The agentic enterprise is forcing companies to rethink what it means to deploy artificial intelligence safely.
At WSO2Con Africa 2026 in Nairobi, WSO2’s Thibaut Rouffineau framed the challenge around three questions: how enterprises get to an agentic operating model without turning it into another prolonged transformation programme, how they govern the infrastructure beneath the agent, and how they retain control once those systems are running.
The argument builds on themes that ran through the conference, where discussions around APIs, identity, enterprise data, workflows and AI governance repeatedly returned to the same architectural problem. An agent can make decisions and perform tasks, but its usefulness depends on the systems it can reach, the identity under which it operates and the controls governing what it is allowed to do. TechTrendsKE’s earlier WSO2Con coverage similarly found that the move from AI experimentation to production depends on connecting agents to existing enterprise infrastructure rather than treating them as isolated applications.
Moving Beyond the Traditional Transformation Path
Rouffineau described the move toward an agentic enterprise as a “generational challenge”, with one of the first questions being whether companies need to complete every conventional digital transformation step before they can benefit from agentic systems.
The presentation illustrated the traditional progression as Digitize, Integrate, Modernize, Agentic, while introducing a “Leapfrog” route that allows organisations to identify workloads where they can move directly toward an agentic outcome. The idea does not make integration or modernization irrelevant. Instead, it asks enterprise technology leaders to distinguish between transformation work that is genuinely necessary for a particular use case and work that can wait while a useful agentic capability is deployed.
That distinction becomes important when organisations have large estates of legacy applications and data. TechTrendsKE’s coverage of WSO2Con’s API discussions found that APIs are becoming a key mechanism for allowing AI systems to reach existing business capabilities, while sessions on enterprise data examined how agents can work with existing information through APIs, tools, MCP and retrieval-augmented generation.
The objective, therefore, is not to abandon the transformation roadmap. It is to find places where an organisation can create measurable value without making the completion of every underlying modernization project a prerequisite.
The Governance Problem Beneath the Agent
The second challenge is more fundamental. Rouffineau used an iceberg to illustrate how little of an enterprise AI system is actually visible to its users.
At the top are agents, the applications that people interact with. Beneath them are connections, including APIs and integrations that allow agents to work with enterprise systems. Beneath those are controls, covering the security, policy and compliance mechanisms that determine what an agent can do.
That architecture changes the meaning of AI governance. If an agent can retrieve customer information, call an internal API, initiate a workflow or pass information to another service, governing the model alone does not govern the activity taking place around it.
WSO2’s own Agent Manager offering provides a useful example of how the company is approaching that problem. The platform has been positioned as an open control plane for agents across frameworks, models and deployment environments, with capabilities covering agent identity, MCP governance, guardrails, runtime controls, observability and lifecycle management.
The distinction matters because an enterprise can have a well-governed model and still have a poorly governed agent. The model may produce an acceptable answer while the surrounding system gives that agent excessive access to data, APIs or business processes.
APIs, Identity and Data Become Part of the Agent Boundary
The conference’s API discussions provide an important piece of this architecture. Once an agent can autonomously select and invoke APIs, those interfaces become more than technical plumbing. They become controlled entry points into enterprise capabilities.
Identity creates another layer. An enterprise needs to know which agent is acting, what permissions it has, whether it is acting on behalf of a person or another system, and what record exists of the action. WSO2Con’s identity discussions examined distinct identities for AI agents, delegated authority, permissions and auditability, reflecting a governance problem that conventional application authentication does not completely resolve.
Enterprise data adds another dependency. An agent cannot create much business value if it has no controlled way to reach the information required to complete a task. At the same time, giving an autonomous system broad access to internal data introduces questions around authorization, privacy, data quality and the boundaries between systems. Those issues featured in WSO2Con sessions focused on making enterprise data usable by agents.
The result is a broader definition of the agent boundary. It includes the model and agent logic, but it also extends through APIs, identity, data, integration, workflow and the policies applied at each point.
Keeping Control as AI Systems Expand
Rouffineau’s third question was about ownership. The presentation linked rapid AI adoption to vendor dependency, service suspension and digital sovereignty, using external news reports to illustrate how enterprises can become exposed to decisions made outside their own organisations.
The sovereignty argument extends beyond where data is physically stored. It raises questions about who controls the infrastructure, where data and requests move, which jurisdiction applies, how identities are managed, and whether an organisation can change models or providers without dismantling its surrounding architecture.
That concern also appears in WSO2Con’s broader programme. Sessions and coverage around data sovereignty and government infrastructure placed control over data, identity and digital infrastructure alongside the adoption of AI systems.
For African enterprises, the question has particular relevance because many organisations operate across cloud providers, international software platforms and multiple regulatory environments. The issue is therefore less about rejecting external technology and more about ensuring that adopting an AI service does not automatically mean surrendering control over the systems and policies surrounding it.
From AI Pilots to a Repeatable Golden Path
The presentation’s answer to the execution problem is the Golden Path, a repeatable route from experimentation to production.
That idea fits closely with another theme from WSO2Con Africa: the gap between an AI demonstration and a production system that can operate reliably inside an enterprise. TechTrendsKE’s coverage of WSO2’s Forward Deployed Engineering approach identified legacy systems, data, workflows and security controls as some of the practical obstacles that have to be addressed before an AI pilot can become a functioning business system.
A repeatable path matters because every successful pilot can otherwise become a one-off engineering project. One team builds an agent, another establishes its own identity model, another develops its own integration pattern, and security teams are forced to assess each implementation from scratch.
The Golden Path is intended to reduce that duplication. WSO2 is also connecting the concept to its Forward Deployed Engineers, who can work with organisations on implementation, while partners provide another route for deployment and integration support.
That gives the concept a practical dimension: a production path needs architecture, tooling, governance and people who know how to apply all three.
WSO2’s Agentic Enterprise Fabric
WSO2’s proposed response is the Agentic Enterprise Fabric, which brings several parts of its platform portfolio into the same architecture.
The WSO2 Agent Platform is positioned around governing agents. The API Platform governs APIs and AI services, while the Integration Platform addresses connections between systems. The Identity Platform governs identities, and the Engineering Platform covers workloads.
The significance of that structure is less about putting five products under one label and more about the architectural proposition behind it. An enterprise agent sits inside an environment where it needs identity, access to APIs, connections to applications, data and a place to execute. Governance therefore has to follow the agent across those boundaries.
Rouffineau also made a point of distinguishing the platform’s completeness from a simple bundle of products. His presentation positioned the individual components as established offerings in their respective categories that can work together as a broader enterprise architecture.
That is a vendor claim, and independent analyst recognition provides additional context, but it should be distinguished from independently measured performance. WSO2’s conference material cited recognition from Forrester and the 2026 AI Tech Awards as part of its case for the platform’s maturity.
Building the Skills and Ecosystem Around Agents
Technology is only one part of the adoption model Rouffineau described. WSO2 is also putting training, webinars, conference material, Forward Deployed Engineers and partners around the platform.
The company said AI-focused online training would begin on October 1, with WSO2Con presentations and keynotes being made available through its YouTube channel. Rouffineau also pointed attendees toward open-source projects and encouraged developers to participate in building the underlying technology.
That approach fits the broader open-source position evident across WSO2’s platform strategy. OpenChoreo and ThunderID were highlighted alongside training and engineering support, while the company’s partner ecosystem was presented as another way organisations can implement the technology.
There is also a human boundary around the autonomy itself. Other WSO2Con sessions examined agentic software development in which AI can plan and execute substantial portions of engineering work while humans retain responsibility for reviewing and approving changes before production.
That principle extends beyond software engineering. The enterprise question is increasingly becoming where autonomous execution is useful and where human authority remains necessary.
Nairobi Closes the 20th WSO2Con With a Regional Milestone
Rouffineau ended by returning to the people behind the technology. He described WSO2Con Africa 2026 as the biggest WSO2Con to date, thanking speakers, partners, organisers and the WSO2 Africa team before bringing the wider team onto the stage.
The milestone is significant because the conference was also the 20th WSO2Con, placing the Nairobi gathering within the longer history of the company’s global event series.
The closing message brought the presentation back to the idea with which it began: community. The agentic enterprise may be built from models, APIs, identities, integrations and controls, but its deployment still depends on engineers, architects, partners and business leaders deciding how those systems should operate.
That is ultimately the more difficult question raised by the presentation. Building an agent is one technical problem. Creating an environment in which thousands of agents can act across enterprise systems while remaining identifiable, governed and under organisational control is a much larger architectural undertaking. WSO2’s proposition at WSO2Con Africa was that enterprises can approach that problem through a repeatable path, a connected platform and a governance model that extends well below the agent itself.
Real ESG impact doesn’t happen in panels alone, it happens in the rooms where financiers, operators, and policymakers actually align. Our GreenShift Forum 2026 cuts the noise, bringing together the people rewiring Africa’s sustainability and energy frameworks for one focused day in Nairobi. Secure your seat.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to info@techtrendsmedia.co.ke





