← Field notes
8 min read

Oncourse, Aikido Security, and the New AI Transformation Blind Spot: Runtime Visibility

The Oncourse and Aikido Security story is a useful signal because it cuts through the usual transformation theatre. Digital transformation doesn’t break because a company lacks ambition. It breaks because leaders can’t see what’s really happening inside the systems they’re asking the business to trust. Runtime visibility sounds technical, almost niche. It isn’t. It’s fast becoming one of the executive controls that separates serious transformation from expensive guesswork.

The source article, How Oncourse gained runtime application visibility during a company-wide digital transformation - Aikido Security, was published via Google News on 22 June 2026. The public summary is brief, but the point is clear enough: during a company-wide digital transformation, Oncourse needed better visibility into applications while they were actually running, not just at design time, not just in code scans, and not just in periodic audits.

That distinction matters. Especially now.

Across Australia, Canada, New Zealand, England, Ireland, Scotland and the United States, leadership teams are pushing AI into customer service, operations, software delivery, finance, compliance and decision support. But many of those initiatives sit on top of application estates that were never designed for AI-speed change. Old workflows, half-documented integrations, cloud sprawl, APIs no one quite owns, and security tooling that produces more alerts than clarity.

If that sounds familiar, it’s not because your organisation is behind. It’s because most organisations are trying to modernise the plane while it’s already in the air.

Runtime visibility is becoming a board-level transformation issue

For years, transformation programmes treated observability, security posture and application visibility as engineering concerns. Important, yes, but usually buried under architecture review boards and tool selection meetings.

That era is ending.

When AI is added to business workflows, the risk profile changes. Applications don’t just process transactions anymore. They trigger recommendations, route work, summarise sensitive data, write code, triage customer issues, and in some cases make semi-automated decisions. If leaders don’t know what services are running, what dependencies they rely on, what vulnerabilities are exploitable, and what behaviour is actually happening in production, they’re not leading transformation. They’re hoping it behaves.

Runtime visibility gives teams a live view of application behaviour in the environment that matters most: production. That’s where the messy truth lives. Not the architecture diagram. Not the vendor slide. The running system.

Aikido’s Oncourse case sits within a wider 22 June 2026 news pattern: digital transformation is no longer limited to software companies. The same Google News cluster included stories on public service delivery, maritime operations, AI infrastructure partnerships and professional leisure markets. The specific sectors differ, but the signal is consistent. Transformation is spreading into operationally complex environments where visibility, governance and resilience matter more than shiny demos.

Unknown block type "table", specify a component for it in the `components.types` option

The point isn’t that every organisation needs the same security platform. They don’t. The point is that visibility is becoming a shared transformation requirement. Whether you’re modernising student services, public infrastructure, customer operations, logistics, insurance claims, field service or software delivery, the leadership question is the same: do we understand the system we’re changing?

AI raises the cost of not knowing

AI doesn’t create the need for runtime visibility. It exposes the lack of it.

Before AI, a poorly understood workflow might create delays, rework or inconsistent reporting. Painful, but often containable. With AI, the same unclear workflow can become automated at scale. Bad handoffs become faster. Poor data lineage becomes harder to explain. Security gaps become easier to trigger. Exceptions multiply quietly.

This is why epoqx keeps coming back to a simple view: most organisations don’t need more AI tools first. They need better systems, workflows and implementation discipline. If you’re wrestling with that gap, our guide on What is the AI implementation gap? is a useful place to start.

The Oncourse example is interesting because runtime application visibility is not a cosmetic improvement. It helps answer practical questions that transformation leaders should be asking before scaling AI-enabled workflows:

  • Which applications and services are actually active in production?
  • Which vulnerabilities matter because they’re reachable at runtime?
  • Which dependencies are business-critical, stale, duplicated or unmanaged?
  • Which APIs, containers, packages or workloads sit inside high-value processes?
  • Where should engineering, security and operations teams focus first?

That last question is underrated. Transformation teams drown when every risk looks equally urgent. Runtime context helps separate theoretical exposure from operational priority.

And that’s where AI strategy gets real. A model can summarise a support ticket, but if the downstream case management system is unstable, opaque or vulnerable, you haven’t transformed the service. You’ve just put a clever interface on a fragile process.

The market signal: transformation is moving from promise to operational proof

There’s a broader market mood shift here. For the past few years, AI transformation has been sold through possibility: copilots, agents, automation, productivity gains, smarter decisions. Fine. Possibility matters.

But the next phase is proof.

CIOs and COOs are being asked tougher questions. What changed in the operating model? Which process improved? How did cycle time, risk, cost or customer experience move? What can be safely scaled? What should be stopped?

That’s why stories like Cloud Exchange 2026: Coast Guard’s Brian Campo on service’s new Digital Transformation Strategy - Federal News Network are worth watching alongside private-sector cases. Government and regulated environments tend to surface the hard parts early: governance, accountability, legacy integration, operational continuity and security.

The same applies to infrastructure news such as Rebellions, CCK Solution Partner on Enterprise AI Transformation Infrastructure - thelec.net. AI transformation infrastructure isn’t only about chips, clouds and models. It’s also about the systems of control that let enterprises operate AI safely inside real workflows.

A simple way to see the shift is this:

Unknown block type "table", specify a component for it in the `components.types` option

The bar has moved. Static governance isn’t enough when systems are dynamic. Annual risk reviews won’t keep up with weekly releases, API changes, model updates and new automation paths.

This doesn’t mean every executive needs to become a security engineer. Please, no. But leaders do need a sharper view of runtime risk as part of transformation governance.

What leaders should learn from the Oncourse signal

The practical lesson is not “buy another dashboard.” Dashboards are cheap. Decision-quality visibility is hard.

A useful runtime visibility capability should help the organisation make better calls about priority, ownership and action. If it only produces more alerts, it’s another tax on already overloaded teams.

For business and technology leaders, the Oncourse signal points to five moves worth making now.

Treat visibility as transformation infrastructure

Runtime visibility should sit alongside cloud architecture, data governance, identity, integration and workflow design. It’s not an afterthought. It’s part of the operating model.

If your organisation is reframing transformation for the AI era, epoqx’s guide on What is digital transformation in 2026? lays out why the conversation has moved beyond “going digital” and into redesigning how work actually runs.

Prioritise exploitable and business-relevant risk

Security teams often face too many findings and too little context. Runtime visibility can help identify which issues are actually present in active workloads and connected to important business services. That makes remediation more targeted.

The executive question becomes: what risk is live, reachable and attached to something that matters?

That’s a much better question than: how many vulnerabilities did the scanner find?

Connect application visibility to workflow outcomes

Transformation isn’t just about applications. It’s about the work those applications support.

If a vulnerable service sits inside a low-use internal tool, that’s one priority. If it sits inside claims handling, student enrolment, payment processing, dispatch, customer onboarding or compliance reporting, that’s a different conversation.

This is where many AI programmes stumble. They optimise a slice of work without mapping the surrounding process. If that sounds painfully familiar, our article Most Businesses Don't Have an AI Problem — They Have an Implementation Gap goes deeper into why pilots often fail to become business impact.

Make visibility useful for non-technical decision-makers

Runtime data needs translation. A COO doesn’t need package-level vulnerability jargon. A CIO doesn’t need a 900-row spreadsheet of unresolved alerts. A board doesn’t need a heatmap that looks impressive but doesn’t drive action.

They need to know where the organisation is exposed, what business process is affected, what the options are, and what trade-off is being made.

That’s not dumbing it down. That’s leadership-grade communication.

Build the capability before AI scales the mess

This may be the most uncomfortable point. AI can make weak systems look productive for a while. Then the cracks widen.

Before rolling out AI agents or deeper automation, leaders should understand the application landscape that those agents will touch. Which systems are trusted? Which APIs are brittle? Which workflows need human control? Which environments lack adequate monitoring?

If you’re still deciding where AI belongs in the first place, How to choose your first AI use case is a more sensible starting point than chasing whatever vendor demo looked best last week.

A simple leadership scorecard for runtime-ready transformation

A practical scorecard can help leadership teams move the conversation from vague assurance to operational readiness. It doesn’t need to be perfect. It does need to be honest.

Unknown block type "table", specify a component for it in the `components.types` option

The percentages above are illustrative maturity targets, not market statistics. The useful part is the shape of the conversation. If your organisation can’t confidently fill in the scorecard, that’s not a failure. It’s a starting point.

And it’s a better starting point than yet another AI pilot with no operational backbone.

Why this matters across the markets epoqx serves

The Australian, Canadian, New Zealand, UK, Irish and US markets all have their own regulatory settings, labour pressures and technology ecosystems. But the transformation pattern is surprisingly similar.

Leaders want faster service delivery. They want more resilient operations. They want AI to reduce friction, not create a new governance swamp. They want teams to move quickly without casually increasing risk.

That tension is exactly where runtime visibility becomes valuable.

In England and Scotland, public and regulated services are under pressure to modernise without losing accountability. In Ireland, where many global technology and operations teams sit, scalable governance is not optional. In Australia, Canada and New Zealand, geographically distributed operations often make system clarity even more important. In the United States, the speed and scale of AI adoption means weak visibility can become a very expensive problem very quickly.

The business case is not only security. It’s operational confidence.

When leaders can see what’s running, where risk lives, and how applications connect to business workflows, they can make cleaner decisions about AI adoption. They can choose where automation should accelerate work, where controls need strengthening, and where a process should be redesigned before AI touches it.

That’s the difference between AI as a feature and AI as transformation.

The Oncourse and Aikido Security story is a reminder that transformation doesn’t become real in strategy decks. It becomes real in production, inside workflows, under load, with customers, staff, partners and regulators depending on it. If you’re ready to discover how AI can create measurable business impact and start your transformation journey with epoqx, visit epoqx and start with the systems that make impact possible.

FAQ

What is runtime application visibility?
Runtime application visibility is the ability to see how applications behave while they are actually running in production. It helps teams understand active services, dependencies, vulnerabilities and operational behaviour.
Why does runtime visibility matter for AI transformation?
AI often sits on top of existing applications, APIs, workflows and data pipelines. Without runtime visibility, organisations may automate fragile or poorly understood processes, increasing operational and security risk.
Is runtime visibility only a security concern?
No. Security is a major use case, but runtime visibility also supports operational resilience, workflow improvement, incident response, prioritisation and executive decision-making.
What should leaders ask before scaling AI across workflows?
Leaders should ask which systems AI will touch, whether those systems are observable in production, who owns them, what risks are live, and how each workflow connects to measurable business outcomes.

Ready to start your next chapter?