All posts

Box's CEO says the enterprise is in the messy period, and means it as a description

Aaron Levie is bullish on agents and blunt about where they actually are. The gap between pilot and production is structural, not temporary, and that is the most useful sentence any vendor CEO has offered this year.

Aaron Levie

CEO, Box

Authority Report

An Authority Report is where we read what people with real operating responsibility said in public, in their own words, and work out what it means for a company that isn’t them.

Four of the five people in this series are pressing the accelerator. This one is the counterweight, and he is not a sceptic, Aaron Levie sells enterprise AI and believes in it loudly. What makes him worth reading is that he is specific about where it currently is.

What he says

On the state of enterprise deployment:

Right now, we’re in the messy period where we have to figure some things out.

He names what has to be figured out (architecture, security, governance) which is what separates this from the usual “early days” hedge. And on where it goes:

We are still in the very early stages of what agentic work looks like in the enterprise and what the rollout looks like.

The prediction underneath both is that agents will become the largest consumer of software and data inside a company, which forces a rethink of how systems grant access to sensitive information.

That last point is the one with teeth, and it is not about capability at all. It is about permissions.

Why the permissions point is the real one

Every access-control system in a company was designed around a person: a named human, in a role, with a job that explains why they can see something. The audit question has always been “should this person have access”, and the answer has always been checkable by asking what they do.

An agent breaks that model in a specific way. It reads at machine speed and volume, and it holds permissions that belong to someone else.

An agent acts with someone’s permissions but is not that someone. It can be asked a question by a person whose own permissions are narrower than the ones it holds, at which point it becomes an elegant way to defeat access control without anyone intending it.

This is not a theoretical concern. It is the single most common reason a working knowledge assistant never gets approved: it works, someone asks it a question whose answer sits in a document they should not see, and the project stops there.

Levie’s framing, agents as the biggest users of software and data, is the general form of that specific failure. The gap is structural because permission models were built for a different kind of user, not because models need another generation.

Why “messy period” is more useful than either alternative

Two other framings dominate the market, and both are less useful.

“AI changes everything, deploy now” is not wrong about direction and gives you nothing to do on Monday, because it does not name the obstacle.

“AI is overhyped, wait” is contradicted by the deployments that do work, the ones with a defined process, an owner and a measurement.

“Messy period, and here is what has to be figured out” is the only one of the three that produces a task list. Architecture, security, governance. None of those are model problems, all of them are solvable, and none of them are solved by waiting for a better model.

It also fits the measured record uncomfortably well.

95 % of enterprise AI pilots produce no measurable result.

MIT Media Lab, Project NANDA. The researchers put the cause in the approach rather than in model quality or regulation, see why pilots stall

Levie is describing the same gap from the vendor side.

What this means at 40 people instead of 40,000

The permission question arrives earlier than you think. It arrives on the first knowledge assistant, and it arrives as an organisational question rather than a technical one: who is allowed to see what, decided by someone with the authority to decide it. In a smaller company that is usually one conversation, which is a genuine advantage: you can have it this week.

Governance at your size is a list, not a framework. Which systems the agent may read. Which it may write to. What it must never do without a person. Three lines per agent. The failure mode is not having too little governance, it is having none written down and discovering the gaps individually.

“Messy” is permission to start. The messy period is not a reason to wait for it to end. It is a description of what running these systems currently feels like: some things work well, some need a person in the loop, and the boundary moves. Companies that expect that ship. Companies that expect a finished product keep piloting.

And take the bullishness seriously too. If agents do become the largest consumers of software and data in a company, then the work of deciding what they may see is not overhead: it is the same work as deciding what an employee may see, done once, for a category of user that is about to get much bigger.

The read

The most valuable thing a vendor CEO can say is a limitation, because it is the statement least aligned with his own interest. Levie’s is precise: the gap between pilot and production is architecture, security and governance, and it is structural rather than temporary.

For a mid-sized company that translates into an unglamorous instruction. Before the next agent, write down what it may read, what it may write and what it may never do alone. That is fifteen minutes, it is the thing that stops the project at week six if you skip it, and it does not get easier by waiting for a better model.

Frequently asked questions

What does Levie mean by the messy period?

That enterprises are moving from chat-based AI to agents that use tools and do real work, and that architecture, security and governance have not caught up. He describes the gap as structural rather than a temporary state.

Why would agents be the largest users of software?

Because they act continuously and at machine speed across systems that were designed for occasional human access. If that holds, access control designed around named people becomes the binding constraint.

Is this an argument for waiting?

No, and Levie does not make it one. It is an argument for treating permissions and governance as part of the build rather than as a review at the end.

What is the minimum governance for one agent?

Three lines: what it may read, what it may write, what it must never do without a person. Written down, per agent, before it goes live.

How does this square with the more bullish voices in this series?

It does not contradict them. Shopify, Salesforce and Amazon describe what happens when it works; Levie describes what has to be true first. Both halves are the same story, and only one of them makes a headline.


Photo: Aaron Levie, by Fortune Live Media, CC BY 2.0, via Wikimedia Commons. Quotes as reported by Fast Company.

Related reading