Enterprise adoption of agentic AI is accelerating faster than many IT leaders anticipated. Against this background, Boomi APAC CTO David Irecki says the old “plumbing” of the enterprise stack is undergoing a renaissance with Boomi repositioning itself at the centre of it.
Over the last three years, Boomi has shifted from being known primarily as an iPaaS or (integration platform-as-a-service) and integration vendor to branding itself as “the data activation company”. This is backed by a string of acquisitions across API management, data management, and AI governance.
“We’re no longer just about connecting applications,” David said. “We help organisations take data that’s spread across ERP, CRM, HR, finance systems, and make it usable in real time for workflows, decision-making, and increasingly AI agents.”
Boomi now organises its capabilities into four core pillars – integration, data management, API management, governance – on top of which is what Boomi calls the data activation layer where trusted data is made available to enterprise workflows.
Atop this stack, organisations are building agents in tools Microsoft, Salesforce, and Boomi itself provides. But David pointed out the company’s differentiator lies in governing how these agents interact with data and systems.
He said, “But the discussion we have with most of our customers is not around the agent design; it’s actually around the agent governance. So governance has now become a major topic because organisations are trying to work out ‘What data are my agents accessing? Who’s actually asking for that data? How do we secure (access) control into those backend systems’.”
To address this, the company has built an agnostic governance layer that oversees agents regardless of where they were built. “We are able to provide observability and governance.”
2024 vs 2026: From summarisation to autonomy
Reflecting on 2024, David described the last two years as an evolution from simple generative AI use cases to autonomous agents that can take real actions.
In 2024, Boomi – like many enterprises – focused heavily on generative AI to provide summarisation and an internal AI assistant Boomi GPT which ingested internal information and helped sales teams for example, quickly craft emails and proposals.
By 2026, this has shifted decisively to autonomy and orchestration where AI agents are embedded into existing workflows.
David gave a retail example: in a traditional order-to-cash flow, an integration function might simply be to call a courier’s API to ship a TV. In an AI-enabled world, that call can be replaced by an agent that dynamically queries multiple carriers in real time and returns the best option based on price, speed, and other requirements.
That might give a five to ten percent efficiency gain, he observed, adding that the more interesting conversation is, “If we rebuilt the process from the ground up using AI, what would that look like?”
OpenAI/Hugging Face breach: A warning shot for agentic AI?
The Boomi interview came just days after reports that OpenAI’s agentic AI escaped a sandbox and exploited unsecured assets on Hugging Face, a high-profile incident that has sharpened focus on the risks of connecting autonomous agents to live systems.
David framed the breach as more of an access control issue for which Boomi’s approach would be to reuse an organisation’s existing identity provider (IdP) as a gatekeeper for AI access.
“It’s all about access control,” David said, explaining that with a capability like Boomi Connect, an agent attempting to access a system like Saleforce, for example, would have its identity checked by the organisation’s IdP. The agent in theory, would be restricted to what its specific user is allowed to see and do, mirroring human access controls.
“Based on my profile, the agent only sees what I’m entitled to view.”
The Broader Challenge
David observed that the incident has intensified conversations about AI readiness, guardrails and identity-aware access to backend systems.
He distilled the key challenge as having to balance autonomy and oversight. In low-risk context, for example recommendations on an e-commerce site, organisations might tolerate more agent autonomy and occasional errors.
In high-risk sectors like healthcare, however, he said, “You want a lot more oversight and humans checking things, because if an AI agent recommends the wrong medication, that could have life-threatening consequences.”

