Skip to main content

M.R. Asks 3 Questions, CEO & Co-founder, Autumn8 AI, Indra Mohan

By September 18, 2026Article

For the last 5 years, Mohan has served as Co-Founder and CEO of Autumn8 AI, a company focused on providing a platform for Agentic AI Compliance.

With an MBA from Harvard, a Masters from Rensselaer Polytechnic Institute, and a Bachelors from the Indian Institute of Technology, Madras, Autumn8 AI’s has been built on Indra’s working knowledge and business systems approach to deliver on the the growing need for the governance, oversight, and responsible application of artificial intelligence as AI systems.

Specifically, Autumn8 provides an Agent-Native AI Platform for Governance, Risk and Compliance (GRC), that reads a company’s policies, code and cloud systems and maps them, continuously, to every control framework, turning compliance from a periodic audit into a live system.

As this week’s headlines are splashed with even more conversations about the security of AI, my conversation with Indra is very timely.

M.R. Rangaswami: What impact is Artificial Intelligence going to have on Governance, Risk, and Compliance?

Indra Mohan: AI will, over time, drive a complete reboot of the GRC application and platform eco-system, because the primary mode of interaction will change from “people-to-people” to “agent-to-agent”.   

Today’s GRC platforms are essentially stand-alone portals that automate the workflows required to verify that people have completed the required compliance tasks. Setting up these workflows, and then changing them as the customer’s environment evolves, requires a lot of manual effort.    

AI-first GRC platforms are now emerging with a completely different approach.  With these platforms, the center of gravity is agent-to-agent communication with the customer’s AI Assistants (i.e. Claude, Open AI, or Gemini instances as well are other AI models) and agentic applications.   The required compliance workflows are automatically created and can seamlessly interoperate with the rest of the customers workflows, which will result in automating most of the manual effort that is currently required for and beyond GRC.   

The deployment of AI-first GRC platforms will have many benefits.  Taking humans mostly out of the loop will result in very significant cost savings for current GRC functions.  The use of agents for monitoring and evidence collection will transform GRC verification from periodic audits to continuous verification.  Since agent swarms can monitor a company’s environment faster and more comprehensively than humans, their deployment will result in better and deeper GRC.  

M.R.: How do you see the reboot towards AI-first GRC Platforms evolving?

Indra: We are seeing the fastest initial adoption from Seed or Series A-stage companies that are not encumbered by their legacy environment.  For these companies, the main drivers are economics (i.e. lower costs) and new capabilities that agent-to-agent communication offers.  These companies view using the current stand-alone portals there are offered by conventional platforms to be cumbersome and inefficient.   

Larger, more established companies that are early adopters are also deploying AI–first platforms but are integrating them with the traditional compliance platforms that they have already deployed and continue to use as their system of record. I expect that hybrid deployments will become more widespread across enterprises for a while, and that AI-first platforms will incrementally replace traditional platforms.

One trend that could accelerate the adoption of AI-first platforms is the widespread development and use of agents by enterprises.  This will drive up the performance requirements for continuous compliance, which in turn would be better addressed by AI-first platforms.     

Another trend that could accelerate adoptions is, of course, AI regulation.  Given the concerns that are currently in the news about swarms of agents that can run amok, this is likely to happen soon.  

And finally, as agents get deployed, new use cases will emerge for compliance that is specific to agents.

M.R.: What risks do you see with the widespread deployment of agents that AI-first platforms are suited to address?

Indra: Transaction-level governance of agents is one such risk. Many companies have already deployed agents at scale, and in most cases governance policies are hard coded into each individual agent. Updating those policies as new threats emerge is therefore slow and cumbersome. AI-first platforms decouple policy from code: policies are authored and stored centrally, then pushed across the relevant agents on the fly. 

Third-party and vendor risk is another area. Agentic tools often rely on external models, plugins, or protocols (MCP servers, connectors, APIs) that touch company data. AI-first platforms are well suited to vendor due diligence, data-handling agreements, and assessing what an integration is allowed to access, especially when the third-party has developed or is using agentic applications.

Data governance is a third area. Agents that can autonomously query or move data across systems raise access-control and data-minimization questions.  This is exactly the territory compliance already governs for human users.  It just needing extension to non-human actors.

M.R. Rangaswami is the Co-Founder of Sandhill.com