Box CEO Aaron Levie:
CIO Advice on Agentic AI and the Enterprise
Box CEO Aaron Levie joins CXOTalk episode 921 to explain why enterprise AI agents stall in production, how they break existing security models, and what CIOs should fix first.
This episode is brought to you by Gartner IT Symposium/Xpo™
Ready to scale agentic AI from pilot to production? Join top CIOs and IT executives at Gartner IT Symposium/Xpo, taking place this October 19th through the 22nd in Orlando, Florida.
Over 300 Gartner analyst-led sessions will cover top priorities shaping IT—from AI value, governance, and cybersecurity to cost optimization, IT operating models, and beyond.
Get practical, actionable insights—and connect with peers tackling the same challenges you are.
Secure your spot today at gartner.com/us/symposium.
AI agents work in demos but stall in production, break existing permission models, and run up costs that CIOs never planned for in traditional IT budgets. Agentic AI in the enterprise has become a direct test for Chief Information Officers. Aaron Levie, co-founder and CEO of Box, joins CXOTalk episode 921 to discuss what agentic AI means for enterprise software, security, and the CIO.
AI agents work in demos but stall in production, break existing permission models, and run up costs that CIOs never planned for in traditional IT budgets. Agentic AI in the enterprise has become a direct test for Chief Information Officers.
Aaron Levie, co-founder and CEO of Box, works with many Fortune 500 companies on exactly these problems and has become a clear voice on what it takes to integrate AI agents into real business workflows. In CXOTalk episode 921, the conversation examines what agents mean for enterprise software, security, and the CIO.
What you will learn:
- Why AI agents stall in production, and how to spot the ones that are ready
- Why your data and permissions matter more than the model you choose
- How agents change enterprise security, and who is liable when one goes wrong
- What CIOs should do first, and what to avoid
- How to control AI costs as agent usage scales
Episode Participants
Aaron Levie is Chief Executive Officer, Cofounder, and Chairman at Box, which he launched in 2005 with CFO and cofounder Dylan Smith. He is the visionary behind the Box product and platform strategy, incorporating the best of secure content collaboration with an intuitive user experience suited to the way people work today. Aaron leads the company in its mission to transform the way people and businesses work so they can achieve their greatest ambitions. He has served on the Board of Directors since April 2005.
Michael Krigsman is a globally recognized analyst, strategic advisor, and industry commentator known for his deep business transformation, innovation, and AI leadership expertise. He has presented at industry events worldwide and written extensively on the reasons for IT failures. His work has been referenced in the media over 1,000 times and in more than 50 books and journal articles; his commentary on technology trends and business strategy reaches a global audience.
In This Episode
Aaron Levie: There was a brief moment where you could rely on the subsidization from venture capitalists and then get tokens for your coding agents. It was a beautiful moment in history, it lasted about a year, and we all had a great time.
Michael Krigsman: Every company wants AI agents, but few CIOs can run them safely at scale. Aaron Levie is co-founder and CEO of Box, which counts 68% of the Fortune 500 as customers.
The promise of agentic coding
Aaron Levie: We are still in the very early stages of what agentic work looks like in the enterprise and what the rollout looks like. We have an interesting dynamic, which is sort of a tale of 2 cities. We have AI kind of agentic coding, which has clearly taken off. And it's within engineering teams, and everybody's kind of figured out what the new practices are around the future of engineering.
And we can kind of get into a little bit around what the differences are between the engineering side and the rest of work. But engineering, obviously, kind of complete vertical takeoff of AI agents. And then you kind of get into the real messy environments of knowledge work, where things are just quite a bit different. It's a lot harder to deploy agents at scale. The agents don't have always access to the right data.
The users are less technical, so they don't know how to sort of always steer them properly. You have to do a lot of work to kind of verify the work that the agent is doing in a way that, in software, you can kind of just, you know, test the software and see if it worked, but you can't do that in a lot of areas of knowledge work.
So I think we're in this really interesting phase where we've seen what the promise of agents looks like in coding in particular. We've seen what the promise of kind of chatbots look like in knowledge work. And now the question is what's the full promise of agents across knowledge work? I think this will be the defining topic certainly over the next few years within the enterprise.
Michael Krigsman: Let's talk about the promise of agents. Just very briefly, first talk about the promise of agents for programming. And then let's shift into what is that promise for knowledge work? And what are the gaps? How do we get there, and what's preventing it? What are the obstacles?
Aaron Levie: Yeah. So the promise of coding is honestly just an incredible gift. Which is, you know, we've all done large engineering projects, and we know how much time, you know, maybe 60, 70, 80% of your engineering time is going into the work that doesn't really actually make the project differentiated per se. It's necessary work, so it's differentiated in the sense that if you didn't do it, you wouldn't be successful.
But it's the very labor-intensive, time-intensive things like, hey, you know, how do we upgrade the version of this library to the latest version? How do we you know, make sure that we're doing all of the edge case testing of our software? How do we go and build all of the end user features that are necessary for this functionality to be delivered? That's where most of the time of engineering goes.
And that, you know, could mean that you want to take on a big project and it, you know, just it from a standing start could take 6 months or a year or 2 years before you see the value of that product delivered to your customers, whether it's an internal solution or a customer-facing solution.
So the promise of agentic coding is, well, what if we could have agents go and do lots and lots of that blocking and tackling work that, that's necessary, and then our job is making sure that we're giving the agents the right plan to work with, we're steering agents in the right direction, we're reviewing the work of those agents, we're deploying, you know, testing and security solutions for whatever they've worked on.
And could we shrink that one-year project into two months? And that was a kind of a fantastical concept that honestly would've, you know, people would not have believed you three or four years ago if you had said that, 'cause all we had was type ahead functionality in our code editor. Now that promise is reality. We're seeing this every single day internally at Box.
We're seeing it from our customers, which is we might be able to literally do, you know, 3, 5, 10 times more work than we were able to do before. And the corollary is you might be able to do it 3 or 5 or 10 times faster. So this is what we're seeing on the engineering side. At Box, it means that we can just build a much more significant product roadmap.
For our customers, it means that they can take on way bigger problems than they could have before, which is amazing. So that, that's the promise.
Michael Krigsman: This episode is brought to you by Gartner IT Symposium/Xpo. Ready to scale agentic AI from pilot to production? Join top CIOs and IT execs this October 19th to 22nd in Orlando, Florida. Over 300 Gartner analyst-led sessions will cover top priorities shaping IT, from AI value, governance, and cybersecurity to cost optimization, IT operating models, and beyond. Get practical insights and connect with peers tackling the same challenges you are.
Secure your spot today at gartner.com/us/symposium. What about knowledge work? Why. You describe that as being messy, complicated.
Why knowledge work resists agents
Aaron Levie: Yeah. So that's the promise, and actually what we're starting to see the early signs of in the engineering side. So now everybody kind of sits around, they say, well, we want that exact same kind of output and outcome in knowledge work. And, you know, you have a, you do have a couple differences that have to be figured out. So the first is that I'll just go through maybe some of the delta.
In engineering, you've got a lot of great properties for agentic work. The work is mostly in a text-based medium, so, you know, you're mostly just writing code. AI agents have been trained on this data, you know, almost, from a plurality of the data that they get trained on, it's lots and lots of code examples on the internet.
They your users are obviously much more technical because they're engineers, and so they can, you know, both implement the technology themselves, but they can keep up with all of the updates that are happening in AI. So it's much easier when a new model comes out that they can go and implement that latest model or when some new kind of alpha emerges in the industry where, you know, if you configure MCPs or CLIs in a certain way, they can adopt that much faster.
You have another property which is that the work is more or less verifiable in that if I build a bunch of code and I can go and do a regression test on it, I can see, you know, did I break anything or does it still work? Now compare that to knowledge work. You know, you have a, you know, generally less technical audience just by definition. The work is sort of less verifiable by definition, so a contract, you can't compute whether the contract is sort of correct or not.
It has to actually sort of, you know, be dealt with. It has to sort of experience reality. It has to experience the red lines from the other party. It has to experience reality of somebody, you know, took your took that case to court. You have to then review the work a lot more to make sure that does it actually sort of do the thing that you want it to do.
You have to review the final financial analysis to make sure, did it pull all the right data in the right way, you know, from your set of spreadsheets. And the agents don't have access to data in exactly the same way that they have access to the data inside of engineering.
So in engineering, you know, from an access control standpoint, in general if you're an engineer working on a project, you already have access to the entire code base relevant to that project, and so by definition, the agent that you're deploying also has access to all of that data.
Well, in the enterprise, we're constantly asking for permission to other systems and other resources and other data environments, and so an agent is only as good as the data that it has access to, but in the enterprise we have lots of systems that are either not well-maintained or the agent can't get access to the right data, or maybe even worse, you have too much access to information.
And we had sort of you know security through obscurity in your organizations, and now all of a sudden the agent is leaking data to the wrong people. So think about just that sort of T chart that I just went through and think about how many differences there are between agentic coding and agentic knowledge work.
So the project ahead for all of us you know, kind of across the economy, whether you're a tech company or you're, you know, a user of technology, is how do we take those same gains that are happening in coding and how do you bring them to the rest of the world and the rest of our organizations? And that is just going to be a very big project that will take years and years of sort of diffusion into organizations.
Now, I'm extremely excited about it because it means there's all new roles that are emerging to go do this. These the upside when you're on the other end is tremendous because now you can actually accelerate your organizational productivity. But make no mistake, this is a very real effort that companies have to go through right now.
CEOs and the AI psychosis trap
Michael Krigsman: Folks, you can ask your questions. When else will you have the chance to ask Aaron Levie, the CEO of Box, pretty much whatever you want? So take advantage of this opportunity and ask your questions. Aaron, you recently said that CEOs are uniquely prone to AI psychosis because, and I quote, "They're sufficiently distant from the last mile of work that still has to happen to generate most value with AI."
Can you unpack that for us?
Aaron Levie: I sort of have my own experience of AI, and then I've seen it from either peers or other people in the industry, and so I kind of. I believe I have a good sort of pulse on this, which is I use AI, I think, as much as any CEO out there. I'm using it for, you know, prototyping of new products developing new ideas, doing lots of market research automating, you know, customer intelligence, and so I'm using all AI all day long.
And at the very start of that journey, you do these things like you prototype a piece of software or you do some market research and you are like, "Oh my God, this thing is going to just automate everything," and, you know, what are the implications of this and what does this mean? And you almost have this sort of existential dread, you know, for a few moments there and, you know, so for some people it lasts longer, and I think I maybe got through it maybe in a couple weeks.
And by the way, it kind of ebbs and flows 'cause a new model comes out and fable emerges and you're like, "Oh my God, I'm experiencing it again. I'm about to get into the AI psychosis mode." And so there's sort of a juncture, which is, you know, one, you can end up on one end of the juncture, which is, "Oh my gosh," like, "we have to retool everything and what are the people going to do?"
And, you know, it gets very existential. And the other end is you start to kind of see, oh no, actually there's still lots and lots of bugs that the agent, you know, wrote. There's still lots of security issues that were generated or even maybe discovered by the agent that now have to go get fixed. There's all the ongoing maintenance of the system that we just deployed. There's new features that we obviously want to go and work on.
That's the coding version, but in the other areas of knowledge work you find, you know, sort of things like, oh, the agent pulled from the wrong piece of data which meant that if I hadn't reviewed that report I would've come to exactly the wrong conclusion and so I had to actually steer the agent a bit more, and it took a lot of work to kind of prompt it in the right way.
So in the other sort of, you know, fork in the road you end up, you know, kind of maybe post-psychosis, which is this period where you realize that, oh actually there's still a lot of work that has to get done to make these agents be effective. And so there's this sort of journey that you go on which is this you know, instant sort of existential dread or high which is, "Oh my gosh, what is this going to mean?"
To then a bit more of kind of a pragmatism that sort of sets in for at least that's kind of where I landed and I think, you know, I have a number of friends that also landed here which is like, oh, okay, actually.
This is actually a technology that is going to boost our productivity, it's going to let us do far more than what we were able to do before but it is not as sort of, you know, doomsy as I think some of the commentary, you know, comes out because actually it's just going to. It, it's going to take a lot of time to fully be able to deploy these agents to be able to get the work done that we need.
And so that last mile thing or the kind of closeness to the problem is really the issue, is like a CEO, by definition, is the furthest away from the real work that's happening in the company. You couldn't get further from you know, in any other role other than maybe the board of directors. And so for us it's very easy to be like, "Oh, well, like I can just automate that engineer," or, "I can go automate that marketing campaign."
But then when you're closer to the problem you realize no, actually you probably just can't have a agent go and do all of that without any human supervision because it's going to do the wrong thing, or the taste of what the agent delivers is going to be off, or it's going to introduce a bug. So that keeps the humans in the loop. You know, really as far as I can tell, for the foreseeable future, that, that's going to maintain the case.
And so I think the thing I encourage CEOs is use the technology actually so much that you get to the other end of that psychosis, and you can actually see in a much more practical and pragmatic way all the places where humans are still necessary to really get the ultimate gains from this technology.
And don't just stop when you just prompt an agent and you just ask it to generate some research report, and then you get blown away, and then you sort of think, "Well, that's just the only thing that's going to happen in the future."
Michael Krigsman: This episode is brought to you by Gartner IT Symposium/Xpo. Ready to scale agentic AI from pilot to production? Join top CIOs and IT execs this October 19th to 22nd in Orlando, Florida. Over 300 Gartner analyst-led sessions will cover top priorities shaping IT, from AI value, governance, and cybersecurity to cost optimization, IT operating models, and beyond. Get practical insights and connect with peers tackling the same challenges you are.
Secure your spot today at gartner.com/us/symposium. I think that there is a huge challenge in terms of calibrating what agents can do, what they can do safely, where you can leave them alone, and this is where people have a hard time. And on this topic, we have, well, we have a bunch of questions that are coming in, and let's start with Gus Bekdash, who is the brave one who asked the first question on Twitter.
And Gus says this, he says "Some projects declare amazing victories because their objectives were so modest. How do you determine the right level of ambition to.
Aaron Levie: Yeah.
Michael Krigsman: Avoid irrelevance by being too small or too large in AI and automation in general?"
Be ambitious, then retry in six months
Aaron Levie: My instinct is always biased toward being more ambitious with what you can do. That will more often lead you to seeing first of all better productivity gains, but then also, you know, you see the edge of this technology much faster. And I do think that, I think anytime you hear stories about people not getting real ROI from agents, it's.
I do think it often approximates you know, not pushing them hard enough and thus, you know, doing very kind of more menial type of work as opposed to let's actually push the limits of this technology and really kind of, you know, get the gains out of it. So I don't have. It's hard to have like a full general piece of feedback other than I would just always bias toward being more ambitious pushing the limits much further.
And then importantly if something fails with AI with whatever that ambitious idea was, maybe a big software project, maybe some, you know, go to market automation activity, you almost have to try it again 6 months later like almost every single time no matter what it is. Because the model progress that's happening right now is still actually an incredible rate of progress that we're seeing. So you often almost have to say, "You know what?
I have to forget about the fact that 6 months ago this didn't work in this particular part of our code base, or in this particular marketing campaign." You know, if you relied on your understanding of image generation as a marketer from 6 months ago, that's already been blown up. The latest image gen models are perfect at being able to do text. They have photorealistic, you know, capabilities in a way that wasn't possible 6 or 12 months ago.
And so if you were in, you know, marketing campaigns, you'd want to kind of reset your understanding. If you're in software projects, something like Fable or GPT-5.5 actually is another step function improvement on what these agents were capable of. We had a project just yesterday where we tested Fable versus Opus 4.8, and you'd think like, "Okay, well these are, should be on the same exact trajectory of progress."
And the thing that Opus 4.8 couldn't do, Fable just finally actually did. And so if you don't actually constantly recheck what is now possible with AI, you will fall into the trap of sort of, you know, kind of believing that maybe the productivity gains aren't there, or you're not able to accomplish as much as you wanted. So I think have very ambitious expectations, constantly be trying the technology and, you know, keep pushing the limits.
The rise of the forward deployed engineer
Michael Krigsman: It is incredible how fast things are changing and how rapidly the capabilities are improving. Let's jump to some more questions. This is from Chris Faulkner on LinkedIn. "What are your thoughts on the forward deployed engineer, FDE concept?"
Aaron Levie: I actually think there's going to be a role for effectively an internal FDE and this is some kind of IT business AI automation engineer type role. I think often it's going to live within the technology or IT organization, but be embedded within the actual line of business that it's trying to bring automation to. So there's the internal version, and then there's the external version coming from either the vendor or the systems integrator or maybe a new consulting firm, which is effectively, you know, as we.
If we go back to what's the difference between coding agents and the rest of knowledge work, it's, a lot of it does come down to how technical the user is and their ability to navigate around all the challenges that agents run into. So one of the big challenges is, you know, do agents have access to the right data to be able to work with? Do they have access to the right internal systems to be able to pull context into the context window to be effective?
Well, an engineer kind of knows all their way around those different systems. They know how to get access to resources they know how to set up MCP servers, they know how to set up CLIs, they can deal with kind of, you know, compute sandboxes that the agent might need to be able to run into. This is just not necessarily how most of knowledge workers were trained. These are not the things that we've ever had to think about.
You know, we, we're kind of used to we go into PowerPoint, we go into Word, we go into G Docs, we go into Slack. We generate, you know, a bunch of stuff. We know how to create files and share them. We know how to do, you know, kind of lightweight manipulation of these tools. But actually for an agent to be really effective, they need access to all the right data.
The data's got to be in the right format. You probably need skills files and ways of having agent sort of, you know, kind of read-me files in the process. This is sort of this agents.md phenomenon that has emerged. You have to have the permissions to actually, you know, turn on the MCP servers. All of that is technology work. There's almost no way for that to not be done by somebody at least either formally trained or has sort of figured out how to be highly technical.
So the job of FDEs is basically go help companies sort of first of all understand today's workflow, and then figure out how to bridge the capability of the technology that is emerging and constantly changing with the workflows of that organization. And sometimes you can get lucky and you can kind of embed agents in existing business process and it sort of just miraculously works. But oftentimes you actually have to re-engineer the process.
You have to migrate the data sources into a modern system. You have to sort of change the workflow so agents can be more effective in that workflow. All of that is effectively the work of the forward deployed engineer, and that forward deployed engineer could come from a vendor like a Box or a Salesforce or a Palantir, or it could come from a systems integrator or maybe a new consulting firm.
So I think there's going to be all these new roles that emerge, which are basically the technical talent that has enough business acumen to get into the business processes of that organization, but successfully implement the tools of AI to actually bring agents to bear on those workflows.
Michael Krigsman: So one of the very interesting aspects of all of this to me is you've got the technology on the one side, and then as you were just describing, you have the organizational ramifications, the implications for the processes, for the talent, for the skills, for the mindsets, for the culture.
But Robbie Hassan on LinkedIn says, "Looking ahead 3 to 5 years," but I'm going to say looking ahead for a year or 2, "do you think the biggest competitive advantage will come from having the best AI models or still owning the best proprietary data workflows and distribution?" And I'll ask you to also incorporate into this the extent to which the models are becoming commoditized.
Aaron Levie: Yeah.
Michael Krigsman: Because you just yourself just described, you know, the using different models, which means you're swapping.
Frontier models need your data architecture
Aaron Levie: I think we're still at a point where I would bet on either a technology company or an end user of the technology that has simultaneously, you know, the frontier models that they're leveraging and the best ability to get those models the right context to be able to work with. And so, you know, kind of sometimes you kind of want to do this thought experiment, which is if you were starting your company from scratch, what would it look like to be able to get the full gains of AI?
And I think it's kind of, you know, pretty intuitive that if you could start your company from scratch, you'd basically design your business processes in such a way where the agent has sort of innate ability to get access to the context it needs to help you automate work. And so if we started a one-person company eh, you know, you'd probably start with like a file system that had all of the context of your business.
It had all of your goals, it had all of your marketing strategy, it had all of your, you know, customer sort of language that you used, and then you'd build your company up from that foundation, which is, okay, agents always need access to the right data to, you know, answer the right question or be able to automate the workflow.
So if you were to build your company from scratch, you would do both the frontier intelligence and you'd have proprietary information and insight that you're giving that agent, and you'd kind of develop a flywheel. And so then as you hired more people in, you would try and sort of maintain that ability for agents to keep having access to the right data. You'd really value sort of sources of truth and authoritative sort of knowledge banks.
You know, one of the problems that traditional enterprises have is our sources of truth are everywhere, and many of them are not well-maintained. But if you were starting from scratch, you would just always be like, "You know what? We always write down our final decisions in a way that agents can get access to, so that way the agent doesn't sort of you know, land on the wrong resource or it gets the wrong insight from some data we give it."
So that, that's what you'd do if you could start from scratch. To, so to the question, you know, what should you do right now in any kind of meaningful or large enterprise, you basically are trying to do whatever you can to get to the point where a company from scratch, you know, it sort of is built up in this kind of way.
So I would be betting on frontier intelligence right now with the combination of access to the right context for those agents to be effective and making sure that your organization is built in such a way where you can get those agents the right data in those workflows. Now, to your second question that you added on top of that, this is sort of a different, you know. Then the question is architecturally, does that mean that you sort of bet entirely on one frontier model?
Probably not. You probably want to sort of design some kind of neutrality where right now I think you should still try and exploit the gains from frontier intelligence as much as possible, but in one or two or three years from now, I think you're going to see this sort of stratification between the cost of frontier intelligence and the cost of sort of the second-best frontier intelligence, but that can do the job extremely well and in a high-quality way for a bunch of sort of long tail tasks.
And I think you're going to end up in a world in, you know, one, two, three years from now where model routing becomes very important, where maybe something like a Fable-esque model gets the planning part of the work and the review part of the work, but the in-between sort of massive token usage comes from maybe something that is a more cost-effective model for that type of work.
So then thus you want to invest in the right kind of architecture that can deliver on that type of outcome. That's probably where we're heading from a kind of tokenomics standpoint. But I think, you know, making sure that you can design an IT architecture and a data architecture that lets you deliver that is super important.
Michael Krigsman: Such a great important point about the designing of the right type of flexible architecture that lets you accommodate changes in models both in terms of the capabilities and the costs.
Aaron Levie: I thought this was true in the kind of cloud and SaaS era, but now it's an order of magnitude more true. We used to have this thought process which is if you show me your IT stack, I'll show you your culture. Which is, you know, if. I can tell you from the tools you use the kind of culture you have and how fast-paced your company can be how innovative it is because you can just see.
Like does the average employee have access to the data that they need to do their work? Can they communicate, you know, instantaneously with their colleagues with very, you know, few barriers? So that was kind of a 10, 15-year-ago version of this when you sort of saw the rise of Zoom and Slack and these kinds of solutions. I think there's a new version today, which is if you show me your IT stack, I'll show you what you're going to be able to get from agents.
I, and I can just you can just see it instantly what kind of agentic productivity and outcomes you will get based on where is your data today, how much is in legacy systems, how much are in systems where the agent has access to these tools. What is the frontier intelligence you're using? And so I think, you know, oftentimes we're having an AI conversation, but it's sort of masking an IT architecture conversation or a data architecture conversation.
And that's really a lot of the conversation we should be having, which is do you have the right data platforms, do you have the right IT architecture to let you get the real productivity gains from AI right now?
The end of subsidized tokens
Michael Krigsman: You mentioned, Aaron, the term tokenomics, and we have a question from Chris Petersen on Twitter, X, who says, "How is Box dealing with model providers and others increasingly moving from subscriptions to pure tokenomic chargeback?" In other words, how are you, how does Box deal with these increasing costs?
Aaron Levie: We definitely preferred the world where it was being subsidized. So those days are over. You know, it was, it was fun while we got it, guys. And it was you know, there was a brief moment where you could rely on the subsidization from venture capitalists and then get, you know, kind of tokens for your coding agents.
Michael Krigsman: That was, a beautiful thing.
Aaron Levie: It was a beautiful moment in history. It lasted about a year and we all had a great time. So, you know, there was definitely actually a period there where you probably could've really exploited it and had 10 years of software development, you know, paid for by LPs and VCs. Unfortunately, those days appear to be coming to an end. But now we're, you know, now we're in a much healthier environment, which is you're more or less going to be paying for the real underlying costs that it takes to deliver this.
And then I think it's just capitalism, you know, microeconomics 101, which is, you know, where are you getting the right ROI from these agents? And you should deploy agents at the work where it's most effective or you are getting that ROI.
You know, we're fortunately in a little bit of a sweet spot where because we're an enterprise software company, because what we build, we have a pretty good pulse on our customer base, so we kind of know how to deploy you know, agents in a way that makes us more productive and lets us ship more software that we think is going to be valuable. So we are, we're kind of smack in the middle of if you have a token maxing company, you know, we're not that.
You know, we don't have a leaderboard internally. We don't try and incentivize the most number of tokens. And then on the other end of the spectrum, maybe you'd have a company which is everything's locked down, and it's really hard to get access to frontier agents. We don't want to be that either.
We try and rely on, you know, more sort of mature, sophisticated approaches of as long as we have a really good product roadmap and we have really good sort of product managers and engineers kind of at, you know, working on designing that, then actually I'd rather move that product roadmap forward as fast as humanly possible, which means that if the token spend goes up exponentially that should actually be correlated with a good thing, which is we can deliver more software to our customers faster.
And then it's more of a CFO exercise, which is how do you plan for that? How do we budget for that? What are the trade-offs we're making in the organization? I do think the corollary to this is we're well past the point where the IT organization can hold the entire budget of AI.
And that, that's actually a healthy thing, and it's a good thing for this as a technology, which is, you know, IT budgets kind of run depending on the industry, maybe 3 fives, you know, 2 to, 2% to 5% of sort of total revenue depending on the kind of industry that you're in. And that's obviously an, a sort of an artificial cap on what AI, AI's potential could be.
You know, maybe you want AI alone to be five percent of your total revenue, so that would be a doubling of the IT budget. Well, to do that, then you ultimately need the line of business to own the budget and own the sort of deployment of where do they want, you know, AI being used in the organization.
So I think we're in this renaissance actually of the IT organization, which is your job now is to bring kind of, you know, some form of intelligence to the entire business and be the sort of experts in the technology and what you're going to be able to deliver with that technology. You're going to partner with the business on where should that get deployed you know, and then that's sort of this interesting budget/use case meets technology and capability kind of pairing that we're going to have for quite some time.
Preparing for an agentic future
Michael Krigsman: We have 3 questions from Maya Cunningham, Abdullah Alganemi, and Aga Salman, and they're all asking how should knowledge workers prepare for an agentic future? What are the AI automation roles? How should they get started in automation? Which tools?
Aaron Levie: I think this is an incredible time if you're super curious, if you're excited by technology, if you're one of these people that geeks out on, you know, the latest version of the iOS release and now it's the latest version of the Claude Cowork release or Codex release. So I would go very deep in the technology. I would be experimenting with it constantly to kind of push the limits of what these tools can do.
The awesome thing is that, you know it, it's one of the first moments in history where almost everybody, and you know there's some asterisks, but almost everybody has the same amount of access to information at the same moment. So, you know, 20 years ago there was this huge advantage where if you were in Silicon Valley you know, you would see the iPhone first 'cause you could go to the developer conference and look at it and you saw what was happening in SAS 'cause most of the companies were located here.
Today in 2026 there's, you know, maybe I have an hour, you know, heads-up of information from anybody else 'cause there's some chat thread that, that's going on with Silicon Valley founders or something. But other than that, we all have access to the same technology effectively at the same moment. Which means that if you're paying attention to the right resources, you know, this podcast being one of them you know, there's other great AI podcasts, you can be as informed as the best expert in the world right now.
You get the same newsfeed as Andrej Karpathy. You get the same newsfeed as Greg Brockman or Dario Amodei and Sam Altman. So if you're getting the same newsfeed, then that means that there's very little that they have access to other than maybe what's in their research labs that you can't take advantage of. So I think we have this cool moment in history where the information sources are keeping up with the pace of the innovation.
Doesn't mean our organizations are, but it means that our ability to tap into what's happening. So I would just be playing with this technology constantly. I'd be pushing the limits, I'd be breaking things and then I would try and figure out what are the implications of this technology to either an organization I already work with or an organization I want to work in? And I think those kinds of people and personalities will be the ones that, you know, for now especially get ahead, you know farther.
Michael Krigsman: It's so true. You know, I am not a developer. I'm a typical knowledge worker, but I force myself to use Claude Code to use it, to learn it, and the things that I can do with coding, like for example on our website that I've wanted to do for years.
Aaron Levie: Yeah.
Michael Krigsman: And it's not only the labor, but the agent has access to specialized knowledge.
Aaron Levie: Yes.
Michael Krigsman: That one person cannot possibly have. Can't. And so instead of having a team of specialists, my agent is doing various things. I mean, I go, it's unbelievable.
Aaron Levie: It's a key insight that some people miss a lot because you're always so used to thinking about this as kind of, you know, we sort of anthropomorphize this technology, you know, probably sometimes too much, but it's not just an engineer or just a marketer. It's got this ability to have the, all of the skills in one.
So I'll often go to AI for product prototyping and I might give it a prompt that is sort of very specific, but sometimes I'll actually add like, "And feel free to add anything else you come up with into the prompt." And so that'll be an explicit, you know, sentence or 2 in the prompt, and it will come up with an idea that far exceeds what I ever would've been able to prompt it to do because it can take in all of these extra domains that it knows about.
And so if you're doing product prototyping, you know, try not to just limit to your own imagination of what you're trying to accomplish. You know, give it that extra nudge that says, "Hey, if you also have better ideas than what I'm telling you to go do, come up with it and show me what you're thinking about."
And the cool thing about AI, I mean, you know, it's getting more expensive, there's no question, but the cool thing about AI is you could just have 5 tabs running and have it go do 5 different versions. So I'm often prototyping in parallel just to see are there things that I'm missing, and can this expand the kind of, you know, use case or capability that I was trying to kind of come up with?
Michael Krigsman: Now would be an excellent time for you to subscribe to the CXOTalk newsletter so we can notify you about upcoming shows and you can really be part of our community. Go to cxotalk.com and sign up for our newsletter, and do that now. We have a very interesting question from Swami Vaidyanathan who says, "How do you see business models change as you bring agents? Overall, where do you see pricing pressure due to simplification and where governance costs nullify the benefits, if there are any?"
Where software value shifts
Aaron Levie: This is a big question in general across the software ecosystem, which is, you know, what's the new value proposition of software in this world of agents? And we've been pretty clear that you know, I think that people can certainly have different takes on this. I think that, you know, for the most part, you're not going to go and vibe code a CRM system or an ERP system.
You know, we don't think that you should be vibe coding a core system of record for your documents and enterprise data just 'cause, you know, first of all, you're benefiting from the fact that there's also another 100,000 customers that need the same technology, so it's the job of that vendor to get really good at doing that one thing really well. And if anything, you know, with AI, we can actually do that for you even faster and even better.
And so I think there's been some kind of confusion about where we're probably going to be applying the, these tokens and these capabilities. So I think the value of kind of the core systems of record, you know, continue to matter a ton. But then the question is what can you do with agents on top of those systems of record, and where can I get even more value from my technology?
And this is what I get really excited by because I think what's going to happen is we're just going to be using our tools far more. I'll give you one example.
I use Salesforce more today than at any point in history, maybe five times more, because I have an MCP server I have their MCP server connected to Claude Cowork, and I'm constantly banging on the MCP server doing various customer intelligence, market intelligence that I would have never done by manually going into Salesforce and kind of pulling up records and looking at them.
And so I actually think that there's been a little bit of a, kind of a misread on the market opportunity, which is actually we're going to move to a world where there's going to be, you know, maybe 100 times more agents than people using software. So in a world of 100 times more agents than people using software, what are we going to use these tools for? We're going to use them for so many more things in our organization.
And we have an interesting lens in this 'cause we get to see it from our customers where they're just processing data at a scale that never would've been possible before with humans. And so all of a sudden the value of your unstructured data assets have gone up. The value of your CRM systems have gone up. The value of what you can now do with your ERP system has gone up.
So that's, I think, the, you know, how the maybe the value shifts over time. And then, you know, things like governance, all of these things become really important for actually then, you know, making sure you can effectively get those gains you know, from those technologies.
Reimagining workflows around abundance
Michael Krigsman: This is from Somok Sengupta, who says, "Internally, within business functions, how are you reimagining workflows using AI? For example, you're looking at traditionally overlooked candidates like.
Aaron Levie: Yeah.
Michael Krigsman: Finance." And I'll mention we recently had as a guest on CXOTalk the CFO of HPE, talking about how she's using agents in the finance function.
Aaron Levie: I think you should really treat this as a technology for abundance. And you almost have to kind of look at your business and stop and ask yourself in every part of your business, "If I had. " And it's just good for a thought exercise. It's, you know, you can't actually afford this, but if I had unlimited capacity in, you know, X, Y, Z area, what would I do differently in that area of work?
And you know, unlimited, let's say, you know, capacity for combing through information, for using judgment, for accessing data. If you could do that at an unlimited amount, what would change about that workflow? And, you know, I think you quickly can start to think through, well, wow there's actually a lot of parts of my business where I've been constrained by my ability to deploy human resources at certain problems, and if I get incrementally unconstrained because now agents can go do a lot of that work, what would I do differently?
So, you know easy example in our kind of world as a B2B company is if I could deploy agents to go and comb through our customer base, we would have much better insights about the right time to have that right message for our customer when they're dealing with some issue that we can be helpful with.
If I could deploy unlimited compute, it would, you know, it would know everything that's going on in every single one of our customers, so we can be that much more helpful in our relationship or our partnership. You know, I think you, in your question, you asked about HR. I posed this question to our recruiting team the other day. I said, you know, "If you could just comb through all of, let's just say, LinkedIn, and you could, you didn't.
And instead of just sort of stopping at, you know, the LinkedIn profile, but you could then hop over to the internet and see what were the GitHub projects that person worked on. You know, what, what's their thought leadership that they've talked in the press about and you could build a sort of full profile of that individual. And at the right moment, when something's going on in that organization, that was the time to either talk to them or recruit them or have a conversation.
You know, how would that change recruiting, as an example? And so you can kind of go through, you know, your entire organization and see where is your business, where could your business actually have completely different returns with. If you had just unlimited capacity to go and work on whatever it is, and be able to have unlimited information. And so, you know, to a CFO, it's, you know, there's a huge wealth of examples, which is, well, what if I could analyze my business totally differently?
What if I could see where maybe there's waste, you know, in the business from a operational, you know, expense standpoint? I can go and take those dollars and reapply them to areas where we need to drive growth, or which parts of my customer base are unprofitable that I can go and kind of tweak the business model for. You know, where are there insights in market opportunities that we should be doubling down in?
All of these things, you're basically constrained today by the amount of people you have to.
Michael Krigsman: Work.
Aaron Levie: Through spreadsheets and work through ERP systems and work through, you know, analytics data. Well, now you can actually throw compute at that problem, and all of a sudden you're no longer constrained by the number of people you have on the team. So I think we're in this real renaissance again of the kind of workflows that we can go and execute. And, but that really does take kind of looking across the organization of where would you have a lot more upside if you could bring, you know, unbounded resources to those areas?
Measuring value, not tokens
Michael Krigsman: This is from Santhosh Vasanthakumar, who says, "What are some of the best practices followed at Box to measure value generated from AI adoption? For example, value maxing versus token maxing."
Aaron Levie: Definitely a big fan of value maxing, and I'm glad that, you know, terminology has already taken over from token maxing pretty quickly. I think, honestly, it's hard to be too generalizable about this. I think it's probably no different than, you know, if you were to ask that exact question 20 years ago, before any form of AI or cloud technology or whatever, you just said, you know, "How does somebody measure the ROI in the marketing team or in the sales team or in the finance team?"
I think you'd have to use whatever tools we, we've always thought about, which is, well, I have a certain amount of dollars. I can deploy those dollars against, you know, a variety of different sort of things in my business. I could do events, I could do. I could deploy marketing campaigns, I could build products, I could hire people at a certain price point. I can do infinite set of things.
So how have we ever measured ROI? It's basically amongst all of these choices and all of these opportunity costs, where is the most effective use of the incremental dollar going to go in? And the, maybe the bittersweet news here is that it is no harder or easier to do this with AI than at any other point in history.
It's always been this kind of squishy thing where there's some judgment and you're kind of, you know, sometimes you guess, and sometimes you guess wrong, and sometimes you guess and you guess right, and then you keep doubling down. AI is no different. You know, we're. You're going to be experimenting. You need, you know, it, the. You need high judgment people.
Maybe the one difference, I guess, is certainly if you know, with the wrong prompt and the wrong limits, you could probably go and spend $50,000 and wake up the next day and have that bill. So you do have to be pretty thoughtful about, okay, where are we going to go deploy these tokens?
But short of just making sure you don't make, you know, catastrophic mistakes like that, I think the problem looks pretty similar to the history of business, which is you need people close to the business with budgets that have high judgment, they understand the technology, they understand what it's capable of, and then you need a rigorous process to constantly be reviewing where are you getting the ROI, you know, from these deployments.
This is not a sort of a one-stop, one-shot kind of environment. This is an ongoing budget management process.
Michael Krigsman: I have to highlight this comment of Aaron's because if you're a CIO, it's not just a matter of the technology. Success is not just a matter of the technology, but of developing, he used this term, judgment and the business acumen. And this is not a new story. This has been going on, you know, forever. It's never been more true than today. It's been true in the past, equally true today.
Okay, this is from Zoe Farrill-Rhoden, who says, "Given the trap one falls into if you don't keep up with AI and the many iterations, what do you see as the most valuable skill knowledge workers the most valuable skill knowledge workers need to have in today's world other than adaptibility?"
Aaron Levie: I do think it's really important to keep up with the technology. I don't know of a replacement to that. Unfortunately, I know that was in as the qualifier to the question, but I think you just have to find a way to stay as current as possible, and it behooves companies for educating their employees as well on this.
Adoption rises from the front line
Michael Krigsman: And let's go to the next one. Greg Walters says "It seems that the best AI implementations rise from employee up versus the C-suite down." Your view on that?
Aaron Levie: I think that's like 90% accurate. I think that there's you know, the person that actually owns the delivery of a particular project is in the best position to know, you know, what's the rate of productivity they can get with AI, assuming that they have religion on this. The only exception is when you just have some things that are either so expensive or transformational that you need the kind of senior leadership to get behind or kind of to identify, but I would generally bias toward that point.
Michael Krigsman: And this is from LinkedIn, from Benyawarath "Yaa" Nithithanatchinnapat, Ph.D. Who says, "Aaron, building on your point about playing with the technology, if everyone has access to similar AI tools and information, what separates a strong early career candidate from the rest? What should students practice or build to demonstrate real AI fluency?"
Aaron Levie: Again, this combination of both technical skill and business acumen is sort of still the best approach, which is if you're interested in marketing, get both really good at marketing and the core principles of marketing, but also understand how AI accelerates building a marketing campaign or doing market research. And so being able to live at that intersection is, I think, still the most sort of potent way that you're going to be able to go and deploy this technology.
And so I would tell that to, you know, if you're in. If you're doing, you know, clinical drug trials and you're in life sciences, you know, deeply understand that, but then also understand how something like Cloud Code or Codex helps accelerate that kind of work.
Michael Krigsman: And Simone Jo Moore says, "Do you see governance changes now as an AI add-on or embedded?" And she'd love you to use the word squishy.
Aaron Levie: Okay, squishy. Squishy for sure. I think it's got to be I think it's mostly embedded, but there's some areas where it's got to be, you know, kind of an adjunct.
Michael Krigsman: Ken Walker: "Using different tabs as a type of peer review between varied iterations." Sounds like that's what you're doing.
Aaron Levie: Yeah.
Michael Krigsman: Tope Ajao says, "Your thoughts on agentic AI have been very helpful. This week at the Blue Chip Data and AI Summit, he was a panelist on the future of work, and he did share the importance of focusing on the pain value against the tools which are moving at a really fast pace." So there is some pain that's involved with keeping up. Thoughts on that, very quickly?
Aaron Levie: I feel the pain all day long, so it's I completely agree.
Advice for CIOs in the agentic era
Michael Krigsman: Okay, Aaron, we have just a couple of minutes. What advice do you have for CIOs in relation to AI adoption?
Aaron Levie: I think it's the most exciting moment in history to be a CIO. There's so much change within technology, so you have. You know, if you're even remotely curious as a, as an IT leader in the IT organization, there's just a, an incredible tsunami of new things to play with and technology to try out. So I think that, that's very exciting.
I think actually the importance of the CIO role, you know, rises dramatically because this is, again, kind of back to a prior point agents are maybe the most technical solution that has ever been deployed to non-technical people. It, you know, you're deploying non-deterministic intelligence into the hands of every knowledge worker that will, it will run wild and, you know, grab the wrong data and produce the wrong report, or produce the right report and produce the right data and generate the right software code.
But that's all determined by your technology architecture. It's all determined by how you deploy these agents. It's all determined by how you trained your users to use them. So I think the role of the CIO becomes substantially more important. You're effectively providing work to your organization. That's the first time in history where IT was responsible for deploying the actual sort of real output of the organization, not just the tools that enable the output.
So this is a, again, an incredible time to be in IT.
Michael Krigsman: Aaron, very fast, an important question from Arsalan Khan on X. The right agent with the right permissions can do great things, but what about agent deployments without any permissions and giving access to all data? How much knowledge is too little to deploy agents?
Aaron Levie: Because of our customer base and because of how we've kind of grown up as a platform we see the danger in too much information in the hands of either the wrong people or the wrong agents, and so I. You know, it's this is definitely a phenomenon where you have to make sure that the right, only the right context gets to the agent. You can't actually just shove as much context as possible to the agent.
First of all, that'll be a security nightmare, and then second of all, it'll actually still get the wrong answer because it'll have too much things to put its attention on. So the right context at the right time with the right guardrails is still a critical problem for agents to work with.
Box and the unstructured data problem
Michael Krigsman: Aaron, we're out of time. Give us the one-minute sales pitch on Box.
Aaron Levie: Well, our job is to hopefully help customers solve many of these problems with their unstructured data. So I think the reason why we're so excited and the reason I'm so passionate about AI is it's the first time in history where we can actually tap into all this data that we have in our organizations. And so at Box, we're trying to build the leading AI platform to help companies tap into all of this unstructured data and knowledge and then work with your entire agentic ecosystem.
So I appreciate you having me on, and these are the topics that we get really excited by.
Michael Krigsman: Aaron Levie, CEO of Box, thank you so much for coming back. This is your sixth time on CXO Talk, and I'm very grateful to you. It's been a fascinating discussion.
Aaron Levie: Thank you.
Michael Krigsman: And everybody, thank you for watching, especially you guys who ask such great questions. You guys are incredible. Before you go, subscribe to the CXOTalk newsletter. Go to cxotalk.com, and we'll see you again next time. We have incredible shows coming up. Take care, everyone.

