Before getting swept up in the excitement of building agentic AI, enterprises need to invest in a robust data foundation and adopt a platform-first mindset.
Agentic AI is a reality for many enterprises, a technology that’s moved beyond prompting exercises, and calls for a clear focus on the underlying technology, said Rashmi Shetty, VP of enterprise AI at Capital One.
“We are dealing with agentic systems that can actually take action,” Shetty told CIO Dive. “Agentic AI now must be treated as an end-to-end system.” Shetty leads the engineering organization for enterprise platforms within Capital One, operationalizing generative AI and agentic AI applications within different lines of business, such as retail bank, risk, legal and compliance.
Prior to the rise of agentic systems, the bank spent the last 14 years transforming its technology “from the bottom of the tech stack up,” CEO Richard Fairbank said during Capital One’s Q2 2026 earnings call in July.
“We’re way down that path, and we continue to invest in some very powerful foundational capabilities as well as AI infrastructure and specific AI experiences,” he said.
Now, Capital One operates both internal and external agentic AI use cases.
Chat Concierge was one of the bank’s marquee external use cases and one of its first multiagent applications, deployed in production over two years ago. The agentic app helps customers navigate the car buying process, including connecting to a dealer, requesting test drives and digitally advancing through the purchase.
Internally, the bank deploys the technology to improve the customer service journey, Shetty said.
Shetty attributes the bank’s current use of operational agentic systems to long-term investments in a robust data foundation with well-governed data pipelines and data lineage.
“Providing agent context becomes that much easier with a very strong data foundation,” she said.
Shaping a clear deployment strategy
The next critical step for Capital One was adopting a platform-first mindset.
Preparing an enterprise platform for agentic use cases with codified policies and policy checks, runtime controls, compliance and any other mandatory enterprise cybersecurity guardrails allows developers to build AI agents quickly on top of a secure foundation, Shetty said.
“Retrofitting any governance and runtime security to fragmented, ad hoc agentic applications after they are built is far more difficult,” Shetty said. “It has to be thought through before building the agentic applications.”
Enterprises need to plan for validating their agentic systems through multiple strategies including rule-based validation, sandbox simulations and evaluations, also known as evals, she said.
Observability, too, has become another crucial element in the agentic AI era. Shetty said observability allows the company to track agent trajectories, tool accuracy and end-to-end latency across multiagent workflows. Observability is enabled by deep domain knowledge, rather than any single tool being a key difference maker, she said.
“There are so many things the evaluation capabilities can bring to the table. You can test vulnerabilities, it can prevent jailbreaks, enforce strict compliance,” she said. “Observability and evals go hand-in-hand.”
Organizations also need to understand that models alone are insufficient, and that a good harness strategy around the model is necessary, Shetty said. A harness allows enterprises to standardize and operationalize controls around AI agents, such as tool permissions, she added.
Lastly, enterprises need to have a plan and understanding of where a human-in-the-loop strategy needs to come into the picture for high-risk actions.
CIOs should ask themselves if their platforms are able to handle agentic workload executions and fully understand the risks involved, Shetty said, as long-term success will depend on resilience and scale.
“One of our core values within our organization is to ensure agentic and GenAI applications are well managed, well governed, secure and standardized in such a way that they meet the regulatory and compliance needs for Capital One, as well as ease the path of development and deployment,” she said.





