Grid of AI agents illustrating the challenge of governing autonomous AI systems with an enterprise agent control plane

Who Gets to Control the AI Agent?

Agent control planes are already arriving. Identity vendors, hyperscalers, data platforms, gateways and security companies are staking claims over where the controls belong – and who gets the final say when autonomous software acts.

AI agents are having a strange moment. They sit somewhere between a homicidal swarming mass and the inventory bot Charlie in accounting Vibe-coded over the long weekend.

On Tuesday, Jacob Coxon quit Anthropic with a warning that companies building some of the world’s most powerful AI systems are “racing straight to self-improving superintelligence and gambling with our lives.” On Thursday, Visa, Mastercard and Ant International launched Know Your Agent, an effort to harden rules around personal AI shopping bots.

Two wildly different examples touch on the same question: When software can act in the world with some autonomy, who decides what it is allowed to do? And who pulls the plug when it goes too far?

That question is rapidly becoming an enterprise architecture problem. Businesses want agents that can query databases, call APIs, open browsers, write code, handle files, spend money and delegate work to other agents. Each new capability makes an agent more useful – and raises the stakes when something goes wrong.

Michael Bell, CEO of Suzu Labs, described the challenge as “threading the needle.” Anyone building an agent, he said, needs to know what it must touch to produce useful results – and keep everything else out of reach.

The more useful an agent becomes, the more authority it needs. Give it too little and the promised productivity disappears. Give it too much and a misunderstood instruction, prompt injection, compromised credential or simply a bad decision can have real-world consequences.

Roblox got a preview of that risk in February. During an internal red-team test, a hidden instruction in a GitHub issue convinced Claude Code to upload company credentials to a public repository.

The Market Is Here. The Map Isn’t

The control-plane debate over how much autonomy to give AI agents is not semantic. Agents are already crossing cloud accounts, SaaS apps, browsers, endpoints, APIs and corporate data. CISOs are being asked to govern that movement with controls scattered across the same terrain.

An agent control plane promises to pull those controls together: know which agents exist, limit what they can reach, govern what they can do and stop them when necessary. The harder question is who gets that authority – and whether it survives when an agent leaves one vendor’s turf for another’s.

The timing is awkward. Enterprises are moving from a handful of experimental agents toward fleets of autonomous software before the industry has settled on how to govern them across platforms. Vendors are already planting flags in identity, cloud, data, gateways and applications, while the standards needed to carry policy and trust between those domains are still catching up.

For CISOs, the choices being made now could decide whether the coming agent estate operates under one coherent set of rules – or becomes another generation of security silos moving at machine speed.

The agent era cannot come fast enough for some companies. Gartner expects task-specific agents in 40% of enterprise applications by the end of this year. It also predicts that by 2027, 40% of enterprises will demote or decommission autonomous agents after production incidents expose governance gaps.

That is a remarkable collision: companies are racing to deploy agents even as analysts expect many of them to discover they cannot safely govern what they built.

“At ten agents, operators may be able to inspect most recommendations,” said Christian Schnedler, CEO of Rilian Technologies. “At a thousand agents, an undifferentiated escalation queue will overwhelm them.” The danger, he said, is that reviewers begin rubber-stamping decisions, turning human approval into a checkbox.

What has changed is the market around that problem. Forrester now treats the agent control plane as a third functional plane in enterprise agent architecture, alongside the systems used to build and orchestrate agents.

The products remain “early and uneven,” often embedded inside individual vendor ecosystems. But the category is no longer theoretical. In a February poll of 47 technology vendors, Forrester found 79% recognized agent control planes as a distinct product category, 92% had assigned a product manager or team to agent governance or control-plane functions, and 40% reported active RFPs or customer buying motions asking for one or its equivalent.

The market is taking shape. Its borders are not.

Everybody Wants a Choke Point

Microsoft calls Agent 365 its “control plane for agents,” extending familiar identity, security, data protection and administration machinery to agent fleets. Snowflake pulls the control plane toward governed enterprise data. Salesforce‘s MuleSoft Agent Fabric calls itself a vendor-agnostic agent control plane built to discover agents, impose policies and control their access across platforms. Palo Alto Networks says the AI gateway can become a mission-critical control plane for agent interactions. ServiceNow‘s AI Control Tower puts discovery, governance, runtime security and observability inside its enterprise workflow platform.

They overlap heavily. They also plant the flag in different ground.

The data platform sees the problem through data. The hyperscaler sees an extension of cloud and enterprise administration. The gateway vendor sees traffic and tool calls. The SaaS platform sees workflows. Identity companies see authority. Security vendors see enforcement and blast radius.

Each is effectively arguing that the best place to control an agent is the place where its own technology already has leverage.

That does not necessarily make the competing views contradictory. What is starting to form looks less like one giant control product than an AI-agent technology stack, with different layers responsible for different kinds of authority.

Security Point Break’s interviews across that stack make the pattern visible. Oak starts with identity. Keyfactor focuses on proving who issued an instruction. Delinea pushes authorization down to individual actions. Island argues policy has to follow an agent across browsers, endpoints, models and tools. ThreatLocker wants hard application boundaries at the endpoint. Cyntros watches for behavior the rules did not anticipate. Xage focuses on limiting blast radius. Rilian argues the final enforcement point has to sit outside the agent on a path it cannot bypass.

Taken together, the control plane looks less like a single choke point than a stack of enforceable ones. The problem is making them behave like one system.

The Missing Control Plane Between the Control Planes

There is a catch to buying identity from one vendor, an AI gateway from another, cloud governance from a third and runtime monitoring from a fourth: each can become another island.

Forrester says this is where the market remains immature. The industry is building plenty of control points, but the standards needed to carry an agent’s identity, permissions and activity cleanly between them are still catching up.

The weak point is the handoff. Agents cross applications, clouds, tools and data stores, carrying authority with them. A control granted in one place has to survive the move. A revoked permission has to stick. And when monitoring spots trouble, the signal has to reach something with the power to stop the action.

Otherwise, enterprises risk recreating an old cybersecurity problem at machine speed: a collection of individually useful security products that cannot agree on what is happening or who is in charge.

For CISOs, that makes the immediate challenge less about finding one magic “agent control plane” to buy than making sure the pieces they already have can work together. Know which agents exist. Give them durable identities. Track what they do. Keep enforcement outside the model. And avoid building a governance system that stops working whenever an agent crosses into another vendor’s territory.

Who Gets the Final Say?

The larger lesson is that no one control solves the problem.

An agent can have the right identity, carry a legitimate instruction and still make a terrible decision. It can stay inside its permissions and still reach too far. It can pass every policy check and then behave in a way nobody anticipated. Each layer closes one gap and exposes the next.

The hard part is making those controls work as one system – and making the answer stick when an agent moves from one system to another.

Rilian‘s engineering team reduces that principle to one line: “Use AI to inform the control system. Do not make AI the control system.”

Rilian comes at the problem from the orchestration layer. Its Caspian agentic harness records the context behind consequential decisions and routes tool calls and other actions through an invocation plane outside the agent itself. Its argument is not that every enterprise needs one monolithic control-plane product, but that the final enforcement point must sit somewhere the agent cannot bypass, with humans pulled back in when the consequences become too great to leave to software.

That may be the closest thing this market has to consensus. Agents can reason, recommend and act. They should not get to decide where their own boundaries end.

The agent control plane is arriving. The fight now is over who holds the leash – and whether it still works when the agent leaves their yard.

Adapted Image originally created by Shawn Suttle from Pixabay

Total
0
Shares
Previous Article
Cisco logo displayed against a red-toned cybersecurity threat graphic

Critical Cisco Firewall Bug Under Attack by Sandworm APT

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading