Governance, Not AI Models, Biggest Enterprise Barrier: Red Hat's Vincent Caldeira
Red Hat APAC CTO Vincent Caldeira says governance, rather than AI model capability, has become the biggest challenge for enterprises moving artificial intelligence into production. He highlighted rising concerns around security, cost, data quality, AI agent behaviour and the need for stronger guardrails as companies scale AI systems.
Written by
Jyoti Mukherjee

New Delhi: As enterprises move artificial intelligence (AI) from small-scale experiments to systems used by employees and customers, governance rather than the underlying AI model has emerged as the biggest challenge, according to Red Hat APAC Chief Technology Officer Vincent Caldeira.
Speaking to ET AI, Caldeira said companies deploying AI at scale are increasingly concerned about two major issues — cost and governance. While an AI proof of concept may be relatively easy to manage for a handful of users, the risks and economics become significantly more complicated when the same system is deployed to hundreds of thousands or millions of customers.
Governance Goes Beyond Cybersecurity
According to Caldeira, enterprise AI governance is not limited to protecting systems against cyberattacks. It also involves monitoring and controlling the consequences of decisions made by AI systems.
An AI application could provide an incorrect recommendation to employees, generate an inappropriate response to a customer or make an inaccurate decision in a business workflow. Enterprises therefore need mechanisms to assess and govern the outcomes produced by AI systems.
This becomes particularly important for organisations operating in highly regulated sectors such as banking, financial services, telecommunications and transportation.
Red Hat's technology is used by several major Indian organisations, including the National Stock Exchange, BSE, UIDAI, Bharti Airtel, Jio Platforms, Tata Motors, IndiGo, State Bank of India, Indian Bank and Bank of India, among others.
AI Agent Security Remains a Major Challenge
Caldeira said agentic AI security has become a much more prominent concern as enterprises explore autonomous systems capable of taking actions and interacting with tools and data.
He argued that companies are still struggling to determine whether an AI agent is sufficiently secure and reliable to be deployed in a production environment, particularly within regulated organisations.
Importantly, Caldeira said the industry does not yet have a platform capable of making an AI agent completely secure out of the box. Although individual technologies and standards are emerging across different layers of AI security, they have not yet been brought together into a comprehensive solution.
This means enterprises must carefully evaluate vendors and their claims rather than assuming that security can simply be switched on when an AI agent is deployed.
Red Hat Focuses on Evaluation-Driven AI Development
Caldeira said Red Hat is addressing these challenges through an approach it calls evaluation-driven development.
Under this model, an AI system is repeatedly evaluated during development and monitored as it moves towards production. The objective is to identify problems early and ensure that the system meets the required standards before being deployed at scale.
Red Hat is also working on real-time guardrails and controls within its cloud-native platform. The idea is to ensure that AI applications can inherit important security and governance controls from the underlying infrastructure.
Caldeira described this approach as "shift down", where identity management, observability, access controls and security policies are incorporated into the platform rather than leaving every application developer to implement them independently.
Model Choice Is No Longer the Central Question
Caldeira also challenged the industry's focus on comparing individual AI models.
He argued that the choice of model is no longer the most important decision when designing an enterprise AI system. Instead, companies should assess the complete system surrounding the model.
This includes how an AI application retrieves information, which tools it can access, how it performs tasks and what controls are placed on an AI agent's actions.
A highly capable frontier model can still deliver poor results if it receives inaccurate or irrelevant information from the enterprise's data systems.
Poor RAG Systems Can Undermine Powerful AI Models
One of the major issues highlighted by Caldeira is the quality of Retrieval-Augmented Generation (RAG) systems.
RAG allows an AI model to retrieve relevant information from external or enterprise data sources before generating an answer. However, if the retrieval system supplies inaccurate, incomplete or irrelevant information, even a highly advanced AI model may produce poor results.
Caldeira said enterprises sometimes blame the model when the actual problem lies in the surrounding system, particularly poor document retrieval and data quality.
This means businesses need to evaluate their entire AI architecture rather than judging performance solely on the basis of the language model being used.
AI Costs Are Another Enterprise Concern
Alongside governance, cost has emerged as another major obstacle to scaling enterprise AI.
Caldeira said some companies have restricted access to coding assistants after high usage costs began to reduce the productivity benefits generated by the tools.
One potential solution is model routing, where simpler tasks are assigned to smaller and less expensive models while more complex queries are directed to powerful frontier models.
Caldeira said Red Hat uses this approach internally and believes intelligently routing coding requests between different types of models can potentially reduce costs by 80-90%.
Enterprise AI Moves Beyond the Pilot Stage
The comments come at a time when companies are increasingly moving beyond AI experimentation and looking at how these systems can be deployed reliably across their organisations.
The transition from pilot projects to enterprise-scale AI brings new requirements around identity, access, observability, security, governance, data quality and cost management.
For businesses, the challenge is therefore no longer simply finding the most powerful AI model. Instead, companies need to build an ecosystem that ensures AI systems operate safely, provide reliable information and remain economically viable at scale.
Caldeira's assessment suggests that the next phase of enterprise AI adoption will depend as much on governance and infrastructure as on advances in model capabilities.
Keep reading
More in Technology
Technology
With Laya, Sol, Articul8 Puts Language Scholars at Heart of Heritage AI
AI company Articul8 is developing a heritage-focused approach to artificial intelligence through Laya, a Sanskrit model, and Sol, a Tamil m…
Technology
Scientifically Speaking: The Mouse With Human Brain Tissue
Scientists have transplanted lab-grown human brain tissue into genetically engineered mice, creating a new model for studying human brain de…
.jpg&w=3840&q=75)
Technology
Nippon Express Group Eyes 3x India Business by 2028, Flags India’s Scale as a Challenge
Japanese logistics major Nippon Express Group plans to triple its India business by the end of 2028, targeting revenue of around $380 millio…

Technology
AI Can Scale Quickly, but Traditional Governance Is Not Enough: Why Enterprises Need a Control Layer
Artificial intelligence can move rapidly from pilot projects into products, workflows and enterprise decision-making, but traditional govern…

Technology
Course Correction? How the Last 10 Days Changed the Way We See AI
A series of events over the past 10 days has sharply changed the debate around artificial intelligence, shifting attention from AI's economi…

Technology
Applied Materials Sees No Demand Risk for India's Chip Push; Ecosystem, Infrastructure the Real Tests
Applied Materials India president Avi Avula said demand is unlikely to be the main obstacle to India's semiconductor ambitions, with both do…
