In short
Why “agentic-first” startups will not disrupt enterprise IT as fast as expected, due to scaling, security, compliance, reliability, and the need for modernization foundations.
Guest background
Chris Lovejoy is global strategy leader at Kyndryl (spun out from IBM ~4 years ago). Kyndryl focuses on IT modernization, security/resiliency, and data/AI, including agentic AI and an AIOps platform that evolved into agentic workflows.
Key claims
Most enterprises are still in pilots, not large-scale production. Agentic AI is costly, insecure/unreliable, and not scalable yet. Enterprises need “rails and tracks” (infrastructure + data + monitoring + registration) before horizontal adoption. By ~2031, about half of traditional IT systems administration tasks may be handled by agentic AI, with humans in/over the loop.
Notable examples
ITIL-based agentification (problem/incident, configuration, patch management); digital-twin testing of agents; “crypto relics” in legacy COBOL; patching vulnerabilities can break legacy context.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOIntroduction to Agentic AI
0:00 to 0:38
Learn about the rising trend of agentic AI and its challenges in enterprise use.
“You know, Agentec AI is a hot new thing.”
Kindrel's Focus Areas
1:03 to 3:01
Discover Kindrel's main areas of focus, including IT modernization and AI.
“I am the global strategy leader for Kindrel.”
Challenges in Deploying Agentic AI
3:01 to 3:44
Explore the barriers preventing successful implementation of agentic AI.
“And we're seeing the benefits of the capabilities, you know, but not in production.”
Kindrel's Role in AI Integration
3:44 to 5:27
Understand how Kindrel assists enterprises in integrating agentic AI.
“And actually, I'm just going to ask before we get too far into it.”
Vertical vs Horizontal Use Cases
5:27 to 7:20
Learn about the different applications of agentic AI in enterprises.
“I'd say that what I see is vertical use cases.”
IT Service Management and Agentic AI
7:20 to 9:10
Examine how agentic AI can transform IT service management processes.
“And so where we're beginning to integrate or work with customers is in thinking about IT service management.”
Building Agents and Infrastructure
9:10 to 11:47
Discover how Kindrel builds agents and the infrastructure needed for AI.
“just give me one of those processes that would be ripe for agentic adoption.”
Agentification and ITIL Processes
11:47 to 14:00
Learn how Kindrel maps ITIL processes to agentic AI for efficiency.
“a direction that we're thinking about right now.”
Exploring Agentic Workflows
14:00 to 15:00
Learn about how agents can integrate into workflows and the importance of orchestration.
“through the agentification of those processes right now, and we have agents that will help get to various levels of maturity within that context.”
The Kindrel Agentic AI Framework
15:00 to 17:00
Discover the components of the Kindrel agentic AI framework and its features.
“So part of it is the policy and sort of digestion and agentic creation engine.”
Show all 30 chapters
Addressing Security Concerns in Agentic Systems
17:00 to 19:30
Understand the security challenges faced by agentic systems and the importance of context.
“And, you know, I've got OpenClaw running on this laptop on my main computer, and I know it's dumb and I keep on meaning to move it.”
The Complexity of Legacy Systems and Compliance
19:30 to 22:20
Learn about the challenges of interacting with legacy systems and the role of compliance.
“So then you bring in generative AI, right?”
Challenges in Modernizing Enterprise Systems
22:20 to 24:40
Explore the difficulties enterprises face when modernizing their systems, including COBOL.
“It's good and also, you know, it's really painful at the same time.”
The Role of AI in Code Refactoring
24:40 to 27:40
Examine how AI tools are utilized in the code refactoring process during modernization.
“because this is a part that, you know, so your folks are listening to Agentec AI, and I'm going to wax rhapsodic about this issue.”
Managing Agents in the Workforce
27:40 to 28:00
Discuss the implications of managing hybrid teams that include numerous agents.
“It doesn't make the, you know, the modernization program, it makes it less ugly.”
Managing Agents in a Hybrid Workforce
28:00 to 29:20
Explore how management structures will evolve to oversee agents in organizations.
“So, so you have this orchestration layer, you're building the agents.”
The Role of Specialized Management Teams
29:20 to 30:50
Understand the need for specialized teams to manage agents effectively.
“So you have one team that does kind of security management, which is security health checking and compliance and audit.”
Decentralizing IT: A New Approach
30:50 to 33:10
Discover the shift towards decentralized IT roles in various business functions.
“Other people say that, you know, you just need to upskill the entire organization so that everybody is competent in working with agents.”
Current Trends in Agent Adoption
33:10 to 36:50
Learn about the acceleration of experimentation and adoption of agent technologies.
“implementing and running the tool just as if they would run like Salesforce.”
Predictions for Agentic AI in IT
36:50 to 37:40
Gain insights on the future impact of agentic AI on IT tasks by 2031.
“And then humans will be in either in the loop or over the loop, if you will.”
Challenges for Agentic Native Startups
37:40 to 40:00
Examine the challenges faced by startups in integrating agentic AI into existing systems.
“I'm not 100 % sure what those, you know, what those segments are going to be right now, but I do think that that will happen.”
Security Risks of Integrating Agentic AI
40:00 to 42:05
Understand the security risks associated with adopting agentic AI systems.
“Until then, the bigger vendors are going to continue to win in the market.”
Understanding Agentic AI in Security Context
42:05 to 43:18
Learn how agentic AI can help in identifying and resolving security threats.
“Not, you know, not limited to, you know, the fact that AI is now available to, you know, the threat actors.”
Common Misconceptions in Cybersecurity
43:18 to 45:38
Explore the frequent misconceptions in cybersecurity incidents and their causes.
“but a lot of what we think are cybersecurity issues sometimes are not.”
The Role of Agents in Security Monitoring
45:38 to 47:40
Discover how agents monitor software systems for vulnerabilities and the need for human oversight.
“of crawl through a system looking for vulnerabilities as sort of virtual white hat attackers is that what they're called, you know.”
Challenges in Cybersecurity Workforce Development
47:40 to 52:52
Understand the challenges in training and developing cybersecurity professionals for emerging technologies.
“You know, what, basically what you're saying, It's not on this, but generally that fire and forget agents are not in the cards now.”
The Need for Practical Education in Cybersecurity
52:52 to 55:44
Learn about the importance of hands-on experience in cybersecurity education and training.
“But because the number of threats is increasing, just because the number of like line one events that you have to chase is decreasing, you still have a lot of stuff.”
The Importance of Reading
56:00 to 56:10
Explore the decline in reading habits and its implications.
“You know, Craig, thank you so much for the time.”
Reflections on Knowledge Acquisition
56:10 to 56:40
Discuss the contrast between traditional reading and modern media consumption.
“That's a frightening, frightening trend that people don't read books anymore.”
Living Through a Unique Era
56:40 to 56:50
Contemplate the significance of the current technological era.
“I think, you know, we're going to all be looking back at this time and saying, wow, I can't believe I lived through this.”
Transcript
Automatic transcript. May contain errors.0:00You know, Agentec AI is a hot new thing. Every large enterprise in the world is trying to figure out how to use it. It's really easy to build really cool things. It's really hard to run them at scale securely, compliantly, resiliently, reliably. My prediction is that by about 2031, about half of all of the kind of the traditional IT systems administration tasks, the line one, line two tasks, they will be provided by agentic AI and then humans will be in either in the loop or over the loop, if you will. so chris it's great to finally talk i know that this has been in the scheduling scheduling uh mode for for months now i usually start by having you introduce yourself and give some of your background if it's relevant and what you're doing at kindrel Sounds good.
1:04So my name is Chris Lovejoy. I am the global strategy leader for Kindrel. Kindrel is a company that is fairly new on the scene. We've been around for about four years now. We're actually a spinoff from IBM. So about four years ago, IBM took the organization that did a combination of strategic outsourcing and IT integration projects spun it out and we became a publicly traded independent organization. And so today we are really focused in three, I'd say, major areas. One is in IT modernization programs. So think about that as, you know, modernizing your legacy infrastructure data centers, whatever the case may be, moving those workloads to the cloud.
2:01Second area is in and around security and resiliency, which is kind of my domain or historic domain. And then the third is really specializing in data and AI and bringing, you know, generative, agentic, all forms of AI to, you know, enable customers new ways of working, if you will. yeah and on um exactly on that point um you know agentic ai is is the hot new thing uh i would i think it's safe to say every large enterprise in the world is trying to figure out how to use it Yes. There have been many pilots over the last year, but very few systems have gone into production, at least in a way that's of any scale that's significant.
3:01You know, we're coming out of the age of experimentation and, you know, where we've all been dabbling in using AI and, you know, agentic AI in particular now. And we're seeing the benefits of the capabilities, you know, but not in production. We are finding it very costly. We're finding it somewhat insecure. We're finding it to be unreliable. And most importantly, it's not scalable. Oh, and if you're in Europe, you know, there are sovereign concerns as well. So, you know, there are some things that are preventing us from going into what I'd call the age of industrialization around agentic AI. And so I think, you know, it's going to be a little bit that we're in this transition period and we'll get there eventually.
3:50Yeah. And so what are those? And actually, I'm just going to ask before we get too far into it. When you're talking in your role to enterprises about Agentex systems, what is Kindrel's role? Are you building stuff? Are you acting as a consultant? What's Kindrel doing in those conversations? So quick analogy, if we were to say that, you know, there's a bullet train, bullet train can go 150 miles an hour and it's sitting on tracks that limit it to about 30 to 60 miles per hour. And this is actually a true story about, you know, trains in the eastern seacoast of the U.S. Legacy infrastructure set up in 1930s, you know, keeping us back.
4:48In that context, what do we do as Kendrell? Our job is to build the train so we can work with the customer and build the agentic AI, that workflow. The other thing that we do, and this is where we really specialize, is we will modernize the infrastructure on which that train is going to actually operate. So our real focus is on preparing the IT infrastructure layer, getting the data layer ready, making sure that you've got all the monitoring, the registration, all the stuff that one would need to actually use agentic AI at scale. That's where we play. Okay. And are you seeing any enterprises adopting agentic AI at scale yet?
5:33It is very rare. to see one at scale. I'd say that what I see is vertical use cases. So for instance, there's some use cases like know your customer or within the healthcare space, invoicing, or if you have a sales cash order process that you can automate using Agentic AI, That seems to be successful. But those are vertical use cases, horizontal use cases where there is an integration of AI workflows across the business horizontally. I have yet to see that. Yeah, yeah. And that's the big promise, right, that you take a business process or workload, break it down into steps, decide what a genetic AI could handle and what a human has to handle and presumably speed up the whole process.
6:32Let me ask, are you talking to any enterprises about that more horizontal application? We are, as a matter of fact. It's beginning. And I think, you know, for most, it is interesting as to what they're looking for when you're talking about the horizontals. A lot of our customers we're talking to right now, obviously, there's a lot of economic insecurity. And so there's sort of this combination of nobody really wants to spend capital because they're worried. And they're not only worried about spending the capital, but they're being pressured by their boards to implement AI. And so there's this combination of, I don't have any money, but they want me to spend money on AI.
7:19So, you know, what do I do? And so where we're beginning to talk to customers and because we're beginning to see some success on our own is we've been, you know, four years ago when we came out of IBM, we created an AIOps platform that enabled us to manage, you know, our, manage our customer systems with a high level of automation. Over time, we've begun to agentify. And so where we're beginning to integrate or work with customers is in thinking about IT service management. So those are all of the processes that are required to manage an IT infrastructure. So we've got a kind of a maturity model, if you will, that allows customers to begin to integrate agentic AI to automate all of those IT service management processes.
8:13Now, the benefit is that it radically reduces the cost of IT service management, in some cases up to 90%. And then you can take those funds and you can use those funds to do the modernization. So it's like a modernization dividend, if you will. So that's where we're really beginning to see customers looking at that from a horizontal. But I'd say it's a bottoms up. it's going to take some time before once you get the foundation ready you know the tracks laid if you will before you can have that the uniform approach to integrating from a vertical perspective yeah yeah and that's interesting that's what i've heard too that a lot of the early applications are in the the it service area partly because those guys understand that uh and it's it's easier the change management's easier.
9:07When you talk about IT service management processes, just give me one of those processes that would be ripe for agentic adoption. Sure. So problem and incident management, configuration management, patch management, those are all good examples of things that can be agentified. Okay. And is Kindrel building that you said that you do build the infrastructure? Yeah. In that case, let's take that case of IT service management. How do you go about that? I mean, do you look at the process, break it down, decide what can be identified? And then do you build the agents? Does the customer build the agents?
10:06Do you recommend off-the-shelf agents? How does that work? Well, today what we're typically doing is so a customer, when they work with us, we have our processes, we have very, very, very well-defined runbooks for how we would implement those processes. So the ontology is defined. And then through AIOps, we also have a lot of information about how that process actually is executed in practice. So we can see the environment in which it executes, what the problems are, et cetera. So what we do is we have what we call an agentic framework and a policy kind of ingester. So what we do is we take that process and we take the data, the insights, we feed it into our kind of engine that crunches the workflow and crunches the insights and builds the agent.
11:01And so we build those agents that allow for the sort of the automation of the process. Now, what differs from customer to customer is how much true autonomy they want to give these agents. So there's this question of, is it an autonomous agent with a human on the top or is it an agent with a human in the middle? There's a big difference there. And so we're seeing some differences there in kind of the way customers want to see those checkpoints be instantiated. But we will build those agents and then we will actually run those agents. We'll register them and run them on our platform. We are beginning to look at running our agents on other people's platforms as well.
11:46And not to be announced, but this is, you know, a direction that we're thinking about right now. Yeah. And you said at the beginning that you've spent, you guys have spent time integrating, or maybe I misunderstood, but integrating agents into your workflows. Can you talk about how extensive that has been, particularly on the horizontal? You know, it's always a, it's a funny thing. We were just talking about this the other day. It's like, how do you actually describe this? Because the definition of an agent is so different. Is it, you know, is it like the orchestration agent or is it the incremental agency?
12:32It's so hard. is the number of tokens that are digested. What I would say is go back to the kind of the ITIL processes. So there are 34 ITIL processes. Of those 34 ITIL processes, there's a subset figure 20 that can be identified. Of those 20, we have... And just define ITIL for... Oh, I'm sorry. I'm sorry. So IT infrastructure library, think about that as the best practices, the implementation blueprints, and the maturity model for how you manage IT. So when you're in kind of the business, you're an IT administrator, you know ITIL. That's kind of like your Bible. You know, you're going to go and patch a system.
13:19ITIL tells you, okay, if you automate this, then you've gotten to ITIL for level three maturity because you're using this level of automation. Very well constructed and defined. So we think about everything within the context of ITIL working toward an ISO certification. So ISO becomes kind of the pinnacle of how you operate. So when we think about agentic AI, we are breaking down those processes into kind of discrete components that are mapped to the IT infrastructure library, and then we agentify those processes. So in answer to your question, we are working through the agentification of those processes right now, and we have agents that will help get to various levels of maturity within that context.
14:15Yeah. And are your agents all based on, on like the granite models or are you model agnostic? Can you go out and find the best model or do you, do you have models in house that you built that are underlying, that are the brain, so to speak of the agents? Yeah, our models, we tend toward open source. So anytime that we can use open source models, that's what we will use. However, you know, there is an IP question for customers and sometimes they want us to use their models. So it really just depends on the customer with whom you're actually interacting. Right, right. And these, you were talking about, you know, there's a big difference if you have a human in the middle of an agentic workflow or on top sort of managing the agent or agents.
15:16uh which which uh do you have and have you built an orchestration layer that gives visibility and management tools to a human uh to to keep track of what the agents are doing what they're allowed to do and that sort of thing yes absolutely so that that is we have something we've we call the Kindrel agentic AI framework that was released, I think, about six months ago. That's exactly what it does. So part of it is the policy and sort of digestion and agentic creation engine. And then there's another component part of it, which is the orchestration engine. Now, think about, you know, in the orchestration engine, think about that as a tool which allows for a single enterprise to manage kind of agentic workflows.
16:16We've also got underneath that, we've got another capability we call Kindrel Bridge. So think about that as multi-tenants because there's a concept of reusability. So what we want to be able to do is take an agent that worked over here for this customer. Now we want to be able to reuse that agent over here for other customers because that allows us to scale the use of the agents in a trustworthy way. So bridge is the mechanism by which we will register. So discover, register, define the policy that needs to be monitored, monitor, and then enforce policy across a spectrum of agents that are operating across multiple orchestration frameworks.
17:03Yeah, and security is a big concern. And, you know, I've got OpenClaw running on this laptop on my main computer, and I know it's dumb and I keep on meaning to move it. But these, from what I understand, you know, agentic systems are full of security holes. uh so how do you address that or how do you uh you know instill confidence in your customers that that what you're delivering to them is secure you know it's really it's interesting um there was a there was an article today um one of the media outlets about um claude having done an exceptionally good job of, you know, identifying vulnerabilities within software.
18:03And it was kind of well touted. And I thought to myself, you know, it's good and bad, you know, on one hand, it's nice to know that, you know, these QA checking tools are improving over time. That's great. The problem is it gives people a false sense of comfort, right? Because, you know, it is, the challenge is context is, is, and this is where the human comes to play nowadays, is, you know, let's say you've got an agent that goes out and it checks to see whether or not there are vulnerabilities within a particular system. It finds, and I'm making this up, finds a communication protocol that is unpatched.
18:49So, you know, goes ahead and patches that protocol. Well, guess what? That protocol was configured the way it was because it's tagged to or it's tied to a 15-year-old legacy, you know, system in the back. And now you've patched it. Now it no longer works. And now you bring down the system. So it's not just a question of vulnerability. It's a question of context and configuration and the complexity of the underlying infrastructure. And as we started out with, most customers are working with a hodgepodge of stuff, multiple clouds, legacy stuff, some SaaS stuff. And the intricacy of that integration is where the problems lie.
19:30And that lack of understanding of how these things interact and why the context for why they are configured the way they are becomes really problematic and is why you need humans in the loop to make sure that you're not doing something dumb. Yeah. And I guess would humans necessarily be aware of of why that patch is not there uh i mean that you know people come and go and documentation is not always what it should be is rarely what it should be so uh yeah how how do you how do you know that context how do you communicate that context to an agentic system Therein is the question, right? So then you bring in generative AI, right?
20:23Because the knowledge base becomes very important. I think this is the interesting thing, is going back to you can't have a 150-mile-per-hour train on a 30-mile-per-hour track. I mean, these are the issues that are holding organizations back. And so when we talk about the need for modernization and the need for uplifting these legacy systems, what you're pointing out is exactly the practical reality of why you can't just dump agentic AI into your infrastructure and think it's going to work. Because it's more than just knowing where your systems are. You have to know why they were configured the way they were.
21:06Yeah. And where is that knowledge generally in an enterprise? Is it in people's heads? Is it in documentation? It depends. I mean, if you have a really good, you know, ticketing problem and incident management system, you know, ticket resolution system, oftentimes that history may be, you know, well-defined. Like if you've got a CMDB, service nail, that sort of thing, you'll have those records. Sometimes you don't. Smaller organizations won't. It just really depends on how robust your compliance has been. And let me emphasize that because this is the, this is the dual edge of, you know, compliance.
21:45It's like we say, you know, compliance is hard. Compliance adds complexity and cost. It also forces hygiene. And there is a reason why there is hygiene. There's reason why auditors look at the record keeping in and around things like, you know, managing critical infrastructure systems. It's because situations like this happen and you have to be able to go to the manual or go to the database or whatever it is so that you can figure out what happened and can unroll it again. But, you know, that's why I have a fraught relationship with regulation or love-hate, whatever you want to call it. It's good and also, you know, it's really painful at the same time.
22:26Yeah, so in modernization, when you talk about modernization, particularly with the IBM history, I go immediately to COBOL. What are the main challenges of modernization in general enterprises? Is it upgrading the language in which systems were built or does it have to do with microservices and containerization and all of that? Um, that's, that's a good question. Every, every organization seems to be a little bit different. You know, there's some common patterns. Let's say if you wanted to go to, as an example, SA, like you're going to be doing an SAP modernization. you know what you find becomes really really hard is so you know the sap you have to go from sap legacy into rise right so we all know we're going to have to move to rise and so there's a you know they're usually most organizations want to do like a two-step so they want to first move to the cloud and then they're going to move to rise after that and then what becomes the problem well the problem isn't necessarily lifting and shifting SAP the application.
23:50It's the networking. It's the provisioning. It's all of the stuff that is integrated into SAP that needs to be kind of reoriented to support a cloud environment. That becomes really painful. And so I'd say it depends. The answer is it really depends on the application environment that you're trying to move. and each of them have their own specific foibles, if you will, that you have to watch out for. Now, companies like ours who have the experience and what it means to lift and shift will know, like you have to look here, you have to look here, you have to look here, but it is, each one, as I said, is painful.
24:33Can I just add one thing though, because you're bringing up COBOL and this is, let's talk about quantum for a second, because this is a part that, you know, so your folks are listening to Agentec AI, and I'm going to wax rhapsodic about this issue. So today we have like 800 billion lines of COBOL code that are supporting critical infrastructure services. Of that, 400 billion lines of that code are supporting our COBOL code that was written 20, 30, sometimes 40 years ago. Now, most organizations would say, oh, okay, well, that's fine because I got a mainframe and the mainframe is the most secure, you know, and that's right.
25:18It is absolutely secure. Here's the challenge is it is built to be backward compatible. So when a mainframe runs, that 40-year-old code basically runs like it was 40 years old, right? So that, again, to keep that in mind. Now, why is that important? That is important because most of this old COBOL code has crypto relics in it. So what happens is the cryptography for that application is actually baked into the code and it doesn't actually manifest itself until it's in memory. And so there's really no way to find it. So one of the things that we're finding now is actually generating a lot of questions about modernization is actually going back to some of these legacy environments, COBOL, Java environments, where the cryptography was actually built into the code.
26:17And now you have to do this archaeological dig to figure out what are the crypto relics to find out now what do I do with those crypto relics? Do I have to refactor the application? Do I, you know, like what are the choices? But this is another one on the horizon beyond the Gen. I that we're all going to be thinking about. Anyway, thank you for letting me take a little detour. Yeah, yeah. Well, even in that, in reviewing millions of lines of COBOL, who, I mean, are at this point, are you using AI to do that review? I mean, are there still, you know, cobalt fluent engineers that can spend weeks reading millions of lines of code to follow what was done and, you know, where any vulnerabilities are or problems and that sort of thing?
27:22I think that this is one of the areas, this is one of the bright spots for AI is actually in doing code refactoring. We've seen a lot of success. We use those tools today because one of the challenges I'd say for a modernization program is kind of that front end, just that kind of the discovery process and understanding like what is it that you need to do. I think this speeds up the process. It doesn't make the, you know, the modernization program, it makes it less ugly. It's still ugly, but it makes it easier to undergo because you have the, you know, you have the tools at the disposal at your disposal on that front end side.
28:04Yeah. Yeah. So, so you have this orchestration layer, you're building the agents. on the customer side what is there some metric of how many agents a single human can manage I mean there's a lot of talk about how middle management is going to shift from managing people to managing hybrid teams, which include dozens, if not hundreds of agents. And then, you know, presumably there'll be a layer of management below mental management that is specialized in managing agents. How many people, I mean, how big is that specialized workforce going to be? Does it need to be specialized? Do you need to have people that really understand the orchestration software, understand how, you know, the fundamentals of how agents work and are competent to manage multiple agents?
29:24You know, it seems to be shaking out in a fairly logical way, which means that, you know, so going back to, you know, sort of if you're talking about using agents for IT, you know, service management, and your team is kind of organized logically. So you have one team that does kind of security management, which is security health checking and compliance and audit. And then you've got another team that's doing problem and incident management and another team that's doing provisioning. It seems that kind of the ownership of the agents is falling within those contexts because there's a logic to it.
30:07They own the process. They own the tools, the underlying environment. They know how it works. They know what good looks like. They know what bad looks like. And the scaling of managers, you know, kind of the ratio of managers to agents is really dependent. It's not clear right now. It's really not clear. It's more about, you know, the sophistication of the agent and that kind of defines like what the structure needs to be. As well as, honestly, the amount of auditing, you know, compliance and checking that needs to take place. you know the more heavily regulated the more you know you're talking about a critical infrastructure industry where uptime is everything the more humans you're going to have in that mix and so therefore like the scale you know in one organization might be one to a hundred another could be one to a thousand it just depends yeah yeah uh i mean it services is a is as i said a good place to start because those guys are are uh they're that's the language they speak right they spend time with technology but what happens when you're applying agents to a business process outside of it i've heard people say well you need you know the structure the id the t department has to become decentralized where you have, you know, in sales, you have an IT guy that sits in sales and can manage agents for the sales team.
31:50Other people say that, you know, you just need to upskill the entire organization so that everybody is competent in working with agents. How do you advise enterprises? So we've got a, actually, it's one of the interesting practices that we built recently is a kind of a reimagining workforce and kind of operations, because this is exactly the problem that a lot of organizations have. Now, I can't say that there's a perfect answer to any of this, because we're all inventing it at the same time. Right.
32:58and using these technologies, not only so they understand art of the possible, but they understand what's going wrong or can go wrong. But at the same time, then they have the specialists, the ones that are responsible for owning, implementing and running the tool just as if they would run like Salesforce. You've got a Salesforce admin. Now you've got the Salesforce, you know, agentic admin. Now, whether they sit in sales or they sit within IT. I think it really depends on the organization. In some organizations, Salesforce sits with the business line. Some organizations, it sits with IT. It just depends.
33:41Yeah. And so do you see this adoption accelerating or are we still at, you know, enterprise leaders are still kind of feeling their way forward you know educating themselves and uh leaning on companies like kindrel to to help figure this out or or is do you see it uh being adopted all over the place and you think oh my god these people don't really understand what they're doing, a lot of them. And, yeah. I think it's, I'd say the experimentation is accelerating. I think it means there's so many projects that are underway, and I think that the level of success for those kind of siloed projects is improving.
34:38So, you know, six months ago, I would say, very rare to see a successful use case. Now we're seeing more successful use cases. That's good. am I seeing more like large scale implementations? I'm seeing a lot more talk about large scale implementations. I'm not seeing a lot more large scale implementations yet. Will we get there? Sure. But not, you know, I think it's, it's like you're pushing this gigantic, like bubble down the, down the road, you know, and it's all this experimentation, but it's just getting pushed and it's getting bigger and bigger and bigger and bigger, but the road still isn't, it's still gravel yeah yeah yeah well that's uh what what i wonder and and and the you know the the media and and the hype always runs far ahead of reality uh uh you know research sort of shows the promise and then the press picks it up as, and the impression among the public is that this is happening.
35:48But do you think it's sort of like self-driving cars that we've got, you know, the basic technology figured out, but there's just a lot of other stuff that has to fall in the line before it becomes widespread? So maybe we're looking at 10 years before enterprises are really grounded in agentic AI. We're assuming, so I just, you know, and I'm going to give you my prediction. You know, my prediction is that if you look at the space I'm in, which the IT infrastructure services market, My prediction is that by about 2031, about half of all of the kind of the traditional IT systems administration tasks, the line one, line two tasks, they will be provided by agentic AI.
Read the full transcript
36:51And then humans will be in either in the loop or over the loop, if you will. That's my prediction. So that's where the market begins to shift. I think it's going to take about five years for us to get the rails and trails in place. That's my guess. Yeah. And that's for IT services. That is for IT services. Yeah. For the broader business functions within an organization, it would then take longer. Or do you think once the IT services end, has it figured out, then it'll spread quickly? I think you need to have the foundation built before you can use that whole scale. I think what you're going to begin to see is pockets of disruption.
37:36So there's going to be a couple of use cases that are going to be just so successful that it's, you know, you're going to disrupt that industry, you're going to disrupt the industry overnight. So I think that will happen. I'm not 100 % sure what those, you know, what those segments are going to be right now, but I do think that that will happen. Yeah. And that's something I've been asking people because I talk to a lot of startups and a lot of them, there is a class of startups that are starting with agentic AI and building agentic first organizations. And I'm sure you've heard Sam Altman's bet on who, you know, how soon before one guy with an agentic workforce builds a billion-dollar company.
38:31And, you know, maybe that will happen someday. someday do you think that there will be a big challenge to legacy uh players in many verticals uh by these agentic native startups who are just going to be faster and and cheaper you know less uh costly to run it's interesting the problem you know like when i talk to these agentic startups. You know, they look, I mean, it's like when you see the demos, you're like, whoa, that is really cool. And you built it in like 10 minutes. That was amazing. You know what? It's really easy to build really cool things. It's really hard to run them at scale securely, compliantly, resiliently, reliably, blah, blah, blah.
39:24So when you ask these, the startups, all right, so where's your infrastructure running? Is it SOC 1, SOC 2, SOC 3 compliant are, you know, oh, you want to hook into my SAP system and into my CRM and into my email system and good luck. It's not happening, right? So I do think that there's, you know, yes, it looks good, certainly looks good. And in a pilot may look good too, but by God, I'm not allowing it into my environment. So I do think there is a, you know, When they figure out how to run reliably, securely, scalably, okay, they can disrupt. Until then, the bigger vendors are going to continue to win in the market.
40:15There will be those that can afford to build their own CRM systems, absolutely. But until that, the sales forces, et cetera, of the world, they're still going to have a locked market. And they're going to be bringing, you know, Agenta capabilities within their software ecosystem. And they're going to be, their customers are going to enjoy the value of those things. So it will be interesting to see what happens. I think it's more likely that the real innovation is going to be coming on the consumer side, where the consumers are less concerned about, you know, integrating these technologies into their finance systems or into their, you know, like all that.
40:52So I think that you'll begin to see more lift in that market than you'll necessarily see in the B2B. So B2C, yes, B2B, unless if it doesn't touch data, then fine. Otherwise, I think it's going to be a little challenging. Yeah, yeah. Yeah, it's going to be fascinating to watch. I mean, presumably these agentic native startups can build all the infrastructure, you know, not at the same time, but as a fast follower to their POC, their proof of concept. And it'll be interesting to see how that happens. On security, when you're looking at integrating an agentic system into IT services, for example, what are the security risks that you focus on?
41:53So, you know, I think we always look at it from two different vantage points. You know, one is that, you know, obviously there are the threat landscape is increasing for a lot of different reasons. Not, you know, not limited to, you know, the fact that AI is now available to, you know, the threat actors. So they're becoming much more sophisticated. And we're seeing, you know, like, for instance, phishing is just amazing nowadays. You know, particularly countries like Japan, Korea, which were sort of isolated because of the language barriers. Now there's no barrier to entry. And so, you know, we're seeing a lot more risk in those particular environments.
42:32And so what that means is you have to have AI, you know, kind of addressing the AI threat. So when we think about agentic AI, it is very useful within a security operations context in being able to identify, triage, and then help in the resolution of the particular issue. So we're seeing it, you know, from that vantage point. When it comes to kind of, you know, the threats and when we think about the risk of agentic AI, you know, it's typical, right? As I was saying, it's vulnerabilities that can be exploited. But I've been in security long enough to know that if you were to look at cyber incidents, and I know this is heresy for somebody in the cyber industry, but a lot of what we think are cybersecurity issues sometimes are not.
43:28They're just like somebody did something really dumb. and we classify it as a cybersecurity issue, may or may not be. But when you break it down, the reason why things fail within an organization is because somebody did something really dumb. They misconfigured something, they did something really dumb, and then it got exploited. Another reason is because the network was configured badly or it failed or whatever the case may be. So you could go kind of go down that list. The only in a small percentage of cases will you have a sophisticated threat actor, you know, get into your environment because of sophisticated means.
44:09So what does that mean? It means that when you're thinking about agentic AI, you've got to think about what are the new risks associated with the implementation of technology, as I was describing when we were talking earlier, where there is the potential for misconfiguration, for failure to upgrade, for performing an upgrade that wasn't good. for deletion of, you have to think about it from a very logical perspective. And so I tend to think about cyber as a set of risks that include, but are not limited to cybersecurity related risks. And what we try to do is reduce the risk to the things that are going to be most likely to happen and who are going to create the biggest impact.
45:09And so again, that is a, I know I'm getting into kind of like the cyber risk expert theology here, but suffice to say, it is what we focus on is oftentimes like the really dumb, really ugly. Did the agent get registered? Did it get provisioned correctly? Was the workflow right? you know all that kind of stuff that becomes kind of the meat and potatoes of what you need to look at yeah do you have i mean it seems like a natural case for agentic ai do you have agents that sort of crawl through a system looking for vulnerabilities as sort of virtual white hat attackers is that what they're called, you know.
45:59Yeah. Yes, exactly. So we have a, it's a digital, our digital trust capability is exactly that. So it's a, it, you know, first of all, it looks for agents, like some, you know, most companies have a lot of agents, but they don't even know they have them. So it looks for agents. It tests, this is actually really cool. What we do is we take agents and is an example, we'll work with Microsoft. Microsoft has a digital twin technology. So what we do is we will do testing of the agent in a digital twin environment. Because the question, digital, you know, one thing is important about agentic AI is it actually learns and it changes its behavior based on how it's learning.
46:44So when you set a policy for how you want to monitor and enforce the policy. You can't establish the policy for what it is today. You want to establish the policy for how you think it's going to grow and evolve, and then constrain it beyond evolving from particular vantage points. So when we're thinking about testing within a digital twin environment, we're thinking about testing the agent under certain circumstances to see how it's going to evolve so that we can create a policy that's monitored. And then we monitor the agent within that context using guardian agents, because, you know, that's cool.
47:28So the guardian agents are the ones that are, you know, performing the testing, policy evolution, policy implementation, and then the monitoring and the enforcement on the backend. Yeah. You know, what, basically what you're saying, It's not on this, but generally that fire and forget agents are not in the cards now. You're going to have to run herd on the agents. In this case where you have agents that are checking the security of software systems, uh it seems like you could have an agent that just runs all the time or a series of agents that are monitoring and checking configurations and you know what data is flowing where and that sort of thing uh or does do even those agents need a human minder they do need a human minder and it actually is it's a tricky one because when you train the agents, like, you know, what is good software?
48:41You get back into the, and I've seen this in real practice. It is amazing when you look at good software and bad software, how similar they are. Good software looks bad and bad software looks good. And so when you're training an agent to identify kind of what vulnerabilities on are, oftentimes they're using kind of the standards that we use. So they'll look at the CVEs and then they'll make a determination based on the CVEs and perhaps some other kind of characteristics. But you can't, it is very, very hard to teach an agent to understand like good software versus bad because as I said, we've got terrible coding practices.
49:24And so that becomes very difficult for of them. So in answer to the question, yes, you definitely need human minders because the human minders, it's important to kind of get the context, continually understand the context of what it is that they're looking at and, you know, kind of reviewing the outputs so that you can make sure that they haven't learned bad coding practices from theoretically good coding coders. Yeah. Yeah. This is all happening so fast. And I get asked by young people a lot, what should they study now? Is there a cohort of cybersecurity or agentic security personnel who are available for companies to hire to manage all this stuff?
50:27Or is this going to have to, this expertise capability, is it going to have to be done through training within organizations? I mean, you know, when I listen to this stuff, I'm not an engineer, obviously, or a coder. I just can't imagine there are enough people that understand this stuff and frankly want to do it to hire, you know, to sift through code bases and watch how agents are operating. It's not like creating software. It's not as creative as that. So, yeah, how are you going to man the bulwarks? It's really interesting you say that because that's another conversation. And you're right.
51:31This is literally like happening under our feet. And we're all trying to catch up. So a lot of, you know, what I'm going to say is, you know, a prediction. I do think that people that have liberal arts, you know, educations that are really good at, you know, analysis and just kind of the fruble construction, like how to ask a question, those are the people that are going to actually win in this marketplace. So, you know, like I was an English major. I'm like, I'm just beyond happy that I'm an English major because I really do think I was taught to, you know, consider the problem set in a very different way than some of my peers, which is fantastic.
52:14I do think over time, you're going to see a different grouping, a different kind of individual, very creative individual, you know, that is going to become kind of the masters of these agents. Specifically in security, though, I mean, And it's an interesting issue in so much as we're not seeing the jobs go away. And in fact, I'd say I'd argue that agentic AI is making up for some of the gap that we've had persistently in this marketplace. So it's allowing us to get a little bit more breathing room. But because the number of threats is increasing, just because the number of like line one events that you have to chase is decreasing, you still have a lot of stuff.
53:05What's interesting, though, is because a lot of the rote skill stuff is being automated, you don't need as many of the entry level folks. You need more sophisticated folks. So that is a really, that's become the challenge is how do you get some of the folks that would have spent a year or two in a sock doing line one, line one and a half job, how do you get them from there to line three, to level three, like overnight? So that becomes the real challenge for us now. Yeah. And how do you do that? I mean, it's funny, my wife is in education research and she has been saying to me for a while that, you know, there's like a huge talent shortfall in cybersecurity.
53:56but and and we she's also been asking me well what happens all these entry-level jobs go away how do people get to the senior leader level or the more senior leader in order to do these jobs if you don't have people coming up through the ranks so yeah how how do you see uh that evolving You know, I've been thinking about this concept of a master craftsman, if you will, a lot, because I think fundamentally we have to actually restore almost like kind of that guild mentality where, you know, a university education becomes a practicum as opposed to, you know, you're learning in books. and not saying that that's not important, but like in security, I need people to come out of college as a level two, level three engineer.
54:52In order for them to do that, they have to have hands on keyboards. In college, day one, performing the job. And so I do think that we are really going to have to think of these apprenticeship programs as being critically important. So it's not just about the education, It's about the application of the skill set, you know, in an area which is kind of co-funded, right? So between the university and between the business and between, you know, perhaps the public sector, there is an investment in kind of the skills build, which is, I think it ended up will be good, but they got to start somewhere.
55:34And they got to get out of school with the ability to be hired. But right now I look at these resumes and a lot of these kids, they've got great resumes, but I don't need them. I need somebody who's been in the field for five to 10 years. That's a different problem. Yeah. Yeah. Yeah. Okay. Well, we're coming up to an hour. Is there anything I haven't asked that you want to say to listeners? No, I do. You know, Craig, thank you so much for the time. And I really appreciate it. Go read books. Yeah, that's right. That's a frightening, frightening trend that people don't read books anymore. I always tell my kids, believe me, you read one book, you'll learn much more than you can from a million TikToks, you know.
56:30Yeah, read the newspaper, read books. But yeah, no, that's a lost art. We're going to have to get back there, though. But, you know, it's a I think as scary as it is and it's an exciting time. I think, you know, we're going to all be looking back at this time and saying, wow, I can't believe I lived through this. It's, you know, it is incredible. Yeah.
From the publisher
Kris Lovejoy, Global Strategy Leader at Kyndryl, has spent her career at the intersection of IT infrastructure and security. Right now, she's one of the people enterprises call when they want to move from AI experimentation to real deployment. Her diagnosis is clear: agentic AI is a bullet train sitting on tracks built for 30 miles per hour. The technology is ready. Most organizations aren't, and the gap between a successful pilot and a production system running at scale is far wider than the hype suggests.
In this conversation with Craig Smith, Lovejoy walks through why IT service management is the smartest entry point for agentic adoption, how cost savings of up to 90% in that area can fund broader modernization, and why the security risks in agentic systems are less about sophisticated hackers and more about misconfiguration, bad context, and human error. She closes with a specific prediction: half of traditional IT administration tasks will be handled by AI agents by 2031, and a surprising take on who will actually thrive in the agentic era: not coders, but people trained to ask the right questions.
For anyone making decisions about AI adoption, this is the most practical conversation available right now.
Subscribe to Eye on A.I. for weekly conversations with the people building and deploying the future of AI.




