Capital One's Agentic AI Playbook: Why Data and Platform Design Come First
Financial services firms rushing to deploy agentic AI systems need to prioritize foundational data infrastructure and platform-level governance before building agents, according to Capital One's enterprise AI leadership.

Enterprises eager to harness agentic AI must first establish a strong data foundation and embrace a platform-first approach, rather than diving headfirst into agent development. The technology has matured beyond simple prompt-based experiments and now demands serious attention to underlying systems architecture, according to Rashmi Shetty, VP of enterprise AI at Capital One.
"We are dealing with agentic systems that can actually take action," Shetty told CIO Dive. "Agentic AI now must be treated as an end-to-end system." Shetty oversees the engineering organization responsible for enterprise platforms at Capital One, where she operationalizes generative AI and agentic AI applications across retail banking, risk, legal and compliance divisions.
Capital One's readiness for agentic systems stems from 14 years of technology modernization efforts. CEO Richard Fairbank noted during the company's Q2 2026 earnings call in July that the bank has been rebuilding "from the bottom of the tech stack up." He added, "We're way down that path, and we continue to invest in some very powerful foundational capabilities as well as AI infrastructure and specific AI experiences."
The bank now operates both customer-facing and internal agentic AI applications. Chat Concierge, deployed in production over two years ago, represents one of the bank's flagship external use cases and an early multiagent application. The tool guides customers through vehicle purchases by connecting them with dealers, arranging test drives and facilitating digital transaction completion. Internally, Capital One deploys similar technology to enhance customer service operations.
Shetty credits the bank's success with operational agentic systems to sustained investment in a robust data foundation featuring well-governed data pipelines and clear data lineage. She explained, "Providing agent context becomes that much easier with a very strong data foundation."
Building governance into the platform layer
Beyond data infrastructure, Capital One adopted a platform-first mindset as the next essential step. Constructing an enterprise platform designed for agentic workloads—complete with embedded policies, policy enforcement, runtime controls, compliance mechanisms and cybersecurity safeguards—enables development teams to build agents rapidly on a secure foundation, Shetty said.
"Retrofitting any governance and runtime security to fragmented, ad hoc agentic applications after they are built is far more difficult," Shetty said. "It has to be thought through before building the agentic applications."
Validation strategies must span multiple approaches, including rule-based checks, sandbox simulations and evaluations—commonly called evals. Observability has emerged as another critical capability in the agentic AI landscape. Shetty emphasized that observability enables tracking of agent decision paths, tool performance and latency across multiagent workflows, with deep domain expertise serving as the primary driver rather than any single monitoring tool.
"There are so many things the evaluation capabilities can bring to the table. You can test vulnerabilities, it can prevent jailbreaks, enforce strict compliance," Shetty said. "Observability and evals go hand-in-hand."
Models themselves are insufficient without a proper harness strategy surrounding them, Shetty cautioned. A harness standardizes and operationalizes controls around agents, such as permissions for tool access. Organizations must also establish clear protocols for human oversight, particularly when agents handle high-risk actions.
CIOs should verify whether their platforms can handle agentic workload execution and fully grasp the associated risks, as long-term success hinges on resilience and scalability. Shetty concluded, "One of our core values within our organization is to ensure agentic and GenAI applications are well managed, well governed, secure and standardized in such a way that they meet the regulatory and compliance needs for Capital One, as well as ease the path of development and deployment."

