AI control is becoming an architecture problem for CIOs
CIOs face multiple AI control layers across orchestration, models, data, identity and governance. The challenge is understanding how those layers work together.
As companies add AI agents, models and embedded capabilities, they are also accumulating systems that control how those technologies behave. Those systems increasingly govern orchestration, model selection, data access, identity, permissions, observability and deployment.
For CIOs, the issue is no longer simply which AI model, agent or tool works best. It is how the growing number of control layers around those technologies fit together -- and what happens when they do not.
Enterprises should not assume one enterprise-wide control plane will be feasible or sufficient. Different platforms are controlling different things, and many of those approaches make sense on their own. The risk is that a series of sensible product decisions eventually produces a fragmented control architecture, with several systems governing AI differently, multiple vendors owning important routing or integration points and responsibility divided among application, data, security, infrastructure and AI teams.
No single purchase creates that problem. The accumulation does.
Recent TechTarget reporting shows how quickly those control functions are spreading across the AI stack. Salesforce is assembling orchestration, identity, permissions, governance, observability and cost visibility around multivendor agents. GitHub is testing runtime model routing. Alteryx is positioning itself between AI systems and governed enterprise data and business logic. Mistral is making infrastructure, deployment and provider choice part of its control pitch.
The vocabulary has moved almost as quickly. In what can feel like a matter of months, CIOs have been asked to think about orchestration, context management, harnesses and control planes. Those concepts are not simply replacing one another. They are increasingly coming together around the same basic problem: how to make AI effective enough to act across enterprise systems while controlling what it can see, what it can do and how those actions are governed.
Earlier orchestration questions centered on how agents, applications and workflows would work together. The emerging question goes one level further: How do the systems that orchestrate, route, observe and govern those agents relate to one another -- and which one is authoritative when their controls overlap?
The control layer becomes control layers
Salesforce's Enterprise AI Harness is designed to orchestrate and govern agents across systems, including agents from other vendors. Its approach brings together functions involving permissions, identity, governance, observability, orchestration and cost visibility. Underneath the broader harness, Salesforce calls its observability component an "AI Control Plane."
GitHub's experimental HydraFusion adds another dimension. Rather than requiring users to select one model for a task, HydraFusion can dynamically choose one model or a combination of models based on the work being done. Model selection can therefore become a run-time control decision rather than a choice made once when a tool is adopted.
Alteryx is approaching the problem from the data side. It is positioning itself as connective tissue between enterprise AI and governed data and business logic.
Integration vendors are addressing yet another part of the control problem. At the Boomi World Tour Sydney, Boomi's Asia Pacific and Japan CTO described governance that includes routing queries to appropriate models and carrying a person's access rights through to an agent acting on that person's behalf. That brings identity and permissions into the same conversation as model routing, integration and agent behavior.
These approaches are not all competing to occupy the exact same technical layer. They control different parts of an AI environment, even as the functions involved -- context, orchestration, permissions, data access, model choice, governance and observability -- increasingly overlap.
The control functions might be coming together. The places where those controls live are multiplying.
Agent harnesses illustrate that convergence. A well-designed harness can surround a model with context management, memory, tools, guardrails, monitoring, error handling and governance. A model-agnostic harness can also make it easier to change underlying models without rebuilding every surrounding capability, although it does not make model replacement effortless.
The control functions might be coming together. The places where those controls live are multiplying.
That is the architectural problem for CIOs.
Sensible product decisions can create an irrational whole
Consider the choices individually. Salesforce's control capabilities might solve a legitimate orchestration problem, GitHub's model routing might improve how development work is handled and Alteryx's governed data layer might help keep business logic consistent across AI tools. An enterprise might also use Microsoft agents, several commercial models, internally developed models and AI embedded inside applications it already owns.
None of those choices is necessarily wrong. In the moment, each could solve a legitimate business or technology problem.
The difficulty appears when the CIO considers the aggregate. Over time, an enterprise could end up with several systems governing AI differently, with permissions behaving one way on one platform and another way on another. One system might decide which model executes a task, another governs the data available to it, and a third controls the agent that takes action.
Visibility can fragment along with the controls. Business logic, context, permissions or orchestration can become tied to particular platforms, making it harder to change vendors later. Responsibility can spread across application, data, security, infrastructure, architecture and AI teams without any one of them having a clear view of how the control layers operate together.
That should sound familiar to CIOs. Enterprise technology has spent years trying to reduce the fragmentation created when applications, integrations, data and business processes are developed independently. AI control technologies are intended to make a complex environment more manageable, but when adopted in isolation, they could ultimately recreate the same problem.
One control plane is probably not the answer
The response should not be to find one vendor and hand it control of everything. That might not be feasible, and given how quickly AI technology and the vendor market are changing, it might not be desirable.
The platforms building orchestration, context, harness and control technologies are responding to real problems. Agents need trusted data, security boundaries, identity, context, oversight and ways to interact safely with enterprise systems and one another. Enterprises need those capabilities, and different platforms will be well-suited to provide different parts of them.
The mistake would be to confuse the control mechanisms supplied by one product with the enterprise's control architecture.
A Salesforce environment might reasonably use Salesforce orchestration without making Salesforce the authority for enterprise identity, data governance or every model-routing decision. A data platform might govern access to trusted business information without becoming the authority for every agent that uses it.
Different layers can remain authoritative for different things. What matters is whether the enterprise understands those boundaries and how one layer interacts with another.
CIOs need visibility across control layers
CIOs should not assume that a single control plane will provide sufficient control over the enterprise AI environment. They need visibility across the multiple control layers they enable and deploy, along with an understanding of how those layers work together.
That visibility needs to be more specific than an inventory. CIOs need to know what each control layer governs, who owns it, what systems or data it depends on, what telemetry it produces and which control takes precedence when two layers make decisions about the same agent, identity, workflow or piece of data.
That means moving some decisions above the individual technology purchase. An enterprise might decide that identity and permission rules need to remain consistent across platforms while allowing application-specific orchestration to remain local. It might establish a single authoritative source for data-access policy while allowing different products to determine how they route work across models. It might require common observability or auditability even when the underlying agents come from several vendors.
The exact division will vary by enterprise, and it is probably too early to prescribe one architecture as the answer.
Ownership gets harder, too. An AI workflow can touch an application, enterprise data, identity, security and infrastructure before the work is done. Each of those areas might have a legitimate owner, but that does not mean anyone has a clear view of the whole thing. A CIO can end up with plenty of control at the individual platform level and still lack visibility across the environment.
CIOs do not have to settle every one of these questions before deploying another agent. The market is too fluid and enterprise environments too different for that.
But visibility matters before standardization does. An organization cannot decide which controls need to be common, which can remain local or which platform should be authoritative until it knows what control points it has accumulated and how they interact.
AI vendors are developing increasingly sophisticated methods to make complex agentic environments manageable. CIOs need to ensure those systems do not become another layer of complexity.
James Alan Miller is a veteran technology editor and writer and Lead Editor for CIO News at Informa TechTarget. He directs coverage of enterprise technology strategy, AI, software, data, infrastructure and the decisions shaping how CIOs manage increasingly complex IT environments.