Executive summary
Dell CTO John Roese explains why agentic AI is reshaping enterprise architecture, pushing intelligence closer to where work happens while making identity, authorization, sovereignty and open standards critical control layers.
Much of the coverage of Dell Technologies World 2026 understandably focused on product announcements: racks, GPUs, storage throughput, local agentic infrastructure and a growing list of model partnerships. But in an extended conversation with John Roese, Global CTO and Chief AI Officer of Dell Technologies, a more consequential thesis emerged about where enterprise AI is heading. It turns on three linked shifts: from generative to agentic, from centralized to distributed, and from cloud-default deployment to workload placement driven by data, control and sovereignty.
His framing of the core transition is deceptively simple:
“AI is changing from being a one-shot tool to being an autonomous work entity inside organizations. We're still very early, but we're at that tipping point. And everything else changes because of it. Organizations change, jobs change, the entire technology stack changes, economics change.”
The distinction matters because a tool and a work entity impose very different requirements. A generative assistant writes, summarizes or codes on request. An agent has objectives, an identity, permissions, costs, data access, dependencies and an operational trace. It can invoke tools and trigger actions. Reasoning about the second in the language of the first is where many enterprise AI programs will fail.
These shifts are not independent. As agency moves deeper into enterprise workflows, intelligence increasingly has to operate close to the data, systems and people involved in the work. Distributed execution makes sovereignty an architectural question. Heterogeneous environments make interoperability essential. And autonomy makes identity, authorization and revocation foundational controls rather than optional security features.
Sovereignty becomes an architectural property
One of Roese's more counterintuitive arguments is not that agentic AI automatically creates sovereignty, but that it makes sovereign architectures more practical and, for some workloads, more natural. That runs against the idea that sovereignty is mainly a compliance constraint added to an otherwise centralized architecture.
“Before agentic, the trend was to pull more of the AI into these big central things that weren't in your country, and that was the only option you had. Now, as we move into agentic, we are pulling out of those environments and bringing them back to the real world.”
The point is architectural rather than political. A one-shot assistant can often run remotely with limited consequences for where the computation happens. An agent embedded in a hospital process, a factory workflow, a bank operation or a public service is different. Data residency, latency, security boundaries, operational continuity and accountability become part of workload placement.
Dell's 2026 push illustrates that direction. The company and Google are bringing Gemini models to Google Distributed Cloud on Dell infrastructure, including on-premises and air-gapped deployment options for organizations with strict security and sovereignty requirements. The broader implication is more important than the product announcement: sovereignty is moving from a late-stage compliance discussion toward a first-class architecture criterion.
Model portability matters more than cloud allegiance
Roese puts the change in center of gravity provocatively:
“The clouds are not that important. The models are important, and having an ability to move those models into other environments is the goal.”
Taken literally, the statement understates the continuing importance of public cloud. The more useful interpretation is that cloud is becoming one execution venue among several rather than the assumed destination for every AI workload. As enterprise AI becomes distributed, the strategic asset is the ability to place models, agents and data where economics, performance, security and sovereignty make the most sense.
That reframes how to read Dell's partnership strategy. In Roese's telling, the critical relationships increasingly sit with model and AI-platform providers, including OpenAI, Anthropic, xAI, Mistral, Cohere and Google, because enterprises want access to capable models without being forced into a single execution environment. For European organizations weighing performance against control, the question becomes less which hyperscaler to standardize on and more which models and agentic workloads can be deployed, governed and moved across environments.
Identity is the anchor for control
The passage most relevant to any executive deploying agents is also where Roese is most emphatic. Asked which adjacent problems Dell considers non-negotiable, he singled out agent identity and authorization:
“Agentic identity and authorization is the single most important control vector in the agentic world. If you do not get that right, you will fail. You will not be able to control your agents. You will have tremendous security problems.”
The distinction needs to be precise. Identity is not authority. Identity establishes which agent is acting. Authorization determines what that agent is allowed to do. Governance determines why it may act, on whose mandate, for how long, under which constraints and with what path to revocation. But without a persistent, addressable agent identity, there is nothing reliable to which those permissions, limits and accountability mechanisms can attach.
This is the operational form of a chain of authority: an accountable principal, a defined mandate, a bounded authority envelope, contextual authorization for consequential actions, and a revocation path. The identity layer is the anchor that makes those controls enforceable across a population of autonomous systems.
Roese also connects this to regulation, describing the need for a way to stop agents. That should be read as an engineering requirement rather than as a blanket legal 'kill-switch' rule for every AI agent. Article 14 of the EU AI Act applies to high-risk AI systems and requires effective human oversight, including the ability, where appropriate, to override, reverse or interrupt operation. The engineering point remains powerful: you cannot revoke or stop an autonomous actor you cannot reliably identify and locate.
What is notable is how Dell chose to act on that conviction. Rather than build a proprietary identity product, Roese describes taking the problem to security partners, Okta among them, and helping shape the surrounding ecosystem.
“I am a lazy engineer. The idea of doing work where other people can do it sufficiently is not interesting.”
Behind the humor is a serious governance principle. A control layer this fundamental should not depend on one infrastructure vendor. Customers need choice, portability and the ability to separate the platform that runs agents from the mechanisms that identify, authorize and audit them. Concentrating authority infrastructure in a single proprietary stack can become a risk in its own right.
Open standards are becoming the connective tissue
If identity and authorization provide control, interoperability determines whether that control can work across a real enterprise. Here the direction of travel is increasingly visible. Several of the most important agentic interoperability projects are converging under neutral Linux Foundation governance rather than remaining tied to individual vendors.
The Model Context Protocol, or MCP, became a founding project of the Linux Foundation's Agentic AI Foundation in late 2025. The Agent2Agent protocol, or A2A, is also hosted by the Linux Foundation and had support from more than 150 organizations by April 2026. They solve different parts of the stack: MCP standardizes how models and agents connect to tools, data and applications, while A2A focuses on communication and coordination between agents. That distinction matters because the enterprise agentic stack will need both forms of interoperability.
Roese describes Dell as actively pushing the industry toward this kind of convergence. Whether every protocol ultimately sits under one foundation matters less than the governance trajectory: the connective tissue of agentic systems is moving toward open, multi-vendor standards. Without that, enterprises risk recreating the application silos of the last two decades, only this time with autonomous software actors operating across them.
Roese is equally clear about where openness becomes harder. Software layers, orchestration, data management and protocols can become increasingly fungible through open communities. Hardware is different. As performance requirements increase, architecture becomes more opinionated and tightly coupled:
“AI is a performance game. Tight coupling is important. The farther you go down the stack, there is an opinion that calcifies into hardware.”
The implication is more nuanced than a simple open-versus-proprietary debate. Enterprises can preserve choice at many layers, but high-performance decisions create dependencies below them. GPU architecture, IO path, data path, memory hierarchy and security design are not infinitely interchangeable. The strategic task is therefore to keep control and interoperability open where possible while accepting deliberate coupling where performance justifies it.
What this means for enterprise leaders
Three implications follow for organizations moving from agentic pilots to production.
First, treat agent identity and authorization as foundational infrastructure. Before scaling agents, establish an inventory of autonomous actors, an accountable owner for each one, a persistent identity, a defined mandate, explicit permissions, logging requirements and a revocation path. Boards and executive committees should ask whether every production agent is addressable and stoppable before asking how many agents the organization can deploy.
Second, design workload placement and sovereignty together. Agentic AI increases the value of running some workloads close to enterprise data, operational systems and regulated environments. Model portability across edge, on-premises, private and public cloud environments should therefore be a first-class architecture criterion. Sovereignty is not achieved simply by moving a model on premises, but distributed architecture can make control over data, models, infrastructure and policy substantially more practical.
Third, favor open and multi-vendor control layers while being explicit about where performance creates coupling. Identity, authorization and agentic protocols should remain as portable and interoperable as possible. Infrastructure choices deeper in the stack will inevitably narrow some options. The objective is not theoretical fungibility at every layer, but the ability to change models, environments and control providers without rebuilding the entire agentic architecture.
The larger conclusion is that agentic AI does not simply add another application layer. It redistributes agency across the enterprise. That changes where AI runs, how systems interoperate and where control has to be enforced.
The next phase of enterprise AI will not be won only by whoever has the most powerful model. It will be won by organizations that can place intelligence where the work happens while making every autonomous actor identifiable, bounded, auditable and revocable. In an agentic enterprise, identity is the anchor, but authority is the real control problem: which agent may do what, on whose mandate, within which limits, and how quickly that authority can be withdrawn.
Adapted and expanded from the author's original French-language chronicle on Dell Technologies World 2026, published on Alliancy, and drawn from the author's extended interview with John Roese, Global CTO and Chief AI Officer of Dell Technologies. Direct quotations are drawn from the interview transcript and lightly edited for readability.
