It’s in Production. It’s Not Vaporware

August 21, 2026

I’ll admit upfront that this is a bit self-serving and probably a bit of a rant. But why do I keep repeating this? A savvy partner and systems evaluator brought this up in a demo recently and pointed out that I had said “it’s in production” several times. The conversation just continued along, but that remark stuck with me and now I need to address it, get it out of my mind if you will.

This is important because vaporware is everywhere these days. And although not new in the tech world, the marketing hype has never been so high and the noise, especially with AI-generated everything, has never been so loud. We also hear the constant cries from investors, customers, and the long line of skeptics about AI-washing or companies “showing up, only able to do 20% of what they said they could do.” And that’s a direct quote. I’ve heard it all through the years and I’m guessing that my reaction is now an auto reflex. It’s my twitch. My tell. 🤔

Well here’s the thing that’s driving that twitch. Our Forensic Control Plane isn’t just in production, it’s been in production for over 5 years. That’s right, 5 years. We’ve got battle scars that go deep, documentation to back up designs, and prior art that shows how we arrived at many of the control patterns agentic AI now requires.

As I noted in another article, this didn’t happen overnight, and those battle scars are well-earned by the team. Even though it’s been in production for over 5 years, the designs, proofs of concept, alpha and beta releases existed long before that. And we didn’t call it agentic back then … that’s just the fancy language we use today.

Control Planes are notoriously difficult. They’re complex to design and build; and for AI, they’re exponentially harder. Why? You are not just worrying about the typical policy enforcement gates and firewalls for software and applications. It’s not as simple as ABAC, RBAC, XACML, Rego, JWT, and the typical rule structures that need to accompany them. You are dealing with and coping with semi-intelligence, and that alone takes the complexity to an entirely different league of its own. You’re trying to control and contain software that interprets, reasons, improvises and gets it wrong more often than you like.

Hard Won Wisdom

Some will say, “I’ll vibe code it over the weekend.” We’ve literally heard others say give me six months … four years ago.

But they are all missing the reality check on semantics, context, ontology, parallel processing, child processing, state maintenance, state propagation, identity, authorization, delegated authorization, multi-agent orchestration, registration, profiling, qualification, and credentialing. On top of it all, you need to cope with the harsh realities of natural language understanding and semantics, something that even frontier model vendors continue to struggle to cope with across ever-expanding and diverse use cases. It’s pretty f*g straightforward for an LLM to generate code these days. That capability is impressive. But generating code and engineering a control system capable of understanding nuanced business operations, policy, strategy and intent across automated workflows are two totally different things.

In today’s enterprise, you have to wonder why so many humans are feeding and driving the machine. I’ve written about this as well and it’s also worth repeating. It’s because the AI machines can’t do what the frontier model pundits say they can do. You now have humans acting as the control infrastructure around a very brittle and ever changing “orb.” We’ve essentially surrounded the “orb” with humans. Humans checking it, correcting it, approving it, watching it, and deciding if it went too far. This was the premise for the last article on The Fixer and The Babysitter.

Given how that “orb” is being utilized in the enterprise for building and backing up agents, you need to worry. And the reality is, you can’t wish or whip-up a control plane overnight. No amount of prompting is going to get you there even with a very expensive LLM and all the scaffolding that’s necessary. Control planes fit for production need maturity. They need to handle the edge cases, failure handling, state management, policy conflicts, telemetry, forensic traceability and the brutality that appears when real systems start behaving in ways you didn’t expect.

Agentic AI is powerful. It will radically change the enterprise. It’s an era leap over the RPA world. But the control infrastructure has not kept pace and everyone is feverishly trying to build it. Engineers are going “this is cool … I love this! Let me work on it.” But, you will find yourself many months from now stuck with the heavy weight of technical debt that is enormously difficult to maintain. The wake up call is the realization that you need to keep pace with the changes in models, the changes in environments, the changes in controls, the changes in telemetry, the changes in policies, the changes in infrastructure, the changes in applications, the changes in dependencies, and the changes in your business workflows.

AI Control Planes Are Emerging

Again, I understand this was a bit of a rant, but hopefully eye-opening into the technical challenges the entire AI and cybersecurity industry is now being forced to confront. That’s why I keep saying “it’s in production.” It’s far more than five years of learning and figuring out what works, what doesn’t work, and how to cope with the complexities of businesses that are moving fast and transforming at a pace we simply haven’t seen with previous technology.

News & InsightsArchetype and Battle Rhythm

See how CharliAI helps enterprises deploy AI without creating unmanaged exposure

Get in touch to see how CharliAI can help your organization control AI access, enforce policy, trace workflow activity, and produce audit-ready evidence across existing systems.

Request an AI Exposure Briefing