Lowe's AI leader sets out six guidelines for governing AI agents

Lowe's AI leader sets out six guidelines for governing AI agents

This is an opinion essay in IEEE Spectrum by Sravan Vadigepalli, an IEEE senior member and a technology executive at Lowe's Cos., where he leads enterprise AI strategy, AI products, and partnerships. He spent the first 10 years of his career doing product management and data analytics by himself, then built and scaled analytics teams at Best Buy and Target. Today he leads enterprise AI transformation at Lowe's, the Fortune 100 home improvement retailer.

His central argument: technology roles are changing from building AI systems to defining how they operate, meaning which decisions they can make autonomously, when they must escalate to a person, and which actions stay off-limits. That shift, he writes, is coming for anyone accountable for what such systems produce. He does not mean casual chatbot users but the engineers, product managers, analysts, and business operators who sign off on work a machine drafted. He calls it the 'governor shift': from executing tasks yourself to setting the intent, principles, and boundaries within systems that execute for you. A business operator might not write code but will decide which pricing exceptions an agent may approve and which it must escalate. That, he says, is governing. The subject is covered in his recently coauthored book, The Enterprise Brain: Rewiring Your Business for the AI-Native Era.

He backs the urgency with a 2025 report from MIT Media Lab's Project NANDA. Despite an estimated US $30 billion to $40 billion in enterprise generative-AI investment, the vast majority of organizations in its dataset had not yet demonstrated measurable profit-and-loss impact, and the report estimated that only about 5 percent of integrated pilots were generating substantial value. Researchers named the pattern the GenAI Divide, a term he adopted for the book. His view is that struggling companies rarely lack technology, since they use the same models as the 5 percent that are winners. They lack people who can direct the systems and stand behind the results.

The six guidelines:

  1. Recognize when you have become 'human middleware'. Middleware is code that passes information between two systems, and many workers have become its human version, pulling data from one tool, reformatting it, and routing it to another team. He calls this the 'administrator trap', set by the architecture rather than by the people caught in it. AI agents now do the relaying well, but they cannot judge which numbers deserve attention, which risks are real, or which compromises are worth making.

  2. Trade rules for principles. Rules, such as a management signature for refunds above a set amount or two reviewers for code, work at human speed. They break when a system makes thousands of decisions per hour and meets situations no rulebook anticipated, such as a complaint covered by three different policies. A rule says to do exactly one thing; a principle says to achieve the outcome without crossing certain lines. Governing AI means writing principles in priority order so the system settles its own conflicts. His examples: never harm the customer; tell the truth even if the company loses a sale; protect the economics, and then move quickly. Underneath sits decision rights, the formal authority over who or what may make a given call. He calls the written collection a 'library of principles'.

  3. Write your culture into your code. Values on office posters mean nothing to an AI agent, so governance should be written as machine-readable instructions in three layers. The constitution states the rules an agent may never break, including never stating a fact it cannot support. The doctrine covers how the business competes and the acceptable trade-offs, such as protecting a long-term relationship over a short-term sale. The playbook holds the tactics for one task.

  4. Install a trust thermostat, not a trust switch. The question that stalls many deployments is what happens if the AI tells a big customer something wrong or quotes a price the company will not honor. Treating trust as a switch leaves two bad options: an unsupervised system, or a human reviewing every transaction, which he says would cost more than the automation would save. In the thermostat model, every decision carries a confidence score measured against the principles. Above an agreed threshold the agent proceeds alone; below it a human decides, and that answer is fed back into the learning loop so the next similar case can clear the threshold on its own. Every decision stays transparent, auditable, and explainable, which he calls a 'glass box'.

  5. Fix context before you govern. A system that cannot see the whole picture cannot be governed, and most enterprise AI fails that test because information sits scattered across applications in incompatible formats. He describes a full loop, CCRAG: Connections feed in raw information such as transactions and service records; Context weaves it into a context graph, a single connected picture of the business that gives agents something close to memory; Reasoning makes the decisions; Actions carry them back into business systems; Governance keeps things aligned with the company's intent. Most organizations obsess over reasoning and underinvest in context and governance, which is where humans play a role.

  6. Learn to lead by exception. Most people are trained to check every report and number. In a governed system the machine flags the cases it could not resolve confidently; routine workflows go untouched, and attention goes to the small portion that is ambiguous, unfamiliar, or high stakes. He says this may feel like losing control but is the opposite, and it makes a 'self-scaling enterprise' possible, one whose output grows without head count growing in proportion. People were not removed from the loop, he writes; they were raised above it.

The essay closes on identity. He says resistance to the shift is rarely technical and more often a question: if the AI does the doing, what do I do? His answer is that judgment was always the job and doing was how it was expressed. AI has made judgment the scarcest resource in the organization, because one person's judgment, written down well, can now guide thousands of decisions each day. He pairs judgment with 'taste': judgment tells you whether an answer is sound, taste tells you whether the question was worth asking and which of a hundred defensible options to offer. He adds that the AI transition rewards instincts many IEEE members already have: systems thinking, precision about requirements, and honesty about failure modes.

Key facts

  • Sravan Vadigepalli, a Lowe's technology executive and IEEE senior member, argues in IEEE Spectrum that people accountable for AI output are moving from building AI systems to governing them, a change he calls the 'governor shift'.
  • He cites a 2025 MIT Media Lab Project NANDA report: an estimated US $30 billion to $40 billion in enterprise generative-AI investment, yet only about 5 percent of integrated pilots generating substantial value.
  • Six guidelines: escape 'human middleware', trade rules for principles, write governance as code in three layers (constitution, doctrine, playbook), use a 'trust thermostat', fix context first (CCRAG), and lead by exception.
  • The trust thermostat: above an agreed confidence threshold the agent acts alone; below it a human decides, and that answer feeds back into the learning loop.
  • He argues AI has made judgment the scarcest resource in the organization, because one person's written-down judgment can guide thousands of decisions each day.

Why it matters

Companies are spending heavily on generative AI, and the essay's framing is that the gap between spend and results is about people and process, not models. The author cites the 2025 Project NANDA report, which estimated US $30 billion to $40 billion in enterprise generative-AI investment and found only about 5 percent of integrated pilots generating substantial value. His claim is that the struggling companies use the same models as the winners and lack people who can direct the systems and stand behind the results. The practical shift he describes is from doing the work to setting intent, principles, and boundaries for systems that do it.

Who it affects

The author says it reaches anyone accountable for what AI systems produce: engineers, product managers, analysts, and business operators who sign off on machine-drafted work. Casual chatbot users are explicitly not the target. Business operators who never write code are included, since deciding which pricing exceptions an agent may approve and which it must escalate counts as governing. He also addresses IEEE members directly, saying their habits of systems thinking, precision about requirements, and honesty about failure modes carry over.

How to use it

The six guidelines are meant as working practice. Audit your week for 'human middleware' tasks such as pulling data from one tool and routing it to another team. Write principles in priority order instead of adding rules, for example never harm the customer, tell the truth even if a sale is lost, protect the economics and then move quickly. Encode them as machine-readable instructions in three layers: a constitution of rules an agent may never break, a doctrine of how the business competes and its acceptable trade-offs, and a playbook of tactics for one task. Set a confidence threshold so agents proceed alone above it and escalate to a human below it, feeding the human's answer back. Invest in connections and context, not only reasoning. Then review exceptions rather than every report.

How solid is it

This is a first-person opinion essay, not a study. The only external evidence is the Project NANDA report, quoted for its investment estimate and its roughly 5 percent figure, which the report itself estimated. The guidelines come from the author's own experience and his book The Enterprise Brain, and the labels (governor shift, administrator trap, trust thermostat, glass box, CCRAG) are his. No data or case results from Lowe's are given showing the guidelines work. The NANDA report's methodology, sample size and exact title are not given beyond the quoted figures. The author's employer and book are disclosed in his own text and bio.

Risks and caveats

The confidence threshold behind the 'trust thermostat' is not quantified, so the central control mechanism is left to the reader to define. The article does not say how many organizations are in the NANDA dataset and gives no timescale for when the governor shift will reach any given role. The author also notes the failure modes he is trying to avoid: treating trust as a switch leaves either an unsupervised system or review of every transaction, which he says would cost more than the automation would save. Since the piece is advocacy from a practitioner who coauthored a book on the subject, treat the framework as one informed view rather than established practice.

“Doing was never really the job, though. Judgment was. Doing was just how we expressed it.”

— Sravan Vadigepalli, IEEE Spectrum