AI Insights

Enterprise Agent Infrastructure: The Missing Layer Between Agent and Production

Chris Jon Graf · AI Strategist & CEOPublished on 21 August 2026

In short

Enterprise agent infrastructure is the operational layer between a working AI agent and its safe, production-grade operation: identity, policy enforcement, sandbox isolation, observability and a deployment harness. Four major launches within a single week in August 2026 show that most companies still lack this layer – and that is exactly where agent projects fail.

One Week, Four Launches, One Message

Between 11 and 19 August 2026, four major vendors published their version of the same answer within eight days of each other. Red Hat extended OpenShift AI with OpenShell. Google expanded its Gemini Enterprise Agent Platform with a runtime, registry and gateway. BCG introduced the Enterprise AI Control Plane (EACP), a vendor-agnostic governance layer. And IBM rolled out its watsonx Agentic Control Plane across AWS and IBM Cloud. The timing is not a coincidence. All four platforms solve the same problem: the operational gap between a working agent prototype and its safe, controlled operation at enterprise scale.

What an Agent Control Plane Actually Does

An agent control plane is not a new AI capability. It is the operating layer underneath it. It answers five questions that no individual agent application can answer on its own:

  • Identity: which agent acts on whose behalf, with which permissions?
  • Policy enforcement: which actions is an agent allowed to take, and which not – enforced at the process level, not only in a prompt?
  • Sandbox isolation: how do you prevent a malfunctioning agent from reaching systems it was never meant to touch?
  • Observability: can you reconstruct, after the fact, exactly what an agent did, when, and why?
  • Deployment harness: how does an agent move from test to production without every team reinventing the process?

Why 'Can We Build Agents' Is the Wrong Question

Building an agent is no longer a significant hurdle. A VentureBeat report from July 2026 put it bluntly: a large share of what companies call 'agents' are, at their core, chatbot wrappers – impressive in a demo, but without the operational substance for production use. The real hurdle sits one layer down.

40%+

of agent projects are abandoned before ever reaching production, according to Gartner/BCG analysis

Two further figures from the BCG survey show exactly where things break down: 27 percent of companies have no mechanism to stop runaway agent costs, and 35 percent name vendor lock-in as their single biggest concern when choosing an agent platform. Neither is a model problem. Both are infrastructure problems.

The Four Launches Compared

Each of the four platforms addresses the control-plane gap with its own emphasis:

  • Red Hat OpenShift AI + OpenShell: agents run as OCI containers with AgentCard metadata in sandboxed deployments, with process-level policy enforcement, developed in collaboration with NVIDIA.
  • Google Gemini Enterprise Agent Platform: an agent runtime, agent registry and agent gateway with MCP and A2A support, scaling serverlessly.
  • BCG Enterprise AI Control Plane (EACP): a governance layer sitting above every individual platform, with an agent and tool registry, identity orchestration and deployment 'golden paths'.
  • IBM watsonx Agentic Control Plane: centralized control of agents across AWS and IBM Cloud, with inventory, governance and scheduling.

Hybrid, Not Single-Vendor: What the 51 Percent Figure Means

One further BCG figure is particularly telling: 51 percent of surveyed companies expect a hybrid control-plane architecture by the end of 2026 – deliberately avoiding lock-in to a single vendor. This mirrors a broader shift also gaining traction in Switzerland: the push for digital sovereignty and open alternatives to US and hyperscaler infrastructure, discussed for instance in the context of Apertus, ETH Zurich's own LLM. The logic is the same: committing too early to a single control-plane architecture costs exactly the flexibility that matters in a fast-moving market.

The Swiss Angle: FINMA, Data Protection and the Audit Trail Requirement

For Swiss companies with regulatory obligations, the control-plane question is not an academic exercise. FINMA-regulated institutions and companies operating under Switzerland's revised data protection law must be able to demonstrate, without gaps, which decision a system made, on what data basis, and with what authorization. That is precisely what a control plane delivers: audit trails, identity mapping and policy enforcement are not optional extras – they are the precondition for an agent being allowed to run in production at all. The fact that Red Hat OpenShift is already widely used across Swiss enterprises gives many mid-market companies a head start here: the infrastructure foundation often already exists, it only needs the agent-specific layer on top.

Where that layer is missing, the result is a pattern many enterprises are already familiar with: individual agents multiplying faster than anyone can track them, without a central registry or identity model to hold them together. That, in essence, is what the new control-plane platforms are built to prevent.

From Pilot to Production: The Next Step

The four launches from the past week also explain why many AI agent governance frameworks fail in practice: a framework on paper does not substitute for technical enforcement. Only once identity, policy and sandbox isolation are actually enforced in operation does a policy become a control.

The first step matters more than the perfect architecture

The natural instinct is to immediately evaluate a complete control-plane solution. A shorter inventory check is usually more useful: which agents are already running in pilot or production, who has access to what, and where is traceability already missing today? That check takes days, not months – and shows precisely which of the four approaches fits your existing system landscape.

Large ERP vendors are moving in the same direction. SAP's build-out of its own agent platform through Autonomous Enterprise and Joule Studio follows an identical pattern: the platform layer, not the individual agent feature, is becoming the actual competitive battleground.

What This Means for the Months Ahead

The question is no longer whether your company can build AI agents – practically any team can do that today with the right tools. The question is whether the operational layer exists that turns a working prototype into a secure, auditable and scalable production operation. That is exactly where the next phase of enterprise AI begins – and exactly where it will be decided who uses the coming twelve months productively, and who ends up among the roughly 40 percent that gets abandoned.

Frequently asked questions

What exactly is an agent control plane?
An agent control plane is the operational layer between an AI agent and its production operation. It governs identity, policy enforcement, sandbox isolation, observability and deployment – regardless of which model or framework the agent was built with.
Why did four vendors launch similar platforms within a single week?
Red Hat, Google, BCG and IBM independently recognized between 11 and 19 August 2026 that companies fail at the same point: not at building agents, but at operating them safely at enterprise scale. The timing shows that a new standard layer of enterprise AI architecture is emerging.
What is agent sprawl and how does it relate to the control-plane gap?
Agent sprawl refers to the uncontrolled proliferation of individual agents without a central registry, identity mapping or cost control. Without a control plane, this problem emerges almost automatically once more than a handful of agents run in production.
Is a control-plane solution mandatory for FINMA-regulated companies?
No specific technology is explicitly mandated. But the requirements around traceability, data protection and risk control are difficult to meet in practice without a layer that delivers audit trails, identity and policy enforcement.
Should Swiss SMEs commit to one vendor or plan for a hybrid approach?
According to BCG data, 51 percent of companies expect a hybrid control-plane architecture without single-vendor lock-in by the end of 2026. For most Swiss SMEs, an approach that builds on existing infrastructure such as Red Hat OpenShift or existing cloud contracts makes more sense than forcing a complete new procurement.

Sources

Would you like to explore this topic for your company?

Check Availability

More articles