Humbot
Schedule Demo
Podcast

Building and Owning the AI Control Plane - Craig Suckling & Dr Sokratis Kartakis Return to HumBot

We're at an inflection point as organizations move from the land of pilots to the land of demanding agentic outcomes. HumBot's first-ever repeat guests, Craig Suckling (Capgemini) and Dr Sokratis Kartakis (Google), return to unpack security at scale, the new unit of transformation, who should build and own the AI control plane, and why experts, not headcount cuts, are the real story.

CCraig Suckling & Dr Sokratis Kartakis
July 10th, 202656 mins watch
#AI Agents#Enterprise AI#AI Control Plane#AI Security

We're at an inflection point. Organizations are moving away from the land of pilots and heterogeneous tools toward the land of demanding agentic outcomes. That shift expands the surface area of decisions leaders have to make—around control, around security, around earning end-user trust.

To dig into what that future looks like, HumBot welcomed back its first-ever repeat guests: Craig Suckling, Head of AI for Europe at Capgemini, and Dr Sokratis Kartakis, GenAI Black Belt at Google. A year on from their first appearance, the conversation moves well past definitions and into the operational reality of scaling agentic AI across the enterprise.

From POC Proliferation to Production Value

Both guests agree: the center of gravity has shifted.

Craig frames it as a move away from "POC proliferation" toward driving scale in production and delivering real business value—value that now has to be measured against total cost of ownership and efficiency, not just a good demo. Thinking has also matured from isolated use cases to end-to-end business workflows, and from a pure technology story to one that spans people, process, culture, and data.

There's also a structural shift happening underneath all of this: SaaS itself is becoming "agentified." Where enterprises used to build and deploy their own agents one-way, they're now also configuring agents that arrive bundled inside every SaaS tool they buy. The result is a heterogeneous, bidirectional flow of agents in and out of the business—and a pressing question of how to control and orchestrate all of it.

Security in a Multi-Agent World

Security remains one of the biggest open domains in the market. Sokratis argues that while new vulnerabilities will keep appearing, organizations still need a defensible point of view on how to resolve them—borrowing from red/blue/green team patterns, but pointed at agents instead of just infrastructure.

The emerging pattern: background, ubiquitous agents that continuously observe systems for vulnerabilities and even fix issues on the fly. But every one of those fixes still needs a human to validate it—technically and from a business perspective, since not every "correct" fix aligns with cost, policy, or context nobody explicitly told the model about.

Craig adds an optimistic counterpoint: just as AI is producing an abundance of software, it should also produce an abundance of more secure software, since so much of the last half-century of code was written—and left with loopholes—by humans. But that only holds if companies explicitly instruct models to write secure code against their own standards, since security tiers and requirements differ wildly by industry (financial services being a good example of tiered criticality).

The New Unit of Transformation

Historically, transformation was planned in units of human hours: X hours of Y expertise. Craig argues that unit has fundamentally changed—it's now value of outcome, or velocity of value.

Time and effort no longer equate to value, because working alongside cohorts of agents can 10x or 50x output. That also breaks old trade-offs: contact centers no longer have to choose between volume of calls and quality of conversation—agents can drive volume while humans focus on the conversations that need real quality. The same logic applies to software engineering, where agentic coding removes the historic bottleneck of never having enough engineers to clear the backlog.

Sokratis cautions that this can't come at the expense of fundamentals. He proposes a practical hiring signal: pair a classic coding interview (do they understand the fundamentals?) with a "vibe coding" interview (can they use modern tools to scale that expertise?). Craig agrees—outcomes also need to be judged laterally, not just within a single team's silo, since a faster forecasting agent that creates a downstream procurement bottleneck isn't actually a win. And delivering an outcome once is different from delivering it repeatedly at scale, which is where standardized foundations—the same tools, platforms, and control planes—start to matter.

Building and Owning the AI Control Plane

Asked what standards leaders should demand from an AI control plane, Sokratis lays out several:

  • Model interoperability - the ability to plug in, evaluate, and switch between models without breaking quality.
  • Economics (FinOps for AI) - understanding the cost/quality trade-off of swapping to cheaper, less capable models.
  • Agentic engineering standards - moving from "vibe coding" to disciplined "agentic engineering," with standardized testing, evaluation, and simulation at every step.
  • End-to-end integration testing - optimizing each step doesn't guarantee the system works end-to-end.
  • Observability - standardized alerting and visibility to continuously optimize the approach.

Craig offers a useful mental model: a control plane is the AI equivalent of human resource management—a common plane to train, deploy, and performance-manage AI (are agents staying within their evals? breaching guardrails?), and, unlike the human analogy, to upgrade every deployed agent at once when regulation changes, or retire agents out of the business entirely.

Is it a separate layer, or does it fold into existing API and data control planes? Both guests agree it needs to be distinct, while integrating tightly with the others:

  • A data/semantic layer unlocks data as a product for both agents and humans—and has a many-to-many relationship with the agentic control plane, since many agents draw on many data sources.
  • An orchestration layer governs agent-to-agent and agent-to-human handoffs.
  • The agentic control plane itself needs to treat agents like users—tracing every action, assigning accountability, and managing multi-layered authentication as agents act on behalf of humans and increasingly on behalf of other agents.

Craig also pushes back gently on the idea of one single, centralized control plane: history shows centralization at absolute scale is hard. Expect conceptually standardized but technically distributed control planes—much like most large enterprises end up with a "catalog of catalogs" rather than a single data catalog.

Who should own it? Craig argues it's still fundamentally a CIO/technology leader's remit—but a very different kind of technology leader: commercially savvy, business-outcome-led, and focused on enablement rather than centralized bottlenecks. Tellingly, both guests point to a real pattern: CIOs increasingly reporting into the Chief Commercial Officer, and in at least one case, the CIO and CHRO roles merging into a single executive accountable for both technology and people impact.

Underneath the central control plane, both agree on a federated model: the control plane provides the standardized "boxes," but business units are accountable for filling them with their own use cases, guardrails, and business logic—for example, a procurement agent might inherit central compliance standards but still need its own limit on how much it can commit to a vendor without human sign-off.

Everyone Becomes a Manager of Agents

Rather than guessing at brand-new job titles, Craig focuses on new attributes inside existing roles. The clearest one: an inversion of today's 80/20 split, where 80% of an organization "does" and 20% "directs." That flips—80% directing cohorts of agents, 20% doing. In his words: "We will all be managers in the future. We will all be directors."

Critical thinking becomes more valuable, not less, because agents still need judgment applied to a messy world. And the world needs both AI experts and domain specialists—in marketing, fraud, supply chain, R&D—who use AI to 10x their existing expertise rather than becoming generalist "AI people."

The conversation turns to real examples: a university hire trained on DevOps over six months, now effectively doing DevOps, data, and ML work by conversing daily with senior colleagues' agents—each agent a curated representation of years of expertise. An executive assistant whose role has quietly expanded to directing agents for social marketing, invoicing, and onboarding, built by other parts of the team and extended to her.

That points to something bigger: persistent, shared corporate memory. One example raised is aerospace manufacturers with 20-year product cycles, where the engineers who built the last version are retiring before the next one starts. Agents that capture and carry forward institutional knowledge remove the classic single-point-of-failure risk of "one person who knew everything."

AI Won't Replace Experts

Sokratis is direct: models don't yet generate genuinely new knowledge—every bit of context an agent uses still comes from a human. That means subject matter experts are more essential, not less: someone has to instruct agents correctly, and someone has to build the business context that makes an agent precise for a specific workflow. The people who "just put a stamp on paper" are being replaced; the people with deep, specialized knowledge who use AI as an assistant are not.

Human-in-the-loop, both agree, is not going away. It's necessary at multiple layers: a product owner or technical SME approving what an agentic system delivered, or the person who built the automation checking it against the standard it was supposed to follow. That accountability has to be layered underneath central standards—a procurement lead, for instance, might inherit the control plane's guardrails but still set their own limit on how much an agent can spend or how many contracts it can sign per day.

On the fear of mass layoffs, both push back with data and reasoning: recent hiring data shows an uptick, not a decline, and this isn't viewed as a zero-sum game—GDP growth from AI expands the total pie for both humans and AI. The bigger risk isn't automation, it's under-adoption: enterprise AI usage still sits around 5% in many large organizations, and the real unlock comes from education, not headcount reduction.

On how to organize the humans who do need retraining, both note this is a familiar pendulum between horizontal (centralized) and vertical (business-embedded) skills—and the answer is a blend of both, with platform builders kept separate from platform users to avoid recreating the very bottlenecks agentic AI is meant to remove.

Key Insights

🔐 Security Needs Layers, Not a Silver Bullet: Background agents can detect and fix vulnerabilities, but every fix still needs a human validator

New Unit of Transformation: Plan around velocity of value and outcomes, not hours of human effort

🧭 Control Plane as AI-HR: Train, deploy, performance-manage, upgrade, and retire agents the way you would manage a workforce

🏛️ Federated Ownership: A central control plane sets the standard boxes; business units own the use cases and local guardrails inside them

👔 80/20 Inversion: Organizations shift from 80% doing/20% directing to 80% directing cohorts of agents/20% doing

🧠 Experts Are the Multiplier: SMEs, not generalists, provide the context and judgment agents cannot generate themselves

📈 Growth, Not Zero-Sum: Hiring data is trending up; the bigger risk is the ~5% adoption ceiling, not job losses

Video Highlights

Here are key moments from our conversation with Craig Suckling and Dr Sokratis Kartakis:

Clip 1: The New Unit of Transformation

Clip 2: Building and Owning the AI Control Plane

Clip 3: Everyone Becomes a Manager of Agents

Clip 4: AI Won't Replace Experts

Conclusion

A year on, Craig Suckling and Dr Sokratis Kartakis return with a shared message: the technology conversation has matured into a business and organizational one. Security, control planes, and human expertise aren't obstacles to agentic scale—they're the foundations of it.

The organizations that win won't be the ones with the most pilots or the most agents deployed. They'll be the ones who build a control plane worth trusting, keep experts firmly in the loop, and help every employee become a confident manager of the agents working alongside them.

Ready to automate your expert workflows?

Deploy autonomous enterprise agents with built-in governance, zero vendor lock-in, and rapid time-to-value.