Mike Rawson

AI-first Enterprise Accelerator & Scaleups

14 July 2026, 5 minutes

Governing the agents: how we’re closing the AI compliance gap

Mike Rawson has spent more than thirty years in enterprise tech. Most recently, he was CIO at citizenM, where he transformed the hotel brand to a digital customer experience platform together with Hypersolid. Over the six years that Mike was there, citizenM scaled from 13 to nearly 40 properties before Marriott acquired the company last October. 

In the nine months since, Mike's gone all in on becoming AI-first. This journey has given him a clear read: most companies' AI agents will never see production. The overarching bottleneck is clear: The concepts are there, the technology is there but. The governance isn't. 

We sat down with him to talk about his career, the roots of the governance shortfall, and how VDA, the governance framework he's building at Hypersolid right now, is meant to close it. In that capacity, Mike is also part of Hypersolid's AI Guild, contributing to our enterprise AI strategy and governance.

With more than 30 years of enterprise technology leadership behind him, Mike is now building VDA and contributing to Hypersolid's AI Guild to help organizations deploy AI safely

Q: Can you walk us through your background?

I've been in tech forever, more than 30 years now. I got my start in New Zealand as CIO of DB Breweries, and when Heineken acquired that business, I was offered a role at their head office in Amsterdam about six months later, working across local, regional, and global tech.

From Heineken, I stepped into a CIO role at citizenM. Over my years there, we expanded to nearly 40 hotels and worked extensively with Hypersolid along the way (for more: case). I'd actually crossed paths with them earlier too, during my time at Heineken. It’s nice to see that Hypersolid is also still working with Heineken and citizenM and a testament to the long-term relationships they build with their customers. 

That whole chapter wrapped up last October when Marriott bought citizenM, and I decided it was time to move on. Since then, I've spent nine months getting serious about being AI-first, and that's when it became clear to me that governance and compliance were the piece most companies were missing.

Q: What's missing when you say companies lack AI governance and compliance?

For enterprise, governance and control have always been mandatory, it's just baked into how things run. What I realized was that this simply wasn't there yet for AI agents.

We saw that firsthand at citizenM. About four years ago, before AI had really taken off, we built our first digital employee, Robbie, to handle accounts payable. Rolling that out taught us that a digital or AI transformation isn't just a technology change; it hits people and process just as hard. By the end of it, Robbie was paying 80 to 90 percent of invoices automatically, and to a higher standard. We deliberately did that first on the employee side, so we could learn the traps before ever putting an agent in front of a customer.

Quote

The real challenge isn't building AI. It's governing it

The real blocker is usually the security officer and the privacy officer, often represented by the CIO or IT lead. Taking anything to production in an enterprise means testing, compliance, the equivalent of a penetration test. With AI, it's the same questions: is it secure, have we tested it, do we know what it's going to do, can we roll it back, who owns the change control? Right now, most enterprises simply don't have answers to those questions for their AI agents. That's the exact gap I built VDA to close.

Quote

Why most enterprise AI projects never make it past the pilot phase

Q: What exactly is VDA?

VDA stands for Verified Digital Agents, and it's built from two pieces: the Agent Control Plane (ACP) and the Agentic Gateway (AIG). 

The first thing VDA does is keep everything in plain English. The business logic behind an agent gets separated out so the business can own it directly, instead of tech having to own everything.

Second, the framework understands your industry and where you are on your journey, so it automatically attaches the compliance you need: NIST, SOC2, and other things most people don't want to deal with, but which are now essentially mandatory.

And third: from August this year, EU AI Act reporting becomes a legal requirement, and the framework generates that report for you as well.

On top of that, VDA has a witness agent. It records, in a legally sound way, every decision made, whether by the agent or by a human in the loop. That gives you documented proof of governance, ready for your auditors.

Quote

VDA is Mike's answer to the governance gap holding back enterprise AI

Q: You mentioned the EU AI Act reporting. What does that actually change for companies running agents?

From this August, it isn't optional anymore, it's a legal requirement. A lot of people assume the whole thing got pushed back, but that's not quite right, the delay only moved the high-risk deadline out to 2027.

Quote

AI governance is becoming a legal requirement, not a best practice

That's exactly what VDA is built to handle. Once an agent runs through the framework, it produces the compliance reporting automatically, on top of the witness agent's audit trail. Without that, you're stuck piecing evidence together after the fact, which rarely holds up when someone actually asks for it. It's also part of why I'm not trying to do this entirely on my own.

Q: What got Hypersolid involved?

It started with conversations with Schalk Stalman, who is now Executive Chairman at Hypersolid. He recognized that this kind of AI transformation was becoming mandatory, and saw an opportunity to build out that hands-on, organization-wide AI transformation capability alongside the agent work Hypersolid was already doing for clients. That conversation picked up speed around an enterprise RFI, and because of my background in that world, I got pulled in to help and present the AI vision that became VDA.

That's what got me actively working with Hypersolid from that point on. Right now that means being involved in a couple of enterprise RFPs, building Penny, a digital employee for our own internal finance department, and putting together VDA, my own governance framework. All of that is aimed at one thing: making sure a client doesn't just get a proof-of-concept agent, but an agentic workflow they can safely run in production, fully compliant and with rollback capabilities if needed.

Q: What's in it for a company that brings its AI agent project to Hypersolid now?

They get an agent that's actually allowed to go live, not just one that works in a demo. Hypersolid already had the agent-building capability, strong technical delivery, real client relationships. What VDA adds is the part that used to get figured out separately on every project. Or as they like to call it at Hypersolid the solid underneath the hyper.

Quote

AI adoption needs more than speed. It needs a solid foundation

Working closely with Tim Bakker, I've aligned VDA with what Hypersolid already does well. So a customer now gets both sides in one place: the best-of-breed, fast-moving agent development, and a framework underneath it that already handles the compliance, governance, and control. That means less time spent building a business case for your own auditors, less risk of getting blocked at the last mile, and a much shorter path to actually running the agent you asked for, rather than watching it stall in review.

Quote

Building AI that is designed to reach production, not just the demo

For us at Hypersolid, this conversation underlines exactly why we brought Mike in. Building agents has never been the hardest part. Getting them into production, in a way security, privacy, and legal teams can actually sign off on, is where most companies get stuck. By bringing the hyper and the solid together, speed and governance don't have to be a trade-off.

This isn't just a plan on paper either, the framework is already in front of real clients, and the August deadline for the EU AI Act keeps getting closer by the week.

Curious what that could look like for your own AI agents? Get in touch, and let's talk about it.


Contact us and let's get started

Ready to close the AI governance gap?