
The conventional wisdom on AI governance is that it slows you down. Lock the tools down and run everything through committee — and a competitor ships first.
Inside the businesses moving fastest with AI, the conversation sounds nothing like that.
That was the case put to Johannesburg’s technology and security leaders on Friday, 31 July 2026, at the Liquid C2 & Cloudflare Executive CISO Breakfast, a session titled “The AI Guardrail Advantage”. Liquid C2, a business of Cassava Technologies, the pan-African group founded by Strive Masiyiwa, hosted the session with Cloudflare. The argument: governance works when it is treated as infrastructure from day one, not policy bolted on after adoption has already spread.
Generative AI use climbed from 33% of organisations in 2023 to 71%, according to McKinsey’s State of AI survey published in March 2025. That adoption curve is the real problem. Most companies are already deep into AI use before security or compliance has been asked to sign off on it.
The pressure is coming from inside the business
Brandon Rochat, Cloudflare’s senior sales manager, said the push for AI governance is coming from customers, not from Cloudflare’s own sales team. “Honestly, it’s client-led,” he said. “Many companies are asking what does AI mean to us, what does it mean for our businesses? We need it, but we don’t know how to control it.”
His answer for businesses still treating governance as tomorrow’s problem was blunt: “All businesses need to look at this. You need to understand AI, and you need to see where you want to make purposeful AI part of your process.”
Where the real exposure sits
Then there is the part of the AI stack most boards haven’t thought about: agents.
Ozgur Danisman, Cloudflare’s director of solutions engineering, singled out autonomous agents — booking, e-mailing and querying systems without a human approving each step — as where he sees companies going wrong. “These agents are having access rights to very critical internal or external systems,” he said, and without the relevant guardrails a business is left with blind spots it cannot see into.
Asked what failure looks like, he gave two specific scenarios. “The next day you come to the office and see a US$10 000 bill because that agent did a lot of queries with the LLM and you didn’t put a budget boundary. Or that agent is over-authorised and just deletes the core database, so your whole system is gone.”
One of those is a bill. The other is the business.

The gateway does the boring, essential work
The mechanism on offer is an AI gateway sitting between people, models and agents, inspecting traffic before it becomes a problem. “So if you have PII information or customer information leaking in an unauthorised way, the AI gateway will stop it before it goes out,” Danisman said, referring to personally identifiable information.
The same layer handles cost, letting businesses set a budget per employee and enforce it. It is the least glamorous form of AI governance and, on the evidence of a $10 000 surprise invoice, possibly the most necessary.
Built on what’s already there
None of this required customers to rip out existing infrastructure, in Liquid C2 and Cloudflare’s telling. Danisman said Cloudflare had been investing in the region for 15 years and had spent the past two years investing in GPUs, with facilities in Johannesburg and Durban — investment customers could draw on rather than build from scratch.
Nor did it require lock-in. “They need a flexible environment where they can easily change to the latest model when they need to,” Danisman said.
The seven-part framework unveiled at the breakfast wasn’t positioned as a product. Liquid C2 and Cloudflare describe it as a governance framework, introduced at the session to help organisations adopt AI securely — starting with how AI is currently being used across different business functions, the regulation it now sits inside, and the risks it poses as adoption outpaces oversight. The framework works through seven governance areas in turn: strategy, documentation, risk, third-party management, compliance, data security and assurance. Liquid C2 and Cloudflare say they will support organisations in putting it into practice across those same areas, including risk and policy development.
The underlying diagnosis holds regardless. Rochat argued the challenge does not vary by how established a business is. “The AI journey is the same for all types of businesses, whether mature or not. Mature businesses have a jump on immature ones, but their needs are the same: using AI to increase productivity, reduce costs, be more competitive.”

The session worked through the risk areas in board language: staff pasting sensitive data into unapproved AI tools, compliance exposure under regulation such as Popia, agent autonomy widening the blast radius of a single mistake, and third-party AI vendors on the risk register. It closed on a practical model: understand AI use cases and ownership, set policy, inspect traffic at the gateway, control access and govern agents.
Guardrails are not the brake. They are what lets a business put its foot down with both hands on the wheel.
For the CISOs who left that breakfast, the next step wasn’t a sales pitch. It was a working session to move the conversation from principle to implementation. Whether that translates into fewer $10 000 surprises will be the real test.
- Read more articles by Liquid C2 on TechCentral
- This promoted content was paid for by the party concerned



