to. Whether it's what you intended is another matter, and when an agent can act across Salesforce, Slack, email, and calendar simultaneously, the blast radius of a misunderstood instruction is far larger than anything a human intern could cause.
The conversation covers the 100,000 agent problem - the reality that each agent handling a discrete task needs its own set of rules about what it's allowed to do, and that number scales to a size no human team can govern manually - and why traditional identity management systems were never built for the failure modes AI agents create. The new threat isn't bad actors getting in; it's authorized people using allowed tools with agents that still do the wrong thing. Barn Door's governance layer sits between the agent and the tools it can access, specifying exactly what each agent is permitted to do in each context, and Venn brings that same capability to individuals who want to understand what's possible before their organizations catch up. This is one of the most practically useful conversations available about what enterprise AI governance actually looks like.
Subscribe to Eye on A.I. for weekly conversations with the people building and deploying the future of AI.




