Capital One’s Agentic AI Strategy: Data, Security & AI Platforms

The rapid growth of agentic AI has pushed enterprises beyond simple chatbot experiments and prompt-based applications. As AI systems become capable of making decisions, using tools, and taking actions on their own, companies need more than powerful models. They need reliable data, strong governance, secure infrastructure, and a platform that can support these systems at scale.

That is the approach Capital One has taken with its agentic AI strategy.

Rashmi Shetty, Vice President of Enterprise AI at Capital One, says organizations should treat agentic AI as an end-to-end technology system rather than simply another application layer.

“We are dealing with agentic systems that can actually take action,” Shetty told CIO Dive. “Agentic AI now must be treated as an end-to-end system.”

Shetty leads the engineering organization responsible for enterprise platforms at Capital One. Her team works on operationalizing generative AI and agentic AI applications across several areas of the business, including retail banking, risk, legal, and compliance.

The bank’s current AI strategy builds on more than a decade of broader technology modernization.

Capital One Built Its AI Foundation Over Time

Capital One did not begin its agentic AI journey from scratch.

During the company’s Q2 2026 earnings call in July, CEO Richard Fairbank said the bank had spent the previous 14 years transforming its technology infrastructure “from the bottom of the tech stack up.”

The company continues to invest in foundational technology, AI infrastructure, and customer-facing AI experiences.

That long-term investment has helped Capital One move from experimenting with generative AI to operating agentic systems in real business environments.

Today, the bank has both internal and customer-facing agentic AI applications.

One of its notable external examples is Chat Concierge, which was also among Capital One’s first multiagent applications. The system has been running in production for more than two years and helps customers navigate the car-buying process.

Instead of simply answering questions, the application can help customers move through different stages of the buying journey. It can connect customers with dealers, request test drives, and help advance the purchase process digitally.

Internally, Capital One also uses agentic AI to improve parts of the customer service experience, according to Shetty.

Why Data Is Central to Capital One’s Agentic AI Strategy

For Capital One, the foundation for agentic AI was established well before autonomous AI systems became a major enterprise trend.

Shetty points to the bank’s long-term investment in data infrastructure as one of the reasons it has been able to operationalize agentic applications.

That includes well-governed data pipelines, reliable data management, and strong data lineage.

For an AI agent to take meaningful action, it needs accurate context. Without trustworthy information about customers, transactions, business processes, and other relevant data, even a capable model can make poor decisions.

“Providing agent context becomes that much easier with a very strong data foundation,” Shetty said.

This is an important distinction for enterprises considering agentic AI. Building an AI agent is not simply a matter of selecting a powerful model and connecting it to a few tools. The quality and accessibility of the underlying data can directly affect how effectively the agent operates.

A Platform-First Approach to Agentic AI

Once the data foundation was in place, Capital One focused on another important part of its strategy: building an enterprise platform that could support agentic applications safely.

Rather than allowing individual teams to create disconnected AI agents and add governance later, the bank takes a platform-first approach.

The idea is straightforward: establish security, governance, compliance, and operational controls at the platform level before developers start building individual agentic applications.

According to Shetty, an enterprise platform should include codified policies and policy checks, runtime controls, compliance requirements, and cybersecurity guardrails.

With those capabilities already built into the underlying platform, developers can create and deploy AI agents more quickly without having to reinvent security and governance controls for every application.

The alternative can create significant problems.

“Retrofitting any governance and runtime security to fragmented, ad hoc agentic applications after they are built is far more difficult,” Shetty said. “It has to be thought through before building the agentic applications.”

For organizations moving from AI experimentation into production, this distinction can become particularly important. The more autonomous an AI system becomes, the more difficult it can be to add controls after the system is already deeply integrated into business processes.

Testing and Evaluation Need to Be Built In

Agentic AI also requires a different approach to testing.

Traditional software testing alone may not be enough for systems that can reason, select tools, interact with multiple systems, and execute tasks.

Shetty recommends using several validation methods, including rule-based checks, sandbox simulations, and AI evaluations, commonly referred to as evals.

These approaches can help organizations test how an agent behaves under normal conditions as well as when it encounters unexpected or potentially dangerous situations.

Evaluation can also be used to identify vulnerabilities, test compliance requirements, and detect attempts to bypass an AI system’s safeguards.

For enterprise deployments, the goal is not simply to determine whether an AI model produces a correct answer. Organizations also need to understand whether an agent follows policies, uses tools appropriately, handles sensitive information correctly, and behaves as expected throughout a complete workflow.

Observability Becomes Essential for Multiagent Systems

As AI agents become more complex, companies also need visibility into what happens during an agent’s execution.

This is where observability becomes especially important.

Shetty says Capital One uses observability to track areas such as agent trajectories, tool accuracy, and end-to-end latency across multiagent workflows.

An agent may call several tools, interact with multiple systems, and pass information between different components before completing a task. Without sufficient visibility, diagnosing a failure can become extremely difficult.

Shetty also emphasizes that successful AI observability depends heavily on domain knowledge rather than simply selecting a particular monitoring tool.

Evaluation and observability therefore work together.

“There are so many things the evaluation capabilities can bring to the table. You can test vulnerabilities, it can prevent jailbreaks, enforce strict compliance,” she said. “Observability and evals go hand-in-hand.”

For enterprise AI teams, this means monitoring should not be treated as an afterthought. Understanding how an agent behaves is part of managing the system itself.

Why AI Models Alone Are Not Enough

Another lesson from Capital One’s approach is that the AI model is only one component of an agentic system.

Organizations also need what Shetty describes as a “harness strategy” around the model.

An AI harness provides a structured layer for controlling how agents operate. It can help standardize and enforce controls such as tool permissions, access policies, and other operational requirements.

This becomes increasingly important as organizations connect AI agents to business systems.

A model might be capable of calling a tool, but an enterprise needs to determine whether it should be allowed to call that tool, under what circumstances, with which permissions, and what should happen if something goes wrong.

The harness provides a way to put those boundaries around the model.

Human Oversight Still Matters

Greater AI autonomy does not mean removing people from every workflow.

Capital One also emphasizes the importance of determining where human oversight should remain in the process, particularly when agents are handling high-risk actions.

A human-in-the-loop strategy can establish points where an employee must review or approve an action before the system proceeds.

The appropriate level of human involvement will vary depending on the application and the potential consequences of an incorrect action.

For low-risk tasks, an agent may be able to operate with minimal intervention. For sensitive financial, legal, compliance, or customer-impacting decisions, organizations may require additional approvals and controls.

What CIOs Should Consider Before Deploying Agentic AI

For technology leaders, Capital One’s experience highlights several questions that should be answered before deploying agentic AI at scale.

Does the organization’s data foundation provide reliable and traceable information?

Can the existing platform support agent workloads?

Are security and compliance controls built into the platform rather than added after deployment?

Can teams evaluate agent behavior before and after production deployment?

Is there sufficient observability to understand how agents make decisions, use tools, and execute workflows?

And, perhaps most importantly, where should human approval be required?

These questions become increasingly important as organizations move from isolated AI experiments to systems that can take real-world actions.

The Long-Term Goal: Secure, Governed and Scalable AI

Capital One’s agentic AI strategy reflects a broader shift in how enterprises are approaching AI deployment.

The focus is moving away from simply finding the most capable model and toward building the infrastructure around that model. Reliable data, governance, security, evaluation, observability, permissions, and human oversight all play a role in determining whether an agentic AI system can operate safely in production.

For Capital One, these capabilities are being built into the enterprise platform rather than added individually to each application.

“One of our core values within our organization is to ensure agentic and GenAI applications are well managed, well governed, secure and standardized in such a way that they meet the regulatory and compliance needs for Capital One, as well as ease the path of development and deployment,” Shetty said.

As agentic AI continues to move into critical business workflows, that platform-first approach may become an increasingly important consideration for enterprises looking to scale AI beyond experimentation and into everyday operations.


Discover more from AiTechtonic - AI & Informative News

Subscribe to get the latest posts sent to your email.