Take the phenomenon of "Shadow AI," for instance: 1. When AI tools are used across different departments, how do you prevent sensitive data from leaking? 2. With departments adopting all sorts of disparate tools, how do you actually achieve centralized governance and control?
Although Microsoft has rolled out an AI governance framework, I think practical implementation remains an uphill battle. Their approach isn't hard to grasp—it essentially boils down to logging activities before and after an Agent executes tasks to enable traceability, but that doesn't solve the core problem.
So, if you want to build a product in this space, I believe it's going to be extremely difficult unless you can come up with a genuinely new approach that truly resolves these pain points.