This blog continues from Part 1’s exploration of Living AI, shifting from its promise to the risks and governance challenges enterprises must address.

New technologies often spread unevenly. Smaller firms adopt them quickly, while larger organizations take longer to absorb them into existing processes and control structures. Artificial intelligence is proving no exception.

The latest shift is toward what I call "Living AI": agents capable not only of consuming information but also of generating new context, producing artifacts, modifying workflows, and influencing their own future behavior. These systems promise significant gains in productivity, but they also introduce new operational challenges.

For large enterprises, the problem is not a lack of technological capability. Many already possess the infrastructure, talent, and capital required to deploy advanced AI systems. But challenges remain; autonomous agents must operate within environments shaped by decades of accumulated processes, regulatory obligations, security controls, and organizational complexity. 

As a result, the barriers to adoption grow disproportionately with scale. Four challenges become particularly important to address: context management, span of control, identity, and governance.

The Four Risks That Compound with Size

1. Context Management

A Living AI agent is not just consuming context. It is producing it. It generates intermediate data, writes notes to itself, and leaves artifacts that shape future behavior.

In a 50-person company, context is bounded: one CRM, one drive, one chat tool, one shared definition of “customer.” In a global enterprise, “customer” can mean different things across systems, access rules, naming conventions, and years of technical debt. Stale memory, leaked context across business units, or grounding in ungoverned data does not just produce a wrong answer. It produces a confidently wrong answer that propagates and poisons agent context. Context complexity scales nonlinearly with organization size.

2. Span of Control

What is each agent allowed to do, and how far can one action propagate?

A Living AI agent that can write a script can also write a destructive one. An agent that can send an email can also send 10,000. In a small org, the blast radius of a bad action is bounded. In a global enterprise, the same action can cascade across business units, geographies, and regulatory regimes before anyone notices. Span of control must be designed explicitly rather than aligned one-to-one with the human user’s permissions 

3. Identity and Access for Non-Human Actors

Over-permission an agent and a single prompt injection becomes a privileged attacker with the keys to your business. Inherit the user’s full access and every employee’s footprint can act at machine speed. Every agent needs a verifiable identity, scoped credentials, short-lived tokens, and auditable delegation chains. A startup can roll this out quickly; a multinational with overlapping identity providers, legacy AD, and M&A-acquired tenants faces a multi-year program. Until then, the security exposure will grow alongside the number of systems, identities, and permissions involved.

4. Governance and ROI

With token costs becoming a major budgetary category, executives are looking for solutions that manage token consumption and tie consumption to tangible business benefits and ROI. Model consumption, infrastructure spending, and software licensing are relatively easy to measure; productivity gains are not. The further decision-makers are removed from day-to-day operations, the harder it becomes to distinguish genuine business impact from anecdotal success stories. A centralized and consistent measurement system becomes critical here. 

As agents are granted broader access to enterprise systems, security teams face a familiar challenge in a new setting: balancing control with usability. Overly restrictive policies can discourage adoption, while insufficient controls can create disproportionate risk. The task for CISOs is not merely to approve AI projects, but to establish policies and governance mechanisms that scale across hundreds of use cases without becoming an obstacle to deployment. 

The Large Enterprise Disadvantage

Smaller organisations can deploy Living AI rapidly due to limited context, identity, and governance surfaces. A 200-person firm can integrate tools like Claude Cowork across systems in weeks and transform workflows.

Global 2000 enterprises cannot move as quickly — at least not safely. They need a structured program that centralises context and enforces narrow, purpose-built agents with guardrails. They must also treat agent identity as a core IAM discipline. Execution should be governed with clear ownership, budgets, and measurable outcomes. 

Those that execute well will close the gap; those that don’t risk falling behind faster, more agile competitors compounding productivity gains.

How Wipro Ventures Is Backing the Builders

At Wipro Ventures, we invest in early- to mid-stage enterprise startups and bring them directly into Wipro's Global 1000 client base. Our thesis on Living AI is straightforward: the winners won't be those with access to the best model. They'll be those who operationalize self-modifying agents responsibly and at scale. Five of our portfolio companies sit squarely at that frontier:

Factory.ai - Agent-native software development. Factory replaces line-by-line coding with parallel, autonomous “Droids” that handle feature development, migrations, modernization, code review, and testing across the SDLC. This is Living AI for engineering: agents that write code, produce test data, and build their own tooling to ship work faster. Wipro is integrating Factory into modernization deals to compress engineering cycles at scale. 

Ema - The Universal AI Employee. Ema deploys AI “employees” that own full workflows including recruiting, support, finance operations, and proposals. It is powered by a Generative Workflow Engine and EmaFusion, which blends 100+ public and private LLMs. For enterprise adoption, Ema redacts sensitive data before using public models and meets SOC 2, ISO 27001, HIPAA, and GDPR. Wipro is deploying Ema for SOX-compliant Procure-to-Pay and Order-to-Cash automation.

Arcade.dev - The actions runtime for enterprise agents. AI agents should not be entrusted to make security decisions about their own tool calls or to manage secrets. Arcade provides the enforcement layer that sits between AI agents and enterprise actions, brokering access, applying policy guardrails, and extending existing IdP, IGA, and PAM controls into agent workflows.

Pay-i - FinOps and governance for GenAI. You can’t govern what you can’t measure. Pay-i brings GenAI observability and financial control by attributing model and agentic workflow costs to use-case-level KPI outcomes, while enforcing live spend controls. It turns Living AI from an open-ended cost center into a governed, value-generating system.

Lineaje - Software supply chain security and AI policy governance. Lineaje helps enterprises verify the provenance of open-source and third-party software components, automate XBOM management, and remediate critical vulnerabilities across the software lifecycle. Its UnifAI platform extends this discipline to agentic AI by discovering AI assets as they are built and enforcing security, data, identity, and compliance policies across development and runtime. 

Together, Factory, Ema, Arcade, Pay-i, and Lineaje give clients five building blocks to support Living AI capabilities in an enterprise that are secure, compliant, and measurable.

The Bottom Line

Living AI is a new execution layer for knowledge work: agents that write their own code, shape their own data, and build their own tools. The hyperscalers have validated the pattern; the open-source community has accelerated it; small organizations are already running with it. For large enterprises, the prize is larger, but the path forward is narrower. At Wipro Ventures, we are betting on, and building with, the companies making the disciplined path possible.

In my next post, I'll be exploring where harness engineering and loop engineering can play a part in this journey.

About the Author

Gideon Wilk
Director, Wipro Ventures

Gideon leads strategy at Wipro Ventures and works closely with our portfolio companies to evangelize their solutions across Wipro's markets. Prior to joining Wipro Ventures, Gideon acquired and operated ezTaxReturn, a tax-preparation software company that has served millions of tax returns. He holds a Bachelor of Applied Science (Industrial Engineering) from the University of Toronto and an MBA from Harvard Business School.