The Executive Summary Subscribe
AI

Your second AI brain and how to control it

Your second AI brain and how to control it
How the control plane and AI second brain are reshaping company operations

Two features are holding companies out front on AI: the control plane and the second brain.

As a board member, you need to be aware of these, what they do and the risks versus the benefits they bring to your company.

I'm in the middle of interviewing 20 CEOs on how they're using AI in their organisations. It is fascinating.

A lot of people think they are really leading out front when they aren't, and there are a few who have built proper proprietary tech. But it is hard to find out where everyone sits and how they are using AI as there isn't a baseline.

Yet.

But there are a lot of firms who have invested in AI with no strategy.

The control plane

A control plane is where the agents are run and governed. Every agent has an identity, a set of permissions, an owner, a budget and a log of everything it did.

A few months ago I was tapped on the shoulder by a cybersecurity startup called Fort Nevis. They asked for some help in positioning their company and taking it to market, so full disclosure, I am a shareholder. (The Proposition - my advisory - is helping and I will do a post on what we're doing.)

But I have learned so much about the control plane from these guys - a team of real CISOs and CIOs in the enterprise space, who are solving their own problem.

They built SARA, an incredible closed-loop system. SARA finds attack paths in companies' architecture. It maps them out, builds the remediation plan and then looks to the human in the middle - the CISO - to decide what to do next.

Many CISOs are distrustful of letting agents fix their security issues, but the backlog of threats coming at them from AI hacking farms is causing the amount of work to be unachievable.

They are slowly seeing that they must use AI to fix and remediate - but how can they trust it?

Enter the control plane, an office tower for agents that forces compliance with company policy.

The control plane provides approval gates for the decisions that need a human signature and there is a way to stop the lot at once. It locks down agents so they can only communicate the way you tell them to.

This helps you to build enterprise-grade AI tech.

I wanted to take Fort Nevis to market because the guys have built enterprise-grade cyber security, the team is one of seasoned, regulated practitioners and it has global clients using it at scale.

Scale is the really hard thing with AI - because there are so many permissions and unknowns in enterprise.

An agent built in one department on somebody's personal API key works beautifully until there are 40 of them, and at that point nobody can tell you what is running, what it costs, what it can reach or what it did last Tuesday.

This is not a rare problem.

An OutSystems survey of 1,900 IT leaders found 96 per cent of enterprises already running agents in some form and 94 per cent calling sprawl an active concern, while only 12 per cent had a central platform to manage any of it.

A control plane is the grown-up in the building.

And you can buy one.

Gartner gave the category a name in March, calling them AI agent management platforms, and the market has moved quickly since.

Kore.ai sells a vendor-agnostic layer that governs agents built on LangGraph, CrewAI, Google ADK, AWS AgentCore, Microsoft Foundry and Salesforce Agentforce. Lyzr does something similar across LangChain, CrewAI, Agentforce and Copilot. Obot is the open-source route for teams who want to start at the MCP layer without a procurement cycle.

Fort Nevis's control plane is called Genesis and it is designed for agentic workflows in regulated companies. It is a Fort to keep agents and your confidential work locked in.

It is also what makes the regulatory conversation work. When somebody asks what your system was given, it can show you what was done, who approved it, that answer will be there if the control plane was set up properly.

In other words, when you need to point the finger at agents, this is essential.

The second brain

A second brain is the layer where everything your company knows is held in a form a machine can use.

Contracts, tickets, call transcripts, product documentation, pricing history, the Slack thread where somebody worked out the answer in 2023. It is indexed by meaning rather than by folder, it respects the permissions of the systems it came from and it gives answers with the source attached.

But you should only give it the minimum amount of data rather than every bit of crap you can find.

What it does is turn institutional memory into something you can question. The new starter then gets answers the 12-year employee would have given on basic questions - so that meeting can be more productive.

Or for example, the bid team pulls the last four proposals and the reasons two of them lost. The support desk answers from what is true today rather than from a knowledge base last updated by someone who left in 2022.

The commercial point is that this is the one part of the stack a competitor cannot buy. Everybody has the same models. Only you have your twenty years of contracts, complaints and customer conversations, and the companies pulling ahead are the ones who have made that material usable rather than merely stored.

You can buy a version of this too.

Glean is the pure play, indexing company applications into a permissions-aware knowledge graph, and it reached around $300m in annual recurring revenue by May, up from $208m at the end of last year.

Microsoft launched its IQ family at Build and described it as a context layer rather than a product. Palantir, Databricks and ServiceNow are arriving at the same place from other directions, and Y Combinator has put the company brain on the list of things it most wants founders to build.

The board question is which parts of this you buy and which parts are yours to own.

For example, a company I am working with is using its brain to track its customer interactions. It has removed HubSpot and Salesforce because they are fed up of too many features and having to employ consultancies to make it work. These are projects that can take years.

They just want it to work - but rather than just building a CRM on its own, they realised they needed to give their new AI some context.

In other words, if you're going to put all your data in one place, you might want to think about owning where it goes and what you do with it - rather than getting charged a high price to work with generic tools. Second chance of life, sort of thing.

The second brain enables you to build what you need in the way you want it built.

This changes the game on software, productivity and operations.

Your employees can also have their own second brain - their own PA, which is driving huge productivity results in admin and mundane tasks, once it's tuned into your real brain and the company's brain.

Why they turn up together

The second brain gives agents what they need to know and the control plane gives them somewhere safe to act - an office where you lay down the rules.

A company with the first and without the second has clever answers and no way to use them at scale.

A company with the second and without the first has beautifully governed agents that know nothing about the business and produce output any competitor could generate in an afternoon.

The risks

A second brain inherits every permissions mistake underneath it. Years of over-shared drives become searchable in an afternoon, which is how salary spreadsheets and redundancy plans end up in front of people who should never see them.

So only feed the brain what it really needs to know - and keep an eye on permissions. Small companies have far less of this to untangle, which is one reason AI is easier for them than for large firms. The board question is whether permissions were fixed before the index was built.

If the brain is given everything all at once, expect old answers with tremendous confidence. Retention, deletion and the ability to show what the system knew on a given date all matter, particularly once a dispute starts and the whole store becomes disclosable.

Each time an answer is provided, you are effectively producing a new document on the topic. That's fine providing it doesn't contain sensitive information.

A control plane concentrates risk by design. It holds credentials for everything, which makes it attractive in the estate - but one compromise here hits a company hard.

Agent isolation, monitoring and a tested kill switch are essential.

If I were on your board, I would ask

  • Who owns these?
  • How many agents are live, and watch whether the answer comes back as a number or as a pause.
  • What happens if your main model provider doubles its price or falls over, and listen for whether switching is a project or a configuration change.
  • What the second brain got wrong last month and how you found out, because a team that can't answer that is measuring nothing.

Good luck

Dan

CEOs read The Executive Summary. Do you?

The AI and growth briefing for the people in the room when the decisions get made.