An OutSystems survey of 1,900 IT leaders found that 96% of enterprises now run AI agents in production β but only 12% can actually govern them. That gap is not a product roadmap problem. It is an operational risk that compounds every week another team spins up another copilot, another embedded agent, another shadow deployment nobody in IT even knows about.
- What Is an AI Agent Control Plane?
- Why 2026 Is the Inflection Point
- 1. Agent Sprawl Hit Critical Mass
- 2. Regulatory Pressure Materialized
- 3. Multi-Vendor Agent Estates Became the Norm
- The Five Leading Approaches: A Detailed Comparison
- 1. IBM watsonx Orchestrate β The Agentic Control Plane
- 2. ServiceNow AI Control Tower
- 3. Google Gemini Enterprise Agent Platform
- 4. Palo Alto Networks Prisma AIRS (via Portkey Acquisition)
- 5. Open-Source: agentgateway (Agentic AI Foundation / Linux Foundation)
- Decision Table: Choosing Your Control Plane
- The Architecture Pattern: What Every Control Plane Has in Common
- Layer 1: Agent Registry and Discovery
- Layer 2: Policy Engine and Identity
- Layer 3: Observability and Telemetry
- Layer 4: Enforcement and Circuit Breaking
- Practical Implementation: Where to Start
- Phase 1: Discovery and Inventory (Weeks 1-4)
- Phase 2: Risk Tiering (Weeks 4-6)
- Phase 3: Vendor Selection and Deployment (Weeks 6-12)
- Phase 4: Operationalize and Scale (Ongoing)
- The Market Trajectory: What Comes Next
- FAQs
- What is the difference between an AI agent control plane and an AI gateway?
- Do I need a control plane if I only have a few AI agents?
- Can I use multiple control planes for different parts of my organization?
- How do open-source options like agentgateway compare to commercial platforms?
- Which compliance frameworks do AI agent control planes support?
- Key Takeaways
- References
In Q2 2026, Forrester published its first-ever Agentic Control Plane Solutions Landscape, identifying 33 vendors competing to close that governance gap. The timing is not coincidental. Three of the worldβs largest enterprise software companies β IBM, ServiceNow, and Google β shipped dedicated agent control planes within weeks of each other. Palo Alto Networks paid roughly $700 million to acquire AI gateway startup Portkey. And the open-source community launched its own answer through the Linux Foundationβs Agentic AI Foundation.
This article breaks down what an AI agent control plane actually is, compares the five leading approaches, and gives you a practical framework for choosing the right one based on where your organization sits on the agent maturity curve.

What Is an AI Agent Control Plane?
Forrester defines the agentic control plane as βa common enterprise governance and control platform that sits above and across a heterogeneous estate of AI agents and agentic skills and applies a consistent envelope of oversight, governance, and controls so the agent portfolio can be managed consistently across platforms, vendors, and use cases.β
In plain terms: it is the operational layer that answers four questions about every AI agent in your organization.
- Discovery β What agents exist, where do they run, and who owns them?
- Governance β What policies, permissions, and guardrails apply to each agent?
- Observability β What is each agent doing right now, and how is it performing?
- Enforcement β Can we shut down a misbehaving agent in real time, before it causes damage?
If you have built or deployed multi-agent systems using frameworks like LangGraph, CrewAI, or Google ADK, you already know how quickly the agent count multiplies once teams start composing agents into workflows. The control plane is the answer to what happens after the build phase β when dozens or hundreds of agents need to coexist in a governed production environment.
Why 2026 Is the Inflection Point
Three converging forces made the control plane category inevitable in 2026:
1. Agent Sprawl Hit Critical Mass
Forresterβs research found that organizations significantly underestimate their AI footprint as agents proliferate through copilots, embedded SaaS features, departmental builds, and shadow projects. Their blunt assessment: βBuyers canβt govern agents they canβt see.β When your enterprise has agents embedded in Salesforce, Microsoft 365, ServiceNow, custom LangGraph deployments, and vendor-specific copilots β all running simultaneously β the governance challenge is fundamentally different from managing a handful of RPA bots.
If you have seen this pattern play out in traditional RPA programs, you will recognize the parallels. Many of the same reasons agentic automation programs fail β lack of governance, no centralized oversight, βshadow automationβ proliferating unchecked β apply directly to the current AI agent landscape, only now the agents are autonomous and can take consequential actions.
2. Regulatory Pressure Materialized
The EU AI Actβs enforcement timeline, NISTβs AI Risk Management Framework updates, and sector-specific AI governance mandates (particularly in financial services and healthcare) created a compliance forcing function. Enterprises cannot simply promise to govern agents later. They need auditable proof that governance is in place β now.
3. Multi-Vendor Agent Estates Became the Norm
No enterprise runs agents from a single vendor. A typical 2026 enterprise agent estate includes Microsoft Copilot agents, Salesforce Agentforce agents, ServiceNow autonomous workflows, custom agents built on open-source frameworks, and vendor-embedded AI features that technically qualify as agents but were never registered anywhere. The control plane exists because no single vendor can govern the whole estate β and every vendor knows it.
The Five Leading Approaches: A Detailed Comparison
The control plane market has already stratified into five distinct approaches. Each reflects a different theory about where governance should live and who should own it.
1. IBM watsonx Orchestrate β The Agentic Control Plane
IBM launched the Agentic Control Plane in June 2026 as part of watsonx Orchestrate, available on both AWS and IBM Cloud. The positioning is explicit: IBM wants watsonx Orchestrate to be the single pane of glass for every AI agent in the enterprise, regardless of where that agent was built.
Key capabilities:
- Multi-framework agent support β IBM native agents, Langflow agents, LangGraph agents, and agents built with the open A2A (agent-to-agent) protocol are all supported, with broader interoperability on the roadmap.
- Agent Catalog β A tenant-level catalog where teams publish agents with semantic versioning, descriptions, categories, and icons. When an agent has dependencies (collaborator agents, Python tools), those travel automatically during publication.
- Security Control Center β Centralized security dashboard with real-time safety guardrails designed to prevent cascading failures in autonomous workflows.
- Natural-language scheduling β Users can schedule recurring agent tasks directly through conversational chat, lowering the barrier for business users to operationalize agents.
- Analytics overhaul β Revamped analytics experience providing end-to-end visibility into agent activities, performance metrics, and usage patterns.
Best fit: Enterprises already invested in IBMβs AI stack, or organizations running heterogeneous agent frameworks (especially LangGraph and A2A-compatible agents) that need a vendor-neutral orchestration layer. IBMβs support for open protocols (A2A) is a meaningful differentiator for organizations wary of lock-in.
At Think 2026, IBM also unveiled a catalog of over 150 pre-built agents, signaling that they see the control plane not just as a governance tool but as an agent marketplace for enterprise reuse.
2. ServiceNow AI Control Tower
ServiceNow took a different angle at Knowledge 2026: rather than positioning as an agent builder, they positioned AI Control Tower as the governance layer that sits above every agent vendor in the enterprise. The ambition is to discover, govern, observe, secure, and measure every AI agent, model, and workflow across the organization β regardless of origin.
Key capabilities:
- Cross-platform discovery β 30 new enterprise integrations spanning AWS, Google Cloud, Microsoft Azure, and enterprise applications like SAP, Oracle, and Workday. This lets AI Control Tower discover AI assets deployed outside ServiceNowβs own ecosystem.
- Risk frameworks β Five new risk assessment frameworks aligned to NIST and EU AI Act standards, providing compliance controls across agents, models, datasets, prompts, and classic ML systems.
- Real-time enforcement β The Control Tower can detect abnormal agent behavior, flag it in real time, automatically revoke the agentβs permissions, and shut it down.
- Identity governance β Extended identity access governance to hyperscaler AI environments and connected devices.
- Project Arc β A joint initiative with NVIDIA creating an autonomous desktop agent secured by the NVIDIA OpenShell runtime and governed by AI Control Tower. This extends governance from cloud agents to desktop-level autonomous workflows.
Best fit: Large enterprises that already use ServiceNow as their IT Service Management (ITSM) or IT Operations Management (ITOM) backbone. ServiceNowβs strength is that it already knows your infrastructure, your users, your approval workflows, and your compliance posture β extending that to AI agent governance is a natural adjacency. The NIST/EU AI Act alignment is particularly relevant for regulated industries.
ServiceNow also deepened its integration with Microsoft, extending AI Control Towerβs governance to Microsoft Agent 365 and the broader Azure-backed Foundry and Copilot Studio ecosystem.
3. Google Gemini Enterprise Agent Platform
At Cloud Next 2026, Google made a significant architectural decision: it rebranded and consolidated Vertex AI into the Gemini Enterprise Agent Platform, absorbing Agentspace into a unified product. The message was clear β Google is no longer selling model access. It is selling the full agentic enterprise platform, with governance at the center.
Key capabilities:
- Unified control plane β Every agent deployed inside a company is visible, auditable, and controllable through a single control layer. Agents built on Agent Platform and surfaced in the Gemini Enterprise app operate under the same rules.
- Govern and Optimize layers β The most meaningful new product at Next β26 focused on identity management, agent registry, gateway functions, anomaly detection, simulation, evaluation, and observability.
- A2A protocol integration β Googleβs Agent-to-Agent (A2A) protocol, designed for cross-vendor agent communication, is natively supported. If you have been building multi-agent systems with Google ADK, the governance layer now provides production-grade oversight for those deployments.
- Security GA β Google Threat Intelligence moved its agentic AI capabilities from public preview to general availability for Enterprise and Enterprise+ customers, specifically targeting automated threat hunting, incident response, and alert triage governance.
Best fit: Organizations building on Google Cloud, particularly those using ADK for multi-agent orchestration. Googleβs advantage is vertical integration β the models, the agent framework, the deployment platform, and the governance layer are all first-party. The trade-off is that the governance story is strongest for Google-native agents and weaker (though improving) for third-party agent estates. Bain & Company, in their post-Next analysis, described Googleβs approach as βthe agentic enterprise control plane coming into viewβ β acknowledging both the ambition and the fact that multi-vendor governance is still a work in progress.
4. Palo Alto Networks Prisma AIRS (via Portkey Acquisition)
Palo Alto Networks completed its acquisition of AI gateway startup Portkey in May 2026, in a deal The New Stack valued at roughly $700 million. This represents the cybersecurity industryβs largest bet on agentic AI governance to date β and it reflects a fundamentally different philosophy from the three approaches above.
Where IBM, ServiceNow, and Google approach the control plane from the platform side (helping you build and manage agents), Palo Alto approaches it from the security side (treating every agent as a βprivileged insiderβ that needs to be monitored, authenticated, and contained).
Key capabilities:
- AI Gateway as central nervous system β Portkey now serves as the AI Gateway for Palo Altoβs Prisma AIRS platform, inspecting, routing, and securing every AI transaction across the enterprise.
- Scale β Portkey processes trillions of tokens per month with latency low enough for agent-to-agent communication, a critical requirement for real-time governance of autonomous agents.
- Multi-model governance β Centralized management across more than 3,000 LLMs and MCP tools, with semantic routing and automated failovers providing 99.99% uptime for autonomous workloads.
- Artifact management β Seamless versioning and secure access control across all AI models, agents, and MCP servers.
- Runtime enforcement β Governance policies enforced at runtime β not just at deployment β meaning the gateway can intervene while agents are actively operating.
Best fit: Security-first organizations, particularly in financial services, government, and healthcare, where the CISOβs office needs to govern AI agents with the same rigor applied to network security. Palo Altoβs approach is especially relevant for enterprises where the security team, not the platform team, owns the agent governance mandate. If your concern is less about βwhich agents existβ and more about βwhat damage can they do,β this is the approach designed for you.
5. Open-Source: agentgateway (Agentic AI Foundation / Linux Foundation)
In June 2026, Solo.io donated its agentgateway project to the Agentic AI Foundation under the Linux Foundationβs governance. This made it the fourth hosted project under the foundation, and it represents the open-source communityβs answer to the proprietary control plane race.
Key capabilities:
- Protocol-agnostic traffic management β Handles MCP (Model Context Protocol), agent-to-agent (A2A), inference, HTTP, and gRPC traffic through a single data plane.
- Community scale β Over 300 contributors across 60 organizations including CoreWeave, Red Hat, Adobe, Salesforce, and Microsoft β an unusually broad coalition for an early-stage project.
- Apache 2.0 licensing β No vendor lock-in, no usage fees, full source access.
- Composability β Designed to be embedded into larger governance stacks rather than replacing them, making it complementary to (rather than competitive with) the proprietary platforms above.
Best fit: Platform engineering teams building custom agent infrastructure, organizations with strong open-source mandates, and companies that want governance primitives without committing to a specific vendorβs control plane vision. The agentgateway is not a complete control plane β it is the data-plane layer that a control plane needs. Think of it as the Envoy of agentic AI: a building block, not a finished product.
For practitioners already working with the prompts-context-loops architecture of modern AI engineering, the agentgateway provides the infrastructure layer that sits beneath those abstractions and governs the traffic between them.
Decision Table: Choosing Your Control Plane
| Criteria | IBM watsonx Orchestrate | ServiceNow AI Control Tower | Google Gemini Enterprise | Palo Alto Prisma AIRS | agentgateway (OSS) |
|---|---|---|---|---|---|
| Primary angle | Build + govern | Govern + comply | Build + govern (Google-native) | Secure + enforce | Route + observe (data plane) |
| Multi-vendor agent discovery | Moderate (A2A, LangGraph, Langflow) | Strong (30+ integrations, AWS/GCP/Azure/SAP/Oracle) | Moderate (strongest for GCP-native) | Strong (3,000+ LLMs, MCP tools) | Protocol-level (MCP, A2A, gRPC) |
| Compliance frameworks | IBM AI Ethics, custom | NIST, EU AI Act (5 frameworks) | Google AI Principles, evolving | Security-first, CISO-aligned | BYO compliance layer |
| Real-time enforcement | Yes (guardrails) | Yes (auto-revoke + shutdown) | Yes (anomaly detection) | Yes (runtime policy enforcement) | Routing-level only |
| Agent catalog/marketplace | 150+ pre-built agents | 50+ specialized agents (Slack/Teams/IT) | Gemini Enterprise app ecosystem | N/A (security focus) | N/A |
| Open protocol support | A2A | Proprietary + Microsoft Agent 365 | A2A (creator) | MCP, multi-model | MCP, A2A, HTTP, gRPC |
| Best for | Multi-framework enterprises | ITSM-centric, regulated | Google Cloud-native | Security-first orgs | Platform engineering teams |
| Availability | GA (June 2026) | Innovation Lab (May); GA expected Aug 2026 | GA (Cloud Next 2026) | GA (May 2026) | Apache 2.0 (June 2026) |
The Architecture Pattern: What Every Control Plane Has in Common
Despite the differences in positioning and feature sets, all five approaches share a common architectural pattern. Understanding this pattern helps you evaluate any control plane β including ones from the other 28 vendors in Forresterβs landscape report that we have not covered here.
Layer 1: Agent Registry and Discovery
Every control plane starts with an inventory. You cannot govern agents you do not know about. The registry discovers agents across the enterprise β including embedded copilots, SaaS-native agents, and custom deployments β and maintains a live catalog with ownership, version, permissions, and dependency metadata.
This is where the 96% vs. 12% gap lives. Most enterprises have agents running in production that no central team authorized, registered, or even knows about. The registry closes that blind spot.
Layer 2: Policy Engine and Identity
Once agents are discovered, the control plane applies governance policies: which tools can each agent access, what data can it read, which actions require human approval, and what identity does the agent operate under. This is the layer that maps enterprise IAM (Identity and Access Management) concepts to agent-level permissions.
ServiceNowβs approach to this layer is particularly mature, given its existing identity governance infrastructure. IBMβs approach leverages its enterprise security heritage. Google integrates with Cloud IAM natively.
Layer 3: Observability and Telemetry
Real-time monitoring of agent activities: what each agent is doing, how long it takes, what errors it encounters, what data it accesses, and how it interacts with other agents. This layer produces the audit trail that compliance teams need and the performance data that operations teams use to optimize.
Layer 4: Enforcement and Circuit Breaking
The critical differentiator between a βgovernance dashboardβ and a true control plane: the ability to intervene in real time. When an agent behaves anomalously β accessing data it should not, taking actions outside its scope, or cascading failures through a multi-agent workflow β the enforcement layer can revoke permissions, halt execution, or reroute traffic. ServiceNowβs auto-revoke-and-shutdown capability and Palo Altoβs runtime policy enforcement are the most aggressive implementations of this layer today.
Practical Implementation: Where to Start
For organizations that have not yet implemented a control plane, the Forrester research suggests a phased approach. Trying to boil the ocean β governing every agent on day one β is a recipe for the project stalling in committee.
Phase 1: Discovery and Inventory (Weeks 1-4)
Before selecting a vendor, run an internal discovery exercise. Catalog every AI agent, copilot, and embedded AI feature running in your environment. Include:
- Vendor-provided agents (Microsoft Copilot, Salesforce Agentforce, ServiceNow autonomous workflows)
- Custom-built agents (LangGraph, CrewAI, Google ADK deployments)
- Shadow agents (departmental experiments, personal GPTs connected to enterprise data, browser-based copilots)
- Embedded AI features in SaaS products that technically qualify as agents
Most organizations discover 3-5x more agents than they expected. That discovery itself often provides the executive sponsorship needed for the governance investment.
Phase 2: Risk Tiering (Weeks 4-6)
Not every agent needs the same level of governance. Tier your agents by risk:
- Tier 1 (critical) β Agents that can take financial actions, access PII, or interact with customers
- Tier 2 (significant) β Agents that access internal business data or make recommendations humans act on
- Tier 3 (low) β Read-only agents, summarization tools, internal productivity copilots
Apply control plane governance to Tier 1 first. This keeps the initial scope manageable while addressing the highest-risk agents immediately.
Phase 3: Vendor Selection and Deployment (Weeks 6-12)
Use the decision table above to shortlist vendors based on your existing infrastructure, compliance requirements, and the composition of your agent estate. Key questions:
- Is your agent estate primarily one vendorβs ecosystem, or genuinely multi-vendor? (Single-vendor β Google or IBM; multi-vendor β ServiceNow or Palo Alto)
- Does governance report to the platform team or the security team? (Platform β IBM, Google, agentgateway; Security β Palo Alto, ServiceNow)
- What compliance frameworks are mandatory for your industry? (EU AI Act / NIST β ServiceNow has the most mature framework alignment)
- Do you need to govern desktop-level agents, not just cloud agents? (Desktop β ServiceNowβs Project Arc with NVIDIA OpenShell)
Phase 4: Operationalize and Scale (Ongoing)
The control plane is not a one-time deployment. As new agents enter the estate β and they will, constantly β the discovery, tiering, and governance cycle repeats. The best implementations treat the control plane as a living system with regular reviews, updated policies, and continuous monitoring.
If you are building custom agents today using frameworks like LangGraph, plan for governance from the start. The LangGraph deployment pipeline should include control plane registration as a standard step, not an afterthought bolted on months after the agent is already in production.
The Market Trajectory: What Comes Next
The AI governance platform market is projected to reach $492 million in 2026 and exceed $1 billion by 2030. Several trends will shape where this market heads:
Consolidation is already happening. Palo Altoβs Portkey acquisition is the first major M&A move, but it will not be the last. Expect infrastructure vendors (cloud providers, security platforms, ITSM providers) to acquire specialized governance startups throughout 2026 and 2027.
Open standards will determine interoperability. The A2A protocol (backed by Google, supported by IBM) and MCP (Model Context Protocol) are emerging as the communication standards agents use to talk to each other and to tools. Control planes that support these protocols natively will have an advantage over those requiring proprietary integrations. The agentgateway projectβs protocol-agnostic approach β handling MCP, A2A, inference, HTTP, and gRPC through one data plane β reflects where the open-source community thinks this is heading.
The βagent gatewayβ category will merge with the control plane category. Today, some vendors offer gateways (traffic management, routing, security enforcement) and others offer control planes (discovery, governance, observability). Within 18 months, the market will expect both capabilities in a single product. Forresterβs landscape report already evaluates vendors across both dimensions.
FAQs
What is the difference between an AI agent control plane and an AI gateway?
An AI gateway operates at the data-plane level β it routes, authenticates, and monitors traffic between agents and the models or tools they access. A control plane operates at the management level β it discovers agents, applies governance policies, provides observability, and enforces compliance. In practice, the market is converging: enterprise buyers expect both capabilities in a single product, and Forrester evaluates vendors across both dimensions. Think of the gateway as the enforcement mechanism and the control plane as the policy and visibility layer that directs it.
Do I need a control plane if I only have a few AI agents?
You probably have more agents than you think. Forresterβs research found that enterprises systematically undercount their AI agent footprint, especially when factoring in embedded copilots, SaaS-native agents, and shadow deployments. If you have fewer than 10 agents, a formal control plane may be premature β but you still need an inventory. Start with a manual discovery exercise and revisit the control plane decision as your agent count grows past the point where a spreadsheet can track them.
Can I use multiple control planes for different parts of my organization?
You can, but it defeats the purpose. The core value of a control plane is a single, unified view of the entire agent estate. Running multiple control planes recreates the visibility gap the technology was designed to close. If organizational politics require divisional autonomy, consider a federated model: one primary control plane with delegated governance domains for different business units.
How do open-source options like agentgateway compare to commercial platforms?
The open-source agentgateway provides data-plane capabilities β traffic routing, protocol handling, and basic observability β under Apache 2.0 licensing with no vendor lock-in. It does not provide the full governance stack (discovery, compliance frameworks, agent catalogs, risk assessment) that commercial platforms offer. It is best positioned as a building block for platform engineering teams constructing custom governance infrastructure, or as the data-plane layer beneath a commercial control plane.
Which compliance frameworks do AI agent control planes support?
ServiceNowβs AI Control Tower leads with five built-in risk frameworks aligned to NIST and EU AI Act standards. IBM integrates with its AI Ethics frameworks and supports custom policy configurations. Google aligns with its published AI Principles and Cloud IAM policies. Palo Alto focuses on security-first compliance aligned with CISO requirements. The specific frameworks supported should be a primary selection criterion for regulated industries β check whether the vendorβs built-in frameworks match your regulatory obligations or whether you will need to build custom policies.
Key Takeaways
- The governance gap is real and urgent: 96% of enterprises run AI agents in production, but only 12% have the tooling to govern them. Forrester has formally recognized βagentic control planeβ as an enterprise software category with 33 vendors.
- Five distinct approaches have emerged: IBM (build + govern), ServiceNow (govern + comply), Google (build + govern, Google-native), Palo Alto Networks (secure + enforce), and open-source agentgateway (route + observe).
- Start with discovery, not vendor selection: Most organizations discover 3-5x more agents than expected. The inventory exercise itself often generates the executive sponsorship for governance investment.
- Match the control plane to governance ownership: If governance reports to the platform team, look at IBM or Google. If it reports to the CISO, look at Palo Alto. If it reports to IT operations, look at ServiceNow.
- Open protocols (A2A, MCP) will be the interoperability backbone: Prioritize control planes with native support for these standards to avoid lock-in as the multi-agent ecosystem matures.
- Plan for governance at build time: If you are building custom agents today, include control plane registration in your deployment pipeline from day one.
References
- Forrester, Agentic Control Plane Solutions Landscape, Q2 2026 β forrester.com
- IBM, βAgentic Control Plane in IBM watsonx Orchestrate: One Place to Control Every AI Agentβ β ibm.com
- ServiceNow Newsroom, βServiceNow expands AI Control Tower to discover, observe, govern, secure, and measure AIβ β newsroom.servicenow.com
- Bain & Company, βGoogle Cloud Next 2026: The Agentic Enterprise Control Plane Comes into Viewβ β bain.com
- Palo Alto Networks, βPalo Alto Networks Completes Acquisition of Portkey to Secure AI Agentsβ β paloaltonetworks.com
- The New Stack, βPalo Alto Networks makes a $700M-class AI bet on Portkey gatewayβ β thenewstack.io
- Forbes, βAgent Gateways Are Becoming The Control Plane For Enterprise AIβ β forbes.com
- TWIML AI, βGoogle Cloud Next β26: Delivering the Agentic Control Planeβ β twimlai.com
- Speakeasy, β2026 Is the Year of Enterprise AI Governanceβ β speakeasy.com
- OutSystems, 2026 IT Leader Survey (cited via Google Cloud Next coverage)









