Your AI Maturity Level Is Your Strategy: Brad Micklea on Climbing the Curve Without Getting Burned
Jozu CEO Brad Micklea joined Optimizely CEO Alex Atsberger for a live Q&A panel at the Software Oasis AI event, fielding audience questions from around the world on how organizations can move up the AI maturity curve without taking on unsafe risk.
Over 30 minutes, Brad covers the first concrete steps for companies moving beyond chatbot-stage AI, how to add security to a strong MLOps practice without slowing down ML teams, why fine-grained tool-use policies matter as MCP servers grow more powerful, how boards should balance pushing for AI progress against verifying the right protections are in place, and why customer impact, not token consumption, is the right way to measure AI maturity.
Watch the full panel above, or read the highlights below.
Most companies know they need to move beyond "web-only AI." Fewer know how to do it without opening themselves up to serious security risk.
That tension was the throughline of a recent Software Oasis panel featuring Jozu CEO Brad Micklea and Optimizely CEO Alex Atsberger. The audience questions came fast, from Boise to Halifax to Dunedin, and Brad's answers offer a practical playbook for any organization trying to climb the AI maturity curve safely. Here are the highlights.
There's no magic path, but there is a practical one
The first question cut right to it: what's the first concrete step for a company still at the chatbot stage that wants to move up the maturity curve without taking on unsafe operational complexity?
Brad didn't sugarcoat it. Moving up the curve unavoidably broadens your security exposure. There's no path that skips the security work entirely.
But it doesn't have to be a massive undertaking either. His recommendation: start with an AI policy gateway, deployed centrally in your network or on laptops, to protect the organization as you move from simple chatbot use to more open workflows.
When you're ready for agentic work, add an isolated containment zone with its own policies. Containment is the foundation, but Brad was clear that it's not enough on its own. The real work is in admission policies and tool-use policies.
Why? Because MCP servers are getting richer, and that's a double-edged sword. Your agent might need 20 of the tools in an MCP server, but not the dangerous five. Not delete. Not drop tables. It still has to read and write or it's useless. That kind of fine-grained control is what separates a usable agentic deployment from a risky one, and the tools to do it exist today.
Security that doesn't slow down your ML team
A question from New Zealand asked how organizations with strong MLOps but weak security can stitch together model packaging, deployment, and guardrails without either side becoming the bottleneck.
Brad's answer: don't mess with the ML team's workflow. They're fast, and you want to keep them fast.
Instead, plug into the tools they already use, whether that's MLflow, Weights & Biases, or something else. The open source KitOps project connects to those tools and turns their outputs into cryptographically secured, versioned packages instead of loose files scattered across hard drives that are nearly impossible to secure, audit, or control.
The best part is that it's invisible to the ML team. They keep working the way they always have, while the security team gets a massive win. Jozu then ingests those packages, runs vulnerability analysis, and gives the security team results they can share back with the ML side. Same tools, same speed, dramatically more security.
What boards should do with the maturity curve
Brad's presentation earlier in the event made the case that your AI maturity level is your strategy. One attendee asked how boards should read that curve when deciding where to invest or cut.
His answer: boards have to do two things at once. Push the company to make the next maturity leap, and verify that those leaps happen with the right protections in place.
He compared it to parenting. You push your kids to jump a little higher and run a little faster, but never in a dangerous environment. You put them in a safe space, and then you tell them to push themselves. Companies work the same way. Build the secure, governed environment first, then push hard. A board that overweights either side, all gas or all brakes, becomes a hindrance instead of a help.
Measure customer impact, not token consumption
Asked how large enterprises should measure progress along the maturity curve beyond counting pilots or agents in production, Brad pushed back on a metric that's become common: token usage.
Heavy token consumption doesn't mean your teams are doing good work with AI, any more than burning a lot of gas means you're driving well. Focus instead on the metrics that matter to your business: customer impact and core business outcomes. If AI isn't materially improving either, it's probably not worth the cost.
He also cautioned against expecting 10x results out of the gate. Improve by 20% this quarter, 10% the next, 30% after that. His own engineering team took a couple of quarters to really get their heads around working with AI. Once they got past that lumpy beginning, things took off. Build that growth pattern into your expectations.
The bottom line
The panel kept returning to the same idea from different angles: speed and security aren't opposites. The organizations that climb the AI maturity curve fastest are the ones that build governed, protected environments first, then push aggressively inside them.
That's the thesis behind everything we build at Jozu. Jozu Hub secures the AI software supply chain so only trusted artifacts reach production, and Jozu Agent Guard governs how agents behave once they run, including the fine-grained tool-use policies Brad described on the panel.
Want to see what that looks like in practice? Visit jozu.com or check out the CNCF-hosted KitOps project to start packaging your AI projects securely today.