Rowan Stewart, Sr. Director of Product, AI Safety & Platform at Transcend, leads product initiatives focused on helping organizations discover, govern, and safely use data in artificial intelligence systems. She brings more than a decade of experience spanning AI and machine learning product development, enterprise software, natural language processing, data strategy, and zero-to-one product leadership. Before joining Transcend, Stewart spent nearly six years at BCG X, where she helped major enterprises develop AI strategies, reinvent internal processes, and build products designed to deliver measurable business outcomes. Earlier in her career, she managed the development of natural language processing APIs for influencer intelligence, including sentiment analysis, knowledge graphs, personality assessment, bot detection, and brand-safety capabilities.
Transcend is the only autonomous data decision platform that answers “can I use this data?” to scale customer growth. Fortune 500 companies and emerging category leaders leverage Transcend to encode complete data use permissions directly into the enterprise systems that process customer data, delivering a real-time source of truth for consent, preferences, and business rules. The result is superior data quality, ethical use that protects the brand, and audit-ready compliance at scale. With Transcend, companies can unlock revenue from AI, personalization, and other first-party data initiatives with confidence. Founded in 2017 by Ben Brook (CEO) and Mike Farrell (CTO), Transcend is headquartered in the San Francisco Bay Area.
You spent nearly six years at BCG X helping some of the world’s largest organizations deploy AI and machine learning solutions before moving into AI safety and governance at Transcend. What were the recurring governance failures or blind spots you observed that convinced you AI governance needed to be built into systems from day one rather than added later?
At BCG, I worked with companies across every stage of AI maturity, and one pattern stuck with me: governance always showed up late. Teams move fast to ship a model or a product, and the conversation about data permissions, consent, or oversight really comes into focus right before production and feels like a ‘gotcha’. Whatever gets built at that point amounts to a patch on a system that was never designed with governance in mind.
That’s part of why I was so excited to join Transcend. Advising companies on what they should do only goes so far. I wanted to help build the infrastructure that makes governance the easy choice.
Many organizations are racing to deploy AI agents across customer support, operations, and knowledge work. How does governing autonomous AI agents differ from governing traditional software systems or even earlier generations of AI models?
Most enterprise security architecture assumes that there’s a human on the other end of every action, and that human can be identified, trusted, and when something goes wrong, held accountable. But agents aren’t people. They act on their own, delegate tasks to other agents, and chain decisions together in ways that rarely map to a single accountable person.
Giving an agent the same static, standing permissions you’d give an employee creates a mismatch because agents lack common sense. Governance has to evaluate the specific action an agent is about to take, in that moment, with that particular data. Most companies are still running the identity and access management playbook they built for humans, and a lot of them are going to discover the gap once agent deployment outpaces the governance built to handle it.
You’ve worked across multiple waves of AI innovation, from NLP products and influencer intelligence platforms to enterprise AI transformation initiatives. How has the conversation around AI safety evolved over the past decade, and what still concerns you most?
Comparing today (and tomorrow’s!) AI to previous generations is fascinating because it’s just an incredibly fast-moving space. The most important evolutions of the last year or two have obviously been the rise of agents and the importance of long running memory management (OpenClaw, anyone?). These agents are able to do so much more at such higher quality, which makes them even more valuable and, of course, even more risky.
As AI systems increasingly make decisions using customer and enterprise data, what are the biggest misconceptions companies have about consent, permissions, and data governance in AI-driven environments?
The most common misconception is treating consent as something you capture once and file away. A customer agrees to a set of terms at signup, and companies assume that agreement holds indefinitely, no matter how the data moves afterward or what new systems it ends up feeding. Consent needs to travel with the data. If someone updates their preferences, or a new regulation changes what’s permissible, that change has to show up everywhere the data lives, not just in the system where consent was originally collected.
The second misconception is treating permissions as a technical detail that IT or legal handles quietly in the background. Once AI systems start making decisions based on that data, permissioning becomes a product and business question, and any gaps in it get inherited directly by whatever AI initiative sits on top.
Many enterprises still rely on static policies and periodic compliance reviews. Why do those approaches struggle in an era where AI systems can continuously learn, adapt, and interact with other agents?
A static policy captures what a system looked like, and what was considered acceptable, at the moment someone wrote it down. AI doesn’t sit still long enough for that snapshot to stay accurate. The model your policy was written for may not be the model you’re running six months later, and a quarterly or annual compliance review can’t keep pace with a system that’s making decisions and adapting the whole time.
Governing something that moves this fast requires policy that moves at the same speed. That means enforcing governance at the point where data is actually used, in real time, rather than checking it after the fact against a document that was already out of date the day it was published.
What does effective governance look like when organizations begin deploying networks of AI agents that collaborate with one another and access multiple internal systems?
This is where the limits of traditional access control become obvious. An agent might be authorized to read a record, call a tool, and hand results to another agent, and each of those steps can look reasonable on its own. The composite action (the thing that actually happened once you chain those steps together) is often something no human explicitly approved. Traditional IAM can confirm whether an agent had permission to touch a system, though it has little to say about whether the data it touched was collected under a consent that covers this particular use, or whether the resulting chain of actions was ever something a person actually signed off on.
Transcend focuses on embedding data-use permissions directly into enterprise workflows. How important is real-time governance infrastructure as organizations move from AI experimentation to production-scale deployment?
During testing, a team can often get by with manual reviews and periodic audits, because the stakes are low. In production, especially with agentic AI, that breaks because the scale is just massive. Today’s system of checklists and meetings is a lose-lose. The compliance and security teams basically get a pinky promise with no continuous enforcement, while the product team is now committed to cumbersome manual reviews that provide little real value to the end user. That’s when real-time infrastructure becomes the only approach that works. Enforcing permissions at the moment data moves or a decision gets made, instead of reconstructing what happened after something’s already gone wrong, is what makes the governance meaningful for compliance, and valuable for users
In your view, what are the most significant risks associated with agentic AI over the next three to five years, and which of those risks are currently being underestimated by business leaders?
I think the model of having agents inherit a user’s permissions is riskier than we realize. Humans have judgement, but an AI will follow your instructions right off a cliff.
How should product teams balance the pressure to ship AI features quickly with the need to establish governance, transparency, and accountability frameworks?
I think one concrete thing is the fix to what I call the “Slop Tax.”
We’ve all very quickly recalibrated our responses to discount the validity and value of AI output. It’s why everyone advises you to remove em dashes (even if they’re the appropriate), why a site that uses the standard Claude color palette feels cheap (even if it looks nice) and why information served up by AI is treated as suspect (even if it’s true). That really affects the perceived value of your product.
The fix for the Slop Tax actually is better governance and transparency. For example, we recently shipped a feature called Vendor AI Usage, that pulls publicly available information about the AI features and governance posture of top companies, to help AI enablement, security, and procurement teams do their work faster. We found that using an multi-agent orchestration framework, alongside gathering and presenting evidence with source links and quotes for their findings, resulted in a massive improvement in the quality of our results. This practice of evidence gathering and agent QA is a win-win because the actual results for the user are better, and the compliance is more robust.
Looking ahead, do you believe AI governance will eventually become a competitive advantage rather than simply a compliance requirement, and what will separate the organizations that get it right from those that fall behind?
I do, and it comes back to the same pattern I watched play out at BCG. Companies that treated governance as something to add once a product was already in market were always caught at the last minute check before scaling, and tended to get stuck in “Pilot Purgatory”The companies that build governance into the system from day one are able to move with a kind of confidence the other group doesn’t have, because they’re not constantly wondering what they’ll find when they finally look closely at how their AI is actually using data.
That gap is only going to widen as agent deployment accelerates. The organizations racing fastest to deploy agents without rethinking how those agents are permissioned are the ones most likely to run into trouble, and by the time they do, the companies that got the infrastructure right will already be operating at a speed the latecomers can’t easily match. Governance stops being a compliance line item once it’s the thing that lets you deploy AI faster and with more confidence than everyone still doing it manually.
Thank you for the great interview, readers who wish to learn more should visit Transcend.