Partnership

The Barrier to Enterprise AI Isn’t the Model. It’s Trust.

•3 min read

Every regulated enterprise we talk to says it wants AI in production. Almost none of them are actually blocked by the model.

According to McKinsey’s 2026 AI Trust Maturity Survey, nearly two-thirds of respondents cite security and risk concerns as the top barrier to fully scaling agentic AI. Governance maturity tells the same story from the other direction: only about a third report maturity levels of three or higher in strategy, governance, and agentic AI controls. Put those findings together and the gap is clear. Enterprises need to be able to verify what their AI systems are doing before they can confidently give them more responsibility.

Picture an enterprise marketing team preparing a product launch across several markets. AI has turned internal research into campaign content, and a reviewer asks what supports a specific product claim. A log showing the final output leaves the question unanswered. The team needs to see which sources informed the claim, how it changed during generation, and what checks were applied before approval. As a CPO, I see a product requirement here: the person accountable for publishing the work needs usable evidence behind it.

That’s the gap we’ve built our next phase of work around. We’ve already built workflow tracing that helps authorized teams inspect how supported AI workflows operate. For enterprises putting their brand, customer data, and internal knowledge into an AI workflow, “trust us” is not enough. Now, as an IBM Business Partner, we’re taking the next step: CambrianEdge.ai’s solution will be built with watsonx, with planned capabilities spanning AI governance, security, and observability.

The technologies we’re planning for those capabilities have distinct roles: IBM watsonx.governance for AI governance, IBM Guardium AI Security for AI security, and IBM Instana for observability. The intended benefit is to give authorized risk and compliance teams a clearer record of supported workflow activity, visibility into operational behavior, and evidence to support review. The specific integrations and their scope remain subject to validation.


There are specific capabilities behind that direction. The faithfulness metric in IBM watsonx.governance evaluates how grounded a model’s output is in the context provided to the model. This can provide a useful signal for reviewing AI-generated responses, but it should not be interpreted as proof that the underlying claim is factually true. In our research workflows, we’re exploring how that signal could help reviewers identify a statement that goes beyond its cited source.


For observability, we intend to use IBM Instana to strengthen visibility across supported workflows. IBM describes Instana as tracing requests across agents, LLM calls, tools, and services and correlating performance, cost, and quality signals. Once implemented and validated in our solution, those capabilities could help our team investigate operational issues and assess where closer review is needed.


Data protection needs the same level of specificity. Our approach is designed around limits on how model providers may use customer data, controlled access to those providers, and tenant-level separation within the platform. The scope of those protections needs to be clear in the applicable agreements and technical documentation. From a product perspective, customers should be able to understand how their information is handled and which protections apply to their deployment.


Along the model-access path, we’re also exploring IBM Guardium AI Security’s prompt and response scanning to help detect prompt injection, personal information exposure, and data leakage. These additional checks would address information entering and leaving an AI interaction. Depending on the policies and implementation we validate, they could provide an earlier opportunity to identify sensitive information and take action before it moves further through a workflow.


For a regulated buyer, this level of visibility needs to become a baseline expectation. A review step after generation still has a role, but it needs support from controls throughout the workflow. The product should surface the evidence and the exceptions early enough for someone to act. If the person approving the work has to reconstruct everything themselves, we have left a critical part of the job unfinished.


The solution will be built with watsonx, and we’ll share details of the individual capabilities as they are validated and deployed. The benefits described here are what we intend to deliver. The direction is clear: AI that an enterprise can stand behind needs governance built into how the product operates. As a co-founder and CPO, that is part of the product promise I want us to deliver.


If you’re evaluating AI for an environment where “we’ll fix it in the next release” isn’t a real answer, this is worth a closer look.


Frequently asked questions

For most regulated enterprises it is trust, not the model. McKinsey’s 2026 AI Trust Maturity Survey found nearly two-thirds of respondents cite security and risk concerns as the top barrier to fully scaling agentic AI, and only about a third report maturity levels of three or higher in strategy, governance and agentic AI controls. Enterprises need to be able to verify what their AI systems are doing before they give them more responsibility.

A log shows the final output, not what supports it. To review a claim, a team needs to see which sources informed it, how it changed during generation, and what checks were applied before approval. The person accountable for publishing the work needs usable evidence behind it.

As an IBM Business Partner, CambrianEdge.ai’s solution will be built with watsonx, with planned capabilities spanning AI governance, security and observability. The technologies planned are IBM watsonx.governance for AI governance, IBM Guardium AI Security for AI security and IBM Instana for observability. The specific integrations and their scope remain subject to validation, and details will be shared as capabilities are validated and deployed.

It evaluates how grounded a model’s output is in the context provided to the model. It can be a useful signal when reviewing AI-generated responses, but it should not be interpreted as proof that the underlying claim is factually true. CambrianEdge.ai is exploring how that signal could help reviewers identify a statement that goes beyond its cited source.

The approach is designed around limits on how model providers may use customer data, controlled access to those providers, and tenant-level separation within the platform. The scope of those protections should be clear in the applicable agreements and technical documentation, so customers can understand how their information is handled and which protections apply to their deployment.

Visibility into what the AI is doing should be a baseline expectation. A review step after generation still has a role, but it needs support from controls throughout the workflow. The product should surface the evidence and the exceptions early enough for someone to act, so the approver doesn’t have to reconstruct everything themselves.
CambrianEdge.ai Logo
Shrey Malhotra

Shrey Malhotra

As the Co-Founder & Chief Product Officer of CambrianEdge.ai, he is building the world’s first human-centered, AI-native marketing platform. A product architect and innovator, he fuses human creativity with AI precision to help marketers work faster, think smarter, and create with impact.

Share Pattern

Share with your community!


Related Blogs

View All